xref: /btstack/src/mesh/mesh_upper_transport.c (revision 370463bf12eb59b0d47517cca5b956b7757296c6)
1 /*
2  * Copyright (C) 2014 BlueKitchen GmbH
3  *
4  * Redistribution and use in source and binary forms, with or without
5  * modification, are permitted provided that the following conditions
6  * are met:
7  *
8  * 1. Redistributions of source code must retain the above copyright
9  *    notice, this list of conditions and the following disclaimer.
10  * 2. Redistributions in binary form must reproduce the above copyright
11  *    notice, this list of conditions and the following disclaimer in the
12  *    documentation and/or other materials provided with the distribution.
13  * 3. Neither the name of the copyright holders nor the names of
14  *    contributors may be used to endorse or promote products derived
15  *    from this software without specific prior written permission.
16  * 4. Any redistribution, use, or modification is done solely for
17  *    personal benefit and not for any commercial purpose or for
18  *    monetary gain.
19  *
20  * THIS SOFTWARE IS PROVIDED BY BLUEKITCHEN GMBH AND CONTRIBUTORS
21  * ``AS IS'' AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT
22  * LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS
23  * FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL MATTHIAS
24  * RINGWALD OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT,
25  * INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING,
26  * BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS
27  * OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED
28  * AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY,
29  * OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF
30  * THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
31  * SUCH DAMAGE.
32  *
33  * Please inquire about commercial licensing options at
34  * [email protected]
35  *
36  */
37 
38 #define BTSTACK_FILE__ "mesh_upper_transport.c"
39 
40 #include "mesh/mesh_upper_transport.h"
41 
42 #include <stdio.h>
43 #include <stdlib.h>
44 #include <string.h>
45 
46 #include "btstack_util.h"
47 #include "btstack_memory.h"
48 #include "btstack_debug.h"
49 
50 #include "mesh/beacon.h"
51 #include "mesh/mesh_iv_index_seq_number.h"
52 #include "mesh/mesh_keys.h"
53 #include "mesh/mesh_lower_transport.h"
54 #include "mesh/mesh_peer.h"
55 #include "mesh/mesh_virtual_addresses.h"
56 
57 // TODO: extract mesh_pdu functions into lower transport or network
58 #include "mesh/mesh_access.h"
59 
60 // combined key x address iterator for upper transport decryption
61 
62 typedef struct {
63     // state
64     mesh_transport_key_iterator_t  key_it;
65     mesh_virtual_address_iterator_t address_it;
66     // elements
67     const mesh_transport_key_t *   key;
68     const mesh_virtual_address_t * address;
69     // address - might be virtual
70     uint16_t dst;
71     // key info
72 } mesh_transport_key_and_virtual_address_iterator_t;
73 
74 static void mesh_upper_transport_validate_segmented_message(void);
75 static void mesh_upper_transport_run(void);
76 
77 // upper transport callbacks - in access layer
78 static void (*mesh_access_message_handler)( mesh_transport_callback_type_t callback_type, mesh_transport_status_t status, mesh_pdu_t * pdu);
79 static void (*mesh_control_message_handler)( mesh_transport_callback_type_t callback_type, mesh_transport_status_t status, mesh_pdu_t * pdu);
80 
81 //
82 static int crypto_active;
83 static uint8_t application_nonce[13];
84 static btstack_crypto_ccm_t ccm;
85 static uint8_t crypto_buffer[MESH_ACCESS_PAYLOAD_MAX];
86 
87 static mesh_transport_key_and_virtual_address_iterator_t mesh_transport_key_it;
88 
89 static mesh_access_pdu_t *      incoming_access_pdu_encrypted;
90 static mesh_access_pdu_t *      incoming_access_pdu_decrypted;
91 
92 static mesh_access_pdu_t        incoming_access_pdu_encrypted_singleton;
93 static mesh_access_pdu_t        incoming_access_pdu_decrypted_singleton;
94 
95 static mesh_control_pdu_t       incoming_control_pdu_singleton;
96 static mesh_control_pdu_t *     incoming_control_pdu;
97 
98 // incoming unsegmented (network) and segmented (transport) control and access messages
99 static btstack_linked_list_t upper_transport_incoming;
100 
101 // outgoing unsegmented and segmented control and access messages
102 static btstack_linked_list_t upper_transport_outgoing;
103 
104 // outgoing upper transport messages that have been sent to lower transport and wait for sent event
105 static btstack_linked_list_t upper_transport_outgoing_active;
106 
107 // TODO: higher layer define used for assert
108 #define MESH_ACCESS_OPCODE_NOT_SET 0xFFFFFFFEu
109 
110 static void mesh_print_hex(const char * name, const uint8_t * data, uint16_t len){
111     printf("%-20s ", name);
112     printf_hexdump(data, len);
113 }
114 // static void mesh_print_x(const char * name, uint32_t value){
115 //     printf("%20s: 0x%x", name, (int) value);
116 // }
117 
118 static void mesh_transport_key_and_virtual_address_iterator_init(mesh_transport_key_and_virtual_address_iterator_t *it,
119                                                                  uint16_t dst, uint16_t netkey_index, uint8_t akf,
120                                                                  uint8_t aid) {
121     printf("KEY_INIT: dst %04x, akf %x, aid %x\n", dst, akf, aid);
122     // config
123     it->dst   = dst;
124     // init elements
125     it->key     = NULL;
126     it->address = NULL;
127     // init element iterators
128     mesh_transport_key_aid_iterator_init(&it->key_it, netkey_index, akf, aid);
129     // init address iterator
130     if (mesh_network_address_virtual(it->dst)){
131         mesh_virtual_address_iterator_init(&it->address_it, dst);
132         // get first key
133         if (mesh_transport_key_aid_iterator_has_more(&it->key_it)) {
134             it->key = mesh_transport_key_aid_iterator_get_next(&it->key_it);
135         }
136     }
137 }
138 
139 // cartesian product: keys x addressses
140 static int mesh_transport_key_and_virtual_address_iterator_has_more(mesh_transport_key_and_virtual_address_iterator_t * it){
141     if (mesh_network_address_virtual(it->dst)) {
142         // find next valid entry
143         while (true){
144             if (mesh_virtual_address_iterator_has_more(&it->address_it)) return 1;
145             if (!mesh_transport_key_aid_iterator_has_more(&it->key_it)) return 0;
146             // get next key
147             it->key = mesh_transport_key_aid_iterator_get_next(&it->key_it);
148             mesh_virtual_address_iterator_init(&it->address_it, it->dst);
149         }
150     } else {
151         return mesh_transport_key_aid_iterator_has_more(&it->key_it);
152     }
153 }
154 
155 static void mesh_transport_key_and_virtual_address_iterator_next(mesh_transport_key_and_virtual_address_iterator_t * it){
156     if (mesh_network_address_virtual(it->dst)) {
157         it->address = mesh_virtual_address_iterator_get_next(&it->address_it);
158     } else {
159         it->key = mesh_transport_key_aid_iterator_get_next(&it->key_it);
160     }
161 }
162 
163 // UPPER TRANSPORT
164 
165 uint16_t mesh_access_dst(mesh_access_pdu_t * access_pdu){
166     return big_endian_read_16(access_pdu->network_header, 7);
167 }
168 
169 uint16_t mesh_access_ctl(mesh_access_pdu_t * access_pdu){
170     return access_pdu->network_header[1] >> 7;
171 }
172 
173 uint32_t mesh_access_seq(mesh_access_pdu_t * access_pdu){
174     return big_endian_read_24(access_pdu->network_header, 2);
175 }
176 
177 void mesh_access_set_nid_ivi(mesh_access_pdu_t * access_pdu, uint8_t nid_ivi){
178     access_pdu->network_header[0] = nid_ivi;
179 }
180 void mesh_access_set_ctl_ttl(mesh_access_pdu_t * access_pdu, uint8_t ctl_ttl){
181     access_pdu->network_header[1] = ctl_ttl;
182 }
183 void mesh_access_set_seq(mesh_access_pdu_t * access_pdu, uint32_t seq){
184     big_endian_store_24(access_pdu->network_header, 2, seq);
185 }
186 void mesh_access_set_src(mesh_access_pdu_t * access_pdu, uint16_t src){
187     big_endian_store_16(access_pdu->network_header, 5, src);
188 }
189 void mesh_access_set_dest(mesh_access_pdu_t * access_pdu, uint16_t dest){
190     big_endian_store_16(access_pdu->network_header, 7, dest);
191 }
192 
193 static void mesh_segmented_pdu_flatten(btstack_linked_list_t * segments, uint8_t segment_len, uint8_t * buffer) {
194     // assemble payload
195     btstack_linked_list_iterator_t it;
196     btstack_linked_list_iterator_init(&it, segments);
197     while (btstack_linked_list_iterator_has_next(&it)) {
198         mesh_network_pdu_t *segment = (mesh_network_pdu_t *) btstack_linked_list_iterator_next(&it);
199         btstack_assert(segment->pdu_header.pdu_type == MESH_PDU_TYPE_NETWORK);
200         // get segment n
201         uint8_t *lower_transport_pdu = mesh_network_pdu_data(segment);
202         uint8_t seg_o = (big_endian_read_16(lower_transport_pdu, 2) >> 5) & 0x001f;
203         uint8_t *segment_data = &lower_transport_pdu[4];
204         (void) memcpy(&buffer[seg_o * segment_len], segment_data, segment_len);
205     }
206 }
207 
208 static uint16_t mesh_upper_pdu_flatten(mesh_upper_transport_pdu_t * upper_pdu, uint8_t * buffer, uint16_t buffer_len) {
209     // assemble payload
210     btstack_linked_list_iterator_t it;
211     btstack_linked_list_iterator_init(&it, &upper_pdu->segments);
212     uint16_t offset = 0;
213     while (btstack_linked_list_iterator_has_next(&it)) {
214         mesh_network_pdu_t *segment = (mesh_network_pdu_t *) btstack_linked_list_iterator_next(&it);
215         btstack_assert(segment->pdu_header.pdu_type == MESH_PDU_TYPE_NETWORK);
216         btstack_assert((offset + segment->len) <= buffer_len);
217         (void) memcpy(&buffer[offset], segment->data, segment->len);
218         offset += segment->len;
219     }
220     return offset;
221 }
222 
223 static void mesh_segmented_append_payload(const uint8_t * payload, uint16_t payload_len, btstack_linked_list_t * segments){
224     uint16_t payload_offset = 0;
225     uint16_t bytes_current_segment = 0;
226     mesh_network_pdu_t * network_pdu = (mesh_network_pdu_t *) btstack_linked_list_get_last_item(segments);
227     if (network_pdu){
228         bytes_current_segment = MESH_NETWORK_PAYLOAD_MAX - network_pdu->len;
229     }
230     while (payload_offset < payload_len){
231         if (bytes_current_segment == 0){
232             network_pdu = mesh_network_pdu_get();
233             btstack_assert(network_pdu != NULL);
234             btstack_linked_list_add_tail(segments, (btstack_linked_item_t *) network_pdu);
235             bytes_current_segment = MESH_NETWORK_PAYLOAD_MAX;
236         }
237         uint16_t bytes_to_copy = btstack_min(bytes_current_segment, payload_len - payload_offset);
238         (void) memcpy(&network_pdu->data[network_pdu->len], &payload[payload_offset], bytes_to_copy);
239         bytes_current_segment -= bytes_to_copy;
240         network_pdu->len += bytes_to_copy;
241         payload_offset += bytes_to_copy;
242     }
243 }
244 
245 // stub lower transport
246 
247 static void mesh_upper_transport_dump_pdus(const char *name, btstack_linked_list_t *list){
248     printf("List: %s:\n", name);
249     btstack_linked_list_iterator_t it;
250     btstack_linked_list_iterator_init(&it, list);
251     while (btstack_linked_list_iterator_has_next(&it)){
252         mesh_pdu_t * pdu = (mesh_pdu_t*) btstack_linked_list_iterator_next(&it);
253         printf("- %p\n", pdu);
254         // printf_hexdump( mesh_pdu_data(pdu), mesh_pdu_len(pdu));
255     }
256 }
257 
258 static void mesh_upper_transport_reset_pdus(btstack_linked_list_t *list){
259     while (!btstack_linked_list_empty(list)){
260         mesh_upper_transport_pdu_free((mesh_pdu_t *) btstack_linked_list_pop(list));
261     }
262 }
263 
264 void mesh_upper_transport_dump(void){
265     mesh_upper_transport_dump_pdus("upper_transport_incoming", &upper_transport_incoming);
266 }
267 
268 void mesh_upper_transport_reset(void){
269     crypto_active = 0;
270     mesh_upper_transport_reset_pdus(&upper_transport_incoming);
271 }
272 
273 static mesh_transport_key_t * mesh_upper_transport_get_outgoing_appkey(uint16_t netkey_index, uint16_t appkey_index){
274     // Device Key is fixed
275     if (appkey_index == MESH_DEVICE_KEY_INDEX) {
276         return mesh_transport_key_get(appkey_index);
277     }
278 
279     // Get key refresh state from subnet
280     mesh_subnet_t * subnet = mesh_subnet_get_by_netkey_index(netkey_index);
281     if (subnet == NULL) return NULL;
282 
283     // identify old and new app keys for given appkey_index
284     mesh_transport_key_t * old_key = NULL;
285     mesh_transport_key_t * new_key = NULL;
286     mesh_transport_key_iterator_t it;
287     mesh_transport_key_iterator_init(&it, netkey_index);
288     while (mesh_transport_key_iterator_has_more(&it)){
289         mesh_transport_key_t * transport_key = mesh_transport_key_iterator_get_next(&it);
290         if (transport_key->appkey_index != appkey_index) continue;
291         if (transport_key->old_key == 0) {
292             new_key = transport_key;
293         } else {
294             old_key = transport_key;
295         }
296     }
297 
298     // if no key is marked as old, just use the current one
299     if (old_key == NULL) return new_key;
300 
301     // use new key if it exists in phase two
302     if ((subnet->key_refresh == MESH_KEY_REFRESH_SECOND_PHASE) && (new_key != NULL)){
303         return new_key;
304     } else {
305         return old_key;
306     }
307 }
308 
309 static uint32_t iv_index_for_ivi_nid(uint8_t ivi_nid){
310     // get IV Index and IVI
311     uint32_t iv_index = mesh_get_iv_index();
312     int ivi = ivi_nid >> 7;
313 
314     // if least significant bit differs, use previous IV Index
315     if ((iv_index & 1 ) ^ ivi){
316         iv_index--;
317     }
318     return iv_index;
319 }
320 
321 static void transport_segmented_setup_nonce(uint8_t * nonce, const mesh_pdu_t * pdu){
322     mesh_access_pdu_t * access_pdu;
323     mesh_upper_transport_pdu_t * upper_pdu;
324     switch (pdu->pdu_type){
325         case MESH_PDU_TYPE_ACCESS:
326             access_pdu = (mesh_access_pdu_t *) pdu;
327             nonce[1] = access_pdu->transmic_len == 8 ? 0x80 : 0x00;
328             (void)memcpy(&nonce[2], &access_pdu->network_header[2], 7);
329             big_endian_store_32(nonce, 9, iv_index_for_ivi_nid(access_pdu->network_header[0]));
330             break;
331         case MESH_PDU_TYPE_UPPER_SEGMENTED_ACCESS:
332         case MESH_PDU_TYPE_UPPER_UNSEGMENTED_ACCESS:
333             upper_pdu = (mesh_upper_transport_pdu_t *) pdu;
334             nonce[1] = upper_pdu->transmic_len == 8 ? 0x80 : 0x00;
335             // 'network header'
336             big_endian_store_24(nonce, 2, upper_pdu->seq);
337             big_endian_store_16(nonce, 5, upper_pdu->src);
338             big_endian_store_16(nonce, 7, upper_pdu->dst);
339             big_endian_store_32(nonce, 9, iv_index_for_ivi_nid(upper_pdu->ivi_nid));
340             break;
341         default:
342             btstack_assert(0);
343             break;
344     }
345 }
346 
347 static void transport_segmented_setup_application_nonce(uint8_t * nonce, const mesh_pdu_t * pdu){
348     nonce[0] = 0x01;
349     transport_segmented_setup_nonce(nonce, pdu);
350     mesh_print_hex("AppNonce", nonce, 13);
351 }
352 
353 static void transport_segmented_setup_device_nonce(uint8_t * nonce, const mesh_pdu_t * pdu){
354     nonce[0] = 0x02;
355     transport_segmented_setup_nonce(nonce, pdu);
356     mesh_print_hex("DeviceNonce", nonce, 13);
357 }
358 
359 static void mesh_upper_transport_process_access_message_done(mesh_access_pdu_t *access_pdu){
360     crypto_active = 0;
361     btstack_assert(mesh_access_ctl(access_pdu) == 0);
362     incoming_access_pdu_encrypted = NULL;
363     mesh_upper_transport_run();
364 }
365 
366 static void mesh_upper_transport_process_control_message_done(mesh_control_pdu_t * control_pdu){
367     crypto_active = 0;
368     incoming_control_pdu = NULL;
369     mesh_upper_transport_run();
370 }
371 
372 static void mesh_upper_transport_validate_segmented_message_ccm(void * arg){
373     UNUSED(arg);
374 
375     uint8_t * upper_transport_pdu     = incoming_access_pdu_decrypted->data;
376     uint8_t   upper_transport_pdu_len = incoming_access_pdu_decrypted->len - incoming_access_pdu_decrypted->transmic_len;
377 
378     mesh_print_hex("Decrypted PDU", upper_transport_pdu, upper_transport_pdu_len);
379 
380     // store TransMIC
381     uint8_t trans_mic[8];
382     btstack_crypto_ccm_get_authentication_value(&ccm, trans_mic);
383     mesh_print_hex("TransMIC", trans_mic, incoming_access_pdu_decrypted->transmic_len);
384 
385     if (memcmp(trans_mic, &upper_transport_pdu[upper_transport_pdu_len], incoming_access_pdu_decrypted->transmic_len) == 0){
386         printf("TransMIC matches\n");
387 
388         // remove TransMIC from payload
389         incoming_access_pdu_decrypted->len -= incoming_access_pdu_decrypted->transmic_len;
390 
391         // if virtual address, update dst to pseudo_dst
392         if (mesh_network_address_virtual(mesh_access_dst(incoming_access_pdu_decrypted))){
393             big_endian_store_16(incoming_access_pdu_decrypted->network_header, 7, mesh_transport_key_it.address->pseudo_dst);
394         }
395 
396         // pass to upper layer
397         btstack_assert(mesh_access_message_handler != NULL);
398         mesh_pdu_t * pdu = (mesh_pdu_t*) incoming_access_pdu_decrypted;
399         mesh_access_message_handler(MESH_TRANSPORT_PDU_RECEIVED, MESH_TRANSPORT_STATUS_SUCCESS, pdu);
400 
401         printf("\n");
402 
403     } else {
404         uint8_t akf = incoming_access_pdu_decrypted->akf_aid_control & 0x40;
405         if (akf){
406             printf("TransMIC does not match, try next key\n");
407             mesh_upper_transport_validate_segmented_message();
408         } else {
409             printf("TransMIC does not match device key, done\n");
410             // done
411             mesh_upper_transport_process_access_message_done(incoming_access_pdu_decrypted);
412         }
413     }
414 }
415 
416 static void mesh_upper_transport_validate_segmented_message_digest(void * arg){
417     UNUSED(arg);
418     uint8_t   upper_transport_pdu_len      = incoming_access_pdu_encrypted->len - incoming_access_pdu_encrypted->transmic_len;
419     uint8_t * upper_transport_pdu_data_in  = incoming_access_pdu_encrypted->data;
420     uint8_t * upper_transport_pdu_data_out = incoming_access_pdu_decrypted->data;
421     btstack_crypto_ccm_decrypt_block(&ccm, upper_transport_pdu_len, upper_transport_pdu_data_in, upper_transport_pdu_data_out, &mesh_upper_transport_validate_segmented_message_ccm, NULL);
422 }
423 
424 static void mesh_upper_transport_validate_segmented_message(void){
425     uint8_t * upper_transport_pdu_data =  incoming_access_pdu_decrypted->data;
426     uint8_t   upper_transport_pdu_len  = incoming_access_pdu_decrypted->len - incoming_access_pdu_decrypted->transmic_len;
427 
428     if (!mesh_transport_key_and_virtual_address_iterator_has_more(&mesh_transport_key_it)){
429         printf("No valid transport key found\n");
430         mesh_upper_transport_process_access_message_done(incoming_access_pdu_decrypted);
431         return;
432     }
433     mesh_transport_key_and_virtual_address_iterator_next(&mesh_transport_key_it);
434     const mesh_transport_key_t * message_key = mesh_transport_key_it.key;
435 
436     if (message_key->akf){
437         transport_segmented_setup_application_nonce(application_nonce, (mesh_pdu_t *) incoming_access_pdu_encrypted);
438     } else {
439         transport_segmented_setup_device_nonce(application_nonce, (mesh_pdu_t *) incoming_access_pdu_encrypted);
440     }
441 
442     // store application / device key index
443     mesh_print_hex("AppOrDevKey", message_key->key, 16);
444     incoming_access_pdu_decrypted->appkey_index = message_key->appkey_index;
445 
446     mesh_print_hex("EncAccessPayload", upper_transport_pdu_data, upper_transport_pdu_len);
447 
448     // decrypt ccm
449     crypto_active = 1;
450     uint16_t aad_len  = 0;
451     if (mesh_network_address_virtual(mesh_access_dst(incoming_access_pdu_decrypted))){
452         aad_len  = 16;
453     }
454     btstack_crypto_ccm_init(&ccm, message_key->key, application_nonce, upper_transport_pdu_len, aad_len, incoming_access_pdu_decrypted->transmic_len);
455 
456     if (aad_len){
457         btstack_crypto_ccm_digest(&ccm, (uint8_t *) mesh_transport_key_it.address->label_uuid, aad_len, &mesh_upper_transport_validate_segmented_message_digest, NULL);
458     } else {
459         mesh_upper_transport_validate_segmented_message_digest(NULL);
460     }
461 }
462 
463 static void mesh_upper_transport_process_segmented_message(void){
464     // copy original pdu
465     (void)memcpy(incoming_access_pdu_decrypted, incoming_access_pdu_encrypted,
466                  sizeof(mesh_access_pdu_t));
467 
468     //
469     uint8_t * upper_transport_pdu     =  incoming_access_pdu_decrypted->data;
470     uint8_t   upper_transport_pdu_len = incoming_access_pdu_decrypted->len - incoming_access_pdu_decrypted->transmic_len;
471     mesh_print_hex("Upper Transport pdu", upper_transport_pdu, upper_transport_pdu_len);
472 
473     uint8_t aid = incoming_access_pdu_decrypted->akf_aid_control & 0x3f;
474     uint8_t akf = (incoming_access_pdu_decrypted->akf_aid_control & 0x40) >> 6;
475 
476     printf("AKF: %u\n",   akf);
477     printf("AID: %02x\n", aid);
478 
479     mesh_transport_key_and_virtual_address_iterator_init(&mesh_transport_key_it, mesh_access_dst(incoming_access_pdu_decrypted),
480                                                          incoming_access_pdu_decrypted->netkey_index, akf, aid);
481     mesh_upper_transport_validate_segmented_message();
482 }
483 
484 static void mesh_upper_transport_message_received(mesh_pdu_t * pdu){
485     btstack_linked_list_add_tail(&upper_transport_incoming, (btstack_linked_item_t*) pdu);
486     mesh_upper_transport_run();
487 }
488 
489 static void mesh_upper_transport_send_access_segmented(mesh_upper_transport_pdu_t * upper_pdu){
490 
491     mesh_segmented_pdu_t * segmented_pdu   = (mesh_segmented_pdu_t *) upper_pdu->lower_pdu;
492     segmented_pdu->pdu_header.pdu_type = MESH_PDU_TYPE_SEGMENTED;
493 
494     // convert mesh_access_pdu_t into mesh_segmented_pdu_t
495     mesh_segmented_append_payload(crypto_buffer, upper_pdu->len, &segmented_pdu->segments);
496 
497     // copy meta
498     segmented_pdu->len = upper_pdu->len;
499     segmented_pdu->netkey_index = upper_pdu->netkey_index;
500     segmented_pdu->transmic_len = upper_pdu->transmic_len;
501     segmented_pdu->akf_aid_control = upper_pdu->akf_aid_control;
502     segmented_pdu->flags = upper_pdu->flags;
503 
504     // setup segmented_pdu header
505     // (void)memcpy(segmented_pdu->network_header, upper_pdu->network_header, 9);
506     // TODO: use fields in mesh_segmented_pdu_t and setup network header in lower transport
507     segmented_pdu->network_header[0] = upper_pdu->ivi_nid;
508     segmented_pdu->network_header[1] = upper_pdu->ctl_ttl;
509     big_endian_store_24(segmented_pdu->network_header, 2, upper_pdu->seq);
510     big_endian_store_16(segmented_pdu->network_header, 5, upper_pdu->src);
511     big_endian_store_16(segmented_pdu->network_header, 7, upper_pdu->dst);
512 
513     // queue up
514     upper_pdu->lower_pdu = (mesh_pdu_t *) segmented_pdu;
515     btstack_linked_list_add(&upper_transport_outgoing_active, (btstack_linked_item_t *) upper_pdu);
516 
517     mesh_lower_transport_send_pdu((mesh_pdu_t*) segmented_pdu);
518 }
519 
520 static void mesh_upper_transport_send_access_unsegmented(mesh_upper_transport_pdu_t * upper_pdu){
521 
522     // provide segment
523     mesh_network_pdu_t * network_pdu = (mesh_network_pdu_t *) upper_pdu->lower_pdu;
524 
525     // setup network pdu
526     network_pdu->pdu_header.pdu_type = MESH_PDU_TYPE_UPPER_UNSEGMENTED_ACCESS;
527     network_pdu->data[0] = upper_pdu->ivi_nid;
528     network_pdu->data[1] = upper_pdu->ctl_ttl;
529     big_endian_store_24(network_pdu->data, 2, upper_pdu->seq);
530     big_endian_store_16(network_pdu->data, 5, upper_pdu->src);
531     big_endian_store_16(network_pdu->data, 7, upper_pdu->dst);
532     network_pdu->netkey_index = upper_pdu->netkey_index;
533 
534     // setup access message
535     network_pdu->data[9] = upper_pdu->akf_aid_control;
536     btstack_assert(upper_pdu->len < 15);
537     (void)memcpy(&network_pdu->data[10], crypto_buffer, upper_pdu->len);
538     network_pdu->len = 10 + upper_pdu->len;
539     network_pdu->flags = 0;
540 
541     // queue up
542     btstack_linked_list_add(&upper_transport_outgoing_active, (btstack_linked_item_t *) upper_pdu);
543 
544     mesh_lower_transport_send_pdu((mesh_pdu_t*) network_pdu);
545 }
546 
547 static void mesh_upper_transport_send_access_ccm(void * arg){
548     crypto_active = 0;
549 
550     mesh_upper_transport_pdu_t * upper_pdu = (mesh_upper_transport_pdu_t *) arg;
551     mesh_print_hex("EncAccessPayload", crypto_buffer, upper_pdu->len);
552     // store TransMIC
553     btstack_crypto_ccm_get_authentication_value(&ccm, &crypto_buffer[upper_pdu->len]);
554     mesh_print_hex("TransMIC", &crypto_buffer[upper_pdu->len], upper_pdu->transmic_len);
555     upper_pdu->len += upper_pdu->transmic_len;
556     mesh_print_hex("UpperTransportPDU", crypto_buffer, upper_pdu->len);
557     switch (upper_pdu->pdu_header.pdu_type){
558         case MESH_PDU_TYPE_UPPER_UNSEGMENTED_ACCESS:
559             mesh_upper_transport_send_access_unsegmented(upper_pdu);
560             break;
561         case MESH_PDU_TYPE_UPPER_SEGMENTED_ACCESS:
562             mesh_upper_transport_send_access_segmented(upper_pdu);
563             break;
564         default:
565             btstack_assert(false);
566     }
567 }
568 
569 static void mesh_upper_transport_send_access_digest(void *arg){
570     mesh_upper_transport_pdu_t * upper_pdu = (mesh_upper_transport_pdu_t *) arg;
571     uint16_t  access_pdu_len  = upper_pdu->len;
572     btstack_crypto_ccm_encrypt_block(&ccm, access_pdu_len, crypto_buffer, crypto_buffer,
573                                      &mesh_upper_transport_send_access_ccm, upper_pdu);
574 }
575 
576 static void mesh_upper_transport_send_access(mesh_upper_transport_pdu_t * upper_pdu){
577 
578     // if dst is virtual address, lookup label uuid and hash
579     uint16_t aad_len = 0;
580     mesh_virtual_address_t * virtual_address = NULL;
581     if (mesh_network_address_virtual(upper_pdu->dst)){
582         virtual_address = mesh_virtual_address_for_pseudo_dst(upper_pdu->dst);
583         if (!virtual_address){
584             printf("No virtual address register for pseudo dst %4x\n", upper_pdu->dst);
585             mesh_access_message_handler(MESH_TRANSPORT_PDU_SENT, MESH_TRANSPORT_STATUS_SEND_FAILED, (mesh_pdu_t *) upper_pdu);
586             return;
587         }
588         // printf("Using hash %4x with LabelUUID: ", virtual_address->hash);
589         // printf_hexdump(virtual_address->label_uuid, 16);
590         aad_len = 16;
591         upper_pdu->dst = virtual_address->hash;
592     }
593 
594     // get app or device key
595     uint16_t appkey_index = upper_pdu->appkey_index;
596     const mesh_transport_key_t * appkey = mesh_upper_transport_get_outgoing_appkey(upper_pdu->netkey_index, appkey_index);
597     if (appkey == NULL){
598         printf("AppKey %04x not found, drop message\n", appkey_index);
599         mesh_access_message_handler(MESH_TRANSPORT_PDU_SENT, MESH_TRANSPORT_STATUS_SEND_FAILED, (mesh_pdu_t *) upper_pdu);
600         return;
601     }
602 
603     // reserve slot
604     mesh_lower_transport_reserve_slot();
605 
606     // reserve one sequence number, which is also used to encrypt access payload
607     uint32_t seq = mesh_sequence_number_next();
608     upper_pdu->flags |= MESH_TRANSPORT_FLAG_SEQ_RESERVED;
609     upper_pdu->seq = seq;
610 
611     // also reserves crypto_buffer
612     crypto_active = 1;
613 
614     // flatten segmented pdu into crypto buffer
615     uint16_t payload_len = mesh_upper_pdu_flatten(upper_pdu, crypto_buffer, sizeof(crypto_buffer));
616     btstack_assert(payload_len == upper_pdu->len);
617 
618     // Dump PDU
619     printf("[+] Upper transport, send upper (un)segmented Access PDU - dest %04x, seq %06x\n", upper_pdu->dst, upper_pdu->seq);
620     mesh_print_hex("Access Payload", crypto_buffer, upper_pdu->len);
621 
622     // setup nonce - uses dst, so after pseudo address translation
623     if (appkey_index == MESH_DEVICE_KEY_INDEX){
624         transport_segmented_setup_device_nonce(application_nonce, (mesh_pdu_t *) upper_pdu);
625     } else {
626         transport_segmented_setup_application_nonce(application_nonce, (mesh_pdu_t *) upper_pdu);
627     }
628 
629     // Dump key
630     mesh_print_hex("AppOrDevKey", appkey->key, 16);
631 
632     // encrypt ccm
633     uint8_t   transmic_len    = upper_pdu->transmic_len;
634     uint16_t  access_pdu_len  = upper_pdu->len;
635     btstack_crypto_ccm_init(&ccm, appkey->key, application_nonce, access_pdu_len, aad_len, transmic_len);
636     if (virtual_address){
637         mesh_print_hex("LabelUUID", virtual_address->label_uuid, 16);
638         btstack_crypto_ccm_digest(&ccm, virtual_address->label_uuid, 16,
639                                   &mesh_upper_transport_send_access_digest, upper_pdu);
640     } else {
641         mesh_upper_transport_send_access_digest(upper_pdu);
642     }
643 }
644 
645 static void mesh_upper_transport_send_unsegmented_control_pdu(mesh_network_pdu_t * network_pdu){
646     // reserve slot
647     mesh_lower_transport_reserve_slot();
648     // reserve sequence number
649     uint32_t seq = mesh_sequence_number_next();
650     mesh_network_pdu_set_seq(network_pdu, seq);
651     // Dump PDU
652     uint8_t opcode = network_pdu->data[9];
653     printf("[+] Upper transport, send unsegmented Control PDU %p - seq %06x opcode %02x\n", network_pdu, seq, opcode);
654     mesh_print_hex("Access Payload", &network_pdu->data[10], network_pdu->len - 10);
655 
656     // send
657      mesh_lower_transport_send_pdu((mesh_pdu_t *) network_pdu);
658 }
659 
660 static void mesh_upper_transport_send_segmented_control_pdu(mesh_upper_transport_pdu_t * upper_pdu){
661     // reserve slot
662     mesh_lower_transport_reserve_slot();
663     // reserve sequence number
664     uint32_t seq = mesh_sequence_number_next();
665     upper_pdu->flags |= MESH_TRANSPORT_FLAG_SEQ_RESERVED;
666     upper_pdu->seq = seq;
667     // Dump PDU
668     // uint8_t opcode = upper_pdu->data[0];
669     // printf("[+] Upper transport, send segmented Control PDU %p - seq %06x opcode %02x\n", upper_pdu, seq, opcode);
670     // mesh_print_hex("Access Payload", &upper_pdu->data[1], upper_pdu->len - 1);
671     // send
672     mesh_segmented_pdu_t * segmented_pdu   = (mesh_segmented_pdu_t *) upper_pdu->lower_pdu;
673     segmented_pdu->pdu_header.pdu_type = MESH_PDU_TYPE_SEGMENTED;
674 
675     // lend segments to lower transport pdu
676     segmented_pdu->segments = upper_pdu->segments;
677     upper_pdu->segments = NULL;
678 
679     // copy meta
680     segmented_pdu->len = upper_pdu->len;
681     segmented_pdu->netkey_index = upper_pdu->netkey_index;
682     segmented_pdu->transmic_len = 0;   // no TransMIC for control
683     segmented_pdu->akf_aid_control = upper_pdu->akf_aid_control;
684     segmented_pdu->flags = upper_pdu->flags;
685 
686     // setup segmented_pdu header
687     // TODO: use fields in mesh_segmented_pdu_t and setup network header in lower transport
688     segmented_pdu->network_header[0] = upper_pdu->ivi_nid;
689     segmented_pdu->network_header[1] = upper_pdu->ctl_ttl;
690     big_endian_store_24(segmented_pdu->network_header, 2, upper_pdu->seq);
691     big_endian_store_16(segmented_pdu->network_header, 5, upper_pdu->src);
692     big_endian_store_16(segmented_pdu->network_header, 7, upper_pdu->dst);
693 
694     // queue up
695     upper_pdu->lower_pdu = (mesh_pdu_t *) segmented_pdu;
696     btstack_linked_list_add(&upper_transport_outgoing_active, (btstack_linked_item_t *) upper_pdu);
697 
698     mesh_lower_transport_send_pdu((mesh_pdu_t *) segmented_pdu);
699 }
700 
701 static void mesh_upper_transport_run(void){
702 
703     while(!btstack_linked_list_empty(&upper_transport_incoming)){
704 
705         if (crypto_active) return;
706 
707         // get next message
708         mesh_pdu_t * pdu =  (mesh_pdu_t *) btstack_linked_list_pop(&upper_transport_incoming);
709         mesh_network_pdu_t   * network_pdu;
710         mesh_segmented_pdu_t   * message_pdu;
711         switch (pdu->pdu_type){
712             case MESH_PDU_TYPE_UNSEGMENTED:
713                 network_pdu = (mesh_network_pdu_t *) pdu;
714                 // control?
715                 if (mesh_network_control(network_pdu)) {
716 
717                     incoming_control_pdu =  &incoming_control_pdu_singleton;
718                     incoming_control_pdu->pdu_header.pdu_type = MESH_PDU_TYPE_CONTROL;
719                     incoming_control_pdu->len =  network_pdu->len;
720                     incoming_control_pdu->netkey_index =  network_pdu->netkey_index;
721 
722                     uint8_t * lower_transport_pdu = mesh_network_pdu_data(network_pdu);
723 
724                     incoming_control_pdu->akf_aid_control = lower_transport_pdu[0];
725                     incoming_control_pdu->len = network_pdu->len - 10; // 9 header + 1 opcode
726                     (void)memcpy(incoming_control_pdu->data, &lower_transport_pdu[1], incoming_control_pdu->len);
727 
728                     // copy meta data into encrypted pdu buffer
729                     (void)memcpy(incoming_control_pdu->network_header, network_pdu->data, 9);
730 
731                     mesh_print_hex("Assembled payload", incoming_control_pdu->data, incoming_control_pdu->len);
732 
733                     // free mesh message
734                     mesh_lower_transport_message_processed_by_higher_layer(pdu);
735 
736                     btstack_assert(mesh_control_message_handler != NULL);
737                     mesh_pdu_t * pdu = (mesh_pdu_t*) incoming_control_pdu;
738                     mesh_control_message_handler(MESH_TRANSPORT_PDU_RECEIVED, MESH_TRANSPORT_STATUS_SUCCESS, pdu);
739 
740                 } else {
741 
742                     incoming_access_pdu_encrypted = &incoming_access_pdu_encrypted_singleton;
743                     incoming_access_pdu_encrypted->pdu_header.pdu_type = MESH_PDU_TYPE_ACCESS;
744                     incoming_access_pdu_decrypted = &incoming_access_pdu_decrypted_singleton;
745 
746                     incoming_access_pdu_encrypted->netkey_index = network_pdu->netkey_index;
747                     incoming_access_pdu_encrypted->transmic_len = 4;
748 
749                     uint8_t * lower_transport_pdu = mesh_network_pdu_data(network_pdu);
750 
751                     incoming_access_pdu_encrypted->akf_aid_control = lower_transport_pdu[0];
752                     incoming_access_pdu_encrypted->len = network_pdu->len - 10; // 9 header + 1 AID
753                     (void)memcpy(incoming_access_pdu_encrypted->data, &lower_transport_pdu[1], incoming_access_pdu_encrypted->len);
754 
755                     // copy meta data into encrypted pdu buffer
756                     (void)memcpy(incoming_access_pdu_encrypted->network_header, network_pdu->data, 9);
757 
758                     mesh_print_hex("Assembled payload", incoming_access_pdu_encrypted->data, incoming_access_pdu_encrypted->len);
759 
760                     // free mesh message
761                     mesh_lower_transport_message_processed_by_higher_layer(pdu);
762 
763                     // get encoded transport pdu and start processing
764                     mesh_upper_transport_process_segmented_message();
765                 }
766                 break;
767             case MESH_PDU_TYPE_SEGMENTED:
768                 message_pdu = (mesh_segmented_pdu_t *) pdu;
769                 uint8_t ctl = mesh_message_ctl(message_pdu);
770                 if (ctl){
771                     incoming_control_pdu=  &incoming_control_pdu_singleton;
772                     incoming_control_pdu->pdu_header.pdu_type = MESH_PDU_TYPE_CONTROL;
773 
774                     // flatten
775                     mesh_segmented_pdu_flatten(&message_pdu->segments, 8, incoming_control_pdu->data);
776 
777                     // copy meta data into encrypted pdu buffer
778                     incoming_control_pdu->len =  message_pdu->len;
779                     incoming_control_pdu->netkey_index =  message_pdu->netkey_index;
780                     incoming_control_pdu->akf_aid_control =  message_pdu->akf_aid_control;
781                     incoming_control_pdu->flags = 0;
782                     (void)memcpy(incoming_control_pdu->network_header, message_pdu->network_header, 9);
783 
784                     mesh_print_hex("Assembled payload", incoming_control_pdu->data, incoming_control_pdu->len);
785 
786                     // free mesh message
787                     mesh_lower_transport_message_processed_by_higher_layer((mesh_pdu_t *)message_pdu);
788 
789                     btstack_assert(mesh_control_message_handler != NULL);
790                     mesh_pdu_t * pdu = (mesh_pdu_t*) incoming_control_pdu;
791                     mesh_access_message_handler(MESH_TRANSPORT_PDU_RECEIVED, MESH_TRANSPORT_STATUS_SUCCESS, pdu);
792 
793                 } else {
794 
795                     incoming_access_pdu_encrypted = &incoming_access_pdu_encrypted_singleton;
796                     incoming_access_pdu_encrypted->pdu_header.pdu_type = MESH_PDU_TYPE_ACCESS;
797                     incoming_access_pdu_decrypted = &incoming_access_pdu_decrypted_singleton;
798 
799                     // flatten
800                     mesh_segmented_pdu_flatten(&message_pdu->segments, 12, incoming_access_pdu_encrypted->data);
801 
802                     // copy meta data into encrypted pdu buffer
803                     incoming_access_pdu_encrypted->len =  message_pdu->len;
804                     incoming_access_pdu_encrypted->netkey_index =  message_pdu->netkey_index;
805                     incoming_access_pdu_encrypted->transmic_len =  message_pdu->transmic_len;
806                     incoming_access_pdu_encrypted->akf_aid_control =  message_pdu->akf_aid_control;
807                     (void)memcpy(incoming_access_pdu_encrypted->network_header, message_pdu->network_header, 9);
808 
809                     mesh_print_hex("Assembled payload", incoming_access_pdu_encrypted->data, incoming_access_pdu_encrypted->len);
810 
811                     // free mesh message
812                     mesh_lower_transport_message_processed_by_higher_layer((mesh_pdu_t *)message_pdu);
813 
814                     // get encoded transport pdu and start processing
815                     mesh_upper_transport_process_segmented_message();
816                 }
817                 break;
818             default:
819                 btstack_assert(0);
820                 break;
821         }
822     }
823 
824     while (!btstack_linked_list_empty(&upper_transport_outgoing)){
825 
826         if (crypto_active) break;
827 
828         mesh_pdu_t * pdu =  (mesh_pdu_t *) btstack_linked_list_get_first_item(&upper_transport_outgoing);
829         if (mesh_lower_transport_can_send_to_dest(mesh_pdu_dst(pdu)) == 0) break;
830 
831         mesh_upper_transport_pdu_t * upper_pdu;
832 
833         switch (pdu->pdu_type){
834             case MESH_PDU_TYPE_UPPER_UNSEGMENTED_CONTROL:
835                 // control pdus can go through directly
836                 btstack_assert(mesh_pdu_ctl(pdu) != 0);
837                 (void) btstack_linked_list_pop(&upper_transport_outgoing);
838                 mesh_upper_transport_send_unsegmented_control_pdu((mesh_network_pdu_t *) pdu);
839                 break;
840             case MESH_PDU_TYPE_UPPER_SEGMENTED_CONTROL:
841                 // control pdus can go through directly
842                 btstack_assert(mesh_pdu_ctl(pdu) != 0);
843                 (void) btstack_linked_list_pop(&upper_transport_outgoing);
844                 mesh_upper_transport_send_segmented_control_pdu((mesh_upper_transport_pdu_t *) pdu);
845                 break;
846             case MESH_PDU_TYPE_UPPER_SEGMENTED_ACCESS:
847                 // segmented access pdus required a mesh-segmented-pdu
848                 upper_pdu = (mesh_upper_transport_pdu_t *) pdu;
849                 if (upper_pdu->lower_pdu == NULL){
850                     upper_pdu->lower_pdu = (mesh_pdu_t *) btstack_memory_mesh_segmented_pdu_get();
851                 }
852                 if (upper_pdu->lower_pdu == NULL) break;
853                 upper_pdu->lower_pdu->pdu_type = MESH_PDU_TYPE_SEGMENTED;
854                 // and a mesh-network-pdu for each segments
855                 // TODO: reserve segments
856                 (void) btstack_linked_list_pop(&upper_transport_outgoing);
857                 mesh_upper_transport_send_access(upper_pdu);
858                 break;
859             case MESH_PDU_TYPE_UPPER_UNSEGMENTED_ACCESS:
860                 // unsegmented access pdus require a single mesh-network-dpu
861                 upper_pdu = (mesh_upper_transport_pdu_t *) pdu;
862                 if (upper_pdu->lower_pdu == NULL){
863                     upper_pdu->lower_pdu = (mesh_pdu_t *) mesh_network_pdu_get();
864                 }
865                 if (upper_pdu->lower_pdu == NULL) break;
866                 (void) btstack_linked_list_pop(&upper_transport_outgoing);
867                 mesh_upper_transport_send_access((mesh_upper_transport_pdu_t *) pdu);
868                 break;
869             default:
870                 btstack_assert(false);
871                 break;
872         }
873     }
874 }
875 
876 static mesh_upper_transport_pdu_t * mesh_upper_transport_find_pdu_for_lower(mesh_pdu_t * pdu_to_find){
877     btstack_linked_list_iterator_t it;
878     btstack_linked_list_iterator_init(&it, &upper_transport_outgoing_active);
879     mesh_upper_transport_pdu_t * upper_pdu;
880     while (btstack_linked_list_iterator_has_next(&it)){
881         mesh_pdu_t * mesh_pdu = (mesh_pdu_t *) btstack_linked_list_iterator_next(&it);
882         switch (mesh_pdu->pdu_type){
883             case MESH_PDU_TYPE_UPPER_SEGMENTED_CONTROL:
884             case MESH_PDU_TYPE_UPPER_UNSEGMENTED_ACCESS:
885             case MESH_PDU_TYPE_UPPER_SEGMENTED_ACCESS:
886                 upper_pdu = (mesh_upper_transport_pdu_t *) mesh_pdu;
887                 if (upper_pdu->lower_pdu == pdu_to_find){
888                     btstack_linked_list_iterator_remove(&it);
889                     return upper_pdu;
890                 }
891                 break;
892             default:
893                 break;
894         }
895     }
896     return NULL;
897 }
898 
899 static void mesh_upper_transport_pdu_handler(mesh_transport_callback_type_t callback_type, mesh_transport_status_t status, mesh_pdu_t * pdu){
900     mesh_upper_transport_pdu_t * upper_pdu;
901     mesh_network_pdu_t * network_pdu;
902     mesh_segmented_pdu_t * segmented_pdu;
903     switch (callback_type){
904         case MESH_TRANSPORT_PDU_RECEIVED:
905             mesh_upper_transport_message_received(pdu);
906             break;
907         case MESH_TRANSPORT_PDU_SENT:
908             switch (pdu->pdu_type){
909                 case MESH_PDU_TYPE_SEGMENTED:
910                     // try to find in outgoing active
911                     upper_pdu = mesh_upper_transport_find_pdu_for_lower(pdu);
912                     btstack_assert(upper_pdu != NULL);
913                     segmented_pdu = (mesh_segmented_pdu_t *) pdu;
914                     // free chunks
915                     while (!btstack_linked_list_empty(&segmented_pdu->segments)){
916                         mesh_network_pdu_t * network_pdu = (mesh_network_pdu_t *) btstack_linked_list_pop(&segmented_pdu->segments);
917                         mesh_network_pdu_free(network_pdu);
918                     }
919                     // free segmented pdu
920                     btstack_memory_mesh_segmented_pdu_free(segmented_pdu);
921                     // TODO: free segmented_pdu
922                     upper_pdu->lower_pdu = NULL;
923                     switch (upper_pdu->pdu_header.pdu_type){
924                         case MESH_PDU_TYPE_UPPER_SEGMENTED_CONTROL:
925                             mesh_control_message_handler(callback_type, status, (mesh_pdu_t *) upper_pdu);
926                             break;
927                         case MESH_PDU_TYPE_UPPER_SEGMENTED_ACCESS:
928                             mesh_access_message_handler(callback_type, status, (mesh_pdu_t *) upper_pdu);
929                             break;
930                         default:
931                             btstack_assert(false);
932                             break;
933                     }
934                     break;
935                 case MESH_PDU_TYPE_UPPER_UNSEGMENTED_ACCESS:
936                     // find corresponding upper transport pdu and free single segment
937                     upper_pdu = mesh_upper_transport_find_pdu_for_lower(pdu);
938                     btstack_assert(upper_pdu != NULL);
939                     btstack_assert(upper_pdu->lower_pdu == (mesh_pdu_t *) pdu);
940                     mesh_network_pdu_free((mesh_network_pdu_t *) pdu);
941                     upper_pdu->lower_pdu = NULL;
942                     mesh_access_message_handler(callback_type, status, (mesh_pdu_t*) upper_pdu);
943                     break;
944                 case MESH_PDU_TYPE_UPPER_UNSEGMENTED_CONTROL:
945                     mesh_access_message_handler(callback_type, status, pdu);
946                     break;
947                 default:
948                     btstack_assert(false);
949                     break;
950             }
951             mesh_upper_transport_run();
952             break;
953         default:
954             break;
955     }
956 }
957 
958 void mesh_upper_transport_pdu_free(mesh_pdu_t * pdu){
959     mesh_network_pdu_t   * network_pdu;
960     mesh_segmented_pdu_t   * message_pdu;
961     switch (pdu->pdu_type) {
962         case MESH_PDU_TYPE_NETWORK:
963             network_pdu = (mesh_network_pdu_t *) pdu;
964             mesh_network_pdu_free(network_pdu);
965             break;
966         case MESH_PDU_TYPE_SEGMENTED:
967             message_pdu = (mesh_segmented_pdu_t *) pdu;
968             mesh_message_pdu_free(message_pdu);
969         default:
970             btstack_assert(false);
971             break;
972     }
973 }
974 
975 void mesh_upper_transport_message_processed_by_higher_layer(mesh_pdu_t * pdu){
976     crypto_active = 0;
977     switch (pdu->pdu_type){
978         case MESH_PDU_TYPE_ACCESS:
979             mesh_upper_transport_process_access_message_done((mesh_access_pdu_t *) pdu);
980         case MESH_PDU_TYPE_CONTROL:
981             mesh_upper_transport_process_control_message_done((mesh_control_pdu_t *) pdu);
982             break;
983         default:
984             btstack_assert(0);
985             break;
986     }
987 }
988 
989 void mesh_upper_transport_send_access_pdu(mesh_pdu_t *pdu){
990     switch (pdu->pdu_type){
991         case MESH_PDU_TYPE_UPPER_SEGMENTED_ACCESS:
992         case MESH_PDU_TYPE_UPPER_UNSEGMENTED_ACCESS:
993             break;
994         default:
995             btstack_assert(false);
996             break;
997     }
998 
999     btstack_assert(((mesh_upper_transport_pdu_t *) pdu)->lower_pdu == NULL);
1000 
1001     btstack_linked_list_add_tail(&upper_transport_outgoing, (btstack_linked_item_t*) pdu);
1002     mesh_upper_transport_run();
1003 }
1004 
1005 void mesh_upper_transport_send_control_pdu(mesh_pdu_t * pdu){
1006     switch (pdu->pdu_type){
1007         case MESH_PDU_TYPE_UPPER_SEGMENTED_CONTROL:
1008             break;
1009         case MESH_PDU_TYPE_UPPER_UNSEGMENTED_CONTROL:
1010             btstack_assert( ((mesh_network_pdu_t *) pdu)->len >= 9);
1011             break;
1012         default:
1013             btstack_assert(false);
1014             break;
1015     }
1016 
1017     btstack_linked_list_add_tail(&upper_transport_outgoing, (btstack_linked_item_t*) pdu);
1018     mesh_upper_transport_run();
1019 }
1020 
1021 static uint8_t mesh_upper_transport_setup_unsegmented_control_pdu(mesh_network_pdu_t * network_pdu, uint16_t netkey_index, uint8_t ttl, uint16_t src, uint16_t dest, uint8_t opcode,
1022                                                                   const uint8_t * control_pdu_data, uint16_t control_pdu_len){
1023 
1024     if (control_pdu_len > 11) return 1;
1025 
1026     const mesh_network_key_t * network_key = mesh_network_key_list_get(netkey_index);
1027     if (!network_key) return 1;
1028 
1029     uint8_t transport_pdu_data[12];
1030     transport_pdu_data[0] = opcode;
1031     (void)memcpy(&transport_pdu_data[1], control_pdu_data, control_pdu_len);
1032     uint16_t transport_pdu_len = control_pdu_len + 1;
1033 
1034     // setup network_pdu
1035     mesh_network_setup_pdu(network_pdu, netkey_index, network_key->nid, 1, ttl, 0, src, dest, transport_pdu_data, transport_pdu_len);
1036 
1037     return 0;
1038 }
1039 
1040 static uint8_t mesh_upper_transport_setup_segmented_control_pdu(mesh_upper_transport_pdu_t * upper_pdu, uint16_t netkey_index, uint8_t ttl, uint16_t src, uint16_t dest, uint8_t opcode,
1041                                                                 const uint8_t * control_pdu_data, uint16_t control_pdu_len){
1042 
1043     if (control_pdu_len > 256) return 1;
1044 
1045     const mesh_network_key_t * network_key = mesh_network_key_list_get(netkey_index);
1046     if (!network_key) return 1;
1047 
1048     upper_pdu->ivi_nid = network_key->nid | ((mesh_get_iv_index_for_tx() & 1) << 7);
1049     upper_pdu->ctl_ttl = ttl;
1050     upper_pdu->src = src;
1051     upper_pdu->dst = dest;
1052     upper_pdu->transmic_len = 0;    // no TransMIC for control
1053     upper_pdu->netkey_index = netkey_index;
1054     upper_pdu->akf_aid_control = opcode;
1055 
1056     mesh_segmented_append_payload(control_pdu_data, control_pdu_len, &upper_pdu->segments);
1057     upper_pdu->len = control_pdu_len;
1058     return 0;
1059 }
1060 
1061 uint8_t mesh_upper_transport_setup_control_pdu(mesh_pdu_t * pdu, uint16_t netkey_index,
1062                                                uint8_t ttl, uint16_t src, uint16_t dest, uint8_t opcode, const uint8_t * control_pdu_data, uint16_t control_pdu_len){
1063     switch (pdu->pdu_type){
1064         case MESH_PDU_TYPE_UPPER_UNSEGMENTED_CONTROL:
1065             return mesh_upper_transport_setup_unsegmented_control_pdu((mesh_network_pdu_t *) pdu, netkey_index, ttl, src, dest, opcode, control_pdu_data, control_pdu_len);
1066         case MESH_PDU_TYPE_UPPER_SEGMENTED_CONTROL:
1067             return mesh_upper_transport_setup_segmented_control_pdu((mesh_upper_transport_pdu_t *) pdu,  netkey_index, ttl, src, dest, opcode, control_pdu_data, control_pdu_len);
1068         default:
1069             btstack_assert(0);
1070             return 1;
1071     }
1072 }
1073 
1074 static uint8_t mesh_upper_transport_setup_segmented_access_pdu_header(mesh_access_pdu_t * access_pdu, uint16_t netkey_index,
1075                                                                       uint16_t appkey_index, uint8_t ttl, uint16_t src, uint16_t dest, uint8_t szmic){
1076 
1077     // get app or device key
1078     const mesh_transport_key_t *appkey;
1079     appkey = mesh_transport_key_get(appkey_index);
1080     if (appkey == NULL) {
1081         printf("[!] Upper transport, setup segmented Access PDU - appkey_index %x unknown\n", appkey_index);
1082         return 1;
1083     }
1084     uint8_t akf_aid = (appkey->akf << 6) | appkey->aid;
1085 
1086     // lookup network by netkey_index
1087     const mesh_network_key_t *network_key = mesh_network_key_list_get(netkey_index);
1088     if (!network_key) return 1;
1089     if (network_key == NULL) {
1090         printf("[!] Upper transport, setup segmented Access PDU - netkey_index %x unknown\n", appkey_index);
1091         return 1;
1092     }
1093 
1094     const uint8_t trans_mic_len = szmic ? 8 : 4;
1095 
1096     // store in transport pdu
1097     access_pdu->transmic_len = trans_mic_len;
1098     access_pdu->netkey_index = netkey_index;
1099     access_pdu->appkey_index = appkey_index;
1100     access_pdu->akf_aid_control = akf_aid;
1101     mesh_access_set_nid_ivi(access_pdu, network_key->nid | ((mesh_get_iv_index_for_tx() & 1) << 7));
1102     mesh_access_set_src(access_pdu, src);
1103     mesh_access_set_dest(access_pdu, dest);
1104     mesh_access_set_ctl_ttl(access_pdu, ttl);
1105     return 0;
1106 }
1107 
1108 static uint8_t mesh_upper_transport_setup_upper_access_pdu_header(mesh_upper_transport_pdu_t * upper_pdu, uint16_t netkey_index,
1109                                                                   uint16_t appkey_index, uint8_t ttl, uint16_t src, uint16_t dest, uint8_t szmic){
1110 
1111     // get app or device key
1112     const mesh_transport_key_t *appkey;
1113     appkey = mesh_transport_key_get(appkey_index);
1114     if (appkey == NULL) {
1115         printf("[!] Upper transport, setup segmented Access PDU - appkey_index %x unknown\n", appkey_index);
1116         return 1;
1117     }
1118     uint8_t akf_aid = (appkey->akf << 6) | appkey->aid;
1119 
1120     // lookup network by netkey_index
1121     const mesh_network_key_t *network_key = mesh_network_key_list_get(netkey_index);
1122     if (!network_key) return 1;
1123     if (network_key == NULL) {
1124         printf("[!] Upper transport, setup segmented Access PDU - netkey_index %x unknown\n", appkey_index);
1125         return 1;
1126     }
1127 
1128     const uint8_t trans_mic_len = szmic ? 8 : 4;
1129 
1130     // store in transport pdu
1131     upper_pdu->ivi_nid = network_key->nid | ((mesh_get_iv_index_for_tx() & 1) << 7);
1132     upper_pdu->ctl_ttl = ttl;
1133     upper_pdu->src = src;
1134     upper_pdu->dst = dest;
1135     upper_pdu->transmic_len = trans_mic_len;
1136     upper_pdu->netkey_index = netkey_index;
1137     upper_pdu->appkey_index = appkey_index;
1138     upper_pdu->akf_aid_control = akf_aid;
1139     return 0;
1140 }
1141 
1142 static uint8_t mesh_upper_transport_setup_upper_access_pdu(mesh_upper_transport_pdu_t * upper_pdu, uint16_t netkey_index, uint16_t appkey_index, uint8_t ttl, uint16_t src, uint16_t dest,
1143                                                            uint8_t szmic, const uint8_t * access_pdu_data, uint8_t access_pdu_len){
1144     int status = mesh_upper_transport_setup_upper_access_pdu_header(upper_pdu, netkey_index, appkey_index, ttl, src,
1145                                                                     dest, szmic);
1146     if (status) return status;
1147 
1148     // store in transport pdu
1149     mesh_segmented_append_payload(access_pdu_data, access_pdu_len, &upper_pdu->segments);
1150     upper_pdu->len = access_pdu_len;
1151     return 0;
1152 }
1153 
1154 
1155 uint8_t mesh_upper_transport_setup_access_pdu_header(mesh_pdu_t * pdu, uint16_t netkey_index, uint16_t appkey_index,
1156                                                      uint8_t ttl, uint16_t src, uint16_t dest, uint8_t szmic){
1157     switch (pdu->pdu_type){
1158         case MESH_PDU_TYPE_ACCESS:
1159             return mesh_upper_transport_setup_segmented_access_pdu_header((mesh_access_pdu_t *) pdu, netkey_index, appkey_index, ttl, src, dest, szmic);
1160         default:
1161             btstack_assert(false);
1162             return 1;
1163     }
1164 }
1165 
1166 uint8_t mesh_upper_transport_setup_access_pdu(mesh_pdu_t * pdu, uint16_t netkey_index, uint16_t appkey_index,
1167                                               uint8_t ttl, uint16_t src, uint16_t dest, uint8_t szmic,
1168                                               const uint8_t * access_pdu_data, uint8_t access_pdu_len){
1169     switch (pdu->pdu_type){
1170         case MESH_PDU_TYPE_UPPER_SEGMENTED_ACCESS:
1171         case MESH_PDU_TYPE_UPPER_UNSEGMENTED_ACCESS:
1172             return mesh_upper_transport_setup_upper_access_pdu((mesh_upper_transport_pdu_t *) pdu, netkey_index,
1173                                                                appkey_index, ttl, src, dest, szmic, access_pdu_data,
1174                                                                access_pdu_len);
1175         default:
1176             btstack_assert(false);
1177             return 1;
1178     }
1179 }
1180 
1181 void mesh_upper_transport_register_access_message_handler(void (*callback)(mesh_transport_callback_type_t callback_type, mesh_transport_status_t status, mesh_pdu_t * pdu)) {
1182     mesh_access_message_handler = callback;
1183 }
1184 
1185 void mesh_upper_transport_register_control_message_handler(void (*callback)(mesh_transport_callback_type_t callback_type, mesh_transport_status_t status, mesh_pdu_t * pdu)){
1186     mesh_control_message_handler = callback;
1187 }
1188 
1189 void mesh_upper_transport_init(){
1190     mesh_lower_transport_set_higher_layer_handler(&mesh_upper_transport_pdu_handler);
1191 }
1192