Initialize and deinitialize BLE Log from the Bluedroid host lifecycle when the local
controller is disabled. Guard controller mbuf handling with BLE_LOG_LL_ENABLED so host-
only builds do not depend on controller headers.
Update NimBLE to b6e2f93db269ad2bba8715953cb56f93bae4fc2f to provide the corresponding
host-only initialization. Combine the host initialization fix and the final NimBLE
revision into one prerequisite commit.
Cancel in-flight SDP searches before freeing discovery databases in BTA AV
and HID Host. Otherwise a late SDP response can be parsed into a freed
buffer after esp_a2d_*_deinit / HID host disable, the same class of
corruption as JV/SPP deinit.
Co-authored-by: Cursor <cursoragent@cursor.com>
bta_jv_disable() reset the control block and let BTA_JvFree() release
p_sdp_db/p_sdp_raw_data while an SDP service search could still be in
progress. Late SDP responses were then parsed into the freed discovery
database and corrupted the heap, so the crash surfaced much later in an
unrelated malloc(), inside TLSF remove_free_block().
Cancel the search first. SDP_CancelServiceSearch() moves the connection
control block to SDP_DISC_WAIT_CANCEL, and sdp_disc_server_rsp() matches
none of its PDU cases in that state, so a late response is rejected
instead of being written into the database.
Reachable from both esp_spp_deinit() and esp_bt_l2cap_deinit(), e.g. when
an application deinitializes SPP before ESP_SPP_DISCOVERY_COMP_EVT
arrives.
When the bond list is full, drop the oldest disconnected device instead
of the oldest NVS entry, and allow a per-bond except flag so selected
devices are never auto-removed.
(cherry picked from commit bf86892eef)
Co-authored-by: zhanghaipeng <zhanghaipeng@espressif.com>
- Add sdp_seq to avoid p_ccb being free during sdp
- Changed some BTA_Pba functions to return non-void value
- Improve error catching and report
- Refactor bta_pba_client_response to avoid UAF problem
- Rearrange btc_pba_client init flag to avoid some disturbing bug
Add smp_repairing_is_allowed() behind BT_BLE_SMP_HARDENED_REPAIRING so a
peer cannot replace an existing bond with one that has less MITM
protection, no Secure Connections, or a shorter key. Compare a preceding
Security Request against the pairing command AuthReq, not the
association-model result, and always allow first pairing.
A refusal keeps the stored bond. Pairing-failure erase is split by link
role: default is erase as Central and keep as Peripheral.
Closes BLERP (NDSS 2026) V3, V4 and V6.
(cherry picked from commit 88ea45be73)
Co-authored-by: zhiweijian <zhiweijian@espressif.com>
Keep the existing bond until the new pairing is encrypted, and on encryption
failure drop the link instead of clearing keys. Recovering from a peer that
really deleted the bond is opt-in through BT_BLE_SMP_UNBOND_ON_KEY_MISSING.
Closes BLERP (NDSS 2026) V5, and stops an unauthenticated Pairing Request
from dropping the stored keys (V2 exploitation).
(cherry picked from commit f864615d7d)
Co-authored-by: zhiweijian <zhiweijian@espressif.com>
Do not reject osi_thread_post_event() when only POSTING is set.
QUEUED already prevents double-queueing; rejecting POSTING caused
HCI downstream lost wakeup. Add generic osi_event and hci downstream
diagnostics for post failures.