Commit Graph
51409 Commits
Author SHA1 Message Date
Ondrej Kosta 9e3ec66892 feat(ci): support downloading extra app artifacts in pytest
Add app_extra S3 artifact type, extend idf-ci download plumbing, and
expose a download_app_extra pytest fixture for managed_components deps.
2026-07-08 08:01:45 +02:00
Euripedes Rocha 97abdf4e3b Merge branch 'contrib/github_pr_18642_v6.0' into 'release/v6.0'
fix(eth): use stored base_increment when computing PTP addend (GitHub PR) (v6.0)

See merge request espressif/esp-idf!49104
2026-07-08 07:59:47 +02:00
Wang Meng Yang b1f7a5b8b8 Merge branch 'bugfix/sdp_null_access_v6.0' into 'release/v6.0'
fix(bt/bluedroid): fixed SDP deinit race with pending callbacks (v6.0)

See merge request espressif/esp-idf!48895
2026-07-08 12:42:23 +08:00
Zhang Wen Xu 0890c0fde4 Merge branch 'fix/reverse-extended-address-byte-order-in-esp-radio-spiel_v6.0' into 'release/v6.0'
fix(openthread): add APIs to clear a single src match short and extended entry in esp radio spinel (v6.0)

See merge request espressif/esp-idf!50453
2026-07-08 02:35:10 +00:00
Tomáš Rohlínek d4fdaae0dd fix(storage/fatfs): fix FAT32 mount integer overflow (CVE-2026-6682)
The initial CVE-2026-6682 fix hardened the exFAT mount path, but the CVE
as reported by runZero is a FAT32 defect in mount_volume() and is
reachable in the default configuration (exFAT and 64-bit LBA disabled).
This corrects the fix.

Root cause: `fasize *= fs->n_fats` is a DWORD multiply with no overflow
guard. A crafted BPB_FATSz32 such as 0x80000001 with NumFATs=2 wraps
`fasize` to 0x00000002. The wrapped (too-small) FAT size places
`fs->database` inside the FAT region, so a forged directory entry yields
an attacker-controlled `finfo.fsize`; a caller using it as a read length
overflows its buffer with attacker-controlled bytes (CVSS 7.6).

Fix: reject per-FAT and reserved+FAT+root system-area sizes that overflow
DWORD before they are used to derive the data-area base. The exFAT
cluster-heap/bitmap 64-bit promotions are retained as defense-in-depth
and relabeled (they are not CVE-2026-6682). SBOM reason updated.
2026-07-07 16:36:32 +02:00
Rahul Tank 38f4edb16e fix(nimble): Fixes for AI reported issues 2026-07-07 16:18:32 +05:30
Ashish Sharma 92cefa205a feat(esp_http_client): detect oversized headers in tx buffer while sending request 2026-07-07 18:18:26 +08:00
Xu Si Yu c61e7ab345 feat(openthread): add APIs to clear a single src match short and extended entry in esp radio spinel 2026-07-07 17:39:42 +08:00
muhaidong 0ed8d91726 fix(wifi): update auth mode threshold doc 2026-07-07 16:00:39 +08:00
muhaidong eda0d8dde1 fix(wifi): update wifi scan threshold doc 2026-07-07 16:00:00 +08:00
muhaidong dbc974cbd8 fix(wifi): fix some wifi bugs 260706 v6.0
1. support weak func for wifi lmac assert
2. post disconnect event after disassociation tx callback
3. update auth mode threshold doc3. update auth mode threshold doc3.
   update auth mode threshold doc
2026-07-07 15:59:18 +08:00
morris db3825c799 Merge branch 'fix/spi_buslock_multi_dev_acq_release_issue_v6.0' into 'release/v6.0'
fix(esp_hw_support): fixed spi buslock multi dev acq/release logic issue (v6.0)

See merge request espressif/esp-idf!49168
2026-07-07 14:53:55 +08:00
morris 2c62bd65b0 Merge branch 'backport/spi_slave_independent_tx_rx_length_v6.0' into 'release/v6.0'
feat(driver_spi): slave driver support config different tx/rx length (v6.0)

See merge request espressif/esp-idf!49964
2026-07-07 14:50:44 +08:00
Scramble ToolsandOndrej Kosta e0becb9e43 fix(esp_eth): use stored base_increment when computing PTP addend
The addend in `emac_hal_ptp_start()` was derived from the floating-point
`config->ptp_req_accuracy_ns` instead of the integer `base_increment`
register that actually drives the sub-second update. The cast to
`uint8_t` loses the fractional part, so the un-corrected addend leaves
the PTP clock running off-rate.

Example: with a 40 MHz XTAL and the default `req_accuracy_ns = 40`,
`base_increment` rounds 85.899 up to 86, leaving the clock +1170 ppm
fast — well outside the IEEE 802.1AS neighborRateRatio limit (~±200
ppm), so strict-1AS bridges refuse asCapable.

Compute the addend from the stored `base_increment` for both rollover
modes: `addend = 2^32 * clk_period_ns / increment_ns`.

Measured on ESP32-P4: neighborRateRatio drops from +1147.5 ppm to
+4.2 ppm, and asCapable is granted.

Co-authored-by: Ondrej Kosta <panzer412@gmail.com>
2026-07-07 08:37:04 +02:00
muhaidong 7afed49b3f fix(wifi): support weak func for wifi lmac assert 2026-07-07 14:07:47 +08:00
muhaidong dd8653bbeb fix(coex): remove unsupported external coex soc caps 2026-07-07 14:07:47 +08:00
morris b3b9ebb516 Merge branch 'bugfix/i2c_set_but_not_used_variable_v6.0' into 'release/v6.0'
fix(i2c): remove unused but set variables (v6.0)

See merge request espressif/esp-idf!50371
2026-07-07 13:13:07 +08:00
Jiang Jiang Jian 0cb8f5ef2d Merge branch 'fix/add_owe_check_pmf_disable_v6.0' into 'release/v6.0'
Add Mode/threshold checks in esp_wifi_disable_pmf_config()(v6.0)

See merge request espressif/esp-idf!48951
2026-07-07 10:46:43 +08:00
morris f4af8b9335 Merge branch 'feature/dma2d_ppa_sleep_retention_support_v6.0' into 'release/v6.0'
feat(ppa): add sleep retention support for DMA2D and PPA (v6.0)

See merge request espressif/esp-idf!50350
2026-07-07 10:35:38 +08:00
Marius Vikhammer 1195a15240 Merge branch 'fix/vfs_fatfs_test_stale_partition_v6.0' into 'release/v6.0'
test(vfs): reformat WL FATFS in setup to avoid stale-partition flakes (v6.0)

See merge request espressif/esp-idf!50401
2026-07-07 09:49:29 +08:00
Tomáš Rohlínek 5b3090c3e2 fix(storage/fatfs): record non-applicable runZero 2026 CVEs in SBOM
Document the three runZero "Seven FatFs bugs" CVEs that require no source change
in this component, so vulnerability scanners have their disposition:

  - CVE-2026-6684: GPT partition-scan loop DoS. Already fixed upstream in R0.16,
    where test_gpt_header() caps the partition-entry count at 128.
  - CVE-2026-6686: read of uninitialized clusters after f_lseek() past EOF.
    Longstanding, behavioral; not a memory-safety defect and zero-filling every
    extended cluster is prohibitively costly on flash.
  - CVE-2026-6688: long-filename overflow in downstream callers. Not exposed in
    ESP-IDF; vfs_fat.c uses bounded copies and fname is bounded by FF_MAX_LFN.

Reference: https://www.runzero.com/blog/fatfs-bugs/
2026-07-06 16:19:09 +02:00
wuzhenghui 97d115919d feat(soc): update PMU & PAU register description 2026-07-06 21:23:16 +08:00
Tomáš Rohlínek da6afc4eee fix(storage/fatfs): clamp exFAT volume-label length in f_getlabel() (CVE-2026-6687)
f_getlabel() extracts the exFAT volume label with a loop bounded by the on-disk
byte dj.dir[XDIR_NumLabel] (0-255):

    for (si = di = hs = 0; si < dj.dir[XDIR_NumLabel]; si++)
        wc = ld_16(dj.dir + XDIR_Label + si * 2);

The exFAT label field holds at most 11 UTF-16 units (22 bytes). A crafted
directory entry with a larger count both reads past the 22-byte label field and,
through put_utf(... &label[di], 4), writes past the end of the caller-provided
label buffer (the canonical API examples use small fixed stack buffers) -> stack
buffer overflow.

Clamp the character count to the exFAT maximum of 11 before the extraction loop.
Record the CVE in the component SBOM.

Note: f_getlabel() takes no destination-buffer size, so under UTF-8 output
(FF_LFN_UNICODE == 2) 11 units can still expand to up to 34 bytes; the clamp
downgrades this from attacker-unbounded to spec-bounded. ESP-IDF's VFS layer
does not call f_getlabel(); direct callers on untrusted media should size their
buffer accordingly. A complete fix requires an upstream size-aware API change.

Reference: https://www.runzero.com/blog/fatfs-bugs/
2026-07-06 14:49:08 +02:00
Tomáš Rohlínek 5019c06dd4 fix(storage/fatfs): guard dirty-cache refill against unsigned LBA wrap (CVE-2026-6685)
After a direct multi-sector disk_read()/disk_write(), FatFs decides whether the
cached sector overlaps the direct-I/O range with:

    fp->sect - sect < cc          (and the FF_FS_TINY variant fs->winsect - sect < cc)

`sect`, `fp->sect` and `fs->winsect` are unsigned LBA_t. On 32-bit LBA_t builds,
if the cached sector is below `sect`, the subtraction wraps to a huge value that
can still compare `< cc`, so the code computes a bogus large offset:

  - in f_write() it mis-copies from the direct write buffer (data corruption);
  - in f_read() it is worse: memcpy(rbuff + (wrapped_offset * SS), ...) is an
    out-of-bounds WRITE into the caller-supplied read buffer.

Add an explicit lower-bound check (fp->sect >= sect, resp. fs->winsect >= sect)
before the range test on both the read and write paths and both the FF_FS_TINY
and normal variants, so the condition is exactly "cached sector lies within
[sect, sect + cc)". Record the CVE in the component SBOM.

Reference: https://www.runzero.com/blog/fatfs-bugs/
2026-07-06 14:49:08 +02:00
Tomáš Rohlínek a407d4f82b fix(storage/fatfs): reject empty exFAT cluster heap (CVE-2026-6683)
CVE-2026-6683 is an exFAT divide-by-zero: with NumClusters == 0 the filesystem
object has fs->n_fatent == 2, and the exFAT "percent in use" update in sync_fs()
computes ... * 100 / (fs->n_fatent - 2) -> division by zero.

That vulnerable exFAT PercInUse sync path was introduced in FatFs R0.16 and is
NOT present in this R0.15 release, so the divide-by-zero itself is not reachable
here. As defense-in-depth (and to keep parity with newer releases) reject an
empty exFAT cluster heap at mount time, which is a malformed volume regardless.

Record the CVE disposition in the component SBOM.

Reference: https://www.runzero.com/blog/fatfs-bugs/
2026-07-06 14:49:08 +02:00
Tomáš Rohlínek 9466a3d529 fix(storage/fatfs): fix exFAT mount integer overflow (CVE-2026-6682)
The exFAT mount path validates that the media is large enough to hold the
declared cluster heap with:

    if (maxlba < (QWORD)fs->database + ncl * fs->csize) ...

`ncl` (DWORD, up to MAX_EXFAT) and `fs->csize` (WORD) are both promoted to
`unsigned int`, so `ncl * fs->csize` is evaluated in 32-bit arithmetic and can
wrap before the QWORD promotion of the sum. A crafted image with a large
NumClusters/SecPerClus can therefore make an undersized volume pass the "size
is large enough" check; subsequent cluster->sector math then addresses media
outside the actual device.

Promote the multiply to 64-bit ((QWORD)ncl * fs->csize). Apply the same
promotion to the bitmap-base computation ((LBA_t)fs->csize * (bcl - 2)), which
has the identical overflow shape. Record the CVE in the component SBOM.

Reference: https://www.runzero.com/blog/fatfs-bugs/
2026-07-06 14:49:08 +02:00
morris 8e9d45c367 Merge branch 'fix/fix_async_color_convert_csc_v6.0' into 'release/v6.0'
fix(dma2d): fix async color convert csc check (v6.0)

See merge request espressif/esp-idf!50239
2026-07-06 19:02:39 +08:00
Luo Xu 85d760323f fix(ble_mesh): re-check scan dev-found cb before scan-rsp invocation
(cherry picked from commit 9a3a767824)

Co-authored-by: luoxu <luoxu@espressif.com>
2026-07-06 17:44:30 +08:00
Luo Xu db95f9081d fix(ble_mesh): comment out logs containing sensitive keys
(cherry picked from commit 781d6b2314)

Co-authored-by: luoxu <luoxu@espressif.com>
2026-07-06 17:44:30 +08:00
Luo Xu 0fd8253754 fix(ble_mesh): validate PB-ADV start segment length
(cherry picked from commit 912ec8dc62)

Co-authored-by: luoxu <luoxu@espressif.com>
2026-07-06 17:44:29 +08:00
Luo Xu 4c79d1f6db fix(ble_mesh): Reset reassembly buffer at start of each transaction
The reassembly buffer must be reset to its origin at the beginning of every
transaction. prov_msg_recv() pulls the PDU type byte (advancing buf->data by
one) and nothing restores it between transactions. Without this reset,
buf->data drifts forward by one byte per received PDU, causing the segment-0
memcpy to write past the end of the statically allocated rx buffer
(PROV_RX_BUF_SIZE), and the XACT_SEG_DATA() offsets used for continuation
segments to be skewed by the accumulated drift.


(cherry picked from commit 2c4acaa2aa)

Co-authored-by: luoxu <luoxu@espressif.com>
2026-07-06 17:44:28 +08:00
Luo Xu fd96eeb6a2 fix(ble_mesh): fix DFD client message parsing and encoding bugs
Fix multiple wire-format and robustness issues in the DFD client
(dfd_cli.c):

- handle_capabilities: read oob_retrieval_supported as u8 instead of
  le32. The server encodes a single byte; le32 over-consumed 3 bytes
  of the URL scheme list and could over-read the buffer.
- handle_upload_status: extract upload_progress from bits 0-6 (& 0x7F)
  and upload_type from bit 7 (>> 7), matching the server encoding
  (progress | BIT(7)). The previous >>1 / &0x01 returned wrong values,
  mis-classified in-band vs OOB, and falsely rejected valid OOB
  messages with high progress.
- handle_dfd_status: correct the transfer-mode byte layout to
  trans_mode bits 0-1, update_policy bit 2, RFU bits 3-7 (previously
  read bits 6-7 / 5), and fix the RFU mask to 0xF8. Now matches the
  struct bitfield definition and the DFD server.
- handle_dfd_status: report status+phase and return early when
  buf->len == 0 (IDLE phase) instead of pulling 10 absent bytes.
- bt_mesh_dfd_cli_distribution_start: encode trans_mode/update_policy
  into bits 0-2 so the server decodes them correctly.
- handle_receiver_list: validate buf->len >= entries_cnt * 5 before
  the loop, and handle entries_cnt == 0 without relying on calloc(0).
- handle_receiver_status: pass the status value (not the whole union)
  to the %d log format, fixing undefined behavior.
- dfd_client_recv_status: drop the dead BLE_MESH_DFD_OP_CAPABILITIES_GET
  case (a client-send opcode) from the receive switch.
- bt_mesh_dfd_cli_receivers_add: widen msg_length to uint32_t to avoid
  uint16_t overflow that bypassed the PDU size guard; add a NULL check
  for the receivers array.
- bt_mesh_dfd_cli_distribution_upload_oob_start: return -EINVAL
  instead of -1 for consistency with the rest of the file.


(cherry picked from commit 43137475e1)

Co-authored-by: luoxu <luoxu@espressif.com>
2026-07-06 17:44:26 +08:00
Luo Xu 81602499af fix(ble_mesh): added max dfd srv count limit
(cherry picked from commit 781218cb62)

Co-authored-by: luoxu <luoxu@espressif.com>
2026-07-06 17:44:24 +08:00
Luo Xu e374e94a58 fix(ble_mesh): reject invalid chunk size
(cherry picked from commit 35cd10fbdf)

Co-authored-by: luoxu <luoxu@espressif.com>
2026-07-06 17:44:22 +08:00
Luo Xu 33ef03c65c fix(ble_mesh): fixed invalid disconnect handler wrote
(cherry picked from commit 52cfff707f)

Co-authored-by: luoxu <luoxu@espressif.com>
2026-07-06 17:44:21 +08:00
Luo Xu 0924e81ca6 fix(ble_mesh): fixed BLE-Mesh NimBLE extended-adv reassembly buffer overflow on COMPLETE fragment
(cherry picked from commit 1b22467f63)

Co-authored-by: luoxu <luoxu@espressif.com>
2026-07-06 17:44:20 +08:00
Luo Xu c146056e55 fix(ble_mesh): fixed BLE-Mesh GATTS read-callback error
(cherry picked from commit 00adfb3cbc)

Co-authored-by: luoxu <luoxu@espressif.com>
2026-07-06 17:44:19 +08:00
Martin VychodilandCursor 7b5116d631 test(vfs): reformat WL FATFS in setup to avoid stale-partition flakes
Reformat the test partition before each mount so those tests always start from
a known-empty filesystem.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-07-06 11:39:30 +02:00
morris 677c69bffb Merge branch 'fix/fix_i2c_olde_example_hang_v6.0' into 'release/v6.0'
fix(i2c_oled): fix example hang when i2c transaction fails (v6.0)

See merge request espressif/esp-idf!50381
2026-07-06 17:07:09 +08:00
Chen Jichang 9a6e58913a fix(dma2d): fix async color convert csc check 2026-07-06 17:01:43 +08:00
Marius Vikhammer d199bb2fa9 Merge branch 'fix/esp_psram_init_fix_v6.0' into 'release/v6.0'
fix(esp_psram): repeated call to init should return invalid state error (v6.0)

See merge request espressif/esp-idf!50274
2026-07-06 16:28:07 +08:00
Marius Vikhammer 50f4bb6f25 Merge branch 'contrib/github_pr_18724_v6.0' into 'release/v6.0'
fix(heap_task_info): Fix incorrect current_usage subtraction on realloc() (GitHub PR) (v6.0)

See merge request espressif/esp-idf!50277
2026-07-06 16:06:30 +08:00
Ashish Sharma 9ad041cc8c fix(mbedtls): fixes TLS1.3 server failing with dynamic buffer 2026-07-06 15:18:38 +08:00
Jiang Jiang Jian ece337bf04 Merge branch 'fix/ble_mesh_disable_adv_pkt_discard_log_v6.0' into 'release/v6.0'
fix(ble_mesh): Disable warning logging when advertising packets are discarded (6.0)

See merge request espressif/esp-idf!50167
2026-07-06 15:13:19 +08:00
Chen Jichang 8350d77bfc fix(i2c_oled): fix example hang when i2c transaction fails
Closes https://github.com/espressif/esp-idf/issues/18713
2026-07-06 15:02:33 +08:00
Mahavir Jain aac5a0bb5b Merge branch 'fix/revert_redundant_rom_pmp_18769_v6.0' into 'release/v6.0'
revert(esp_hw_support): Re-add separate D-ROM PMP entry on C6/H2 (v6.0)

See merge request espressif/esp-idf!50360
2026-07-06 10:01:59 +05:30
Island 797d399dee Merge branch 'fix/ble-log-64-bit-io-setup-support_v6.0' into 'release/v6.0'
fix(ble_log): use BIT64 over BIT to support 64-bit IO setup (6.0)

See merge request espressif/esp-idf!50331
2026-07-06 12:22:07 +08:00
Mahavir Jain dfba68bc53 Merge branch 'fix/aes_dma_psram_encrypted_mem_s31_v6.0' into 'release/v6.0'
fix(mbedtls/aes): Fix AES-DMA over encrypted PSRAM on ESP32-S31 (v6.0)

See merge request espressif/esp-idf!50253
2026-07-06 09:48:36 +05:30
Xu Si Yu 15388539b6 fix(openthread): use spi slave tx_length/rx_length and remove rx DMA bounce buffer 2026-07-06 11:58:08 +08:00
Xu Si Yu 5aea50f035 fix(openthread): replace all malloc calls with calloc to avoid hidden uninitialized memory issues 2026-07-06 11:58:08 +08:00