Commit Graph
400 Commits
Author SHA1 Message Date
Martin Vychodil 75ff3d22a4 fix(fatfs): preserve access mode in VFS F_SETFL
F_SETFL was replacing the whole flags word, so fcntl(fd, F_SETFL, O_APPEND)
made F_GETFL report O_RDONLY|O_APPEND. Keep O_ACCMODE and apply only POSIX
status flags.
2026-08-20 14:45:44 +02:00
Jiang Jiang Jian 16107a2261 Merge branch 'bugfix/vfs_fat_readdir_stat_cache_v5.5' into 'release/v5.5'
fix(fatfs): move readdir-stat cache to per-DIR stream (v5.5)

See merge request espressif/esp-idf!50905
2026-08-06 12:24:10 +08:00
Jiang Jiang Jian a2e9abc655 Merge branch 'fix/fatfs_vulnerabilities_v5.5' into 'release/v5.5'
fix(fatfs): harden against runZero 2026 FatFs bugs (v5.5)

See merge request espressif/esp-idf!50426
2026-07-21 12:06:44 +08:00
Jiang Jiang Jian 1acff98167 Merge branch 'bugfix/idfci-8839-remove-orphan-test-configs_v5.5' into 'release/v5.5'
fix(fatfs): re-enable fatfs and vfs psram/ccomp CI tests (v5.5)

See merge request espressif/esp-idf!50186
2026-07-21 12:05:42 +08:00
sonika.rathi 40955b23d5 fix(fatfs): move readdir-stat cache to per-DIR stream
Move cached_fileinfo and dir_path from vfs_fat_ctx_t to vfs_fat_dir_t so
each open DIR* has its own readdir→stat cache.
2026-07-17 19:10:35 +02:00
Tomáš Rohlínek 9be9b3e60b fix(storage/fatfs): fix FAT32 mount integer overflow (CVE-2026-6682)
The initial CVE-2026-6682 fix hardened the exFAT mount path, but the CVE
as reported by runZero is a FAT32 defect in mount_volume() and is
reachable in the default configuration (exFAT and 64-bit LBA disabled).
This corrects the fix.

Root cause: `fasize *= fs->n_fats` is a DWORD multiply with no overflow
guard. A crafted BPB_FATSz32 such as 0x80000001 with NumFATs=2 wraps
`fasize` to 0x00000002. The wrapped (too-small) FAT size places
`fs->database` inside the FAT region, so a forged directory entry yields
an attacker-controlled `finfo.fsize`; a caller using it as a read length
overflows its buffer with attacker-controlled bytes (CVSS 7.6).

Fix: reject per-FAT and reserved+FAT+root system-area sizes that overflow
DWORD before they are used to derive the data-area base. The exFAT
cluster-heap/bitmap 64-bit promotions are retained as defense-in-depth
and relabeled (they are not CVE-2026-6682). SBOM reason updated.
2026-07-07 16:36:34 +02:00
Tomáš Rohlínek 655ff3269a fix(storage/fatfs): record non-applicable runZero 2026 CVEs in SBOM
Document the three runZero "Seven FatFs bugs" CVEs that require no source change
in this component, so vulnerability scanners have their disposition:

  - CVE-2026-6684: GPT partition-scan loop DoS. Already fixed upstream in R0.16,
    where test_gpt_header() caps the partition-entry count at 128.
  - CVE-2026-6686: read of uninitialized clusters after f_lseek() past EOF.
    Longstanding, behavioral; not a memory-safety defect and zero-filling every
    extended cluster is prohibitively costly on flash.
  - CVE-2026-6688: long-filename overflow in downstream callers. Not exposed in
    ESP-IDF; vfs_fat.c uses bounded copies and fname is bounded by FF_MAX_LFN.

Reference: https://www.runzero.com/blog/fatfs-bugs/
2026-07-06 16:19:16 +02:00
Tomáš Rohlínek 1cd2874952 fix(storage/fatfs): clamp exFAT volume-label length in f_getlabel() (CVE-2026-6687)
f_getlabel() extracts the exFAT volume label with a loop bounded by the on-disk
byte dj.dir[XDIR_NumLabel] (0-255):

    for (si = di = hs = 0; si < dj.dir[XDIR_NumLabel]; si++)
        wc = ld_16(dj.dir + XDIR_Label + si * 2);

The exFAT label field holds at most 11 UTF-16 units (22 bytes). A crafted
directory entry with a larger count both reads past the 22-byte label field and,
through put_utf(... &label[di], 4), writes past the end of the caller-provided
label buffer (the canonical API examples use small fixed stack buffers) -> stack
buffer overflow.

Clamp the character count to the exFAT maximum of 11 before the extraction loop.
Record the CVE in the component SBOM.

Note: f_getlabel() takes no destination-buffer size, so under UTF-8 output
(FF_LFN_UNICODE == 2) 11 units can still expand to up to 34 bytes; the clamp
downgrades this from attacker-unbounded to spec-bounded. ESP-IDF's VFS layer
does not call f_getlabel(); direct callers on untrusted media should size their
buffer accordingly. A complete fix requires an upstream size-aware API change.

Reference: https://www.runzero.com/blog/fatfs-bugs/
2026-07-06 14:52:36 +02:00
Tomáš Rohlínek 362fd7380e fix(storage/fatfs): guard dirty-cache refill against unsigned LBA wrap (CVE-2026-6685)
After a direct multi-sector disk_read()/disk_write(), FatFs decides whether the
cached sector overlaps the direct-I/O range with:

    fp->sect - sect < cc          (and the FF_FS_TINY variant fs->winsect - sect < cc)

`sect`, `fp->sect` and `fs->winsect` are unsigned LBA_t. On 32-bit LBA_t builds,
if the cached sector is below `sect`, the subtraction wraps to a huge value that
can still compare `< cc`, so the code computes a bogus large offset:

  - in f_write() it mis-copies from the direct write buffer (data corruption);
  - in f_read() it is worse: memcpy(rbuff + (wrapped_offset * SS), ...) is an
    out-of-bounds WRITE into the caller-supplied read buffer.

Add an explicit lower-bound check (fp->sect >= sect, resp. fs->winsect >= sect)
before the range test on both the read and write paths and both the FF_FS_TINY
and normal variants, so the condition is exactly "cached sector lies within
[sect, sect + cc)". Record the CVE in the component SBOM.

Reference: https://www.runzero.com/blog/fatfs-bugs/
2026-07-06 14:52:36 +02:00
Tomáš Rohlínek 0efd85ffea fix(storage/fatfs): reject empty exFAT cluster heap (CVE-2026-6683)
CVE-2026-6683 is an exFAT divide-by-zero: with NumClusters == 0 the filesystem
object has fs->n_fatent == 2, and the exFAT "percent in use" update in sync_fs()
computes ... * 100 / (fs->n_fatent - 2) -> division by zero.

That vulnerable exFAT PercInUse sync path was introduced in FatFs R0.16 and is
NOT present in this R0.15 release, so the divide-by-zero itself is not reachable
here. As defense-in-depth (and to keep parity with newer releases) reject an
empty exFAT cluster heap at mount time, which is a malformed volume regardless.

Record the CVE disposition in the component SBOM.

Reference: https://www.runzero.com/blog/fatfs-bugs/
2026-07-06 14:52:36 +02:00
Tomáš Rohlínek 94a6d8143e fix(storage/fatfs): fix exFAT mount integer overflow (CVE-2026-6682)
The exFAT mount path validates that the media is large enough to hold the
declared cluster heap with:

    if (maxlba < (QWORD)fs->database + ncl * fs->csize) ...

`ncl` (DWORD, up to MAX_EXFAT) and `fs->csize` (WORD) are both promoted to
`unsigned int`, so `ncl * fs->csize` is evaluated in 32-bit arithmetic and can
wrap before the QWORD promotion of the sum. A crafted image with a large
NumClusters/SecPerClus can therefore make an undersized volume pass the "size
is large enough" check; subsequent cluster->sector math then addresses media
outside the actual device.

Promote the multiply to 64-bit ((QWORD)ncl * fs->csize). Apply the same
promotion to the bitmap-base computation ((LBA_t)fs->csize * (bcl - 2)), which
has the identical overflow shape. Record the CVE in the component SBOM.

Reference: https://www.runzero.com/blog/fatfs-bugs/
2026-07-06 14:52:36 +02:00
sonika.rathi 6731a52061 fix(fatfs): re-enable fatfs and vfs psram/ccomp CI tests 2026-06-30 09:10:29 +02:00
Martin VychodilandCursor 6191a72408 fix(fatfs): Fixed VFS adapter early return paths
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-28 14:47:22 +02:00
Martin Vychodil 2bbae5e1ba fix(fatfs): Fixed uninitialized FATFS pointer for already mounted path
Co-authored-by: Cursor <cursoragent@cursor.com>

# Conflicts:
#	components/fatfs/host_test/main/test_fatfs_vfs.cpp
#	components/fatfs/vfs/vfs_fat_bdl.c
2026-06-28 14:47:12 +02:00
Adam Múdry 0242c79881 fix(fatfs): Fix esp_vfs_fat_unregister_path leak if esp_vfs_unregister fails 2026-06-17 14:03:56 +02:00
sonika.rathi 01116e4c9e fix(storage): mark storage pytest apps flaky in CI 2026-05-21 15:48:10 +02:00
sonika.rathi b8ee46ee02 fix(fatfs): remove incorrect retval description from void ff_mutex_delete 2026-05-12 01:43:41 +08:00
sonika.rathi c01c7104ca fix(fatfs): fix f_getfree crash when volume not mounted or mount failed 2026-05-12 01:43:41 +08:00
Martin Vychodil b60d57ee13 Merge branch 'bugfix/fatfs_memory_leak_with_dyn_buffer_v5.5' into 'release/v5.5'
fix(fatfs): fix a memory leak bug when FF_USE_DYN_BUFFER was enabled (v5.5)

See merge request espressif/esp-idf!47877
2026-05-10 21:29:13 +08:00
sonika.rathi dad5dd867e fix(fatfs): fix readdir/stat path buffer sizing in test 2026-05-05 12:16:49 +02:00
LiPeng 1509cc63af fix(fatfs): fix a memory leak bug when FF_USE_DYN_BUFFER was enabled 2026-04-24 18:56:45 +08:00
Evgeny Torbin d412f4b858 ci: remove unused test cases 2026-03-13 16:06:08 +08:00
Adam Múdry 531dfe2cf3 fix: wl_fatfsgen.py conform to lower Python version 2026-02-05 12:53:50 +01:00
Adam Múdry 9bf47db1d1 fix(fatfs): Calculate max_pos in wl_fatfsgen.py safe mode correctly 2026-02-05 12:53:50 +01:00
Adam Múdry 6754908683 fix: Satisfy Python formatter 2026-02-05 12:53:50 +01:00
igor.udot 562a730d7c ci: remove esp32c3 from sdcard_sdmode 2026-02-05 13:21:09 +08:00
Adam Múdry 93ff1aec46 Merge branch 'feat/remove_const_from_voltopart' into 'master'
feat(fatfs/diskio): Remove const from PARTITION VolToPart

Closes IDFGH-13211

See merge request espressif/esp-idf!38150
2025-04-16 23:46:19 +08:00
Tomas Rohlinek 7005b101bf Merge branch 'fix/fatfs_use_dyn_buf_kconfig_mistake' into 'master'
fix(fatfs): Mistake in Kconfig for FATFS_USE_DYN_BUFFERS

Closes IDF-11789

See merge request espressif/esp-idf!35182
2025-04-09 23:45:03 +08:00
Tomáš Rohlínek b1997ebab6 feat(storage/fatfs): add dynamic buffer usage test 2025-04-09 14:02:44 +02:00
Martin Vychodil fe73a61b2b Merge branch 'fix/fatfs_rw_mount_ro_image' into 'master'
feat(storage/fatfs): increase log legibility for fatfs mount

Closes IDF-12569

See merge request espressif/esp-idf!37407
2025-04-09 16:29:57 +08:00
Adam Múdry 82dac1f1bd fix(fatfs): Mistake in Kconfig for FATFS_USE_DYN_BUFFERS 2025-04-09 09:18:02 +02:00
Tomas Rohlinek f945dae618 Merge branch 'contrib/github_pr_15247' into 'master'
refactor(components/fatfs): replace assert expression (GitHub PR)

Closes IDFGH-14473

See merge request espressif/esp-idf!38194
2025-04-02 18:21:55 +08:00
Adam Múdry b5b2fbc87d feat(fatfs/diskio): Remove const from PARTITION VolToPart
Closes https://github.com/espressif/esp-idf/issues/14148
2025-03-31 13:35:39 +02:00
Chen Jichang 6c4271d4bb feat(esp32h4): disable unsupported build 2025-03-28 14:41:29 +08:00
Chen Jichang c34b4eb882 feat(esp32h4): enable ESP32H4 ci build 2025-03-28 14:41:28 +08:00
Adam Múdry 58fbcfb407 Merge branch 'feat/ff_fs_nofsinfo_kconfig' into 'master'
feat(fatfs): Add an option to set FF_FS_NOFSINFO value

Closes IDFGH-14467

See merge request espressif/esp-idf!36592
2025-03-20 20:18:52 +08:00
igor.udot daf2d31008 test: format all test scripts 2025-03-05 12:08:48 +08:00
Tomáš Rohlínek df8a16281b feat(storage/fatfs): increase log legibility for fatfs mount 2025-02-28 14:59:48 +01:00
Adam Múdry d87a6d4b61 feat(fatfs): Add Kconfig options to set FF_FS_NOFSINFO value
Closes https://github.com/espressif/esp-idf/issues/15241
2025-02-21 21:39:44 +08:00
Martin Vychodil aa23c8099d Merge branch 'fix/vfs_compiler_warings' into 'master'
fix(components): Compiler reports some warnings

Closes IDFGH-14289

See merge request espressif/esp-idf!36692
2025-02-07 15:22:25 +08:00
gaoxu 5ef4f20778 feat(esp32h21): disable unsupported build test 2025-02-06 15:47:51 +08:00
sonika.rathi 50dc84ca6e fix(fatfs): make the diskio functions static
Closes https://github.com/espressif/esp-idf/issues/15248
2025-02-03 09:29:46 +01:00
safocl 4da9b8654c fix(storage/fatfs): Compiler unused warning
esp-idf/components/fatfs/diskio/diskio_rawflash.c warning: unused variable 'part' [-Wunused-variable]
   XX |     const esp_partition_t* part = s_ff_raw_handles[pdrv];
      |                            ^~~~
esp-idf/components/fatfs/vfs/vfs_fat_sdmmc.c warning: unused variable 'found' [-Wunused-variable]
  XXX |     bool found = s_get_context_id_by_card(card, &id);
      |          ^~~~~
2025-01-31 23:26:12 +04:00
safocl c399089248 refactor(components/fatfs): replace assert EXPR
assert expressions in the diskio_wl.c file contains a magical calculations.
Replace them with an equality check.
2025-01-29 23:25:27 +04:00
Tomáš Rohlínek a700e7c210 fix(storage/fatfs): use standard flex-array fields, instead of extension 2025-01-29 09:08:44 +01:00
Ivan Grokhotkov a1042c0cc2 feat(fatfs): add support for a few fcntl commands 2024-12-03 15:32:58 +01:00
Alexey Lapshin 888b5f7e8d feat(newlib): add picolibc support 2024-12-02 21:35:56 +07:00
Tomáš Rohlínek fdffba6f4c feat(storage/fatfs): move fatfs to new VFS API 2024-11-21 07:41:40 +01:00
wanckl 8a467ffd9a feat(driver_sdspi): c61 sdspi support 2024-10-24 13:54:08 +08:00
sonika.rathi 459f2517a8 feat(fatfs): enable partition handling for sectors less than 128 2024-10-08 13:35:08 +02:00