Commit graph

63518 commits

Author SHA1 Message Date
Marcio Ribeiro
25a3aaaa9d arch/risc-v/esp32c2: add ESP32-C2 chip support
Introduce RV32IMC chip architecture with HAL integration and Espressif
common Kconfig for the ESP8684 SoC, including XTAL, UART0 pin range,
and SPI flash clock options.

Assisted-by: Claude:claude-opus-5
Signed-off-by: Marcio Ribeiro <marcio.ribeiro@espressif.com>
2026-09-25 21:08:00 +08:00
Marco Casaroli
5513029711 arch/arm: Build a loadable module and a shared library as FDPIC too.
CONFIG_FDPIC teaches the ELF module path what an FDPIC object is, so an
application built as a module gets -mfdpic -fPIC and the
arm-uclinuxfdpiceabi linker.  The loadable module path, which apps builds
with DYNLIB = y and which apps/Library.mk uses for a shared library, was
left as it was: a -r partial link with the stock linker.  That leaves an
object with no dynamic section, so the loader has nothing to bind an import
to, and there is no way to build a library an FDPIC module can call.

Give that path the same treatment.  CMODULEFLAGS and CXXMODULEFLAGS gain the
FDPIC compiler flags, and LDMODULEFLAGS links a shared object rather than a
partial one.  The entry point is left to the caller, because a module is
entered at _start while a library is only ever called into.

CXXMODULEFLAGS is also defined for the first time.  apps/Library.mk compiles
every C++ source of a shared library with it and no architecture defined it,
so those sources were compiled with no architecture flags at all.

Assisted-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
2026-09-25 09:56:10 -03:00
Austin.Chen
5197329b67 arch/arm/stm32h5: add SDMMC1/SDMMC2 driver
Add the STM32H5 SDMMC1/SDMMC2 lower-half SDIO driver (interrupt-mode and
IDMA transfers, SD/SDIO card mode), following the same structure as the
existing STM32H7 SDMMC driver.

Three fixes were needed to get this actually building, selectable, and
correct:

- The driver checked CONFIG_STM32H5_SDMMC1/CONFIG_STM32H5_SDMMC_IDMA/
  CONFIG_STM32H5_SDMMC_XFRDEBUG, but the real Kconfig symbols selected by
  this chip are the shared CONFIG_STM32_SDMMC1/CONFIG_STM32_SDMMC_IDMA/
  CONFIG_STM32_SDMMC_XFRDEBUG (see arch/arm/src/common/stm32/Kconfig.sdio,
  Kconfig.periph). With the old names the driver silently compiled out.
  Renamed all guards in stm32_sdmmc.c to match. Also fixed a similar typo,
  STM32H5_SRAM3_SIZE -> STM32_SRAM3_SIZE, in the IDMA-reach check.

- arch/arm/src/common/stm32/Kconfig.sdio's STM32_SDMMC_IDMA and the
  SDMMC1/2 SDIO-mode/pull-up options depended on ARCH_CHIP_STM32H7 /
  STM32_COMMON_F7_H7 only. Extended STM32_SDMMC_IDMA to also allow
  ARCH_CHIP_STM32H5, and switched the SDIO-mode/pull-up options to
  STM32_COMMON_F7_H7_H5, matching the pattern already used for other
  STM32H5 peripherals (Ethernet, ADC, SPI, timers).

- stm32_sdmmc.c was only added to Make.defs, not to CMakeLists.txt, so
  the driver would silently be omitted from CMake builds. Added it to
  the same unconditional source list as stm32_exti_gpio.c.

Also ports a fix from a related STM32H7 SDMMC commit
(2cb7b7c03e): stm32_recvdma()'s aligned
IDMA receive path invalidated the destination buffer before the DMA but
never again after it completed, so a speculative cache prefetch into
that buffer between those two points could shadow the freshly-received
data with a stale line. Added the missing post-DMA invalidate, matching
the pattern already used elsewhere on this chip for other DMA-capable
peripherals (e.g. stm32_ethernet.c's RX path).

Needed for a custom STM32H5 board that uses SDMMC1 in SDIO mode with
IDMA to talk to an onboard WiFi module.

Co-authored-by: Liam Howatt <liamhowatt@geotab.com>
Signed-off-by: Marwan Madkour <marwanmadkour@geotab.com>
2026-09-25 18:30:40 +08:00
raiden00pl
425e77e44e arch/nrf52,nrf53,nrf91: fix nxstyle issues
arch/nrf52,nrf53,nrf91: fix nxstyle issues

Signed-off-by: raiden00pl <raiden00@railab.me>
2026-09-25 18:24:36 +08:00
raiden00pl
058da97e95 arm/nrf52,nrf53: fix SAADC channel limit register value
CHLIMIT was written with (limith < 16) | limith, which put the high
limit into the low field and a boolean into bit 0. Shift the high
limit to bits 16-31 and the low limit to bits 0-15.

Assisted-by: Claude Code
Signed-off-by: raiden00pl <raiden00@railab.me>
2026-09-25 18:24:36 +08:00
raiden00pl
574bbf618f arm/nrf52,nrf53,nrf91: fix SPI sndblock ops field
The non-exchange ops table initialized .sndlock, which does not exist
in struct spi_ops_s and fails to compile without CONFIG_SPI_EXCHANGE.

Assisted-by: Claude Code
Signed-off-by: raiden00pl <raiden00@railab.me>
2026-09-25 18:24:36 +08:00
raiden00pl
e5e06d6bde arm/nrf52,nrf53,nrf91: fix PWM driver bugs
- SEQSTARTED0 and STOPPED events were not cleared before waiting for
  them, so the second start or stop returned immediately
- PWM_DECODER_MODE_* shifted 8 instead of shifting to bit 8
- PWM_PSEL_PIN_MASK and PWM_PSEL_PORT_MASK referenced TWI shift names
- PWM_PSEL_CONNECTED described the disconnected state

Assisted-by: Claude Code
Signed-off-by: raiden00pl <raiden00@railab.me>
2026-09-25 18:24:36 +08:00
raiden00pl
c8f699a4e3 arm/nrf52,nrf53,nrf91: fix GPIOTE driver bugs
- set_port_event checked the wrong port when deciding whether the
  PORT interrupt can be disabled
- set_event could pick a free channel instead of the one already
  assigned to the pin
- LATCH registers were cleared by writing zeros
- header declared nrfxx_gpio_set_task for a function defined as
  nrfxx_gpiote_set_task

Assisted-by: Claude Code
Signed-off-by: raiden00pl <raiden00@railab.me>
2026-09-25 18:24:36 +08:00
raiden00pl
f86b05351f arm/nrf52,nrf53,nrf91: fix RTC driver bugs
- setcc/getcc accepted channel index equal to the channel count
- init never marked the instance as in use
- NRFxx_RTC_GETCC called setcc instead of getcc

Assisted-by: Claude Code
Signed-off-by: raiden00pl <raiden00@railab.me>
2026-09-25 18:24:36 +08:00
raiden00pl
d490c80df2 arm/nrf52,nrf53,nrf91: fix TIMER driver bugs
- setcc/getcc accepted channel index equal to the channel count
- init never marked the instance as in use
- TIM_PRESCALER_MASK used the maximum value as the mask

Assisted-by: Claude Code
Signed-off-by: raiden00pl <raiden00@railab.me>
2026-09-25 18:24:36 +08:00
Alan Carvalho de Assis
a315d19fac tools/nxstyle: allow the OpenGL and TinyGL identifier prefixes
OpenGL names are mixed case by definition (glVertex3f(), GLfloat,
GL_QUADS) and so are the TinyGL framebuffer helpers (ZBuffer,
ZB_open()), so any application that uses apps/graphics/tinygl fails the
"Mixed case identifier" check on every GL call.

Add "gl", "GL" and "ZB" to the list of white-listed prefixes, like the
existing entries for other third party APIs (lua_, cJSON, XK_, ...).

Assisted-by: Claude Opus 5.5 (1M context)
Signed-off-by: Alan Carvalho de Assis <acassis@gmail.com>
2026-09-25 18:18:10 +08:00
raiden00pl
0942bae6ef arm/nrf54l: add GRTC and tickless scheduling
arm/nrf54l: add GRTC and tickless scheduling

Assisted-by: Codex:GPT-6
Signed-off-by: raiden00pl <raiden00@railab.me>
2026-09-25 10:48:00 +02:00
raiden00pl
04d2c9013c arm/nrf54l: add TIMER support
arm/nrf54l: add TIMER support

Assisted-by: Codex:GPT-6
Signed-off-by: raiden00pl <raiden00@railab.me>
2026-09-25 10:48:00 +02:00
raiden00pl
311214f90c boards/thingy53: fix possible out of bound write for rgb
properly initialize PWM info struct to avoid out of bound write

Signed-off-by: raiden00pl <raiden00@railab.me>
2026-09-25 10:46:24 +02:00
raiden00pl
be46d87e1a boards/thingy53: add ADC support
add ADC support for thingy53

Signed-off-by: raiden00pl <raiden00@railab.me>
2026-09-25 10:46:24 +02:00
raiden00pl
dff3977d4c boards/thingy53: fix ADC and QSPI pin macros
use the NRF53 prefix for the ADC and QSPI pin definitions

Signed-off-by: raiden00pl <raiden00@railab.me>
2026-09-25 10:46:24 +02:00
rongbaichuan
00a379c3f7 sched/semaphore: Fix pre-existing nxstyle issues in the touched files
The CI style check runs nxstyle over every file a pull request touches,
so the files changed by the previous two commits have to comply even
where the problems were not introduced here.  504 errors in 25 files are
fixed: whitespace, blank lines, brace placement, switch/case indentation,
label indentation and comment blocks only, with no functional change.

Assisted-by: DeepSeek Harness:deepseek-flash
Signed-off-by: rongbaichuan <rongbaichuan1027@163.com>
2026-09-25 10:37:43 +02:00
rongbaichuan
9c461f03ac sched/semaphore: Correct the return value comment of nxsem_init/nxmutex_init
nxsem_init(), nxsem_destroy(), nxmutex_init(), nxmutex_destroy(),
nxrmutex_init() and nxrmutex_destroy() cannot fail, so promising a
negated errno value on failure documents an error that is never returned.
The coding standard asks the returned value description to identify all
error values of a function, and there are none, so state that OK is
always returned.

Follows "sched/semaphore: Remove the return value check of
nxsem_init/nxmutex_init", which removed the last checks of these values.

Assisted-by: DeepSeek Harness:deepseek-flash
Signed-off-by: rongbaichuan <rongbaichuan1027@163.com>
2026-09-25 10:37:43 +02:00
rongbaichuan
59d5ce0f31 sched/semaphore: Remove the return value check of nxsem_init/nxmutex_init
nxsem_init(), nxsem_destroy(), nxmutex_init() and nxmutex_destroy()
always return OK, so checking the result only leaves dead code: the
compiler cannot remove it, because these are cross-translation-unit calls
and the nxrmutex_destroy() test is duplicated into every inlined call
site.

Apply the convention already established in commit a47a36bc5b (PR #7473)
to the two definitions which still test the value and to the 54 remaining
call sites. No signature or prototype is changed.

Testing: stm32f103-minimum:nsh builds with -Os without new warnings.

Assisted-by: DeepSeek Harness:deepseek-flash
Signed-off-by: rongbaichuan <rongbaichuan1027@163.com>
2026-09-25 10:37:43 +02:00
Alan Carvalho de Assis
17edaf458f boards/sim: Fix coding style to let the PR pass
Recently the nxstyle became more restrictive so it got some issues
that used to be ignored in the pass.

Signed-off-by: Alan C. Assis <acassis@gmail.com>
2026-09-25 10:36:28 +02:00
Alan Carvalho de Assis
31d3598f6a arch/sim: buffer several mouse reports
sim_mouse registered /dev/mouse0 with room for a single report.  The
X11 event loop handles all pending X events at once every
CONFIG_SIM_X11EVENT_INTERVAL ms, so a quick click (button press and
release in the same period) overwrote the press before the application
could read it, and the click was lost.

Add CONFIG_SIM_MOUSE_BUFFSIZE (default 16) for the number of buffered
reports, like CONFIG_SIM_KEYBOARD_BUFFSIZE for the keyboard.

Assisted-by: Claude Opus 5.5 (1M context)
Signed-off-by: Alan Carvalho de Assis <acassis@gmail.com>
2026-09-25 10:36:28 +02:00
Alan Carvalho de Assis
e73dd2a9a9 boards/sim: register /dev/mouse0 when CONFIG_SIM_MOUSE is enabled
The X11 mouse emulation driver (arch/sim/src/sim/sim_mouse.c) is built
and fed by the X11 event loop whenever CONFIG_SIM_MOUSE=y, but nothing
ever called sim_mouse_initialize(), so /dev/mouse0 was never registered
and applications could not read any mouse reports.  Since nothing
referenced sim_mouse.o, the linker did not even pull it in and the
build failed with "undefined reference to `sim_mouseevent'".

Call sim_mouse_initialize(0) from sim_bringup(), next to the existing
touchscreen and keyboard initialization.

Tested with sim:nsh + CONFIG_SIM_X11FB, CONFIG_SIM_MOUSE and
CONFIG_SIM_KEYBOARD: /dev/mouse0 is now listed and reports left, middle
and right button state plus pointer motion.

Signed-off-by: Alan C. Assis <acassis@gmai.com>
Assisted-by: Claude Opus 5.5 (1M context)
2026-09-25 10:36:28 +02:00
Alan Carvalho de Assis
843cf6d581 wireless/bluetooth: Validate Number Of Completed Packets event.
Two problems in hci_num_completed_packets().

Number_of_Handles is a single octet, but it was read with BT_LE162HOST(),
which takes the first octet of the handle that follows it as the high
byte.  A one-octet field could therefore produce a loop count of up to
65535.

The loop was then bounded only by that count and not by the data that was
actually received, so it walked past the end of the event, reading handle
and count pairs out of whatever followed it.

Read the field at its declared width, and require the pairs the event
claims to have been received before reading them.

Per-connection credit accounting, which this handler still does not do,
is a separate change.

Ref: Core v6.0, Vol 4, Part E, 7.7.19 (Number Of Completed Packets event)
Testing: builds for sim:bluetooth with Make; every commit in this series
verified to build individually.

Signed-off-by: Alan C. Assis <acassis@gmail.com>
Assisted-by: Claude Code Opus 5
2026-09-25 10:35:51 +02:00
Marco Casaroli
27d621e4c7 arch/x86_64: Let the architecture select ARCH_HAVE_FORK.
Review of #19772 asked for this shape, and it applies to every architecture in
the series.

ARCH_HAVE_FORK described when it was available from inside its own definition,
which put the per-architecture condition somewhere nobody looks.  The
architecture now says so itself.

The condition repeats the ARCH_ADDRENV dependency rather than relying on it,
because a select bypasses depends on:  without that repetition an architecture
could offer fork() where there is no address environment to duplicate.

Assisted-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
2026-09-24 18:02:36 -03:00
Marco Casaroli
95c326704e arch/x86_64: Implement up_addrenv_fork() and provide POSIX fork().
Duplicate an address environment into freshly allocated pages mapped at the
same virtual addresses, which is what POSIX fork() is built on.

x86_64_fork_syscall() then lets the child run at the parent's stack addresses.
A pointer to a stack local taken before fork() must name the same object in
the child that it named in the parent, so the child adopts the parent's stack
geometry rather than being given a relocated copy; the parent's stack is
already in the duplicate, at the parent's address, with its contents.  That
shows up as a zero offset, which also means the copy would have the same
source and destination, so both the copy and the frame-pointer relocation are
skipped.

Build-verified on qemu-intel64:knsh_romfs.  NuttX on qemu-intel64 requires
tsc-deadline and pcid, which TCG does not implement, so it cannot be run on
this host.

Assisted-by: Claude Code:claude-opus-5
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
2026-09-24 18:02:36 -03:00
Royyan Zahir
026f77d940 arch/arm64/imx9: give the ELE a physical address and the cache a virtual one.
The ELE addresses memory physically; cache maintenance takes a virtual
address. Both buffer calls supply one and use it for both, in opposite
directions: get_random() runs up_flush_dcache() on a physical address,
get_key() hands the enclave a virtual one. Both fail silently, and both
are correct only while the two are equal.

Take the virtual address in both, maintain the cache on it, and translate
for the message. get_random() also gains the alignment check get_key()
already has.

Signed-off-by: Royyan Zahir <royzah@gmail.com>
2026-09-24 10:36:52 -03:00
dechao_gong
c2f19eef3d Documentation/rtl8730e: document the general-purpose UART ports
Add a Features bullet and a "uart" configuration section to the
RTL8730E EVB board page describing UART0-2 as /dev/ttyS1-3 at
115200 8N1, the serialrx / serialblaster loopback examples and the
runtime TERMIOS support, following the pke8721daf board format.

Signed-off-by: dechao_gong <dechao_gong@realsil.com.cn>
Assisted-by: Claude <noreply@anthropic.com>
2026-09-24 21:24:35 +08:00
dechao_gong
ec7ee53f6f arch/arm/rtl8730e: add UART character driver support
Expose the RTL8730E general-purpose UARTs through the shared Ameba
serial driver (arch/arm/src/common/ameba/ameba_uart.c) by adding the
chip-specific glue, build wiring and a board port table.  The change is
gated by CONFIG_AMEBA_UART (default disabled); the LOG-UART keeps the
console and /dev/ttyS0.

Chip glue (ameba_uart_chip.h) supplies the three UART controller
register bases, GIC IRQ numbers (SPI 50/51/52 -> NuttX IRQ 82/83/84),
APB clock masks and pin-mux codes.  The board registers UART0-2 as
/dev/ttyS1-3 at 115200 8N1; UART3 is reserved for Bluetooth.  Pads are
picked from the EVB break-out (the UART crossbar maps each controller to
many pads, so this is purely a board choice).

Also fix an RX-timeout interrupt storm in the shared driver: the
RX-timeout status (LSR bit9) is latched and is not cleared by draining
the RX FIFO, so on a level-triggered GIC (RTL8730E) the ISR must
explicitly write TOICF, matching the vendor SDK serial_api.c.  The
extra register write is harmless on the NVIC-based M33 Ameba parts and
was regression-tested on them.

Signed-off-by: dechao_gong <dechao_gong@realsil.com.cn>
Assisted-by: Claude <noreply@anthropic.com>
2026-09-24 21:24:35 +08:00
dechao_gong
a28daa454b boards/arm/rtl8730e: fix SMP cache-line false sharing on Cortex-A32
Under sustained dual-core critical-section traffic (e.g. several UART
ISRs) the two Cortex-A32 cores live-lock trading failed STREX.  The
generic critical-section lock g_cpu_irqlock (an LDREX/STREX spinlock)
and the plain non-atomic bitmap g_cpu_irqset are defined back-to-back
in sched/irq/irq_csection.c and land in the same 64-byte cache line.
The A32 exclusive monitor reserves a full cache line, so one core's
ordinary store to g_cpu_irqset clears the other core's LDREX
reservation on g_cpu_irqlock.

Separate the two symbols onto their own cache lines in the board link
script, leaving the generic scheduler source untouched (relies on the
toolchain emitting per-object -fdata-sections).

Signed-off-by: dechao_gong <dechao_gong@realsil.com.cn>
Assisted-by: Claude <noreply@anthropic.com>
2026-09-24 21:24:35 +08:00
raiden00pl
f021af714d drivers/ioexpander/sx1509: include nuttx/arch.h for up_mdelay
up_mdelay() is used in the reset sequence but nuttx/arch.h was not
included, causing an implicit-declaration build error.

Signed-off-by: raiden00pl <raiden00@railab.me>
2026-09-24 20:16:12 +08:00
raiden00pl
1a0032105d drivers/ioexpander/sx1509: implement the pin PWM operation
Implement ioe_setpwm for the SX1509 by mapping the duty cycle to the
LED driver ON intensity of the pin.

Assisted-by: Claude Code
Signed-off-by: raiden00pl <raiden00@railab.me>
2026-09-24 20:16:12 +08:00
raiden00pl
c31b87ee1e drivers/ioexpander: add an optional pin PWM operation
Add an ioe_setpwm operation (guarded by CONFIG_IOEXPANDER_PWM) for
expanders that can modulate their outputs, e.g. through a LED driver
engine.

Assisted-by: Claude Code
Signed-off-by: raiden00pl <raiden00@railab.me>
2026-09-24 20:16:12 +08:00
raiden00pl
9eb6969843 boards/thingy91: add rgb led support
add rgb led support for thingy91

Signed-off-by: raiden00pl <raiden00@railab.me>
2026-09-24 09:59:04 +02:00
Marcio Ribeiro
ccf67497c7 arch/risc-v/espressif: keep RTC backup data in DRAM without RTC memory
SoCs such as the ESP32-C2 have no RTC retention memory, so RTC_DATA_ATTR
cannot be used for the persistent RTC time.  Place the backup data in DRAM
on those chips, where the saved time does not survive deep sleep.

Assisted-by: Claude:claude-opus-5
Signed-off-by: Marcio Ribeiro <marcio.ribeiro@espressif.com>
2026-09-24 09:54:28 +02:00
Alan Carvalho de Assis
a73bea0653 wireless/bluetooth: Reject GATT operations on unconnected peers.
The GATT ioctls looked up a connection by address and then checked only
that a connection object existed, not that it had reached CONNECTED.
While a connection is still being established conn->att is NULL, and
bt_att_create_pdu() dereferenced it to read the ATT MTU, so issuing
SIOCBTEXCHANGE, SIOCBTDISCOVER, SIOCBTGATTRD or SIOCBTGATTWR for a peer
that is merely pending faulted.  Any task with access to the network
device can reach that path, and in PROTECTED and KERNEL builds the fault
is taken in the kernel on behalf of user code.

Require CONNECTED in those four ioctls, releasing the reference the
lookup took, and make bt_att_create_pdu() return NULL when there is no
ATT context instead of relying on every caller having checked first.

Testing: builds for sim:bluetooth with Make; every commit in this series
verified to build individually.  On sim:bluetooth with CONFIG_BTSAK=y:

  nsh> ifup bnep0
  ifup bnep0...OK
  nsh> bt bnep0 gatt connect 11:22:33:44:55:66 public
  Connect pending...
  nsh> bt bnep0 gatt exchange-mtu 11:22:33:44:55:66 public
  ERROR:  ioctl(SIOCBTEXCHANGE) failed: 107

107 is ENOTCONN, and the shell continues to run; before this change the
same sequence terminated the simulator in bt_att_create_pdu().

Signed-off-by: Alan C. Assis <acassis@gmail.com>
Assisted-by: Claude Code Opus 5
2026-09-24 09:51:44 +02:00
Afonso Oliveira
a6cab8293d Documentation/erbium: Add ET-Minion core diagram and references.
Add the ET-Minion core diagram from the Erbium documentation
(aifoundry-org/erbium, Apache-2.0) and a short description of the
ET-Minion neighborhood, as suggested in review. Link the Erbium core,
interrupt, memory map and UART documentation and ET-platform, and note
that silicon uses a 10 MHz mtime while the emulator default is 2 MHz.

Signed-off-by: Afonso Oliveira <afonso.oliveira707@gmail.com>
2026-09-24 15:38:14 +08:00
Afonso Oliveira
cb53b267e5 Documentation/erbium: Document the Minion emulator port.
Describe the Erbium architecture and the Minion board: supported scope,
memory map and interrupts, toolchain constraints, Make and CMake
configurations, how to build the pinned public emulator, and how to run
the NSH and ostest images in it.

Signed-off-by: Afonso Oliveira <afonso.oliveira707@gmail.com>
2026-09-24 15:38:14 +08:00
Afonso Oliveira
0b35d45b2c riscv/erbium: Add standalone Minion emulator support.
Add an initial port for the AIFoundry Erbium Minion core running on the
public ET-platform system emulator (erbium_emu). NuttX boots directly
from a firmware ELF at 0x40000200, runs in machine mode on hart 0 with
SMP disabled, and parks secondary harts before they touch memory.

The chip layer provides startup, PLIC interrupts, the UART0 console
driver and the machine timer. Context switching, FPU save/restore,
heap, idle and timer handling reuse the common RISC-V code. Atomics use
interrupt masking because the core does not implement the A extension.

Erbium implements the F extension but executes fdiv/fsqrt and FENCE.I
in microcode, which a standalone image does not provide. The board build
files pass -mno-fdiv to GCC when the FPU is enabled, so those operations
use software helpers. Startup initializes the FPU without the common
FENCE.I sequence, and the board configurations disable the dynamic ELF
loader, which also relies on FENCE.I.

Add minion:nsh and minion:ostest configurations, Make and CMake
support, CMake CI build entries, and a host script that runs prebuilt
images in the emulator and checks the console and OS test results.

Tested with emulator revision 836a4ab600e9 and xPack GCC 14.3.0: both
configurations build with Make and CMake, ostest exits with status 0
including the FPU tests, and the NSH console, procfs, timer and UART
receive paths work. Silicon, SMP, protected builds and reboot are not
covered by this initial port.

Signed-off-by: Afonso Oliveira <afonso.oliveira707@gmail.com>
2026-09-24 15:38:14 +08:00
raiden00pl
95cdd306f0 arm/nrf54l: add initial nrf54l support
add initial nrf54l support (Cortex-M33 only)

Assisted-by: Codex:GPT-6
Signed-off-by: raiden00pl <raiden00@railab.me>
2026-09-24 11:10:46 +08:00
Royyan Zahir
5b2311ef2d boards/arm/imxrt: add the Holybro Pixhawk 6X-RT
A MIMXRT1176 flight controller built to the Pixhawk FMUv6X-RT standard, so
the port also covers the NXP MR-VMU-RT1176.

Board data comes from PX4, which already carries it as a NuttX board config:
the clock tree, the LPUART1 pinmux, and the Macronix octal flash
configuration block the boot ROM reads at offset 0x400.

The board ships with the PX4 bootloader in the first 128 KB of QSPI, so the
image links at 0x30020000 and is loaded by it rather than written to the
flash base. The console is CDC/ACM as on teensy-4.x, so a USB cable is the
only thing needed to run NuttX here.

Signed-off-by: Royyan Zahir <royzah@gmail.com>
2026-09-23 18:51:23 -03:00
Alan Carvalho de Assis
2cdeceae6e tools/ci: Fix esptool issue
There is a issue that exist on esptool and was fixed on version
5.3.0: https://github.com/espressif/esptool/releases/tag/v5.3.0
elf2image: Correct pad length for ram-only-header flash segments (Sylvio Alves - c637749)

Signed-off-by: Alan C. Assis <acassis@gmail.com>
2026-09-23 08:59:07 -03:00
Alan Carvalho de Assis
c728586a48 wireless/bluetooth: Validate event length before parsing HCI events.
hci_event() consumed the event header and dispatched on the event code
without checking that a header had been received, and hci_le_meta_event()
did the same for the subevent code.  Each handler then cast the remaining
buffer to its event structure and read fields out of it, so a short event
was parsed from whatever followed it in memory - including the fields
that identify a connection and carry its encryption state.

Check that the header is present before reading it, that the parameters
the event declares were actually received, and that enough parameters
remain for the structure the selected handler casts to.  Events failing a
check are dropped with a diagnostic rather than parsed.

le_adv_report() continues to do its own checking, because the report
count and the per-report lengths vary within that event.

Ref: Core v6.0, Vol 4, Part E, 5.4.4 (HCI Event packets)
Ref: Core v6.0, Vol 4, Part E, 7.7 (Events)
Testing: builds for sim:bluetooth with Make; every commit in this series
verified to build individually.  Not yet exercised at runtime - the
scriptable controller injects truncated events separately.

Signed-off-by: Alan C. Assis <acassis@gmail.com>
Assisted-by: Claude Code Opus 5
2026-09-23 08:58:44 -03:00
Felipe Moura
3c3afd04bd espressif/esp_pm.c: restore GPIO config after using it as a wake source
Arming a pin as a light-sleep wake source destroyed whatever it was
configured as, permanently.

esp_pm_gpio_wakeup_prepare() has to reconfigure each masked pin to plain
INPUT and hand it to gpio_wakeup_enable(), because the wakeup path only
supports level triggering.  It then never put anything back.  A pin that
was also a normal peripheral interrupt -- a sensor's data-ready line, say
-- came out of the first light sleep with its trigger mode gone and never
interrupted again.  Nothing failed loudly; the device just went silent.

Fixed generically rather than per-board:

  - esp_configgpio() now remembers the last attr applied to each pin, and
    a new esp_getconfiggpio() hands it back.  This is what lets the PM
    code restore a pin without having to know what the pin is for.

  - esp_pm_gpio_wakeup_prepare() saves each masked pin's attr before
    overwriting it, and a new esp_pm_gpio_wakeup_restore() puts it back
    as soon as esp_pm_light_sleep_start() returns.

Tied to the physical sleep/wake cycle deliberately, not to PM state
transitions.  An earlier attempt used a board-level pm_register()/notify()
callback and never fired at all, because the board sits in PM_STANDBY
without transitioning back to PM_NORMAL -- there is no state change to
hang the restore on.  The return from esp_pm_light_sleep_start() is the
one event that always happens exactly once per sleep.

Assisted-by: Claude:claude-opus-5
Signed-off-by: Felipe Moura <moura.fmo@gmail.com>
2026-09-23 08:36:17 -03:00
Felipe Moura
4818198a0d drivers/lsm6ds3trc_uorb.c: keep the reset comment board/arch-agnostic
#20231 added a comment ahead of the sensor's power-on SW_RESET that
named esp32s3-specific things in otherwise generic driver code:
esptool/RTS-pin reset vocabulary, a literal path to
boards/xtensa/esp32s3/common/src/esp32s3_board_lsm6ds3trc.c, and the
espressif-arch esp_gpioirqenable() function.

None of that is specific to this driver's actual logic, which is
reached by any board wiring this sensor's INT1 through its own
config->attach() callback, whatever the arch. Reworded to describe
the reset/level-trigger requirement in those generic terms instead,
and dropped an ESP32S3-collar bring-up anecdote that does not belong
in driver documentation.

Signed-off-by: Felipe Moura <moura.fmo@gmail.com>
Assisted-by: Claude:claude-sonnet-5
2026-09-23 08:22:52 +02:00
Daniel P. Carvalho
87f2744e6c arch/arm/stm32h5: fail the PHY initialization when the reset times out.
The driver has the same code as the one of the STM32H7. When the PHY did
not clear the reset bit in time, stm32_phyinit() returned the result of
the last MDIO read. The bus reads all ones when the PHY does not answer
yet, and that read succeeds, so the function returned OK and the driver
went on with its default of 10 Mbps and half duplex, while the PHY could
negotiate 100 Mbps and full duplex.

Return -ETIMEDOUT, so that bringing the interface up fails and the
failure is not hidden.

It builds for nucleo-h563zi:netnsh, but it was not tested on hardware.

Signed-off-by: Daniel P. Carvalho <danieloak@gmail.com>
Assisted-by: Claude:claude-sonnet-5
2026-09-23 08:21:59 +02:00
Daniel P. Carvalho
a4c608c591 arch/arm/stm32h7: do not log the frames of packet sockets as unknown.
A frame that a packet socket consumes was given to pkt_input() and then
logged as "Dropped, Unknown type" because it is neither IP nor ARP. With
a PTP grandmaster on the network that is one warning for each frame, and
the log of RAM fills in seconds, so it hides the messages of the start of
the system.

Do not log the frames of the type of PTP or of IPv6 when packet sockets
are enabled, as the driver of the legacy STM32 does.

Signed-off-by: Daniel P. Carvalho <danieloak@gmail.com>
Assisted-by: Claude:claude-sonnet-5
2026-09-23 08:21:59 +02:00
Daniel P. Carvalho
0a4ab69e52 arch/arm/stm32h7: fail the PHY initialization when the reset times out.
When the PHY did not clear the reset bit in time, stm32_phyinit()
returned the result of the last MDIO read. The bus reads all ones when
the PHY does not answer yet, and that read succeeds, so the function
returned OK and the driver went on with its default of 10 Mbps and half
duplex, while the PHY negotiated 100 Mbps and full duplex. The interface
was up and could not talk to anyone.

Return -ETIMEDOUT, so that bringing the interface up fails and the
failure is not hidden.

Signed-off-by: Daniel P. Carvalho <danieloak@gmail.com>
Assisted-by: Claude:claude-sonnet-5
2026-09-23 08:21:59 +02:00
Xiang Xiao
fa1bbce9c9 libc/stdio: allocate a buffer in getdelim() when *lineptr is NULL
POSIX requires getdelim()/getline() to allocate a new buffer whenever
*lineptr is NULL, regardless of the value of *n.  The previous code read
the buffer size from *n unconditionally and only fell back to the initial
size when *n was zero, so a caller that passes *lineptr == NULL together
with an uninitialized (non-zero) *n caused lib_malloc() to be invoked with
that garbage size and typically fail with ENOMEM.

Treat a NULL *lineptr the same as a zero *n: (re)allocate from the known
BUFSIZE_INIT and ignore the untrusted *n.  This matches the glibc
behaviour that portable code relies on (for example toybox grep, which
calls getdelim() with an uninitialized size variable).

Signed-off-by: Xiang Xiao <xiaoxiang@xiaomi.com>
2026-09-23 12:52:09 +08:00
Ahmed Ashraf NourEldeen
af65d2e04a arch/xtensa/espressif: Add IRQ lookup by interrupt handle.
Add esp_get_irq() to retrieve the IRQ associated with an interrupt
handle.

This allows the ESP OS abstraction to recover the IRQ when freeing an
interrupt from its handle.

The corresponding change in esp-hal-3rdparty is required to use this
API when freeing interrupts.

Related: #20216

Signed-off-by: Ahmed Ashraf NourEldeen <a.programmer55559@gmail.com>
2026-09-23 12:22:26 +08:00
Ahmed Ashraf NourEldeen
162369111e arch/risc-v/espressif: Add IRQ lookup by interrupt handle.
Add esp_get_irq() to retrieve the IRQ associated with an interrupt
handle.

This allows the ESP OS abstraction to recover the IRQ when freeing an
interrupt from its handle.

The corresponding change in esp-hal-3rdparty is required to use this
API when freeing interrupts.

Related: #20216

Signed-off-by: Ahmed Ashraf NourEldeen <a.programmer55559@gmail.com>
2026-09-23 12:22:26 +08:00