Route the ESP32_BT_* defaults through the generic BT_CTLR_* symbols
so a standard BT_CTLR_* toggle reaches the vendor knobs without
further user intervention. Select the matching BT_CTLR_*_SUPPORT
capabilities from BT_ESP32, and add Kconfig entries for the BLE 5.x
feature gates, controller power placement and light-sleep XTAL.
(cherry picked from commit a556fcac1a2df26d7964fd1a9e9776a49c76a6b4)
Signed-off-by: Sylvio Alves <sylvio.alves@espressif.com>
ext2_fetch_direntry() trusted the on-disk de_rec_len and de_name_len,
and the lookup and readdir paths advanced traversal by an unvalidated
de_rec_len. A crafted ext2 image could trigger an out-of-bounds read
past the directory block buffer or a zero-progress loop in any path
that walks a directory.
Validate rec_len and name_len in the parser, and reject entries whose
header does not fit in the remaining block or whose rec_len would
cross the block boundary in each caller.
Signed-off-by: Flavio Ceolin <flavio@hubblenetwork.com>
(cherry picked from commit 7cdb534a3c)
Disable all things pa11y due to CI issues that are taking too long to
fix :|
Signed-off-by: Benjamin Cabé <benjamin@zephyrproject.org>
(cherry picked from commit 63b5615160)
Register pm as a separate LOG module, in order to fix build
errors.
Signed-off-by: Raffael Rostagno <raffael.rostagno@espressif.com>
(cherry picked from commit 1664f43963)
The GPIO subsystem forwards GPIO_INT_WAKEUP from dt_flags into the trig
argument of pin_interrupt_configure(). Wakeup source configuration is
already handled in gpio_esp32_config(); strip the bit before passing trig
to convert_int_type() to avoid -EINVAL return.
Signed-off-by: Raffael Rostagno <raffael.rostagno@espressif.com>
(cherry picked from commit 2a0650072e)
ESP32 cache has no per-address invalidate primitive, so
cache_hal_invalidate_addr() aborts. Skip the flash IROM/DROM
invalidate step on ESP32 only.
Signed-off-by: Sylvio Alves <sylvio.alves@espressif.com>
(cherry picked from commit 75cb1c3364)
spi_mcux_init_common() can fail, propagate the error on TURN_ON
instead of silently ignoring it.
Signed-off-by: Sofian Elmotiem <sofianelmotiem@gmail.com>
(cherry picked from commit fddc5c2ce0)
For PM2 (suspend-to-idle), flexcomm registers are retained so a full
init_common is not needed. Instead, disable the I2C master before
applying the sleep pinctrl state on SUSPEND, and re-enable it after
restoring the default pinctrl state on RESUME.
Initialize the master with enableMaster = false in init_common so that
TURN_ON does not prematurely enable the master before RESUME restores
the pinctrl state. pm_device_driver_init always calls RESUME after
TURN_ON so the master is enabled correctly on both first boot and PM3
wakeup.
Signed-off-by: Sofian Elmotiem <sofianelmotiem@gmail.com>
(cherry picked from commit 81bc8fd62f)
The FLEXCAN_MbHandleIRQ function expects the last mailbox index as a
parameter, not the total number of mailboxes. Mailbox indices are
zero-based (0 to N-1), so passing the mailbox count directly causes
an off-by-one error that could lead to accessing an invalid mailbox
index during interrupt handling.
This fix changes the fourth parameter from `config->number_of_mb` to
`config->number_of_mb - 1U`, ensuring the correct last mailbox index
is passed to the IRQ handler.
The issue could manifest as incorrect interrupt handling or potential
memory access violations when processing CAN mailbox interrupts,
particularly when all available mailboxes are configured in classical
CAN.
Signed-off-by: William Tang <william.tang@nxp.com>
(cherry picked from commit fa50b30d10)
When sc=0, a framed ISO PDU segment header includes a 3-byte time_offset
field, so seg_hdr->len must be at least PDU_ISO_SEG_TIMEOFFSET_SIZE.
isoal_check_seg_header() accepted segments with sc=0 and len<3 as valid,
allowing isoal_rx_framed_consume() to underflow, causing an
out-of-bounds read of up to 255 bytes of adjacent memory into an HCI ISO
packet delivered to the host.
Signed-off-by: Flavio Ceolin <flavio@hubblenetwork.com>
(cherry picked from commit 28080d80fc)
Pull in additional MAXUSB fixes for checks of busy endpoints to work
properly for EP0 as well.
Signed-off-by: Pete Johanson <pete.johanson@analog.com>
(cherry picked from commit 30bef2a126)
Add missing null buffer checks in event callbacks for IN/OUT done handling,
various small fixes for halted state handling, remove some unnecessary
logging for expected failure modes, etc
Signed-off-by: Pete Johanson <pete.johanson@analog.com>
(cherry picked from commit a0d8f78655)
One of the flash tests assumes that *half* of the partition is
divisible by the erase block size.
This partition was set arbitrarily at 500KiB, so let's just
set it to 512KiB to avoid that test failing.
Signed-off-by: Alberto Escolar Piedras <alberto.escolar.piedras@nordicsemi.no>
(cherry picked from commit ce2fdbe434)
One of the flash tests assumes that *half* of the partition is
divisible by the erase block size.
This partition was set arbitrarily at 500KiB, so let's just
set it to 512KiB to avoid that test failing.
Signed-off-by: Alberto Escolar Piedras <alberto.escolar.piedras@nordicsemi.no>
(cherry picked from commit 6086d6ebfb)
Add call to 'net_if_mcast_monitor' to inform ENET layer to join or leave
a multicast group.
Signed-off-by: Cristian Bulacu <cristian.bulacu@nxp.com>
(cherry picked from commit 5287851640)
There are situations where internal DNS resolver will reject the packet,
and in this case, query index is not calculated.
This may break forwarding mechanism;
If DNS packet forwarding is enabled, and internal validation fails, some
checks are done and an attempt to calculate query index is performed, so
the packet can be forwarded and used.
Signed-off-by: Cristian Bulacu <cristian.bulacu@nxp.com>
(cherry picked from commit 217a5ac0ca)
Add a LONG(0) at a 16-byte aligned start of .flash.rodata_end so
the merged flash.rodata segment size never lands on a boundary
that trips esptool's --ram-only-header alignment assertion during
elf2image.
Applied to all espressif socs since the issue is not chip-specific.
Signed-off-by: Sylvio Alves <sylvio.alves@espressif.com>
(cherry picked from commit 55d2bc7702)
The limit check on mq_attr used && instead of ||, so a request
exceeding only one of CONFIG_MSG_SIZE_MAX or CONFIG_POSIX_MQ_OPEN_MAX
was accepted. The buffer was then allocated as
msg_size * max_msgs without overflow checking, allowing the
multiplication to wrap and produce an under-sized heap buffer
that a later mq_send() would overflow.
Reject when either limit is exceeded, and use size_mul_overflow()
before k_malloc().
Signed-off-by: Flavio Ceolin <flavio@hubblenetwork.com>
(cherry picked from commit 8a1fe0f6ad)
To build for the nrf5340bsim//cpunet with the IPC service, one
needs to build also with the cpuapp image.
Without it no workable final executable/image is produced.
Let's just platform_exclude it.
Signed-off-by: Alberto Escolar Piedras <alberto.escolar.piedras@nordicsemi.no>
(cherry picked from commit b5e39d57cd)
The LL_ADC_GetChannelSingleDiff function to know whether an ADC channel
is configured as differential or single-ended was not used correctly.
This lead to systematically disabling the ADC to reconfigure it, even if
the configuration was already the correct one.
Instead of returning the mode, LL_ADC_GetChannelSingleDiff returns the
channel if it is configured as differential, or 0 if it is single-ended.
Signed-off-by: Guillaume Gautier <guillaume.gautier-ext@st.com>
(cherry picked from commit 8c39353686)
Fix the test on the number of arguments in the erase command
to get the optional size argument that was mistakenly increased by
cb2382d25b ("drivers: flash: flash_shell.c: Requires device on
destructive ops") and made the argument never considered.
Signed-off-by: Etienne Carriere <etienne.carriere@st.com>
(cherry picked from commit aaf1c39145)
In case of using ethernet as backbone interface, some NICs may want to
have checksum set to 0 for a correct computation.
This commit aims to address this issue by checking if hardware has
offload capabilities and setting IPV6 packet checksums to 0, if needed.
Signed-off-by: Cristian Bulacu <cristian.bulacu@nxp.com>
(cherry picked from commit 553e505e6b)
mbedtls_ssl_get_peer_cid() always writes MBEDTLS_SSL_CID_OUT_LEN_MAX
bytes into the destination buffer regardless of the actual CID length.
tls_opt_dtls_peer_connection_id_value_get() passed the caller-supplied
optval directly without checking it was large enough, allowing an OOB
write of up to 31 bytes past the buffer end.
Signed-off-by: Flavio Ceolin <flavio@hubblenetwork.com>
(cherry picked from commit aa317825a5)
Set MPU attribute to mark the region as Normal memory
Signed-off-by: Yassine El Aissaoui <yassine.elaissaoui@nxp.com>
(cherry picked from commit c1f002c450)
This panel appears to require horizontal mirroring and pixel format
change according to testing by the community.
https://github.com/zephyrproject-rtos/zephyr/pull/106862#
issuecomment-4335491195
Signed-off-by: Abderrahmane JARMOUNI <git@jarmouni.me>
Signed-off-by: Benjamin Cabé <benjamin@zephyrproject.org>
(cherry picked from commit 96929ff729)
After rewroking ili9xxx driver orientation logic, this panel appears to
require vertical mirroring according to testing by the community.
https://github.com/zephyrproject-rtos/zephyr/pull/106862#
issuecomment-4189488230
Signed-off-by: Abderrahmane JARMOUNI <git@jarmouni.me>
Signed-off-by: Eve Redero <eve.redero@gmail.com>
(cherry picked from commit 12ac8102bd)
All supported controllers (ILI9340/9341/9342C/9163C/9488) use
identical MADCTL register bit definitions. Hence the current separate
command sets CMD_SET_1/CMD_SET_2 is unnecessary. Remove it and
implement a single, datasheet-compliant orientation mapping for all
ILI9xxx controllers.
Replace rotation logic with the universal datasheet mappings:
- 0°: 0x00
- 90°: MV + MX
- 180°: MX + MY
- 270°: MV + MY
Add devicetree properties for panel-specific corrections:
- h-mirror/v-mirror: for mirroring variations
- bottom-top-refresh/right-left-refresh: for non-standard scan
directions
Fixes https://github.com/zephyrproject-rtos/zephyr/issues/105521 and
https://github.com/zephyrproject-rtos/zephyr/issues/106489
Signed-off-by: Abderrahmane JARMOUNI <git@jarmouni.me>
(cherry picked from commit baf3fe29f5)
Rename inversion config to bit_inversion for clarity as it concerns
memory values inversion.
Signed-off-by: Abderrahmane JARMOUNI <git@jarmouni.me>
(cherry picked from commit fc09a575ba)
If the (addr + size) overflows the memory address space,
the inner loop may not run to check for permission. Since
the default return value was 0 (meaning permitted), it
would incorrectly say memory access was okay. Fix this by
changing the default return value to -EINVAL. Only after
the loop of validating the whole input address range then
we set the return value to 0 to say memory access is
permitted. Also check for addition overflow.
Signed-off-by: Daniel Leung <daniel.leung@intel.com>
(cherry picked from commit 3b1bdaf548)
When FLASH_USES_MAPPED_PARTITION is enabled, Kconfig skips
FLASH_LOAD_OFFSET and FLASH_LOAD_SIZE. However, the linker scripts
only used the DT-based ROM_ADDR/ROM_SIZE path when both
FLASH_USES_MAPPED_PARTITION and CONFIG_XIP were set. For non-XIP
modes (e.g. MCUboot ram_load), the code fell through to the else
branch relying on the missing configs, causing ROM_SIZE to underflow
to 0xFFFFFFFFFFFFFFFF and a linker overflow error.
Fix by checking only FLASH_USES_MAPPED_PARTITION for ROM_SIZE, and
handling ROM_ADDR separately for XIP (DT address) vs non-XIP
(RAM_ADDR).
Signed-off-by: Albort Xue <yao.xue@nxp.com>
(cherry picked from commit 1cf0cc2a5c)
Same issue as the GPIO driver: esp32_pin_is_valid() and
esp32_pin_is_output_capable() use BIT() which overflows on 32-bit
Xtensa for pin numbers >= 32.
Fix by using BIT64() to match the 64-bit SOC_GPIO_VALID_GPIO_MASK.
Signed-off-by: Matin Lotfaliei <matinlotfali@gmail.com>
(cherry picked from commit d53115be07)
gpio_pin_is_valid() and gpio_pin_is_output_capable() use BIT() which
expands to (1UL << n). On 32-bit Xtensa targets, unsigned long is
32 bits, so BIT(n) for n >= 32 is undefined behavior.
This causes gpio1 pins (GPIO32+) to always fail validation with
-EINVAL, breaking any peripheral connected to GPIO32-GPIO48 on
ESP32-S3 (and similar ESP32 variants with gpio1).
Fix by using BIT64() which correctly handles pin numbers >= 32
since SOC_GPIO_VALID_GPIO_MASK is already a 64-bit value.
Signed-off-by: Matin Lotfaliei <matinlotfali@gmail.com>
(cherry picked from commit 68398e706b)
Insert an explicit `. = ALIGN(0x10)` at the end of the flash
text region in every Espressif SoC linker script. The flash MMU
maps code in fixed-size segments and image headers record each
segment with a 16-byte-multiple length, so the boundary between
the text region and whatever follows must land on a clean 16-byte
address. Relying on the preceding `. += 16` padding or `ALIGN(4)`
only guaranteed 4-byte alignment, which left the segment size
off-grid on builds where prior input sections happened to end at
an unaligned offset.
Signed-off-by: Sylvio Alves <sylvio.alves@espressif.com>
(cherry picked from commit a5f6efb682)
Set DROM_SEG_ORG equal to IROM_SEG_ORG and add a NOLOAD dummy
section in drom0_0_seg that advances past the end of .text.
The MMU allocator advances free_head by irom_len + drom_len
assuming the two segments are adjacent. The previous 8MB gap
left the rodata virtual range unreserved, causing 8MB PSRAM
mapping to overrun .rodata.
Place the esp_psram object in IRAM so PSRAM init does not
depend on flash reads while MSPI clock and tuning registers
are transitioning. Split esp_init_psram into chip-init plus
mmu-map steps and invalidate the flash IROM/DROM ranges in
between so the next flash fetch reloads with the final MSPI
settings.
Signed-off-by: Sylvio Alves <sylvio.alves@espressif.com>
(cherry picked from commit d46d6be856)
ffa_create_top() was opening files with FS_O_CREATE | FS_O_WRITE
only, which caused host applications like 'cat' to fail with
Permission denied when trying to read the file through FUSE. This
is because FAT filesystem explicitly checks the READ flag before
allowing read access.
Fix by replacing FS_O_WRITE with FS_O_RDWR so the file is opened
with both read and write access.
Signed-off-by: Surya Prakash T <suryat@aerlync.com>
(cherry picked from commit 8f959ad0e6)
Add IEEE802154_CONFIG_CSMA_CA_BACKOFFS configuration handling in
the ieee802154 driver.
Signed-off-by: Vincent Tardy <vincent.tardy@st.com>
(cherry picked from commit 22436297bd)
Copy the information filled in the Tx packet by the link layer
during IEEE 802.15.4 transmission before exiting the
stm32wba_802154_tx() function.
Drop the packet from the Tx_done callback issued by the
link layer after a radio reset.
Signed-off-by: Vincent Tardy <vincent.tardy@st.com>
(cherry picked from commit 4c4385cfa2)
Add a guard for `eth_esp32_iomux_rmii_clk_input` function to fix the
following error:
error: 'eth_esp32_iomux_rmii_clk_input' defined but not used
[-Werror=unused-function] 245 | static void
eth_esp32_iomux_rmii_clk_input(void)
Signed-off-by: Bartosz Bilas <bartosz.bilas@hotmail.com>
(cherry picked from commit 22ebd56407)
Both GPIO and RTC IO pad types support pad hold function.
Current implementation is only covering digital GPIOs. If the user
selects an RTC IO pin with `sleep-hold-en`, an `abort()` inside the
HAL can happen, depending on the SoC. Extend the implementation to
handle RTC IO pads through the correct hold path and add proper
validation with a warning for pads that support neither hold type.
Signed-off-by: Raffael Rostagno <raffael.rostagno@espressif.com>
(cherry picked from commit d03a7b150a)
Reject malformed nrf_wifi_umac_event_power_save_info payloads before
copying TWT entries into struct wifi_ps_config. The handler previously
trusted num_twt_flows and indexed twt_flow_info[] without checking
WIFI_MAX_TWT_FLOWS or event_len, which could overflow the fixed Zephyr
twt_flows buffer and read past the event buffer.
Fix issue #108848.
Signed-off-by: Chaitanya Tata <Chaitanya.Tata@nordicsemi.no>
Assisted-by: Cursor:Auto
(cherry picked from commit a2c4324acd)
Include guard was missing in lwm2m_pull_context.h internal header.
Signed-off-by: Robert Lubos <robert.lubos@nordicsemi.no>
(cherry picked from commit 55be451592)
Use the same size for the URI buffer in the FW object implementation as
in the FW pull download helper module. That way, if the server writes
too long URI to handle in the FW pull mode, it'll get an error response
immediately instead of failing at firmware download start.
Signed-off-by: Robert Lubos <robert.lubos@nordicsemi.no>
(cherry picked from commit b96deb12ad)
Verify the URI length provided to lwm2m_pull_context_start_transfer()
before use, otherwise in case the URI string is longer than the buffer,
only part of it was copied w/o NULL terminator, which could lead to
out-of-bound reads and other undefined behavior.
As the string length is now validated, just use strcpy() instead of
memcpy(), no need to copy the whole buffer.
Signed-off-by: Robert Lubos <robert.lubos@nordicsemi.no>
(cherry picked from commit 99a164df5c)
Run address sanitizer to catch any undefined behavior issues
in the code.
Signed-off-by: Jukka Rissanen <jukka.rissanen@nordicsemi.no>
(cherry picked from commit d5ced71a8c)
Use memcmp() to compare values instead of direct comparison.
Without this, some of the tests were failing because this
comparison "" != "" was true when ASAN was enabled.
Signed-off-by: Jukka Rissanen <jukka.rissanen@nordicsemi.no>
(cherry picked from commit 007a274258)
The test code accessed buffer outside of limits. Fix it by
setting the string length properly in the test.
Signed-off-by: Jukka Rissanen <jukka.rissanen@nordicsemi.no>
(cherry picked from commit 2df51049e4)
Make sure that IPv6 address parsing works as expected.
Assisted-by: Claude:claude-sonnet-4.6
Signed-off-by: Jukka Rissanen <jukka.rissanen@nordicsemi.no>
(cherry picked from commit 1c79d0c467)
Make sure we will not overflow the ipaddress buffer if
port number is given.
Signed-off-by: Jukka Rissanen <jukka.rissanen@nordicsemi.no>
(cherry picked from commit 6e119a636a)