Commit Graph
53616 Commits
Author SHA1 Message Date
Song Ruo Jing a59daff749 fix(uart): fix uart sw flow ctrl XOFF char write to wrong reg on ESP32C6
Add software flow control test case

Introduced in e6ef4d1791

Closes https://github.com/espressif/esp-idf/issues/18779
2026-07-15 16:45:39 +08:00
wuzhenghui 981208a9ad fix(esp_hw_support): disable esp32 livelock workaround before stall another core 2026-07-15 16:10:51 +08:00
Aditya Patwardhan 39a219331c Merge branch 'feature/update-openocd-to-v0.12.0-esp32-20260703_v6.1' into 'release/v6.1'
feat(tools): update openocd version to v0.12.0-esp32-20260703 (v6.1)

See merge request espressif/esp-idf!50502
2026-07-15 12:26:55 +05:30
wanckl fa157ab86d fix(driver_twai): add fd test on ci 2026-07-15 11:22:56 +08:00
wanckl 5912fe2107 feat(driver_twai): fd hardware support time trigger trans 2026-07-15 11:22:45 +08:00
wanckl a415ba1fcf fix(driver_twai): fixed legacy twai OOB issue when rx dlc larger than 8 2026-07-15 10:46:52 +08:00
radek.tandler f26db8177e fix(nvs_flash): fixed cleanup after nvs_set_blob failed on ESP_ERR_NVS_NOT_ENOUGH_SPACE
- fixed identification of blob parts to be cleaned by using right starting chunk index
  - improved localisation of blobs for cases where some of pages get reclaimed
  - created host test cases covering the edge cases above
2026-07-14 16:42:27 +02:00
yi chen e9c3ed8fb4 fix(wear_levelling): guard WL_Flash::write()/read() against size==0 underflow
WL_Flash::write() and WL_Flash::read() computed:

    uint32_t count = (size - 1) / this->cfg.wl_page_size;

`size` is `size_t` (unsigned). Neither the public wl_write()/wl_read() API
(wear_levelling.cpp), nor the newer wl_bdl_write()/wl_bdl_read() block-device
path (wl_blockdev.cpp), reject size == 0 before calling into WL_Flash, and
wear_levelling.h does not document size == 0 as invalid (a 0-byte
write/read is a reasonable no-op, mirroring POSIX write()/read() with
count == 0).

When size == 0, `size - 1` wraps around to SIZE_MAX, so `count` becomes an
enormous page count instead of 0. The functions then loop that many times,
reading (write()) or writing (read()) `wl_page_size` bytes per iteration
through the flash partition, immediately walking past the caller-supplied
buffer on the very first iteration:

  - write(): out-of-bounds *read* from the caller's `src` buffer.
  - read():  out-of-bounds *write* into the caller's `dest` buffer -- the
             more severe case, since it corrupts caller memory with flash
             content instead of merely over-reading.

Verified with a standalone reproduction that compiles the unmodified
WL_Flash.cpp against a mock Flash_Access partition: calling
`wl.write(0, an_8_byte_buffer, 0)` with no other change immediately
segfaults (confirmed count == 0xFFFFFFFF for wl_page_size == 4096); with
this fix applied the same call returns ESP_OK without touching memory
outside the buffer, and normal non-zero-size read/write is unaffected.

Add an early `size == 0` return (mirroring the existing `!initialized`
guard) to both functions, and a host_test regression case exercising
wl_write()/wl_read() with size == 0 through the public API.

Disclosure: this fix was prepared with AI assistance (Claude) and reviewed
by me before submission.

Signed-off-by: yi chen <94xhn1@gmail.com>
2026-07-14 12:22:53 +02:00
Chen ChenandCursor 0fbbcd7271 fix: update flash encryption mock build check
Use a non-deprecated bootloader support API in the mock build test.
Keep the test focused on validating the generated bootloader support mock.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-07-14 17:30:29 +08:00
Vincent Hamp 9980a9f53a fix(mocks): add missing esp_hal_* includes 2026-07-14 17:30:29 +08:00
Akshat Agrawal 9c42f5f06f fix(nan): Transmit NULL packet correctly to avoid NDP termination 2026-07-14 10:31:40 +05:30
Shreyas Sheth 1519772ea8 fix(wpa_supplicant): Fix issues related to pmkid mismatch and eloop for dpp 2026-07-14 10:31:19 +05:30
tarun.kumar abe397bdf8 fix(wifi) : Correct blacklist flag
- Fixes state desync where global blacklist was cleared but blacklist bss flag was true causing rejection of correct AP as well.
2026-07-14 10:31:06 +05:30
zhangyanjiao a83db6a045 fix(wifi): fixed the offchan tx fail when SPIRAM_TRY_ALLOCATE_WIFI_LWIP enabled 2026-07-14 10:30:52 +05:30
Zhang Hai Peng b50cef44fb docs(ble/bluedroid): fix markdown formatting in example docs
(cherry picked from commit dba450de6b)

Co-authored-by: zhanghaipeng <zhanghaipeng@espressif.com>
2026-07-14 10:37:22 +08:00
Zhang Hai Peng a6404dcf8d fix(ble/bluedroid): downgrade numeric comparison log to warning
(cherry picked from commit 72a49ed53b)

Co-authored-by: zhanghaipeng <zhanghaipeng@espressif.com>
2026-07-14 10:37:22 +08:00
Zhang Hai Peng f4c2b75897 fix(ble/bluedroid): preserve ext adv state when set params fails
Only update extend_adv_cb after HCI Set Extended Advertising
Parameters succeeds, so a failed update does not corrupt cached
legacy_pdu and related fields used by adv data validation.


(cherry picked from commit 31bd80fee8)

Co-authored-by: zhanghaipeng <zhanghaipeng@espressif.com>
2026-07-14 10:37:21 +08:00
Zhang Hai Peng 169bf6975b fix(ble/bluedroid): reject invalid ATT error code 0x00 on client
Map received error reason 0x00 to GATT_UNKNOWN_ERROR so the client
does not report GATT_SUCCESS with zero-length data on malformed errors.


(cherry picked from commit 1b6f9380f4)

Co-authored-by: zhanghaipeng <zhanghaipeng@espressif.com>
2026-07-14 10:36:38 +08:00
Zhang Hai Peng be95975fee fix(ble/bluedroid): use sr_cmd status for GATT server error rsp
When sending an ATT error response after a failed server operation,
use p_tcb->sr_cmd.status instead of the last app callback status so
invalid error code 0x00 is not sent to the peer.


(cherry picked from commit 4c0488d92a)

Co-authored-by: zhanghaipeng <zhanghaipeng@espressif.com>
2026-07-14 10:36:36 +08:00
Zhang Hai Peng 96b27367a1 fix(ble/bluedroid): match read-multiple-var responses by handle
(cherry picked from commit 979c7dc567)

Co-authored-by: zhanghaipeng <zhanghaipeng@espressif.com>
2026-07-14 10:36:34 +08:00
Zhang Hai Peng 2bb2f01dd3 fix(ble/bluedroid): match read-multiple responses by handle
Read Multiple may mix stack auto-responses with app async responses,
so multi_rsp_q order can differ from the request handle order. Look up
each response by handle (with occurrence for duplicates) instead of
walking the queue by index, and treat opcode-only buffers as empty.


(cherry picked from commit f91a41510c)

Co-authored-by: zhanghaipeng <zhanghaipeng@espressif.com>
2026-07-14 10:36:33 +08:00
yi chen e8e1987a6a fix(vfs): use MAX_FDS instead of VFS_MAX_COUNT when clearing fd table on unregister
esp_vfs_unregister_with_id() scanned only the first VFS_MAX_COUNT
(default 8, max 20) slots of s_fd_table[MAX_FDS] (MAX_FDS = FD_SETSIZE,
64 on non-Cygwin targets) when clearing stale references to the
unregistered VFS. Every other loop over s_fd_table in this file
(and in vfs_calls.c) correctly bounds on MAX_FDS.

Any global fd >= VFS_MAX_COUNT that was still open against the VFS
being unregistered was left with a stale vfs_index pointing at a slot
that esp_get_free_index() can immediately hand out to the next
esp_vfs_register*() call, causing later operations on that fd to be
routed into an unrelated filesystem's context.

Signed-off-by: yi chen <94xhn1@gmail.com>
2026-07-13 15:58:26 +02:00
Guillaume Souchere 150a067da5 fix(console): Clamp linenoise cols field to 80 if getColums returns less than that 2026-07-13 12:15:56 +02:00
Guillaume Souchere cad3ef220e fix(console): Fix security code review findings 2026-07-13 12:15:56 +02:00
gaoxu a0be9bdfbd ci(csi): added test for MIPI-CSI host error event 2026-07-13 18:03:49 +08:00
gaoxu 666326e55c feat(csi): add MIPI-CSI host error event 2026-07-13 18:03:49 +08:00
morris 13282c44b0 test(drivers): run flash encryption apps on real hardware
Replace the virtual efuse flash-encryption flow in parlio, rmt, and lcd
test apps with real-device flash_enc configs so CI can validate the same
path used on encryption runners.
2026-07-13 17:13:24 +08:00
morris f91e2baa41 feat(jpeg): simplify decoder example and add pytest coverage 2026-07-13 16:18:51 +08:00
Samuel Obuch 88f7f94bc9 feat(tools): update openocd version to v0.12.0-esp32-20260703 2026-07-13 09:53:58 +02:00
Chen Chen dcea873c15 docs(i2s): add note for ws setting under DEFAULT config
Closes https://github.com/espressif/esp-idf/issues/18744
2026-07-13 15:23:19 +08:00
C.S.M 9adcf8677b feat(psram): Add unencrypted region for psram for esp32s31 2026-07-13 15:01:29 +08:00
C.S.M e92e669dee fix(jpeg): JPEG can encode and decode in encryption situation 2026-07-13 15:00:31 +08:00
Chen Chen a907115eba change(i2s): allow config tx sync params while tx channel is running 2026-07-13 14:43:55 +08:00
Chen Chen b8218f4fe1 refactor(i2s): combine separate callback registers into single one 2026-07-13 14:43:55 +08:00
Chen Chen c27bd91874 feat(i2s): release i2s tx sync APIs 2026-07-13 14:43:55 +08:00
Chen Chen f44f4a82e6 feat(i2s): support TX FIFO sync on esp32s31 2026-07-13 14:43:55 +08:00
morris a28640f417 fix(i2c): remove unused but set variables 2026-07-13 14:40:45 +08:00
Ashish Sharma 8d8068aee3 fix(esp_tee): fix DS-lock leak, intr-matrix OOB, calloc overflow, attestation leak 2026-07-13 14:40:44 +08:00
Ashish Sharma 2a63a05a85 fix(esp-tls): reject NULL host/url in plain-TCP and async HTTP connect 2026-07-13 14:40:44 +08:00
Ashish Sharma e4304fab76 fix(mbedtls): validate crypto input lengths (TEE OOB, auth-bypass, overflows) 2026-07-13 14:40:44 +08:00
Ashish Sharma e382f878cc fix(esp_https_server): free TLS session on transport_ctx OOM in httpd_ssl_open 2026-07-13 14:40:44 +08:00
Ashish Sharma 35227e41e9 fix(esp_hal_security): clamp tag_len in aes_hal_gcm_read_tag to prevent OOB 2026-07-13 14:40:44 +08:00
Ashish Sharma bcfb0407f9 fix(bootloader_support): guard NULL efuse digest slot in secure-boot verify 2026-07-13 14:40:44 +08:00
Ashish Sharma ef4ecd0591 fix(esp_http_client): fix digest-auth leaks and credential/handle use-after-free 2026-07-13 14:40:44 +08:00
Ashish Sharma b589180b8b fix(esp_http_server): close UAF/double-free, buffer underflows, and OOB read 2026-07-13 14:40:44 +08:00
Ashish Sharma 9843bcc8dc fix(app_update): close OOB read, rollback-guard gap, and length underflow 2026-07-13 14:40:44 +08:00
hebinglin 0682c52828 fix(esp_hw_support): fix xtal unstable when carry 154 and ble cases 2026-07-13 12:11:49 +08:00
morris 0f3a788f16 fix(sdspi): reject oversized pre-read data before block receive
Guard start_command_read_blocks against cards that place TOKEN_BLOCK_START so early that extra_data_size exceeds the bytes expected on the current iteration. Without this check, the unsigned subtraction for will_receive underflows and propagates into memset, SPI transaction length, and memcpy counts against the fixed 516-byte block buffer.
2026-07-13 11:18:12 +08:00
morris f1cc319c2d fix(spi_slave): free DMA-private buffers when transaction queue is full
spi_slave_queue_trans calls spi_slave_setup_priv_trans to allocate
DMA buffers, then tries xQueueSend. If the queue is full the function
returns ESP_ERR_TIMEOUT without freeing those buffers, leaking up to
2 * max_transfer_sz per failed call. Call spi_slave_uninstall_priv_trans
before returning the timeout.
2026-07-13 11:18:12 +08:00
morris 2ab4b39ce5 fix(jpeg): release platform mutex on semaphore/pm-lock allocation failure
jpeg_acquire_codec_handle acquires s_jpeg_platform.mutex at entry
but two ESP_RETURN_ON_* macros (semaphore-create and PM-lock-create
failure) return without releasing it. Replace with ESP_GOTO_ON_*
that jumps to a cleanup label which frees partial resources, NULLs
the codec pointer, and releases the mutex.
2026-07-13 11:18:12 +08:00