From ce21e3fa9945ce03f54583981e4d87fede424f94 Mon Sep 17 00:00:00 2001 From: Alexey Lapshin Date: Fri, 6 Feb 2026 13:35:40 +0700 Subject: [PATCH 1/4] fix(ci): check all components using static analyzer --- .gitlab/ci/pre_check.yml | 11 ----------- .gitlab/ci/static-code-analysis.yml | 11 +++++++++++ 2 files changed, 11 insertions(+), 11 deletions(-) diff --git a/.gitlab/ci/pre_check.yml b/.gitlab/ci/pre_check.yml index 49c3920ebda..574b4024c80 100644 --- a/.gitlab/ci/pre_check.yml +++ b/.gitlab/ci/pre_check.yml @@ -191,17 +191,6 @@ baseline_manifest_sha: expire_in: 1 week when: always -gcc_static_analyzer: - extends: - - .pre_check_template - - .rules:build - variables: - CI_CCACHE_DISABLE: 1 - ANALYZING_APP: "examples/get-started/hello_world" - script: - - echo "CONFIG_COMPILER_STATIC_ANALYZER=y" >> ${ANALYZING_APP}/sdkconfig.defaults - - idf-build-apps build -p ${ANALYZING_APP} - retry_failed_jobs: extends: - .pre_check_template diff --git a/.gitlab/ci/static-code-analysis.yml b/.gitlab/ci/static-code-analysis.yml index 15eabc15985..7ea40235313 100644 --- a/.gitlab/ci/static-code-analysis.yml +++ b/.gitlab/ci/static-code-analysis.yml @@ -16,6 +16,17 @@ clang_tidy_check: --limit-file tools/ci/static-analysis-rules.yml --xtensa-include-dir +gcc_static_analyzer: + extends: + - .pre_check_template + - .rules:patterns:clang_tidy + variables: + CI_CCACHE_DISABLE: 1 + ANALYZING_APP: "examples/get-started/hello_world" + script: + - echo "CONFIG_COMPILER_STATIC_ANALYZER=y" >> ${ANALYZING_APP}/sdkconfig.defaults + - sed -i 's/.*MINIMAL_BUILD.*//g' ${ANALYZING_APP}/CMakeLists.txt + - idf-build-apps build -p ${ANALYZING_APP} # ## build stage ## Sonarqube related jobs put here for this reason: From 1b503b8eb5ff4d760b99af8a8e6f259aae5d0399 Mon Sep 17 00:00:00 2001 From: Alexey Lapshin Date: Fri, 6 Feb 2026 14:14:52 +0700 Subject: [PATCH 2/4] fix(esp_driver_spi): fix static analyzer checks --- components/esp_driver_spi/src/gpspi/spi_master.c | 2 ++ 1 file changed, 2 insertions(+) diff --git a/components/esp_driver_spi/src/gpspi/spi_master.c b/components/esp_driver_spi/src/gpspi/spi_master.c index 9ddef9900b2..1ccf81ec731 100644 --- a/components/esp_driver_spi/src/gpspi/spi_master.c +++ b/components/esp_driver_spi/src/gpspi/spi_master.c @@ -803,6 +803,7 @@ static void SPI_MASTER_ISR_ATTR spi_format_hal_trans_struct(spi_device_t *dev, s // Setup the transaction-specified registers and linked-list used by the DMA (or FIFO if DMA is not used) static void SPI_MASTER_ISR_ATTR spi_new_trans(spi_device_t *dev, spi_trans_priv_t *trans_buf) { + assert(dev != NULL); spi_host_t *host = dev->host; spi_transaction_t *trans = trans_buf->trans; spi_hal_context_t *hal = &(dev->host->hal); @@ -898,6 +899,7 @@ static void SPI_MASTER_ISR_ATTR s_sct_load_dma_link(spi_device_t *dev, spi_dma_d static void SPI_MASTER_ISR_ATTR spi_new_sct_trans(spi_device_t *dev, spi_sct_trans_priv_t *cur_sct_trans) { + assert(dev != NULL); dev->host->cur_cs = dev->id; //Reconfigure according to device settings, the function only has effect when the dev_id is changed. From 72a3697c6ccfa6eb1b65e892dd6864927a27d5e3 Mon Sep 17 00:00:00 2001 From: Alexey Lapshin Date: Fri, 6 Feb 2026 14:16:44 +0700 Subject: [PATCH 3/4] fix(protocomm): fix error handling for esp_srp_exchange_proofs() --- components/protocomm/src/crypto/srp6a/esp_srp.c | 10 +++++----- 1 file changed, 5 insertions(+), 5 deletions(-) diff --git a/components/protocomm/src/crypto/srp6a/esp_srp.c b/components/protocomm/src/crypto/srp6a/esp_srp.c index 1ae4aa80022..c4bbe4cc8c5 100644 --- a/components/protocomm/src/crypto/srp6a/esp_srp.c +++ b/components/protocomm/src/crypto/srp6a/esp_srp.c @@ -1,5 +1,5 @@ /* - * SPDX-FileCopyrightText: 2022-2025 Espressif Systems (Shanghai) CO LTD + * SPDX-FileCopyrightText: 2022-2026 Espressif Systems (Shanghai) CO LTD * * SPDX-License-Identifier: Apache-2.0 */ @@ -774,10 +774,10 @@ esp_err_t esp_srp_exchange_proofs(esp_srp_handle_t *hd, char *username, uint16_t "Hash operation failed: status=%d, hash_len=%d", status, hash_len); int pad_len = hd->len_n - hd->len_g; s = calloc(pad_len, sizeof(char)); - ESP_RETURN_ON_FALSE(s, ESP_ERR_NO_MEM, TAG, "Failed to allocate memory"); + ESP_GOTO_ON_FALSE(s, ESP_ERR_NO_MEM, error, TAG, "Failed to allocate memory"); status = psa_hash_setup(&hash_op, PSA_ALG_SHA_512); - ESP_RETURN_ON_FALSE(status == PSA_SUCCESS, ESP_FAIL, TAG, "Failed to setup hash operation: %d", status); + ESP_GOTO_ON_FALSE(status == PSA_SUCCESS, ESP_FAIL, error, TAG, "Failed to setup hash operation: %d", status); psa_hash_update(&hash_op, (unsigned char *)s, pad_len); psa_hash_update(&hash_op, (unsigned char *)hd->bytes_g, hd->len_g); @@ -790,7 +790,7 @@ esp_err_t esp_srp_exchange_proofs(esp_srp_handle_t *hd, char *username, uint16_t unsigned char digest[SHA512_HASH_SZ]; status = psa_hash_setup(&hash_op, PSA_ALG_SHA_512); - ESP_RETURN_ON_FALSE(status == PSA_SUCCESS, ESP_FAIL, TAG, "Failed to setup hash operation: %d", status); + ESP_GOTO_ON_FALSE(status == PSA_SUCCESS, ESP_FAIL, error, TAG, "Failed to setup hash operation: %d", status); psa_hash_update(&hash_op, hash_n_xor_g, SHA512_HASH_SZ); psa_hash_update(&hash_op, hash_I, SHA512_HASH_SZ); @@ -808,7 +808,7 @@ esp_err_t esp_srp_exchange_proofs(esp_srp_handle_t *hd, char *username, uint16_t /* M is now validated, let's proceed to H(AMK) */ status = psa_hash_setup(&hash_op, PSA_ALG_SHA_512); - ESP_RETURN_ON_FALSE(status == PSA_SUCCESS, ESP_FAIL, TAG, "Failed to setup hash operation: %d", status); + ESP_GOTO_ON_FALSE(status == PSA_SUCCESS, ESP_FAIL, error, TAG, "Failed to setup hash operation: %d", status); psa_hash_update(&hash_op, (unsigned char *)hd->bytes_A, hd->len_A); psa_hash_update(&hash_op, digest, SHA512_HASH_SZ); From 040bbb7de201a7abb92a4806909b46323bffadd8 Mon Sep 17 00:00:00 2001 From: Alexey Lapshin Date: Fri, 6 Feb 2026 18:29:41 +0700 Subject: [PATCH 4/4] fix(esp_driver_i3c): fix NULL pointer dereference --- components/esp_driver_i3c/i3c_master.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/components/esp_driver_i3c/i3c_master.c b/components/esp_driver_i3c/i3c_master.c index f1f1e0bf5a7..45d260db564 100644 --- a/components/esp_driver_i3c/i3c_master.c +++ b/components/esp_driver_i3c/i3c_master.c @@ -173,7 +173,7 @@ static bool handle_transfer_complete_int(i3c_master_bus_handle_t i3c_master) atomic_store(&i3c_master->fsm, I3C_FSM_ENABLE); } - if (trans_desc->i2c_trans) { + if (trans_desc && trans_desc->i2c_trans) { i3c_master_i2c_device_handle_t i2c_dev = (i3c_master_i2c_device_handle_t)i3c_master->cur_trans->dev_handle; if (i3c_master->cur_trans->read_buffer != NULL) { size_t dma_rcv_size = gdma_link_count_buffer_size_till_eof(i3c_master->rx_dma_link, 0);