xref: /btstack/src/mesh/mesh_upper_transport.c (revision e9c1630436c6576476b8331acbfab80acc4fe61a)
1 /*
2  * Copyright (C) 2014 BlueKitchen GmbH
3  *
4  * Redistribution and use in source and binary forms, with or without
5  * modification, are permitted provided that the following conditions
6  * are met:
7  *
8  * 1. Redistributions of source code must retain the above copyright
9  *    notice, this list of conditions and the following disclaimer.
10  * 2. Redistributions in binary form must reproduce the above copyright
11  *    notice, this list of conditions and the following disclaimer in the
12  *    documentation and/or other materials provided with the distribution.
13  * 3. Neither the name of the copyright holders nor the names of
14  *    contributors may be used to endorse or promote products derived
15  *    from this software without specific prior written permission.
16  * 4. Any redistribution, use, or modification is done solely for
17  *    personal benefit and not for any commercial purpose or for
18  *    monetary gain.
19  *
20  * THIS SOFTWARE IS PROVIDED BY BLUEKITCHEN GMBH AND CONTRIBUTORS
21  * ``AS IS'' AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT
22  * LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS
23  * FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL MATTHIAS
24  * RINGWALD OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT,
25  * INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING,
26  * BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS
27  * OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED
28  * AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY,
29  * OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF
30  * THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
31  * SUCH DAMAGE.
32  *
33  * Please inquire about commercial licensing options at
34  * [email protected]
35  *
36  */
37 
38 #define BTSTACK_FILE__ "mesh_upper_transport.c"
39 
40 #include "mesh/mesh_upper_transport.h"
41 
42 #include <stdio.h>
43 #include <stdlib.h>
44 #include <string.h>
45 
46 #include "btstack_util.h"
47 #include "btstack_memory.h"
48 #include "btstack_debug.h"
49 
50 #include "mesh/beacon.h"
51 #include "mesh/mesh_iv_index_seq_number.h"
52 #include "mesh/mesh_keys.h"
53 #include "mesh/mesh_lower_transport.h"
54 #include "mesh/mesh_peer.h"
55 #include "mesh/mesh_virtual_addresses.h"
56 
57 // TODO: extract mesh_pdu functions into lower transport or network
58 #include "mesh/mesh_access.h"
59 
60 // combined key x address iterator for upper transport decryption
61 
62 typedef struct {
63     // state
64     mesh_transport_key_iterator_t  key_it;
65     mesh_virtual_address_iterator_t address_it;
66     // elements
67     const mesh_transport_key_t *   key;
68     const mesh_virtual_address_t * address;
69     // address - might be virtual
70     uint16_t dst;
71     // key info
72 } mesh_transport_key_and_virtual_address_iterator_t;
73 
74 static void mesh_upper_transport_validate_segmented_message(void);
75 static void mesh_upper_transport_run(void);
76 
77 static int crypto_active;
78 
79 static mesh_unsegmented_pdu_t * incoming_unsegmented_pdu_raw;
80 
81 static mesh_segmented_pdu_t     incoming_message_pdu_singleton;
82 
83 static mesh_access_pdu_t *      incoming_access_pdu_encrypted;
84 static mesh_access_pdu_t *      incoming_access_pdu_decrypted;
85 
86 static mesh_access_pdu_t        incoming_access_pdu_encrypted_singleton;
87 static mesh_access_pdu_t        incoming_access_pdu_decrypted_singleton;
88 
89 static mesh_control_pdu_t       incoming_control_pdu_singleton;
90 static mesh_control_pdu_t *     incoming_control_pdu;
91 
92 static mesh_segmented_pdu_t         outgoing_segmented_pdu_singleton;
93 static mesh_upper_transport_pdu_t * outgoing_upper_transport_pdu;
94 
95 static uint8_t application_nonce[13];
96 static btstack_crypto_ccm_t ccm;
97 static uint8_t crypto_buffer[MESH_ACCESS_PAYLOAD_MAX];
98 static mesh_transport_key_and_virtual_address_iterator_t mesh_transport_key_it;
99 
100 // upper transport callbacks - in access layer
101 static void (*mesh_access_message_handler)( mesh_transport_callback_type_t callback_type, mesh_transport_status_t status, mesh_pdu_t * pdu);
102 static void (*mesh_control_message_handler)( mesh_transport_callback_type_t callback_type, mesh_transport_status_t status, mesh_pdu_t * pdu);
103 
104 // incoming unsegmented (network) and segmented (transport) control and access messages
105 static btstack_linked_list_t upper_transport_incoming;
106 
107 // outgoing unsegmented (network) and segmented (uppert_transport_outgoing) control and access messages
108 static btstack_linked_list_t upper_transport_outgoing;
109 
110 
111 // TODO: higher layer define used for assert
112 #define MESH_ACCESS_OPCODE_NOT_SET 0xFFFFFFFEu
113 
114 static void mesh_print_hex(const char * name, const uint8_t * data, uint16_t len){
115     printf("%-20s ", name);
116     printf_hexdump(data, len);
117 }
118 // static void mesh_print_x(const char * name, uint32_t value){
119 //     printf("%20s: 0x%x", name, (int) value);
120 // }
121 
122 static void mesh_transport_key_and_virtual_address_iterator_init(mesh_transport_key_and_virtual_address_iterator_t *it,
123                                                                  uint16_t dst, uint16_t netkey_index, uint8_t akf,
124                                                                  uint8_t aid) {
125     printf("KEY_INIT: dst %04x, akf %x, aid %x\n", dst, akf, aid);
126     // config
127     it->dst   = dst;
128     // init elements
129     it->key     = NULL;
130     it->address = NULL;
131     // init element iterators
132     mesh_transport_key_aid_iterator_init(&it->key_it, netkey_index, akf, aid);
133     // init address iterator
134     if (mesh_network_address_virtual(it->dst)){
135         mesh_virtual_address_iterator_init(&it->address_it, dst);
136         // get first key
137         if (mesh_transport_key_aid_iterator_has_more(&it->key_it)) {
138             it->key = mesh_transport_key_aid_iterator_get_next(&it->key_it);
139         }
140     }
141 }
142 
143 // cartesian product: keys x addressses
144 static int mesh_transport_key_and_virtual_address_iterator_has_more(mesh_transport_key_and_virtual_address_iterator_t * it){
145     if (mesh_network_address_virtual(it->dst)) {
146         // find next valid entry
147         while (true){
148             if (mesh_virtual_address_iterator_has_more(&it->address_it)) return 1;
149             if (!mesh_transport_key_aid_iterator_has_more(&it->key_it)) return 0;
150             // get next key
151             it->key = mesh_transport_key_aid_iterator_get_next(&it->key_it);
152             mesh_virtual_address_iterator_init(&it->address_it, it->dst);
153         }
154     } else {
155         return mesh_transport_key_aid_iterator_has_more(&it->key_it);
156     }
157 }
158 
159 static void mesh_transport_key_and_virtual_address_iterator_next(mesh_transport_key_and_virtual_address_iterator_t * it){
160     if (mesh_network_address_virtual(it->dst)) {
161         it->address = mesh_virtual_address_iterator_get_next(&it->address_it);
162     } else {
163         it->key = mesh_transport_key_aid_iterator_get_next(&it->key_it);
164     }
165 }
166 
167 // UPPER TRANSPORT
168 
169 uint16_t mesh_access_dst(mesh_access_pdu_t * access_pdu){
170     return big_endian_read_16(access_pdu->network_header, 7);
171 }
172 
173 uint16_t mesh_access_ctl(mesh_access_pdu_t * access_pdu){
174     return access_pdu->network_header[1] >> 7;
175 }
176 
177 uint32_t mesh_access_seq(mesh_access_pdu_t * access_pdu){
178     return big_endian_read_24(access_pdu->network_header, 2);
179 }
180 
181 void mesh_access_set_nid_ivi(mesh_access_pdu_t * access_pdu, uint8_t nid_ivi){
182     access_pdu->network_header[0] = nid_ivi;
183 }
184 void mesh_access_set_ctl_ttl(mesh_access_pdu_t * access_pdu, uint8_t ctl_ttl){
185     access_pdu->network_header[1] = ctl_ttl;
186 }
187 void mesh_access_set_seq(mesh_access_pdu_t * access_pdu, uint32_t seq){
188     big_endian_store_24(access_pdu->network_header, 2, seq);
189 }
190 void mesh_access_set_src(mesh_access_pdu_t * access_pdu, uint16_t src){
191     big_endian_store_16(access_pdu->network_header, 5, src);
192 }
193 void mesh_access_set_dest(mesh_access_pdu_t * access_pdu, uint16_t dest){
194     big_endian_store_16(access_pdu->network_header, 7, dest);
195 }
196 
197 static void mesh_segmented_pdu_flatten(btstack_linked_list_t * segments, uint8_t segment_len, uint8_t * buffer) {
198     // assemble payload
199     btstack_linked_list_iterator_t it;
200     btstack_linked_list_iterator_init(&it, segments);
201     while (btstack_linked_list_iterator_has_next(&it)) {
202         mesh_network_pdu_t *segment = (mesh_network_pdu_t *) btstack_linked_list_iterator_next(&it);
203         btstack_assert(segment->pdu_header.pdu_type == MESH_PDU_TYPE_NETWORK);
204         // get segment n
205         uint8_t *lower_transport_pdu = mesh_network_pdu_data(segment);
206         uint8_t seg_o = (big_endian_read_16(lower_transport_pdu, 2) >> 5) & 0x001f;
207         uint8_t *segment_data = &lower_transport_pdu[4];
208         (void) memcpy(&buffer[seg_o * segment_len], segment_data, segment_len);
209     }
210 }
211 
212 static uint16_t mesh_upper_pdu_flatten(mesh_upper_transport_pdu_t * upper_pdu, uint8_t * buffer, uint16_t buffer_len) {
213     // assemble payload
214     btstack_linked_list_iterator_t it;
215     btstack_linked_list_iterator_init(&it, &upper_pdu->segments);
216     uint16_t offset = 0;
217     while (btstack_linked_list_iterator_has_next(&it)) {
218         mesh_network_pdu_t *segment = (mesh_network_pdu_t *) btstack_linked_list_iterator_next(&it);
219         btstack_assert(segment->pdu_header.pdu_type == MESH_PDU_TYPE_NETWORK);
220         btstack_assert((offset + segment->len) <= buffer_len);
221         (void) memcpy(&buffer[offset], segment->data, segment->len);
222         offset += segment->len;
223     }
224     return offset;
225 }
226 
227 static void mesh_segmented_append_payload(const uint8_t * payload, uint16_t payload_len, btstack_linked_list_t * segments){
228     uint16_t payload_offset = 0;
229     uint16_t bytes_current_segment = 0;
230     mesh_network_pdu_t * network_pdu = (mesh_network_pdu_t *) btstack_linked_list_get_last_item(segments);
231     if (network_pdu){
232         bytes_current_segment = MESH_NETWORK_PAYLOAD_MAX - network_pdu->len;
233     }
234     while (payload_offset < payload_len){
235         if (bytes_current_segment == 0){
236             network_pdu = mesh_network_pdu_get();
237             btstack_assert(network_pdu != NULL);
238             btstack_linked_list_add_tail(segments, (btstack_linked_item_t *) network_pdu);
239             bytes_current_segment = MESH_NETWORK_PAYLOAD_MAX;
240         }
241         uint16_t bytes_to_copy = btstack_min(bytes_current_segment, payload_len - payload_offset);
242         (void) memcpy(&network_pdu->data[network_pdu->len], &payload[payload_offset], bytes_to_copy);
243         bytes_current_segment -= bytes_to_copy;
244         network_pdu->len += bytes_to_copy;
245         payload_offset += bytes_to_copy;
246     }
247 }
248 
249 // stub lower transport
250 
251 static void mesh_upper_transport_dump_pdus(const char *name, btstack_linked_list_t *list){
252     printf("List: %s:\n", name);
253     btstack_linked_list_iterator_t it;
254     btstack_linked_list_iterator_init(&it, list);
255     while (btstack_linked_list_iterator_has_next(&it)){
256         mesh_pdu_t * pdu = (mesh_pdu_t*) btstack_linked_list_iterator_next(&it);
257         printf("- %p\n", pdu);
258         // printf_hexdump( mesh_pdu_data(pdu), mesh_pdu_len(pdu));
259     }
260 }
261 
262 static void mesh_upper_transport_reset_pdus(btstack_linked_list_t *list){
263     while (!btstack_linked_list_empty(list)){
264         mesh_upper_transport_pdu_free((mesh_pdu_t *) btstack_linked_list_pop(list));
265     }
266 }
267 
268 void mesh_upper_transport_dump(void){
269     printf("incoming_unsegmented_pdu_raw: %p\n", incoming_unsegmented_pdu_raw);
270     mesh_upper_transport_dump_pdus("upper_transport_incoming", &upper_transport_incoming);
271 }
272 
273 void mesh_upper_transport_reset(void){
274     crypto_active = 0;
275     if (incoming_unsegmented_pdu_raw){
276         mesh_network_pdu_t * network_pdu = incoming_unsegmented_pdu_raw->segment;
277         btstack_assert(network_pdu != NULL);
278         incoming_unsegmented_pdu_raw->segment = NULL;
279         mesh_network_pdu_free(network_pdu);
280         incoming_unsegmented_pdu_raw = NULL;
281     }
282     outgoing_upper_transport_pdu = NULL;
283     mesh_upper_transport_reset_pdus(&upper_transport_incoming);
284 }
285 
286 static mesh_transport_key_t * mesh_upper_transport_get_outgoing_appkey(uint16_t netkey_index, uint16_t appkey_index){
287     // Device Key is fixed
288     if (appkey_index == MESH_DEVICE_KEY_INDEX) {
289         return mesh_transport_key_get(appkey_index);
290     }
291 
292     // Get key refresh state from subnet
293     mesh_subnet_t * subnet = mesh_subnet_get_by_netkey_index(netkey_index);
294     if (subnet == NULL) return NULL;
295 
296     // identify old and new app keys for given appkey_index
297     mesh_transport_key_t * old_key = NULL;
298     mesh_transport_key_t * new_key = NULL;
299     mesh_transport_key_iterator_t it;
300     mesh_transport_key_iterator_init(&it, netkey_index);
301     while (mesh_transport_key_iterator_has_more(&it)){
302         mesh_transport_key_t * transport_key = mesh_transport_key_iterator_get_next(&it);
303         if (transport_key->appkey_index != appkey_index) continue;
304         if (transport_key->old_key == 0) {
305             new_key = transport_key;
306         } else {
307             old_key = transport_key;
308         }
309     }
310 
311     // if no key is marked as old, just use the current one
312     if (old_key == NULL) return new_key;
313 
314     // use new key if it exists in phase two
315     if ((subnet->key_refresh == MESH_KEY_REFRESH_SECOND_PHASE) && (new_key != NULL)){
316         return new_key;
317     } else {
318         return old_key;
319     }
320 }
321 
322 static uint32_t iv_index_for_ivi_nid(uint8_t ivi_nid){
323     // get IV Index and IVI
324     uint32_t iv_index = mesh_get_iv_index();
325     int ivi = ivi_nid >> 7;
326 
327     // if least significant bit differs, use previous IV Index
328     if ((iv_index & 1 ) ^ ivi){
329         iv_index--;
330     }
331     return iv_index;
332 }
333 
334 static void transport_segmented_setup_nonce(uint8_t * nonce, const mesh_pdu_t * pdu){
335     mesh_access_pdu_t * access_pdu;
336     mesh_upper_transport_pdu_t * upper_pdu;
337     switch (pdu->pdu_type){
338         case MESH_PDU_TYPE_ACCESS:
339             access_pdu = (mesh_access_pdu_t *) pdu;
340             nonce[1] = access_pdu->transmic_len == 8 ? 0x80 : 0x00;
341             (void)memcpy(&nonce[2], &access_pdu->network_header[2], 7);
342             big_endian_store_32(nonce, 9, iv_index_for_ivi_nid(access_pdu->network_header[0]));
343             break;
344         case MESH_PDU_TYPE_UPPER_SEGMENTED_ACCESS:
345         case MESH_PDU_TYPE_UPPER_UNSEGMENTED_ACCESS:
346             upper_pdu = (mesh_upper_transport_pdu_t *) pdu;
347             nonce[1] = upper_pdu->transmic_len == 8 ? 0x80 : 0x00;
348             // 'network header'
349             big_endian_store_24(nonce, 2, upper_pdu->seq);
350             big_endian_store_16(nonce, 5, upper_pdu->src);
351             big_endian_store_16(nonce, 7, upper_pdu->dst);
352             big_endian_store_32(nonce, 9, iv_index_for_ivi_nid(upper_pdu->ivi_nid));
353             break;
354         default:
355             btstack_assert(0);
356             break;
357     }
358 }
359 
360 static void transport_segmented_setup_application_nonce(uint8_t * nonce, const mesh_pdu_t * pdu){
361     nonce[0] = 0x01;
362     transport_segmented_setup_nonce(nonce, pdu);
363     mesh_print_hex("AppNonce", nonce, 13);
364 }
365 
366 static void transport_segmented_setup_device_nonce(uint8_t * nonce, const mesh_pdu_t * pdu){
367     nonce[0] = 0x02;
368     transport_segmented_setup_nonce(nonce, pdu);
369     mesh_print_hex("DeviceNonce", nonce, 13);
370 }
371 
372 static void mesh_upper_transport_process_message_done(mesh_segmented_pdu_t *message_pdu){
373     crypto_active = 0;
374     btstack_assert(message_pdu == &incoming_message_pdu_singleton);
375     mesh_network_pdu_t * network_pdu = (mesh_network_pdu_t *) btstack_linked_list_pop(&incoming_message_pdu_singleton.segments);
376     if (mesh_network_control(network_pdu)) {
377         btstack_assert(0);
378     } else {
379         btstack_assert(network_pdu != NULL);
380         mesh_network_pdu_free(network_pdu);
381         mesh_pdu_t * pdu = (mesh_pdu_t *) incoming_unsegmented_pdu_raw;
382         incoming_unsegmented_pdu_raw = NULL;
383         mesh_lower_transport_message_processed_by_higher_layer(pdu);
384     }
385     mesh_upper_transport_run();
386 }
387 
388 static void mesh_upper_transport_process_unsegmented_message_done(mesh_pdu_t * pdu){
389     btstack_assert(pdu != NULL);
390     btstack_assert(pdu->pdu_type == MESH_PDU_TYPE_UNSEGMENTED);
391 
392     mesh_unsegmented_pdu_t * unsegmented_incoming_pdu = (mesh_unsegmented_pdu_t *) pdu;
393     btstack_assert(unsegmented_incoming_pdu == incoming_unsegmented_pdu_raw);
394 
395     crypto_active = 0;
396     incoming_unsegmented_pdu_raw = NULL;
397     mesh_network_pdu_t * network_pdu = unsegmented_incoming_pdu->segment;
398     if (!mesh_network_control(network_pdu)) {
399         mesh_network_pdu_free(network_pdu);
400     }
401 
402     mesh_lower_transport_message_processed_by_higher_layer(pdu);
403     mesh_upper_transport_run();
404 }
405 
406 static void mesh_upper_transport_process_access_message_done(mesh_access_pdu_t *access_pdu){
407     crypto_active = 0;
408     btstack_assert(mesh_access_ctl(access_pdu) == 0);
409     incoming_access_pdu_encrypted = NULL;
410     mesh_upper_transport_run();
411 }
412 
413 static void mesh_upper_transport_process_control_message_done(mesh_control_pdu_t * control_pdu){
414     crypto_active = 0;
415     incoming_control_pdu = NULL;
416     mesh_upper_transport_run();
417 }
418 
419 static void mesh_upper_transport_validate_segmented_message_ccm(void * arg){
420     UNUSED(arg);
421 
422     uint8_t * upper_transport_pdu     = incoming_access_pdu_decrypted->data;
423     uint8_t   upper_transport_pdu_len = incoming_access_pdu_decrypted->len - incoming_access_pdu_decrypted->transmic_len;
424 
425     mesh_print_hex("Decrypted PDU", upper_transport_pdu, upper_transport_pdu_len);
426 
427     // store TransMIC
428     uint8_t trans_mic[8];
429     btstack_crypto_ccm_get_authentication_value(&ccm, trans_mic);
430     mesh_print_hex("TransMIC", trans_mic, incoming_access_pdu_decrypted->transmic_len);
431 
432     if (memcmp(trans_mic, &upper_transport_pdu[upper_transport_pdu_len], incoming_access_pdu_decrypted->transmic_len) == 0){
433         printf("TransMIC matches\n");
434 
435         // remove TransMIC from payload
436         incoming_access_pdu_decrypted->len -= incoming_access_pdu_decrypted->transmic_len;
437 
438         // if virtual address, update dst to pseudo_dst
439         if (mesh_network_address_virtual(mesh_access_dst(incoming_access_pdu_decrypted))){
440             big_endian_store_16(incoming_access_pdu_decrypted->network_header, 7, mesh_transport_key_it.address->pseudo_dst);
441         }
442 
443         // pass to upper layer
444         btstack_assert(mesh_access_message_handler != NULL);
445         mesh_pdu_t * pdu = (mesh_pdu_t*) incoming_access_pdu_decrypted;
446         mesh_access_message_handler(MESH_TRANSPORT_PDU_RECEIVED, MESH_TRANSPORT_STATUS_SUCCESS, pdu);
447 
448         printf("\n");
449 
450     } else {
451         uint8_t akf = incoming_access_pdu_decrypted->akf_aid_control & 0x40;
452         if (akf){
453             printf("TransMIC does not match, try next key\n");
454             mesh_upper_transport_validate_segmented_message();
455         } else {
456             printf("TransMIC does not match device key, done\n");
457             // done
458             mesh_upper_transport_process_access_message_done(incoming_access_pdu_decrypted);
459         }
460     }
461 }
462 
463 static void mesh_upper_transport_validate_segmented_message_digest(void * arg){
464     UNUSED(arg);
465     uint8_t   upper_transport_pdu_len      = incoming_access_pdu_encrypted->len - incoming_access_pdu_encrypted->transmic_len;
466     uint8_t * upper_transport_pdu_data_in  = incoming_access_pdu_encrypted->data;
467     uint8_t * upper_transport_pdu_data_out = incoming_access_pdu_decrypted->data;
468     btstack_crypto_ccm_decrypt_block(&ccm, upper_transport_pdu_len, upper_transport_pdu_data_in, upper_transport_pdu_data_out, &mesh_upper_transport_validate_segmented_message_ccm, NULL);
469 }
470 
471 static void mesh_upper_transport_validate_segmented_message(void){
472     uint8_t * upper_transport_pdu_data =  incoming_access_pdu_decrypted->data;
473     uint8_t   upper_transport_pdu_len  = incoming_access_pdu_decrypted->len - incoming_access_pdu_decrypted->transmic_len;
474 
475     if (!mesh_transport_key_and_virtual_address_iterator_has_more(&mesh_transport_key_it)){
476         printf("No valid transport key found\n");
477         mesh_upper_transport_process_access_message_done(incoming_access_pdu_decrypted);
478         return;
479     }
480     mesh_transport_key_and_virtual_address_iterator_next(&mesh_transport_key_it);
481     const mesh_transport_key_t * message_key = mesh_transport_key_it.key;
482 
483     if (message_key->akf){
484         transport_segmented_setup_application_nonce(application_nonce, (mesh_pdu_t *) incoming_access_pdu_encrypted);
485     } else {
486         transport_segmented_setup_device_nonce(application_nonce, (mesh_pdu_t *) incoming_access_pdu_encrypted);
487     }
488 
489     // store application / device key index
490     mesh_print_hex("AppOrDevKey", message_key->key, 16);
491     incoming_access_pdu_decrypted->appkey_index = message_key->appkey_index;
492 
493     mesh_print_hex("EncAccessPayload", upper_transport_pdu_data, upper_transport_pdu_len);
494 
495     // decrypt ccm
496     crypto_active = 1;
497     uint16_t aad_len  = 0;
498     if (mesh_network_address_virtual(mesh_access_dst(incoming_access_pdu_decrypted))){
499         aad_len  = 16;
500     }
501     btstack_crypto_ccm_init(&ccm, message_key->key, application_nonce, upper_transport_pdu_len, aad_len, incoming_access_pdu_decrypted->transmic_len);
502 
503     if (aad_len){
504         btstack_crypto_ccm_digest(&ccm, (uint8_t *) mesh_transport_key_it.address->label_uuid, aad_len, &mesh_upper_transport_validate_segmented_message_digest, NULL);
505     } else {
506         mesh_upper_transport_validate_segmented_message_digest(NULL);
507     }
508 }
509 
510 static void mesh_upper_transport_process_segmented_message(void){
511     // copy original pdu
512     (void)memcpy(incoming_access_pdu_decrypted, incoming_access_pdu_encrypted,
513                  sizeof(mesh_access_pdu_t));
514 
515     //
516     uint8_t * upper_transport_pdu     =  incoming_access_pdu_decrypted->data;
517     uint8_t   upper_transport_pdu_len = incoming_access_pdu_decrypted->len - incoming_access_pdu_decrypted->transmic_len;
518     mesh_print_hex("Upper Transport pdu", upper_transport_pdu, upper_transport_pdu_len);
519 
520     uint8_t aid = incoming_access_pdu_decrypted->akf_aid_control & 0x3f;
521     uint8_t akf = (incoming_access_pdu_decrypted->akf_aid_control & 0x40) >> 6;
522 
523     printf("AKF: %u\n",   akf);
524     printf("AID: %02x\n", aid);
525 
526     mesh_transport_key_and_virtual_address_iterator_init(&mesh_transport_key_it, mesh_access_dst(incoming_access_pdu_decrypted),
527                                                          incoming_access_pdu_decrypted->netkey_index, akf, aid);
528     mesh_upper_transport_validate_segmented_message();
529 }
530 
531 static void mesh_upper_transport_message_received(mesh_pdu_t * pdu){
532     btstack_linked_list_add_tail(&upper_transport_incoming, (btstack_linked_item_t*) pdu);
533     mesh_upper_transport_run();
534 }
535 
536 static void mesh_upper_transport_send_access_segmented(mesh_upper_transport_pdu_t * upper_pdu){
537 
538     // TODO: store upper pdu in outgoing pdus active or similar
539     outgoing_upper_transport_pdu = upper_pdu;
540 
541     mesh_segmented_pdu_t * message_pdu   = &outgoing_segmented_pdu_singleton;
542     message_pdu->pdu_header.pdu_type = MESH_PDU_TYPE_SEGMENTED;
543 
544     // convert mesh_access_pdu_t into mesh_segmented_pdu_t
545     mesh_segmented_append_payload(crypto_buffer, upper_pdu->len, &message_pdu->segments);
546 
547     // copy meta
548     message_pdu->len = upper_pdu->len;
549     message_pdu->netkey_index = upper_pdu->netkey_index;
550     message_pdu->transmic_len = upper_pdu->transmic_len;
551     message_pdu->akf_aid_control = upper_pdu->akf_aid_control;
552     message_pdu->flags = upper_pdu->flags;
553 
554     // setup message_pdu header
555     // (void)memcpy(message_pdu->network_header, upper_pdu->network_header, 9);
556     // TODO: use fields in mesh_segmented_pdu_t and setup network header in lower transport
557     message_pdu->network_header[0] = upper_pdu->ivi_nid;
558     message_pdu->network_header[1] = upper_pdu->ctl_ttl;
559     big_endian_store_24(message_pdu->network_header, 2, upper_pdu->seq);
560     big_endian_store_16(message_pdu->network_header, 5, upper_pdu->src);
561     big_endian_store_16(message_pdu->network_header, 7, upper_pdu->dst);
562 
563     mesh_lower_transport_send_pdu((mesh_pdu_t*) message_pdu);
564 }
565 
566 static void mesh_upper_transport_send_access_unsegmented(mesh_upper_transport_pdu_t * upper_pdu){
567 
568     // TODO: store upper pdu in outgoing pdus active or similar
569     outgoing_upper_transport_pdu = upper_pdu;
570 
571     // provide segment
572     mesh_network_pdu_t * network_pdu = mesh_network_pdu_get();
573     btstack_assert(network_pdu);
574 
575     // setup network pdu
576     network_pdu->pdu_header.pdu_type = MESH_PDU_TYPE_UPPER_UNSEGMENTED_ACCESS;
577     network_pdu->data[0] = upper_pdu->ivi_nid;
578     network_pdu->data[1] = upper_pdu->ctl_ttl;
579     big_endian_store_24(network_pdu->data, 2, upper_pdu->seq);
580     big_endian_store_16(network_pdu->data, 5, upper_pdu->src);
581     big_endian_store_16(network_pdu->data, 7, upper_pdu->dst);
582     network_pdu->netkey_index = upper_pdu->netkey_index;
583 
584     // setup access message
585     network_pdu->data[9] = upper_pdu->akf_aid_control;
586     btstack_assert(upper_pdu->len < 15);
587     (void)memcpy(&network_pdu->data[10], crypto_buffer, upper_pdu->len);
588     network_pdu->len = 10 + upper_pdu->len;
589     network_pdu->flags = 0;
590 
591     mesh_lower_transport_send_pdu((mesh_pdu_t*) network_pdu);
592 }
593 
594 static void mesh_upper_transport_send_access_ccm(void * arg){
595     crypto_active = 0;
596 
597     mesh_upper_transport_pdu_t * upper_pdu = (mesh_upper_transport_pdu_t *) arg;
598     mesh_print_hex("EncAccessPayload", crypto_buffer, upper_pdu->len);
599     // store TransMIC
600     btstack_crypto_ccm_get_authentication_value(&ccm, &crypto_buffer[upper_pdu->len]);
601     mesh_print_hex("TransMIC", &crypto_buffer[upper_pdu->len], upper_pdu->transmic_len);
602     upper_pdu->len += upper_pdu->transmic_len;
603     mesh_print_hex("UpperTransportPDU", crypto_buffer, upper_pdu->len);
604     switch (upper_pdu->pdu_header.pdu_type){
605         case MESH_PDU_TYPE_UPPER_UNSEGMENTED_ACCESS:
606             mesh_upper_transport_send_access_unsegmented(upper_pdu);
607             break;
608         case MESH_PDU_TYPE_UPPER_SEGMENTED_ACCESS:
609             mesh_upper_transport_send_access_segmented(upper_pdu);
610             break;
611         default:
612             btstack_assert(false);
613     }
614 }
615 
616 static void mesh_upper_transport_send_access_digest(void *arg){
617     mesh_upper_transport_pdu_t * upper_pdu = (mesh_upper_transport_pdu_t *) arg;
618     uint16_t  access_pdu_len  = upper_pdu->len;
619     btstack_crypto_ccm_encrypt_block(&ccm, access_pdu_len, crypto_buffer, crypto_buffer,
620                                      &mesh_upper_transport_send_access_ccm, upper_pdu);
621 }
622 
623 static void mesh_upper_transport_send_access(mesh_upper_transport_pdu_t * upper_pdu){
624 
625     // if dst is virtual address, lookup label uuid and hash
626     uint16_t aad_len = 0;
627     mesh_virtual_address_t * virtual_address = NULL;
628     if (mesh_network_address_virtual(upper_pdu->dst)){
629         virtual_address = mesh_virtual_address_for_pseudo_dst(upper_pdu->dst);
630         if (!virtual_address){
631             printf("No virtual address register for pseudo dst %4x\n", upper_pdu->dst);
632             mesh_access_message_handler(MESH_TRANSPORT_PDU_SENT, MESH_TRANSPORT_STATUS_SEND_FAILED, (mesh_pdu_t *) upper_pdu);
633             return;
634         }
635         // printf("Using hash %4x with LabelUUID: ", virtual_address->hash);
636         // printf_hexdump(virtual_address->label_uuid, 16);
637         aad_len = 16;
638         upper_pdu->dst = virtual_address->hash;
639     }
640 
641     // get app or device key
642     uint16_t appkey_index = upper_pdu->appkey_index;
643     const mesh_transport_key_t * appkey = mesh_upper_transport_get_outgoing_appkey(upper_pdu->netkey_index, appkey_index);
644     if (appkey == NULL){
645         printf("AppKey %04x not found, drop message\n", appkey_index);
646         mesh_access_message_handler(MESH_TRANSPORT_PDU_SENT, MESH_TRANSPORT_STATUS_SEND_FAILED, (mesh_pdu_t *) upper_pdu);
647         return;
648     }
649 
650     // reserve slot
651     mesh_lower_transport_reserve_slot();
652 
653     // reserve one sequence number, which is also used to encrypt access payload
654     uint32_t seq = mesh_sequence_number_next();
655     upper_pdu->flags |= MESH_TRANSPORT_FLAG_SEQ_RESERVED;
656     upper_pdu->seq = seq;
657 
658     // also reserves crypto_buffer
659     crypto_active = 1;
660 
661     // flatten segmented pdu into crypto buffer
662     uint16_t payload_len = mesh_upper_pdu_flatten(upper_pdu, crypto_buffer, sizeof(crypto_buffer));
663     btstack_assert(payload_len == upper_pdu->len);
664 
665     // Dump PDU
666     printf("[+] Upper transport, send upper (un)segmented Access PDU - dest %04x, seq %06x\n", upper_pdu->dst, upper_pdu->seq);
667     mesh_print_hex("Access Payload", crypto_buffer, upper_pdu->len);
668 
669     // setup nonce - uses dst, so after pseudo address translation
670     if (appkey_index == MESH_DEVICE_KEY_INDEX){
671         transport_segmented_setup_device_nonce(application_nonce, (mesh_pdu_t *) upper_pdu);
672     } else {
673         transport_segmented_setup_application_nonce(application_nonce, (mesh_pdu_t *) upper_pdu);
674     }
675 
676     // Dump key
677     mesh_print_hex("AppOrDevKey", appkey->key, 16);
678 
679     // encrypt ccm
680     uint8_t   transmic_len    = upper_pdu->transmic_len;
681     uint16_t  access_pdu_len  = upper_pdu->len;
682     btstack_crypto_ccm_init(&ccm, appkey->key, application_nonce, access_pdu_len, aad_len, transmic_len);
683     if (virtual_address){
684         mesh_print_hex("LabelUUID", virtual_address->label_uuid, 16);
685         btstack_crypto_ccm_digest(&ccm, virtual_address->label_uuid, 16,
686                                   &mesh_upper_transport_send_access_digest, upper_pdu);
687     } else {
688         mesh_upper_transport_send_access_digest(upper_pdu);
689     }
690 }
691 
692 static void mesh_upper_transport_send_unsegmented_control_pdu(mesh_network_pdu_t * network_pdu){
693     // reserve slot
694     mesh_lower_transport_reserve_slot();
695     // reserve sequence number
696     uint32_t seq = mesh_sequence_number_next();
697     mesh_network_pdu_set_seq(network_pdu, seq);
698     // Dump PDU
699     uint8_t opcode = network_pdu->data[9];
700     printf("[+] Upper transport, send unsegmented Control PDU %p - seq %06x opcode %02x\n", network_pdu, seq, opcode);
701     mesh_print_hex("Access Payload", &network_pdu->data[10], network_pdu->len - 10);
702 
703     // send
704      mesh_lower_transport_send_pdu((mesh_pdu_t *) network_pdu);
705 }
706 
707 static void mesh_upper_transport_send_segmented_control_pdu(mesh_upper_transport_pdu_t * upper_pdu){
708     // reserve slot
709     mesh_lower_transport_reserve_slot();
710     // reserve sequence number
711     uint32_t seq = mesh_sequence_number_next();
712     upper_pdu->flags |= MESH_TRANSPORT_FLAG_SEQ_RESERVED;
713     upper_pdu->seq = seq;
714     // Dump PDU
715     // uint8_t opcode = upper_pdu->data[0];
716     // printf("[+] Upper transport, send segmented Control PDU %p - seq %06x opcode %02x\n", upper_pdu, seq, opcode);
717     // mesh_print_hex("Access Payload", &upper_pdu->data[1], upper_pdu->len - 1);
718     // send
719     outgoing_upper_transport_pdu = upper_pdu;
720     mesh_segmented_pdu_t *messagePdu = &outgoing_segmented_pdu_singleton;
721     messagePdu->pdu_header.pdu_type = MESH_PDU_TYPE_SEGMENTED;
722 
723     // lend segments to lower transport pdu
724     messagePdu->segments = upper_pdu->segments;
725     upper_pdu->segments = NULL;
726 
727     // copy meta
728     messagePdu->len = upper_pdu->len;
729     messagePdu->netkey_index = upper_pdu->netkey_index;
730     messagePdu->transmic_len = 0;   // no TransMIC for control
731     messagePdu->akf_aid_control = upper_pdu->akf_aid_control;
732     messagePdu->flags = upper_pdu->flags;
733 
734     // setup message_pdu header
735     // TODO: use fields in mesh_segmented_pdu_t and setup network header in lower transport
736     messagePdu->network_header[0] = upper_pdu->ivi_nid;
737     messagePdu->network_header[1] = upper_pdu->ctl_ttl;
738     big_endian_store_24(messagePdu->network_header, 2, upper_pdu->seq);
739     big_endian_store_16(messagePdu->network_header, 5, upper_pdu->src);
740     big_endian_store_16(messagePdu->network_header, 7, upper_pdu->dst);
741 
742     mesh_lower_transport_send_pdu((mesh_pdu_t *) messagePdu);
743 }
744 
745 static void mesh_upper_transport_run(void){
746 
747     while(!btstack_linked_list_empty(&upper_transport_incoming)){
748 
749         if (crypto_active) return;
750 
751         // get next message
752         mesh_pdu_t * pdu =  (mesh_pdu_t *) btstack_linked_list_pop(&upper_transport_incoming);
753         mesh_network_pdu_t   * network_pdu;
754         mesh_segmented_pdu_t   * message_pdu;
755         mesh_unsegmented_pdu_t * unsegmented_pdu;
756         switch (pdu->pdu_type){
757             case MESH_PDU_TYPE_UNSEGMENTED:
758                 unsegmented_pdu = (mesh_unsegmented_pdu_t *) pdu;
759                 network_pdu = unsegmented_pdu->segment;
760                 btstack_assert(network_pdu != NULL);
761                 // control?
762                 if (mesh_network_control(network_pdu)) {
763 
764                     incoming_control_pdu =  &incoming_control_pdu_singleton;
765                     incoming_control_pdu->pdu_header.pdu_type = MESH_PDU_TYPE_CONTROL;
766                     incoming_control_pdu->len =  network_pdu->len;
767                     incoming_control_pdu->netkey_index =  network_pdu->netkey_index;
768 
769                     uint8_t * lower_transport_pdu = mesh_network_pdu_data(network_pdu);
770 
771                     incoming_control_pdu->akf_aid_control = lower_transport_pdu[0];
772                     incoming_control_pdu->len = network_pdu->len - 10; // 9 header + 1 opcode
773                     (void)memcpy(incoming_control_pdu->data, &lower_transport_pdu[1], incoming_control_pdu->len);
774 
775                     // copy meta data into encrypted pdu buffer
776                     (void)memcpy(incoming_control_pdu->network_header, network_pdu->data, 9);
777 
778                     mesh_print_hex("Assembled payload", incoming_control_pdu->data, incoming_control_pdu->len);
779 
780                     // free mesh message
781                     mesh_lower_transport_message_processed_by_higher_layer(pdu);
782 
783                     btstack_assert(mesh_control_message_handler != NULL);
784                     mesh_pdu_t * pdu = (mesh_pdu_t*) incoming_control_pdu;
785                     mesh_control_message_handler(MESH_TRANSPORT_PDU_RECEIVED, MESH_TRANSPORT_STATUS_SUCCESS, pdu);
786 
787                 } else {
788 
789                     incoming_access_pdu_encrypted = &incoming_access_pdu_encrypted_singleton;
790                     incoming_access_pdu_encrypted->pdu_header.pdu_type = MESH_PDU_TYPE_ACCESS;
791                     incoming_access_pdu_decrypted = &incoming_access_pdu_decrypted_singleton;
792 
793                     incoming_access_pdu_encrypted->netkey_index = network_pdu->netkey_index;
794                     incoming_access_pdu_encrypted->transmic_len = 4;
795 
796                     uint8_t * lower_transport_pdu = mesh_network_pdu_data(network_pdu);
797 
798                     incoming_access_pdu_encrypted->akf_aid_control = lower_transport_pdu[0];
799                     incoming_access_pdu_encrypted->len = network_pdu->len - 10; // 9 header + 1 AID
800                     (void)memcpy(incoming_access_pdu_encrypted->data, &lower_transport_pdu[1], incoming_access_pdu_encrypted->len);
801 
802                     // copy meta data into encrypted pdu buffer
803                     (void)memcpy(incoming_access_pdu_encrypted->network_header, network_pdu->data, 9);
804 
805                     mesh_print_hex("Assembled payload", incoming_access_pdu_encrypted->data, incoming_access_pdu_encrypted->len);
806 
807                     // free mesh message
808                     mesh_lower_transport_message_processed_by_higher_layer(pdu);
809 
810                     // get encoded transport pdu and start processing
811                     mesh_upper_transport_process_segmented_message();
812                 }
813                 break;
814             case MESH_PDU_TYPE_SEGMENTED:
815                 message_pdu = (mesh_segmented_pdu_t *) pdu;
816                 uint8_t ctl = mesh_message_ctl(message_pdu);
817                 if (ctl){
818                     incoming_control_pdu=  &incoming_control_pdu_singleton;
819                     incoming_control_pdu->pdu_header.pdu_type = MESH_PDU_TYPE_CONTROL;
820 
821                     // flatten
822                     mesh_segmented_pdu_flatten(&message_pdu->segments, 8, incoming_control_pdu->data);
823 
824                     // copy meta data into encrypted pdu buffer
825                     incoming_control_pdu->len =  message_pdu->len;
826                     incoming_control_pdu->netkey_index =  message_pdu->netkey_index;
827                     incoming_control_pdu->akf_aid_control =  message_pdu->akf_aid_control;
828                     incoming_control_pdu->flags = 0;
829                     (void)memcpy(incoming_control_pdu->network_header, message_pdu->network_header, 9);
830 
831                     mesh_print_hex("Assembled payload", incoming_control_pdu->data, incoming_control_pdu->len);
832 
833                     // free mesh message
834                     mesh_lower_transport_message_processed_by_higher_layer((mesh_pdu_t *)message_pdu);
835 
836                     btstack_assert(mesh_control_message_handler != NULL);
837                     mesh_pdu_t * pdu = (mesh_pdu_t*) incoming_control_pdu;
838                     mesh_access_message_handler(MESH_TRANSPORT_PDU_RECEIVED, MESH_TRANSPORT_STATUS_SUCCESS, pdu);
839 
840                 } else {
841 
842                     incoming_access_pdu_encrypted = &incoming_access_pdu_encrypted_singleton;
843                     incoming_access_pdu_encrypted->pdu_header.pdu_type = MESH_PDU_TYPE_ACCESS;
844                     incoming_access_pdu_decrypted = &incoming_access_pdu_decrypted_singleton;
845 
846                     // flatten
847                     mesh_segmented_pdu_flatten(&message_pdu->segments, 12, incoming_access_pdu_encrypted->data);
848 
849                     // copy meta data into encrypted pdu buffer
850                     incoming_access_pdu_encrypted->len =  message_pdu->len;
851                     incoming_access_pdu_encrypted->netkey_index =  message_pdu->netkey_index;
852                     incoming_access_pdu_encrypted->transmic_len =  message_pdu->transmic_len;
853                     incoming_access_pdu_encrypted->akf_aid_control =  message_pdu->akf_aid_control;
854                     (void)memcpy(incoming_access_pdu_encrypted->network_header, message_pdu->network_header, 9);
855 
856                     mesh_print_hex("Assembled payload", incoming_access_pdu_encrypted->data, incoming_access_pdu_encrypted->len);
857 
858                     // free mesh message
859                     mesh_lower_transport_message_processed_by_higher_layer((mesh_pdu_t *)message_pdu);
860 
861                     // get encoded transport pdu and start processing
862                     mesh_upper_transport_process_segmented_message();
863                 }
864                 break;
865             default:
866                 btstack_assert(0);
867                 break;
868         }
869     }
870 
871     while (!btstack_linked_list_empty(&upper_transport_outgoing)){
872 
873         if (crypto_active) break;
874 
875         if (outgoing_upper_transport_pdu != NULL) break;
876 
877         mesh_pdu_t * pdu =  (mesh_pdu_t *) btstack_linked_list_get_first_item(&upper_transport_outgoing);
878         if (mesh_lower_transport_can_send_to_dest(mesh_pdu_dst(pdu)) == 0) break;
879 
880         (void) btstack_linked_list_pop(&upper_transport_outgoing);
881 
882 
883         switch (pdu->pdu_type){
884             case MESH_PDU_TYPE_UPPER_UNSEGMENTED_CONTROL:
885                 btstack_assert(mesh_pdu_ctl(pdu) != 0);
886                 mesh_upper_transport_send_unsegmented_control_pdu((mesh_network_pdu_t *) pdu);
887                 break;
888             case MESH_PDU_TYPE_UPPER_SEGMENTED_CONTROL:
889                 mesh_upper_transport_send_segmented_control_pdu((mesh_upper_transport_pdu_t *) pdu);
890                 break;
891             case MESH_PDU_TYPE_UPPER_SEGMENTED_ACCESS:
892             case MESH_PDU_TYPE_UPPER_UNSEGMENTED_ACCESS:
893                 mesh_upper_transport_send_access((mesh_upper_transport_pdu_t *) pdu);
894                 break;
895             default:
896                 btstack_assert(false);
897                 break;
898         }
899     }
900 }
901 
902 static void mesh_upper_transport_pdu_handler(mesh_transport_callback_type_t callback_type, mesh_transport_status_t status, mesh_pdu_t * pdu){
903     mesh_pdu_t * pdu_to_report;
904     mesh_upper_transport_pdu_t * upper_pdu;
905     switch (callback_type){
906         case MESH_TRANSPORT_PDU_RECEIVED:
907             mesh_upper_transport_message_received(pdu);
908             break;
909         case MESH_TRANSPORT_PDU_SENT:
910             switch (pdu->pdu_type){
911                 case MESH_PDU_TYPE_SEGMENTED:
912                     // free chunks
913                     while (!btstack_linked_list_empty(&outgoing_segmented_pdu_singleton.segments)){
914                         mesh_network_pdu_t * network_pdu = (mesh_network_pdu_t *) btstack_linked_list_pop(&outgoing_segmented_pdu_singleton.segments);
915                         mesh_network_pdu_free(network_pdu);
916                     }
917                     // notify upper layer but use transport pdu
918                     pdu_to_report = (mesh_pdu_t *) outgoing_upper_transport_pdu;
919                     outgoing_upper_transport_pdu = NULL;
920                     if (mesh_pdu_ctl(pdu_to_report)){
921                         mesh_control_message_handler(callback_type, status, pdu_to_report);
922                     } else {
923                         mesh_access_message_handler(callback_type, status, pdu_to_report);
924                     }
925                     break;
926                 case MESH_PDU_TYPE_UPPER_UNSEGMENTED_ACCESS:
927                     upper_pdu = outgoing_upper_transport_pdu;
928                     outgoing_upper_transport_pdu = NULL;
929                     mesh_access_message_handler(callback_type, status, (mesh_pdu_t*) upper_pdu);
930                     break;
931                 case MESH_PDU_TYPE_UPPER_UNSEGMENTED_CONTROL:
932                     mesh_access_message_handler(callback_type, status, pdu);
933                     break;
934                 default:
935                     btstack_assert(false);
936                     break;
937             }
938             mesh_upper_transport_run();
939             break;
940         default:
941             break;
942     }
943 }
944 
945 void mesh_upper_transport_pdu_free(mesh_pdu_t * pdu){
946     mesh_network_pdu_t   * network_pdu;
947     mesh_segmented_pdu_t   * message_pdu;
948     switch (pdu->pdu_type) {
949         case MESH_PDU_TYPE_NETWORK:
950             network_pdu = (mesh_network_pdu_t *) pdu;
951             mesh_network_pdu_free(network_pdu);
952             break;
953         case MESH_PDU_TYPE_SEGMENTED:
954             message_pdu = (mesh_segmented_pdu_t *) pdu;
955             mesh_message_pdu_free(message_pdu);
956         default:
957             btstack_assert(false);
958             break;
959     }
960 }
961 
962 void mesh_upper_transport_message_processed_by_higher_layer(mesh_pdu_t * pdu){
963     crypto_active = 0;
964     switch (pdu->pdu_type){
965         case MESH_PDU_TYPE_ACCESS:
966             mesh_upper_transport_process_access_message_done((mesh_access_pdu_t *) pdu);
967         case MESH_PDU_TYPE_CONTROL:
968             mesh_upper_transport_process_control_message_done((mesh_control_pdu_t *) pdu);
969             break;
970         default:
971             btstack_assert(0);
972             break;
973     }
974 }
975 
976 void mesh_upper_transport_send_access_pdu(mesh_pdu_t *pdu){
977     switch (pdu->pdu_type){
978         case MESH_PDU_TYPE_UPPER_SEGMENTED_ACCESS:
979         case MESH_PDU_TYPE_UPPER_UNSEGMENTED_ACCESS:
980             break;
981         default:
982             btstack_assert(false);
983             break;
984     }
985 
986     btstack_linked_list_add_tail(&upper_transport_outgoing, (btstack_linked_item_t*) pdu);
987     mesh_upper_transport_run();
988 }
989 
990 void mesh_upper_transport_send_control_pdu(mesh_pdu_t * pdu){
991     switch (pdu->pdu_type){
992         case MESH_PDU_TYPE_UPPER_SEGMENTED_CONTROL:
993             break;
994         case MESH_PDU_TYPE_UPPER_UNSEGMENTED_CONTROL:
995             btstack_assert( ((mesh_network_pdu_t *) pdu)->len >= 9);
996             break;
997         default:
998             btstack_assert(false);
999             break;
1000     }
1001 
1002     btstack_linked_list_add_tail(&upper_transport_outgoing, (btstack_linked_item_t*) pdu);
1003     mesh_upper_transport_run();
1004 }
1005 
1006 static uint8_t mesh_upper_transport_setup_unsegmented_control_pdu(mesh_network_pdu_t * network_pdu, uint16_t netkey_index, uint8_t ttl, uint16_t src, uint16_t dest, uint8_t opcode,
1007                                                                   const uint8_t * control_pdu_data, uint16_t control_pdu_len){
1008 
1009     if (control_pdu_len > 11) return 1;
1010 
1011     const mesh_network_key_t * network_key = mesh_network_key_list_get(netkey_index);
1012     if (!network_key) return 1;
1013 
1014     uint8_t transport_pdu_data[12];
1015     transport_pdu_data[0] = opcode;
1016     (void)memcpy(&transport_pdu_data[1], control_pdu_data, control_pdu_len);
1017     uint16_t transport_pdu_len = control_pdu_len + 1;
1018 
1019     // setup network_pdu
1020     mesh_network_setup_pdu(network_pdu, netkey_index, network_key->nid, 1, ttl, 0, src, dest, transport_pdu_data, transport_pdu_len);
1021 
1022     return 0;
1023 }
1024 
1025 static uint8_t mesh_upper_transport_setup_segmented_control_pdu(mesh_upper_transport_pdu_t * upper_pdu, uint16_t netkey_index, uint8_t ttl, uint16_t src, uint16_t dest, uint8_t opcode,
1026                                                                 const uint8_t * control_pdu_data, uint16_t control_pdu_len){
1027 
1028     if (control_pdu_len > 256) return 1;
1029 
1030     const mesh_network_key_t * network_key = mesh_network_key_list_get(netkey_index);
1031     if (!network_key) return 1;
1032 
1033     upper_pdu->ivi_nid = network_key->nid | ((mesh_get_iv_index_for_tx() & 1) << 7);
1034     upper_pdu->ctl_ttl = ttl;
1035     upper_pdu->src = src;
1036     upper_pdu->dst = dest;
1037     upper_pdu->transmic_len = 0;    // no TransMIC for control
1038     upper_pdu->netkey_index = netkey_index;
1039     upper_pdu->akf_aid_control = opcode;
1040 
1041     mesh_segmented_append_payload(control_pdu_data, control_pdu_len, &upper_pdu->segments);
1042     upper_pdu->len = control_pdu_len;
1043     return 0;
1044 }
1045 
1046 uint8_t mesh_upper_transport_setup_control_pdu(mesh_pdu_t * pdu, uint16_t netkey_index,
1047                                                uint8_t ttl, uint16_t src, uint16_t dest, uint8_t opcode, const uint8_t * control_pdu_data, uint16_t control_pdu_len){
1048     switch (pdu->pdu_type){
1049         case MESH_PDU_TYPE_UPPER_UNSEGMENTED_CONTROL:
1050             return mesh_upper_transport_setup_unsegmented_control_pdu((mesh_network_pdu_t *) pdu, netkey_index, ttl, src, dest, opcode, control_pdu_data, control_pdu_len);
1051         case MESH_PDU_TYPE_UPPER_SEGMENTED_CONTROL:
1052             return mesh_upper_transport_setup_segmented_control_pdu((mesh_upper_transport_pdu_t *) pdu,  netkey_index, ttl, src, dest, opcode, control_pdu_data, control_pdu_len);
1053         default:
1054             btstack_assert(0);
1055             return 1;
1056     }
1057 }
1058 
1059 static uint8_t mesh_upper_transport_setup_unsegmented_access_pdu_header(mesh_unsegmented_pdu_t * unsegmented_pdu, uint16_t netkey_index,
1060                                                                         uint16_t appkey_index, uint8_t ttl, uint16_t src, uint16_t dest){
1061 
1062     mesh_network_pdu_t * network_pdu = unsegmented_pdu->segment;
1063 
1064     // get app or device key
1065     const mesh_transport_key_t * appkey;
1066     appkey = mesh_transport_key_get(appkey_index);
1067     if (appkey == NULL){
1068         printf("appkey_index %x unknown\n", appkey_index);
1069         return 1;
1070     }
1071     uint8_t akf_aid = (appkey->akf << 6) | appkey->aid;
1072 
1073     // lookup network by netkey_index
1074     const mesh_network_key_t * network_key = mesh_network_key_list_get(netkey_index);
1075     if (!network_key) return 1;
1076 
1077     unsegmented_pdu->appkey_index = appkey_index;
1078 
1079     network_pdu->data[9] = akf_aid;
1080     // setup network_pdu
1081     mesh_network_setup_pdu_header(network_pdu, netkey_index, network_key->nid, 0, ttl, 0, src, dest);
1082     return 0;
1083 }
1084 
1085 static uint8_t mesh_upper_transport_setup_segmented_access_pdu_header(mesh_access_pdu_t * access_pdu, uint16_t netkey_index,
1086                                                                       uint16_t appkey_index, uint8_t ttl, uint16_t src, uint16_t dest, uint8_t szmic){
1087 
1088     // get app or device key
1089     const mesh_transport_key_t *appkey;
1090     appkey = mesh_transport_key_get(appkey_index);
1091     if (appkey == NULL) {
1092         printf("[!] Upper transport, setup segmented Access PDU - appkey_index %x unknown\n", appkey_index);
1093         return 1;
1094     }
1095     uint8_t akf_aid = (appkey->akf << 6) | appkey->aid;
1096 
1097     // lookup network by netkey_index
1098     const mesh_network_key_t *network_key = mesh_network_key_list_get(netkey_index);
1099     if (!network_key) return 1;
1100     if (network_key == NULL) {
1101         printf("[!] Upper transport, setup segmented Access PDU - netkey_index %x unknown\n", appkey_index);
1102         return 1;
1103     }
1104 
1105     const uint8_t trans_mic_len = szmic ? 8 : 4;
1106 
1107     // store in transport pdu
1108     access_pdu->transmic_len = trans_mic_len;
1109     access_pdu->netkey_index = netkey_index;
1110     access_pdu->appkey_index = appkey_index;
1111     access_pdu->akf_aid_control = akf_aid;
1112     mesh_access_set_nid_ivi(access_pdu, network_key->nid | ((mesh_get_iv_index_for_tx() & 1) << 7));
1113     mesh_access_set_src(access_pdu, src);
1114     mesh_access_set_dest(access_pdu, dest);
1115     mesh_access_set_ctl_ttl(access_pdu, ttl);
1116     return 0;
1117 }
1118 
1119 static uint8_t mesh_upper_transport_setup_upper_access_pdu_header(mesh_upper_transport_pdu_t * upper_pdu, uint16_t netkey_index,
1120                                                                   uint16_t appkey_index, uint8_t ttl, uint16_t src, uint16_t dest, uint8_t szmic){
1121 
1122     // get app or device key
1123     const mesh_transport_key_t *appkey;
1124     appkey = mesh_transport_key_get(appkey_index);
1125     if (appkey == NULL) {
1126         printf("[!] Upper transport, setup segmented Access PDU - appkey_index %x unknown\n", appkey_index);
1127         return 1;
1128     }
1129     uint8_t akf_aid = (appkey->akf << 6) | appkey->aid;
1130 
1131     // lookup network by netkey_index
1132     const mesh_network_key_t *network_key = mesh_network_key_list_get(netkey_index);
1133     if (!network_key) return 1;
1134     if (network_key == NULL) {
1135         printf("[!] Upper transport, setup segmented Access PDU - netkey_index %x unknown\n", appkey_index);
1136         return 1;
1137     }
1138 
1139     const uint8_t trans_mic_len = szmic ? 8 : 4;
1140 
1141     // store in transport pdu
1142     upper_pdu->ivi_nid = network_key->nid | ((mesh_get_iv_index_for_tx() & 1) << 7);
1143     upper_pdu->ctl_ttl = ttl;
1144     upper_pdu->src = src;
1145     upper_pdu->dst = dest;
1146     upper_pdu->transmic_len = trans_mic_len;
1147     upper_pdu->netkey_index = netkey_index;
1148     upper_pdu->appkey_index = appkey_index;
1149     upper_pdu->akf_aid_control = akf_aid;
1150     return 0;
1151 }
1152 
1153 static uint8_t mesh_upper_transport_setup_upper_access_pdu(mesh_upper_transport_pdu_t * upper_pdu, uint16_t netkey_index, uint16_t appkey_index, uint8_t ttl, uint16_t src, uint16_t dest,
1154                                                            uint8_t szmic, const uint8_t * access_pdu_data, uint8_t access_pdu_len){
1155     int status = mesh_upper_transport_setup_upper_access_pdu_header(upper_pdu, netkey_index, appkey_index, ttl, src,
1156                                                                     dest, szmic);
1157     if (status) return status;
1158 
1159     // store in transport pdu
1160     mesh_segmented_append_payload(access_pdu_data, access_pdu_len, &upper_pdu->segments);
1161     upper_pdu->len = access_pdu_len;
1162     return 0;
1163 }
1164 
1165 
1166 uint8_t mesh_upper_transport_setup_access_pdu_header(mesh_pdu_t * pdu, uint16_t netkey_index, uint16_t appkey_index,
1167                                                      uint8_t ttl, uint16_t src, uint16_t dest, uint8_t szmic){
1168     switch (pdu->pdu_type){
1169         case MESH_PDU_TYPE_ACCESS:
1170             return mesh_upper_transport_setup_segmented_access_pdu_header((mesh_access_pdu_t *) pdu, netkey_index, appkey_index, ttl, src, dest, szmic);
1171         case MESH_PDU_TYPE_UNSEGMENTED:
1172             return mesh_upper_transport_setup_unsegmented_access_pdu_header((mesh_unsegmented_pdu_t *) pdu, netkey_index, appkey_index, ttl, src, dest);
1173         default:
1174             btstack_assert(false);
1175             return 1;
1176     }
1177 }
1178 
1179 uint8_t mesh_upper_transport_setup_access_pdu(mesh_pdu_t * pdu, uint16_t netkey_index, uint16_t appkey_index,
1180                                               uint8_t ttl, uint16_t src, uint16_t dest, uint8_t szmic,
1181                                               const uint8_t * access_pdu_data, uint8_t access_pdu_len){
1182     switch (pdu->pdu_type){
1183         case MESH_PDU_TYPE_UPPER_SEGMENTED_ACCESS:
1184         case MESH_PDU_TYPE_UPPER_UNSEGMENTED_ACCESS:
1185             return mesh_upper_transport_setup_upper_access_pdu((mesh_upper_transport_pdu_t *) pdu, netkey_index,
1186                                                                appkey_index, ttl, src, dest, szmic, access_pdu_data,
1187                                                                access_pdu_len);
1188         default:
1189             btstack_assert(false);
1190             return 1;
1191     }
1192 }
1193 
1194 void mesh_upper_transport_register_access_message_handler(void (*callback)(mesh_transport_callback_type_t callback_type, mesh_transport_status_t status, mesh_pdu_t * pdu)) {
1195     mesh_access_message_handler = callback;
1196 }
1197 
1198 void mesh_upper_transport_register_control_message_handler(void (*callback)(mesh_transport_callback_type_t callback_type, mesh_transport_status_t status, mesh_pdu_t * pdu)){
1199     mesh_control_message_handler = callback;
1200 }
1201 
1202 void mesh_upper_transport_init(){
1203     mesh_lower_transport_set_higher_layer_handler(&mesh_upper_transport_pdu_handler);
1204 }
1205