Commit Graph
37627 Commits
Author SHA1 Message Date
zhiweijian 4fd1ebb4a9 fix(ble/bluedroid): clean up LE CoC connect on CCB alloc failure 2026-07-10 10:57:10 +08:00
zhiweijian 34b59d30ae docs(ble/bluedroid): note ISO BIG HCI alloc failure not checked 2026-07-10 10:56:59 +08:00
zhiweijian 82e71c1767 fix(ble/bluedroid): fix direct-connect cleanup and adv bounds 2026-07-10 10:56:47 +08:00
zhiweijian 93ab11d564 fix(ble/bluedroid): validate BLE confirm/OOB and sec-check device 2026-07-10 10:56:38 +08:00
zhiweijian 98efe02385 fix(ble/bluedroid): validate SMP pair-fail reason and OOB device 2026-07-10 10:56:25 +08:00
zhiweijian 6c3267ee84 fix(ble/bluedroid): route ATT indication-conf timeout separately 2026-07-10 10:55:59 +08:00
zhiweijian bb00b9817d fix(ble/bluedroid): validate ATT PDU sizes 2026-07-10 10:55:39 +08:00
zhiweijian 37562af0ea fix(ble/bluedroid): re-lookup GATT TCB after enc-complete callback 2026-07-10 10:55:29 +08:00
zhiweijian 4ce692ac0c fix(ble/bluedroid): fix GATT long read and Service Changed CCC 2026-07-10 10:54:53 +08:00
zhiweijian ac35ae6f2d fix(ble/bluedroid): validate GATT client discovery handles 2026-07-10 10:54:38 +08:00
zhiweijian 27ff0cf8c7 fix(ble/bluedroid): cap Read By Type length and free failed service decl 2026-07-10 10:54:30 +08:00
zhiweijian 995c1508e8 fix(ble/bluedroid): guard GATT database hash and serialization 2026-07-10 10:54:21 +08:00
zhiweijian f86739b03d fix(ble/bluedroid): fix GATT server busy errors and sr_cmd handling 2026-07-10 10:54:07 +08:00
zhiweijian 0645ba469d fix(ble/bluedroid): fix GATT teardown and service-change flow 2026-07-10 10:53:21 +08:00
zhiweijian ac93d94958 fix(ble/bluedroid): fix GATT service lifecycle leaks 2026-07-10 10:53:01 +08:00
zhiweijian b83327f3ca fix(ble/bluedroid): add GATT resource-cleanup helpers 2026-07-10 10:52:43 +08:00
Wang Meng Yang 607f6d09ed Merge branch 'feat/support_bluedroid_le_coc_and_eatt' into 'master'
feat(ble/bluedroid): Support bluedroid LE COC and EATT features

See merge request espressif/esp-idf!50171
2026-07-10 10:14:44 +08:00
morris ab70690fff refactor(lcd): move sleep retention config into driver layer
Move LCD I80 retention descriptors and related comments out of
esp_hal_lcd and into esp_lcd so the backup policy stays with the driver
implementation.
2026-07-10 10:05:01 +08:00
Renz Christian Bagaporo 907f4a66d9 Merge branch 'fix/lp_core_gpio_wakeup' into 'master'
fix(ulp): wake pin wakes ESP32-P4 from deep sleep on P4

Closes IDF-15823

See merge request espressif/esp-idf!49855
2026-07-10 07:44:36 +08:00
yi chen 641c2f7c53 fix(protocomm): free response buffers on 2nd psa_cipher_update failure
In handle_session_command1(), if the second psa_cipher_update()
call (encrypting the device verify data to send back to the client)
fails, the error path only frees the outbuf ciphertext buffer. The
out (Sec1Payload) and out_resp (SessionResp1) structures allocated
just before it are never freed, and neither the cipher operation
(cur_session->ctx_aes) nor the imported key (key_id) are released.

The caller (sec1_req_handler(), via sec1_session_setup()) returns
immediately on a non-ESP_OK result without doing any cleanup of its
own here - sec1_session_setup_cleanup() only runs on the success
path, once resp->sec1 has actually been assigned - so nothing else
ever frees these on this path.

Add psa_cipher_abort()/psa_destroy_key() and free() for out/out_resp,
matching the cleanup already done for every other failure branch
earlier in this same function.

Fixes #18804

Signed-off-by: yi chen <94xhn1@gmail.com>
2026-07-10 06:53:44 +08:00
Euripedes Rocha 4e5f081396 Merge branch 'fix/sec-1162-1189-1190-null-checks' into 'master'
fix(esp_netif): harden NULL and OOM handling in netif APIs (SEC-1162, SEC-1189, SEC-1190)

See merge request espressif/esp-idf!50306
2026-07-09 17:01:20 +02:00
morris 03acfa1051 Merge branch 'refactor/move_regdma_entry_config_to_driver_layer_spi' into 'master'
refactor(spi): move sleep retention config into driver layer

See merge request espressif/esp-idf!50499
2026-07-09 22:48:37 +08:00
Martin Vychodil f0887bcf87 Merge branch 'contrib/github_pr_18772' into 'master'
docs(nvs): remove unused return code (GitHub PR)

Closes IDFGH-17878

See merge request espressif/esp-idf!50560
2026-07-09 21:14:32 +08:00
Shreyas Sheth 53e36b0ce4 fix(wpa_supplicant): Fix issues related to pmkid mismatch and eloop for dpp 2026-07-09 17:38:49 +05:30
Euripedes Rocha Filho 8be9903462 fix(esp_netif): reject NULL hostname in esp_netif_set_hostname_api
esp_netif_set_hostname_api() dereferenced hostname via strlen() without
checking it for NULL first, causing a NULL pointer dereference.
2026-07-09 13:58:56 +02:00
hebinglin bd61356c03 feat(esp_hw_support): add analog_wait_ctrl_retention in s2m m2s m2a to reduce retention time 2026-07-09 19:43:35 +08:00
Wang Meng Yang 84bb8fc207 Merge branch 'bugfix/avrc_ca_attr_id_check' into 'master'
fix(bt): Fix the validation of AVRCP metadata attr_id in handle_rc_attributes_rsp

See merge request espressif/esp-idf!50546
2026-07-09 19:42:43 +08:00
Wu Zheng Hui d26f5682cf Merge branch 'change/change_regdma_malloc_caps' into 'master'
change(heap): reserve DMA pool with low priority MALLOC_CAP_DEFAULT cap

See merge request espressif/esp-idf!50255
2026-07-09 19:32:56 +08:00
Hu Rui 6e8f9119f1 Merge branch 'fix/uhci_rx_fsm' into 'master'
fix(uhci): rx fsm race condition

Closes IDFGH-17845

See merge request espressif/esp-idf!50498
2026-07-09 18:52:49 +08:00
Euripedes Rocha Filho 29aa464bec fix(esp_netif): harden NULL and OOM handling in netif APIs
Add a malloc NULL check in esp_netif_br_glue_add_port and stop freeing
the existing port list when realloc fails. Validate the mac argument in
esp_netif_set_mac and config->base in esp_netif_new_api before use.
2026-07-09 12:42:49 +02:00
Jiang Jiang Jian 74005f29cf Merge branch 'fix/support_two_MAC_only_esp32s31' into 'master'
fix(esp32s31): restrict UNIVERSAL_MAC_ADDRESSES to Two

See merge request espressif/esp-idf!50389
2026-07-09 17:40:40 +08:00
Jiang Jiang Jian 12dd02396b Merge branch 'bugfix/change_pvt_timer_target_param' into 'master'
feat(pvt): change pvt timer target & limit on master

See merge request espressif/esp-idf!50472
2026-07-09 16:53:01 +08:00
morris f5bbafc050 refactor(ledc): move sleep retention config into driver layer
Move per-target LEDC regdma retention descriptors out of esp_hal_ledc
and into
esp_driver_ledc so the driver owns its backup scope and restore flow.
2026-07-09 15:42:51 +08:00
morris 6b29697fc8 Merge branch 'fix/fix_i2s_i80_color_size_check' into 'master'
fix(lcd): add color size check for i80 and boundary check for rgb

Closes SEC-1141 and SEC-1150

See merge request espressif/esp-idf!50201
2026-07-09 15:16:01 +08:00
yangfeng 156ea55ed1 fix(bt): Fix the validation of AVRCP metadata attr_id in handle_rc_attributes_rsp 2026-07-09 14:52:09 +08:00
Jiang Jiang Jian a7883b90c5 Merge branch 'fix/blacklist_flag_correction' into 'master'
Correct blacklist flag

Closes WIFIBUG-1959

See merge request espressif/esp-idf!49830
2026-07-09 14:44:42 +08:00
hebinglin 4d383a7d8a fix(esp_hw_support): fix xtal unstable when carry 154 and ble cases 2026-07-09 14:29:12 +08:00
morris 583c7414a0 Merge branch 'feat/sec_esp_drivers' into 'master'
fix(drivers): harden multiple peripheral drivers against local DoS and memory corruption

Closes SEC-1183, SEC-1181, SEC-1191, SEC-1120, SEC-1154, SEC-1138, SEC-1136, and SEC-1140

See merge request espressif/esp-idf!50203
2026-07-09 14:21:11 +08:00
zhiweijian 83f0831c53 feat(ble/bluedroid): Support bluedroid LE COC and EATT features 2026-07-09 14:03:01 +08:00
morris 13b23bcdb3 refactor(spi): move sleep retention config into driver layer
Move per-target GPSPI regdma retention descriptors out of esp_hal_gpspi
and
into esp_driver_spi so the driver owns its backup scope and restore
sequence.
2026-07-09 11:53:44 +08:00
Xu Si Yu ad931960dd fix(openthread): disable software retx security in spinel-only config 2026-07-09 11:27:57 +08:00
Hu Rui 026313df81 fix(uhci): rx fsm race condition
Closes https://github.com/espressif/esp-idf/issues/18746
2026-07-09 10:58:47 +08:00
morris 368900cedd refactor(mwdt): move sleep retention config into system layer
Move MWDT retention descriptors out of esp_hal_wdt and into esp_system
so the backup policy lives with the watchdog users, while keeping the
per-chip retention sources under the existing port/soc target
directories.
2026-07-09 10:37:59 +08:00
morris b99459931a fix(sdspi): reject oversized pre-read data before block receive
Guard start_command_read_blocks against cards that place TOKEN_BLOCK_START so early that extra_data_size exceeds the bytes expected on the current iteration. Without this check, the unsigned subtraction for will_receive underflows and propagates into memset, SPI transaction length, and memcpy counts against the fixed 516-byte block buffer.
2026-07-09 10:27:01 +08:00
morris 498f9aa96a fix(spi_slave): free DMA-private buffers when transaction queue is full
spi_slave_queue_trans calls spi_slave_setup_priv_trans to allocate
DMA buffers, then tries xQueueSend. If the queue is full the function
returns ESP_ERR_TIMEOUT without freeing those buffers, leaking up to
2 * max_transfer_sz per failed call. Call spi_slave_uninstall_priv_trans
before returning the timeout.
2026-07-09 10:27:01 +08:00
morris e86fcc8b48 fix(jpeg): release platform mutex on semaphore/pm-lock allocation failure
jpeg_acquire_codec_handle acquires s_jpeg_platform.mutex at entry
but two ESP_RETURN_ON_* macros (semaphore-create and PM-lock-create
failure) return without releasing it. Replace with ESP_GOTO_ON_*
that jumps to a cleanup label which frees partial resources, NULLs
the codec pointer, and releases the mutex.
2026-07-09 10:27:01 +08:00
morris 73031f7280 fix(i2c): release platform mutex on intr/pm_lock delete failure
ESP_RETURN_ON_ERROR inside the s_i2c_platform.mutex critical section
returns without releasing the mutex, permanently blocking all I2C
bus operations. Replace with ESP_GOTO_ON_ERROR that jumps to a
cleanup label releasing the mutex before return.
2026-07-09 10:27:01 +08:00
morris 56f56b887b fix(csi): move csi_fsm init before resource allocation to fix err-path leak
CSI_FSM_INIT is 1, but the controller struct is zero-allocated.
Any failure before the former csi_fsm assignment (near the end of
esp_cam_new_csi_ctlr) jumped to err: which called s_del_csi_ctlr.
That function bailed out immediately because csi_fsm == 0, leaking
the claimed slot, queue, bridge, DMA channel, PM lock, and backup
buffer. Move csi_fsm = CSI_FSM_INIT right after a successful claim
so the err: path properly tears down all allocated resources.
2026-07-09 10:27:01 +08:00
morris 944c74dbda fix(adc): add missing input validation for channel and ret_handle
- adc_cali_curve_fitting: validate config->chan in check_valid() to
  prevent OOB access into s_adc_cali_chan_compens compensation table
- adc_filter: make s_adc_filter_free idempotent on !UNIT_BINDED SoCs
  to prevent double-free on repeated adc_del_continuous_iir_filter
- adc_cali_line_fitting(esp32): fix config && config typo to
  config && ret_handle, preventing NULL-pointer dereference
2026-07-09 10:27:01 +08:00
Zhang Wen Xu c828d0d709 Merge branch 'feat/update_openthread_submodule_and_br_lib_20260624' into 'master'
feat(openthread): update openthread submodule

Closes IDFCI-2648

See merge request espressif/esp-idf!49974
2026-07-08 12:36:23 +00:00