mirror of
https://github.com/mikecarper/MeshCore.git
synced 2026-08-28 18:58:19 +00:00
Merge remote-tracking branch 'upstream/dev' into fix/scoped-reply-routing
# Conflicts: # examples/simple_repeater/MyMesh.cpp
This commit is contained in:
@@ -147,11 +147,10 @@ uint8_t MyMesh::handleLoginReq(const mesh::Identity& sender, const uint8_t* secr
|
||||
uint8_t MyMesh::handleAnonRegionsReq(const mesh::Identity& sender, uint32_t sender_timestamp, const uint8_t* data) {
|
||||
if (anon_limiter.allow(rtc_clock.getCurrentTime())) {
|
||||
// request data has: {reply-path-len}{reply-path}
|
||||
reply_path_len = *data & 63;
|
||||
reply_path_hash_size = (*data >> 6) + 1;
|
||||
data++;
|
||||
reply_path_len = *data++;
|
||||
if (!mesh::Packet::isValidPathLen(reply_path_len)) return 0; // reject - bad encoding
|
||||
|
||||
memcpy(reply_path, data, ((uint8_t)reply_path_len) * reply_path_hash_size);
|
||||
mesh::Packet::writePath(reply_path, data, reply_path_len);
|
||||
// data += (uint8_t)reply_path_len * reply_path_hash_size;
|
||||
|
||||
memcpy(reply_data, &sender_timestamp, 4); // prefix with sender_timestamp, like a tag
|
||||
@@ -166,11 +165,10 @@ uint8_t MyMesh::handleAnonRegionsReq(const mesh::Identity& sender, uint32_t send
|
||||
uint8_t MyMesh::handleAnonOwnerReq(const mesh::Identity& sender, uint32_t sender_timestamp, const uint8_t* data) {
|
||||
if (anon_limiter.allow(rtc_clock.getCurrentTime())) {
|
||||
// request data has: {reply-path-len}{reply-path}
|
||||
reply_path_len = *data & 63;
|
||||
reply_path_hash_size = (*data >> 6) + 1;
|
||||
data++;
|
||||
reply_path_len = *data++;
|
||||
if (!mesh::Packet::isValidPathLen(reply_path_len)) return 0; // reject - bad encoding
|
||||
|
||||
memcpy(reply_path, data, ((uint8_t)reply_path_len) * reply_path_hash_size);
|
||||
mesh::Packet::writePath(reply_path, data, reply_path_len);
|
||||
// data += (uint8_t)reply_path_len * reply_path_hash_size;
|
||||
|
||||
memcpy(reply_data, &sender_timestamp, 4); // prefix with sender_timestamp, like a tag
|
||||
@@ -186,11 +184,10 @@ uint8_t MyMesh::handleAnonOwnerReq(const mesh::Identity& sender, uint32_t sender
|
||||
uint8_t MyMesh::handleAnonClockReq(const mesh::Identity& sender, uint32_t sender_timestamp, const uint8_t* data) {
|
||||
if (anon_limiter.allow(rtc_clock.getCurrentTime())) {
|
||||
// request data has: {reply-path-len}{reply-path}
|
||||
reply_path_len = *data & 63;
|
||||
reply_path_hash_size = (*data >> 6) + 1;
|
||||
data++;
|
||||
reply_path_len = *data++;
|
||||
if (!mesh::Packet::isValidPathLen(reply_path_len)) return 0; // reject - bad encoding
|
||||
|
||||
memcpy(reply_path, data, ((uint8_t)reply_path_len) * reply_path_hash_size);
|
||||
mesh::Packet::writePath(reply_path, data, reply_path_len);
|
||||
// data += (uint8_t)reply_path_len * reply_path_hash_size;
|
||||
|
||||
memcpy(reply_data, &sender_timestamp, 4); // prefix with sender_timestamp, like a tag
|
||||
@@ -581,7 +578,7 @@ void MyMesh::onAnonDataRecv(mesh::Packet *packet, const uint8_t *secret, const m
|
||||
data[len] = 0; // ensure null terminator
|
||||
uint8_t reply_len;
|
||||
|
||||
reply_path_len = -1;
|
||||
reply_path_len = 0xFF;
|
||||
if (data[4] == 0 || data[4] >= ' ') { // is password, ie. a login request
|
||||
reply_len = handleLoginReq(sender, secret, timestamp, &data[4], packet->isRouteFlood());
|
||||
} else if (data[4] == ANON_REQ_TYPE_REGIONS && packet->isRouteDirect()) {
|
||||
@@ -600,7 +597,7 @@ void MyMesh::onAnonDataRecv(mesh::Packet *packet, const uint8_t *secret, const m
|
||||
ClientInfo* client = acl.getClient(sender.pub_key, PUB_KEY_SIZE);
|
||||
bool have_out_path = client != NULL && client->out_path_len != OUT_PATH_UNKNOWN;
|
||||
|
||||
auto route = mesh::chooseReplyRoute(packet->isRouteFlood(), reply_path_len >= 0, have_out_path);
|
||||
auto route = mesh::chooseReplyRoute(packet->isRouteFlood(), reply_path_len != 0xFF, have_out_path);
|
||||
|
||||
if (route == mesh::REPLY_ROUTE_PATH_RETURN) {
|
||||
// let this sender know path TO here, so they can use sendDirect(), and ALSO encode the response
|
||||
@@ -614,8 +611,7 @@ void MyMesh::onAnonDataRecv(mesh::Packet *packet, const uint8_t *secret, const m
|
||||
if (reply == NULL) return;
|
||||
|
||||
if (route == mesh::REPLY_ROUTE_DIRECT_SUPPLIED) {
|
||||
uint8_t path_len = ((reply_path_hash_size - 1) << 6) | (reply_path_len & 63);
|
||||
sendDirect(reply, reply_path, path_len, SERVER_RESPONSE_DELAY);
|
||||
sendDirect(reply, reply_path, reply_path_len, SERVER_RESPONSE_DELAY);
|
||||
} else if (route == mesh::REPLY_ROUTE_DIRECT_OUT_PATH) {
|
||||
sendDirect(reply, client->out_path, client->out_path_len, SERVER_RESPONSE_DELAY);
|
||||
} else {
|
||||
|
||||
@@ -93,8 +93,7 @@ class MyMesh : public mesh::Mesh, public CommonCLICallbacks {
|
||||
CommonCLI _cli;
|
||||
uint8_t reply_data[MAX_PACKET_PAYLOAD];
|
||||
uint8_t reply_path[MAX_PATH_SIZE];
|
||||
int8_t reply_path_len;
|
||||
uint8_t reply_path_hash_size;
|
||||
uint8_t reply_path_len;
|
||||
TransportKeyStore key_store;
|
||||
RegionMap region_map, temp_map;
|
||||
RegionEntry* load_stack[8];
|
||||
|
||||
@@ -91,6 +91,7 @@ build_flags = ${arduino_base.build_flags}
|
||||
-D NRF52_PLATFORM
|
||||
-D LFS_NO_ASSERT=1
|
||||
-D EXTRAFS=1
|
||||
-D USE_CC310_HW_CRYPTO=1
|
||||
lib_deps =
|
||||
${arduino_base.lib_deps}
|
||||
https://github.com/oltaco/CustomLFS#0.2.2
|
||||
|
||||
+19
-1
@@ -4,6 +4,11 @@
|
||||
#include <ed_25519.h>
|
||||
#include <Ed25519.h>
|
||||
|
||||
#ifdef USE_CC310_HW_CRYPTO
|
||||
#include <Adafruit_nRFCrypto.h>
|
||||
#include "nrf_cc310/include/crys_ec_edw_api.h"
|
||||
#endif
|
||||
|
||||
namespace mesh {
|
||||
|
||||
Identity::Identity() {
|
||||
@@ -15,7 +20,20 @@ Identity::Identity(const char* pub_hex) {
|
||||
}
|
||||
|
||||
bool Identity::verify(const uint8_t* sig, const uint8_t* message, int msg_len) const {
|
||||
#if 0
|
||||
#ifdef USE_CC310_HW_CRYPTO
|
||||
// nRF52840 CryptoCell CC310 hardware Ed25519 verification. The software
|
||||
// implementations need ~3KB of stack (which can overflow the Adafruit core's
|
||||
// 4KB loop task stack from the advert receive path); the hardware path
|
||||
// needs much less, around 600-700bytes. The CC310 workspace is static, faster,
|
||||
// should save power at scale as well.
|
||||
static CRYS_ECEDW_TempBuff_t cc310_tmp;
|
||||
nRFCrypto.begin();
|
||||
CRYSError_t rc = CRYS_ECEDW_Verify((uint8_t*)sig, CRYS_ECEDW_SIGNATURE_BYTES,
|
||||
(uint8_t*)pub_key, CRYS_ECEDW_MOD_SIZE_IN_BYTES,
|
||||
(uint8_t*)message, (size_t)msg_len, &cc310_tmp);
|
||||
nRFCrypto.end();
|
||||
return rc == CRYS_OK;
|
||||
#elif 0
|
||||
// NOTE: memory corruption bug was found in this function!!
|
||||
return ed25519_verify(sig, message, msg_len, pub_key);
|
||||
#else
|
||||
|
||||
+97
-1
@@ -2,6 +2,13 @@
|
||||
#include <AES.h>
|
||||
#include <SHA256.h>
|
||||
|
||||
#ifdef USE_CC310_HW_CRYPTO
|
||||
#include <Adafruit_nRFCrypto.h>
|
||||
#include "nrf_cc310/include/crys_hash.h"
|
||||
#include "nrf_cc310/include/crys_hmac.h"
|
||||
#include "nrf_cc310/include/ssi_aes.h"
|
||||
#endif
|
||||
|
||||
#ifdef ARDUINO
|
||||
#include <Arduino.h>
|
||||
#endif
|
||||
@@ -15,19 +22,58 @@ uint32_t RNG::nextInt(uint32_t _min, uint32_t _max) {
|
||||
}
|
||||
|
||||
void Utils::sha256(uint8_t *hash, size_t hash_len, const uint8_t* msg, int msg_len) {
|
||||
#ifdef USE_CC310_HW_CRYPTO
|
||||
static CRYS_HASH_Result_t result;
|
||||
nRFCrypto.begin();
|
||||
CRYS_HASH(CRYS_HASH_SHA256_mode, (uint8_t*)msg, (size_t)msg_len, result);
|
||||
nRFCrypto.end();
|
||||
memcpy(hash, result, hash_len);
|
||||
#else
|
||||
SHA256 sha;
|
||||
sha.update(msg, msg_len);
|
||||
sha.finalize(hash, hash_len);
|
||||
#endif
|
||||
}
|
||||
|
||||
void Utils::sha256(uint8_t *hash, size_t hash_len, const uint8_t* frag1, int frag1_len, const uint8_t* frag2, int frag2_len) {
|
||||
#ifdef USE_CC310_HW_CRYPTO
|
||||
static CRYS_HASHUserContext_t ctx;
|
||||
static CRYS_HASH_Result_t result;
|
||||
nRFCrypto.begin();
|
||||
CRYS_HASH_Init(&ctx, CRYS_HASH_SHA256_mode);
|
||||
CRYS_HASH_Update(&ctx, (uint8_t*)frag1, (size_t)frag1_len);
|
||||
CRYS_HASH_Update(&ctx, (uint8_t*)frag2, (size_t)frag2_len);
|
||||
CRYS_HASH_Finish(&ctx, result);
|
||||
nRFCrypto.end();
|
||||
memcpy(hash, result, hash_len);
|
||||
#else
|
||||
SHA256 sha;
|
||||
sha.update(frag1, frag1_len);
|
||||
sha.update(frag2, frag2_len);
|
||||
sha.finalize(hash, hash_len);
|
||||
#endif
|
||||
}
|
||||
|
||||
int Utils::decrypt(const uint8_t* shared_secret, uint8_t* dest, const uint8_t* src, int src_len) {
|
||||
#ifdef USE_CC310_HW_CRYPTO
|
||||
static SaSiAesUserContext_t ctx;
|
||||
SaSiAesUserKeyData_t keyData = { (uint8_t*)shared_secret, CIPHER_KEY_SIZE };
|
||||
uint8_t* dp = dest;
|
||||
const uint8_t* sp = src;
|
||||
size_t dummy_out = 0;
|
||||
|
||||
nRFCrypto.begin();
|
||||
SaSi_AesInit(&ctx, SASI_AES_DECRYPT, SASI_AES_MODE_ECB, SASI_AES_PADDING_NONE);
|
||||
SaSi_AesSetKey(&ctx, SASI_AES_USER_KEY, &keyData, sizeof(keyData));
|
||||
while (sp - src < src_len) {
|
||||
SaSi_AesBlock(&ctx, (uint8_t*)sp, 16, dp);
|
||||
dp += 16; sp += 16;
|
||||
}
|
||||
SaSi_AesFinish(&ctx, 0, NULL, 0, NULL, &dummy_out);
|
||||
SaSi_AesFree(&ctx);
|
||||
nRFCrypto.end();
|
||||
return sp - src;
|
||||
#else
|
||||
AES128 aes;
|
||||
uint8_t* dp = dest;
|
||||
const uint8_t* sp = src;
|
||||
@@ -39,9 +85,34 @@ int Utils::decrypt(const uint8_t* shared_secret, uint8_t* dest, const uint8_t* s
|
||||
}
|
||||
|
||||
return sp - src; // will always be multiple of 16
|
||||
#endif
|
||||
}
|
||||
|
||||
int Utils::encrypt(const uint8_t* shared_secret, uint8_t* dest, const uint8_t* src, int src_len) {
|
||||
#ifdef USE_CC310_HW_CRYPTO
|
||||
static SaSiAesUserContext_t ctx;
|
||||
SaSiAesUserKeyData_t keyData = { (uint8_t*)shared_secret, CIPHER_KEY_SIZE };
|
||||
uint8_t* dp = dest;
|
||||
size_t dummy_out = 0;
|
||||
|
||||
nRFCrypto.begin();
|
||||
SaSi_AesInit(&ctx, SASI_AES_ENCRYPT, SASI_AES_MODE_ECB, SASI_AES_PADDING_NONE);
|
||||
SaSi_AesSetKey(&ctx, SASI_AES_USER_KEY, &keyData, sizeof(keyData));
|
||||
while (src_len >= 16) {
|
||||
SaSi_AesBlock(&ctx, (uint8_t*)src, 16, dp);
|
||||
dp += 16; src += 16; src_len -= 16;
|
||||
}
|
||||
if (src_len > 0) { // remaining partial block — zero-pad to 16 bytes
|
||||
uint8_t tmp[16] = {};
|
||||
memcpy(tmp, src, src_len);
|
||||
SaSi_AesBlock(&ctx, tmp, 16, dp);
|
||||
dp += 16;
|
||||
}
|
||||
SaSi_AesFinish(&ctx, 0, NULL, 0, NULL, &dummy_out);
|
||||
SaSi_AesFree(&ctx);
|
||||
nRFCrypto.end();
|
||||
return dp - dest;
|
||||
#else
|
||||
AES128 aes;
|
||||
uint8_t* dp = dest;
|
||||
|
||||
@@ -58,15 +129,27 @@ int Utils::encrypt(const uint8_t* shared_secret, uint8_t* dest, const uint8_t* s
|
||||
dp += 16;
|
||||
}
|
||||
return dp - dest; // will always be multiple of 16
|
||||
#endif
|
||||
}
|
||||
|
||||
int Utils::encryptThenMAC(const uint8_t* shared_secret, uint8_t* dest, const uint8_t* src, int src_len) {
|
||||
int enc_len = encrypt(shared_secret, dest + CIPHER_MAC_SIZE, src, src_len);
|
||||
|
||||
#ifdef USE_CC310_HW_CRYPTO
|
||||
static CRYS_HMACUserContext_t hmac_ctx;
|
||||
static CRYS_HASH_Result_t hmac_result;
|
||||
nRFCrypto.begin();
|
||||
CRYS_HMAC_Init(&hmac_ctx, CRYS_HASH_SHA256_mode, (uint8_t*)shared_secret, PUB_KEY_SIZE);
|
||||
CRYS_HMAC_Update(&hmac_ctx, dest + CIPHER_MAC_SIZE, enc_len);
|
||||
CRYS_HMAC_Finish(&hmac_ctx, hmac_result);
|
||||
nRFCrypto.end();
|
||||
memcpy(dest, hmac_result, CIPHER_MAC_SIZE);
|
||||
#else
|
||||
SHA256 sha;
|
||||
sha.resetHMAC(shared_secret, PUB_KEY_SIZE);
|
||||
sha.update(dest + CIPHER_MAC_SIZE, enc_len);
|
||||
sha.finalizeHMAC(shared_secret, PUB_KEY_SIZE, dest, CIPHER_MAC_SIZE);
|
||||
#endif
|
||||
|
||||
return CIPHER_MAC_SIZE + enc_len;
|
||||
}
|
||||
@@ -75,12 +158,25 @@ int Utils::MACThenDecrypt(const uint8_t* shared_secret, uint8_t* dest, const uin
|
||||
if (src_len <= CIPHER_MAC_SIZE) return 0; // invalid src bytes
|
||||
|
||||
uint8_t hmac[CIPHER_MAC_SIZE];
|
||||
#ifdef USE_CC310_HW_CRYPTO
|
||||
{
|
||||
static CRYS_HMACUserContext_t hmac_ctx;
|
||||
static CRYS_HASH_Result_t hmac_result;
|
||||
nRFCrypto.begin();
|
||||
CRYS_HMAC_Init(&hmac_ctx, CRYS_HASH_SHA256_mode, (uint8_t*)shared_secret, PUB_KEY_SIZE);
|
||||
CRYS_HMAC_Update(&hmac_ctx, (uint8_t*)(src + CIPHER_MAC_SIZE), src_len - CIPHER_MAC_SIZE);
|
||||
CRYS_HMAC_Finish(&hmac_ctx, hmac_result);
|
||||
nRFCrypto.end();
|
||||
memcpy(hmac, hmac_result, CIPHER_MAC_SIZE);
|
||||
}
|
||||
#else
|
||||
{
|
||||
SHA256 sha;
|
||||
sha.resetHMAC(shared_secret, PUB_KEY_SIZE);
|
||||
sha.update(src + CIPHER_MAC_SIZE, src_len - CIPHER_MAC_SIZE);
|
||||
sha.finalizeHMAC(shared_secret, PUB_KEY_SIZE, hmac, CIPHER_MAC_SIZE);
|
||||
}
|
||||
#endif
|
||||
if (memcmp(hmac, src, CIPHER_MAC_SIZE) == 0) {
|
||||
return decrypt(shared_secret, dest, src + CIPHER_MAC_SIZE, src_len - CIPHER_MAC_SIZE);
|
||||
}
|
||||
@@ -150,4 +246,4 @@ int Utils::parseTextParts(char* text, const char* parts[], int max_num, char sep
|
||||
return num;
|
||||
}
|
||||
|
||||
}
|
||||
}
|
||||
|
||||
@@ -36,8 +36,8 @@ class CustomLR1110 : public LR1110 {
|
||||
bool getRxBoostedGainMode() const { return _rx_boosted; }
|
||||
|
||||
int16_t startReceive() override {
|
||||
// include the PREAMBLE_DETECTED irq bit in reported flags
|
||||
return LR1110::startReceive(RADIOLIB_LR11X0_IRQ_PREAMBLE_DETECTED, RADIOLIB_IRQ_RX_DEFAULT_FLAGS | (1UL << RADIOLIB_IRQ_PREAMBLE_DETECTED), RADIOLIB_IRQ_RX_DEFAULT_MASK, 0);
|
||||
// include the PREAMBLE_DETECTED irq bit in reported flags.
|
||||
return LR1110::startReceive(RADIOLIB_LR11X0_RX_TIMEOUT_INF, RADIOLIB_IRQ_RX_DEFAULT_FLAGS | (1UL << RADIOLIB_IRQ_PREAMBLE_DETECTED), RADIOLIB_IRQ_RX_DEFAULT_MASK, 0);
|
||||
}
|
||||
|
||||
bool isReceiving() {
|
||||
@@ -92,4 +92,4 @@ class CustomLR1110 : public LR1110 {
|
||||
}
|
||||
|
||||
uint8_t getSpreadingFactor() const { return spreadingFactor; }
|
||||
};
|
||||
};
|
||||
|
||||
@@ -3,6 +3,9 @@
|
||||
#include <Mesh.h>
|
||||
#include <RadioLib.h>
|
||||
|
||||
#ifdef USE_CC310_HW_CRYPTO
|
||||
#include <Adafruit_nRFCrypto.h>
|
||||
#endif
|
||||
struct PacketMillis {
|
||||
uint32_t preambleMillis; // preamble-detect -> header-valid deadline
|
||||
uint32_t payloadMillis; // header-valid -> rx-done deadline
|
||||
@@ -86,8 +89,15 @@ public:
|
||||
RadioNoiseListener(PhysicalLayer& radio): _radio(&radio) { }
|
||||
|
||||
void random(uint8_t* dest, size_t sz) override {
|
||||
#ifdef USE_CC310_HW_CRYPTO
|
||||
// CC310 TRNG is higher quality and environment-independent vs radio RSSI noise.
|
||||
nRFCrypto.begin();
|
||||
nRFCrypto.Random.generate(dest, (uint16_t)sz);
|
||||
nRFCrypto.end();
|
||||
#else
|
||||
for (int i = 0; i < sz; i++) {
|
||||
dest[i] = _radio->randomByte() ^ (::random(0, 256) & 0xFF);
|
||||
}
|
||||
#endif
|
||||
}
|
||||
};
|
||||
|
||||
@@ -2,6 +2,7 @@
|
||||
extends = esp32c6_base
|
||||
board = esp32-c6-devkitm-1
|
||||
board_build.partitions = min_spiffs.csv ; get around 4mb flash limit
|
||||
board_build.flash_mode = dio ; board manifest defaults to qio, which causes a boot crash-loop on this module
|
||||
build_flags =
|
||||
${esp32c6_base.build_flags}
|
||||
${sensor_base.build_flags}
|
||||
|
||||
@@ -30,6 +30,8 @@ void initVariant() {
|
||||
digitalWrite(PIN_GPS_STANDBY, HIGH);
|
||||
pinMode(PIN_GPS_EN, OUTPUT);
|
||||
digitalWrite(PIN_GPS_EN, HIGH);
|
||||
pinMode(PIN_GPS_RESET, OUTPUT);
|
||||
digitalWrite(PIN_GPS_RESET, HIGH);
|
||||
// PIN_GPS_RESET (pin 29 / REINIT) is intentionally left floating (input).
|
||||
// Driving it HIGH holds the L76K silent, so it never streams NMEA and the
|
||||
// firmware reports "no GPS". Letting it float lets the module run, matching
|
||||
// the Meshtastic M6 variant. See GPS_RESET (-1) in variant.h.
|
||||
}
|
||||
|
||||
@@ -102,7 +102,12 @@
|
||||
#define PIN_GPS_RX (2)
|
||||
#define PIN_GPS_TX (3)
|
||||
#define PIN_GPS_EN (6) // EN
|
||||
#define PIN_GPS_RESET (29)
|
||||
#define PIN_GPS_RESET (29) // REINIT - must FLOAT; driving it (esp. HIGH) silences the L76K
|
||||
// The M6's L76K streams NMEA on its own and must not have its REINIT pin driven.
|
||||
// Tell the location provider there is no reset pin so it never touches pin 29
|
||||
// (driving it HIGH holds the module silent). Matches Meshtastic, which leaves
|
||||
// this pin as an input. See variant.cpp (pin 29 is intentionally not configured).
|
||||
#define GPS_RESET (-1)
|
||||
#define PIN_GPS_STANDBY (30) // STANDBY
|
||||
#define PIN_GPS_PPS (31)
|
||||
#define GPS_BAUD_RATE 9600
|
||||
|
||||
Reference in New Issue
Block a user