Commit Graph
35566 Commits
Author SHA1 Message Date
morris 30df02cb6a Merge branch 'fix/dac_continuous_flag' into 'release/v6.0'
fix(dac): dac_continuous set is_cyclic flag in async mode

See merge request espressif/esp-idf!50490
2026-07-09 11:11:44 +08:00
Song Ruo Jing 9db6c73022 fix(dma2d): fix non-usable DMA2D_CSC_TX_SCRAMBLE option 2026-07-08 23:15:57 +08:00
Song Ruo JingandCursor 3294481ac4 fix(dma2d): fix race with dma2d_force_end and ISR
free_up_channels can only be called once for a started transaction.
Double free will undesirely stop the next picked 2D-DMA transaction on the same channel.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-07-08 23:15:56 +08:00
Xu Si Yu 30a2d5c25d feat(openthread): update thread-lib for upstream b678a4f6
* esp-openthread: thread_zigbee/esp-openthread@47428f1e8
* openthread: espressif/openthread@b678a4f63
* esp-idf: espressif/esp-idf@c629a359b
2026-07-08 13:01:42 +00:00
Mahavir Jain cf06294ca9 Merge branch 'fix/esp_http_client_header_buffer_too_small_v6.0' into 'release/v6.0'
feat(esp_http_client): detect oversized headers in tx buffer at send site (v6.0)

See merge request espressif/esp-idf!50314
2026-07-08 18:25:12 +05:30
Mahavir Jain 65aeed5c00 Merge branch 'fix/tls1_3_dynamic_buffer_server_crash_v6.0' into 'release/v6.0'
fix(mbedtls): fixes TLS1.3 server failing with dynamic buffer (v6.0)

See merge request espressif/esp-idf!50387
2026-07-08 18:23:37 +05:30
Mahavir Jain 77fd953aba Merge branch 'fix/harden_mbedtls_port_layer_v6.0' into 'release/v6.0'
fix(mbedtls): harden port layer to zeroize sensitive material (v6.0)

See merge request espressif/esp-idf!50316
2026-07-08 18:22:31 +05:30
Xu Si Yu c629a359b7 feat(openthread): update openthread submodule 2026-07-08 20:38:44 +08:00
Xu Si Yu ebc79defd7 fix(openthread): fix TREL peer discovery by selecting IPv6 from mDNS address list 2026-07-08 20:38:44 +08:00
Song Ruo Jing 4fbbc16ac6 fix(dma2d): add a dequeue mechanism for dma2d driver
JPEG driver should be able to either dequeue a pending transaction from
a 2D-DMA pool or force end a processing transaction.
2026-07-08 20:11:08 +08:00
Euripedes Rocha 9369102192 Merge branch 'fix/mqtt_remove_leftovers_v6.0' into 'release/v6.0'
fix(mqtt): Remove mqtt leftovers from IDF

See merge request espressif/esp-idf!49552
2026-07-08 11:03:15 +02:00
Rahul Tank 519ff91e23 Merge branch 'bugfix/ai_reviewer_nimble_1.6_v6.0' into 'release/v6.0'
fix(nimble): Fixes for AI reported issues (v6.0)

See merge request espressif/esp-idf!50014
2026-07-08 13:57:25 +05:30
Hu Rui 45d04d1239 fix(dac): dac_continuous set is_cyclic flag in async mode 2026-07-08 15:47:07 +08:00
Erhan Kurubas 4182ddebbd fix(esp_coredump): count only written tasks against MAX_TASKS_NUM limit 2026-07-08 08:44:29 +02:00
Erhan Kurubas b89a1b517d fix(esp_coredump): fix unused-but-set-variable warnings 2026-07-08 08:44:10 +02:00
Jiang Jiang Jian ecb9d864d5 Merge branch 'feat/update_pmu_pau_reg_description_v6.0' into 'release/v6.0'
feat(soc): update esp32c61 PMU & PAU reg header descriptions (v6.0)

See merge request espressif/esp-idf!50432
2026-07-08 14:33:53 +08:00
Jiang Jiang Jian 2a15269b80 Merge branch 'bugfix/fix_some_wifi_bugs_260706_v6.0' into 'release/v6.0'
fix(wifi): fix some wifi bugs 260706 v6.0(Backport v6.0)

See merge request espressif/esp-idf!50396
2026-07-08 14:26:57 +08:00
Ondrej Kosta 6eb451f40f feat(esp_eth): update test_apps to use Ethernet test component
Move test logic into the eth_test_app managed component and slim down
the test_apps main target and pytest suite accordingly.
2026-07-08 08:01:45 +02:00
Euripedes Rocha 97abdf4e3b Merge branch 'contrib/github_pr_18642_v6.0' into 'release/v6.0'
fix(eth): use stored base_increment when computing PTP addend (GitHub PR) (v6.0)

See merge request espressif/esp-idf!49104
2026-07-08 07:59:47 +02:00
Wang Meng Yang b1f7a5b8b8 Merge branch 'bugfix/sdp_null_access_v6.0' into 'release/v6.0'
fix(bt/bluedroid): fixed SDP deinit race with pending callbacks (v6.0)

See merge request espressif/esp-idf!48895
2026-07-08 12:42:23 +08:00
Tomáš Rohlínek d4fdaae0dd fix(storage/fatfs): fix FAT32 mount integer overflow (CVE-2026-6682)
The initial CVE-2026-6682 fix hardened the exFAT mount path, but the CVE
as reported by runZero is a FAT32 defect in mount_volume() and is
reachable in the default configuration (exFAT and 64-bit LBA disabled).
This corrects the fix.

Root cause: `fasize *= fs->n_fats` is a DWORD multiply with no overflow
guard. A crafted BPB_FATSz32 such as 0x80000001 with NumFATs=2 wraps
`fasize` to 0x00000002. The wrapped (too-small) FAT size places
`fs->database` inside the FAT region, so a forged directory entry yields
an attacker-controlled `finfo.fsize`; a caller using it as a read length
overflows its buffer with attacker-controlled bytes (CVSS 7.6).

Fix: reject per-FAT and reserved+FAT+root system-area sizes that overflow
DWORD before they are used to derive the data-area base. The exFAT
cluster-heap/bitmap 64-bit promotions are retained as defense-in-depth
and relabeled (they are not CVE-2026-6682). SBOM reason updated.
2026-07-07 16:36:32 +02:00
Rahul Tank 38f4edb16e fix(nimble): Fixes for AI reported issues 2026-07-07 16:18:32 +05:30
Ashish Sharma 92cefa205a feat(esp_http_client): detect oversized headers in tx buffer while sending request 2026-07-07 18:18:26 +08:00
Xu Si Yu c61e7ab345 feat(openthread): add APIs to clear a single src match short and extended entry in esp radio spinel 2026-07-07 17:39:42 +08:00
muhaidong 0ed8d91726 fix(wifi): update auth mode threshold doc 2026-07-07 16:00:39 +08:00
muhaidong eda0d8dde1 fix(wifi): update wifi scan threshold doc 2026-07-07 16:00:00 +08:00
muhaidong dbc974cbd8 fix(wifi): fix some wifi bugs 260706 v6.0
1. support weak func for wifi lmac assert
2. post disconnect event after disassociation tx callback
3. update auth mode threshold doc3. update auth mode threshold doc3.
   update auth mode threshold doc
2026-07-07 15:59:18 +08:00
morris db3825c799 Merge branch 'fix/spi_buslock_multi_dev_acq_release_issue_v6.0' into 'release/v6.0'
fix(esp_hw_support): fixed spi buslock multi dev acq/release logic issue (v6.0)

See merge request espressif/esp-idf!49168
2026-07-07 14:53:55 +08:00
morris 2c62bd65b0 Merge branch 'backport/spi_slave_independent_tx_rx_length_v6.0' into 'release/v6.0'
feat(driver_spi): slave driver support config different tx/rx length (v6.0)

See merge request espressif/esp-idf!49964
2026-07-07 14:50:44 +08:00
Scramble ToolsandOndrej Kosta e0becb9e43 fix(esp_eth): use stored base_increment when computing PTP addend
The addend in `emac_hal_ptp_start()` was derived from the floating-point
`config->ptp_req_accuracy_ns` instead of the integer `base_increment`
register that actually drives the sub-second update. The cast to
`uint8_t` loses the fractional part, so the un-corrected addend leaves
the PTP clock running off-rate.

Example: with a 40 MHz XTAL and the default `req_accuracy_ns = 40`,
`base_increment` rounds 85.899 up to 86, leaving the clock +1170 ppm
fast — well outside the IEEE 802.1AS neighborRateRatio limit (~±200
ppm), so strict-1AS bridges refuse asCapable.

Compute the addend from the stored `base_increment` for both rollover
modes: `addend = 2^32 * clk_period_ns / increment_ns`.

Measured on ESP32-P4: neighborRateRatio drops from +1147.5 ppm to
+4.2 ppm, and asCapable is granted.

Co-authored-by: Ondrej Kosta <panzer412@gmail.com>
2026-07-07 08:37:04 +02:00
muhaidong 7afed49b3f fix(wifi): support weak func for wifi lmac assert 2026-07-07 14:07:47 +08:00
muhaidong dd8653bbeb fix(coex): remove unsupported external coex soc caps 2026-07-07 14:07:47 +08:00
morris b3b9ebb516 Merge branch 'bugfix/i2c_set_but_not_used_variable_v6.0' into 'release/v6.0'
fix(i2c): remove unused but set variables (v6.0)

See merge request espressif/esp-idf!50371
2026-07-07 13:13:07 +08:00
Jiang Jiang Jian 0cb8f5ef2d Merge branch 'fix/add_owe_check_pmf_disable_v6.0' into 'release/v6.0'
Add Mode/threshold checks in esp_wifi_disable_pmf_config()(v6.0)

See merge request espressif/esp-idf!48951
2026-07-07 10:46:43 +08:00
morris f4af8b9335 Merge branch 'feature/dma2d_ppa_sleep_retention_support_v6.0' into 'release/v6.0'
feat(ppa): add sleep retention support for DMA2D and PPA (v6.0)

See merge request espressif/esp-idf!50350
2026-07-07 10:35:38 +08:00
Marius Vikhammer 1195a15240 Merge branch 'fix/vfs_fatfs_test_stale_partition_v6.0' into 'release/v6.0'
test(vfs): reformat WL FATFS in setup to avoid stale-partition flakes (v6.0)

See merge request espressif/esp-idf!50401
2026-07-07 09:49:29 +08:00
Tomáš Rohlínek 5b3090c3e2 fix(storage/fatfs): record non-applicable runZero 2026 CVEs in SBOM
Document the three runZero "Seven FatFs bugs" CVEs that require no source change
in this component, so vulnerability scanners have their disposition:

  - CVE-2026-6684: GPT partition-scan loop DoS. Already fixed upstream in R0.16,
    where test_gpt_header() caps the partition-entry count at 128.
  - CVE-2026-6686: read of uninitialized clusters after f_lseek() past EOF.
    Longstanding, behavioral; not a memory-safety defect and zero-filling every
    extended cluster is prohibitively costly on flash.
  - CVE-2026-6688: long-filename overflow in downstream callers. Not exposed in
    ESP-IDF; vfs_fat.c uses bounded copies and fname is bounded by FF_MAX_LFN.

Reference: https://www.runzero.com/blog/fatfs-bugs/
2026-07-06 16:19:09 +02:00
wuzhenghui 97d115919d feat(soc): update PMU & PAU register description 2026-07-06 21:23:16 +08:00
Tomáš Rohlínek da6afc4eee fix(storage/fatfs): clamp exFAT volume-label length in f_getlabel() (CVE-2026-6687)
f_getlabel() extracts the exFAT volume label with a loop bounded by the on-disk
byte dj.dir[XDIR_NumLabel] (0-255):

    for (si = di = hs = 0; si < dj.dir[XDIR_NumLabel]; si++)
        wc = ld_16(dj.dir + XDIR_Label + si * 2);

The exFAT label field holds at most 11 UTF-16 units (22 bytes). A crafted
directory entry with a larger count both reads past the 22-byte label field and,
through put_utf(... &label[di], 4), writes past the end of the caller-provided
label buffer (the canonical API examples use small fixed stack buffers) -> stack
buffer overflow.

Clamp the character count to the exFAT maximum of 11 before the extraction loop.
Record the CVE in the component SBOM.

Note: f_getlabel() takes no destination-buffer size, so under UTF-8 output
(FF_LFN_UNICODE == 2) 11 units can still expand to up to 34 bytes; the clamp
downgrades this from attacker-unbounded to spec-bounded. ESP-IDF's VFS layer
does not call f_getlabel(); direct callers on untrusted media should size their
buffer accordingly. A complete fix requires an upstream size-aware API change.

Reference: https://www.runzero.com/blog/fatfs-bugs/
2026-07-06 14:49:08 +02:00
Tomáš Rohlínek 5019c06dd4 fix(storage/fatfs): guard dirty-cache refill against unsigned LBA wrap (CVE-2026-6685)
After a direct multi-sector disk_read()/disk_write(), FatFs decides whether the
cached sector overlaps the direct-I/O range with:

    fp->sect - sect < cc          (and the FF_FS_TINY variant fs->winsect - sect < cc)

`sect`, `fp->sect` and `fs->winsect` are unsigned LBA_t. On 32-bit LBA_t builds,
if the cached sector is below `sect`, the subtraction wraps to a huge value that
can still compare `< cc`, so the code computes a bogus large offset:

  - in f_write() it mis-copies from the direct write buffer (data corruption);
  - in f_read() it is worse: memcpy(rbuff + (wrapped_offset * SS), ...) is an
    out-of-bounds WRITE into the caller-supplied read buffer.

Add an explicit lower-bound check (fp->sect >= sect, resp. fs->winsect >= sect)
before the range test on both the read and write paths and both the FF_FS_TINY
and normal variants, so the condition is exactly "cached sector lies within
[sect, sect + cc)". Record the CVE in the component SBOM.

Reference: https://www.runzero.com/blog/fatfs-bugs/
2026-07-06 14:49:08 +02:00
Tomáš Rohlínek a407d4f82b fix(storage/fatfs): reject empty exFAT cluster heap (CVE-2026-6683)
CVE-2026-6683 is an exFAT divide-by-zero: with NumClusters == 0 the filesystem
object has fs->n_fatent == 2, and the exFAT "percent in use" update in sync_fs()
computes ... * 100 / (fs->n_fatent - 2) -> division by zero.

That vulnerable exFAT PercInUse sync path was introduced in FatFs R0.16 and is
NOT present in this R0.15 release, so the divide-by-zero itself is not reachable
here. As defense-in-depth (and to keep parity with newer releases) reject an
empty exFAT cluster heap at mount time, which is a malformed volume regardless.

Record the CVE disposition in the component SBOM.

Reference: https://www.runzero.com/blog/fatfs-bugs/
2026-07-06 14:49:08 +02:00
Tomáš Rohlínek 9466a3d529 fix(storage/fatfs): fix exFAT mount integer overflow (CVE-2026-6682)
The exFAT mount path validates that the media is large enough to hold the
declared cluster heap with:

    if (maxlba < (QWORD)fs->database + ncl * fs->csize) ...

`ncl` (DWORD, up to MAX_EXFAT) and `fs->csize` (WORD) are both promoted to
`unsigned int`, so `ncl * fs->csize` is evaluated in 32-bit arithmetic and can
wrap before the QWORD promotion of the sum. A crafted image with a large
NumClusters/SecPerClus can therefore make an undersized volume pass the "size
is large enough" check; subsequent cluster->sector math then addresses media
outside the actual device.

Promote the multiply to 64-bit ((QWORD)ncl * fs->csize). Apply the same
promotion to the bitmap-base computation ((LBA_t)fs->csize * (bcl - 2)), which
has the identical overflow shape. Record the CVE in the component SBOM.

Reference: https://www.runzero.com/blog/fatfs-bugs/
2026-07-06 14:49:08 +02:00
morris 8e9d45c367 Merge branch 'fix/fix_async_color_convert_csc_v6.0' into 'release/v6.0'
fix(dma2d): fix async color convert csc check (v6.0)

See merge request espressif/esp-idf!50239
2026-07-06 19:02:39 +08:00
Luo Xu 85d760323f fix(ble_mesh): re-check scan dev-found cb before scan-rsp invocation
(cherry picked from commit 9a3a767824)

Co-authored-by: luoxu <luoxu@espressif.com>
2026-07-06 17:44:30 +08:00
Luo Xu db95f9081d fix(ble_mesh): comment out logs containing sensitive keys
(cherry picked from commit 781d6b2314)

Co-authored-by: luoxu <luoxu@espressif.com>
2026-07-06 17:44:30 +08:00
Luo Xu 0fd8253754 fix(ble_mesh): validate PB-ADV start segment length
(cherry picked from commit 912ec8dc62)

Co-authored-by: luoxu <luoxu@espressif.com>
2026-07-06 17:44:29 +08:00
Luo Xu 4c79d1f6db fix(ble_mesh): Reset reassembly buffer at start of each transaction
The reassembly buffer must be reset to its origin at the beginning of every
transaction. prov_msg_recv() pulls the PDU type byte (advancing buf->data by
one) and nothing restores it between transactions. Without this reset,
buf->data drifts forward by one byte per received PDU, causing the segment-0
memcpy to write past the end of the statically allocated rx buffer
(PROV_RX_BUF_SIZE), and the XACT_SEG_DATA() offsets used for continuation
segments to be skewed by the accumulated drift.


(cherry picked from commit 2c4acaa2aa)

Co-authored-by: luoxu <luoxu@espressif.com>
2026-07-06 17:44:28 +08:00
Luo Xu fd96eeb6a2 fix(ble_mesh): fix DFD client message parsing and encoding bugs
Fix multiple wire-format and robustness issues in the DFD client
(dfd_cli.c):

- handle_capabilities: read oob_retrieval_supported as u8 instead of
  le32. The server encodes a single byte; le32 over-consumed 3 bytes
  of the URL scheme list and could over-read the buffer.
- handle_upload_status: extract upload_progress from bits 0-6 (& 0x7F)
  and upload_type from bit 7 (>> 7), matching the server encoding
  (progress | BIT(7)). The previous >>1 / &0x01 returned wrong values,
  mis-classified in-band vs OOB, and falsely rejected valid OOB
  messages with high progress.
- handle_dfd_status: correct the transfer-mode byte layout to
  trans_mode bits 0-1, update_policy bit 2, RFU bits 3-7 (previously
  read bits 6-7 / 5), and fix the RFU mask to 0xF8. Now matches the
  struct bitfield definition and the DFD server.
- handle_dfd_status: report status+phase and return early when
  buf->len == 0 (IDLE phase) instead of pulling 10 absent bytes.
- bt_mesh_dfd_cli_distribution_start: encode trans_mode/update_policy
  into bits 0-2 so the server decodes them correctly.
- handle_receiver_list: validate buf->len >= entries_cnt * 5 before
  the loop, and handle entries_cnt == 0 without relying on calloc(0).
- handle_receiver_status: pass the status value (not the whole union)
  to the %d log format, fixing undefined behavior.
- dfd_client_recv_status: drop the dead BLE_MESH_DFD_OP_CAPABILITIES_GET
  case (a client-send opcode) from the receive switch.
- bt_mesh_dfd_cli_receivers_add: widen msg_length to uint32_t to avoid
  uint16_t overflow that bypassed the PDU size guard; add a NULL check
  for the receivers array.
- bt_mesh_dfd_cli_distribution_upload_oob_start: return -EINVAL
  instead of -1 for consistency with the rest of the file.


(cherry picked from commit 43137475e1)

Co-authored-by: luoxu <luoxu@espressif.com>
2026-07-06 17:44:26 +08:00
Luo Xu 81602499af fix(ble_mesh): added max dfd srv count limit
(cherry picked from commit 781218cb62)

Co-authored-by: luoxu <luoxu@espressif.com>
2026-07-06 17:44:24 +08:00
Luo Xu e374e94a58 fix(ble_mesh): reject invalid chunk size
(cherry picked from commit 35cd10fbdf)

Co-authored-by: luoxu <luoxu@espressif.com>
2026-07-06 17:44:22 +08:00