1 // SPDX-License-Identifier: GPL-2.0 2 /* 3 BlueZ - Bluetooth protocol stack for Linux 4 Copyright (C) 2011 Nokia Corporation and/or its subsidiary(-ies). 5 6 THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS 7 OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, 8 FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT OF THIRD PARTY RIGHTS. 9 IN NO EVENT SHALL THE COPYRIGHT HOLDER(S) AND AUTHOR(S) BE LIABLE FOR ANY 10 CLAIM, OR ANY SPECIAL INDIRECT OR CONSEQUENTIAL DAMAGES, OR ANY DAMAGES 11 WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN 12 ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF 13 OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. 14 15 ALL LIABILITY, INCLUDING LIABILITY FOR INFRINGEMENT OF ANY PATENTS, 16 COPYRIGHTS, TRADEMARKS OR OTHER RIGHTS, RELATING TO USE OF THIS 17 SOFTWARE IS DISCLAIMED. 18 */ 19 20 #include <linux/debugfs.h> 21 #include <linux/scatterlist.h> 22 #include <crypto/aes-cbc-macs.h> 23 #include <crypto/aes.h> 24 #include <crypto/kpp.h> 25 #include <crypto/utils.h> 26 27 #include <net/bluetooth/bluetooth.h> 28 #include <net/bluetooth/hci_core.h> 29 #include <net/bluetooth/l2cap.h> 30 #include <net/bluetooth/mgmt.h> 31 32 #include "ecdh_helper.h" 33 #include "smp.h" 34 35 #define SMP_DEV(hdev) \ 36 ((struct smp_dev *)((struct l2cap_chan *)((hdev)->smp_data))->data) 37 38 /* Low-level debug macros to be used for stuff that we don't want 39 * accidentally in dmesg, i.e. the values of the various crypto keys 40 * and the inputs & outputs of crypto functions. 41 */ 42 #ifdef DEBUG 43 #define SMP_DBG(fmt, ...) printk(KERN_DEBUG "%s: " fmt, __func__, \ 44 ##__VA_ARGS__) 45 #else 46 #define SMP_DBG(fmt, ...) no_printk(KERN_DEBUG "%s: " fmt, __func__, \ 47 ##__VA_ARGS__) 48 #endif 49 50 #define SMP_ALLOW_CMD(smp, code) set_bit(code, &smp->allow_cmd) 51 52 /* Keys which are not distributed with Secure Connections */ 53 #define SMP_SC_NO_DIST (SMP_DIST_ENC_KEY | SMP_DIST_LINK_KEY) 54 55 #define SMP_TIMEOUT secs_to_jiffies(30) 56 57 #define ID_ADDR_TIMEOUT msecs_to_jiffies(200) 58 59 #define AUTH_REQ_MASK(dev) (hci_dev_test_flag(dev, HCI_SC_ENABLED) ? \ 60 0x3f : 0x07) 61 #define KEY_DIST_MASK 0x07 62 63 /* Maximum message length that can be passed to smp_aes_cmac */ 64 #define CMAC_MSG_MAX 80 65 66 enum { 67 SMP_FLAG_TK_VALID, 68 SMP_FLAG_CFM_PENDING, 69 SMP_FLAG_MITM_AUTH, 70 SMP_FLAG_COMPLETE, 71 SMP_FLAG_INITIATOR, 72 SMP_FLAG_SC, 73 SMP_FLAG_REMOTE_PK, 74 SMP_FLAG_DEBUG_KEY, 75 SMP_FLAG_WAIT_USER, 76 SMP_FLAG_DHKEY_PENDING, 77 SMP_FLAG_REMOTE_OOB, 78 SMP_FLAG_LOCAL_OOB, 79 SMP_FLAG_CT2, 80 }; 81 82 struct smp_dev { 83 /* Secure Connections OOB data */ 84 bool local_oob; 85 u8 local_pk[64]; 86 u8 local_rand[16]; 87 bool debug_key; 88 89 struct crypto_kpp *tfm_ecdh; 90 }; 91 92 struct smp_chan { 93 struct l2cap_conn *conn; 94 struct delayed_work security_timer; 95 unsigned long allow_cmd; /* Bitmask of allowed commands */ 96 97 u8 preq[7]; /* SMP Pairing Request */ 98 u8 prsp[7]; /* SMP Pairing Response */ 99 u8 prnd[16]; /* SMP Pairing Random (local) */ 100 u8 rrnd[16]; /* SMP Pairing Random (remote) */ 101 u8 pcnf[16]; /* SMP Pairing Confirm */ 102 u8 tk[16]; /* SMP Temporary Key */ 103 u8 rr[16]; /* Remote OOB ra/rb value */ 104 u8 lr[16]; /* Local OOB ra/rb value */ 105 u8 enc_key_size; 106 u8 remote_key_dist; 107 bdaddr_t id_addr; 108 u8 id_addr_type; 109 u8 irk[16]; 110 struct smp_csrk *csrk; 111 struct smp_csrk *responder_csrk; 112 struct smp_ltk *ltk; 113 struct smp_ltk *responder_ltk; 114 struct smp_irk *remote_irk; 115 u8 *link_key; 116 unsigned long flags; 117 u8 method; 118 u8 passkey_round; 119 120 /* Secure Connections variables */ 121 u8 local_pk[64]; 122 u8 remote_pk[64]; 123 u8 dhkey[32]; 124 u8 mackey[16]; 125 126 struct crypto_kpp *tfm_ecdh; 127 }; 128 129 /* These debug key values are defined in the SMP section of the core 130 * specification. debug_pk is the public debug key and debug_sk the 131 * private debug key. 132 */ 133 static const u8 debug_pk[64] = { 134 0xe6, 0x9d, 0x35, 0x0e, 0x48, 0x01, 0x03, 0xcc, 135 0xdb, 0xfd, 0xf4, 0xac, 0x11, 0x91, 0xf4, 0xef, 136 0xb9, 0xa5, 0xf9, 0xe9, 0xa7, 0x83, 0x2c, 0x5e, 137 0x2c, 0xbe, 0x97, 0xf2, 0xd2, 0x03, 0xb0, 0x20, 138 139 0x8b, 0xd2, 0x89, 0x15, 0xd0, 0x8e, 0x1c, 0x74, 140 0x24, 0x30, 0xed, 0x8f, 0xc2, 0x45, 0x63, 0x76, 141 0x5c, 0x15, 0x52, 0x5a, 0xbf, 0x9a, 0x32, 0x63, 142 0x6d, 0xeb, 0x2a, 0x65, 0x49, 0x9c, 0x80, 0xdc, 143 }; 144 145 static const u8 debug_sk[32] = { 146 0xbd, 0x1a, 0x3c, 0xcd, 0xa6, 0xb8, 0x99, 0x58, 147 0x99, 0xb7, 0x40, 0xeb, 0x7b, 0x60, 0xff, 0x4a, 148 0x50, 0x3f, 0x10, 0xd2, 0xe3, 0xb3, 0xc9, 0x74, 149 0x38, 0x5f, 0xc5, 0xa3, 0xd4, 0xf6, 0x49, 0x3f, 150 }; 151 152 static inline void swap_buf(const u8 *src, u8 *dst, size_t len) 153 { 154 size_t i; 155 156 for (i = 0; i < len; i++) 157 dst[len - 1 - i] = src[i]; 158 } 159 160 /* The following functions map to the LE SC SMP crypto functions 161 * AES-CMAC, f4, f5, f6, g2 and h6. 162 */ 163 164 static int smp_aes_cmac(const u8 k[16], const u8 *m, size_t len, u8 mac[16]) 165 { 166 uint8_t tmp[16], mac_msb[16], msg_msb[CMAC_MSG_MAX]; 167 struct aes_cmac_key key __cleanup(aes_cmac_zeroize_key); 168 int err; 169 170 if (len > CMAC_MSG_MAX) 171 return -EFBIG; 172 173 /* Swap key and message from LSB to MSB */ 174 swap_buf(k, tmp, 16); 175 swap_buf(m, msg_msb, len); 176 177 SMP_DBG("msg (len %zu) %*phN", len, (int) len, m); 178 SMP_DBG("key %16phN", k); 179 180 err = aes_cmac_preparekey(&key, tmp, 16); 181 memzero_explicit(tmp, sizeof(tmp)); 182 if (WARN_ON_ONCE(err)) /* Should never happen, as 16 is valid keylen */ 183 return err; 184 aes_cmac(&key, msg_msb, len, mac_msb); 185 186 swap_buf(mac_msb, mac, 16); 187 188 SMP_DBG("mac %16phN", mac); 189 190 return 0; 191 } 192 193 static int smp_f4(const u8 u[32], const u8 v[32], const u8 x[16], u8 z, 194 u8 res[16]) 195 { 196 u8 m[65]; 197 int err; 198 199 SMP_DBG("u %32phN", u); 200 SMP_DBG("v %32phN", v); 201 SMP_DBG("x %16phN z %02x", x, z); 202 203 m[0] = z; 204 memcpy(m + 1, v, 32); 205 memcpy(m + 33, u, 32); 206 207 err = smp_aes_cmac(x, m, sizeof(m), res); 208 if (err) 209 return err; 210 211 SMP_DBG("res %16phN", res); 212 213 return err; 214 } 215 216 static int smp_f5(const u8 w[32], const u8 n1[16], const u8 n2[16], 217 const u8 a1[7], const u8 a2[7], u8 mackey[16], u8 ltk[16]) 218 { 219 /* The btle, salt and length "magic" values are as defined in 220 * the SMP section of the Bluetooth core specification. In ASCII 221 * the btle value ends up being 'btle'. The salt is just a 222 * random number whereas length is the value 256 in little 223 * endian format. 224 */ 225 const u8 btle[4] = { 0x65, 0x6c, 0x74, 0x62 }; 226 const u8 salt[16] = { 0xbe, 0x83, 0x60, 0x5a, 0xdb, 0x0b, 0x37, 0x60, 227 0x38, 0xa5, 0xf5, 0xaa, 0x91, 0x83, 0x88, 0x6c }; 228 const u8 length[2] = { 0x00, 0x01 }; 229 u8 m[53], t[16]; 230 int err; 231 232 SMP_DBG("w %32phN", w); 233 SMP_DBG("n1 %16phN n2 %16phN", n1, n2); 234 SMP_DBG("a1 %7phN a2 %7phN", a1, a2); 235 236 err = smp_aes_cmac(salt, w, 32, t); 237 if (err) 238 return err; 239 240 SMP_DBG("t %16phN", t); 241 242 memcpy(m, length, 2); 243 memcpy(m + 2, a2, 7); 244 memcpy(m + 9, a1, 7); 245 memcpy(m + 16, n2, 16); 246 memcpy(m + 32, n1, 16); 247 memcpy(m + 48, btle, 4); 248 249 m[52] = 0; /* Counter */ 250 251 err = smp_aes_cmac(t, m, sizeof(m), mackey); 252 if (err) 253 return err; 254 255 SMP_DBG("mackey %16phN", mackey); 256 257 m[52] = 1; /* Counter */ 258 259 err = smp_aes_cmac(t, m, sizeof(m), ltk); 260 if (err) 261 return err; 262 263 SMP_DBG("ltk %16phN", ltk); 264 265 return 0; 266 } 267 268 static int smp_f6(const u8 w[16], const u8 n1[16], const u8 n2[16], 269 const u8 r[16], const u8 io_cap[3], const u8 a1[7], 270 const u8 a2[7], u8 res[16]) 271 { 272 u8 m[65]; 273 int err; 274 275 SMP_DBG("w %16phN", w); 276 SMP_DBG("n1 %16phN n2 %16phN", n1, n2); 277 SMP_DBG("r %16phN io_cap %3phN a1 %7phN a2 %7phN", r, io_cap, a1, a2); 278 279 memcpy(m, a2, 7); 280 memcpy(m + 7, a1, 7); 281 memcpy(m + 14, io_cap, 3); 282 memcpy(m + 17, r, 16); 283 memcpy(m + 33, n2, 16); 284 memcpy(m + 49, n1, 16); 285 286 err = smp_aes_cmac(w, m, sizeof(m), res); 287 if (err) 288 return err; 289 290 SMP_DBG("res %16phN", res); 291 292 return err; 293 } 294 295 static int smp_g2(const u8 u[32], const u8 v[32], const u8 x[16], 296 const u8 y[16], u32 *val) 297 { 298 u8 m[80], tmp[16]; 299 int err; 300 301 SMP_DBG("u %32phN", u); 302 SMP_DBG("v %32phN", v); 303 SMP_DBG("x %16phN y %16phN", x, y); 304 305 memcpy(m, y, 16); 306 memcpy(m + 16, v, 32); 307 memcpy(m + 48, u, 32); 308 309 err = smp_aes_cmac(x, m, sizeof(m), tmp); 310 if (err) 311 return err; 312 313 *val = get_unaligned_le32(tmp); 314 *val %= 1000000; 315 316 SMP_DBG("val %06u", *val); 317 318 return 0; 319 } 320 321 static int smp_h6(const u8 w[16], const u8 key_id[4], u8 res[16]) 322 { 323 int err; 324 325 SMP_DBG("w %16phN key_id %4phN", w, key_id); 326 327 err = smp_aes_cmac(w, key_id, 4, res); 328 if (err) 329 return err; 330 331 SMP_DBG("res %16phN", res); 332 333 return err; 334 } 335 336 static int smp_h7(const u8 w[16], const u8 salt[16], u8 res[16]) 337 { 338 int err; 339 340 SMP_DBG("w %16phN salt %16phN", w, salt); 341 342 err = smp_aes_cmac(salt, w, 16, res); 343 if (err) 344 return err; 345 346 SMP_DBG("res %16phN", res); 347 348 return err; 349 } 350 351 /* The following functions map to the legacy SMP crypto functions e, c1, 352 * s1 and ah. 353 */ 354 355 static int smp_e(const u8 *k, u8 *r) 356 { 357 struct aes_enckey aes; 358 uint8_t tmp[16], data[16]; 359 int err; 360 361 SMP_DBG("k %16phN r %16phN", k, r); 362 363 /* The most significant octet of key corresponds to k[0] */ 364 swap_buf(k, tmp, 16); 365 366 err = aes_prepareenckey(&aes, tmp, 16); 367 if (err) { 368 BT_ERR("cipher setkey failed: %d", err); 369 return err; 370 } 371 372 /* Most significant octet of plaintextData corresponds to data[0] */ 373 swap_buf(r, data, 16); 374 375 aes_encrypt(&aes, data, data); 376 377 /* Most significant octet of encryptedData corresponds to data[0] */ 378 swap_buf(data, r, 16); 379 380 SMP_DBG("r %16phN", r); 381 382 memzero_explicit(&aes, sizeof(aes)); 383 return err; 384 } 385 386 static int smp_c1(const u8 k[16], 387 const u8 r[16], const u8 preq[7], const u8 pres[7], u8 _iat, 388 const bdaddr_t *ia, u8 _rat, const bdaddr_t *ra, u8 res[16]) 389 { 390 u8 p1[16], p2[16]; 391 int err; 392 393 SMP_DBG("k %16phN r %16phN", k, r); 394 SMP_DBG("iat %u ia %6phN rat %u ra %6phN", _iat, ia, _rat, ra); 395 SMP_DBG("preq %7phN pres %7phN", preq, pres); 396 397 memset(p1, 0, 16); 398 399 /* p1 = pres || preq || _rat || _iat */ 400 p1[0] = _iat; 401 p1[1] = _rat; 402 memcpy(p1 + 2, preq, 7); 403 memcpy(p1 + 9, pres, 7); 404 405 SMP_DBG("p1 %16phN", p1); 406 407 /* res = r XOR p1 */ 408 crypto_xor_cpy(res, r, p1, sizeof(p1)); 409 410 /* res = e(k, res) */ 411 err = smp_e(k, res); 412 if (err) { 413 BT_ERR("Encrypt data error"); 414 return err; 415 } 416 417 /* p2 = padding || ia || ra */ 418 memcpy(p2, ra, 6); 419 memcpy(p2 + 6, ia, 6); 420 memset(p2 + 12, 0, 4); 421 422 SMP_DBG("p2 %16phN", p2); 423 424 /* res = res XOR p2 */ 425 crypto_xor(res, p2, sizeof(p2)); 426 427 /* res = e(k, res) */ 428 err = smp_e(k, res); 429 if (err) 430 BT_ERR("Encrypt data error"); 431 432 return err; 433 } 434 435 static int smp_s1(const u8 k[16], 436 const u8 r1[16], const u8 r2[16], u8 _r[16]) 437 { 438 int err; 439 440 /* Just least significant octets from r1 and r2 are considered */ 441 memcpy(_r, r2, 8); 442 memcpy(_r + 8, r1, 8); 443 444 err = smp_e(k, _r); 445 if (err) 446 BT_ERR("Encrypt data error"); 447 448 return err; 449 } 450 451 static int smp_ah(const u8 irk[16], const u8 r[3], u8 res[3]) 452 { 453 u8 _res[16]; 454 int err; 455 456 /* r' = padding || r */ 457 memcpy(_res, r, 3); 458 memset(_res + 3, 0, 13); 459 460 err = smp_e(irk, _res); 461 if (err) { 462 BT_ERR("Encrypt error"); 463 return err; 464 } 465 466 /* The output of the random address function ah is: 467 * ah(k, r) = e(k, r') mod 2^24 468 * The output of the security function e is then truncated to 24 bits 469 * by taking the least significant 24 bits of the output of e as the 470 * result of ah. 471 */ 472 memcpy(res, _res, 3); 473 474 return 0; 475 } 476 477 bool smp_irk_matches(struct hci_dev *hdev, const u8 irk[16], 478 const bdaddr_t *bdaddr) 479 { 480 struct l2cap_chan *chan = hdev->smp_data; 481 u8 hash[3]; 482 int err; 483 484 if (!chan || !chan->data) 485 return false; 486 487 bt_dev_dbg(hdev, "RPA %pMR IRK %*phN", bdaddr, 16, irk); 488 489 err = smp_ah(irk, &bdaddr->b[3], hash); 490 if (err) 491 return false; 492 493 return !crypto_memneq(bdaddr->b, hash, 3); 494 } 495 496 int smp_generate_rpa(struct hci_dev *hdev, const u8 irk[16], bdaddr_t *rpa) 497 { 498 struct l2cap_chan *chan = hdev->smp_data; 499 int err; 500 501 if (!chan || !chan->data) 502 return -EOPNOTSUPP; 503 504 get_random_bytes(&rpa->b[3], 3); 505 506 rpa->b[5] &= 0x3f; /* Clear two most significant bits */ 507 rpa->b[5] |= 0x40; /* Set second most significant bit */ 508 509 err = smp_ah(irk, &rpa->b[3], rpa->b); 510 if (err < 0) 511 return err; 512 513 bt_dev_dbg(hdev, "RPA %pMR", rpa); 514 515 return 0; 516 } 517 518 int smp_generate_oob(struct hci_dev *hdev, u8 hash[16], u8 rand[16]) 519 { 520 struct l2cap_chan *chan = hdev->smp_data; 521 struct smp_dev *smp; 522 int err; 523 524 if (!chan || !chan->data) 525 return -EOPNOTSUPP; 526 527 smp = chan->data; 528 529 if (hci_dev_test_flag(hdev, HCI_USE_DEBUG_KEYS)) { 530 bt_dev_dbg(hdev, "Using debug keys"); 531 err = set_ecdh_privkey(smp->tfm_ecdh, debug_sk); 532 if (err) 533 return err; 534 memcpy(smp->local_pk, debug_pk, 64); 535 smp->debug_key = true; 536 } else { 537 while (true) { 538 /* Generate key pair for Secure Connections */ 539 err = generate_ecdh_keys(smp->tfm_ecdh, smp->local_pk); 540 if (err) 541 return err; 542 543 /* This is unlikely, but we need to check that 544 * we didn't accidentally generate a debug key. 545 */ 546 if (crypto_memneq(smp->local_pk, debug_pk, 64)) 547 break; 548 } 549 smp->debug_key = false; 550 } 551 552 SMP_DBG("OOB Public Key X: %32phN", smp->local_pk); 553 SMP_DBG("OOB Public Key Y: %32phN", smp->local_pk + 32); 554 555 get_random_bytes(smp->local_rand, 16); 556 557 err = smp_f4(smp->local_pk, smp->local_pk, smp->local_rand, 0, hash); 558 if (err < 0) 559 return err; 560 561 memcpy(rand, smp->local_rand, 16); 562 563 smp->local_oob = true; 564 565 return 0; 566 } 567 568 static void smp_send_cmd(struct l2cap_conn *conn, u8 code, u16 len, void *data) 569 { 570 struct l2cap_chan *chan = conn->smp; 571 struct smp_chan *smp; 572 struct kvec iv[2]; 573 struct msghdr msg; 574 575 if (!chan) 576 return; 577 578 bt_dev_dbg(conn->hcon->hdev, "code 0x%2.2x", code); 579 580 iv[0].iov_base = &code; 581 iv[0].iov_len = 1; 582 583 iv[1].iov_base = data; 584 iv[1].iov_len = len; 585 586 memset(&msg, 0, sizeof(msg)); 587 588 iov_iter_kvec(&msg.msg_iter, ITER_SOURCE, iv, 2, 1 + len); 589 590 l2cap_chan_send(chan, &msg, 1 + len, NULL); 591 592 if (!chan->data) 593 return; 594 595 smp = chan->data; 596 597 cancel_delayed_work_sync(&smp->security_timer); 598 schedule_delayed_work(&smp->security_timer, SMP_TIMEOUT); 599 } 600 601 static u8 authreq_to_seclevel(u8 authreq) 602 { 603 if (authreq & SMP_AUTH_MITM) { 604 if (authreq & SMP_AUTH_SC) 605 return BT_SECURITY_FIPS; 606 else 607 return BT_SECURITY_HIGH; 608 } else { 609 return BT_SECURITY_MEDIUM; 610 } 611 } 612 613 static __u8 seclevel_to_authreq(__u8 sec_level) 614 { 615 switch (sec_level) { 616 case BT_SECURITY_FIPS: 617 case BT_SECURITY_HIGH: 618 return SMP_AUTH_MITM | SMP_AUTH_BONDING; 619 case BT_SECURITY_MEDIUM: 620 return SMP_AUTH_BONDING; 621 default: 622 return SMP_AUTH_NONE; 623 } 624 } 625 626 static void build_pairing_cmd(struct l2cap_conn *conn, 627 struct smp_cmd_pairing *req, 628 struct smp_cmd_pairing *rsp, __u8 authreq) 629 { 630 struct l2cap_chan *chan = conn->smp; 631 struct smp_chan *smp = chan->data; 632 struct hci_conn *hcon = conn->hcon; 633 struct hci_dev *hdev = hcon->hdev; 634 u8 local_dist = 0, remote_dist = 0, oob_flag = SMP_OOB_NOT_PRESENT; 635 636 if (hci_dev_test_flag(hdev, HCI_BONDABLE)) { 637 local_dist = SMP_DIST_ENC_KEY | SMP_DIST_SIGN; 638 remote_dist = SMP_DIST_ENC_KEY | SMP_DIST_SIGN; 639 authreq |= SMP_AUTH_BONDING; 640 } else { 641 authreq &= ~SMP_AUTH_BONDING; 642 } 643 644 if (hci_dev_test_flag(hdev, HCI_RPA_RESOLVING)) 645 remote_dist |= SMP_DIST_ID_KEY; 646 647 if (hci_dev_test_flag(hdev, HCI_PRIVACY)) 648 local_dist |= SMP_DIST_ID_KEY; 649 650 if (hci_dev_test_flag(hdev, HCI_SC_ENABLED) && 651 (authreq & SMP_AUTH_SC)) { 652 struct oob_data *oob_data; 653 u8 bdaddr_type; 654 655 if (hci_dev_test_flag(hdev, HCI_SSP_ENABLED)) { 656 local_dist |= SMP_DIST_LINK_KEY; 657 remote_dist |= SMP_DIST_LINK_KEY; 658 } 659 660 if (hcon->dst_type == ADDR_LE_DEV_PUBLIC) 661 bdaddr_type = BDADDR_LE_PUBLIC; 662 else 663 bdaddr_type = BDADDR_LE_RANDOM; 664 665 mutex_lock(&hdev->remote_oob_lock); 666 oob_data = hci_find_remote_oob_data(hdev, &hcon->dst, 667 bdaddr_type); 668 if (oob_data && oob_data->present) { 669 set_bit(SMP_FLAG_REMOTE_OOB, &smp->flags); 670 oob_flag = SMP_OOB_PRESENT; 671 memcpy(smp->rr, oob_data->rand256, 16); 672 memcpy(smp->pcnf, oob_data->hash256, 16); 673 SMP_DBG("OOB Remote Confirmation: %16phN", smp->pcnf); 674 SMP_DBG("OOB Remote Random: %16phN", smp->rr); 675 } 676 mutex_unlock(&hdev->remote_oob_lock); 677 678 } else { 679 authreq &= ~SMP_AUTH_SC; 680 } 681 682 if (rsp == NULL) { 683 req->io_capability = conn->hcon->io_capability; 684 req->oob_flag = oob_flag; 685 req->max_key_size = hdev->le_max_key_size; 686 req->init_key_dist = local_dist; 687 req->resp_key_dist = remote_dist; 688 req->auth_req = (authreq & AUTH_REQ_MASK(hdev)); 689 690 smp->remote_key_dist = remote_dist; 691 return; 692 } 693 694 rsp->io_capability = conn->hcon->io_capability; 695 rsp->oob_flag = oob_flag; 696 rsp->max_key_size = hdev->le_max_key_size; 697 rsp->init_key_dist = req->init_key_dist & remote_dist; 698 rsp->resp_key_dist = req->resp_key_dist & local_dist; 699 rsp->auth_req = (authreq & AUTH_REQ_MASK(hdev)); 700 701 smp->remote_key_dist = rsp->init_key_dist; 702 } 703 704 static u8 check_enc_key_size(struct l2cap_conn *conn, __u8 max_key_size) 705 { 706 struct l2cap_chan *chan = conn->smp; 707 struct hci_dev *hdev = conn->hcon->hdev; 708 struct smp_chan *smp = chan->data; 709 710 if (conn->hcon->pending_sec_level == BT_SECURITY_FIPS && 711 max_key_size != SMP_MAX_ENC_KEY_SIZE) 712 return SMP_ENC_KEY_SIZE; 713 714 if (max_key_size > hdev->le_max_key_size || 715 max_key_size < SMP_MIN_ENC_KEY_SIZE) 716 return SMP_ENC_KEY_SIZE; 717 718 smp->enc_key_size = max_key_size; 719 720 return 0; 721 } 722 723 static void smp_chan_destroy(struct l2cap_conn *conn) 724 { 725 struct l2cap_chan *chan = conn->smp; 726 struct smp_chan *smp = chan->data; 727 struct hci_conn *hcon = conn->hcon; 728 bool complete; 729 730 BUG_ON(!smp); 731 732 cancel_delayed_work_sync(&smp->security_timer); 733 734 complete = test_bit(SMP_FLAG_COMPLETE, &smp->flags); 735 mgmt_smp_complete(hcon, complete); 736 737 kfree_sensitive(smp->csrk); 738 kfree_sensitive(smp->responder_csrk); 739 kfree_sensitive(smp->link_key); 740 741 crypto_free_kpp(smp->tfm_ecdh); 742 743 /* Ensure that we don't leave any debug key around if debug key 744 * support hasn't been explicitly enabled. 745 */ 746 if (smp->ltk && smp->ltk->type == SMP_LTK_P256_DEBUG && 747 !hci_dev_test_flag(hcon->hdev, HCI_KEEP_DEBUG_KEYS)) { 748 list_del_rcu(&smp->ltk->list); 749 kfree_rcu(smp->ltk, rcu); 750 smp->ltk = NULL; 751 } 752 753 /* If pairing failed clean up any keys we might have */ 754 if (!complete) { 755 if (smp->ltk) { 756 list_del_rcu(&smp->ltk->list); 757 kfree_rcu(smp->ltk, rcu); 758 } 759 760 if (smp->responder_ltk) { 761 list_del_rcu(&smp->responder_ltk->list); 762 kfree_rcu(smp->responder_ltk, rcu); 763 } 764 765 if (smp->remote_irk) { 766 list_del_rcu(&smp->remote_irk->list); 767 kfree_rcu(smp->remote_irk, rcu); 768 } 769 } 770 771 chan->data = NULL; 772 kfree_sensitive(smp); 773 hci_conn_drop(hcon); 774 } 775 776 static void smp_failure(struct l2cap_conn *conn, u8 reason) 777 { 778 struct hci_conn *hcon = conn->hcon; 779 struct l2cap_chan *chan = conn->smp; 780 781 if (reason) 782 smp_send_cmd(conn, SMP_CMD_PAIRING_FAIL, sizeof(reason), 783 &reason); 784 785 mgmt_auth_failed(hcon, HCI_ERROR_AUTH_FAILURE); 786 787 if (chan->data) 788 smp_chan_destroy(conn); 789 } 790 791 #define JUST_WORKS 0x00 792 #define JUST_CFM 0x01 793 #define REQ_PASSKEY 0x02 794 #define CFM_PASSKEY 0x03 795 #define REQ_OOB 0x04 796 #define DSP_PASSKEY 0x05 797 #define OVERLAP 0xFF 798 799 static const u8 gen_method[5][5] = { 800 { JUST_WORKS, JUST_CFM, REQ_PASSKEY, JUST_WORKS, REQ_PASSKEY }, 801 { JUST_WORKS, JUST_CFM, REQ_PASSKEY, JUST_WORKS, REQ_PASSKEY }, 802 { CFM_PASSKEY, CFM_PASSKEY, REQ_PASSKEY, JUST_WORKS, CFM_PASSKEY }, 803 { JUST_WORKS, JUST_CFM, JUST_WORKS, JUST_WORKS, JUST_CFM }, 804 { CFM_PASSKEY, CFM_PASSKEY, REQ_PASSKEY, JUST_WORKS, OVERLAP }, 805 }; 806 807 static const u8 sc_method[5][5] = { 808 { JUST_WORKS, JUST_CFM, REQ_PASSKEY, JUST_WORKS, REQ_PASSKEY }, 809 { JUST_WORKS, CFM_PASSKEY, REQ_PASSKEY, JUST_WORKS, CFM_PASSKEY }, 810 { DSP_PASSKEY, DSP_PASSKEY, REQ_PASSKEY, JUST_WORKS, DSP_PASSKEY }, 811 { JUST_WORKS, JUST_CFM, JUST_WORKS, JUST_WORKS, JUST_CFM }, 812 { DSP_PASSKEY, CFM_PASSKEY, REQ_PASSKEY, JUST_WORKS, CFM_PASSKEY }, 813 }; 814 815 static u8 get_auth_method(struct smp_chan *smp, u8 local_io, u8 remote_io) 816 { 817 /* If either side has unknown io_caps, use JUST_CFM (which gets 818 * converted later to JUST_WORKS if we're initiators. 819 */ 820 if (local_io > SMP_IO_KEYBOARD_DISPLAY || 821 remote_io > SMP_IO_KEYBOARD_DISPLAY) 822 return JUST_CFM; 823 824 if (test_bit(SMP_FLAG_SC, &smp->flags)) 825 return sc_method[remote_io][local_io]; 826 827 return gen_method[remote_io][local_io]; 828 } 829 830 static int tk_request(struct l2cap_conn *conn, u8 remote_oob, u8 auth, 831 u8 local_io, u8 remote_io) 832 { 833 struct hci_conn *hcon = conn->hcon; 834 struct l2cap_chan *chan = conn->smp; 835 struct smp_chan *smp = chan->data; 836 u32 passkey = 0; 837 int ret; 838 839 /* Initialize key for JUST WORKS */ 840 memset(smp->tk, 0, sizeof(smp->tk)); 841 clear_bit(SMP_FLAG_TK_VALID, &smp->flags); 842 843 bt_dev_dbg(hcon->hdev, "auth:%u lcl:%u rem:%u", auth, local_io, 844 remote_io); 845 846 /* If neither side wants MITM, either "just" confirm an incoming 847 * request or use just-works for outgoing ones. The JUST_CFM 848 * will be converted to JUST_WORKS if necessary later in this 849 * function. If either side has MITM look up the method from the 850 * table. 851 */ 852 if (!(auth & SMP_AUTH_MITM)) 853 smp->method = JUST_CFM; 854 else 855 smp->method = get_auth_method(smp, local_io, remote_io); 856 857 /* Don't confirm locally initiated pairing attempts */ 858 if (smp->method == JUST_CFM && test_bit(SMP_FLAG_INITIATOR, 859 &smp->flags)) 860 smp->method = JUST_WORKS; 861 862 /* Don't bother user space with no IO capabilities */ 863 if (smp->method == JUST_CFM && 864 hcon->io_capability == HCI_IO_NO_INPUT_OUTPUT) 865 smp->method = JUST_WORKS; 866 867 /* If Just Works, Continue with Zero TK and ask user-space for 868 * confirmation */ 869 if (smp->method == JUST_WORKS) { 870 ret = mgmt_user_confirm_request(hcon->hdev, &hcon->dst, 871 hcon->type, 872 hcon->dst_type, 873 passkey, 1); 874 if (ret) 875 return ret; 876 set_bit(SMP_FLAG_WAIT_USER, &smp->flags); 877 return 0; 878 } 879 880 /* If this function is used for SC -> legacy fallback we 881 * can only recover the just-works case. 882 */ 883 if (test_bit(SMP_FLAG_SC, &smp->flags)) 884 return -EINVAL; 885 886 /* Not Just Works/Confirm results in MITM Authentication */ 887 if (smp->method != JUST_CFM) { 888 set_bit(SMP_FLAG_MITM_AUTH, &smp->flags); 889 if (hcon->pending_sec_level < BT_SECURITY_HIGH) 890 hcon->pending_sec_level = BT_SECURITY_HIGH; 891 } 892 893 /* If both devices have Keyboard-Display I/O, the initiator 894 * Confirms and the responder Enters the passkey. 895 */ 896 if (smp->method == OVERLAP) { 897 if (test_bit(SMP_FLAG_INITIATOR, &smp->flags)) 898 smp->method = CFM_PASSKEY; 899 else 900 smp->method = REQ_PASSKEY; 901 } 902 903 /* Generate random passkey. */ 904 if (smp->method == CFM_PASSKEY) { 905 memset(smp->tk, 0, sizeof(smp->tk)); 906 get_random_bytes(&passkey, sizeof(passkey)); 907 passkey %= 1000000; 908 put_unaligned_le32(passkey, smp->tk); 909 bt_dev_dbg(hcon->hdev, "PassKey: %u", passkey); 910 set_bit(SMP_FLAG_TK_VALID, &smp->flags); 911 } 912 913 if (smp->method == REQ_PASSKEY) 914 ret = mgmt_user_passkey_request(hcon->hdev, &hcon->dst, 915 hcon->type, hcon->dst_type); 916 else if (smp->method == JUST_CFM) 917 ret = mgmt_user_confirm_request(hcon->hdev, &hcon->dst, 918 hcon->type, hcon->dst_type, 919 passkey, 1); 920 else 921 ret = mgmt_user_passkey_notify(hcon->hdev, &hcon->dst, 922 hcon->type, hcon->dst_type, 923 passkey, 0); 924 925 return ret; 926 } 927 928 static u8 smp_confirm(struct smp_chan *smp) 929 { 930 struct l2cap_conn *conn = smp->conn; 931 struct smp_cmd_pairing_confirm cp; 932 int ret; 933 934 bt_dev_dbg(conn->hcon->hdev, "conn %p", conn); 935 936 ret = smp_c1(smp->tk, smp->prnd, smp->preq, smp->prsp, 937 conn->hcon->init_addr_type, &conn->hcon->init_addr, 938 conn->hcon->resp_addr_type, &conn->hcon->resp_addr, 939 cp.confirm_val); 940 if (ret) 941 return SMP_UNSPECIFIED; 942 943 clear_bit(SMP_FLAG_CFM_PENDING, &smp->flags); 944 945 smp_send_cmd(smp->conn, SMP_CMD_PAIRING_CONFIRM, sizeof(cp), &cp); 946 947 if (test_bit(SMP_FLAG_INITIATOR, &smp->flags)) 948 SMP_ALLOW_CMD(smp, SMP_CMD_PAIRING_CONFIRM); 949 else 950 SMP_ALLOW_CMD(smp, SMP_CMD_PAIRING_RANDOM); 951 952 return 0; 953 } 954 955 static u8 smp_random(struct smp_chan *smp) 956 { 957 struct l2cap_conn *conn = smp->conn; 958 struct hci_conn *hcon = conn->hcon; 959 u8 confirm[16]; 960 int ret; 961 962 bt_dev_dbg(conn->hcon->hdev, "conn %p %s", conn, 963 test_bit(SMP_FLAG_INITIATOR, &smp->flags) ? "initiator" : 964 "responder"); 965 966 ret = smp_c1(smp->tk, smp->rrnd, smp->preq, smp->prsp, 967 hcon->init_addr_type, &hcon->init_addr, 968 hcon->resp_addr_type, &hcon->resp_addr, confirm); 969 if (ret) 970 return SMP_UNSPECIFIED; 971 972 if (crypto_memneq(smp->pcnf, confirm, sizeof(smp->pcnf))) { 973 bt_dev_err(hcon->hdev, "pairing failed " 974 "(confirmation values mismatch)"); 975 return SMP_CONFIRM_FAILED; 976 } 977 978 if (test_bit(SMP_FLAG_INITIATOR, &smp->flags)) { 979 u8 stk[16]; 980 __le64 rand = 0; 981 __le16 ediv = 0; 982 983 smp_s1(smp->tk, smp->rrnd, smp->prnd, stk); 984 985 if (test_and_set_bit(HCI_CONN_ENCRYPT_PEND, &hcon->flags)) 986 return SMP_UNSPECIFIED; 987 988 hci_le_start_enc(hcon, ediv, rand, stk, smp->enc_key_size); 989 hcon->enc_key_size = smp->enc_key_size; 990 set_bit(HCI_CONN_STK_ENCRYPT, &hcon->flags); 991 } else { 992 u8 stk[16], auth; 993 __le64 rand = 0; 994 __le16 ediv = 0; 995 996 smp_send_cmd(conn, SMP_CMD_PAIRING_RANDOM, sizeof(smp->prnd), 997 smp->prnd); 998 999 smp_s1(smp->tk, smp->prnd, smp->rrnd, stk); 1000 1001 auth = test_bit(SMP_FLAG_MITM_AUTH, &smp->flags) ? 1 : 0; 1002 1003 /* Even though there's no _RESPONDER suffix this is the 1004 * responder STK we're adding for later lookup (the initiator 1005 * STK never needs to be stored). 1006 */ 1007 hci_add_ltk(hcon->hdev, &hcon->dst, hcon->dst_type, 1008 SMP_STK, auth, stk, smp->enc_key_size, ediv, rand); 1009 } 1010 1011 return 0; 1012 } 1013 1014 static void smp_notify_keys(struct l2cap_conn *conn) 1015 { 1016 struct l2cap_chan *chan = conn->smp; 1017 struct smp_chan *smp = chan->data; 1018 struct hci_conn *hcon = conn->hcon; 1019 struct hci_dev *hdev = hcon->hdev; 1020 struct smp_cmd_pairing *req = (void *) &smp->preq[1]; 1021 struct smp_cmd_pairing *rsp = (void *) &smp->prsp[1]; 1022 bool persistent; 1023 1024 if (hcon->type == ACL_LINK) { 1025 if (hcon->key_type == HCI_LK_DEBUG_COMBINATION) 1026 persistent = false; 1027 else 1028 persistent = !test_bit(HCI_CONN_FLUSH_KEY, 1029 &hcon->flags); 1030 } else { 1031 /* The LTKs, IRKs and CSRKs should be persistent only if 1032 * both sides had the bonding bit set in their 1033 * authentication requests. 1034 */ 1035 persistent = !!((req->auth_req & rsp->auth_req) & 1036 SMP_AUTH_BONDING); 1037 } 1038 1039 if (smp->remote_irk) { 1040 mgmt_new_irk(hdev, smp->remote_irk, persistent); 1041 1042 /* Now that user space can be considered to know the 1043 * identity address track the connection based on it 1044 * from now on (assuming this is an LE link). 1045 */ 1046 if (hcon->type == LE_LINK) { 1047 bacpy(&hcon->dst, &smp->remote_irk->bdaddr); 1048 hcon->dst_type = smp->remote_irk->addr_type; 1049 /* Use a short delay to make sure the new address is 1050 * propagated _before_ the channels. 1051 */ 1052 queue_delayed_work(hdev->workqueue, 1053 &conn->id_addr_timer, 1054 ID_ADDR_TIMEOUT); 1055 } 1056 } 1057 1058 if (smp->csrk) { 1059 smp->csrk->bdaddr_type = hcon->dst_type; 1060 bacpy(&smp->csrk->bdaddr, &hcon->dst); 1061 mgmt_new_csrk(hdev, smp->csrk, persistent); 1062 } 1063 1064 if (smp->responder_csrk) { 1065 smp->responder_csrk->bdaddr_type = hcon->dst_type; 1066 bacpy(&smp->responder_csrk->bdaddr, &hcon->dst); 1067 mgmt_new_csrk(hdev, smp->responder_csrk, persistent); 1068 } 1069 1070 if (smp->ltk) { 1071 smp->ltk->bdaddr_type = hcon->dst_type; 1072 bacpy(&smp->ltk->bdaddr, &hcon->dst); 1073 mgmt_new_ltk(hdev, smp->ltk, persistent); 1074 } 1075 1076 if (smp->responder_ltk) { 1077 smp->responder_ltk->bdaddr_type = hcon->dst_type; 1078 bacpy(&smp->responder_ltk->bdaddr, &hcon->dst); 1079 mgmt_new_ltk(hdev, smp->responder_ltk, persistent); 1080 } 1081 1082 if (smp->link_key) { 1083 struct link_key *key; 1084 u8 type; 1085 1086 if (test_bit(SMP_FLAG_DEBUG_KEY, &smp->flags)) 1087 type = HCI_LK_DEBUG_COMBINATION; 1088 else if (hcon->sec_level == BT_SECURITY_FIPS) 1089 type = HCI_LK_AUTH_COMBINATION_P256; 1090 else 1091 type = HCI_LK_UNAUTH_COMBINATION_P256; 1092 1093 key = hci_add_link_key(hdev, smp->conn->hcon, &hcon->dst, 1094 smp->link_key, type, 0, &persistent); 1095 if (key) { 1096 mgmt_new_link_key(hdev, key, persistent); 1097 1098 /* Don't keep debug keys around if the relevant 1099 * flag is not set. 1100 */ 1101 if (!hci_dev_test_flag(hdev, HCI_KEEP_DEBUG_KEYS) && 1102 key->type == HCI_LK_DEBUG_COMBINATION) { 1103 list_del_rcu(&key->list); 1104 kfree_rcu(key, rcu); 1105 } 1106 } 1107 } 1108 } 1109 1110 static void sc_add_ltk(struct smp_chan *smp) 1111 { 1112 struct hci_conn *hcon = smp->conn->hcon; 1113 u8 key_type, auth; 1114 1115 if (test_bit(SMP_FLAG_DEBUG_KEY, &smp->flags)) 1116 key_type = SMP_LTK_P256_DEBUG; 1117 else 1118 key_type = SMP_LTK_P256; 1119 1120 if (hcon->pending_sec_level == BT_SECURITY_FIPS) 1121 auth = 1; 1122 else 1123 auth = 0; 1124 1125 smp->ltk = hci_add_ltk(hcon->hdev, &hcon->dst, hcon->dst_type, 1126 key_type, auth, smp->tk, smp->enc_key_size, 1127 0, 0); 1128 } 1129 1130 static void sc_generate_link_key(struct smp_chan *smp) 1131 { 1132 /* From core spec. Spells out in ASCII as 'lebr'. */ 1133 const u8 lebr[4] = { 0x72, 0x62, 0x65, 0x6c }; 1134 1135 smp->link_key = kzalloc(16, GFP_KERNEL); 1136 if (!smp->link_key) 1137 return; 1138 1139 if (test_bit(SMP_FLAG_CT2, &smp->flags)) { 1140 /* SALT = 0x000000000000000000000000746D7031 */ 1141 const u8 salt[16] = { 0x31, 0x70, 0x6d, 0x74 }; 1142 1143 if (smp_h7(smp->tk, salt, smp->link_key)) { 1144 kfree_sensitive(smp->link_key); 1145 smp->link_key = NULL; 1146 return; 1147 } 1148 } else { 1149 /* From core spec. Spells out in ASCII as 'tmp1'. */ 1150 const u8 tmp1[4] = { 0x31, 0x70, 0x6d, 0x74 }; 1151 1152 if (smp_h6(smp->tk, tmp1, smp->link_key)) { 1153 kfree_sensitive(smp->link_key); 1154 smp->link_key = NULL; 1155 return; 1156 } 1157 } 1158 1159 if (smp_h6(smp->link_key, lebr, smp->link_key)) { 1160 kfree_sensitive(smp->link_key); 1161 smp->link_key = NULL; 1162 return; 1163 } 1164 } 1165 1166 static void smp_allow_key_dist(struct smp_chan *smp) 1167 { 1168 /* Allow the first expected phase 3 PDU. The rest of the PDUs 1169 * will be allowed in each PDU handler to ensure we receive 1170 * them in the correct order. 1171 */ 1172 if (smp->remote_key_dist & SMP_DIST_ENC_KEY) 1173 SMP_ALLOW_CMD(smp, SMP_CMD_ENCRYPT_INFO); 1174 else if (smp->remote_key_dist & SMP_DIST_ID_KEY) 1175 SMP_ALLOW_CMD(smp, SMP_CMD_IDENT_INFO); 1176 else if (smp->remote_key_dist & SMP_DIST_SIGN) 1177 SMP_ALLOW_CMD(smp, SMP_CMD_SIGN_INFO); 1178 } 1179 1180 static void sc_generate_ltk(struct smp_chan *smp) 1181 { 1182 /* From core spec. Spells out in ASCII as 'brle'. */ 1183 const u8 brle[4] = { 0x65, 0x6c, 0x72, 0x62 }; 1184 struct hci_conn *hcon = smp->conn->hcon; 1185 struct hci_dev *hdev = hcon->hdev; 1186 struct link_key *key; 1187 1188 key = hci_find_link_key(hdev, &hcon->dst); 1189 if (!key) { 1190 bt_dev_err(hdev, "no Link Key found to generate LTK"); 1191 return; 1192 } 1193 1194 if (key->type == HCI_LK_DEBUG_COMBINATION) 1195 set_bit(SMP_FLAG_DEBUG_KEY, &smp->flags); 1196 1197 if (test_bit(SMP_FLAG_CT2, &smp->flags)) { 1198 /* SALT = 0x000000000000000000000000746D7032 */ 1199 const u8 salt[16] = { 0x32, 0x70, 0x6d, 0x74 }; 1200 1201 if (smp_h7(key->val, salt, smp->tk)) 1202 return; 1203 } else { 1204 /* From core spec. Spells out in ASCII as 'tmp2'. */ 1205 const u8 tmp2[4] = { 0x32, 0x70, 0x6d, 0x74 }; 1206 1207 if (smp_h6(key->val, tmp2, smp->tk)) 1208 return; 1209 } 1210 1211 if (smp_h6(smp->tk, brle, smp->tk)) 1212 return; 1213 1214 sc_add_ltk(smp); 1215 } 1216 1217 static void smp_distribute_keys(struct smp_chan *smp) 1218 { 1219 struct smp_cmd_pairing *req, *rsp; 1220 struct l2cap_conn *conn = smp->conn; 1221 struct hci_conn *hcon = conn->hcon; 1222 struct hci_dev *hdev = hcon->hdev; 1223 __u8 *keydist; 1224 1225 bt_dev_dbg(hdev, "conn %p", conn); 1226 1227 rsp = (void *) &smp->prsp[1]; 1228 1229 /* The responder sends its keys first */ 1230 if (test_bit(SMP_FLAG_INITIATOR, &smp->flags) && 1231 (smp->remote_key_dist & KEY_DIST_MASK)) { 1232 smp_allow_key_dist(smp); 1233 return; 1234 } 1235 1236 req = (void *) &smp->preq[1]; 1237 1238 if (test_bit(SMP_FLAG_INITIATOR, &smp->flags)) { 1239 keydist = &rsp->init_key_dist; 1240 *keydist &= req->init_key_dist; 1241 } else { 1242 keydist = &rsp->resp_key_dist; 1243 *keydist &= req->resp_key_dist; 1244 } 1245 1246 if (test_bit(SMP_FLAG_SC, &smp->flags)) { 1247 if (hcon->type == LE_LINK && (*keydist & SMP_DIST_LINK_KEY)) 1248 sc_generate_link_key(smp); 1249 if (hcon->type == ACL_LINK && (*keydist & SMP_DIST_ENC_KEY)) 1250 sc_generate_ltk(smp); 1251 1252 /* Clear the keys which are generated but not distributed */ 1253 *keydist &= ~SMP_SC_NO_DIST; 1254 } 1255 1256 bt_dev_dbg(hdev, "keydist 0x%x", *keydist); 1257 1258 if (*keydist & SMP_DIST_ENC_KEY) { 1259 struct smp_cmd_encrypt_info enc; 1260 struct smp_cmd_initiator_ident ident; 1261 struct smp_ltk *ltk; 1262 u8 authenticated; 1263 __le16 ediv; 1264 __le64 rand; 1265 1266 /* Make sure we generate only the significant amount of 1267 * bytes based on the encryption key size, and set the rest 1268 * of the value to zeroes. 1269 */ 1270 get_random_bytes(enc.ltk, smp->enc_key_size); 1271 memset(enc.ltk + smp->enc_key_size, 0, 1272 sizeof(enc.ltk) - smp->enc_key_size); 1273 1274 get_random_bytes(&ediv, sizeof(ediv)); 1275 get_random_bytes(&rand, sizeof(rand)); 1276 1277 smp_send_cmd(conn, SMP_CMD_ENCRYPT_INFO, sizeof(enc), &enc); 1278 1279 authenticated = hcon->sec_level == BT_SECURITY_HIGH; 1280 ltk = hci_add_ltk(hdev, &hcon->dst, hcon->dst_type, 1281 SMP_LTK_RESPONDER, authenticated, enc.ltk, 1282 smp->enc_key_size, ediv, rand); 1283 smp->responder_ltk = ltk; 1284 1285 ident.ediv = ediv; 1286 ident.rand = rand; 1287 1288 smp_send_cmd(conn, SMP_CMD_INITIATOR_IDENT, sizeof(ident), 1289 &ident); 1290 1291 *keydist &= ~SMP_DIST_ENC_KEY; 1292 } 1293 1294 if (*keydist & SMP_DIST_ID_KEY) { 1295 struct smp_cmd_ident_addr_info addrinfo; 1296 struct smp_cmd_ident_info idinfo; 1297 1298 memcpy(idinfo.irk, hdev->irk, sizeof(idinfo.irk)); 1299 1300 smp_send_cmd(conn, SMP_CMD_IDENT_INFO, sizeof(idinfo), &idinfo); 1301 1302 /* The hci_conn contains the local identity address 1303 * after the connection has been established. 1304 * 1305 * This is true even when the connection has been 1306 * established using a resolvable random address. 1307 */ 1308 bacpy(&addrinfo.bdaddr, &hcon->src); 1309 addrinfo.addr_type = hcon->src_type; 1310 1311 smp_send_cmd(conn, SMP_CMD_IDENT_ADDR_INFO, sizeof(addrinfo), 1312 &addrinfo); 1313 1314 *keydist &= ~SMP_DIST_ID_KEY; 1315 } 1316 1317 if (*keydist & SMP_DIST_SIGN) { 1318 struct smp_cmd_sign_info sign; 1319 struct smp_csrk *csrk; 1320 1321 /* Generate a new random key */ 1322 get_random_bytes(sign.csrk, sizeof(sign.csrk)); 1323 1324 csrk = kzalloc_obj(*csrk); 1325 if (csrk) { 1326 if (hcon->sec_level > BT_SECURITY_MEDIUM) 1327 csrk->type = MGMT_CSRK_LOCAL_AUTHENTICATED; 1328 else 1329 csrk->type = MGMT_CSRK_LOCAL_UNAUTHENTICATED; 1330 memcpy(csrk->val, sign.csrk, sizeof(csrk->val)); 1331 } 1332 smp->responder_csrk = csrk; 1333 1334 smp_send_cmd(conn, SMP_CMD_SIGN_INFO, sizeof(sign), &sign); 1335 1336 *keydist &= ~SMP_DIST_SIGN; 1337 } 1338 1339 /* If there are still keys to be received wait for them */ 1340 if (smp->remote_key_dist & KEY_DIST_MASK) { 1341 smp_allow_key_dist(smp); 1342 return; 1343 } 1344 1345 set_bit(SMP_FLAG_COMPLETE, &smp->flags); 1346 smp_notify_keys(conn); 1347 1348 smp_chan_destroy(conn); 1349 } 1350 1351 static void smp_timeout(struct work_struct *work) 1352 { 1353 struct smp_chan *smp = container_of(work, struct smp_chan, 1354 security_timer.work); 1355 struct l2cap_conn *conn = smp->conn; 1356 1357 bt_dev_dbg(conn->hcon->hdev, "conn %p", conn); 1358 1359 hci_disconnect(conn->hcon, HCI_ERROR_AUTH_FAILURE); 1360 } 1361 1362 static struct smp_chan *smp_chan_create(struct l2cap_conn *conn) 1363 { 1364 struct hci_conn *hcon = conn->hcon; 1365 struct l2cap_chan *chan = conn->smp; 1366 struct smp_chan *smp; 1367 1368 smp = kzalloc_obj(*smp, GFP_ATOMIC); 1369 if (!smp) 1370 return NULL; 1371 1372 smp->tfm_ecdh = crypto_alloc_kpp("ecdh-nist-p256", 0, 0); 1373 if (IS_ERR(smp->tfm_ecdh)) { 1374 bt_dev_err(hcon->hdev, "Unable to create ECDH crypto context"); 1375 goto zfree_smp; 1376 } 1377 1378 smp->conn = conn; 1379 chan->data = smp; 1380 1381 SMP_ALLOW_CMD(smp, SMP_CMD_PAIRING_FAIL); 1382 1383 INIT_DELAYED_WORK(&smp->security_timer, smp_timeout); 1384 1385 hci_conn_hold(hcon); 1386 1387 return smp; 1388 1389 zfree_smp: 1390 kfree_sensitive(smp); 1391 return NULL; 1392 } 1393 1394 static int sc_mackey_and_ltk(struct smp_chan *smp, u8 mackey[16], u8 ltk[16]) 1395 { 1396 struct hci_conn *hcon = smp->conn->hcon; 1397 u8 *na, *nb, a[7], b[7]; 1398 1399 if (test_bit(SMP_FLAG_INITIATOR, &smp->flags)) { 1400 na = smp->prnd; 1401 nb = smp->rrnd; 1402 } else { 1403 na = smp->rrnd; 1404 nb = smp->prnd; 1405 } 1406 1407 memcpy(a, &hcon->init_addr, 6); 1408 memcpy(b, &hcon->resp_addr, 6); 1409 a[6] = hcon->init_addr_type; 1410 b[6] = hcon->resp_addr_type; 1411 1412 return smp_f5(smp->dhkey, na, nb, a, b, mackey, ltk); 1413 } 1414 1415 static void sc_dhkey_check(struct smp_chan *smp) 1416 { 1417 struct hci_conn *hcon = smp->conn->hcon; 1418 struct smp_cmd_dhkey_check check; 1419 u8 a[7], b[7], *local_addr, *remote_addr; 1420 u8 io_cap[3], r[16]; 1421 1422 memcpy(a, &hcon->init_addr, 6); 1423 memcpy(b, &hcon->resp_addr, 6); 1424 a[6] = hcon->init_addr_type; 1425 b[6] = hcon->resp_addr_type; 1426 1427 if (test_bit(SMP_FLAG_INITIATOR, &smp->flags)) { 1428 local_addr = a; 1429 remote_addr = b; 1430 memcpy(io_cap, &smp->preq[1], 3); 1431 } else { 1432 local_addr = b; 1433 remote_addr = a; 1434 memcpy(io_cap, &smp->prsp[1], 3); 1435 } 1436 1437 memset(r, 0, sizeof(r)); 1438 1439 if (smp->method == REQ_PASSKEY || smp->method == DSP_PASSKEY) 1440 put_unaligned_le32(hcon->passkey_notify, r); 1441 1442 if (smp->method == REQ_OOB) 1443 memcpy(r, smp->rr, 16); 1444 1445 smp_f6(smp->mackey, smp->prnd, smp->rrnd, r, io_cap, local_addr, 1446 remote_addr, check.e); 1447 1448 smp_send_cmd(smp->conn, SMP_CMD_DHKEY_CHECK, sizeof(check), &check); 1449 } 1450 1451 static u8 sc_passkey_send_confirm(struct smp_chan *smp) 1452 { 1453 struct l2cap_conn *conn = smp->conn; 1454 struct hci_conn *hcon = conn->hcon; 1455 struct smp_cmd_pairing_confirm cfm; 1456 u8 r; 1457 1458 r = ((hcon->passkey_notify >> smp->passkey_round) & 0x01); 1459 r |= 0x80; 1460 1461 get_random_bytes(smp->prnd, sizeof(smp->prnd)); 1462 1463 if (smp_f4(smp->local_pk, smp->remote_pk, smp->prnd, r, 1464 cfm.confirm_val)) 1465 return SMP_UNSPECIFIED; 1466 1467 smp_send_cmd(conn, SMP_CMD_PAIRING_CONFIRM, sizeof(cfm), &cfm); 1468 1469 return 0; 1470 } 1471 1472 static u8 sc_passkey_round(struct smp_chan *smp, u8 smp_op) 1473 { 1474 struct l2cap_conn *conn = smp->conn; 1475 struct hci_conn *hcon = conn->hcon; 1476 struct hci_dev *hdev = hcon->hdev; 1477 u8 cfm[16], r; 1478 1479 /* Ignore the PDU if we've already done 20 rounds (0 - 19) */ 1480 if (smp->passkey_round >= 20) 1481 return 0; 1482 1483 switch (smp_op) { 1484 case SMP_CMD_PAIRING_RANDOM: 1485 r = ((hcon->passkey_notify >> smp->passkey_round) & 0x01); 1486 r |= 0x80; 1487 1488 if (smp_f4(smp->remote_pk, smp->local_pk, smp->rrnd, r, cfm)) 1489 return SMP_UNSPECIFIED; 1490 1491 if (crypto_memneq(smp->pcnf, cfm, 16)) 1492 return SMP_CONFIRM_FAILED; 1493 1494 smp->passkey_round++; 1495 1496 if (smp->passkey_round == 20) { 1497 /* Generate MacKey and LTK */ 1498 if (sc_mackey_and_ltk(smp, smp->mackey, smp->tk)) 1499 return SMP_UNSPECIFIED; 1500 } 1501 1502 /* The round is only complete when the initiator 1503 * receives pairing random. 1504 */ 1505 if (!test_bit(SMP_FLAG_INITIATOR, &smp->flags)) { 1506 smp_send_cmd(conn, SMP_CMD_PAIRING_RANDOM, 1507 sizeof(smp->prnd), smp->prnd); 1508 if (smp->passkey_round == 20) 1509 SMP_ALLOW_CMD(smp, SMP_CMD_DHKEY_CHECK); 1510 else 1511 SMP_ALLOW_CMD(smp, SMP_CMD_PAIRING_CONFIRM); 1512 return 0; 1513 } 1514 1515 /* Start the next round */ 1516 if (smp->passkey_round != 20) 1517 return sc_passkey_round(smp, 0); 1518 1519 /* Passkey rounds are complete - start DHKey Check */ 1520 sc_dhkey_check(smp); 1521 SMP_ALLOW_CMD(smp, SMP_CMD_DHKEY_CHECK); 1522 1523 break; 1524 1525 case SMP_CMD_PAIRING_CONFIRM: 1526 if (test_bit(SMP_FLAG_WAIT_USER, &smp->flags)) { 1527 set_bit(SMP_FLAG_CFM_PENDING, &smp->flags); 1528 return 0; 1529 } 1530 1531 SMP_ALLOW_CMD(smp, SMP_CMD_PAIRING_RANDOM); 1532 1533 if (test_bit(SMP_FLAG_INITIATOR, &smp->flags)) { 1534 smp_send_cmd(conn, SMP_CMD_PAIRING_RANDOM, 1535 sizeof(smp->prnd), smp->prnd); 1536 return 0; 1537 } 1538 1539 return sc_passkey_send_confirm(smp); 1540 1541 case SMP_CMD_PUBLIC_KEY: 1542 default: 1543 /* Initiating device starts the round */ 1544 if (!test_bit(SMP_FLAG_INITIATOR, &smp->flags)) 1545 return 0; 1546 1547 bt_dev_dbg(hdev, "Starting passkey round %u", 1548 smp->passkey_round + 1); 1549 1550 SMP_ALLOW_CMD(smp, SMP_CMD_PAIRING_CONFIRM); 1551 1552 return sc_passkey_send_confirm(smp); 1553 } 1554 1555 return 0; 1556 } 1557 1558 static int sc_user_reply(struct smp_chan *smp, u16 mgmt_op, __le32 passkey) 1559 { 1560 struct l2cap_conn *conn = smp->conn; 1561 struct hci_conn *hcon = conn->hcon; 1562 u8 smp_op; 1563 1564 clear_bit(SMP_FLAG_WAIT_USER, &smp->flags); 1565 1566 switch (mgmt_op) { 1567 case MGMT_OP_USER_PASSKEY_NEG_REPLY: 1568 smp_failure(smp->conn, SMP_PASSKEY_ENTRY_FAILED); 1569 return 0; 1570 case MGMT_OP_USER_CONFIRM_NEG_REPLY: 1571 smp_failure(smp->conn, SMP_NUMERIC_COMP_FAILED); 1572 return 0; 1573 case MGMT_OP_USER_PASSKEY_REPLY: 1574 hcon->passkey_notify = le32_to_cpu(passkey); 1575 smp->passkey_round = 0; 1576 1577 if (test_and_clear_bit(SMP_FLAG_CFM_PENDING, &smp->flags)) 1578 smp_op = SMP_CMD_PAIRING_CONFIRM; 1579 else 1580 smp_op = 0; 1581 1582 if (sc_passkey_round(smp, smp_op)) 1583 return -EIO; 1584 1585 return 0; 1586 } 1587 1588 /* Initiator sends DHKey check first */ 1589 if (test_bit(SMP_FLAG_INITIATOR, &smp->flags)) { 1590 sc_dhkey_check(smp); 1591 SMP_ALLOW_CMD(smp, SMP_CMD_DHKEY_CHECK); 1592 } else if (test_and_clear_bit(SMP_FLAG_DHKEY_PENDING, &smp->flags)) { 1593 sc_dhkey_check(smp); 1594 sc_add_ltk(smp); 1595 } 1596 1597 return 0; 1598 } 1599 1600 int smp_user_confirm_reply(struct hci_conn *hcon, u16 mgmt_op, __le32 passkey) 1601 { 1602 struct l2cap_conn *conn = hcon->l2cap_data; 1603 struct l2cap_chan *chan; 1604 struct smp_chan *smp; 1605 u32 value; 1606 int err; 1607 1608 if (!conn) 1609 return -ENOTCONN; 1610 1611 bt_dev_dbg(conn->hcon->hdev, ""); 1612 1613 chan = conn->smp; 1614 if (!chan) 1615 return -ENOTCONN; 1616 1617 l2cap_chan_lock(chan); 1618 if (!chan->data) { 1619 err = -ENOTCONN; 1620 goto unlock; 1621 } 1622 1623 smp = chan->data; 1624 1625 if (test_bit(SMP_FLAG_SC, &smp->flags)) { 1626 err = sc_user_reply(smp, mgmt_op, passkey); 1627 goto unlock; 1628 } 1629 1630 switch (mgmt_op) { 1631 case MGMT_OP_USER_PASSKEY_REPLY: 1632 value = le32_to_cpu(passkey); 1633 memset(smp->tk, 0, sizeof(smp->tk)); 1634 bt_dev_dbg(conn->hcon->hdev, "PassKey: %u", value); 1635 put_unaligned_le32(value, smp->tk); 1636 fallthrough; 1637 case MGMT_OP_USER_CONFIRM_REPLY: 1638 set_bit(SMP_FLAG_TK_VALID, &smp->flags); 1639 break; 1640 case MGMT_OP_USER_PASSKEY_NEG_REPLY: 1641 case MGMT_OP_USER_CONFIRM_NEG_REPLY: 1642 smp_failure(conn, SMP_PASSKEY_ENTRY_FAILED); 1643 err = 0; 1644 goto unlock; 1645 default: 1646 smp_failure(conn, SMP_PASSKEY_ENTRY_FAILED); 1647 err = -EOPNOTSUPP; 1648 goto unlock; 1649 } 1650 1651 err = 0; 1652 1653 /* If it is our turn to send Pairing Confirm, do so now */ 1654 if (test_bit(SMP_FLAG_CFM_PENDING, &smp->flags)) { 1655 u8 rsp = smp_confirm(smp); 1656 if (rsp) 1657 smp_failure(conn, rsp); 1658 } 1659 1660 unlock: 1661 l2cap_chan_unlock(chan); 1662 return err; 1663 } 1664 1665 static void build_bredr_pairing_cmd(struct smp_chan *smp, 1666 struct smp_cmd_pairing *req, 1667 struct smp_cmd_pairing *rsp) 1668 { 1669 struct l2cap_conn *conn = smp->conn; 1670 struct hci_dev *hdev = conn->hcon->hdev; 1671 u8 local_dist = 0, remote_dist = 0; 1672 1673 if (hci_dev_test_flag(hdev, HCI_BONDABLE)) { 1674 local_dist = SMP_DIST_ENC_KEY | SMP_DIST_SIGN; 1675 remote_dist = SMP_DIST_ENC_KEY | SMP_DIST_SIGN; 1676 } 1677 1678 if (hci_dev_test_flag(hdev, HCI_RPA_RESOLVING)) 1679 remote_dist |= SMP_DIST_ID_KEY; 1680 1681 if (hci_dev_test_flag(hdev, HCI_PRIVACY)) 1682 local_dist |= SMP_DIST_ID_KEY; 1683 1684 if (!rsp) { 1685 memset(req, 0, sizeof(*req)); 1686 1687 req->auth_req = SMP_AUTH_CT2; 1688 req->init_key_dist = local_dist; 1689 req->resp_key_dist = remote_dist; 1690 req->max_key_size = conn->hcon->enc_key_size; 1691 1692 smp->remote_key_dist = remote_dist; 1693 1694 return; 1695 } 1696 1697 memset(rsp, 0, sizeof(*rsp)); 1698 1699 rsp->auth_req = SMP_AUTH_CT2; 1700 rsp->max_key_size = conn->hcon->enc_key_size; 1701 rsp->init_key_dist = req->init_key_dist & remote_dist; 1702 rsp->resp_key_dist = req->resp_key_dist & local_dist; 1703 1704 smp->remote_key_dist = rsp->init_key_dist; 1705 } 1706 1707 static u8 smp_cmd_pairing_req(struct l2cap_conn *conn, struct sk_buff *skb) 1708 { 1709 struct smp_cmd_pairing rsp, *req = (void *) skb->data; 1710 struct l2cap_chan *chan = conn->smp; 1711 struct hci_dev *hdev = conn->hcon->hdev; 1712 struct smp_chan *smp = chan->data; 1713 u8 key_size, auth, sec_level; 1714 int ret; 1715 1716 bt_dev_dbg(hdev, "conn %p", conn); 1717 1718 if (skb->len < sizeof(*req)) 1719 return SMP_INVALID_PARAMS; 1720 1721 if (smp && test_bit(SMP_FLAG_INITIATOR, &smp->flags)) 1722 return SMP_CMD_NOTSUPP; 1723 1724 if (!smp) { 1725 smp = smp_chan_create(conn); 1726 if (!smp) 1727 return SMP_UNSPECIFIED; 1728 } 1729 1730 /* We didn't start the pairing, so match remote */ 1731 auth = req->auth_req & AUTH_REQ_MASK(hdev); 1732 1733 if (!hci_dev_test_flag(hdev, HCI_BONDABLE) && 1734 (auth & SMP_AUTH_BONDING)) 1735 return SMP_PAIRING_NOTSUPP; 1736 1737 if (hci_dev_test_flag(hdev, HCI_SC_ONLY) && !(auth & SMP_AUTH_SC)) 1738 return SMP_AUTH_REQUIREMENTS; 1739 1740 smp->preq[0] = SMP_CMD_PAIRING_REQ; 1741 memcpy(&smp->preq[1], req, sizeof(*req)); 1742 skb_pull(skb, sizeof(*req)); 1743 1744 /* If the remote side's OOB flag is set it means it has 1745 * successfully received our local OOB data - therefore set the 1746 * flag to indicate that local OOB is in use. 1747 */ 1748 if (req->oob_flag == SMP_OOB_PRESENT && SMP_DEV(hdev)->local_oob) 1749 set_bit(SMP_FLAG_LOCAL_OOB, &smp->flags); 1750 1751 /* SMP over BR/EDR requires special treatment */ 1752 if (conn->hcon->type == ACL_LINK) { 1753 /* We must have a BR/EDR SC link */ 1754 if (!test_bit(HCI_CONN_AES_CCM, &conn->hcon->flags) && 1755 !hci_dev_test_flag(hdev, HCI_FORCE_BREDR_SMP)) 1756 return SMP_CROSS_TRANSP_NOT_ALLOWED; 1757 1758 set_bit(SMP_FLAG_SC, &smp->flags); 1759 1760 build_bredr_pairing_cmd(smp, req, &rsp); 1761 1762 if (req->auth_req & SMP_AUTH_CT2) 1763 set_bit(SMP_FLAG_CT2, &smp->flags); 1764 1765 key_size = min(req->max_key_size, rsp.max_key_size); 1766 if (check_enc_key_size(conn, key_size)) 1767 return SMP_ENC_KEY_SIZE; 1768 1769 /* Clear bits which are generated but not distributed */ 1770 smp->remote_key_dist &= ~SMP_SC_NO_DIST; 1771 1772 smp->prsp[0] = SMP_CMD_PAIRING_RSP; 1773 memcpy(&smp->prsp[1], &rsp, sizeof(rsp)); 1774 smp_send_cmd(conn, SMP_CMD_PAIRING_RSP, sizeof(rsp), &rsp); 1775 1776 smp_distribute_keys(smp); 1777 return 0; 1778 } 1779 1780 build_pairing_cmd(conn, req, &rsp, auth); 1781 1782 if (rsp.auth_req & SMP_AUTH_SC) { 1783 set_bit(SMP_FLAG_SC, &smp->flags); 1784 1785 if (rsp.auth_req & SMP_AUTH_CT2) 1786 set_bit(SMP_FLAG_CT2, &smp->flags); 1787 } 1788 1789 if (conn->hcon->io_capability == HCI_IO_NO_INPUT_OUTPUT) 1790 sec_level = BT_SECURITY_MEDIUM; 1791 else 1792 sec_level = authreq_to_seclevel(auth); 1793 1794 if (sec_level > conn->hcon->pending_sec_level) 1795 conn->hcon->pending_sec_level = sec_level; 1796 1797 /* If we need MITM check that it can be achieved. */ 1798 if (conn->hcon->pending_sec_level >= BT_SECURITY_HIGH) { 1799 u8 method; 1800 1801 method = get_auth_method(smp, conn->hcon->io_capability, 1802 req->io_capability); 1803 if (method == JUST_WORKS || method == JUST_CFM) 1804 return SMP_AUTH_REQUIREMENTS; 1805 1806 /* Force MITM bit if it isn't set by the initiator. */ 1807 auth |= SMP_AUTH_MITM; 1808 rsp.auth_req |= SMP_AUTH_MITM; 1809 } 1810 1811 key_size = min(req->max_key_size, rsp.max_key_size); 1812 if (check_enc_key_size(conn, key_size)) 1813 return SMP_ENC_KEY_SIZE; 1814 1815 get_random_bytes(smp->prnd, sizeof(smp->prnd)); 1816 1817 smp->prsp[0] = SMP_CMD_PAIRING_RSP; 1818 memcpy(&smp->prsp[1], &rsp, sizeof(rsp)); 1819 1820 smp_send_cmd(conn, SMP_CMD_PAIRING_RSP, sizeof(rsp), &rsp); 1821 1822 clear_bit(SMP_FLAG_INITIATOR, &smp->flags); 1823 1824 /* Strictly speaking we shouldn't allow Pairing Confirm for the 1825 * SC case, however some implementations incorrectly copy RFU auth 1826 * req bits from our security request, which may create a false 1827 * positive SC enablement. 1828 */ 1829 SMP_ALLOW_CMD(smp, SMP_CMD_PAIRING_CONFIRM); 1830 1831 if (test_bit(SMP_FLAG_SC, &smp->flags)) { 1832 SMP_ALLOW_CMD(smp, SMP_CMD_PUBLIC_KEY); 1833 /* Clear bits which are generated but not distributed */ 1834 smp->remote_key_dist &= ~SMP_SC_NO_DIST; 1835 /* Wait for Public Key from Initiating Device */ 1836 return 0; 1837 } 1838 1839 /* Request setup of TK */ 1840 ret = tk_request(conn, 0, auth, rsp.io_capability, req->io_capability); 1841 if (ret) 1842 return SMP_UNSPECIFIED; 1843 1844 return 0; 1845 } 1846 1847 static u8 sc_send_public_key(struct smp_chan *smp) 1848 { 1849 struct hci_dev *hdev = smp->conn->hcon->hdev; 1850 1851 bt_dev_dbg(hdev, ""); 1852 1853 if (test_bit(SMP_FLAG_LOCAL_OOB, &smp->flags)) { 1854 struct l2cap_chan *chan = hdev->smp_data; 1855 struct smp_dev *smp_dev; 1856 1857 if (!chan || !chan->data) 1858 return SMP_UNSPECIFIED; 1859 1860 smp_dev = chan->data; 1861 1862 memcpy(smp->local_pk, smp_dev->local_pk, 64); 1863 memcpy(smp->lr, smp_dev->local_rand, 16); 1864 1865 if (smp_dev->debug_key) 1866 set_bit(SMP_FLAG_DEBUG_KEY, &smp->flags); 1867 1868 goto done; 1869 } 1870 1871 if (hci_dev_test_flag(hdev, HCI_USE_DEBUG_KEYS)) { 1872 bt_dev_dbg(hdev, "Using debug keys"); 1873 if (set_ecdh_privkey(smp->tfm_ecdh, debug_sk)) 1874 return SMP_UNSPECIFIED; 1875 memcpy(smp->local_pk, debug_pk, 64); 1876 set_bit(SMP_FLAG_DEBUG_KEY, &smp->flags); 1877 } else { 1878 while (true) { 1879 /* Generate key pair for Secure Connections */ 1880 if (generate_ecdh_keys(smp->tfm_ecdh, smp->local_pk)) 1881 return SMP_UNSPECIFIED; 1882 1883 /* This is unlikely, but we need to check that 1884 * we didn't accidentally generate a debug key. 1885 */ 1886 if (crypto_memneq(smp->local_pk, debug_pk, 64)) 1887 break; 1888 } 1889 } 1890 1891 done: 1892 SMP_DBG("Local Public Key X: %32phN", smp->local_pk); 1893 SMP_DBG("Local Public Key Y: %32phN", smp->local_pk + 32); 1894 1895 smp_send_cmd(smp->conn, SMP_CMD_PUBLIC_KEY, 64, smp->local_pk); 1896 1897 return 0; 1898 } 1899 1900 static u8 smp_cmd_pairing_rsp(struct l2cap_conn *conn, struct sk_buff *skb) 1901 { 1902 struct smp_cmd_pairing *req, *rsp = (void *) skb->data; 1903 struct l2cap_chan *chan = conn->smp; 1904 struct smp_chan *smp = chan->data; 1905 struct hci_dev *hdev = conn->hcon->hdev; 1906 u8 key_size, auth; 1907 int ret; 1908 1909 bt_dev_dbg(hdev, "conn %p", conn); 1910 1911 if (skb->len < sizeof(*rsp)) 1912 return SMP_INVALID_PARAMS; 1913 1914 if (!test_bit(SMP_FLAG_INITIATOR, &smp->flags)) 1915 return SMP_CMD_NOTSUPP; 1916 1917 skb_pull(skb, sizeof(*rsp)); 1918 1919 req = (void *) &smp->preq[1]; 1920 1921 key_size = min(req->max_key_size, rsp->max_key_size); 1922 if (check_enc_key_size(conn, key_size)) 1923 return SMP_ENC_KEY_SIZE; 1924 1925 auth = rsp->auth_req & AUTH_REQ_MASK(hdev); 1926 1927 if (hci_dev_test_flag(hdev, HCI_SC_ONLY) && !(auth & SMP_AUTH_SC)) 1928 return SMP_AUTH_REQUIREMENTS; 1929 1930 /* If the remote side's OOB flag is set it means it has 1931 * successfully received our local OOB data - therefore set the 1932 * flag to indicate that local OOB is in use. 1933 */ 1934 if (rsp->oob_flag == SMP_OOB_PRESENT && SMP_DEV(hdev)->local_oob) 1935 set_bit(SMP_FLAG_LOCAL_OOB, &smp->flags); 1936 1937 smp->prsp[0] = SMP_CMD_PAIRING_RSP; 1938 memcpy(&smp->prsp[1], rsp, sizeof(*rsp)); 1939 1940 /* Update remote key distribution in case the remote cleared 1941 * some bits that we had enabled in our request. 1942 */ 1943 smp->remote_key_dist &= rsp->resp_key_dist; 1944 1945 if ((req->auth_req & SMP_AUTH_CT2) && (auth & SMP_AUTH_CT2)) 1946 set_bit(SMP_FLAG_CT2, &smp->flags); 1947 1948 /* For BR/EDR this means we're done and can start phase 3 */ 1949 if (conn->hcon->type == ACL_LINK) { 1950 /* Clear bits which are generated but not distributed */ 1951 smp->remote_key_dist &= ~SMP_SC_NO_DIST; 1952 smp_distribute_keys(smp); 1953 return 0; 1954 } 1955 1956 if ((req->auth_req & SMP_AUTH_SC) && (auth & SMP_AUTH_SC)) 1957 set_bit(SMP_FLAG_SC, &smp->flags); 1958 else if (conn->hcon->pending_sec_level > BT_SECURITY_HIGH) 1959 conn->hcon->pending_sec_level = BT_SECURITY_HIGH; 1960 1961 /* If we need MITM check that it can be achieved */ 1962 if (conn->hcon->pending_sec_level >= BT_SECURITY_HIGH) { 1963 u8 method; 1964 1965 method = get_auth_method(smp, req->io_capability, 1966 rsp->io_capability); 1967 if (method == JUST_WORKS || method == JUST_CFM) 1968 return SMP_AUTH_REQUIREMENTS; 1969 } 1970 1971 get_random_bytes(smp->prnd, sizeof(smp->prnd)); 1972 1973 /* Update remote key distribution in case the remote cleared 1974 * some bits that we had enabled in our request. 1975 */ 1976 smp->remote_key_dist &= rsp->resp_key_dist; 1977 1978 if (test_bit(SMP_FLAG_SC, &smp->flags)) { 1979 /* Clear bits which are generated but not distributed */ 1980 smp->remote_key_dist &= ~SMP_SC_NO_DIST; 1981 SMP_ALLOW_CMD(smp, SMP_CMD_PUBLIC_KEY); 1982 return sc_send_public_key(smp); 1983 } 1984 1985 auth |= req->auth_req; 1986 1987 ret = tk_request(conn, 0, auth, req->io_capability, rsp->io_capability); 1988 if (ret) 1989 return SMP_UNSPECIFIED; 1990 1991 set_bit(SMP_FLAG_CFM_PENDING, &smp->flags); 1992 1993 /* Can't compose response until we have been confirmed */ 1994 if (test_bit(SMP_FLAG_TK_VALID, &smp->flags)) 1995 return smp_confirm(smp); 1996 1997 return 0; 1998 } 1999 2000 static u8 sc_check_confirm(struct smp_chan *smp) 2001 { 2002 struct l2cap_conn *conn = smp->conn; 2003 2004 bt_dev_dbg(conn->hcon->hdev, ""); 2005 2006 if (smp->method == REQ_PASSKEY || smp->method == DSP_PASSKEY) 2007 return sc_passkey_round(smp, SMP_CMD_PAIRING_CONFIRM); 2008 2009 if (test_bit(SMP_FLAG_INITIATOR, &smp->flags)) { 2010 smp_send_cmd(conn, SMP_CMD_PAIRING_RANDOM, sizeof(smp->prnd), 2011 smp->prnd); 2012 SMP_ALLOW_CMD(smp, SMP_CMD_PAIRING_RANDOM); 2013 } 2014 2015 return 0; 2016 } 2017 2018 /* Work-around for some implementations that incorrectly copy RFU bits 2019 * from our security request and thereby create the impression that 2020 * we're doing SC when in fact the remote doesn't support it. 2021 */ 2022 static int fixup_sc_false_positive(struct smp_chan *smp) 2023 { 2024 struct l2cap_conn *conn = smp->conn; 2025 struct hci_conn *hcon = conn->hcon; 2026 struct hci_dev *hdev = hcon->hdev; 2027 struct smp_cmd_pairing *req, *rsp; 2028 u8 auth; 2029 2030 /* The issue is only observed when we're in responder role */ 2031 if (test_bit(SMP_FLAG_INITIATOR, &smp->flags)) 2032 return SMP_UNSPECIFIED; 2033 2034 if (hci_dev_test_flag(hdev, HCI_SC_ONLY)) { 2035 bt_dev_err(hdev, "refusing legacy fallback in SC-only mode"); 2036 return SMP_UNSPECIFIED; 2037 } 2038 2039 bt_dev_err(hdev, "trying to fall back to legacy SMP"); 2040 2041 req = (void *) &smp->preq[1]; 2042 rsp = (void *) &smp->prsp[1]; 2043 2044 /* Rebuild key dist flags which may have been cleared for SC */ 2045 smp->remote_key_dist = (req->init_key_dist & rsp->resp_key_dist); 2046 2047 auth = req->auth_req & AUTH_REQ_MASK(hdev); 2048 2049 if (tk_request(conn, 0, auth, rsp->io_capability, req->io_capability)) { 2050 bt_dev_err(hdev, "failed to fall back to legacy SMP"); 2051 return SMP_UNSPECIFIED; 2052 } 2053 2054 clear_bit(SMP_FLAG_SC, &smp->flags); 2055 2056 return 0; 2057 } 2058 2059 static u8 smp_cmd_pairing_confirm(struct l2cap_conn *conn, struct sk_buff *skb) 2060 { 2061 struct l2cap_chan *chan = conn->smp; 2062 struct smp_chan *smp = chan->data; 2063 struct hci_conn *hcon = conn->hcon; 2064 struct hci_dev *hdev = hcon->hdev; 2065 2066 bt_dev_dbg(hdev, "conn %p %s", conn, 2067 test_bit(SMP_FLAG_INITIATOR, &smp->flags) ? "initiator" : 2068 "responder"); 2069 2070 if (skb->len < sizeof(smp->pcnf)) 2071 return SMP_INVALID_PARAMS; 2072 2073 memcpy(smp->pcnf, skb->data, sizeof(smp->pcnf)); 2074 skb_pull(skb, sizeof(smp->pcnf)); 2075 2076 if (test_bit(SMP_FLAG_SC, &smp->flags)) { 2077 int ret; 2078 2079 /* Public Key exchange must happen before any other steps */ 2080 if (test_bit(SMP_FLAG_REMOTE_PK, &smp->flags)) 2081 return sc_check_confirm(smp); 2082 2083 bt_dev_err(hdev, "Unexpected SMP Pairing Confirm"); 2084 2085 ret = fixup_sc_false_positive(smp); 2086 if (ret) 2087 return ret; 2088 } 2089 2090 if (test_bit(SMP_FLAG_INITIATOR, &smp->flags)) { 2091 smp_send_cmd(conn, SMP_CMD_PAIRING_RANDOM, sizeof(smp->prnd), 2092 smp->prnd); 2093 SMP_ALLOW_CMD(smp, SMP_CMD_PAIRING_RANDOM); 2094 return 0; 2095 } 2096 2097 if (test_bit(SMP_FLAG_TK_VALID, &smp->flags)) 2098 return smp_confirm(smp); 2099 2100 set_bit(SMP_FLAG_CFM_PENDING, &smp->flags); 2101 2102 return 0; 2103 } 2104 2105 static u8 smp_cmd_pairing_random(struct l2cap_conn *conn, struct sk_buff *skb) 2106 { 2107 struct l2cap_chan *chan = conn->smp; 2108 struct smp_chan *smp = chan->data; 2109 struct hci_conn *hcon = conn->hcon; 2110 u8 *pkax, *pkbx, *na, *nb, confirm_hint; 2111 u32 passkey = 0; 2112 int err; 2113 2114 bt_dev_dbg(hcon->hdev, "conn %p", conn); 2115 2116 if (skb->len < sizeof(smp->rrnd)) 2117 return SMP_INVALID_PARAMS; 2118 2119 memcpy(smp->rrnd, skb->data, sizeof(smp->rrnd)); 2120 skb_pull(skb, sizeof(smp->rrnd)); 2121 2122 if (!test_bit(SMP_FLAG_SC, &smp->flags)) 2123 return smp_random(smp); 2124 2125 if (test_bit(SMP_FLAG_INITIATOR, &smp->flags)) { 2126 pkax = smp->local_pk; 2127 pkbx = smp->remote_pk; 2128 na = smp->prnd; 2129 nb = smp->rrnd; 2130 } else { 2131 pkax = smp->remote_pk; 2132 pkbx = smp->local_pk; 2133 na = smp->rrnd; 2134 nb = smp->prnd; 2135 } 2136 2137 if (smp->method == REQ_OOB) { 2138 if (!test_bit(SMP_FLAG_INITIATOR, &smp->flags)) 2139 smp_send_cmd(conn, SMP_CMD_PAIRING_RANDOM, 2140 sizeof(smp->prnd), smp->prnd); 2141 SMP_ALLOW_CMD(smp, SMP_CMD_DHKEY_CHECK); 2142 goto mackey_and_ltk; 2143 } 2144 2145 /* Passkey entry has special treatment */ 2146 if (smp->method == REQ_PASSKEY || smp->method == DSP_PASSKEY) 2147 return sc_passkey_round(smp, SMP_CMD_PAIRING_RANDOM); 2148 2149 if (test_bit(SMP_FLAG_INITIATOR, &smp->flags)) { 2150 u8 cfm[16]; 2151 2152 err = smp_f4(smp->remote_pk, smp->local_pk, smp->rrnd, 0, cfm); 2153 if (err) 2154 return SMP_UNSPECIFIED; 2155 2156 if (crypto_memneq(smp->pcnf, cfm, 16)) 2157 return SMP_CONFIRM_FAILED; 2158 } else { 2159 smp_send_cmd(conn, SMP_CMD_PAIRING_RANDOM, sizeof(smp->prnd), 2160 smp->prnd); 2161 SMP_ALLOW_CMD(smp, SMP_CMD_DHKEY_CHECK); 2162 } 2163 2164 mackey_and_ltk: 2165 /* Generate MacKey and LTK */ 2166 err = sc_mackey_and_ltk(smp, smp->mackey, smp->tk); 2167 if (err) 2168 return SMP_UNSPECIFIED; 2169 2170 if (smp->method == REQ_OOB) { 2171 if (test_bit(SMP_FLAG_INITIATOR, &smp->flags)) { 2172 sc_dhkey_check(smp); 2173 SMP_ALLOW_CMD(smp, SMP_CMD_DHKEY_CHECK); 2174 } 2175 return 0; 2176 } 2177 2178 err = smp_g2(pkax, pkbx, na, nb, &passkey); 2179 if (err) 2180 return SMP_UNSPECIFIED; 2181 2182 /* Always require user confirmation for Just-Works pairing to prevent 2183 * impersonation attacks, or in case of a legitimate device that is 2184 * repairing use the confirmation as acknowledgment to proceed with the 2185 * creation of new keys. 2186 */ 2187 confirm_hint = smp->method == JUST_WORKS ? 1 : 0; 2188 2189 err = mgmt_user_confirm_request(hcon->hdev, &hcon->dst, hcon->type, 2190 hcon->dst_type, passkey, confirm_hint); 2191 if (err) 2192 return SMP_UNSPECIFIED; 2193 2194 set_bit(SMP_FLAG_WAIT_USER, &smp->flags); 2195 2196 return 0; 2197 } 2198 2199 static bool smp_ltk_encrypt(struct l2cap_conn *conn, u8 sec_level) 2200 { 2201 struct smp_ltk *key; 2202 struct hci_conn *hcon = conn->hcon; 2203 2204 key = hci_find_ltk(hcon->hdev, &hcon->dst, hcon->dst_type, hcon->role); 2205 if (!key) 2206 return false; 2207 2208 if (smp_ltk_sec_level(key) < sec_level) 2209 return false; 2210 2211 if (test_and_set_bit(HCI_CONN_ENCRYPT_PEND, &hcon->flags)) 2212 return true; 2213 2214 hci_le_start_enc(hcon, key->ediv, key->rand, key->val, key->enc_size); 2215 hcon->enc_key_size = key->enc_size; 2216 2217 /* We never store STKs for initiator role, so clear this flag */ 2218 clear_bit(HCI_CONN_STK_ENCRYPT, &hcon->flags); 2219 2220 return true; 2221 } 2222 2223 bool smp_sufficient_security(struct hci_conn *hcon, u8 sec_level, 2224 enum smp_key_pref key_pref) 2225 { 2226 if (sec_level == BT_SECURITY_LOW) 2227 return true; 2228 2229 /* If we're encrypted with an STK but the caller prefers using 2230 * LTK claim insufficient security. This way we allow the 2231 * connection to be re-encrypted with an LTK, even if the LTK 2232 * provides the same level of security. Only exception is if we 2233 * don't have an LTK (e.g. because of key distribution bits). 2234 */ 2235 if (key_pref == SMP_USE_LTK && 2236 test_bit(HCI_CONN_STK_ENCRYPT, &hcon->flags) && 2237 hci_find_ltk(hcon->hdev, &hcon->dst, hcon->dst_type, hcon->role)) 2238 return false; 2239 2240 if (hcon->sec_level >= sec_level) 2241 return true; 2242 2243 return false; 2244 } 2245 2246 static void smp_send_pairing_req(struct smp_chan *smp, __u8 auth) 2247 { 2248 struct smp_cmd_pairing cp; 2249 2250 if (smp->conn->hcon->type == ACL_LINK) 2251 build_bredr_pairing_cmd(smp, &cp, NULL); 2252 else 2253 build_pairing_cmd(smp->conn, &cp, NULL, auth); 2254 2255 smp->preq[0] = SMP_CMD_PAIRING_REQ; 2256 memcpy(&smp->preq[1], &cp, sizeof(cp)); 2257 2258 smp_send_cmd(smp->conn, SMP_CMD_PAIRING_REQ, sizeof(cp), &cp); 2259 SMP_ALLOW_CMD(smp, SMP_CMD_PAIRING_RSP); 2260 2261 set_bit(SMP_FLAG_INITIATOR, &smp->flags); 2262 } 2263 2264 static u8 smp_cmd_security_req(struct l2cap_conn *conn, struct sk_buff *skb) 2265 { 2266 struct smp_cmd_security_req *rp = (void *) skb->data; 2267 struct hci_conn *hcon = conn->hcon; 2268 struct hci_dev *hdev = hcon->hdev; 2269 struct smp_chan *smp; 2270 u8 sec_level, auth; 2271 2272 bt_dev_dbg(hdev, "conn %p", conn); 2273 2274 /* SMP over BR/EDR only covers cross-transport key derivation; the 2275 * Security Request procedure has no BR/EDR counterpart. Reject it 2276 * here, otherwise smp_ltk_encrypt() finds the peer's LE LTK 2277 * (ADDR_LE_DEV_PUBLIC and BDADDR_BREDR are both 0) and issues 2278 * HCI_OP_LE_START_ENC on the ACL handle, which the controller 2279 * rejects and hci_cs_le_start_enc() turns into a disconnect. Reply 2280 * without smp_failure(): this is not an authentication failure, and 2281 * MGMT_EV_AUTH_FAILED would make bluetoothd drop the device. 2282 */ 2283 if (hcon->type != LE_LINK) { 2284 u8 reason = SMP_CMD_NOTSUPP; 2285 2286 smp_send_cmd(conn, SMP_CMD_PAIRING_FAIL, sizeof(reason), 2287 &reason); 2288 return 0; 2289 } 2290 2291 if (skb->len < sizeof(*rp)) 2292 return SMP_INVALID_PARAMS; 2293 2294 if (hcon->role != HCI_ROLE_MASTER) 2295 return SMP_CMD_NOTSUPP; 2296 2297 auth = rp->auth_req & AUTH_REQ_MASK(hdev); 2298 2299 if (hci_dev_test_flag(hdev, HCI_SC_ONLY) && !(auth & SMP_AUTH_SC)) 2300 return SMP_AUTH_REQUIREMENTS; 2301 2302 if (hcon->io_capability == HCI_IO_NO_INPUT_OUTPUT) 2303 sec_level = BT_SECURITY_MEDIUM; 2304 else 2305 sec_level = authreq_to_seclevel(auth); 2306 2307 if (smp_sufficient_security(hcon, sec_level, SMP_USE_LTK)) { 2308 /* If link is already encrypted with sufficient security we 2309 * still need refresh encryption as per Core Spec 5.0 Vol 3, 2310 * Part H 2.4.6 2311 */ 2312 smp_ltk_encrypt(conn, hcon->sec_level); 2313 return 0; 2314 } 2315 2316 if (sec_level > hcon->pending_sec_level) 2317 hcon->pending_sec_level = sec_level; 2318 2319 if (smp_ltk_encrypt(conn, hcon->pending_sec_level)) 2320 return 0; 2321 2322 smp = smp_chan_create(conn); 2323 if (!smp) 2324 return SMP_UNSPECIFIED; 2325 2326 if (!hci_dev_test_flag(hdev, HCI_BONDABLE) && 2327 (auth & SMP_AUTH_BONDING)) 2328 return SMP_PAIRING_NOTSUPP; 2329 2330 skb_pull(skb, sizeof(*rp)); 2331 2332 smp_send_pairing_req(smp, auth); 2333 2334 return 0; 2335 } 2336 2337 static void smp_send_security_req(struct smp_chan *smp, __u8 auth) 2338 { 2339 struct smp_cmd_security_req cp; 2340 2341 cp.auth_req = auth; 2342 smp_send_cmd(smp->conn, SMP_CMD_SECURITY_REQ, sizeof(cp), &cp); 2343 SMP_ALLOW_CMD(smp, SMP_CMD_PAIRING_REQ); 2344 2345 clear_bit(SMP_FLAG_INITIATOR, &smp->flags); 2346 } 2347 2348 int smp_conn_security(struct hci_conn *hcon, __u8 sec_level) 2349 { 2350 struct l2cap_conn *conn; 2351 struct l2cap_chan *chan; 2352 struct smp_chan *smp; 2353 __u8 authreq; 2354 int ret; 2355 2356 /* Caller shall ensure there can be no race with l2cap_conn_del() */ 2357 conn = context_unsafe(hcon->l2cap_data); 2358 2359 bt_dev_dbg(hcon->hdev, "conn %p hcon %p level 0x%2.2x", conn, hcon, 2360 sec_level); 2361 2362 /* This may be NULL if there's an unexpected disconnection */ 2363 if (!conn) 2364 return 1; 2365 2366 if (!hci_dev_test_flag(hcon->hdev, HCI_LE_ENABLED)) 2367 return 1; 2368 2369 if (smp_sufficient_security(hcon, sec_level, SMP_USE_LTK)) 2370 return 1; 2371 2372 if (sec_level > hcon->pending_sec_level) 2373 hcon->pending_sec_level = sec_level; 2374 2375 if (hcon->role == HCI_ROLE_MASTER) 2376 if (smp_ltk_encrypt(conn, hcon->pending_sec_level)) 2377 return 0; 2378 2379 chan = conn->smp; 2380 if (!chan) { 2381 bt_dev_err(hcon->hdev, "security requested but not available"); 2382 return 1; 2383 } 2384 2385 l2cap_chan_lock(chan); 2386 2387 /* If SMP is already in progress ignore this request */ 2388 if (chan->data) { 2389 ret = 0; 2390 goto unlock; 2391 } 2392 2393 smp = smp_chan_create(conn); 2394 if (!smp) { 2395 ret = 1; 2396 goto unlock; 2397 } 2398 2399 authreq = seclevel_to_authreq(sec_level); 2400 2401 if (hci_dev_test_flag(hcon->hdev, HCI_SC_ENABLED)) { 2402 authreq |= SMP_AUTH_SC; 2403 if (hci_dev_test_flag(hcon->hdev, HCI_SSP_ENABLED)) 2404 authreq |= SMP_AUTH_CT2; 2405 } 2406 2407 /* Don't attempt to set MITM if setting is overridden by debugfs 2408 * Needed to pass certification test SM/MAS/PKE/BV-01-C 2409 */ 2410 if (!hci_dev_test_flag(hcon->hdev, HCI_FORCE_NO_MITM)) { 2411 /* Require MITM if IO Capability allows or the security level 2412 * requires it. 2413 */ 2414 if (hcon->io_capability != HCI_IO_NO_INPUT_OUTPUT || 2415 hcon->pending_sec_level > BT_SECURITY_MEDIUM) 2416 authreq |= SMP_AUTH_MITM; 2417 } 2418 2419 if (hcon->role == HCI_ROLE_MASTER) 2420 smp_send_pairing_req(smp, authreq); 2421 else 2422 smp_send_security_req(smp, authreq); 2423 2424 ret = 0; 2425 2426 unlock: 2427 l2cap_chan_unlock(chan); 2428 return ret; 2429 } 2430 2431 int smp_cancel_and_remove_pairing(struct hci_dev *hdev, bdaddr_t *bdaddr, 2432 u8 addr_type) 2433 { 2434 struct hci_conn *hcon; 2435 struct l2cap_conn *conn; 2436 struct l2cap_chan *chan; 2437 struct smp_chan *smp; 2438 int err; 2439 2440 err = hci_remove_ltk(hdev, bdaddr, addr_type); 2441 hci_remove_irk(hdev, bdaddr, addr_type); 2442 2443 hcon = hci_conn_hash_lookup_le(hdev, bdaddr, addr_type); 2444 if (!hcon) 2445 goto done; 2446 2447 lockdep_assert_held(&hcon->hdev->lock); 2448 2449 conn = hcon->l2cap_data; 2450 if (!conn) 2451 goto done; 2452 2453 chan = conn->smp; 2454 if (!chan) 2455 goto done; 2456 2457 l2cap_chan_lock(chan); 2458 2459 smp = chan->data; 2460 if (smp) { 2461 /* Set keys to NULL to make sure smp_failure() does not try to 2462 * remove and free already invalidated rcu list entries. */ 2463 smp->ltk = NULL; 2464 smp->responder_ltk = NULL; 2465 smp->remote_irk = NULL; 2466 2467 if (test_bit(SMP_FLAG_COMPLETE, &smp->flags)) 2468 smp_failure(conn, 0); 2469 else 2470 smp_failure(conn, SMP_UNSPECIFIED); 2471 err = 0; 2472 } 2473 2474 l2cap_chan_unlock(chan); 2475 2476 done: 2477 return err; 2478 } 2479 2480 static int smp_cmd_encrypt_info(struct l2cap_conn *conn, struct sk_buff *skb) 2481 { 2482 struct smp_cmd_encrypt_info *rp = (void *) skb->data; 2483 struct l2cap_chan *chan = conn->smp; 2484 struct smp_chan *smp = chan->data; 2485 2486 bt_dev_dbg(conn->hcon->hdev, "conn %p", conn); 2487 2488 if (skb->len < sizeof(*rp)) 2489 return SMP_INVALID_PARAMS; 2490 2491 /* Pairing is aborted if any blocked keys are distributed */ 2492 if (hci_is_blocked_key(conn->hcon->hdev, HCI_BLOCKED_KEY_TYPE_LTK, 2493 rp->ltk)) { 2494 bt_dev_warn_ratelimited(conn->hcon->hdev, 2495 "LTK blocked for %pMR", 2496 &conn->hcon->dst); 2497 return SMP_INVALID_PARAMS; 2498 } 2499 2500 SMP_ALLOW_CMD(smp, SMP_CMD_INITIATOR_IDENT); 2501 2502 skb_pull(skb, sizeof(*rp)); 2503 2504 memcpy(smp->tk, rp->ltk, sizeof(smp->tk)); 2505 2506 return 0; 2507 } 2508 2509 static int smp_cmd_initiator_ident(struct l2cap_conn *conn, struct sk_buff *skb) 2510 { 2511 struct smp_cmd_initiator_ident *rp = (void *)skb->data; 2512 struct l2cap_chan *chan = conn->smp; 2513 struct smp_chan *smp = chan->data; 2514 struct hci_dev *hdev = conn->hcon->hdev; 2515 struct hci_conn *hcon = conn->hcon; 2516 struct smp_ltk *ltk; 2517 u8 authenticated; 2518 2519 bt_dev_dbg(hdev, "conn %p", conn); 2520 2521 if (skb->len < sizeof(*rp)) 2522 return SMP_INVALID_PARAMS; 2523 2524 /* Mark the information as received */ 2525 smp->remote_key_dist &= ~SMP_DIST_ENC_KEY; 2526 2527 if (smp->remote_key_dist & SMP_DIST_ID_KEY) 2528 SMP_ALLOW_CMD(smp, SMP_CMD_IDENT_INFO); 2529 else if (smp->remote_key_dist & SMP_DIST_SIGN) 2530 SMP_ALLOW_CMD(smp, SMP_CMD_SIGN_INFO); 2531 2532 skb_pull(skb, sizeof(*rp)); 2533 2534 authenticated = (hcon->sec_level == BT_SECURITY_HIGH); 2535 ltk = hci_add_ltk(hdev, &hcon->dst, hcon->dst_type, SMP_LTK, 2536 authenticated, smp->tk, smp->enc_key_size, 2537 rp->ediv, rp->rand); 2538 smp->ltk = ltk; 2539 if (!(smp->remote_key_dist & KEY_DIST_MASK)) 2540 smp_distribute_keys(smp); 2541 2542 return 0; 2543 } 2544 2545 static int smp_cmd_ident_info(struct l2cap_conn *conn, struct sk_buff *skb) 2546 { 2547 struct smp_cmd_ident_info *info = (void *) skb->data; 2548 struct l2cap_chan *chan = conn->smp; 2549 struct smp_chan *smp = chan->data; 2550 2551 bt_dev_dbg(conn->hcon->hdev, ""); 2552 2553 if (skb->len < sizeof(*info)) 2554 return SMP_INVALID_PARAMS; 2555 2556 /* Pairing is aborted if any blocked keys are distributed */ 2557 if (hci_is_blocked_key(conn->hcon->hdev, HCI_BLOCKED_KEY_TYPE_IRK, 2558 info->irk)) { 2559 bt_dev_warn_ratelimited(conn->hcon->hdev, 2560 "Identity key blocked for %pMR", 2561 &conn->hcon->dst); 2562 return SMP_INVALID_PARAMS; 2563 } 2564 2565 SMP_ALLOW_CMD(smp, SMP_CMD_IDENT_ADDR_INFO); 2566 2567 skb_pull(skb, sizeof(*info)); 2568 2569 memcpy(smp->irk, info->irk, 16); 2570 2571 return 0; 2572 } 2573 2574 static int smp_cmd_ident_addr_info(struct l2cap_conn *conn, 2575 struct sk_buff *skb) 2576 { 2577 struct smp_cmd_ident_addr_info *info = (void *) skb->data; 2578 struct l2cap_chan *chan = conn->smp; 2579 struct smp_chan *smp = chan->data; 2580 struct hci_conn *hcon = conn->hcon; 2581 bdaddr_t rpa; 2582 2583 bt_dev_dbg(hcon->hdev, ""); 2584 2585 if (skb->len < sizeof(*info)) 2586 return SMP_INVALID_PARAMS; 2587 2588 /* Mark the information as received */ 2589 smp->remote_key_dist &= ~SMP_DIST_ID_KEY; 2590 2591 if (smp->remote_key_dist & SMP_DIST_SIGN) 2592 SMP_ALLOW_CMD(smp, SMP_CMD_SIGN_INFO); 2593 2594 skb_pull(skb, sizeof(*info)); 2595 2596 /* Strictly speaking the Core Specification (4.1) allows sending 2597 * an empty address which would force us to rely on just the IRK 2598 * as "identity information". However, since such 2599 * implementations are not known of and in order to not over 2600 * complicate our implementation, simply pretend that we never 2601 * received an IRK for such a device. 2602 * 2603 * The Identity Address must also be a Static Random or Public 2604 * Address, which hci_is_identity_address() checks for. 2605 */ 2606 if (!bacmp(&info->bdaddr, BDADDR_ANY) || 2607 !hci_is_identity_address(&info->bdaddr, info->addr_type)) { 2608 bt_dev_err(hcon->hdev, "ignoring IRK with no identity address"); 2609 goto distribute; 2610 } 2611 2612 /* Drop IRK if peer is using identity address during pairing but is 2613 * providing different address as identity information. 2614 * 2615 * Microsoft Surface Precision Mouse is known to have this bug. 2616 */ 2617 if (hci_is_identity_address(&hcon->dst, hcon->dst_type) && 2618 (bacmp(&info->bdaddr, &hcon->dst) || 2619 info->addr_type != hcon->dst_type)) { 2620 bt_dev_err(hcon->hdev, 2621 "ignoring IRK with invalid identity address"); 2622 goto distribute; 2623 } 2624 2625 bacpy(&smp->id_addr, &info->bdaddr); 2626 smp->id_addr_type = info->addr_type; 2627 2628 if (hci_bdaddr_is_rpa(&hcon->dst, hcon->dst_type)) 2629 bacpy(&rpa, &hcon->dst); 2630 else 2631 bacpy(&rpa, BDADDR_ANY); 2632 2633 smp->remote_irk = hci_add_irk(conn->hcon->hdev, &smp->id_addr, 2634 smp->id_addr_type, smp->irk, &rpa); 2635 2636 distribute: 2637 if (!(smp->remote_key_dist & KEY_DIST_MASK)) 2638 smp_distribute_keys(smp); 2639 2640 return 0; 2641 } 2642 2643 static int smp_cmd_sign_info(struct l2cap_conn *conn, struct sk_buff *skb) 2644 { 2645 struct smp_cmd_sign_info *rp = (void *) skb->data; 2646 struct l2cap_chan *chan = conn->smp; 2647 struct smp_chan *smp = chan->data; 2648 struct smp_csrk *csrk; 2649 2650 bt_dev_dbg(conn->hcon->hdev, "conn %p", conn); 2651 2652 if (skb->len < sizeof(*rp)) 2653 return SMP_INVALID_PARAMS; 2654 2655 /* Mark the information as received */ 2656 smp->remote_key_dist &= ~SMP_DIST_SIGN; 2657 2658 skb_pull(skb, sizeof(*rp)); 2659 2660 csrk = kzalloc_obj(*csrk); 2661 if (csrk) { 2662 if (conn->hcon->sec_level > BT_SECURITY_MEDIUM) 2663 csrk->type = MGMT_CSRK_REMOTE_AUTHENTICATED; 2664 else 2665 csrk->type = MGMT_CSRK_REMOTE_UNAUTHENTICATED; 2666 memcpy(csrk->val, rp->csrk, sizeof(csrk->val)); 2667 } 2668 smp->csrk = csrk; 2669 smp_distribute_keys(smp); 2670 2671 return 0; 2672 } 2673 2674 static u8 sc_select_method(struct smp_chan *smp) 2675 { 2676 struct smp_cmd_pairing *local, *remote; 2677 u8 local_mitm, remote_mitm, local_io, remote_io, method; 2678 2679 if (test_bit(SMP_FLAG_REMOTE_OOB, &smp->flags) || 2680 test_bit(SMP_FLAG_LOCAL_OOB, &smp->flags)) 2681 return REQ_OOB; 2682 2683 /* The preq/prsp contain the raw Pairing Request/Response PDUs 2684 * which are needed as inputs to some crypto functions. To get 2685 * the "struct smp_cmd_pairing" from them we need to skip the 2686 * first byte which contains the opcode. 2687 */ 2688 if (test_bit(SMP_FLAG_INITIATOR, &smp->flags)) { 2689 local = (void *) &smp->preq[1]; 2690 remote = (void *) &smp->prsp[1]; 2691 } else { 2692 local = (void *) &smp->prsp[1]; 2693 remote = (void *) &smp->preq[1]; 2694 } 2695 2696 local_io = local->io_capability; 2697 remote_io = remote->io_capability; 2698 2699 local_mitm = (local->auth_req & SMP_AUTH_MITM); 2700 remote_mitm = (remote->auth_req & SMP_AUTH_MITM); 2701 2702 /* If either side wants MITM, look up the method from the table, 2703 * otherwise use JUST WORKS. 2704 */ 2705 if (local_mitm || remote_mitm) 2706 method = get_auth_method(smp, local_io, remote_io); 2707 else 2708 method = JUST_WORKS; 2709 2710 /* Don't confirm locally initiated pairing attempts */ 2711 if (method == JUST_CFM && test_bit(SMP_FLAG_INITIATOR, &smp->flags)) 2712 method = JUST_WORKS; 2713 2714 return method; 2715 } 2716 2717 static int smp_cmd_public_key(struct l2cap_conn *conn, struct sk_buff *skb) 2718 { 2719 struct smp_cmd_public_key *key = (void *) skb->data; 2720 struct hci_conn *hcon = conn->hcon; 2721 struct l2cap_chan *chan = conn->smp; 2722 struct smp_chan *smp = chan->data; 2723 struct hci_dev *hdev = hcon->hdev; 2724 struct crypto_kpp *tfm_ecdh; 2725 struct smp_cmd_pairing_confirm cfm; 2726 int err; 2727 2728 bt_dev_dbg(hdev, "conn %p", conn); 2729 2730 if (skb->len < sizeof(*key)) 2731 return SMP_INVALID_PARAMS; 2732 2733 /* Check if remote and local public keys are the same and debug key is 2734 * not in use. 2735 */ 2736 if (!test_bit(SMP_FLAG_DEBUG_KEY, &smp->flags) && 2737 !crypto_memneq(key, smp->local_pk, 64)) { 2738 bt_dev_err(hdev, "Remote and local public keys are identical"); 2739 return SMP_DHKEY_CHECK_FAILED; 2740 } 2741 2742 memcpy(smp->remote_pk, key, 64); 2743 2744 if (test_bit(SMP_FLAG_REMOTE_OOB, &smp->flags)) { 2745 err = smp_f4(smp->remote_pk, smp->remote_pk, smp->rr, 0, 2746 cfm.confirm_val); 2747 if (err) 2748 return SMP_UNSPECIFIED; 2749 2750 if (crypto_memneq(cfm.confirm_val, smp->pcnf, 16)) 2751 return SMP_CONFIRM_FAILED; 2752 } 2753 2754 /* Non-initiating device sends its public key after receiving 2755 * the key from the initiating device. 2756 */ 2757 if (!test_bit(SMP_FLAG_INITIATOR, &smp->flags)) { 2758 err = sc_send_public_key(smp); 2759 if (err) 2760 return err; 2761 } 2762 2763 SMP_DBG("Remote Public Key X: %32phN", smp->remote_pk); 2764 SMP_DBG("Remote Public Key Y: %32phN", smp->remote_pk + 32); 2765 2766 /* Compute the shared secret on the same crypto tfm on which the private 2767 * key was set/generated. 2768 */ 2769 if (test_bit(SMP_FLAG_LOCAL_OOB, &smp->flags)) { 2770 struct l2cap_chan *hchan = hdev->smp_data; 2771 struct smp_dev *smp_dev; 2772 2773 if (!hchan || !hchan->data) 2774 return SMP_UNSPECIFIED; 2775 2776 smp_dev = hchan->data; 2777 2778 tfm_ecdh = smp_dev->tfm_ecdh; 2779 } else { 2780 tfm_ecdh = smp->tfm_ecdh; 2781 } 2782 2783 if (compute_ecdh_secret(tfm_ecdh, smp->remote_pk, smp->dhkey)) 2784 return SMP_UNSPECIFIED; 2785 2786 SMP_DBG("DHKey %32phN", smp->dhkey); 2787 2788 set_bit(SMP_FLAG_REMOTE_PK, &smp->flags); 2789 2790 smp->method = sc_select_method(smp); 2791 2792 bt_dev_dbg(hdev, "selected method 0x%02x", smp->method); 2793 2794 /* JUST_WORKS and JUST_CFM result in an unauthenticated key */ 2795 if (smp->method == JUST_WORKS || smp->method == JUST_CFM) 2796 hcon->pending_sec_level = BT_SECURITY_MEDIUM; 2797 else 2798 hcon->pending_sec_level = BT_SECURITY_FIPS; 2799 2800 if (!crypto_memneq(debug_pk, smp->remote_pk, 64)) 2801 set_bit(SMP_FLAG_DEBUG_KEY, &smp->flags); 2802 2803 if (smp->method == DSP_PASSKEY) { 2804 get_random_bytes(&hcon->passkey_notify, 2805 sizeof(hcon->passkey_notify)); 2806 hcon->passkey_notify %= 1000000; 2807 hcon->passkey_entered = 0; 2808 smp->passkey_round = 0; 2809 if (mgmt_user_passkey_notify(hdev, &hcon->dst, hcon->type, 2810 hcon->dst_type, 2811 hcon->passkey_notify, 2812 hcon->passkey_entered)) 2813 return SMP_UNSPECIFIED; 2814 SMP_ALLOW_CMD(smp, SMP_CMD_PAIRING_CONFIRM); 2815 return sc_passkey_round(smp, SMP_CMD_PUBLIC_KEY); 2816 } 2817 2818 if (smp->method == REQ_OOB) { 2819 if (test_bit(SMP_FLAG_INITIATOR, &smp->flags)) 2820 smp_send_cmd(conn, SMP_CMD_PAIRING_RANDOM, 2821 sizeof(smp->prnd), smp->prnd); 2822 2823 SMP_ALLOW_CMD(smp, SMP_CMD_PAIRING_RANDOM); 2824 2825 return 0; 2826 } 2827 2828 if (test_bit(SMP_FLAG_INITIATOR, &smp->flags)) 2829 SMP_ALLOW_CMD(smp, SMP_CMD_PAIRING_CONFIRM); 2830 2831 if (smp->method == REQ_PASSKEY) { 2832 if (mgmt_user_passkey_request(hdev, &hcon->dst, hcon->type, 2833 hcon->dst_type)) 2834 return SMP_UNSPECIFIED; 2835 SMP_ALLOW_CMD(smp, SMP_CMD_PAIRING_CONFIRM); 2836 set_bit(SMP_FLAG_WAIT_USER, &smp->flags); 2837 return 0; 2838 } 2839 2840 /* The Initiating device waits for the non-initiating device to 2841 * send the confirm value. 2842 */ 2843 if (test_bit(SMP_FLAG_INITIATOR, &smp->flags)) 2844 return 0; 2845 2846 err = smp_f4(smp->local_pk, smp->remote_pk, smp->prnd, 0, 2847 cfm.confirm_val); 2848 if (err) 2849 return SMP_UNSPECIFIED; 2850 2851 smp_send_cmd(conn, SMP_CMD_PAIRING_CONFIRM, sizeof(cfm), &cfm); 2852 SMP_ALLOW_CMD(smp, SMP_CMD_PAIRING_RANDOM); 2853 2854 return 0; 2855 } 2856 2857 static int smp_cmd_dhkey_check(struct l2cap_conn *conn, struct sk_buff *skb) 2858 { 2859 struct smp_cmd_dhkey_check *check = (void *) skb->data; 2860 struct l2cap_chan *chan = conn->smp; 2861 struct hci_conn *hcon = conn->hcon; 2862 struct smp_chan *smp = chan->data; 2863 u8 a[7], b[7], *local_addr, *remote_addr; 2864 u8 io_cap[3], r[16], e[16]; 2865 int err; 2866 2867 bt_dev_dbg(hcon->hdev, "conn %p", conn); 2868 2869 if (skb->len < sizeof(*check)) 2870 return SMP_INVALID_PARAMS; 2871 2872 memcpy(a, &hcon->init_addr, 6); 2873 memcpy(b, &hcon->resp_addr, 6); 2874 a[6] = hcon->init_addr_type; 2875 b[6] = hcon->resp_addr_type; 2876 2877 if (test_bit(SMP_FLAG_INITIATOR, &smp->flags)) { 2878 local_addr = a; 2879 remote_addr = b; 2880 memcpy(io_cap, &smp->prsp[1], 3); 2881 } else { 2882 local_addr = b; 2883 remote_addr = a; 2884 memcpy(io_cap, &smp->preq[1], 3); 2885 } 2886 2887 memset(r, 0, sizeof(r)); 2888 2889 if (smp->method == REQ_PASSKEY || smp->method == DSP_PASSKEY) 2890 put_unaligned_le32(hcon->passkey_notify, r); 2891 else if (smp->method == REQ_OOB) 2892 memcpy(r, smp->lr, 16); 2893 2894 err = smp_f6(smp->mackey, smp->rrnd, smp->prnd, r, io_cap, remote_addr, 2895 local_addr, e); 2896 if (err) 2897 return SMP_UNSPECIFIED; 2898 2899 if (crypto_memneq(check->e, e, 16)) 2900 return SMP_DHKEY_CHECK_FAILED; 2901 2902 if (!test_bit(SMP_FLAG_INITIATOR, &smp->flags)) { 2903 if (test_bit(SMP_FLAG_WAIT_USER, &smp->flags)) { 2904 set_bit(SMP_FLAG_DHKEY_PENDING, &smp->flags); 2905 return 0; 2906 } 2907 2908 /* Responder sends DHKey check as response to initiator */ 2909 sc_dhkey_check(smp); 2910 } 2911 2912 sc_add_ltk(smp); 2913 2914 if (test_bit(SMP_FLAG_INITIATOR, &smp->flags)) { 2915 hci_le_start_enc(hcon, 0, 0, smp->tk, smp->enc_key_size); 2916 hcon->enc_key_size = smp->enc_key_size; 2917 } 2918 2919 return 0; 2920 } 2921 2922 static int smp_cmd_keypress_notify(struct l2cap_conn *conn, 2923 struct sk_buff *skb) 2924 { 2925 struct smp_cmd_keypress_notify *kp = (void *) skb->data; 2926 2927 bt_dev_dbg(conn->hcon->hdev, "value 0x%02x", kp->value); 2928 2929 return 0; 2930 } 2931 2932 static int smp_sig_channel(struct l2cap_chan *chan, struct sk_buff *skb) 2933 { 2934 struct l2cap_conn *conn = chan->conn; 2935 struct hci_conn *hcon = conn->hcon; 2936 struct smp_chan *smp; 2937 __u8 code, reason; 2938 int err = 0; 2939 2940 if (skb->len < 1) 2941 return -EILSEQ; 2942 2943 if (!hci_dev_test_flag(hcon->hdev, HCI_LE_ENABLED)) { 2944 reason = SMP_PAIRING_NOTSUPP; 2945 goto done; 2946 } 2947 2948 code = skb->data[0]; 2949 skb_pull(skb, sizeof(code)); 2950 2951 smp = chan->data; 2952 2953 if (code > SMP_CMD_MAX) 2954 goto drop; 2955 2956 if (smp && !test_and_clear_bit(code, &smp->allow_cmd)) { 2957 /* If there is a context and the command is not allowed consider 2958 * it a failure so the session is cleanup properly. 2959 */ 2960 switch (code) { 2961 case SMP_CMD_IDENT_INFO: 2962 case SMP_CMD_IDENT_ADDR_INFO: 2963 case SMP_CMD_SIGN_INFO: 2964 /* 3.6.1. Key distribution and generation 2965 * 2966 * A device may reject a distributed key by sending the 2967 * Pairing Failed command with the reason set to 2968 * "Key Rejected". 2969 */ 2970 smp_failure(conn, SMP_KEY_REJECTED); 2971 break; 2972 } 2973 goto drop; 2974 } 2975 2976 /* If we don't have a context the only allowed commands are 2977 * pairing request and security request. 2978 */ 2979 if (!smp && code != SMP_CMD_PAIRING_REQ && code != SMP_CMD_SECURITY_REQ) 2980 goto drop; 2981 2982 switch (code) { 2983 case SMP_CMD_PAIRING_REQ: 2984 reason = smp_cmd_pairing_req(conn, skb); 2985 break; 2986 2987 case SMP_CMD_PAIRING_FAIL: 2988 smp_failure(conn, 0); 2989 err = -EPERM; 2990 break; 2991 2992 case SMP_CMD_PAIRING_RSP: 2993 reason = smp_cmd_pairing_rsp(conn, skb); 2994 break; 2995 2996 case SMP_CMD_SECURITY_REQ: 2997 reason = smp_cmd_security_req(conn, skb); 2998 break; 2999 3000 case SMP_CMD_PAIRING_CONFIRM: 3001 reason = smp_cmd_pairing_confirm(conn, skb); 3002 break; 3003 3004 case SMP_CMD_PAIRING_RANDOM: 3005 reason = smp_cmd_pairing_random(conn, skb); 3006 break; 3007 3008 case SMP_CMD_ENCRYPT_INFO: 3009 reason = smp_cmd_encrypt_info(conn, skb); 3010 break; 3011 3012 case SMP_CMD_INITIATOR_IDENT: 3013 reason = smp_cmd_initiator_ident(conn, skb); 3014 break; 3015 3016 case SMP_CMD_IDENT_INFO: 3017 reason = smp_cmd_ident_info(conn, skb); 3018 break; 3019 3020 case SMP_CMD_IDENT_ADDR_INFO: 3021 reason = smp_cmd_ident_addr_info(conn, skb); 3022 break; 3023 3024 case SMP_CMD_SIGN_INFO: 3025 reason = smp_cmd_sign_info(conn, skb); 3026 break; 3027 3028 case SMP_CMD_PUBLIC_KEY: 3029 reason = smp_cmd_public_key(conn, skb); 3030 break; 3031 3032 case SMP_CMD_DHKEY_CHECK: 3033 reason = smp_cmd_dhkey_check(conn, skb); 3034 break; 3035 3036 case SMP_CMD_KEYPRESS_NOTIFY: 3037 reason = smp_cmd_keypress_notify(conn, skb); 3038 break; 3039 3040 default: 3041 bt_dev_dbg(hcon->hdev, "Unknown command code 0x%2.2x", code); 3042 reason = SMP_CMD_NOTSUPP; 3043 goto done; 3044 } 3045 3046 done: 3047 if (!err) { 3048 if (reason) 3049 smp_failure(conn, reason); 3050 kfree_skb(skb); 3051 } 3052 3053 return err; 3054 3055 drop: 3056 bt_dev_err(hcon->hdev, "unexpected SMP command 0x%02x from %pMR", 3057 code, &hcon->dst); 3058 kfree_skb(skb); 3059 return 0; 3060 } 3061 3062 static void smp_teardown_cb(struct l2cap_chan *chan, int err) 3063 { 3064 struct l2cap_conn *conn = chan->conn; 3065 3066 bt_dev_dbg(conn->hcon->hdev, "chan %p", chan); 3067 3068 if (chan->data) 3069 smp_chan_destroy(conn); 3070 3071 conn->smp = NULL; 3072 l2cap_chan_put(chan); 3073 } 3074 3075 static void bredr_pairing(struct l2cap_chan *chan) 3076 { 3077 struct l2cap_conn *conn = chan->conn; 3078 struct hci_conn *hcon = conn->hcon; 3079 struct hci_dev *hdev = hcon->hdev; 3080 struct smp_chan *smp; 3081 3082 bt_dev_dbg(hdev, "chan %p", chan); 3083 3084 /* Only new pairings are interesting */ 3085 if (!test_bit(HCI_CONN_NEW_LINK_KEY, &hcon->flags)) 3086 return; 3087 3088 /* Don't bother if we're not encrypted */ 3089 if (!test_bit(HCI_CONN_ENCRYPT, &hcon->flags)) 3090 return; 3091 3092 /* Only initiator may initiate SMP over BR/EDR */ 3093 if (hcon->role != HCI_ROLE_MASTER) 3094 return; 3095 3096 /* Secure Connections support must be enabled */ 3097 if (!hci_dev_test_flag(hdev, HCI_SC_ENABLED)) 3098 return; 3099 3100 /* BR/EDR must use Secure Connections for SMP */ 3101 if (!test_bit(HCI_CONN_AES_CCM, &hcon->flags) && 3102 !hci_dev_test_flag(hdev, HCI_FORCE_BREDR_SMP)) 3103 return; 3104 3105 /* If our LE support is not enabled don't do anything */ 3106 if (!hci_dev_test_flag(hdev, HCI_LE_ENABLED)) 3107 return; 3108 3109 /* Don't bother if remote LE support is not enabled */ 3110 if (!lmp_host_le_capable(hcon)) 3111 return; 3112 3113 /* Remote must support SMP fixed chan for BR/EDR */ 3114 if (!(conn->remote_fixed_chan & L2CAP_FC_SMP_BREDR)) 3115 return; 3116 3117 /* Don't bother if SMP is already ongoing */ 3118 if (chan->data) 3119 return; 3120 3121 smp = smp_chan_create(conn); 3122 if (!smp) { 3123 bt_dev_err(hdev, "unable to create SMP context for BR/EDR"); 3124 return; 3125 } 3126 3127 set_bit(SMP_FLAG_SC, &smp->flags); 3128 3129 bt_dev_dbg(hdev, "starting SMP over BR/EDR"); 3130 3131 smp_send_pairing_req(smp, 0x00); 3132 } 3133 3134 static void smp_resume_cb(struct l2cap_chan *chan) 3135 { 3136 struct smp_chan *smp = chan->data; 3137 struct l2cap_conn *conn = chan->conn; 3138 struct hci_conn *hcon = conn->hcon; 3139 3140 bt_dev_dbg(hcon->hdev, "chan %p", chan); 3141 3142 if (hcon->type == ACL_LINK) { 3143 bredr_pairing(chan); 3144 return; 3145 } 3146 3147 if (!smp) 3148 return; 3149 3150 if (!test_bit(HCI_CONN_ENCRYPT, &hcon->flags)) 3151 return; 3152 3153 cancel_delayed_work(&smp->security_timer); 3154 3155 smp_distribute_keys(smp); 3156 } 3157 3158 static void smp_ready_cb(struct l2cap_chan *chan) 3159 { 3160 struct l2cap_conn *conn = chan->conn; 3161 struct hci_conn *hcon = conn->hcon; 3162 3163 bt_dev_dbg(hcon->hdev, "chan %p", chan); 3164 3165 /* No need to call l2cap_chan_hold() here since we already own 3166 * the reference taken in smp_new_conn_cb(). This is just the 3167 * first time that we tie it to a specific pointer. The code in 3168 * l2cap_core.c ensures that there's no risk this function won't 3169 * get called if smp_new_conn_cb was previously called. 3170 */ 3171 conn->smp = chan; 3172 3173 if (hcon->type == ACL_LINK && test_bit(HCI_CONN_ENCRYPT, &hcon->flags)) 3174 bredr_pairing(chan); 3175 } 3176 3177 static int smp_recv_cb(struct l2cap_chan *chan, struct sk_buff *skb) 3178 { 3179 int err; 3180 3181 bt_dev_dbg(chan->conn->hcon->hdev, "chan %p", chan); 3182 3183 err = smp_sig_channel(chan, skb); 3184 if (err) { 3185 struct smp_chan *smp = chan->data; 3186 3187 if (smp) 3188 cancel_delayed_work_sync(&smp->security_timer); 3189 3190 hci_disconnect(chan->conn->hcon, HCI_ERROR_AUTH_FAILURE); 3191 } 3192 3193 return err; 3194 } 3195 3196 static struct sk_buff *smp_alloc_skb_cb(struct l2cap_chan *chan, 3197 unsigned long hdr_len, 3198 unsigned long len, int nb) 3199 { 3200 struct sk_buff *skb; 3201 3202 skb = bt_skb_alloc(hdr_len + len, GFP_KERNEL); 3203 if (!skb) 3204 return ERR_PTR(-ENOMEM); 3205 3206 skb->priority = HCI_PRIO_MAX; 3207 bt_cb(skb)->l2cap.chan = chan; 3208 3209 return skb; 3210 } 3211 3212 static const struct l2cap_ops smp_chan_ops = { 3213 .name = "Security Manager", 3214 .ready = smp_ready_cb, 3215 .recv = smp_recv_cb, 3216 .alloc_skb = smp_alloc_skb_cb, 3217 .teardown = smp_teardown_cb, 3218 .resume = smp_resume_cb, 3219 3220 .new_connection = l2cap_chan_no_new_connection, 3221 .state_change = l2cap_chan_no_state_change, 3222 .close = l2cap_chan_no_close, 3223 .defer = l2cap_chan_no_defer, 3224 .suspend = l2cap_chan_no_suspend, 3225 .set_shutdown = l2cap_chan_no_set_shutdown, 3226 .get_sndtimeo = l2cap_chan_no_get_sndtimeo, 3227 }; 3228 3229 static inline int smp_new_conn_cb(struct l2cap_chan *chan, 3230 struct l2cap_chan *new_chan) 3231 { 3232 new_chan->ops = &smp_chan_ops; 3233 3234 /* Other L2CAP channels may request SMP routines in order to 3235 * change the security level. This means that the SMP channel 3236 * lock must be considered in its own category to avoid lockdep 3237 * warnings. 3238 */ 3239 atomic_set(&new_chan->nesting, L2CAP_NESTING_SMP); 3240 3241 return 0; 3242 } 3243 3244 static const struct l2cap_ops smp_root_chan_ops = { 3245 .name = "Security Manager Root", 3246 .new_connection = smp_new_conn_cb, 3247 3248 /* None of these are implemented for the root channel */ 3249 .close = l2cap_chan_no_close, 3250 .alloc_skb = l2cap_chan_no_alloc_skb, 3251 .recv = l2cap_chan_no_recv, 3252 .state_change = l2cap_chan_no_state_change, 3253 .teardown = l2cap_chan_no_teardown, 3254 .ready = l2cap_chan_no_ready, 3255 .defer = l2cap_chan_no_defer, 3256 .suspend = l2cap_chan_no_suspend, 3257 .resume = l2cap_chan_no_resume, 3258 .set_shutdown = l2cap_chan_no_set_shutdown, 3259 .get_sndtimeo = l2cap_chan_no_get_sndtimeo, 3260 }; 3261 3262 static struct l2cap_chan *smp_add_cid(struct hci_dev *hdev, u16 cid) 3263 { 3264 struct l2cap_chan *chan; 3265 struct smp_dev *smp; 3266 struct crypto_kpp *tfm_ecdh; 3267 3268 if (cid == L2CAP_CID_SMP_BREDR) { 3269 smp = NULL; 3270 goto create_chan; 3271 } 3272 3273 smp = kzalloc_obj(*smp); 3274 if (!smp) 3275 return ERR_PTR(-ENOMEM); 3276 3277 tfm_ecdh = crypto_alloc_kpp("ecdh-nist-p256", 0, 0); 3278 if (IS_ERR(tfm_ecdh)) { 3279 bt_dev_err(hdev, "Unable to create ECDH crypto context"); 3280 kfree_sensitive(smp); 3281 return ERR_CAST(tfm_ecdh); 3282 } 3283 3284 smp->local_oob = false; 3285 smp->tfm_ecdh = tfm_ecdh; 3286 3287 create_chan: 3288 chan = l2cap_chan_create(); 3289 if (!chan) { 3290 if (smp) { 3291 crypto_free_kpp(smp->tfm_ecdh); 3292 kfree_sensitive(smp); 3293 } 3294 return ERR_PTR(-ENOMEM); 3295 } 3296 3297 chan->data = smp; 3298 3299 l2cap_add_scid(chan, cid); 3300 3301 l2cap_chan_set_defaults(chan, NULL); 3302 3303 if (cid == L2CAP_CID_SMP) { 3304 u8 bdaddr_type; 3305 3306 hci_copy_identity_address(hdev, &chan->src, &bdaddr_type); 3307 3308 if (bdaddr_type == ADDR_LE_DEV_PUBLIC) 3309 chan->src_type = BDADDR_LE_PUBLIC; 3310 else 3311 chan->src_type = BDADDR_LE_RANDOM; 3312 } else { 3313 bacpy(&chan->src, &hdev->bdaddr); 3314 chan->src_type = BDADDR_BREDR; 3315 } 3316 3317 chan->state = BT_LISTEN; 3318 chan->mode = L2CAP_MODE_BASIC; 3319 chan->imtu = L2CAP_DEFAULT_MTU; 3320 chan->ops = &smp_root_chan_ops; 3321 3322 /* Set correct nesting level for a parent/listening channel */ 3323 atomic_set(&chan->nesting, L2CAP_NESTING_PARENT); 3324 3325 return chan; 3326 } 3327 3328 static void smp_del_chan(struct l2cap_chan *chan) 3329 { 3330 struct smp_dev *smp; 3331 3332 BT_DBG("chan %p", chan); 3333 3334 smp = chan->data; 3335 if (smp) { 3336 chan->data = NULL; 3337 crypto_free_kpp(smp->tfm_ecdh); 3338 kfree_sensitive(smp); 3339 } 3340 3341 l2cap_chan_put(chan); 3342 } 3343 3344 int smp_force_bredr(struct hci_dev *hdev, bool enable) 3345 { 3346 if (enable == hci_dev_test_flag(hdev, HCI_FORCE_BREDR_SMP)) 3347 return -EALREADY; 3348 3349 if (enable) { 3350 struct l2cap_chan *chan; 3351 3352 chan = smp_add_cid(hdev, L2CAP_CID_SMP_BREDR); 3353 if (IS_ERR(chan)) 3354 return PTR_ERR(chan); 3355 3356 hdev->smp_bredr_data = chan; 3357 } else { 3358 struct l2cap_chan *chan; 3359 3360 chan = hdev->smp_bredr_data; 3361 hdev->smp_bredr_data = NULL; 3362 smp_del_chan(chan); 3363 } 3364 3365 hci_dev_change_flag(hdev, HCI_FORCE_BREDR_SMP); 3366 3367 return 0; 3368 } 3369 3370 int smp_register(struct hci_dev *hdev) 3371 { 3372 struct l2cap_chan *chan; 3373 3374 bt_dev_dbg(hdev, ""); 3375 3376 /* If the controller does not support Low Energy operation, then 3377 * there is also no need to register any SMP channel. 3378 */ 3379 if (!lmp_le_capable(hdev)) 3380 return 0; 3381 3382 if (WARN_ON(hdev->smp_data)) { 3383 chan = hdev->smp_data; 3384 hdev->smp_data = NULL; 3385 smp_del_chan(chan); 3386 } 3387 3388 chan = smp_add_cid(hdev, L2CAP_CID_SMP); 3389 if (IS_ERR(chan)) 3390 return PTR_ERR(chan); 3391 3392 hdev->smp_data = chan; 3393 3394 if (!lmp_sc_capable(hdev)) { 3395 /* Flag can be already set here (due to power toggle) */ 3396 if (!hci_dev_test_flag(hdev, HCI_FORCE_BREDR_SMP)) 3397 return 0; 3398 } 3399 3400 if (WARN_ON(hdev->smp_bredr_data)) { 3401 chan = hdev->smp_bredr_data; 3402 hdev->smp_bredr_data = NULL; 3403 smp_del_chan(chan); 3404 } 3405 3406 chan = smp_add_cid(hdev, L2CAP_CID_SMP_BREDR); 3407 if (IS_ERR(chan)) { 3408 int err = PTR_ERR(chan); 3409 chan = hdev->smp_data; 3410 hdev->smp_data = NULL; 3411 smp_del_chan(chan); 3412 return err; 3413 } 3414 3415 hdev->smp_bredr_data = chan; 3416 3417 return 0; 3418 } 3419 3420 void smp_unregister(struct hci_dev *hdev) 3421 { 3422 struct l2cap_chan *chan; 3423 3424 if (hdev->smp_bredr_data) { 3425 chan = hdev->smp_bredr_data; 3426 hdev->smp_bredr_data = NULL; 3427 smp_del_chan(chan); 3428 } 3429 3430 if (hdev->smp_data) { 3431 chan = hdev->smp_data; 3432 hdev->smp_data = NULL; 3433 smp_del_chan(chan); 3434 } 3435 } 3436 3437 #if IS_ENABLED(CONFIG_BT_SELFTEST_SMP) 3438 3439 static int __init test_debug_key(struct crypto_kpp *tfm_ecdh) 3440 { 3441 u8 pk[64]; 3442 int err; 3443 3444 err = set_ecdh_privkey(tfm_ecdh, debug_sk); 3445 if (err) 3446 return err; 3447 3448 err = generate_ecdh_public_key(tfm_ecdh, pk); 3449 if (err) 3450 return err; 3451 3452 if (crypto_memneq(pk, debug_pk, 64)) 3453 return -EINVAL; 3454 3455 return 0; 3456 } 3457 3458 static int __init test_ah(void) 3459 { 3460 const u8 irk[16] = { 3461 0x9b, 0x7d, 0x39, 0x0a, 0xa6, 0x10, 0x10, 0x34, 3462 0x05, 0xad, 0xc8, 0x57, 0xa3, 0x34, 0x02, 0xec }; 3463 const u8 r[3] = { 0x94, 0x81, 0x70 }; 3464 const u8 exp[3] = { 0xaa, 0xfb, 0x0d }; 3465 u8 res[3]; 3466 int err; 3467 3468 err = smp_ah(irk, r, res); 3469 if (err) 3470 return err; 3471 3472 if (crypto_memneq(res, exp, 3)) 3473 return -EINVAL; 3474 3475 return 0; 3476 } 3477 3478 static int __init test_c1(void) 3479 { 3480 const u8 k[16] = { 3481 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 3482 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00 }; 3483 const u8 r[16] = { 3484 0xe0, 0x2e, 0x70, 0xc6, 0x4e, 0x27, 0x88, 0x63, 3485 0x0e, 0x6f, 0xad, 0x56, 0x21, 0xd5, 0x83, 0x57 }; 3486 const u8 preq[7] = { 0x01, 0x01, 0x00, 0x00, 0x10, 0x07, 0x07 }; 3487 const u8 pres[7] = { 0x02, 0x03, 0x00, 0x00, 0x08, 0x00, 0x05 }; 3488 const u8 _iat = 0x01; 3489 const u8 _rat = 0x00; 3490 const bdaddr_t ra = { { 0xb6, 0xb5, 0xb4, 0xb3, 0xb2, 0xb1 } }; 3491 const bdaddr_t ia = { { 0xa6, 0xa5, 0xa4, 0xa3, 0xa2, 0xa1 } }; 3492 const u8 exp[16] = { 3493 0x86, 0x3b, 0xf1, 0xbe, 0xc5, 0x4d, 0xa7, 0xd2, 3494 0xea, 0x88, 0x89, 0x87, 0xef, 0x3f, 0x1e, 0x1e }; 3495 u8 res[16]; 3496 int err; 3497 3498 err = smp_c1(k, r, preq, pres, _iat, &ia, _rat, &ra, res); 3499 if (err) 3500 return err; 3501 3502 if (crypto_memneq(res, exp, 16)) 3503 return -EINVAL; 3504 3505 return 0; 3506 } 3507 3508 static int __init test_s1(void) 3509 { 3510 const u8 k[16] = { 3511 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 3512 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00 }; 3513 const u8 r1[16] = { 3514 0x88, 0x77, 0x66, 0x55, 0x44, 0x33, 0x22, 0x11 }; 3515 const u8 r2[16] = { 3516 0x00, 0xff, 0xee, 0xdd, 0xcc, 0xbb, 0xaa, 0x99 }; 3517 const u8 exp[16] = { 3518 0x62, 0xa0, 0x6d, 0x79, 0xae, 0x16, 0x42, 0x5b, 3519 0x9b, 0xf4, 0xb0, 0xe8, 0xf0, 0xe1, 0x1f, 0x9a }; 3520 u8 res[16]; 3521 int err; 3522 3523 err = smp_s1(k, r1, r2, res); 3524 if (err) 3525 return err; 3526 3527 if (crypto_memneq(res, exp, 16)) 3528 return -EINVAL; 3529 3530 return 0; 3531 } 3532 3533 static int __init test_f4(void) 3534 { 3535 const u8 u[32] = { 3536 0xe6, 0x9d, 0x35, 0x0e, 0x48, 0x01, 0x03, 0xcc, 3537 0xdb, 0xfd, 0xf4, 0xac, 0x11, 0x91, 0xf4, 0xef, 3538 0xb9, 0xa5, 0xf9, 0xe9, 0xa7, 0x83, 0x2c, 0x5e, 3539 0x2c, 0xbe, 0x97, 0xf2, 0xd2, 0x03, 0xb0, 0x20 }; 3540 const u8 v[32] = { 3541 0xfd, 0xc5, 0x7f, 0xf4, 0x49, 0xdd, 0x4f, 0x6b, 3542 0xfb, 0x7c, 0x9d, 0xf1, 0xc2, 0x9a, 0xcb, 0x59, 3543 0x2a, 0xe7, 0xd4, 0xee, 0xfb, 0xfc, 0x0a, 0x90, 3544 0x9a, 0xbb, 0xf6, 0x32, 0x3d, 0x8b, 0x18, 0x55 }; 3545 const u8 x[16] = { 3546 0xab, 0xae, 0x2b, 0x71, 0xec, 0xb2, 0xff, 0xff, 3547 0x3e, 0x73, 0x77, 0xd1, 0x54, 0x84, 0xcb, 0xd5 }; 3548 const u8 z = 0x00; 3549 const u8 exp[16] = { 3550 0x2d, 0x87, 0x74, 0xa9, 0xbe, 0xa1, 0xed, 0xf1, 3551 0x1c, 0xbd, 0xa9, 0x07, 0xf1, 0x16, 0xc9, 0xf2 }; 3552 u8 res[16]; 3553 int err; 3554 3555 err = smp_f4(u, v, x, z, res); 3556 if (err) 3557 return err; 3558 3559 if (crypto_memneq(res, exp, 16)) 3560 return -EINVAL; 3561 3562 return 0; 3563 } 3564 3565 static int __init test_f5(void) 3566 { 3567 const u8 w[32] = { 3568 0x98, 0xa6, 0xbf, 0x73, 0xf3, 0x34, 0x8d, 0x86, 3569 0xf1, 0x66, 0xf8, 0xb4, 0x13, 0x6b, 0x79, 0x99, 3570 0x9b, 0x7d, 0x39, 0x0a, 0xa6, 0x10, 0x10, 0x34, 3571 0x05, 0xad, 0xc8, 0x57, 0xa3, 0x34, 0x02, 0xec }; 3572 const u8 n1[16] = { 3573 0xab, 0xae, 0x2b, 0x71, 0xec, 0xb2, 0xff, 0xff, 3574 0x3e, 0x73, 0x77, 0xd1, 0x54, 0x84, 0xcb, 0xd5 }; 3575 const u8 n2[16] = { 3576 0xcf, 0xc4, 0x3d, 0xff, 0xf7, 0x83, 0x65, 0x21, 3577 0x6e, 0x5f, 0xa7, 0x25, 0xcc, 0xe7, 0xe8, 0xa6 }; 3578 const u8 a1[7] = { 0xce, 0xbf, 0x37, 0x37, 0x12, 0x56, 0x00 }; 3579 const u8 a2[7] = { 0xc1, 0xcf, 0x2d, 0x70, 0x13, 0xa7, 0x00 }; 3580 const u8 exp_ltk[16] = { 3581 0x38, 0x0a, 0x75, 0x94, 0xb5, 0x22, 0x05, 0x98, 3582 0x23, 0xcd, 0xd7, 0x69, 0x11, 0x79, 0x86, 0x69 }; 3583 const u8 exp_mackey[16] = { 3584 0x20, 0x6e, 0x63, 0xce, 0x20, 0x6a, 0x3f, 0xfd, 3585 0x02, 0x4a, 0x08, 0xa1, 0x76, 0xf1, 0x65, 0x29 }; 3586 u8 mackey[16], ltk[16]; 3587 int err; 3588 3589 err = smp_f5(w, n1, n2, a1, a2, mackey, ltk); 3590 if (err) 3591 return err; 3592 3593 if (crypto_memneq(mackey, exp_mackey, 16)) 3594 return -EINVAL; 3595 3596 if (crypto_memneq(ltk, exp_ltk, 16)) 3597 return -EINVAL; 3598 3599 return 0; 3600 } 3601 3602 static int __init test_f6(void) 3603 { 3604 const u8 w[16] = { 3605 0x20, 0x6e, 0x63, 0xce, 0x20, 0x6a, 0x3f, 0xfd, 3606 0x02, 0x4a, 0x08, 0xa1, 0x76, 0xf1, 0x65, 0x29 }; 3607 const u8 n1[16] = { 3608 0xab, 0xae, 0x2b, 0x71, 0xec, 0xb2, 0xff, 0xff, 3609 0x3e, 0x73, 0x77, 0xd1, 0x54, 0x84, 0xcb, 0xd5 }; 3610 const u8 n2[16] = { 3611 0xcf, 0xc4, 0x3d, 0xff, 0xf7, 0x83, 0x65, 0x21, 3612 0x6e, 0x5f, 0xa7, 0x25, 0xcc, 0xe7, 0xe8, 0xa6 }; 3613 const u8 r[16] = { 3614 0xc8, 0x0f, 0x2d, 0x0c, 0xd2, 0x42, 0xda, 0x08, 3615 0x54, 0xbb, 0x53, 0xb4, 0x3b, 0x34, 0xa3, 0x12 }; 3616 const u8 io_cap[3] = { 0x02, 0x01, 0x01 }; 3617 const u8 a1[7] = { 0xce, 0xbf, 0x37, 0x37, 0x12, 0x56, 0x00 }; 3618 const u8 a2[7] = { 0xc1, 0xcf, 0x2d, 0x70, 0x13, 0xa7, 0x00 }; 3619 const u8 exp[16] = { 3620 0x61, 0x8f, 0x95, 0xda, 0x09, 0x0b, 0x6c, 0xd2, 3621 0xc5, 0xe8, 0xd0, 0x9c, 0x98, 0x73, 0xc4, 0xe3 }; 3622 u8 res[16]; 3623 int err; 3624 3625 err = smp_f6(w, n1, n2, r, io_cap, a1, a2, res); 3626 if (err) 3627 return err; 3628 3629 if (crypto_memneq(res, exp, 16)) 3630 return -EINVAL; 3631 3632 return 0; 3633 } 3634 3635 static int __init test_g2(void) 3636 { 3637 const u8 u[32] = { 3638 0xe6, 0x9d, 0x35, 0x0e, 0x48, 0x01, 0x03, 0xcc, 3639 0xdb, 0xfd, 0xf4, 0xac, 0x11, 0x91, 0xf4, 0xef, 3640 0xb9, 0xa5, 0xf9, 0xe9, 0xa7, 0x83, 0x2c, 0x5e, 3641 0x2c, 0xbe, 0x97, 0xf2, 0xd2, 0x03, 0xb0, 0x20 }; 3642 const u8 v[32] = { 3643 0xfd, 0xc5, 0x7f, 0xf4, 0x49, 0xdd, 0x4f, 0x6b, 3644 0xfb, 0x7c, 0x9d, 0xf1, 0xc2, 0x9a, 0xcb, 0x59, 3645 0x2a, 0xe7, 0xd4, 0xee, 0xfb, 0xfc, 0x0a, 0x90, 3646 0x9a, 0xbb, 0xf6, 0x32, 0x3d, 0x8b, 0x18, 0x55 }; 3647 const u8 x[16] = { 3648 0xab, 0xae, 0x2b, 0x71, 0xec, 0xb2, 0xff, 0xff, 3649 0x3e, 0x73, 0x77, 0xd1, 0x54, 0x84, 0xcb, 0xd5 }; 3650 const u8 y[16] = { 3651 0xcf, 0xc4, 0x3d, 0xff, 0xf7, 0x83, 0x65, 0x21, 3652 0x6e, 0x5f, 0xa7, 0x25, 0xcc, 0xe7, 0xe8, 0xa6 }; 3653 const u32 exp_val = 0x2f9ed5ba % 1000000; 3654 u32 val; 3655 int err; 3656 3657 err = smp_g2(u, v, x, y, &val); 3658 if (err) 3659 return err; 3660 3661 if (val != exp_val) 3662 return -EINVAL; 3663 3664 return 0; 3665 } 3666 3667 static int __init test_h6(void) 3668 { 3669 const u8 w[16] = { 3670 0x9b, 0x7d, 0x39, 0x0a, 0xa6, 0x10, 0x10, 0x34, 3671 0x05, 0xad, 0xc8, 0x57, 0xa3, 0x34, 0x02, 0xec }; 3672 const u8 key_id[4] = { 0x72, 0x62, 0x65, 0x6c }; 3673 const u8 exp[16] = { 3674 0x99, 0x63, 0xb1, 0x80, 0xe2, 0xa9, 0xd3, 0xe8, 3675 0x1c, 0xc9, 0x6d, 0xe7, 0x02, 0xe1, 0x9a, 0x2d }; 3676 u8 res[16]; 3677 int err; 3678 3679 err = smp_h6(w, key_id, res); 3680 if (err) 3681 return err; 3682 3683 if (crypto_memneq(res, exp, 16)) 3684 return -EINVAL; 3685 3686 return 0; 3687 } 3688 3689 static char test_smp_buffer[32]; 3690 3691 static ssize_t test_smp_read(struct file *file, char __user *user_buf, 3692 size_t count, loff_t *ppos) 3693 { 3694 return simple_read_from_buffer(user_buf, count, ppos, test_smp_buffer, 3695 strlen(test_smp_buffer)); 3696 } 3697 3698 static const struct file_operations test_smp_fops = { 3699 .open = simple_open, 3700 .read = test_smp_read, 3701 .llseek = default_llseek, 3702 }; 3703 3704 static int __init run_selftests(struct crypto_kpp *tfm_ecdh) 3705 { 3706 ktime_t calltime, delta, rettime; 3707 unsigned long long duration; 3708 int err; 3709 3710 calltime = ktime_get(); 3711 3712 err = test_debug_key(tfm_ecdh); 3713 if (err) { 3714 BT_ERR("debug_key test failed"); 3715 goto done; 3716 } 3717 3718 err = test_ah(); 3719 if (err) { 3720 BT_ERR("smp_ah test failed"); 3721 goto done; 3722 } 3723 3724 err = test_c1(); 3725 if (err) { 3726 BT_ERR("smp_c1 test failed"); 3727 goto done; 3728 } 3729 3730 err = test_s1(); 3731 if (err) { 3732 BT_ERR("smp_s1 test failed"); 3733 goto done; 3734 } 3735 3736 err = test_f4(); 3737 if (err) { 3738 BT_ERR("smp_f4 test failed"); 3739 goto done; 3740 } 3741 3742 err = test_f5(); 3743 if (err) { 3744 BT_ERR("smp_f5 test failed"); 3745 goto done; 3746 } 3747 3748 err = test_f6(); 3749 if (err) { 3750 BT_ERR("smp_f6 test failed"); 3751 goto done; 3752 } 3753 3754 err = test_g2(); 3755 if (err) { 3756 BT_ERR("smp_g2 test failed"); 3757 goto done; 3758 } 3759 3760 err = test_h6(); 3761 if (err) { 3762 BT_ERR("smp_h6 test failed"); 3763 goto done; 3764 } 3765 3766 rettime = ktime_get(); 3767 delta = ktime_sub(rettime, calltime); 3768 duration = (unsigned long long) ktime_to_ns(delta) >> 10; 3769 3770 BT_INFO("SMP test passed in %llu usecs", duration); 3771 3772 done: 3773 if (!err) 3774 snprintf(test_smp_buffer, sizeof(test_smp_buffer), 3775 "PASS (%llu usecs)\n", duration); 3776 else 3777 snprintf(test_smp_buffer, sizeof(test_smp_buffer), "FAIL\n"); 3778 3779 debugfs_create_file("selftest_smp", 0444, bt_debugfs, NULL, 3780 &test_smp_fops); 3781 3782 return err; 3783 } 3784 3785 int __init bt_selftest_smp(void) 3786 { 3787 struct crypto_kpp *tfm_ecdh; 3788 int err; 3789 3790 tfm_ecdh = crypto_alloc_kpp("ecdh-nist-p256", 0, 0); 3791 if (IS_ERR(tfm_ecdh)) { 3792 BT_ERR("Unable to create ECDH crypto context"); 3793 return PTR_ERR(tfm_ecdh); 3794 } 3795 3796 err = run_selftests(tfm_ecdh); 3797 3798 crypto_free_kpp(tfm_ecdh); 3799 3800 return err; 3801 } 3802 3803 #endif 3804