Commit Graph
54414 Commits
Author SHA1 Message Date
Jiang Jiang Jian 837f886710 Merge branch 'bugfix/dpp_stray_auth_confirm_v6.1' into 'release/v6.1'
fix(esp_wifi): Harden dpp Auth confirm and drop mismatched auth confirms

See merge request espressif/esp-idf!52311
2026-09-04 15:43:58 +08:00
Wang Meng Yang ec6c7bea5c Merge branch 'bugfix/delete_unused_avrcp_rcb_v6.1' into 'release/v6.1'
fix(bt/bluedroid): delete the unused AVRCP acceptor RCB when A2DP open fails (v6.1)

See merge request espressif/esp-idf!52412
2026-09-04 15:29:42 +08:00
morris 9679b0bc35 Merge branch 'bugfix/uart_extra_current_consumption_in_sleep_v6.1' into 'release/v6.1'
fix(uart): reduce current consumption in sleep mode (v6.1)

See merge request espressif/esp-idf!52344
2026-09-04 14:18:40 +08:00
Mahavir Jain 156d8938f1 Merge branch 'fix/crt-bundle-unaligned-reads_v6.1' into 'release/v6.1'
fix(mbedtls): read crt bundle byte-wise to avoid misaligned flash access (v6.1)

See merge request espressif/esp-idf!51723
2026-09-04 11:00:13 +05:30
Mahavir Jain 027c75bb0a Merge branch 'fix/aes_op_zero_buf_check_v6.1' into 'release/v6.1'
fix(mbedtls/aes): reject an all-zero AES block output in the encrypt direction (v6.1)

See merge request espressif/esp-idf!52196
2026-09-04 10:48:08 +05:30
Laukik Hase dedf93a5e5 fix(esp_tee): Fix AEAD output buffer slicing in the tee_basic example 2026-09-04 10:20:32 +05:30
Laukik Hase 4dd7ac7d73 change(esp_tee): Limit the TEE secure storage AEAD operation input buffer length 2026-09-04 10:20:21 +05:30
Laukik Hase f8d0bae631 feat(esp_tee): Disable the MBEDTLS_PSA_ASSUME_EXCLUSIVE_BUFFERS option for TEE build 2026-09-04 10:20:21 +05:30
Laukik Hase 4057fcda2d fix(esp_tee): Snapshot input arguments in TEE memory before secure service execution 2026-09-04 10:20:21 +05:30
Laukik Hase 02bf7ea021 change(esp_tee): Force non-deterministic ECDSA signing for TEE secure storage keys 2026-09-04 10:20:20 +05:30
Laukik Hase bc6b8f7fa5 feat(esp_tee): Use CTR-DRBG for assisting random number generation in TEE
- For ESP-TEE, fault-assert in `esp_random()` if the RNG is held in a
  freeze state
2026-09-04 10:20:20 +05:30
Laukik Hase 79751671ce feat(hal): Add LL-API to check whether RNG is enabled
- Also add RNG LL-APIs for ESP32-C61
2026-09-04 10:20:20 +05:30
Laukik Hase f26c18bd5b fix(esp_tee): Reject re-entrant secure service calls from the REE 2026-09-04 10:20:19 +05:30
Sajia 1b60eab541 refactor(wifi): Improve owe scan time and refactor code 2026-09-04 12:04:43 +08:00
tarun.kumar 4c5df8be98 fix(wifi) : Add scan only parser to show AP full compatibility 2026-09-04 12:04:04 +08:00
tarun.kumar 04f2001014 fix(wifi) : Add validation check in roc and tx_req api's, update doc 2026-09-04 12:03:49 +08:00
tarun.kumar f30c83058f fix(wifi) : Made changes to scan and doing it group decreasing scan time and increasing throughput 2026-09-04 12:03:38 +08:00
Mahavir Jain 1612b25e70 fix(build): word-align the length symbol of embedded data files
The generated assembly emitted <name>_length immediately after the raw
payload bytes, so the 32-bit word landed misaligned whenever the data
size was not a multiple of 4. Consumers declare it as a 32-bit object
(e.g. `extern const size_t <name>_length` in the ULP firmware loaders),
so the compiler emits an alignment-assuming word load, which is a
misaligned flash read prone to spurious load faults on chips with
SOC_CPU_MISALIGNED_ACCESS_ON_PMP_MISMATCH_ISSUE (ESP32-C6/H2/H21).
2026-09-04 11:51:56 +08:00
Mahavir Jain e44c357a02 fix(mbedtls): read crt bundle byte-wise to avoid misaligned flash access
The offset table and the per-cert length fields of the certificate
bundle were read through uint16_t*/uint32_t* casts, which compile to
halfword/word loads at addresses with no alignment guarantee: bundles
supplied via esp_crt_bundle_set() can start anywhere, and cert entries
are byte-packed, so their 16-bit fields land at arbitrary offsets.

On chips with SOC_CPU_MISALIGNED_ACCESS_ON_PMP_MISMATCH_ISSUE (DIG-694:
ESP32-C6/H2/H21) a misaligned load from memory-mapped flash can take a
spurious "Load access fault" when it sits within two instructions of an
access to a differently-permissioned region, observed as a crash in
esp_crt_check_bundle()/CA callback during TLS handshakes with a bundle
that happened to be placed at an odd address.
2026-09-04 11:51:56 +08:00
Akshat Agrawal c74d81ab51 fix(wpa_supplicant): Assign correct return value for SAE y-construction failure 2026-09-04 11:44:40 +08:00
Jiang Jiang Jian 9c8d416346 Merge branch 'fix/update_trng_workflow_for_esp32s31_v6.1' into 'release/v6.1'
fix(rng): fix esp_random failed beacuse do not enable RNG clock(v6.1)

See merge request espressif/esp-idf!52317
2026-09-04 11:42:23 +08:00
morris 131a7974ac Merge branch 'feat/atomic-internal_v6.1' into 'release/v6.1'
fix(driver): allocate driver objects containing atomic variables from internal SRAM (v6.1)

See merge request espressif/esp-idf!52340
2026-09-04 11:16:08 +08:00
Shu Chen 7462e1d2e3 Merge branch 'fix/fix_openthread_netif_glue_deinit_issue_v6.1' into 'release/v6.1'
fix(openthread): fix stack deinit by reversing netif glue teardown and hardening workflow cleanup (v6.1)

See merge request espressif/esp-idf!52397
2026-09-04 03:08:09 +00:00
Zhi Wei Jian 5eb72d5eab feat(ble/bluedroid): reject LE re-pairing that weakens an existing bond
Add smp_repairing_is_allowed() behind BT_BLE_SMP_HARDENED_REPAIRING so a
peer cannot replace an existing bond with one that has less MITM
protection, no Secure Connections, or a shorter key. Compare a preceding
Security Request against the pairing command AuthReq, not the
association-model result, and always allow first pairing.

A refusal keeps the stored bond. Pairing-failure erase is split by link
role: default is erase as Central and keep as Peripheral.

Closes BLERP (NDSS 2026) V3, V4 and V6.


(cherry picked from commit 88ea45be73)

Co-authored-by: zhiweijian <zhiweijian@espressif.com>
2026-09-04 11:04:00 +08:00
Zhi Wei Jian 5ed6b8dc0c fix(ble/bluedroid): harden LE bond handling across encryption
Keep the existing bond until the new pairing is encrypted, and on encryption
failure drop the link instead of clearing keys. Recovering from a peer that
really deleted the bond is opt-in through BT_BLE_SMP_UNBOND_ON_KEY_MISSING.

Closes BLERP (NDSS 2026) V5, and stops an unauthenticated Pairing Request
from dropping the stored keys (V2 exploitation).


(cherry picked from commit f864615d7d)

Co-authored-by: zhiweijian <zhiweijian@espressif.com>
2026-09-04 11:03:59 +08:00
Island 6955bf97cb Merge branch 'change/ble_update_lib_20260901_v6.1' into 'release/v6.1'
change(ble): [AUTO_MR] 20260901 - Update ESP BLE Controller Lib (6.1)

See merge request espressif/esp-idf!52285
2026-09-04 10:53:29 +08:00
cjin df470e9dee feat(sleep): applied regi2c conflict process at regdma rf 2026-09-04 10:51:55 +08:00
cjin aebcc6842d fix(phy): add fe dependency when enable rf with regdma 2026-09-04 10:51:14 +08:00
cjin c2a1465dc2 fix(sleep): fix reject trigger when wifi is enabled 2026-09-04 10:51:14 +08:00
zhuanghang 55b00bb1e4 feat(802.15.4): enable switch rf with regdma for 15.4 2026-09-04 10:51:04 +08:00
cjin 275e34f318 fix(phy): added fe set freq reset to rf retention list 2026-09-04 10:27:25 +08:00
cjin 40dbcb9ea6 feat(phy): support retention module for phy FE retgisters 2026-09-04 10:27:25 +08:00
cjin 3c875310d1 feat(modem): add phy retention related api 2026-09-04 10:27:25 +08:00
cjin a79519d844 feat(phy): add skip list to sleep phy link context and fix deinit crash 2026-09-04 10:27:25 +08:00
cjin 506e3b30ed feat(sleep): add config SOC_PM_SUPPORT_REGDMA_TRIGGERED_PHY 2026-09-04 10:27:25 +08:00
cjin 77003bcf0c feat(sleep_modem): allow multi modem to enable rf with regdma 2026-09-04 10:27:25 +08:00
cjin 0780acf55e feat(modem): rename the sleep modem functions 2026-09-04 10:27:25 +08:00
cjin ee6cda2551 feat(phy): added skip method for phy retention list 2026-09-04 10:27:25 +08:00
cjin 639ae612ed feat(phy): rename sleep modem state to sleep phy 2026-09-04 10:27:25 +08:00
Island a03feffce8 Merge branch 'idf/ble_mesh_iv_recover_v6.1' into 'release/v6.1'
feat(ble_mesh): Enable IV Index recovery by default (6.1)

See merge request espressif/esp-idf!51973
2026-09-04 10:25:57 +08:00
Matteo Sandrin e8db799e9f fix(bt/bluedroid): delete the unused AVRCP acceptor RCB when A2DP open fails 2026-09-04 10:07:47 +08:00
Shu Chen e87eb3bd62 Merge branch 'feat/support_multipan_feature_host_20260813_v6.1' into 'release/v6.1'
feat(openthread): add support for the multipan feature on host devices (v6.1)

See merge request espressif/esp-idf!52373
2026-09-04 02:07:20 +00:00
morris 69889c4097 Merge branch 'refactor/dac_examples_v6.1' into 'release/v6.1'
refactor(dac): remove adc read back in dac example, prepare for s31 (v6.1)

See merge request espressif/esp-idf!52330
2026-09-04 09:53:18 +08:00
morris 50f822e709 Merge branch 'fix/ci_h4_enable_spi_test_backport' into 'release/v6.1'
fix(driver_twai): fix potential crash when node_delete from high priority task (v6.1)

See merge request espressif/esp-idf!51987
2026-09-04 09:52:12 +08:00
Liu Linyan ed16327b81 feat(ble_audio): Add CAP Handover (U2B & B2U) example 2026-09-04 09:26:24 +08:00
Liu Linyan 130e4a07bb fix(ble_audio): Fix wrong registration when multiple tbs instances exist 2026-09-04 09:26:24 +08:00
Liu Linyan ae452a0ce9 feat(ble_audio): Support BLE ISO & BLE Audio deinitialization 2026-09-04 09:26:24 +08:00
Liu Linyan 1aa418d673 fix(ble_audio): Miscellaneous fixes for running coordinated set 2026-09-04 09:26:24 +08:00
Liu Linyan cd0572bbb6 feat(ble_audio): Miscellaneous update for ISO & Audio examples 2026-09-04 09:26:24 +08:00
Liu Linyan 89ea6e2b08 fix(ble_audio): Recover ISO HCI cmd from a dropped hciT wakeup 2026-09-04 09:26:24 +08:00