Commit Graph
51694 Commits
Author SHA1 Message Date
Jiang Jiang Jian 7bcd65c9be Merge branch 'fix/fix_esp_tee_iv_length_check_v6.0' into 'release/v6.0'
feat(esp_tee): ESP-TEE Security Audit fixes (v6.0)

See merge request espressif/esp-idf!50851
2026-07-22 10:37:48 +08:00
Jiang Jiang Jian 4c69588e41 Merge branch 'test/idf-additions-coverage_v6.0' into 'release/v6.0'
test(freertos): expand IDF additions test coverage (v6.0)

See merge request espressif/esp-idf!50820
2026-07-22 10:35:34 +08:00
Jiang Jiang Jian f9058d5328 Merge branch 'feat/enable_cross_signed_cert_suppport_default_v6.0' into 'release/v6.0'
feat(mbedtls): enable cross signed certificate verification support by default (v6.0)

See merge request espressif/esp-idf!50535
2026-07-22 10:30:53 +08:00
Jiang Jiang Jian bd994cb0f3 Merge branch 'bugfix/memory-safety-and-validation_v6.0' into 'release/v6.0'
fix(security): findings from project Vanessa (v6.0)

See merge request espressif/esp-idf!50391
2026-07-22 10:28:14 +08:00
Jiang Jiang Jian 5edd750418 Merge branch 'fix/harden_esp_security_v6.0' into 'release/v6.0'
fix(esp_security): harden crypto peripheral error handling (v6.0)

See merge request espressif/esp-idf!50325
2026-07-22 10:26:51 +08:00
Konstantin Kondrashov 58caaebbf5 fix(esp_event): free queued legacy cleanup ctx on loop delete
When a loop is deleted while an internal legacy "cleanup" event is still
queued (posted by a deferred self-unregistration from within a handler),
esp_event_loop_delete() drained the queue but only freed the post payload,
leaking the heap copy of the handler context allocated for the legacy path.

Free ctx->handler_ctx for queued legacy cleanup events while draining the
queue, mirroring the cleanup done in esp_event_loop_run().

Add a regression test that leaves a legacy cleanup event queued and asserts
no memory is leaked on loop deletion.
2026-07-21 17:15:20 +03:00
Konstantin Kondrashov 0a66277300 fix(esp_event): clear running_task before releasing mutex on tick timeout
When esp_event_loop_run() exited via the ticks-expired break path,
loop->running_task was left pointing to the current task handle.
Any subsequent trylock in esp_event_handler_unregister_with_internal()
would see a stale non-NULL running_task and take the wrong code path.
2026-07-21 17:15:20 +03:00
Konstantin Kondrashov 90bfe49549 fix(esp_event): prevent UAF race between post and loop delete (SEC-222)
esp_event_post_to() could access loop->queue / loop->mutex after
esp_event_loop_delete() freed them when both ran concurrently.

Introduce esp_event_loop_state_t with:
- posts_in_flight: reference-count incremented atomically (under
  state.lock spinlock) before touching any loop resources, decremented
  on every exit path via goto on_err.
- deleting: atomic_bool set by esp_event_loop_delete() to block new
  posts from entering the critical section.

esp_event_loop_delete() sets deleting=true, then busy-waits (releasing
and re-acquiring loop->mutex each tick) until posts_in_flight reaches
zero before proceeding with teardown.

esp_event_isr_post_to() performs a lock-free atomic_load of deleting as
a best-effort guard; ISR context cannot participate in the spinlock
protocol but the window is documented and accepted.
2026-07-21 17:15:19 +03:00
Konstantin Kondrashov c0fc78ca26 fix(esp_event): skip dispatch for internal cleanup events (SEC-221)
After processing an esp_event_handler_cleanup sentinel, execution fell
through into the regular dispatch block. Every loop-level (ANY_BASE/
ANY_ID) handler was invoked with base="cleanup" and event_data pointing
at the internal esp_event_remove_handler_context_t struct.

Consequences:
- Information disclosure: internal handler addresses and loop instance
  pointer are exposed to every loop-level handler.
- UAF: if a handler stores event_data for later use, post_instance_delete
  frees the ctx, turning the stored pointer into a dangling reference.
- Logic corruption: handlers that switch on base with a default branch
  misbehave on every unregister anywhere in the system.

Fix: wrap the regular dispatch block in an else clause so it is skipped
entirely for cleanup events. post_instance_delete, ticks accounting, and
xSemaphoreGiveRecursive remain in the shared tail executed for both paths.

Closes SEC_221
2026-07-21 16:51:40 +03:00
Konstantin Kondrashov 086faab0c5 fix(esp_event): use recursive mutex API in handler unregister (SEC-220)
1) loop->mutex is created with xSemaphoreCreateRecursiveMutex(). FreeRTOS
requires that recursive mutexes are only acquired and released with
xSemaphoreTakeRecursive / xSemaphoreGiveRecursive.

esp_event_handler_unregister_with_internal() used the non-recursive
xSemaphoreTake(loop->mutex, 0) / xSemaphoreGive(loop->mutex) in the fast
path. The non-recursive Take bypasses uxRecursiveCallCount bookkeeping;
if the same task subsequently takes the mutex recursively (e.g. re-entry
from a handler or a follow-up register), the call count drifts. The
non-recursive Give then unconditionally drops the holder, allowing another
task to acquire the mutex while the original task still believes it holds
the lock — a full lock violation on the handler list leading to UAF and
potential RCE on attacker-driven event floods.

Fix: replace xSemaphoreTake/xSemaphoreGive with the Recursive variants in
the fast (try-take with timeout 0) path of unregister_with_internal.

2) avoid use-after-free when unregistering handler from a callback

The recursive try-lock introduced in SEC-220 succeeds re-entrantly when a
handler unregisters itself from within its own callback, causing the handler
node to be freed immediately while the dispatch loop still writes profiling
counters to it after the callback returns. Route the in-callback case to the
deferred cleanup path and only free directly once no dispatch is active.

Closes SEC_220
2026-07-21 16:51:40 +03:00
Konstantin Kondrashov a2d865b4c8 fix(esp_event): protect is_handler_registered traversal with mutex (SEC-219)
esp_event_is_handler_registered() walked loop_nodes, base_nodes, id_nodes
and handler lists with no lock held, then released an unowned mutex at the
'out:' label via xSemaphoreGive().

Concurrent register/unregister/delete operations can free handler nodes
during the unlocked walk (SLIST UAF). The xSemaphoreGive on an unowned
recursive mutex corrupts the recursive call-count of any task that
legitimately holds the mutex.

Fix:
- Take loop->mutex with xSemaphoreTakeRecursive before the traversal.
- Replace xSemaphoreGive at the 'out:' label with xSemaphoreGiveRecursive
  so every exit path holds the mutex for exactly one balanced take/give.

Closes SEC_219
2026-07-21 16:51:39 +03:00
Konstantin Kondrashov 2fec4e6930 fix(esp_event): fix format string vulnerability in esp_event_dump (SEC-064)
fprintf(file, buf) is a format-string sink: if any registered event base
or handler name contains "%", fprintf interprets it as a format directive,
causing an information leak or crash.

Replace with fprintf(file, "%s", buf) so the buffer is always treated as
plain text regardless of its content.

Closes SEC_064
2026-07-21 16:51:39 +03:00
Adam Múdry 50b715d93f fix(sdmmc): BDL calculate sectors cast fix
Closes https://github.com/espressif/esp-idf/issues/18875
2026-07-21 15:03:07 +02:00
Adam Múdry d52b12fe11 fix(sdmmc): Add a better handling of devices accessing PSRAM through DMA
Closes https://github.com/espressif/esp-idf/issues/18412
2026-07-21 15:03:07 +02:00
Zhou Xiao 2bb70519ea fix(bt): keep BLE log ISR state in internal RAM
(cherry picked from commit 2fa434eb50)

Co-authored-by: Zhou Xiao <zhouxiao@espressif.com>
2026-07-21 19:44:18 +08:00
Martin Vychodil 406ac81a03 Merge branch 'contrib/github_pr_18400_v6.0' into 'release/v6.0'
Improve logging for VFS start_select function (GitHub PR) (v6.0)

See merge request espressif/esp-idf!49550
2026-07-21 19:30:10 +08:00
Konstantin Kondrashov 666dc3b438 fix(bootloader): increase partition table offset for ESP32-P4 in affected test configs 2026-07-21 13:35:35 +03:00
Konstantin Kondrashov decd12a726 fix(esp_image_format): validate MMU page size 2026-07-21 13:35:35 +03:00
Konstantin Kondrashov 747facfa27 fix(esp_image_format): verify length of segment #0 for app description 2026-07-21 13:35:35 +03:00
Konstantin Kondrashov e8c1dad0c1 fix(esp_image_format): Verify image segment count 2026-07-21 13:35:35 +03:00
gadget-man 22d46e4f22 Fix bug in logging for VFS start_select function
Resolves issue identified in https://github.com/espressif/esp-idf/issues/18398 by seperating logging when `vfs == NULL`

Closes https://github.com/espressif/esp-idf/pull/18400
Closes https://github.com/espressif/esp-idf/issues/18398
2026-07-21 11:37:34 +02:00
Shreyas Sheth b9066a7747 fix(esp_wifi): Backport dpp and other fixes
1) Fix crash while connecting to dpp akm
2) Fix phy ref cnt for power management for offchannel_tx
3) Introduced a variable to indicate dpp ap for scan results
4) Introduced WIFI_AUTH_UNKNOWN for ap with misconfigured security parameters
2026-07-21 13:52:33 +05:30
Alexey Gerenkov f4058b3648 Merge branch 'enable_esp32p4_jtag_tests_v6.0' into 'release/v6.0'
Enable esp32p4 jtag tests (v6.0)

See merge request espressif/esp-idf!50547
2026-07-21 12:09:21 +08:00
morris 5d0975e307 Merge branch 'feat/i2s_duplex_update_v6.0' into 'release/v6.0'
feat(i2s): allow full duplex mode in less strict condition (v6.0)

See merge request espressif/esp-idf!50866
2026-07-21 11:09:18 +08:00
Luo XuandWang Mengyang 5ab9a740d8 fix(bt): Fixed build error on array-bounds in HFP AG
(cherry picked from commit bbd20cae01)

Co-authored-by: Wang Mengyang <wangmengyang@espressif.com>
2026-07-21 11:02:55 +08:00
Luo Xu f871af7be8 feat(ble_log): mirror local compression headers
(cherry picked from commit ee732a4591)

Co-authored-by: luoxu <luoxu@espressif.com>
2026-07-21 11:02:55 +08:00
Jiang Jiang Jian fb02baed9b Merge branch 'bugfix/fix_some_coex_bugs_260720_v6.0' into 'release/v6.0'
Bugfix/fix some coex bugs 260720 v6.0(Backport v6.0)

See merge request espressif/esp-idf!50943
2026-07-21 10:56:10 +08:00
Zhang Hai Peng 824621c324 fix(ble/bluedroid): track ext scan state for rand addr check
Update inq_var.state only after btsnd_hcic_ble_ext_scan_enable succeeds.
Clear BTM_BLE_SCANNING on explicit stop and controller scan timeout.


(cherry picked from commit 23519567e4)

Co-authored-by: zhanghaipeng <zhanghaipeng@espressif.com>
2026-07-21 10:53:26 +08:00
Zhang Hai Peng 11149ca943 change(ble/bluedroid): disable host trace logs when BLE Log host is off
Default all Bluedroid layer trace levels to NONE when BLE async log
is enabled without BLE_LOG_HOST_LOG.


(cherry picked from commit 1f8f935e3f)

Co-authored-by: zhanghaipeng <zhanghaipeng@espressif.com>
2026-07-21 10:44:11 +08:00
Zhang Hai Peng ef7e5db718 fix(esp_hid/bluedroid): remove app-layer CCC gating in HID device
Do not check CCCD before sending notify in battery_set,
input_set and feature_set.


(cherry picked from commit 81bbcaca4e)

Co-authored-by: zhanghaipeng <zhanghaipeng@espressif.com>
2026-07-21 10:43:57 +08:00
morris ed43092fa5 Merge branch 'fix/fix_i2s_i80_color_size_check_v6.0' into 'release/v6.0'
fix(lcd): add color size check for i80 and boundary check for rgb (v6.0)

See merge request espressif/esp-idf!50962
2026-07-21 10:26:40 +08:00
morris 9a12e8c9d2 Merge branch 'fix/fix_image_header_check_v6.0' into 'release/v6.0'
image header: fixed image header segment count check (v6.0)

See merge request espressif/esp-idf!50935
2026-07-21 10:12:07 +08:00
Renz Bagaporo bd83aa20f0 fix(ulp): clear LP GPIO edge wakeup latch 2026-07-21 10:50:42 +09:00
Renz Bagaporo 40ef985efb docs(esp_ringbuf): update ringbuf create API notes 2026-07-21 10:46:21 +09:00
Renz Bagaporo 52f1a8dfda fix(esp_ringbuf): validate/guard ringbuf size 2026-07-21 10:46:21 +09:00
Renz Bagaporo 379ab73a7c fix(esp_ringbuf): add test for max item size underflow 2026-07-21 10:46:21 +09:00
Alexey Gerenkov c0992a3a5a Merge branch 'sysview_test_fixes_v6.0' into 'release/v6.0'
Sysview test fixes v6.0

See merge request espressif/esp-idf!50729
2026-07-20 18:45:30 +08:00
Jin Cheng 00f6890dfe fix(bt/bluedroid): fixed possible 1-byte OOB read in bta_hh_ctrl_dat_act
Closes SEC-786
2026-07-20 16:35:15 +08:00
Konstantin Kondrashov 6b95e00788 feat(ipc_isr): adds IPC ISR safe API for other CPU stall API 2026-07-20 11:20:23 +03:00
Jiang Jiang Jian 6e1dc59ed9 Merge branch 'fix/blacklist_flag_correction_v6.0' into 'release/v6.0'
fix(wifi): Correct blacklist flag(v6.0)

See merge request espressif/esp-idf!50919
2026-07-20 16:17:55 +08:00
Chen Jichang 635ac8461c fix(lcd): add color size check for i80 and boundary check for rgb 2026-07-20 16:16:03 +08:00
morris 9e040f4c20 Merge branch 'bugfix/ana_cmpr_macro_v6.0' into 'release/v6.0'
fix(ana_cmpr): Fix swapped POS/NEG cross interrupt masks on ESP32-C5/P4 (v6.0)

See merge request espressif/esp-idf!50799
2026-07-20 14:22:39 +08:00
Jiang Jiang Jian a2cd919a64 Merge branch 'bugfix/bug_bounty_av_v6.0' into 'release/v6.0'
fix(bt/bluedroid): Fix bug bounty issues about A/V from NVIDIA (v6.0)

See merge request espressif/esp-idf!50477
2026-07-20 13:54:41 +08:00
muhaidong ecf281be4a fix(coex): fix coex status get issue 2026-07-20 12:02:23 +08:00
Xu Si Yu a2b9628d49 fix(coex): move 15.4 register configuration to 15.4 init 2026-07-20 11:58:33 +08:00
Alexey Lapshin 795b2ec96f feat(tools): tools: update esp-rom-elf to version 20260528
Closes https://github.com/espressif/esp-idf/issues/18755
2026-07-20 10:58:29 +07:00
Jiang Jiang Jian 3befd9d774 Merge branch 'bugfix/add_en_rst_in_pvt_func_for_p4_backport_v6.0' into 'release/v6.0'
fix(pvt): add en reset in pvt func for p4 on release v6.0

See merge request espressif/esp-idf!50882
2026-07-20 11:39:00 +08:00
Jiang Jiang Jian f298dd2110 Merge branch 'bugfix/sdmmc-ddr-response-buffer-leak_v6.0' into 'release/v6.0'
fix(sdmmc): free DMA response buffer on DDR mode switch failure (v6.0)

See merge request espressif/esp-idf!50886
2026-07-20 10:45:54 +08:00
Jiang Jiang Jian d1d8dd478d Merge branch 'bugfix/nvs-flash-erase-partition-leak_v6.0' into 'release/v6.0'
fix(nvs_flash): delete temporary NVSPartition after erase (v6.0)

See merge request espressif/esp-idf!50891
2026-07-20 10:45:35 +08:00
Jiang Jiang Jian f24018d113 Merge branch 'feature/enable_zb_for_esp32p4_v6.0' into 'release/v6.0'
feat(soc): enable zb* extensions for esp32p4 greater v3 (v6.0)

See merge request espressif/esp-idf!50779
2026-07-20 10:44:17 +08:00