- Check os_malloc failure in wpas_mbo_update_non_pref_chan
- Guard WAPI EID read with wpa_ie_len >= 1 in wpa_parse_wpa_ie
- Require full 5-byte RRM Enabled Capabilities IE before copy
- NULL-check FT mobility domain before memcmp in wpa_set_bss
- Use wpabuf_clear_free for WPS decrypted M4/M6/M8 data
- Drop redundant wpabuf_free before clear_free in eap_peap
Roaming previously used REASON_RSSI (5), which APs decode as Load
Balancing. Send Low RSSI (16) from RoamingApp and the example
without changing the public btm_query_reason enum.
Enable Tag/AP reboot recovery and image restore, plus OTS DATA_WRITE.
AP start only brings up PAwR; scan is explicit via restart_scan.
Ported onto current master ESL/OTS APIs (ble_esl_state_t,
ble_esl_key_material_t, ble_esl_address_t at the public boundary).
commit d6771a0608 made gen_soc_caps_kconfig.py import esp_pylib, but the
check-generated-soc-caps-kconfig hook never listed it in additional_dependencies.
Since the hook uses language: python (isolated env), the import failed with
ModuleNotFoundError. Add esp-pylib to match the other scripts that depend on it.
Move the PMU internal voltage calibration related efuse read LL
functions
from efuse_ll.h into pmu_ll.h, renaming them with the pmu_ll prefix.
efuse_ll.h should only contain efuse controller or system-global
functions;
other modules' private efuse bits belong to their own LL layer.
Affected chips: esp32c5, esp32c6, esp32c61, esp32h2, esp32h4, esp32p4.
Moved functions (renamed efuse_ll_get_* -> pmu_ll_get_*):
- get_active_hp_dbias, get_active_lp_dbias
- get_dbias_vol_gap
- get_lslp_dbg, get_dslp_dbg (where present)
- get_lslp_hp_dbias, get_dslp_lp_dbias (where present)
- get_dslp_dbias (esp32h2)
Fix DTM TX buffer leak in the BLE controller that could cause memory exhaustion and Interrupt WDT timeout during or after DTM TX tests.
Closes BLERP-3072 and BLERP-3097
See merge request espressif/esp-idf!52250
Keep gated-clk refcnt under s_clk_tree_spinlock only, and call
esp_crypto_common_clk_enable outside PERIPH_RCC so crypto (RCC→clk_tree)
and modem (clk_tree→RCC) cannot deadlock on periph_spinlock
Co-authored-by: Cursor <cursoragent@cursor.com>
The adjtime() wrapper stored the microsecond offset into the 32-bit
`long` timex.offset field without checking for overflow. A large delta
(e.g. 400 days) was computed in 64-bit and silently truncated when
assigned, wrapping into a small value that passed the ~35 minute range
check. adjtime() then returned 0 instead of the expected -1.
Compute the offset in int64_t and reject values that do not fit in the
timex.offset field with EINVAL. Add a regression test for a multi-day delta.
Closes https://github.com/espressif/esp-idf/issues/19051
fix(ppa): fix for SRM operation potential block if do 90/270 degree rotation
Closes IDFGH-18204 and IDFGH-17870
See merge request espressif/esp-idf!49657