Commit Graph
35828 Commits
Author SHA1 Message Date
tarun.kumar fd0d67c3dc fix(wifi): Correct blacklist flag 2026-07-17 17:09:24 +05:30
Wang Meng Yang 27a5aba8e1 Merge branch 'feat/ble_log_compression_module_cfg_update_v6.0' into 'release/v6.0'
Feat/ble log compression module cfg update (6.0)

See merge request espressif/esp-idf!49875
2026-07-17 19:35:49 +08:00
yi chen fde03cee88 fix(spiffs): fix off-by-one in spiffsgen.py obj name length check
SpiffsFS.create_file() rejected names only when strictly longer than
obj_name_len, but CONFIG_SPIFFS_OBJ_NAME_LEN's documented semantics
(see components/spiffs/Kconfig) are that the length includes the
zero-termination character, so the maximum number of actual name
characters is obj_name_len - 1.

With the old check, a name exactly obj_name_len characters long was
accepted. SpiffsObjIndexPage.to_binary() then computes the NUL padding
after the name as (obj_name_len - len(name)), which is 0 in that case,
so the generated image's fixed-size name field ends up with no NUL
terminator anywhere in its reserved region.

Fix the boundary so the generator enforces the same maximum length
that the Kconfig help text documents.
2026-07-17 13:03:30 +02:00
yi chen d057757a20 fix(esp_partition): prevent size_t overflow bypassing bounds checks on linux target
esp_partition_write/read/erase_range/mmap in partition_linux.c (the
`linux` target backend used by --preview set-target linux / host_test)
validated the requested range with `offset + size > partition->size`.
When `size` is close to SIZE_MAX, this addition wraps around size_t and
can evaluate to a small value, so the check passes even though the
request is far out of bounds. A caller passing e.g.
esp_partition_write(partition, 1, src, SIZE_MAX) sails through both
bounds checks and reaches the byte-copy loop with new_size == SIZE_MAX,
causing out-of-bounds reads/writes far past both the caller's buffer
and the mmap'd emulated-flash file.

Replace all four instances with the overflow-safe form already used by
the other esp_partition backends (partition_target.c,
partition_bootloader.c, partition_tee.c):
`size > partition->size - offset`, which is safe because the preceding
check already guarantees offset <= partition->size.

Signed-off-by: yi chen <94xhn1@gmail.com>
2026-07-17 12:48:48 +02:00
Martin Vychodil 326a998708 Merge branch 'fix/sdmmc_cmd_err_switch_case_handling_v6.0' into 'release/v6.0'
fix(sdmmc): sdmmc_cmd.c fixed error handling in certain if and switch statements (v6.0)

See merge request espressif/esp-idf!50683
2026-07-17 18:23:40 +08:00
Ashish Sharma 2c4bcab8d2 feat(mbedtls): enable cross signed certificate verification support by default 2026-07-17 18:12:56 +08:00
sonika.rathi 473dd30a96 fix(fatfs): move readdir-stat cache to per-DIR stream
Move cached_fileinfo and dir_path from vfs_fat_ctx_t to vfs_fat_dir_t so
each open DIR* has its own readdir→stat cache.
2026-07-17 12:09:26 +02:00
Sumeet Singh 73ef4148a8 fix(nimble): Add option to disable IEEE and UDI Characteristic in DIS (v6.0) 2026-07-17 14:57:20 +05:30
sonika.rathi 3ad5251819 fix(nvs_flash): delete temporary NVSPartition after erase 2026-07-17 10:57:27 +02:00
sonika.rathi 849a342fe0 fix(sdmmc): free DMA response buffer on DDR mode switch failure 2026-07-17 10:47:47 +02:00
wuzhenghui 5d528ee6d4 feat(esp_hw_support): fix esp32p4 PVT retention link 2026-07-17 16:24:05 +08:00
yanzihan@espressif.com d6e6ee1dbb feat(pvt): add en reset in pvt func for p4 on master 2026-07-17 16:23:53 +08:00
Jiang Jiang Jian a89931243c Merge branch 'bugfix/change_pvt_timer_target_param_backport_v6.0' into 'release/v6.0'
feat(pvt): change pvt timer target & limit on release v6.0

See merge request espressif/esp-idf!50814
2026-07-17 16:13:16 +08:00
Chen Chen 5c7be29ef2 refactor(i2s): make the slot_bit_width checks unique 2026-07-17 14:38:27 +08:00
Chen Chen 47bb180049 feat(i2s): allow full duplex mode in less strict condition 2026-07-17 14:38:27 +08:00
Rahul Tank 6a24b81921 Merge branch 'bugfix/add_extra_prints_v6.0' into 'release/v6.0'
fix(nimble): Remove SOC_ESP_NIMBLE_CONTROLLER from unnecessary locations (v6.0)

See merge request espressif/esp-idf!50095
2026-07-17 10:42:27 +05:30
morris afb9f5a719 Merge branch 'feat/csi_error_event_v6.0' into 'release/v6.0'
Add MIPI-CSI error event (v6.0)

See merge request espressif/esp-idf!50681
2026-07-17 12:17:02 +08:00
Jiang Jiang Jian 7c49a6a4d8 Merge branch 'fix/move_cache_lock_workaround_out_of_ipc_stall_v6.0' into 'release/v6.0'
fix(esp_hw_support): disable esp32 livelock workaround before stall another core (v6.0)

See merge request espressif/esp-idf!50770
2026-07-17 11:26:23 +08:00
linruihao eb81835174 fix(bt/bluedroid): fix crash during bredr inquiry when zero-addr device is found 2026-07-17 10:39:19 +08:00
Aditya Patwardhan cc2cfc17ba Merge branch 'fix/nvs-encrypted-partition-destructor-zeroize_v6.0' into 'release/v6.0'
fix(nvs_flash): zeroize XTS contexts when encrypted partition is destroyed (v6.0)

See merge request espressif/esp-idf!50806
2026-07-16 22:32:40 +05:30
morris 8ca8e00621 Merge branch 'feat/uhci_send_multi_buffer_v6.0' into 'release/v6.0'
feat(uhci): support transmit multi buffer (v6.0)

See merge request espressif/esp-idf!50777
2026-07-16 19:26:34 +08:00
Ashish Sharma d85cb8d7cc fix(esp_tee): fix DS-lock leak, intr-matrix OOB, calloc overflow, attestation leak 2026-07-16 18:24:47 +08:00
Ashish Sharma d710be28f3 fix(esp-tls): reject NULL host/url in plain-TCP and async HTTP connect 2026-07-16 18:24:47 +08:00
Ashish Sharma 2e6f9b8b42 fix(mbedtls): validate crypto input lengths (TEE OOB, auth-bypass, overflows) 2026-07-16 18:24:47 +08:00
Ashish Sharma 47e0435f99 fix(esp_https_server): free TLS session on transport_ctx OOM in httpd_ssl_open 2026-07-16 18:24:47 +08:00
Ashish Sharma 7bcafe2171 fix(esp_hal_security): clamp tag_len in aes_hal_gcm_read_tag to prevent OOB 2026-07-16 18:24:47 +08:00
Ashish Sharma e2537bb5e4 fix(bootloader_support): guard NULL efuse digest slot in secure-boot verify 2026-07-16 18:24:47 +08:00
Ashish Sharma 89f40a3b93 fix(esp_http_client): fix digest-auth leaks and credential/handle use-after-free 2026-07-16 18:24:47 +08:00
Ashish Sharma ea005e8316 fix(esp_http_server): close UAF/double-free, buffer underflows, and OOB read 2026-07-16 18:24:47 +08:00
Ashish Sharma 2742100127 fix(app_update): close OOB read, rollback-guard gap, and length underflow 2026-07-16 18:24:47 +08:00
morris 80f969e279 Merge branch 'isp_dma_one_frame_v6.0' into 'release/v6.0'
feat(isp): support isp dma input and add example (v6.0)

See merge request espressif/esp-idf!50755
2026-07-16 17:17:25 +08:00
luoxu 47e012a968 feat(ble): reorganize log compression Kconfig
Move log-compression Kconfig files to host/ and profile/mesh/ directories and update source paths.
2026-07-16 16:58:00 +08:00
sonika.rathi 0545b56e7a fix(wear_levelling): shorten zero-size guard comments 2026-07-16 09:35:43 +02:00
Rahul Tank bf03b83dfe fix(nimble): Fix ECC HW byte-order and dropped SOC_ESP_NIMBLE_CONTROLLER 2026-07-16 12:29:32 +05:30
Meet Patel 75248d0637 test(freertos): expand IDF additions test coverage
Improve coverage of idf_additions.h task utility APIs and correct
WithCaps delete usage in existing tests to avoid heap leaks.
2026-07-16 08:47:39 +02:00
Konstantin Kondrashov d5869bb6ee fix(bootloader): Hide bootloader anti-rollback Kconfig where not supported 2026-07-16 09:38:04 +03:00
yanzihan@espressif.com 77effaabb2 feat(pvt): change pvt timer target & limit 2026-07-16 14:14:14 +08:00
Aditya Patwardhan 970b54962f fix(nvs_flash): zeroize XTS contexts when encrypted partition is destroyed
NVSEncryptedPartition held two XTS_CONTEXT members (mEctxt, mDctxt) for
encryption / decryption. Their AES round keys are derived from the NVS
encryption key (HMAC-derived or plaintext from nvs_keys partition) and
therefore are sensitive secrets.

The destructor was empty, so when the NVS encrypted partition object
was destroyed -- on nvs_flash_deinit_partition(), on initialization
errors, and on any other teardown path -- the XTS round keys were left
in DRAM until the freed object's memory happened to be overwritten by
a later allocation. A subsequent stack/heap leak primitive would
recover the AES key from those bytes.

Fix:
* Initialize both XTS contexts in the constructor so the destructor's
  free path is always safe (previously xts_init was only called in
  init(); destruction before init() would have run xts_free on an
  uninitialized struct).
* Provide a real destructor that calls XTS_FUNC(xts_free) on both
  contexts, which performs mbedtls_platform_zeroize / esp_aes_xts free
  semantics on the underlying AES contexts.
2026-07-16 10:34:01 +05:30
Tiago Medicci a4239cab38 test(ana_cmpr): Add edge-specific interrupt direction test case
Add a Unity test case that arms only ANA_CMPR_CROSS_POS (resp. only
ANA_CMPR_CROSS_NEG) on a unit and asserts that a real transition of
the matching direction fires the callback exactly once, while a
transition of the opposite (never-armed) direction does not fire at
all.

This closes a gap in the existing test_apps: none of the current
cases isolate cross direction, so a swapped POS/NEG interrupt mask in
the LL layer (fixed in the previous commit) previously went
undetected.

On the scan-based comparator IP (ESP32-H4/S31), a crossing is only
sampled/latched when a scan is explicitly triggered, so the new test
case also triggers a scan after each level change on that IP, plus
one extra priming scan right after enabling the unit so the internal
compare state starts in sync with the already-set initial GPIO level.

Signed-off-by: Tiago Medicci <tiago.medicci@espressif.com>
2026-07-16 11:42:00 +08:00
Tiago Medicci 9014e35377 fix(ana_cmpr): Fix swapped POS/NEG cross interrupt masks on ESP32-C5/P4/C61
In components/soc/esp32c5/register/soc/gpio_ext_struct.h (ESP32-C5),
components/soc/esp32c61/register/soc/gpio_ext_struct.h (ESP32-C61),
and components/soc/esp32p4/register/hw_ver3/soc/gpio_struct.h
(ESP32-P4), the analog comparator raw/status/enable/clear register
fields are named comp_neg_0_*/comp0_neg_* for bit 0 and
comp_pos_0_*/comp0_pos_* for bit 1, but each field's own comment says
the opposite: bit 0 is documented as "analog comparator pos edge
interrupt raw/status/enable/clear" and bit 1 as the "neg" counterpart.
The LL masks were defined from the field names rather than from this
documented behavior, so ANALOG_CMPR_LL_POS_CROSS_INTR_MASK() ended up
selecting bit 1 and ANALOG_CMPR_LL_NEG_CROSS_INTR_MASK() bit 0.

A new test case, added in the following commit, arms only one cross
direction at a time and checks that a matching transition fires the
callback while the opposite, never-armed direction does not; without
this fix it reproducibly fails on ESP32-C5, ESP32-P4, and ESP32-C61.

Signed-off-by: Tiago Medicci <tiago.medicci@espressif.com>
2026-07-16 11:29:17 +08:00
luoxu 5f25d81bed feat(ble): split log compression Kconfig into separate mesh and host files 2026-07-16 11:24:47 +08:00
Luo Xu 2aba002266 fix(ble): fix Bluedroid log compression for newly added modules
(cherry picked from commit 8d4f1cb608)

Co-authored-by: luoxu <luoxu@espressif.com>
2026-07-16 11:24:47 +08:00
Martin Vychodil 7b3c4fca5b Merge branch 'fix/cleanup_after_failed_nvs_set_blob_v6.0' into 'release/v6.0'
Fixed cleanup after nvs_set_blob failed on ESP_ERR_NVS_NOT_ENOUGH_SPACE (v6.0)

See merge request espressif/esp-idf!50743
2026-07-15 18:41:21 +08:00
gaoxu bdf42b6a99 ci(csi): added test for MIPI-CSI host error event 2026-07-15 18:14:36 +08:00
Aditya Patwardhan d79940bd3b fix(esp-tls): Keep deprecated use_secure_element field for compatibility
Restore the use_secure_element field in esp_tls_cfg_t, esp_tls_cfg_server_t
and httpd_ssl_config_t, and esp_transport_ssl_use_secure_element(), as
deprecated no-ops so that existing code keeps compiling. Setting them now
fails at runtime with ESP_ERR_NOT_SUPPORTED, as the feature is accessed
via the esp_key_config_t interface. To be removed in the next major release.

No compile-time deprecation attribute on this release branch; the field and
function stay warning-free here and carry only documentation notes.
2026-07-15 15:35:28 +05:30
Alexey Lapshin 8c6ac38275 feat(soc): enable zb* extensions for esp32p4 greater v3 2026-07-15 16:46:44 +07:00
Hu Rui 1dbf4678ef feat(uhci): support transmit multi buffer 2026-07-15 17:34:38 +08:00
morris f1ddd46629 Merge branch 'feat/sec_esp_drivers_v6.0' into 'release/v6.0'
fix(drivers): harden multiple peripheral drivers against local DoS and memory corruption (v6.0)

See merge request espressif/esp-idf!50557
2026-07-15 16:53:40 +08:00
wuzhenghui 68bb4a1c44 fix(esp_hw_support): disable esp32 livelock workaround before stall another core 2026-07-15 16:28:17 +08:00
morris ff81dad1bd Merge branch 'fix/legacy_twai_rx_non_iso_dlc_oob_v6.0' into 'release/v6.0'
fix(driver_twai): fixed legacy twai OOB issue when rx dlc larger than 8 (v6.0)

See merge request espressif/esp-idf!50750
2026-07-15 16:01:02 +08:00