Commit Graph
5722 Commits
Author SHA1 Message Date
Zhi Wei Jian bd8ce47005 fix(ble/bluedroid): validate GATT client discovery handles
(cherry picked from commit ac35ae6f2d)

Co-authored-by: zhiweijian <zhiweijian@espressif.com>
2026-07-14 12:04:21 +08:00
Zhi Wei Jian 98a8e41c83 fix(ble/bluedroid): cap Read By Type length and free failed service decl
(cherry picked from commit 27ff0cf8c7)

Co-authored-by: zhiweijian <zhiweijian@espressif.com>
2026-07-14 12:04:21 +08:00
Zhi Wei Jian 418cf61513 fix(ble/bluedroid): guard GATT database hash and serialization
(cherry picked from commit 995c1508e8)

Co-authored-by: zhiweijian <zhiweijian@espressif.com>
2026-07-14 12:04:21 +08:00
Zhi Wei Jian de2544c5de fix(ble/bluedroid): fix GATT server busy errors and sr_cmd handling
(cherry picked from commit f86739b03d)

Co-authored-by: zhiweijian <zhiweijian@espressif.com>
2026-07-14 12:04:20 +08:00
Zhi Wei Jian 07f3362a98 fix(ble/bluedroid): fix GATT teardown and service-change flow
(cherry picked from commit 0645ba469d)

Co-authored-by: zhiweijian <zhiweijian@espressif.com>
2026-07-14 12:04:20 +08:00
Zhi Wei Jian bdba7a71d7 fix(ble/bluedroid): fix GATT service lifecycle leaks
(cherry picked from commit ac93d94958)

Co-authored-by: zhiweijian <zhiweijian@espressif.com>
2026-07-14 12:04:19 +08:00
Zhi Wei Jian 6e0ea41536 fix(ble/bluedroid): add GATT resource-cleanup helpers
(cherry picked from commit b83327f3ca)

Co-authored-by: zhiweijian <zhiweijian@espressif.com>
2026-07-14 12:04:19 +08:00
Zhi Wei Jian 87d614ba91 feat(ble/bluedroid): Support bluedroid LE COC and EATT features
(cherry picked from commit 83f0831c53)

Co-authored-by: zhiweijian <zhiweijian@espressif.com>
2026-07-14 11:56:06 +08:00
Jiang Jiang Jian 11e4196a49 Merge branch 'fix/ble_mesh_fixed_issues_v6.0' into 'release/v6.0'
Resolve reported BLE mesh stack issues (6.0)

See merge request espressif/esp-idf!50407
2026-07-09 12:36:16 +08:00
Jiang Jiang Jian f579370571 Merge branch 'fix/reduce_acl_event_gaps_v6.0' into 'release/v6.0'
feat(ble): updated libble to 71d180a4 for esp32h4 and esp32s31 (6.0)

See merge request espressif/esp-idf!49592
2026-07-09 12:30:26 +08:00
Rahul Tank 519ff91e23 Merge branch 'bugfix/ai_reviewer_nimble_1.6_v6.0' into 'release/v6.0'
fix(nimble): Fixes for AI reported issues (v6.0)

See merge request espressif/esp-idf!50014
2026-07-08 13:57:25 +05:30
Wang Meng Yang b1f7a5b8b8 Merge branch 'bugfix/sdp_null_access_v6.0' into 'release/v6.0'
fix(bt/bluedroid): fixed SDP deinit race with pending callbacks (v6.0)

See merge request espressif/esp-idf!48895
2026-07-08 12:42:23 +08:00
Rahul Tank 38f4edb16e fix(nimble): Fixes for AI reported issues 2026-07-07 16:18:32 +05:30
Luo Xu 85d760323f fix(ble_mesh): re-check scan dev-found cb before scan-rsp invocation
(cherry picked from commit 9a3a767824)

Co-authored-by: luoxu <luoxu@espressif.com>
2026-07-06 17:44:30 +08:00
Luo Xu db95f9081d fix(ble_mesh): comment out logs containing sensitive keys
(cherry picked from commit 781d6b2314)

Co-authored-by: luoxu <luoxu@espressif.com>
2026-07-06 17:44:30 +08:00
Luo Xu 0fd8253754 fix(ble_mesh): validate PB-ADV start segment length
(cherry picked from commit 912ec8dc62)

Co-authored-by: luoxu <luoxu@espressif.com>
2026-07-06 17:44:29 +08:00
Luo Xu 4c79d1f6db fix(ble_mesh): Reset reassembly buffer at start of each transaction
The reassembly buffer must be reset to its origin at the beginning of every
transaction. prov_msg_recv() pulls the PDU type byte (advancing buf->data by
one) and nothing restores it between transactions. Without this reset,
buf->data drifts forward by one byte per received PDU, causing the segment-0
memcpy to write past the end of the statically allocated rx buffer
(PROV_RX_BUF_SIZE), and the XACT_SEG_DATA() offsets used for continuation
segments to be skewed by the accumulated drift.


(cherry picked from commit 2c4acaa2aa)

Co-authored-by: luoxu <luoxu@espressif.com>
2026-07-06 17:44:28 +08:00
Luo Xu fd96eeb6a2 fix(ble_mesh): fix DFD client message parsing and encoding bugs
Fix multiple wire-format and robustness issues in the DFD client
(dfd_cli.c):

- handle_capabilities: read oob_retrieval_supported as u8 instead of
  le32. The server encodes a single byte; le32 over-consumed 3 bytes
  of the URL scheme list and could over-read the buffer.
- handle_upload_status: extract upload_progress from bits 0-6 (& 0x7F)
  and upload_type from bit 7 (>> 7), matching the server encoding
  (progress | BIT(7)). The previous >>1 / &0x01 returned wrong values,
  mis-classified in-band vs OOB, and falsely rejected valid OOB
  messages with high progress.
- handle_dfd_status: correct the transfer-mode byte layout to
  trans_mode bits 0-1, update_policy bit 2, RFU bits 3-7 (previously
  read bits 6-7 / 5), and fix the RFU mask to 0xF8. Now matches the
  struct bitfield definition and the DFD server.
- handle_dfd_status: report status+phase and return early when
  buf->len == 0 (IDLE phase) instead of pulling 10 absent bytes.
- bt_mesh_dfd_cli_distribution_start: encode trans_mode/update_policy
  into bits 0-2 so the server decodes them correctly.
- handle_receiver_list: validate buf->len >= entries_cnt * 5 before
  the loop, and handle entries_cnt == 0 without relying on calloc(0).
- handle_receiver_status: pass the status value (not the whole union)
  to the %d log format, fixing undefined behavior.
- dfd_client_recv_status: drop the dead BLE_MESH_DFD_OP_CAPABILITIES_GET
  case (a client-send opcode) from the receive switch.
- bt_mesh_dfd_cli_receivers_add: widen msg_length to uint32_t to avoid
  uint16_t overflow that bypassed the PDU size guard; add a NULL check
  for the receivers array.
- bt_mesh_dfd_cli_distribution_upload_oob_start: return -EINVAL
  instead of -1 for consistency with the rest of the file.


(cherry picked from commit 43137475e1)

Co-authored-by: luoxu <luoxu@espressif.com>
2026-07-06 17:44:26 +08:00
Luo Xu 81602499af fix(ble_mesh): added max dfd srv count limit
(cherry picked from commit 781218cb62)

Co-authored-by: luoxu <luoxu@espressif.com>
2026-07-06 17:44:24 +08:00
Luo Xu e374e94a58 fix(ble_mesh): reject invalid chunk size
(cherry picked from commit 35cd10fbdf)

Co-authored-by: luoxu <luoxu@espressif.com>
2026-07-06 17:44:22 +08:00
Luo Xu 33ef03c65c fix(ble_mesh): fixed invalid disconnect handler wrote
(cherry picked from commit 52cfff707f)

Co-authored-by: luoxu <luoxu@espressif.com>
2026-07-06 17:44:21 +08:00
Luo Xu 0924e81ca6 fix(ble_mesh): fixed BLE-Mesh NimBLE extended-adv reassembly buffer overflow on COMPLETE fragment
(cherry picked from commit 1b22467f63)

Co-authored-by: luoxu <luoxu@espressif.com>
2026-07-06 17:44:20 +08:00
Luo Xu c146056e55 fix(ble_mesh): fixed BLE-Mesh GATTS read-callback error
(cherry picked from commit 00adfb3cbc)

Co-authored-by: luoxu <luoxu@espressif.com>
2026-07-06 17:44:19 +08:00
Jiang Jiang Jian ece337bf04 Merge branch 'fix/ble_mesh_disable_adv_pkt_discard_log_v6.0' into 'release/v6.0'
fix(ble_mesh): Disable warning logging when advertising packets are discarded (6.0)

See merge request espressif/esp-idf!50167
2026-07-06 15:13:19 +08:00
Island 797d399dee Merge branch 'fix/ble-log-64-bit-io-setup-support_v6.0' into 'release/v6.0'
fix(ble_log): use BIT64 over BIT to support 64-bit IO setup (6.0)

See merge request espressif/esp-idf!50331
2026-07-06 12:22:07 +08:00
Wang Meng Yang 967825b6e2 Merge branch 'bugfix/bbp_issues_v6.0' into 'release/v6.0'
Bugfix/bbp issues v6.0

See merge request espressif/esp-idf!50189
2026-07-06 11:16:54 +08:00
Rahul Tank c79592004e fix(nimble): Defer Events / ATT related information from stack
Defer Events/ ATT related GAP events from stack until connection
 event is sent to GAP layer
2026-07-03 11:17:23 +05:30
Zhou Xiao c83fdad6dd fix(ble_log): use BIT64 over BIT to support 64-bit IO setup
(cherry picked from commit a2876d304e)

Co-authored-by: Zhou Xiao <zhouxiao@espressif.com>
2026-07-03 12:04:59 +08:00
Zhou Xiao c4743f1d70 change(ble): [AUTO_MR] Update lib_esp32c6 to a6519790
(cherry picked from commit 226a0483b1)

Co-authored-by: Zhou Xiao <zhouxiao@espressif.com>
2026-07-01 10:35:34 +08:00
Zhou Xiao db5d0803d9 change(ble): [AUTO_MR] Update lib_esp32c5 to a6519790
(cherry picked from commit a43358587c)

Co-authored-by: Zhou Xiao <zhouxiao@espressif.com>
2026-07-01 10:35:34 +08:00
Zhou Xiao 5c11f97421 change(ble): [AUTO_MR] Update lib_esp32h2 to a6519790
(cherry picked from commit 8a744e8e93)

Co-authored-by: Zhou Xiao <zhouxiao@espressif.com>
2026-07-01 10:35:33 +08:00
Wang Meng Yang 5f4062d827 Merge branch 'bugfix/ai_review_btu_common_v6.0' into 'release/v6.0'
fix: Fix the critical issues of btu and bt_common from AI review report (v6.0)

See merge request espressif/esp-idf!50122
2026-06-30 19:25:09 +08:00
luoxu b710ac9830 fix(ble_mesh): Disable warning logging when advertising packets are discarded 2026-06-30 16:59:12 +08:00
Jin Cheng 0d118139ff fix(bt/bluedroid): fixed possible OOB write in btc_a2dp_sink_handle_inc_media 2026-06-30 14:43:00 +08:00
Jin Cheng 2a6c38d1eb fix(bt/bluedroid): fixed possible OOB read/write in process_l2cap_cmd 2026-06-30 14:42:56 +08:00
Jiang Jiang Jian d40f9586c5 Merge branch 'bugfix/ai_review_a2dp_v6.0' into 'release/v6.0'
fix(bt): Fix the critical issues related to A2DP from AI review report (v6.0)

See merge request espressif/esp-idf!50128
2026-06-30 12:03:32 +08:00
Jin Cheng f3230cae05 fix(bt/bluedroid): fixed SDP deinit race with pending callbacks
Cancel any active SDP search during disabling and mark the BTA SDP
callbacks inactive so late search completions are not propagated
after deinit. Guard BTC side SDP completion handling after cleanup
to avoid null references.
2026-06-30 11:57:31 +08:00
Island 518eabeb7d Merge branch 'bugfix/fix_bluedroid_static_random_conn_rpa_v6.0' into 'release/v6.0'
fix(ble/bluedroid): skip identity conversion for static random direct connect (6.0)

See merge request espressif/esp-idf!50085
2026-06-30 10:24:28 +08:00
Island e73366f64c Merge branch 'bugfix/fix_bluedroid_rpa_whitelist_conn_v6.0' into 'release/v6.0'
Fix connection failure when using RPA with whitelist filtering(ESP32) (6.0)

See merge request espressif/esp-idf!50091
2026-06-30 10:23:12 +08:00
Rahul Tank cd0ad239a6 Merge branch 'bugfix/nimble_issues_02062026_v6.0' into 'release/v6.0'
fix(nimble):  Fix few nimble issues 02062026 (v6.0)

See merge request espressif/esp-idf!49153
2026-06-29 21:52:48 +05:30
Island 6e73125228 Merge branch 'feat/spi_log_qa_frame_check_v6.0' into 'release/v6.0'
feat(ble_log): add FINAL_STAT session-end frame and flush hook before controller restart (6.0)

See merge request espressif/esp-idf!49958
2026-06-29 20:25:50 +08:00
Zhang Hai Peng af02bd9018 fix(ble/bluedroid): return ESP_ERR_INVALID_ARG for invalid conn params
Return ESP_ERR_INVALID_ARG instead of ESP_FAIL when connection
parameter validation fails


(cherry picked from commit 6c53838e66)

Co-authored-by: zhanghaipeng <zhanghaipeng@espressif.com>
2026-06-29 19:04:29 +08:00
Zhang Hai Peng add48e6f2c fix(ble/bluedroid): add context to GATTC reg-notify cache warning
Include client_if, handle, bd_addr, and server cache state in the
warning logged when notification registration skips handle validation.


(cherry picked from commit 1085a32be8)

Co-authored-by: zhanghaipeng <zhanghaipeng@espressif.com>
2026-06-29 19:04:29 +08:00
Zhang Hai Peng b13f63fd7f fix(ble/bluedroid): report conn param update failure for unknown BD_ADDR
Route unknown BD_ADDR and other immediate failures through the existing
need_cb path so ESP_GAP_BLE_UPDATE_CONN_PARAMS_EVT is always delivered.


(cherry picked from commit f9eaeb5e84)

Co-authored-by: zhanghaipeng <zhanghaipeng@espressif.com>
2026-06-29 19:04:29 +08:00
Zhang Hai Peng 0217c922fe fix(ble/bluedroid): preserve ATT error on prepare write completion
Skip prepare-write echo validation when the GATT stack reports a
non-success status. ATT Error Response carries no prepare-write echo
body (rsp_len=0), so the check incorrectly overwrote errors such as
GATT_INSUF_AUTHENTICATION (0x05) with GATT_INVALID_PDU (0x04).


(cherry picked from commit d5b9350d0f)

Co-authored-by: zhanghaipeng <zhanghaipeng@espressif.com>
2026-06-29 19:04:29 +08:00
Zhang Hai Peng a8ee33b38f fix(ble/bluedroid): preserve HCI status on BLE 4.2 GAP failures
Return BTM_HCI_ERROR | hci_status from legacy BLE 4.2 GAP HCI command
paths instead of mapping failures to BTM_ILLEGAL_VALUE or
BTM_NO_RESOURCES. Add btm_ble_status_from_hci() helper and propagate
real status through scan start/stop completion callbacks.


(cherry picked from commit 47dd785a18)

Co-authored-by: zhanghaipeng <zhanghaipeng@espressif.com>
2026-06-29 19:04:29 +08:00
Zhang Hai Peng 005e8029a9 feat(ble/bluedroid): Optimize Bluedroid memory usage
- Delete unused device records (~356B each)


(cherry picked from commit 7d1c0e9a32)

Co-authored-by: zhanghaipeng <zhanghaipeng@espressif.com>
2026-06-29 19:04:29 +08:00
Zhang Hai Peng ad3a325cc9 fix(ble/bluedroid): cap Read By Type response length at ATT maximum
Read By Type Response Length is one octet (max 255). When MTU was
large enough to return a long characteristic value in one pair, the
server wrote (UINT8)(value_len + 2) and overflowed (e.g. 513 -> 1),
so the client rejected the PDU as GATT_INVALID_PDU (0x04).

Cap server value to 253 bytes per pair, clamp the length byte, and
continue long reads via Read Blob when the capped size is returned.


(cherry picked from commit 97905afccc)

Co-authored-by: zhanghaipeng <zhanghaipeng@espressif.com>
2026-06-29 19:04:29 +08:00
Zhang Hai Peng 50b98393c6 fix(ble/bluedroid): Fixed potential double Execute Write Response
(cherry picked from commit 0a93ccd3b3)

Co-authored-by: zhanghaipeng <zhanghaipeng@espressif.com>
2026-06-29 19:04:29 +08:00
Zhang Hai Peng be3b2cf56b fix(ble/bluedroid): unblock sync HCI cmd on Command Status error
Release the BLE sync semaphore and record HCI status when a
synchronous command is rejected via Command Status, since no
Command Complete event follows.


(cherry picked from commit 29ae92f4ef)

Co-authored-by: zhanghaipeng <zhanghaipeng@espressif.com>
2026-06-29 19:04:29 +08:00