Commit Graph
52064 Commits
Author SHA1 Message Date
Island 6eb40db09d Merge branch 'feat/adapt_uhci_code_260824_v6.0' into 'release/v6.0'
refactor(hci): switch HCI UART DMA transport to UHCI driver APIs (6.0)

See merge request espressif/esp-idf!52160
2026-09-04 17:58:17 +08:00
morris 31ceb68a04 Merge branch 'fix/jpeg_enc_header_oob_v6.0' into 'release/v6.0'
fix(jpeg): validate encoder buffer sizes before header/DMA access (backport v6.0)

See merge request espressif/esp-idf!52122
2026-09-04 17:57:34 +08:00
morris 17dabceecf Merge branch 'fix/dualcore_branch_predictor_cache_race_v6.0' into 'release/v6.0'
fix(spi_flash): disable branch prediction on the parked core during flash ops (v6.0)

See merge request espressif/esp-idf!52202
2026-09-04 17:57:09 +08:00
morris c2638a5689 Merge branch 'fix/i2s_tdm_5slot_clock_test_v6.0' into 'release/v6.0'
fix(hal): prevent overflow in fractional clock division (v6.0)

See merge request espressif/esp-idf!51430
2026-09-04 17:56:03 +08:00
YoungsunLi c4e8f1e709 fix(esp_lcd): yield from SPI ISR when color trans done callback wakes a task
The return value of on_color_trans_done ("whether a high priority task
has been waken up by this function", see esp_lcd_types.h) was discarded
by the SPI backend. A task unblocked from inside the callback (e.g. via
xSemaphoreGiveFromISR) therefore did not get scheduled until the next
FreeRTOS tick, adding up to 10 ms of latency per color transfer with the
default CONFIG_FREERTOS_HZ=100. The i80 backend already honors the
contract (need_yield -> portYIELD_FROM_ISR); do the same here.
2026-09-04 17:50:07 +08:00
Alexey Gerenkov 2007a7c8db Merge branch 'feature/update-openocd-to-v0.12.0-esp32-20260831_v6.0' into 'release/v6.0'
feat(tools): update openocd version to v0.12.0-esp32-20260831 (v6.0)

See merge request espressif/esp-idf!52392
2026-09-04 17:32:14 +08:00
Alexey Gerenkov 3d678a280b Merge branch 'add_trace_doc_section_v6.0' into 'release/v6.0'
docs(esp_trace): restructure tracing docs with esp_trace as master (v6.0)

See merge request espressif/esp-idf!52265
2026-09-04 17:22:14 +08:00
morris e214cf1b20 Merge branch 'feat/atomic-internal_v6.0' into 'release/v6.0'
fix(driver): allocate driver objects containing atomic variables from internal SRAM (v6.0)

See merge request espressif/esp-idf!52341
2026-09-04 17:18:55 +08:00
Rahul Tank c0b30a11db Merge branch 'bugfix/fix_stale_conn_cccd_v6.0' into 'release/v6.0'
fix(nimble): fix crash on disconnect due to stale per-connection CCCD pool (v6.0)

See merge request espressif/esp-idf!51951
2026-09-04 14:42:22 +05:30
Fu Hanxi 9ae18190fd revert: custom ci_python_constraint_branch 2026-09-04 10:57:09 +02:00
Fu Hanxi 14297ada26 Merge branch 'ci/apply-common-scripts-v6.0' into 'release/v6.0'
ci: apply common-scripts refactor (v6.0)

See merge request espressif/esp-idf!50991
2026-09-04 09:33:06 +02:00
Mahavir Jain 068fb15c0f Merge branch 'fix/crt-bundle-unaligned-reads_v6.0' into 'release/v6.0'
fix(mbedtls): read crt bundle byte-wise to avoid misaligned flash access (v6.0)

See merge request espressif/esp-idf!51724
2026-09-04 12:31:11 +05:30
wuzhenghui 38493ef42a change(esp_hw_support): optimize pmu_sleep RAM cost 2026-09-04 14:51:01 +08:00
wuzhenghuiandCursor ddfaf24b06 change(esp_hw_support): optimize retention driver RAM cost
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-04 14:51:00 +08:00
Rahul Tank a64ac3a8f6 fix(nimble): fix crash on disconnect due to stale per-connection CCCD pool 2026-09-04 12:17:48 +05:30
Island 6ecedac2cd Merge branch 'bugfix/fixed_ble_deinit_crash_issue_6.0' into 'release/v6.0'
fix(bt): fixed mempool deinit crash issue

See merge request espressif/esp-idf!52139
2026-09-04 14:35:26 +08:00
Mahavir Jain 64b477f8c9 fix(build): word-align the length symbol of embedded data files
The generated assembly emitted <name>_length immediately after the raw
payload bytes, so the 32-bit word landed misaligned whenever the data
size was not a multiple of 4. Consumers declare it as a 32-bit object
(e.g. `extern const size_t <name>_length` in the ULP firmware loaders),
so the compiler emits an alignment-assuming word load, which is a
misaligned flash read prone to spurious load faults on chips with
SOC_CPU_MISALIGNED_ACCESS_ON_PMP_MISMATCH_ISSUE (ESP32-C6/H2/H21).
2026-09-04 11:06:54 +05:30
Mahavir Jain ec3877cf6c fix(mbedtls): read crt bundle byte-wise to avoid misaligned flash access
The offset table and the per-cert length fields of the certificate
bundle were read through uint16_t*/uint32_t* casts, which compile to
halfword/word loads at addresses with no alignment guarantee: bundles
supplied via esp_crt_bundle_set() can start anywhere, and cert entries
are byte-packed, so their 16-bit fields land at arbitrary offsets.

On chips with SOC_CPU_MISALIGNED_ACCESS_ON_PMP_MISMATCH_ISSUE (DIG-694:
ESP32-C6/H2/H21) a misaligned load from memory-mapped flash can take a
spurious "Load access fault" when it sits within two instructions of an
access to a differently-permissioned region, observed as a crash in
esp_crt_check_bundle()/CA callback during TLS handshakes with a bundle
that happened to be placed at an odd address.
2026-09-04 11:06:54 +05:30
Laukik Hase 540e380321 fix(esp_tee): Fix AEAD output buffer slicing in the tee_basic example 2026-09-04 10:23:34 +05:30
Laukik Hase c7f74fd751 change(esp_tee): Limit the TEE secure storage AEAD operation input buffer length 2026-09-04 10:23:25 +05:30
Laukik Hase a4d6b802a7 feat(esp_tee): Disable the MBEDTLS_PSA_ASSUME_EXCLUSIVE_BUFFERS option for TEE build 2026-09-04 10:23:25 +05:30
Laukik Hase e5c3063dee fix(esp_tee): Snapshot input arguments in TEE memory before secure service execution
- Also fix the `tee_cli_app` build failure due to TEE heap size overflow
2026-09-04 10:23:25 +05:30
Laukik Hase e9cd262217 change(esp_tee): Force non-deterministic ECDSA signing for TEE secure storage keys 2026-09-04 10:23:24 +05:30
Laukik Hase 8e34cc16cc feat(esp_tee): Use CTR-DRBG for assisting random number generation in TEE
- For ESP-TEE, fault-assert in `esp_random()` if the RNG is held in a
  freeze state
2026-09-04 10:23:24 +05:30
Laukik Hase eb0a81b89a feat(hal): Add LL-API to check whether RNG is enabled
- Also add RNG LL-APIs for ESP32-C61
2026-09-04 10:23:24 +05:30
Laukik Hase e01f93eec4 fix(esp_tee): Reject re-entrant secure service calls from the REE 2026-09-04 10:23:23 +05:30
Ashish Sharma e41ac40b86 fix(ws): enforce payload length encoding minimality and MSB constraints
Independently reported in parallel by DatanoiseTV <syso.berlin@icloud.com>
2026-09-04 12:03:15 +08:00
Ashish Sharma ebd8108ccc fix(ws): reject RSV bits, reserved opcodes, fragmented control frames 2026-09-04 12:01:03 +08:00
hejiaxin 340ce2b338 fix(bt_pbap): Fix some bugs in bluedroid PBAP
- Add sdp_seq to avoid p_ccb being free during sdp
- Changed some BTA_Pba functions to return non-void value
- Improve error catching and report
- Refactor bta_pba_client_response to avoid UAF problem
- Rearrange btc_pba_client init flag to avoid some disturbing bug
2026-09-04 11:55:05 +08:00
hejiaxin b2c98e72cd fix(bt_avrcp): size some AVRC command buffers 2026-09-04 11:51:39 +08:00
Zhi Wei Jian 2bada5b678 feat(ble/bluedroid): reject LE re-pairing that weakens an existing bond
Add smp_repairing_is_allowed() behind BT_BLE_SMP_HARDENED_REPAIRING so a
peer cannot replace an existing bond with one that has less MITM
protection, no Secure Connections, or a shorter key. Compare a preceding
Security Request against the pairing command AuthReq, not the
association-model result, and always allow first pairing.

A refusal keeps the stored bond. Pairing-failure erase is split by link
role: default is erase as Central and keep as Peripheral.

Closes BLERP (NDSS 2026) V3, V4 and V6.


(cherry picked from commit 88ea45be73)

Co-authored-by: zhiweijian <zhiweijian@espressif.com>
2026-09-04 11:03:52 +08:00
Zhi Wei Jian 6b9b3d969e fix(ble/bluedroid): harden LE bond handling across encryption
Keep the existing bond until the new pairing is encrypted, and on encryption
failure drop the link instead of clearing keys. Recovering from a peer that
really deleted the bond is opt-in through BT_BLE_SMP_UNBOND_ON_KEY_MISSING.

Closes BLERP (NDSS 2026) V5, and stops an unauthenticated Pairing Request
from dropping the stored keys (V2 exploitation).


(cherry picked from commit f864615d7d)

Co-authored-by: zhiweijian <zhiweijian@espressif.com>
2026-09-04 11:03:52 +08:00
ShenWeilong d3b4dd9584 fix(ble): Check if there are illegal library files in controller lib path 2026-09-04 11:03:01 +08:00
ShenWeilong 3dbbafbbb3 fix(bt): fixed mempool deinit crash issue 2026-09-04 11:00:59 +08:00
Shu Chen 1ccc930b04 Merge branch 'fix/fix_openthread_netif_glue_deinit_issue_v6.0' into 'release/v6.0'
fix(openthread): fix stack deinit by reversing netif glue teardown and hardening workflow cleanup (v6.0)

See merge request espressif/esp-idf!52398
2026-09-04 02:45:20 +00:00
hejiaxin 4226c1fdd4 fix(bt_obex): fix some bugs in bluedroid obex
- fix goepc wait state switch
- fix psm unbind's mismatch
- fix some resources leak
- fix goep connection's incorrect ternimation when congesting
- Add some NULL ptr check
2026-09-04 10:20:04 +08:00
Matteo Sandrin ffa442cb5d fix(bt/bluedroid): delete the unused AVRCP acceptor RCB when A2DP open fails 2026-09-04 10:07:55 +08:00
yangfeng 9905ffe7f5 fix(bt): Fix compatibility with A2DP API legacy usage methods
- Modify the timing of API calls in the A2DP example
- Closes https://github.com/espressif/esp-idf/issues/18786
2026-09-04 10:02:48 +08:00
liqigan 822f1617bf change(bt/bluedroid): Used dynamic osi event to reduce lock cost 2026-09-04 09:41:19 +08:00
zhanghaipeng 6d23cb7278 docs(bt): clarify Bluedroid GATT signed write API comments
Correct misleading CHAR_PROP_BIT_AUTH wording and document CSRK-based
signed write usage for server permissions and client write APIs.
2026-09-04 09:40:32 +08:00
zhanghaipeng ad5a7d778e fix(ble/bluedroid): allow osi_event re-post during POSTING window
Do not reject osi_thread_post_event() when only POSTING is set.
QUEUED already prevents double-queueing; rejecting POSTING caused
HCI downstream lost wakeup. Add generic osi_event and hci downstream
diagnostics for post failures.
2026-09-04 09:40:32 +08:00
liqigan 4412ff55b2 fix(bt/bluedroid): Fixed use after free issue on osi_event_delete 2026-09-04 09:40:29 +08:00
liqigan 1dcaf24129 fix(bt/bluedroid): Fixed HID host reconnection bug and enabled load HID devices
Closes https://github.com/espressif/esp-idf/issues/18335
2026-09-04 09:32:58 +08:00
liqigan 6c27057d67 change(bt/bluedroid): Refactored HCI ACL datapath 2026-09-04 09:32:58 +08:00
liqigan 20757b7933 change(bt/bluedroid): Refactored HID host datapath 2026-09-04 09:32:58 +08:00
Jin Cheng 10ee735306 fix(bt/bluedroid): fixed BTA event dispatch race during module disable
- Gate bta_sys_event() on both 'is_reg' and 'reg[id]' to prevent
  stale event delivery.
- Defer bta_sys_deregister() to the end of profile disable handlers
  to ensure pending DISABLE events are processed.
- Add disabling flag to HFP AG for tracking asynchronous teardown.
2026-09-04 09:13:18 +08:00
Rahul Tank 93f74eb464 Merge branch 'bugfix/fix_nimble_issues_3092026_v6.0' into 'release/v6.0'
feat(nimble): Fix few nimble issues 03092026(v6.0)

See merge request espressif/esp-idf!52355
2026-09-04 05:50:01 +05:30
Wang Meng Yang ff0587bde0 Merge branch 'bugfix/avrcp_version_compatibility_v6.0' into 'release/v6.0'
fix(bt): Fix the issue of AVRCP version compatibility (v6.0)

See merge request espressif/esp-idf!52087
2026-09-04 08:13:00 +08:00
Wang Meng Yang 2d5899d022 Merge branch 'fix/bluedroid_aireview_v6.0' into 'release/v6.0'
Fix/bluedroid aireview (v6.0)

See merge request espressif/esp-idf!51480
2026-09-04 07:55:43 +08:00
Fu Hanxi cba7d2aae4 ci: move check_submodule_sync to ci/actions/common 2026-09-03 20:25:14 +02:00