Add an opt-in STM32N6_DEBUG setting to reopen the debug access port and
secure/non-secure debug at the current BSEC protection level. Enable the
BSEC clock and configure access before clock and memory initialization so
a debugger can attach to a flash-booted development image.
Assisted-by: Codex:GPT-6
Signed-off-by: raiden00pl <raiden00@railab.me>
In the nominal ROM clock configuration, flash boot leaves PLL1 driving
the CPU at 400 MHz. Skipping clock setup when PLL1 is already selected
makes SysTick run twice as fast as the board's 200 MHz configuration
expects.
Switch CPU and system clocks to HSI before reconfiguring PLL1, then apply
the board clock tree.
Remove the incorrect comments claiming CFGR1 and CFGR2 lock after the first
clock switch.
Assisted-by: Codex:GPT-6
Signed-off-by: raiden00pl <raiden00@railab.me>
Add stm32h7s8-dk board support for nsh running out of internal flash,
including LEDs and user button.
Signed-off-by: Peter Barada <peter.barada@gmail.com>
spi_setfrequency() in pic32mz_spi.c rounded the baud rate divisor down,
so the SCK frequency could be higher than the one requested by the
device driver (e.g. 20 MHz requested with a 100 MHz PBCLK2 gave 25 MHz).
A request above PBCLK/2 gave a zero divisor and a division by zero when
computing the actual frequency; the SST26 driver's default of 64 MHz
does that with any peripheral bus clock below 128 MHz.
Round the divisor up instead, so the actual frequency never exceeds the
requested one and the divisor is never zero. Boards whose requested
frequency is not an exact divisor of PBCLK/2 now run SPI at a lower
clock than before.
Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Daniel P. Carvalho <danieloak@gmail.com>
Indent the case labels of switch statements, wrap long lines, align
braces and add blank lines after declarations so that both files pass
checkpatch.sh. No functional change.
Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Daniel P. Carvalho <danieloak@gmail.com>
Re-indent the case labels of up_ioctl() and fix the remaining nxstyle
errors (long comment line, missing blank lines after declarations).
No functional change.
Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Daniel P. Carvalho <danieloak@gmail.com>
A task woken from a semaphore, a signal wait, a message queue or an event
wait gets its timeout watchdog cancelled, but most waiters set none, and
wd_cancel() then only takes the critical section to find that out.
Check WDOG_ISACTIVE() first at these call sites. Each already holds the
critical section, so wd_expiration() cannot be running the watchdog on
another CPU and the check is exact on SMP too. wd_cancel() itself keeps
its locked check.
Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
Add the blank line nxstyle wants after three declarations. No code
change.
Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
If the `etc_romfs.c` file already exists (and therefore the `etc` folder does not exist), there is no need to use this function.
Signed-off-by: simbit18 <simbit18@gmail.com>
ttyname_r() passed the caller buffer straight to fcntl(F_GETPATH)
whenever buflen >= TTY_NAME_MAX, but every FIOC_FILEPATH handler
writes the path bounded by PATH_MAX and ignores the caller buffer
size. A tty registered under a nested /dev path, or reached through
rpmsgfs, has a path longer than TTY_NAME_MAX and overwrote the caller
buffer, silently corrupting memory behind a zero return code. The
small-buffer branch had the same defect against its own stack local
char name[TTY_NAME_MAX]. Gate the direct write on PATH_MAX instead
and stage the path through a PATH_MAX path buffer obtained via
lib_get_tempbuffer(), returning ERANGE when it does not fit.
Verified on sim:nsh with a test driver registered at an 85-character
tty path: pre-fix, ttyname_r(buf, TTY_NAME_MAX) returned 0 and
smashed the canaries behind the buffer, and the small-buffer branch
panicked; post-fix both cases return ERANGE with the canaries intact.
Assisted-by: Claude Code (glm-5.3) <claude@anthropic.com>
Signed-off-by: Junbo Zheng <zhengjunbo1@xiaomi.com>
The Config.K0 cache algorithm applies to both the I- and the D-Cache,
but the startup code only initialized the tags of the caches that were
selected in Kconfig. With only MIPS32_ICACHE the D-Cache was enabled
with indeterminate tags. Initialize the tags of both caches whenever
K0 is made cacheable (like the XC32 startup code does), and add the
missing hazard barrier after writing Config.
MIPS32_ICACHE now selects MIPS32_DCACHE when the chip has one, so that
the D-Cache maintenance needed for DMA is built whenever the D-Cache is
in use.
Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Daniel P. Carvalho <danieloak@gmail.com>
Several bugs made the MIPS32 cache functions unusable:
- The range functions rounded the end address down instead of up and
stopped before it, so the last line was never handled. A range
within a single line started a loop that only ended when the address
wrapped around 4 GB, which took seconds.
- HIT_WRITEBACK_D was 0x15, which is Hit_Writeback_Inv_D. Hit
Writeback D is 0x19. up_clean_dcache() now uses it and
up_flush_dcache() uses Hit_Writeback_Inv_D.
- The *_all functions used Hit operations over a KSEG0 range the size of
the cache, which only affects lines caching that range. Use index
operations instead: Index_Invalidate_I, Index_Writeback_Inv_D and, to
discard the D-Cache, Index_Store_Tag_D with a zero tag.
- With CONFIG_MIPS32_CACHE_AUTOINFO the line size was computed with a
right shift instead of a left shift.
- The CACHE_OP loop label was "1", the same label the callers use to
skip the operation, and the branch delay slot was left to whatever
instruction followed.
- up_coherent_dcache() called up_invalidate_icache_all() even when it is
not built.
Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Daniel P. Carvalho <danieloak@gmail.com>
A carrier with a switch port wired MAC to MAC has no PHY on MDIO, and
ifup failed. With IMXRT_ENET_FIXED_LINK the configured PHY, or the
board's PHY list, is tried first; if none answers the MAC runs at
100 Mbps full duplex and SIOCGMIIREG reports the link up, so the
network monitor keeps the interface up.
Signed-off-by: Royyan Zahir <royzah@gmail.com>
This adds support for the OTP flash region in the STM32H5 via both
low-level functions and an eFuse lower half driver.
Assisted-by: Claude:claude-sonnet-5
Signed-off-by: Darryl Ring <darryl@bluerobotics.com>
Since the ELF linker script keeps .eh_frame, a relocatable --gc-sections
link leaves R_X86_64_NONE relocations for collected functions. The loader
rejected them, so no kernel-mode program could be loaded on x86_64.
Assisted-by: Claude:claude-opus-5.5
Signed-off-by: raiden00pl <raiden00@railab.me>
Add CONFIG_STM32_DAC_LL_OPS support to the common STM32 DAC driver
(stm32_dac_m3m4_v1). This provides low-level ops (llops) and helper
macros (DAC_ENABLE, DAC_WRITE_DRO, DAC_START_DMA, DAC_STOP_DMA,
DAC_DUMP_REGS) matching the existing interface in stm32l4 and stm32h7.
This allows real-time control applications (such as power converters,
inverters, and function generators) to operate the DAC peripheral directly
without char driver VFS overhead.
Assisted-by: Antigravity:gemini-3.8-flash
Signed-off-by: Daniel P. Carvalho <danieloak@gmail.com>
nxsig_abnormal_termination() popped the thread's pthread cleanup
handlers in the kernel, so in the protected and kernel builds a process
could get its own code called with kernel privilege by raising a fatal
signal. POSIX runs cleanup handlers on pthread_exit() and on acting upon
a cancellation; termination by a signal is as if by _exit(), which runs
none.
Signed-off-by: Royyan Zahir <royzah@gmail.com>
Add the blank line required by nxstyle between the local declaration and the following statement in task_restart().
Signed-off-by: yushuailong <yyyusl@qq.com>
Kernel threads use the statically allocated g_kthread_group. If initialization of the first kernel thread fails, the common error path currently passes that static object to kmm_free(), corrupting the kernel heap.
Only free dynamically allocated task groups and detach the failed group from the TCB before returning.
Assisted-by: OpenAI Codex
Signed-off-by: yushuailong <yyyusl@qq.com>
group_kill_children() marks the task group as exiting, but task restart reuses that same group. Leaving the flag set causes later group shutdown to skip child termination and changes cancellation behavior for threads created after the restart.
Clear GROUP_FLAG_EXITING after the old child threads have been removed so the reused group starts in its normal state.
Assisted-by: OpenAI Codex
Signed-off-by: yushuailong <yyyusl@qq.com>
Add support for high-cycle flash which can be used for EEPROM emulation.
Assisted-by: Claude:claude-opus-5.5
Signed-off-by: Darryl Ring <darryl@bluerobotics.com>
Select the cache line size from either ARMV7M_DCACHE_LINESIZE or
ARMV8M_DCACHE_LINESIZE, so the driver can also be used with D-cache
enabled on the i.MX RT1180 Cortex-M33.
Also fix the imxrt1180-evk USB DMA allocator alignment. Pad the header
to the 32-byte DMA alignment, so that the buffer remains aligned.
Signed-off-by: Jukka Laitinen <jukka.laitinen@tii.ae>
Fix the usb phy pll bring-up sequence to match the imxrt1170 and
imxrt1180 RM:
1 enable the reference clock for the pll
2 enable the pll regulator
3 release the phy from reset
4 power up the pll
5 configure the pll_sic[pll_div_sel]
Signed-off-by: Jukka Laitinen <jukka.laitinen@tii.ae>
Use Floyd cycle detection on the mutex wait-for chain so only threads that actually participate in a cycle are reported. This avoids omitting the last cycle member and incorrectly including threads that merely lead into a deadlock.
Also handle empty output buffers and document truncation semantics.
Assisted-by: OpenAI Codex
Signed-off-by: yushuailong <yyyusl@qq.com>
Any ecall below CONFIG_SYS_RESERVED reached the context switch and signal
return paths from U-mode: a process could crash the kernel or return to
S-mode through a signal return nobody dispatched.
Signed-off-by: Royyan Zahir <royzah@gmail.com>
Any svc below CONFIG_SYS_RESERVED reached the context switch and signal
return paths from EL0: a process could crash the kernel or return to
EL1 through a signal return nobody dispatched.
Signed-off-by: Royyan Zahir <royzah@gmail.com>
STM32G0B1 devices provide SPI2, but their chip configuration does not
select STM32_HAVE_SPI2. Since STM32_SPI2 depends on that capability,
an explicit CONFIG_STM32_SPI2=y request is dropped by Kconfig.
Select the capability for STM32G0B1 so boards can enable the existing
SPI2 driver. SPI2 remains disabled unless requested. Other chip
families and the driver implementation are unchanged.
The STM32G0B1 datasheet DS13560, section 3.23, documents SPI2:
https://www.st.com/resource/en/datasheet/stm32g0b1re.pdf
Verified before/after configuration on STM32G0B1RE and STM32G0B1CE,
with STM32G071RB as an unchanged control. The same one-line fix is
included in the Golgi STM32G0B1CE firmware build 7248, whose build and
hardware acceptance were recorded on September 25, 2026.
Assisted-by: Codex:GPT-6
Signed-off-by: jsanchez-2g <jsanchez@2g-eng.com>
Describe the GPT timer support on the RA8M1 platform page and the
Arduino shield header's D2-D13 GPIO mapping on the EK-RA8M1 board page,
including the ek-ra8m1:timer-gpio configuration used to test them.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Assisted-by: Claude:claude-sonnet-5
Signed-off-by: leocafonso <leocafonso@gmail.com>
Register GPT0 (32-bit) as /dev/timer0 and GPT9 (16-bit) as /dev/timer1
during bring-up.
Register the Arduino Uno shield header's D2-D5 as inputs and D6-D13 as
outputs through the generic GPIO expander driver, as /dev/gpio0-3 and
/dev/gpio4-11.
Add the ek-ra8m1:timer-gpio configuration (nsh plus both GPT channels,
the GPIO support above, and apps/examples/gpio and
apps/examples/timer_gpio), used to validate the GPT timer driver on
hardware with an oscilloscope.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Assisted-by: Claude:claude-sonnet-5
Signed-off-by: leocafonso <leocafonso@gmail.com>
Add the General PWM Timer (GPT) as a generic timer, registered as
/dev/timerN through the upper-half timer driver. GPT0-7 are 32-bit,
GPT8-13 are 16-bit, and the timeout can be changed while running.
Give each ICU event used by GPT its own enum value instead of a
__COUNTER__-based macro, since the latter can hand out a different
number at every use.
Live period changes to the same prescaler now reload through GTPBR
(the buffered period register) instead of stopping the counter,
matching Renesas's own FSP driver, and fix a hardware-confirmed bug
where an uninitialized GTPBR silently corrupted the period after the
first cycle.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Assisted-by: Claude:claude-sonnet-5
Signed-off-by: leocafonso <leocafonso@gmail.com>
The LPSPI_CCR register is write only in imxrt1180. Therefore, the existing
modifyreg32 calls can't be used to set the fields. Use direct putreg8
writes to update the PCSSCK, SCKPCS, DBT and SCKDIV.
Signed-off-by: Jukka Laitinen <jukka.laitinen@tii.ae>
At imxrt_lpspibus_initialize the code tried to read IMXRT_LPSPI_CR to
detect whether the SPI is already initialized. This doesn't work on
imxrt118x, if the LPSPI clock is still gated. But the gate is
opened only during the initialization. So this is a chicken-egg
problem.
Instead of reading the register, just have an "initialized" flag in
priv.
Signed-off-by: Jukka Laitinen <jukka.laitinen@tii.ae>
The table index and the nesting depth were checked by DEBUGASSERT only,
and arm64 and risc-v let the first number past the table through.
Signed-off-by: Royyan Zahir <royzah@gmail.com>
pgalloc() is a syscall in a kernel build. Its start was checked by
DEBUGASSERT only and its end not at all, so a user task could map pages
past ARCH_ADDRENV_VEND.
Signed-off-by: Royyan Zahir <royzah@gmail.com>
The check CI job runs nxstyle over the whole file once it is touched,
and mmcsd_ioctl()/mmcsd_iocmd() carried pre-existing violations: case
labels and their blocks were indented one level too shallow, and four
argument continuation lines exceeded 78 columns. Reindent the two
switch bodies and rewrap the long call sites (local buffer variables
for the CMD8/18/25 data pointers, operand-per-line for the CMD23
ternary). No functional change.
Signed-off-by: rikaken2004 <244897142+rikaken2004@users.noreply.github.com>
The non-DMA data paths discard the return value of SDIO_RECVSETUP in
mmcsd_readsingle() and mmcsd_readmultiple() and of SDIO_SENDSETUP in
mmcsd_writesingle(), mmcsd_writemultiple() and the CMD56 read/write
helpers, so when the lower half fails to set up the transfer the
driver still issues CMD17/18/24/25/56 and the failure only surfaces
later as an unrelated-looking transfer timeout. The DMA paths in the
same functions all check SDIO_DMARECVSETUP/SDIO_DMASENDSETUP, cancel
the transfer and propagate the error, so mirror that handling on the
non-DMA paths.
Signed-off-by: rikaken2004 <244897142+rikaken2004@users.noreply.github.com>
clock_get_sched_ticks() stored the value of read_seqbegin(), a
uint32_t, in an unsigned int and passed it back to read_seqretry().
Where int is 16 bits the copy is truncated, so once the 32-bit
sequence number passes 65535 read_seqretry() always reports a change
and the loop never ends. The sequence advances once per tick, so after
65536 ticks (11 minutes at 100 Hz) the next caller, the timer interrupt
itself, spins forever with interrupts disabled and the system stops.
Seen on the CDP1802 (16-bit int): NSH stopped answering after 55
minutes at 20 Hz. AVR has the same problem. hrtimer's readers of the
same lock already use uint32_t. Don't assume int is 32-bit :-D
Signed-off-by: Alan Carvalho de Assis <acassis@gmail.com>
Assisted-by: Claude Opus 5.5 (claude-opus-5-5)
O_DIRECTORY, O_NOFOLLOW, O_NOATIME, O_CLOEXEC, __O_SYNC, O_PATH and
__O_TMPFILE are defined as shifts by 16 to 22 bits. Where int is 16
bits (AVR, for example), these shifts exceed the width of the type:
GCC evaluates them to 0, and the -Wshift-count-overflow warning is not
shown because include/ is a system include directory. The oflags
argument of open() is an int, so it could not carry those bits anyway.
As a result, on arch with int equal 16-bit opendir() opens directories
without O_DIRECTORY, so opening a mount point such as /proc fails with
ENOENT, and O_CLOEXEC and O_NOFOLLOW have no effect.
When UINT_MAX is 0xffff, use the unused bits 2 to 4 for O_DIRECTORY,
O_CLOEXEC and O_NOFOLLOW, define O_NOATIME and __O_SYNC as 0 (O_SYNC
falls back to O_DSYNC), and leave O_PATH and O_TMPFILE undefined, so
that code which needs them fails to build instead of silently opening
with the wrong flags; nothing in the tree uses them. _O_MAXBIT becomes
15. On bigger systems (32-bit, 64-bit) keep the original bit shift.
Signed-off-by: Alan Carvalho de Assis <acassis@gmail.com>
Assisted-by: Claude Opus 5.5 (claude-opus-5-5)
A stopped oscillator sets OS in the seconds register and leaves stale
time behind, which the driver returned as the time. Return -EAGAIN, as
it already does before it is enabled, so the clock starts unset instead
of wrong. Setting the time clears OS.
Signed-off-by: Royyan Zahir <royzah@gmail.com>