Commit graph

1496 commits

Author SHA1 Message Date
aviralgarg05
79daf2c5a9 system/nxstore: Harden package icon caching.
Read cached icons completely, validate the RGB565 format and exact payload size, and discard corrupt cache entries so a later launch can retry acquisition.

Key the local cache by package name and version so a catalog update cannot silently reuse an older icon.

Assisted-by: OpenAI Codex:gpt-5.6-sol
Signed-off-by: aviralgarg05 <gargaviral99@gmail.com>
2026-07-24 15:25:58 +05:30
aviralgarg05
63c540cbbb system/nxstore: Correct the scroll threshold comment.
Keep the list behavior documentation consistent with the 20-pixel threshold used by the tested implementation.

Assisted-by: OpenAI Codex:gpt-5.6-sol
Signed-off-by: aviralgarg05 <gargaviral99@gmail.com>
2026-07-24 15:25:58 +05:30
aviralgarg05
ab5036fcab system/nxstore: Honor installed launch metadata.
Use nxstore-owned framebuffer and input configuration symbols instead of relying on an unrelated LVGL demo configuration.

Load the manifest for the installed version before launching it, validate that it matches the installed database entry, and pass its recorded arguments to posix_spawn(). Check spawn-attribute setup errors as well.

Add the shared supervisor-bar height header to the nxstore change itself so the branch builds independently and framebuffer applications can follow the required reserved-strip contract.

Assisted-by: Codex:gpt-5
Signed-off-by: aviralgarg05 <gargaviral99@gmail.com>
2026-07-24 15:25:58 +05:30
aviralgarg05
7fb624df4c system/nxstore: Retry synchronization on network readiness.
Remove the dependency on an ESP-specific DHCP global. Retry catalog synchronization for a bounded period only while the network stack reports readiness-related errors, allowing the same frontend to work with Wi-Fi, Ethernet, and other boards.

Keep the LVGL timer serviced between attempts so the interface remains responsive while the network comes up.

Assisted-by: Codex:gpt-5
Signed-off-by: aviralgarg05 <gargaviral99@gmail.com>
2026-07-24 15:25:58 +05:30
aviralgarg05
3d8bbb8630 system/nxstore: address review findings and fix hardware-found bugs.
Review/hardening findings from the companion nxpkg PRs:

- Own framebuffer/input device paths instead of borrowing
  CONFIG_EXAMPLES_LVGLDEMO_FBDEVPATH/INPUT_DEVPATH from an unrelated
  example app: new CONFIG_SYSTEM_NXSTORE_FBDEVPATH/INPUT_DEVPATH
  Kconfig string options (defaulting to /dev/fb0 and /dev/input0).

- g_index moves from a static struct to a heap-allocated
  FAR struct pkg_index_s * (pkg_zalloc()), with a "Not enough memory to
  load the catalog." UI fallback if the allocation fails.

- nxstore_launch() now loads the specific installed version's manifest
  via pkg_metadata_load_manifest_path() instead of combining a
  rollback-selected version with whatever the current catalog entry
  happens to describe for that name - those can disagree after a
  rollback if the catalog has since moved on. Also passes through the
  installed manifest's launch_args/launch_argc (previously always
  argv[1] = NULL).

- title_text buffer sized PKG_NAME_MAX + PKG_VERSION_MAX + 5 instead of
  a fixed 96, fixing a real compiler truncation warning.

- README.txt moved to the companion NuttX documentation PR rather than
  shipping user-facing documentation as an in-tree README.

Bugs found bringing this up on real hardware:

- LV_EVENT_LONG_PRESSED could fire for a touch that was actually
  driving a scroll of the app list: if a drag starts slowly enough
  that the long-press timer (400ms) elapses before the finger crosses
  the scroll-lock distance, LVGL hasn't committed the gesture to
  scrolling yet and still delivers the long-press event, silently
  uninstalling whatever card the touch happened to land on. Ignore the
  long-press if this input device is currently attributed to scrolling
  any object (lv_indev_get_scroll_obj()).

- Tapping an installed-app card to launch it, while a different
  install was in progress elsewhere in the list (or another app was
  already running), was allowed through unconditionally - install_worker()
  auto-launches its own package once done, and letting a second launch
  through independently meant whichever one finished last silently
  overwrote g_running, leaving the other process alive, unsupervised,
  and drawing into the same shared framebuffer with no way to close it
  from this UI again. Both the direct-launch and fresh-install paths in
  install_btn_event_cb() now refuse (with a toast) if g_running.active
  or g_active.manifest indicate another app is already running or about
  to be.

- nxstore_is_installed() only checked the package *name*, not which
  version was actually on disk - an older installed version showed as
  plain "Installed" identically to a current one, and tapping it
  silently launched the stale payload with no update indication or
  action. Add nxstore_is_up_to_date() (compares the installed version
  against the catalog's latest manifest) and a third status_bar color
  (in addition to not-installed/up-to-date) plus a "Update available -
  tap to update" subtitle for the mismatch case; tapping such a card
  now goes through the install path (which fetches and auto-launches
  the newly installed version) instead of the direct-launch path.

- lv_indev_set_scroll_limit() was set to 255 (copied from examples/
  lvgldemo/lvgldemo.c, whose own touch-drift mitigation this file
  reused), requiring a nearly-full-screen drag before a touch was even
  recognized as a scroll gesture. Unlike that demo, this screen's app
  list is scrolled constantly, and a threshold that large read as
  broken/laggy scrolling rather than drift protection. Lowered to 20,
  enough to reject typical touch-driver jitter while still recognizing
  a real scroll almost immediately; momentum stays off (scroll_throw
  0), which is what the dual-launch/scroll-lock fixes above actually
  depend on, not the gesture-start threshold.

Also adds nxstore_load_icon(): best-effort loads and caches a
package's optional icon (manifest->icon) as a raw RGB565 image LVGL
can render with no decoder (this board has no PNG/JPEG decode
capability), falling back to the existing colored-circle-plus-glyph
rendering on any failure (no icon set, download failed, corrupt/
oversized file) so a bad icon never blocks a package from being
listed or installed.

Assisted-by: Claude:claude-sonnet-5
Signed-off-by: aviralgarg05 <gargaviral99@gmail.com>
2026-07-24 15:25:58 +05:30
aviralgarg05
778bc0e64c system/nxstore: add LVGL app-store UI.
Add nxstore, an LVGL-based frontend for nxpkg (system/nxpkg): lists
packages from the local index, installs/launches the selected one,
and supervises whatever it hands the screen to.

Card-based app list (populate_app_list()): each row shows name,
version, and description/status, install/launch state reflected via
icon glyph and color (LV_SYMBOL_DOWNLOAD/PLAY, accent/success color),
and a sliding-segment progress bar during install (no real byte-level
progress is available from pkg_install(), so this reads as
'actively working' without fabricating a percentage). Explicit
LV_STATE_PRESSED styling on every tappable row/button, since no LVGL
theme is loaded and a tap would otherwise give no visual feedback at
all.

Supervisor screen (build_run_screen()/nxstore_enter_running_screen()):
a launched app (e.g. a game that owns /dev/fb0 directly, not just
another LVGL client) gets a dedicated screen with a name label and a
Close button, confined to the border region the launched app's own
scaled/centered framebuffer output never draws into, so switching
back to it doesn't fight over pixels with whatever the app already
put in the framebuffer.

Close/reap handling (close_running_app_event_cb()/
nxstore_poll_running_app()): sends SIGTERM and polls waitpid(WNOHANG)
for the launched pid, but explicitly also treats waitpid() returning
ECHILD as 'already gone' rather than 'still running' - both the
close-button handler and the passive per-loop poll independently race
to reap the same child, so whichever one loses that race must not
spin forever waiting for a wait() that can now never succeed. Requires
the target app to install its own SIGTERM handler to exit cleanly
(this is why there is no generic force-kill fallback here: an
earlier version of this code called task_delete() when SIGTERM wasn't
reaped quickly enough, which was found on real hardware to hang the
entire board - not just the one task - when it landed mid
framebuffer/heap access on this flat-memory build).

Toast notifications (nxstore_toast()) provide a transient, unmissable
confirmation for install/uninstall/launch outcomes and app-closed
events, additive to the durable per-row subtitle text rather than a
replacement for it.

nxstore's own boot-time catalog sync waits (bounded, 15s) on
g_wifi_dhcp_ret before attempting a network fetch, since Wi-Fi
association completing doesn't imply DHCP has - an HTTP fetch
attempted in that window fails with -ENETUNREACH even though the
link itself is already up, indistinguishable from being genuinely
offline without this wait.

Assisted-by: Claude:claude-sonnet-5
Signed-off-by: aviralgarg05 <gargaviral99@gmail.com>
2026-07-24 15:25:58 +05:30
aviralgarg05
f363a8f444 system/nxpkg: Protect live locks from filesystem clock skew.
Record a per-boot token and owner PID in every package, installed-database, and synchronization lock. A contender now keeps a lock held while its recorded owner task is alive, regardless of unreliable FAT modification timestamps.

Reclaim locks from exited owners or earlier boots immediately, while retaining timestamp-based migration handling for legacy empty lock files. This prevents a just-created live lock from being mistaken for a decades-old stale file on targets whose mounted filesystem clock does not match CLOCK_REALTIME.

Assisted-by: OpenAI Codex:gpt-5.6-sol
Signed-off-by: aviralgarg05 <gargaviral99@gmail.com>
2026-07-24 15:25:58 +05:30
aviralgarg05
38c608326a system/nxpkg: Address follow-up review findings.
Shorten the installed-database lock description and centralize pkg_sync() cleanup, as requested in review. Replace repeated protocol literals with named constants and preserve errno before cleanup calls can overwrite it.

Store the synchronized catalog source in the catalog itself so the catalog and its relative-artifact base are committed atomically. Continue reading the former sidecar format for upgrade compatibility, and normalize array-form catalogs before adding the private source field.

Compare numeric version prefixes without strtol() overflow and retain lexical comparison of suffixes.

Assisted-by: Codex:gpt-5
Signed-off-by: aviralgarg05 <gargaviral99@gmail.com>
2026-07-24 15:25:58 +05:30
aviralgarg05
8571175bb9 system/nxpkg: fix concurrency and versioning bugs found in review.
- pkg_sync(): index.jsn and repo.url were updated as two independent
  atomic writes with nothing serializing the pair against a second,
  concurrent pkg_sync() call - each write stayed internally
  consistent, but the pair didn't, so one sync's index could end up on
  disk next to a different sync's source URL. Add a dedicated sync
  lock (pkg_repo_acquire_sync_lock(), mirroring the existing installed-
  db lock's blocking-retry-with-stale-reclaim pattern) around the
  whole read-fetch-write sequence. Also renew the lock's mtime as data
  actually arrives (pkg_repo_sink(), via a new renew_lock_path field
  threaded through pkg_acquire_source()) rather than only stamping it
  once at acquire time - a lock acquired once and then measured
  against a fixed 10-minute staleness window could otherwise be
  reclaimed mid-download on a large-enough file over a slow-enough
  link, even though the download was still genuinely in progress.
  pkg_reclaim_stale_lock() (renamed from pkg_install_reclaim_stale_lock,
  made public) is shared between both lock kinds rather than
  duplicated.

- pkg_install_prune_oldest_version(): deleted the pruned version's
  on-disk payload directory before the updated installed database was
  even durably saved. If pkg_metadata_save_installed() subsequently
  failed, the payload was already gone but the last successfully-saved
  instpkg.jsn could still list that version as installed. The victim
  version is now handed back to the caller (threaded through
  pkg_install_add_version()/pkg_install_update_installed()) so
  pkg_install() can defer the actual directory removal until after the
  save succeeds.

- pkg_metadata_version_token_cmp(): two version tokens with equal
  numeric prefixes (e.g. "1a" and "1b", both parsing as 1) compared as
  equal instead of falling back to a lexical comparison of what
  follows the number, contradicting this function's own documented
  behavior and silently treating genuinely different versions as the
  same one. Compare the non-numeric remainder lexically when the
  numeric prefixes match instead of falling through.

Assisted-by: Claude:claude-sonnet-5
Signed-off-by: aviralgarg05 <gargaviral99@gmail.com>
2026-07-24 15:25:58 +05:30
aviralgarg05
455af497ca system/nxpkg: address lifecycle review findings.
Fix real correctness/security gaps found during review, on top of the
network sync and CLI completion work:

- pkg_install(): commit the installed database before writing the
  current/previous pointer files, and before advancing transaction
  state past ACTIVATED. Those are recovery bookkeeping and convenience
  mirrors respectively - once the installed database itself is
  durably committed, a failure to refresh either one must not trigger
  the failure-cleanup path, which could otherwise delete a payload the
  database now legitimately points at. Also stop treating an existing
  version directory as newly created when reinstalling an
  already-installed version, so a failed reinstall can't delete a
  working install.

- pkg_uninstall()/pkg_rollback(): acquire the per-package install lock
  in addition to the installed-db lock, drop the entry from the
  authoritative database first, and only then remove payload files -
  a crash between those two steps can leave orphaned files, which are
  reclaimable, but never leaves the database pointing at a payload
  that's already gone.

- pkg_sync(): stage each sync to a PID-qualified temp filename instead
  of a single fixed name, so concurrent sync calls can no longer race
  on the same staging file. Return real negative errno codes instead
  of EXIT_SUCCESS/EXIT_FAILURE, matching the rest of this API; pkg_main.c
  maps that back to a process exit code at the CLI boundary.

- pkg_metadata_parse_installed_entry(): validate that name/current/
  previous/every entry in versions[] are safe path components, and that
  current (and previous, if set) actually appear in versions[] - a
  corrupted or tampered installed-packages database can no longer
  reference a nonexistent version or smuggle a path-traversal sequence
  through a field this code already trusted implicitly.

- pkg_store_write_all()/pkg_repo_sink(): treat a zero-byte write() as
  -EIO instead of looping on it silently.

- Removed the malloc()-falls-back-to-kmm_malloc() logic in pkg_malloc/
  pkg_zalloc/pkg_realloc/pkg_free entirely - it required tracking which
  allocator owned a given pointer via kmm_heapmember(), which is
  specific to this target's flat, single-heap memory model and not a
  sound general application API. These are now plain wrappers around
  malloc/calloc/realloc/free.

- Added pkg_metadata_load_manifest_path(), so a caller (e.g. the
  nxstore GUI frontend, launching an installed package) can load the
  manifest actually recorded for a specific installed version, instead
  of combining a rollback-selected version with whatever the current
  catalog happens to describe for that package name - those can
  disagree after a rollback if the catalog has since moved on.

- Storage root default changed from /tmp/nxpkg to /var/lib/nxpkg,
  following the conventional persistent application-data location
  instead of a path whose own name suggests non-persistent storage. A
  board without persistent storage mounted at /var, or that wants a
  different location (e.g. an SD card), still overrides this via
  CONFIG_SYSTEM_NXPKG_ROOT as before.

- Moved system/nxpkg/README.txt into the companion NuttX documentation
  PR rather than shipping user-facing documentation as an in-tree
  README.

Assisted-by: Claude:claude-sonnet-5
Signed-off-by: aviralgarg05 <gargaviral99@gmail.com>
2026-07-24 15:25:58 +05:30
aviralgarg05
81b88922f7 system/nxpkg: network sync, install hardening, and CLI completion.
Fill in most of what the initial nxpkg slice deferred: network sync
and artifact acquisition over plain HTTP (verified via SHA-256), an
install rewrite that supports network sources and reclaims state left
by an interrupted previous install, and wiring update/remove/rollback/
available into the CLI.

Harden the package path against untrusted input along the way: bounded
memory-safety helpers and explicit size limits throughout, storage
read/write hardened against partially-written files, path-traversal
rejection in manifest name/version before they reach the filesystem,
and a fix for a lost-update race on the shared installed-packages
database (two concurrent installs of different packages could
otherwise silently clobber each other's recorded state).

Add an optional manifest icon field for the nxstore GUI frontend to
consume, raise PKG_INDEX_MAX now that the in-memory index is
heap-allocated, and document the repository layout and local server
setup in system/nxpkg/README.txt.

Also fixes a real build break: pkg_runtime_compat() unconditionally
referenced CONFIG_ARCH_BOARD, a Kconfig string symbol with no default
clause under ARCH_BOARD_CUSTOM, so it is left entirely undefined
rather than defined-but-empty on a custom board - falls back to
CONFIG_ARCH_BOARD_CUSTOM_NAME instead. Routes pkg_error()/pkg_info()
through syslog rather than stdio, since neither is visible to a
supervisor with no attached console.

Assisted-by: Claude:claude-sonnet-5
Signed-off-by: aviralgarg05 <gargaviral99@gmail.com>
2026-07-24 15:25:57 +05:30
Jorge Guzman
865393d419 system/curl: add a small curl-like HTTP client command
Add the "curl" NSH command: a command-line HTTP client built on top of
the netutils webclient library. It implements a subset of the real curl
options: GET and POST (and other methods via -X), custom request headers
(-H), a raw request body (-d, including -d @file), multipart/form-data
file uploads (-F name=@file), saving the response body to a file (-o)
and verbose output (-v). HTTP only (no HTTPS).

Signed-off-by: Jorge Guzman <jorge.gzm@gmail.com>
2026-07-20 10:21:57 +02:00
Old-Ding
62d04ed484 system: fastboot: bound filedump path parsing
Parse the filedump path token into the existing PATH_MAX-sized buffer
before reading the optional offset and size arguments. This bounds the
write without constructing a scanf format string at runtime.

Signed-off-by: Old-Ding <35417409+Old-Ding@users.noreply.github.com>
2026-07-16 15:59:21 +08:00
Old-Ding
1d5f816874 system: audio: parse command filenames with PATH_MAX
Parse command filename tokens into PATH_MAX-sized buffers before
reading optional raw audio parameters. This bounds nxplayer and
nxrecorder input without runtime-built scanf formats.

Signed-off-by: Old-Ding <35417409+Old-Ding@users.noreply.github.com>
2026-07-11 12:40:07 -03:00
Alan Carvalho de Assis
707b24e5cb system/ping: Fix a segmentation fault when using ping
nsh> ping google.com
[   37.180000] dns_query_error: ERROR: IPv4 dns_recv_response fa: -84,
               server address: 8.8.8.8
Segmentation fault.

Signed-off-by: Alan C. Assis <acassis@gmail.com>
2026-07-09 09:42:30 +08:00
Old-Ding
5226be524c system/vncviewer: Drain truncated desktop names
The RFB ServerInit message carries the desktop name as a length-prefixed field. vncviewer caps the copied name to fit conn->name, but it must still consume the remaining bytes from the socket when the advertised name is longer than the local buffer.

Drain the unused suffix so the next RFB message is read from the correct boundary. Reuse the same discard helper for other skipped RFB payloads.

Signed-off-by: Old-Ding <ai.neo.ae86@gmail.com>
2026-07-09 09:28:13 +08:00
Old-Ding
64f9e8a4b7 system: nxinit: bound debug argv dump
Check the service argv array bound before reading the current entry in the debug dump loop. A full argument array may not have an in-array NULL terminator, so the old condition could read one entry past the array while CONFIG_SYSTEM_NXINIT_DEBUG is enabled.

Signed-off-by: Old-Ding <35417409+Old-Ding@users.noreply.github.com>
2026-07-07 09:47:23 +08:00
Old-Ding
6eead56aa9 system: resmonitor: check CPU load reads
Keep the default zero CPU value when the procfs load file cannot be read, and trim only the newline that was actually present. This avoids parsing uninitialized stack data in fillcpu and avoids writing before the showinfo CPU buffer when fgets returns no data.

Signed-off-by: Old-Ding <35417409+Old-Ding@users.noreply.github.com>
2026-07-06 16:31:38 +08:00
Xiang Xiao
5ead824fff apps: Fix O_ACCMODE bitmask checks after Linux flag alignment
After aligning NuttX open() flag constants with Linux (O_RDONLY=0,
O_WRONLY=1, O_RDWR=2), code that used '(flags & O_RDONLY)' or
'(flags & O_WRONLY)' as a bitmask check is broken because O_RDONLY
is now 0.  Fix by using '(flags & O_ACCMODE)' comparisons instead.

  - usrsocktest: replace 'flags & O_RDWR' with 'flags & O_ACCMODE'
    in fcntl F_GETFL assertions
  - dd: verify mode used '(oflags & O_RDONLY)' to detect verify;
    replace with '(oflags & O_ACCMODE) == O_RDWR'
  - dpopen: replace '(oflag & O_RDWR) == O_RDWR' with
    '(oflag & O_ACCMODE) == O_RDWR'
  - usbmsc: replace 'flags & O_WRONLY' with
    '(flags & O_ACCMODE) == O_RDONLY'
  - fcntl_test: replace '(flags & O_WRONLY) == 0' with
    '(flags & O_ACCMODE) == O_RDONLY'

Signed-off-by: Xiang Xiao <xiaoxiang@xiaomi.com>
2026-06-30 12:19:58 -04:00
Xiang Xiao
d172f81ecc apps: Replace O_RDOK with O_RDONLY after alias removal
The O_RDOK/O_WROK aliases have been removed from fcntl.h.  Replace
all remaining O_RDOK usage with O_RDONLY in the apps repository.

Signed-off-by: Xiang Xiao <xiaoxiang@xiaomi.com>
2026-06-29 07:42:09 +02:00
aviralgarg05
da143595e1 apps: add missing module metadata for executable tools
Add the missing module metadata for the executable ELF helpers used by the package fixture flow so the generated artifacts describe their target and type consistently.

Also fix the existing embedlog spelling issue that is picked up by the current apps check, keeping this branch clean under CI.

Signed-off-by: aviralgarg05 <gargaviral99@gmail.com>
2026-06-22 22:27:07 +08:00
aviralgarg05
65854ea805 system/nxpkg: add local package lifecycle helper
Add the initial nxpkg command, metadata and store handling, the local install/list path, and the repository export helper.

Keep the current flow scoped to local artifacts and target-qualified repository entries so it remains usable as an incremental MVP while follow-up features land separately.

Signed-off-by: aviralgarg05 <gargaviral99@gmail.com>
2026-06-20 15:05:28 -03:00
Nightt
fa2dd70386 system/popen: Avoid copying FILE
Use fopencookie() to attach the popen fd and shell pid to the returned FILE stream instead of copying FILE into the popen container.

Keep the upstream dpopen()/dpclose() implementation as the process and descriptor backend, and make pclose() close the cookie-backed stream directly.

Fixes #2937.

Signed-off-by: Nightt <87569709+nightt5879@users.noreply.github.com>
2026-06-09 19:35:15 +08:00
hanzhijian
03171162f1 system/uorb: introduce CONFIG_UORB_FORMAT for format string control
Introduce a new CONFIG_UORB_FORMAT Kconfig option to control whether
uORB format strings are compiled in. UORB_LISTENER, UORB_GENERATOR,
and DEBUG_UORB all select UORB_FORMAT automatically, so format strings
are included when any of these features are enabled.

This replaces the previous approach of guarding format strings with
CONFIG_DEBUG_UORB, which prevented uorb_listener from displaying
sensor data when debug output was disabled.

Signed-off-by: hanzhijian <hanzhijian@zepp.com>
2026-06-09 17:02:03 +08:00
hanzj
8b4d20e411 system/uorb: fix listener_top not showing topic data
listener_update() only prints topic data when delta_generation is
non-zero (i.e., new data arrived since last check). In listener_top,
the first call adds objects to the list, and subsequent calls only
print if new data was published between iterations. This results in
listener_top -T showing only the header with no topic rows.

Fix by always printing the current topic state in listener_update,
setting frequency to 0 when no new data arrives. This ensures
listener_top displays all topics every iteration.

Fixes apache/nuttx-apps#3202

Signed-off-by: hanzj <hanzhijian@zepp.com>
2026-06-06 18:27:56 +08:00
fangpeina
1d7d4fe67e system/nxinit: fix init parser to handle multiple quoted arguments
Fix argument parsing in init_parse_arguments() to properly handle
multiple quoted arguments like 'echo "arg1" "arg2"' by skipping
quote characters after processing them.

Signed-off-by: fangpeina <fangpeina@xiaomi.com>
2026-06-05 09:43:45 +08:00
wangjianyu3
d79d8107b3 system/nxinit: Fix signal mask inheritance
The init process has blocked all signals, spawned services would
inherit that mask. This could cause services to miss important
signals like SIGTERM during graceful shutdown.

Signed-off-by: wangjianyu3 <wangjianyu3@xiaomi.com>
2026-06-05 09:43:45 +08:00
wangjianyu3
b73a5acf92 system/nxinit: Fix missing check for import argument
Add missing return value check for init_parse_arguments function.

Signed-off-by: wangjianyu3 <wangjianyu3@xiaomi.com>
2026-06-05 09:43:45 +08:00
v-maomingju
63c691eae2 system/nxinit: fix unused variable warning
fix the unused variable warnings for name and status in init.c.

Signed-off-by: v-maomingju <v-maomingju@xiaomi.com>
2026-06-05 09:43:45 +08:00
wangjianyu3
84d6b1276f system/nxinit: Avoid SIGCHLD race with ppoll()
Pending all signals(SIGCHLD) when ppoll() is not invoked to
avoid race conditions.

Case reproduction

  Set examples/hello as a service that exits immediately after startup.

  ```init.rc
  on boot
     start hello

  service hello hello
     restart_period 0
  ```

  Log - without this patch:

    # Service hello only restarts about 100 times, ppoll is not woken up
    # after the hello process with PID 119 exits.

    [    4.391274] [ 2] [ 0] init_main: service 'hello' pid 118 exited status 0
    [    4.401423] [ 2] [ 0] init_main: started service 'hello' pid 119

  Log - with this patch:

    # ppoll() can still be woken up normally after tens of thousands of
    # restarts of service hello in stress test.

    [  268.447747] [ 2] [ 0] init_main: service 'hello' pid 34503 exited status 0

Signed-off-by: wangjianyu3 <wangjianyu3@xiaomi.com>
2026-06-05 09:43:45 +08:00
fangpeina
78bf19c83c system/nxinit: prevent parser from reading past string boundry
Any string ending with whitespace passed to init_parse_arguments()
could cause the parser to advance past the string boundary and read
unintended memory content.
 - " echo "A" \0& echo "B" should be parsed
   as a command with two argvs instand of five.
 - "command arg  " may lead to uncertain results.

Signed-off-by: fangpeina <fangpeina@xiaomi.com>
2026-06-05 09:43:45 +08:00
wangjianyu3
b0fdffb7f6 system/nxinit: Fix timespec incomplete error in action.h
/.../apps/system/nxinit/action.h:72:19: error: field 'time_run' has incomplete type
    72 |   struct timespec time_run;
       |                   ^~~~~~~~

Signed-off-by: wangjianyu3 <wangjianyu3@xiaomi.com>
2026-06-05 09:43:45 +08:00
fangpeina
62b74502fe system/nxinit: fix uninitialized 'wstatus' warning
reap_process() referenced an undeclared identifier 'wtatus' on
the WIFSIGNALED branch (typo of 'wstatus'). Some toolchains then
flagged a -Wmaybe-uninitialized on the surrounding wstatus use.

Correct the typo so WIFSIGNALED/WTERMSIG operate on the actual
wstatus value returned by waitpid().

Signed-off-by: fangpeina <fangpeina@xiaomi.com>
2026-06-05 09:43:45 +08:00
fangpeina
3d26835e0c system/nxinit: fix compilation errors in action.c
action.c uses clock_gettime(CLOCK_MONOTONIC, ...) but did not
pull in <nuttx/clock.h> directly, which fails to build on
configurations where the header is not transitively included.

Add the missing #include.

Signed-off-by: fangpeina <fangpeina@xiaomi.com>
2026-06-05 09:43:45 +08:00
wangjianyu3
df01c3cbfc system/nxinit: Handle trailing file '\0'
When ETC_ROMFS is disabled to reduce the bin size, we can provide the init.rc
file via a pseudo-file in the boards/vendor directory. For example:
  - CONFIG_ETC_ROMFS=n
  - CONFIG_PSEUDOFS_FILE=y
  - CONFIG_DISABLE_PSEUDOFS_OPERATIONS=n
  ```C
  FAR const char *init_rc =
    "on init\n"
    "    start console\n";
    "service console sh\n"
    "    restart_period 100\n";

  int fd = open("/etc/init.d/init.rc", O_WRONLY | O_CREAT);
  /* ... */
  ssize_t n = write(fd, init_rc, strlen(init_rc) + 1);
  /* ... */
  close(fd);
  ```

The last character '\0' in the file content will be treated as a new line,
and the number of parsed parameters will be zero (abnormal, there should be
at least one keyword).

Signed-off-by: wangjianyu3 <wangjianyu3@xiaomi.com>
2026-06-05 09:43:45 +08:00
hanzj
e86c0b997d system/nxinit: skip empty lines in init.rc parser
Empty lines in init.rc caused parsing to fail with -EINVAL because init_parse_arguments() returns 0 for empty strings, triggering the 'argc < 1' error path in init_action_parse() and accessing uninitialized argv[0] in init_service_parse().

Fix by skipping empty lines and lines containing only whitespace before attempting to match section keywords or calling parser callbacks.

Fixes apache/nuttx-apps#3513

Signed-off-by: hanzj <hanzhijian@zepp.com>
2026-06-04 13:11:09 -03:00
cuiziwei
740fda9630 system/popen: support no-shell mode via posix_spawnp
When NSH_LIBRARY is not available, dpopen()/popen() can still execute
commands by splitting the command string by whitespace and calling
posix_spawnp() directly.  Shell syntax (pipes, redirects, globbing)
is not supported in this mode.

Add CONFIG_SYSTEM_POPEN_MAXARGUMENTS (default 7) to control the
argv array size for the no-shell path.

Remove the hard dependency on NSH_LIBRARY from SYSTEM_POPEN so the
feature can be used in minimal configurations without a shell.

Signed-off-by: cuiziwei <cuiziwei@xiaomi.com>
2026-06-02 23:35:28 +08:00
cuiziwei
0d35e2e0bb system/popen: add dpopen/dpclose fd-based interface
Add dpopen()/dpclose() as the descriptor-based counterpart of
popen()/pclose(), analogous to how dprintf() relates to fprintf().
dpopen() returns a raw file descriptor instead of a FILE stream,
avoiding the stdio.h dependency for callers that only need an fd.

Refactor popen() as a thin wrapper: dpopen() + fdopen() + FILE
container.  All pipe creation and process spawning logic now lives
in dpopen.c.

Also remove the hard dependency on NSH_LIBRARY from SYSTEM_POPEN.
When NSH is available, commands are executed through sh -c with full
shell syntax support.  When NSH is not available, commands are split
by whitespace and executed directly via posix_spawnp().

Add CONFIG_SYSTEM_POPEN_MAXARGUMENTS (default 7) to control the
argv array size for the no-shell path.

Signed-off-by: cuiziwei <cuiziwei@xiaomi.com>
2026-06-02 23:35:28 +08:00
Arjav Patel
5e91459b1a system/microros: Add UDP and serial custom transport backends.
Micro XRCE-DDS expects the application to supply open/close/write/read
callbacks for the wire transport. Add a single dispatcher that
registers the selected backend via rmw_uros_set_custom_transport(),
plus two backends:

transport/microros_transport_udp.c
  BSD-socket UDP backend. Opens an AF_INET/SOCK_DGRAM socket,
  resolves CONFIG_MICROROS_AGENT_IP/PORT, connect()s it, and uses
  send/recv. The socket fd is stashed in uxrCustomTransport->args
  so no module-level state is needed.

transport/microros_transport_serial.c
  termios serial backend. Opens CONFIG_MICROROS_SERIAL_DEVICE with
  O_RDWR|O_NOCTTY|O_CLOEXEC, switches to raw 8N1 at
  CONFIG_MICROROS_SERIAL_BAUD, and uses poll/read/write. Fd is
  again stashed in uxrCustomTransport->args.

Both backends are mutually exclusive at compile time via Kconfig;
the dispatcher selects which set of callbacks to register. Wired
into both the legacy Make build (CSRCS in system/microros/Makefile)
and the CMake build (separate microros_transport static library
with the transport directory only exposed to its INTERFACE).

Signed-off-by: Arjav Patel <arjav1528@gmail.com>
2026-06-02 00:15:25 +08:00
Arjav Patel
0a0118b93c system/microros: Wire libmicroros include layout and sim final link.
libmicroros is installed by colcon under include/<pkg>/<pkg>/file.h
for ament-packaged headers (e.g. rcl, rmw, rosidl) and the flat
include/<pkg>/file.h for a few others (e.g. rclc). A single
-I include/ therefore resolves <rclc/rclc.h> but not <rcl/rcl.h>.

Enumerate every immediate subdirectory of include/ in addition to
include/ itself so both layouts resolve.

Switch the library hand-off from LDLIBS to EXTRA_LIBS. The sim
target's final link pulls EXTRA_LIBS, not LDLIBS, so the previous
form left rcl/rclc/rcutils symbols unresolved.

Signed-off-by: Arjav Patel <arjav1528@gmail.com>
2026-06-02 00:15:25 +08:00
Arjav Patel
3d6ea0ccec system/microros: Fix toolchain attribute strip breaking libc inlines.
micro_ros_lib/toolchain.cmake.in initialised C and CXX flags with
-D'__attribute__(x)=' to silence GCC attributes the upstream ament
build is not aware of. The strip also removed __gnu_inline__ and
__always_inline__ from NuttX's libc string.h inlines, so each
micro-ROS translation unit emitted external definitions of strcmp,
strcpy, strlen and friends. Sim final link then failed with ~50
multiple-definition errors.

Drop the define from both flag init lines so the attributes survive
and the inlines collapse as intended.

Signed-off-by: Arjav Patel <arjav1528@gmail.com>
2026-06-02 00:15:25 +08:00
hanzj
07647d3fd4 system/lzf: Fix missing space in Kconfig help text.
Fix a missing space in the Kconfig help text for SYSTEM_LZF:
'Enable theLZF' → 'Enable the LZF'.

Signed-off-by: Zepp-Hanzj <Zepp-Hanzj@users.noreply.github.com>
Signed-off-by: hanzj <hanzjian@zepp.com>
2026-05-28 21:27:01 +02:00
Nightt
c0fc208202 system/settings: Bound storage string handling
Use configured key, value, and filename limits while loading and saving settings storage data.

The text backend now builds backup filenames with a sized buffer and bounded formatting, and both text and binary loading reject keys or string values that are not terminated within their configured field sizes. This completes #3109 without changing the storage formats.

Signed-off-by: Nightt <87569709+nightt5879@users.noreply.github.com>
2026-05-28 14:35:54 +02:00
Nightt
a74b2fc61b system/settings: Bound public string handling
Use strnlen() for public key, value, and storage path length checks so user-provided settings strings are validated against the configured maximum sizes before they are scanned.

Use bounded key comparisons and strlcpy() for fixed-size settings fields. This addresses part of #3109 without changing the settings API or storage formats.

Signed-off-by: Nightt <87569709+nightt5879@users.noreply.github.com>
2026-05-28 14:35:54 +02:00
Matteo Golin
418cf21224 apps/nxinit: Fix uninitialized variable
Without debug enabled, the code would not compile due to checking
`WIFEXITED(wstatus)` when `wstatus` was uninitialized.

Signed-off-by: Matteo Golin <matteo.golin@gmail.com>
2026-05-28 01:08:11 -03:00
Matteo Golin
2b5899c7d4 apps/nxinit: Make init.rc file path configurable
The init.rc file path is now configurable to allow users to choose where
to put the startup script. This is useful for devices that mount
external media to a special directory like `/sd`.

Signed-off-by: Matteo Golin <matteo.golin@gmail.com>
2026-05-28 01:08:11 -03:00
Matteo Golin
6d8708184e apps/nxinit: Fix service length error
Would not compile due to typo in macro describing service name length.

Change ensures that:
* We do not malloc an extra `len` bytes since this is already allocated
  as part of the struct
* The name string always has a null terminating byte

Signed-off-by: Matteo Golin <matteo.golin@gmail.com>

FIx
2026-05-28 01:08:11 -03:00
Matteo Golin
241096a87b apps/nxinit: Fix Kconfig typo
Fix typo in help string.

Signed-off-by: Matteo Golin <matteo.golin@gmail.com>
2026-05-28 01:08:11 -03:00
Alan Carvalho de Assis
c28e61fd39 system/nxinit: Change NXInit to EXPERIMENTAL
Since NXInit still under development, it is better to change it to
EXPERIMENTAL.

Signed-off-by: Alan C. Assis <acassis@gmail.com>
2026-05-27 17:20:07 -03:00
Alan Carvalho de Assis
5341a2fc92 system/nxinit: Add final event
Add the final event option to the Kconfig

Signed-off-by: Alan C. Assis <acassis@gmail.com>
2026-05-27 17:20:07 -03:00