Ashish Sharma
cecbc54c04
fix(esp_tee): fixes double panic when ESP-TEE panics
2026-07-09 11:59:23 +05:30
Ashish Sharma
cdedde2fea
fix(esp_tee): release SHA held by HMAC after crypto peripheral reset
2026-07-09 11:58:48 +05:30
Ashish Sharma
28f3d0be4a
fix(mbedtls): fixes TLS1.3 server failing with dynamic buffer
2026-07-06 15:18:48 +08:00
Ashish Sharma
ce7abcf087
fix(esp-tls): guard against NULL PSK hint to prevent crash
2026-07-03 11:36:33 +08:00
Ashish Sharma
dedb02dd25
fix(esp_http_server): take ctrl_sock_semaphore on shutdown and async wake
...
httpd_stop() and httpd_req_async_handler_complete() both pushed
messages onto the control mbox via cs_send_to_ctrl_sock() without
reserving a slot in ctrl_sock_semaphore. Once the silent-drop fix
made the semaphore unconditional, the bypass became a real bug:
when the mbox is saturated by pending httpd_queue_work() items the
unguarded sendto() can return ENOBUFS, and even when it succeeds it
leaves the semaphore overstating free slots until the consumer
drains the message — a window during which a concurrent
httpd_queue_work() can take a slot but still find the mbox full.
Acquire the semaphore (portMAX_DELAY) before both sends and give it
back on send failure so the take/give invariant is preserved. The
httpd task is the consumer in both paths, so blocking is bounded
and deadlock-free. Reword the stale "no-op give on full" comment in
httpd_process_ctrl_msg() to reflect that only the recv-error path
relies on the cap behavior now.
2026-06-05 17:37:55 +08:00
Ashish Sharma
fcc140c11c
fix(esp_http_server): prevent silent message drop in httpd_queue_work
...
Closes https://github.com/espressif/esp-idf/issues/18563
2026-06-05 17:37:55 +08:00
Ashish Sharma
99fc683322
fix(mbedtls): fixes build failure with clang21
...
Closes https://github.com/espressif/esp-idf/issues/18456
2026-06-05 16:49:29 +08:00
Ashish Sharma
26de0e2137
fix(esp_prov): fixes sec2 client possible public length truncation
2026-05-20 11:54:44 +08:00
Ashish Sharma
d0903c1cb4
fix(http_request): fixes failing pytest
2026-05-11 18:08:54 +08:00
Ashish Sharma
f8dec92a06
fix(esp_http_server): fixes websocket recv error handling
...
Closes https://github.com/espressif/esp-idf/issues/18483
2026-05-10 19:26:08 +08:00
Ashish Sharma
71eb2dbe6a
fix(protocomm): fixes potential issues that can lead to crash during device provisioning
2026-04-29 16:22:14 +08:00
Ashish Sharma
c2cccd0b56
fix(esp_hal_security): fixes failing hmac_hal_configure with efuse_key for p4 rev < 3
...
Closes https://github.com/espressif/esp-idf/issues/18370
2026-04-28 14:51:39 +05:30
Ashish Sharma
c7c41c91ea
fix(mbedtls): relaxes performance numbers for RSA operations
2026-04-27 11:42:56 +08:00
Ashish Sharma
d4b067dc25
change(mbedtls): adds CVE-2025-66442 to exclude list.
...
The CVE is applicable with Clang using LLVM's select-optimize feature. ESP-IDF uses GCC as default compiler and sets -Os as the default optimisation flag
2026-04-22 15:42:51 +08:00
Ashish Sharma
05921ab663
fix(esp_srp): reject SRP client public key when A mod N is zero
2026-04-20 11:23:32 +08:00
Ashish Sharma
8ddb998a8f
feat(esp_tls): extends esp-tls test apps
2026-04-17 14:41:45 +08:00
Ashish Sharma
2f560ce2cd
fix(esp_tls): check tls connection finished before read/write operation
2026-04-17 14:41:45 +08:00
Ashish Sharma
dba7694724
feat(esp_http_server): adds check for crlf in response creation
2026-04-13 10:32:41 +08:00
Ashish Sharma
6aeb829555
feat(esp_local_ctrl): adds basic test app
2026-04-12 18:19:11 +08:00
Ashish Sharma
1ede92febf
fix(esp_local_ctrl): fixes a potential double free
2026-04-12 18:19:11 +08:00
Ashish Sharma
08c4b0eb68
feat(cjson): update to latest master
2026-04-02 13:33:49 +08:00
Ashish Sharma
6293b28504
feat(mbedtls): update to version 3.6.6
2026-04-02 11:34:22 +08:00
Ashish Sharma
cca227e022
feat(esp-tls): adds per ssl context state management
2026-03-30 13:45:28 +08:00
Ashish Sharma
a4c40112c3
fix: removes deprecated http_crypto sources
2026-03-30 13:45:28 +08:00
Ashish Sharma
9681ec0f9c
fix: fixes failing dynamic buffer tests
2026-03-30 13:45:28 +08:00
Ashish Sharma
c692c1ec8b
fix(wifi_provisioning): fixes memory leak on OOM
2026-03-27 10:15:49 +08:00
Ashish Sharma
0f294a2d96
fix(wifi_provisioning): fixes potential null dereference on malformed packet
2026-03-26 11:45:06 +08:00
Ashish Sharma
08c8c17436
fix: fixes memory leak with subprotocols
2026-03-23 18:42:48 +08:00
Ashish Sharma
00a2f7fbbb
fix: fixes websocket server possible null dereference
2026-03-23 18:42:45 +08:00
Ashish Sharma
da9b3ce548
fix(esp_http_client): delete Content-Length header when using Transfer-Encoding
...
Closes https://github.com/espressif/esp-idf/issues/18242
2026-03-17 12:21:09 +08:00
Ashish Sharma
4425dbf4af
feat(http_server): adds example to test server pong response
2026-03-16 16:55:54 +08:00
Ashish Sharma
6f392e6fd6
feat(http_server): improve websocket server handling
...
1. Adds post handshake callback
2. Removes requirement to handle HTTP_GET message in websocket handler
Closes https://github.com/espressif/esp-idf/issues/18215
2026-03-16 13:57:59 +08:00
Ashish Sharma
1e27eb204b
feat(esp_http_client): adds API to get transport socket
2026-01-22 18:24:45 +08:00
Ashish Sharma
7ef71e9770
fix: stop reading ws data when peer closes the connection
...
Closes https://github.com/espressif/esp-idf/issues/17822
2026-01-22 18:16:37 +08:00
Ashish Sharma
4c0c9d2d6a
fix: fixes potential ws server deadlock with blocking work queue
...
Closes https://github.com/espressif/esp-idf/issues/17591
2026-01-22 18:12:03 +08:00
Ashish Sharma
613b878df3
fix(esp_http_client): fix incorrect digest calculation for SHA256 auth digest
...
According to RFC 7616, nonce-prime and cnonce-prime is used for SHA-256-sess only and not for SHA-256.
This commit updates the check and uses nonce only for "-sess" algorithms.
Regression from 66995965e7
2026-01-07 10:19:04 +08:00
Ashish Sharma
30f93c0516
feat(mbedtls): update to version 3.6.5
2025-11-11 16:47:45 +08:00
Ashish Sharma
6b0796b2a4
fix(esp_tls): limit ret code from esp_mbedtls_handshake
2025-09-24 15:48:30 +08:00
Ashish Sharma
5e7c32897f
change(cjson): update cjson version to 1.7.19
2025-09-11 15:35:55 +08:00
Ashish Sharma
8a8d01565e
fix(esp_http_client): fix possible double memory free
2025-08-01 14:22:10 +08:00
Ashish Sharma
163db6a8a5
feat(mbedtls): adds support for RSA decryption with DS peripheral
2025-07-21 09:27:06 +08:00
Ashish Sharma
ab8770fe5a
fix(esp_http_client): fix memory leak in current_header_value buffer
...
Fixed memory leak in esp_http_client_cleanup() where current_header_value
buffer was not being freed when ESP_ERR_HTTP_FETCH_HEADER is returned
during header parsing failures.
2025-07-18 12:01:39 +08:00
Ashish Sharma
a3af8972ae
feat(mbedtls): update to version 3.6.4
2025-07-04 17:34:00 +08:00
Ashish Sharma
3a9cce2a92
docs(system/esp_https_ota): adds ECIES-256 to pre-enc ota design doc
2025-07-04 17:29:24 +08:00
Ashish Sharma
156ead0cd5
fix(mbedtls): Fixes failing TLS 1.3 server handshake
...
Closes https://github.com/espressif/esp-idf/issues/15984
2025-06-16 11:27:48 +05:30
Ashish Sharma
08d78dcd7e
fix(esp_tls): fix failing build with TLS1.3 only and dynamic buffer
2025-06-16 09:22:57 +08:00
Ashish Sharma
b3843ea09a
change: adds CVE-2023-53154 to cJSON sbom exclude list
2025-05-26 17:29:14 +08:00
Ashish Sharma
c18e53b672
feat(cjson): update to latest upstream
2025-05-19 09:50:59 +08:00
Ashish Sharma
415e0f3c86
feat(mbedtls): add support for dynamic buffer for TLS1.3
...
Closes https://github.com/espressif/esp-idf/issues/15448
2025-04-24 12:05:36 +08:00
Ashish Sharma
0bad622a7a
fix(esp_tls): use correct sockaddr struct size when calling connect()
...
Closes https://github.com/espressif/esp-idf/issues/15812
2025-04-23 13:23:44 +08:00
Ashish Sharma
0de1429834
fix(mbedtls): remove logical dead code from mbedtls
2025-04-17 13:43:48 +08:00
Ashish Sharma
11890df95a
Merge branch 'bugfix/fix_cert_verification_ds_tls1.3' into 'master'
...
fix(component/mbedtls): Fix failing cert verification with TLS1.3 and DS peripheral
Closes IDFGH-14097
See merge request espressif/esp-idf!37634
2025-04-14 12:31:50 +08:00
Ashish Sharma
b62e486247
fix(component/mbedtls): Fix failing cert verification with TLS1.3 and DS peripheral
2025-04-11 18:34:16 +08:00
Ashish Sharma
b126ebb596
feat(mbedtls): new config to allow weak cert verification
2025-03-28 15:46:48 +08:00
Ashish Sharma
0291bee0ff
feat(mbedtls): update to version 3.6.3
2025-03-28 13:03:12 +08:00
Ashish Sharma
88fa3e2c9e
feat(security): fixes review comments
2025-03-17 18:23:14 +08:00
Ashish Sharma
4c23ba3c1f
feat(security): update idf.py extensions to support security feature application
2025-03-17 18:23:14 +08:00
Ashish Sharma
fbecd65e2a
feat(security): update README.md to include support for esp32s3
2025-03-17 18:23:14 +08:00
Ashish Sharma
2fc151d2a9
fix(component/mbedtls): Adds github root cert to cmn_crt_authorities.csv
2025-03-17 14:32:06 +08:00