Commit graph

63851 commits

Author SHA1 Message Date
Marco Casaroli
12d5e1c0ba libs/libc/pwd: Add getlogin() and getlogin_r().
POSIX specifies getlogin() and getlogin_r(), and NuttX did not have
them.  NuttX has no login sessions, so the login name is the name of
the real user ID in the user database, from getpwuid_r(): "root" when
there is no passwd file.

Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
2026-10-10 02:32:17 +08:00
Marco Casaroli
73760338dc include/ar.h: Add the archive file header.
Programs that read the members of archive (.a) files include <ar.h>
for struct ar_hdr and the ARMAG, SARMAG and ARFMAG constants, and
NuttX did not have it.  The header describes the common ar file
format: the magic string, then a 60-byte ASCII header per member.

Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
2026-10-10 02:32:17 +08:00
Lourens Naude
a661949f8a boards/arm/imxrt/fmu-v6xrt: Add an rptun configuration for the CM4.
The Pixhawk 6X-RT is an RT1176.  The rptun configuration registers the
CM4 as /dev/rptun/cm4 from the board bring-up with the TCM memory map
the LMEM backdoor window allows, maps the shared window non-cacheable
and loads the CM4 ELF on rptun start.  The image comes from the SD card
(CONFIG_FMU_V6XRT_CM4_FIRMWARE) or, with CONFIG_FMU_V6XRT_CM4_ROMFS,
from the etc ROMFS built from src/etc/cm4.elf, so no card is needed.
The nsh rptun builtin starts and stops the core and rpmsg ping
/dev/rpmsg/cm4 exercises the link; syslog goes to a RAM log readable
with dmesg.  The board page documents the configuration and the
uploader.

Assisted-by: Claude:claude-fable-5-1
Signed-off-by: Lourens Naude <lourens@bearmetal.eu>
2026-10-10 02:12:26 +08:00
Lourens Naude
5dcaf8ace8 Documentation/platforms/arm/imxrt: Document the RT1170 CM4 rptun driver.
Document CONFIG_IMXRT_RPTUN: what the driver does at start and stop,
the memory map rules the board must follow (only the first 128 KB of
the backdoor window reaches the CM4, boot from the backdoor alias,
shared window mapped non-cacheable), the carveout resource the CM4
table must carry for the vrings and buffers, and the kick ordering the
CM4 firmware must honour.

Assisted-by: Claude:claude-fable-5-1
Signed-off-by: Lourens Naude <lourens@bearmetal.eu>
2026-10-10 02:12:26 +08:00
Lourens Naude
bc44441f9d arch/arm/src/imxrt: Add an RPTUN backend for the RT1170 CM4.
The i.MX RT1176 pairs the Cortex-M7 with a Cortex-M4 that NuttX left
in ROM-held reset.  This backend lets NuttX on the CM7 run the CM4 as
an RPTUN remote.  The loader writes the CM4 ELF through the LMEM
backdoor window, the boot vector goes into IOMUXC_LPSR_GPR0/1 as the
backdoor alias of the code TCM (the CM4-native address does not boot,
which NXP's MCMGR also assumes), and SRC releases the core.

A released slice cannot be held in reset again: a software reset is a
pulse after which the core restarts from the boot vector.  Stop
therefore parks the core in a wfi loop written over the start of its
image, and the next start reloads the image.

Virtqueue kicks travel on MU-A channel 0.  A kick into a full mailbox
is coalesced, because the remote rescans every virtqueue on any kick.
SRC_SRMR is set so a CM4 lockup resets only the CM4 instead of the
whole chip.

The board supplies the remote name, the ELF path, the address
environment, the boot vector and the autostart choice through
imxrt_rptun_init().  Gated by IMXRT_HAVE_CM4, which only the
MIMXRT1176 selects; selects DEV_SIMPLE_ADDRENV for libmetal.

Assisted-by: Claude:claude-fable-5-1
Signed-off-by: Lourens Naude <lourens@bearmetal.eu>
2026-10-10 02:12:26 +08:00
raiden00pl
db514c3e63 arch/arm/src/common/stm32: enable backup domain access for LSI on U5
On U5 LSION is in RCC_BDCR, which is write-protected after reset.
Without PWR DBP set the LSION write is ignored and stm32_rcc_enablelsi()
waits forever for LSIRDY.

- Add STM32_HAVE_IP_PWR_M33_V1 (U5) to the common PWR register
  dispatcher and the common stm32_pwr.h, so common code can reach the
  U5 PWR definitions and stm32_pwr_enablebkp().
- Rename stm32u5/hardware/stm32_pwr.h to stm32u5xx_pwr.h, so the common
  dispatcher can include it.
- In stm32_lsi.c enable backup domain write access around the BDCR
  update, as the common LSE drivers do.

Signed-off-by: raiden00pl <raiden00@railab.me>
Assisted-by: Claude Code
2026-10-10 02:11:46 +08:00
raiden00pl
a98162efc6 arch/arm/src/stm32: unify LSI driver and make RCC headers per-family
Merge the per-family LSI oscillator drivers into a single core-agnostic
common/stm32/stm32_lsi.c.

To let a common/stm32 driver resolve RCC register definitions for every
family without a central chip enumeration, the
common/stm32/hardware/stm32_rcc.h dispatcher is removed and each family
that uses it now provides its own hardware/stm32_rcc.h.

stm32_lsi.c is built unconditionally for all families (including C5 and
U3, which had no LSI driver before); unused code is dropped by the linker.
The WB stm32_rcc_enable_lsi()/stm32_rcc_disable_lsi() are renamed to the
common stm32_rcc_enablelsi()/stm32_rcc_disablelsi().

Signed-off-by: raiden00pl <raiden00@railab.me>
Assisted-by: Claude Code
2026-10-10 02:11:46 +08:00
Marco Casaroli
1fe1cd4eaa libs/libc/elf: Read the symbol table at once for RELA relocations.
libelf_relocateadd() keeps a cache of CONFIG_LIBC_ELF_SYMBOL_CACHECOUNT
symbols in a list and reads each missing symbol from the file.  A large
module has many more relocations than symbols (one with 1.1 million
relocations against 82000 symbols took more than 30 minutes to load
from a 9P share), and most of that time is spent in single reads.

If there is memory for it, read the whole symbol table in one read and
resolve each symbol only once.  Otherwise use the cache as before.

Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
2026-10-10 02:09:57 +08:00
Royyan Zahir
5f5991a0f2 arch/arm: redirect an M-profile thread to its signal action once
A signal action queued at syscall return pends PendSV for the running
thread, but the same SVC can switch to another thread first. PendSV then
saw that thread, the redirect was lost and the handler did not run until
a later PendSV landed on the target, which could happen while it was
already in arm_sigdeliver: the second redirect overwrote saved_regs, the
inner delivery cleared sigdeliver and the outer one branched to address
0. ostest sighand and signest hard faulted in a protected build.

The redirect is now checked against the thread being switched in, and a
thread already redirected is left alone until arm_sigdeliver restores
its context.

Signed-off-by: Royyan Zahir <royzah@gmail.com>
2026-10-09 15:08:33 -03:00
Ari Kimari
3e456050d3 arch/arm/imxrt: RT1180evk QSPI flash pin and clock configs
Add QSPI flash pin and clock configs

Signed-off-by: Ari Kimari <ari.kimari@tii.ae>
2026-10-09 15:06:56 -03:00
Marco Casaroli
31a74e37de boards/arm/tiva/lm3s6965-ek: Drop wget from qemu-flat to free flash.
lm3s6965-ek:qemu-flat used 261952 of its 262144 bytes of flash, so
almost any growth of common code made its build fail with "region
`flash' overflowed".

Disable the wget example and the web client library it needs (which
also removes the NSH wget command).  This frees 5180 bytes.  The
configuration keeps its other network tools (ping, DHCP, DNS, NTP,
telnetd, tftp, netcat), and wget is still built by 10 other
configurations.

Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
2026-10-10 02:05:21 +08:00
raiden00pl
fd85ab56ae arch/sim/src/sim/posix/sim_tapdev.c: drop the frame on a TAP write error.
sim_tapdev_send() called exit(1) when write() failed. The host fails
every write with EIO while the TAP interface is down, so setting the
TAP down on the host killed the sim. Drop the frame instead, like a
NIC without carrier, and log errno (the old message logged -1).

Assisted-by: Claude:claude-opus-5-5
Signed-off-by: raiden00pl <raiden00@railab.me>
2026-10-09 15:04:22 -03:00
Ari Kimari
afa5c7c65b arch/arm/imxrt: rt118x ocram heap size fix
Some checks are pending
Build Documentation / build-html (push) Waiting to run
MemBrowse Memory Report / changes-filter (push) Waiting to run
MemBrowse Memory Report / load-targets (push) Waiting to run
MemBrowse Memory Report / identical (push) Blocked by required conditions
MemBrowse Memory Report / analyze (push) Blocked by required conditions
Fix OCRAM heap for rt118x

Signed-off-by: Ari Kimari <ari.kimari@tii.ae>
2026-10-09 22:39:51 +08:00
raiden00pl
621f525804 arch/x86_64/intel64: attach shared vector handlers only once.
The vector table is shared by all CPUs, but the fault, debug and SMP
IPI handlers were attached again on every CPU (up_irqinitialize(),
x86_64_hwdebug_init() and x86_64_ap_boot()). With CONFIG_IRQCHAIN this
adds duplicate chain entries per CPU and exhausts the IRQ chain pool,
so later irq_attach() calls from drivers fail with -ENOMEM.

Attach these handlers once, on CPU0. The SMP IPI handler prototypes
move to intel64.h, under CONFIG_SMP.

Assisted-by: Claude:claude-opus-5-5
Signed-off-by: raiden00pl <raiden00@railab.me>
2026-10-09 22:39:22 +08:00
raiden00pl
24c8bd45c0 arch/x86_64/x86_64_hwdebug.c: fix nxstyle issues.
Add the blank lines after declarations that nxstyle requires.

Assisted-by: Claude:claude-opus-5-5
Signed-off-by: raiden00pl <raiden00@railab.me>
2026-10-09 22:39:22 +08:00
Marco Casaroli
55cd85c9ab arch/arm64: Map a region that does not start at a page table boundary.
create_region() mapped up to ENTRIES_PER_PGT pages through one final
level table, from whatever address the region started at.  The text
region starts one page after the reserved area, so a region that
crossed the end of the table wrapped around and mapped its last pages
over the first entries of the same table.  In a program with more than
about 2 MB of text, the reserved area became read-only and the kernel
faulted in umm_initialize().

Walk the region one final level table at a time.

Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
2026-10-09 11:20:33 -03:00
Marco Casaroli
3515e44845 libs/libc/machine/arm64: Do not dereference a NULL symbol in up_relocateadd().
libelf_relocateadd() passes sym as NULL for a relocation against symbol
index 0, such as R_AARCH64_NONE.  up_relocateadd() read sym->st_value
first, so loading a module with such a relocation faulted in the kernel.

Accept a NULL symbol for R_AARCH64_NONE and fail any other type, as the
other architectures do.

Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
2026-10-09 10:41:26 -03:00
Marco Casaroli
fe34a3ee78 include/string.h: Also declare strcasecmp() and strncasecmp().
POSIX declares strcasecmp() and strncasecmp() in <strings.h>.  glibc,
musl and newlib also declare them in <string.h>, and some programs
rely on that: they include only <string.h> and get an implicit
declaration on NuttX.

Declare the two functions in <string.h> too.  Only the prototypes are
added: the BSD macros of <strings.h> (bcopy(), bzero() and others) stay
out of <string.h>.

Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
2026-10-09 10:39:26 -03:00
Ari Kimari
e794a88e1e arch/arm/imxrt: DMA buffer size config
Add DMA buffer size config option

Signed-off-by: Ari Kimari <ari.kimari@tii.ae>
2026-10-09 20:45:02 +08:00
Royyan Zahir
612fcb5c5a fs/mmap: back user anonymous mappings with pages in a kernel build
The kernel ran the process's own heap allocator on metadata the process
controls, and at teardown freed it from whatever address space was
current. User anonymous mappings are now fresh pages mapped into the
process, as the REVISIT asked.

Signed-off-by: Royyan Zahir <royzah@gmail.com>
2026-10-09 20:44:44 +08:00
Royyan Zahir
87998e3f61 sched/signal: validate a sigevent where it is registered
A SIGEV_SIGNAL | SIGEV_THREAD_ID timer skipped timer_create's signal
check, and nxsig_notification honoured any thread ID. Add
nxsig_event_valid(): the signal must exist and a SIGEV_THREAD_ID target
must be one of the caller's own threads, as on Linux. timer_create,
gpio, button and phy_notify call it before storing an event, so the
caller gets EINVAL and an expiring timer never fails its DEBUGVERIFY.

Signed-off-by: Royyan Zahir <royzah@gmail.com>
2026-10-09 20:34:16 +08:00
Royyan Zahir
bcff4ae00d drivers/input, drivers/ioexpander: nxstyle
No functional change; the next commit touches both files.

Signed-off-by: Royyan Zahir <royzah@gmail.com>
2026-10-09 20:34:16 +08:00
Royyan Zahir
24368b8008 boards/stm32g4: leave capabilities out of the cansock configs
nucleo-g431rb:cansock and b-g431b-esc1:cansock fill their 128 KB of
flash to the last few hundred bytes, and the capability checks overflow
them.

Signed-off-by: Royyan Zahir <royzah@gmail.com>
2026-10-09 09:31:21 -03:00
Royyan Zahir
4c76b78e93 Documentation: describe process capabilities
What each capability guards, the prctl() interface, inheritance through
the task group, and where the checks sit.

Signed-off-by: Royyan Zahir <royzah@gmail.com>
2026-10-09 09:31:21 -03:00
Royyan Zahir
36cb05ca2f Documentation: codespell in os/scheduling/index.rst
codespell flags pre-empted in this page, so any change to it fails the
check. Spell it preempted.

Signed-off-by: Royyan Zahir <royzah@gmail.com>
2026-10-09 09:31:21 -03:00
Royyan Zahir
66eac21f68 boards: reset and power-off need PR_CAP_ADMIN
boardctl(BOARDIOC_RESET) and boardctl(BOARDIOC_POWEROFF) refuse a task
group without it.

Signed-off-by: Royyan Zahir <royzah@gmail.com>
2026-10-09 09:31:21 -03:00
Royyan Zahir
ab63263b7f boards: nxstyle in boardctl.c
Indentation and comment fixes only, so the next change passes the style
check.

Signed-off-by: Royyan Zahir <royzah@gmail.com>
2026-10-09 09:31:21 -03:00
Royyan Zahir
5745970b1e sched, binfmt: spawning needs PR_CAP_SPAWN
exec_internal(), which posix_spawn(), execve() and exec() all reach,
nxtask_spawn_create() and nxtask_create() check it. nxthread_create()
does not: kernel threads go through it too.

Signed-off-by: Royyan Zahir <royzah@gmail.com>
2026-10-09 09:31:21 -03:00
Royyan Zahir
e55c073799 fs: raw storage needs PR_CAP_RAWIO
Opening a block or MTD node, mount() and umount2() need it, and so does
a BCH character node, which checks in its own open(): a node made by
bchdev_register() is a character driver, so the inode type cannot tell
it apart. The checks sit in file_vopen(), nx_mount() and nx_umount2(),
which every path reaches; kernel threads hold every capability.

Signed-off-by: Royyan Zahir <royzah@gmail.com>
2026-10-09 09:31:21 -03:00
Royyan Zahir
90ab43a7f5 drivers/bch: nxstyle in bchdev_driver.c
Indent the bch_seek() switch cases so the file passes nxstyle.

Signed-off-by: Royyan Zahir <royzah@gmail.com>
2026-10-09 09:31:21 -03:00
Royyan Zahir
e70cd6bf45 sched: process capabilities
A task group holds PR_CAP_RAWIO, PR_CAP_SPAWN and PR_CAP_ADMIN, inherits
them from its creator and can only drop them. Every build: the kernel and
init start with all three, so nothing changes until a task drops one.
CONFIG_SCHED_CAPABILITIES, off with DEFAULT_SMALL, lets a board short of
flash leave the checks out.

Signed-off-by: Royyan Zahir <royzah@gmail.com>
2026-10-09 09:31:21 -03:00
wangjianyu3
fdf5ea919e boards/arm64/qemu/qemu-armv8a: switch citest/citest_smp to nxinit
Use init_main as the init entry point and enable SYSTEM_NXINIT with the
/etc ROMFS, so nxinit starts nsh as the console service.

Assisted-by: OpenCode:claude-sonnet-5
Signed-off-by: wangjianyu3 <wangjianyu3@xiaomi.com>
2026-10-09 20:29:28 +08:00
Royyan Zahir
79cab1c2e3 drivers/mtd: keep MTDIOC_ERASESECTORS inside its partition
The ioctl passed the erase to the parent unchecked, so an erase from the
last block on reached the next partition. part_erase() already bounds it.

Signed-off-by: Royyan Zahir <royzah@gmail.com>
2026-10-09 20:24:53 +08:00
Marco Casaroli
dcc3b7b384 libs/libc/locale: Add getlocalename_l().
POSIX.1-2024 adds getlocalename_l(), which returns the name of the
locale of one category of a locale object.  NuttX supports only the "C"
locale, so the function returns "C" for every valid category, and NULL
with errno set to EINVAL for an invalid one.  It is built with
CONFIG_LIBC_LOCALE, like the other locale functions.

Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
2026-10-09 20:07:32 +08:00
Marco Casaroli
314348cafe libs/libc/time: Add tzset() for builds without time zones.
POSIX requires tzset(), but NuttX declared and defined it only with
CONFIG_LIBC_LOCALTIME, so programs that call it do not build without
that option.  Without CONFIG_LIBC_LOCALTIME there are no time zones and
local time is UTC, so tzset() has nothing to do.

Declare tzset() always, and add an empty one for builds without
CONFIG_LIBC_LOCALTIME.

Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
2026-10-09 20:07:32 +08:00
Marco Casaroli
7942d18fd5 sched/task: Do not log a missing or unloadable program as an exec error.
posix_spawn() and execve() logged every failed exec at error level.  A
shell normally tries a program first: NSH with CONFIG_NSH_FILE_APPS
spawns each command from PATH before its built-in command, and bash
runs a script itself when execve() returns ENOEXEC.  So every built-in
NSH command printed

  nxposix_spawn_exec: ERROR: exec failed: 2

although nothing was wrong.  The caller gets the error code and reports
it if it needs to.

Do not log ENOENT and ENOEXEC.  Other errors are logged as before.

Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
2026-10-09 19:52:55 +08:00
Vedprakash Rana
0072a34bc5 docs: improve getting started guidance
Add a note for first-time contributors explaining that building the
simulator locally can help verify the development environment before
submitting changes.

Assisted-by: ChatGPT:GPT-5.6 Luna
Signed-off-by: Vedprakash Rana <vedprakashkumarrana8@gmail.com>
2026-10-09 18:40:55 +08:00
Royyan Zahir
b2e04cf122 drivers/crypto/se05x: nxstyle in pnt_se05x_api.c
Add the blank line nxstyle wants after declarations.

Signed-off-by: Royyan Zahir <royzah@gmail.com>
2026-10-09 18:30:34 +08:00
Royyan Zahir
7b58ee84fe tools/nxstyle: allow the NXP Plug&Trust names
drivers/crypto/pnt calls the Plug&Trust middleware, whose API and types
are mixed case (Se05x_API_*, SE05x_*, kSE05x_*, smStatus_t), so any
change to those files failed the check.

Signed-off-by: Royyan Zahir <royzah@gmail.com>
2026-10-09 18:30:34 +08:00
Royyan Zahir
6b4e6a0335 drivers/crypto/se05x: zero the size a failed read leaves
pnt_se05x_get_data() compared the object size with the buffer even when ReadSize had failed and left it unset.

Signed-off-by: Royyan Zahir <royzah@gmail.com>
2026-10-09 18:30:34 +08:00
Daniel P. Carvalho
324a0cd437 boards/arm/stm32l4/nucleo-l432kc: Add support for external W25 SPI flash.
This commit adds board support for connecting an external Winbond W25
SPI NOR flash memory via SPI1 on the Nucleo-L432KC:
- Define W25_SPI1_CS on PA11.
- Configure SPI1 chip select and presence detection in stm32_spi.c.
- Add stm32_w25initialize() to initialize SPI1, bind the W25 driver,
  and register /dev/mtd0, /dev/mtdblock0 (FTL), and optionally /dev/smart0.
- Call stm32_w25initialize() during bringup when CONFIG_MTD_W25 is enabled.

Assisted-by: gemini-3.8-flash
Signed-off-by: Daniel P. Carvalho <danieloak@gmail.com>
2026-10-09 18:29:41 +08:00
Zhaoqi Xu
081e55461e arch/xtensa/esp32s3: Make SPI CS, MOSI and MISO pins signed.
The CS, MOSI and MISO pins can be set to -1 in Kconfig when the board
does not use them, and esp32s3_spi_init() skips a pin when it is
negative. The pins are stored as uint8_t in esp32s3_spi_config_s, so
-1 becomes 255, every "pin >= 0" check is always true, and 255 is
passed to esp_gpiowrite() and esp_configgpio(), which trips their
DEBUGASSERT.

Store these three pins as int8_t so -1 is kept and the existing checks
work.

Fixes apache/nuttx#20186

Assisted-by: Grok Bot
Signed-off-by: Zhaoqi Xu <lzy00419@outlook.com>
2026-10-09 18:29:04 +08:00
jsanchez-2g
6189fefdcf arm/stm32h7: Include LSI helper when both consumers are enabled.
The filter expression for CONFIG_STM32_IWDG and CONFIG_STM32_RTC_LSICLOCK
returns "y y" when both are enabled. Comparing that result with "y"
omits stm32_lsi.c, leaving calls to stm32_rcc_enablelsi() unresolved.

Test for a nonempty result instead. Include the helper once when either
or both consumers are enabled, and omit it when neither is enabled.
This changes source selection only, without changing clock or watchdog
policy.

Assisted-by: Codex:GPT-6
Signed-off-by: jsanchez-2g <jsanchez@2g-eng.com>
2026-10-09 18:28:06 +08:00
raiden00pl
e570885eb7 sensors: add ccs811 eCO2/TVOC driver
Implement the ams CCS811 digital gas sensor

Assisted-by: Claude Code
Signed-off-by: raiden00pl <raiden00@railab.me>
2026-10-09 18:27:21 +08:00
Swatantra Yadav
f14e5f4d28 Documentation/netutils: add comprehensive guide for webclient
Provide a complete documentation page for the webclient network utility
in Documentation/applications/netutils/webclient/index.rst, replacing
the previous 7-line placeholder stub.

Includes:
- Architecture overview (NSH wget engine + programmatic C API)
- Key features (HTTP/1.0, HTTP/1.1, chunked encoding, pluggable TLS,
  non-blocking I/O, proxy tunneling)
- Detailed Kconfig configuration table and dependencies
- NSH wget syntax, options, and real-world usage examples
- C API reference for simple helpers (wget, wget_post) and the
  context-based API (struct webclient_context)
- Complete, runnable C application example for file downloads

Addresses #11081

Signed-off-by: Swatantra Yadav <maverickswatantra@gmail.com>
2026-10-09 18:26:40 +08:00
msli-dev
494cadb869 stm32h7/sdmmc: Add configurable IDMA bounce buffering.
Use per-instance aligned buffers for memory that SDMMC IDMA cannot
access directly or that does not meet cache alignment requirements.
Copy writes before IDMA and copy successful bounced reads in the
waiting thread. Report the configured capacity through maxrequest.

Keep a positive IDMA RAM allow-list and runtime setup validation.
Invalidate only the actual DMA destination, prioritize errors over
DATAEND, and stop data access before releasing buffer ownership.
Reset an active data path on abort while restoring host bus settings;
clear cancellation state and handle immediate/watchdog-start errors.

This commit contains the STM32H7 driver and its Kconfig changes only.
The preceding commit supplies the common SDIO/MMCSD functionality.

Assisted-by: Codex:GPT-6
Signed-off-by: msli-dev <747640013@qq.com>
2026-10-09 18:26:12 +08:00
msli-dev
844ef9c678 mmcsd: Honor optional SDIO host request limits.
Add an optional maxrequest callback at the end of sdio_dev_s. A zero
or unset callback adds no host-specific limit; nonzero values are byte
limits that apply to all request buffers.

Combine the host limit with MMCSD_MULTIBLOCK_LIMIT when splitting
block reads and writes. Reject a host limit smaller than one block and
oversized raw multi-block commands before starting the transfer.

Cancel receive setup after a failed CMD23, attempt CMD12 after failed
open-ended multi-block reads, and propagate stop-command failures.
Keep these generic MMC/SD changes separate from the STM32H7 driver.

Assisted-by: Codex:GPT-6
Signed-off-by: msli-dev <747640013@qq.com>
2026-10-09 18:26:12 +08:00
rikaken2004
693513f034 arch/arm64: make per-core -mcpu flags reachable in both build systems
Every ARCH_CORTEX_A5x config selects ARCH_ARMV8A, and both
Toolchain.defs and cmake/Toolchain.cmake test CONFIG_ARCH_ARMV8A at
the head of the chain, so the -mcpu=cortex-a53/a55/a57/a72 branches
were unreachable and all Cortex-A targets built with plain
-march=armv8-a, losing per-core scheduling/tuning.

Test the specific cores first so -mcpu wins for them; the generic
ARCH_ARMV8A branch still covers cores without a dedicated entry and
keeps the armv8.5-a/MTE handling. Also add the missing cortex-a55
branch to the cmake toolchain for parity with the makefile.

Signed-off-by: rikaken2004 <244897142+rikaken2004@users.noreply.github.com>
2026-10-09 18:13:57 +08:00
Royyan Zahir
dfd1bf6738 arch/arm64/imx9: skip unused PWM channel slots
A channel number of zero marks an unused slot, as pwm.rst documents.
pwm_start() handed every slot to pwm_update_duty(), which refuses
channel 0, so a caller that fills only some slots, like PX4's tone
alarm, got EINVAL.

Signed-off-by: Royyan Zahir <royzah@gmail.com>
2026-10-09 18:11:57 +08:00
Royyan Zahir
e65ca99128 sched/timer: a timer handle works only in its own process
timer_gethandle() accepted any allocated timer in the system, so a
process could set, read or delete another process's timer by its handle.
Accept a handle only from a thread of the owner's process. The expiry
callback runs in interrupt context, where the current task is unrelated,
and is exempt.

Signed-off-by: Royyan Zahir <royzah@gmail.com>
2026-10-09 18:11:17 +08:00