Skip to content

Commit

Permalink
Verify the device is under commissioning before accessing/storing inf…
Browse files Browse the repository at this point in the history
…ormation in fabric (#15204)
  • Loading branch information
yufengwangca authored and pull[bot] committed Sep 22, 2023
1 parent 22a606c commit 9c0917b
Show file tree
Hide file tree
Showing 2 changed files with 13 additions and 2 deletions.
Original file line number Diff line number Diff line change
Expand Up @@ -527,6 +527,10 @@ bool emberAfOperationalCredentialsClusterAddNOCCallback(app::CommandHandler * co

emberAfPrintln(EMBER_AF_PRINT_DEBUG, "OpCreds: commissioner has added a NOC");

VerifyOrExit(Server::GetInstance().GetCommissioningWindowManager().CommissioningWindowStatus() !=
AdministratorCommissioning::CommissioningWindowStatus::kWindowNotOpen,
nocResponse = OperationalCertStatus::kInvalidNOC);

err = gFabricBeingCommissioned.SetNOCCert(NOCValue);
VerifyOrExit(err == CHIP_NO_ERROR, nocResponse = ConvertToNOCResponseStatus(err));

Expand Down Expand Up @@ -747,6 +751,10 @@ bool emberAfOperationalCredentialsClusterCSRRequestCallback(app::CommandHandler
size_t nocsrLengthEstimate = 0;
ByteSpan kNoVendorReserved;

VerifyOrExit(Server::GetInstance().GetCommissioningWindowManager().CommissioningWindowStatus() !=
AdministratorCommissioning::CommissioningWindowStatus::kWindowNotOpen,
err = CHIP_ERROR_INCORRECT_STATE);

// Always generate a new operational keypair for any new CSRRequest
if (gFabricBeingCommissioned.GetOperationalKey() != nullptr)
{
Expand Down Expand Up @@ -815,6 +823,10 @@ bool emberAfOperationalCredentialsClusterAddTrustedRootCertificateCallback(

emberAfPrintln(EMBER_AF_PRINT_DEBUG, "OpCreds: commissioner has added a trusted root Cert");

VerifyOrExit(Server::GetInstance().GetCommissioningWindowManager().CommissioningWindowStatus() !=
AdministratorCommissioning::CommissioningWindowStatus::kWindowNotOpen,
status = EMBER_ZCL_STATUS_FAILURE);

// TODO: Ensure we do not duplicate roots in storage, and detect "same key, different cert" errors
// TODO: Validate cert signature prior to setting.
VerifyOrExit(gFabricBeingCommissioned.SetRootCert(RootCertificate) == CHIP_NO_ERROR, status = EMBER_ZCL_STATUS_INVALID_FIELD);
Expand Down
3 changes: 1 addition & 2 deletions src/app/server/CommissioningWindowManager.cpp
Original file line number Diff line number Diff line change
Expand Up @@ -88,6 +88,7 @@ void CommissioningWindowManager::ResetState()
mECMPasscodeID = 0;
mECMIterations = 0;
mECMSaltLength = 0;
mWindowStatus = app::Clusters::AdministratorCommissioning::CommissioningWindowStatus::kWindowNotOpen;

memset(&mECMPASEVerifier, 0, sizeof(mECMPASEVerifier));
memset(mECMSalt, 0, sizeof(mECMSalt));
Expand Down Expand Up @@ -334,8 +335,6 @@ CHIP_ERROR CommissioningWindowManager::StopAdvertisement(bool aShuttingDown)
}
#endif

mWindowStatus = AdministratorCommissioning::CommissioningWindowStatus::kWindowNotOpen;

// If aShuttingDown, don't try to change our DNS-SD advertisements.
if (!aShuttingDown)
{
Expand Down

0 comments on commit 9c0917b

Please sign in to comment.