sensor_poll() arms a per-subscriber watchdog for fetch()-only sensors
with a requested interval. The watchdog handler sensor_fetch_expired()
dereferences the subscriber and re-arms itself unless user->fds is NULL.
sensor_poll() teardown clears user->fds and cancels the watchdog, but
sensor_close() removed the subscriber from the user list and freed it
without doing either. A close() racing an armed timer therefore lets
the handler run after the subscriber is freed, causing a timer-context
use-after-free and re-arm of a freed watchdog.
Mirror the poll teardown in sensor_close(): clear user->fds and cancel
user->wdog under upper->lock before notifying other users and freeing
the subscriber.
Fixes#20145.
Signed-off-by: arnavsharma990 <2006arnavsharma@gmail.com>
Document the Python format and lint tools enforced by checkpatch.sh and CI,
and show how to run the existing Python auto-format path.
Assisted-by: ChatGPT:gpt-5.6-sol
Signed-off-by: Taha Zarif <tahazarif380@gmail.com>
atexit_call_exitfuncs() cached its loop bound on entry
(for (idx = aehead->nfuncs - 1; idx >= 0; idx--)), while
atexit_register() appends new entries at funcs[nfuncs] and bumps nfuncs.
Any function registered by an exit handler via atexit() / on_exit() /
__cxa_atexit() lands above the cached bound and is never invoked, even
though the registration returns OK.
This contradicts the exit(3) documentation that NuttX mirrors verbatim
in its own exit() docstring (libs/libc/stdlib/lib_exit.c):
It is possible for one of these functions to use atexit(3) or
on_exit(3) to register an additional function to be executed
during exit processing; the new registration is added to the
front of the list of functions that remain to be called.
The same restructure closes a second defect: atexit_call_exitfuncs()
read and cleared the task-group-shared ta_exit list without holding
ta_lock, while atexit_register() takes it ("The following must be
atomic"). Entries are now claimed under the lock and the handler is
invoked with the lock released, so a handler re-entering
atexit_register() cannot deadlock (also safe with the non-recursive
nxmutex used here).
Evidence: exit(3) man page, DESCRIPTION -
https://man7.org/linux/man-pages/man3/exit.3.html
NuttX mirrors this passage verbatim in its own exit() docstring --
5a209a853e/libs/libc/stdlib/lib_exit.c (L65-L70)
Before:
```
A handler that registers another function during exit processing
gets a success return from atexit(), but the new function is never
invoked - it lands above the loop bound cached on entry.
```
After:
```
A registration made during exit processing runs before the older
remaining handlers (order A -> B -> C below), matching the exit(3)
guarantee, and the list is consumed under ta_lock.
```
Testing:
Simulated (sim:nsh, CONFIG_LIBC_MAX_EXITFUNS=8).
Build and run:
```
cmake -B build -DBOARD_CONFIG=sim:nsh -GNinja
cmake -S . -B build # after setting CONFIG_LIBC_MAX_EXITFUNS=8
# in build/.config (sim:nsh default is 1)
cmake --build build -j$(nproc)
(echo hello; echo poweroff) | ./build/nuttx
```
"hello" runs the test at the NSH prompt; poweroff terminates the sim.
The test was carried by apps/examples/hello/hello_main.c (scratch only,
not part of this commit); its diff:
```
--- a/examples/hello/hello_main.c
+++ b/examples/hello/hello_main.c
@@ -24,6 +24,7 @@
#include <nuttx/config.h>
#include <stdio.h>
+#include <stdlib.h>
/****************************************************************************
* Public Functions
@@ -33,8 +34,29 @@
* hello_main
****************************************************************************/
+static void handler_b(void)
+{
+ printf("ATEXIT-TEST: handler B called (registered during exit)\n");
+}
+
+static void handler_a(void)
+{
+ int ret;
+
+ printf("ATEXIT-TEST: handler A called\n");
+ ret = atexit(handler_b);
+ printf("ATEXIT-TEST: atexit(handler_b) inside A returned %d\n", ret);
+}
+
+static void handler_c(void)
+{
+ printf("ATEXIT-TEST: handler C called\n");
+}
+
int main(int argc, FAR char *argv[])
{
printf("Hello, World!!\n");
+ atexit(handler_c); /* older entry, must run LAST */
+ atexit(handler_a); /* registers handler_b during exit */
return 0;
}
```
Before the fix:
```
Hello, World!!
ATEXIT-TEST: handler A called
ATEXIT-TEST: atexit(handler_b) inside A returned 0
ATEXIT-TEST: handler C called
```
(handler B is never invoked although its registration returned 0)
After the fix:
```
Hello, World!!
ATEXIT-TEST: handler A called
ATEXIT-TEST: atexit(handler_b) inside A returned 0
ATEXIT-TEST: handler B called (registered during exit)
ATEXIT-TEST: handler C called
```
Assisted-by: Claude Code (GLM-5.3) <claude@anthropic.com>
Signed-off-by: Junbo Zheng <zhengjunbo1@xiaomi.com>
strlcpy() was given sizeof(tcb->name), i.e. CONFIG_TASK_NAME_SIZE + 1,
but the documented caller contract is a buffer of CONFIG_TASK_NAME_SIZE
bytes (include/sys/prctl.h). When a task name is exactly
CONFIG_TASK_NAME_SIZE chars (the normal result of nxtask_setup_name()
truncation), the terminating NUL lands one byte past the caller buffer.
Pass CONFIG_TASK_NAME_SIZE to strlcpy() so the copy is truncated
in-bounds, and drop the stale forced-NUL line left over from the strncpy
era (it ran after the overflow had already happened).
Before:
```
guard byte placed right after a CONFIG_TASK_NAME_SIZE caller buffer
reads 0x00 (expected 0xAA) after the call: strlcpy writes its
terminating NUL one byte past the buffer when the task name is exactly
CONFIG_TASK_NAME_SIZE chars.
```
After:
```
strlcpy(name, tcb->name, CONFIG_TASK_NAME_SIZE) writes at most
CONFIG_TASK_NAME_SIZE bytes; the caller buffer stays intact.
```
Testing:
Simulated (sim:nsh, CONFIG_TASK_NAME_SIZE=31).
Build and run:
```
cmake -B build -DBOARD_CONFIG=sim:nsh -GNinja
cmake --build build -j$(nproc)
echo hello | ./build/nuttx
```
then run "hello" at the NSH prompt.
The test was carried by apps/examples/hello/hello_main.c (scratch only,
not part of this commit); its diff:
```
--- a/examples/hello/hello_main.c
+++ b/examples/hello/hello_main.c
@@ -24,6 +24,8 @@
#include <nuttx/config.h>
#include <stdio.h>
+#include <string.h>
+#include <sys/prctl.h>
/****************************************************************************
* Public Functions
@@ -35,6 +37,55 @@
int main(int argc, FAR char *argv[])
{
+ /* Longest-legal task name: exactly CONFIG_TASK_NAME_SIZE chars, the
+ * normal result of nxtask_setup_name() truncation.
+ */
+
+ static const char longname[] =
+ "0123456789ABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789";
+
+ /* Caller buffer per the documented prctl(PR_GET_NAME) contract, with a
+ * guard byte immediately after it to detect the 1-byte overflow.
+ */
+
+ struct
+ {
+ char buf[CONFIG_TASK_NAME_SIZE];
+ volatile unsigned char guard;
+ } s;
+
+ _Static_assert(sizeof(longname) - 1 > CONFIG_TASK_NAME_SIZE,
+ "test name must exceed CONFIG_TASK_NAME_SIZE");
+
printf("Hello, World!!\n");
+ printf("prctl test: CONFIG_TASK_NAME_SIZE=%d\n", CONFIG_TASK_NAME_SIZE);
+
+ s.guard = 0xaa;
+ s.buf[0] = '\0';
+
+ if (prctl(PR_SET_NAME, (unsigned long)longname) != 0)
+ {
+ printf("prctl test: PR_SET_NAME failed\n");
+ return 1;
+ }
+
+ if (prctl(PR_GET_NAME, (unsigned long)s.buf) != 0)
+ {
+ printf("prctl test: PR_GET_NAME failed\n");
+ return 1;
+ }
+
+ printf("prctl test: guard=0x%02x (expected 0xaa), name len=%zu, "
+ "last char=0x%02x\n",
s.guard, strlen(s.buf), (unsigned char)s.buf[strlen(s.buf)]);
+
+ if (s.guard != 0xaa)
+ {
+ printf("prctl test: FAIL - terminating NUL written 1 byte past "
+ "the caller buffer\n");
+ return 1;
+ }
+
+ printf("prctl test: PASS - caller buffer intact\n");
return 0;
}
```
Before the fix:
```
prctl test: guard=0x00 (expected 0xaa), name len=30, last char=0x00
prctl test: FAIL - terminating NUL written 1 byte past the caller buffer
```
After the fix:
```
prctl test: guard=0xaa (expected 0xaa), name len=30, last char=0x00
prctl test: PASS - caller buffer intact
```
Assisted-by: Claude Code (GLM-5.3) <claude@anthropic.com>
Signed-off-by: Junbo Zheng <zhengjunbo1@xiaomi.com>
The compilation of stm32_mpuinit.c is guarded by CMakeLists.txt and
Make.defs, so this is unneccessary.
Signed-off-by: Darryl Ring <darryl@bluerobotics.com>
If CONFIG_ARM_MPU and CONFIG_STM32_ICACHE are set, this will configure an
MPU region marking the OTP flash as non-cacheable. This prevents hard faults
when accessing the 4K OTP region from software.
Signed-off-by: Darryl Ring <darryl@bluerobotics.ca>
This adds MPU initialization code based on the STM32U5. Unlike the
STM32U5 code, though, this allows the MPU to be used outside of
PROTECTED build mode.
PROTECTED build mode is still not yet supported.
Assisted-by: Claude:claude-sonnet-5
Signed-off-by: Darryl Ring <darryl@bluerobotics.com>
Add a Peripheral Support section to the board page listing the GPIO and
MCU_MCSPI0 drivers, and replace the "UART console only" warning on both
the chip and board pages -- it no longer describes the port. The
replacement states what actually constrains the port: NuttX runs on the
R5F under RemoteProc and depends on the bootloader or Linux Device
Manager having powered and clocked the peripherals, because there is no
TISCI client yet.
Assisted-by: Claude Code:claude-opus-5
Signed-off-by: Ulaş Sertan Kemeç <sertan.usk@gmail.com>
Adds the AM67 GPIO lower half and a polled MCU_MCSPI0 master driver, with the
pad configuration both need. The K3 instance is not the OMAP2 layout: an HL
header block precedes the functional registers.
Chip select is released only after CHSTAT.EOT, since a high SCLK otherwise
drops it mid-word and truncates the write, and CHCTRL.EN stays asserted between
transfers.
t3-gem-o1 registers /dev/spi0 for its ICM-20948 (CS3) and LPS22DF (CS1), and
raises NSH_MAXARGUMENTS to 16 so the spi tool can address a device.
Verified on t3-gem-o1: WHO_AM_I reads 0xEA on CS3 and 0xB4 on CS1, and the
ICM-20948 streams continuous accelerometer samples over the bus.
Co-authored-by: Ulaş Sertan Kemeç <sertan.usk@gmail.com>
Assisted-by: Cursor
Assisted-by: Claude Code:claude-opus-4-8
Signed-off-by: Ulaş Sertan Kemeç <sertan.usk@gmail.com>
config.h and CONFIG_* are produced at configure time. kconfig-tweak
edits .config without going through the menuconfig target, so Ninja
left a stale header. Watch .config with CMAKE_CONFIGURE_DEPENDS.
Fixesapache/nuttx#12322
Signed-off-by: Zhaoqi Xu <lzy00419@outlook.com>
APB1 bit 16 is CRS, not CRC (CRC is on AHB). RCC_CRRCR only holds the
HSIUSB48 calibration; the HSIUSB48 enable lives in RCC_CR.
Assisted-by: Claude Code
Signed-off-by: raiden00pl <raiden00@railab.me>
Gate the 32-bit USB DRD FS path of the common M0 usbdev driver on
STM32_HAVE_IP_USBDEV_M0_V2 instead of the STM32G0 family symbol.
Assisted-by: Claude Code
Signed-off-by: raiden00pl <raiden00@railab.me>
The new CONFIG_FS_AIO_LISTIO_MAX option defaults to 10 and lio_listio()
now rejects nent > {AIO_LISTIO_MAX} with EINVAL. The LTP release pinned
by apps/testing/ltp (20230516) submits 256 requests in a single batch from
conformance/interfaces/lio_listio/2-1.c, so ltp_interfaces_lio_listio_2_1
now fails on every configuration that enables CONFIG_TESTING_LTP
(sim:citest, rv-virt:citest, sim:posix_test):
lio_listio/2-1.c Error at lio_listio() 22: Invalid argument
The EINVAL check itself is required by POSIX, so keep it and raise the
default instead; the limit no longer costs memory because the requests are
linked through the aiocb's own lio_link.
While here, keep _POSIX_AIO_LISTIO_MAX at its POSIX-mandated value of 2
and let AIO_LISTIO_MAX carry the configurable implementation limit.
Signed-off-by: Xiang Xiao <xiaoxiang@xiaomi.com>
aio_fsync()/aio_read()/aio_write()/lio_listio() initialized
aiocbp->lio_link with list_initialize(), which makes the node
self-referential (prev = next = &node). aio_signal() tests
list_in_list(&lio_link) to detect lio_listio batches, so it wrongly
entered the lio_listio completion path for every standalone AIO
operation and notified through the uninitialized
lio_sigevent/lio_sigwork.
With CONFIG_SIG_EVTHREAD=y, garbage lio_sigevent.sigev_notify ==
SIGEV_THREAD caused nxsig_notification() to queue &lio_sigwork.work
onto the low-priority work queue with garbage func/value. After the
aiocb was freed, the dangling work_s was dispatched with worker=NULL,
crashing in work_dispatch().
Fix: initialize lio_link with list_clear_node() (prev = next = NULL)
so list_in_list() returns false for non-lio_listio operations and
aio_signal() skips the lio_listio path.
While there, reject a NULL aiocbp in aio_fsync(): POSIX Issue 6 no
longer defines a NULL special case, and the old DEBUGASSERT() panicked
debug builds.
Co-developed-by: dengwenqi <dengwenqi@xiaomi.com>
Co-developed-by: fangxinyong <fangxinyong@xiaomi.com>
Signed-off-by: fangxinyong <fangxinyong@xiaomi.com>
Signed-off-by: dengwenqi <dengwenqi@xiaomi.com>
Signed-off-by: Xiang Xiao <xiaoxiang@xiaomi.com>
lio_listio() links each aiocbp->lio_link into its batch list before
submitting the I/O, but submitted the operations through the public
aio_read()/aio_write(), which re-initialized lio_link and destroyed
the list membership. With an aiocb pre-filled with garbage (as in
ostest), the completion path then walked an invalid list.
Extract aio_read_internal()/aio_write_internal() that skip the
lio_link setup; aio_read()/aio_write() initialize lio_link (and
reject a NULL aiocbp) before calling the internal functions, while
lio_listio() calls the internal functions directly to preserve its
own lio_link setup. For entries that are not part of a batch,
lio_listio() self-initializes lio_link instead.
Signed-off-by: Xiang Xiao <xiaoxiang@xiaomi.com>
aio_fsync() never initialized aiocbp->lio_link, but the reworked
aio_signal() tests list_in_list(&lio_link) on every completion. With
an uninitialized (or zero-filled) lio_link the behavior was
unpredictable; initialize the node so standalone fsync operations are
self-consistent.
Signed-off-by: tengshuangshuang <tengshuangshuang@xiaomi.com>
aio_suspend() checked the completion status once and then performed a
single sigtimedwait(). Any SIGPOLL delivered by an unrelated AIO
operation (one not referenced by 'list') woke the caller even though
none of the awaited requests had completed, and with a timeout the
remaining wait time was not preserved either.
Re-check the completion status after every wakeup and continue
waiting, recomputing the remaining time from the absolute deadline so
that the full timeout is honored.
Signed-off-by: wushenhui <wushenhui@xiaomi.com>
Per POSIX, aio_read() and aio_write() must return -1 and set errno to
EINVAL when the request cannot be queued (aio_reqprio < 0,
aio_offset < 0), and the error must also be retrievable via
aio_error(). Conversely, when queuing fails with a bad file
descriptor, the error belongs to the asynchronous operation: the
functions must return 0 and report EBADF through aio_error().
- Merge the offset/reqprio checks and return ERROR with errno set,
after storing the result in aio_result for aio_error().
- Drop the aio_fildes < 0 early return: a closed descriptor is now
caught by fcntl()/aio_queue() and reported through aio_result with
the function returning OK.
- aio_error(): report -EINVAL (failed validation) through errno
instead of returning it as an error value.
Signed-off-by: tengshuangshuang <tengshuangshuang@xiaomi.com>
aioc_decant() frees the AIO container and detaches the aiocbp. The
I/O workers (aio_read_worker, aio_write_worker, aio_fsync_worker)
called it before signaling completion, so aio_signal() and any code
touching the container afterwards ran on freed memory. Additionally,
if the caller closed the file early the detached container could be
reused with a stale file reference. Move aioc_decant() to after
aio_signal() and use aioc->aioc_aiocbp directly in the workers.
aio_cancel() also had two problems: with no aiocbp it looped over
g_aio_pending with a do/while that skipped the list re-entry check, so
a failed work_cancel() on an already running I/O caused an endless
loop; and an invalid fildes only checked 'fildes < 0' instead of
validating the descriptor, so a closed fd was not reported as EBADF.
Use a for-loop that always advances and validate the descriptor with
file_get()/file_put().
Co-developed-by: wushenhui <wushenhui@xiaomi.com>
Signed-off-by: wushenhui <wushenhui@xiaomi.com>
Signed-off-by: tengshuangshuang <tengshuangshuang@xiaomi.com>
lio_listio() never validated 'nent' against {AIO_LISTIO_MAX}, so a
batch larger than the documented limit was silently accepted, and the
hard-coded _POSIX_AIO_LISTIO_MAX value of 2 was too small for real
workloads (LTP uses 10 entries per call).
Add the FS_AIO_LISTIO_MAX Kconfig option (default 10), use it for
_POSIX_AIO_LISTIO_MAX in include/limits.h, validate 'nent' in
lio_listio(), and report the limit through sysconf(_SC_AIO_LISTIO_MAX).
Signed-off-by: tengshuangshuang <tengshuangshuang@xiaomi.com>
POSIX declares lio_listio() as:
int lio_listio(int, struct aiocb *restrict const [restrict], int,
struct sigevent *restrict);
Update the prototype in include/aio.h (and the implementation and
libc.csv entry) accordingly, and drop the parameter names from the
other aio_* prototypes for consistency.
Signed-off-by: guoshichao <guoshichao@xiaomi.com>
When a queued operation fails immediately (bad fd, EINVAL, or a failed
aio_read/aio_write submission), lio_listio() unconditionally deleted
the aiocbp from the request list. In LIO_WAIT mode (or when no sig was
requested) the lio_link nodes were never linked into the list, so
list_delete() corrupted memory and crashed.
Only unlink the node when it was actually linked, i.e. when
mode == LIO_NOWAIT and a sigevent was provided.
Signed-off-by: tengshuangshuang <tengshuangshuang@xiaomi.com>
When lio_listio() is called with LIO_NOWAIT and a non-NULL sig, and no
I/O could be queued (or all entries are LIO_NOP/NULL), the completion
notification dereferences a NULL aiocbp picked from an empty iteration,
crashing nxsig_notification().
Scan the list for any non-NULL entry before delivering the
notification, and skip it entirely when the list contains only NULL
entries.
Signed-off-by: zhengyu16 <zhengyu16@xiaomi.com>
Previously, lio_listio() called aio_read()/aio_write() to submit the
I/O and only then initialized the per-request notification state
(aio_priv based), so a worker thread could complete an operation before
that state was set up (thread-unsafe), and the completion notification
hijacked the per-request sigevent machinery.
Rework the implementation: lio_listio() now links every aiocb of the
batch into a list (lio_link) before any I/O is submitted. When an
operation completes, aio_signal() removes its node from the list under
aio_lock() and delivers the lio_listio completion notification only
when the list becomes empty. The unused aio_priv field is replaced by
the lio_link/lio_sigevent/lio_sigwork fields in struct aiocb.
Co-developed-by: wushenhui <wushenhui@xiaomi.com>
Signed-off-by: wushenhui <wushenhui@xiaomi.com>
Signed-off-by: Xiang Xiao <xiaoxiang@xiaomi.com>
lio_listio() submits I/O through the internal aio_read/aio_write
helpers and is only built when CONFIG_FS_AIO is enabled. Keeping it in
libs/libc splits one subsystem across two directories and forces fs/aio
to export internal interfaces to the libc build.
Move the file (and its two build system entries) from libs/libc/aio to
fs/aio so that the whole AIO implementation lives in one place.
Signed-off-by: Xiang Xiao <xiaoxiang@xiaomi.com>
Install the published NTFC 0.0.3 package from PyPI instead of the
temporary upstream main dependency.
Keep the retry loop and fail the job when all installation attempts are
exhausted.
Signed-off-by: raiden00pl <raiden00@railab.me>
Allow sim HCI socket users to select the host-side HCI target at runtime
with --bt-dev. Passing --bt-dev=hciN overrides CONFIG_SIM_HCISOCKET_DEVID
for the BlueZ HCI user channel, while omitting the option keeps the existing
configured default behavior.
Also allow --bt-dev=/path/to/socket to connect to an H:4 stream exposed
through a Unix-domain socket. This lets sim applications use a controller
provided by another host process or by a UART-to-Unix-socket bridge without
requiring BlueZ raw HCI privileges for the NuttX process.
Use host-side output for early --bt-dev parse errors, since NuttX stdio is
not initialized before nx_start().
Document the BlueZ and Unix socket modes, including the capability
requirements for BlueZ and the socat bridge example for Unix socket mode.
Testing:
Host: Ubuntu 22.04 x86_64
Board/config: sim:bthcisock
Style checks:
git diff --check HEAD~2..HEAD
PATH=/home/mi/bsim-auto-test/.venv/bin:$PATH \
./tools/checkpatch.sh -c -u -m -g HEAD~2..HEAD
Clean build:
make distclean
./tools/configure.sh -l -a ../../nuttx-apps sim:bthcisock
kconfig-tweak --file .config --set-val STACK_USAGE_WARNING 0
make olddefconfig
make -j16
Invalid runtime argument smoke test:
./nuttx --bt-dev=invalid
Verified the command exits with status 1 and reports the invalid target
without crashing before nx_start().
Unix socket HCI smoke test:
socat -d -d UNIX-LISTEN:/tmp/hci.sock,fork,reuseaddr \
/dev/ttyACM2,b1000000,raw,echo=0,crtscts=1
printf 'ifconfig\nbt bnep0 info\npoweroff\n' | \
timeout 20s ./nuttx --bt-dev=/tmp/hci.sock
Verified the sim registers the Bluetooth network device as bnep0 and
bt bnep0 info reads the controller state through the Unix-socket HCI
path, including BDAddr aa:bb:cc:dd:ee:ff from the attached controller.
Assisted-by: OpenAI Codex
Signed-off-by: Lingao Meng <menglingao@xiaomi.com>
Start the simulated HCI socket receive watchdog only after the host HCI
socket has been opened successfully. The previous code armed the watchdog
immediately after driver registration, before the Bluetooth stack opened the
driver and before the device had a valid host fd.
Cancel the watchdog on close/free and close any opened host fd during
allocation-failure cleanup. This keeps the polling path tied to the actual
socket lifetime and prevents the watchdog from polling an invalid host fd.
Testing:
Host: Ubuntu 22.04 x86_64
Board/config: sim:bthcisock
Style checks:
git diff --check HEAD~2..HEAD
PATH=/home/mi/bsim-auto-test/.venv/bin:$PATH \
./tools/checkpatch.sh -c -u -m -g HEAD~2..HEAD
Clean build:
make distclean
./tools/configure.sh -l -a ../../nuttx-apps sim:bthcisock
kconfig-tweak --file .config --set-val STACK_USAGE_WARNING 0
make olddefconfig
make -j16
Default startup smoke test:
printf 'poweroff\n' | timeout 10s ./nuttx
Verified the sim still reaches NSH and powers off cleanly. When no
host HCI controller is available through the default BlueZ target, the
board reports sim_bthcisock_register() failure and continues booting;
no invalid-fd watchdog crash occurs.
Assisted-by: OpenAI Codex
Signed-off-by: Lingao Meng <menglingao@xiaomi.com>
Add support for using a BabbleSim PHY as the monotonic time source for
the Linux sim target. When CONFIG_SIM_BSIM_TIME is enabled, the sim
host build links a small host-side time helper against the BabbleSim
PhyCom and Util libraries. The helper joins the BabbleSim PHY wait
protocol and advances NuttX monotonic time through PB_MSG_WAIT requests
instead of Linux wall-time sleeps.
A SIM binary built with CONFIG_SIM_BSIM_TIME enabled joins BabbleSim time
at startup. Runtime options allow the test runner to select the
BabbleSim simulation id, PHY id, and device number:
--sim-bsim-sid=<simulation-id>
--sim-bsim-pid=<phy-id>
--sim-bsim-dev=<device-number>
Keep the integration inside the sim host time path rather than exposing
a new application API. RTC/realtime reads still use the host realtime
clock; the BabbleSim source is used only for monotonic time after the sim
has joined the PHY. The Kconfig option depends on the sleep based
walltime mode and is disabled for SMP and non-Linux hosts.
The build requires BSIM_COMPONENTS_PATH for headers and either
BSIM_OUT_PATH or BSIM_LIBS_DIR for shared libraries. The path checks are
skipped for clean, distclean, clean_context, and context targets so a
tree with CONFIG_SIM_BSIM_TIME enabled can still be cleaned without
exporting the BabbleSim environment first.
Document the configuration, build environment, runtime options, and the
requirement that the BabbleSim PHY process is started separately by the
test runner.
Testing:
Host: Ubuntu 22.04 x86_64
Board/config: sim:nsh
Style check:
git diff --check
Default sim build and smoke test:
./tools/configure.sh -l -a ../nuttx-apps sim:nsh
make -j16
printf 'help\npoweroff\n' | timeout 20s ./nuttx
BabbleSim-enabled build:
kconfig-tweak --file .config \
-e SIM_WALLTIME_SLEEP \
-d SIM_WALLTIME_SIGNAL \
-e SIM_BSIM_TIME
make olddefconfig
BSIM_OUT_PATH=/tmp/bsworld/build/babblesim/bsim \
BSIM_COMPONENTS_PATH=/tmp/bsworld/build/babblesim/bsim/components \
make -j16
Verified actual BabbleSim PHY time integration without a controller by
starting bs_2G4_phy_v1 and running NSH usleep through the PHY wait
barrier:
bs_2G4_phy_v1 -s=<sid> -D=1 -defmodem=BLE_simple -nodump
printf 'usleep 1000000\npoweroff\n' | \
./nuttx --sim-bsim-sid=<sid> \
--sim-bsim-pid=2G4 \
--sim-bsim-dev=0
The same 1 second simulated sleep completed in 19 ms wall time when no
handbrake device was present. With handbrake registered as device 1:
bs_2G4_phy_v1 -s=<sid> -D=2 -defmodem=BLE_simple -nodump
bs_device_handbrake -s=<sid> -p=2G4 -d=1 -pp=50000 -r=1
the same NuttX usleep test completed in 985 ms wall time. A shorter
200 ms check showed the same behavior: 27 ms without handbrake and
172 ms with handbrake. This verifies that NuttX sim time advances
through the BabbleSim PHY and that the handbrake affects the NuttX sim
device.
Also verified make distclean succeeds after CONFIG_SIM_BSIM_TIME was
enabled and without exporting BSIM_COMPONENTS_PATH.
BSWorld out-of-tree native BLE examples:
./tools/configure.sh -l /path/to/bsim-auto-test/tests/nuttx/native_ble/source/advertiser/config
make -j16
exodus --tarball -o /path/to/bsim-auto-test/tests/nuttx/native_ble/source/advertiser/prebuilt/nuttx.tgz nuttx
./tools/configure.sh -l /path/to/bsim-auto-test/tests/nuttx/native_ble/source/scanner/config
make -j16
exodus --tarball -o /path/to/bsim-auto-test/tests/nuttx/native_ble/source/scanner/prebuilt/nuttx.tgz nuttx
pytest tests/nuttx/native_ble -q --no-ellisys
Assisted-by: OpenAI Codex
Signed-off-by: Lingao Meng <menglingao@xiaomi.com>
bitbucket.org/nuttx/buildroot returns 404, as does every other repository
under that Bitbucket organisation. The buildroot that still carries the
NuttX toolchain, ldnxflat included, is github.com/patacongo/buildroot.
Thirty three files carried the dead address, most of them as a "Bitbucket
download site" for a board's toolchain. There are no downloads to offer, so
those now name the repository, and the surrounding prose says so.
The other dead Bitbucket addresses are left alone: nuttx/nuttx, nuttx/tools,
nuttx/uclibc and nuttx/nxwidgets need a decision each about what replaces
them, which is not this patch. patacongo/obsoleted is still there.
Assisted-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
The download link is dead: bitbucket.org/nuttx/buildroot is gone, and the
buildroot that still carries ldnxflat is github.com/patacongo/buildroot.
The instructions were also more than is needed. mknxflat came in tree with
PR #19600, so only ldnxflat has to be built, and an ordinary arm-none-eabi
GCC compiles and links NXFLAT modules: a board does not have to select
CONFIG_ARM_TOOLCHAIN_BUILDROOT to use them. What ldnxflat does need is a
binutils source and build tree, because it reads its input through libbfd.
The CI test list said mknxflat is what the container lacks. It is in tree
now; ldnxflat is the one that is missing.
Assisted-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
A function pointer under FDPIC is not a code address. Because each
PT_LOAD segment is placed independently, a pointer has to carry the data
base its callee will need, so it is a two-word descriptor: the entry
point, and the base to install in the PIC register before branching.
R_ARM_FUNCDESC_VALUE says "the thing you are patching is such a
descriptor", and R_ARM_FUNCDESC says "manufacture one and give me its
address".
Both need state a relocation cannot carry. A descriptor's second word is
the *object's* data base, from DT_PLTGOT, and R_ARM_FUNCDESC carves
descriptors from a pool whose cursor has to survive from one relocation
to the next. up_relocate() is handed only a relocation, a resolved
symbol and an address to patch.
arch_data is the existing channel for exactly this -- RISC-V already uses
it to remember a HI20 relocation while its LO12 partner is processed --
but nothing has ever put loader state into it: it is declared zeroed and
written only by up_relocate() itself. So ARCH_ELFDATA_INIT and
ARCH_ELFDATA_FINI are added, seeding the block from the loadinfo before
the relocation loop and reading the cursor back after. Both default to
nothing, so an architecture that does not define them is unaffected, and
RISC-V's use of arch_data is untouched. libelf_relocatedyn() walks both
dynamic tables under one arch_data, so the cursor spans the whole object.
The addend handling is the part that is easy to get wrong. REL format
keeps the addend in place, in the word about to become the entry point,
and a pointer to a static function is referenced through its *section*
symbol -- the value is the section base and the offset, including the
Thumb bit, is entirely in the addend. Dropping it yields an even address
and the core faults trying to execute it as ARM code.
The GOT written into a descriptor is the loading object's own, even for
an imported function, which is what makes a callback work: when the base
firmware's qsort() calls back into a module's comparison function, the
module needs its own data base in the PIC register.
libelf_relocatedyn()'s imported-symbol path needed a change to suit. It
stores the resolved address directly and never calls up_relocate(), which
cannot produce a two-word descriptor, so under FDPIC the resolved value
now goes through up_relocate() and the relocation type decides what to
write.
Implemented for armv7-m and armv8-m, the profiles FDPIC targets; the
other ARM variants gain the arch_data block but no new relocations.
Built and booted mps3-an547:picostest and lm3s6965-ek:qemu-nxflat, the
ELF PIC and NXFLAT users of this code, both unchanged.
Assisted-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>