Commit Graph
54490 Commits
Author SHA1 Message Date
peter.marcisovsky 8a9a79468e fix(usb_device_example): Remove non-existing tinyusb reset weak callback 2026-07-22 19:41:02 +08:00
Mahavir Jain c566ace1f6 fix(esp_system): fixes build failure with XIP PSRAM + BSS/NoInit in external memory
Declare ext_ram_xip_seg as a distinct region overlapping drom_seg at the
same origin (the esp32s3/c5/c61/h4 pattern) instead of aliasing drom_seg,
so .ext_ram.dummy has its own location counter and .ext_ram.bss reclaims
the VMA space of NOLOAD rodata (.rodata_wlog_*), saving up to one MMU
page of PSRAM on esp32s31. No layout change on esp32p4.

Closes https://github.com/espressif/esp-idf/issues/18791
Related https://github.com/espressif/esp-idf/issues/14992
2026-07-22 16:39:25 +05:30
morris 49fba58f08 fix(riscv_trace): protect shared RCC register access with PERIPH_RCC_ATOMIC
riscv_trace_ll_enable_bus_clock and riscv_trace_ll_reset_register operate
on shared HP_SYS_CLKRST registers and were called concurrently from both
cores during SECONDARY init, creating RMW race conditions.

Move the clock/reset logic out of the HAL layer into
esp_riscv_trace_early_init, protected by PERIPH_RCC_ATOMIC() spinlock.
Wrap the LL functions with macros that enforce the caller must be inside
a PERIPH_RCC_ATOMIC() critical section at compile time.
2026-07-22 19:02:58 +08:00
Chen Ji Chang 1421a250a2 Merge branch 'doces/add_pcnt_pull_migreation_guide' into 'master'
docs(pcnt): add gpio pull mode migration guide

Closes IDFGH-18004

See merge request espressif/esp-idf!51009
2026-07-22 19:01:23 +08:00
Konstantin Kondrashov 217fc2b7e5 Merge branch 'fix/esp_timer_task_dispatch_wedge' into 'master'
fix(esp_timer): Fix esp_timer task dispatch stall

Closes IDFGH-17935

See merge request espressif/esp-idf!50788
2026-07-22 13:47:58 +03:00
sonika.rathi 78e78d7996 fix(nvs_flash): initialize accumulatedCRC32 in cmpItem 2026-07-22 10:45:05 +02:00
Wang Mengyang 53b357790b fix(bt): Fixed blocking during LMP packet type negotiation on ESP32-S31
In the Bluetooth connections with some smartphones, communication can possibly be blocked
during packet type negotation, when ESP32-S31 attempts to finalize the ACL-U transmission
and waits for the last Tx ACL-U packet to be transmitted, but peer device rejects the
packet with FLOW=STOP in its packet, thus causing a deadlock.

Closes https://github.com/espressif/esp-idf/issues/18797
2026-07-22 16:41:08 +08:00
Roland Dobai 480d5f2559 Merge branch 'chore/remove_old_root_managed_components_tests' into 'master'
chore: Remove old root managed components tests

See merge request espressif/esp-idf!51047
2026-07-22 10:36:58 +02:00
Ivan Grokhotkov d3766ffdea Merge branch 'feature/build-file-command' into 'master'
feat: add idf.py build-file command for standalone C files

Closes IDF-15453

See merge request espressif/esp-idf!47618
2026-07-22 10:34:38 +02:00
wuzhenghui 09253d3f48 feat(esp_security): make esp32s31 on-demand crypto clock management optional 2026-07-22 16:32:46 +08:00
wuzhenghui a04dc898db feat(esp_security): support s31 security clock management 2026-07-22 16:32:45 +08:00
wuzhenghui c7de92feda change(hal): rename PLL_F80M to REF_80M for esp32s31 peripherals clock defination 2026-07-22 16:32:13 +08:00
wuzhenghui 90cb8a760d feat(esp_hw_support): disable all unused pll source in rtc_clk_init to save power 2026-07-22 16:32:12 +08:00
wuzhenghui 7c75525edd fix(driver): fix drivers clock management 2026-07-22 16:32:12 +08:00
wuzhenghui 11ccd4c304 feat(esp_hw_support): support esp32s31 clock tree management 2026-07-22 16:32:12 +08:00
Jiang Jiang Jian ade59336b6 Merge branch 'bugfix/fix_crash_issue_on_esptouch_v2' into 'master'
fix(wifi): added validation for password and reserved data length in ESPTouch v2

Closes WIFI-7448, WIFI-7484, WIFI-7482, and WIFI-7444

See merge request espressif/esp-idf!50110
2026-07-22 16:27:15 +08:00
morris 44247cf304 Merge branch 'refactor/extract-esp_hal_debug_assist' into 'master'
refactor(hal): extract assist_debug, debug_probe and trace into esp_hal_debug_assist

See merge request espressif/esp-idf!50968
2026-07-22 16:15:13 +08:00
wuzhenghui b697c31f40 fix(esp_hw_support): fix deepsleep deadlock if threadsafe claim is not enabled 2026-07-22 15:26:31 +08:00
Wang Meng Yang cfb35e1a4a Merge branch 'bugfix/idf_ci_example_avrcp' into 'master'
fix(bt/example): Add log in the failure path for avrcp_ct_metadata example

Closes IDFCI-10118

See merge request espressif/esp-idf!50651
2026-07-22 15:16:25 +08:00
Chen Jichang f0fd8fb0d0 docs(pcnt): add gpio pull mode migration guide
Closes https://github.com/espressif/esp-idf/issues/18862
2026-07-22 14:47:22 +08:00
liqigan 0564b09e86 fix(bt/bluedroid): Fixed use after free issue on osi_event_delete 2026-07-22 14:41:20 +08:00
liqigan 39b4b3f329 fix(bt/bluedroid): Fixed HID host reconnection bug and enabled load HID devices
Closes https://github.com/espressif/esp-idf/issues/18335
2026-07-22 14:41:20 +08:00
liqigan 540a4216df change(bt/bluedroid): Refactored HCI ACL datapath 2026-07-22 14:41:20 +08:00
liqigan db12b3c279 change(bt/bluedroid): Refactored HID host datapath 2026-07-22 14:41:18 +08:00
Wang Meng Yang bc428c91d5 Merge branch 'bugfix/bredr_critical_bugs' into 'master'
bugfix: fix issues raised from AI review

See merge request espressif/esp-idf!49755
2026-07-22 14:31:28 +08:00
Astha Verma c653c09b9e fix(nimble): Handle Read Remote Supported Features failure correctly 2026-07-22 11:58:57 +05:30
Alexey Lapshin 631ad9033c feat(build): add RISC-V ZCMP post-link workaround check
Validate linked RISC-V executables when
CONFIG_COMPILER_ENABLE_RISCV_ZCMP is enabled on affected chips.
Disassemble each function and reject mstatus.MIE clears that lack an
earlier mintthresh write of 0xff.

Handle csrrci, csrrw, and register-mask csrrc patterns while ignoring
csrrs. Add build-only coverage for valid and invalid sequences with
CMake v1 and v2.

Stop the hardware stack guard before switching stacks during restart,
and keep ZCMP disabled for TEE test apps that still require the
workaround.
2026-07-22 13:04:20 +07:00
Island 904d960cd6 Merge branch 'fix/ble-log-store-access-fault' into 'master'
fix: Ensure BLE Log Global Variables in Internal RAM

See merge request espressif/esp-idf!51024
2026-07-22 14:02:23 +08:00
Konstantin Kondrashov 35e5def13c Merge branch 'fix/bootloader_log_format_drom_vaddr' into 'master'
fix(bootloader): use correct format specifier for MMU_LL_END_DROM_ENTRY_VADDR

Closes IDFGH-17999

See merge request espressif/esp-idf!50927
2026-07-22 08:59:12 +03:00
Konstantin Kondrashov 66b5056f23 fix(bootloader): use correct format specifier for MMU_LL_END_DROM_ENTRY_VADDR 2026-07-22 08:59:11 +03:00
wuzhenghui 16a59e04fe feat(esp_pm): implement tickless idle test for WAITI mode 2026-07-22 12:55:53 +08:00
wuzhenghui 0aa75e183b feat(esp_pm): add tickless idle support in WAITI mode to reduce power consumption 2026-07-22 12:55:53 +08:00
wuzhenghui 306d54b6d5 feat(int_wdt): add pause and resume functions for cpu1 interrupt watchdog 2026-07-22 12:55:52 +08:00
wuzhenghui 412bce6544 fix(rtc_timer): disable target before setting wakeup time to avoid intermediate states 2026-07-22 12:55:52 +08:00
Chen Chen 18e4aae030 feat(mcpwm): fix mcpwm clock init failure
Closes https://github.com/espressif/esp-idf/issues/18666
Closes https://github.com/espressif/esp-idf/issues/18777
2026-07-22 11:41:26 +08:00
zhuanghang bdd962c685 feat(phy): update phy lib for esp32s31 & esp32c6 for track 2026-07-22 11:11:20 +08:00
Ivan Grokhotkov (bot)andClaude Fable 5 b3a0e166fe feat: add compile_options support to idf.py build-file
Allow specifying extra compiler flags (warning flags, preprocessor
definitions, etc.) via a new 'compile_options' entry in the
idf-build-file frontmatter. The options are applied to the source
file via target_compile_options in the generated main component
CMakeLists, with CMake quoting so that flags like -DMSG="hello world"
reach the compiler exactly as written.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-21 22:04:41 +02:00
Ivan GrokhotkovandClaude Fable 5 16275df0a1 feat: add idf.py build-file command for standalone C files
Add a new idf.py extension that allows building standalone C files
without requiring full project boilerplate. Source files can include
optional YAML frontmatter in block comments to specify sdkconfig
options, component dependencies, and target configuration.

When the frontmatter configuration changes, the stale sdkconfig is
removed so the new defaults are applied, and a target change also
clears the build directory since IDF_TARGET is pinned in the CMake
cache.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-21 22:04:41 +02:00
Konstantin Kondrashov 10f8b195b0 Merge branch 'fix/log-unsigned-msec-format' into 'master'
fix(log): use unsigned format specifier for esp_log_system_timestamp msec

See merge request espressif/esp-idf!50989
2026-07-21 18:32:49 +03:00
Konstantin Kondrashov 95bba8e982 Merge branch 'fix/heap-trace-calloc' into 'master'
fix(heap): trace heap_caps_calloc allocations in standalone heap tracing

Closes IDF-15995

See merge request espressif/esp-idf!50990
2026-07-21 17:55:53 +03:00
Daniel Paul ee93f899c2 chore: Remove old root managed components tests 2026-07-21 16:01:27 +02:00
yi chen 62e507ab8e fix(log): fix out-of-bounds reads in binary log for buffer log apis
- Fix MAX(len,2) reading beyond buffer when len=1
- Fix buffer_len=0 ambiguity with strlen fallback
- Add BUFFER_LEN_NOT_SET sentinel (-1)
- Read exactly len bytes, not forced minimum

Merges https://github.com/espressif/esp-idf/pull/18825
2026-07-21 16:47:50 +03:00
Konstantin Kondrashov 268a9b071f Merge branch 'fix/esp-event-security-fixes' into 'master'
fix(esp_event): multiple security and stability fixes

Closes SEC-064, SEC-219, SEC-220, SEC-221, SEC-222, and IDFGH-17955

See merge request espressif/esp-idf!50442
2026-07-21 16:27:51 +03:00
Adam Múdry b1755caa63 Merge branch 'fix/sdmmc_bdl_casting' into 'master'
fix(sdmmc): BDL calculate sectors cast fix

Closes IDFGH-18017

See merge request espressif/esp-idf!51039
2026-07-21 15:15:33 +02:00
Konstantin Kondrashov 82e6c831e7 fix(esp_event): free queued legacy cleanup ctx on loop delete
When a loop is deleted while an internal legacy "cleanup" event is still
queued (posted by a deferred self-unregistration from within a handler),
esp_event_loop_delete() drained the queue but only freed the post payload,
leaking the heap copy of the handler context allocated for the legacy path.

Free ctx->handler_ctx for queued legacy cleanup events while draining the
queue, mirroring the cleanup done in esp_event_loop_run().

Add a regression test that leaves a legacy cleanup event queued and asserts
no memory is leaked on loop deletion.
2026-07-21 15:33:47 +03:00
Konstantin Kondrashov e8ffb477a0 fix(esp_event): clear running_task before releasing mutex on tick timeout
When esp_event_loop_run() exited via the ticks-expired break path,
loop->running_task was left pointing to the current task handle.
Any subsequent trylock in esp_event_handler_unregister_with_internal()
would see a stale non-NULL running_task and take the wrong code path.
2026-07-21 15:25:58 +03:00
Konstantin Kondrashov 9d2d32524b fix(esp_event): prevent UAF race between post and loop delete (SEC-222)
esp_event_post_to() could access loop->queue / loop->mutex after
esp_event_loop_delete() freed them when both ran concurrently.

Introduce esp_event_loop_state_t with:
- posts_in_flight: reference-count incremented atomically (under
  state.lock spinlock) before touching any loop resources, decremented
  on every exit path via goto on_err.
- deleting: atomic_bool set by esp_event_loop_delete() to block new
  posts from entering the critical section.

esp_event_loop_delete() sets deleting=true, then busy-waits (releasing
and re-acquiring loop->mutex each tick) until posts_in_flight reaches
zero before proceeding with teardown.

esp_event_isr_post_to() performs a lock-free atomic_load of deleting as
a best-effort guard; ISR context cannot participate in the spinlock
protocol but the window is documented and accepted.
2026-07-21 15:25:58 +03:00
Konstantin Kondrashov 736275e562 fix(esp_event): skip dispatch for internal cleanup events (SEC-221)
After processing an esp_event_handler_cleanup sentinel, execution fell
through into the regular dispatch block. Every loop-level (ANY_BASE/
ANY_ID) handler was invoked with base="cleanup" and event_data pointing
at the internal esp_event_remove_handler_context_t struct.

Consequences:
- Information disclosure: internal handler addresses and loop instance
  pointer are exposed to every loop-level handler.
- UAF: if a handler stores event_data for later use, post_instance_delete
  frees the ctx, turning the stored pointer into a dangling reference.
- Logic corruption: handlers that switch on base with a default branch
  misbehave on every unregister anywhere in the system.

Fix: wrap the regular dispatch block in an else clause so it is skipped
entirely for cleanup events. post_instance_delete, ticks accounting, and
xSemaphoreGiveRecursive remain in the shared tail executed for both paths.

Closes SEC_221
2026-07-21 15:25:57 +03:00
Konstantin Kondrashov 4ab4d5b894 fix(esp_event): use recursive mutex API in handler unregister (SEC-220)
1) loop->mutex is created with xSemaphoreCreateRecursiveMutex(). FreeRTOS
requires that recursive mutexes are only acquired and released with
xSemaphoreTakeRecursive / xSemaphoreGiveRecursive.

esp_event_handler_unregister_with_internal() used the non-recursive
xSemaphoreTake(loop->mutex, 0) / xSemaphoreGive(loop->mutex) in the fast
path. The non-recursive Take bypasses uxRecursiveCallCount bookkeeping;
if the same task subsequently takes the mutex recursively (e.g. re-entry
from a handler or a follow-up register), the call count drifts. The
non-recursive Give then unconditionally drops the holder, allowing another
task to acquire the mutex while the original task still believes it holds
the lock — a full lock violation on the handler list leading to UAF and
potential RCE on attacker-driven event floods.

Fix: replace xSemaphoreTake/xSemaphoreGive with the Recursive variants in
the fast (try-take with timeout 0) path of unregister_with_internal.

2) avoid use-after-free when unregistering handler from a callback

The recursive try-lock introduced in SEC-220 succeeds re-entrantly when a
handler unregisters itself from within its own callback, causing the handler
node to be freed immediately while the dispatch loop still writes profiling
counters to it after the callback returns. Route the in-callback case to the
deferred cleanup path and only free directly once no dispatch is active.

Closes SEC_220
2026-07-21 15:25:57 +03:00
Konstantin Kondrashov 2c935ea861 fix(esp_event): protect is_handler_registered traversal with mutex (SEC-219)
esp_event_is_handler_registered() walked loop_nodes, base_nodes, id_nodes
and handler lists with no lock held, then released an unowned mutex at the
'out:' label via xSemaphoreGive().

Concurrent register/unregister/delete operations can free handler nodes
during the unlocked walk (SLIST UAF). The xSemaphoreGive on an unowned
recursive mutex corrupts the recursive call-count of any task that
legitimately holds the mutex.

Fix:
- Take loop->mutex with xSemaphoreTakeRecursive before the traversal.
- Replace xSemaphoreGive at the 'out:' label with xSemaphoreGiveRecursive
  so every exit path holds the mutex for exactly one balanced take/give.

Closes SEC_219
2026-07-21 15:25:57 +03:00