|
SDK for TESAIoT Dev Kit
API reference & tutorials (ModusToolbox)
|
Variables | |
| const uint8_t | nus_gatt_database [] |
| The byte-packed GATT database blob handed to wiced_bt_gatt_db_init(). | |
| const uint16_t | nus_gatt_database_len |
| Byte length of the blob, passed alongside it. | |
| const uint8_t | NUS_UUID_SERVICE [16] |
| The 128-bit service UUID (6E400001-B5A3-F393-E0A9-E50E24DCCA9E) in on-air byte order. | |
| const uint8_t | NUS_UUID_CHAR_RX [16] |
| RX characteristic UUID (6E400002-..., host → device); referenced nowhere as a symbol. | |
| const uint8_t | NUS_UUID_CHAR_TX [16] |
| TX characteristic UUID (6E400003-..., device → host, notify); same standing as RX. | |
Five symbols: the GATT database blob, its length, and the three NUS UUIDs. Compiled only with ENABLE_PAGE_BENTO_BUDDY=1 (default 0, proj_cm33_ns/Makefile:64, :305); rebuild after make getlibs — Flag gate (read first).
Declarations: nus_gatt_db.h (the shipped header declares all five as extern; the generated bento_secure_undeclared.h lists them as "no declaration found" — nus_gatt_db.h is the declaration to use). Definitions live in nus_gatt_db.c, archived in libbento_secure.a. These are data symbols, not functions: the raw grep counts were declarations, and the corrected counts below are hand-verified. Attribute handles are contiguous 0x01..0x0F (some AIROC versions reject gaps).
The GATT permissions do not require pairing.** The database grants RX GATTDB_PERM_WRITE_CMD | GATTDB_PERM_WRITE_REQ, TX GATTDB_PERM_READABLE, and the CCCD GATTDB_PERM_READABLE | GATTDB_PERM_WRITE_REQ — no GATTDB_PERM_AUTH_* bit is set on any of the three. The shipped archive says the same thing: in libbento_secure.a member bento_core_11.o, the .rodata entries for handles 0x0C, 0x0E and 0x0F carry permission bytes 0x8C, 0x82 and 0x0A, and neither AUTH_WRITABLE (0x40) nor AUTH_READABLE (0x10) appears in any of them (checked 2026-08-29). An unpaired peer can therefore write RX, read TX and enable notifications, and gets no Insufficient Authentication error.
The pairing that actually runs is Just Works.** ble_nus.c sets local_io_cap = BTM_IO_CAPABILITIES_NONE (NoInputNoOutput) and auth_req = BTM_LE_AUTH_REQ_SC_BOND — no MITM bit. The link is encrypted well enough to defeat passive sniffing but has no protection against an active MITM attacker, and no passkey is ever displayed. Advertising is open: the device accepts any central. Bonds are held in RAM only and are lost on reboot.
What limits the exposure:** none of this is compiled by default. The module is gated on ENABLE_PAGE_BENTO_BUDDY, which is 0 in both shipped templates and set hard to 0 in bsps/TARGET_KIT_PSE84_AI/bsp_features.mk:90. The three prebuilt template images carry zero nus_, ble_nus_ and wiced_bt_ symbols (checked 2026-08-30) — the radio is never brought up. Everything above applies only once you turn that flag on.
LE Secure Connections with a DisplayOnly 6-digit passkey is the intended design but is not yet implemented (NUS core send). Together with a GATT layer that does not demand pairing first, that means you must treat the link as unauthenticated* and put the authorisation check in the command layer, not in the GATT permissions.
|
extern |
The byte-packed GATT database blob handed to wiced_bt_gatt_db_init().
|
extern |
Byte length of the blob, passed alongside it.
|
extern |
The 128-bit service UUID (6E400001-B5A3-F393-E0A9-E50E24DCCA9E) in on-air byte order.
|
extern |
RX characteristic UUID (6E400002-..., host → device); referenced nowhere as a symbol.
|
extern |
TX characteristic UUID (6E400003-..., device → host, notify); same standing as RX.