Commit Graph
34376 Commits
Author SHA1 Message Date
zwx 76d6f3e193 fix(ieee802154): fix teardown order 2026-09-09 18:57:40 +08:00
yinqingzhao 55b54fb090 fix(phy): update esp32c5 multiple phy init data bin 2026-09-09 17:20:44 +08:00
yinqingzhao 55a52ccea6 fix(phy): fix phy init data type and multiple bin offset incorrect 2026-09-09 17:20:44 +08:00
yinqingzhao 2fb26b0083 feat(test_app): add test app for multiple phy init data 2026-09-09 17:20:26 +08:00
wuzhenghuiandCursor 7fda2351ef fix(esp_hw_support): restore brownout after deep sleep rejection on ESP32-S2
ESP32-S2 disables the brownout detector before deep sleep; if sleep is
rejected, re-init it so BOD is not left disabled (PM-519).

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-09 17:11:11 +08:00
Astha Verma 4c82b25c84 fix(nimble): Fix nimble HID service discovery 2026-09-09 14:11:51 +05:30
yi chen 369cc3d903 fix(esp_http_client): prevent silent truncation after read timeouts
A blocking transport read can return zero when no data arrives before
timeout. Passing that zero length to http_parser_execute signals EOF while
a response is incomplete, puts the parser in HPE_INVALID_EOF_STATE, and
causes later response bytes to be discarded. The shortened response can
then be treated as successful.

Skip parser execution for every zero-length transport read, not only async
reads. Also compare the raw esp_transport_read result against raw
ERR_TCP_TRANSPORT values so timeout and peer-close failures retain their
documented HTTP error classifications.

A standalone reproduction built with the unmodified HTTP parser showed the
blocking timeout transition to HPE_INVALID_EOF_STATE and loss of the
remaining 15 bytes. Skipping the zero-length parser call delivered the full
chunk and message-complete callback.

Disclosure: this fix was prepared with AI assistance (Claude) and reviewed by me before submission.

Constraint: esp_http_client_get_data returns raw transport result values before esp_transport_translate_error.
Rejected: Keep the async-only zero-length guard | blocking transport reads also return zero on timeout.
Confidence: high
Scope-risk: moderate
Directive: Do not pass a transient zero-length transport read to the HTTP parser as EOF.
Tested: standalone blocking mid-chunk timeout reproduction; source-only duplicate-comment cleanup; git diff --check
Not-tested: hardware TLS transport integration
Signed-off-by: yi chen <94xhn1@gmail.com>
2026-09-09 14:51:42 +08:00
Zhang Hai Peng 530f485c58 fix(bt): remove noisy OSI event handler enter/exit debug logs
These per-event traces fire on every async dispatch and flood BT logs
without aiding diagnosis; higher-layer traces remain for debugging.


(cherry picked from commit b9b9b8633f)

Co-authored-by: zhanghaipeng <zhanghaipeng@espressif.com>
2026-09-09 14:26:15 +08:00
Zhang Hai Peng 2e2209d693 fix(bt): update ESP32 libbtdm_app.a to 919c7f4b
- fixed dtm tx buffer leak issue


(cherry picked from commit ab7bb35192)

Co-authored-by: zhanghaipeng <zhanghaipeng@espressif.com>
2026-09-09 14:26:15 +08:00
Zhang Hai Peng ab58d739aa fix(bt/bluedroid): prefer disconnected peers when evicting overflow bonds
When the bond list is full, drop the oldest disconnected device instead
of the oldest NVS entry, and allow a per-bond except flag so selected
devices are never auto-removed.


(cherry picked from commit bf86892eef)

Co-authored-by: zhanghaipeng <zhanghaipeng@espressif.com>
2026-09-09 14:25:53 +08:00
Jin Cheng fa80443093 fix(bt/bluedroid): fixed JV disable event has no handler in Bluedroid 2026-09-09 13:54:24 +08:00
Rahul Tank c8cf7e34c1 Merge branch 'bugfix/fix_coex_crash_v5.5' into 'release/v5.5'
fix(nimble): Prevent crash in deinit when host init was not completed (v5.5)

See merge request espressif/esp-idf!52566
2026-09-09 11:18:09 +05:30
Jiang Jiang Jian 30144483d6 Merge branch 'bugfix/fix_chip_cant_sleep_after_connect_failed_v5.5' into 'release/v5.5'
fix(wifi): fix chip cant sleep when disconnecting at probe process

See merge request espressif/esp-idf!52541
2026-09-09 12:23:27 +08:00
Jiang Jiang Jian e3572650cb Merge branch 'fix/roam_fixes_v5.5' into 'release/v5.5'
Require RSSI gain before low-RSSI roam and added reason codes(v5.5)

See merge request espressif/esp-idf!52476
2026-09-09 10:58:01 +08:00
harshal.patil 950c9b1c38 fix(esp_security): cover the crypto reset coupling in the driver locks
A peripheral's reset also resets the ones it occupies, so a lock has to cover
both. Gate the ECDSA MPI lock on SOC_ECDSA_USES_MPI rather than the runtime
ecdsa_ll_is_mpi_required() and set that capability on C5, lock the Key Manager
path in esp_key_mgr.c, clean HMAC after its reset, and enable DS before the
primitives its reset covers.
2026-09-08 19:47:32 +05:30
radek.tandler da41d31a14 fix(esp_security): Stop ECDSA and Key Manager resets from corrupting concurrent crypto
ECDSA enable pulses a reset that also holds SHA in reset, and SHA shares
its DMA with AES. Key Manager enable pulses a reset that also covers the
XTS-AES flash encryption key-usage selector. Neither path was serialized
against those victims, so a hardware ECDSA/HMAC/DS operation could
corrupt a concurrent SHA/AES transfer or an in-flight encrypted flash
read.

- Take the SHA/AES lock inside esp_crypto_ecdsa_lock_acquire(), before
  MPI, matching the DS lock order (sha_aes < mpi)
- Add esp_crypto_key_mgr_enable_periph_clk_no_reset() and switch ECDSA,
  HMAC and DS to it; they only need the key-usage selector writable
- Hold esp_crypto_key_manager_lock across those clock enable/disable
  pairs so selector writes stay serialized without resetting KM
2026-09-08 19:46:19 +05:30
Shen Wei Long 5aa32e7e9f fix(ble): Check if there are illegal library files in controller lib path
(cherry picked from commit 40706bf28f)

Co-authored-by: ShenWeilong <shenweilong@espressif.com>
2026-09-08 20:10:21 +08:00
Martin Vychodil d27411ddb9 Merge branch 'fix/sdmmc_wait_for_idle_busy_poll_starving_cpu_cores_v5.5' into 'release/v5.5'
fix(sdmmc): back off between CMD13 polls while waiting for card to be ready (v5.5)

See merge request espressif/esp-idf!52534
2026-09-08 19:14:20 +08:00
Rahul Tank 78ff85eb74 fix(nimble): Prevent crash in deinit when host init was not completed 2026-09-08 15:36:52 +05:30
morris d8e64a9163 Merge branch 'bugfix/uart_extra_current_consumption_in_sleep_v5.5' into 'release/v5.5'
fix(uart): reduce current consumption in sleep mode (v5.5)

See merge request espressif/esp-idf!52348
2026-09-08 15:07:47 +08:00
zwx 36b1759428 fix(openthread): fix null pointer deref, uninitialized struct, and unbounded strcpy in spinel/RCP code 2026-09-08 14:58:15 +08:00
morris 622f84b75d Merge branch 'feat/add_timeout_return_for_dsi_panel_v5.5' into 'release/v5.5'
feat(dsi): add timeout check for lp cmd rx (v5.5)

See merge request espressif/esp-idf!52314
2026-09-08 14:45:37 +08:00
morris 9d23161ad5 Merge branch 'fix/spi_flash_keep_program_erase_in_iram_v5.5' into 'release/v5.5'
fix(spi_flash): keep program and erase paths in IRAM (v5.5)

See merge request espressif/esp-idf!51893
2026-09-08 14:43:34 +08:00
Rahul Tank 8650dcc896 fix(nimble): Add hardware error event handling as normal event 2026-09-08 12:10:59 +05:30
liuning 4b93eee0bb fix(wifi): fix chip cant sleep when disconnecting at probe process 2026-09-08 11:47:27 +08:00
Jiang Jiang Jian 69001928d0 Merge branch 'bugfix/qos_not_reported_v5.5' into 'release/v5.5'
fix(bt/controller): update ESP32 libbtdm_app.a to fix missing QoS_Setup_Cmpl event (v5.5)

See merge request espressif/esp-idf!52492
2026-09-08 10:36:02 +08:00
Island 6c9ae2761e Merge branch 'fix/fix_ble_retention_dependency_order_v5.5' into 'release/v5.5'
fix(ble): fix ble retention dependency order (5.5)

See merge request espressif/esp-idf!52464
2026-09-08 10:25:11 +08:00
Adam Múdry c70648edb6 fix(sdmmc): back off between CMD13 polls while waiting for card to be ready
The loops waiting for the card to leave its busy state started their yield
backoff at 100 ms. A card is typically busy for a few milliseconds after a
write, so the backoff never fired and every write was followed by hundreds
of back-to-back CMD13 commands. Occupying the host controller like this
slows down unrelated work on both cores, not just the calling task.

Delay between polls instead, starting at CONFIG_SD_READY_POLL_PERIOD_START_US
(100 us) and doubling. Both the delay and the configured start period are
capped at one FreeRTOS tick period, where vTaskDelay() already yields and one
command per tick is not a storm. A typical wait now costs a handful of
commands instead of hundreds.

Applies to sdmmc_wait_for_idle(), sdmmc_init_sd_wait_data_ready() and
read_tuning_block().

Closes https://github.com/espressif/esp-idf/issues/19034
2026-09-07 19:44:02 +02:00
Zhang Hai Peng b8709f9f13 fix(ble/bluedroid): restore find info PDU stop on UUID format mismatch
Restore GATT_NO_RESOURCES when sequential attributes have differing UUID
sizes so gatts_process_find_info() stops building the response PDU.


(cherry picked from commit 196cb39545)

Co-authored-by: zhanghaipeng <zhanghaipeng@espressif.com>
2026-09-07 20:38:14 +08:00
cjin 8e5df72d46 fix(ble): fix ble retention dependency order 2026-09-07 20:20:27 +08:00
Rahul Tank b45a624fd0 Merge branch 'bugfix/fix_ble_pair_attack_v5.5' into 'release/v5.5'
fix(nimble): Fix for BLERP attack (v5.5)

See merge request espressif/esp-idf!52352
2026-09-07 17:38:33 +05:30
Zhi Wei Jian aaa7312c26 feat(ble/bluedroid): reject LE re-pairing that weakens an existing bond
Add smp_repairing_is_allowed() behind BT_BLE_SMP_HARDENED_REPAIRING so a
peer cannot replace an existing bond with one that has less MITM
protection, no Secure Connections, or a shorter key. Compare a preceding
Security Request against the pairing command AuthReq, not the
association-model result, and always allow first pairing.

A refusal keeps the stored bond. Pairing-failure erase is split by link
role: default is erase as Central and keep as Peripheral.

Closes BLERP (NDSS 2026) V3, V4 and V6.


(cherry picked from commit 88ea45be73)

Co-authored-by: zhiweijian <zhiweijian@espressif.com>
2026-09-07 19:45:54 +08:00
Zhi Wei Jian 93f8ae845b fix(ble/bluedroid): harden LE bond handling across encryption
Keep the existing bond until the new pairing is encrypted, and on encryption
failure drop the link instead of clearing keys. Recovering from a peer that
really deleted the bond is opt-in through BT_BLE_SMP_UNBOND_ON_KEY_MISSING.

Closes BLERP (NDSS 2026) V5, and stops an unauthenticated Pairing Request
from dropping the stored keys (V2 exploitation).


(cherry picked from commit f864615d7d)

Co-authored-by: zhiweijian <zhiweijian@espressif.com>
2026-09-07 19:45:54 +08:00
Nachiket Kukade 055550e26e Merge branch 'fix/eloop-wifi-deinit-leak-delay_v5.5' into 'release/v5.5'
test(wifi): wait for the idle task after esp_wifi_deinit in Wi-Fi UTs (Backport v5.5)

See merge request espressif/esp-idf!52513
2026-09-07 19:36:09 +08:00
Laukik Hase 59efed194c Merge branch 'fix/tee_disallow_reentrant_sec_svc_v5.5' into 'release/v5.5'
feat(esp_tee): Backports to v5.5

See merge request espressif/esp-idf!52289
2026-09-07 16:22:43 +05:30
Sarvesh Bodakhe 57c0fb83da test(wifi): wait for the idle task after esp_wifi_deinit in Wi-Fi UTs
The Wi-Fi task deletes itself when esp_wifi_deinit() is called, and FreeRTOS
only reclaims its TCB and stack from the idle task afterwards. Test apps that
read the heap right after deinit therefore see that memory as still allocated
and report a leak, most visibly as the eloop unit tests failing on ESP32.

Wait for the idle task at every point where a test deinitialises Wi-Fi
before a leak check, replacing the single-tick delays that only matched what
esp_wifi_deinit() already waits for internally.

(cherry picked from commit bff264775a)
2026-09-07 15:47:36 +05:30
Chen Jichang b5aa9dabc3 fix(mcpwm): correct the wrong capture prescale 2026-09-07 17:06:25 +08:00
Rahul Tank 58b4f19cdf fix(nimble): Fix for BLERP attack 2026-09-07 14:00:57 +05:30
Rahul Tank 45ce9e56c8 Merge branch 'bugfix/fix_null_proc_dereference_v5.5' into 'release/v5.5'
fix(nimble): Avoid NULL proc dereference in GATT client procedures (v5.5)

See merge request espressif/esp-idf!52219
2026-09-07 13:53:50 +05:30
Jin Cheng b69c04df58 fix(bt/controller): update ESP32 libbtdm_app.a to fix missing QoS_Setup_Cmpl event 2026-09-07 12:22:38 +08:00
Jiang Jiang Jian 00cac0b72f Merge branch 'contrib/github_pr_19038_v5.5' into 'release/v5.5'
fix(esp_lcd): yield from SPI ISR when color trans done callback wakes a task (GitHub PR) (v5.5)

See merge request espressif/esp-idf!52455
2026-09-07 11:27:48 +08:00
Jiang Jiang Jian 0cdf36ae5b Merge branch 'fix/sae_pwe_ecc_fail_v5.5' into 'release/v5.5'
fix(wpa_supplicant): Assign correct return value for SAE y-construction failure (v5.5)

See merge request espressif/esp-idf!52359
2026-09-07 11:27:39 +08:00
Jiang Jiang Jian e4404da2c4 Merge branch 'debug/idf-15875-fix_v5.5' into 'release/v5.5'
fix(psram): suspend external cache during CPU freq switch on esp32p4 (v5.5)

See merge request espressif/esp-idf!51686
2026-09-07 11:27:20 +08:00
Jiang Jiang Jian 290bea2cc6 Merge branch 'fix/ringbuf_max_item_size_v5.5' into 'release/v5.5'
fix(esp_ringbuf): harden ringbuf creation sizes checks (v5.5)

See merge request espressif/esp-idf!51001
2026-09-07 11:26:54 +08:00
Wang Meng Yang 362a1776ec Merge branch 'bugfix/delete_unused_avrcp_rcb_v5.5' into 'release/v5.5'
fix(bt/bluedroid): delete the unused AVRCP acceptor RCB when A2DP open fails (v5.5)

See merge request espressif/esp-idf!52414
2026-09-06 12:36:05 +08:00
Rahul Tank 45e5ccc1e4 fix(nimble): Avoid NULL proc dereference in GATT client procedures 2026-09-06 09:54:15 +05:30
Wang Meng Yang ca6bee0af8 Merge branch 'bugfix/fix_osi_event_bug_v5.5' into 'release/v5.5'
Bugfix/fix osi event bug[backport v5.5]

See merge request espressif/esp-idf!52324
2026-09-06 12:14:33 +08:00
tarun.kumar dec90d82d6 fix(wifi) : Added more reason codes for blacklist roam 2026-09-04 18:23:15 +05:30
tarun.kumar 0f6972bf92 fix(wifi): Preserve roam_config ABI and clamp roam diff
Append low_rssi_roam_diff so existing struct members keep their offsets,
and clamp runtime values to 1-99 so determine_best_ap() cannot see 0 or wrap.
2026-09-04 18:23:15 +05:30
tarun.kumar 9648cc51a1 fix(wifi): Require RSSI gain before low-RSSI roam
Low-RSSI roaming used determine_best_ap(0), so a 1 dB better AP was
enough and nearby APs could ping-pong. Add ESP_WIFI_ROAMING_LOW_RSSI_ROAM_DIFF
(default 5 dB) as hysteresis for that path.
2026-09-04 18:23:15 +05:30