Commit graph

1559 commits

Author SHA1 Message Date
Jorge Guzman
ee20ddd0ba system/zbus: Port the Zephyr zbus message bus to NuttX
Port of the Zephyr RTOS zbus (many-to-many message bus with typed
channels and decoupled observers), built entirely on native NuttX
primitives and preserving the original declarative API
(ZBUS_CHAN_DEFINE, ZBUS_LISTENER_DEFINE, ZBUS_SUBSCRIBER_DEFINE, ...).

Features: listeners (synchronous callbacks), subscribers (queue of
channel references), message subscribers (ordered message copies),
async listeners (callback on a dedicated task), runtime observers,
per-observation notification masks, observer enable/disable, message
validators, channel user data, publish statistics, lookup by
name/numeric id and channel/observer iteration.

Mapping to NuttX primitives:
- Channel/observer registration: link-time iterable sections
  (include/nuttx/iterable_sections.h); the observers of a channel are
  named after their position in the definition, so the linker sorts the
  notification order, and the declarative macros are built on
  nuttx/macro.h (CONCATENATE, FOREACH_ARG and the FOREACH_IDX_ARG added
  in a companion nuttx commit) rather than on a private macro engine.
  Notification masks live in .bss with their initial value preserved in
  ROM and applied on lazy init.
- Channel lock: sem_t (enable CONFIG_PRIORITY_INHERITANCE instead of
  the Zephyr priority-boost/HLP); timeouts are computed with the
  clock_timespec_* helpers from nuttx/clock.h.
- Subscriber queues: kernel message queues (file_mq_*) opened lazily
  via pthread_once, usable from any task; mq payload copying replaces
  the Zephyr net_buf machinery entirely.
- Async listeners: one task per listener (task_create, priority and
  stack size configurable) blocking on the listener queue; a task
  rather than a pthread so it outlives the first API caller.
- Timeouts: milliseconds with CLOCK_MONOTONIC deadlines
  (ZBUS_NO_WAIT/ZBUS_FOREVER).

Includes a runnable example (examples/zbus, CONFIG_EXAMPLES_ZBUS) and a
cmocka test suite (testing/zbus, CONFIG_TESTING_ZBUS) covering the full
API: 17/17 tests passing on linum-stm32h753bi hardware, including
multi-channel index grouping, mask semantics, runtime observer error
paths, notification order (the observers of a channel run in the order
they are listed, and an observation bound with ZBUS_CHAN_ADD_OBS() runs
after all of them), queue overflow/timeout semantics, async listener
bursts,
bit-exact float/double payload delivery across every observer type
(sensor-style messages with a float-math validator) and an
interrupt-driven publisher (kernel timer interrupt -> signal -> sampling
thread -> zbus_chan_pub, the recommended pattern for interrupt sources).

Requirements: FLAT build; CONFIG_MQ_MAXMSGSIZE >= pointer size +
CONFIG_ZBUS_MSG_SUBSCRIBER_MAX_MSG_SIZE for message subscribers; board
linker script including <nuttx/linker/common-rom.ld> or the generic
CONFIG_ITERABLE_SECTIONS_LINKER_INSERT mode.

Not ported: multi-domain proxy agent (experimental upstream); publishing
from interrupt handlers (userspace library: hand the data to a thread).

Documentation lives in the nuttx repository
(Documentation/applications/system/zbus).

Assisted-by: Claude Code
Signed-off-by: Jorge Guzman <jorge.gzm@gmail.com>
2026-09-21 18:46:31 -03:00
Justin Hammond
41a2c9d982 system/uorb: Select the printf extension the format strings need.
Every topic's format string is printed through orb_info() or
orb_fprintf(), and both reach the data through "%pB", which is a NuttX
extension rather than a standard conversion.  UORB_FORMAT turns that
code on without turning the extension on, so a configuration that
enables the listener but not the debug output builds cleanly, runs, and
prints a pointer where the reading should be:

  sensor_voltage(now:4294968998000):0xc0203c98B

The address is the va_format the extension was supposed to expand, and
the trailing B is the conversion character being taken as ordinary
text.  Nothing warns, because to the compiler and to printf this is a
valid format string that means something else.

DEBUG_UORB already selects the extension, so the fault is invisible to
anyone who turned that on.  The two are independent options and only
one of them declared what it needed.  Move the select onto UORB_FORMAT,
which is the option that decides whether the format strings are
compiled in at all.

Signed-off-by: Justin Hammond <justin@dynam.ac>
2026-09-20 22:30:19 +08:00
Justin Hammond
3cfb129dbf system/sensortest: Put a blank line after the declarations.
Each of the ten print helpers opens with a declaration followed
immediately by its printf, which nxstyle reports as an error on every
one of them.  The file cannot be checked cleanly until they are fixed,
so a later change to it starts from a failing run and has to sort its
own errors from the existing ones.

Whitespace only.  git diff -w is empty.

Signed-off-by: Justin Hammond <justin@dynam.ac>
2026-09-20 09:24:47 -04:00
Justin Hammond
6d45e5404d system/sensortest: Add rows for the voltage, current and power topics.
The three electrical topics exist and publish, but sensortest rejects
their node names before opening them: its table is matched by name and
carries each structure's size, so a type without a row is one the tool
cannot read at all.

All three are a timestamp and a single value, the shape print_valf
already handles.

Signed-off-by: Justin Hammond <justin@dynam.ac>
2026-09-20 09:24:47 -04:00
fangpeina
2f76986584 system/fastboot: fix pre-existing nxstyle warnings
Add missing blank lines after variable declarations and fix
alignment in preprocessor conditionals. These are pre-existing
style issues exposed by the latest nxstyle version.

Signed-off-by: fangpeina <fangpeina@xiaomi.com>
2026-09-16 00:09:34 +08:00
fangpeina
3b993dfbb6 system/fastboot: Add serial (UART) transport backend.
Add a serial transport alongside the existing USB and TCP backends.
The serial backend reuses the TCP v1 wire framing (FB01 handshake
plus an 8-byte big-endian length prefix) so the host side needs no
new tool: socat bridges the UART to a TCP socket and the standard
fastboot tool connects via tcp:.

The serial port path is configured at build time through Kconfig
SYSTEM_FASTBOOTD_SERIAL_PORT.

Signed-off-by: fangpeina <fangpeina@xiaomi.com>
2026-09-16 00:09:34 +08:00
fangpeina
43dcb51087 system/fastboot: extract framed_read helper and simplify tcp_read
Extract fastboot_framed_read() that handles TCP v1 wire framing:
handshake detection (FB01 exchange) and 8-byte big-endian length
prefix parsing.  Simplify fastboot_tcp_read() to reuse this helper
for both initial handshake and subsequent data frames.

This prepares for adding a serial transport that shares the same
framed protocol.

Signed-off-by: fangpeina <fangpeina@xiaomi.com>
2026-09-16 00:09:34 +08:00
fangpeina
bac662c215 system/fastboot: add per-transport Kconfig options for USB and TCP
Add SYSTEM_FASTBOOTD_USB (default y) and SYSTEM_FASTBOOTD_TCP
(default y) to allow disabling individual transports independently.

Replace direct CONFIG_USBFASTBOOT / CONFIG_NET_TCP guards in the
transport code with the new fastbootd-level Kconfig symbols.

Signed-off-by: fangpeina <fangpeina@xiaomi.com>
2026-09-16 00:09:34 +08:00
fangpeina
06ceed1afb system/fastboot: fix buffer pointer and length in fastboot_read_all
The read loop was passing the original buf pointer and full length on
every iteration, causing subsequent reads to overwrite previous data
and potentially request more bytes than the remaining buffer space.

Update buf and len after each successful read to advance through the
buffer correctly.

Signed-off-by: fangpeina <fangpeina@xiaomi.com>
2026-09-16 00:09:34 +08:00
wangjianyu3
2085e1ca96 system/nxinit: add fallback option to resolve preset service conflict
The preset kvdb service defined in parser.c conflicts with user-defined
kvdb service in board-level init.rc, causing:

  Error redefined service 'kvdb'

Add SVC_FALLBACK flag and fallback service option. When a service
is marked as fallback, it will be silently ignored if another
service with the same name already exists. This is the semantic
opposite of override:

- override: new definition replaces old
- fallback: new definition yields to old
- old has fallback + new arrives: old yields to new

If neither flag is set, duplicate service names still produce
EEXIST error as before.

Mark the preset kvdb service as fallback so that board-specific
init.rc can freely define its own kvdb service without conflict.

Signed-off-by: wangjianyu3 <wangjianyu3@xiaomi.com>
2026-09-16 00:08:45 +08:00
wangjianyu3
5f7db152b2 system/nxinit: fix rptun builtin blocking the action queue
RPTUNIOC_START returns the (positive) pid of the rptun kernel thread
in async mode (CONFIG_RPTUN_START_SYNC unset). The action engine
treats any positive builtin return value as the pid of a spawned
child and waitpid()s on it (action.c: "if (ret > 0) pid_running =
ret"). The rptun thread is a detached kthread, never a child of init,
so that wait blocks the whole action queue forever and "on init" /
console never run. Normalize a successful start to 0.

Assisted-by: OpenCode:claude-sonnet-5
Signed-off-by: wangjianyu3 <wangjianyu3@xiaomi.com>
2026-09-16 00:08:45 +08:00
wangyongrong
64f65dbf3d system/nxinit: add rptun and unlink builtin commands
BL uses init framework (not NSH), so the NSH rptun command is not
available. Add rptun as an init builtin command that supports
start and stop subcommands. Also add a generic unlink builtin
command for removing device nodes.

Usage in init.bl.rc:
  rptun stop /dev/rptun/corecs
  unlink /dev/rptun/corecs
  rptun start /dev/rptun/corecs

- rptun start/stop: open device, ioctl(RPTUNIOC_START/STOP), close
- unlink: generic command to unlink any file/device node

Signed-off-by: wangyongrong <wangyongrong@xiaomi.com>
2026-09-16 00:08:45 +08:00
wangjianyu3
04ee0d45ef system/nxinit: use TRACE_DEVERROR_BIT|TRACE_CLSERROR_BIT, not TRACE_BITSET
usbtrace_enable(TRACE_BITSET) was copied from nsh's CONFIG_USBDEV_TRACE
block without also copying nsh's local #define TRACE_BITSET or the
<nuttx/usb/usbdev_trace.h> include it needs. TRACE_BITSET has no
built-in definition; every other CONFIG_USBDEV_TRACE caller in the
tree (nsh, composite, cdcacm, usbmsc) defines its own. This compiled
fine as long as CONFIG_SYSTEM_NXINIT and CONFIG_USBDEV_TRACE were never
both on for the same board; the two combined for the first time and
init.c failed to build with 'TRACE_BITSET' undeclared.

Add the missing include and inline the same error-only bitset those
other callers fall back to when none of their granular trace options
are enabled, since this file has no such granular Kconfig of its own.

Assisted-by: OpenCode:claude-sonnet-5
Signed-off-by: wangjianyu3 <wangjianyu3@xiaomi.com>
2026-09-16 00:08:22 +08:00
wangjianyu3
c8ffe2a5e1 system/nxinit: add CONFIG_SYSTEM_NXINIT_STDOUT for printf-based log output
Syslog may be output via services such as DFX. When debugging the init
component (e.g., service startup failures, including DFX-related
exceptions), syslog may not be output properly.

Add a debug Kconfig option SYSTEM_NXINIT_STDOUT that redirects all init
log macros (init_debug/info/warn/err) to printf instead of syslog.
This is useful for early boot debugging when syslog is not yet
available or serial console shows no output.

Introduce init_log_output() macro as the common log backend, selected
at compile time between printf (with appended newline) and syslog.

Signed-off-by: wangjianyu3 <wangjianyu3@xiaomi.com>
2026-09-15 09:17:06 -03:00
lljwork2021
6284bdc50e system/xrcedds: add eProsima Micro XRCE-DDS
Add a lightweight Micro XRCE-DDS Client integration with UDP transport support and a publisher example.

Signed-off-by: lljwork2021 <lljwork2021@163.com>
2026-09-15 09:14:39 -03:00
Daniel P. Carvalho
d9cb21d909 netutils/ptpd: fix drift divergence and post-jump bootstrap
1. Post-jump drift bootstrap: on the first Sync packet following a step
   jump, do not compute frequency drift against a synthesized zero delta,
   which previously caused the entire residual phase offset (~ms) to be
   mistaken for frequency drift (~million ppb) and immediately absorbed.
2. Drift rate formula: normalize the adjustment contribution by the actual
   measurement interval instead of the adjtime slew period, and compute
   natural delta rate as (delta - last_delta + last_adjtime) / interval.
3. Remove broken last_delta > delta comparison that prevented offsets from
   converging and applied inverted corrections on negative overshoots.
4. Correct ptp_adjtime() invocation to always pass adjustment_ns for
   CLOCK_REALTIME slewing rather than dropping drift compensation when
   delta exceeds threshold. Clamp adjustment_ns to the hardware slew limit
   so last_adjtime_ns accurately mirrors the true slew applied.
5. Enable Delay_Req in E2E mode once clock is tracking (not jumping) and
   allow software timestamping latency in ptp_process_delay_resp().
6. Propagate initialization return code from ptpd_start() and avoid
   unconditional failure print in do_ptpd_start().

Assisted-by: Claude:claude-sonnet-5
Assisted-by: Gemini:gemini-3.8-flash-medium
Signed-off-by: Daniel P. Carvalho <danieloak@gmail.com>
2026-09-15 09:09:00 -03:00
likun17
d1b15db361 system/uorb: add resistance, conductivity, energy and charge topics.
Declare and define the uORB metadata for the resistance, conductivity,
energy and charge types, and register them in g_sensor_list[] so that
orb_get_meta() and uorb_listener can resolve them by name.

Signed-off-by: likun17 <likun17@xiaomi.com>
2026-09-14 23:56:06 +08:00
likun17
b93c947608 system/uorb: add voltage, current and power topics
Declare and define the uORB metadata for the voltage, current and power
types, and register them in g_sensor_list[] so that orb_get_meta() and
uorb_listener can resolve them by name.

Signed-off-by: likun17 <likun17@xiaomi.com>
2026-09-14 23:56:06 +08:00
likun17
00d9af873d system/uorb: add missing metadata for velocity and ambient_temp
SENSOR_TYPE_VELOCITY and SENSOR_TYPE_AMBIENT_TEMPERATURE have an
entry in the kernel g_sensor_meta[] table but no ORB_DECLARE/ORB_DEFINE
in user space, so ORB_ID() fails to link, callers must fall back to
orb_open() by name and lose the o_size check, and uorb_listener cannot
monitor them.
Add the missing metadata and register both in g_sensor_list[];
ambient_temp reuses struct sensor_temp the same way sensor_light_uncal
already reuses struct sensor_light.

Signed-off-by: likun17 <likun17@xiaomi.com>
2026-09-14 23:56:06 +08:00
wangjianyu3
bc0ed23a5d system/nxinit: add a per-service "console" option
Services started by nxinit (e.g. "sh") do not open a console device on
their own, unlike nsh_main, which explicitly does so via
nsh_consolemain()/nsh_waitusbready() for USB gadget consoles
(CDC-ACM/PL2303). When such a board switches its top-level init from
nsh_main to nxinit, no code path ever registers/connects the USB
console gadget, and a service that just execs a plain "sh" inherits
whatever (invalid, for a USB gadget console not yet opened at the time
the idle task file descriptors are set up) stdio nxinit itself has.

Add a "console [<device>]" service option: a service declared with it
gets the given device (CONFIG_SYSTEM_NXINIT_CONSOLE_DEV, "/dev/console"
by default, if no device is given) opened and dup'd onto its stdin,
stdout and stderr via posix_spawn_file_actions before it is spawned.
This does not depend on nsh being enabled at all.

For a USB gadget console, the device does not exist until the gadget
is actually registered; boards using one are expected to bring it up
themselves before any service using "console" is started (e.g. via an
"exec -- sercon" action in their init.rc, since apps/system/cdcacm
already implements exactly that registration step and does not depend
on nxinit or nsh either).

console_file_actions() runs after the previous commit's time_started
update, so a failure to build the console's file actions is covered by
the same up to date timestamp - no separate clock_gettime() call is
needed on this failure path.

Covered by a new unit test, test_nxinit_service_console_option, that
exercises the option with and without an explicit device, and confirms
services without the option are left untouched.

Assisted-by: Kiro:claude-sonnet-5
Signed-off-by: wangjianyu3 <wangjianyu3@xiaomi.com>
2026-09-10 23:12:06 +08:00
wangjianyu3
a90c12b6da system/nxinit: retry a service whose spawn failed
init_service_refresh() ignored the return value of init_service_start().
If spawning a restarting service failed for any reason (e.g.
posix_spawnp() itself failing), the service stayed SVC_RESTARTING
forever with nothing left to re-arm its retry timer: this function's
return value drives the poll timeout in the caller's event loop
(main()), and a failed spawn does not fork a child, so there is no
SIGCHLD either to wake it up some other way. If this service happens
to be the only pending timer, the poll blocks indefinitely and the
service is never attempted again.

Check the return value and, on failure, feed the service restart
period into the poll timeout computed by this function, the same way
a successfully started/still-restarting service already does.

Also move the CLOCK_MONOTONIC read that updates a service's
time_started from after a successful spawn to before the spawn is
even attempted, so that time_started stays current on a failed spawn
too - otherwise, once woken up (by the fix above or by an unrelated
event), a repeatedly failing service would look permanently overdue
(elapsed time computed against a stale timestamp) and get retried
immediately regardless of its restart_period.

Assisted-by: Kiro:claude-sonnet-5
Signed-off-by: wangjianyu3 <wangjianyu3@xiaomi.com>
2026-09-10 23:12:06 +08:00
wangjianyu3
3b86850d27 system/nxinit: fix missing blank line after declaration in service.c
nxstyle flags a missing blank line between the declaration of "s" and
the first statement in option_reboot_on_failure(); pre-existing,
unrelated to any behavioral change here.

Assisted-by: Kiro:claude-sonnet-5
Signed-off-by: wangjianyu3 <wangjianyu3@xiaomi.com>
2026-09-10 23:12:06 +08:00
Junbo Zheng
46b8774f7f system/grep: Add grep command with regex support
Add a standalone grep application under apps/system/grep/. It uses the
NuttX libc regex library (regcomp/regexec) to support -i, -n, -v, -r,
-H and -h options plus stdin input and recursive directory search.

SYSTEM_GREP depends on LIBC_REGEX, so the regex library must be enabled
first -- CONFIG_SYSTEM_GREP only becomes selectable once LIBC_REGEX is
turned on.

Signed-off-by: Junbo Zheng <zhengjunbo1@xiaomi.com>
2026-09-09 10:34:10 +08:00
wangjianyu3
63698738a8 system/nxinit: add cmocka unit tests for parser/action/service
Add a test/ subdirectory (mirroring apps/system/uorb/test/) with
cmocka-based unit tests covering the NxInit logic most prone to
regression:

- init_parse_arguments(): plain/quoted arguments, "--" separator vs.
  "--option" long options (regression coverage for a previously fixed
  bug), argv-capacity truncation (asserting the exact folded contents
  of the last slot, not just its presence).
- init_parse_config_file()/init_parse_config_lines()/
  init_parse_config_buffer(): section routing, blank/whitespace-only
  line skipping, unknown-section rejection, over-length line rejection,
  and a line straddling two read-buffer refills, exercised through both
  the file-based and buffer-based entry points.
- Action event matching: exact match, invert (!=), fnmatch wildcards,
  and AND semantics across multiple events per action.
- Service conflict detection: duplicate service name rejection,
  override replacing an earlier duplicate, and the SERVICE_ARGS_MAX
  boundary built dynamically from CONFIG_SYSTEM_NXINIT_SERVICE_ARGS_MAX
  rather than a hardcoded value.

Test sources compile action.c/parser.c/service.c a second time into a
separate nxinit_unit_test program, gated behind new
CONFIG_SYSTEM_NXINIT_TEST (depends on TESTING_CMOCKA); the default init
program is unaffected. The CMake path builds a dedicated
nxinit_unit_test target (with test/test_nxinit.c placed first in SRCS
so nuttx_add_application() renames its main() correctly); the Make path
appends the test sources into the shared CSRCS list.

Supporting bits required to make the suite exercise the real code:

- init_parse_config_buffer() is declared in parser.h and made
  non-static so the buffer-based boundary test can call it directly,
  alongside the existing init_parse_config_file() entry point.
- CONFIG_SYSTEM_NXINIT_ACTION_EVENTS_MAX default is raised from 1 to 2
  so an action can carry more than one event ("on evA && evB"), which
  the multi-event AND-semantics test exercises; a single event slot
  made that test dead code.
- CONFIG_SYSTEM_NXINIT_TEST_STACKSIZE defaults to 8192: several parser
  test cases build multi-hundred-byte stack buffers on top of cmocka's
  own overhead, and the previous DEFAULT_TASK_STACKSIZE (2048)
  overflowed the test task's stack silently on real hardware (no crash
  dump, no watchdog reset, output just stopped) partway through the
  suite.

Testing:
Built via `make CROSSDEV=riscv-none-elf-` for
esp32p4-pico-wifi-wareshare:nsh (CONFIG_SYSTEM_NXINIT_TEST=y) and ran
nxinit_unit_test on real esp32p4-pico-wifi-wareshare hardware over
UART:

  nsh> nxinit_unit_test
  [==========] nxinit_tests: Running 18 test(s).
  ...
  [==========] nxinit_tests: 18 test(s) run.
  [  PASSED  ] 18 test(s).

nxstyle clean on all touched files.

Assisted-by: GitHubCopilot:claude-sonnet-5
Signed-off-by: wangjianyu3 <wangjianyu3@xiaomi.com>
2026-08-28 09:33:47 -03:00
wangjianyu3
7a1c6aaa7c system/nxinit: fix stack-buffer-overflow in init_parse_config_buffer
init_parse_config_buffer() computed the per-refill copy length as
MIN(len - off, sizeof(tmp)) without subtracting the 'n' leftover bytes
already held at the front of 'tmp' from a previous refill, so
memcpy(&tmp[n], ..., r) could write past the end of tmp[]. The
file-based twin, init_parse_config_file(), already gets this right
(read(fd, &buf[n], sizeof(buf) - n)).

Reproduced locally with an AddressSanitizer host harness feeding the
real 95-byte builtin "preset" rc content through
init_parse_config_buffer() at CONFIG_SYSTEM_NXINIT_RC_LINE_MAX=32/48:
ASan reports a stack-buffer-overflow on the 'tmp' array. Fixed to
MIN(len - off, sizeof(tmp) - n) and reverified clean at
RC_LINE_MAX=32/48/64/128.

The default config never hits this (the builtin preset is 95 bytes and
the default RC_LINE_MAX is 128), but SYSTEM_NXINIT_RC_LINE_MAX had no
lower bound, so lowering it towards 32/48 for a smaller build would
silently corrupt the stack while parsing the preset during boot. Add a
"range 64 4096" bound so the value can no longer be set below the
builtin preset's needs.

Assisted-by: opencode:mimo-v2.5-pro
Signed-off-by: wangjianyu3 <wangjianyu3@xiaomi.com>
2026-08-28 09:33:47 -03:00
wangjianyu3
a31fe191fa system/nxinit: fix missing blank line after declaration in parser.c
init_parse_config_file() declares 'r' inside the read loop with no
blank line before the following 'if (r < 0)' statement, violating the
NuttX coding standard (nxstyle: "Missing blank line after
declarations"). checkpatch.sh runs a whole-file nxstyle check on any
file a commit touches, not diff-only, so this pre-existing issue
surfaced on this PR's CI once parser.c was touched again.

Assisted-by: GitHubCopilot:claude-sonnet-5
Signed-off-by: wangjianyu3 <wangjianyu3@xiaomi.com>
2026-08-28 09:33:47 -03:00
wangjianyu3
5c3f14ae76 system/nxinit: fix truncated line loss in config parser
init_parse_config_lines() had a dead early "continue" for a truly
empty line (buf == "\0") that skipped the memmove() bookkeeping its
sibling whitespace-only-line branch performs. When a real empty line
appeared mid-buffer, subsequent bytes were never shifted to the front
of the working buffer, corrupting the remaining-length tracking and
silently dropping every line after it for that refill chunk.

The whitespace-skip loop right below already handles the empty-string
case correctly (the loop body never executes, so it falls straight
into the "only whitespace" -> memmove -> continue path), so the buggy
early exit is simply redundant and removed.

Assisted-by: GitHubCopilot:claude-sonnet-5
Signed-off-by: wangjianyu3 <wangjianyu3@xiaomi.com>
2026-08-28 09:33:47 -03:00
wangjianyu3
11c1c6bece system/nxinit: add 'set' builtin command for environment variables
Previously, 'set KEY VALUE' in init.rc was not recognized as a builtin
command. It fell through to posix_spawnp(), which ran it in a
temporary child shell. The environment variable was set only in the
child process and lost when it exited, so services started afterward
never inherited it.

Register cmd_set as an init builtin that calls setenv(key, value, 1)
directly in the init process. The command takes exactly 2 arguments
(key and value). All code is guarded by CONFIG_DISABLE_ENVIRON so it
compiles out when environment support is disabled.

Since child processes inherit init's environment, 'set TZ Asia/Shanghai'
in init.rc now correctly propagates to all subsequently started
services.

Signed-off-by: wangjianyu3 <wangjianyu3@xiaomi.com>
2026-08-28 09:30:53 -03:00
wangjianyu3
ec33a924a5 system/nxinit: increase SERVICE_ARGS_MAX default to 16
The previous default of 8 is insufficient for services with many
arguments (e.g. ptpd needs 10 argv slots). When exceeded, argv lacks
a NULL terminator, causing posix_spawnp to read out of bounds.

Increase default to 16 to prevent argument truncation for typical
daemon services.

Signed-off-by: wangjianyu3 <wangjianyu3@xiaomi.com>
2026-08-28 09:30:53 -03:00
zhengyu16
9cda1fbb60 fs: rename PSEUDOFS_SOFTLINKS to FS_LINKS
The link support is no longer limited to the pseudo file system and now
covers both soft (symbolic) links and hard links across the VFS.  Update
all references to the renamed configuration option PSEUDOFS_SOFTLINKS,
which has been renamed to FS_LINKS in the NuttX kernel, so that nshlib,
the interpreters, adb, tlpi and the test suites keep building.

This must be merged together with the corresponding NuttX change that
performs the actual kernel-side rename.

Signed-off-by: zhengyu16 <zhengyu16@xiaomi.com>
2026-08-27 13:31:34 +08:00
wangjianyu3
82eb73da76 system/nxinit: fix unkown -> unknown typo in resetcause[]
codespell flagged this in PR #3751 CI:
  system/nxinit/init.c:119: unkown ==> unknown
  system/nxinit/init.c:130: unkown ==> unknown

Both entries were introduced by the resetcause-for-triggers commit and
are unrelated to the earlier nxstyle regression already discussed on
the PR.

Assisted-by: GitHubCopilot:claude-sonnet-5
Signed-off-by: wangjianyu3 <wangjianyu3@xiaomi.com>
2026-08-26 10:00:02 -03:00
wangjianyu3
c91fe7bf01 system/nxinit: Add missing "assert" entry to resetflag
Add the missing mapping entries in the resetflag[] array to prevent
potential NULL pointer dereference when accessing reset.flag.

The resetflag array uses designated initializers and must have entries
for all BOARDIOC_SOFTRESETCAUSE_* values to avoid array holes.

Reported by: xuchuntian@xiaomi.com
Signed-off-by: wangjianyu3 <wangjianyu3@xiaomi.com>
2026-08-26 10:00:02 -03:00
wangjianyu3
ee32ebda06 system/nxinit: Add subreason for sys.boot.reason
init.rc

  on init && property:sys.boot.reason=watchdog,4
     ...

  on init && property:sys.boot.reason=bootloader|recovery|thermal
     ...

Test

  cause->cause = BOARDIOC_RESETCAUSE_CPU_RWDT;
  cause->flag  = 4
  init_main: setprop key:sys.boot.reason value:watchdog,4

  cause->cause = BOARDIOC_RESETCAUSE_CPU_SOFT;
  cause->flag  = BOARDIOC_SOFTRESETCAUSE_ENTER_BOOTLOADER;
  init_main: setprop key:sys.boot.reason value:bootloader

Signed-off-by: wangjianyu3 <wangjianyu3@xiaomi.com>
2026-08-26 10:00:02 -03:00
wangjianyu3
fd35a05249 system/nxinit: Add resetcause for triggers
Add built-in property sys.boot.reason, which allows action triggers to be
executed on specific reset cause.

For example:
  ```
  on property:sys.boot.reason=cpu_soft_reset(bootloader)
      echo "bootloader mode ..."
      start fastboot
  ```

Signed-off-by: wangjianyu3 <wangjianyu3@xiaomi.com>
2026-08-26 10:00:02 -03:00
fangpeina
4cb0068732 system/nxinit: support compound command execution
Example in init.rc:
  echo "start" && hello && echo "done"
  ls /missing || echo "not found"
  echo "A" && echo "B" || echo "fallback"

Signed-off-by: fangpeina <fangpeina@xiaomi.com>
2026-08-26 10:00:02 -03:00
raiden00pl
9545e12054 system/readline: add caller-selectable control handling
Let CPython handle Ctrl-D and signals without changing existing NSH behavior.

Signed-off-by: raiden00pl <raiden00@railab.me>
Assisted-by: Claude Code
2026-08-24 22:15:31 +08:00
wangjianyu3
0923948d80 system/nxinit: fix event-board timing
Move the boot event orchestration into a preset config buffer so the
"init" and (optional) "netinit"/"finalinit" events are triggered as a
serialized chain rather than queued back-to-back in main(). This fixes
the timing between preset event initialization and board initialization.

Adapted for the community tree: BOARDIOC_INIT has been removed upstream
(replaced by CONFIG_BOARD_LATE_INITIALIZE), so no board_init/board_finalinit
builtins are added and no boardctl(BOARDIOC_INIT)/boardctl(BOARDIOC_FINALINIT)
calls are reintroduced; board device init is now performed by the kernel
before init starts.

netinit is not a boardctl call, so it is kept in the serialized event
chain like the original: add a "netinit" builtin that calls
netinit_bringup(), driven by "on init -> trigger netinit -> on netinit",
instead of calling netinit_bringup() directly in main(). finalinit
remains a pure event for user-defined services to hook.

Assisted-by: GitHubCopilot:claude-opus-4.8
Signed-off-by: wangjianyu3 <wangjianyu3@xiaomi.com>
2026-08-24 20:11:14 +08:00
jingfei
6d178011d5 system/nxinit: Add start_cpu support for action
Add support for starting a cpu's software.
Depends on `BOARDCTL_START_CPU`.

Signed-off-by: jingfei <jingfei@xiaomi.com>
2026-08-24 20:11:14 +08:00
wangjianyu3
a485d9636b system/nxinit: Add boot support for action
Add support for booting a new application firmware image.
Depends on `BOARDCTL_BOOT_IMAGE`.

When the built-in boot command of nsh is enabled, the built-in boot
command of Init will take precedence (see init_builtin_run()). To use
the built-in boot command of nsh, use: `exec -- sh boot [args...]`.

Referred to nshlib/nsh_syscmds.c: cmd_boot()

Signed-off-by: wangjianyu3 <wangjianyu3@xiaomi.com>
2026-08-24 20:11:14 +08:00
wangjianyu3
e0a1031bcc system/nxinit: add check loop to init_parse_config_buffer
Add the parser[n].check validation loop to init_parse_config_buffer(),
matching the same pattern already used in init_parse_config_file().
This ensures that services and actions parsed from in-memory buffers
are properly validated after parsing.

Signed-off-by: wangjianyu3 <wangjianyu3@xiaomi.com>
2026-08-24 20:11:14 +08:00
wangjianyu3
63eb6c79f2 system/nxinit: Extract init_parse_config_buffer()
Extract the init_parse_config_buffer() interface from the init_parse_config_file() function.

Signed-off-by: wangjianyu3 <wangjianyu3@xiaomi.com>
2026-08-24 20:11:14 +08:00
raiden00pl
96f6e7d460 system/readline: restore terminal attributes safely
Track successful mode changes so failed setup cannot corrupt terminal state.

Signed-off-by: raiden00pl <raiden00@railab.me>
Assisted-by: Claude Code
2026-08-22 08:45:03 -03:00
wangjianyu3
247a8c03cb system/nxinit: fix argument parser treating --option as -- separator
The init_parse_arguments() function checked for '--' by only
comparing the first two characters, causing options like --system,
--nofork to be misinterpreted as the '--' argument separator. This
truncated the remaining arguments. Add an isblank() check on the
third character to ensure only standalone '--' followed by whitespace
triggers the separator logic.

Assisted-by: GitHubCopilot:claude-4.6-opus
Signed-off-by: wangjianyu3 <wangjianyu3@xiaomi.com>
2026-08-22 17:36:04 +08:00
wangjianyu3
8ff98a6b51 system/nxinit: Parse default cpu-specific configs
On the basis of init.rc, add default parsing of cpu-specific configs.
- /etc/init.d/init.rc
- /etc/init.d/init.cpu${CPUID}.rc

Refactor function `init_parse_configs()` to parse files from the default path
instead of identifying and parsing directories or files, as the functionality
is unnecessary.

Signed-off-by: wangjianyu3 <wangjianyu3@xiaomi.com>
2026-08-22 17:36:04 +08:00
raiden00pl
e21cf5c292 system/expat: add reusable XML parser package
add reusable XML parser package

Signed-off-by: raiden00pl <raiden00@railab.me>
Assisted-by: OpenAI Codex:gpt-5
2026-08-21 20:09:58 +08:00
aviralgarg05
0eb44a1085 system/nxstore: add an LVGL app-store front end
Add an LVGL front end for browsing, installing, updating, and launching nxpkg entries. Keep network and install work off the UI path, and stop launched apps with SIGTERM.

Signed-off-by: aviralgarg05 <gargaviral99@gmail.com>
2026-08-18 15:23:15 -03:00
aviralgarg05
2fcb2dfbdd system/nxpkg: complete the package lifecycle
Add the remaining package commands. Order database and payload updates so failures do not leave stale version pointers.

Signed-off-by: aviralgarg05 <gargaviral99@gmail.com>
2026-08-17 09:20:57 -03:00
aviralgarg05
c4fd2b9b0e system/nxpkg: fetch repositories over HTTP
Download catalogs and artifacts with bounded buffers and atomic staging. Prepare storage before taking the lock so first-run syncs are safe.

Signed-off-by: aviralgarg05 <gargaviral99@gmail.com>
2026-08-17 09:20:39 -03:00
aviralgarg05
0717e05248 system/nxpkg: validate catalog and database contents
Validate package fields before using them and ensure version pointers refer to installed entries. Keep installed manifests available for rollback.

Signed-off-by: aviralgarg05 <gargaviral99@gmail.com>
2026-08-17 09:20:22 -03:00
aviralgarg05
d0c15c8c87 system/nxpkg: make package storage crash-safe
Make the nxpkg storage root configurable and write owned files through temporary paths before renaming them. Record lock ownership so processes can recover abandoned locks safely.

Signed-off-by: aviralgarg05 <gargaviral99@gmail.com>
2026-08-17 09:13:41 -03:00