Commit Graph
54141 Commits
Author SHA1 Message Date
linruihao 8cbb5276c2 fix(bt/bluedroid): fix crash during bredr inquiry when zero-addr device is found 2026-07-13 16:25:18 +08:00
morris bedeedafec refactor(etm): move ETM retention info from HAL to driver layer
Move soc_etm_retention_desc_t type definition and soc_etm_retention_info
data from hal component to esp_hw_support component, following the
pattern of other peripheral retention data (e.g. MWDT).

- Create esp_private/etm_retention.h with type and extern declaration
- Create port/<target>/etm_retention.c for each target with retention data
- Remove hal/<target>/etm_periph.c and hal/include/hal/etm_periph.h
- Update esp_etm.c to include the new header
- Update CMakeLists.txt in both components
2026-07-13 15:37:52 +08:00
Euripedes Rocha 6ef9a267f1 Merge branch 'fix/sec-1137-br-glue-double-free' into 'master'
fix(esp_netif): harden br_glue instance-handler cleanup against double-free (SEC-1137)

Closes SEC-1137

See merge request espressif/esp-idf!50337
2026-07-13 09:33:50 +02:00
Fu Hanxi ab97a4ebd1 Merge branch 'ci/update-check-version-labels' into 'master'
ci: update check-version tags

See merge request espressif/esp-idf!48662
2026-07-13 09:20:42 +02:00
liqigan 1b49e48bfd feat(bt/controller): Added LMP debug vendor HCI and fixed some bugs ts on ESP32-S31 2026-07-13 15:15:59 +08:00
gaoxu 24a51e6b16 feat(csi): add MIPI-CSI host error event 2026-07-13 15:10:16 +08:00
Renz Bagaporo 36c9e1aadb fix(esp_timer): enable dump overflow test on linux 2026-07-13 15:52:13 +09:00
Guillaume Souchere b11bb8ea60 Merge branch 'fix/esp-timer-linux-isr-dispatch-in-alarm-thread' into 'master'
fix(esp_timer): process ISR-dispatch timers in alarm thread on Linux

See merge request espressif/esp-idf!50464
2026-07-13 08:51:53 +02:00
Renz Bagaporo 694032c1b1 fix(esp_timer): avoid dump buffer overflow
print_timer_info advanced the dump cursor by snprintf's return value. When a timer line was truncated, snprintf returned the full would-be length, which could move the cursor past the heap buffer and wrap the remaining size before the next write. Add a bounded append helper that clamps truncation to the end of the buffer while preserving the NUL terminator.
2026-07-13 15:45:00 +09:00
nilesh.kale edb3f9daf1 fix(esp_http_client): check http_parser errno after execute to avoid DoS loop 2026-07-13 12:10:15 +05:30
Guillaume Souchere 83d3573027 fix(console): Clamp linenoise cols field to 80 if getColums returns less than that 2026-07-13 08:38:26 +02:00
morris 26647472cc Merge branch 'refactor/move_regdma_entry_config_to_driver_layer_lcd' into 'master'
refactor(lcd): move sleep retention config into driver layer

See merge request espressif/esp-idf!50601
2026-07-13 14:36:54 +08:00
Vincent Hamp 3a8fbfe6c3 fix(mocks): add missing esp_hal_* includes 2026-07-13 08:35:27 +02:00
morris 08346e011a test(drivers): run flash encryption apps on real hardware
Replace the virtual efuse flash-encryption flow in parlio, rmt, and lcd
test apps with real-device flash_enc configs so CI can validate the same
path used on encryption runners.
2026-07-13 14:33:47 +08:00
Renz Bagaporo 5213f1965f fix(esp_timer): add target test for long dump lines 2026-07-13 15:20:57 +09:00
Ashish Sharma 9a99613f1b fix(esp_tee): ensure hal assert is enabled for tee builds 2026-07-13 13:44:56 +08:00
Ashish Sharma 133c1c6f6d fix(esp_tee): enforce MMU-map vaddr validity at the REE->TEE boundary 2026-07-13 13:42:58 +08:00
Ashish Sharma 15d9f9f0bc fix(esp_tee): fixes IV length check for TEE AEAD operations 2026-07-13 13:42:58 +08:00
Alexey Lapshin 46ddc0f4b2 fix(bt): fix unused-but-set-variable warnings 2026-07-13 12:01:15 +07:00
He Binglin e1b1969b8a Merge branch 'fix/esp_idf_h4h21_ana_wait_short' into 'master'
fix(esp_hw_support): fix xtal unstable when carry 154 and ble cases

See merge request espressif/esp-idf!50249
2026-07-13 11:51:58 +08:00
Armando (Dou Yiwen) 29a0803fa5 fix: fixed image header segment count check
Signed-off-by: Armando (Dou Yiwen) <douyiwen@espressif.com>
2026-07-13 11:29:35 +08:00
morris f0f8317e3f Merge branch 'refactor/move_regdma_entry_config_to_driver_layer' into 'master'
refactor(I2S): move sleep retention config into driver layers

See merge request espressif/esp-idf!50300
2026-07-13 11:24:54 +08:00
morris 34a9b4c717 Merge branch 'refactor/move_regdma_entry_config_to_driver_layer_ledc' into 'master'
refactor(ledc): move sleep retention config into driver layer

See merge request espressif/esp-idf!50553
2026-07-13 11:24:14 +08:00
igor.udot c8c9b5940a ci: update check-version tags 2026-07-13 10:27:46 +08:00
Zhi Wei Jian 2e6cbccd55 Merge branch 'feat/support_bluedroid_dual_identify' into 'master'
feat(ble/bluedroid): Support bluedroid dual indentify

See merge request espressif/esp-idf!49640
2026-07-13 10:03:39 +08:00
yi chen e628a207ac fix(spiffs): fix off-by-one in spiffsgen.py obj name length check
SpiffsFS.create_file() rejected names only when strictly longer than
obj_name_len, but CONFIG_SPIFFS_OBJ_NAME_LEN's documented semantics
(see components/spiffs/Kconfig) are that the length includes the
zero-termination character, so the maximum number of actual name
characters is obj_name_len - 1.

With the old check, a name exactly obj_name_len characters long was
accepted. SpiffsObjIndexPage.to_binary() then computes the NUL padding
after the name as (obj_name_len - len(name)), which is 0 in that case,
so the generated image's fixed-size name field ends up with no NUL
terminator anywhere in its reserved region.

Fix the boundary so the generator enforces the same maximum length
that the Kconfig help text documents.
2026-07-13 08:29:48 +08:00
morris 7561d2c5c2 refactor(i2s): move sleep retention config into driver layer
Move per-target I2S regdma retention descriptors out of esp_hal_i2s and
into esp_driver_i2s so the driver owns its backup scope and restore
sequence.
2026-07-12 22:38:39 +08:00
Shengyu Qu 062c948c18 fix(spi_flash): add #if check for s_mxic_set_required_regs()
Currently, s_mxic_set_required_regs() lacks checking for
CONFIG_SPI_FLASH_SUPPORT_MXIC_OPI_CHIP. And this causes a defined but not
used warning when MXIC flash driver is disabled in project config. So add
a #if check for this to supress warning.

Signed-off-by: Shengyu Qu <wiagn@4d2.org>
2026-07-12 03:38:54 +08:00
yi chen 03822bb5a6 fix(vfs): use MAX_FDS instead of VFS_MAX_COUNT when clearing fd table on unregister
esp_vfs_unregister_with_id() scanned only the first VFS_MAX_COUNT
(default 8, max 20) slots of s_fd_table[MAX_FDS] (MAX_FDS = FD_SETSIZE,
64 on non-Cygwin targets) when clearing stale references to the
unregistered VFS. Every other loop over s_fd_table in this file
(and in vfs_calls.c) correctly bounds on MAX_FDS.

Any global fd >= VFS_MAX_COUNT that was still open against the VFS
being unregistered was left with a stale vfs_index pointing at a slot
that esp_get_free_index() can immediately hand out to the next
esp_vfs_register*() call, causing later operations on that fd to be
routed into an unrelated filesystem's context.

Signed-off-by: yi chen <94xhn1@gmail.com>
2026-07-12 03:38:04 +08:00
yi chen daae1fb403 fix(esp_partition): prevent size_t overflow bypassing bounds checks on linux target
esp_partition_write/read/erase_range/mmap in partition_linux.c (the
`linux` target backend used by --preview set-target linux / host_test)
validated the requested range with `offset + size > partition->size`.
When `size` is close to SIZE_MAX, this addition wraps around size_t and
can evaluate to a small value, so the check passes even though the
request is far out of bounds. A caller passing e.g.
esp_partition_write(partition, 1, src, SIZE_MAX) sails through both
bounds checks and reaches the byte-copy loop with new_size == SIZE_MAX,
causing out-of-bounds reads/writes far past both the caller's buffer
and the mmap'd emulated-flash file.

Replace all four instances with the overflow-safe form already used by
the other esp_partition backends (partition_target.c,
partition_bootloader.c, partition_tee.c):
`size > partition->size - offset`, which is safe because the preceding
check already guarantees offset <= partition->size.

Signed-off-by: yi chen <94xhn1@gmail.com>
2026-07-12 03:30:37 +08:00
Meet Patel 25fe69f946 Merge branch 'bugfix/pthread_find_key_uaf' into 'master'
fix(pthread,ulp): harden TLS key lookup and ULP bss_size validation

Closes SEC-248 and SEC-1122

See merge request espressif/esp-idf!50410
2026-07-11 23:18:21 +05:30
yi chen 7461a9f900 fix(wear_levelling): guard WL_Flash::write()/read() against size==0 underflow
WL_Flash::write() and WL_Flash::read() computed:

    uint32_t count = (size - 1) / this->cfg.wl_page_size;

`size` is `size_t` (unsigned). Neither the public wl_write()/wl_read() API
(wear_levelling.cpp), nor the newer wl_bdl_write()/wl_bdl_read() block-device
path (wl_blockdev.cpp), reject size == 0 before calling into WL_Flash, and
wear_levelling.h does not document size == 0 as invalid (a 0-byte
write/read is a reasonable no-op, mirroring POSIX write()/read() with
count == 0).

When size == 0, `size - 1` wraps around to SIZE_MAX, so `count` becomes an
enormous page count instead of 0. The functions then loop that many times,
reading (write()) or writing (read()) `wl_page_size` bytes per iteration
through the flash partition, immediately walking past the caller-supplied
buffer on the very first iteration:

  - write(): out-of-bounds *read* from the caller's `src` buffer.
  - read():  out-of-bounds *write* into the caller's `dest` buffer -- the
             more severe case, since it corrupts caller memory with flash
             content instead of merely over-reading.

Verified with a standalone reproduction that compiles the unmodified
WL_Flash.cpp against a mock Flash_Access partition: calling
`wl.write(0, an_8_byte_buffer, 0)` with no other change immediately
segfaults (confirmed count == 0xFFFFFFFF for wl_page_size == 4096); with
this fix applied the same call returns ESP_OK without touching memory
outside the buffer, and normal non-zero-size read/write is unaffected.

Add an early `size == 0` return (mirroring the existing `!initialized`
guard) to both functions, and a host_test regression case exercising
wl_write()/wl_read() with size == 0 through the public API.

Disclosure: this fix was prepared with AI assistance (Claude) and reviewed
by me before submission.

Signed-off-by: yi chen <94xhn1@gmail.com>
2026-07-12 01:02:21 +08:00
Chen Yu Dong 89590855a0 Merge branch 'refactor/esp_wifi_regulatory_esp_pylib' into 'master'
refactor(esp_wifi): migrate regulatory tools to esp-pylib

See merge request espressif/esp-idf!49976
2026-07-12 00:49:48 +08:00
morris 485cdbb3a3 Merge branch 'cleanup/remove-idf_test-component' into 'master'
chore: remove unused idf_test component

See merge request espressif/esp-idf!50637
2026-07-11 09:21:51 +08:00
Euripedes Rocha Filho 6147454558 fix(esp_netif): Removes double-free path and NULL dereference in bridge 2026-07-10 14:10:01 +02:00
Hu Rui e88643bc61 Merge branch 'fix/touch_read_check' into 'master'
fix(touch): fix hw_ver1 read data check

Closes IDFGH-17938

See merge request espressif/esp-idf!50617
2026-07-10 20:00:21 +08:00
Euripedes Rocha 9f6ddaebf1 Merge branch 'fix/sec-347-hostname-null-check' into 'master'
fix(esp_netif): reject NULL hostname in esp_netif_set_hostname_api (SEC_347)

See merge request espressif/esp-idf!50344
2026-07-10 13:50:00 +02:00
Konstantin Kondrashov 7cac7e0b86 Merge branch 'fix/remove-bootloader-desc-from-app-build' into 'master'
fix(esp_bootloader_format): Remove bootloader description from app build

See merge request espressif/esp-idf!50576
2026-07-10 14:05:55 +03:00
morris d6a0bb8221 chore: remove unused idf_test component
The idf_test component was previously cleaned up but accidentally
reintroduced when adding esp32s31 support. It only contained an empty
header file (idf_performance_target.h) with no references anywhere
in the codebase.

Also removes the corresponding entry from astyle-rules.yml.
2026-07-10 18:07:24 +08:00
Laukik Hase 095c1d87e5 Merge branch 'feat/mspi_pms_support' into 'master'
feat(security): Add support for flash/PSRAM protection through MSPI PMS

Closes IDF-13836

See merge request espressif/esp-idf!48817
2026-07-10 15:30:05 +05:30
zhiweijian 1de0d2fef7 feat(ble/bluedroid): Add bluedroid dual identify server example 2026-07-10 17:57:25 +08:00
zhiweijian 2358786647 feat(ble/bluedroid): Support bluedroid dual identity 2026-07-10 17:57:09 +08:00
morris 7695890be8 Merge branch 'refactor/move_regdma_entry_config_to_driver_layer_mwdt' into 'master'
refactor(mwdt): move sleep retention config into system layer

See merge request espressif/esp-idf!50414
2026-07-10 17:52:36 +08:00
Konstantin Kondrashov 8913d4cf61 fix(esp_bootloader_format): Remove bootloader description from app build
The removed function `esp_bootloader_get_description` never worked in the app build.
It can be used only in the bootloader build.

To read the bootloader description from app, there is another function
`esp_ota_get_bootloader_description`.
2026-07-10 12:17:59 +03:00
Wu Zheng Hui cfc1bf3752 Merge branch 'fix/allow_task_and_coredump_mem_in_spm' into 'master'
fix(esp_hw_support): update memory pointer checks for SPM support

See merge request espressif/esp-idf!50615
2026-07-10 17:05:53 +08:00
morris 506c4c0bd3 Merge branch 'refactor/move_regdma_entry_config_to_driver_layer_emac' into 'master'
refactor(emac): move sleep retention config into driver layer

See merge request espressif/esp-idf!50554
2026-07-10 16:48:55 +08:00
morris 70ddc14d4f refactor(emac): move sleep retention config into driver layer
Keep the EMAC regdma retention definitions in esp_eth so the backup
layout stays aligned with driver-owned sleep retention behavior.
2026-07-10 16:01:41 +08:00
Laukik Hase 5dce8db8fe ci(hal): Extend the PMS HAL test app to verify the MSPI PMS (flash) protection 2026-07-10 13:13:10 +05:30
Laukik Hase 11fe9fdad6 feat(hal): Add support for flash/PSRAM protection through MSPI PMS 2026-07-10 13:13:09 +05:30
Hu Rui 2b8f3605ee fix(touch): fix hw_ver1 read data check
Closes https://github.com/espressif/esp-idf/issues/18811
2026-07-10 14:56:10 +08:00