]> git.ipfire.org Git - thirdparty/kernel/stable.git/commitdiff
Bluetooth: Fix setting correct security level when initiating SMP
authorJohan Hedberg <johan.hedberg@intel.com>
Thu, 18 Sep 2014 08:26:32 +0000 (11:26 +0300)
committerZefan Li <lizefan@huawei.com>
Mon, 2 Feb 2015 09:04:37 +0000 (17:04 +0800)
commit 5eb596f55cacc2389554a8d7572d90d5e9d4269d upstream.

We can only determine the final security level when both pairing request
and response have been exchanged. When initiating pairing the starting
target security level is set to MEDIUM unless explicitly specified to be
HIGH, so that we can still perform pairing even if the remote doesn't
have MITM capabilities. However, once we've received the pairing
response we should re-consult the remote and local IO capabilities and
upgrade the target security level if necessary.

Without this patch the resulting Long Term Key will occasionally be
reported to be unauthenticated when it in reality is an authenticated
one.

Signed-off-by: Johan Hedberg <johan.hedberg@intel.com>
Signed-off-by: Marcel Holtmann <marcel@holtmann.org>
[lizf: Backported to 3.4: adjust context]
Signed-off-by: Zefan Li <lizefan@huawei.com>
net/bluetooth/smp.c

index 605156f13899d45d0000513c3253254ace189982..61e2494dc18821cf9e0e000121aa7f1fb8dc9122 100644 (file)
@@ -325,8 +325,11 @@ static int tk_request(struct l2cap_conn *conn, u8 remote_oob, u8 auth,
        }
 
        /* Not Just Works/Confirm results in MITM Authentication */
-       if (method != JUST_CFM)
+       if (method != JUST_CFM) {
                set_bit(SMP_FLAG_MITM_AUTH, &smp->smp_flags);
+               if (hcon->pending_sec_level < BT_SECURITY_HIGH)
+                       hcon->pending_sec_level = BT_SECURITY_HIGH;
+       }
 
        /* If both devices have Keyoard-Display I/O, the master
         * Confirms and the slave Enters the passkey.