1 // SPDX-License-Identifier: GPL-2.0 2 /* 3 BlueZ - Bluetooth protocol stack for Linux 4 Copyright (C) 2011 Nokia Corporation and/or its subsidiary(-ies). 5 6 THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS 7 OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, 8 FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT OF THIRD PARTY RIGHTS. 9 IN NO EVENT SHALL THE COPYRIGHT HOLDER(S) AND AUTHOR(S) BE LIABLE FOR ANY 10 CLAIM, OR ANY SPECIAL INDIRECT OR CONSEQUENTIAL DAMAGES, OR ANY DAMAGES 11 WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN 12 ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF 13 OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. 14 15 ALL LIABILITY, INCLUDING LIABILITY FOR INFRINGEMENT OF ANY PATENTS, 16 COPYRIGHTS, TRADEMARKS OR OTHER RIGHTS, RELATING TO USE OF THIS 17 SOFTWARE IS DISCLAIMED. 18 */ 19 20 #include <linux/debugfs.h> 21 #include <linux/scatterlist.h> 22 #include <crypto/aes-cbc-macs.h> 23 #include <crypto/aes.h> 24 #include <crypto/kpp.h> 25 #include <crypto/utils.h> 26 27 #include <net/bluetooth/bluetooth.h> 28 #include <net/bluetooth/hci_core.h> 29 #include <net/bluetooth/l2cap.h> 30 #include <net/bluetooth/mgmt.h> 31 32 #include "ecdh_helper.h" 33 #include "smp.h" 34 35 #define SMP_DEV(hdev) \ 36 ((struct smp_dev *)((struct l2cap_chan *)((hdev)->smp_data))->data) 37 38 /* Low-level debug macros to be used for stuff that we don't want 39 * accidentally in dmesg, i.e. the values of the various crypto keys 40 * and the inputs & outputs of crypto functions. 41 */ 42 #ifdef DEBUG 43 #define SMP_DBG(fmt, ...) printk(KERN_DEBUG "%s: " fmt, __func__, \ 44 ##__VA_ARGS__) 45 #else 46 #define SMP_DBG(fmt, ...) no_printk(KERN_DEBUG "%s: " fmt, __func__, \ 47 ##__VA_ARGS__) 48 #endif 49 50 #define SMP_ALLOW_CMD(smp, code) set_bit(code, &smp->allow_cmd) 51 52 /* Keys which are not distributed with Secure Connections */ 53 #define SMP_SC_NO_DIST (SMP_DIST_ENC_KEY | SMP_DIST_LINK_KEY) 54 55 #define SMP_TIMEOUT secs_to_jiffies(30) 56 57 #define ID_ADDR_TIMEOUT msecs_to_jiffies(200) 58 59 #define AUTH_REQ_MASK(dev) (hci_dev_test_flag(dev, HCI_SC_ENABLED) ? \ 60 0x3f : 0x07) 61 #define KEY_DIST_MASK 0x07 62 63 /* Maximum message length that can be passed to smp_aes_cmac */ 64 #define CMAC_MSG_MAX 80 65 66 enum { 67 SMP_FLAG_TK_VALID, 68 SMP_FLAG_CFM_PENDING, 69 SMP_FLAG_MITM_AUTH, 70 SMP_FLAG_COMPLETE, 71 SMP_FLAG_INITIATOR, 72 SMP_FLAG_SC, 73 SMP_FLAG_REMOTE_PK, 74 SMP_FLAG_DEBUG_KEY, 75 SMP_FLAG_WAIT_USER, 76 SMP_FLAG_DHKEY_PENDING, 77 SMP_FLAG_REMOTE_OOB, 78 SMP_FLAG_LOCAL_OOB, 79 SMP_FLAG_CT2, 80 }; 81 82 struct smp_dev { 83 /* Secure Connections OOB data */ 84 bool local_oob; 85 u8 local_pk[64]; 86 u8 local_rand[16]; 87 bool debug_key; 88 89 struct crypto_kpp *tfm_ecdh; 90 }; 91 92 struct smp_chan { 93 struct l2cap_conn *conn; 94 struct delayed_work security_timer; 95 unsigned long allow_cmd; /* Bitmask of allowed commands */ 96 97 u8 preq[7]; /* SMP Pairing Request */ 98 u8 prsp[7]; /* SMP Pairing Response */ 99 u8 prnd[16]; /* SMP Pairing Random (local) */ 100 u8 rrnd[16]; /* SMP Pairing Random (remote) */ 101 u8 pcnf[16]; /* SMP Pairing Confirm */ 102 u8 tk[16]; /* SMP Temporary Key */ 103 u8 rr[16]; /* Remote OOB ra/rb value */ 104 u8 lr[16]; /* Local OOB ra/rb value */ 105 u8 enc_key_size; 106 u8 remote_key_dist; 107 bdaddr_t id_addr; 108 u8 id_addr_type; 109 u8 irk[16]; 110 struct smp_csrk *csrk; 111 struct smp_csrk *responder_csrk; 112 struct smp_ltk *ltk; 113 struct smp_ltk *responder_ltk; 114 struct smp_irk *remote_irk; 115 u8 *link_key; 116 unsigned long flags; 117 u8 method; 118 u8 passkey_round; 119 120 /* Secure Connections variables */ 121 u8 local_pk[64]; 122 u8 remote_pk[64]; 123 u8 dhkey[32]; 124 u8 mackey[16]; 125 126 struct crypto_kpp *tfm_ecdh; 127 }; 128 129 /* These debug key values are defined in the SMP section of the core 130 * specification. debug_pk is the public debug key and debug_sk the 131 * private debug key. 132 */ 133 static const u8 debug_pk[64] = { 134 0xe6, 0x9d, 0x35, 0x0e, 0x48, 0x01, 0x03, 0xcc, 135 0xdb, 0xfd, 0xf4, 0xac, 0x11, 0x91, 0xf4, 0xef, 136 0xb9, 0xa5, 0xf9, 0xe9, 0xa7, 0x83, 0x2c, 0x5e, 137 0x2c, 0xbe, 0x97, 0xf2, 0xd2, 0x03, 0xb0, 0x20, 138 139 0x8b, 0xd2, 0x89, 0x15, 0xd0, 0x8e, 0x1c, 0x74, 140 0x24, 0x30, 0xed, 0x8f, 0xc2, 0x45, 0x63, 0x76, 141 0x5c, 0x15, 0x52, 0x5a, 0xbf, 0x9a, 0x32, 0x63, 142 0x6d, 0xeb, 0x2a, 0x65, 0x49, 0x9c, 0x80, 0xdc, 143 }; 144 145 static const u8 debug_sk[32] = { 146 0xbd, 0x1a, 0x3c, 0xcd, 0xa6, 0xb8, 0x99, 0x58, 147 0x99, 0xb7, 0x40, 0xeb, 0x7b, 0x60, 0xff, 0x4a, 148 0x50, 0x3f, 0x10, 0xd2, 0xe3, 0xb3, 0xc9, 0x74, 149 0x38, 0x5f, 0xc5, 0xa3, 0xd4, 0xf6, 0x49, 0x3f, 150 }; 151 152 static inline void swap_buf(const u8 *src, u8 *dst, size_t len) 153 { 154 size_t i; 155 156 for (i = 0; i < len; i++) 157 dst[len - 1 - i] = src[i]; 158 } 159 160 /* The following functions map to the LE SC SMP crypto functions 161 * AES-CMAC, f4, f5, f6, g2 and h6. 162 */ 163 164 static int smp_aes_cmac(const u8 k[16], const u8 *m, size_t len, u8 mac[16]) 165 { 166 uint8_t tmp[16], mac_msb[16], msg_msb[CMAC_MSG_MAX]; 167 struct aes_cmac_key key __cleanup(aes_cmac_zeroize_key); 168 int err; 169 170 if (len > CMAC_MSG_MAX) 171 return -EFBIG; 172 173 /* Swap key and message from LSB to MSB */ 174 swap_buf(k, tmp, 16); 175 swap_buf(m, msg_msb, len); 176 177 SMP_DBG("msg (len %zu) %*phN", len, (int) len, m); 178 SMP_DBG("key %16phN", k); 179 180 err = aes_cmac_preparekey(&key, tmp, 16); 181 memzero_explicit(tmp, sizeof(tmp)); 182 if (WARN_ON_ONCE(err)) /* Should never happen, as 16 is valid keylen */ 183 return err; 184 aes_cmac(&key, msg_msb, len, mac_msb); 185 186 swap_buf(mac_msb, mac, 16); 187 188 SMP_DBG("mac %16phN", mac); 189 190 return 0; 191 } 192 193 static int smp_f4(const u8 u[32], const u8 v[32], const u8 x[16], u8 z, 194 u8 res[16]) 195 { 196 u8 m[65]; 197 int err; 198 199 SMP_DBG("u %32phN", u); 200 SMP_DBG("v %32phN", v); 201 SMP_DBG("x %16phN z %02x", x, z); 202 203 m[0] = z; 204 memcpy(m + 1, v, 32); 205 memcpy(m + 33, u, 32); 206 207 err = smp_aes_cmac(x, m, sizeof(m), res); 208 if (err) 209 return err; 210 211 SMP_DBG("res %16phN", res); 212 213 return err; 214 } 215 216 static int smp_f5(const u8 w[32], const u8 n1[16], const u8 n2[16], 217 const u8 a1[7], const u8 a2[7], u8 mackey[16], u8 ltk[16]) 218 { 219 /* The btle, salt and length "magic" values are as defined in 220 * the SMP section of the Bluetooth core specification. In ASCII 221 * the btle value ends up being 'btle'. The salt is just a 222 * random number whereas length is the value 256 in little 223 * endian format. 224 */ 225 const u8 btle[4] = { 0x65, 0x6c, 0x74, 0x62 }; 226 const u8 salt[16] = { 0xbe, 0x83, 0x60, 0x5a, 0xdb, 0x0b, 0x37, 0x60, 227 0x38, 0xa5, 0xf5, 0xaa, 0x91, 0x83, 0x88, 0x6c }; 228 const u8 length[2] = { 0x00, 0x01 }; 229 u8 m[53], t[16]; 230 int err; 231 232 SMP_DBG("w %32phN", w); 233 SMP_DBG("n1 %16phN n2 %16phN", n1, n2); 234 SMP_DBG("a1 %7phN a2 %7phN", a1, a2); 235 236 err = smp_aes_cmac(salt, w, 32, t); 237 if (err) 238 return err; 239 240 SMP_DBG("t %16phN", t); 241 242 memcpy(m, length, 2); 243 memcpy(m + 2, a2, 7); 244 memcpy(m + 9, a1, 7); 245 memcpy(m + 16, n2, 16); 246 memcpy(m + 32, n1, 16); 247 memcpy(m + 48, btle, 4); 248 249 m[52] = 0; /* Counter */ 250 251 err = smp_aes_cmac(t, m, sizeof(m), mackey); 252 if (err) 253 return err; 254 255 SMP_DBG("mackey %16phN", mackey); 256 257 m[52] = 1; /* Counter */ 258 259 err = smp_aes_cmac(t, m, sizeof(m), ltk); 260 if (err) 261 return err; 262 263 SMP_DBG("ltk %16phN", ltk); 264 265 return 0; 266 } 267 268 static int smp_f6(const u8 w[16], const u8 n1[16], const u8 n2[16], 269 const u8 r[16], const u8 io_cap[3], const u8 a1[7], 270 const u8 a2[7], u8 res[16]) 271 { 272 u8 m[65]; 273 int err; 274 275 SMP_DBG("w %16phN", w); 276 SMP_DBG("n1 %16phN n2 %16phN", n1, n2); 277 SMP_DBG("r %16phN io_cap %3phN a1 %7phN a2 %7phN", r, io_cap, a1, a2); 278 279 memcpy(m, a2, 7); 280 memcpy(m + 7, a1, 7); 281 memcpy(m + 14, io_cap, 3); 282 memcpy(m + 17, r, 16); 283 memcpy(m + 33, n2, 16); 284 memcpy(m + 49, n1, 16); 285 286 err = smp_aes_cmac(w, m, sizeof(m), res); 287 if (err) 288 return err; 289 290 SMP_DBG("res %16phN", res); 291 292 return err; 293 } 294 295 static int smp_g2(const u8 u[32], const u8 v[32], const u8 x[16], 296 const u8 y[16], u32 *val) 297 { 298 u8 m[80], tmp[16]; 299 int err; 300 301 SMP_DBG("u %32phN", u); 302 SMP_DBG("v %32phN", v); 303 SMP_DBG("x %16phN y %16phN", x, y); 304 305 memcpy(m, y, 16); 306 memcpy(m + 16, v, 32); 307 memcpy(m + 48, u, 32); 308 309 err = smp_aes_cmac(x, m, sizeof(m), tmp); 310 if (err) 311 return err; 312 313 *val = get_unaligned_le32(tmp); 314 *val %= 1000000; 315 316 SMP_DBG("val %06u", *val); 317 318 return 0; 319 } 320 321 static int smp_h6(const u8 w[16], const u8 key_id[4], u8 res[16]) 322 { 323 int err; 324 325 SMP_DBG("w %16phN key_id %4phN", w, key_id); 326 327 err = smp_aes_cmac(w, key_id, 4, res); 328 if (err) 329 return err; 330 331 SMP_DBG("res %16phN", res); 332 333 return err; 334 } 335 336 static int smp_h7(const u8 w[16], const u8 salt[16], u8 res[16]) 337 { 338 int err; 339 340 SMP_DBG("w %16phN salt %16phN", w, salt); 341 342 err = smp_aes_cmac(salt, w, 16, res); 343 if (err) 344 return err; 345 346 SMP_DBG("res %16phN", res); 347 348 return err; 349 } 350 351 /* The following functions map to the legacy SMP crypto functions e, c1, 352 * s1 and ah. 353 */ 354 355 static int smp_e(const u8 *k, u8 *r) 356 { 357 struct aes_enckey aes; 358 uint8_t tmp[16], data[16]; 359 int err; 360 361 SMP_DBG("k %16phN r %16phN", k, r); 362 363 /* The most significant octet of key corresponds to k[0] */ 364 swap_buf(k, tmp, 16); 365 366 err = aes_prepareenckey(&aes, tmp, 16); 367 if (err) { 368 BT_ERR("cipher setkey failed: %d", err); 369 return err; 370 } 371 372 /* Most significant octet of plaintextData corresponds to data[0] */ 373 swap_buf(r, data, 16); 374 375 aes_encrypt(&aes, data, data); 376 377 /* Most significant octet of encryptedData corresponds to data[0] */ 378 swap_buf(data, r, 16); 379 380 SMP_DBG("r %16phN", r); 381 382 memzero_explicit(&aes, sizeof(aes)); 383 return err; 384 } 385 386 static int smp_c1(const u8 k[16], 387 const u8 r[16], const u8 preq[7], const u8 pres[7], u8 _iat, 388 const bdaddr_t *ia, u8 _rat, const bdaddr_t *ra, u8 res[16]) 389 { 390 u8 p1[16], p2[16]; 391 int err; 392 393 SMP_DBG("k %16phN r %16phN", k, r); 394 SMP_DBG("iat %u ia %6phN rat %u ra %6phN", _iat, ia, _rat, ra); 395 SMP_DBG("preq %7phN pres %7phN", preq, pres); 396 397 memset(p1, 0, 16); 398 399 /* p1 = pres || preq || _rat || _iat */ 400 p1[0] = _iat; 401 p1[1] = _rat; 402 memcpy(p1 + 2, preq, 7); 403 memcpy(p1 + 9, pres, 7); 404 405 SMP_DBG("p1 %16phN", p1); 406 407 /* res = r XOR p1 */ 408 crypto_xor_cpy(res, r, p1, sizeof(p1)); 409 410 /* res = e(k, res) */ 411 err = smp_e(k, res); 412 if (err) { 413 BT_ERR("Encrypt data error"); 414 return err; 415 } 416 417 /* p2 = padding || ia || ra */ 418 memcpy(p2, ra, 6); 419 memcpy(p2 + 6, ia, 6); 420 memset(p2 + 12, 0, 4); 421 422 SMP_DBG("p2 %16phN", p2); 423 424 /* res = res XOR p2 */ 425 crypto_xor(res, p2, sizeof(p2)); 426 427 /* res = e(k, res) */ 428 err = smp_e(k, res); 429 if (err) 430 BT_ERR("Encrypt data error"); 431 432 return err; 433 } 434 435 static int smp_s1(const u8 k[16], 436 const u8 r1[16], const u8 r2[16], u8 _r[16]) 437 { 438 int err; 439 440 /* Just least significant octets from r1 and r2 are considered */ 441 memcpy(_r, r2, 8); 442 memcpy(_r + 8, r1, 8); 443 444 err = smp_e(k, _r); 445 if (err) 446 BT_ERR("Encrypt data error"); 447 448 return err; 449 } 450 451 static int smp_ah(const u8 irk[16], const u8 r[3], u8 res[3]) 452 { 453 u8 _res[16]; 454 int err; 455 456 /* r' = padding || r */ 457 memcpy(_res, r, 3); 458 memset(_res + 3, 0, 13); 459 460 err = smp_e(irk, _res); 461 if (err) { 462 BT_ERR("Encrypt error"); 463 return err; 464 } 465 466 /* The output of the random address function ah is: 467 * ah(k, r) = e(k, r') mod 2^24 468 * The output of the security function e is then truncated to 24 bits 469 * by taking the least significant 24 bits of the output of e as the 470 * result of ah. 471 */ 472 memcpy(res, _res, 3); 473 474 return 0; 475 } 476 477 bool smp_irk_matches(struct hci_dev *hdev, const u8 irk[16], 478 const bdaddr_t *bdaddr) 479 { 480 struct l2cap_chan *chan = hdev->smp_data; 481 u8 hash[3]; 482 int err; 483 484 if (!chan || !chan->data) 485 return false; 486 487 bt_dev_dbg(hdev, "RPA %pMR IRK %*phN", bdaddr, 16, irk); 488 489 err = smp_ah(irk, &bdaddr->b[3], hash); 490 if (err) 491 return false; 492 493 return !crypto_memneq(bdaddr->b, hash, 3); 494 } 495 496 int smp_generate_rpa(struct hci_dev *hdev, const u8 irk[16], bdaddr_t *rpa) 497 { 498 struct l2cap_chan *chan = hdev->smp_data; 499 int err; 500 501 if (!chan || !chan->data) 502 return -EOPNOTSUPP; 503 504 get_random_bytes(&rpa->b[3], 3); 505 506 rpa->b[5] &= 0x3f; /* Clear two most significant bits */ 507 rpa->b[5] |= 0x40; /* Set second most significant bit */ 508 509 err = smp_ah(irk, &rpa->b[3], rpa->b); 510 if (err < 0) 511 return err; 512 513 bt_dev_dbg(hdev, "RPA %pMR", rpa); 514 515 return 0; 516 } 517 518 int smp_generate_oob(struct hci_dev *hdev, u8 hash[16], u8 rand[16]) 519 { 520 struct l2cap_chan *chan = hdev->smp_data; 521 struct smp_dev *smp; 522 int err; 523 524 if (!chan || !chan->data) 525 return -EOPNOTSUPP; 526 527 smp = chan->data; 528 529 if (hci_dev_test_flag(hdev, HCI_USE_DEBUG_KEYS)) { 530 bt_dev_dbg(hdev, "Using debug keys"); 531 err = set_ecdh_privkey(smp->tfm_ecdh, debug_sk); 532 if (err) 533 return err; 534 memcpy(smp->local_pk, debug_pk, 64); 535 smp->debug_key = true; 536 } else { 537 while (true) { 538 /* Generate key pair for Secure Connections */ 539 err = generate_ecdh_keys(smp->tfm_ecdh, smp->local_pk); 540 if (err) 541 return err; 542 543 /* This is unlikely, but we need to check that 544 * we didn't accidentally generate a debug key. 545 */ 546 if (crypto_memneq(smp->local_pk, debug_pk, 64)) 547 break; 548 } 549 smp->debug_key = false; 550 } 551 552 SMP_DBG("OOB Public Key X: %32phN", smp->local_pk); 553 SMP_DBG("OOB Public Key Y: %32phN", smp->local_pk + 32); 554 555 get_random_bytes(smp->local_rand, 16); 556 557 err = smp_f4(smp->local_pk, smp->local_pk, smp->local_rand, 0, hash); 558 if (err < 0) 559 return err; 560 561 memcpy(rand, smp->local_rand, 16); 562 563 smp->local_oob = true; 564 565 return 0; 566 } 567 568 static void smp_send_cmd(struct l2cap_conn *conn, u8 code, u16 len, void *data) 569 { 570 struct l2cap_chan *chan = conn->smp; 571 struct smp_chan *smp; 572 struct kvec iv[2]; 573 struct msghdr msg; 574 575 if (!chan) 576 return; 577 578 bt_dev_dbg(conn->hcon->hdev, "code 0x%2.2x", code); 579 580 iv[0].iov_base = &code; 581 iv[0].iov_len = 1; 582 583 iv[1].iov_base = data; 584 iv[1].iov_len = len; 585 586 memset(&msg, 0, sizeof(msg)); 587 588 iov_iter_kvec(&msg.msg_iter, ITER_SOURCE, iv, 2, 1 + len); 589 590 l2cap_chan_send(chan, &msg, 1 + len, NULL); 591 592 if (!chan->data) 593 return; 594 595 smp = chan->data; 596 597 cancel_delayed_work_sync(&smp->security_timer); 598 schedule_delayed_work(&smp->security_timer, SMP_TIMEOUT); 599 } 600 601 static u8 authreq_to_seclevel(u8 authreq) 602 { 603 if (authreq & SMP_AUTH_MITM) { 604 if (authreq & SMP_AUTH_SC) 605 return BT_SECURITY_FIPS; 606 else 607 return BT_SECURITY_HIGH; 608 } else { 609 return BT_SECURITY_MEDIUM; 610 } 611 } 612 613 static __u8 seclevel_to_authreq(__u8 sec_level) 614 { 615 switch (sec_level) { 616 case BT_SECURITY_FIPS: 617 case BT_SECURITY_HIGH: 618 return SMP_AUTH_MITM | SMP_AUTH_BONDING; 619 case BT_SECURITY_MEDIUM: 620 return SMP_AUTH_BONDING; 621 default: 622 return SMP_AUTH_NONE; 623 } 624 } 625 626 static void build_pairing_cmd(struct l2cap_conn *conn, 627 struct smp_cmd_pairing *req, 628 struct smp_cmd_pairing *rsp, __u8 authreq) 629 { 630 struct l2cap_chan *chan = conn->smp; 631 struct smp_chan *smp = chan->data; 632 struct hci_conn *hcon = conn->hcon; 633 struct hci_dev *hdev = hcon->hdev; 634 u8 local_dist = 0, remote_dist = 0, oob_flag = SMP_OOB_NOT_PRESENT; 635 636 if (hci_dev_test_flag(hdev, HCI_BONDABLE)) { 637 local_dist = SMP_DIST_ENC_KEY | SMP_DIST_SIGN; 638 remote_dist = SMP_DIST_ENC_KEY | SMP_DIST_SIGN; 639 authreq |= SMP_AUTH_BONDING; 640 } else { 641 authreq &= ~SMP_AUTH_BONDING; 642 } 643 644 if (hci_dev_test_flag(hdev, HCI_RPA_RESOLVING)) 645 remote_dist |= SMP_DIST_ID_KEY; 646 647 if (hci_dev_test_flag(hdev, HCI_PRIVACY)) 648 local_dist |= SMP_DIST_ID_KEY; 649 650 if (hci_dev_test_flag(hdev, HCI_SC_ENABLED) && 651 (authreq & SMP_AUTH_SC)) { 652 struct oob_data *oob_data; 653 u8 bdaddr_type; 654 655 if (hci_dev_test_flag(hdev, HCI_SSP_ENABLED)) { 656 local_dist |= SMP_DIST_LINK_KEY; 657 remote_dist |= SMP_DIST_LINK_KEY; 658 } 659 660 if (hcon->dst_type == ADDR_LE_DEV_PUBLIC) 661 bdaddr_type = BDADDR_LE_PUBLIC; 662 else 663 bdaddr_type = BDADDR_LE_RANDOM; 664 665 oob_data = hci_find_remote_oob_data(hdev, &hcon->dst, 666 bdaddr_type); 667 if (oob_data && oob_data->present) { 668 set_bit(SMP_FLAG_REMOTE_OOB, &smp->flags); 669 oob_flag = SMP_OOB_PRESENT; 670 memcpy(smp->rr, oob_data->rand256, 16); 671 memcpy(smp->pcnf, oob_data->hash256, 16); 672 SMP_DBG("OOB Remote Confirmation: %16phN", smp->pcnf); 673 SMP_DBG("OOB Remote Random: %16phN", smp->rr); 674 } 675 676 } else { 677 authreq &= ~SMP_AUTH_SC; 678 } 679 680 if (rsp == NULL) { 681 req->io_capability = conn->hcon->io_capability; 682 req->oob_flag = oob_flag; 683 req->max_key_size = hdev->le_max_key_size; 684 req->init_key_dist = local_dist; 685 req->resp_key_dist = remote_dist; 686 req->auth_req = (authreq & AUTH_REQ_MASK(hdev)); 687 688 smp->remote_key_dist = remote_dist; 689 return; 690 } 691 692 rsp->io_capability = conn->hcon->io_capability; 693 rsp->oob_flag = oob_flag; 694 rsp->max_key_size = hdev->le_max_key_size; 695 rsp->init_key_dist = req->init_key_dist & remote_dist; 696 rsp->resp_key_dist = req->resp_key_dist & local_dist; 697 rsp->auth_req = (authreq & AUTH_REQ_MASK(hdev)); 698 699 smp->remote_key_dist = rsp->init_key_dist; 700 } 701 702 static u8 check_enc_key_size(struct l2cap_conn *conn, __u8 max_key_size) 703 { 704 struct l2cap_chan *chan = conn->smp; 705 struct hci_dev *hdev = conn->hcon->hdev; 706 struct smp_chan *smp = chan->data; 707 708 if (conn->hcon->pending_sec_level == BT_SECURITY_FIPS && 709 max_key_size != SMP_MAX_ENC_KEY_SIZE) 710 return SMP_ENC_KEY_SIZE; 711 712 if (max_key_size > hdev->le_max_key_size || 713 max_key_size < SMP_MIN_ENC_KEY_SIZE) 714 return SMP_ENC_KEY_SIZE; 715 716 smp->enc_key_size = max_key_size; 717 718 return 0; 719 } 720 721 static void smp_chan_destroy(struct l2cap_conn *conn) 722 { 723 struct l2cap_chan *chan = conn->smp; 724 struct smp_chan *smp = chan->data; 725 struct hci_conn *hcon = conn->hcon; 726 bool complete; 727 728 BUG_ON(!smp); 729 730 cancel_delayed_work_sync(&smp->security_timer); 731 732 complete = test_bit(SMP_FLAG_COMPLETE, &smp->flags); 733 mgmt_smp_complete(hcon, complete); 734 735 kfree_sensitive(smp->csrk); 736 kfree_sensitive(smp->responder_csrk); 737 kfree_sensitive(smp->link_key); 738 739 crypto_free_kpp(smp->tfm_ecdh); 740 741 /* Ensure that we don't leave any debug key around if debug key 742 * support hasn't been explicitly enabled. 743 */ 744 if (smp->ltk && smp->ltk->type == SMP_LTK_P256_DEBUG && 745 !hci_dev_test_flag(hcon->hdev, HCI_KEEP_DEBUG_KEYS)) { 746 list_del_rcu(&smp->ltk->list); 747 kfree_rcu(smp->ltk, rcu); 748 smp->ltk = NULL; 749 } 750 751 /* If pairing failed clean up any keys we might have */ 752 if (!complete) { 753 if (smp->ltk) { 754 list_del_rcu(&smp->ltk->list); 755 kfree_rcu(smp->ltk, rcu); 756 } 757 758 if (smp->responder_ltk) { 759 list_del_rcu(&smp->responder_ltk->list); 760 kfree_rcu(smp->responder_ltk, rcu); 761 } 762 763 if (smp->remote_irk) { 764 list_del_rcu(&smp->remote_irk->list); 765 kfree_rcu(smp->remote_irk, rcu); 766 } 767 } 768 769 chan->data = NULL; 770 kfree_sensitive(smp); 771 hci_conn_drop(hcon); 772 } 773 774 static void smp_failure(struct l2cap_conn *conn, u8 reason) 775 { 776 struct hci_conn *hcon = conn->hcon; 777 struct l2cap_chan *chan = conn->smp; 778 779 if (reason) 780 smp_send_cmd(conn, SMP_CMD_PAIRING_FAIL, sizeof(reason), 781 &reason); 782 783 mgmt_auth_failed(hcon, HCI_ERROR_AUTH_FAILURE); 784 785 if (chan->data) 786 smp_chan_destroy(conn); 787 } 788 789 #define JUST_WORKS 0x00 790 #define JUST_CFM 0x01 791 #define REQ_PASSKEY 0x02 792 #define CFM_PASSKEY 0x03 793 #define REQ_OOB 0x04 794 #define DSP_PASSKEY 0x05 795 #define OVERLAP 0xFF 796 797 static const u8 gen_method[5][5] = { 798 { JUST_WORKS, JUST_CFM, REQ_PASSKEY, JUST_WORKS, REQ_PASSKEY }, 799 { JUST_WORKS, JUST_CFM, REQ_PASSKEY, JUST_WORKS, REQ_PASSKEY }, 800 { CFM_PASSKEY, CFM_PASSKEY, REQ_PASSKEY, JUST_WORKS, CFM_PASSKEY }, 801 { JUST_WORKS, JUST_CFM, JUST_WORKS, JUST_WORKS, JUST_CFM }, 802 { CFM_PASSKEY, CFM_PASSKEY, REQ_PASSKEY, JUST_WORKS, OVERLAP }, 803 }; 804 805 static const u8 sc_method[5][5] = { 806 { JUST_WORKS, JUST_CFM, REQ_PASSKEY, JUST_WORKS, REQ_PASSKEY }, 807 { JUST_WORKS, CFM_PASSKEY, REQ_PASSKEY, JUST_WORKS, CFM_PASSKEY }, 808 { DSP_PASSKEY, DSP_PASSKEY, REQ_PASSKEY, JUST_WORKS, DSP_PASSKEY }, 809 { JUST_WORKS, JUST_CFM, JUST_WORKS, JUST_WORKS, JUST_CFM }, 810 { DSP_PASSKEY, CFM_PASSKEY, REQ_PASSKEY, JUST_WORKS, CFM_PASSKEY }, 811 }; 812 813 static u8 get_auth_method(struct smp_chan *smp, u8 local_io, u8 remote_io) 814 { 815 /* If either side has unknown io_caps, use JUST_CFM (which gets 816 * converted later to JUST_WORKS if we're initiators. 817 */ 818 if (local_io > SMP_IO_KEYBOARD_DISPLAY || 819 remote_io > SMP_IO_KEYBOARD_DISPLAY) 820 return JUST_CFM; 821 822 if (test_bit(SMP_FLAG_SC, &smp->flags)) 823 return sc_method[remote_io][local_io]; 824 825 return gen_method[remote_io][local_io]; 826 } 827 828 static int tk_request(struct l2cap_conn *conn, u8 remote_oob, u8 auth, 829 u8 local_io, u8 remote_io) 830 { 831 struct hci_conn *hcon = conn->hcon; 832 struct l2cap_chan *chan = conn->smp; 833 struct smp_chan *smp = chan->data; 834 u32 passkey = 0; 835 int ret; 836 837 /* Initialize key for JUST WORKS */ 838 memset(smp->tk, 0, sizeof(smp->tk)); 839 clear_bit(SMP_FLAG_TK_VALID, &smp->flags); 840 841 bt_dev_dbg(hcon->hdev, "auth:%u lcl:%u rem:%u", auth, local_io, 842 remote_io); 843 844 /* If neither side wants MITM, either "just" confirm an incoming 845 * request or use just-works for outgoing ones. The JUST_CFM 846 * will be converted to JUST_WORKS if necessary later in this 847 * function. If either side has MITM look up the method from the 848 * table. 849 */ 850 if (!(auth & SMP_AUTH_MITM)) 851 smp->method = JUST_CFM; 852 else 853 smp->method = get_auth_method(smp, local_io, remote_io); 854 855 /* Don't confirm locally initiated pairing attempts */ 856 if (smp->method == JUST_CFM && test_bit(SMP_FLAG_INITIATOR, 857 &smp->flags)) 858 smp->method = JUST_WORKS; 859 860 /* Don't bother user space with no IO capabilities */ 861 if (smp->method == JUST_CFM && 862 hcon->io_capability == HCI_IO_NO_INPUT_OUTPUT) 863 smp->method = JUST_WORKS; 864 865 /* If Just Works, Continue with Zero TK and ask user-space for 866 * confirmation */ 867 if (smp->method == JUST_WORKS) { 868 ret = mgmt_user_confirm_request(hcon->hdev, &hcon->dst, 869 hcon->type, 870 hcon->dst_type, 871 passkey, 1); 872 if (ret) 873 return ret; 874 set_bit(SMP_FLAG_WAIT_USER, &smp->flags); 875 return 0; 876 } 877 878 /* If this function is used for SC -> legacy fallback we 879 * can only recover the just-works case. 880 */ 881 if (test_bit(SMP_FLAG_SC, &smp->flags)) 882 return -EINVAL; 883 884 /* Not Just Works/Confirm results in MITM Authentication */ 885 if (smp->method != JUST_CFM) { 886 set_bit(SMP_FLAG_MITM_AUTH, &smp->flags); 887 if (hcon->pending_sec_level < BT_SECURITY_HIGH) 888 hcon->pending_sec_level = BT_SECURITY_HIGH; 889 } 890 891 /* If both devices have Keyboard-Display I/O, the initiator 892 * Confirms and the responder Enters the passkey. 893 */ 894 if (smp->method == OVERLAP) { 895 if (test_bit(SMP_FLAG_INITIATOR, &smp->flags)) 896 smp->method = CFM_PASSKEY; 897 else 898 smp->method = REQ_PASSKEY; 899 } 900 901 /* Generate random passkey. */ 902 if (smp->method == CFM_PASSKEY) { 903 memset(smp->tk, 0, sizeof(smp->tk)); 904 get_random_bytes(&passkey, sizeof(passkey)); 905 passkey %= 1000000; 906 put_unaligned_le32(passkey, smp->tk); 907 bt_dev_dbg(hcon->hdev, "PassKey: %u", passkey); 908 set_bit(SMP_FLAG_TK_VALID, &smp->flags); 909 } 910 911 if (smp->method == REQ_PASSKEY) 912 ret = mgmt_user_passkey_request(hcon->hdev, &hcon->dst, 913 hcon->type, hcon->dst_type); 914 else if (smp->method == JUST_CFM) 915 ret = mgmt_user_confirm_request(hcon->hdev, &hcon->dst, 916 hcon->type, hcon->dst_type, 917 passkey, 1); 918 else 919 ret = mgmt_user_passkey_notify(hcon->hdev, &hcon->dst, 920 hcon->type, hcon->dst_type, 921 passkey, 0); 922 923 return ret; 924 } 925 926 static u8 smp_confirm(struct smp_chan *smp) 927 { 928 struct l2cap_conn *conn = smp->conn; 929 struct smp_cmd_pairing_confirm cp; 930 int ret; 931 932 bt_dev_dbg(conn->hcon->hdev, "conn %p", conn); 933 934 ret = smp_c1(smp->tk, smp->prnd, smp->preq, smp->prsp, 935 conn->hcon->init_addr_type, &conn->hcon->init_addr, 936 conn->hcon->resp_addr_type, &conn->hcon->resp_addr, 937 cp.confirm_val); 938 if (ret) 939 return SMP_UNSPECIFIED; 940 941 clear_bit(SMP_FLAG_CFM_PENDING, &smp->flags); 942 943 smp_send_cmd(smp->conn, SMP_CMD_PAIRING_CONFIRM, sizeof(cp), &cp); 944 945 if (test_bit(SMP_FLAG_INITIATOR, &smp->flags)) 946 SMP_ALLOW_CMD(smp, SMP_CMD_PAIRING_CONFIRM); 947 else 948 SMP_ALLOW_CMD(smp, SMP_CMD_PAIRING_RANDOM); 949 950 return 0; 951 } 952 953 static u8 smp_random(struct smp_chan *smp) 954 { 955 struct l2cap_conn *conn = smp->conn; 956 struct hci_conn *hcon = conn->hcon; 957 u8 confirm[16]; 958 int ret; 959 960 bt_dev_dbg(conn->hcon->hdev, "conn %p %s", conn, 961 test_bit(SMP_FLAG_INITIATOR, &smp->flags) ? "initiator" : 962 "responder"); 963 964 ret = smp_c1(smp->tk, smp->rrnd, smp->preq, smp->prsp, 965 hcon->init_addr_type, &hcon->init_addr, 966 hcon->resp_addr_type, &hcon->resp_addr, confirm); 967 if (ret) 968 return SMP_UNSPECIFIED; 969 970 if (crypto_memneq(smp->pcnf, confirm, sizeof(smp->pcnf))) { 971 bt_dev_err(hcon->hdev, "pairing failed " 972 "(confirmation values mismatch)"); 973 return SMP_CONFIRM_FAILED; 974 } 975 976 if (test_bit(SMP_FLAG_INITIATOR, &smp->flags)) { 977 u8 stk[16]; 978 __le64 rand = 0; 979 __le16 ediv = 0; 980 981 smp_s1(smp->tk, smp->rrnd, smp->prnd, stk); 982 983 if (test_and_set_bit(HCI_CONN_ENCRYPT_PEND, &hcon->flags)) 984 return SMP_UNSPECIFIED; 985 986 hci_le_start_enc(hcon, ediv, rand, stk, smp->enc_key_size); 987 hcon->enc_key_size = smp->enc_key_size; 988 set_bit(HCI_CONN_STK_ENCRYPT, &hcon->flags); 989 } else { 990 u8 stk[16], auth; 991 __le64 rand = 0; 992 __le16 ediv = 0; 993 994 smp_send_cmd(conn, SMP_CMD_PAIRING_RANDOM, sizeof(smp->prnd), 995 smp->prnd); 996 997 smp_s1(smp->tk, smp->prnd, smp->rrnd, stk); 998 999 auth = test_bit(SMP_FLAG_MITM_AUTH, &smp->flags) ? 1 : 0; 1000 1001 /* Even though there's no _RESPONDER suffix this is the 1002 * responder STK we're adding for later lookup (the initiator 1003 * STK never needs to be stored). 1004 */ 1005 hci_add_ltk(hcon->hdev, &hcon->dst, hcon->dst_type, 1006 SMP_STK, auth, stk, smp->enc_key_size, ediv, rand); 1007 } 1008 1009 return 0; 1010 } 1011 1012 static void smp_notify_keys(struct l2cap_conn *conn) 1013 { 1014 struct l2cap_chan *chan = conn->smp; 1015 struct smp_chan *smp = chan->data; 1016 struct hci_conn *hcon = conn->hcon; 1017 struct hci_dev *hdev = hcon->hdev; 1018 struct smp_cmd_pairing *req = (void *) &smp->preq[1]; 1019 struct smp_cmd_pairing *rsp = (void *) &smp->prsp[1]; 1020 bool persistent; 1021 1022 if (hcon->type == ACL_LINK) { 1023 if (hcon->key_type == HCI_LK_DEBUG_COMBINATION) 1024 persistent = false; 1025 else 1026 persistent = !test_bit(HCI_CONN_FLUSH_KEY, 1027 &hcon->flags); 1028 } else { 1029 /* The LTKs, IRKs and CSRKs should be persistent only if 1030 * both sides had the bonding bit set in their 1031 * authentication requests. 1032 */ 1033 persistent = !!((req->auth_req & rsp->auth_req) & 1034 SMP_AUTH_BONDING); 1035 } 1036 1037 if (smp->remote_irk) { 1038 mgmt_new_irk(hdev, smp->remote_irk, persistent); 1039 1040 /* Now that user space can be considered to know the 1041 * identity address track the connection based on it 1042 * from now on (assuming this is an LE link). 1043 */ 1044 if (hcon->type == LE_LINK) { 1045 bacpy(&hcon->dst, &smp->remote_irk->bdaddr); 1046 hcon->dst_type = smp->remote_irk->addr_type; 1047 /* Use a short delay to make sure the new address is 1048 * propagated _before_ the channels. 1049 */ 1050 queue_delayed_work(hdev->workqueue, 1051 &conn->id_addr_timer, 1052 ID_ADDR_TIMEOUT); 1053 } 1054 } 1055 1056 if (smp->csrk) { 1057 smp->csrk->bdaddr_type = hcon->dst_type; 1058 bacpy(&smp->csrk->bdaddr, &hcon->dst); 1059 mgmt_new_csrk(hdev, smp->csrk, persistent); 1060 } 1061 1062 if (smp->responder_csrk) { 1063 smp->responder_csrk->bdaddr_type = hcon->dst_type; 1064 bacpy(&smp->responder_csrk->bdaddr, &hcon->dst); 1065 mgmt_new_csrk(hdev, smp->responder_csrk, persistent); 1066 } 1067 1068 if (smp->ltk) { 1069 smp->ltk->bdaddr_type = hcon->dst_type; 1070 bacpy(&smp->ltk->bdaddr, &hcon->dst); 1071 mgmt_new_ltk(hdev, smp->ltk, persistent); 1072 } 1073 1074 if (smp->responder_ltk) { 1075 smp->responder_ltk->bdaddr_type = hcon->dst_type; 1076 bacpy(&smp->responder_ltk->bdaddr, &hcon->dst); 1077 mgmt_new_ltk(hdev, smp->responder_ltk, persistent); 1078 } 1079 1080 if (smp->link_key) { 1081 struct link_key *key; 1082 u8 type; 1083 1084 if (test_bit(SMP_FLAG_DEBUG_KEY, &smp->flags)) 1085 type = HCI_LK_DEBUG_COMBINATION; 1086 else if (hcon->sec_level == BT_SECURITY_FIPS) 1087 type = HCI_LK_AUTH_COMBINATION_P256; 1088 else 1089 type = HCI_LK_UNAUTH_COMBINATION_P256; 1090 1091 key = hci_add_link_key(hdev, smp->conn->hcon, &hcon->dst, 1092 smp->link_key, type, 0, &persistent); 1093 if (key) { 1094 mgmt_new_link_key(hdev, key, persistent); 1095 1096 /* Don't keep debug keys around if the relevant 1097 * flag is not set. 1098 */ 1099 if (!hci_dev_test_flag(hdev, HCI_KEEP_DEBUG_KEYS) && 1100 key->type == HCI_LK_DEBUG_COMBINATION) { 1101 list_del_rcu(&key->list); 1102 kfree_rcu(key, rcu); 1103 } 1104 } 1105 } 1106 } 1107 1108 static void sc_add_ltk(struct smp_chan *smp) 1109 { 1110 struct hci_conn *hcon = smp->conn->hcon; 1111 u8 key_type, auth; 1112 1113 if (test_bit(SMP_FLAG_DEBUG_KEY, &smp->flags)) 1114 key_type = SMP_LTK_P256_DEBUG; 1115 else 1116 key_type = SMP_LTK_P256; 1117 1118 if (hcon->pending_sec_level == BT_SECURITY_FIPS) 1119 auth = 1; 1120 else 1121 auth = 0; 1122 1123 smp->ltk = hci_add_ltk(hcon->hdev, &hcon->dst, hcon->dst_type, 1124 key_type, auth, smp->tk, smp->enc_key_size, 1125 0, 0); 1126 } 1127 1128 static void sc_generate_link_key(struct smp_chan *smp) 1129 { 1130 /* From core spec. Spells out in ASCII as 'lebr'. */ 1131 const u8 lebr[4] = { 0x72, 0x62, 0x65, 0x6c }; 1132 1133 smp->link_key = kzalloc(16, GFP_KERNEL); 1134 if (!smp->link_key) 1135 return; 1136 1137 if (test_bit(SMP_FLAG_CT2, &smp->flags)) { 1138 /* SALT = 0x000000000000000000000000746D7031 */ 1139 const u8 salt[16] = { 0x31, 0x70, 0x6d, 0x74 }; 1140 1141 if (smp_h7(smp->tk, salt, smp->link_key)) { 1142 kfree_sensitive(smp->link_key); 1143 smp->link_key = NULL; 1144 return; 1145 } 1146 } else { 1147 /* From core spec. Spells out in ASCII as 'tmp1'. */ 1148 const u8 tmp1[4] = { 0x31, 0x70, 0x6d, 0x74 }; 1149 1150 if (smp_h6(smp->tk, tmp1, smp->link_key)) { 1151 kfree_sensitive(smp->link_key); 1152 smp->link_key = NULL; 1153 return; 1154 } 1155 } 1156 1157 if (smp_h6(smp->link_key, lebr, smp->link_key)) { 1158 kfree_sensitive(smp->link_key); 1159 smp->link_key = NULL; 1160 return; 1161 } 1162 } 1163 1164 static void smp_allow_key_dist(struct smp_chan *smp) 1165 { 1166 /* Allow the first expected phase 3 PDU. The rest of the PDUs 1167 * will be allowed in each PDU handler to ensure we receive 1168 * them in the correct order. 1169 */ 1170 if (smp->remote_key_dist & SMP_DIST_ENC_KEY) 1171 SMP_ALLOW_CMD(smp, SMP_CMD_ENCRYPT_INFO); 1172 else if (smp->remote_key_dist & SMP_DIST_ID_KEY) 1173 SMP_ALLOW_CMD(smp, SMP_CMD_IDENT_INFO); 1174 else if (smp->remote_key_dist & SMP_DIST_SIGN) 1175 SMP_ALLOW_CMD(smp, SMP_CMD_SIGN_INFO); 1176 } 1177 1178 static void sc_generate_ltk(struct smp_chan *smp) 1179 { 1180 /* From core spec. Spells out in ASCII as 'brle'. */ 1181 const u8 brle[4] = { 0x65, 0x6c, 0x72, 0x62 }; 1182 struct hci_conn *hcon = smp->conn->hcon; 1183 struct hci_dev *hdev = hcon->hdev; 1184 struct link_key *key; 1185 1186 key = hci_find_link_key(hdev, &hcon->dst); 1187 if (!key) { 1188 bt_dev_err(hdev, "no Link Key found to generate LTK"); 1189 return; 1190 } 1191 1192 if (key->type == HCI_LK_DEBUG_COMBINATION) 1193 set_bit(SMP_FLAG_DEBUG_KEY, &smp->flags); 1194 1195 if (test_bit(SMP_FLAG_CT2, &smp->flags)) { 1196 /* SALT = 0x000000000000000000000000746D7032 */ 1197 const u8 salt[16] = { 0x32, 0x70, 0x6d, 0x74 }; 1198 1199 if (smp_h7(key->val, salt, smp->tk)) 1200 return; 1201 } else { 1202 /* From core spec. Spells out in ASCII as 'tmp2'. */ 1203 const u8 tmp2[4] = { 0x32, 0x70, 0x6d, 0x74 }; 1204 1205 if (smp_h6(key->val, tmp2, smp->tk)) 1206 return; 1207 } 1208 1209 if (smp_h6(smp->tk, brle, smp->tk)) 1210 return; 1211 1212 sc_add_ltk(smp); 1213 } 1214 1215 static void smp_distribute_keys(struct smp_chan *smp) 1216 { 1217 struct smp_cmd_pairing *req, *rsp; 1218 struct l2cap_conn *conn = smp->conn; 1219 struct hci_conn *hcon = conn->hcon; 1220 struct hci_dev *hdev = hcon->hdev; 1221 __u8 *keydist; 1222 1223 bt_dev_dbg(hdev, "conn %p", conn); 1224 1225 rsp = (void *) &smp->prsp[1]; 1226 1227 /* The responder sends its keys first */ 1228 if (test_bit(SMP_FLAG_INITIATOR, &smp->flags) && 1229 (smp->remote_key_dist & KEY_DIST_MASK)) { 1230 smp_allow_key_dist(smp); 1231 return; 1232 } 1233 1234 req = (void *) &smp->preq[1]; 1235 1236 if (test_bit(SMP_FLAG_INITIATOR, &smp->flags)) { 1237 keydist = &rsp->init_key_dist; 1238 *keydist &= req->init_key_dist; 1239 } else { 1240 keydist = &rsp->resp_key_dist; 1241 *keydist &= req->resp_key_dist; 1242 } 1243 1244 if (test_bit(SMP_FLAG_SC, &smp->flags)) { 1245 if (hcon->type == LE_LINK && (*keydist & SMP_DIST_LINK_KEY)) 1246 sc_generate_link_key(smp); 1247 if (hcon->type == ACL_LINK && (*keydist & SMP_DIST_ENC_KEY)) 1248 sc_generate_ltk(smp); 1249 1250 /* Clear the keys which are generated but not distributed */ 1251 *keydist &= ~SMP_SC_NO_DIST; 1252 } 1253 1254 bt_dev_dbg(hdev, "keydist 0x%x", *keydist); 1255 1256 if (*keydist & SMP_DIST_ENC_KEY) { 1257 struct smp_cmd_encrypt_info enc; 1258 struct smp_cmd_initiator_ident ident; 1259 struct smp_ltk *ltk; 1260 u8 authenticated; 1261 __le16 ediv; 1262 __le64 rand; 1263 1264 /* Make sure we generate only the significant amount of 1265 * bytes based on the encryption key size, and set the rest 1266 * of the value to zeroes. 1267 */ 1268 get_random_bytes(enc.ltk, smp->enc_key_size); 1269 memset(enc.ltk + smp->enc_key_size, 0, 1270 sizeof(enc.ltk) - smp->enc_key_size); 1271 1272 get_random_bytes(&ediv, sizeof(ediv)); 1273 get_random_bytes(&rand, sizeof(rand)); 1274 1275 smp_send_cmd(conn, SMP_CMD_ENCRYPT_INFO, sizeof(enc), &enc); 1276 1277 authenticated = hcon->sec_level == BT_SECURITY_HIGH; 1278 ltk = hci_add_ltk(hdev, &hcon->dst, hcon->dst_type, 1279 SMP_LTK_RESPONDER, authenticated, enc.ltk, 1280 smp->enc_key_size, ediv, rand); 1281 smp->responder_ltk = ltk; 1282 1283 ident.ediv = ediv; 1284 ident.rand = rand; 1285 1286 smp_send_cmd(conn, SMP_CMD_INITIATOR_IDENT, sizeof(ident), 1287 &ident); 1288 1289 *keydist &= ~SMP_DIST_ENC_KEY; 1290 } 1291 1292 if (*keydist & SMP_DIST_ID_KEY) { 1293 struct smp_cmd_ident_addr_info addrinfo; 1294 struct smp_cmd_ident_info idinfo; 1295 1296 memcpy(idinfo.irk, hdev->irk, sizeof(idinfo.irk)); 1297 1298 smp_send_cmd(conn, SMP_CMD_IDENT_INFO, sizeof(idinfo), &idinfo); 1299 1300 /* The hci_conn contains the local identity address 1301 * after the connection has been established. 1302 * 1303 * This is true even when the connection has been 1304 * established using a resolvable random address. 1305 */ 1306 bacpy(&addrinfo.bdaddr, &hcon->src); 1307 addrinfo.addr_type = hcon->src_type; 1308 1309 smp_send_cmd(conn, SMP_CMD_IDENT_ADDR_INFO, sizeof(addrinfo), 1310 &addrinfo); 1311 1312 *keydist &= ~SMP_DIST_ID_KEY; 1313 } 1314 1315 if (*keydist & SMP_DIST_SIGN) { 1316 struct smp_cmd_sign_info sign; 1317 struct smp_csrk *csrk; 1318 1319 /* Generate a new random key */ 1320 get_random_bytes(sign.csrk, sizeof(sign.csrk)); 1321 1322 csrk = kzalloc_obj(*csrk); 1323 if (csrk) { 1324 if (hcon->sec_level > BT_SECURITY_MEDIUM) 1325 csrk->type = MGMT_CSRK_LOCAL_AUTHENTICATED; 1326 else 1327 csrk->type = MGMT_CSRK_LOCAL_UNAUTHENTICATED; 1328 memcpy(csrk->val, sign.csrk, sizeof(csrk->val)); 1329 } 1330 smp->responder_csrk = csrk; 1331 1332 smp_send_cmd(conn, SMP_CMD_SIGN_INFO, sizeof(sign), &sign); 1333 1334 *keydist &= ~SMP_DIST_SIGN; 1335 } 1336 1337 /* If there are still keys to be received wait for them */ 1338 if (smp->remote_key_dist & KEY_DIST_MASK) { 1339 smp_allow_key_dist(smp); 1340 return; 1341 } 1342 1343 set_bit(SMP_FLAG_COMPLETE, &smp->flags); 1344 smp_notify_keys(conn); 1345 1346 smp_chan_destroy(conn); 1347 } 1348 1349 static void smp_timeout(struct work_struct *work) 1350 { 1351 struct smp_chan *smp = container_of(work, struct smp_chan, 1352 security_timer.work); 1353 struct l2cap_conn *conn = smp->conn; 1354 1355 bt_dev_dbg(conn->hcon->hdev, "conn %p", conn); 1356 1357 hci_disconnect(conn->hcon, HCI_ERROR_AUTH_FAILURE); 1358 } 1359 1360 static struct smp_chan *smp_chan_create(struct l2cap_conn *conn) 1361 { 1362 struct hci_conn *hcon = conn->hcon; 1363 struct l2cap_chan *chan = conn->smp; 1364 struct smp_chan *smp; 1365 1366 smp = kzalloc_obj(*smp, GFP_ATOMIC); 1367 if (!smp) 1368 return NULL; 1369 1370 smp->tfm_ecdh = crypto_alloc_kpp("ecdh-nist-p256", 0, 0); 1371 if (IS_ERR(smp->tfm_ecdh)) { 1372 bt_dev_err(hcon->hdev, "Unable to create ECDH crypto context"); 1373 goto zfree_smp; 1374 } 1375 1376 smp->conn = conn; 1377 chan->data = smp; 1378 1379 SMP_ALLOW_CMD(smp, SMP_CMD_PAIRING_FAIL); 1380 1381 INIT_DELAYED_WORK(&smp->security_timer, smp_timeout); 1382 1383 hci_conn_hold(hcon); 1384 1385 return smp; 1386 1387 zfree_smp: 1388 kfree_sensitive(smp); 1389 return NULL; 1390 } 1391 1392 static int sc_mackey_and_ltk(struct smp_chan *smp, u8 mackey[16], u8 ltk[16]) 1393 { 1394 struct hci_conn *hcon = smp->conn->hcon; 1395 u8 *na, *nb, a[7], b[7]; 1396 1397 if (test_bit(SMP_FLAG_INITIATOR, &smp->flags)) { 1398 na = smp->prnd; 1399 nb = smp->rrnd; 1400 } else { 1401 na = smp->rrnd; 1402 nb = smp->prnd; 1403 } 1404 1405 memcpy(a, &hcon->init_addr, 6); 1406 memcpy(b, &hcon->resp_addr, 6); 1407 a[6] = hcon->init_addr_type; 1408 b[6] = hcon->resp_addr_type; 1409 1410 return smp_f5(smp->dhkey, na, nb, a, b, mackey, ltk); 1411 } 1412 1413 static void sc_dhkey_check(struct smp_chan *smp) 1414 { 1415 struct hci_conn *hcon = smp->conn->hcon; 1416 struct smp_cmd_dhkey_check check; 1417 u8 a[7], b[7], *local_addr, *remote_addr; 1418 u8 io_cap[3], r[16]; 1419 1420 memcpy(a, &hcon->init_addr, 6); 1421 memcpy(b, &hcon->resp_addr, 6); 1422 a[6] = hcon->init_addr_type; 1423 b[6] = hcon->resp_addr_type; 1424 1425 if (test_bit(SMP_FLAG_INITIATOR, &smp->flags)) { 1426 local_addr = a; 1427 remote_addr = b; 1428 memcpy(io_cap, &smp->preq[1], 3); 1429 } else { 1430 local_addr = b; 1431 remote_addr = a; 1432 memcpy(io_cap, &smp->prsp[1], 3); 1433 } 1434 1435 memset(r, 0, sizeof(r)); 1436 1437 if (smp->method == REQ_PASSKEY || smp->method == DSP_PASSKEY) 1438 put_unaligned_le32(hcon->passkey_notify, r); 1439 1440 if (smp->method == REQ_OOB) 1441 memcpy(r, smp->rr, 16); 1442 1443 smp_f6(smp->mackey, smp->prnd, smp->rrnd, r, io_cap, local_addr, 1444 remote_addr, check.e); 1445 1446 smp_send_cmd(smp->conn, SMP_CMD_DHKEY_CHECK, sizeof(check), &check); 1447 } 1448 1449 static u8 sc_passkey_send_confirm(struct smp_chan *smp) 1450 { 1451 struct l2cap_conn *conn = smp->conn; 1452 struct hci_conn *hcon = conn->hcon; 1453 struct smp_cmd_pairing_confirm cfm; 1454 u8 r; 1455 1456 r = ((hcon->passkey_notify >> smp->passkey_round) & 0x01); 1457 r |= 0x80; 1458 1459 get_random_bytes(smp->prnd, sizeof(smp->prnd)); 1460 1461 if (smp_f4(smp->local_pk, smp->remote_pk, smp->prnd, r, 1462 cfm.confirm_val)) 1463 return SMP_UNSPECIFIED; 1464 1465 smp_send_cmd(conn, SMP_CMD_PAIRING_CONFIRM, sizeof(cfm), &cfm); 1466 1467 return 0; 1468 } 1469 1470 static u8 sc_passkey_round(struct smp_chan *smp, u8 smp_op) 1471 { 1472 struct l2cap_conn *conn = smp->conn; 1473 struct hci_conn *hcon = conn->hcon; 1474 struct hci_dev *hdev = hcon->hdev; 1475 u8 cfm[16], r; 1476 1477 /* Ignore the PDU if we've already done 20 rounds (0 - 19) */ 1478 if (smp->passkey_round >= 20) 1479 return 0; 1480 1481 switch (smp_op) { 1482 case SMP_CMD_PAIRING_RANDOM: 1483 r = ((hcon->passkey_notify >> smp->passkey_round) & 0x01); 1484 r |= 0x80; 1485 1486 if (smp_f4(smp->remote_pk, smp->local_pk, smp->rrnd, r, cfm)) 1487 return SMP_UNSPECIFIED; 1488 1489 if (crypto_memneq(smp->pcnf, cfm, 16)) 1490 return SMP_CONFIRM_FAILED; 1491 1492 smp->passkey_round++; 1493 1494 if (smp->passkey_round == 20) { 1495 /* Generate MacKey and LTK */ 1496 if (sc_mackey_and_ltk(smp, smp->mackey, smp->tk)) 1497 return SMP_UNSPECIFIED; 1498 } 1499 1500 /* The round is only complete when the initiator 1501 * receives pairing random. 1502 */ 1503 if (!test_bit(SMP_FLAG_INITIATOR, &smp->flags)) { 1504 smp_send_cmd(conn, SMP_CMD_PAIRING_RANDOM, 1505 sizeof(smp->prnd), smp->prnd); 1506 if (smp->passkey_round == 20) 1507 SMP_ALLOW_CMD(smp, SMP_CMD_DHKEY_CHECK); 1508 else 1509 SMP_ALLOW_CMD(smp, SMP_CMD_PAIRING_CONFIRM); 1510 return 0; 1511 } 1512 1513 /* Start the next round */ 1514 if (smp->passkey_round != 20) 1515 return sc_passkey_round(smp, 0); 1516 1517 /* Passkey rounds are complete - start DHKey Check */ 1518 sc_dhkey_check(smp); 1519 SMP_ALLOW_CMD(smp, SMP_CMD_DHKEY_CHECK); 1520 1521 break; 1522 1523 case SMP_CMD_PAIRING_CONFIRM: 1524 if (test_bit(SMP_FLAG_WAIT_USER, &smp->flags)) { 1525 set_bit(SMP_FLAG_CFM_PENDING, &smp->flags); 1526 return 0; 1527 } 1528 1529 SMP_ALLOW_CMD(smp, SMP_CMD_PAIRING_RANDOM); 1530 1531 if (test_bit(SMP_FLAG_INITIATOR, &smp->flags)) { 1532 smp_send_cmd(conn, SMP_CMD_PAIRING_RANDOM, 1533 sizeof(smp->prnd), smp->prnd); 1534 return 0; 1535 } 1536 1537 return sc_passkey_send_confirm(smp); 1538 1539 case SMP_CMD_PUBLIC_KEY: 1540 default: 1541 /* Initiating device starts the round */ 1542 if (!test_bit(SMP_FLAG_INITIATOR, &smp->flags)) 1543 return 0; 1544 1545 bt_dev_dbg(hdev, "Starting passkey round %u", 1546 smp->passkey_round + 1); 1547 1548 SMP_ALLOW_CMD(smp, SMP_CMD_PAIRING_CONFIRM); 1549 1550 return sc_passkey_send_confirm(smp); 1551 } 1552 1553 return 0; 1554 } 1555 1556 static int sc_user_reply(struct smp_chan *smp, u16 mgmt_op, __le32 passkey) 1557 { 1558 struct l2cap_conn *conn = smp->conn; 1559 struct hci_conn *hcon = conn->hcon; 1560 u8 smp_op; 1561 1562 clear_bit(SMP_FLAG_WAIT_USER, &smp->flags); 1563 1564 switch (mgmt_op) { 1565 case MGMT_OP_USER_PASSKEY_NEG_REPLY: 1566 smp_failure(smp->conn, SMP_PASSKEY_ENTRY_FAILED); 1567 return 0; 1568 case MGMT_OP_USER_CONFIRM_NEG_REPLY: 1569 smp_failure(smp->conn, SMP_NUMERIC_COMP_FAILED); 1570 return 0; 1571 case MGMT_OP_USER_PASSKEY_REPLY: 1572 hcon->passkey_notify = le32_to_cpu(passkey); 1573 smp->passkey_round = 0; 1574 1575 if (test_and_clear_bit(SMP_FLAG_CFM_PENDING, &smp->flags)) 1576 smp_op = SMP_CMD_PAIRING_CONFIRM; 1577 else 1578 smp_op = 0; 1579 1580 if (sc_passkey_round(smp, smp_op)) 1581 return -EIO; 1582 1583 return 0; 1584 } 1585 1586 /* Initiator sends DHKey check first */ 1587 if (test_bit(SMP_FLAG_INITIATOR, &smp->flags)) { 1588 sc_dhkey_check(smp); 1589 SMP_ALLOW_CMD(smp, SMP_CMD_DHKEY_CHECK); 1590 } else if (test_and_clear_bit(SMP_FLAG_DHKEY_PENDING, &smp->flags)) { 1591 sc_dhkey_check(smp); 1592 sc_add_ltk(smp); 1593 } 1594 1595 return 0; 1596 } 1597 1598 int smp_user_confirm_reply(struct hci_conn *hcon, u16 mgmt_op, __le32 passkey) 1599 { 1600 struct l2cap_conn *conn = hcon->l2cap_data; 1601 struct l2cap_chan *chan; 1602 struct smp_chan *smp; 1603 u32 value; 1604 int err; 1605 1606 if (!conn) 1607 return -ENOTCONN; 1608 1609 bt_dev_dbg(conn->hcon->hdev, ""); 1610 1611 chan = conn->smp; 1612 if (!chan) 1613 return -ENOTCONN; 1614 1615 l2cap_chan_lock(chan); 1616 if (!chan->data) { 1617 err = -ENOTCONN; 1618 goto unlock; 1619 } 1620 1621 smp = chan->data; 1622 1623 if (test_bit(SMP_FLAG_SC, &smp->flags)) { 1624 err = sc_user_reply(smp, mgmt_op, passkey); 1625 goto unlock; 1626 } 1627 1628 switch (mgmt_op) { 1629 case MGMT_OP_USER_PASSKEY_REPLY: 1630 value = le32_to_cpu(passkey); 1631 memset(smp->tk, 0, sizeof(smp->tk)); 1632 bt_dev_dbg(conn->hcon->hdev, "PassKey: %u", value); 1633 put_unaligned_le32(value, smp->tk); 1634 fallthrough; 1635 case MGMT_OP_USER_CONFIRM_REPLY: 1636 set_bit(SMP_FLAG_TK_VALID, &smp->flags); 1637 break; 1638 case MGMT_OP_USER_PASSKEY_NEG_REPLY: 1639 case MGMT_OP_USER_CONFIRM_NEG_REPLY: 1640 smp_failure(conn, SMP_PASSKEY_ENTRY_FAILED); 1641 err = 0; 1642 goto unlock; 1643 default: 1644 smp_failure(conn, SMP_PASSKEY_ENTRY_FAILED); 1645 err = -EOPNOTSUPP; 1646 goto unlock; 1647 } 1648 1649 err = 0; 1650 1651 /* If it is our turn to send Pairing Confirm, do so now */ 1652 if (test_bit(SMP_FLAG_CFM_PENDING, &smp->flags)) { 1653 u8 rsp = smp_confirm(smp); 1654 if (rsp) 1655 smp_failure(conn, rsp); 1656 } 1657 1658 unlock: 1659 l2cap_chan_unlock(chan); 1660 return err; 1661 } 1662 1663 static void build_bredr_pairing_cmd(struct smp_chan *smp, 1664 struct smp_cmd_pairing *req, 1665 struct smp_cmd_pairing *rsp) 1666 { 1667 struct l2cap_conn *conn = smp->conn; 1668 struct hci_dev *hdev = conn->hcon->hdev; 1669 u8 local_dist = 0, remote_dist = 0; 1670 1671 if (hci_dev_test_flag(hdev, HCI_BONDABLE)) { 1672 local_dist = SMP_DIST_ENC_KEY | SMP_DIST_SIGN; 1673 remote_dist = SMP_DIST_ENC_KEY | SMP_DIST_SIGN; 1674 } 1675 1676 if (hci_dev_test_flag(hdev, HCI_RPA_RESOLVING)) 1677 remote_dist |= SMP_DIST_ID_KEY; 1678 1679 if (hci_dev_test_flag(hdev, HCI_PRIVACY)) 1680 local_dist |= SMP_DIST_ID_KEY; 1681 1682 if (!rsp) { 1683 memset(req, 0, sizeof(*req)); 1684 1685 req->auth_req = SMP_AUTH_CT2; 1686 req->init_key_dist = local_dist; 1687 req->resp_key_dist = remote_dist; 1688 req->max_key_size = conn->hcon->enc_key_size; 1689 1690 smp->remote_key_dist = remote_dist; 1691 1692 return; 1693 } 1694 1695 memset(rsp, 0, sizeof(*rsp)); 1696 1697 rsp->auth_req = SMP_AUTH_CT2; 1698 rsp->max_key_size = conn->hcon->enc_key_size; 1699 rsp->init_key_dist = req->init_key_dist & remote_dist; 1700 rsp->resp_key_dist = req->resp_key_dist & local_dist; 1701 1702 smp->remote_key_dist = rsp->init_key_dist; 1703 } 1704 1705 static u8 smp_cmd_pairing_req(struct l2cap_conn *conn, struct sk_buff *skb) 1706 { 1707 struct smp_cmd_pairing rsp, *req = (void *) skb->data; 1708 struct l2cap_chan *chan = conn->smp; 1709 struct hci_dev *hdev = conn->hcon->hdev; 1710 struct smp_chan *smp = chan->data; 1711 u8 key_size, auth, sec_level; 1712 int ret; 1713 1714 bt_dev_dbg(hdev, "conn %p", conn); 1715 1716 if (skb->len < sizeof(*req)) 1717 return SMP_INVALID_PARAMS; 1718 1719 if (smp && test_bit(SMP_FLAG_INITIATOR, &smp->flags)) 1720 return SMP_CMD_NOTSUPP; 1721 1722 if (!smp) { 1723 smp = smp_chan_create(conn); 1724 if (!smp) 1725 return SMP_UNSPECIFIED; 1726 } 1727 1728 /* We didn't start the pairing, so match remote */ 1729 auth = req->auth_req & AUTH_REQ_MASK(hdev); 1730 1731 if (!hci_dev_test_flag(hdev, HCI_BONDABLE) && 1732 (auth & SMP_AUTH_BONDING)) 1733 return SMP_PAIRING_NOTSUPP; 1734 1735 if (hci_dev_test_flag(hdev, HCI_SC_ONLY) && !(auth & SMP_AUTH_SC)) 1736 return SMP_AUTH_REQUIREMENTS; 1737 1738 smp->preq[0] = SMP_CMD_PAIRING_REQ; 1739 memcpy(&smp->preq[1], req, sizeof(*req)); 1740 skb_pull(skb, sizeof(*req)); 1741 1742 /* If the remote side's OOB flag is set it means it has 1743 * successfully received our local OOB data - therefore set the 1744 * flag to indicate that local OOB is in use. 1745 */ 1746 if (req->oob_flag == SMP_OOB_PRESENT && SMP_DEV(hdev)->local_oob) 1747 set_bit(SMP_FLAG_LOCAL_OOB, &smp->flags); 1748 1749 /* SMP over BR/EDR requires special treatment */ 1750 if (conn->hcon->type == ACL_LINK) { 1751 /* We must have a BR/EDR SC link */ 1752 if (!test_bit(HCI_CONN_AES_CCM, &conn->hcon->flags) && 1753 !hci_dev_test_flag(hdev, HCI_FORCE_BREDR_SMP)) 1754 return SMP_CROSS_TRANSP_NOT_ALLOWED; 1755 1756 set_bit(SMP_FLAG_SC, &smp->flags); 1757 1758 build_bredr_pairing_cmd(smp, req, &rsp); 1759 1760 if (req->auth_req & SMP_AUTH_CT2) 1761 set_bit(SMP_FLAG_CT2, &smp->flags); 1762 1763 key_size = min(req->max_key_size, rsp.max_key_size); 1764 if (check_enc_key_size(conn, key_size)) 1765 return SMP_ENC_KEY_SIZE; 1766 1767 /* Clear bits which are generated but not distributed */ 1768 smp->remote_key_dist &= ~SMP_SC_NO_DIST; 1769 1770 smp->prsp[0] = SMP_CMD_PAIRING_RSP; 1771 memcpy(&smp->prsp[1], &rsp, sizeof(rsp)); 1772 smp_send_cmd(conn, SMP_CMD_PAIRING_RSP, sizeof(rsp), &rsp); 1773 1774 smp_distribute_keys(smp); 1775 return 0; 1776 } 1777 1778 build_pairing_cmd(conn, req, &rsp, auth); 1779 1780 if (rsp.auth_req & SMP_AUTH_SC) { 1781 set_bit(SMP_FLAG_SC, &smp->flags); 1782 1783 if (rsp.auth_req & SMP_AUTH_CT2) 1784 set_bit(SMP_FLAG_CT2, &smp->flags); 1785 } 1786 1787 if (conn->hcon->io_capability == HCI_IO_NO_INPUT_OUTPUT) 1788 sec_level = BT_SECURITY_MEDIUM; 1789 else 1790 sec_level = authreq_to_seclevel(auth); 1791 1792 if (sec_level > conn->hcon->pending_sec_level) 1793 conn->hcon->pending_sec_level = sec_level; 1794 1795 /* If we need MITM check that it can be achieved. */ 1796 if (conn->hcon->pending_sec_level >= BT_SECURITY_HIGH) { 1797 u8 method; 1798 1799 method = get_auth_method(smp, conn->hcon->io_capability, 1800 req->io_capability); 1801 if (method == JUST_WORKS || method == JUST_CFM) 1802 return SMP_AUTH_REQUIREMENTS; 1803 1804 /* Force MITM bit if it isn't set by the initiator. */ 1805 auth |= SMP_AUTH_MITM; 1806 rsp.auth_req |= SMP_AUTH_MITM; 1807 } 1808 1809 key_size = min(req->max_key_size, rsp.max_key_size); 1810 if (check_enc_key_size(conn, key_size)) 1811 return SMP_ENC_KEY_SIZE; 1812 1813 get_random_bytes(smp->prnd, sizeof(smp->prnd)); 1814 1815 smp->prsp[0] = SMP_CMD_PAIRING_RSP; 1816 memcpy(&smp->prsp[1], &rsp, sizeof(rsp)); 1817 1818 smp_send_cmd(conn, SMP_CMD_PAIRING_RSP, sizeof(rsp), &rsp); 1819 1820 clear_bit(SMP_FLAG_INITIATOR, &smp->flags); 1821 1822 /* Strictly speaking we shouldn't allow Pairing Confirm for the 1823 * SC case, however some implementations incorrectly copy RFU auth 1824 * req bits from our security request, which may create a false 1825 * positive SC enablement. 1826 */ 1827 SMP_ALLOW_CMD(smp, SMP_CMD_PAIRING_CONFIRM); 1828 1829 if (test_bit(SMP_FLAG_SC, &smp->flags)) { 1830 SMP_ALLOW_CMD(smp, SMP_CMD_PUBLIC_KEY); 1831 /* Clear bits which are generated but not distributed */ 1832 smp->remote_key_dist &= ~SMP_SC_NO_DIST; 1833 /* Wait for Public Key from Initiating Device */ 1834 return 0; 1835 } 1836 1837 /* Request setup of TK */ 1838 ret = tk_request(conn, 0, auth, rsp.io_capability, req->io_capability); 1839 if (ret) 1840 return SMP_UNSPECIFIED; 1841 1842 return 0; 1843 } 1844 1845 static u8 sc_send_public_key(struct smp_chan *smp) 1846 { 1847 struct hci_dev *hdev = smp->conn->hcon->hdev; 1848 1849 bt_dev_dbg(hdev, ""); 1850 1851 if (test_bit(SMP_FLAG_LOCAL_OOB, &smp->flags)) { 1852 struct l2cap_chan *chan = hdev->smp_data; 1853 struct smp_dev *smp_dev; 1854 1855 if (!chan || !chan->data) 1856 return SMP_UNSPECIFIED; 1857 1858 smp_dev = chan->data; 1859 1860 memcpy(smp->local_pk, smp_dev->local_pk, 64); 1861 memcpy(smp->lr, smp_dev->local_rand, 16); 1862 1863 if (smp_dev->debug_key) 1864 set_bit(SMP_FLAG_DEBUG_KEY, &smp->flags); 1865 1866 goto done; 1867 } 1868 1869 if (hci_dev_test_flag(hdev, HCI_USE_DEBUG_KEYS)) { 1870 bt_dev_dbg(hdev, "Using debug keys"); 1871 if (set_ecdh_privkey(smp->tfm_ecdh, debug_sk)) 1872 return SMP_UNSPECIFIED; 1873 memcpy(smp->local_pk, debug_pk, 64); 1874 set_bit(SMP_FLAG_DEBUG_KEY, &smp->flags); 1875 } else { 1876 while (true) { 1877 /* Generate key pair for Secure Connections */ 1878 if (generate_ecdh_keys(smp->tfm_ecdh, smp->local_pk)) 1879 return SMP_UNSPECIFIED; 1880 1881 /* This is unlikely, but we need to check that 1882 * we didn't accidentally generate a debug key. 1883 */ 1884 if (crypto_memneq(smp->local_pk, debug_pk, 64)) 1885 break; 1886 } 1887 } 1888 1889 done: 1890 SMP_DBG("Local Public Key X: %32phN", smp->local_pk); 1891 SMP_DBG("Local Public Key Y: %32phN", smp->local_pk + 32); 1892 1893 smp_send_cmd(smp->conn, SMP_CMD_PUBLIC_KEY, 64, smp->local_pk); 1894 1895 return 0; 1896 } 1897 1898 static u8 smp_cmd_pairing_rsp(struct l2cap_conn *conn, struct sk_buff *skb) 1899 { 1900 struct smp_cmd_pairing *req, *rsp = (void *) skb->data; 1901 struct l2cap_chan *chan = conn->smp; 1902 struct smp_chan *smp = chan->data; 1903 struct hci_dev *hdev = conn->hcon->hdev; 1904 u8 key_size, auth; 1905 int ret; 1906 1907 bt_dev_dbg(hdev, "conn %p", conn); 1908 1909 if (skb->len < sizeof(*rsp)) 1910 return SMP_INVALID_PARAMS; 1911 1912 if (!test_bit(SMP_FLAG_INITIATOR, &smp->flags)) 1913 return SMP_CMD_NOTSUPP; 1914 1915 skb_pull(skb, sizeof(*rsp)); 1916 1917 req = (void *) &smp->preq[1]; 1918 1919 key_size = min(req->max_key_size, rsp->max_key_size); 1920 if (check_enc_key_size(conn, key_size)) 1921 return SMP_ENC_KEY_SIZE; 1922 1923 auth = rsp->auth_req & AUTH_REQ_MASK(hdev); 1924 1925 if (hci_dev_test_flag(hdev, HCI_SC_ONLY) && !(auth & SMP_AUTH_SC)) 1926 return SMP_AUTH_REQUIREMENTS; 1927 1928 /* If the remote side's OOB flag is set it means it has 1929 * successfully received our local OOB data - therefore set the 1930 * flag to indicate that local OOB is in use. 1931 */ 1932 if (rsp->oob_flag == SMP_OOB_PRESENT && SMP_DEV(hdev)->local_oob) 1933 set_bit(SMP_FLAG_LOCAL_OOB, &smp->flags); 1934 1935 smp->prsp[0] = SMP_CMD_PAIRING_RSP; 1936 memcpy(&smp->prsp[1], rsp, sizeof(*rsp)); 1937 1938 /* Update remote key distribution in case the remote cleared 1939 * some bits that we had enabled in our request. 1940 */ 1941 smp->remote_key_dist &= rsp->resp_key_dist; 1942 1943 if ((req->auth_req & SMP_AUTH_CT2) && (auth & SMP_AUTH_CT2)) 1944 set_bit(SMP_FLAG_CT2, &smp->flags); 1945 1946 /* For BR/EDR this means we're done and can start phase 3 */ 1947 if (conn->hcon->type == ACL_LINK) { 1948 /* Clear bits which are generated but not distributed */ 1949 smp->remote_key_dist &= ~SMP_SC_NO_DIST; 1950 smp_distribute_keys(smp); 1951 return 0; 1952 } 1953 1954 if ((req->auth_req & SMP_AUTH_SC) && (auth & SMP_AUTH_SC)) 1955 set_bit(SMP_FLAG_SC, &smp->flags); 1956 else if (conn->hcon->pending_sec_level > BT_SECURITY_HIGH) 1957 conn->hcon->pending_sec_level = BT_SECURITY_HIGH; 1958 1959 /* If we need MITM check that it can be achieved */ 1960 if (conn->hcon->pending_sec_level >= BT_SECURITY_HIGH) { 1961 u8 method; 1962 1963 method = get_auth_method(smp, req->io_capability, 1964 rsp->io_capability); 1965 if (method == JUST_WORKS || method == JUST_CFM) 1966 return SMP_AUTH_REQUIREMENTS; 1967 } 1968 1969 get_random_bytes(smp->prnd, sizeof(smp->prnd)); 1970 1971 /* Update remote key distribution in case the remote cleared 1972 * some bits that we had enabled in our request. 1973 */ 1974 smp->remote_key_dist &= rsp->resp_key_dist; 1975 1976 if (test_bit(SMP_FLAG_SC, &smp->flags)) { 1977 /* Clear bits which are generated but not distributed */ 1978 smp->remote_key_dist &= ~SMP_SC_NO_DIST; 1979 SMP_ALLOW_CMD(smp, SMP_CMD_PUBLIC_KEY); 1980 return sc_send_public_key(smp); 1981 } 1982 1983 auth |= req->auth_req; 1984 1985 ret = tk_request(conn, 0, auth, req->io_capability, rsp->io_capability); 1986 if (ret) 1987 return SMP_UNSPECIFIED; 1988 1989 set_bit(SMP_FLAG_CFM_PENDING, &smp->flags); 1990 1991 /* Can't compose response until we have been confirmed */ 1992 if (test_bit(SMP_FLAG_TK_VALID, &smp->flags)) 1993 return smp_confirm(smp); 1994 1995 return 0; 1996 } 1997 1998 static u8 sc_check_confirm(struct smp_chan *smp) 1999 { 2000 struct l2cap_conn *conn = smp->conn; 2001 2002 bt_dev_dbg(conn->hcon->hdev, ""); 2003 2004 if (smp->method == REQ_PASSKEY || smp->method == DSP_PASSKEY) 2005 return sc_passkey_round(smp, SMP_CMD_PAIRING_CONFIRM); 2006 2007 if (test_bit(SMP_FLAG_INITIATOR, &smp->flags)) { 2008 smp_send_cmd(conn, SMP_CMD_PAIRING_RANDOM, sizeof(smp->prnd), 2009 smp->prnd); 2010 SMP_ALLOW_CMD(smp, SMP_CMD_PAIRING_RANDOM); 2011 } 2012 2013 return 0; 2014 } 2015 2016 /* Work-around for some implementations that incorrectly copy RFU bits 2017 * from our security request and thereby create the impression that 2018 * we're doing SC when in fact the remote doesn't support it. 2019 */ 2020 static int fixup_sc_false_positive(struct smp_chan *smp) 2021 { 2022 struct l2cap_conn *conn = smp->conn; 2023 struct hci_conn *hcon = conn->hcon; 2024 struct hci_dev *hdev = hcon->hdev; 2025 struct smp_cmd_pairing *req, *rsp; 2026 u8 auth; 2027 2028 /* The issue is only observed when we're in responder role */ 2029 if (test_bit(SMP_FLAG_INITIATOR, &smp->flags)) 2030 return SMP_UNSPECIFIED; 2031 2032 if (hci_dev_test_flag(hdev, HCI_SC_ONLY)) { 2033 bt_dev_err(hdev, "refusing legacy fallback in SC-only mode"); 2034 return SMP_UNSPECIFIED; 2035 } 2036 2037 bt_dev_err(hdev, "trying to fall back to legacy SMP"); 2038 2039 req = (void *) &smp->preq[1]; 2040 rsp = (void *) &smp->prsp[1]; 2041 2042 /* Rebuild key dist flags which may have been cleared for SC */ 2043 smp->remote_key_dist = (req->init_key_dist & rsp->resp_key_dist); 2044 2045 auth = req->auth_req & AUTH_REQ_MASK(hdev); 2046 2047 if (tk_request(conn, 0, auth, rsp->io_capability, req->io_capability)) { 2048 bt_dev_err(hdev, "failed to fall back to legacy SMP"); 2049 return SMP_UNSPECIFIED; 2050 } 2051 2052 clear_bit(SMP_FLAG_SC, &smp->flags); 2053 2054 return 0; 2055 } 2056 2057 static u8 smp_cmd_pairing_confirm(struct l2cap_conn *conn, struct sk_buff *skb) 2058 { 2059 struct l2cap_chan *chan = conn->smp; 2060 struct smp_chan *smp = chan->data; 2061 struct hci_conn *hcon = conn->hcon; 2062 struct hci_dev *hdev = hcon->hdev; 2063 2064 bt_dev_dbg(hdev, "conn %p %s", conn, 2065 test_bit(SMP_FLAG_INITIATOR, &smp->flags) ? "initiator" : 2066 "responder"); 2067 2068 if (skb->len < sizeof(smp->pcnf)) 2069 return SMP_INVALID_PARAMS; 2070 2071 memcpy(smp->pcnf, skb->data, sizeof(smp->pcnf)); 2072 skb_pull(skb, sizeof(smp->pcnf)); 2073 2074 if (test_bit(SMP_FLAG_SC, &smp->flags)) { 2075 int ret; 2076 2077 /* Public Key exchange must happen before any other steps */ 2078 if (test_bit(SMP_FLAG_REMOTE_PK, &smp->flags)) 2079 return sc_check_confirm(smp); 2080 2081 bt_dev_err(hdev, "Unexpected SMP Pairing Confirm"); 2082 2083 ret = fixup_sc_false_positive(smp); 2084 if (ret) 2085 return ret; 2086 } 2087 2088 if (test_bit(SMP_FLAG_INITIATOR, &smp->flags)) { 2089 smp_send_cmd(conn, SMP_CMD_PAIRING_RANDOM, sizeof(smp->prnd), 2090 smp->prnd); 2091 SMP_ALLOW_CMD(smp, SMP_CMD_PAIRING_RANDOM); 2092 return 0; 2093 } 2094 2095 if (test_bit(SMP_FLAG_TK_VALID, &smp->flags)) 2096 return smp_confirm(smp); 2097 2098 set_bit(SMP_FLAG_CFM_PENDING, &smp->flags); 2099 2100 return 0; 2101 } 2102 2103 static u8 smp_cmd_pairing_random(struct l2cap_conn *conn, struct sk_buff *skb) 2104 { 2105 struct l2cap_chan *chan = conn->smp; 2106 struct smp_chan *smp = chan->data; 2107 struct hci_conn *hcon = conn->hcon; 2108 u8 *pkax, *pkbx, *na, *nb, confirm_hint; 2109 u32 passkey = 0; 2110 int err; 2111 2112 bt_dev_dbg(hcon->hdev, "conn %p", conn); 2113 2114 if (skb->len < sizeof(smp->rrnd)) 2115 return SMP_INVALID_PARAMS; 2116 2117 memcpy(smp->rrnd, skb->data, sizeof(smp->rrnd)); 2118 skb_pull(skb, sizeof(smp->rrnd)); 2119 2120 if (!test_bit(SMP_FLAG_SC, &smp->flags)) 2121 return smp_random(smp); 2122 2123 if (test_bit(SMP_FLAG_INITIATOR, &smp->flags)) { 2124 pkax = smp->local_pk; 2125 pkbx = smp->remote_pk; 2126 na = smp->prnd; 2127 nb = smp->rrnd; 2128 } else { 2129 pkax = smp->remote_pk; 2130 pkbx = smp->local_pk; 2131 na = smp->rrnd; 2132 nb = smp->prnd; 2133 } 2134 2135 if (smp->method == REQ_OOB) { 2136 if (!test_bit(SMP_FLAG_INITIATOR, &smp->flags)) 2137 smp_send_cmd(conn, SMP_CMD_PAIRING_RANDOM, 2138 sizeof(smp->prnd), smp->prnd); 2139 SMP_ALLOW_CMD(smp, SMP_CMD_DHKEY_CHECK); 2140 goto mackey_and_ltk; 2141 } 2142 2143 /* Passkey entry has special treatment */ 2144 if (smp->method == REQ_PASSKEY || smp->method == DSP_PASSKEY) 2145 return sc_passkey_round(smp, SMP_CMD_PAIRING_RANDOM); 2146 2147 if (test_bit(SMP_FLAG_INITIATOR, &smp->flags)) { 2148 u8 cfm[16]; 2149 2150 err = smp_f4(smp->remote_pk, smp->local_pk, smp->rrnd, 0, cfm); 2151 if (err) 2152 return SMP_UNSPECIFIED; 2153 2154 if (crypto_memneq(smp->pcnf, cfm, 16)) 2155 return SMP_CONFIRM_FAILED; 2156 } else { 2157 smp_send_cmd(conn, SMP_CMD_PAIRING_RANDOM, sizeof(smp->prnd), 2158 smp->prnd); 2159 SMP_ALLOW_CMD(smp, SMP_CMD_DHKEY_CHECK); 2160 } 2161 2162 mackey_and_ltk: 2163 /* Generate MacKey and LTK */ 2164 err = sc_mackey_and_ltk(smp, smp->mackey, smp->tk); 2165 if (err) 2166 return SMP_UNSPECIFIED; 2167 2168 if (smp->method == REQ_OOB) { 2169 if (test_bit(SMP_FLAG_INITIATOR, &smp->flags)) { 2170 sc_dhkey_check(smp); 2171 SMP_ALLOW_CMD(smp, SMP_CMD_DHKEY_CHECK); 2172 } 2173 return 0; 2174 } 2175 2176 err = smp_g2(pkax, pkbx, na, nb, &passkey); 2177 if (err) 2178 return SMP_UNSPECIFIED; 2179 2180 /* Always require user confirmation for Just-Works pairing to prevent 2181 * impersonation attacks, or in case of a legitimate device that is 2182 * repairing use the confirmation as acknowledgment to proceed with the 2183 * creation of new keys. 2184 */ 2185 confirm_hint = smp->method == JUST_WORKS ? 1 : 0; 2186 2187 err = mgmt_user_confirm_request(hcon->hdev, &hcon->dst, hcon->type, 2188 hcon->dst_type, passkey, confirm_hint); 2189 if (err) 2190 return SMP_UNSPECIFIED; 2191 2192 set_bit(SMP_FLAG_WAIT_USER, &smp->flags); 2193 2194 return 0; 2195 } 2196 2197 static bool smp_ltk_encrypt(struct l2cap_conn *conn, u8 sec_level) 2198 { 2199 struct smp_ltk *key; 2200 struct hci_conn *hcon = conn->hcon; 2201 2202 key = hci_find_ltk(hcon->hdev, &hcon->dst, hcon->dst_type, hcon->role); 2203 if (!key) 2204 return false; 2205 2206 if (smp_ltk_sec_level(key) < sec_level) 2207 return false; 2208 2209 if (test_and_set_bit(HCI_CONN_ENCRYPT_PEND, &hcon->flags)) 2210 return true; 2211 2212 hci_le_start_enc(hcon, key->ediv, key->rand, key->val, key->enc_size); 2213 hcon->enc_key_size = key->enc_size; 2214 2215 /* We never store STKs for initiator role, so clear this flag */ 2216 clear_bit(HCI_CONN_STK_ENCRYPT, &hcon->flags); 2217 2218 return true; 2219 } 2220 2221 bool smp_sufficient_security(struct hci_conn *hcon, u8 sec_level, 2222 enum smp_key_pref key_pref) 2223 { 2224 if (sec_level == BT_SECURITY_LOW) 2225 return true; 2226 2227 /* If we're encrypted with an STK but the caller prefers using 2228 * LTK claim insufficient security. This way we allow the 2229 * connection to be re-encrypted with an LTK, even if the LTK 2230 * provides the same level of security. Only exception is if we 2231 * don't have an LTK (e.g. because of key distribution bits). 2232 */ 2233 if (key_pref == SMP_USE_LTK && 2234 test_bit(HCI_CONN_STK_ENCRYPT, &hcon->flags) && 2235 hci_find_ltk(hcon->hdev, &hcon->dst, hcon->dst_type, hcon->role)) 2236 return false; 2237 2238 if (hcon->sec_level >= sec_level) 2239 return true; 2240 2241 return false; 2242 } 2243 2244 static void smp_send_pairing_req(struct smp_chan *smp, __u8 auth) 2245 { 2246 struct smp_cmd_pairing cp; 2247 2248 if (smp->conn->hcon->type == ACL_LINK) 2249 build_bredr_pairing_cmd(smp, &cp, NULL); 2250 else 2251 build_pairing_cmd(smp->conn, &cp, NULL, auth); 2252 2253 smp->preq[0] = SMP_CMD_PAIRING_REQ; 2254 memcpy(&smp->preq[1], &cp, sizeof(cp)); 2255 2256 smp_send_cmd(smp->conn, SMP_CMD_PAIRING_REQ, sizeof(cp), &cp); 2257 SMP_ALLOW_CMD(smp, SMP_CMD_PAIRING_RSP); 2258 2259 set_bit(SMP_FLAG_INITIATOR, &smp->flags); 2260 } 2261 2262 static u8 smp_cmd_security_req(struct l2cap_conn *conn, struct sk_buff *skb) 2263 { 2264 struct smp_cmd_security_req *rp = (void *) skb->data; 2265 struct hci_conn *hcon = conn->hcon; 2266 struct hci_dev *hdev = hcon->hdev; 2267 struct smp_chan *smp; 2268 u8 sec_level, auth; 2269 2270 bt_dev_dbg(hdev, "conn %p", conn); 2271 2272 if (skb->len < sizeof(*rp)) 2273 return SMP_INVALID_PARAMS; 2274 2275 if (hcon->role != HCI_ROLE_MASTER) 2276 return SMP_CMD_NOTSUPP; 2277 2278 auth = rp->auth_req & AUTH_REQ_MASK(hdev); 2279 2280 if (hci_dev_test_flag(hdev, HCI_SC_ONLY) && !(auth & SMP_AUTH_SC)) 2281 return SMP_AUTH_REQUIREMENTS; 2282 2283 if (hcon->io_capability == HCI_IO_NO_INPUT_OUTPUT) 2284 sec_level = BT_SECURITY_MEDIUM; 2285 else 2286 sec_level = authreq_to_seclevel(auth); 2287 2288 if (smp_sufficient_security(hcon, sec_level, SMP_USE_LTK)) { 2289 /* If link is already encrypted with sufficient security we 2290 * still need refresh encryption as per Core Spec 5.0 Vol 3, 2291 * Part H 2.4.6 2292 */ 2293 smp_ltk_encrypt(conn, hcon->sec_level); 2294 return 0; 2295 } 2296 2297 if (sec_level > hcon->pending_sec_level) 2298 hcon->pending_sec_level = sec_level; 2299 2300 if (smp_ltk_encrypt(conn, hcon->pending_sec_level)) 2301 return 0; 2302 2303 smp = smp_chan_create(conn); 2304 if (!smp) 2305 return SMP_UNSPECIFIED; 2306 2307 if (!hci_dev_test_flag(hdev, HCI_BONDABLE) && 2308 (auth & SMP_AUTH_BONDING)) 2309 return SMP_PAIRING_NOTSUPP; 2310 2311 skb_pull(skb, sizeof(*rp)); 2312 2313 smp_send_pairing_req(smp, auth); 2314 2315 return 0; 2316 } 2317 2318 static void smp_send_security_req(struct smp_chan *smp, __u8 auth) 2319 { 2320 struct smp_cmd_security_req cp; 2321 2322 cp.auth_req = auth; 2323 smp_send_cmd(smp->conn, SMP_CMD_SECURITY_REQ, sizeof(cp), &cp); 2324 SMP_ALLOW_CMD(smp, SMP_CMD_PAIRING_REQ); 2325 2326 clear_bit(SMP_FLAG_INITIATOR, &smp->flags); 2327 } 2328 2329 int smp_conn_security(struct hci_conn *hcon, __u8 sec_level) 2330 { 2331 struct l2cap_conn *conn; 2332 struct l2cap_chan *chan; 2333 struct smp_chan *smp; 2334 __u8 authreq; 2335 int ret; 2336 2337 /* Caller shall ensure there can be no race with l2cap_conn_del() */ 2338 conn = context_unsafe(hcon->l2cap_data); 2339 2340 bt_dev_dbg(hcon->hdev, "conn %p hcon %p level 0x%2.2x", conn, hcon, 2341 sec_level); 2342 2343 /* This may be NULL if there's an unexpected disconnection */ 2344 if (!conn) 2345 return 1; 2346 2347 if (!hci_dev_test_flag(hcon->hdev, HCI_LE_ENABLED)) 2348 return 1; 2349 2350 if (smp_sufficient_security(hcon, sec_level, SMP_USE_LTK)) 2351 return 1; 2352 2353 if (sec_level > hcon->pending_sec_level) 2354 hcon->pending_sec_level = sec_level; 2355 2356 if (hcon->role == HCI_ROLE_MASTER) 2357 if (smp_ltk_encrypt(conn, hcon->pending_sec_level)) 2358 return 0; 2359 2360 chan = conn->smp; 2361 if (!chan) { 2362 bt_dev_err(hcon->hdev, "security requested but not available"); 2363 return 1; 2364 } 2365 2366 l2cap_chan_lock(chan); 2367 2368 /* If SMP is already in progress ignore this request */ 2369 if (chan->data) { 2370 ret = 0; 2371 goto unlock; 2372 } 2373 2374 smp = smp_chan_create(conn); 2375 if (!smp) { 2376 ret = 1; 2377 goto unlock; 2378 } 2379 2380 authreq = seclevel_to_authreq(sec_level); 2381 2382 if (hci_dev_test_flag(hcon->hdev, HCI_SC_ENABLED)) { 2383 authreq |= SMP_AUTH_SC; 2384 if (hci_dev_test_flag(hcon->hdev, HCI_SSP_ENABLED)) 2385 authreq |= SMP_AUTH_CT2; 2386 } 2387 2388 /* Don't attempt to set MITM if setting is overridden by debugfs 2389 * Needed to pass certification test SM/MAS/PKE/BV-01-C 2390 */ 2391 if (!hci_dev_test_flag(hcon->hdev, HCI_FORCE_NO_MITM)) { 2392 /* Require MITM if IO Capability allows or the security level 2393 * requires it. 2394 */ 2395 if (hcon->io_capability != HCI_IO_NO_INPUT_OUTPUT || 2396 hcon->pending_sec_level > BT_SECURITY_MEDIUM) 2397 authreq |= SMP_AUTH_MITM; 2398 } 2399 2400 if (hcon->role == HCI_ROLE_MASTER) 2401 smp_send_pairing_req(smp, authreq); 2402 else 2403 smp_send_security_req(smp, authreq); 2404 2405 ret = 0; 2406 2407 unlock: 2408 l2cap_chan_unlock(chan); 2409 return ret; 2410 } 2411 2412 int smp_cancel_and_remove_pairing(struct hci_dev *hdev, bdaddr_t *bdaddr, 2413 u8 addr_type) 2414 { 2415 struct hci_conn *hcon; 2416 struct l2cap_conn *conn; 2417 struct l2cap_chan *chan; 2418 struct smp_chan *smp; 2419 int err; 2420 2421 err = hci_remove_ltk(hdev, bdaddr, addr_type); 2422 hci_remove_irk(hdev, bdaddr, addr_type); 2423 2424 hcon = hci_conn_hash_lookup_le(hdev, bdaddr, addr_type); 2425 if (!hcon) 2426 goto done; 2427 2428 lockdep_assert_held(&hcon->hdev->lock); 2429 2430 conn = hcon->l2cap_data; 2431 if (!conn) 2432 goto done; 2433 2434 chan = conn->smp; 2435 if (!chan) 2436 goto done; 2437 2438 l2cap_chan_lock(chan); 2439 2440 smp = chan->data; 2441 if (smp) { 2442 /* Set keys to NULL to make sure smp_failure() does not try to 2443 * remove and free already invalidated rcu list entries. */ 2444 smp->ltk = NULL; 2445 smp->responder_ltk = NULL; 2446 smp->remote_irk = NULL; 2447 2448 if (test_bit(SMP_FLAG_COMPLETE, &smp->flags)) 2449 smp_failure(conn, 0); 2450 else 2451 smp_failure(conn, SMP_UNSPECIFIED); 2452 err = 0; 2453 } 2454 2455 l2cap_chan_unlock(chan); 2456 2457 done: 2458 return err; 2459 } 2460 2461 static int smp_cmd_encrypt_info(struct l2cap_conn *conn, struct sk_buff *skb) 2462 { 2463 struct smp_cmd_encrypt_info *rp = (void *) skb->data; 2464 struct l2cap_chan *chan = conn->smp; 2465 struct smp_chan *smp = chan->data; 2466 2467 bt_dev_dbg(conn->hcon->hdev, "conn %p", conn); 2468 2469 if (skb->len < sizeof(*rp)) 2470 return SMP_INVALID_PARAMS; 2471 2472 /* Pairing is aborted if any blocked keys are distributed */ 2473 if (hci_is_blocked_key(conn->hcon->hdev, HCI_BLOCKED_KEY_TYPE_LTK, 2474 rp->ltk)) { 2475 bt_dev_warn_ratelimited(conn->hcon->hdev, 2476 "LTK blocked for %pMR", 2477 &conn->hcon->dst); 2478 return SMP_INVALID_PARAMS; 2479 } 2480 2481 SMP_ALLOW_CMD(smp, SMP_CMD_INITIATOR_IDENT); 2482 2483 skb_pull(skb, sizeof(*rp)); 2484 2485 memcpy(smp->tk, rp->ltk, sizeof(smp->tk)); 2486 2487 return 0; 2488 } 2489 2490 static int smp_cmd_initiator_ident(struct l2cap_conn *conn, struct sk_buff *skb) 2491 { 2492 struct smp_cmd_initiator_ident *rp = (void *)skb->data; 2493 struct l2cap_chan *chan = conn->smp; 2494 struct smp_chan *smp = chan->data; 2495 struct hci_dev *hdev = conn->hcon->hdev; 2496 struct hci_conn *hcon = conn->hcon; 2497 struct smp_ltk *ltk; 2498 u8 authenticated; 2499 2500 bt_dev_dbg(hdev, "conn %p", conn); 2501 2502 if (skb->len < sizeof(*rp)) 2503 return SMP_INVALID_PARAMS; 2504 2505 /* Mark the information as received */ 2506 smp->remote_key_dist &= ~SMP_DIST_ENC_KEY; 2507 2508 if (smp->remote_key_dist & SMP_DIST_ID_KEY) 2509 SMP_ALLOW_CMD(smp, SMP_CMD_IDENT_INFO); 2510 else if (smp->remote_key_dist & SMP_DIST_SIGN) 2511 SMP_ALLOW_CMD(smp, SMP_CMD_SIGN_INFO); 2512 2513 skb_pull(skb, sizeof(*rp)); 2514 2515 authenticated = (hcon->sec_level == BT_SECURITY_HIGH); 2516 ltk = hci_add_ltk(hdev, &hcon->dst, hcon->dst_type, SMP_LTK, 2517 authenticated, smp->tk, smp->enc_key_size, 2518 rp->ediv, rp->rand); 2519 smp->ltk = ltk; 2520 if (!(smp->remote_key_dist & KEY_DIST_MASK)) 2521 smp_distribute_keys(smp); 2522 2523 return 0; 2524 } 2525 2526 static int smp_cmd_ident_info(struct l2cap_conn *conn, struct sk_buff *skb) 2527 { 2528 struct smp_cmd_ident_info *info = (void *) skb->data; 2529 struct l2cap_chan *chan = conn->smp; 2530 struct smp_chan *smp = chan->data; 2531 2532 bt_dev_dbg(conn->hcon->hdev, ""); 2533 2534 if (skb->len < sizeof(*info)) 2535 return SMP_INVALID_PARAMS; 2536 2537 /* Pairing is aborted if any blocked keys are distributed */ 2538 if (hci_is_blocked_key(conn->hcon->hdev, HCI_BLOCKED_KEY_TYPE_IRK, 2539 info->irk)) { 2540 bt_dev_warn_ratelimited(conn->hcon->hdev, 2541 "Identity key blocked for %pMR", 2542 &conn->hcon->dst); 2543 return SMP_INVALID_PARAMS; 2544 } 2545 2546 SMP_ALLOW_CMD(smp, SMP_CMD_IDENT_ADDR_INFO); 2547 2548 skb_pull(skb, sizeof(*info)); 2549 2550 memcpy(smp->irk, info->irk, 16); 2551 2552 return 0; 2553 } 2554 2555 static int smp_cmd_ident_addr_info(struct l2cap_conn *conn, 2556 struct sk_buff *skb) 2557 { 2558 struct smp_cmd_ident_addr_info *info = (void *) skb->data; 2559 struct l2cap_chan *chan = conn->smp; 2560 struct smp_chan *smp = chan->data; 2561 struct hci_conn *hcon = conn->hcon; 2562 bdaddr_t rpa; 2563 2564 bt_dev_dbg(hcon->hdev, ""); 2565 2566 if (skb->len < sizeof(*info)) 2567 return SMP_INVALID_PARAMS; 2568 2569 /* Mark the information as received */ 2570 smp->remote_key_dist &= ~SMP_DIST_ID_KEY; 2571 2572 if (smp->remote_key_dist & SMP_DIST_SIGN) 2573 SMP_ALLOW_CMD(smp, SMP_CMD_SIGN_INFO); 2574 2575 skb_pull(skb, sizeof(*info)); 2576 2577 /* Strictly speaking the Core Specification (4.1) allows sending 2578 * an empty address which would force us to rely on just the IRK 2579 * as "identity information". However, since such 2580 * implementations are not known of and in order to not over 2581 * complicate our implementation, simply pretend that we never 2582 * received an IRK for such a device. 2583 * 2584 * The Identity Address must also be a Static Random or Public 2585 * Address, which hci_is_identity_address() checks for. 2586 */ 2587 if (!bacmp(&info->bdaddr, BDADDR_ANY) || 2588 !hci_is_identity_address(&info->bdaddr, info->addr_type)) { 2589 bt_dev_err(hcon->hdev, "ignoring IRK with no identity address"); 2590 goto distribute; 2591 } 2592 2593 /* Drop IRK if peer is using identity address during pairing but is 2594 * providing different address as identity information. 2595 * 2596 * Microsoft Surface Precision Mouse is known to have this bug. 2597 */ 2598 if (hci_is_identity_address(&hcon->dst, hcon->dst_type) && 2599 (bacmp(&info->bdaddr, &hcon->dst) || 2600 info->addr_type != hcon->dst_type)) { 2601 bt_dev_err(hcon->hdev, 2602 "ignoring IRK with invalid identity address"); 2603 goto distribute; 2604 } 2605 2606 bacpy(&smp->id_addr, &info->bdaddr); 2607 smp->id_addr_type = info->addr_type; 2608 2609 if (hci_bdaddr_is_rpa(&hcon->dst, hcon->dst_type)) 2610 bacpy(&rpa, &hcon->dst); 2611 else 2612 bacpy(&rpa, BDADDR_ANY); 2613 2614 smp->remote_irk = hci_add_irk(conn->hcon->hdev, &smp->id_addr, 2615 smp->id_addr_type, smp->irk, &rpa); 2616 2617 distribute: 2618 if (!(smp->remote_key_dist & KEY_DIST_MASK)) 2619 smp_distribute_keys(smp); 2620 2621 return 0; 2622 } 2623 2624 static int smp_cmd_sign_info(struct l2cap_conn *conn, struct sk_buff *skb) 2625 { 2626 struct smp_cmd_sign_info *rp = (void *) skb->data; 2627 struct l2cap_chan *chan = conn->smp; 2628 struct smp_chan *smp = chan->data; 2629 struct smp_csrk *csrk; 2630 2631 bt_dev_dbg(conn->hcon->hdev, "conn %p", conn); 2632 2633 if (skb->len < sizeof(*rp)) 2634 return SMP_INVALID_PARAMS; 2635 2636 /* Mark the information as received */ 2637 smp->remote_key_dist &= ~SMP_DIST_SIGN; 2638 2639 skb_pull(skb, sizeof(*rp)); 2640 2641 csrk = kzalloc_obj(*csrk); 2642 if (csrk) { 2643 if (conn->hcon->sec_level > BT_SECURITY_MEDIUM) 2644 csrk->type = MGMT_CSRK_REMOTE_AUTHENTICATED; 2645 else 2646 csrk->type = MGMT_CSRK_REMOTE_UNAUTHENTICATED; 2647 memcpy(csrk->val, rp->csrk, sizeof(csrk->val)); 2648 } 2649 smp->csrk = csrk; 2650 smp_distribute_keys(smp); 2651 2652 return 0; 2653 } 2654 2655 static u8 sc_select_method(struct smp_chan *smp) 2656 { 2657 struct smp_cmd_pairing *local, *remote; 2658 u8 local_mitm, remote_mitm, local_io, remote_io, method; 2659 2660 if (test_bit(SMP_FLAG_REMOTE_OOB, &smp->flags) || 2661 test_bit(SMP_FLAG_LOCAL_OOB, &smp->flags)) 2662 return REQ_OOB; 2663 2664 /* The preq/prsp contain the raw Pairing Request/Response PDUs 2665 * which are needed as inputs to some crypto functions. To get 2666 * the "struct smp_cmd_pairing" from them we need to skip the 2667 * first byte which contains the opcode. 2668 */ 2669 if (test_bit(SMP_FLAG_INITIATOR, &smp->flags)) { 2670 local = (void *) &smp->preq[1]; 2671 remote = (void *) &smp->prsp[1]; 2672 } else { 2673 local = (void *) &smp->prsp[1]; 2674 remote = (void *) &smp->preq[1]; 2675 } 2676 2677 local_io = local->io_capability; 2678 remote_io = remote->io_capability; 2679 2680 local_mitm = (local->auth_req & SMP_AUTH_MITM); 2681 remote_mitm = (remote->auth_req & SMP_AUTH_MITM); 2682 2683 /* If either side wants MITM, look up the method from the table, 2684 * otherwise use JUST WORKS. 2685 */ 2686 if (local_mitm || remote_mitm) 2687 method = get_auth_method(smp, local_io, remote_io); 2688 else 2689 method = JUST_WORKS; 2690 2691 /* Don't confirm locally initiated pairing attempts */ 2692 if (method == JUST_CFM && test_bit(SMP_FLAG_INITIATOR, &smp->flags)) 2693 method = JUST_WORKS; 2694 2695 return method; 2696 } 2697 2698 static int smp_cmd_public_key(struct l2cap_conn *conn, struct sk_buff *skb) 2699 { 2700 struct smp_cmd_public_key *key = (void *) skb->data; 2701 struct hci_conn *hcon = conn->hcon; 2702 struct l2cap_chan *chan = conn->smp; 2703 struct smp_chan *smp = chan->data; 2704 struct hci_dev *hdev = hcon->hdev; 2705 struct crypto_kpp *tfm_ecdh; 2706 struct smp_cmd_pairing_confirm cfm; 2707 int err; 2708 2709 bt_dev_dbg(hdev, "conn %p", conn); 2710 2711 if (skb->len < sizeof(*key)) 2712 return SMP_INVALID_PARAMS; 2713 2714 /* Check if remote and local public keys are the same and debug key is 2715 * not in use. 2716 */ 2717 if (!test_bit(SMP_FLAG_DEBUG_KEY, &smp->flags) && 2718 !crypto_memneq(key, smp->local_pk, 64)) { 2719 bt_dev_err(hdev, "Remote and local public keys are identical"); 2720 return SMP_DHKEY_CHECK_FAILED; 2721 } 2722 2723 memcpy(smp->remote_pk, key, 64); 2724 2725 if (test_bit(SMP_FLAG_REMOTE_OOB, &smp->flags)) { 2726 err = smp_f4(smp->remote_pk, smp->remote_pk, smp->rr, 0, 2727 cfm.confirm_val); 2728 if (err) 2729 return SMP_UNSPECIFIED; 2730 2731 if (crypto_memneq(cfm.confirm_val, smp->pcnf, 16)) 2732 return SMP_CONFIRM_FAILED; 2733 } 2734 2735 /* Non-initiating device sends its public key after receiving 2736 * the key from the initiating device. 2737 */ 2738 if (!test_bit(SMP_FLAG_INITIATOR, &smp->flags)) { 2739 err = sc_send_public_key(smp); 2740 if (err) 2741 return err; 2742 } 2743 2744 SMP_DBG("Remote Public Key X: %32phN", smp->remote_pk); 2745 SMP_DBG("Remote Public Key Y: %32phN", smp->remote_pk + 32); 2746 2747 /* Compute the shared secret on the same crypto tfm on which the private 2748 * key was set/generated. 2749 */ 2750 if (test_bit(SMP_FLAG_LOCAL_OOB, &smp->flags)) { 2751 struct l2cap_chan *hchan = hdev->smp_data; 2752 struct smp_dev *smp_dev; 2753 2754 if (!hchan || !hchan->data) 2755 return SMP_UNSPECIFIED; 2756 2757 smp_dev = hchan->data; 2758 2759 tfm_ecdh = smp_dev->tfm_ecdh; 2760 } else { 2761 tfm_ecdh = smp->tfm_ecdh; 2762 } 2763 2764 if (compute_ecdh_secret(tfm_ecdh, smp->remote_pk, smp->dhkey)) 2765 return SMP_UNSPECIFIED; 2766 2767 SMP_DBG("DHKey %32phN", smp->dhkey); 2768 2769 set_bit(SMP_FLAG_REMOTE_PK, &smp->flags); 2770 2771 smp->method = sc_select_method(smp); 2772 2773 bt_dev_dbg(hdev, "selected method 0x%02x", smp->method); 2774 2775 /* JUST_WORKS and JUST_CFM result in an unauthenticated key */ 2776 if (smp->method == JUST_WORKS || smp->method == JUST_CFM) 2777 hcon->pending_sec_level = BT_SECURITY_MEDIUM; 2778 else 2779 hcon->pending_sec_level = BT_SECURITY_FIPS; 2780 2781 if (!crypto_memneq(debug_pk, smp->remote_pk, 64)) 2782 set_bit(SMP_FLAG_DEBUG_KEY, &smp->flags); 2783 2784 if (smp->method == DSP_PASSKEY) { 2785 get_random_bytes(&hcon->passkey_notify, 2786 sizeof(hcon->passkey_notify)); 2787 hcon->passkey_notify %= 1000000; 2788 hcon->passkey_entered = 0; 2789 smp->passkey_round = 0; 2790 if (mgmt_user_passkey_notify(hdev, &hcon->dst, hcon->type, 2791 hcon->dst_type, 2792 hcon->passkey_notify, 2793 hcon->passkey_entered)) 2794 return SMP_UNSPECIFIED; 2795 SMP_ALLOW_CMD(smp, SMP_CMD_PAIRING_CONFIRM); 2796 return sc_passkey_round(smp, SMP_CMD_PUBLIC_KEY); 2797 } 2798 2799 if (smp->method == REQ_OOB) { 2800 if (test_bit(SMP_FLAG_INITIATOR, &smp->flags)) 2801 smp_send_cmd(conn, SMP_CMD_PAIRING_RANDOM, 2802 sizeof(smp->prnd), smp->prnd); 2803 2804 SMP_ALLOW_CMD(smp, SMP_CMD_PAIRING_RANDOM); 2805 2806 return 0; 2807 } 2808 2809 if (test_bit(SMP_FLAG_INITIATOR, &smp->flags)) 2810 SMP_ALLOW_CMD(smp, SMP_CMD_PAIRING_CONFIRM); 2811 2812 if (smp->method == REQ_PASSKEY) { 2813 if (mgmt_user_passkey_request(hdev, &hcon->dst, hcon->type, 2814 hcon->dst_type)) 2815 return SMP_UNSPECIFIED; 2816 SMP_ALLOW_CMD(smp, SMP_CMD_PAIRING_CONFIRM); 2817 set_bit(SMP_FLAG_WAIT_USER, &smp->flags); 2818 return 0; 2819 } 2820 2821 /* The Initiating device waits for the non-initiating device to 2822 * send the confirm value. 2823 */ 2824 if (test_bit(SMP_FLAG_INITIATOR, &smp->flags)) 2825 return 0; 2826 2827 err = smp_f4(smp->local_pk, smp->remote_pk, smp->prnd, 0, 2828 cfm.confirm_val); 2829 if (err) 2830 return SMP_UNSPECIFIED; 2831 2832 smp_send_cmd(conn, SMP_CMD_PAIRING_CONFIRM, sizeof(cfm), &cfm); 2833 SMP_ALLOW_CMD(smp, SMP_CMD_PAIRING_RANDOM); 2834 2835 return 0; 2836 } 2837 2838 static int smp_cmd_dhkey_check(struct l2cap_conn *conn, struct sk_buff *skb) 2839 { 2840 struct smp_cmd_dhkey_check *check = (void *) skb->data; 2841 struct l2cap_chan *chan = conn->smp; 2842 struct hci_conn *hcon = conn->hcon; 2843 struct smp_chan *smp = chan->data; 2844 u8 a[7], b[7], *local_addr, *remote_addr; 2845 u8 io_cap[3], r[16], e[16]; 2846 int err; 2847 2848 bt_dev_dbg(hcon->hdev, "conn %p", conn); 2849 2850 if (skb->len < sizeof(*check)) 2851 return SMP_INVALID_PARAMS; 2852 2853 memcpy(a, &hcon->init_addr, 6); 2854 memcpy(b, &hcon->resp_addr, 6); 2855 a[6] = hcon->init_addr_type; 2856 b[6] = hcon->resp_addr_type; 2857 2858 if (test_bit(SMP_FLAG_INITIATOR, &smp->flags)) { 2859 local_addr = a; 2860 remote_addr = b; 2861 memcpy(io_cap, &smp->prsp[1], 3); 2862 } else { 2863 local_addr = b; 2864 remote_addr = a; 2865 memcpy(io_cap, &smp->preq[1], 3); 2866 } 2867 2868 memset(r, 0, sizeof(r)); 2869 2870 if (smp->method == REQ_PASSKEY || smp->method == DSP_PASSKEY) 2871 put_unaligned_le32(hcon->passkey_notify, r); 2872 else if (smp->method == REQ_OOB) 2873 memcpy(r, smp->lr, 16); 2874 2875 err = smp_f6(smp->mackey, smp->rrnd, smp->prnd, r, io_cap, remote_addr, 2876 local_addr, e); 2877 if (err) 2878 return SMP_UNSPECIFIED; 2879 2880 if (crypto_memneq(check->e, e, 16)) 2881 return SMP_DHKEY_CHECK_FAILED; 2882 2883 if (!test_bit(SMP_FLAG_INITIATOR, &smp->flags)) { 2884 if (test_bit(SMP_FLAG_WAIT_USER, &smp->flags)) { 2885 set_bit(SMP_FLAG_DHKEY_PENDING, &smp->flags); 2886 return 0; 2887 } 2888 2889 /* Responder sends DHKey check as response to initiator */ 2890 sc_dhkey_check(smp); 2891 } 2892 2893 sc_add_ltk(smp); 2894 2895 if (test_bit(SMP_FLAG_INITIATOR, &smp->flags)) { 2896 hci_le_start_enc(hcon, 0, 0, smp->tk, smp->enc_key_size); 2897 hcon->enc_key_size = smp->enc_key_size; 2898 } 2899 2900 return 0; 2901 } 2902 2903 static int smp_cmd_keypress_notify(struct l2cap_conn *conn, 2904 struct sk_buff *skb) 2905 { 2906 struct smp_cmd_keypress_notify *kp = (void *) skb->data; 2907 2908 bt_dev_dbg(conn->hcon->hdev, "value 0x%02x", kp->value); 2909 2910 return 0; 2911 } 2912 2913 static int smp_sig_channel(struct l2cap_chan *chan, struct sk_buff *skb) 2914 { 2915 struct l2cap_conn *conn = chan->conn; 2916 struct hci_conn *hcon = conn->hcon; 2917 struct smp_chan *smp; 2918 __u8 code, reason; 2919 int err = 0; 2920 2921 if (skb->len < 1) 2922 return -EILSEQ; 2923 2924 if (!hci_dev_test_flag(hcon->hdev, HCI_LE_ENABLED)) { 2925 reason = SMP_PAIRING_NOTSUPP; 2926 goto done; 2927 } 2928 2929 code = skb->data[0]; 2930 skb_pull(skb, sizeof(code)); 2931 2932 smp = chan->data; 2933 2934 if (code > SMP_CMD_MAX) 2935 goto drop; 2936 2937 if (smp && !test_and_clear_bit(code, &smp->allow_cmd)) { 2938 /* If there is a context and the command is not allowed consider 2939 * it a failure so the session is cleanup properly. 2940 */ 2941 switch (code) { 2942 case SMP_CMD_IDENT_INFO: 2943 case SMP_CMD_IDENT_ADDR_INFO: 2944 case SMP_CMD_SIGN_INFO: 2945 /* 3.6.1. Key distribution and generation 2946 * 2947 * A device may reject a distributed key by sending the 2948 * Pairing Failed command with the reason set to 2949 * "Key Rejected". 2950 */ 2951 smp_failure(conn, SMP_KEY_REJECTED); 2952 break; 2953 } 2954 goto drop; 2955 } 2956 2957 /* If we don't have a context the only allowed commands are 2958 * pairing request and security request. 2959 */ 2960 if (!smp && code != SMP_CMD_PAIRING_REQ && code != SMP_CMD_SECURITY_REQ) 2961 goto drop; 2962 2963 switch (code) { 2964 case SMP_CMD_PAIRING_REQ: 2965 reason = smp_cmd_pairing_req(conn, skb); 2966 break; 2967 2968 case SMP_CMD_PAIRING_FAIL: 2969 smp_failure(conn, 0); 2970 err = -EPERM; 2971 break; 2972 2973 case SMP_CMD_PAIRING_RSP: 2974 reason = smp_cmd_pairing_rsp(conn, skb); 2975 break; 2976 2977 case SMP_CMD_SECURITY_REQ: 2978 reason = smp_cmd_security_req(conn, skb); 2979 break; 2980 2981 case SMP_CMD_PAIRING_CONFIRM: 2982 reason = smp_cmd_pairing_confirm(conn, skb); 2983 break; 2984 2985 case SMP_CMD_PAIRING_RANDOM: 2986 reason = smp_cmd_pairing_random(conn, skb); 2987 break; 2988 2989 case SMP_CMD_ENCRYPT_INFO: 2990 reason = smp_cmd_encrypt_info(conn, skb); 2991 break; 2992 2993 case SMP_CMD_INITIATOR_IDENT: 2994 reason = smp_cmd_initiator_ident(conn, skb); 2995 break; 2996 2997 case SMP_CMD_IDENT_INFO: 2998 reason = smp_cmd_ident_info(conn, skb); 2999 break; 3000 3001 case SMP_CMD_IDENT_ADDR_INFO: 3002 reason = smp_cmd_ident_addr_info(conn, skb); 3003 break; 3004 3005 case SMP_CMD_SIGN_INFO: 3006 reason = smp_cmd_sign_info(conn, skb); 3007 break; 3008 3009 case SMP_CMD_PUBLIC_KEY: 3010 reason = smp_cmd_public_key(conn, skb); 3011 break; 3012 3013 case SMP_CMD_DHKEY_CHECK: 3014 reason = smp_cmd_dhkey_check(conn, skb); 3015 break; 3016 3017 case SMP_CMD_KEYPRESS_NOTIFY: 3018 reason = smp_cmd_keypress_notify(conn, skb); 3019 break; 3020 3021 default: 3022 bt_dev_dbg(hcon->hdev, "Unknown command code 0x%2.2x", code); 3023 reason = SMP_CMD_NOTSUPP; 3024 goto done; 3025 } 3026 3027 done: 3028 if (!err) { 3029 if (reason) 3030 smp_failure(conn, reason); 3031 kfree_skb(skb); 3032 } 3033 3034 return err; 3035 3036 drop: 3037 bt_dev_err(hcon->hdev, "unexpected SMP command 0x%02x from %pMR", 3038 code, &hcon->dst); 3039 kfree_skb(skb); 3040 return 0; 3041 } 3042 3043 static void smp_teardown_cb(struct l2cap_chan *chan, int err) 3044 { 3045 struct l2cap_conn *conn = chan->conn; 3046 3047 bt_dev_dbg(conn->hcon->hdev, "chan %p", chan); 3048 3049 if (chan->data) 3050 smp_chan_destroy(conn); 3051 3052 conn->smp = NULL; 3053 l2cap_chan_put(chan); 3054 } 3055 3056 static void bredr_pairing(struct l2cap_chan *chan) 3057 { 3058 struct l2cap_conn *conn = chan->conn; 3059 struct hci_conn *hcon = conn->hcon; 3060 struct hci_dev *hdev = hcon->hdev; 3061 struct smp_chan *smp; 3062 3063 bt_dev_dbg(hdev, "chan %p", chan); 3064 3065 /* Only new pairings are interesting */ 3066 if (!test_bit(HCI_CONN_NEW_LINK_KEY, &hcon->flags)) 3067 return; 3068 3069 /* Don't bother if we're not encrypted */ 3070 if (!test_bit(HCI_CONN_ENCRYPT, &hcon->flags)) 3071 return; 3072 3073 /* Only initiator may initiate SMP over BR/EDR */ 3074 if (hcon->role != HCI_ROLE_MASTER) 3075 return; 3076 3077 /* Secure Connections support must be enabled */ 3078 if (!hci_dev_test_flag(hdev, HCI_SC_ENABLED)) 3079 return; 3080 3081 /* BR/EDR must use Secure Connections for SMP */ 3082 if (!test_bit(HCI_CONN_AES_CCM, &hcon->flags) && 3083 !hci_dev_test_flag(hdev, HCI_FORCE_BREDR_SMP)) 3084 return; 3085 3086 /* If our LE support is not enabled don't do anything */ 3087 if (!hci_dev_test_flag(hdev, HCI_LE_ENABLED)) 3088 return; 3089 3090 /* Don't bother if remote LE support is not enabled */ 3091 if (!lmp_host_le_capable(hcon)) 3092 return; 3093 3094 /* Remote must support SMP fixed chan for BR/EDR */ 3095 if (!(conn->remote_fixed_chan & L2CAP_FC_SMP_BREDR)) 3096 return; 3097 3098 /* Don't bother if SMP is already ongoing */ 3099 if (chan->data) 3100 return; 3101 3102 smp = smp_chan_create(conn); 3103 if (!smp) { 3104 bt_dev_err(hdev, "unable to create SMP context for BR/EDR"); 3105 return; 3106 } 3107 3108 set_bit(SMP_FLAG_SC, &smp->flags); 3109 3110 bt_dev_dbg(hdev, "starting SMP over BR/EDR"); 3111 3112 smp_send_pairing_req(smp, 0x00); 3113 } 3114 3115 static void smp_resume_cb(struct l2cap_chan *chan) 3116 { 3117 struct smp_chan *smp = chan->data; 3118 struct l2cap_conn *conn = chan->conn; 3119 struct hci_conn *hcon = conn->hcon; 3120 3121 bt_dev_dbg(hcon->hdev, "chan %p", chan); 3122 3123 if (hcon->type == ACL_LINK) { 3124 bredr_pairing(chan); 3125 return; 3126 } 3127 3128 if (!smp) 3129 return; 3130 3131 if (!test_bit(HCI_CONN_ENCRYPT, &hcon->flags)) 3132 return; 3133 3134 cancel_delayed_work(&smp->security_timer); 3135 3136 smp_distribute_keys(smp); 3137 } 3138 3139 static void smp_ready_cb(struct l2cap_chan *chan) 3140 { 3141 struct l2cap_conn *conn = chan->conn; 3142 struct hci_conn *hcon = conn->hcon; 3143 3144 bt_dev_dbg(hcon->hdev, "chan %p", chan); 3145 3146 /* No need to call l2cap_chan_hold() here since we already own 3147 * the reference taken in smp_new_conn_cb(). This is just the 3148 * first time that we tie it to a specific pointer. The code in 3149 * l2cap_core.c ensures that there's no risk this function won't 3150 * get called if smp_new_conn_cb was previously called. 3151 */ 3152 conn->smp = chan; 3153 3154 if (hcon->type == ACL_LINK && test_bit(HCI_CONN_ENCRYPT, &hcon->flags)) 3155 bredr_pairing(chan); 3156 } 3157 3158 static int smp_recv_cb(struct l2cap_chan *chan, struct sk_buff *skb) 3159 { 3160 int err; 3161 3162 bt_dev_dbg(chan->conn->hcon->hdev, "chan %p", chan); 3163 3164 err = smp_sig_channel(chan, skb); 3165 if (err) { 3166 struct smp_chan *smp = chan->data; 3167 3168 if (smp) 3169 cancel_delayed_work_sync(&smp->security_timer); 3170 3171 hci_disconnect(chan->conn->hcon, HCI_ERROR_AUTH_FAILURE); 3172 } 3173 3174 return err; 3175 } 3176 3177 static struct sk_buff *smp_alloc_skb_cb(struct l2cap_chan *chan, 3178 unsigned long hdr_len, 3179 unsigned long len, int nb) 3180 { 3181 struct sk_buff *skb; 3182 3183 skb = bt_skb_alloc(hdr_len + len, GFP_KERNEL); 3184 if (!skb) 3185 return ERR_PTR(-ENOMEM); 3186 3187 skb->priority = HCI_PRIO_MAX; 3188 bt_cb(skb)->l2cap.chan = chan; 3189 3190 return skb; 3191 } 3192 3193 static const struct l2cap_ops smp_chan_ops = { 3194 .name = "Security Manager", 3195 .ready = smp_ready_cb, 3196 .recv = smp_recv_cb, 3197 .alloc_skb = smp_alloc_skb_cb, 3198 .teardown = smp_teardown_cb, 3199 .resume = smp_resume_cb, 3200 3201 .new_connection = l2cap_chan_no_new_connection, 3202 .state_change = l2cap_chan_no_state_change, 3203 .close = l2cap_chan_no_close, 3204 .defer = l2cap_chan_no_defer, 3205 .suspend = l2cap_chan_no_suspend, 3206 .set_shutdown = l2cap_chan_no_set_shutdown, 3207 .get_sndtimeo = l2cap_chan_no_get_sndtimeo, 3208 }; 3209 3210 static inline int smp_new_conn_cb(struct l2cap_chan *chan, 3211 struct l2cap_chan *new_chan) 3212 { 3213 new_chan->ops = &smp_chan_ops; 3214 3215 /* Other L2CAP channels may request SMP routines in order to 3216 * change the security level. This means that the SMP channel 3217 * lock must be considered in its own category to avoid lockdep 3218 * warnings. 3219 */ 3220 atomic_set(&new_chan->nesting, L2CAP_NESTING_SMP); 3221 3222 return 0; 3223 } 3224 3225 static const struct l2cap_ops smp_root_chan_ops = { 3226 .name = "Security Manager Root", 3227 .new_connection = smp_new_conn_cb, 3228 3229 /* None of these are implemented for the root channel */ 3230 .close = l2cap_chan_no_close, 3231 .alloc_skb = l2cap_chan_no_alloc_skb, 3232 .recv = l2cap_chan_no_recv, 3233 .state_change = l2cap_chan_no_state_change, 3234 .teardown = l2cap_chan_no_teardown, 3235 .ready = l2cap_chan_no_ready, 3236 .defer = l2cap_chan_no_defer, 3237 .suspend = l2cap_chan_no_suspend, 3238 .resume = l2cap_chan_no_resume, 3239 .set_shutdown = l2cap_chan_no_set_shutdown, 3240 .get_sndtimeo = l2cap_chan_no_get_sndtimeo, 3241 }; 3242 3243 static struct l2cap_chan *smp_add_cid(struct hci_dev *hdev, u16 cid) 3244 { 3245 struct l2cap_chan *chan; 3246 struct smp_dev *smp; 3247 struct crypto_kpp *tfm_ecdh; 3248 3249 if (cid == L2CAP_CID_SMP_BREDR) { 3250 smp = NULL; 3251 goto create_chan; 3252 } 3253 3254 smp = kzalloc_obj(*smp); 3255 if (!smp) 3256 return ERR_PTR(-ENOMEM); 3257 3258 tfm_ecdh = crypto_alloc_kpp("ecdh-nist-p256", 0, 0); 3259 if (IS_ERR(tfm_ecdh)) { 3260 bt_dev_err(hdev, "Unable to create ECDH crypto context"); 3261 kfree_sensitive(smp); 3262 return ERR_CAST(tfm_ecdh); 3263 } 3264 3265 smp->local_oob = false; 3266 smp->tfm_ecdh = tfm_ecdh; 3267 3268 create_chan: 3269 chan = l2cap_chan_create(); 3270 if (!chan) { 3271 if (smp) { 3272 crypto_free_kpp(smp->tfm_ecdh); 3273 kfree_sensitive(smp); 3274 } 3275 return ERR_PTR(-ENOMEM); 3276 } 3277 3278 chan->data = smp; 3279 3280 l2cap_add_scid(chan, cid); 3281 3282 l2cap_chan_set_defaults(chan, NULL); 3283 3284 if (cid == L2CAP_CID_SMP) { 3285 u8 bdaddr_type; 3286 3287 hci_copy_identity_address(hdev, &chan->src, &bdaddr_type); 3288 3289 if (bdaddr_type == ADDR_LE_DEV_PUBLIC) 3290 chan->src_type = BDADDR_LE_PUBLIC; 3291 else 3292 chan->src_type = BDADDR_LE_RANDOM; 3293 } else { 3294 bacpy(&chan->src, &hdev->bdaddr); 3295 chan->src_type = BDADDR_BREDR; 3296 } 3297 3298 chan->state = BT_LISTEN; 3299 chan->mode = L2CAP_MODE_BASIC; 3300 chan->imtu = L2CAP_DEFAULT_MTU; 3301 chan->ops = &smp_root_chan_ops; 3302 3303 /* Set correct nesting level for a parent/listening channel */ 3304 atomic_set(&chan->nesting, L2CAP_NESTING_PARENT); 3305 3306 return chan; 3307 } 3308 3309 static void smp_del_chan(struct l2cap_chan *chan) 3310 { 3311 struct smp_dev *smp; 3312 3313 BT_DBG("chan %p", chan); 3314 3315 smp = chan->data; 3316 if (smp) { 3317 chan->data = NULL; 3318 crypto_free_kpp(smp->tfm_ecdh); 3319 kfree_sensitive(smp); 3320 } 3321 3322 l2cap_chan_put(chan); 3323 } 3324 3325 int smp_force_bredr(struct hci_dev *hdev, bool enable) 3326 { 3327 if (enable == hci_dev_test_flag(hdev, HCI_FORCE_BREDR_SMP)) 3328 return -EALREADY; 3329 3330 if (enable) { 3331 struct l2cap_chan *chan; 3332 3333 chan = smp_add_cid(hdev, L2CAP_CID_SMP_BREDR); 3334 if (IS_ERR(chan)) 3335 return PTR_ERR(chan); 3336 3337 hdev->smp_bredr_data = chan; 3338 } else { 3339 struct l2cap_chan *chan; 3340 3341 chan = hdev->smp_bredr_data; 3342 hdev->smp_bredr_data = NULL; 3343 smp_del_chan(chan); 3344 } 3345 3346 hci_dev_change_flag(hdev, HCI_FORCE_BREDR_SMP); 3347 3348 return 0; 3349 } 3350 3351 int smp_register(struct hci_dev *hdev) 3352 { 3353 struct l2cap_chan *chan; 3354 3355 bt_dev_dbg(hdev, ""); 3356 3357 /* If the controller does not support Low Energy operation, then 3358 * there is also no need to register any SMP channel. 3359 */ 3360 if (!lmp_le_capable(hdev)) 3361 return 0; 3362 3363 if (WARN_ON(hdev->smp_data)) { 3364 chan = hdev->smp_data; 3365 hdev->smp_data = NULL; 3366 smp_del_chan(chan); 3367 } 3368 3369 chan = smp_add_cid(hdev, L2CAP_CID_SMP); 3370 if (IS_ERR(chan)) 3371 return PTR_ERR(chan); 3372 3373 hdev->smp_data = chan; 3374 3375 if (!lmp_sc_capable(hdev)) { 3376 /* Flag can be already set here (due to power toggle) */ 3377 if (!hci_dev_test_flag(hdev, HCI_FORCE_BREDR_SMP)) 3378 return 0; 3379 } 3380 3381 if (WARN_ON(hdev->smp_bredr_data)) { 3382 chan = hdev->smp_bredr_data; 3383 hdev->smp_bredr_data = NULL; 3384 smp_del_chan(chan); 3385 } 3386 3387 chan = smp_add_cid(hdev, L2CAP_CID_SMP_BREDR); 3388 if (IS_ERR(chan)) { 3389 int err = PTR_ERR(chan); 3390 chan = hdev->smp_data; 3391 hdev->smp_data = NULL; 3392 smp_del_chan(chan); 3393 return err; 3394 } 3395 3396 hdev->smp_bredr_data = chan; 3397 3398 return 0; 3399 } 3400 3401 void smp_unregister(struct hci_dev *hdev) 3402 { 3403 struct l2cap_chan *chan; 3404 3405 if (hdev->smp_bredr_data) { 3406 chan = hdev->smp_bredr_data; 3407 hdev->smp_bredr_data = NULL; 3408 smp_del_chan(chan); 3409 } 3410 3411 if (hdev->smp_data) { 3412 chan = hdev->smp_data; 3413 hdev->smp_data = NULL; 3414 smp_del_chan(chan); 3415 } 3416 } 3417 3418 #if IS_ENABLED(CONFIG_BT_SELFTEST_SMP) 3419 3420 static int __init test_debug_key(struct crypto_kpp *tfm_ecdh) 3421 { 3422 u8 pk[64]; 3423 int err; 3424 3425 err = set_ecdh_privkey(tfm_ecdh, debug_sk); 3426 if (err) 3427 return err; 3428 3429 err = generate_ecdh_public_key(tfm_ecdh, pk); 3430 if (err) 3431 return err; 3432 3433 if (crypto_memneq(pk, debug_pk, 64)) 3434 return -EINVAL; 3435 3436 return 0; 3437 } 3438 3439 static int __init test_ah(void) 3440 { 3441 const u8 irk[16] = { 3442 0x9b, 0x7d, 0x39, 0x0a, 0xa6, 0x10, 0x10, 0x34, 3443 0x05, 0xad, 0xc8, 0x57, 0xa3, 0x34, 0x02, 0xec }; 3444 const u8 r[3] = { 0x94, 0x81, 0x70 }; 3445 const u8 exp[3] = { 0xaa, 0xfb, 0x0d }; 3446 u8 res[3]; 3447 int err; 3448 3449 err = smp_ah(irk, r, res); 3450 if (err) 3451 return err; 3452 3453 if (crypto_memneq(res, exp, 3)) 3454 return -EINVAL; 3455 3456 return 0; 3457 } 3458 3459 static int __init test_c1(void) 3460 { 3461 const u8 k[16] = { 3462 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 3463 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00 }; 3464 const u8 r[16] = { 3465 0xe0, 0x2e, 0x70, 0xc6, 0x4e, 0x27, 0x88, 0x63, 3466 0x0e, 0x6f, 0xad, 0x56, 0x21, 0xd5, 0x83, 0x57 }; 3467 const u8 preq[7] = { 0x01, 0x01, 0x00, 0x00, 0x10, 0x07, 0x07 }; 3468 const u8 pres[7] = { 0x02, 0x03, 0x00, 0x00, 0x08, 0x00, 0x05 }; 3469 const u8 _iat = 0x01; 3470 const u8 _rat = 0x00; 3471 const bdaddr_t ra = { { 0xb6, 0xb5, 0xb4, 0xb3, 0xb2, 0xb1 } }; 3472 const bdaddr_t ia = { { 0xa6, 0xa5, 0xa4, 0xa3, 0xa2, 0xa1 } }; 3473 const u8 exp[16] = { 3474 0x86, 0x3b, 0xf1, 0xbe, 0xc5, 0x4d, 0xa7, 0xd2, 3475 0xea, 0x88, 0x89, 0x87, 0xef, 0x3f, 0x1e, 0x1e }; 3476 u8 res[16]; 3477 int err; 3478 3479 err = smp_c1(k, r, preq, pres, _iat, &ia, _rat, &ra, res); 3480 if (err) 3481 return err; 3482 3483 if (crypto_memneq(res, exp, 16)) 3484 return -EINVAL; 3485 3486 return 0; 3487 } 3488 3489 static int __init test_s1(void) 3490 { 3491 const u8 k[16] = { 3492 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 3493 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00 }; 3494 const u8 r1[16] = { 3495 0x88, 0x77, 0x66, 0x55, 0x44, 0x33, 0x22, 0x11 }; 3496 const u8 r2[16] = { 3497 0x00, 0xff, 0xee, 0xdd, 0xcc, 0xbb, 0xaa, 0x99 }; 3498 const u8 exp[16] = { 3499 0x62, 0xa0, 0x6d, 0x79, 0xae, 0x16, 0x42, 0x5b, 3500 0x9b, 0xf4, 0xb0, 0xe8, 0xf0, 0xe1, 0x1f, 0x9a }; 3501 u8 res[16]; 3502 int err; 3503 3504 err = smp_s1(k, r1, r2, res); 3505 if (err) 3506 return err; 3507 3508 if (crypto_memneq(res, exp, 16)) 3509 return -EINVAL; 3510 3511 return 0; 3512 } 3513 3514 static int __init test_f4(void) 3515 { 3516 const u8 u[32] = { 3517 0xe6, 0x9d, 0x35, 0x0e, 0x48, 0x01, 0x03, 0xcc, 3518 0xdb, 0xfd, 0xf4, 0xac, 0x11, 0x91, 0xf4, 0xef, 3519 0xb9, 0xa5, 0xf9, 0xe9, 0xa7, 0x83, 0x2c, 0x5e, 3520 0x2c, 0xbe, 0x97, 0xf2, 0xd2, 0x03, 0xb0, 0x20 }; 3521 const u8 v[32] = { 3522 0xfd, 0xc5, 0x7f, 0xf4, 0x49, 0xdd, 0x4f, 0x6b, 3523 0xfb, 0x7c, 0x9d, 0xf1, 0xc2, 0x9a, 0xcb, 0x59, 3524 0x2a, 0xe7, 0xd4, 0xee, 0xfb, 0xfc, 0x0a, 0x90, 3525 0x9a, 0xbb, 0xf6, 0x32, 0x3d, 0x8b, 0x18, 0x55 }; 3526 const u8 x[16] = { 3527 0xab, 0xae, 0x2b, 0x71, 0xec, 0xb2, 0xff, 0xff, 3528 0x3e, 0x73, 0x77, 0xd1, 0x54, 0x84, 0xcb, 0xd5 }; 3529 const u8 z = 0x00; 3530 const u8 exp[16] = { 3531 0x2d, 0x87, 0x74, 0xa9, 0xbe, 0xa1, 0xed, 0xf1, 3532 0x1c, 0xbd, 0xa9, 0x07, 0xf1, 0x16, 0xc9, 0xf2 }; 3533 u8 res[16]; 3534 int err; 3535 3536 err = smp_f4(u, v, x, z, res); 3537 if (err) 3538 return err; 3539 3540 if (crypto_memneq(res, exp, 16)) 3541 return -EINVAL; 3542 3543 return 0; 3544 } 3545 3546 static int __init test_f5(void) 3547 { 3548 const u8 w[32] = { 3549 0x98, 0xa6, 0xbf, 0x73, 0xf3, 0x34, 0x8d, 0x86, 3550 0xf1, 0x66, 0xf8, 0xb4, 0x13, 0x6b, 0x79, 0x99, 3551 0x9b, 0x7d, 0x39, 0x0a, 0xa6, 0x10, 0x10, 0x34, 3552 0x05, 0xad, 0xc8, 0x57, 0xa3, 0x34, 0x02, 0xec }; 3553 const u8 n1[16] = { 3554 0xab, 0xae, 0x2b, 0x71, 0xec, 0xb2, 0xff, 0xff, 3555 0x3e, 0x73, 0x77, 0xd1, 0x54, 0x84, 0xcb, 0xd5 }; 3556 const u8 n2[16] = { 3557 0xcf, 0xc4, 0x3d, 0xff, 0xf7, 0x83, 0x65, 0x21, 3558 0x6e, 0x5f, 0xa7, 0x25, 0xcc, 0xe7, 0xe8, 0xa6 }; 3559 const u8 a1[7] = { 0xce, 0xbf, 0x37, 0x37, 0x12, 0x56, 0x00 }; 3560 const u8 a2[7] = { 0xc1, 0xcf, 0x2d, 0x70, 0x13, 0xa7, 0x00 }; 3561 const u8 exp_ltk[16] = { 3562 0x38, 0x0a, 0x75, 0x94, 0xb5, 0x22, 0x05, 0x98, 3563 0x23, 0xcd, 0xd7, 0x69, 0x11, 0x79, 0x86, 0x69 }; 3564 const u8 exp_mackey[16] = { 3565 0x20, 0x6e, 0x63, 0xce, 0x20, 0x6a, 0x3f, 0xfd, 3566 0x02, 0x4a, 0x08, 0xa1, 0x76, 0xf1, 0x65, 0x29 }; 3567 u8 mackey[16], ltk[16]; 3568 int err; 3569 3570 err = smp_f5(w, n1, n2, a1, a2, mackey, ltk); 3571 if (err) 3572 return err; 3573 3574 if (crypto_memneq(mackey, exp_mackey, 16)) 3575 return -EINVAL; 3576 3577 if (crypto_memneq(ltk, exp_ltk, 16)) 3578 return -EINVAL; 3579 3580 return 0; 3581 } 3582 3583 static int __init test_f6(void) 3584 { 3585 const u8 w[16] = { 3586 0x20, 0x6e, 0x63, 0xce, 0x20, 0x6a, 0x3f, 0xfd, 3587 0x02, 0x4a, 0x08, 0xa1, 0x76, 0xf1, 0x65, 0x29 }; 3588 const u8 n1[16] = { 3589 0xab, 0xae, 0x2b, 0x71, 0xec, 0xb2, 0xff, 0xff, 3590 0x3e, 0x73, 0x77, 0xd1, 0x54, 0x84, 0xcb, 0xd5 }; 3591 const u8 n2[16] = { 3592 0xcf, 0xc4, 0x3d, 0xff, 0xf7, 0x83, 0x65, 0x21, 3593 0x6e, 0x5f, 0xa7, 0x25, 0xcc, 0xe7, 0xe8, 0xa6 }; 3594 const u8 r[16] = { 3595 0xc8, 0x0f, 0x2d, 0x0c, 0xd2, 0x42, 0xda, 0x08, 3596 0x54, 0xbb, 0x53, 0xb4, 0x3b, 0x34, 0xa3, 0x12 }; 3597 const u8 io_cap[3] = { 0x02, 0x01, 0x01 }; 3598 const u8 a1[7] = { 0xce, 0xbf, 0x37, 0x37, 0x12, 0x56, 0x00 }; 3599 const u8 a2[7] = { 0xc1, 0xcf, 0x2d, 0x70, 0x13, 0xa7, 0x00 }; 3600 const u8 exp[16] = { 3601 0x61, 0x8f, 0x95, 0xda, 0x09, 0x0b, 0x6c, 0xd2, 3602 0xc5, 0xe8, 0xd0, 0x9c, 0x98, 0x73, 0xc4, 0xe3 }; 3603 u8 res[16]; 3604 int err; 3605 3606 err = smp_f6(w, n1, n2, r, io_cap, a1, a2, res); 3607 if (err) 3608 return err; 3609 3610 if (crypto_memneq(res, exp, 16)) 3611 return -EINVAL; 3612 3613 return 0; 3614 } 3615 3616 static int __init test_g2(void) 3617 { 3618 const u8 u[32] = { 3619 0xe6, 0x9d, 0x35, 0x0e, 0x48, 0x01, 0x03, 0xcc, 3620 0xdb, 0xfd, 0xf4, 0xac, 0x11, 0x91, 0xf4, 0xef, 3621 0xb9, 0xa5, 0xf9, 0xe9, 0xa7, 0x83, 0x2c, 0x5e, 3622 0x2c, 0xbe, 0x97, 0xf2, 0xd2, 0x03, 0xb0, 0x20 }; 3623 const u8 v[32] = { 3624 0xfd, 0xc5, 0x7f, 0xf4, 0x49, 0xdd, 0x4f, 0x6b, 3625 0xfb, 0x7c, 0x9d, 0xf1, 0xc2, 0x9a, 0xcb, 0x59, 3626 0x2a, 0xe7, 0xd4, 0xee, 0xfb, 0xfc, 0x0a, 0x90, 3627 0x9a, 0xbb, 0xf6, 0x32, 0x3d, 0x8b, 0x18, 0x55 }; 3628 const u8 x[16] = { 3629 0xab, 0xae, 0x2b, 0x71, 0xec, 0xb2, 0xff, 0xff, 3630 0x3e, 0x73, 0x77, 0xd1, 0x54, 0x84, 0xcb, 0xd5 }; 3631 const u8 y[16] = { 3632 0xcf, 0xc4, 0x3d, 0xff, 0xf7, 0x83, 0x65, 0x21, 3633 0x6e, 0x5f, 0xa7, 0x25, 0xcc, 0xe7, 0xe8, 0xa6 }; 3634 const u32 exp_val = 0x2f9ed5ba % 1000000; 3635 u32 val; 3636 int err; 3637 3638 err = smp_g2(u, v, x, y, &val); 3639 if (err) 3640 return err; 3641 3642 if (val != exp_val) 3643 return -EINVAL; 3644 3645 return 0; 3646 } 3647 3648 static int __init test_h6(void) 3649 { 3650 const u8 w[16] = { 3651 0x9b, 0x7d, 0x39, 0x0a, 0xa6, 0x10, 0x10, 0x34, 3652 0x05, 0xad, 0xc8, 0x57, 0xa3, 0x34, 0x02, 0xec }; 3653 const u8 key_id[4] = { 0x72, 0x62, 0x65, 0x6c }; 3654 const u8 exp[16] = { 3655 0x99, 0x63, 0xb1, 0x80, 0xe2, 0xa9, 0xd3, 0xe8, 3656 0x1c, 0xc9, 0x6d, 0xe7, 0x02, 0xe1, 0x9a, 0x2d }; 3657 u8 res[16]; 3658 int err; 3659 3660 err = smp_h6(w, key_id, res); 3661 if (err) 3662 return err; 3663 3664 if (crypto_memneq(res, exp, 16)) 3665 return -EINVAL; 3666 3667 return 0; 3668 } 3669 3670 static char test_smp_buffer[32]; 3671 3672 static ssize_t test_smp_read(struct file *file, char __user *user_buf, 3673 size_t count, loff_t *ppos) 3674 { 3675 return simple_read_from_buffer(user_buf, count, ppos, test_smp_buffer, 3676 strlen(test_smp_buffer)); 3677 } 3678 3679 static const struct file_operations test_smp_fops = { 3680 .open = simple_open, 3681 .read = test_smp_read, 3682 .llseek = default_llseek, 3683 }; 3684 3685 static int __init run_selftests(struct crypto_kpp *tfm_ecdh) 3686 { 3687 ktime_t calltime, delta, rettime; 3688 unsigned long long duration; 3689 int err; 3690 3691 calltime = ktime_get(); 3692 3693 err = test_debug_key(tfm_ecdh); 3694 if (err) { 3695 BT_ERR("debug_key test failed"); 3696 goto done; 3697 } 3698 3699 err = test_ah(); 3700 if (err) { 3701 BT_ERR("smp_ah test failed"); 3702 goto done; 3703 } 3704 3705 err = test_c1(); 3706 if (err) { 3707 BT_ERR("smp_c1 test failed"); 3708 goto done; 3709 } 3710 3711 err = test_s1(); 3712 if (err) { 3713 BT_ERR("smp_s1 test failed"); 3714 goto done; 3715 } 3716 3717 err = test_f4(); 3718 if (err) { 3719 BT_ERR("smp_f4 test failed"); 3720 goto done; 3721 } 3722 3723 err = test_f5(); 3724 if (err) { 3725 BT_ERR("smp_f5 test failed"); 3726 goto done; 3727 } 3728 3729 err = test_f6(); 3730 if (err) { 3731 BT_ERR("smp_f6 test failed"); 3732 goto done; 3733 } 3734 3735 err = test_g2(); 3736 if (err) { 3737 BT_ERR("smp_g2 test failed"); 3738 goto done; 3739 } 3740 3741 err = test_h6(); 3742 if (err) { 3743 BT_ERR("smp_h6 test failed"); 3744 goto done; 3745 } 3746 3747 rettime = ktime_get(); 3748 delta = ktime_sub(rettime, calltime); 3749 duration = (unsigned long long) ktime_to_ns(delta) >> 10; 3750 3751 BT_INFO("SMP test passed in %llu usecs", duration); 3752 3753 done: 3754 if (!err) 3755 snprintf(test_smp_buffer, sizeof(test_smp_buffer), 3756 "PASS (%llu usecs)\n", duration); 3757 else 3758 snprintf(test_smp_buffer, sizeof(test_smp_buffer), "FAIL\n"); 3759 3760 debugfs_create_file("selftest_smp", 0444, bt_debugfs, NULL, 3761 &test_smp_fops); 3762 3763 return err; 3764 } 3765 3766 int __init bt_selftest_smp(void) 3767 { 3768 struct crypto_kpp *tfm_ecdh; 3769 int err; 3770 3771 tfm_ecdh = crypto_alloc_kpp("ecdh-nist-p256", 0, 0); 3772 if (IS_ERR(tfm_ecdh)) { 3773 BT_ERR("Unable to create ECDH crypto context"); 3774 return PTR_ERR(tfm_ecdh); 3775 } 3776 3777 err = run_selftests(tfm_ecdh); 3778 3779 crypto_free_kpp(tfm_ecdh); 3780 3781 return err; 3782 } 3783 3784 #endif 3785