Browse Source

Fix room/repeater/sensor silent message rejection when companion RTC diverges from app clock

Don't store the login timestamp in last_timestamp. Login uses the
companion's RTC while messages use the app's clock - when these diverge,
messages get silently rejected by the replay check (sender_timestamp <
last_timestamp). Login replay protection is already handled by hasSeen()
in the mesh layer.

Fixes #1551
pull/1889/head
Wouter Bijen 5 months ago
parent
commit
edcdf7dea5
  1. 5
      examples/simple_repeater/MyMesh.cpp
  2. 5
      examples/simple_room_server/MyMesh.cpp
  3. 5
      examples/simple_sensor/SensorMesh.cpp

5
examples/simple_repeater/MyMesh.cpp

@ -117,7 +117,10 @@ uint8_t MyMesh::handleLoginReq(const mesh::Identity& sender, const uint8_t* secr
}
MESH_DEBUG_PRINTLN("Login success!");
client->last_timestamp = sender_timestamp;
// NOTE: don't update last_timestamp here - login uses companion RTC which may differ
// from the app clock used for messages. Mixing the two causes silent message rejection
// when the companion RTC runs ahead of the app clock (see #1551).
// Login replay protection is already handled by hasSeen() in the mesh layer.
client->last_activity = getRTCClock()->getCurrentTime();
client->permissions &= ~0x03;
client->permissions |= perms;

5
examples/simple_room_server/MyMesh.cpp

@ -321,7 +321,10 @@ void MyMesh::onAnonDataRecv(mesh::Packet *packet, const uint8_t *secret, const m
}
MESH_DEBUG_PRINTLN("Login success!");
client->last_timestamp = sender_timestamp;
// NOTE: don't update last_timestamp here - login uses companion RTC which may differ
// from the app clock used for messages. Mixing the two causes silent message rejection
// when the companion RTC runs ahead of the app clock (see #1551).
// Login replay protection is already handled by hasSeen() in the mesh layer.
client->extra.room.sync_since = sender_sync_since;
client->extra.room.pending_ack = 0;
client->extra.room.push_failures = 0;

5
examples/simple_sensor/SensorMesh.cpp

@ -352,7 +352,10 @@ uint8_t SensorMesh::handleLoginReq(const mesh::Identity& sender, const uint8_t*
}
MESH_DEBUG_PRINTLN("Login success!");
client->last_timestamp = sender_timestamp;
// NOTE: don't update last_timestamp here - login uses companion RTC which may differ
// from the app clock used for messages. Mixing the two causes silent message rejection
// when the companion RTC runs ahead of the app clock (see #1551).
// Login replay protection is already handled by hasSeen() in the mesh layer.
client->last_activity = getRTCClock()->getCurrentTime();
client->permissions |= PERM_ACL_ADMIN;
memcpy(client->shared_secret, secret, PUB_KEY_SIZE);

Loading…
Cancel
Save