The PMS grants and refuses physical addresses, so it never sees an access
that no MMU entry translates. The cache answered such an access with zeros
and raised nothing, and the task carried on with a value it never should
have had.
Enable EXTMEM_MMU_ENTRY_FAULT and route the Cache Invalid Access interrupt
to the handler that already serves the PMS monitors. An unprivileged task
that makes the access is terminated with SIGSEGV; a privileged one still
panics. The latch is level triggered, so it is cleared with the others.
Read the cause before the clear, so the log tells the two apart: a PMS
violation is a refused translation, an MMU entry fault is an access that was
never translated.
Give the kernel_oct configuration the addresses that examples/sandbox needs
to name its targets.
Assisted-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
When an unprivileged task takes a fault the system cannot recover from, it
now gets a fatal SIGSEGV and only that task ends. A fault in privileged code
still panics.
What decides it is the interrupted context, not the cause: the saved PS says
whether the fault was taken in User Mode. A list of causes would leave every
cause off the list as a way for a user task to stop the machine, and there
are many -- a divide by zero, a privileged instruction, a load/store error,
and an illegal instruction, which is how a refused fetch from kernel text
arrives on this chip (TRM v1.8 p.699: a denied external-memory access is
answered with 0xdeadbeaf instead of trapping). PS.UM is clear in a kernel
thread, in a system call made on the user's behalf and in an interrupt
handler, so those still panic. If the recoverable-fault dispatcher is
enabled it still gets first refusal on causes 28, 29 and 20, the only ones
re-executing can help.
esp32s3_userfault_abort() records the exception frame as the task's context,
dispatches SIGSEGV, and returns the redirected frame, so the vector's RFE
resumes the task in the signal trampoline, whose default action exits it.
CONFIG_ESP32S3_USERFAULT_ABORT enables it, default y wherever there is an
unprivileged world, and selects SIG_DEFAULT and SIG_SIGKILL_ACTION.
Verified on an ESP32-S3 DevKitC with a WROOM-2 module,
esp32s3-devkit:kernel_oct: a user task that writes through NULL, reads a wild
address, divides by zero, calls into a buffer of garbage or branches into
kernel text is terminated on its own, while an unrelated task keeps running.
Stack overflow is not contained. On the windowed ABI it faults inside the
window overflow handler and arrives as a double exception with PS.UM already
clear; guard pages are the answer, and separate work.
Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
Separate the world split from the protected user image, give WORLD1 its own
vector table and its own PMS permissions -- including the PSRAM -- clean up
the user cache-MMU windows, and stop keeping the page pool mapped.
Folds in:
xtensa/esp32s3: separate the world split from the protected user image
xtensa/esp32s3: give the unprivileged world its own vector table
xtensa/esp32s3: give the unprivileged world its permissions
xtensa/esp32s3: clean up the user cache-MMU windows
xtensa/esp32s3: stop keeping the page pool mapped
xtensa/esp32s3: give the PSRAM its own PMS permissions
Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
Implement the same initial clock configuration as what imxrt1176 has. Make an own table
for PLL and root clock configurations for m33 and m7 targets. For the PLLs the code still
only supports configuring the ARM_PLL.
The difference to imxrt1176 is, that instead of just boolean .enable field, this table
uses an .action field with 3 states: CONFIGURE, DISABLE and IGNORE. The reason is,
that some root clocks can't be just forcefully stopped, but need a root-clock-specific
sequence. This is solved by just leaving these clocks marked as IGNORE, so they retain
their current state.
Specifically, disabling the SEMC and NETC roots by M33 will prevent the M7 from booting.
Also FLEXSPI shouldn't be touched, if the code is being executed from there.
Also add a function for enabling 24 MHz oscillator clock, and an extendable function to
enable the clock sources based on the clock configuration table.
Assisted-by: Claude Code
Signed-off-by: Jukka Laitinen <jukka.laitinen@tii.ae>
Add board support for the EK-RA8M1 evaluation kit with nsh and
nsh-leds configurations, linker script, LED support and bring-up.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Signed-off-by: leocafonso <leocafonso@gmail.com>
Add CMake build support for the stm32l476vg-disco board by introducing
board and source CMakeLists.txt files.
This allows the stm32l476vg-disco:nsh configuration to build successfully
with the CMake build system.
Fixes: #20366
Signed-off-by: Ahmed Ashraf NourEldeen <a.programmer55559@gmail.com>
Publishes /proc/pinctrl on both boards, which lists every pad with the
function it currently carries. The startup banner counts how many pads
differ from their reset values, once, at boot; this answers the same
question at any later moment, which is what is wanted when a driver has
just reconfigured a pad and the result is not what was expected.
PINCTRL_PROCFS depends on FS_PROCFS_REGISTER, the entry registering
itself at run time rather than being one of the built in ones. Neither
board set it, and without it the symbol is dropped when the configuration
is regenerated and the entry never appears, which is silent: the
defconfig still reads as though the feature were on.
Assisted-by: Claude:claude-opus-5
Signed-off-by: Justin Hammond <justin@dynam.ac>
Log one line from board start up with the pad count and how many differ
from their reset defaults, through eic7700x_pinctrl_count(). A helper
holds its locals so nothing stays on the stack for the bring up that
follows.
Turn the pinctrl driver's error output on for both boards, so a refused
pad write says why rather than merely failing.
Assisted-by: Claude:claude-opus-5
Signed-off-by: Justin Hammond <justin@dynam.ac>
A module's D-Space is separate from its I-Space, so its read-only data is not
at a fixed offset from its text. GCC assumes that it is and loads a string
literal PC-relative, which reads I-Space at run time. A module could
therefore carry no string and reach no static.
lm3s6965-ek has had -mno-pic-data-is-text-relative in its own Make.defs since
2021 (issue #3737), and the CMake build gives it to every PIC configuration,
so the flag moves to where it belonged and the board's copy goes. That copy
also probed for GCC older than 4.9.4, which NuttX no longer supports. Clang
has no such option, hence the guard.
Assisted-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
Suppress the peer notifications while a ring keeps delivering work, batch
the receive completions into one kick per burst and drop the redundant
txdone signal from the transmit path. Validate the peer controlled frame
lengths, accept descriptor chains on both lanes, keep every ring access on
the upper half's work thread so the interrupt context callbacks stay lock
free, and prefer the MAC from the configuration space, falling back to the
Kconfig address or a random one.
Signed-off-by: zhanghongyu <zhanghongyu@xiaomi.com>
kernel_oct targets a WROOM-2 N32R8V: octal flash, and 8 MB of PSRAM for the
page pool. The defaults size the pool for that part, with 8 pages of 64 KiB
for each of the text, data and heap regions, so 1.5 MB per process. fork()
duplicates the address environment, so a parent and a child need 3 MB at once
and a module with 2 MB of PSRAM cannot do it.
kernel_n8r2 sizes the same build for such a module. Each region is 2 pages,
so a process takes 384 KiB and a fork() peaks at 768 KiB, inside a 1.5 MB pool
placed at 0x80000 to leave the start of the PSRAM alone.
The flash is quad and runs in DIO mode, so this configuration also exercises
the CONFIG_ESP32S3_FLASH_MODE_OCT guard in kernel-space.ld from the quad side,
which kernel_oct cannot.
This is tight by construction. ostest has 115 KiB of text against a 128 KiB
text region. A larger program needs a module with more PSRAM, not a larger
pool.
Verified on an ESP32-S3-DevKitC with an N8R2 module, 8 MB flash in DIO mode
and 2 MB of embedded quad PSRAM. ostest reports "Parent and child had
independent memory" and exits with status 0.
Assisted-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
The page pool is carved out of the PSRAM that user processes run from, and
the external memory permissions are indexed by physical address, so a
permanent kernel window onto the pool is a window onto every process, which
no permission setting can close.
Stop mapping the pool. The kernel reaches a pool page through a small
scratch region instead, mapped for one operation and invalidated afterwards.
esp32s3_pgmap() takes a slot, esp32s3_pgunmap() releases it, and
ARCH_KMAP_VBASE and ARCH_KMAP_NPAGES describe the region. Two slots are
enough, because the deepest user is up_addrenv_fork(), which holds a source
and a destination page at once.
Assisted-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
The common Xtensa BUILD_KERNEL support needs the chip to say what it can do
and where its memory goes.
The chip selects the address environment options it now implements, keeps the
kernel and user heaps apart, and the linker scripts separate kernel from user
text and data so the two worlds can be given different permissions.
kernel_oct configures a board for it, with the user-program layout and the
boot ROMFS a kernel build loads its programs from. The ROMFS placeholder is
rebuilt with the image, the generated copy is ignored, and the programs are
given stack sizes and room for a fork() child.
Assisted-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
Give the ESP32-S3 the arch_addrenv_t machinery that BUILD_KERNEL needs: a
per-process page directory built from the 64 KiB MMU pages of the chip, with
allocation, teardown, and the vaddr-to-paddr translation that the kernel uses
to reach a user buffer.
The MMU, PMS and WCL primitives are exposed as an arch API first, because the
address environment code and the protected user split both need them and
neither owns them.
Assisted-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
The protected kernel linker (kernel-space.ld) placed the octal (OPI)
flash bring-up helpers -- esp_rom_spiflash / esp_rom_opiflash_*,
spi_flash_oct_flash_init, mmu_hal, mspi_timing_*, bootloader_flash*,
efuse_hal/efuse_utility, esp_mmu_map and esp32s3_spi_timing -- in mapped
flash. During configure_cpu_caches() / spi_flash_init_chip_state() in
__start these run while the flash mapping is being reconfigured, which
faults (illegal instruction) on octal-flash modules such as the
ESP32-S3-WROOM-2. Quad-flash parts never exercise the OPI path, so the
problem was latent.
Place those functions in .iram0.text (mirroring the flat sections
script) so they are safe to execute during flash reconfiguration.
Assisted-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
The TRDC (Trusted Resource Domain Controller) configuration should be completely
driven by the board configuration, and not hard-coded:
- Add tables for the current GPIO configuration and MDA configuration.
- Fix the GPIO configurations for M7; previously GPIO access from M7 was
denied because of secure/nonsecure setting.
Signed-off-by: Jukka Laitinen <jukka.laitinen@tii.ae>
Add NSH bringup for the Espressif ESP8684-DevKitM. The nsh defconfig
uses a 26 MHz XTAL, 4 MB flash, and debug features for the MINI-1 module.
Assisted-by: Claude:claude-opus-5
Signed-off-by: Marcio Ribeiro <marcio.ribeiro@espressif.com>
Add linker scripts and shared board drivers reused by ESP32-C2 boards,
and wire common Kconfig into the board configuration tree.
Assisted-by: Claude:claude-opus-5
Signed-off-by: Marcio Ribeiro <marcio.ribeiro@espressif.com>
Recently the nxstyle became more restrictive so it got some issues
that used to be ignored in the pass.
Signed-off-by: Alan C. Assis <acassis@gmail.com>
The X11 mouse emulation driver (arch/sim/src/sim/sim_mouse.c) is built
and fed by the X11 event loop whenever CONFIG_SIM_MOUSE=y, but nothing
ever called sim_mouse_initialize(), so /dev/mouse0 was never registered
and applications could not read any mouse reports. Since nothing
referenced sim_mouse.o, the linker did not even pull it in and the
build failed with "undefined reference to `sim_mouseevent'".
Call sim_mouse_initialize(0) from sim_bringup(), next to the existing
touchscreen and keyboard initialization.
Tested with sim:nsh + CONFIG_SIM_X11FB, CONFIG_SIM_MOUSE and
CONFIG_SIM_KEYBOARD: /dev/mouse0 is now listed and reports left, middle
and right button state plus pointer motion.
Signed-off-by: Alan C. Assis <acassis@gmai.com>
Assisted-by: Claude Opus 5.5 (1M context)
Expose the RTL8730E general-purpose UARTs through the shared Ameba
serial driver (arch/arm/src/common/ameba/ameba_uart.c) by adding the
chip-specific glue, build wiring and a board port table. The change is
gated by CONFIG_AMEBA_UART (default disabled); the LOG-UART keeps the
console and /dev/ttyS0.
Chip glue (ameba_uart_chip.h) supplies the three UART controller
register bases, GIC IRQ numbers (SPI 50/51/52 -> NuttX IRQ 82/83/84),
APB clock masks and pin-mux codes. The board registers UART0-2 as
/dev/ttyS1-3 at 115200 8N1; UART3 is reserved for Bluetooth. Pads are
picked from the EVB break-out (the UART crossbar maps each controller to
many pads, so this is purely a board choice).
Also fix an RX-timeout interrupt storm in the shared driver: the
RX-timeout status (LSR bit9) is latched and is not cleared by draining
the RX FIFO, so on a level-triggered GIC (RTL8730E) the ISR must
explicitly write TOICF, matching the vendor SDK serial_api.c. The
extra register write is harmless on the NVIC-based M33 Ameba parts and
was regression-tested on them.
Signed-off-by: dechao_gong <dechao_gong@realsil.com.cn>
Assisted-by: Claude <noreply@anthropic.com>
Under sustained dual-core critical-section traffic (e.g. several UART
ISRs) the two Cortex-A32 cores live-lock trading failed STREX. The
generic critical-section lock g_cpu_irqlock (an LDREX/STREX spinlock)
and the plain non-atomic bitmap g_cpu_irqset are defined back-to-back
in sched/irq/irq_csection.c and land in the same 64-byte cache line.
The A32 exclusive monitor reserves a full cache line, so one core's
ordinary store to g_cpu_irqset clears the other core's LDREX
reservation on g_cpu_irqlock.
Separate the two symbols onto their own cache lines in the board link
script, leaving the generic scheduler source untouched (relies on the
toolchain emitting per-object -fdata-sections).
Signed-off-by: dechao_gong <dechao_gong@realsil.com.cn>
Assisted-by: Claude <noreply@anthropic.com>
Add an initial port for the AIFoundry Erbium Minion core running on the
public ET-platform system emulator (erbium_emu). NuttX boots directly
from a firmware ELF at 0x40000200, runs in machine mode on hart 0 with
SMP disabled, and parks secondary harts before they touch memory.
The chip layer provides startup, PLIC interrupts, the UART0 console
driver and the machine timer. Context switching, FPU save/restore,
heap, idle and timer handling reuse the common RISC-V code. Atomics use
interrupt masking because the core does not implement the A extension.
Erbium implements the F extension but executes fdiv/fsqrt and FENCE.I
in microcode, which a standalone image does not provide. The board build
files pass -mno-fdiv to GCC when the FPU is enabled, so those operations
use software helpers. Startup initializes the FPU without the common
FENCE.I sequence, and the board configurations disable the dynamic ELF
loader, which also relies on FENCE.I.
Add minion:nsh and minion:ostest configurations, Make and CMake
support, CMake CI build entries, and a host script that runs prebuilt
images in the emulator and checks the console and OS test results.
Tested with emulator revision 836a4ab600e9 and xPack GCC 14.3.0: both
configurations build with Make and CMake, ostest exits with status 0
including the FPU tests, and the NSH console, procfs, timer and UART
receive paths work. Silicon, SMP, protected builds and reboot are not
covered by this initial port.
Signed-off-by: Afonso Oliveira <afonso.oliveira707@gmail.com>
A MIMXRT1176 flight controller built to the Pixhawk FMUv6X-RT standard, so
the port also covers the NXP MR-VMU-RT1176.
Board data comes from PX4, which already carries it as a NuttX board config:
the clock tree, the LPUART1 pinmux, and the Macronix octal flash
configuration block the boot ROM reads at offset 0x400.
The board ships with the PX4 bootloader in the first 128 KB of QSPI, so the
image links at 0x30020000 and is loaded by it rather than written to the
flash base. The console is CDC/ACM as on teensy-4.x, so a USB cable is the
only thing needed to run NuttX here.
Signed-off-by: Royyan Zahir <royzah@gmail.com>
The flexspi_nor_config_s was missing four fields, resulting the fields after the
missing ones being read from wrong positions.
Align the struct properly according to the reference manual.
Signed-off-by: Jukka Laitinen <jukka.laitinen@tii.ae>
Correct switch and declaration indentation, separate declarations from code,
and wrap a long comment in the SPI driver. Fix the timer driver and both
STM32L5 board LED implementations checked by the commonization PR.
These are formatting changes only.
Signed-off-by: raiden00pl <raiden00@railab.me>
Select STM32_HAVE_IP_GPIO_M33_V1 and STM32_HAVE_IP_EXTI_M33_V1 and
drop the family GPIO and EXTI sources and headers in favor of the
common Cortex-M33 v1 implementation.
Define both EXTI register banks and retain the named bit definitions.
Use shared line and selector helpers without per-line conditionals.
Clear each GPIO selector with the same byte mask, as the H5 driver does.
Cover both 32-bit banks and H5 line inventories for later migration.
The common EXTI driver also routes the selected port through EXTICR,
which the family driver never programmed, so GPIO interrupts now work
on ports other than GPIOA.
Signed-off-by: raiden00pl <raiden00@railab.me>
Assisted-by: Claude Code
The FIFO watermark flag is a level: it stays high until the worker
actually drains the FIFO below the threshold. Configuring INT1 as RISING
made that a race the driver could lose permanently.
lsm6ds3trc_interrupt() disables its IRQ on entry and re-enables it after
the worker has run. With an edge trigger, if the line is still high when
the IRQ is re-enabled -- which is precisely what happens whenever a drain
does not take the FIFO below the watermark -- there is no new low-to-high
transition left to detect, and the line goes mute forever. Observed as a
board that serviced exactly one watermark after boot and then never
again, reproducible 2 out of 2 reflashes.
ONHIGH matches the physical meaning of the pin and is immune to it: a
level trigger re-asserts on its own for as long as the condition holds,
and the disable/enable pairing around servicing is what stops that from
live-locking.
Validated with more than 900 consecutive drains (~100 min) including real
sleep -> GPIO-wake -> resume transitions, the exact case that used to
wedge.
Signed-off-by: Felipe Moura <moura.fmo@gmail.com>
Assisted-by: Claude:claude-opus-5
Wire the shared ameba_gpio driver to the RTL8730E CA32 core.
The CA32 replaces the vendor CA32 OS as BL33; the SDK startup that
normally initialises GPIO_PORTx[] never runs under NuttX. The three
GPIO port base addresses are patched at runtime inside
rtl8730e_gpio_initialize() before any ROM GPIO function is called.
GPIO_INTStatusGet and GPIO_INTStatusClearEdge are absent from the
RTL8730E ROM and are provided as static inline helpers in the new
ameba_gpio_chip.h.
Key changes:
- ameba_gpio_chip.h (new): chip parameters, split AMEBA_APBPERIPH_GPIO
/ AMEBA_APBPERIPH_GPIO_CLK bits, inline INTStatus helpers
- ameba_gpio.c: add AMEBA_APBPERIPH_GPIO_CLK fallback macro so chips
with separate periph/clock enable bits work without driver changes
- Make.defs: enable ameba_gpio.c + rtl8730e_flash_stubs.c + lib_rom.a
under CONFIG_AMEBA_GPIO; consolidate flash_stubs into GPIO||FLASH_FS
- ameba_board.mk: remove duplicate lib_rom.a (Make.defs is authoritative)
- rtl8730e_flash_stubs.c: make _strcmp weak; delegate Pinmux_Config to
lib_rom.a's _Pinmux_Config so GPIO pad mux is configured correctly
- Kconfig: source common/ameba/Kconfig to expose CONFIG_AMEBA_GPIO
- dramboot.ld: include .sramdram.only.data in .data so GPIO_PORTx[] is
copied to RAM by the normal arm_data_initialize() path
- scripts/Make.defs: extend --no-warn-mismatch to GPIO and WiFi configs
- rtl8730e_gpio.c (new): pin table (PB19 output /dev/gpio0, PB20 input
/dev/gpio1, PB11 falling-edge interrupt /dev/gpio2) + GPIO_PORTx patch
- configs/gpio/ (new): defconfig for GPIO example verification
- nxstyle.c: add _Pinmux_ to mixed-case whitelist (ROM symbol)
Hardware verified on RTL8730E CA32:
- PB19 output write 0/1, readback matches
- PB20 input reads PB19-driven level
- PB11 falling-edge interrupt triggers correctly
Signed-off-by: dechao_gong <dechao_gong@realsil.com.cn>
Assisted-by: Claude <noreply@anthropic.com>
nsh plus networking over the rptun/virtio-net link to the A53: enables
DRIVERS_VHOST_NET with the buffer sizing the link needs (IOB pool and chains,
NET_LL_GUARDSIZE covering the ethernet and virtio-net headers) and ICMP
sockets for ping. Also gives CI an in-tree configuration that compiles the
vhost-net driver.
Verified on t3-gem-o1: ifup, then ping from the peer with 0% loss.
Assisted-by: Claude Code:claude-fable-5
Signed-off-by: Ulaş Sertan Kemeç <sertan.usk@gmail.com>
Adopt the zbus message bus on the linum-stm32h753bi (first adopter
board):
- scripts/flash.ld: include the iterable sections common fragments
(2 lines: common-rom.ld inside .text, common-ram.ld inside .data).
- configs/zbus/defconfig: board configuration enabling zbus with all
observer types, the zbus example and its cmocka test suite
(./tools/configure.sh linum-stm32h753bi:zbus).
- Board documentation: describe the new configuration.
Validated on hardware: the 16-test cmocka suite passes twice in the
same boot and the zbus example produces the expected output.
Assisted-by: Claude Code
Signed-off-by: Jorge Guzman <jorge.gzm@gmail.com>
platform_autoconf.h is a hand-maintained minimal header that provides the
SDK #defines required by the fwlib sources compiled during PREBUILD. Unlike
the other Ameba ICs (which use ameba_gen_autoconf.sh to regenerate it from
SDK menuconfig), RTL8730E uses a static file because the amebasmart SDK
does not ship a pre-generated autoconf and running menuconfig in CI is not
feasible.
The file was previously gitignored along with all other prebuilt/ artifacts,
so CI had no platform_autoconf.h on a clean clone, causing:
fatal error: platform_autoconf.h: No such file or directory
Fix: add !platform_autoconf.h exception to prebuilt/.gitignore and track
the file in git. Local clean build verified (nuttx.bin 550 KB generated).
Signed-off-by: dechao_gong <dechao_gong@realsil.com.cn>
Assisted-by: Claude <noreply@anthropic.com>
Two CI issues in the RTL8730E (AmebaSmart CA32) port:
1. PREBUILD used $(ARCHOPTIMIZATION) which injects --param=min-pagesize=0
on GCC>=12. arm-none-eabi-gcc in CI does not recognise this flag.
Fix: replace $(ARCHOPTIMIZATION) with explicit -Os -ffunction-sections
-fdata-sections in both the fwlib and wifi PREBUILD loops, matching the
pattern already used by the other Ameba ICs (rtl8721dx/8720f/8721f).
2. boards/arm/rtl8730e/rtl8730e_evb/configs/nsh/defconfig was out of sync
with `make savedefconfig` output (missing CONFIG_ARCH_CHIP_RTL8730E_CA32,
wrong ordering of several NETUTILS options, and redundant entries that
are auto-selected by Kconfig). Regenerated with olddefconfig+savedefconfig.
Signed-off-by: dechao_gong <dechao_gong@realsil.com.cn>
Assisted-by: Claude <noreply@anthropic.com>
Add the rtl8730e_evb (RTL8730E Evaluation Board) with an nsh configuration
that demonstrates the RTL8730E baseline feature set:
- Dual-core SMP (CONFIG_SMP=y, CONFIG_SMP_NCPUS=2)
- Wi-Fi station and SoftAP via wapi
- DHCP client (wlan0) and DHCP server (wlan1/AP mode)
- littlefs persistent storage at /data on SPI NOR flash
- iperf2 TCP/UDP throughput measurement
- NSH console over the LOG-UART
Board formerly named ca32-evb; renamed to follow the rtlXXXX_evb
convention used by all other Ameba boards.
Signed-off-by: dechao_gong <dechao_gong@realsil.com.cn>
Assisted-by: Claude Sonnet 4.6 <noreply@anthropic.com>
Replace the CMake skeleton with full SDK build machinery, mirroring
the make-side ameba_board.mk. RTL8730E differs from the KM4-based
ICs in three ways that prevent a direct include(ameba_board.cmake):
- No SDK autoconf / image2 ldscript generation: the board uses its own
dramboot.ld and a static prebuilt platform_autoconf.h
- No NP firmware build: KM0/KM4 are prebuilt blobs in prebuilt/
- No -mcmse: CA32 is ARMv7-A, not Cortex-M33; uses -DCONFIG_ARM_CORE_CA32
The ameba_build_lib() helper (adapted from ameba_board.cmake) compiles
SDK sources with an isolated flag set into libameba_fwlib.a and
libameba_wifi.a, avoiding NuttX header conflicts.
Key additions:
- libameba_fwlib.a: arch.c + log.c + sscanf_minimal.c always; IPC for
WiFi/FlashFS; ameba_flash_ram.c for FlashFS
- lib_rom.a linked for GPIO or FlashFS (GPIO_Init, Pinmux_Config, etc.)
- libameba_wifi.a + prebuilt WHC host libs for WiFi
- VFS1 geometry extracted from platform_autoconf.h via
target_compile_definitions (set_property(SOURCE) has scope issues in
NuttX's include()-based CMake structure)
- `flash` target calls ameba_smart_flash.sh
Verified: gpio (1186 targets) and nsh (1530 targets) configs both
build cleanly; /data mounts at correct 2 MB partition size.
Signed-off-by: dechao_gong <dechao_gong@realsil.com.cn>
Assisted-by: Claude Sonnet 4.6 <noreply@anthropic.com>
RTL8730E has dual Cortex-A32 cores (CA32) in the AP domain. Core1 is
powered off by default and requires an explicit HSYS power-on sequence
before ATF SP_MIN can service the PSCI CPU_ON call. Without it, SP_MIN
writes the entry point to the mailbox and times out waiting for Core1 to
poll it.
Add rtl8730e_core1_power_on() that mirrors SDK smp.c:rtk_core1_power_on():
assert reset, assert isolation, two-stage power-on with up_udelay() for
correct 50/50/500/50 us timing, then release isolation and reset. Call it
from up_cpu_start() before psci_cpu_on().
Enable CONFIG_SMP / CONFIG_SMP_NCPUS=2 / CONFIG_ARM_PSCI in the nsh
defconfig.
Enabling SMP also exposed a latent WHC skb alignment bug: the Realtek
WHC WiFi driver keeps the AP/NP DDR views coherent with by-VA
DCache_Clean/Invalidate at SKB_CACHE_SZ (64 on RTL8730E) granularity,
which requires every skb buffer to be cache-line aligned. The port had
omitted CONFIG_MM_DEFAULT_ALIGNMENT (defaulting to 8; the 8721Dx parts
set 32), so heap-allocated skb buffers were unaligned and the cache
maintenance spilled onto the neighbouring skb struct, corrupting its
immutable buf pointer (seen as skb->buf = 0x05 and a TX memcpy data
abort on "renew wlan0"). This was harmless on single core -- the
non-shareable DDR mapping made the stray maintenance a no-op -- but the
SMP shareable mapping plus real dual-core concurrency turned it into a
hard fault. Set CONFIG_MM_DEFAULT_ALIGNMENT=64 in the nsh defconfig.
Hardware verified on RTL8730E (C-cut): /proc/cpuinfo shows both processor 0
and processor 1; getprime 2 completes two concurrent threads in ~573 ms
(same as single-thread), confirming true parallel execution across both cores.
"renew wlan0" now obtains a DHCP lease (192.168.1.101) without faulting.
Assisted-by: Claude Sonnet 4.6 <noreply@anthropic.com>
Signed-off-by: dechao_gong <dechao_gong@realsil.com.cn>
Add NuttX support for the Realtek AmebaSmart (RTL8730E) running on the
CA32 (Cortex-A32) application core, with the KM4/KM0 cores kept as
vendor firmware (KM4 acts as the WiFi network processor over WHC IPC).
Stage 1 bring-up, hardware verified:
- CA32 boot / exception vectors / MMU + page allocator / heap
- LOGUART console (RX via KM0-owned IPC + shared memory)
- IRQ controller, timer, serial
- On-chip SPI NOR flash MTD -> littlefs mounted at /data
- WHC-host WiFi netdev (STA): scan / connect / DHCP, verified end to
end (association -> 4-way -> DHCP -> ping, bidirectional TCP)
IC-agnostic Ameba glue is shared from arch/arm/src/common/ameba via a
relative VPATH entry (matching the rtl8721dx pattern), which also avoids
the empty mkdeps --dep-path that a leading-":" VPATH entry produced and
which intermittently broke parallel .ddc dependency generation.
The FIP packaging / flash image assembly is driven by
common/ameba/tools/ameba_smart_flash.sh from the board scripts.
Vendor blobs and build artefacts under the board prebuilt/ directory are
kept out of the tree via prebuilt/.gitignore.
Signed-off-by: dechao_gong <dechao_gong@realsil.com.cn>
Makes /proc/reset available, so which peripherals are held can be read
while the board is running rather than only for the eight lines the
startup report names.
RESET_PROCFS depends on FS_PROCFS_REGISTER, which neither board set.
Without it the symbol is dropped when the configuration is regenerated
and the entry never appears, which is silent: the defconfig still reads
as though the feature were on.
Assisted-by: Claude:claude-opus-5
Signed-off-by: Justin Hammond <justin@dynam.ac>
A peripheral held in reset reads like one that is absent, and the boot
loader does not leave the same lines released on every board or every
boot. One line at startup says how much is held:
reset: 324 lines, 117 held
Beside the clock tree's line and for the same reason: the summary is
worth seeing on every boot, and the detail belongs in /proc where it can
be read when it is wanted.
The driver's error output is enabled, matching the clock driver. Info
level is not, since nothing at that level prints on a healthy boot.
Assisted-by: Claude:claude-opus-5
Signed-off-by: Justin Hammond <justin@dynam.ac>
Connects the R5F to Linux remoteproc over the NAVSS mailbox.
The mailbox ISR only drains the FIFO and acknowledges; OpenAMP delivery is
deferred to HPWORK, because the rpmsg rx path takes mutexes and allocates.
The resource table publishes two vdevs, rpmsg and virtio-net, leaving every
vring address FW_RSC_ADDR_ANY: Linux allocates them from the R5F DMA pool and
rejects fixed addresses outside it.
Shared IPC memory is mapped Non-cacheable, since the R5F is not coherent with
the A53 and cached mappings leave NuttX reading stale vring state.
Also drops the duplicate arm_mpu.c from CHIP_CSRCS.
Assisted-by: Claude Code:claude-fable-5
Signed-off-by: Ulaş Sertan Kemeç <sertan.usk@gmail.com>
CONFIG_EXAMPLES_COMP_DACPATH matched its Kconfig default value, which
make savedefconfig drops as redundant. The stale explicit line made
the committed defconfig differ from what a clean savedefconfig
produces, failing CI's defconfig-completeness check even though the
board builds fine either way.
Assisted-by: Claude:claude-sonnet-5
Signed-off-by: Daniel P. Carvalho <danieloak@gmail.com>
Implement ao_ioctl in stm32_comp_m3m4_v2.c to handle ANIOC_COMP_ENABLE and
ANIOC_COMP_DISABLE commands. Also add CONFIG_STM32_COMP_INIT_DISABLED to
allow keeping the comparator disabled after driver initialization until
explicitly enabled.
Update nucleo-g431kb:comp defconfig to enable CONFIG_EXAMPLES_COMP and
set default DAC path for comparator ramp verification.
Assisted-by: Gemini:gemini-2.5-pro
Signed-off-by: Daniel P. Carvalho <danieloak@gmail.com>
Add a standalone tool to create AHAB container for imxrt118x. This can
generate a trivial unsigned image without appending ELE.
The tool can be used to create bootable images for m33. To do anything
more complicated, the user needs to use the official SPSDK tool from
NXP.
Assisted-by: Claude Code:claude-opus-5-0
Signed-off-by: Jukka Laitinen <jukka.laitinen@tii.ae>