Commit Graph
29767 Commits
Author SHA1 Message Date
Island fa6f2b6133 Merge branch 'bugfix/fix_bluedroid_read_multi_v5.3' into 'release/v5.3'
fix(ble/bluedroid): fix GATT Read Multiple response handling (5.3)

See merge request espressif/esp-idf!50706
2026-07-20 10:37:20 +08:00
Armando (Dou Yiwen) a461861678 fix: fixed image header segment count check
Signed-off-by: Armando (Dou Yiwen) <douyiwen@espressif.com>
2026-07-20 10:25:46 +08:00
yangfeng 26071a5a71 fix(bt/bluedroid): Fix unchecked p_ctrl_cback and p_msg_cback in AVRC
Closes SEC-1186
2026-07-19 10:25:26 +08:00
yangfeng 46d6b17f62 fix(bt/bluedroid): Fix missing NULL check on p_cfg in AVDT_ReconfigReq
Closes SEC-1187
2026-07-19 10:25:26 +08:00
Wang Meng Yang 4d956042dd Merge branch 'bugfix/fix_bredr_inq_crash_v5.3' into 'release/v5.3'
fix(bt/bluedroid): fix crash during bredr inquiry when zero-addr device is found (v5.3)

See merge request espressif/esp-idf!50857
2026-07-19 10:22:17 +08:00
Rahul Tank e69b7f37ff Merge branch 'bugfix/add_dis_ieee_udi_to_config_v5.3' into 'release/v5.3'
fix(nimble): Add option to disable IEEE and UDI Characteristic in DIS (v5.3)

See merge request espressif/esp-idf!50763
2026-07-18 09:31:51 +05:30
tarun.kumar 3cea633600 fix(wifi): Correct blacklist flag 2026-07-17 18:03:07 +05:30
Wang Meng Yang 8e905e0a52 Merge branch 'bugfix/smp_sec_flags_v5.3' into 'release/v5.3'
fix(bt/bluedroid): fixed several security issues from NVIDIA (v5.3)

See merge request espressif/esp-idf!50569
2026-07-17 20:01:24 +08:00
sonika.rathi fe8249a9a7 fix(spiffs): shorten obj_name_len guard comment 2026-07-17 13:04:12 +02:00
yi chen ed9f3d7950 fix(spiffs): fix off-by-one in spiffsgen.py obj name length check
SpiffsFS.create_file() rejected names only when strictly longer than
obj_name_len, but CONFIG_SPIFFS_OBJ_NAME_LEN's documented semantics
(see components/spiffs/Kconfig) are that the length includes the
zero-termination character, so the maximum number of actual name
characters is obj_name_len - 1.

With the old check, a name exactly obj_name_len characters long was
accepted. SpiffsObjIndexPage.to_binary() then computes the NUL padding
after the name as (obj_name_len - len(name)), which is 0 in that case,
so the generated image's fixed-size name field ends up with no NUL
terminator anywhere in its reserved region.

Fix the boundary so the generator enforces the same maximum length
that the Kconfig help text documents.
2026-07-17 13:04:12 +02:00
yi chen 7fd4573266 fix(esp_partition): prevent size_t overflow bypassing bounds checks on linux target
esp_partition_write/read/erase_range/mmap in partition_linux.c (the
`linux` target backend used by --preview set-target linux / host_test)
validated the requested range with `offset + size > partition->size`.
When `size` is close to SIZE_MAX, this addition wraps around size_t and
can evaluate to a small value, so the check passes even though the
request is far out of bounds. A caller passing e.g.
esp_partition_write(partition, 1, src, SIZE_MAX) sails through both
bounds checks and reaches the byte-copy loop with new_size == SIZE_MAX,
causing out-of-bounds reads/writes far past both the caller's buffer
and the mmap'd emulated-flash file.

Replace all four instances with the overflow-safe form already used by
the other esp_partition backends (partition_target.c,
partition_bootloader.c, partition_tee.c):
`size > partition->size - offset`, which is safe because the preceding
check already guarantees offset <= partition->size.

Signed-off-by: yi chen <94xhn1@gmail.com>
2026-07-17 12:49:31 +02:00
Sumeet Singh 67b458a3ab fix(nimble): Add option to disable IEEE and UDI Characteristic in DIS (v5.3) 2026-07-17 14:59:47 +05:30
Kapil Gupta 84e46ae39b fix(wpa_supplicant): Correct some functions in crypto porting layer 2026-07-17 14:02:45 +05:30
Rahul Tank 933f1f8b19 fix(nimble): Fix ECC HW byte-order and dropped SOC_ESP_NIMBLE_CONTROLLER 2026-07-17 10:50:06 +05:30
morris acdae8ad4e Merge branch 'fix/uart_is_enable_check_error_on_s3_v5.3' into 'release/v5.3'
Fix ESP32-S3 uart2 is_enabled check error (v5.3)

See merge request espressif/esp-idf!49351
2026-07-17 12:16:26 +08:00
linruihao 75f9bc84d0 fix(bt/bluedroid): fix crash during bredr inquiry when zero-addr device is found 2026-07-17 10:39:36 +08:00
luoxu 019e6d753b feat(ble): reorganize log compression Kconfig
Move log-compression Kconfig files to host/ and profile/mesh/ directories and update source paths.
2026-07-16 21:54:37 +08:00
Meet Patel 0a5508af07 test(freertos): expand IDF additions test coverage
Improve coverage of idf_additions.h task utility APIs and correct
WithCaps delete usage in existing tests to avoid heap leaks.
2026-07-16 11:04:33 +02:00
sonika.rathi 730a5a474f fix(wear_levelling): fix codespell issue in host test 2026-07-16 09:45:53 +02:00
luoxu 44dabf960a feat(ble): split log compression Kconfig into separate mesh and host files 2026-07-16 11:50:23 +08:00
Luo Xu 1e4709a1e4 fix(ble): fix Bluedroid log compression for newly added modules
(cherry picked from commit 8d4f1cb608)

Co-authored-by: luoxu <luoxu@espressif.com>
2026-07-16 11:50:23 +08:00
Martin Vychodil a2f7d4b004 Merge branch 'fix/cleanup_after_failed_nvs_set_blob_v5.3' into 'release/v5.3'
Fixed cleanup after nvs_set_blob failed on ESP_ERR_NVS_NOT_ENOUGH_SPACE (v5.3)

See merge request espressif/esp-idf!50746
2026-07-15 18:38:48 +08:00
Euripedes Rocha dddeb71ef8 Merge branch 'fix/lwip_sec_high_v5.3' into 'release/v5.3'
fix(lwip): high severity lwip fixes (v5.3)

See merge request espressif/esp-idf!50596
2026-07-15 10:49:18 +02:00
Island 1cb47dcaa7 Merge branch 'feat/support_bluedroid_le_coc_and_eatt_v5.3' into 'release/v5.3'
feat(ble/bluedroid): Support bluedroid LE COC and EATT features (5.3)

See merge request espressif/esp-idf!50712
2026-07-15 14:02:56 +08:00
morris a6008cbeea Merge branch 'bugfix/dma2d_dequeue_mechanism_v5.3' into 'release/v5.3'
fix(dma2d): add a dequeue mechanism for dma2d driver (v5.3)

See merge request espressif/esp-idf!50517
2026-07-15 12:01:18 +08:00
morris 947281f046 Merge branch 'contrib/github_pr_18677_v5.3' into 'release/v5.3'
fix(uart): fix threshold configuration loss when interrupts are disabled (v5.3)

See merge request espressif/esp-idf!50527
2026-07-15 11:59:15 +08:00
morris 33ab160fa5 Merge branch 'fix/fix_rgb_frame_buffer_alignment_v5.3' into 'release/v5.3'
fix(gdma): fix buffer alignment when psram ecc enabled (v5.3)

See merge request espressif/esp-idf!50000
2026-07-15 11:53:58 +08:00
radek.tandler 1d8ca0c66b fix(nvs_flash): fixed cleanup after nvs_set_blob failed on ESP_ERR_NVS_NOT_ENOUGH_SPACE
- fixed identification of blob parts to be cleaned by using right starting chunk index
  - improved localisation of blobs for cases where some of pages get reclaimed
  - created host test cases covering the edge cases above
2026-07-14 17:34:41 +02:00
Euripedes Rocha 7a911c980d Merge branch 'fix/w5500_rx_buffer_corruption_recovery_v5.3' into 'release/v5.3'
fix(esp_eth): recover W5500 RX path on corrupted frame length (v5.3)

See merge request espressif/esp-idf!50649
2026-07-14 14:34:00 +02:00
yi chen 5259ebd1e7 fix(wear_levelling): guard WL_Flash::write()/read() against size==0 underflow
WL_Flash::write() and WL_Flash::read() computed:

    uint32_t count = (size - 1) / this->cfg.wl_page_size;

`size` is `size_t` (unsigned). Neither the public wl_write()/wl_read() API
(wear_levelling.cpp), nor the newer wl_bdl_write()/wl_bdl_read() block-device
path (wl_blockdev.cpp), reject size == 0 before calling into WL_Flash, and
wear_levelling.h does not document size == 0 as invalid (a 0-byte
write/read is a reasonable no-op, mirroring POSIX write()/read() with
count == 0).

When size == 0, `size - 1` wraps around to SIZE_MAX, so `count` becomes an
enormous page count instead of 0. The functions then loop that many times,
reading (write()) or writing (read()) `wl_page_size` bytes per iteration
through the flash partition, immediately walking past the caller-supplied
buffer on the very first iteration:

  - write(): out-of-bounds *read* from the caller's `src` buffer.
  - read():  out-of-bounds *write* into the caller's `dest` buffer -- the
             more severe case, since it corrupts caller memory with flash
             content instead of merely over-reading.

Verified with a standalone reproduction that compiles the unmodified
WL_Flash.cpp against a mock Flash_Access partition: calling
`wl.write(0, an_8_byte_buffer, 0)` with no other change immediately
segfaults (confirmed count == 0xFFFFFFFF for wl_page_size == 4096); with
this fix applied the same call returns ESP_OK without touching memory
outside the buffer, and normal non-zero-size read/write is unaffected.

Add an early `size == 0` return (mirroring the existing `!initialized`
guard) to both functions, and a host_test regression case exercising
wl_write()/wl_read() with size == 0 through the public API.

Disclosure: this fix was prepared with AI assistance (Claude) and reviewed
by me before submission.

Signed-off-by: yi chen <94xhn1@gmail.com>
2026-07-14 12:23:53 +02:00
zhiweijian bfdb6f5c9e fix(ble/bluedroid): guard GATT database hash and serialization 2026-07-14 14:59:15 +08:00
Zhi Wei Jian 329c1c8f8e feat(ble/bluedroid): Support bluedroid dual identity
(cherry picked from commit 2358786647)

Co-authored-by: zhiweijian <zhiweijian@espressif.com>
2026-07-14 14:26:15 +08:00
Rahul Tank 43280d9be8 Merge branch 'bugfix/fix_bond_store_overflow_v5.3' into 'release/v5.3'
fix(nimble): Fix bond-store overflow when IRK is enabled (v5.3)

See merge request espressif/esp-idf!50627
2026-07-14 11:17:48 +05:30
Zhi Wei Jian ebd9ca130e fix(ble/bluedroid): use BOOLEAN for BLE HCI command builders
(cherry picked from commit abbf001120)

Co-authored-by: zhiweijian <zhiweijian@espressif.com>
2026-07-14 12:03:55 +08:00
Zhi Wei Jian 5f7deedd8b fix(ble/bluedroid): clean up LE CoC connect on CCB alloc failure
(cherry picked from commit 4fd1ebb4a9)

Co-authored-by: zhiweijian <zhiweijian@espressif.com>
2026-07-14 12:03:54 +08:00
Zhi Wei Jian f080478455 docs(ble/bluedroid): note ISO BIG HCI alloc failure not checked
(cherry picked from commit 34b59d30ae)

Co-authored-by: zhiweijian <zhiweijian@espressif.com>
2026-07-14 12:03:54 +08:00
Zhi Wei Jian ea9fdcd2e0 fix(ble/bluedroid): fix direct-connect cleanup and adv bounds
(cherry picked from commit 82e71c1767)

Co-authored-by: zhiweijian <zhiweijian@espressif.com>
2026-07-14 12:03:54 +08:00
Zhi Wei Jian 1f3d235a9f fix(ble/bluedroid): validate BLE confirm/OOB and sec-check device
(cherry picked from commit 93ab11d564)

Co-authored-by: zhiweijian <zhiweijian@espressif.com>
2026-07-14 12:03:53 +08:00
Zhi Wei Jian 7e677879a6 fix(ble/bluedroid): validate SMP pair-fail reason and OOB device
(cherry picked from commit 98efe02385)

Co-authored-by: zhiweijian <zhiweijian@espressif.com>
2026-07-14 12:03:53 +08:00
Zhi Wei Jian de4598284a fix(ble/bluedroid): route ATT indication-conf timeout separately
(cherry picked from commit 6c3267ee84)

Co-authored-by: zhiweijian <zhiweijian@espressif.com>
2026-07-14 12:03:52 +08:00
Zhi Wei Jian 315ff40e71 fix(ble/bluedroid): validate ATT PDU sizes
(cherry picked from commit bb00b9817d)

Co-authored-by: zhiweijian <zhiweijian@espressif.com>
2026-07-14 12:03:52 +08:00
Zhi Wei Jian c3d78e8c66 fix(ble/bluedroid): re-lookup GATT TCB after enc-complete callback
(cherry picked from commit 37562af0ea)

Co-authored-by: zhiweijian <zhiweijian@espressif.com>
2026-07-14 12:03:52 +08:00
Zhi Wei Jian 80992db5a6 fix(ble/bluedroid): fix GATT long read and Service Changed CCC
(cherry picked from commit 4ce692ac0c)

Co-authored-by: zhiweijian <zhiweijian@espressif.com>
2026-07-14 12:03:51 +08:00
Zhi Wei Jian c5ee2be0ed fix(ble/bluedroid): validate GATT client discovery handles
(cherry picked from commit ac35ae6f2d)

Co-authored-by: zhiweijian <zhiweijian@espressif.com>
2026-07-14 12:03:51 +08:00
Zhi Wei Jian c202b37fa8 fix(ble/bluedroid): cap Read By Type length and free failed service decl
(cherry picked from commit 27ff0cf8c7)

Co-authored-by: zhiweijian <zhiweijian@espressif.com>
2026-07-14 12:03:51 +08:00
Zhi Wei Jian 6fa7f4195d fix(ble/bluedroid): fix GATT server busy errors and sr_cmd handling
(cherry picked from commit f86739b03d)

Co-authored-by: zhiweijian <zhiweijian@espressif.com>
2026-07-14 12:03:50 +08:00
Zhi Wei Jian a6fed3daae fix(ble/bluedroid): fix GATT teardown and service-change flow
(cherry picked from commit 0645ba469d)

Co-authored-by: zhiweijian <zhiweijian@espressif.com>
2026-07-14 12:03:50 +08:00
Zhi Wei Jian 0927c1990d fix(ble/bluedroid): fix GATT service lifecycle leaks
(cherry picked from commit ac93d94958)

Co-authored-by: zhiweijian <zhiweijian@espressif.com>
2026-07-14 12:03:49 +08:00
Zhi Wei Jian c33e3c13bc fix(ble/bluedroid): add GATT resource-cleanup helpers
(cherry picked from commit b83327f3ca)

Co-authored-by: zhiweijian <zhiweijian@espressif.com>
2026-07-14 12:03:49 +08:00
Zhi Wei Jian 1b3a7a04c2 feat(ble/bluedroid): Support bluedroid LE COC and EATT features
(cherry picked from commit 83f0831c53)

Co-authored-by: zhiweijian <zhiweijian@espressif.com>
2026-07-14 11:56:00 +08:00