SDK for TESAIoT Dev Kit
API reference & tutorials (ModusToolbox)
Loading...
Searching...
No Matches

Variables

const uint8_t nus_gatt_database []
 The byte-packed GATT database blob handed to wiced_bt_gatt_db_init().
const uint16_t nus_gatt_database_len
 Byte length of the blob, passed alongside it.
const uint8_t NUS_UUID_SERVICE [16]
 The 128-bit service UUID (6E400001-B5A3-F393-E0A9-E50E24DCCA9E) in on-air byte order.
const uint8_t NUS_UUID_CHAR_RX [16]
 RX characteristic UUID (6E400002-..., host → device); referenced nowhere as a symbol.
const uint8_t NUS_UUID_CHAR_TX [16]
 TX characteristic UUID (6E400003-..., device → host, notify); same standing as RX.

Detailed Description

Five symbols: the GATT database blob, its length, and the three NUS UUIDs. Compiled only with ENABLE_PAGE_BENTO_BUDDY=1 (default 0, proj_cm33_ns/Makefile:64, :305); rebuild after make getlibs — Flag gate (read first).

Declarations: nus_gatt_db.h (the shipped header declares all five as extern; the generated bento_secure_undeclared.h lists them as "no declaration found" — nus_gatt_db.h is the declaration to use). Definitions live in nus_gatt_db.c, archived in libbento_secure.a. These are data symbols, not functions: the raw grep counts were declarations, and the corrected counts below are hand-verified. Attribute handles are contiguous 0x01..0x0F (some AIROC versions reject gaps).

The GATT permissions do not require pairing.** The database grants RX GATTDB_PERM_WRITE_CMD | GATTDB_PERM_WRITE_REQ, TX GATTDB_PERM_READABLE, and the CCCD GATTDB_PERM_READABLE | GATTDB_PERM_WRITE_REQ — no GATTDB_PERM_AUTH_* bit is set on any of the three. The shipped archive says the same thing: in libbento_secure.a member bento_core_11.o, the .rodata entries for handles 0x0C, 0x0E and 0x0F carry permission bytes 0x8C, 0x82 and 0x0A, and neither AUTH_WRITABLE (0x40) nor AUTH_READABLE (0x10) appears in any of them (checked 2026-08-29). An unpaired peer can therefore write RX, read TX and enable notifications, and gets no Insufficient Authentication error.

The pairing that actually runs is Just Works.** ble_nus.c sets local_io_cap = BTM_IO_CAPABILITIES_NONE (NoInputNoOutput) and auth_req = BTM_LE_AUTH_REQ_SC_BOND — no MITM bit. The link is encrypted well enough to defeat passive sniffing but has no protection against an active MITM attacker, and no passkey is ever displayed. Advertising is open: the device accepts any central. Bonds are held in RAM only and are lost on reboot.

What limits the exposure:** none of this is compiled by default. The module is gated on ENABLE_PAGE_BENTO_BUDDY, which is 0 in both shipped templates and set hard to 0 in bsps/TARGET_KIT_PSE84_AI/bsp_features.mk:90. The three prebuilt template images carry zero nus_, ble_nus_ and wiced_bt_ symbols (checked 2026-08-30) — the radio is never brought up. Everything above applies only once you turn that flag on.

LE Secure Connections with a DisplayOnly 6-digit passkey is the intended design but is not yet implemented (NUS core send). Together with a GATT layer that does not demand pairing first, that means you must treat the link as unauthenticated* and put the authorisation check in the command layer, not in the GATT permissions.

Variant
mtb-mpy and mtb-only

Variable Documentation

◆ nus_gatt_database

const uint8_t nus_gatt_database[]
extern

The byte-packed GATT database blob handed to wiced_bt_gatt_db_init().

Contract
The byte-packed GATT database blob handed to wiced_bt_gatt_db_init(). Keep it in lock-step with the nus_attr_handle enum in nus_gatt_db.h. Its sole real use is inside ble_nus_init(). Template call sites: 0; archived call site ble_nus.c:630 (wiced_bt_gatt_db_init(nus_gatt_database, nus_gatt_database_len, NULL);; definition nus_gatt_db.c:83 — compiled into libbento_secure.a, not shipped as source).
Variant
mtb-mpy and mtb-only

◆ nus_gatt_database_len

const uint16_t nus_gatt_database_len
extern

Byte length of the blob, passed alongside it.

Contract
Byte length of the blob, passed alongside it. Template call sites: 0; archived call site ble_nus.c:629-630 (logged as (unsigned)nus_gatt_database_len then passed to wiced_bt_gatt_db_init; definition nus_gatt_db.c:165 — compiled into libbento_secure.a, not shipped as source).
Variant
mtb-mpy and mtb-only

◆ NUS_UUID_SERVICE

const uint8_t NUS_UUID_SERVICE[16]
extern

The 128-bit service UUID (6E400001-B5A3-F393-E0A9-E50E24DCCA9E) in on-air byte order.

Contract
The 128-bit service UUID in on-air byte order (6E400001-B5A3-F393-E0A9-E50E24DCCA9E, little-endian). Its one real use is the scan-response payload. Template call sites: 0; archived call site ble_nus.c:684 (srsp[0].p_data = (uint8_t *)NUS_UUID_SERVICE;; definition nus_gatt_db.c:48 — compiled into libbento_secure.a, not shipped as source).
Variant
mtb-mpy and mtb-only

◆ NUS_UUID_CHAR_RX

const uint8_t NUS_UUID_CHAR_RX[16]
extern

RX characteristic UUID (6E400002-..., host → device); referenced nowhere as a symbol.

Contract
Referenced nowhere as a symbol in any tree: the same 16 bytes are inlined raw into nus_gatt_database[] (nus_gatt_db.c:83). The extern exists for tooling and host-side tests; no firmware code path needs it. The authored example does the one legitimate job — locating the characteristic inside the blob.
Variant
mtb-mpy and mtb-only
Example (authored — no shipped call site)
static void bento_ex_nus_uuid_char_rx(void)
{
/* Scan the byte-packed GATT DB for the RX characteristic's UUID —
* the only place the bytes actually live in firmware. */
const uint8_t *found = NULL;
for (uint16_t i = 0; i + 16u <= nus_gatt_database_len; i++) {
if (memcmp(&nus_gatt_database[i], NUS_UUID_CHAR_RX, 16u) == 0) {
found = &nus_gatt_database[i]; /* decl or value entry */
break;
}
}
if (found == NULL) {
/* DB and header drifted out of lock-step — a bug worth failing
* a host-side test over. */
}
}

◆ NUS_UUID_CHAR_TX

const uint8_t NUS_UUID_CHAR_TX[16]
extern

TX characteristic UUID (6E400003-..., device → host, notify); same standing as RX.

Contract
Same standing as NUS_UUID_CHAR_RX: referenced only as raw bytes inside nus_gatt_database[]; no firmware code path consumes the symbol.
Variant
mtb-mpy and mtb-only
Example (authored — no shipped call site)
static void bento_ex_nus_uuid_char_tx(void)
{
/* A 16-byte UUID as it arrives from a discovery log / sniffer —
* little-endian on-air order on both sides, so identification is a
* straight compare: */
uint8_t uuid_le[16];
memcpy(uuid_le, NUS_UUID_CHAR_TX, sizeof(uuid_le));
bool is_tx = (memcmp(uuid_le, NUS_UUID_CHAR_TX, 16u) == 0);
(void)is_tx; /* true: notify-side characteristic */
}