Commit graph

63608 commits

Author SHA1 Message Date
rikaken2004
414d300e1a drivers/mmcsd/mmcsd_sdio.c: check RECVSETUP/SENDSETUP return on non-DMA paths
The non-DMA data paths discard the return value of SDIO_RECVSETUP in
mmcsd_readsingle() and mmcsd_readmultiple() and of SDIO_SENDSETUP in
mmcsd_writesingle(), mmcsd_writemultiple() and the CMD56 read/write
helpers, so when the lower half fails to set up the transfer the
driver still issues CMD17/18/24/25/56 and the failure only surfaces
later as an unrelated-looking transfer timeout. The DMA paths in the
same functions all check SDIO_DMARECVSETUP/SDIO_DMASENDSETUP, cancel
the transfer and propagate the error, so mirror that handling on the
non-DMA paths.

Signed-off-by: rikaken2004 <244897142+rikaken2004@users.noreply.github.com>
2026-10-01 22:14:44 +08:00
Alan Carvalho de Assis
91008cf1b1 sched/clock: keep the seqlock sequence in uint32_t
clock_get_sched_ticks() stored the value of read_seqbegin(), a
uint32_t, in an unsigned int and passed it back to read_seqretry().
Where int is 16 bits the copy is truncated, so once the 32-bit
sequence number passes 65535 read_seqretry() always reports a change
and the loop never ends.  The sequence advances once per tick, so after
65536 ticks (11 minutes at 100 Hz) the next caller, the timer interrupt
itself, spins forever with interrupts disabled and the system stops.

Seen on the CDP1802 (16-bit int): NSH stopped answering after 55
minutes at 20 Hz.  AVR has the same problem.  hrtimer's readers of the
same lock already use uint32_t. Don't assume int is 32-bit :-D

Signed-off-by: Alan Carvalho de Assis <acassis@gmail.com>
Assisted-by: Claude Opus 5.5 (claude-opus-5-5)
2026-10-01 10:17:21 -03:00
Alan Carvalho de Assis
1dfa028808 include/fcntl.h: keep open() flags within a 16-bit int
O_DIRECTORY, O_NOFOLLOW, O_NOATIME, O_CLOEXEC, __O_SYNC, O_PATH and
__O_TMPFILE are defined as shifts by 16 to 22 bits.  Where int is 16
bits (AVR, for example), these shifts exceed the width of the type:
GCC evaluates them to 0, and the -Wshift-count-overflow warning is not
shown because include/ is a system include directory.  The oflags
argument of open() is an int, so it could not carry those bits anyway.

As a result, on arch with int equal 16-bit opendir() opens directories
without O_DIRECTORY, so opening a mount point such as /proc fails with
ENOENT, and O_CLOEXEC and O_NOFOLLOW have no effect.

When UINT_MAX is 0xffff, use the unused bits 2 to 4 for O_DIRECTORY,
O_CLOEXEC and O_NOFOLLOW, define O_NOATIME and __O_SYNC as 0 (O_SYNC
falls back to O_DSYNC), and leave O_PATH and O_TMPFILE undefined, so
that code which needs them fails to build instead of silently opening
with the wrong flags; nothing in the tree uses them.  _O_MAXBIT becomes
15. On bigger systems (32-bit, 64-bit) keep the original bit shift.

Signed-off-by: Alan Carvalho de Assis <acassis@gmail.com>
Assisted-by: Claude Opus 5.5 (claude-opus-5-5)
2026-10-01 08:54:02 -03:00
Royyan Zahir
1d8fb674da drivers/timers/pcf85263: report a lost time as lost.
Some checks are pending
Build Documentation / build-html (push) Waiting to run
MemBrowse Memory Report / changes-filter (push) Waiting to run
MemBrowse Memory Report / load-targets (push) Waiting to run
MemBrowse Memory Report / identical (push) Blocked by required conditions
MemBrowse Memory Report / analyze (push) Blocked by required conditions
A stopped oscillator sets OS in the seconds register and leaves stale
time behind, which the driver returned as the time. Return -EAGAIN, as
it already does before it is enabled, so the clock starts unset instead
of wrong. Setting the time clears OS.

Signed-off-by: Royyan Zahir <royzah@gmail.com>
2026-10-01 18:05:07 +08:00
Beat Küng
e9ddc4b9d1 Documentation/guides/rust: update config requirements
And CONFIG_LIBC_MUTEX_BACKTRACE=0 is required for
https://github.com/rust-lang/libc/pull/5555
2026-10-01 17:58:02 +08:00
Abhishek Mishra
cb70a35d46 Documentation/tflite-micro: describe the new tflm tool options
Document -I, -d, -x and -n, the operators the tool now registers from
the model, how outputs and inputs are handled, and a hostfs example
that runs the hello-world sine model from NSH.

Signed-off-by: Abhishek Mishra <mishra.abhishek2808@gmail.com>
2026-10-01 17:55:53 +08:00
Marco Casaroli
e8a3d4ee1c Documentation/esp32s3: Describe memory protection and the kernel build.
Some checks are pending
Build Documentation / build-html (push) Waiting to run
MemBrowse Memory Report / changes-filter (push) Waiting to run
MemBrowse Memory Report / load-targets (push) Waiting to run
MemBrowse Memory Report / identical (push) Blocked by required conditions
MemBrowse Memory Report / analyze (push) Blocked by required conditions
The chip page did not say which build modes the ESP32-S3 supports, how a
KERNEL build uses the MMU, or what happens when user code takes a fault.
Add a section for that, with the console messages of a fault and the
options CONFIG_ESP32S3_USERFAULT_ABORT and CONFIG_ESP32S3_PAGEFAULT.

On the board page, kernel_oct said the shell needs the full path of a
program, but /system/bin is in PATH.  Say that instead, describe the
isolation of a process, and show how ostest and sandbox check it.  Also
add a section for ksta_softap, which had none.

Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
2026-09-30 13:40:16 -03:00
Marco Casaroli
e7c6367533 arch/arm: Call FDPIC constructors with the module's own data base.
Under FDPIC an .init_array or .fini_array entry is a code address, but a
C function pointer is a function descriptor.  crt0 called each entry
through a function pointer, so it read the constructor's first
instructions as a descriptor and jumped to garbage.

Call each entry with fdpic_call() and the data base from fdpic_base(),
which is the module's own.  Without CONFIG_FDPIC both are a direct call,
as before.

Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
2026-09-30 13:40:02 -03:00
Marco Casaroli
4db7594eb6 libs/libc/elf: Read the dynamic relocations at their file offset.
DT_REL and DT_JMPREL hold the link-time address of their table, and the
loader read the table at that value as a file offset.  The two are equal
only when the segment that holds it starts at file offset 0.  An object
linked with its text at file offset 0x1000, as the tree's gnu-elf.ld does,
had its relocations read from padding, so none were applied and the
module called through unrelocated pointers.

Translate the address through the PT_LOAD headers first.

Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
2026-09-30 13:40:02 -03:00
Marco Casaroli
ec78241ebe libs/libc/elf: Load an FDPIC object's data into the data heap.
An architecture that sets CONFIG_ARCH_USE_DATA_HEAP gives a loaded module
its data from up_dataheap_memalign(), because the ordinary heap is not where
that data belongs there.  The ELF loader honours it for every object but an
FDPIC one: an FDPIC object places its writable segment on its own, and that
allocation, and the two places that free it, still use lib_memalign() and
lib_free().  Its text already comes from the text heap.

So an FDPIC module's data goes to the data heap too, and back to it when the
module is unloaded or removed.

On mps3-an547, which sets both heaps, fdpicxip loaded the data of its two
instances at 0x1007220 and 0x104e480, in the ordinary heap.  With this change
they are at 0x21000000 and 0x21000180, in the SRAM2 data heap, and both
instances run.  In a protected build the difference matters: there the
ordinary heap is kernel memory, and the module takes a data access violation
on its first access to its data.

Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
2026-09-30 13:39:45 -03:00
Felipe Moura
1c6ed642bf espressif: stop leaking a Wi-Fi interrupt handle on every esp_wifi_start()
set_intr_wrapper() allocates a new intr_handle_data_t from the kernel
heap each time the Wi-Fi driver calls it, and the driver calls it on
every esp_wifi_start() -- twice per start on esp32s3 -- not only the
first time.  clear_intr_wrapper() is a no-op, so the IRQ still holds the
handle from the previous start: esp_set_handle() refuses to replace it
with -EINVAL, the return value is ignored, and the new block is lost.

Any application that stops and restarts Wi-Fi to save power therefore
loses a few bytes of kernel heap per cycle, without bound.

Look up the vector descriptor first, then reuse the handle already
registered for the IRQ and only allocate and register one when there is
none.  A failed descriptor lookup no longer touches the registered
handle.

The same code is present in the esp32, esp32s2, esp32s3, esp32c3 and
esp32c6 Wi-Fi adapters; all five are fixed the same way.

Signed-off-by: Felipe Moura <moura.fmo@gmail.com>
Assisted-by: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-30 13:25:42 -03:00
Marcio Ribeiro
b38b03072a boards/risc-v/esp32c2/esp8684-devkitm: add ROMFS and extra configs
Add BMP180, ROMFS, MCUBoot NSH, ostest, and tickless defconfigs plus the
matching bring-up hooks.

Assisted-by: Claude:claude-opus-5
Signed-off-by: Marcio Ribeiro <marcio.ribeiro@espressif.com>
2026-09-30 11:49:41 -03:00
Marcio Ribeiro
106273a370 boards/risc-v/esp32c2/common: add sensor and ROMFS board helpers
Add BMP180/BMP280 helpers and ROMFS init scripts used by non-SoC
board features.

Assisted-by: Claude:claude-opus-5
Signed-off-by: Marcio Ribeiro <marcio.ribeiro@espressif.com>
2026-09-30 11:49:41 -03:00
Royyan Zahir
6bec3b6f5b arch/arm64/imx9: reject PWM channels outside the timer
A negative channel passed both checks, and TPM took one past the end,
so a caller could write FlexIO and TPM registers it does not own. TPM
also dropped the error and reported success.

Signed-off-by: Royyan Zahir <royzah@gmail.com>
2026-09-30 09:24:36 -03:00
Jukka Laitinen
4295024832 boards/imxrt/imxrt1180-evk: Add buttons example app and SW8 button configuration
Some checks are pending
MemBrowse Memory Report / changes-filter (push) Waiting to run
MemBrowse Memory Report / load-targets (push) Waiting to run
MemBrowse Memory Report / identical (push) Blocked by required conditions
MemBrowse Memory Report / analyze (push) Blocked by required conditions
Add a button configuration to test GPIO inputs.

Signed-off-by: Jukka Laitinen <jukka.laitinen@tii.ae>
2026-09-30 14:10:58 +08:00
Jukka Laitinen
a48fd7363a arch/arm/imxrt: Fix rgpio interrupt definitions
Pack the LOWLEVEL/HIGHLEVEL/RISINGEDGE/FALLINGEDGE directly into correct bits in
pinset.

Signed-off-by: Jukka Laitinen <jukka.laitinen@tii.ae>
2026-09-30 14:10:58 +08:00
Jukka Laitinen
f55525b0fa arch/arm/imxrt: Fix GPIO / IOMUX macros for imxrt1180
There were some bits erroneously copied from imx9. For IMXRT1180, the
GPIO_AD* and GPIO_AON* pads should have SRE, DSE, PUE, PUS and ODE bits
on SW_PAD_CTL_PAD register.

The GPIO_EMC_*, GPIO_SD_*, GPIO_B1_* and GPIO_B2_* have a bit different fields,
PDRV, PULL and ODE.

Signed-off-by: Jukka Laitinen <jukka.laitinen@tii.ae>
2026-09-30 14:10:58 +08:00
Jukka Laitinen
88a4331348 arch/arm/imxrt: Fix imxrt_clockconfig_ver3 c++ linkage
There was a mismatched EXTERN definition for ver3 in imxrt_periphclks.h,
and the extern definitions should be there in imxrt_clockconfig_ver3.h

Signed-off-by: Jukka Laitinen <jukka.laitinen@tii.ae>
2026-09-30 14:10:58 +08:00
Marcio Ribeiro
2d5ef658ee Documentation/risc-v/esp32c2: add ESP32-C2 and ESP8684-DevKitM pages
Some checks failed
MemBrowse Memory Report / changes-filter (push) Waiting to run
MemBrowse Memory Report / load-targets (push) Waiting to run
MemBrowse Memory Report / identical (push) Blocked by required conditions
MemBrowse Memory Report / analyze (push) Blocked by required conditions
Build Documentation / build-html (push) Has been cancelled
Document the chip (toolchain, Simple Boot, peripherals, MCUBoot) and
the DevKitM-1 board (pinout, headers, RGB, existing defconfigs),
including vendor figures.

Assisted-by: Cursor:Grok 4.6
Signed-off-by: Marcio Ribeiro <marcio.ribeiro@espressif.com>
2026-09-29 14:40:08 -03:00
Marcio Ribeiro
c1affc5923 boards/risc-v/esp32c2/esp8684-devkitm: add on-chip peripheral configs
Add GPIO, buttons, and defconfigs/bring-up for ADC, I2C, PWM, SPI,
timers, watchdog, eFuse, crypto, RTC, and related C2 peripherals.

Assisted-by: Claude:claude-opus-5
Signed-off-by: Marcio Ribeiro <marcio.ribeiro@espressif.com>
2026-09-29 14:39:55 -03:00
Marcio Ribeiro
2f715c4918 boards/risc-v/esp32c2/common: add on-chip peripheral board helpers
Add ADC, I2C, LEDC, SPI, SPI flash, MMCSD and RNG helpers used by
the ESP32-C2 board bring-up.

Assisted-by: Claude:claude-opus-5
Signed-off-by: Marcio Ribeiro <marcio.ribeiro@espressif.com>
2026-09-29 14:39:55 -03:00
raiden00pl
3ab1b4b8fe arm/nrf54l: add RRAM progmem support
add RRAM progmem support

Assisted-by: Codex:GPT-6
Signed-off-by: raiden00pl <raiden00@railab.me>
2026-09-29 14:29:04 -03:00
Marco Casaroli
1ccd940e44 arch/xtensa: Use one name for the stack frame alignment.
Two files each defined the same 16 byte constant, KSTACK_ALIGNMENT and
SIGTRAMP_STACK_ALIGN.  Use STACKFRAME_ALIGN, which arch/xtensa/include/irq.h
already gives as 16, with the STACKFRAME_ALIGN_DOWN() of nuttx/irq.h.

STACK_ALIGNMENT is not the name to use here.  It is TLS_STACK_ALIGN when
CONFIG_TLS_ALIGNED is set, which is the alignment of a thread stack and not
of a frame.

Assisted-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
2026-09-29 11:13:47 -03:00
Marco Casaroli
1b59698bde xtensa/esp32s3: Report an access through an invalid MMU entry.
The PMS grants and refuses physical addresses, so it never sees an access
that no MMU entry translates.  The cache answered such an access with zeros
and raised nothing, and the task carried on with a value it never should
have had.

Enable EXTMEM_MMU_ENTRY_FAULT and route the Cache Invalid Access interrupt
to the handler that already serves the PMS monitors.  An unprivileged task
that makes the access is terminated with SIGSEGV;  a privileged one still
panics.  The latch is level triggered, so it is cleared with the others.

Read the cause before the clear, so the log tells the two apart:  a PMS
violation is a refused translation, an MMU entry fault is an access that was
never translated.

Give the kernel_oct configuration the addresses that examples/sandbox needs
to name its targets.

Assisted-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
2026-09-29 11:13:47 -03:00
Marco Casaroli
df782bd1e5 xtensa/esp32s3: Stop an unreportable cache fault from livelocking.
Reporting a fault can itself fault.  syslog reaches memory the fault being
reported may have made unreachable, so esp32s3_pagefault_dispatch() is
re-entered from inside its own _alert() and never returns, and the console
fills with the same half-printed line forever.  Found under Espressif's QEMU,
where PSRAM never initialises and the kernel build needs it; the board's
PSRAM works, so hardware does not take this path.

A fault repeating at the same address and PC is not helped by reporting it
again, so the dispatcher tries three times and then halts with interrupts
off.  esp32s3_userfault_abort() clears the count through
esp32s3_pagefault_clear_repeat(): reaching it means the fault was contained,
so only unbroken recursion stops the machine, and three probes at one
address do not halt a healthy system.

Verified under QEMU: 12,958,521 bytes of output in 60 s before, four reports
and a halt after.  On an ESP32-S3 DevKitC, esp32s3-devkit:kernel_oct, three
identical sandbox probes in one boot are all contained.

Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
2026-09-29 11:13:47 -03:00
Marco Casaroli
802ccef86f xtensa/esp32s3: Abort the faulting user task on an unrecoverable fault.
When an unprivileged task takes a fault the system cannot recover from, it
now gets a fatal SIGSEGV and only that task ends.  A fault in privileged code
still panics.

What decides it is the interrupted context, not the cause: the saved PS says
whether the fault was taken in User Mode.  A list of causes would leave every
cause off the list as a way for a user task to stop the machine, and there
are many -- a divide by zero, a privileged instruction, a load/store error,
and an illegal instruction, which is how a refused fetch from kernel text
arrives on this chip (TRM v1.8 p.699: a denied external-memory access is
answered with 0xdeadbeaf instead of trapping).  PS.UM is clear in a kernel
thread, in a system call made on the user's behalf and in an interrupt
handler, so those still panic.  If the recoverable-fault dispatcher is
enabled it still gets first refusal on causes 28, 29 and 20, the only ones
re-executing can help.

esp32s3_userfault_abort() records the exception frame as the task's context,
dispatches SIGSEGV, and returns the redirected frame, so the vector's RFE
resumes the task in the signal trampoline, whose default action exits it.
CONFIG_ESP32S3_USERFAULT_ABORT enables it, default y wherever there is an
unprivileged world, and selects SIG_DEFAULT and SIG_SIGKILL_ACTION.

Verified on an ESP32-S3 DevKitC with a WROOM-2 module,
esp32s3-devkit:kernel_oct: a user task that writes through NULL, reads a wild
address, divides by zero, calls into a buffer of garbage or branches into
kernel text is terminated on its own, while an unrelated task keeps running.

Stack overflow is not contained.  On the windowed ABI it faults inside the
window overflow handler and arrives as a double exception with PS.UM already
clear; guard pages are the answer, and separate work.

Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
2026-09-29 11:13:47 -03:00
Marco Casaroli
c6b23e3e21 xtensa/esp32s3: Isolate the unprivileged world.
Separate the world split from the protected user image, give WORLD1 its own
vector table and its own PMS permissions -- including the PSRAM -- clean up
the user cache-MMU windows, and stop keeping the page pool mapped.

Folds in:
  xtensa/esp32s3: separate the world split from the protected user image
  xtensa/esp32s3: give the unprivileged world its own vector table
  xtensa/esp32s3: give the unprivileged world its permissions
  xtensa/esp32s3: clean up the user cache-MMU windows
  xtensa/esp32s3: stop keeping the page pool mapped
  xtensa/esp32s3: give the PSRAM its own PMS permissions

Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
2026-09-29 11:13:47 -03:00
Jukka Laitinen
c7080cbdfe arch/arm/imxrt: Small cleanups for OCOTP headers
- Add conditional includes for both 117x/118x headers in hardware/imxrt_ocotp.h
- Add CHIP_ID and UNIQUE_ID addresses in imxrt118x_ocotp.h
- Remove access to those timing registers which don't exist on imxrt117x,
  which don't exist on that chip, in imxrt_ocotp_initialize.

Signed-off-by: Jukka Laitinen <jukka.laitinen@tii.ae>
2026-09-29 08:27:28 -03:00
Jukka Laitinen
9fa22b32c1 arch/arm/imxrt: Add board-specific clock configuration tables for imxrt118x
Implement the same initial clock configuration as what imxrt1176 has. Make an own table
for PLL and root clock configurations for m33 and m7 targets. For the PLLs the code still
only supports configuring the ARM_PLL.

The difference to imxrt1176 is, that instead of just boolean .enable field, this table
uses an .action field with 3 states: CONFIGURE, DISABLE and IGNORE. The reason is,
that some root clocks can't be just forcefully stopped, but need a root-clock-specific
sequence. This is solved by just leaving these clocks marked as IGNORE, so they retain
their current state.

Specifically, disabling the SEMC and NETC roots by M33 will prevent the M7 from booting.
Also FLEXSPI shouldn't be touched, if the code is being executed from there.

Also add a function for enabling 24 MHz oscillator clock, and an extendable function to
enable the clock sources based on the clock configuration table.

Assisted-by: Claude Code
Signed-off-by: Jukka Laitinen <jukka.laitinen@tii.ae>
2026-09-29 18:40:10 +08:00
leocafonso
ec916ba564 Documentation/arm/ra8m1: Add Renesas RA8M1 documentation
Some checks are pending
Build Documentation / build-html (push) Waiting to run
MemBrowse Memory Report / changes-filter (push) Waiting to run
MemBrowse Memory Report / load-targets (push) Waiting to run
MemBrowse Memory Report / identical (push) Blocked by required conditions
MemBrowse Memory Report / analyze (push) Blocked by required conditions
Add platform and EK-RA8M1 board documentation.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Signed-off-by: leocafonso <leocafonso@gmail.com>
2026-09-29 06:46:52 -03:00
leocafonso
9d0008c3b2 boards/arm/ra8m1: Add Renesas EK-RA8M1 board support
Add board support for the EK-RA8M1 evaluation kit with nsh and
nsh-leds configurations, linker script, LED support and bring-up.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Signed-off-by: leocafonso <leocafonso@gmail.com>
2026-09-29 06:46:52 -03:00
leocafonso
1515b3fafd arch/arm/ra8m1: Add Renesas RA8M1 chip support
Add initial architecture support for the Renesas RA8M1 (Cortex-M85)
family: clock configuration, GPIO, ICU/IRQ handling, SCI serial,
system timer, option setting and start-up code, plus the Kconfig and
build system integration.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Signed-off-by: leocafonso <leocafonso@gmail.com>
2026-09-29 06:46:52 -03:00
Erik Englund
0fafd0bc7f arch/risc-v/espressif: Fix nxstyle issues in esp_serial.c.
Some checks are pending
Build Documentation / build-html (push) Waiting to run
MemBrowse Memory Report / changes-filter (push) Waiting to run
MemBrowse Memory Report / load-targets (push) Waiting to run
MemBrowse Memory Report / identical (push) Blocked by required conditions
MemBrowse Memory Report / analyze (push) Blocked by required conditions
Indent the case labels of the esp_ioctl() switch one level deeper, as
nxstyle expects, fix the odd indentation of the TIOCSERGSTRUCT case
and add the missing blank lines after declarations.  No functional
change.

Assisted-by: Claude:claude-opus-5-5
Signed-off-by: Erik Englund <erik.englund@gmail.com>
2026-09-29 09:10:53 +08:00
Erik Englund
d0a86138ce arch/risc-v/espressif: Release RS-485 DIR on TX_DONE.
In RS-485 mode the DIR (DE) pin was only released on TX_BRK_IDLE_DONE.
That interrupt is part of the UART break feature (UART_TXD_BRK), which
this driver never enables, so it does not fire after normal data: DIR
stayed asserted after the first transmit and the port never received
again.

TX_DONE is the right event, but the upper half calls txint(false) as
soon as its software buffer is empty, while the last bytes are still
in the FIFO (see #15888), so it has to outlive txint(false):

* txint(false) keeps TX_DONE enabled on an RS-485 port.
* On TX_DONE with the software buffer and TX FIFO empty, the handler
  waits (bounded) for the transmitter to go idle, releases DIR and
  disables TX_DONE.
* txempty() uses uart_hal_is_tx_idle() (FIFO count and FSM state).
  The raw TXFIFO_EMPTY bit only means the FIFO is below its empty
  threshold, so tcdrain() could return with data still in the FIFO.

Same approach as the ESP32-S3 fix in #20389.

Assisted-by: Claude:claude-opus-5-5
Signed-off-by: Erik Englund <erik.englund@gmail.com>
2026-09-29 09:10:53 +08:00
Erik Englund
5dd13b578d arch/risc-v/espressif: Fix dangling else in esp_setup() for RS-485.
The RS-485 tx_idle_num block in esp_setup() ends in a bare "else" that
binds to the next statement, which is now leave_critical_section().  On
an RS-485 port esp_setup() therefore returns with interrupts disabled.

uart_open() hides this behind its own critical section, but a
tcsetattr() that changes the line settings calls esp_setup() through
TCSETS and leaves the calling task running with interrupts off.  On an
ESP32-C3 the system tick stops advancing in that task.

Assisted-by: Claude:claude-opus-5-5
Signed-off-by: Erik Englund <erik.englund@gmail.com>
2026-09-29 09:10:53 +08:00
Max Kriegleder
fe7eff404e arch/xtensa/esp32s3: Release RS-485 DIR on TX_DONE.
In RS-485 mode the driver released the direction (DE) pin only on
TX_BRK_IDLE_DONE. That interrupt belongs to the break feature
(UART_TXD_BRK), which this driver never enables, so it never fired and
DIR stayed asserted after the first transmit. The board then kept driving
the bus and collided with every reply. The interrupt was also never
cleared, so had it fired, the handler would have re-entered forever.

TX_DONE cannot simply replace it: the upper half calls txint(false) as
soon as its software buffer drains, which disabled TX_DONE while the last
bytes were still in the FIFO (see #15888).

* Keep TX_DONE enabled in txint(false) while in RS-485 mode.
* In the handler, on TX_DONE with the software buffer and TX FIFO empty,
  wait (bounded) for the transmitter FSM to go idle so the last stop bit
  is not clipped, release DIR and disable TX_DONE. This is how ESP-IDF's
  RS-485 half-duplex mode handles it.
* Make txempty() use FIFO count and FSM state, as ESP-IDF's
  uart_ll_is_tx_idle() does. The raw TX_DONE bit reads 0 before the
  first transmission and is now cleared by the handler, which would
  make tcdrain() wait for its full timeout.

Tested on an ESP32-S3 board with an SP3485 transceiver (DE/RE on GPIO21)
at 115200 baud, doing Modbus RTU reads against a servo drive: without the
patch every request timed out; with it DIR drops right after the last stop
bit and all reads succeed.

Assisted-by: Claude:claude-opus-5-5
Signed-off-by: Max Kriegleder <max.kriegleder@gmail.com>
2026-09-29 09:09:24 +08:00
Marco Casaroli
3297bbec44 arch/arm/mps: Let user code run modules from the text and data heaps.
In a protected build a module loaded by exec() runs as a user task, and
the loader puts it in the text and data heaps, which on this chip are
SRAM2.  Nothing gave user code access to SRAM2: the region that would have
done so, in arm_addregion(), exists only with CONFIG_MM_REGIONS > 1, and it
is built with mpu_user_intsram(), which on ARMv8-M is execute-never.  So
the module faulted on its first instruction.

The protected build now maps SRAM2 for user code to read, write and
execute when either heap is in use.  Privileged execution stays allowed,
since a kernel module loaded with insmod lands in the same heaps.

On mps3-an547:knsh under QEMU, with CONFIG_ELF, both heaps and the ROMFS
variant of examples/elf, errno faulted on its first instruction with an
instruction access violation at 0x21000001.  Now every module of the
example runs to the end.

Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
2026-09-28 16:46:05 -03:00
Marco Casaroli
b960000dc8 arch/arm/mps: Add a blank line after a declaration.
Whitespace only, and older than the changes that follow.  nxstyle checks
every file a pull request touches in full.

Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
2026-09-28 16:46:05 -03:00
Marco Casaroli
08c0cce0d9 libs/libc: Define the NXFLAT ABI marker in libc.
Every NXFLAT module imports __nxflat_abi_v2, and the loader resolves it
against the symbol table exec() is given, like any other import.  It was
defined in binfmt/libnxflat, which is enough for a flat build, where the
firmware and the applications are one image.

In a protected build the table comes from the application, in the user
image, which cannot see a kernel symbol: the user image fails to link with
an undefined reference to __nxflat_abi_v2 as soon as an application
generates its table from the modules' imports, as examples/nxflat does.  A
kernel build is the same, with one image per process.

libc is linked into each of those images, so the marker is defined there
now.  Nothing else changes: its value is still never used.

On mps3-an547:knsh under QEMU with CONFIG_NXFLAT and examples/nxflat, the
user image links, and errno, hello, mutex, pthread and struct run.
lm3s6965-ek:qemu-nxflat still runs every module to the end.

Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
2026-09-28 16:45:48 -03:00
Marco Casaroli
899c56c218 binfmt/libnxflat: Fix the style of libnxflat_bind.c.
Whitespace only, and older than the change that follows it.  nxstyle
checks every file a pull request touches in full, and this one had 37
errors: the case labels of the relocation switch sat at the column of its
brace, three assignments were one column short, and a declaration had no
blank line after it.

Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
2026-09-28 16:45:48 -03:00
Marco Casaroli
295f0e373c tools/nxflat: Leave ARM unwind tables out of an NXFLAT module.
CONFIG_UNWINDER_ARM compiles everything with -funwind-tables, modules
included, so each module carries .ARM.exidx and .ARM.extab.  The NXFLAT
link scripts do not name them, and ldnxflat placed them in D-Space, where
the first R_ARM_PREL31 entry stopped the conversion:

  ldnxflat: arm relocation 42 at D-Space 00000018 is not handled

That relocation cannot be handled: an exidx entry is an offset from itself
to a function in I-Space, and the distance between the two segments is only
known when the loader places them.  Nothing unwinds through a module
either, since the unwinder only reads the firmware's own table.

So ldnxflat leaves both sections out of the images, and with them the
relocations against them, as it already does for sections it does not
place.  A module without unwind tables converts exactly as before.

On mps3-an547:nsh under QEMU with CONFIG_UNWINDER_ARM and examples/nxflat,
the modules failed to convert; now they convert and errno, hello, mutex,
pthread and struct run.  The eleven modules of tools/nxflat/testsuite.sh
convert to the same bytes as before.

Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
2026-09-28 16:45:09 -03:00
Daniel P. Carvalho
317bfcf67c arch/arm/stm32h7: declare NETDEV_TX_STAMP capability flag
Some checks are pending
MemBrowse Memory Report / changes-filter (push) Waiting to run
MemBrowse Memory Report / load-targets (push) Waiting to run
MemBrowse Memory Report / identical (push) Blocked by required conditions
MemBrowse Memory Report / analyze (push) Blocked by required conditions
Advertise NETDEV_TX_STAMP in dev.d_features during stm32_ethinitialize()
when CONFIG_STM32_ETH_TIMESTAMP_TX is enabled, indicating that the STM32H7
Ethernet driver provides hardware TX timestamping.

Assisted-by: Gemini:gemini-3.8-pro
Assisted-by: Claude:claude-sonnet-5
Signed-off-by: Daniel P. Carvalho <danieloak@gmail.com>
2026-09-28 12:53:24 -03:00
Daniel P. Carvalho
864132395d arch/arm/stm32: declare NETDEV_TX_STAMP capability flag
Advertise the NETDEV_TX_STAMP capability flag in stm32_ethinitialize()
when CONFIG_STM32_ETH_TIMESTAMP_TX is enabled, indicating that the driver
provides hardware TX timestamping.

Assisted-by: Gemini:gemini-3.8-pro
Assisted-by: Claude:claude-sonnet-5
Signed-off-by: Daniel P. Carvalho <danieloak@gmail.com>
2026-09-28 12:53:24 -03:00
Claude
6e14c8cfe5 net/netdev: add NETDEV_TX_STAMP and handle SIOCETHTOOL ETHTOOL_GET_TS_INFO
Add the NETDEV_TX_STAMP capability flag to d_features, next to the
existing NETDEV_RX_STAMP, so a driver can declare that it delivers
hardware TX timestamps.

SIOCETHTOOL and ETHTOOL_GET_TS_INFO were already defined but not
implemented.  Add struct ethtool_ts_info, with the same layout as
Linux, and handle SIOCETHTOOL in netdev_ioctl.c so that userspace (such
as ptpd) can query the timestamping capabilities of an interface the
same way linuxptp/ptp4l does on Linux:

- ETHTOOL_GET_TS_INFO fills so_timestamping from d_features:
  RX_HARDWARE | RAW_HARDWARE with NETDEV_RX_STAMP, otherwise
  RX_SOFTWARE | SOFTWARE (the stack stamps received packets with
  CLOCK_REALTIME), and TX_HARDWARE | RAW_HARDWARE with NETDEV_TX_STAMP.
  phc_index is -1, tx_types and rx_filters are zero.
- Any other ethtool command is passed to the driver's d_ioctl when
  CONFIG_NETDEV_IOCTL is enabled, otherwise -ENOTTY is returned.

Assisted-by: Claude:claude-sonnet-5
Signed-off-by: Daniel P. Carvalho <danieloak@gmail.com>
2026-09-28 12:53:24 -03:00
Claude
b7001f2d9f include/sys/socket.h: give SOF_TIMESTAMPING_* their Linux values
All SOF_TIMESTAMPING_* flags currently alias 1 << SO_TIMESTAMPING, so
they cannot tell hardware from software or RX from TX.  Give them their
distinct Linux values, and add SOF_TIMESTAMPING_RX_HARDWARE,
SOF_TIMESTAMPING_RX_SOFTWARE and SOF_TIMESTAMPING_SYS_HARDWARE, so that
they can also describe the timestamping capabilities of an interface
(so_timestamping of ETHTOOL_GET_TS_INFO).

This does not change behaviour: setsockopt(SO_TIMESTAMPING) only checks
for a non-zero value and getsockopt() returns 0 or 1, so existing users
and binaries built with the previous values keep working.  The
individual flags are still not honoured.

Assisted-by: Claude:claude-sonnet-5
Signed-off-by: Daniel P. Carvalho <danieloak@gmail.com>
2026-09-28 12:53:24 -03:00
Royyan Zahir
68dd87f4df arch/arm64/imx9: add key store, signing and persistence to the ELE
The EdgeLock Enclave offers a key store the mailbox driver did not
reach. A key generated in there is permitted one algorithm and one
usage, and export can be withheld, so the private half has no command
that returns it.

Adds the session, key store and key management services, key generation,
signing by handle, and the storage exchange that makes a key store
outlive a boot. Storage runs the other way round from every other
command: the enclave asks the host to write its key store down and to
give it back, and those requests arrive while a command of this side's
is still outstanding, so the reply tag is what tells them apart.

Two things a port has to know and neither reference nor header says.
Key store commands carry a trailing crc, the exclusive or of every word
including the header, without which the enclave answers rating 0xb9. And
a persistent key lifetime is a statement of intent: the strict flag on
key generation is what writes the key to the store, and without it a
store exported around the key comes back without it.

Every mailbox wait is bounded. An enclave that stops answering must not
take the calling thread with it, and a reply buffer is a kilobyte, which
does not belong on the stack of whatever task asked for a signature.

Tested on an i.MX93: a P-256 key generated in the enclave, signing a
digest whose signature verifies against the returned public half on a
host, and still doing so after the board has been powered off.

Signed-off-by: Royyan Zahir <royzah@gmail.com>
2026-09-28 21:50:43 +08:00
Justin Hammond
86da4d11ea drivers/usbhost: Correct the style of usbhost_hub.c.
nxstyle reports fourteen errors in this file.  The switch in
usbhost_hub_configdesc() puts its case labels level with the brace that
opens the switch rather than one step further in, and a declaration is
followed straight away by a statement.

CI checks every file a patch touches rather than only the lines it
changes, so these have to go before anything else in this file can be
altered.

Whitespace, three comments rewrapped to stay inside the line limit
after the extra indent, and one blank line.  No code changes: git diff
-w shows only the comments.

Assisted-by: Claude:claude-opus-5
Signed-off-by: Justin Hammond <justin@dynam.ac>
2026-09-28 21:45:57 +08:00
Justin Hammond
ed046adeb4 drivers/usbhost: Tell the host stack which controller a port belongs to.
struct usbhost_roothubport_s carries the number of the controller its port
belongs to, so a port can be named on a system with more than one.
Nothing set it.

Take the number from whoever brings the controller up rather than counting
registrations, which would agree with the name the driver reports only
while controllers are registered in the order they are named.

Assisted-by: Claude:claude-opus-5
Signed-off-by: Justin Hammond <justin@dynam.ac>
2026-09-28 21:45:57 +08:00
Justin Hammond
ba7c7e1f77 drivers/usbhost: Support USB hubs on xHCI.
The driver refused CONFIG_USBHOST_HUB outright.  Everything needed to
describe a device behind a hub is now in place, so implement the rest.

- xhci_device_init() took a root hub port and read the slot, the control
  endpoint and the device out of it, all of which belong to the device.
  It now takes the hub port and the control endpoint, and records the
  device on the root port only when that is where it sits: once a hub is
  plugged in, the device a root port names is the hub.  xhci_address_set()
  and xhci_device_deinit() likewise work on a device, and
  xhci_disconnect() finds the device by the port going away.
- The hub asks for a port's control endpoint before it reports the
  connection, so xhci_epalloc() has nothing to attach one to.  It returns
  an endpoint with no slot, and xhci_connect() gives it one when it
  creates the device.
- A hub must be described to the controller as a hub before anything
  behind it can be reached, and nothing knows it is one when its slot is
  created.  xhci_hub_update() corrects the slot context with a Configure
  Endpoint command the first time something appears behind it.
- A hub reports each changed port without waiting for the last to be dealt
  with, so the connect method queues them; holding one pointer meant the
  second report overwrote the first.  No more can be outstanding than the
  controller has slots.
- Report the root port and slot counts from HCSPARAMS1, and the port count
  from a hub's descriptor.

Tested on an EIC7700X board with a hub on one controller and a keyboard on
the other.  Behind the hub, a 59 GB mass storage device mounts and reads a
file back, and a composite CDC device gives four ttyACM nodes.

Assisted-by: Claude:claude-opus-5
Signed-off-by: Justin Hammond <justin@dynam.ac>
2026-09-28 21:45:57 +08:00
Justin Hammond
9af6540381 drivers/usbhost: Describe a device behind a hub to the xHCI controller.
A controller reaches a device by the path to it and, for a slow device,
through the hub that translates for it.  Neither was described, so a
device behind a hub was addressed as though it were on the root port.

The route string is that path: each hub between the device and the root
contributes a nibble holding the port the next thing down occupies, tier
nearest the root in the lowest nibble.  Walking up from the device reaches
the deepest tier first, so shifting left by a nibble each time leaves them
in the order the field wants.  The walk stops after five, which is what
the field holds and what USB allows, and a port above fifteen is clamped.

Slot context dword 2 names the transaction translator carrying a low or
full speed device behind a high speed hub.  It reports the hub by slot,
where EHCI reports it by USB address, and it names the nearest high speed
ancestor rather than the immediate parent, since a full speed hub below a
high speed one is itself carried by the translator above it.  The think
time comes from the hub descriptor by way of the hub class driver, in the
same units.

xhci_epalloc() carried a copy of sam_ehci.c's block, writing
epinfo->hubaddr and epinfo->hubport, which is how EHCI describes a split
transaction in its queue head.  This driver never read either field, and
xHCI wants the information in the slot context.  Both fields and the code
setting them are removed.

Multi-TT is not set, for the reason given in the previous commit.

No functional change: hubs cannot be enabled yet, and a device on a root
port has neither hubs above it nor a translator.

Assisted-by: Claude:claude-opus-5
Signed-off-by: Justin Hammond <justin@dynam.ac>
2026-09-28 21:45:57 +08:00