Commit Graph
36132 Commits
Author SHA1 Message Date
Jiang Jiang Jian dc330a5273 Merge branch 'bugfix/wpa_supplicant_upstream_security_issues_v6.0' into 'release/v6.0'
esp_wifi: Port security issues from upstream supplicant (v6.0)

See merge request espressif/esp-idf!52675
2026-09-15 12:03:35 +08:00
Jiang Jiang Jian d27b57156f Merge branch 'feat/pm_components_ram_optimize_v6.0' into 'release/v6.0'
feat(pm): pm components ram optimize (v6.0)

See merge request espressif/esp-idf!52426
2026-09-15 12:03:15 +08:00
Jiang Jiang Jian 2abf18324f Merge branch 'bugfix/fix_example_power_save_build_fail_issue_v6.0' into 'release/v6.0'
fix(esp_timer): preserve timer_process_alarm symbol for ldgen(Backport v6.0)

See merge request espressif/esp-idf!52740
2026-09-15 12:01:00 +08:00
Wang Meng Yang 50b9a4b19e Merge branch 'fix/bt_hfp_v6.0' into 'release/v6.0'
fix(bt_hfp): Fix some bugs in hfp (v6.0)

See merge request espressif/esp-idf!52750
2026-09-15 09:30:43 +08:00
Wang Meng Yang bde2b24561 Merge branch 'bugfix/fix_pbac_pm_config_v6.0' into 'release/v6.0'
fix(bt/bluedroid): enable sniff power management for PBAP client (v6.0)

See merge request espressif/esp-idf!52762
2026-09-14 17:23:33 +08:00
Euripedes Rocha 9b68b8ff53 Merge branch 'fix/ieee802_3_reset_time_v6.0' into 'release/v6.0'
fix(esp_eth): fixed Ethernet PHY HW reset timing in common PHY code (v6.0)

See merge request espressif/esp-idf!51711
2026-09-14 10:02:42 +02:00
morris d9b02e9c06 Merge branch 'fix/mcpwm_cap_prescale_v6.0' into 'release/v6.0'
fix(mcpwm): correct the wrong capture prescale (v6.0)

See merge request espressif/esp-idf!52505
2026-09-14 15:14:49 +08:00
Ondrej Kosta ed6d83b3af fix(esp_eth): fixed Ethernet PHY HW reset timing in common PHY code 2026-09-14 09:01:46 +02:00
Euripedes Rocha de07da4a74 Merge branch 'fix/ethernet_init_ver_v6.0' into 'release/v6.0'
ci(esp_eth): use fixed version of eth_test_app (v6.0)

See merge request espressif/esp-idf!51588
2026-09-14 09:00:54 +02:00
Euripedes Rocha a85d83ebf5 Merge branch 'contrib/github_pr_18648_v6.0' into 'release/v6.0'
esp_eth: make OpenETH ISR logging DRAM-safe (GitHub PR) (v6.0)

See merge request espressif/esp-idf!51924
2026-09-14 09:00:08 +02:00
Island 4891edcd73 Merge branch 'change/ble_update_lib_20260904_v6.0' into 'release/v6.0'
change(ble): [AUTO_MR] 20260904 - Update ESP BLE Controller Lib (6.0)

See merge request espressif/esp-idf!52439
2026-09-14 10:36:09 +08:00
linruihao a3fa33aad3 fix(bt/bluedroid): enable sniff power management for PBAP client 2026-09-14 10:19:17 +08:00
Marius Vikhammer ba1d9d48e3 Merge branch 'fix/esp_task_stack_is_sane_cache_disabled_spm_check' into 'release/v6.0'
fix(spi_flash): recognize SPM-resident stacks as cache-disable-safe (ESP32-P4)

See merge request espressif/esp-idf!52737
2026-09-14 09:56:02 +08:00
Mahavir Jain 8e2153965f Merge branch 'fix/mbedtls_gcm_multipart_and_ecp_pubkey_v6.0' into 'release/v6.0'
Fix/mbedTLS port layer security fixes (394, 1214, 1206) (v6.0)

See merge request espressif/esp-idf!52195
2026-09-13 16:45:07 +05:30
Mahavir Jain afe335355d Merge branch 'fix/esp_crt_bundle_allocator_symmetry_v6.0' into 'release/v6.0'
fix(esp_crt_bundle): match memory allocator in cross-signed callback (v6.0)

See merge request espressif/esp-idf!52729
2026-09-13 16:42:05 +05:30
Shreeyash Bhakare ec250befd6 fix(nimble): Send Prepare Write Request before Execute Write in write long with zero-length data 2026-09-11 14:57:16 +05:30
hejiaxin f43561e692 fix(bt_hfp): Fix some bugs in hfp
- Fix hfp callback data length
- Fix the solution of unknown AT command
2026-09-11 17:25:51 +08:00
Alexey Gerenkov 65f14a0d53 Merge branch 'esp_trace_optimizations_v6.0' into 'release/v6.0'
change(esp_trace): compile hot path at -O2 regardless of project optimization (v6.0)

See merge request espressif/esp-idf!52658
2026-09-11 17:20:09 +08:00
Rahul Tank 8da0b7af1f Merge branch 'bugfix/nimble_issues_08092026_v6.0' into 'release/v6.0'
fix few nimble issues 08092026 (v6.0)

See merge request espressif/esp-idf!52601
2026-09-11 14:20:57 +05:30
zhaoweiliang b6520d92d5 change(ble): [AUTO_MR] Update lib_esp32c5 to acd9a26e 2026-09-11 16:18:06 +08:00
zhaoweiliang 4f4ee5eded change(ble): [AUTO_MR] Update lib_esp32h2 to acd9a26e 2026-09-11 16:17:08 +08:00
zhaoweiliang 13ba93d55c change(ble): [AUTO_MR] Update lib_esp32c6 to acd9a26e 2026-09-11 16:15:38 +08:00
muhaidong 90fff319cd fix(esp_timer): preserve timer_process_alarm symbol for ldgen 2026-09-11 16:00:29 +08:00
Guillaume Souchere a28c236c21 fix(spi_flash): Check for SPM memory in esp_task_stack_is_sane_cache_disabled 2026-09-11 09:42:26 +02:00
Island e088053614 Merge branch 'fix/ble_log_compression_issue_on_windows_v6.0' into 'release/v6.0'
fix(bt): fix BLE log compression build on Windows (6.0)

See merge request espressif/esp-idf!51246
2026-09-11 14:53:34 +08:00
Island bb3321fedd Merge branch 'feat/bt_osal_build_configurable_v6.0' into 'release/v6.0'
feat(bt): Add Kconfig option to build the BT OSAL conditionally (6.0)

See merge request espressif/esp-idf!52516
2026-09-11 14:35:24 +08:00
Island 959545a41b Merge branch 'fix/ble_mesh_added_gatt_err_rsp_v6.0' into 'release/v6.0'
fix(ble_mesh): align GATTS read/write response handling with ATT (6.0)

See merge request espressif/esp-idf!51463
2026-09-11 14:33:57 +08:00
Ashish Sharma a6adc3b5e8 fix(esp_crt_bundle): match memory allocator in cross-signed callback
Closes https://github.com/espressif/esp-idf/issues/19053
2026-09-11 14:10:06 +08:00
morris efa3456ec5 Merge branch 'feat/spi_add_data_output_inversion_v6.0' into 'release/v6.0'
feat(spi): support data output inversion (backport v6.0)

See merge request espressif/esp-idf!52714
2026-09-11 12:14:06 +08:00
Shu Chen 1a11140e13 Merge branch 'fix/openthread-udp-host-interface_v6.0' into 'release/v6.0'
fix(openthread): preserve host interface on UDP receive (v6.0)

See merge request espressif/esp-idf!52690
2026-09-11 03:41:59 +00:00
Marius Vikhammer d0e38712e3 Merge branch 'fix/lp_core_rc_fast_delay_freq_v6.0' into 'release/v6.0'
fix(ulp): hardcode LP core RC_FAST frequency per target (v6.0)

See merge request espressif/esp-idf!52671
2026-09-11 09:54:56 +08:00
Steven (Yang Minghui) 624a9c6551 feat(spi): support data output inversion 2026-09-10 22:08:59 +08:00
Island 0c269a2f66 Merge branch 'fix/esp32-ble-dtm-txbuf-leak_v6.0' into 'release/v6.0'
Fix DTM TX buffer leak in the BLE controller that could cause memory exhaustion and Interrupt WDT timeout during or after DTM TX tests. (6.0)

See merge request espressif/esp-idf!52615
2026-09-10 20:50:53 +08:00
Island 0d25ea96d7 Merge branch 'feat/opt_prefer_bond_device_when_evicting_overflow_bonds_v6.0' into 'release/v6.0'
fix(bt/bluedroid): prefer disconnected peers when evicting overflow bonds (6.0)

See merge request espressif/esp-idf!52610
2026-09-10 20:50:40 +08:00
Island ba6bbdeb41 Merge branch 'bugfix/fix_bluedroid_find_info_format_mismatch_v6.0' into 'release/v6.0'
fix(ble/bluedroid): restore find info PDU stop on UUID format mismatch (6.0)

See merge request espressif/esp-idf!52080
2026-09-10 20:50:30 +08:00
Rahul Tank 768198540a Merge branch 'bugfix/hardware_error_assert_v6.0' into 'release/v6.0'
fix(nimble): Add hardware error event handling as normal event (v6.0)

See merge request espressif/esp-idf!52553
2026-09-10 17:33:50 +05:30
zwx 890b939847 fix(openthread): preserve host interface on UDP receive 2026-09-10 16:22:31 +08:00
Martin Vychodil c734860ba1 Merge branch 'feature/fatfs_bdl_v6.0' into 'release/v6.0'
feat(fatfs): Add BDL support to FatFS component (v6.0)

See merge request espressif/esp-idf!52557
2026-09-10 16:10:00 +08:00
Martin Vychodil e0c1910bb0 Merge branch 'fix/fatfs-vfs-fcntl-setfl_v6.0_2' into 'release/v6.0'
fix(fatfs): preserve access mode in VFS F_SETFL (v6.0)

See merge request espressif/esp-idf!51922
2026-09-10 16:07:28 +08:00
morris 3fd62e1c09 Merge branch 'feat/support_link_switch_for_parlio_tx_v6.0' into 'release/v6.0'
feat(parlio_tx): apply the gdma link switch event to parlio_tx (v6.0)

See merge request espressif/esp-idf!51423
2026-09-10 14:42:20 +08:00
sonika.rathi 00e6b37985 fix(fatfs): avoid stack overflow in BDL diskio partition test
(cherry picked from commit 1d08a22a14)
2026-09-10 08:36:18 +02:00
LiPeng 841c3a4de7 fix(fatfs): fix a memory leak bug when FF_USE_DYN_BUFFER was enabled
BDL diskio test part only; the rest of the commit is already on release/v6.0
via 4f7b1af0f9, which predates components/fatfs/test_apps/bdl.

(cherry picked from commit a8b5b8d582)
2026-09-10 08:36:12 +02:00
Richard Allen 0e59d78459 TLS: Avoid discarded-qualifiers
Just a build issue fix depending on GCC5+ configuration, fixes:

assignment discards 'const' qualifier from pointer target type [-Werror=discarded-qualifiers]
return discards 'const' qualifier from pointer target type [-Werror=discarded-qualifiers]

Signed-off-by: Richard Allen <richard@bryghtlabs.com>
2026-09-10 11:32:36 +05:30
Jimi Chen c90545c85d SAE: Fix crash due to NULL pointer dereference in H2E parsing
In H2E (Hash-to-Element) mode, sae_parse_commit() parses the optional
Anti-Clogging Token Container by calling sae_parse_token_container().

However, callers of sae_parse_commit() that do not require retrieving
the anti-clogging token (such as PASN initiator/responder and SME auth)
pass NULL for the token and token_len output arguments.

If the peer sends a Commit frame containing a valid Anti-Clogging
Token Container element, sae_parse_token_container() unconditionally
sets *token and *token_len, resulting in a NULL pointer dereference
(SIGSEGV) and crashing wpa_supplicant.

Fix this by adding NULL checks before writing to token and token_len.
Update the debug log to print the token directly using 'pos'.

Fixes: 5e32fb0170f4 ("SAE: Use Anti-Clogging Token Container element with H2E")
Signed-off-by: Amarnath Hullur Subramanyam <amarnathhs@google.com>
2026-09-10 11:32:32 +05:30
Jouni Malinen 5a671d7412 Require network_ctx and AKMP match for accepting PMKSA entry
When wpa_supplicant was processing EAPOL-Key msg 1/4 with a PMKID
indicated by the AP/Authenticator, a PMKSA for the same AA was accepted
without enforcing matching network_ctx (i.e., same network configuration
block) and AKMP. This could allow misbehaving APs to make wpa_supplicant
use an unacceptable PMKSA entry that was generated for a different
network for AKMP under certain conditions. This could result in showing
a connection to an incorrect network when an attacker has credentials to
one network in wpa_supplicant configuration, but not to another network.

Fix this by accepting the PMKID to set the PMKSA for an association only
if the PMKSA with the same PMKID is for the same network and was
generated using the same AKMP.

Signed-off-by: Jouni Malinen <jouni.malinen@oss.qualcomm.com>
2026-09-10 11:32:19 +05:30
Aditi bd545de697 feat(wpa_supplicant): Match SPA when searching PMKSA cache
Store the supplicant address (SPA) in PMKSA cache entries and match
it when looking up the PMKSA cache.

(partially picked from commit 18cbdbf2b1)
2026-09-10 11:27:53 +05:30
Jiang Jiang Jian b5016c7765 Merge branch 'bugfix/fix_crash_issue_on_smartconfig_and_mbssid_v6.0' into 'release/v6.0'
fix(wifi): added validation for password and reserved data length in ESPTouch v2 (v6.0)

See merge request espressif/esp-idf!51393
2026-09-10 11:27:28 +08:00
Jiang Jiang Jian 8dec8dc0b8 Merge branch 'fix/fix_issues_when_support_multiple_phy_init_data_v6.0' into 'release/v6.0'
Fix/fix issues when support multiple phy init data v6.0(backport v6.0)

See merge request espressif/esp-idf!52585
2026-09-10 11:11:34 +08:00
Luo Xu 59a30e9ba2 fix(bt): fix BLE log compression build on Windows
The BLE log compression feature (CONFIG_BT_LOG_CRITICAL_ONLY ->
BLE_COMPRESSED_LOG_ENABLE) failed to build on Windows while working
correctly on Linux, due to two shell/platform-specific issues in the
compression script.

1. Module/source argument quoting. CMakeLists.txt passes the
   semicolon-separated module and source lists wrapped in single quotes
   ("'${MODULES}'") to protect ';' from POSIX shells, which strip them.
   cmd.exe does not treat single quotes as quoting characters, so on
   Windows the quotes reached the script literally and
   args.module.split(';') produced "'BLE_MESH" / "BLE_HOST'" instead of
   the clean names. These never matched the YAML module keys, every
   module was skipped ("Skipping module ... - config not found"), the
   compressed sources were never generated, and the build failed. Strip
   surrounding quote characters before splitting; this is a no-op on
   Linux/macOS where the shell already removed them.

2. CRLF line endings. With core.autocrlf=true the IDF sources are
   checked out as CRLF on Windows. The generated *_log_index.h macros
   use backslash-newline line-continuation; a backslash followed by
   '\r\n' is not a valid continuation in C, producing floods of syntax
   errors when the header is compiled. Write generated headers with
   newline='' to force LF, and normalize source content to LF right
   after reading so '\r' embedded inside multi-line argument expressions
   is also handled. Byte offsets stay consistent because both tree-sitter
   parsing and tag replacement operate on the normalized content.

Verified by full clean builds of examples/bluetooth/esp_ble_mesh/
vendor_models/vendor_client (esp32c6, bluedroid + mesh) from both
cmd.exe and PowerShell; both produce an identical vendor_client.bin.


(cherry picked from commit aa9b565a6d)

Co-authored-by: luoxu <luoxu@espressif.com>
2026-09-10 10:29:15 +08:00
Luo Xu 12aa692dcc fix(ble_mesh): align GATTS read/write response handling with ATT
bt_mesh_bta_gatts_cb did not always answer ATT Read/Write Requests:
- READ: on a callback error it only logged a warning and sent nothing; a
  0-byte read (Read Blob at an offset equal to the value length) also sent
  nothing, although it is a successful empty read.
- WRITE: on a callback error it sent nothing, and a partial/zero write was
  treated as success.
- Both: when the handle was not found or the attribute had no read/write
  callback, the request was silently dropped.

An ATT Request must always be answered:

- READ: len >= 0 is success -> Read Response (a 0-byte read yields an empty
  value); len < 0 -> ATT Error Response carrying the callback's error code
  (-len, since BLE_MESH_GATT_ERR(x) == -x). The copy length is clamped to
  the source buffer size as a defensive bound. If the handle is unknown or
  the attribute has no read callback, respond with INVALID_HANDLE /
  READ_NOT_PERMITTED.
- WRITE: when need_rsp is set, always reply. len == write length -> Write
  Response; otherwise (negative ATT error, partial write, or 0) -> ATT
  Error Response (the negative code, or UNLIKELY for partial/0). If the
  handle is unknown or the attribute has no write callback, respond with
  INVALID_HANDLE / WRITE_NOT_PERMITTED. Write Without Response still sends
  no response.

A non-success status passed to BTA_GATTS_SendRsp is turned into an ATT
Error Response by the GATT layer (gatt_sr_process_app_rsp ->
gatt_send_error_rsp).


(cherry picked from commit ed1f4de3a3)

Co-authored-by: luoxu <luoxu@espressif.com>
2026-09-10 10:29:07 +08:00