POSIX specifies getlogin() and getlogin_r(), and NuttX did not have
them. NuttX has no login sessions, so the login name is the name of
the real user ID in the user database, from getpwuid_r(): "root" when
there is no passwd file.
Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
Programs that read the members of archive (.a) files include <ar.h>
for struct ar_hdr and the ARMAG, SARMAG and ARFMAG constants, and
NuttX did not have it. The header describes the common ar file
format: the magic string, then a 60-byte ASCII header per member.
Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
The Pixhawk 6X-RT is an RT1176. The rptun configuration registers the
CM4 as /dev/rptun/cm4 from the board bring-up with the TCM memory map
the LMEM backdoor window allows, maps the shared window non-cacheable
and loads the CM4 ELF on rptun start. The image comes from the SD card
(CONFIG_FMU_V6XRT_CM4_FIRMWARE) or, with CONFIG_FMU_V6XRT_CM4_ROMFS,
from the etc ROMFS built from src/etc/cm4.elf, so no card is needed.
The nsh rptun builtin starts and stops the core and rpmsg ping
/dev/rpmsg/cm4 exercises the link; syslog goes to a RAM log readable
with dmesg. The board page documents the configuration and the
uploader.
Assisted-by: Claude:claude-fable-5-1
Signed-off-by: Lourens Naude <lourens@bearmetal.eu>
Document CONFIG_IMXRT_RPTUN: what the driver does at start and stop,
the memory map rules the board must follow (only the first 128 KB of
the backdoor window reaches the CM4, boot from the backdoor alias,
shared window mapped non-cacheable), the carveout resource the CM4
table must carry for the vrings and buffers, and the kick ordering the
CM4 firmware must honour.
Assisted-by: Claude:claude-fable-5-1
Signed-off-by: Lourens Naude <lourens@bearmetal.eu>
The i.MX RT1176 pairs the Cortex-M7 with a Cortex-M4 that NuttX left
in ROM-held reset. This backend lets NuttX on the CM7 run the CM4 as
an RPTUN remote. The loader writes the CM4 ELF through the LMEM
backdoor window, the boot vector goes into IOMUXC_LPSR_GPR0/1 as the
backdoor alias of the code TCM (the CM4-native address does not boot,
which NXP's MCMGR also assumes), and SRC releases the core.
A released slice cannot be held in reset again: a software reset is a
pulse after which the core restarts from the boot vector. Stop
therefore parks the core in a wfi loop written over the start of its
image, and the next start reloads the image.
Virtqueue kicks travel on MU-A channel 0. A kick into a full mailbox
is coalesced, because the remote rescans every virtqueue on any kick.
SRC_SRMR is set so a CM4 lockup resets only the CM4 instead of the
whole chip.
The board supplies the remote name, the ELF path, the address
environment, the boot vector and the autostart choice through
imxrt_rptun_init(). Gated by IMXRT_HAVE_CM4, which only the
MIMXRT1176 selects; selects DEV_SIMPLE_ADDRENV for libmetal.
Assisted-by: Claude:claude-fable-5-1
Signed-off-by: Lourens Naude <lourens@bearmetal.eu>
On U5 LSION is in RCC_BDCR, which is write-protected after reset.
Without PWR DBP set the LSION write is ignored and stm32_rcc_enablelsi()
waits forever for LSIRDY.
- Add STM32_HAVE_IP_PWR_M33_V1 (U5) to the common PWR register
dispatcher and the common stm32_pwr.h, so common code can reach the
U5 PWR definitions and stm32_pwr_enablebkp().
- Rename stm32u5/hardware/stm32_pwr.h to stm32u5xx_pwr.h, so the common
dispatcher can include it.
- In stm32_lsi.c enable backup domain write access around the BDCR
update, as the common LSE drivers do.
Signed-off-by: raiden00pl <raiden00@railab.me>
Assisted-by: Claude Code
Merge the per-family LSI oscillator drivers into a single core-agnostic
common/stm32/stm32_lsi.c.
To let a common/stm32 driver resolve RCC register definitions for every
family without a central chip enumeration, the
common/stm32/hardware/stm32_rcc.h dispatcher is removed and each family
that uses it now provides its own hardware/stm32_rcc.h.
stm32_lsi.c is built unconditionally for all families (including C5 and
U3, which had no LSI driver before); unused code is dropped by the linker.
The WB stm32_rcc_enable_lsi()/stm32_rcc_disable_lsi() are renamed to the
common stm32_rcc_enablelsi()/stm32_rcc_disablelsi().
Signed-off-by: raiden00pl <raiden00@railab.me>
Assisted-by: Claude Code
libelf_relocateadd() keeps a cache of CONFIG_LIBC_ELF_SYMBOL_CACHECOUNT
symbols in a list and reads each missing symbol from the file. A large
module has many more relocations than symbols (one with 1.1 million
relocations against 82000 symbols took more than 30 minutes to load
from a 9P share), and most of that time is spent in single reads.
If there is memory for it, read the whole symbol table in one read and
resolve each symbol only once. Otherwise use the cache as before.
Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
A signal action queued at syscall return pends PendSV for the running
thread, but the same SVC can switch to another thread first. PendSV then
saw that thread, the redirect was lost and the handler did not run until
a later PendSV landed on the target, which could happen while it was
already in arm_sigdeliver: the second redirect overwrote saved_regs, the
inner delivery cleared sigdeliver and the outer one branched to address
0. ostest sighand and signest hard faulted in a protected build.
The redirect is now checked against the thread being switched in, and a
thread already redirected is left alone until arm_sigdeliver restores
its context.
Signed-off-by: Royyan Zahir <royzah@gmail.com>
lm3s6965-ek:qemu-flat used 261952 of its 262144 bytes of flash, so
almost any growth of common code made its build fail with "region
`flash' overflowed".
Disable the wget example and the web client library it needs (which
also removes the NSH wget command). This frees 5180 bytes. The
configuration keeps its other network tools (ping, DHCP, DNS, NTP,
telnetd, tftp, netcat), and wget is still built by 10 other
configurations.
Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
sim_tapdev_send() called exit(1) when write() failed. The host fails
every write with EIO while the TAP interface is down, so setting the
TAP down on the host killed the sim. Drop the frame instead, like a
NIC without carrier, and log errno (the old message logged -1).
Assisted-by: Claude:claude-opus-5-5
Signed-off-by: raiden00pl <raiden00@railab.me>
The vector table is shared by all CPUs, but the fault, debug and SMP
IPI handlers were attached again on every CPU (up_irqinitialize(),
x86_64_hwdebug_init() and x86_64_ap_boot()). With CONFIG_IRQCHAIN this
adds duplicate chain entries per CPU and exhausts the IRQ chain pool,
so later irq_attach() calls from drivers fail with -ENOMEM.
Attach these handlers once, on CPU0. The SMP IPI handler prototypes
move to intel64.h, under CONFIG_SMP.
Assisted-by: Claude:claude-opus-5-5
Signed-off-by: raiden00pl <raiden00@railab.me>
create_region() mapped up to ENTRIES_PER_PGT pages through one final
level table, from whatever address the region started at. The text
region starts one page after the reserved area, so a region that
crossed the end of the table wrapped around and mapped its last pages
over the first entries of the same table. In a program with more than
about 2 MB of text, the reserved area became read-only and the kernel
faulted in umm_initialize().
Walk the region one final level table at a time.
Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
libelf_relocateadd() passes sym as NULL for a relocation against symbol
index 0, such as R_AARCH64_NONE. up_relocateadd() read sym->st_value
first, so loading a module with such a relocation faulted in the kernel.
Accept a NULL symbol for R_AARCH64_NONE and fail any other type, as the
other architectures do.
Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
POSIX declares strcasecmp() and strncasecmp() in <strings.h>. glibc,
musl and newlib also declare them in <string.h>, and some programs
rely on that: they include only <string.h> and get an implicit
declaration on NuttX.
Declare the two functions in <string.h> too. Only the prototypes are
added: the BSD macros of <strings.h> (bcopy(), bzero() and others) stay
out of <string.h>.
Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
The kernel ran the process's own heap allocator on metadata the process
controls, and at teardown freed it from whatever address space was
current. User anonymous mappings are now fresh pages mapped into the
process, as the REVISIT asked.
Signed-off-by: Royyan Zahir <royzah@gmail.com>
A SIGEV_SIGNAL | SIGEV_THREAD_ID timer skipped timer_create's signal
check, and nxsig_notification honoured any thread ID. Add
nxsig_event_valid(): the signal must exist and a SIGEV_THREAD_ID target
must be one of the caller's own threads, as on Linux. timer_create,
gpio, button and phy_notify call it before storing an event, so the
caller gets EINVAL and an expiring timer never fails its DEBUGVERIFY.
Signed-off-by: Royyan Zahir <royzah@gmail.com>
nucleo-g431rb:cansock and b-g431b-esc1:cansock fill their 128 KB of
flash to the last few hundred bytes, and the capability checks overflow
them.
Signed-off-by: Royyan Zahir <royzah@gmail.com>
What each capability guards, the prctl() interface, inheritance through
the task group, and where the checks sit.
Signed-off-by: Royyan Zahir <royzah@gmail.com>
exec_internal(), which posix_spawn(), execve() and exec() all reach,
nxtask_spawn_create() and nxtask_create() check it. nxthread_create()
does not: kernel threads go through it too.
Signed-off-by: Royyan Zahir <royzah@gmail.com>
Opening a block or MTD node, mount() and umount2() need it, and so does
a BCH character node, which checks in its own open(): a node made by
bchdev_register() is a character driver, so the inode type cannot tell
it apart. The checks sit in file_vopen(), nx_mount() and nx_umount2(),
which every path reaches; kernel threads hold every capability.
Signed-off-by: Royyan Zahir <royzah@gmail.com>
A task group holds PR_CAP_RAWIO, PR_CAP_SPAWN and PR_CAP_ADMIN, inherits
them from its creator and can only drop them. Every build: the kernel and
init start with all three, so nothing changes until a task drops one.
CONFIG_SCHED_CAPABILITIES, off with DEFAULT_SMALL, lets a board short of
flash leave the checks out.
Signed-off-by: Royyan Zahir <royzah@gmail.com>
Use init_main as the init entry point and enable SYSTEM_NXINIT with the
/etc ROMFS, so nxinit starts nsh as the console service.
Assisted-by: OpenCode:claude-sonnet-5
Signed-off-by: wangjianyu3 <wangjianyu3@xiaomi.com>
The ioctl passed the erase to the parent unchecked, so an erase from the
last block on reached the next partition. part_erase() already bounds it.
Signed-off-by: Royyan Zahir <royzah@gmail.com>
POSIX.1-2024 adds getlocalename_l(), which returns the name of the
locale of one category of a locale object. NuttX supports only the "C"
locale, so the function returns "C" for every valid category, and NULL
with errno set to EINVAL for an invalid one. It is built with
CONFIG_LIBC_LOCALE, like the other locale functions.
Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
POSIX requires tzset(), but NuttX declared and defined it only with
CONFIG_LIBC_LOCALTIME, so programs that call it do not build without
that option. Without CONFIG_LIBC_LOCALTIME there are no time zones and
local time is UTC, so tzset() has nothing to do.
Declare tzset() always, and add an empty one for builds without
CONFIG_LIBC_LOCALTIME.
Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
posix_spawn() and execve() logged every failed exec at error level. A
shell normally tries a program first: NSH with CONFIG_NSH_FILE_APPS
spawns each command from PATH before its built-in command, and bash
runs a script itself when execve() returns ENOEXEC. So every built-in
NSH command printed
nxposix_spawn_exec: ERROR: exec failed: 2
although nothing was wrong. The caller gets the error code and reports
it if it needs to.
Do not log ENOENT and ENOEXEC. Other errors are logged as before.
Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
Add a note for first-time contributors explaining that building the
simulator locally can help verify the development environment before
submitting changes.
Assisted-by: ChatGPT:GPT-5.6 Luna
Signed-off-by: Vedprakash Rana <vedprakashkumarrana8@gmail.com>
drivers/crypto/pnt calls the Plug&Trust middleware, whose API and types
are mixed case (Se05x_API_*, SE05x_*, kSE05x_*, smStatus_t), so any
change to those files failed the check.
Signed-off-by: Royyan Zahir <royzah@gmail.com>
pnt_se05x_get_data() compared the object size with the buffer even when ReadSize had failed and left it unset.
Signed-off-by: Royyan Zahir <royzah@gmail.com>
This commit adds board support for connecting an external Winbond W25
SPI NOR flash memory via SPI1 on the Nucleo-L432KC:
- Define W25_SPI1_CS on PA11.
- Configure SPI1 chip select and presence detection in stm32_spi.c.
- Add stm32_w25initialize() to initialize SPI1, bind the W25 driver,
and register /dev/mtd0, /dev/mtdblock0 (FTL), and optionally /dev/smart0.
- Call stm32_w25initialize() during bringup when CONFIG_MTD_W25 is enabled.
Assisted-by: gemini-3.8-flash
Signed-off-by: Daniel P. Carvalho <danieloak@gmail.com>
The CS, MOSI and MISO pins can be set to -1 in Kconfig when the board
does not use them, and esp32s3_spi_init() skips a pin when it is
negative. The pins are stored as uint8_t in esp32s3_spi_config_s, so
-1 becomes 255, every "pin >= 0" check is always true, and 255 is
passed to esp_gpiowrite() and esp_configgpio(), which trips their
DEBUGASSERT.
Store these three pins as int8_t so -1 is kept and the existing checks
work.
Fixesapache/nuttx#20186
Assisted-by: Grok Bot
Signed-off-by: Zhaoqi Xu <lzy00419@outlook.com>
The filter expression for CONFIG_STM32_IWDG and CONFIG_STM32_RTC_LSICLOCK
returns "y y" when both are enabled. Comparing that result with "y"
omits stm32_lsi.c, leaving calls to stm32_rcc_enablelsi() unresolved.
Test for a nonempty result instead. Include the helper once when either
or both consumers are enabled, and omit it when neither is enabled.
This changes source selection only, without changing clock or watchdog
policy.
Assisted-by: Codex:GPT-6
Signed-off-by: jsanchez-2g <jsanchez@2g-eng.com>
Provide a complete documentation page for the webclient network utility
in Documentation/applications/netutils/webclient/index.rst, replacing
the previous 7-line placeholder stub.
Includes:
- Architecture overview (NSH wget engine + programmatic C API)
- Key features (HTTP/1.0, HTTP/1.1, chunked encoding, pluggable TLS,
non-blocking I/O, proxy tunneling)
- Detailed Kconfig configuration table and dependencies
- NSH wget syntax, options, and real-world usage examples
- C API reference for simple helpers (wget, wget_post) and the
context-based API (struct webclient_context)
- Complete, runnable C application example for file downloads
Addresses #11081
Signed-off-by: Swatantra Yadav <maverickswatantra@gmail.com>
Use per-instance aligned buffers for memory that SDMMC IDMA cannot
access directly or that does not meet cache alignment requirements.
Copy writes before IDMA and copy successful bounced reads in the
waiting thread. Report the configured capacity through maxrequest.
Keep a positive IDMA RAM allow-list and runtime setup validation.
Invalidate only the actual DMA destination, prioritize errors over
DATAEND, and stop data access before releasing buffer ownership.
Reset an active data path on abort while restoring host bus settings;
clear cancellation state and handle immediate/watchdog-start errors.
This commit contains the STM32H7 driver and its Kconfig changes only.
The preceding commit supplies the common SDIO/MMCSD functionality.
Assisted-by: Codex:GPT-6
Signed-off-by: msli-dev <747640013@qq.com>
Add an optional maxrequest callback at the end of sdio_dev_s. A zero
or unset callback adds no host-specific limit; nonzero values are byte
limits that apply to all request buffers.
Combine the host limit with MMCSD_MULTIBLOCK_LIMIT when splitting
block reads and writes. Reject a host limit smaller than one block and
oversized raw multi-block commands before starting the transfer.
Cancel receive setup after a failed CMD23, attempt CMD12 after failed
open-ended multi-block reads, and propagate stop-command failures.
Keep these generic MMC/SD changes separate from the STM32H7 driver.
Assisted-by: Codex:GPT-6
Signed-off-by: msli-dev <747640013@qq.com>
Every ARCH_CORTEX_A5x config selects ARCH_ARMV8A, and both
Toolchain.defs and cmake/Toolchain.cmake test CONFIG_ARCH_ARMV8A at
the head of the chain, so the -mcpu=cortex-a53/a55/a57/a72 branches
were unreachable and all Cortex-A targets built with plain
-march=armv8-a, losing per-core scheduling/tuning.
Test the specific cores first so -mcpu wins for them; the generic
ARCH_ARMV8A branch still covers cores without a dedicated entry and
keeps the armv8.5-a/MTE handling. Also add the missing cortex-a55
branch to the cmake toolchain for parity with the makefile.
Signed-off-by: rikaken2004 <244897142+rikaken2004@users.noreply.github.com>
A channel number of zero marks an unused slot, as pwm.rst documents.
pwm_start() handed every slot to pwm_update_duty(), which refuses
channel 0, so a caller that fills only some slots, like PX4's tone
alarm, got EINVAL.
Signed-off-by: Royyan Zahir <royzah@gmail.com>
timer_gethandle() accepted any allocated timer in the system, so a
process could set, read or delete another process's timer by its handle.
Accept a handle only from a thread of the owner's process. The expiry
callback runs in interrupt context, where the current task is unrelated,
and is exempt.
Signed-off-by: Royyan Zahir <royzah@gmail.com>