arch/arm/rp23xx: Check the flash MTD region against the flash size.
Some checks are pending
Build Documentation / build-html (push) Waiting to run
MemBrowse Memory Report / changes-filter (push) Waiting to run
MemBrowse Memory Report / load-targets (push) Waiting to run
MemBrowse Memory Report / identical (push) Blocked by required conditions
MemBrowse Memory Report / analyze (push) Blocked by required conditions

RP23XX_FLASH_MTD_OFFSET and RP23XX_FLASH_MTD_SIZE come from Kconfig.
If the region ends past the end of the flash, the flash wraps the
address around, and an erase or program hits the start of the flash,
where the NuttX image is.  For example, a 4M region at 1M does not
fit on the 4M flash of a Raspberry Pi Pico 2.

Read the JEDEC ID at initialization, in QMI direct mode as the Pico
SDK flash_do_cmd() does, and refuse a region that does not fit.  The
capacity byte is log2 of the size in bytes.  If the ID does not look
valid, warn and do not check.

Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
This commit is contained in:
Marco Casaroli 2026-10-07 09:19:12 +02:00 • committed by Alan C. Assis
parent cb87f99b6e
commit e7f9aaa52b
3 changed files with 123 additions and 4 deletions

View file

@ -322,7 +322,9 @@ The region is described by ``RP23XX_FLASH_MTD_OFFSET`` (byte offset from
``0x10000000``) and ``RP23XX_FLASH_MTD_SIZE``, both of which must be multiples
of the 4096 byte erase sector. The driver refuses to initialize if the region
would overlap the NuttX image (it checks ``__flash_binary_end``), so a bad
offset fails at boot instead of corrupting the running firmware.
offset fails at boot instead of corrupting the running firmware. It also
reads the flash size from the JEDEC ID and refuses a region that ends past the
end of the flash, because such an address wraps around to the image.
Erase and program go through the bootrom flash routines. Because those
operations stall instruction fetch from the same flash, the driver runs them