Commit Graph
5769 Commits
Author SHA1 Message Date
yangfeng 39e7e142f7 fix(bluedroid): Fix the compilation issue of BCM_STRNCPY_S 2026-08-24 16:53:18 +08:00
Rahul Tank 93f18f1383 Merge branch 'bugfix/irk_smp_bond_issue_v5.5' into 'release/v5.5'
fix(nimble): Fix unpair_oldest_peer deleting wrong device (v5.5)

See merge request espressif/esp-idf!51837
2026-08-19 16:24:04 +05:30
Wang Meng Yang 2caf79b402 Merge branch 'fix/aireview_pbap_v5.5' into 'release/v5.5'
fix(bt_pbap): Fix some bugs in bluedroid PBAP (v5.5)

See merge request espressif/esp-idf!51729
2026-08-19 10:42:01 +08:00
Wang Meng Yang 9fcbdc00ef Merge branch 'bugfix/ai_review_a2dp_v5.5' into 'release/v5.5'
fix(bt): Fix the critical issues related to A2DP from AI review report (v5.5)

See merge request espressif/esp-idf!50129
2026-08-19 10:38:19 +08:00
Rahul Tank 6c52b417f1 fix(nimble): Fix unpair_oldest_peer deleting wrong device
Sort bond entries by bond_count after in-place updates to maintain correct
eviction order, and log IRK resolving-list failures instead of failing the bond.
2026-08-18 12:46:43 +05:30
yangfeng 26dfcb0c86 fix(bt): Fix compatibility with A2DP API legacy usage methods
- Modify the timing of API calls in the A2DP example
- Closes https://github.com/espressif/esp-idf/issues/18786
2026-08-18 11:26:53 +08:00
yangfeng c1a1c97189 fix(bt): Fix the critical issues related to A2DP from AI review report
AVDT:
- Roll back CCB allocation when cmd/rsp queue creation fails
- Free media packet on invalid handle in AVDT_WriteReqOpt
- Zero-init timeout failure message before GETCAP callback
- Initialize lcid_tbl to 0xFF to avoid mapping to tc_tbl[0]
BTA/AVRCP:
- Use size_t for AVRC message copy buffer allocation
- Allocate before register in BTA_AvEnable
- Guard BTA_AvRegister callback when enable never completed
- Remove invalid free of inline Cover Art image_descriptor
A2DP BTC/API:
- Default g_a2dp_on_deinit to true before profile init
- Reject source audio send when A2DP is deiniting
- Add shutdown state check in btc_a2dp_sink_shutdown
- Guard A2DP source timer against freed dynamic local param
2026-08-18 11:26:53 +08:00
Rahul Tank 14b61b5b7f fix(nimble): Add separate helper functions to register notification/indication 2026-08-18 07:37:38 +05:30
Wang Meng Yang 9d7bd46045 Merge branch 'change/refactor_hidh_datapath_v5.5' into 'release/v5.5'
Change/refactor hidh datapath[backport v5.5]

See merge request espressif/esp-idf!51280
2026-08-17 10:25:28 +08:00
Rahul Tank f542038478 fix(nimble): Add fix to handle service reset during server start 2026-08-14 13:51:54 +05:30
hejiaxin 67e32f0568 fix(bt_pbap): Fix some bugs in bluedroid PBAP
- Add sdp_seq to avoid p_ccb being free during sdp
- Changed some BTA_Pba functions to return non-void value
- Improve error catching and report
- Refactor bta_pba_client_response to avoid UAF problem
- Rearrange btc_pba_client init flag to avoid some disturbing bug
2026-08-13 14:32:24 +08:00
Rahul Tank f47df3ad41 fix(nimble): Fix adding device to resolving list when defer connection 2026-08-13 10:24:15 +05:30
liqigan a3e4d10f2a fix(bt/bluedroid): Fixed use after free issue on osi_event_delete 2026-08-13 07:49:29 +08:00
liqigan cc404fc1ca fix(bt/bluedroid): Fixed HID host reconnection bug and enabled load HID devices
Closes https://github.com/espressif/esp-idf/issues/18335
2026-08-13 07:49:29 +08:00
liqigan e9ab88137c change(bt/bluedroid): Refactored HCI ACL datapath 2026-08-13 07:49:29 +08:00
liqigan 1fdd376d3d change(bt/bluedroid): Refactored HID host datapath 2026-08-13 07:49:29 +08:00
Rahul Tank fb72cbe6b9 fix(nimble): Added change to stop adv before starting new adv 2026-08-11 11:31:02 +05:30
Rahul Tank c33ee32f1d fix(nimble): Remove extra free to avoid double free 2026-08-10 19:25:12 +05:30
Jiang Jiang Jian c8713ab22c Merge branch 'feat/support_pawr_connect_evt_v5.5' into 'release/v5.5'
feat(ble/bluedroid): Support PAWR connection event (5.5)

See merge request espressif/esp-idf!51441
2026-08-06 11:25:19 +08:00
Island 1c58330176 Merge branch 'fix/ble_mesh_added_gatt_err_rsp_v5.5' into 'release/v5.5'
fix(ble_mesh): align GATTS read/write response handling with ATT (5.5)

See merge request espressif/esp-idf!51462
2026-08-05 16:02:56 +08:00
hejiaxin 49f12e853e feat(bluedroid): Add config to place btu and hci task stack in psram
- Also adjust the osi_thread_stop implementation.
2026-08-04 14:55:59 +08:00
Rahul Tank 53bde34029 Merge branch 'bugfix/add_nimble_cve_v5.5' into 'release/v5.5'
fix(nimble): Fixes for various NimBLE CVEs (v5.5)

See merge request espressif/esp-idf!51202
2026-08-04 12:11:34 +05:30
Wang Meng Yang 89a63e35b8 Merge branch 'fix/aireview_critical_v5.5' into 'release/v5.5'
fix: Fix some critical bugs in classic bt (v5.5)

See merge request espressif/esp-idf!51290
2026-08-04 14:16:54 +08:00
Rahul Tank 9ffcc9821e fix(nimble): Fixes for various NimBLE CVEs 2026-08-03 23:45:23 +05:30
Luo Xu 3033a5fffb fix(ble_mesh): align GATTS read/write response handling with ATT
bt_mesh_bta_gatts_cb did not always answer ATT Read/Write Requests:
- READ: on a callback error it only logged a warning and sent nothing; a
  0-byte read (Read Blob at an offset equal to the value length) also sent
  nothing, although it is a successful empty read.
- WRITE: on a callback error it sent nothing, and a partial/zero write was
  treated as success.
- Both: when the handle was not found or the attribute had no read/write
  callback, the request was silently dropped.

An ATT Request must always be answered:

- READ: len >= 0 is success -> Read Response (a 0-byte read yields an empty
  value); len < 0 -> ATT Error Response carrying the callback's error code
  (-len, since BLE_MESH_GATT_ERR(x) == -x). The copy length is clamped to
  the source buffer size as a defensive bound. If the handle is unknown or
  the attribute has no read callback, respond with INVALID_HANDLE /
  READ_NOT_PERMITTED.
- WRITE: when need_rsp is set, always reply. len == write length -> Write
  Response; otherwise (negative ATT error, partial write, or 0) -> ATT
  Error Response (the negative code, or UNLIKELY for partial/0). If the
  handle is unknown or the attribute has no write callback, respond with
  INVALID_HANDLE / WRITE_NOT_PERMITTED. Write Without Response still sends
  no response.

A non-success status passed to BTA_GATTS_SendRsp is turned into an ATT
Error Response by the GATT layer (gatt_sr_process_app_rsp ->
gatt_send_error_rsp).


(cherry picked from commit ed1f4de3a3)

Co-authored-by: luoxu <luoxu@espressif.com>
2026-08-03 21:43:46 +08:00
Zhi Wei Jian ecf32535bc fix(ble/bluedroid): Build LE event mask from host feature macros
(cherry picked from commit 68dff5d798)

Co-authored-by: zhiweijian <zhiweijian@espressif.com>
2026-08-03 15:25:54 +08:00
Zhi Wei Jian 49cddfd411 feat(ble/bluedroid): Support PAWR connection event
(cherry picked from commit 7da7fa42ac)

Co-authored-by: zhiweijian <zhiweijian@espressif.com>
2026-08-03 15:25:53 +08:00
Island c41feceb86 Merge branch 'fix/ble_log_compression_issue_on_windows_v5.5' into 'release/v5.5'
fix(bt): fix BLE log compression build on Windows (5.5)

See merge request espressif/esp-idf!51245
2026-08-03 11:31:41 +08:00
Island 4e5966a7f0 Merge branch 'feat/update_mesh_lib_to_supported_get_lib_ver_v5.5' into 'release/v5.5'
Feat/update mesh lib to supported get lib ver (5.5)

See merge request espressif/esp-idf!51172
2026-08-03 11:30:16 +08:00
Island 3844dee2e7 Merge branch 'fix/fix_some_ble_sleep_issues_v5.5' into 'release/v5.5'
Fix/fix some ble sleep issues (5.5)

See merge request espressif/esp-idf!51318
2026-07-31 11:09:57 +08:00
Rahul Tank 55cca8b8b4 fix(nimble): Deliver PAwR peripheral CONNECT via sync callback 2026-07-30 16:33:07 +05:30
Wang Meng Yang fa27fd0a52 Merge branch 'fix/bluedroid_aireview_v5.5' into 'release/v5.5'
Fix/bluedroid aireview (v5.5)

See merge request espressif/esp-idf!51295
2026-07-30 14:28:55 +08:00
cjin 2fca2f8b49 fix(bt): fix deselect slow clk missing on ESP32-C5 2026-07-30 10:39:30 +08:00
Island bc9e3b168e Merge branch 'change/ble_update_lib_20260717_v5.5' into 'release/v5.5'
change(ble): [AUTO_MR] 20260717 - Update ESP BLE Controller Lib (5.5)

See merge request espressif/esp-idf!50931
2026-07-30 10:08:05 +08:00
Jin Cheng 6e4bd4152d fix(bt/bluedroid): fixed incorrect eSCO packet type validation under secure connection mode in BlueDroid 2026-07-29 17:30:25 +08:00
hejiaxin 60289a9c60 fix(bt): Fix some bug in stm_sco.c
- Memory safety
- State machine & logic integrity
- Resource leaks
- Edge cases check
2026-07-29 17:30:25 +08:00
hejiaxin 18c6d51e46 fix(bt_stack): Fix some critical bugs in classic_bt stack
related: obex, smp, pbap, sdp, rfcomm, stack_dm

- Deinit function doesn't delete connection when OBEX_DYNAMIC_MEMORY is on
- Union tGOEPC_DATA sometimes is free by osi_free in some cases when it contains mtu_id
- Add correct free and return solution after fail
- Fix symbol mistake in mod calculation
- Fix pointer-related UAF problems and memory free problems
- Fix buffer overflows and out-of-bounds access
- Fix infinite loops triggered by integer overflow wraparound
- Fix double free
- Change layer_specific usage to avoid heap overflow
- Add some NULL check for pointers
- Fix sdp_db free function
- Fix state table mismatch
2026-07-29 17:05:35 +08:00
Rahul Tank 80e8f463c3 fix(nimble): update sbom file with cve details 2026-07-29 12:50:20 +05:30
Island c96d10b850 Merge branch 'feat/add_bt_common_npl_v5.5' into 'release/v5.5'
feat(bt): Add host-agnostic BT OSAL and shared BLE profile task (5.5)

See merge request espressif/esp-idf!51218
2026-07-29 15:00:28 +08:00
cjin 57d2a46509 change(ble): [AUTO_MR] Update lib_esp32c6 to 18aafc6f 2026-07-29 08:36:20 +08:00
cjin 4d0df8eef3 change(ble): [AUTO_MR] Update lib_esp32c5 to 18aafc6f 2026-07-29 08:36:20 +08:00
cjin 3bf8c8d7d5 change(ble): [AUTO_MR] Update lib_esp32h2 to 18aafc6f 2026-07-29 08:36:20 +08:00
Luo Xu 2921dd77b9 fix(bt): fix BLE log compression build on Windows
The BLE log compression feature (CONFIG_BT_LOG_CRITICAL_ONLY ->
BLE_COMPRESSED_LOG_ENABLE) failed to build on Windows while working
correctly on Linux, due to two shell/platform-specific issues in the
compression script.

1. Module/source argument quoting. CMakeLists.txt passes the
   semicolon-separated module and source lists wrapped in single quotes
   ("'${MODULES}'") to protect ';' from POSIX shells, which strip them.
   cmd.exe does not treat single quotes as quoting characters, so on
   Windows the quotes reached the script literally and
   args.module.split(';') produced "'BLE_MESH" / "BLE_HOST'" instead of
   the clean names. These never matched the YAML module keys, every
   module was skipped ("Skipping module ... - config not found"), the
   compressed sources were never generated, and the build failed. Strip
   surrounding quote characters before splitting; this is a no-op on
   Linux/macOS where the shell already removed them.

2. CRLF line endings. With core.autocrlf=true the IDF sources are
   checked out as CRLF on Windows. The generated *_log_index.h macros
   use backslash-newline line-continuation; a backslash followed by
   '\r\n' is not a valid continuation in C, producing floods of syntax
   errors when the header is compiled. Write generated headers with
   newline='' to force LF, and normalize source content to LF right
   after reading so '\r' embedded inside multi-line argument expressions
   is also handled. Byte offsets stay consistent because both tree-sitter
   parsing and tag replacement operate on the normalized content.

Verified by full clean builds of examples/bluetooth/esp_ble_mesh/
vendor_models/vendor_client (esp32c6, bluedroid + mesh) from both
cmd.exe and PowerShell; both produce an identical vendor_client.bin.


(cherry picked from commit aa9b565a6d)

Co-authored-by: luoxu <luoxu@espressif.com>
2026-07-28 13:43:38 +08:00
luoxu 0d0df66dfc feat(ble_mesh): update lib to 79e3fee04e 2026-07-28 12:07:09 +08:00
chenjianhua 4460584d07 feat(bt): Add host-agnostic BT OSAL and shared BLE profile task
- Add bt_osal: event queues, mutexes, semaphores, callouts, etc.
- Add the shared BLE profile task and event queue
- Bring both up and tear them down in the host init/deinit paths
- Add unit tests for the OSAL and the profile task
2026-07-27 19:29:56 +08:00
Fu Hanxi d359f42f6d ci: apply idf-ci 1.x
(cherry picked from commit 21d772a24da646bfb672418cf056199cad9b17e4)
2026-07-27 10:52:35 +02:00
Luo Xu 1974089f9f feat(ble_mesh): supported get lib version
(cherry picked from commit 56f78da32c)

Co-authored-by: luoxu <luoxu@espressif.com>
2026-07-27 10:03:16 +08:00
Shreeyash Bhakare 87f48471c5 fix(nimble): Added security related fixes 2026-07-25 08:56:22 +05:30
Astha Verma d2708d151d fix(nimble): Restore throughput after switching from LE Coded PHY 2026-07-24 18:04:48 +05:30
Rahul Tank 4e3f2de1e0 Merge branch 'bugfix/red_rem_feat_evt_v5.5' into 'release/v5.5'
Handle Read Remote Supported Feature failure (v5.5)

See merge request espressif/esp-idf!50810
2026-07-24 14:26:38 +05:30