Commit Graph
52662 Commits
Author SHA1 Message Date
Mahavir Jain 3c828801b0 Merge branch 'docs/update_vulnerability_list_19055026' into 'master'
docs(vulnerabilities): sync vulnerability list for 5 advisories

See merge request espressif/esp-idf!48691
2026-05-19 19:44:56 +05:30
igor.masar 7d0344ac39 feat(usb): Enable ESP32-S31 USB device examples
Enable ESP32-S31 in the USB device example build rules, supported
target tables, USB PHY pin mapping, and pytest target parametrization.

The target supports USB-OTG through its USB 2.0 PHY. Keep ESP32-S31
USB device tests marked as temporary CI skips until runners with the
usb_device tag are available.
2026-05-19 15:10:47 +02:00
sonika.rathi 44e2d244e8 fix(nvs_flash): scope NVS unity tests to correct CI configs 2026-05-19 15:09:31 +02:00
wuzhenghui 858ecf6f70 feat(esp_hw_support): check psram data is not corrupted after lightsleep 2026-05-19 21:01:21 +08:00
Konstantin Kondrashov 1ced5355fd feat(docs): Update efuse doc for H21 2026-05-19 15:38:19 +03:00
Shu Chen 61eea2fc4f Merge branch 'bugfix/openthread_exclude_cve' into 'master'
fix(openthread): exclude CVE-2026-8369 from the list

See merge request espressif/esp-idf!48552
2026-05-19 12:26:13 +00:00
Konstantin Kondrashov b0da67ab1d feat(docs): Update efuse doc for H4 2026-05-19 15:17:50 +03:00
yinqingzhao 6a29152dec feat(wifi): update itwt example for different chips 2026-05-19 20:00:04 +08:00
Chen Ji Chang ee9e481ae4 Merge branch 'feat/support_lcd_gdb_buffer_display' into 'master'
feat(lcd): provide a gdb extension to dump buffer

Closes IDF-15296

See merge request espressif/esp-idf!47902
2026-05-19 19:37:37 +08:00
Ivan Grokhotkov fef508583a feat(tools): update qemu version to esp_develop_9.2.2_20260417 2026-05-19 12:36:55 +01:00
C.S.M 004a21f3df Merge branch 'feat/usb_serial_jtag_s31' into 'master'
feat(usj): Add usj support on esp32s31

Closes IDF-14788

See merge request espressif/esp-idf!48566
2026-05-19 19:36:04 +08:00
wuzhenghui 15e4028e2d fix(esp_hw_support): fix psram data corrupt after lightsleep if halfsleep is enabled 2026-05-19 19:26:29 +08:00
Sarvesh Bodakhe a17b3e97c6 fix(wifi): NAN per-service subscriber security state
The singleton subscriber security cache was overwritten on each new
subscribe, breaking PMKID match for all but the most recent service.
Move security state to own_svc, matched cred index to peer_svc.
2026-05-19 16:54:17 +05:30
Sarvesh Bodakhe b3512ccf7d change(wifi): NAN security_cfg as pointer
security_cfg in wifi_nan_publish_cfg_t / wifi_nan_subscribe_cfg_t is a
large struct; pass it by pointer so callers don't bloat their cfg copy.
Driver deep-copies during publish/subscribe, so caller may free right
after the API returns. Add NULL-check when security_reqd is set.

Update both example apps to declare a local security_cfg and assign its
address. Add help text on EXAMPLE_NAN_SECURITY_ENABLED.
2026-05-19 16:54:17 +05:30
Sarvesh Bodakhe caba5dcfea refactor(wifi): NAN datapath header cleanups and docs
- Rename NAN_IPV6_ADDR_ID_LEN / IS_ZERO_NAN_ADDR_ID to ..._IPV6_IDENTIFIER
  so the names no longer read like MAC-address constants; drop the
  duplicate macro definition in esp_nan.h.
- Replace literal lengths with named macros: WIFI_OUI_LEN for
  nan_vendor_ie_t.vendor_oui, and a new WIFI_MAC_ADDR_LEN (private)
  applied to the NAN-related structs and callbacks in esp_private/wifi.h.
- Document each callback in struct nan_sync_callbacks and each helper
  in struct nan_secure_dp_funcs: when fired / when invoked, what each
  argument means, and the matching spec section where useful.
- Note in wifi_nan_datapath_req_t / wifi_nan_datapath_resp_t that they
  cover the NCS-SK credential model only; pairing-based cipher suites
  (NCS-PK-PASN) install per-peer ND-PMKs via a separate pairing API
  without changing these structs. Record why per-NDP credential
  injection at response time is not viable: the responder's PMKID
  lookup happens at M1 receive time, before the indication event
  surfaces to the host.
2026-05-19 16:54:12 +05:30
Konstantin Kondrashov b853ad7091 fix(pmu_sleep): Wait eFuse memory update after sleep for ESP32H4 2026-05-19 14:11:34 +03:00
Rahul Tank 74aa38f563 fix(nimble): Fix compilation issues while using bdtm porting files 2026-05-19 18:30:25 +08:00
zhiweijian 86cff270dc fix(ble/bluedroid): note LE Coded PHY impact on Wi-Fi coexistence in bluedroid GAP/GATT APIs 2026-05-19 17:52:34 +08:00
linruihao df492d5c2f fix(coex): fix ble coded phy rx issue when aborted by coex 2026-05-19 17:52:07 +08:00
sonika.rathi 67ce49943b test(nvs_bootloader): mark nvs bootloader pytest as flaky 2026-05-19 11:49:09 +02:00
Ashish Sharma 96d8dbd781 docs(vulnerabilities): sync vulnerability list for 5 advisories 2026-05-19 17:42:56 +08:00
Frantisek Hrbata 9b6aefc567 Merge branch 'fix/cmakev2_manager_seed_known_components' into 'master'
fix(cmakev2/manager): seed known_components for namespace rewrite

See merge request espressif/esp-idf!48453
2026-05-19 11:38:19 +02:00
Frantisek Hrbata d43470cf93 Merge branch 'fix/cmakev2-bootloader-spiram-source-guards' into 'master'
fix(esp_hw_support): guard SPIRAM uses with !BOOTLOADER_BUILD

See merge request espressif/esp-idf!48447
2026-05-19 11:32:53 +02:00
Chen Chen 145bf152de feat(i2s): add BLE destination config for esp32s31 2026-05-19 17:31:48 +08:00
Shu Chen ef99c7d07f Merge branch 'feat/support_s31_openthread_br' into 'master'
feat(openthread): add ESP32-S31 support for examples build targets

Closes IDF-14801

See merge request espressif/esp-idf!48576
2026-05-19 09:21:34 +00:00
Chen Chen 84ca614368 fix(i2c): fix i2c pd management leak & resource recycle 2026-05-19 17:14:34 +08:00
C.S.M 854d00cab1 feat(usj): Add usb serial jtag support on esp32s31 2026-05-19 16:16:31 +08:00
Zhang Wen Xu 5f5781bb42 Merge branch 'fix/optimize_the_ot_ci' into 'master'
fix(openthread): wait for all onlink GUAs to finish DAD before tests

See merge request espressif/esp-idf!48676
2026-05-19 07:46:02 +00:00
zhiweijian e970ce1f69 fix(coex): support esp32h4 BLE iso coexist 2026-05-19 15:42:09 +08:00
muhaidong 60fc699da6 fix(coex): update test_md5.sh for esp32h4 2026-05-19 15:42:09 +08:00
Xu Si Yu de2dfcbfd9 fix(coex): support esp32h4 coexist 2026-05-19 15:42:09 +08:00
Renz Christian Bagaporo e95cab4be8 Merge branch 'ci/reenable_base_macadr_test_h4' into 'master'
test(ci): reenable skipped ESP32-H4 base mac address test

Closes IDF-15600

See merge request espressif/esp-idf!48555
2026-05-19 14:57:21 +08:00
Renz Christian Bagaporo 050c091fb4 Merge branch 'ci/reenable_pthread_test_h4' into 'master'
test(ci): re-enable skipped ESP32-H4 pthread tests

Closes IDF-15638

See merge request espressif/esp-idf!48534
2026-05-19 14:56:24 +08:00
Aditya Patwardhan 138ebe2d85 fix(mbedtls): use constant-time compare and zeroize key material
Replace memcmp with mbedtls_ct_memcmp in PSA MAC verify_finish entries
(CMAC, HMAC-transparent, HMAC-opaque) to prevent timing side-channel
MAC forgery, and unconditionally zeroize the locally-computed MAC on
the stack before return so a later stack-disclosure primitive cannot
recover the valid MAC.

Replace bzero with mbedtls_platform_zeroize in AES context free paths.
2026-05-19 12:15:28 +05:30
linruihao e68bf4e8d8 fix(bt): Correct the error code in pairing when pin code req rejected by host 2026-05-19 14:44:14 +08:00
Sarvesh Bodakhe cfecf60986 feat(wifi): NAN multi-credential discovery security
Replace scalar passphrase/PMK in wifi_nan_discovery_security_params_t
with wifi_nan_credential_t[N] array (cap 4) per Wi-Fi Aware v4.0
§9.5.21.4. Drop public PMKID array and service-level csid_bitmap.

Rename wifi_nan_datapath_security_params_t -> wifi_nan_security_params_t;
add wifi_nan_peer_sdf_security_t for multi-PMKID peer-RX. The
derive_security_params callback takes (svc_name, sec_cfg, out_derived[])
and runs once per credential on the WiFi task. Split nan_record_own_svc
into claim/finalize so the WiFi-task callback finds the pending slot
by name and mirrors derived material — no main-task PBKDF2.
2026-05-19 11:11:55 +05:30
Sarvesh Bodakhe 2da41618f5 test(wifi): NAN PMK derivation crypto test
Unit-test the ND-PMK derivation path against known-good vectors using
the wpa_supplicant-ported pbkdf2_sha256.
2026-05-19 11:07:07 +05:30
Sarvesh Bodakhe 0244cb362b feat(wifi): NAN encrypted NDP example apps
nan_publisher / nan_subscriber demonstrate the secure NDP path:
publisher acts as the responder + UDP echo server, subscriber as the
initiator. Both support passphrase and pre-shared PMK modes via
menuconfig; PMK hex strings are decoded with the same helper on both
sides so endpoints derive matching PMKIDs.
2026-05-19 11:07:06 +05:30
Sarvesh Bodakhe 94f226d73b feat(wifi): NAN encrypted datapath (Wi-Fi Aware M1-M4 handshake)
Implement the NAN Data Path encrypted datapath per Wi-Fi Aware v4.0
(§7.1.3.5, §9.5.16):

- Responder + initiator sides of the M1-M4 Shared-Key Descriptor
  exchange, with MIC compute/verify, PTK derivation, and PMK/PMKID
  derivation via PBKDF2-SHA256 over passphrase or pre-shared PMK.
- CSIA / SCIA attribute build + parse, NCS-SK-128 cipher suite.
- Per-NDL security context on ndl_info::security_ctx; per-svc PMK cache.
- ndp_response_indication callback for initiator peer-NDI binding.
- host<->blob ABI migrated from 27 direct esp_nan_* externs to a single
  nan_secure_dp_funcs callback struct in esp_private/wifi.h.
- nan_security.c split out of nan_app.c (~340 lines de-duplicated into
  shared M1-M4 helpers).
- CONFIG_ESP_WIFI_NAN_ENCRYPTED_DATAPATH gates the secure path so non-
  security builds compile out the crypto/handshake code.
- ROM patch (esp32s31): mask ieee80211_encap_esfbuf to match the
  c5/c6/c61 pattern for NAN-capable chips.

Hardening: PMK stack copies zeroized on every return, NDP attribute
parsers bounds-checked, CSID range-checked before shifting, NDL slot
reuse only when handshake state is IDLE, get_csia/scia_len aligned with
their builders on empty input.

API surface: NDP security types moved out of esp_wifi_types_generic.h
into esp_private/wifi.h (internal-only). security pointer dropped from
struct ndp_cb_peer_info. Discovery-side wifi_nan_security_type_t and
the NDP Info callbacks removed (subsumed by csid_bitmap and SSI
respectively).
2026-05-19 11:07:06 +05:30
Sarvesh Bodakhe 67aeac85e5 feat(wpa_supplicant): expose pbkdf2_sha256 for NAN crypto
Re-export the pbkdf2_sha256 declaration from sha256.h and add the
mbedTLS-backed implementation in crypto_mbedtls.c. NAN uses this for
ND-PMK derivation from a passphrase; the helper is also available for
any future caller that needs RFC 8018 PBKDF2 over SHA-256.
2026-05-19 10:48:13 +05:30
Xu Si Yu cb41455677 fix(openthread): wait for all onlink GUAs to finish DAD before tests 2026-05-19 11:55:51 +08:00
Xu Si Yu 919ee1b61d feat(openthread): support s31 openthread br lib
* esp-openthread: thread_zigbee/esp-openthread@2e7e04a30
* openthread: espressif/openthread@a98813b30
* esp-idf: espressif/esp-idf@f91b20b51
2026-05-19 03:52:09 +00:00
Island 8f28ebb6d1 Merge branch 'change/ble_update_lib_20260518' into 'master'
change(ble): [AUTO_MR] 20260518 - Update ESP BLE Controller Lib

Closes IDFCI-3078 and BT-4351

See merge request espressif/esp-idf!48652
2026-05-19 11:50:54 +08:00
Xu Si Yu f91b20b516 feat(openthread): add ESP32-S31 support for examples build targets 2026-05-19 11:35:54 +08:00
wuzhenghui 4876a7ad94 fix(esp_system): fix build err if int_wdt is not enabled on esp32 2026-05-19 11:32:42 +08:00
Jiang Jiang Jian f091260321 Merge branch 'bugfix/update_wifi_scan_threshold_doc' into 'master'
fix(wifi): update auth mode threshold doc

Closes FCS-1689

See merge request espressif/esp-idf!37685
2026-05-19 11:29:18 +08:00
wuzhenghui 11a8a16639 fix(esp_system): remove intwdt config critical area for chips except esp32 2026-05-19 11:28:48 +08:00
Hu Rui 2981e7ae01 Merge branch 'feat/touch_sleep_esp32s31' into 'master'
feat(touch): support touch sleep on ESP32-S31

Closes IDF-15566 and IDF-14796

See merge request espressif/esp-idf!48443
2026-05-19 11:24:01 +08:00
Chen Ji Chang 43b397eb9e Merge branch 'feat/support_parlio_on_s31' into 'master'
feat(parlio): support parlio on s31

Closes IDF-14711, IDF-14712, IDF-14713, and IDF-15645

See merge request espressif/esp-idf!48028
2026-05-19 10:40:45 +08:00
Shu Chen 51ac8546d5 Merge branch 'feat/add_target_esp32h21' into 'master'
Feat/add target esp32h21

See merge request espressif/esp-idf!48531
2026-05-19 02:39:37 +00:00