At the end of a directory the 9P server returns no entries.
v9fs_client_convertdir() then failed with -EIO, so readdir() returned
NULL with errno set to EIO at the end of every directory. A program
that checks errno after readdir() reports an I/O error.
Return -ENOENT when the server returns no entries. The VFS turns that
into a clean end of directory. Also check the space for the fixed part
of an entry against the bytes left after head, not against the whole
buffer.
Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
nxstyle reports a missing blank line after a declaration in
v9fs_vfs_ioctl(). No functional change.
Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
The QEMU virt machine has a PL031 RTC at 0x09010000 (SPI 2), which QEMU
sets from the host clock. qemu-armv8a did not register it, so the
system time started at CONFIG_START_YEAR, and files on a host share
(v9fs, hostfs) had times years in the future.
With CONFIG_RTC_PL031, up_rtc_initialize() now registers the PL031 as
the RTC, so the system time starts at the host's time.
The new option QEMU_RTC_PL031_SYNC makes the boot wait (up to a second)
for the RTC second to change. The PL031 counts whole seconds, so
without the wait the time starts up to a second behind the host.
Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
struct pl031_lowerhalf_s always had a struct lower_setalarm_s field,
but rtc.h defines that type only with CONFIG_RTC_ALARM, so the driver
did not compile without alarms. No configuration enabled RTC_PL031, so
nothing caught it. The field is used only by the alarm code; give it
the same condition.
Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
arch_setjmp.S stores d8-d15 only under CONFIG_ARCH_FPU, but it did not
include nuttx/config.h. So setjmp() never saved these registers and
longjmp() never restored them. They are callee-saved (AAPCS64), so a
function that kept a value in one of them could see it change after a
longjmp().
Include nuttx/config.h. The assembly then stores d8-d15, eight bytes
each, at offsets 112 to 176. struct setjmp_buf_s declared them as
eight 4-byte floats, 32 bytes short, so declare them as uint64_t too.
jmp_buf is now 176 bytes with the FPU, and its layout matches the
assembly.
Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
pgalloc() grows a process heap for sbrk(). It extended the address
environment of the running task (addrenv_own). While exec() sets up a
new process, the caller selects the new address environment and
allocates the new process's stack from its heap. When that stack does
not fit in the initial heap, the heap must grow, but the running task is
the caller. For the kernel thread that starts init this was an
assertion; for a user task it would have grown the caller's heap.
Use the selected address environment (addrenv_curr). For a normal sbrk()
it is the same as addrenv_own.
Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
C99 7.16 requires true and false to expand to the integer constants 1
and 0, suitable for use in #if. NuttX defined them as (bool)1 and
(bool)0, so a preprocessor condition such as "#if !true" did not
compile.
Define them as 1 and 0. The values do not change; only their type in
an expression changes, from bool to int, as the standard requires.
Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
<memory.h> declares the memory functions of <string.h>, such as
memcpy() and memset(). It is not in POSIX, but glibc, musl and newlib
provide it, and some programs still include it. On NuttX they failed:
fatal error: memory.h: No such file or directory
Add it. It only includes <string.h>.
Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
arch_mcount.S selects the ARMv6-M code with CONFIG_ARCH_CORTEXM0 and
CONFIG_ARCH_CORTEXM23, but it did not include nuttx/config.h. So it
always assembled the Thumb-2 code, and CONFIG_PROFILE_MINI did not
build on Cortex-M0, M0+ and M23:
arch_mcount.S:48: Error: cannot honor width suffix -- `bic r1,r1,#1'
Include nuttx/config.h.
Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
Both copies sized the buffer in one pass and filled it in another,
rereading user memory; a second thread could lengthen a string or the
list between them and overflow the kernel heap.
Signed-off-by: Royyan Zahir <royzah@gmail.com>
The INA226 driver was character mode only, and stayed that way after
everything around it moved, because the sensor framework had no type it
could publish: there was nothing for volts or amps until now.
Add the framework version beside it, in the shape the tree uses for a
part with both. The old driver is untouched and still builds by
default; the new one replaces it when SENSORS_INA226_UORB is set.
The part publishes three topics, voltage, current and power, from a
single reading that they all share the timestamp of. Reading once per
topic would put three transfers on the bus for one sample and, worse,
would leave the three values describing three different instants, which
is the wrong property for a power measurement: the product of a voltage
and a current measured at different moments is not the power at either.
The power is computed here rather than read from the part, because the
part's own power register needs its calibration register given a
current scale first, and multiplying two values already in hand does
not.
One worker feeds all three, so it starts when the first topic is
subscribed and stops when the last goes away, and the part is left
powered down until then rather than converting into a void.
Each topic keeps the interval it asked for and the worker runs at the
shortest of them, since one reading serves all three. Neither is taken
at face value: asking faster than the part converts returns the same
reading twice, and a period shorter than a clock tick rounds down to no
delay at all, which would leave the worker re-queueing itself with the
bus never idle. Both floors are applied and the caller is told what it
will actually get, which is what the interface is for.
The shunt is rejected if it is zero or negative, which would otherwise
divide by zero on the first reading.
Assisted-by: Claude:claude-opus-5
Signed-off-by: Justin Hammond <justin@dynam.ac>
Add uSD card driver configuration for 4-bit, HS mode 50MHz
- Add root clock configuration for the uSDHC
- Add pin muxing for the uSD card
- Add fat_dma_alloc and fat_dma_free functions
- Initialize the usdhc driver in board's init
Signed-off-by: Jukka Laitinen <jukka.laitinen@tii.ae>
This allows using >25MHz bus speeds by adding a configration option
to set SDIO_CAPS_SD_HS_MODE capability.
Signed-off-by: Jukka Laitinen <jukka.laitinen@tii.ae>
- Add the missing clock gating macros for imxrt118x
- Change sw_cd_gpio from int32_t to gpio_pinset_t (64-bits on 118x)
- Invalidate cache again after the data has been received. Cache might
be refilled by a prefetch or, in theory, by cpu read touching the same
cache line - even though the latter should not happen.
- Map any DMA accesses to/from DTCM to the shadow address window, which
gives the uSDHC DMA access to the DTCM.
Signed-off-by: Jukka Laitinen <jukka.laitinen@tii.ae>
Extend the underline to match the 28-character heading so the Sphinx
build does not fail with a title underline too short warning.
Assisted-by: Codex:GPT-6
Signed-off-by: jsanchez-2g <jsanchez@2g-eng.com>
Implement the MTD write callback when CONFIG_MTD_BYTE_WRITE is enabled,
allowing unaligned byte writes without changing existing block operations.
Reject ranges outside the physical device and return zero for valid empty
writes without SPI traffic.
Use the initialized SPI device ID, hold the bus lock across the request,
and issue write-enable for each transfer. With CONFIG_RAMTRON_CHUNKING,
split writes at the write-buffer boundaries of chunk-limited parts.
Document the optional callback and its bounds and chunk behavior.
Verified with mocked-SPI host tests, driver compilation with byte writes
and chunking enabled/disabled, and a Conductor STM32H743BI hardware test
covering single-byte and unaligned writes, surrounding-byte preservation,
invalid ranges, and restoration of the original FRAM contents. Hardware
coverage is limited to the installed 32 KiB part.
Assisted-by: Codex:GPT-6
Signed-off-by: jsanchez-2g <jsanchez@2g-eng.com>
With CONFIG_NET_PROMISCUOUS, also enable the multicast and "not me"
unicast receive filters (ETHRXFC MCEN and NOTMEEN), so that the MAC
accepts every frame on the link, as the option's help text describes.
Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Daniel P. Carvalho <danieloak@gmail.com>
Use init_main as the init entry point and enable SYSTEM_NXINIT with the
/etc ROMFS, so nxinit starts nsh as the console service.
Assisted-by: OpenCode:claude-sonnet-5
Signed-off-by: wangjianyu3 <wangjianyu3@xiaomi.com>
Add etc/init.d/init.rc and build it into the /etc ROMFS for Make and
CMake. The kernel-build romfs image uses the same ROM disk minor, so
skip it with CONFIG_ETC_ROMFS and register it only with BUILD_KERNEL.
Assisted-by: OpenCode:claude-sonnet-5 Kiro:claude-opus-5
Signed-off-by: wangjianyu3 <wangjianyu3@xiaomi.com>
CPP is also used to preprocess init.rc into the /etc ROMFS. Without -P
it emits GNU linemarkers, which nxinit's parser rejects.
Assisted-by: OpenCode:claude-sonnet-5
Signed-off-by: wangjianyu3 <wangjianyu3@xiaomi.com>
A JRCR reset only flushes and halts the job ring; a second reset, once
JRINT reports the halt done, completes it, as Linux's caam_reset_hw_jr()
does. With the single write the ring stayed halted, so the RNG
instantiate job never completed and every boot logged "job ring did not
answer" before the settle loop's second ring init finished the reset.
Signed-off-by: Royyan Zahir <royzah@gmail.com>
Add the Microchip EV49N51A Ethernet to Wi-Fi Bridge board, built around
the WFI32E01PE module (PIC32MZ-W1) with a LAN8720A Ethernet PHY.
The nsh configuration runs SYSCLK at 200 MHz with the console on UART1
(dedicated pins RA8/RA9, header J203, 115200 8N1) and drives the red and
green user LEDs on RK1/RK3. It selects PGC2/PGD2 as the debug channel.
The SST26VF032B serial flash on SPI1 (dedicated pins, CS on RA1) is
exported as /dev/mtdblock0. Its SPI frequency is set to 20 MHz: the SST26
driver's 64 MHz default is above PBCLK3/2 (25 MHz), which pic32mz_spi.c
does not handle.
mips-debug.ld is used with every toolchain. It has no OUTPUT_FORMAT,
because XC32 and Pinguino name their little-endian ELF targets
differently; the board passes -EL to the linker instead. With XC32 the
board builds with -mno-dsp -mno-dspr2: NuttX does not enable or save the
DSP ASE state.
Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Daniel P. Carvalho <danieloak@gmail.com>
Add the PIC32MZ-W1 family, used in Microchip's WFI32E01 Wi-Fi modules.
W1 shares the MIPS32 M-Class core and much of the peripheral IP with
PIC32MZ EC/EF, but its SFR map, IRQ vectors, PPS registers and
configuration words are laid out differently, so these are new files
selected by CONFIG_ARCH_CHIP_PIC32MZW1:
- hardware/pic32mzw1_*.h, irq_pic32mzw1.h: memory map, PPS, IRQ vectors
and configuration words, from the PIC32MZ-W_DFP (Apache-2.0).
- pic32mz_wfi32_pwrclk.c: W1 does not set up its PLLs from the
configuration words. Software starts the 40 MHz crystal oscillator,
runs SYSCLK at 200 MHz from the system PLL, starts the Ethernet/Wi-Fi
PLL and switches the regulator from MLDO to buck mode using the
factory trim values (on B0 silicon). Facts not found in the
data sheet or DFP are marked [EX] in comments; they come from
Microchip's WFI32 Ethernet/Wi-Fi bridge example firmware.
- pic32mz_head.S, pic32mz_config.h: emit the W1 configuration words
(DEVCFG0/1/2/4, FBCFG0, FCPN0, FSIGN0).
- W1 differences in shared code: PREFEN only accepts 0/1, PB6DIV clocks
the CPU and is left alone, UART1/2, SPI1/2 and I2C2 are clocked from
PBCLK3 and the timers from PBCLK1 (data sheet Table 11-1), I2C1 and
I2C2 are not contiguous in the SFR map, UART1 and SPI1 can use their
dedicated (non-PPS) pins.
New Kconfig options: PIC32MZ_W1_PMU_MLDO (keep the regulator in its
power-on MLDO mode), PIC32MZ_W1_FLASH_WAITSTATES (default 5, the value
used by Microchip's example at 200 MHz) and PIC32MZ_W1_BOOTTRACE (polled
early boot trace on UART1, a bring-up aid).
Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Daniel P. Carvalho <danieloak@gmail.com>
Update the W25Q device documentation to reflect support for SPI NOR
flash memories up to 512 Mbit (64 MB) using 4-byte address mode.
Assisted-by: gemini-3.8-flash
Signed-off-by: Daniel P. Carvalho <danieloak@gmail.com>
This commit adds 4-byte address mode support to the Winbond W25 SPI
NOR flash driver (drivers/mtd/w25.c):
- Detect W25_JEDEC_CAPACITY_256MBIT (0x19) and W25_JEDEC_CAPACITY_512MBIT (0x20).
- Send W25_EN4B (0xB7) command to enter 4-byte address mode on initialization
when chip capacity >= 256Mbit.
- Expand w25_dev_s nsectors to uint32_t to support chips > 128Mbit.
- Add w25_sendaddr() helper supporting both 3-byte and 4-byte addressing
for sector erase, byte read, page write, and byte write.
- Verified on hardware with Winbond W25Q256JV (256Mbit / 32MB):
both raw MTD block access at >20MB (>16MB boundary) and SmartFS
mounting and file reading are verified working.
Assisted-by: gemini-3.8-flash
Signed-off-by: Daniel P. Carvalho <danieloak@gmail.com>
netdev_lower_carrier_XXX can't be called before netdev is registered
Signed-off-by: p-szafonimateusz <p-szafonimateusz@xiaomi.com>
Signed-off-by: dongjiuzhu1 <dongjiuzhu1@xiaomi.com>
ctucanfd_sock_recv() did not compile with CONFIG_CAN_CTUCANFD_SOCKET:
* the rwcnt bounds check used an undeclared 'frame' instead of
'rxframe';
* the !CONFIG_NET_CAN_EXTID paths used 'continue' outside a loop.
Both error paths now free the allocated RX packet and return NULL,
so a dropped frame no longer leaks the netpkt. Also add the blank
lines after declarations that nxstyle requires in this file.
Assisted-by: Claude:claude-opus-5-5
Signed-off-by: raiden00pl <raiden00@railab.me>
board_spisd_initialize() logged "ERROR: Failed to mount the SDCARD" at
every boot when the mount failed. The two usual causes are no card in
the slot and a card with no filesystem. Neither is an error: the block
device is registered, and the card can be formatted with mkfatfs and
mounted later.
Log -EINVAL and -ENODEV from nx_mount() with finfo(). Other errors
are still logged with ferr(), as the rest of the file does.
Also include errno.h, which the file used without including it.
Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
Provide a complete documentation guide for the tftpc (TFTP client) network
utility in Documentation/applications/netutils/tftpc/index.rst, replacing
the previous 5-line placeholder stub.
Includes:
- Architecture overview (NSH get/put engine + programmatic C APIs)
- Key features (RFC 1350, octet/netascii modes, streaming callbacks, dynamic TID port negotiation)
- Configuration options table and networking prerequisites
- NSH get and put command synopses, option flags, and terminal examples
- C API reference for filesystem helpers (tftpget, tftpput) and streaming callbacks (tftpget_cb, tftpput_cb)
- Complete, runnable C application example demonstrating callback-based streaming downloads
Addresses #11081
Signed-off-by: Swatantra Yadav <maverickswatantra@gmail.com>
mmu_write_ttbr0() writes TTBR0_EL1 and then invalidates the TLB. A write
to TTBR0_EL1 takes effect only at the next context synchronization event,
so until the ISB at the end of the invalidation, a table walk can still
use the old table. The instruction fetches of the invalidation sequence
itself do such walks. An entry that they cache after the TLBI completes
stays valid: walk cache entries are not tagged with the table base, and
the kernel and every process use ASID 0.
A kernel build then translates a user address of the new process through
a level 0 entry of the old table, and gets a level 1 translation fault.
Under QEMU with HVF on Apple silicon this happens on every boot of
qemu-armv8a:knsh: up_addrenv_va_to_pa() fails for the first user buffer,
and virtio gets a descriptor with address 0. TCG has no walk caches, so
it does not show the problem.
Add an ISB after the write, as the Arm ARM sequence for a TTBR change
without an ASID change requires: write, ISB, TLBI, DSB, ISB.
Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
Every other driver subdirectory adds bare file names to CSRCS and points
VPATH and DEPPATH at itself, so drivers/lcd/st7365p.c is built as
drivers/st7365p.o. segger/Make.defs instead put the path in CSRCS, so its
objects were built as drivers/segger/serial_rtt.o and friends.
The generated rules in drivers/Make.dep name their target with the basename
of the source -- mkdeps calls basename() and prefixes --obj-path -- so they
read "serial_rtt.o: segger/serial_rtt.c ... nuttx/config.h". No such file
was ever built. The dependency rule and the compile rule named different
targets, and nothing under drivers/segger was ever recompiled when a header
or the configuration changed.
The result is a stale object silently linked against fresh ones. Enabling
CONFIG_TTY_SIGINT, for instance, adds a pid_t to struct uart_dev_s, which
moves every field after it. serial.c is rebuilt and reads dev->ops from its
new offset; serial_rtt.o is not, and its statically initialised device still
has ops four bytes lower. uart_open() then branches through whatever
follows it, and the board hard faults in uart_attach() before the console
has emitted a byte -- a symptom with no visible connection to its cause.
Use the same convention as the other subdirectories.
Tested on a Pimoroni Pico Plus 2 W with the RTT console
(pimoroni-pico-plus-2-w:nsh with CONFIG_SERIAL_RTT_CONSOLE). On master,
touching nuttx/serial/serial.h or enabling CONFIG_TTY_SIGINT does not
recompile segger/serial_rtt.c, and the incrementally built image prints
nothing on RTT. With this change, serial_rtt.c is recompiled in both
cases, and the same incremental build boots to NSH over RTT.
drivers/mtd/Make.defs has the same shape for its downloaded dhara and nvblk
sources and is left alone: it adds both nvblk.c and mtd/nvblk/src/nvblk.c,
whose basenames collide, so it needs more than a change of convention.
Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
The completion handler did:
dmach->callback(...);
dmach->callback = NULL; /* after the call */
so a callback that registers itself again -- which is the only way for a
driver to keep a channel running continuously -- has that registration
wiped the moment it returns. The channel transfers one more block and
then goes deaf, with no error raised anywhere and nothing in the
registers to say why. A PWM audio driver hit this and worked around it
by restarting from a thread instead, which put a millisecond of silence
into every buffer boundary.
Lift the callback and its argument out first and clear them before the
call. One-shot behaviour is unchanged for every existing user, since
none of them re-register from inside the call; the difference is only
that one which does now survives.
Tested on a Pimoroni Pico Plus 2 W (pimoroni-pico-plus-2-w:nsh) with a
local test: a memory-to-memory transfer whose callback starts the next
one, 100 times. Master gives 1 completion of 100; this change gives 100.
The existing users (SPI, I2S, CYW43439, WS2812) do not start a transfer
from inside the callback, so they do not change.
Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
nxstyle reports "Missing blank line after declarations" in
rp23xx_dmachannel(). Add the blank line, because CI checks every file
that a change touches.
No functional change. The change is whitespace only.
Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
Select STM32_HAVE_IP_USART_M33_V3 and drop the family serial, USART
header, and low-level console sources. Provide the USART clock and RCC
gate definitions for all thirteen ports in stm32_rcc_m33.h and the RX
DMA request numbers in the family DMA signal map. Include the family
DMA header from stm32.h so the common driver reaches the DMA API.
Extend the common Cortex-M33 v3 USART support with the STM32H5
features: USART6, UART7-9, USART10-11, and UART12 ports, the LPUART
prescaler for low baud rates, RX DMA through the family-provided
request number, wakeup-from-stop CR3 definitions, and per-port
descriptors gated by the family peripheral options.
Enable the USART FIFO for every Cortex-M33 family. The low-level
console uses the per-port kernel clock and RCC gate, which corrects
the UART9 and UART12 enable register. The RX DMA callback delivers
data only while reception is enabled.
The non-BSD break ioctl now uses the send-break request register
instead of a CR1 bit this USART IP does not have. Correct the UART12
gates and the RXDMA and console undef lists in the USART driver
header. Raise STM32_NUSART to six on the H56x and H57x parts so UART12
fits the device table, add the missing UART9 buffers, write LPUART CR1
only on the USART path, and build device names with snprintf so minors
above nine are valid.
Keep the termios flow control fields writable so TCSETS compiles with
input flow control, let up_putc emit a bare newline since syslog adds
the carriage return, and make the unconfigure-on-close options
available to every Cortex-M33 family.
Signed-off-by: raiden00pl <raiden00@railab.me>
Assisted-by: Claude Code
Select STM32_HAVE_IP_GPIO_M33_V1 and STM32_HAVE_IP_EXTI_M33_V1 and
drop the family GPIO and EXTI sources and headers in favor of the
common Cortex-M33 v1 implementation. Add the RM0481 line count for the
H56x and H57x parts to the common EXTI line inventory.
Add GPIO_PORTI to the common Cortex-M33 pin encoding for the parts
with a ninth GPIO port.
Signed-off-by: raiden00pl <raiden00@railab.me>
Assisted-by: Claude Code
Enable STM32_COMMON_M33 for STM32H5 and drop the family reset, NVIC,
SysTick, and idle sources in favor of the common Cortex-M33 v1
implementation. The common heap allocator replaces the generic ARM one
through a STM32_PRIMARY_SRAM_SIZE spanning the contiguous SRAM banks
and skips the SRAM2 region when the primary heap already covers it.
Rename the family RCC header to stm32_rcc_m33.h for the common RCC
dispatch.
Add the SRAM3 parity initialization block and the CONFIG_STM32_ICACHE
enable call to the common reset handler, taken from the STM32H5 start
logic. Without CONFIG_STM32_ICACHE the reset handler disables an
ICACHE left enabled by a bootloader on STM32_HAVE_ICACHE families.
Move the flat-build MPU initialization to stm32_mpuinit_m33_v1.c in
common/stm32, built for every Cortex-M33 family with ARM_MPU, and
declare stm32_mpuinitialize for ARM_MPU as well as protected builds.
Declare stm32_board_initialize in the common start header.
Signed-off-by: raiden00pl <raiden00@railab.me>
Assisted-by: Claude Code
tone_register() takes a struct oneshot_lowerhalf_s *, and the header does not
include the one that defines it. Including tone.h first therefore creates the
tag in prototype scope, and passing a real oneshot to it fails with the
memorable diagnostic "expected 'struct oneshot_lowerhalf_s *' but argument is
of type 'struct oneshot_lowerhalf_s *'".
Every existing user happens to include nuttx/timers/oneshot.h first, which is
why this has not bitten before.
Tested with a small file that includes nuttx/audio/tone.h first and calls
tone_register(). Before the change, GCC 13.2 gives the warning above and
GCC 15.3 stops with an error. After the change, both compile it without a
diagnostic. stm32f103-minimum:audio_tone builds.
Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
Every BATIOC_* case in the gauge upper half calls dev->ops->X() after
checking only that the *argument* pointer is non-NULL. The operations
themselves are optional -- max1704x.c implements four of the eight, and
the in-tree fake gauge leaves chipid and operate NULL -- so asking a gauge
for something it does not provide calls through a NULL pointer.
On ARM that is not a null dereference but a branch to address 0, which has
the Thumb bit clear: the core takes a usage fault with CFSR bit 17,
INVSTATE, escalated to a hard fault. From userspace it looks like the
program stopped mid-run for no reason, and on a board whose assert path
delays before resetting it looks like a hang.
Guard all eight. A missing method is now ENOTTY, which is what the default
case already returns for an unrecognised command and what a caller can
sensibly probe for.
Tested on sim:nsh with the fake gauge and a local test app. Before the
change, ioctl(BATIOC_CHIPID) kills the simulator with SIGSEGV. After the
change, BATIOC_CHIPID and BATIOC_OPERATE return ENOTTY and
BATIOC_VOLTAGE still returns the voltage. nucleo-f412zg:nsh with
BATTERY_GAUGE, MAX1704X, BQ27426 and BATTERY_FAKE_GAUGE builds.
Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
Whitespace only. Add a blank line after the declarations in the BATIOC_*
cases, and indent two case labels like the others. The errors are older
than the next commit, but checkpatch checks the whole file.
Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
Under CONFIG_AUDIO_MULTI_SESSION, audio_pause() and audio_resume() take a
session argument, but two internal call sites still passed only the file
pointer:
audio.c:612 audio_start() forwarding a resume of a paused device
audio.c:694 audio_stop() forwarding a pause
Neither compiles, so the option cannot be selected at all -- which is
presumably why nobody has noticed.
Guarded the way the rest of the file guards the same pair.
Tested on sim:nsh with AUDIO, AUDIO_MULTI_SESSION and AUDIO_NULL. Before
the change, audio.c does not compile. After the change, the build passes.
A local test app on the null audio device runs both changed paths:
AUDIOIOC_START on a paused device resumes it, and AUDIOIOC_STOP while
another open is paused pauses the device. Both return 0.
Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
Whitespace only. Add a blank line after two declarations. The errors
are older than the next commit, but checkpatch checks the whole file.
Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
An unprivileged task that touched memory it does not own took the whole
system down. The MMU refused the access, as it should, and then
x86_64_fault_panic_isr() panicked -- so a contained application bug
became a system-wide outage. x86_64 had no user-fault recovery at all,
while arm64, RISC-V and esp32s3 each have one, and ISR13 and ISR14 here
went straight to a handler whose own comment says "Don't even brother
to recover, just dump the regs and PANIC."
The decision has to be made in the handler. The user-task check in
_assert() looks like it already covers this, but a fault arrives as an
exception, so up_interrupt_context() is already true by the time it is
reached and the panic branch is taken no matter who faulted.
The CPL in the saved CS is the whole test, and on this architecture it
is exact: everything that runs on behalf of a user task inside the
kernel -- a system call body, an interrupt handler, a kernel thread --
runs in ring 0, so a fault there is correctly refused recovery. That is
what RISC-V reads out of STATUS_PPP and arm64 out of SPSR_MODE_EL0T.
x86_64 cannot use TCB_FLAG_SYSCALL the way those two do: it has never
set it, and making it do so is a separate change with its own hazards
(see the note in x86_64_syscall()). The task type is checked as well,
as RISC-V does, so that a frame that cannot be trusted -- an early-boot
fault, before any user task exists -- cannot talk its way in with a
stale selector.
Recovery is the same shape as the other architectures -- RIP to _exit,
first argument SIGSEGV, TCB_FLAG_FORCED_CANCEL raised -- plus the three
x86_64 specifics:
* CS and SS move to the kernel selectors together with RIP. The frame
being rewritten is the one x86_64_fullcontextrestore() is about to
iretq from, and iretq takes the target privilege level from the CS
it pops; in long mode it pops SS with it even when the level does
not change.
* RSP moves to the top of the task's own kernel stack. _exit() must
not run on the user stack the fault came from, because the address
environment that stack belongs to is torn down while _exit() is
still running. The kernel stack is free -- the fault was taken in
user mode, so no system call of this task is in flight. The -8
reproduces the offset a call would have left, which is what the SysV
ABI states its 16-byte rule against and what up_initial_state() sets
up for the same reason.
* RFLAGS is reset to the value up_initial_state() gives a new thread
rather than carried over. The faulting task's flags are its own to
set, and DF in particular must be clear on entry to any C function.
ISR6 is routed through the same handler. An invalid opcode is
attributable to the instruction that raised it, so a user task running
garbage should die on its own rather than take the system with it --
the same conclusion esp32s3 reached for EXCCAUSE_ILLEGAL. ISR8 keeps
panicking unconditionally: a double fault says an exception could not be
delivered at all, and there is nothing left to trust.
The message gives the fault address (CR2) only for a page fault, because
the other exceptions do not set CR2.
X86_GDT_PL_MASK and X86_GDT_RPL_USER now live in intel64/arch.h beside
the selectors they mask; x86_64_fork.c had a private copy of the latter.
Verified on qemu-intel64:knsh_romfs under QEMU TCG with
apps/examples/sandbox. The probe targets kernel .text at _stext
(0x100909000). This config sets CONFIG_RAM_START to 0x0, a Kconfig
default, so the address is given on the command line. The "x" probes
call the address; that mode was added to the sandbox locally for the
test.
sandbox r 0x100909000 -> Exception 14, error code 5, 2816
sandbox w 0x100909000 -> Exception 14, error code 7, 2816
sandbox x 0x100909000 -> Exception 14 at RIP=100909000, 2816
sandbox r 0x8000000000000000 -> Exception 13 (non-canonical), 2816
sandbox x 0x80000000d -> Exception 6 at RIP=80000000d, 2816
All five probes run in one boot and report CONTAINED. The offender
dies with SIGSEGV, the parent survives, a canary thread keeps running,
and the memory and descriptors of the offender come back. The shell
answers after the last probe. Without this change each probe panics
the system.
ostest exits with status 0 on knsh_romfs, fork and vfork included. It
also exits with status 0 on the flat qemu-intel64:nsh with
CONFIG_SCHED_THREAD_LOCAL disabled. With it enabled, ostest faults in
sched_thread_local_test() with and without this change.
Each vector is reached deliberately. A non-canonical address is a #GP
rather than a #PF, which the read and call probes never produce on their
own. The #UD needs no corrupt binary either: the crt0 stub this
architecture links into every user ELF already ends in a ud2 at
_stext+0xd, and with CONFIG_ARCH_TEXT_VBASE at 0x800000000 the call
probe can simply be aimed at it, executing an invalid opcode in ring 3
out of the process's own text.
The negative direction was checked too, on the flat build, where the
same non-canonical read is taken at CPL 0: it reaches
x86_64_fault_panic_isr() exactly as before and panics with a full
register dump reporting CPL 0.
Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
Two problems in the same path make a contained user fault look like a
kernel failure.
arm64_el1_undef() dumps the words around ELR. For an exception taken
from EL0, ELR is a user address, and the words around it can be in a
page that is not mapped. Then the memcpy faults inside the fatal
handler. That nested exception trips the DEBUGASSERT in
arm64_fatal_handler(), and the fault that the user took is not reported.
The ESR that tells what happened is lost. Skip the dump when the
exception came from EL0. At EL1 the address is kernel code that was
just fetched, so keep the dump there.
arm64_fatal_handler() then reports the fault that it recovers from as
"PANIC: Unhandled user exception", followed by a full register dump.
But there is no panic: it sets TCB_FLAG_FORCED_CANCEL, changes ELR to
_exit(SIGSEGV), and the system continues without the offending task.
Print "Segmentation fault in <process> (PID n: <thread>)" instead, the
same message as risc-v, and keep the register dump for the
PANIC_WITH_REGS() path, which is fatal.
Tested on QEMU qemu-armv8a:knsh with examples/sandbox and ostest. A
user read or write of kernel memory (0x40000000) now prints:
arm64_exception_handler: ESR_ELn: 0x9200000e
arm64_fatal_handler: Segmentation fault in sandbox (PID 10: sandbox)
arm64_fatal_handler: Reason: DABT (lower EL) - Data Abort from a ...
sandbox: the offender exited with status 2816
Before this change it printed "PANIC: Unhandled user exception" and a
register dump for the same recovered fault. An undefined instruction
at EL0 now prints "Undefined instruction at <ELR>" without the dump,
then the same segmentation fault message. The shell survives in all
cases, and ostest exits with status 0 before and after this change.
Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>