diff --git a/protobufs b/protobufs index 519a0c7c9..8b68f2736 160000 --- a/protobufs +++ b/protobufs @@ -1 +1 @@ -Subproject commit 519a0c7c9c60c415ebdd948b14d1f4072f9b6562 +Subproject commit 8b68f273671ed3bca7c0bb8596f0f082232fae63 diff --git a/src/mesh/generated/meshtastic/admin.pb.h b/src/mesh/generated/meshtastic/admin.pb.h index 82644bc2a..223705b28 100644 --- a/src/mesh/generated/meshtastic/admin.pb.h +++ b/src/mesh/generated/meshtastic/admin.pb.h @@ -198,6 +198,28 @@ typedef struct _meshtastic_LockdownAuth { way to reset the session clock is a reboot, which costs a boot from the on-flash, HMAC-bound counter. */ uint32_t max_session_seconds; + /* Disable lockdown mode. Requires a valid passphrase in the same + message (the device must prove the operator owns it before + reverting at-rest encryption). On success the firmware decrypts + every stored config / channel / nodedb file back to plaintext, + removes the wrapped DEK, unlock token, monotonic-counter, and + backoff files, and reboots out of lockdown. + + This is the inverse of the provision/unlock path: it is how the + client app's "lockdown mode" toggle returns a device to normal + operation. + + NOT reversed by this operation: APPROTECT. Once the debug port + lockout has been burned (on silicon where it is effective) it is + permanent — disabling lockdown decrypts your data and removes the + access gates, but the SWD/JTAG port stays locked for the life of + the device (recoverable only via a full chip erase over a debug + probe, which destroys all data). Clients should make this + irreversibility clear at the moment lockdown is first enabled. + + When true the passphrase field is still required; boots_remaining, + valid_until_epoch, max_session_seconds, and lock_now are ignored. */ + bool disable; } meshtastic_LockdownAuth; /* Parameters for setting up Meshtastic for ameteur radio usage */ @@ -521,7 +543,7 @@ extern "C" { #define meshtastic_AdminMessage_init_default {0, {0}, {0, {0}}} #define meshtastic_AdminMessage_InputEvent_init_default {0, 0, 0, 0} #define meshtastic_AdminMessage_OTAEvent_init_default {_meshtastic_OTAMode_MIN, {0, {0}}} -#define meshtastic_LockdownAuth_init_default {{0, {0}}, 0, 0, 0, 0} +#define meshtastic_LockdownAuth_init_default {{0, {0}}, 0, 0, 0, 0, 0} #define meshtastic_HamParameters_init_default {"", 0, 0, ""} #define meshtastic_NodeRemoteHardwarePinsResponse_init_default {0, {meshtastic_NodeRemoteHardwarePin_init_default, meshtastic_NodeRemoteHardwarePin_init_default, meshtastic_NodeRemoteHardwarePin_init_default, meshtastic_NodeRemoteHardwarePin_init_default, meshtastic_NodeRemoteHardwarePin_init_default, meshtastic_NodeRemoteHardwarePin_init_default, meshtastic_NodeRemoteHardwarePin_init_default, meshtastic_NodeRemoteHardwarePin_init_default, meshtastic_NodeRemoteHardwarePin_init_default, meshtastic_NodeRemoteHardwarePin_init_default, meshtastic_NodeRemoteHardwarePin_init_default, meshtastic_NodeRemoteHardwarePin_init_default, meshtastic_NodeRemoteHardwarePin_init_default, meshtastic_NodeRemoteHardwarePin_init_default, meshtastic_NodeRemoteHardwarePin_init_default, meshtastic_NodeRemoteHardwarePin_init_default}} #define meshtastic_SharedContact_init_default {0, false, meshtastic_User_init_default, 0, 0} @@ -534,7 +556,7 @@ extern "C" { #define meshtastic_AdminMessage_init_zero {0, {0}, {0, {0}}} #define meshtastic_AdminMessage_InputEvent_init_zero {0, 0, 0, 0} #define meshtastic_AdminMessage_OTAEvent_init_zero {_meshtastic_OTAMode_MIN, {0, {0}}} -#define meshtastic_LockdownAuth_init_zero {{0, {0}}, 0, 0, 0, 0} +#define meshtastic_LockdownAuth_init_zero {{0, {0}}, 0, 0, 0, 0, 0} #define meshtastic_HamParameters_init_zero {"", 0, 0, ""} #define meshtastic_NodeRemoteHardwarePinsResponse_init_zero {0, {meshtastic_NodeRemoteHardwarePin_init_zero, meshtastic_NodeRemoteHardwarePin_init_zero, meshtastic_NodeRemoteHardwarePin_init_zero, meshtastic_NodeRemoteHardwarePin_init_zero, meshtastic_NodeRemoteHardwarePin_init_zero, meshtastic_NodeRemoteHardwarePin_init_zero, meshtastic_NodeRemoteHardwarePin_init_zero, meshtastic_NodeRemoteHardwarePin_init_zero, meshtastic_NodeRemoteHardwarePin_init_zero, meshtastic_NodeRemoteHardwarePin_init_zero, meshtastic_NodeRemoteHardwarePin_init_zero, meshtastic_NodeRemoteHardwarePin_init_zero, meshtastic_NodeRemoteHardwarePin_init_zero, meshtastic_NodeRemoteHardwarePin_init_zero, meshtastic_NodeRemoteHardwarePin_init_zero, meshtastic_NodeRemoteHardwarePin_init_zero}} #define meshtastic_SharedContact_init_zero {0, false, meshtastic_User_init_zero, 0, 0} @@ -557,6 +579,7 @@ extern "C" { #define meshtastic_LockdownAuth_valid_until_epoch_tag 3 #define meshtastic_LockdownAuth_lock_now_tag 4 #define meshtastic_LockdownAuth_max_session_seconds_tag 5 +#define meshtastic_LockdownAuth_disable_tag 6 #define meshtastic_HamParameters_call_sign_tag 1 #define meshtastic_HamParameters_tx_power_tag 2 #define meshtastic_HamParameters_frequency_tag 3 @@ -754,7 +777,8 @@ X(a, STATIC, SINGULAR, BYTES, passphrase, 1) \ X(a, STATIC, SINGULAR, UINT32, boots_remaining, 2) \ X(a, STATIC, SINGULAR, UINT32, valid_until_epoch, 3) \ X(a, STATIC, SINGULAR, BOOL, lock_now, 4) \ -X(a, STATIC, SINGULAR, UINT32, max_session_seconds, 5) +X(a, STATIC, SINGULAR, UINT32, max_session_seconds, 5) \ +X(a, STATIC, SINGULAR, BOOL, disable, 6) #define meshtastic_LockdownAuth_CALLBACK NULL #define meshtastic_LockdownAuth_DEFAULT NULL @@ -869,7 +893,7 @@ extern const pb_msgdesc_t meshtastic_SHTXX_config_msg; #define meshtastic_AdminMessage_size 511 #define meshtastic_HamParameters_size 31 #define meshtastic_KeyVerificationAdmin_size 25 -#define meshtastic_LockdownAuth_size 54 +#define meshtastic_LockdownAuth_size 56 #define meshtastic_NodeRemoteHardwarePinsResponse_size 496 #define meshtastic_SCD30_config_size 27 #define meshtastic_SCD4X_config_size 29 diff --git a/src/mesh/generated/meshtastic/config.pb.h b/src/mesh/generated/meshtastic/config.pb.h index d30441167..62d1ea8da 100644 --- a/src/mesh/generated/meshtastic/config.pb.h +++ b/src/mesh/generated/meshtastic/config.pb.h @@ -356,7 +356,21 @@ typedef enum _meshtastic_Config_LoRaConfig_ModemPreset { /* Narrow Slow Moderate range preset optimized for EU 868MHz band with 62.5kHz bandwidth. Comparable link budget and data rate to LONG_FAST. */ - meshtastic_Config_LoRaConfig_ModemPreset_NARROW_SLOW = 13 + meshtastic_Config_LoRaConfig_ModemPreset_NARROW_SLOW = 13, + /* Tiny Fast + Preset optimized for compliance with Amateur Radio restrictions with 20kHz bandwidth. + Many regions limit data transmission bandwidth in lower amateur bands (2 Meter). + Note: TCXO with tight tolerances (±5 ppm or better) is *absolutely required* at these narrow bandwidths. + Only compatible with SX127x and SX126x chipsets. + Comparable link budget and data rate to LONG_FAST. */ + meshtastic_Config_LoRaConfig_ModemPreset_TINY_FAST = 14, + /* Tiny Slow + Preset optimized for compliance with Amateur Radio restrictions with 20kHz bandwidth. + Many regions limit data transmission bandwidth in lower amateur bands (2 Meter). + Note: TCXO with tight tolerances (±5 ppm or better) is *absolutely required* at these narrow bandwidths. + Only compatible with SX127x and SX126x chipsets. + Comparable link budget and data rate to LONG_MODERATE. */ + meshtastic_Config_LoRaConfig_ModemPreset_TINY_SLOW = 15 } meshtastic_Config_LoRaConfig_ModemPreset; typedef enum _meshtastic_Config_LoRaConfig_FEM_LNA_Mode { @@ -749,8 +763,8 @@ extern "C" { #define _meshtastic_Config_LoRaConfig_RegionCode_ARRAYSIZE ((meshtastic_Config_LoRaConfig_RegionCode)(meshtastic_Config_LoRaConfig_RegionCode_ITU3_70CM+1)) #define _meshtastic_Config_LoRaConfig_ModemPreset_MIN meshtastic_Config_LoRaConfig_ModemPreset_LONG_FAST -#define _meshtastic_Config_LoRaConfig_ModemPreset_MAX meshtastic_Config_LoRaConfig_ModemPreset_NARROW_SLOW -#define _meshtastic_Config_LoRaConfig_ModemPreset_ARRAYSIZE ((meshtastic_Config_LoRaConfig_ModemPreset)(meshtastic_Config_LoRaConfig_ModemPreset_NARROW_SLOW+1)) +#define _meshtastic_Config_LoRaConfig_ModemPreset_MAX meshtastic_Config_LoRaConfig_ModemPreset_TINY_SLOW +#define _meshtastic_Config_LoRaConfig_ModemPreset_ARRAYSIZE ((meshtastic_Config_LoRaConfig_ModemPreset)(meshtastic_Config_LoRaConfig_ModemPreset_TINY_SLOW+1)) #define _meshtastic_Config_LoRaConfig_FEM_LNA_Mode_MIN meshtastic_Config_LoRaConfig_FEM_LNA_Mode_DISABLED #define _meshtastic_Config_LoRaConfig_FEM_LNA_Mode_MAX meshtastic_Config_LoRaConfig_FEM_LNA_Mode_NOT_PRESENT diff --git a/src/mesh/generated/meshtastic/mesh.pb.h b/src/mesh/generated/meshtastic/mesh.pb.h index 192aeeffe..f9c6efb59 100644 --- a/src/mesh/generated/meshtastic/mesh.pb.h +++ b/src/mesh/generated/meshtastic/mesh.pb.h @@ -658,7 +658,14 @@ typedef enum _meshtastic_LockdownStatus_State { token's TTL. */ meshtastic_LockdownStatus_State_UNLOCKED = 3, /* Passphrase rejected. backoff_seconds is non-zero when rate-limited. */ - meshtastic_LockdownStatus_State_UNLOCK_FAILED = 4 + meshtastic_LockdownStatus_State_UNLOCK_FAILED = 4, + /* Lockdown is supported by this firmware but not currently active + (no passphrase has been provisioned, or it was disabled via + AdminMessage.lockdown_auth.disable). The device is operating in + normal, non-encrypted mode. Clients render the lockdown-mode + toggle as OFF on receiving this. Distinct from NEEDS_PROVISION, + which is only used during an in-progress enable flow. */ + meshtastic_LockdownStatus_State_DISABLED = 5 } meshtastic_LockdownStatus_State; /* Struct definitions */ @@ -1533,8 +1540,8 @@ extern "C" { #define _meshtastic_LogRecord_Level_ARRAYSIZE ((meshtastic_LogRecord_Level)(meshtastic_LogRecord_Level_CRITICAL+1)) #define _meshtastic_LockdownStatus_State_MIN meshtastic_LockdownStatus_State_STATE_UNSPECIFIED -#define _meshtastic_LockdownStatus_State_MAX meshtastic_LockdownStatus_State_UNLOCK_FAILED -#define _meshtastic_LockdownStatus_State_ARRAYSIZE ((meshtastic_LockdownStatus_State)(meshtastic_LockdownStatus_State_UNLOCK_FAILED+1)) +#define _meshtastic_LockdownStatus_State_MAX meshtastic_LockdownStatus_State_DISABLED +#define _meshtastic_LockdownStatus_State_ARRAYSIZE ((meshtastic_LockdownStatus_State)(meshtastic_LockdownStatus_State_DISABLED+1)) #define meshtastic_Position_location_source_ENUMTYPE meshtastic_Position_LocSource #define meshtastic_Position_altitude_source_ENUMTYPE meshtastic_Position_AltSource