Commit Graph
53523 Commits
Author SHA1 Message Date
yangfeng e8108fefe1 fix(bt/bluedroid): Fix missing NULL check on p_cfg in AVDT_ReconfigReq
Closes SEC-1187
2026-07-16 11:30:38 +08:00
Li Shuai 4b8e1e8710 change(esp_pm): add kconfig option for REGDMA sleep clock ICG 2026-07-16 11:30:14 +08:00
Sarvesh Bodakhe faaaea8e67 fix(wpa_supplicant): guard pbkdf2_sha256 for PSA-provided SHA-256
mbedtls 4.x is PSA-first: CONFIG_MBEDTLS_SHA256_C now maps to
PSA_WANT_ALG_SHA_256, and on ESP targets the hardware SHA accelerator
serves SHA-256 through PSA, leaving the legacy MBEDTLS_SHA256_C builtin
macro undefined. The inner guard on pbkdf2_sha256 was gating on bare
MBEDTLS_SHA256_C, so the function was compiled out and NAN ND-PMK
derivation (nan_derive_nd_pmk_from_passphrase) failed to link.

Guard on (MBEDTLS_SHA256_C || PSA_WANT_ALG_SHA_256) to match the idiom
already used elsewhere in the supplicant mbedtls port (tls_mbedtls.c),
covering both the legacy builtin and PSA-provided SHA-256.
2026-07-16 11:29:29 +08:00
Jiang Jiang Jian 5595996fe8 Merge branch 'feat/update_pmu_pau_reg_description_v6.1' into 'release/v6.1'
feat(soc): update esp32c61 PMU & PAU reg header descriptions (v6.1)

See merge request espressif/esp-idf!50431
2026-07-16 11:28:44 +08:00
Jiang Jiang Jian 66ed442256 Merge branch 'fix/fatfs_vulnerabilities_v6.1' into 'release/v6.1'
fix(fatfs): harden against runZero 2026 FatFs bugs (v6.1)

See merge request espressif/esp-idf!50424
2026-07-16 11:28:22 +08:00
Jiang Jiang Jian f6eadf3e95 Merge branch 'fix/fix_mpll_enable_order_v6.1' into 'release/v6.1'
fix(esp_hw_support): fix esp32s31 mpll initialization (v6.1)

See merge request espressif/esp-idf!50430
2026-07-16 11:28:17 +08:00
Jiang Jiang Jian 0196213a13 Merge branch 'fix/ble_mesh_fixed_issues_v6.1' into 'release/v6.1'
Resolve reported BLE mesh stack issues (6.1)

See merge request espressif/esp-idf!50408
2026-07-16 11:27:36 +08:00
Jiang Jiang Jian f174b3baa6 Merge branch 'fix/vfs_fatfs_test_stale_partition_v6.1' into 'release/v6.1'
test(vfs): reformat WL FATFS in setup to avoid stale-partition flakes (v6.1)

See merge request espressif/esp-idf!50400
2026-07-16 11:27:21 +08:00
Jiang Jiang Jian 0e479cbf81 Merge branch 'bugfix/i2c_set_but_not_used_variable_v6.1' into 'release/v6.1'
fix(i2c): remove unused but set variables (v6.1)

See merge request espressif/esp-idf!50370
2026-07-16 10:48:53 +08:00
Jiang Jiang Jian 301caa6d45 Merge branch 'docs/ulp_fsm_instruction_v6.1' into 'release/v6.1'
docs(ulp): clarify ULP FSM instruction cycle timing (v6.1)

See merge request espressif/esp-idf!50365
2026-07-16 10:48:39 +08:00
Jiang Jiang Jian e813155ec4 Merge branch 'feature/dma2d_ppa_sleep_retention_support_v6.1' into 'release/v6.1'
feat(ppa): add sleep retention support for DMA2D and PPA (v6.1)

See merge request espressif/esp-idf!50342
2026-07-16 10:48:27 +08:00
Jiang Jiang Jian 479ff2c98b Merge branch 'change/change_regdma_malloc_caps_v6.1' into 'release/v6.1'
change(esp_hw_support): change regdma malloc caps to allow getting memory in the DMA pool (v6.1)

See merge request espressif/esp-idf!50257
2026-07-16 10:44:21 +08:00
Jiang Jiang Jian 3e573b992b Merge branch 'fix/fix_async_color_convert_csc_v6.1' into 'release/v6.1'
fix(dma2d): fix async color convert csc check (v6.1)

See merge request espressif/esp-idf!50238
2026-07-16 10:43:55 +08:00
Jiang Jiang Jian 68137eca5d Merge branch 'fix/fix_ble_rtc_register_issue_after_reset_v6.1' into 'release/v6.1'
fix(ble): fix ble rtc reset issues on esp32-h4 and esp32-s31 (6.1)

See merge request espressif/esp-idf!50204
2026-07-16 10:43:26 +08:00
Jiang Jiang Jian 7a0db8d0aa Merge branch 'fix/ble_mesh_disable_adv_pkt_discard_log_v6.1' into 'release/v6.1'
fix(ble_mesh): Disable warning logging when advertising packets are discarded (6.1)

See merge request espressif/esp-idf!50168
2026-07-16 10:42:18 +08:00
Jiang Jiang Jian 590dab22f9 Merge branch 'fix/fix_rgb_frame_buffer_alignment_v6.1' into 'release/v6.1'
fix(gdma): fix buffer alignment when psram ecc enabled (v6.1)

See merge request espressif/esp-idf!49996
2026-07-16 10:40:18 +08:00
Jiang Jiang Jian b259c51ee3 Merge branch 'change/update_c61_gdma_header_v6.1' into 'release/v6.1'
change(ahb_dma): update c61 eco3 header files (v6.1)

See merge request espressif/esp-idf!49835
2026-07-16 10:38:55 +08:00
Konstantin Kondrashov 5bc1dfc166 fix(bootloader): handle extra component dirs in v1 subproject
Closes https://github.com/espressif/esp-idf/issues/18651
2026-07-16 10:37:12 +08:00
Mahavir Jain 1918bb2b10 Merge branch 'bugfix/memory-safety-and-validation_v6.1' into 'release/v6.1'
fix(security): findings from project Vanessa (v6.1)

See merge request espressif/esp-idf!50390
2026-07-15 21:52:48 +05:30
Michael.B 48f5135a8d spi_flash: fix PSRAM rodata phys2cache mapping
Use the full rodata page range when converting flash physical addresses back to cache addresses for XIP PSRAM. RISC-V extram stack coredump tests are temporarily skipped in CI until coredump supports PSRAM task stacks (IDF-15623).
2026-07-15 18:57:08 +08:00
Xiao Xufeng 8b7b2008da bootloader_utils: fixed missing unmap in load_partition_table when table verify failed 2026-07-15 18:57:08 +08:00
Xiao Xufeng 3e8389cc31 fix(mmap): fixed some API read wrong data via mmap when flash being erased/written while XIP on PSRAM
Before:

The cache won't be disabled when XIP on psram. But during flash
erasing/programming, read data will be courrupt.

When XIP in psram is enabled, the image is not mapped to the cache so
usually there will be no flash access. The only way to read from flash
is via the driver or use mmap. The driver has protection during erasing,
while th mmap region not.

Now:

Mmap APIs provide a flag to make mmap->unmap region mutually exclusive
to flash erase/programming when XIP from psram. SPI Flash write APIs
will benefit from this. When the flag is used, no concurrent access to
mapped region will happen while writing; otherwise the cache will be
disable to avoid data corruption.

Most ESP-IDF APIs calls mmap with this flag. As for users calling
mmap-like APIs directly, they can choose whether to enable this by a
flag.

Closes https://github.com/espressif/esp-idf/issues/14897
2026-07-15 18:57:08 +08:00
Aditya Patwardhan 3e6429e881 fix(esp-tls): Keep deprecated use_secure_element field for compatibility
Restore the use_secure_element field in esp_tls_cfg_t, esp_tls_cfg_server_t
and httpd_ssl_config_t, and esp_transport_ssl_use_secure_element(), as
deprecated no-ops so that existing code keeps compiling. Setting them now
fails at runtime with ESP_ERR_NOT_SUPPORTED, as the feature is accessed
via the esp_key_config_t interface. To be removed in the next major release.

No compile-time deprecation attribute on this release branch; the field and
function stay warning-free here and carry only documentation notes.
2026-07-15 15:34:17 +05:30
wuzhenghui 981208a9ad fix(esp_hw_support): disable esp32 livelock workaround before stall another core 2026-07-15 16:10:51 +08:00
Aditya Patwardhan 39a219331c Merge branch 'feature/update-openocd-to-v0.12.0-esp32-20260703_v6.1' into 'release/v6.1'
feat(tools): update openocd version to v0.12.0-esp32-20260703 (v6.1)

See merge request espressif/esp-idf!50502
2026-07-15 12:26:55 +05:30
radek.tandler f26db8177e fix(nvs_flash): fixed cleanup after nvs_set_blob failed on ESP_ERR_NVS_NOT_ENOUGH_SPACE
- fixed identification of blob parts to be cleaned by using right starting chunk index
  - improved localisation of blobs for cases where some of pages get reclaimed
  - created host test cases covering the edge cases above
2026-07-14 16:42:27 +02:00
yi chen e9c3ed8fb4 fix(wear_levelling): guard WL_Flash::write()/read() against size==0 underflow
WL_Flash::write() and WL_Flash::read() computed:

    uint32_t count = (size - 1) / this->cfg.wl_page_size;

`size` is `size_t` (unsigned). Neither the public wl_write()/wl_read() API
(wear_levelling.cpp), nor the newer wl_bdl_write()/wl_bdl_read() block-device
path (wl_blockdev.cpp), reject size == 0 before calling into WL_Flash, and
wear_levelling.h does not document size == 0 as invalid (a 0-byte
write/read is a reasonable no-op, mirroring POSIX write()/read() with
count == 0).

When size == 0, `size - 1` wraps around to SIZE_MAX, so `count` becomes an
enormous page count instead of 0. The functions then loop that many times,
reading (write()) or writing (read()) `wl_page_size` bytes per iteration
through the flash partition, immediately walking past the caller-supplied
buffer on the very first iteration:

  - write(): out-of-bounds *read* from the caller's `src` buffer.
  - read():  out-of-bounds *write* into the caller's `dest` buffer -- the
             more severe case, since it corrupts caller memory with flash
             content instead of merely over-reading.

Verified with a standalone reproduction that compiles the unmodified
WL_Flash.cpp against a mock Flash_Access partition: calling
`wl.write(0, an_8_byte_buffer, 0)` with no other change immediately
segfaults (confirmed count == 0xFFFFFFFF for wl_page_size == 4096); with
this fix applied the same call returns ESP_OK without touching memory
outside the buffer, and normal non-zero-size read/write is unaffected.

Add an early `size == 0` return (mirroring the existing `!initialized`
guard) to both functions, and a host_test regression case exercising
wl_write()/wl_read() with size == 0 through the public API.

Disclosure: this fix was prepared with AI assistance (Claude) and reviewed
by me before submission.

Signed-off-by: yi chen <94xhn1@gmail.com>
2026-07-14 12:22:53 +02:00
Akshat Agrawal 9c42f5f06f fix(nan): Transmit NULL packet correctly to avoid NDP termination 2026-07-14 10:31:40 +05:30
Shreyas Sheth 1519772ea8 fix(wpa_supplicant): Fix issues related to pmkid mismatch and eloop for dpp 2026-07-14 10:31:19 +05:30
tarun.kumar abe397bdf8 fix(wifi) : Correct blacklist flag
- Fixes state desync where global blacklist was cleared but blacklist bss flag was true causing rejection of correct AP as well.
2026-07-14 10:31:06 +05:30
zhangyanjiao a83db6a045 fix(wifi): fixed the offchan tx fail when SPIRAM_TRY_ALLOCATE_WIFI_LWIP enabled 2026-07-14 10:30:52 +05:30
Zhang Hai Peng b50cef44fb docs(ble/bluedroid): fix markdown formatting in example docs
(cherry picked from commit dba450de6b)

Co-authored-by: zhanghaipeng <zhanghaipeng@espressif.com>
2026-07-14 10:37:22 +08:00
Zhang Hai Peng a6404dcf8d fix(ble/bluedroid): downgrade numeric comparison log to warning
(cherry picked from commit 72a49ed53b)

Co-authored-by: zhanghaipeng <zhanghaipeng@espressif.com>
2026-07-14 10:37:22 +08:00
Zhang Hai Peng f4c2b75897 fix(ble/bluedroid): preserve ext adv state when set params fails
Only update extend_adv_cb after HCI Set Extended Advertising
Parameters succeeds, so a failed update does not corrupt cached
legacy_pdu and related fields used by adv data validation.


(cherry picked from commit 31bd80fee8)

Co-authored-by: zhanghaipeng <zhanghaipeng@espressif.com>
2026-07-14 10:37:21 +08:00
Zhang Hai Peng 169bf6975b fix(ble/bluedroid): reject invalid ATT error code 0x00 on client
Map received error reason 0x00 to GATT_UNKNOWN_ERROR so the client
does not report GATT_SUCCESS with zero-length data on malformed errors.


(cherry picked from commit 1b6f9380f4)

Co-authored-by: zhanghaipeng <zhanghaipeng@espressif.com>
2026-07-14 10:36:38 +08:00
Zhang Hai Peng be95975fee fix(ble/bluedroid): use sr_cmd status for GATT server error rsp
When sending an ATT error response after a failed server operation,
use p_tcb->sr_cmd.status instead of the last app callback status so
invalid error code 0x00 is not sent to the peer.


(cherry picked from commit 4c0488d92a)

Co-authored-by: zhanghaipeng <zhanghaipeng@espressif.com>
2026-07-14 10:36:36 +08:00
Zhang Hai Peng 96b27367a1 fix(ble/bluedroid): match read-multiple-var responses by handle
(cherry picked from commit 979c7dc567)

Co-authored-by: zhanghaipeng <zhanghaipeng@espressif.com>
2026-07-14 10:36:34 +08:00
Zhang Hai Peng 2bb2f01dd3 fix(ble/bluedroid): match read-multiple responses by handle
Read Multiple may mix stack auto-responses with app async responses,
so multi_rsp_q order can differ from the request handle order. Look up
each response by handle (with occurrence for duplicates) instead of
walking the queue by index, and treat opcode-only buffers as empty.


(cherry picked from commit f91a41510c)

Co-authored-by: zhanghaipeng <zhanghaipeng@espressif.com>
2026-07-14 10:36:33 +08:00
yi chen e8e1987a6a fix(vfs): use MAX_FDS instead of VFS_MAX_COUNT when clearing fd table on unregister
esp_vfs_unregister_with_id() scanned only the first VFS_MAX_COUNT
(default 8, max 20) slots of s_fd_table[MAX_FDS] (MAX_FDS = FD_SETSIZE,
64 on non-Cygwin targets) when clearing stale references to the
unregistered VFS. Every other loop over s_fd_table in this file
(and in vfs_calls.c) correctly bounds on MAX_FDS.

Any global fd >= VFS_MAX_COUNT that was still open against the VFS
being unregistered was left with a stale vfs_index pointing at a slot
that esp_get_free_index() can immediately hand out to the next
esp_vfs_register*() call, causing later operations on that fd to be
routed into an unrelated filesystem's context.

Signed-off-by: yi chen <94xhn1@gmail.com>
2026-07-13 15:58:26 +02:00
Guillaume Souchere 150a067da5 fix(console): Clamp linenoise cols field to 80 if getColums returns less than that 2026-07-13 12:15:56 +02:00
Guillaume Souchere cad3ef220e fix(console): Fix security code review findings 2026-07-13 12:15:56 +02:00
gaoxu a0be9bdfbd ci(csi): added test for MIPI-CSI host error event 2026-07-13 18:03:49 +08:00
gaoxu 666326e55c feat(csi): add MIPI-CSI host error event 2026-07-13 18:03:49 +08:00
morris f91e2baa41 feat(jpeg): simplify decoder example and add pytest coverage 2026-07-13 16:18:51 +08:00
Samuel Obuch 88f7f94bc9 feat(tools): update openocd version to v0.12.0-esp32-20260703 2026-07-13 09:53:58 +02:00
C.S.M 9adcf8677b feat(psram): Add unencrypted region for psram for esp32s31 2026-07-13 15:01:29 +08:00
C.S.M e92e669dee fix(jpeg): JPEG can encode and decode in encryption situation 2026-07-13 15:00:31 +08:00
morris a28640f417 fix(i2c): remove unused but set variables 2026-07-13 14:40:45 +08:00
Ashish Sharma 8d8068aee3 fix(esp_tee): fix DS-lock leak, intr-matrix OOB, calloc overflow, attestation leak 2026-07-13 14:40:44 +08:00
Ashish Sharma 2a63a05a85 fix(esp-tls): reject NULL host/url in plain-TCP and async HTTP connect 2026-07-13 14:40:44 +08:00