Commit Graph
5340 Commits
Author SHA1 Message Date
Rahul Tank 43280d9be8 Merge branch 'bugfix/fix_bond_store_overflow_v5.3' into 'release/v5.3'
fix(nimble): Fix bond-store overflow when IRK is enabled (v5.3)

See merge request espressif/esp-idf!50627
2026-07-14 11:17:48 +05:30
Island 9c65614fa5 Merge branch 'fix/ble_mesh_fixed_issues_v5.3' into 'release/v5.3'
Resolve reported BLE mesh stack issues (5.3)

See merge request espressif/esp-idf!50404
2026-07-14 10:16:53 +08:00
Rahul Tank dd42e3ced3 fix(nimble): Fix bond-store overflow when IRK is enabled 2026-07-10 13:31:39 +05:30
Rahul Tank 86297605f9 fix(nimble): Fixes for AI reported issues 2026-07-07 16:34:25 +05:30
Luo Xu 865c1143b7 fix(ble_mesh): re-check scan dev-found cb before scan-rsp invocation
(cherry picked from commit 9a3a767824)

Co-authored-by: luoxu <luoxu@espressif.com>
2026-07-06 17:43:51 +08:00
Luo Xu b11bd0c0eb fix(ble_mesh): comment out logs containing sensitive keys
(cherry picked from commit 781d6b2314)

Co-authored-by: luoxu <luoxu@espressif.com>
2026-07-06 17:43:50 +08:00
Luo Xu 5ef184d780 fix(ble_mesh): validate PB-ADV start segment length
(cherry picked from commit 912ec8dc62)

Co-authored-by: luoxu <luoxu@espressif.com>
2026-07-06 17:43:50 +08:00
Luo Xu 4721dba6ca fix(ble_mesh): Reset reassembly buffer at start of each transaction
The reassembly buffer must be reset to its origin at the beginning of every
transaction. prov_msg_recv() pulls the PDU type byte (advancing buf->data by
one) and nothing restores it between transactions. Without this reset,
buf->data drifts forward by one byte per received PDU, causing the segment-0
memcpy to write past the end of the statically allocated rx buffer
(PROV_RX_BUF_SIZE), and the XACT_SEG_DATA() offsets used for continuation
segments to be skewed by the accumulated drift.


(cherry picked from commit 2c4acaa2aa)

Co-authored-by: luoxu <luoxu@espressif.com>
2026-07-06 17:43:49 +08:00
Luo Xu 4255fbaf84 fix(ble_mesh): fix DFD client message parsing and encoding bugs
Fix multiple wire-format and robustness issues in the DFD client
(dfd_cli.c):

- handle_capabilities: read oob_retrieval_supported as u8 instead of
  le32. The server encodes a single byte; le32 over-consumed 3 bytes
  of the URL scheme list and could over-read the buffer.
- handle_upload_status: extract upload_progress from bits 0-6 (& 0x7F)
  and upload_type from bit 7 (>> 7), matching the server encoding
  (progress | BIT(7)). The previous >>1 / &0x01 returned wrong values,
  mis-classified in-band vs OOB, and falsely rejected valid OOB
  messages with high progress.
- handle_dfd_status: correct the transfer-mode byte layout to
  trans_mode bits 0-1, update_policy bit 2, RFU bits 3-7 (previously
  read bits 6-7 / 5), and fix the RFU mask to 0xF8. Now matches the
  struct bitfield definition and the DFD server.
- handle_dfd_status: report status+phase and return early when
  buf->len == 0 (IDLE phase) instead of pulling 10 absent bytes.
- bt_mesh_dfd_cli_distribution_start: encode trans_mode/update_policy
  into bits 0-2 so the server decodes them correctly.
- handle_receiver_list: validate buf->len >= entries_cnt * 5 before
  the loop, and handle entries_cnt == 0 without relying on calloc(0).
- handle_receiver_status: pass the status value (not the whole union)
  to the %d log format, fixing undefined behavior.
- dfd_client_recv_status: drop the dead BLE_MESH_DFD_OP_CAPABILITIES_GET
  case (a client-send opcode) from the receive switch.
- bt_mesh_dfd_cli_receivers_add: widen msg_length to uint32_t to avoid
  uint16_t overflow that bypassed the PDU size guard; add a NULL check
  for the receivers array.
- bt_mesh_dfd_cli_distribution_upload_oob_start: return -EINVAL
  instead of -1 for consistency with the rest of the file.


(cherry picked from commit 43137475e1)

Co-authored-by: luoxu <luoxu@espressif.com>
2026-07-06 17:43:49 +08:00
Luo Xu d17cc4d0ce fix(ble_mesh): added max dfd srv count limit
(cherry picked from commit 781218cb62)

Co-authored-by: luoxu <luoxu@espressif.com>
2026-07-06 17:43:43 +08:00
Luo Xu ed236b7b0d fix(ble_mesh): reject invalid chunk size
(cherry picked from commit 35cd10fbdf)

Co-authored-by: luoxu <luoxu@espressif.com>
2026-07-06 17:43:43 +08:00
Luo Xu 98875dc920 fix(ble_mesh): fixed invalid disconnect handler wrote
(cherry picked from commit 52cfff707f)

Co-authored-by: luoxu <luoxu@espressif.com>
2026-07-06 17:43:42 +08:00
Luo Xu 9aef1fc224 fix(ble_mesh): fixed BLE-Mesh NimBLE extended-adv reassembly buffer overflow on COMPLETE fragment
(cherry picked from commit 1b22467f63)

Co-authored-by: luoxu <luoxu@espressif.com>
2026-07-06 17:43:42 +08:00
Luo Xu f9da09de61 fix(ble_mesh): fixed BLE-Mesh GATTS read-callback error
(cherry picked from commit 00adfb3cbc)

Co-authored-by: luoxu <luoxu@espressif.com>
2026-07-06 17:43:41 +08:00
Jiang Jiang Jian 698b47d8fd Merge branch 'fix/ble_mesh_disable_adv_pkt_discard_log_v5.3' into 'release/v5.3'
fix(ble_mesh): Disable warning logging when advertising packets are discarded (5.3)

See merge request espressif/esp-idf!50164
2026-07-06 15:13:29 +08:00
Island 4292cd472c Merge branch 'fix/ble-log-64-bit-io-setup-support_v5.3' into 'release/v5.3'
fix(ble_log): use BIT64 over BIT to support 64-bit IO setup (5.3)

See merge request espressif/esp-idf!50328
2026-07-06 12:23:17 +08:00
Wang Meng Yang 2f00d765d6 Merge branch 'bugfix/bbp_issues_v5.3' into 'release/v5.3'
Bugfix/bbp issues v5.3

See merge request espressif/esp-idf!50192
2026-07-06 11:56:03 +08:00
Wang Meng Yang 91abdc6674 Merge branch 'bugfix/ai_review_btu_common_v5.3' into 'release/v5.3'
fix: Fix the critical issues of btu and bt_common from AI review report (v5.3)

See merge request espressif/esp-idf!50125
2026-07-06 10:48:27 +08:00
Rahul Tank 9b92b5a02b fix(nimble): Defer Events / ATT related information from stack
Defer Events/ ATT related GAP events from stack until connection
 event is sent to GAP layer
2026-07-03 11:21:08 +05:30
Zhou Xiao c9de85f36a fix(ble_log): use BIT64 over BIT to support 64-bit IO setup
(cherry picked from commit a2876d304e)

Co-authored-by: Zhou Xiao <zhouxiao@espressif.com>
2026-07-03 12:04:53 +08:00
Zhou Xiao 8de35b14e7 change(ble): [AUTO_MR] Update lib_esp32c6 to a6519790
(cherry picked from commit 226a0483b1)

Co-authored-by: Zhou Xiao <zhouxiao@espressif.com>
2026-07-01 10:35:26 +08:00
Zhou Xiao 92d34dbeca change(ble): [AUTO_MR] Update lib_esp32h2 to a6519790
(cherry picked from commit 8a744e8e93)

Co-authored-by: Zhou Xiao <zhouxiao@espressif.com>
2026-07-01 10:35:26 +08:00
Wang Meng Yang 97b1c64b67 Merge branch 'bugfix/ai_review_a2dp_v5.3' into 'release/v5.3'
fix(bt): Fix the critical issues related to A2DP from AI review report (v5.3)

See merge request espressif/esp-idf!50131
2026-06-30 19:23:18 +08:00
luoxu 9613093789 fix(ble_mesh): Disable warning logging when advertising packets are discarded 2026-06-30 17:00:57 +08:00
Jin Cheng 3ee2494c06 fix(bt/bluedroid): fixed possible OOB read/write in process_l2cap_cmd 2026-06-30 15:13:50 +08:00
Island c43788173b Merge branch 'bugfix/fix_bluedroid_static_random_conn_rpa_v5.3' into 'release/v5.3'
fix(ble/bluedroid): skip identity conversion for static random direct connect (5.3)

See merge request espressif/esp-idf!50082
2026-06-30 10:25:01 +08:00
Island 90491f8457 Merge branch 'bugfix/fix_bluedroid_rpa_whitelist_conn_v5.3' into 'release/v5.3'
Fix connection failure when using RPA with whitelist filtering(ESP32) (5.3)

See merge request espressif/esp-idf!50088
2026-06-30 10:23:56 +08:00
yangfeng a099dd706e fix(bt): Fix the critical issues related to A2DP from AI review report
AVDT:
- Roll back CCB allocation when cmd/rsp queue creation fails
- Free media packet on invalid handle in AVDT_WriteReqOpt
- Zero-init timeout failure message before GETCAP callback
- Initialize lcid_tbl to 0xFF to avoid mapping to tc_tbl[0]
BTA/AVRCP:
- Use size_t for AVRC message copy buffer allocation
- Allocate before register in BTA_AvEnable
- Guard BTA_AvRegister callback when enable never completed
A2DP BTC/API:
- Default g_a2dp_on_deinit to true before profile init
- Add shutdown state check in btc_a2dp_sink_shutdown
- Guard A2DP source timer against freed dynamic local param
2026-06-29 15:12:33 +08:00
yangfeng 7f4a58cf27 fix: Fix the critical issues of btu and bt_common from AI review report
- advance connect queue on synchronous connect_cb failure
- lock bta_alarm_hash_map in all BTA timer APIs
- free controller params after stack disable; cleanup on init fail
- handle BTE_InitStack failure and signal init future
- validate HCI remote name event length before parse
- drop stale L2CAP quick-timer alarm events
2026-06-29 14:49:30 +08:00
Rahul Tank e9604aa3b0 Merge branch 'bugfix/fix_gatt_crash_v5.3' into 'release/v5.3'
fix(nimble): Add npl locks to avoid race condition (v5.3)

See merge request espressif/esp-idf!50069
2026-06-29 10:21:13 +05:30
zhanghaipeng f582365c84 fix(bt): update ESP32 libbtdm_app.a to 4a0f94d5
- Fix connection failure when using RPA with whitelist filtering
- Fix disconnect with reason 0x08 during full scan
- Fix peer RPA resolution failure when advertising with a local identity address
2026-06-29 10:43:57 +08:00
Jin Cheng dc65ed2a64 fix(bt/controller): fixed several BR/EDR controller bugs found by WVT regression tests on ESP32 2026-06-29 10:43:54 +08:00
Island dc5b776305 Merge branch 'feat/add_ble_core_6x_feature_for_bluedroid_v5.3' into 'release/v5.3'
Feat/add ble core 6x feature for bluedroid (5.3)

See merge request espressif/esp-idf!50050
2026-06-29 10:31:45 +08:00
Zhang Hai Peng 1824570f90 fix(ble/bluedroid): preserve HCI status on BLE 4.2 GAP failures
Return BTM_HCI_ERROR | hci_status from legacy BLE 4.2 GAP HCI command
paths instead of mapping failures to BTM_ILLEGAL_VALUE or
BTM_NO_RESOURCES. Add btm_ble_status_from_hci() helper and propagate
real status through scan start/stop completion callbacks.


(cherry picked from commit 47dd785a18)

Co-authored-by: zhanghaipeng <zhanghaipeng@espressif.com>
2026-06-26 20:24:46 +08:00
Zhang Hai Peng b416e7f61b feat(ble/bluedroid): Optimize Bluedroid memory usage
- Delete unused device records (~356B each)


(cherry picked from commit 7d1c0e9a32)

Co-authored-by: zhanghaipeng <zhanghaipeng@espressif.com>
2026-06-26 20:24:24 +08:00
Zhang Hai Peng 1130ad21f8 fix(ble/bluedroid): cap Read By Type response length at ATT maximum
Read By Type Response Length is one octet (max 255). When MTU was
large enough to return a long characteristic value in one pair, the
server wrote (UINT8)(value_len + 2) and overflowed (e.g. 513 -> 1),
so the client rejected the PDU as GATT_INVALID_PDU (0x04).

Cap server value to 253 bytes per pair, clamp the length byte, and
continue long reads via Read Blob when the capped size is returned.


(cherry picked from commit 97905afccc)

Co-authored-by: zhanghaipeng <zhanghaipeng@espressif.com>
2026-06-26 20:24:07 +08:00
Zhang Hai Peng 6ac3fd1a18 fix(ble/bluedroid): Fixed potential double Execute Write Response
(cherry picked from commit 0a93ccd3b3)

Co-authored-by: zhanghaipeng <zhanghaipeng@espressif.com>
2026-06-26 20:23:50 +08:00
Zhang Hai Peng 7400a89196 fix(ble/bluedroid): preserve ATT error on prepare write completion
Skip prepare-write echo validation when the GATT stack reports a
non-success status. ATT Error Response carries no prepare-write echo
body (rsp_len=0), so the check incorrectly overwrote errors such as
GATT_INSUF_AUTHENTICATION (0x05) with GATT_INVALID_PDU (0x04).


(cherry picked from commit d5b9350d0f)

Co-authored-by: zhanghaipeng <zhanghaipeng@espressif.com>
2026-06-26 20:23:28 +08:00
Zhang Hai Peng ee46100f53 fix(ble/bluedroid): unblock sync HCI cmd on Command Status error
Release the BLE sync semaphore and record HCI status when a
synchronous command is rejected via Command Status, since no
Command Complete event follows.


(cherry picked from commit 29ae92f4ef)

Co-authored-by: zhanghaipeng <zhanghaipeng@espressif.com>
2026-06-26 20:16:40 +08:00
Zhang Hai Peng 47d267a365 fix(ble/bluedroid): set REQ_WAITING before GATTC service-change rediscovery
When service change cancels in-progress discovery, bta_gattc_disc_cmpl()
re-triggers discovery without marking auto_update as REQ_WAITING. If a
client command is queued in p_q_cmd, bta_gattc_start_discover() refuses
to restart and the command is never dispatched.


(cherry picked from commit 13926bb9bc)

Co-authored-by: zhanghaipeng <zhanghaipeng@espressif.com>
2026-06-26 20:16:22 +08:00
Zhang Hai Peng fd6a76d00d fix(ble/bluedroid): report conn param update failure for unknown BD_ADDR
Route unknown BD_ADDR and other immediate failures through the existing
need_cb path so ESP_GAP_BLE_UPDATE_CONN_PARAMS_EVT is always delivered.


(cherry picked from commit f9eaeb5e84)

Co-authored-by: zhanghaipeng <zhanghaipeng@espressif.com>
2026-06-26 20:16:03 +08:00
Zhang Hai Peng f052415e45 fix(ble/bluedroid): add context to GATTC reg-notify cache warning
Include client_if, handle, bd_addr, and server cache state in the
warning logged when notification registration skips handle validation.


(cherry picked from commit 1085a32be8)

Co-authored-by: zhanghaipeng <zhanghaipeng@espressif.com>
2026-06-26 20:16:03 +08:00
Zhang Hai Peng 2888b48bea fix(ble/bluedroid): return ESP_ERR_INVALID_ARG for invalid conn params
Return ESP_ERR_INVALID_ARG instead of ESP_FAIL when connection
parameter validation fails


(cherry picked from commit 6c53838e66)

Co-authored-by: zhanghaipeng <zhanghaipeng@espressif.com>
2026-06-26 20:16:02 +08:00
Zhang Hai Peng 96bac63edb fix(ble/bluedroid): reject adv data on legacy directed ext adv
(cherry picked from commit c339cec380)

Co-authored-by: zhanghaipeng <zhanghaipeng@espressif.com>
2026-06-26 20:15:45 +08:00
Zhang Hai Peng d9300e1364 fix(ble/bluedroid): skip identity conversion for static random direct connect
Do not rewrite static or non-resolvable random peer addresses to
identity type 0x03 when CONFIG_BT_BLE_RPA_SUPPORTED is enabled.


(cherry picked from commit 2ef10ef488)

Co-authored-by: zhanghaipeng <zhanghaipeng@espressif.com>
2026-06-26 20:15:26 +08:00
Sumeet Singh 959fa33438 fix(nimble): Add npl locks to avoid race condition (v5.3) 2026-06-26 12:29:36 +05:30
Jiang Jiang Jian 1874d5ba0d Merge branch 'bugfix/ai_review_hfp_v5.3' into 'release/v5.3'
fix(bt): Fix the critical issues related to HFP from AI review report (v5.3)

See merge request espressif/esp-idf!50010
2026-06-26 14:06:41 +08:00
Island bdbe3ee28e Merge branch 'fix/reduce_acl_event_gaps_v5.3' into 'release/v5.3'
feat(ble): updated libble to 71d180a4 for esp32h4 and esp32s31 (5.3)

See merge request espressif/esp-idf!49589
2026-06-26 10:47:12 +08:00
Zhi Wei Jian a842d54f4d feat(ble/bluedroid): add CS Security Requirements host support (Core 6.3)
(cherry picked from commit 919622c01c)

Co-authored-by: zhiweijian <zhiweijian@espressif.com>
2026-06-26 09:08:17 +08:00
Zhi Wei Jian ea68f1efd1 feat(ble/bluedroid): add LE UTP host support (Core 6.2)
(cherry picked from commit 3844e24207)

Co-authored-by: zhiweijian <zhiweijian@espressif.com>
2026-06-26 09:08:16 +08:00