Extend the test peripheral with receipt timestamps and an auto-recycle
hook so runtime tests can observe handoff latency and sustain arrivals from
dispatch completion.
Add a standalone Unity app covering fixed first-submission deadlines,
callback-entry batch drain, shared ESP timer task fairness, periodic
timestamp light-sleep behavior, synchronous flush, dispatch latency,
deinit races, bounded inflight peaks, and timeout conversion at both
supported tick rates. Verify FIFO delivery and reject delayed-consumer and
extra-marker false positives.
Render BLE_LOG_RT_PERF lines in the performance log parser and
cross-reference the runtime and performance apps from their READMEs.
Replace the dedicated BLE Log FreeRTOS task with a deferred esp_timer
batch dispatch. The first submission anchors a one-shot 1 ms deadline;
the callback drains the queue depth captured at entry and schedules the
next fixed defer only for arrivals left behind. Later submissions cannot
move the current deadline, and no fixed batch-size cap limits throughput.
Protect queue and timer lifetime with runtime references. Drain queued
submissions before ble_log_lbm_flush_all_trans waits for transport
ownership to return, so synchronous flush does not depend on the deferred
alarm firing.
Keep the defer alarm as a light-sleep wake source and select
ESP_TIMER_IN_IRAM. Timestamp synchronization uses the shared ESP timer task
with skipped unhandled events, so it neither wakes light sleep nor replays
missed periods. Retain legacy task and trigger symbols as hidden no-op
sdkconfig compatibility options.
New ble_log_test app captures the runtime hook output through the test
peripheral and validates the version info frame: source code, BLE Log
version, a hex-valid idf commit that must be non-zero, per-lib commit
fields non-zero exactly when the matching lib is linked, and chip
model/revision matching esp_chip_info(). The README carries the
generated empty Supported Targets table to match the build-test
manifest.
The test drives transports via sustained writes instead of
ble_log_flush(): the flush window disables the module, so hook frames
written during a flush would be dropped.
Also move .build-test-rules.yml from ble_log_perf_test/ to the
test_apps/ root (one manifest entry per app, as elsewhere in ESP-IDF).
Both apps stay disabled until BLE Log test runners are available.
Verified: full esp32c6 build of the app; the build-test checker's own
parsing logic confirms the README table matches the manifest.
Replace the 2-byte BLE Log info record with a 58-byte version info
frame (BLE_LOG_VERSION 5 -> 6; the abandoned branch that claimed the
version-6 slot frees it, so the overall bump stays 5 -> 6):
- idf build commit (12 bytes), injected at build time by
register_ble_log_idf_commit() next to the other register_* helpers;
the git probe is only trusted when the IDF tree itself is a
repo/worktree, since rev-parse walks up parent directories
- controller, btdm_common, BLE Mesh and BLE Audio lib commits (10
bytes each, zero-padded), every getter guarded by the exact
condition that links its lib, so configs without the lib leave the
field zero (no link errors)
- chip model and revision from esp_chip_info() at runtime
Lib strings are copied NUL-safely instead of assuming a fixed hash
length; the mesh commit is the substring after the last space of
bt_mesh_v11_commit_str. Frame layout is pinned by a static assert.
Verified on target: esp32, esp32c3, esp32c5 and esp32h4 boards (the
h4 run covers controller + btdm_common + mesh in one build); the
audio-enabled build is blocked by pre-existing esp_ble_audio compile
errors on this base (audio symbol verified with nm instead).
Add smp_repairing_is_allowed() behind BT_BLE_SMP_HARDENED_REPAIRING so a
peer cannot replace an existing bond with one that has less MITM
protection, no Secure Connections, or a shorter key. Compare a preceding
Security Request against the pairing command AuthReq, not the
association-model result, and always allow first pairing.
A refusal keeps the stored bond. Pairing-failure erase is split by link
role: default is erase as Central and keep as Peripheral.
Closes BLERP (NDSS 2026) V3, V4 and V6.
Keep the existing bond until the new pairing is encrypted, and on encryption
failure drop the link instead of clearing keys. Recovering from a peer that
really deleted the bond is opt-in through BT_BLE_SMP_UNBOND_ON_KEY_MISSING.
Closes BLERP (NDSS 2026) V5, and stops an unauthenticated Pairing Request
from dropping the stored keys (V2 exploitation).