Rahul Tank
bf03b83dfe
fix(nimble): Fix ECC HW byte-order and dropped SOC_ESP_NIMBLE_CONTROLLER
2026-07-16 12:29:32 +05:30
Martin Vychodil
7b3c4fca5b
Merge branch 'fix/cleanup_after_failed_nvs_set_blob_v6.0' into 'release/v6.0'
...
Fixed cleanup after nvs_set_blob failed on ESP_ERR_NVS_NOT_ENOUGH_SPACE (v6.0)
See merge request espressif/esp-idf!50743
2026-07-15 18:41:21 +08:00
morris
f1ddd46629
Merge branch 'feat/sec_esp_drivers_v6.0' into 'release/v6.0'
...
fix(drivers): harden multiple peripheral drivers against local DoS and memory corruption (v6.0)
See merge request espressif/esp-idf!50557
2026-07-15 16:53:40 +08:00
morris
ff81dad1bd
Merge branch 'fix/legacy_twai_rx_non_iso_dlc_oob_v6.0' into 'release/v6.0'
...
fix(driver_twai): fixed legacy twai OOB issue when rx dlc larger than 8 (v6.0)
See merge request espressif/esp-idf!50750
2026-07-15 16:01:02 +08:00
Island
2dc3285e57
Merge branch 'bugfix/fix_bluedroid_read_multi_v6.0' into 'release/v6.0'
...
fix(ble/bluedroid): fix GATT Read Multiple response handling (6.0)
See merge request espressif/esp-idf!50709
2026-07-15 15:38:50 +08:00
Island
1dc74d56a2
Merge branch 'feat/support_bluedroid_le_coc_and_eatt_v6.0' into 'release/v6.0'
...
feat(ble/bluedroid): Support bluedroid LE COC and EATT features (6.0)
See merge request espressif/esp-idf!50715
2026-07-15 14:02:50 +08:00
morris
4edbc85a4a
Merge branch 'bugfix/uart_sw_flow_ctrl_xoff_char_v6.0' into 'release/v6.0'
...
fix(uart): fix uart sw flow ctrl XOFF char write to wrong reg on ESP32C6 (v6.0)
See merge request espressif/esp-idf!50524
2026-07-15 11:52:07 +08:00
morris
a408170eca
Merge branch 'fix/jpeg_enc_encrypt_v6.0' into 'release/v6.0'
...
fix(jpeg): Jpeg can encode and decode in encryption situation (backport v6.0)
See merge request espressif/esp-idf!50664
2026-07-15 11:50:38 +08:00
wanckl
ae628e4e98
fix(driver_twai): add fd test on ci
2026-07-15 11:23:51 +08:00
wanckl
9da7cc92b3
feat(driver_twai): fd hardware support time trigger trans
2026-07-15 11:23:44 +08:00
wanckl
f05afe5722
fix(driver_twai): fixed legacy twai OOB issue when rx dlc larger than 8
2026-07-15 10:47:22 +08:00
radek.tandler
daf4796ef6
fix(nvs_flash): fixed cleanup after nvs_set_blob failed on ESP_ERR_NVS_NOT_ENOUGH_SPACE
...
- fixed identification of blob parts to be cleaned by using right starting chunk index
- improved localisation of blobs for cases where some of pages get reclaimed
- created host test cases covering the edge cases above
2026-07-14 16:42:55 +02:00
Zhi Wei Jian
1ade9c6f0e
feat(ble/bluedroid): Support bluedroid dual identity
...
(cherry picked from commit 2358786647 )
Co-authored-by: zhiweijian <zhiweijian@espressif.com >
2026-07-14 14:17:33 +08:00
Rahul Tank
8982238192
Merge branch 'bugfix/fix_bond_store_overflow_v6.0' into 'release/v6.0'
...
fix(nimble): Fix bond-store overflow when IRK is enabled (v6.0)
See merge request espressif/esp-idf!50624
2026-07-14 11:17:35 +05:30
Zhi Wei Jian
279ad49fb0
fix(ble/bluedroid): use BOOLEAN for BLE HCI command builders
...
(cherry picked from commit abbf001120 )
Co-authored-by: zhiweijian <zhiweijian@espressif.com >
2026-07-14 12:04:31 +08:00
Zhi Wei Jian
05e35f842a
fix(ble/bluedroid): clean up LE CoC connect on CCB alloc failure
...
(cherry picked from commit 4fd1ebb4a9 )
Co-authored-by: zhiweijian <zhiweijian@espressif.com >
2026-07-14 12:04:25 +08:00
Zhi Wei Jian
656af102e8
docs(ble/bluedroid): note ISO BIG HCI alloc failure not checked
...
(cherry picked from commit 34b59d30ae )
Co-authored-by: zhiweijian <zhiweijian@espressif.com >
2026-07-14 12:04:25 +08:00
Zhi Wei Jian
8efe8f6ff4
fix(ble/bluedroid): fix direct-connect cleanup and adv bounds
...
(cherry picked from commit 82e71c1767 )
Co-authored-by: zhiweijian <zhiweijian@espressif.com >
2026-07-14 12:04:24 +08:00
Zhi Wei Jian
395229d444
fix(ble/bluedroid): validate BLE confirm/OOB and sec-check device
...
(cherry picked from commit 93ab11d564 )
Co-authored-by: zhiweijian <zhiweijian@espressif.com >
2026-07-14 12:04:24 +08:00
Zhi Wei Jian
273c463497
fix(ble/bluedroid): validate SMP pair-fail reason and OOB device
...
(cherry picked from commit 98efe02385 )
Co-authored-by: zhiweijian <zhiweijian@espressif.com >
2026-07-14 12:04:23 +08:00
Zhi Wei Jian
179ea3578f
fix(ble/bluedroid): route ATT indication-conf timeout separately
...
(cherry picked from commit 6c3267ee84 )
Co-authored-by: zhiweijian <zhiweijian@espressif.com >
2026-07-14 12:04:23 +08:00
Zhi Wei Jian
0e4c3ca05d
fix(ble/bluedroid): validate ATT PDU sizes
...
(cherry picked from commit bb00b9817d )
Co-authored-by: zhiweijian <zhiweijian@espressif.com >
2026-07-14 12:04:23 +08:00
Zhi Wei Jian
7383c07af9
fix(ble/bluedroid): re-lookup GATT TCB after enc-complete callback
...
(cherry picked from commit 37562af0ea )
Co-authored-by: zhiweijian <zhiweijian@espressif.com >
2026-07-14 12:04:22 +08:00
Zhi Wei Jian
c7d6a7ce9e
fix(ble/bluedroid): fix GATT long read and Service Changed CCC
...
(cherry picked from commit 4ce692ac0c )
Co-authored-by: zhiweijian <zhiweijian@espressif.com >
2026-07-14 12:04:22 +08:00
Zhi Wei Jian
bd8ce47005
fix(ble/bluedroid): validate GATT client discovery handles
...
(cherry picked from commit ac35ae6f2d )
Co-authored-by: zhiweijian <zhiweijian@espressif.com >
2026-07-14 12:04:21 +08:00
Zhi Wei Jian
98a8e41c83
fix(ble/bluedroid): cap Read By Type length and free failed service decl
...
(cherry picked from commit 27ff0cf8c7 )
Co-authored-by: zhiweijian <zhiweijian@espressif.com >
2026-07-14 12:04:21 +08:00
Zhi Wei Jian
418cf61513
fix(ble/bluedroid): guard GATT database hash and serialization
...
(cherry picked from commit 995c1508e8 )
Co-authored-by: zhiweijian <zhiweijian@espressif.com >
2026-07-14 12:04:21 +08:00
Zhi Wei Jian
de2544c5de
fix(ble/bluedroid): fix GATT server busy errors and sr_cmd handling
...
(cherry picked from commit f86739b03d )
Co-authored-by: zhiweijian <zhiweijian@espressif.com >
2026-07-14 12:04:20 +08:00
Zhi Wei Jian
07f3362a98
fix(ble/bluedroid): fix GATT teardown and service-change flow
...
(cherry picked from commit 0645ba469d )
Co-authored-by: zhiweijian <zhiweijian@espressif.com >
2026-07-14 12:04:20 +08:00
Zhi Wei Jian
bdba7a71d7
fix(ble/bluedroid): fix GATT service lifecycle leaks
...
(cherry picked from commit ac93d94958 )
Co-authored-by: zhiweijian <zhiweijian@espressif.com >
2026-07-14 12:04:19 +08:00
Zhi Wei Jian
6e0ea41536
fix(ble/bluedroid): add GATT resource-cleanup helpers
...
(cherry picked from commit b83327f3ca )
Co-authored-by: zhiweijian <zhiweijian@espressif.com >
2026-07-14 12:04:19 +08:00
Zhi Wei Jian
87d614ba91
feat(ble/bluedroid): Support bluedroid LE COC and EATT features
...
(cherry picked from commit 83f0831c53 )
Co-authored-by: zhiweijian <zhiweijian@espressif.com >
2026-07-14 11:56:06 +08:00
Zhang Hai Peng
d53c6ad240
fix(ble/bluedroid): downgrade numeric comparison log to warning
...
(cherry picked from commit 72a49ed53b )
Co-authored-by: zhanghaipeng <zhanghaipeng@espressif.com >
2026-07-14 10:37:17 +08:00
Zhang Hai Peng
4e60648f13
fix(ble/bluedroid): preserve ext adv state when set params fails
...
Only update extend_adv_cb after HCI Set Extended Advertising
Parameters succeeds, so a failed update does not corrupt cached
legacy_pdu and related fields used by adv data validation.
(cherry picked from commit 31bd80fee8 )
Co-authored-by: zhanghaipeng <zhanghaipeng@espressif.com >
2026-07-14 10:37:16 +08:00
Zhang Hai Peng
2a1436daa2
fix(ble/bluedroid): reject invalid ATT error code 0x00 on client
...
Map received error reason 0x00 to GATT_UNKNOWN_ERROR so the client
does not report GATT_SUCCESS with zero-length data on malformed errors.
(cherry picked from commit 1b6f9380f4 )
Co-authored-by: zhanghaipeng <zhanghaipeng@espressif.com >
2026-07-14 10:36:30 +08:00
Zhang Hai Peng
1a914b54d7
fix(ble/bluedroid): use sr_cmd status for GATT server error rsp
...
When sending an ATT error response after a failed server operation,
use p_tcb->sr_cmd.status instead of the last app callback status so
invalid error code 0x00 is not sent to the peer.
(cherry picked from commit 4c0488d92a )
Co-authored-by: zhanghaipeng <zhanghaipeng@espressif.com >
2026-07-14 10:36:29 +08:00
Zhang Hai Peng
af4690857c
fix(ble/bluedroid): match read-multiple-var responses by handle
...
(cherry picked from commit 979c7dc567 )
Co-authored-by: zhanghaipeng <zhanghaipeng@espressif.com >
2026-07-14 10:36:28 +08:00
Zhang Hai Peng
bd4b2050a0
fix(ble/bluedroid): match read-multiple responses by handle
...
Read Multiple may mix stack auto-responses with app async responses,
so multi_rsp_q order can differ from the request handle order. Look up
each response by handle (with occurrence for duplicates) instead of
walking the queue by index, and treat opcode-only buffers as empty.
(cherry picked from commit f91a41510c )
Co-authored-by: zhanghaipeng <zhanghaipeng@espressif.com >
2026-07-14 10:36:27 +08:00
C.S.M
1873ca6359
fix(jpeg): JPEG can encode and decode in encryption situation
2026-07-13 19:56:28 +08:00
morris
7bb15a69f7
fix(sdspi): reject oversized pre-read data before block receive
...
Guard start_command_read_blocks against cards that place TOKEN_BLOCK_START so early that extra_data_size exceeds the bytes expected on the current iteration. Without this check, the unsigned subtraction for will_receive underflows and propagates into memset, SPI transaction length, and memcpy counts against the fixed 516-byte block buffer.
2026-07-13 17:49:03 +08:00
morris
ff4eae5bb1
fix(spi_slave): free DMA-private buffers when transaction queue is full
...
spi_slave_queue_trans calls spi_slave_setup_priv_trans to allocate
DMA buffers, then tries xQueueSend. If the queue is full the function
returns ESP_ERR_TIMEOUT without freeing those buffers, leaking up to
2 * max_transfer_sz per failed call. Call spi_slave_uninstall_priv_trans
before returning the timeout.
2026-07-13 17:49:03 +08:00
morris
54289e87fd
fix(jpeg): release platform mutex on semaphore/pm-lock allocation failure
...
jpeg_acquire_codec_handle acquires s_jpeg_platform.mutex at entry
but two ESP_RETURN_ON_* macros (semaphore-create and PM-lock-create
failure) return without releasing it. Replace with ESP_GOTO_ON_*
that jumps to a cleanup label which frees partial resources, NULLs
the codec pointer, and releases the mutex.
2026-07-13 17:49:03 +08:00
morris
bb48ee0f43
fix(i2c): release platform mutex on intr/pm_lock delete failure
...
ESP_RETURN_ON_ERROR inside the s_i2c_platform.mutex critical section
returns without releasing the mutex, permanently blocking all I2C
bus operations. Replace with ESP_GOTO_ON_ERROR that jumps to a
cleanup label releasing the mutex before return.
2026-07-13 17:43:13 +08:00
morris
ee07d33840
fix(csi): move csi_fsm init before resource allocation to fix err-path leak
...
CSI_FSM_INIT is 1, but the controller struct is zero-allocated.
Any failure before the former csi_fsm assignment (near the end of
esp_cam_new_csi_ctlr) jumped to err: which called s_del_csi_ctlr.
That function bailed out immediately because csi_fsm == 0, leaking
the claimed slot, queue, bridge, DMA channel, PM lock, and backup
buffer. Move csi_fsm = CSI_FSM_INIT right after a successful claim
so the err: path properly tears down all allocated resources.
2026-07-13 17:43:13 +08:00
morris
4cf13298af
fix(adc): add missing input validation for channel and ret_handle
...
- adc_cali_curve_fitting: validate config->chan in check_valid() to
prevent OOB access into s_adc_cali_chan_compens compensation table
- adc_filter: make s_adc_filter_free idempotent on !UNIT_BINDED SoCs
to prevent double-free on repeated adc_del_continuous_iir_filter
- adc_cali_line_fitting(esp32): fix config && config typo to
config && ret_handle, preventing NULL-pointer dereference
2026-07-13 17:43:13 +08:00
morris
df9d2b7ab8
Merge branch 'refactor/move_regdma_entry_config_to_driver_layer_emac_v6.0' into 'release/v6.0'
...
refactor(emac): move sleep retention config into driver layer (v6.0)
See merge request espressif/esp-idf!50620
2026-07-13 17:15:22 +08:00
morris
c2aa496f98
feat(jpeg): simplify decoder example and add pytest coverage
2026-07-13 15:15:39 +08:00
Jiang Jiang Jian
98bdf38ad6
Merge branch 'change/change_regdma_malloc_caps_v6.0' into 'release/v6.0'
...
change(esp_hw_support): change regdma malloc caps to allow getting memory in the DMA pool (v6.0)
See merge request espressif/esp-idf!50258
2026-07-13 10:34:55 +08:00
morris
9881bfd2c8
Merge branch 'fix/touch_read_check_v6.0' into 'release/v6.0'
...
fix(touch): fix hw_ver1 read data check (v6.0)
See merge request espressif/esp-idf!50639
2026-07-11 19:20:12 +08:00
Euripedes Rocha
d1933fd664
Merge branch 'fix/sec-347-hostname-null-check_v6.0' into 'release/v6.0'
...
fix(esp_netif): reject NULL hostname in esp_netif_set_hostname_api (SEC_347) (v6.0)
See merge request espressif/esp-idf!50588
2026-07-10 14:10:03 +02:00