From e4fb743a856915765c2871467a38a25e61aa394c Mon Sep 17 00:00:00 2001 From: Abtin Keshavarzian Date: Mon, 6 Jan 2025 13:27:26 -0800 Subject: [PATCH] [border-agent] track successful connection with ephemeral key (#11109) This commit adds a new variable, `mDidConnectWithEphemeralKey`, which tracks whether a successful secure session is established using the ephemeral key. This variable is used in `HandleConnected()` to determine whether to stop using the ephemeral key when the Border Agent is notified that the secure session is disconnected. This change ensures that ephemeral key use is not stopped after a failed connection attempt, while still guaranteeing that an ephemeral key can only be used once. Without this fix, a failed connection attempt would immediately stop the use of the ephemeral key. With this change, the intended `kMaxEphemeralKeyConnectionAttempts` will be applied. --- src/core/meshcop/border_agent.cpp | 10 ++++++++-- src/core/meshcop/border_agent.hpp | 3 ++- 2 files changed, 10 insertions(+), 3 deletions(-) diff --git a/src/core/meshcop/border_agent.cpp b/src/core/meshcop/border_agent.cpp index 20523602e..fb62e1225 100644 --- a/src/core/meshcop/border_agent.cpp +++ b/src/core/meshcop/border_agent.cpp @@ -56,6 +56,7 @@ BorderAgent::BorderAgent(Instance &aInstance) #endif #if OPENTHREAD_CONFIG_BORDER_AGENT_EPHEMERAL_KEY_ENABLE , mUsingEphemeralKey(false) + , mDidConnectWithEphemeralKey(false) , mOldUdpPort(0) , mEphemeralKeyTimer(aInstance) , mEphemeralKeyTask(aInstance) @@ -246,6 +247,7 @@ void BorderAgent::HandleConnected(Dtls::Session::ConnectEvent aEvent) #if OPENTHREAD_CONFIG_BORDER_AGENT_EPHEMERAL_KEY_ENABLE if (mUsingEphemeralKey) { + mDidConnectWithEphemeralKey = true; mCounters.mEpskcSecureSessionSuccesses++; mEphemeralKeyTask.Post(); } @@ -264,7 +266,10 @@ void BorderAgent::HandleConnected(Dtls::Session::ConnectEvent aEvent) #if OPENTHREAD_CONFIG_BORDER_AGENT_EPHEMERAL_KEY_ENABLE if (mUsingEphemeralKey) { - RestartAfterRemovingEphemeralKey(); + if (mDidConnectWithEphemeralKey) + { + RestartAfterRemovingEphemeralKey(); + } if (aEvent == Dtls::Session::kDisconnectedError) { @@ -735,7 +740,8 @@ Error BorderAgent::SetEphemeralKey(const char *aKeyString, uint32_t aTimeout, ui // callbacks (like `HandleConnected()`) may be invoked from // `Start()` itself. - mUsingEphemeralKey = true; + mUsingEphemeralKey = true; + mDidConnectWithEphemeralKey = false; error = Start(aUdpPort, reinterpret_cast(aKeyString), static_cast(length)); diff --git a/src/core/meshcop/border_agent.hpp b/src/core/meshcop/border_agent.hpp index 60f4160d1..ba96bc926 100644 --- a/src/core/meshcop/border_agent.hpp +++ b/src/core/meshcop/border_agent.hpp @@ -337,7 +337,8 @@ private: bool mIdInitialized; #endif #if OPENTHREAD_CONFIG_BORDER_AGENT_EPHEMERAL_KEY_ENABLE - bool mUsingEphemeralKey; + bool mUsingEphemeralKey : 1; + bool mDidConnectWithEphemeralKey : 1; uint16_t mOldUdpPort; EphemeralKeyTimer mEphemeralKeyTimer; EphemeralKeyTask mEphemeralKeyTask;