Commit graph

136,983 commits

Author SHA1 Message Date
Maureen Helm
2da2114960 release: Zephyr 4.4.1-rc1 v4.4.1-rc1
Set version to v4.4.1-rc1.

Signed-off-by: Maureen Helm <maureen.helm@analog.com>
2026-06-03 10:39:23 -05:00
Sylvio Alves
7f01467238 drivers: bluetooth: esp32: align controller knobs with zephyr
Route the ESP32_BT_* defaults through the generic BT_CTLR_* symbols
so a standard BT_CTLR_* toggle reaches the vendor knobs without
further user intervention. Select the matching BT_CTLR_*_SUPPORT
capabilities from BT_ESP32, and add Kconfig entries for the BLE 5.x
feature gates, controller power placement and light-sleep XTAL.

(cherry picked from commit a556fcac1a2df26d7964fd1a9e9776a49c76a6b4)
Signed-off-by: Sylvio Alves <sylvio.alves@espressif.com>
2026-06-03 08:27:25 -05:00
Flavio Ceolin
afe7a4e631 fs: ext2: validate directory entry structure before traversal
ext2_fetch_direntry() trusted the on-disk de_rec_len and de_name_len,
and the lookup and readdir paths advanced traversal by an unvalidated
de_rec_len. A crafted ext2 image could trigger an out-of-bounds read
past the directory block buffer or a zero-progress loop in any path
that walks a directory.

Validate rec_len and name_len in the parser, and reject entries whose
header does not fit in the remaining block or whose rec_len would
cross the block boundary in each caller.

Signed-off-by: Flavio Ceolin <flavio@hubblenetwork.com>
(cherry picked from commit 7cdb534a3c)
2026-06-03 08:27:04 -05:00
Benjamin Cabé
43df11979d ci: workflows: doc-build: disable pa11y check temporarily
Disable all things pa11y due to CI issues that are taking too long to
fix :|

Signed-off-by: Benjamin Cabé <benjamin@zephyrproject.org>
(cherry picked from commit 63b5615160)
2026-06-02 17:14:17 -05:00
Raffael Rostagno
2415a76857 soc: esp32: pm: Register module LOG
Register pm as a separate LOG module, in order to fix build
errors.

Signed-off-by: Raffael Rostagno <raffael.rostagno@espressif.com>
(cherry picked from commit 1664f43963)
2026-06-02 17:14:06 -05:00
Raffael Rostagno
f5e2028502 drivers: gpio: esp32: Handle GPIO_INT_WAKEUP in pin_interrupt_configure
The GPIO subsystem forwards GPIO_INT_WAKEUP from dt_flags into the trig
argument of pin_interrupt_configure(). Wakeup source configuration is
already handled in gpio_esp32_config(); strip the bit before passing trig
to convert_int_type() to avoid -EINVAL return.

Signed-off-by: Raffael Rostagno <raffael.rostagno@espressif.com>
(cherry picked from commit 2a0650072e)
2026-06-02 09:15:38 -05:00
Sylvio Alves
04901fbbf6 soc: espressif: fix psram cache invalidate abort on esp32
ESP32 cache has no per-address invalidate primitive, so
cache_hal_invalidate_addr() aborts. Skip the flash IROM/DROM
invalidate step on ESP32 only.

Signed-off-by: Sylvio Alves <sylvio.alves@espressif.com>
(cherry picked from commit 75cb1c3364)
2026-06-02 09:14:35 -05:00
Sofian Elmotiem
5587ffc56e drivers: spi: mcux_flexcomm: check return value of init_common
spi_mcux_init_common() can fail, propagate the error on TURN_ON
instead of silently ignoring it.

Signed-off-by: Sofian Elmotiem <sofianelmotiem@gmail.com>
(cherry picked from commit fddc5c2ce0)
2026-06-02 09:13:34 -05:00
Sofian Elmotiem
79d1c1f1c2 drivers: i2c: mcux_flexcomm: use I2C_MasterEnable on PM RESUME/SUSPEND
For PM2 (suspend-to-idle), flexcomm registers are retained so a full
init_common is not needed. Instead, disable the I2C master before
applying the sleep pinctrl state on SUSPEND, and re-enable it after
restoring the default pinctrl state on RESUME.

Initialize the master with enableMaster = false in init_common so that
TURN_ON does not prematurely enable the master before RESUME restores
the pinctrl state. pm_device_driver_init always calls RESUME after
TURN_ON so the master is enabled correctly on both first boot and PM3
wakeup.

Signed-off-by: Sofian Elmotiem <sofianelmotiem@gmail.com>
(cherry picked from commit 81bc8fd62f)
2026-06-02 09:13:34 -05:00
William Tang
0b669d715b drivers: can: mcux: flexcan: Fix off-by-one error in MB IRQ handling
The FLEXCAN_MbHandleIRQ function expects the last mailbox index as a
parameter, not the total number of mailboxes. Mailbox indices are
zero-based (0 to N-1), so passing the mailbox count directly causes
an off-by-one error that could lead to accessing an invalid mailbox
index during interrupt handling.

This fix changes the fourth parameter from `config->number_of_mb` to
`config->number_of_mb - 1U`, ensuring the correct last mailbox index
is passed to the IRQ handler.

The issue could manifest as incorrect interrupt handling or potential
memory access violations when processing CAN mailbox interrupts,
particularly when all available mailboxes are configured in classical
CAN.

Signed-off-by: William Tang <william.tang@nxp.com>
(cherry picked from commit fa50b30d10)
2026-05-29 15:38:36 -05:00
Flavio Ceolin
68553e1d46 Bluetooth: Controller: Fix OOB read in ISOAL
When sc=0, a framed ISO PDU segment header includes a 3-byte time_offset
field, so seg_hdr->len must be at least PDU_ISO_SEG_TIMEOFFSET_SIZE.
isoal_check_seg_header() accepted segments with sc=0 and len<3 as valid,
allowing isoal_rx_framed_consume() to underflow, causing an
out-of-bounds read of up to 255 bytes of adjacent memory into an HCI ISO
packet delivered to the host.

Signed-off-by: Flavio Ceolin <flavio@hubblenetwork.com>
(cherry picked from commit 28080d80fc)
2026-05-29 15:38:05 -05:00
Pete Johanson
5f4d4598ab manifest: hal_adi: Pull in additional EP0 fixes
Pull in additional MAXUSB fixes for checks of busy endpoints to work
properly for EP0 as well.

Signed-off-by: Pete Johanson <pete.johanson@analog.com>
(cherry picked from commit 30bef2a126)
2026-05-29 15:37:22 -05:00
Pete Johanson
c5df48ea08 drivers: usb: udc: Buffer null checks, EP0 OUT handling, etc
Add missing null buffer checks in event callbacks for IN/OUT done handling,
various small fixes for halted state handling, remove some unnecessary
logging for expected failure modes, etc

Signed-off-by: Pete Johanson <pete.johanson@analog.com>
(cherry picked from commit a0d8f78655)
2026-05-29 15:37:22 -05:00
Alberto Escolar Piedras
16fb5b81da boards nrf54lm20bsim: Change storage partition size to 512KiB
One of the flash tests assumes that *half* of the partition is
divisible by the erase block size.
This partition was set arbitrarily at 500KiB, so let's just
set it to 512KiB to avoid that test failing.

Signed-off-by: Alberto Escolar Piedras <alberto.escolar.piedras@nordicsemi.no>
(cherry picked from commit ce2fdbe434)
2026-05-29 15:36:36 -05:00
Alberto Escolar Piedras
695273aa42 boards nrf54l15bsim: Change storage partition size to 512KiB
One of the flash tests assumes that *half* of the partition is
divisible by the erase block size.
This partition was set arbitrarily at 500KiB, so let's just
set it to 512KiB to avoid that test failing.

Signed-off-by: Alberto Escolar Piedras <alberto.escolar.piedras@nordicsemi.no>
(cherry picked from commit 6086d6ebfb)
2026-05-29 15:36:36 -05:00
Joakim Tjernlund
1d16e52813 arm64: mmu: Address clang -Wunused-function warnings
These warnings are fixed:

mmu.c:101:20: warning: unused function 'inc_table_ref' [-Wunused-function]

mmu.c:118:20: warning: unused function 'is_table_single_referenced'
[-Wunused-function]

mmu.c:157:20: warning: unused function 'is_inval_desc' [-Wunused-function]

mmu.c:809:20: warning: unused function 'invalidate_tlb_page'
[-Wunused-function]

Signed-off-by: Joakim Tjernlund <joakim.tjernlund@nokia.com>
(cherry picked from commit 9447b2b7b6)
2026-05-29 15:36:19 -05:00
Cristian Bulacu
5ff95467a4 net: openthread: border_router: Fix multicast forwarding on ethernet
Add call to 'net_if_mcast_monitor' to inform ENET layer to join or leave
a multicast group.

Signed-off-by: Cristian Bulacu <cristian.bulacu@nxp.com>
(cherry picked from commit 5287851640)
2026-05-27 10:33:22 -05:00
Cristian Bulacu
07d42c9f48 net: dns: Enhance DNS packet forwarding mechanism
There are situations where internal DNS resolver will reject the packet,
and in this case, query index is not calculated.
This may break forwarding mechanism;
If DNS packet forwarding is enabled, and internal validation fails, some
checks are done and an attempt to calculate query index is performed, so
the packet can be forwarded and used.

Signed-off-by: Cristian Bulacu <cristian.bulacu@nxp.com>
(cherry picked from commit 217a5ac0ca)
2026-05-27 10:32:49 -05:00
Sylvio Alves
f19cec9da8 soc: espressif: update flash.rodata segment alignment
Add a LONG(0) at a 16-byte aligned start of .flash.rodata_end so
the merged flash.rodata segment size never lands on a boundary
that trips esptool's --ram-only-header alignment assertion during
elf2image.

Applied to all espressif socs since the issue is not chip-specific.

Signed-off-by: Sylvio Alves <sylvio.alves@espressif.com>
(cherry picked from commit 55d2bc7702)
2026-05-27 10:32:20 -05:00
Flavio Ceolin
f0b6738bae posix: mqueue: fix integer overflow in mq_open() buffer allocation
The limit check on mq_attr used && instead of ||, so a request
exceeding only one of CONFIG_MSG_SIZE_MAX or CONFIG_POSIX_MQ_OPEN_MAX
was accepted. The buffer was then allocated as
msg_size * max_msgs without overflow checking, allowing the
multiplication to wrap and produce an under-sized heap buffer
that a later mq_send() would overflow.

Reject when either limit is exceeded, and use size_mul_overflow()
before k_malloc().

Signed-off-by: Flavio Ceolin <flavio@hubblenetwork.com>
(cherry picked from commit 8a1fe0f6ad)
2026-05-27 10:31:48 -05:00
Alberto Escolar Piedras
d5aef8a98b tests zbus proxy_agent ipc_backend: Exclude nrf5340bsim//cpunet
To build for the nrf5340bsim//cpunet with the IPC service, one
needs to  build also with the cpuapp image.
Without it no workable final executable/image is produced.

Let's just platform_exclude it.

Signed-off-by: Alberto Escolar Piedras <alberto.escolar.piedras@nordicsemi.no>
(cherry picked from commit b5e39d57cd)
2026-05-27 10:31:19 -05:00
Guillaume Gautier
1d14cccce7 drivers: adc: stm32: fix get channel differential
The LL_ADC_GetChannelSingleDiff function to know whether an ADC channel
is configured as differential or single-ended was not used correctly.
This lead to systematically disabling the ADC to reconfigure it, even if
the configuration was already the correct one.

Instead of returning the mode, LL_ADC_GetChannelSingleDiff returns the
channel if it is configured as differential, or 0 if it is single-ended.

Signed-off-by: Guillaume Gautier <guillaume.gautier-ext@st.com>
(cherry picked from commit 8c39353686)
2026-05-27 10:30:30 -05:00
Etienne Carriere
f6f7e4d496 drivers: flash: flash_shell.c: fix size argument on erase command
Fix the test on the number of arguments in the erase command
to get the optional size argument that was mistakenly increased by
cb2382d25b ("drivers: flash: flash_shell.c: Requires device on
destructive ops") and made the argument never considered.

Signed-off-by: Etienne Carriere <etienne.carriere@st.com>
(cherry picked from commit aaf1c39145)
2026-05-27 10:30:08 -05:00
Cristian Bulacu
4e92540565 openthread: border_router: Remove IPV6 packet checksum when forwarding
In case of using ethernet as backbone interface, some NICs may want to
have checksum set to 0 for a correct computation.
This commit aims to address this issue by checking if hardware has
offload capabilities and setting IPV6 packet checksums to 0, if needed.

Signed-off-by: Cristian Bulacu <cristian.bulacu@nxp.com>
(cherry picked from commit 553e505e6b)
2026-05-27 10:29:42 -05:00
Flavio Ceolin
647e9e3ae1 net: sockets/tls: valide buffer in peer_connection_id_value_get
mbedtls_ssl_get_peer_cid() always writes MBEDTLS_SSL_CID_OUT_LEN_MAX
bytes into the destination buffer regardless of the actual CID length.
tls_opt_dtls_peer_connection_id_value_get() passed the caller-supplied
optval directly without checking it was large enough, allowing an OOB
write of up to 31 bytes past the buffer end.

Signed-off-by: Flavio Ceolin <flavio@hubblenetwork.com>
(cherry picked from commit aa317825a5)
2026-05-26 16:16:23 -05:00
Yassine El Aissaoui
65ab922eda dts: nxp: mcxw23: Fix faults caused by unaligned access on shared memory
Set MPU attribute to mark the region as Normal memory

Signed-off-by: Yassine El Aissaoui <yassine.elaissaoui@nxp.com>
(cherry picked from commit c1f002c450)
2026-05-26 16:15:37 -05:00
Abderrahmane JARMOUNI
faca839bb9 boards: wio_terminal: fix display mirroring & color
This panel appears to require horizontal mirroring and pixel format
change according to testing by the community.
https://github.com/zephyrproject-rtos/zephyr/pull/106862#
issuecomment-4335491195

Signed-off-by: Abderrahmane JARMOUNI <git@jarmouni.me>
Signed-off-by: Benjamin Cabé <benjamin@zephyrproject.org>
(cherry picked from commit 96929ff729)
2026-05-26 16:15:03 -05:00
Abderrahmane JARMOUNI
a3ff7d9af5 boards: st: st25dv_mb1283_disco: fix display vertical mirroring
After rewroking ili9xxx driver orientation logic, this panel appears to
require vertical mirroring according to testing by the community.
https://github.com/zephyrproject-rtos/zephyr/pull/106862#
issuecomment-4189488230

Signed-off-by: Abderrahmane JARMOUNI <git@jarmouni.me>
Signed-off-by: Eve Redero <eve.redero@gmail.com>
(cherry picked from commit 12ac8102bd)
2026-05-26 16:15:03 -05:00
Abderrahmane JARMOUNI
67a5419c01 drivers: display: ili9xxx: fix orientation logic
All supported controllers (ILI9340/9341/9342C/9163C/9488) use
identical MADCTL register bit definitions. Hence the current separate
command sets CMD_SET_1/CMD_SET_2 is unnecessary. Remove it and
implement a single, datasheet-compliant orientation mapping for all
ILI9xxx controllers.

Replace rotation logic with the universal datasheet mappings:
  - 0°:   0x00
  - 90°:  MV + MX
  - 180°: MX + MY
  - 270°: MV + MY

Add devicetree properties for panel-specific corrections:
  - h-mirror/v-mirror: for mirroring variations
  - bottom-top-refresh/right-left-refresh: for non-standard scan
  directions

Fixes https://github.com/zephyrproject-rtos/zephyr/issues/105521 and
https://github.com/zephyrproject-rtos/zephyr/issues/106489

Signed-off-by: Abderrahmane JARMOUNI <git@jarmouni.me>
(cherry picked from commit baf3fe29f5)
2026-05-26 16:15:03 -05:00
Abderrahmane JARMOUNI
0d3c28bc01 drivers: display: ili9xxx: rename inversion config
Rename inversion config to bit_inversion for clarity as it concerns
memory values inversion.

Signed-off-by: Abderrahmane JARMOUNI <git@jarmouni.me>
(cherry picked from commit fc09a575ba)
2026-05-26 16:15:03 -05:00
Daniel Leung
af452e0108 xtensa: mpu: fix arch_buffer_validate() if overflow
If the (addr + size) overflows the memory address space,
the inner loop may not run to check for permission. Since
the default return value was 0 (meaning permitted), it
would incorrectly say memory access was okay. Fix this by
changing the default return value to -EINVAL. Only after
the loop of validating the whole input address range then
we set the return value to 0 to say memory access is
permitted. Also check for addition overflow.

Signed-off-by: Daniel Leung <daniel.leung@intel.com>
(cherry picked from commit 3b1bdaf548)
2026-05-26 16:14:46 -05:00
Albort Xue
42dfc7204b linker: fix mapped-partition ROM_SIZE for non-XIP boot modes
When FLASH_USES_MAPPED_PARTITION is enabled, Kconfig skips
FLASH_LOAD_OFFSET and FLASH_LOAD_SIZE. However, the linker scripts
only used the DT-based ROM_ADDR/ROM_SIZE path when both
FLASH_USES_MAPPED_PARTITION and CONFIG_XIP were set. For non-XIP
modes (e.g. MCUboot ram_load), the code fell through to the else
branch relying on the missing configs, causing ROM_SIZE to underflow
to 0xFFFFFFFFFFFFFFFF and a linker overflow error.

Fix by checking only FLASH_USES_MAPPED_PARTITION for ROM_SIZE, and
handling ROM_ADDR separately for XIP (DT address) vs non-XIP
(RAM_ADDR).

Signed-off-by: Albort Xue <yao.xue@nxp.com>
(cherry picked from commit 1cf0cc2a5c)
2026-05-26 16:14:02 -05:00
Matin Lotfaliei
26306789f1 drivers: pinctrl: esp32: fix BIT overflow for pins >= 32
Same issue as the GPIO driver: esp32_pin_is_valid() and
esp32_pin_is_output_capable() use BIT() which overflows on 32-bit
Xtensa for pin numbers >= 32.

Fix by using BIT64() to match the 64-bit SOC_GPIO_VALID_GPIO_MASK.

Signed-off-by: Matin Lotfaliei <matinlotfali@gmail.com>
(cherry picked from commit d53115be07)
2026-05-26 16:13:23 -05:00
Matin Lotfaliei
dec2168f04 drivers: gpio: esp32: fix BIT overflow for pins >= 32
gpio_pin_is_valid() and gpio_pin_is_output_capable() use BIT() which
expands to (1UL << n). On 32-bit Xtensa targets, unsigned long is
32 bits, so BIT(n) for n >= 32 is undefined behavior.

This causes gpio1 pins (GPIO32+) to always fail validation with
-EINVAL, breaking any peripheral connected to GPIO32-GPIO48 on
ESP32-S3 (and similar ESP32 variants with gpio1).

Fix by using BIT64() which correctly handles pin numbers >= 32
since SOC_GPIO_VALID_GPIO_MASK is already a 64-bit value.

Signed-off-by: Matin Lotfaliei <matinlotfali@gmail.com>
(cherry picked from commit 68398e706b)
2026-05-26 16:13:23 -05:00
Sylvio Alves
9ddeaf1bf7 soc: espressif: align flash text end to 16-byte boundary
Insert an explicit `. = ALIGN(0x10)` at the end of the flash
text region in every Espressif SoC linker script. The flash MMU
maps code in fixed-size segments and image headers record each
segment with a 16-byte-multiple length, so the boundary between
the text region and whatever follows must land on a clean 16-byte
address. Relying on the preceding `. += 16` padding or `ALIGN(4)`
only guaranteed 4-byte alignment, which left the segment size
off-grid on builds where prior input sections happened to end at
an unaligned offset.

Signed-off-by: Sylvio Alves <sylvio.alves@espressif.com>
(cherry picked from commit a5f6efb682)
2026-05-21 12:08:58 -05:00
Sylvio Alves
5d48749ccb soc: esp32c5: place drom adjacent to irom in linear space
Set DROM_SEG_ORG equal to IROM_SEG_ORG and add a NOLOAD dummy
section in drom0_0_seg that advances past the end of .text.
The MMU allocator advances free_head by irom_len + drom_len
assuming the two segments are adjacent. The previous 8MB gap
left the rodata virtual range unreserved, causing 8MB PSRAM
mapping to overrun .rodata.

Place the esp_psram object in IRAM so PSRAM init does not
depend on flash reads while MSPI clock and tuning registers
are transitioning. Split esp_init_psram into chip-init plus
mmu-map steps and invalidate the flash IROM/DROM ranges in
between so the next flash fetch reloads with the final MSPI
settings.

Signed-off-by: Sylvio Alves <sylvio.alves@espressif.com>
(cherry picked from commit d46d6be856)
2026-05-21 12:08:58 -05:00
Surya Prakash T
be7956ac74 fs: fix FUSE open permissions and validate flags
ffa_create_top() was opening files with FS_O_CREATE | FS_O_WRITE
only, which caused host applications like 'cat' to fail with
Permission denied when trying to read the file through FUSE. This
is because FAT filesystem explicitly checks the READ flag before
allowing read access.

Fix by replacing FS_O_WRITE with FS_O_RDWR so the file is opened
with both read and write access.

Signed-off-by: Surya Prakash T <suryat@aerlync.com>
(cherry picked from commit 8f959ad0e6)
2026-05-21 12:07:49 -05:00
Vincent Tardy
f379b64dad drivers: ieee802154: stm32wba: Add CSMA_CA backoffs config request
Add IEEE802154_CONFIG_CSMA_CA_BACKOFFS configuration handling in
the ieee802154 driver.

Signed-off-by: Vincent Tardy <vincent.tardy@st.com>
(cherry picked from commit 22436297bd)
2026-05-21 12:07:12 -05:00
Vincent Tardy
b498db95c1 drivers: ieee802154: stm32wba: fix tx packet handling issues
Copy the information filled in the Tx packet by the link layer
during IEEE 802.15.4 transmission before exiting the
stm32wba_802154_tx() function.
Drop the packet from the Tx_done callback issued by the
link layer after a radio reset.

Signed-off-by: Vincent Tardy <vincent.tardy@st.com>
(cherry picked from commit 4c4385cfa2)
2026-05-21 12:07:12 -05:00
Bartosz Bilas
ac8c49db9e drivers: ethernet: esp32: guard eth_esp32_iomux_rmii_clk_input
Add a guard for `eth_esp32_iomux_rmii_clk_input` function to fix the
following error:

error: 'eth_esp32_iomux_rmii_clk_input' defined but not used
[-Werror=unused-function] 245 | static void
eth_esp32_iomux_rmii_clk_input(void)

Signed-off-by: Bartosz Bilas <bartosz.bilas@hotmail.com>
(cherry picked from commit 22ebd56407)
2026-05-21 12:06:20 -05:00
Raffael Rostagno
78945243f4 pm: esp32: Fix support to pad hold function
Both GPIO and RTC IO pad types support pad hold function.
Current implementation is only covering digital GPIOs. If the user
selects an RTC IO pin with `sleep-hold-en`, an `abort()` inside the
HAL can happen, depending on the SoC. Extend the implementation to
handle RTC IO pads through the correct hold path and add proper
validation with a warning for pads that support neither hold type.

Signed-off-by: Raffael Rostagno <raffael.rostagno@espressif.com>
(cherry picked from commit d03a7b150a)
2026-05-21 12:05:09 -05:00
Chaitanya Tata
c4475941c2 drivers: wifi: nrf_wifi: Validate PS event TWT flow count and length
Reject malformed nrf_wifi_umac_event_power_save_info payloads before
copying TWT entries into struct wifi_ps_config. The handler previously
trusted num_twt_flows and indexed twt_flow_info[] without checking
WIFI_MAX_TWT_FLOWS or event_len, which could overflow the fixed Zephyr
twt_flows buffer and read past the event buffer.

Fix issue #108848.

Signed-off-by: Chaitanya Tata <Chaitanya.Tata@nordicsemi.no>
Assisted-by: Cursor:Auto
(cherry picked from commit a2c4324acd)
2026-05-21 12:04:19 -05:00
Robert Lubos
1c6f909157 net: lwm2m: Add include guard in lwm2m_pull_context.h
Include guard was missing in lwm2m_pull_context.h internal header.

Signed-off-by: Robert Lubos <robert.lubos@nordicsemi.no>
(cherry picked from commit 55be451592)
2026-05-19 15:14:00 -05:00
Robert Lubos
519e176ce4 net: lwm2m: Align URI size in FW object with FW pull helper
Use the same size for the URI buffer in the FW object implementation as
in the FW pull download helper module. That way, if the server writes
too long URI to handle in the FW pull mode, it'll get an error response
immediately instead of failing at firmware download start.

Signed-off-by: Robert Lubos <robert.lubos@nordicsemi.no>
(cherry picked from commit b96deb12ad)
2026-05-19 15:14:00 -05:00
Robert Lubos
f6b65b95b5 net: lwm2m: Verify URI string length before use in FW pull mode
Verify the URI length provided to lwm2m_pull_context_start_transfer()
before use, otherwise in case the URI string is longer than the buffer,
only part of it was copied w/o NULL terminator, which could lead to
out-of-bound reads and other undefined behavior.

As the string length is now validated, just use strcpy() instead of
memcpy(), no need to copy the whole buffer.

Signed-off-by: Robert Lubos <robert.lubos@nordicsemi.no>
(cherry picked from commit 99a164df5c)
2026-05-19 15:14:00 -05:00
Jukka Rissanen
b4d26cf134 tests: net: utils: Enable ASAN
Run address sanitizer to catch any undefined behavior issues
in the code.

Signed-off-by: Jukka Rissanen <jukka.rissanen@nordicsemi.no>
(cherry picked from commit d5ced71a8c)
2026-05-19 15:13:25 -05:00
Jukka Rissanen
765fe6e427 tests: net: utils: Check empty value using memcmp()
Use memcmp() to compare values instead of direct comparison.
Without this, some of the tests were failing because this
comparison "" != "" was true when ASAN was enabled.

Signed-off-by: Jukka Rissanen <jukka.rissanen@nordicsemi.no>
(cherry picked from commit 007a274258)
2026-05-19 15:13:25 -05:00
Jukka Rissanen
bafe43f032 tests: net: utils: Fix test case having a buffer overflow
The test code accessed buffer outside of limits. Fix it by
setting the string length properly in the test.

Signed-off-by: Jukka Rissanen <jukka.rissanen@nordicsemi.no>
(cherry picked from commit 2df51049e4)
2026-05-19 15:13:25 -05:00
Jukka Rissanen
9ff8efda24 tests: net: utils: Add IPv6 tests for address parser
Make sure that IPv6 address parsing works as expected.

Assisted-by: Claude:claude-sonnet-4.6
Signed-off-by: Jukka Rissanen <jukka.rissanen@nordicsemi.no>
(cherry picked from commit 1c79d0c467)
2026-05-19 15:13:25 -05:00
Jukka Rissanen
883419d6d3 net: utils: Fix possible overflow in IPv6 address parsing
Make sure we will not overflow the ipaddress buffer if
port number is given.

Signed-off-by: Jukka Rissanen <jukka.rissanen@nordicsemi.no>
(cherry picked from commit 6e119a636a)
2026-05-19 15:13:25 -05:00