[border-agent] track successful connection with ephemeral key (#11109)

This commit adds a new variable, `mDidConnectWithEphemeralKey`, which
tracks whether a successful secure session is established using the
ephemeral key. This variable is used in `HandleConnected()` to
determine whether to stop using the ephemeral key when the Border
Agent is notified that the secure session is disconnected.

This change ensures that ephemeral key use is not stopped after a
failed connection attempt, while still guaranteeing that an ephemeral
key can only be used once.

Without this fix, a failed connection attempt would immediately stop
the use of the ephemeral key. With this change, the intended
`kMaxEphemeralKeyConnectionAttempts` will be applied.
This commit is contained in:
Abtin Keshavarzian
2025-01-06 13:27:26 -08:00
committed by GitHub
parent 54f6c273ca
commit e4fb743a85
2 changed files with 10 additions and 3 deletions
+8 -2
View File
@@ -56,6 +56,7 @@ BorderAgent::BorderAgent(Instance &aInstance)
#endif
#if OPENTHREAD_CONFIG_BORDER_AGENT_EPHEMERAL_KEY_ENABLE
, mUsingEphemeralKey(false)
, mDidConnectWithEphemeralKey(false)
, mOldUdpPort(0)
, mEphemeralKeyTimer(aInstance)
, mEphemeralKeyTask(aInstance)
@@ -246,6 +247,7 @@ void BorderAgent::HandleConnected(Dtls::Session::ConnectEvent aEvent)
#if OPENTHREAD_CONFIG_BORDER_AGENT_EPHEMERAL_KEY_ENABLE
if (mUsingEphemeralKey)
{
mDidConnectWithEphemeralKey = true;
mCounters.mEpskcSecureSessionSuccesses++;
mEphemeralKeyTask.Post();
}
@@ -264,7 +266,10 @@ void BorderAgent::HandleConnected(Dtls::Session::ConnectEvent aEvent)
#if OPENTHREAD_CONFIG_BORDER_AGENT_EPHEMERAL_KEY_ENABLE
if (mUsingEphemeralKey)
{
RestartAfterRemovingEphemeralKey();
if (mDidConnectWithEphemeralKey)
{
RestartAfterRemovingEphemeralKey();
}
if (aEvent == Dtls::Session::kDisconnectedError)
{
@@ -735,7 +740,8 @@ Error BorderAgent::SetEphemeralKey(const char *aKeyString, uint32_t aTimeout, ui
// callbacks (like `HandleConnected()`) may be invoked from
// `Start()` itself.
mUsingEphemeralKey = true;
mUsingEphemeralKey = true;
mDidConnectWithEphemeralKey = false;
error = Start(aUdpPort, reinterpret_cast<const uint8_t *>(aKeyString), static_cast<uint8_t>(length));
+2 -1
View File
@@ -337,7 +337,8 @@ private:
bool mIdInitialized;
#endif
#if OPENTHREAD_CONFIG_BORDER_AGENT_EPHEMERAL_KEY_ENABLE
bool mUsingEphemeralKey;
bool mUsingEphemeralKey : 1;
bool mDidConnectWithEphemeralKey : 1;
uint16_t mOldUdpPort;
EphemeralKeyTimer mEphemeralKeyTimer;
EphemeralKeyTask mEphemeralKeyTask;