Commit Graph
53434 Commits
Author SHA1 Message Date
Aditya Patwardhan 3e6429e881 fix(esp-tls): Keep deprecated use_secure_element field for compatibility
Restore the use_secure_element field in esp_tls_cfg_t, esp_tls_cfg_server_t
and httpd_ssl_config_t, and esp_transport_ssl_use_secure_element(), as
deprecated no-ops so that existing code keeps compiling. Setting them now
fails at runtime with ESP_ERR_NOT_SUPPORTED, as the feature is accessed
via the esp_key_config_t interface. To be removed in the next major release.

No compile-time deprecation attribute on this release branch; the field and
function stay warning-free here and carry only documentation notes.
2026-07-15 15:34:17 +05:30
Aditya Patwardhan 39a219331c Merge branch 'feature/update-openocd-to-v0.12.0-esp32-20260703_v6.1' into 'release/v6.1'
feat(tools): update openocd version to v0.12.0-esp32-20260703 (v6.1)

See merge request espressif/esp-idf!50502
2026-07-15 12:26:55 +05:30
radek.tandler f26db8177e fix(nvs_flash): fixed cleanup after nvs_set_blob failed on ESP_ERR_NVS_NOT_ENOUGH_SPACE
- fixed identification of blob parts to be cleaned by using right starting chunk index
  - improved localisation of blobs for cases where some of pages get reclaimed
  - created host test cases covering the edge cases above
2026-07-14 16:42:27 +02:00
Akshat Agrawal 9c42f5f06f fix(nan): Transmit NULL packet correctly to avoid NDP termination 2026-07-14 10:31:40 +05:30
Shreyas Sheth 1519772ea8 fix(wpa_supplicant): Fix issues related to pmkid mismatch and eloop for dpp 2026-07-14 10:31:19 +05:30
tarun.kumar abe397bdf8 fix(wifi) : Correct blacklist flag
- Fixes state desync where global blacklist was cleared but blacklist bss flag was true causing rejection of correct AP as well.
2026-07-14 10:31:06 +05:30
zhangyanjiao a83db6a045 fix(wifi): fixed the offchan tx fail when SPIRAM_TRY_ALLOCATE_WIFI_LWIP enabled 2026-07-14 10:30:52 +05:30
Zhang Hai Peng b50cef44fb docs(ble/bluedroid): fix markdown formatting in example docs
(cherry picked from commit dba450de6b)

Co-authored-by: zhanghaipeng <zhanghaipeng@espressif.com>
2026-07-14 10:37:22 +08:00
Zhang Hai Peng a6404dcf8d fix(ble/bluedroid): downgrade numeric comparison log to warning
(cherry picked from commit 72a49ed53b)

Co-authored-by: zhanghaipeng <zhanghaipeng@espressif.com>
2026-07-14 10:37:22 +08:00
Zhang Hai Peng f4c2b75897 fix(ble/bluedroid): preserve ext adv state when set params fails
Only update extend_adv_cb after HCI Set Extended Advertising
Parameters succeeds, so a failed update does not corrupt cached
legacy_pdu and related fields used by adv data validation.


(cherry picked from commit 31bd80fee8)

Co-authored-by: zhanghaipeng <zhanghaipeng@espressif.com>
2026-07-14 10:37:21 +08:00
Zhang Hai Peng 169bf6975b fix(ble/bluedroid): reject invalid ATT error code 0x00 on client
Map received error reason 0x00 to GATT_UNKNOWN_ERROR so the client
does not report GATT_SUCCESS with zero-length data on malformed errors.


(cherry picked from commit 1b6f9380f4)

Co-authored-by: zhanghaipeng <zhanghaipeng@espressif.com>
2026-07-14 10:36:38 +08:00
Zhang Hai Peng be95975fee fix(ble/bluedroid): use sr_cmd status for GATT server error rsp
When sending an ATT error response after a failed server operation,
use p_tcb->sr_cmd.status instead of the last app callback status so
invalid error code 0x00 is not sent to the peer.


(cherry picked from commit 4c0488d92a)

Co-authored-by: zhanghaipeng <zhanghaipeng@espressif.com>
2026-07-14 10:36:36 +08:00
Zhang Hai Peng 96b27367a1 fix(ble/bluedroid): match read-multiple-var responses by handle
(cherry picked from commit 979c7dc567)

Co-authored-by: zhanghaipeng <zhanghaipeng@espressif.com>
2026-07-14 10:36:34 +08:00
Zhang Hai Peng 2bb2f01dd3 fix(ble/bluedroid): match read-multiple responses by handle
Read Multiple may mix stack auto-responses with app async responses,
so multi_rsp_q order can differ from the request handle order. Look up
each response by handle (with occurrence for duplicates) instead of
walking the queue by index, and treat opcode-only buffers as empty.


(cherry picked from commit f91a41510c)

Co-authored-by: zhanghaipeng <zhanghaipeng@espressif.com>
2026-07-14 10:36:33 +08:00
Guillaume Souchere 150a067da5 fix(console): Clamp linenoise cols field to 80 if getColums returns less than that 2026-07-13 12:15:56 +02:00
Guillaume Souchere cad3ef220e fix(console): Fix security code review findings 2026-07-13 12:15:56 +02:00
Samuel Obuch 88f7f94bc9 feat(tools): update openocd version to v0.12.0-esp32-20260703 2026-07-13 09:53:58 +02:00
morris a28640f417 fix(i2c): remove unused but set variables 2026-07-13 14:40:45 +08:00
Ashish Sharma 8d8068aee3 fix(esp_tee): fix DS-lock leak, intr-matrix OOB, calloc overflow, attestation leak 2026-07-13 14:40:44 +08:00
Ashish Sharma 2a63a05a85 fix(esp-tls): reject NULL host/url in plain-TCP and async HTTP connect 2026-07-13 14:40:44 +08:00
Ashish Sharma e4304fab76 fix(mbedtls): validate crypto input lengths (TEE OOB, auth-bypass, overflows) 2026-07-13 14:40:44 +08:00
Ashish Sharma e382f878cc fix(esp_https_server): free TLS session on transport_ctx OOM in httpd_ssl_open 2026-07-13 14:40:44 +08:00
Ashish Sharma 35227e41e9 fix(esp_hal_security): clamp tag_len in aes_hal_gcm_read_tag to prevent OOB 2026-07-13 14:40:44 +08:00
Ashish Sharma bcfb0407f9 fix(bootloader_support): guard NULL efuse digest slot in secure-boot verify 2026-07-13 14:40:44 +08:00
Ashish Sharma ef4ecd0591 fix(esp_http_client): fix digest-auth leaks and credential/handle use-after-free 2026-07-13 14:40:44 +08:00
Ashish Sharma b589180b8b fix(esp_http_server): close UAF/double-free, buffer underflows, and OOB read 2026-07-13 14:40:44 +08:00
Ashish Sharma 9843bcc8dc fix(app_update): close OOB read, rollback-guard gap, and length underflow 2026-07-13 14:40:44 +08:00
hebinglin 0682c52828 fix(esp_hw_support): fix xtal unstable when carry 154 and ble cases 2026-07-13 12:11:49 +08:00
morris 0f3a788f16 fix(sdspi): reject oversized pre-read data before block receive
Guard start_command_read_blocks against cards that place TOKEN_BLOCK_START so early that extra_data_size exceeds the bytes expected on the current iteration. Without this check, the unsigned subtraction for will_receive underflows and propagates into memset, SPI transaction length, and memcpy counts against the fixed 516-byte block buffer.
2026-07-13 11:18:12 +08:00
morris f1cc319c2d fix(spi_slave): free DMA-private buffers when transaction queue is full
spi_slave_queue_trans calls spi_slave_setup_priv_trans to allocate
DMA buffers, then tries xQueueSend. If the queue is full the function
returns ESP_ERR_TIMEOUT without freeing those buffers, leaking up to
2 * max_transfer_sz per failed call. Call spi_slave_uninstall_priv_trans
before returning the timeout.
2026-07-13 11:18:12 +08:00
morris 2ab4b39ce5 fix(jpeg): release platform mutex on semaphore/pm-lock allocation failure
jpeg_acquire_codec_handle acquires s_jpeg_platform.mutex at entry
but two ESP_RETURN_ON_* macros (semaphore-create and PM-lock-create
failure) return without releasing it. Replace with ESP_GOTO_ON_*
that jumps to a cleanup label which frees partial resources, NULLs
the codec pointer, and releases the mutex.
2026-07-13 11:18:12 +08:00
morris cd28383088 fix(i2c): release platform mutex on intr/pm_lock delete failure
ESP_RETURN_ON_ERROR inside the s_i2c_platform.mutex critical section
returns without releasing the mutex, permanently blocking all I2C
bus operations. Replace with ESP_GOTO_ON_ERROR that jumps to a
cleanup label releasing the mutex before return.
2026-07-13 11:16:54 +08:00
morris 2c2f5ebf20 fix(csi): move csi_fsm init before resource allocation to fix err-path leak
CSI_FSM_INIT is 1, but the controller struct is zero-allocated.
Any failure before the former csi_fsm assignment (near the end of
esp_cam_new_csi_ctlr) jumped to err: which called s_del_csi_ctlr.
That function bailed out immediately because csi_fsm == 0, leaking
the claimed slot, queue, bridge, DMA channel, PM lock, and backup
buffer. Move csi_fsm = CSI_FSM_INIT right after a successful claim
so the err: path properly tears down all allocated resources.
2026-07-13 11:16:54 +08:00
morris 403074177f fix(adc): add missing input validation for channel and ret_handle
- adc_cali_curve_fitting: validate config->chan in check_valid() to
  prevent OOB access into s_adc_cali_chan_compens compensation table
- adc_filter: make s_adc_filter_free idempotent on !UNIT_BINDED SoCs
  to prevent double-free on repeated adc_del_continuous_iir_filter
- adc_cali_line_fitting(esp32): fix config && config typo to
  config && ret_handle, preventing NULL-pointer dereference
2026-07-13 11:16:54 +08:00
morris 1fb5dafdad chore: remove unused idf_test component
The idf_test component was previously cleaned up but accidentally
reintroduced when adding esp32s31 support. It only contained an empty
header file (idf_performance_target.h) with no references anywhere
in the codebase.

Also removes the corresponding entry from astyle-rules.yml.
2026-07-13 10:12:13 +08:00
Hu Rui c629c200a9 fix(touch): fix hw_ver1 read data check
Closes https://github.com/espressif/esp-idf/issues/18811
2026-07-10 20:01:33 +08:00
Li Shuai a95e35309d fix(esp_hw_support): fix missing CPU retention register range macros for ESP32S31 2026-07-10 18:13:29 +08:00
morris 8a420be0c7 refactor(emac): move sleep retention config into driver layer
Keep the EMAC regdma retention definitions in esp_eth so the backup
layout stays aligned with driver-owned sleep retention behavior.
2026-07-10 16:03:08 +08:00
Mahavir Jain 41582e1777 Merge branch 'ci/fix_esp_tee_cli_app_build_v6.1' into 'release/v6.1'
ci(esp_tee): Fix `tee_cli_app` build failure due to heap size overflow (v6.1)

See merge request espressif/esp-idf!50613
2026-07-10 11:56:40 +05:30
wuzhenghui b388afd2f3 fix(esp_hw_support): update memory pointer checks for SPM support 2026-07-10 14:19:47 +08:00
Laukik Hase 87a5664883 ci(esp_tee): Fix tee_cli_app build failure due to heap size overflow
- Also fix the `unused variable` warning while builing the PSA
  AES tests with `tee_test_fw` app
2026-07-10 10:30:02 +05:30
Mahavir Jain 33217d154f Merge branch 'fix/esp_http_client_header_buffer_too_small_v6.1' into 'release/v6.1'
feat(esp_http_client): detect oversized headers in tx buffer at send site (v6.1)

See merge request espressif/esp-idf!50313
2026-07-10 09:41:40 +05:30
Mahavir Jain 5288101bdc Merge branch 'fix/harden_esp_security_v6.1' into 'release/v6.1'
fix(esp_security): harden crypto peripheral error handling (v6.1)

See merge request espressif/esp-idf!50324
2026-07-10 09:39:59 +05:30
Mahavir Jain f0fbd9d9fa Merge branch 'fix/tls1_3_dynamic_buffer_server_crash_v6.1' into 'release/v6.1'
fix(mbedtls): fixes TLS1.3 server failing with dynamic buffer (v6.1)

See merge request espressif/esp-idf!50386
2026-07-10 09:38:26 +05:30
David Cermak 0eafcb83e0 fix(lwip): tcp/ooseq: do not accept empty fin seg (+ other fixes)
* Update submodule: git log --oneline 9d2d8041..c6f2f878
  - test(lwip): add DHCP MTU validation unit test (espressif/esp-lwip@c6f2f878)
  - ppp: fix potential oob read in VJ decompression (espressif/esp-lwip@2ff439e6)
  - ip6-frag: Fix incorrect memcpy size to the actual struct (espressif/esp-lwip@91ad363b)
  - tcp/ooseq: do not accept empty fin seg (espressif/esp-lwip@fe4fb18c)
2026-07-09 16:04:37 +02:00
David Cermak 880b4cc2e9 fix(lwip): Adds nullchecks after DHCP server alloc'd pools 2026-07-09 16:04:37 +02:00
David Cermak d45d04dc43 fix(lwip): reject invalid DHCP MTU option values
Validate MTU from DHCP option 26 against RFC 2132 minimum (68 bytes)
before applying to netif->mtu, preventing rogue DHCP servers from
setting MTU to 0 or other dangerously low values that cause integer
wraparound in IPv4 fragmentation.
2026-07-09 16:04:37 +02:00
Hu Rui c73094392f fix(uhci): rx fsm race condition
Closes https://github.com/espressif/esp-idf/issues/18746
2026-07-09 18:55:12 +08:00
Jack 7ca1369ffc docs(esp_hw_support): fix IEEE 802.15.4 spelling and EUI-64 byte-range notation
Correct "802.154" to "802.15.4" and change the EUI-64 derivation notation
from base_mac[0:3]/base_mac[3:6] to the inclusive base_mac[0:2]/base_mac[3:5]
in the esp32h2/esp32h21/esp32h4 Kconfig.mac help text and the EN/zh_CN
misc_system_api docs.

Co-authored-by: Cursor <cursoragent@cursor.com>
(cherry picked from commit 811c64c17c)
2026-07-09 17:44:22 +08:00
Jack b5cd9ce7fa docs(esp_hw_support): document one-universal-MAC scheme and esp32s31 Four-option constraint
Add help text to the esp32h2/esp32h21/esp32h4 Kconfig.mac explaining
that these chips only consume one universally administered MAC address:
the IEEE 802.154 EUI-64 is derived from the base MAC and MAC_EXT, and
Bluetooth reuses the base MAC as-is (no BT offset, since there is no
Wi-Fi).

Add a matching 1-MAC derivation table and note to misc_system_api.rst
(EN and zh_CN) under a new `.. only:: esp32h2 or esp32h21 or esp32h4`
block, and exclude these targets from the generic 4/2 table.

Add an esp32s31-only note stating that the "Four" option may only be
used with a customer-provided custom base MAC range, since ESP32-S31
only provides two universally administered MAC addresses in eFuse.

Co-authored-by: Cursor <cursoragent@cursor.com>
(cherry picked from commit e3bc260178)
2026-07-09 17:44:22 +08:00