New ble_log_test app captures the runtime hook output through the test
peripheral and validates the version info frame: source code, BLE Log
version, a hex-valid idf commit that must be non-zero, per-lib commit
fields non-zero exactly when the matching lib is linked, and chip
model/revision matching esp_chip_info(). The README carries the
generated empty Supported Targets table to match the build-test
manifest.
The test drives transports via sustained writes instead of
ble_log_flush(): the flush window disables the module, so hook frames
written during a flush would be dropped.
Also move .build-test-rules.yml from ble_log_perf_test/ to the
test_apps/ root (one manifest entry per app, as elsewhere in ESP-IDF).
Both apps stay disabled until BLE Log test runners are available.
Verified: full esp32c6 build of the app; the build-test checker's own
parsing logic confirms the README table matches the manifest.
Replace the 2-byte BLE Log info record with a 58-byte version info
frame (BLE_LOG_VERSION 5 -> 6; the abandoned branch that claimed the
version-6 slot frees it, so the overall bump stays 5 -> 6):
- idf build commit (12 bytes), injected at build time by
register_ble_log_idf_commit() next to the other register_* helpers;
the git probe is only trusted when the IDF tree itself is a
repo/worktree, since rev-parse walks up parent directories
- controller, btdm_common, BLE Mesh and BLE Audio lib commits (10
bytes each, zero-padded), every getter guarded by the exact
condition that links its lib, so configs without the lib leave the
field zero (no link errors)
- chip model and revision from esp_chip_info() at runtime
Lib strings are copied NUL-safely instead of assuming a fixed hash
length; the mesh commit is the substring after the last space of
bt_mesh_v11_commit_str. Frame layout is pinned by a static assert.
Verified on target: esp32, esp32c3, esp32c5 and esp32h4 boards (the
h4 run covers controller + btdm_common + mesh in one build); the
audio-enabled build is blocked by pre-existing esp_ble_audio compile
errors on this base (audio symbol verified with nm instead).
Add smp_repairing_is_allowed() behind BT_BLE_SMP_HARDENED_REPAIRING so a
peer cannot replace an existing bond with one that has less MITM
protection, no Secure Connections, or a shorter key. Compare a preceding
Security Request against the pairing command AuthReq, not the
association-model result, and always allow first pairing.
A refusal keeps the stored bond. Pairing-failure erase is split by link
role: default is erase as Central and keep as Peripheral.
Closes BLERP (NDSS 2026) V3, V4 and V6.
Keep the existing bond until the new pairing is encrypted, and on encryption
failure drop the link instead of clearing keys. Recovering from a peer that
really deleted the bond is opt-in through BT_BLE_SMP_UNBOND_ON_KEY_MISSING.
Closes BLERP (NDSS 2026) V5, and stops an unauthenticated Pairing Request
from dropping the stored keys (V2 exploitation).
fix(bt/bluedroid): fixed the function prototype of the command handler of READ LOCAL SUPPORTED CODECS.
Closes BTQABR2023-888
See merge request espressif/esp-idf!51832
Do not reject osi_thread_post_event() when only POSTING is set.
QUEUED already prevents double-queueing; rejecting POSTING caused
HCI downstream lost wakeup. Add generic osi_event and hci downstream
diagnostics for post failures.
Introduce a seq_cst closing gate shared by the runtime and the LBM:
submitters increment the reference count before checking the inited
flag, and deinit closes the gate and waits for the count to drain
before deleting tasks, timers, queues, or buffers. A producer either
observes shutdown or its reference is visible to the wait, which makes
ble_log_deinit safe while write APIs are still active.
Submitters no longer block on the queue while holding a reference: a
timeout-0 send that cannot queue recycles the transport so its data
survives for the next flush.
Extract ble_log_ref_count_try_acquire/wait into the utility layer and
gate every LBM writer through ble_log_lbm_ref_acquire. ble_log_deinit
now closes the LBM gate first (ble_log_lbm_close) instead of clearing
the enable flag.
Move transport ownership from the runtime to the LBM: submit and
recycle now hand the peripheral-owned flag explicitly instead of the
runtime reaching back into LBM buffers. The submit path never blocks
producers - a transport that cannot be queued is recycled immediately
so its data survives for the next flush.
Cross-context ownership accesses go through explicit atomic helpers:
release-store on recycle pairs with acquire-loads in the flush paths,
and the inflight high-water mark stays a relaxed CAS-max (a plain
volatile update races the runtime hook's statistics reads).
- Gate bta_sys_event() on both 'is_reg' and 'reg[id]' to prevent
stale event delivery.
- Defer bta_sys_deregister() to the end of profile disable handlers
to ensure pending DISABLE events are processed.
- Add disabling flag to HFP AG for tracking asynchronous teardown.
Sort bond entries by bond_count after in-place updates to maintain correct
eviction order, and log IRK resolving-list failures instead of failing the bond.
Add a Unity-based perf test app under ble_log/test_apps with two
separate measurement purposes:
- throughput: multi-task (write_hex x3) + LL task/HCI + ISR + compressed
writers under 2 Mbps / 20 Mbps link caps, measuring system-wide
throughput only
- cycle: single-writer write_hex / write_hex_ll / compressed writes at
link=0, measuring per-frame cycles; the compressed path is split into
the encode phase and the write_hex phase via test-only counters in
ble_log_compression.c
Add the test-only transport (CONFIG_BLE_LOG_PRPH_TEST) that models DMA
ownership transfer and link-rate backpressure.