Received: by 2002:a9a:4c47:0:b029:116:c383:538 with SMTP id u7csp1115956lko; Tue, 13 Jul 2021 17:24:12 -0700 (PDT) X-Google-Smtp-Source: ABdhPJxAb3MhMByG0ktbsFUwIoS9cNblRbcrEa2tbTtShD8VvMOVmxOSVtxcbAPOCyXDAnJ7YK9F X-Received: by 2002:a6b:7619:: with SMTP id g25mr5135886iom.151.1626222251907; Tue, 13 Jul 2021 17:24:11 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1626222251; cv=none; d=google.com; s=arc-20160816; b=Yo+YXpKviLvP0WOVSkMdCAV3DRA4hS3rhaPFs8Z/8fHj6WMI9dgyxbQfLSrmEVJ8ZN 7BX4pBJaU07oJmiPqW/PsCtfJ0rlIQB4EH2RgeECBnEvsdL3VRXWxUZylPShEZTF1kyG 5ZJuU/EZ09ms82FMNZ36ONmBnXJSrMrmrftUQa3XAckPpKmkjgRshBYAQ2yiqLqOkqJk QWWShwOyadSjQVfWFhe8XNeVjZ40lK5w36y9vhAaU50PFUJsP7WiLAQYhmhzmQ+TmKMT XaIrAyuyLAcFtiPAxN6Jwh7tA+RqOvXsWLuVYbELWOwQSqgKbW1O20sqS8oUOUy2gMNW 55kA== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:content-transfer-encoding:mime-version :message-id:date:subject:to:from:dkim-signature; bh=NXbJfurgKICWNVQFX642RsimOUp1jbBIxlMZi53/Dow=; b=bjFHKlkVu7ZFvTHTBALp861TVFbqfjgXU3yxGxD4AJU1LvLPn/aWsZbvz1PeQXIIug fVzSWzxXRKMVMMHq6MIS6lj2sRmRX/jzGHSRcJg8vLbW5joE4IXP5Ggzyu+QoRONx4RA sW05/+aRsn7eEDnnhkDHkyYitLk9UC5B6clmUxLM18wzJ15KDhd8i4hERV3MQDa8azt2 bSgekXmOaonSj46S6rZyAm0MLM5hCAayPfl408s53YtKauFOaqMszTitaHOZMxxW7tdY jst6gh3Jk21LKKk1uGY9Hm4Dmmpk+bLsQMWkZQb3omXCEeS5PZOFEjZg6rlee4b0y617 uDHQ== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@gmail.com header.s=20161025 header.b=ajypaVSJ; spf=pass (google.com: domain of linux-bluetooth-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) smtp.mailfrom=linux-bluetooth-owner@vger.kernel.org; dmarc=pass (p=NONE sp=QUARANTINE dis=NONE) header.from=gmail.com Return-Path: Received: from vger.kernel.org (vger.kernel.org. [23.128.96.18]) by mx.google.com with ESMTP id f11si628313jav.53.2021.07.13.17.23.42; Tue, 13 Jul 2021 17:24:11 -0700 (PDT) Received-SPF: pass (google.com: domain of linux-bluetooth-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) client-ip=23.128.96.18; Authentication-Results: mx.google.com; dkim=pass header.i=@gmail.com header.s=20161025 header.b=ajypaVSJ; spf=pass (google.com: domain of linux-bluetooth-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) smtp.mailfrom=linux-bluetooth-owner@vger.kernel.org; dmarc=pass (p=NONE sp=QUARANTINE dis=NONE) header.from=gmail.com Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S237033AbhGNAZR (ORCPT + 99 others); Tue, 13 Jul 2021 20:25:17 -0400 Received: from lindbergh.monkeyblade.net ([23.128.96.19]:38252 "EHLO lindbergh.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S237022AbhGNAZR (ORCPT ); Tue, 13 Jul 2021 20:25:17 -0400 Received: from mail-pj1-x1036.google.com (mail-pj1-x1036.google.com [IPv6:2607:f8b0:4864:20::1036]) by lindbergh.monkeyblade.net (Postfix) with ESMTPS id 0BCAEC0613DD for ; Tue, 13 Jul 2021 17:22:27 -0700 (PDT) Received: by mail-pj1-x1036.google.com with SMTP id p9so178817pjl.3 for ; Tue, 13 Jul 2021 17:22:27 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=from:to:subject:date:message-id:mime-version :content-transfer-encoding; bh=NXbJfurgKICWNVQFX642RsimOUp1jbBIxlMZi53/Dow=; b=ajypaVSJuF2HuJVoSwN5C31vCHiRxT45MdAXl0Y45/WyQ3cF4T1Q3TtkJ1/U726X44 7y+8g/BvGrbpBTm0jIzKwrW1+Uns8oSkyas0+4J4I4x8J1WAa4dSacOd0hj8VjO2nxK+ hdPe1+S4a2bwcEihxacrlGdxQJ+uq/9XYbCjJqX82i4oPjIgkFugqEwrNZyfsLBog4+G WHDPWjgvEMp4RZBEeqAIv22Rf2hgzHCfAzkwOSyH4L3fWc59nYcHl11Ojnlo9aYS85x/ 2LJd3N0OPuORIs14umZHBU/90s8w/1LIQ50Nki1gW+Z99efk8bzUmyXQsCnHF2J8Knwg b5Qw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:from:to:subject:date:message-id:mime-version :content-transfer-encoding; bh=NXbJfurgKICWNVQFX642RsimOUp1jbBIxlMZi53/Dow=; b=Hr3uLYq3JorxlF+wwiPchWCdV+U+tIOjRM8njMIygHUQasqxCZGnT7DM8UPJtzKfuG 4vz4GaR4stZiuza5NBi6CseMJSeekl13kb803TLirgC8jaGazzQQ2jHS/L66Xr33u8tO BzQ4c4u7RjHCnU6Uo7ee4+tMo6O6Jj6761p6+lvXzxSsbenvA0n8NqLLBqslnoVnvYah u59wYkwjch8yPQ4RDjE/y6xMuh8xbMwf6VQj9Yl9jaMVtIehmOsS4M67AoRWa8UDqtuN fvvBEBLZSTXrn7IcVoW+IrIVxqAFvWsmghNpVh1wzfmxTkkxcMLuaSW6QMP+fQXeYLmF LWVA== X-Gm-Message-State: AOAM530gynOt/m1W06ilvja2qISHNE6SRmTqif7UOM2VHK9YFgzSuxsI rvIrHwgdgRqRlY2YnEHFc8uV2MfT9V3NwA== X-Received: by 2002:a17:90a:9205:: with SMTP id m5mr898713pjo.172.1626222146235; Tue, 13 Jul 2021 17:22:26 -0700 (PDT) Received: from lvondent-mobl4.intel.com (c-71-56-157-77.hsd1.or.comcast.net. [71.56.157.77]) by smtp.gmail.com with ESMTPSA id s15sm307818pfw.207.2021.07.13.17.22.25 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 13 Jul 2021 17:22:25 -0700 (PDT) From: Luiz Augusto von Dentz To: linux-bluetooth@vger.kernel.org Subject: [PATCH v2] btdev: Add proper checks for own_addr_type for extended advertising Date: Tue, 13 Jul 2021 17:22:24 -0700 Message-Id: <20210714002224.2632842-1-luiz.dentz@gmail.com> X-Mailer: git-send-email 2.31.1 MIME-Version: 1.0 Content-Transfer-Encoding: 8bit Precedence: bulk List-ID: X-Mailing-List: linux-bluetooth@vger.kernel.org From: Luiz Augusto von Dentz own_addr_type 0x01 and 0x03 shall check that a random address has properly been set and in case of 0x03 the resolving list actually contains the irk of the identity address: BLUETOOTH CORE SPECIFICATION Version 5.2 | Vol 4, Part E page 2596 'If the advertising set's Own_Address_Type parameter is set to 0x01 and the random address for the advertising set has not been initialized, the Controller shall return the error code Invalid HCI Command Parameters (0x12).' BLUETOOTH CORE SPECIFICATION Version 5.2 | Vol 4, Part E page 2597 'If the advertising set's Own_Address_Type parameter is set to 0x03, the controller's resolving list did not contain a matching entry, and the random address for the advertising set has not been initialized, the Controller shall return the error code Invalid HCI Command Parameters (0x12).' --- v2: Fix checks for Own_Address_Type when is to 0x03 since it can work with both resolving list _and_ when a random address is set. emulator/btdev.c | 44 ++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 44 insertions(+) diff --git a/emulator/btdev.c b/emulator/btdev.c index 1567713d2..b6142f176 100644 --- a/emulator/btdev.c +++ b/emulator/btdev.c @@ -4538,6 +4538,20 @@ static bool ext_adv_timeout(void *user_data) return false; } +static struct btdev_rl *rl_find(struct btdev *dev, uint8_t type, uint8_t *addr) +{ + unsigned int i; + + for (i = 0; i < ARRAY_SIZE(dev->le_rl); i++) { + struct btdev_rl *rl = &dev->le_rl[i]; + + if (RL_ADDR_EQUAL(rl, type, addr)) + return rl; + } + + return NULL; +} + static int cmd_set_ext_adv_enable(struct btdev *dev, const void *data, uint8_t len) { @@ -4561,6 +4575,7 @@ static int cmd_set_ext_adv_enable(struct btdev *dev, const void *data, for (i = 0; i < cmd->num_of_sets; i++) { const struct bt_hci_cmd_ext_adv_set *eas; struct le_ext_adv *ext_adv; + bool random_addr; eas = data + sizeof(*cmd) + (sizeof(*eas) * i); @@ -4576,6 +4591,35 @@ static int cmd_set_ext_adv_enable(struct btdev *dev, const void *data, goto exit_complete; } + random_addr = bacmp((bdaddr_t *)ext_adv->random_addr, + BDADDR_ANY); + + /* If the advertising set's Own_Address_Type parameter + * is set to 0x01 and the random address for + * the advertising set has not been initialized, the + * Controller shall return the error code Invalid HCI + * Command Parameters (0x12). + */ + if (ext_adv->own_addr_type == 0x01 && !random_addr) { + status = BT_HCI_ERR_INVALID_PARAMETERS; + goto exit_complete; + } + + /* If the advertising set's Own_Address_Type parameter is set + * to 0x03, the controller's resolving list did not contain a + * matching entry, and the random address for the advertising + * set has not been initialized, the Controller shall return the + * error code Invalid HCI Command Parameters (0x12). + */ + if (ext_adv->own_addr_type == 0x03 && !random_addr) { + if (!dev->le_rl_enable || + !rl_find(dev, ext_adv->direct_addr_type, + ext_adv->direct_addr)) { + status = BT_HCI_ERR_INVALID_PARAMETERS; + goto exit_complete; + } + } + ext_adv->enable = cmd->enable; if (!cmd->enable) -- 2.31.1