mirror of
https://github.com/liquidraver/ZephCore.git
synced 2026-09-02 04:38:27 +00:00
The ESP32 BLE controller glue guards ble_enc_funcs_reset() on CONFIG_BT_CTRL_BLE_SECURITY_ENABLE, an ESP-IDF sdkconfig symbol that is never defined in a Zephyr build. The call is therefore compiled out and the controller's LE Secure Connections encryption table is left uninitialised, so SC pairing derives a wrong session key and the link is terminated with HCI reason 0x3D (MIC failure). This breaks pairing for SC-capable centrals (e.g. Pixel 7 / recent Android); legacy-pairing centrals use a different path and are unaffected. The existing CONFIG_ESP32_BT_CTLR_LE_SECURITY_ENABLE=y only sets .enc_en and does not reach this guard. Correct the guard to BLE_SECURITY_ENABLE, which esp_bt.h already derives from CONFIG_ESP32_BT_CTLR_LE_SECURITY_ENABLE (the Zephyr knob) and already uses for .enc_en. Carried as a managed hal_espressif patch via the existing zephcore_apply_patches() mechanism (mirrors the loramac-node patch). Verified on Heltec Wireless Tracker (ESP32-S3): device reaches security level 4, pairing complete bonded=1; Pixel 7 bonds over SC and the companion app communicates; older Samsung still pairs. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>