Commit Graph
35398 Commits
Author SHA1 Message Date
Song Ruo Jing 0075f2b724 refactor(ppa): change test case to cpp style 2026-06-16 19:32:39 +08:00
Song Ruo Jing 9a5fed0f14 fix(ppa): fix hang if blend operation on a YUV format input background image
Closes https://github.com/espressif/esp-idf/issues/18687
2026-06-16 19:32:25 +08:00
Konstantin Kondrashov 255478ce73 fix(bootloader): handle extra component dirs in v1 subproject
Closes https://github.com/espressif/esp-idf/issues/18651
2026-06-16 12:20:48 +03:00
Abanoub Salah 5c2be9ecc4 fix(ulp_riscv): Prioritize error bits over data flags in I2C interrupt wait 2026-06-16 12:18:24 +03:00
Mahavir Jain 1afc579e07 change(bootloader): honor SECURE_BOOT_ALLOW_UNUSED_DIGEST_SLOTS during first boot
Previously the bootloader unconditionally revoked unused secure boot key
digest slots while permanently enabling secure boot on the first boot,
ignoring CONFIG_SECURE_BOOT_ALLOW_UNUSED_DIGEST_SLOTS. Now the config is
honored on this path too: when set, the unused digest slots are left
un-revoked. This is safe as long as the debug and download interfaces are
disabled.

Update the Kconfig help and the Secure Boot v2 guide (en and zh_CN)
accordingly.
2026-06-16 13:30:03 +05:30
Ashish Sharma beed5fe81f fix(protocomm): null output buffer pointer on crypto failure 2026-06-16 14:47:17 +08:00
Ashish Sharma f92ccb1348 fix(rsa_ds): make RSA-OAEP unpadding constant-time 2026-06-16 14:46:24 +08:00
Ashish Sharma c313d339ab fix(rsa_ds): make PKCS#1 v1.5 unpadding constant-time 2026-06-16 14:46:24 +08:00
Marius Vikhammer 53be90b9cb test(esp_timer): increased test latency requirement for H4 2026-06-16 14:39:54 +08:00
wuzhenghui 76ddc45d6d fix(esp_pm): malloc pm_lock in internal mem 2026-06-16 11:53:32 +08:00
harshal.patil 5f824c8683 fix(secure_boot): range-check ECDSA r,s in bootloader before ROM verify 2026-06-12 17:32:38 +05:30
Jin Cheng 2ac34db41c fix(bt/bluedroid): added buffer length check for OBEX APIs 2026-06-12 18:32:39 +08:00
Jin Cheng 0285bb55d2 fix(bt/bluedroid): added buffer length check for HID Device data indication 2026-06-12 18:32:39 +08:00
Jin Cheng a7aca1c1a3 fix(bt/bluedroid): added validation for all SMP BR opcode lengths in smp_br_data_received 2026-06-12 18:32:39 +08:00
Jin Cheng 043bad5c30 fix(bt/bluedroid): fixed CTKD link key authentication downgrade in SC-Only mode 2026-06-12 18:32:39 +08:00
Jin Cheng 129ce07ece fix(bt/bluedroid): added buffer length check for HID host data indication 2026-06-12 18:32:39 +08:00
Jin Cheng 9a6d04f65e fix(bt/bluedroid): added buffer length check for L2CAP related functions 2026-06-12 18:32:39 +08:00
surengab 4bdf427ca1 fix(ws_transport): reject oversized 64-bit WebSocket payload length 2026-06-12 11:59:58 +02:00
Laukik Hase 39a4cf5e56 feat(esp_tee): Clear out all sensitive buffers explicitly after TEE crypto operations 2026-06-12 10:04:07 +05:30
Laukik Hase 61b88163be ci(esp_tee): Add test-case for verifying the TEE Secure Storage encryption 2026-06-12 10:04:07 +05:30
Laukik Hase 93466c1fd3 feat(esp_tee): Add some required fields in the attestation token
- Chip ID from the ROM
- Device MAC address from eFuse BLK1
- Device Optional Unique ID from eFuse BLK2
2026-06-12 10:04:06 +05:30
Laukik Hase 6bd173b806 ci(esp_tee): Fix TEE test-suite failures with Secure Boot enabled 2026-06-12 10:04:04 +05:30
Laukik Hase f37a2cd35b feat(esp_tee): Remove unused components from the PSA Crypto library 2026-06-12 10:03:03 +05:30
Laukik Hase 140e1ae1f3 ci(esp_tee): Removed common_components dependency from ESP-TEE test-apps 2026-06-12 10:03:02 +05:30
Zhou Xiao 638cd4c1bd change(ble): [AUTO_MR] Update lib_esp32c2 to 750d4902
(cherry picked from commit 897f3b2af1)

Co-authored-by: Zhou Xiao <zhouxiao@espressif.com>
2026-06-12 12:14:38 +08:00
Aditya Patwardhan 839352f836 Merge branch 'fix/disable_secure_boot_v2_ecdsa_v6.0' into 'release/v6.0'
Fix/disable secure boot v2 ecdsa (v6.0)

See merge request espressif/esp-idf!49470
2026-06-11 07:48:52 +05:30
morris 970c2f83c3 Merge branch 'fix/jpeg_cve_fix_v6.0' into 'release/v6.0'
fix(jpeg_decoder): Add some strict check to avoid bad picture attack (backport v6.0)

See merge request espressif/esp-idf!49254
2026-06-11 10:13:09 +08:00
JiangGuangMingandCursor a90989cd6f feat(usb): add usb wakeup from light sleep example
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-11 09:24:04 +08:00
JiangGuangMingandCursor 6b3f1f077f feat(esp_hal_usb): add usb suspend wakeup status in ll layer
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-11 09:13:20 +08:00
JiangGuangMingandCursor e89a04d89e feat(sleep/usb): support usb as wakeup source from light sleep
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-11 09:13:20 +08:00
Marius Vikhammer 4dd862314d fix(ulp): fixes potential race-condition for lp-timer wakeup with lp-core
Reconfigure wakeup time before enabling the wakeup source to avoid
a wakeup from potentially stale values.

Closes https://github.com/espressif/esp-idf/issues/17009
2026-06-11 09:02:28 +08:00
Aditya Patwardhan 94be07050f change(secure_boot): mark ECDSA based Secure Boot V2 as insecure on affected SoCs
ECDSA based Secure Boot V2 is not functional for certain input vectors on
ESP32-C5/C61/H2/P4 and on the preview targets ESP32-H4/H21. RSA based Secure
Boot V2 is the recommended scheme where the SoC supports it. This issue will be
fixed in a future hardware ECO revision; more details will be shared through the
hardware errata document.

A new hidden Kconfig option SECURE_BOOT_V2_ECDSA_INSECURE marks the affected
mass-production SoCs (ESP32-C5/C61/H2/P4). On these SoCs, when hardware Secure
Boot V2 is enabled, the ECDSA (V2) signing scheme is no longer offered by
default; it must be turned on explicitly via SECURE_BOOT_V2_FORCE_ENABLE_ECDSA
under "Allow potentially insecure options" (CONFIG_SECURE_BOOT_INSECURE). App
signing without hardware Secure Boot is not affected. Note that ESP32-C61 has no
RSA based Secure Boot V2, so it has no Secure Boot scheme enabled by default.

The preview targets ESP32-H4 and ESP32-H21 mark ECDSA Secure Boot V2 as not
supported in their SoC capabilities instead of using the option above. As
ESP32-H4 has no other Secure Boot V2 scheme, Secure Boot is disabled entirely on
it; ESP32-H21 retains RSA based Secure Boot V2.

The security documentation keeps the ECDSA Secure Boot V2 content visible and
adds a warning describing the limitation (including that ECDSA Secure Boot V2 on
ESP32-C61 is not recommended for production). CI apps that exercise ECDSA Secure
Boot V2 on the affected SoCs set CONFIG_SECURE_BOOT_V2_FORCE_ENABLE_ECDSA
accordingly.
2026-06-10 18:06:48 +05:30
Chen Jichang a82f0d2bc3 fix(rgb_lcd): fix gdma link switch not take effect 2026-06-10 20:26:01 +08:00
Zhi Wei Jian b55f972546 fix(bt): fix BTC task and BLE mesh bluedroid adapter
(cherry picked from commit 678fb93245)

Co-authored-by: zhiweijian <zhiweijian@espressif.com>
2026-06-10 19:54:01 +08:00
Zhi Wei Jian 848bdc0301 fix(ble/bluedroid): fix HCI command and BTU robustness
(cherry picked from commit c9d13aaf64)

Co-authored-by: zhiweijian <zhiweijian@espressif.com>
2026-06-10 19:54:00 +08:00
Zhi Wei Jian cebf129df8 fix(ble/bluedroid): fix CTE and ISO API validation
(cherry picked from commit 0c3c894b7d)

Co-authored-by: zhiweijian <zhiweijian@espressif.com>
2026-06-10 19:54:00 +08:00
Zhi Wei Jian b60fe364f0 fix(ble/bluedroid): fix GATT server lifecycle and callbacks
(cherry picked from commit 54a1e31916)

Co-authored-by: zhiweijian <zhiweijian@espressif.com>
2026-06-10 19:54:00 +08:00
Zhi Wei Jian 7e97000e5c fix(ble/bluedroid): fix GATT client API parameter validation
(cherry picked from commit 653477c3e9)

Co-authored-by: zhiweijian <zhiweijian@espressif.com>
2026-06-10 19:53:59 +08:00
Zhi Wei Jian 349b4cf8a9 fix(ble/bluedroid): fix GATT client cache and service discovery
(cherry picked from commit b3ff15ed31)

Co-authored-by: zhiweijian <zhiweijian@espressif.com>
2026-06-10 19:53:59 +08:00
Zhi Wei Jian 638e633e04 fix(ble/bluedroid): fix GAP BLE API parameter validation
(cherry picked from commit e3311c81c4)

Co-authored-by: zhiweijian <zhiweijian@espressif.com>
2026-06-10 19:53:59 +08:00
Zhi Wei Jian b464721a8d fix(ble/bluedroid): fix BLE bonding key storage validation
(cherry picked from commit 62cdd4ac38)

Co-authored-by: zhiweijian <zhiweijian@espressif.com>
2026-06-10 19:53:58 +08:00
gaoxu d51f64d719 fix(adc): fix ADC monitor channel 8/9 error
(Closes https://github.com/espressif/esp-idf/issues/17768)
2026-06-10 15:10:18 +08:00
Laukik Hase 6af1af7d99 fix(esp_tee): Harden the TEE secure services against REE manipulation
- `bootloader_flash_execute_command_common`: whitelist the flash command
   opcodes the REE actually uses; reject the rest
- `spi_flash_hal_* services`: a forged `host->driver` could hijack TEE
   control flow since the HAL dispatches through it, so swap
   `host->driver` to a TEE-rodata vtable around each HAL call
- Deny partition table and bootloader writes by default and permit
  bootloader writes only when explicitly enabled via
  `CONFIG_SPI_FLASH_DANGEROUS_WRITE_ALLOWED` option
- Protect the TEE-assigned interrupt pin configuration against REE
- Validate nested DS context pointers in start/finish_sign and bound
  the result copy to the SoC max signature size
- Fix the stack usage in service dispatcher argument parsing
2026-06-10 12:06:26 +05:30
Song Ruo Jing a242565623 fix(spi_flash): gpspi flash clock could reach higher frequency 2026-06-09 21:56:36 +08:00
harshal.patil b420f20040 test(esp_hal_security): warm up ECC const-time loop before measuring 2026-06-09 15:07:55 +05:30
harshal.patil 6b8f830991 fix(esp_tee): Reset crypto peripherals before the panic-induced reset 2026-06-09 15:07:55 +05:30
harshal.patil c1f70a4cb5 fix(esp_rom): Patch ets_ecdsa_verify() to include signature bounds check 2026-06-09 15:07:53 +05:30
harshal.patil 3195c942da fix(mbedtls): validate ECDSA signature range and harden ECC memory power-down 2026-06-09 15:02:59 +05:30
hebinglin f088b73ea8 fix(ulp): fix lp uart keep wakeup triggered 2026-06-08 19:49:42 +08:00
Frantisek Hrbata 003e049ba8 fix(esp_hw_support): guard SPIRAM-dependent code with !BOOTLOADER_BUILD
The bootloader subproject's full Kconfig discovery resolves CONFIG_SPIRAM=y
when the parent app has it enabled, even though esp_psram is not linked
into the bootloader (the CMake gate is
'if(NOT non_os_build) if(CONFIG_SPIRAM) idf_component_optional_requires(PRIVATE esp_psram)').
Shared sources in esp_hw_support that #include esp_psram private headers
or call esp_psram functions guarded only by '#if CONFIG_SPIRAM' then fail
to compile in the bootloader with
"fatal error: esp_private/esp_psram_extram.h: No such file or directory".

Mirror the CMake gate in source guards: every '#if CONFIG_SPIRAM' block in
a bootloader-compiled source that touches esp_psram becomes
'#if !BOOTLOADER_BUILD && CONFIG_SPIRAM'. The leaked CONFIG_SPIRAM value
in the bootloader's sdkconfig.h is then harmless because every dependent
block evaluates to false.

Sites updated:
- esp_memory_utils.c: include of esp_psram_extram.h and all
  esp_psram_check_ptr_addr() call sites
- port/esp32{c5,c61,p4}/cpu_region_protect.c: include of
  esp_psram_extram.h (inner SPIRAM_FETCH/RODATA/PRE_CONFIGURE blocks are
  already inside outer !BOOTLOADER_BUILD guards)

Signed-off-by: Frantisek Hrbata <frantisek.hrbata@espressif.com>
2026-06-08 18:34:50 +08:00