Commit graph

25321 commits

Author SHA1 Message Date
Marco Casaroli
e7c6367533 arch/arm: Call FDPIC constructors with the module's own data base.
Under FDPIC an .init_array or .fini_array entry is a code address, but a
C function pointer is a function descriptor.  crt0 called each entry
through a function pointer, so it read the constructor's first
instructions as a descriptor and jumped to garbage.

Call each entry with fdpic_call() and the data base from fdpic_base(),
which is the module's own.  Without CONFIG_FDPIC both are a direct call,
as before.

Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
2026-09-30 13:40:02 -03:00
Felipe Moura
1c6ed642bf espressif: stop leaking a Wi-Fi interrupt handle on every esp_wifi_start()
set_intr_wrapper() allocates a new intr_handle_data_t from the kernel
heap each time the Wi-Fi driver calls it, and the driver calls it on
every esp_wifi_start() -- twice per start on esp32s3 -- not only the
first time.  clear_intr_wrapper() is a no-op, so the IRQ still holds the
handle from the previous start: esp_set_handle() refuses to replace it
with -EINVAL, the return value is ignored, and the new block is lost.

Any application that stops and restarts Wi-Fi to save power therefore
loses a few bytes of kernel heap per cycle, without bound.

Look up the vector descriptor first, then reuse the handle already
registered for the IRQ and only allocate and register one when there is
none.  A failed descriptor lookup no longer touches the registered
handle.

The same code is present in the esp32, esp32s2, esp32s3, esp32c3 and
esp32c6 Wi-Fi adapters; all five are fixed the same way.

Signed-off-by: Felipe Moura <moura.fmo@gmail.com>
Assisted-by: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-30 13:25:42 -03:00
Royyan Zahir
6bec3b6f5b arch/arm64/imx9: reject PWM channels outside the timer
A negative channel passed both checks, and TPM took one past the end,
so a caller could write FlexIO and TPM registers it does not own. TPM
also dropped the error and reported success.

Signed-off-by: Royyan Zahir <royzah@gmail.com>
2026-09-30 09:24:36 -03:00
Jukka Laitinen
a48fd7363a arch/arm/imxrt: Fix rgpio interrupt definitions
Pack the LOWLEVEL/HIGHLEVEL/RISINGEDGE/FALLINGEDGE directly into correct bits in
pinset.

Signed-off-by: Jukka Laitinen <jukka.laitinen@tii.ae>
2026-09-30 14:10:58 +08:00
Jukka Laitinen
f55525b0fa arch/arm/imxrt: Fix GPIO / IOMUX macros for imxrt1180
There were some bits erroneously copied from imx9. For IMXRT1180, the
GPIO_AD* and GPIO_AON* pads should have SRE, DSE, PUE, PUS and ODE bits
on SW_PAD_CTL_PAD register.

The GPIO_EMC_*, GPIO_SD_*, GPIO_B1_* and GPIO_B2_* have a bit different fields,
PDRV, PULL and ODE.

Signed-off-by: Jukka Laitinen <jukka.laitinen@tii.ae>
2026-09-30 14:10:58 +08:00
Jukka Laitinen
88a4331348 arch/arm/imxrt: Fix imxrt_clockconfig_ver3 c++ linkage
There was a mismatched EXTERN definition for ver3 in imxrt_periphclks.h,
and the extern definitions should be there in imxrt_clockconfig_ver3.h

Signed-off-by: Jukka Laitinen <jukka.laitinen@tii.ae>
2026-09-30 14:10:58 +08:00
raiden00pl
3ab1b4b8fe arm/nrf54l: add RRAM progmem support
add RRAM progmem support

Assisted-by: Codex:GPT-6
Signed-off-by: raiden00pl <raiden00@railab.me>
2026-09-29 14:29:04 -03:00
Marco Casaroli
1ccd940e44 arch/xtensa: Use one name for the stack frame alignment.
Two files each defined the same 16 byte constant, KSTACK_ALIGNMENT and
SIGTRAMP_STACK_ALIGN.  Use STACKFRAME_ALIGN, which arch/xtensa/include/irq.h
already gives as 16, with the STACKFRAME_ALIGN_DOWN() of nuttx/irq.h.

STACK_ALIGNMENT is not the name to use here.  It is TLS_STACK_ALIGN when
CONFIG_TLS_ALIGNED is set, which is the alignment of a thread stack and not
of a frame.

Assisted-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
2026-09-29 11:13:47 -03:00
Marco Casaroli
1b59698bde xtensa/esp32s3: Report an access through an invalid MMU entry.
The PMS grants and refuses physical addresses, so it never sees an access
that no MMU entry translates.  The cache answered such an access with zeros
and raised nothing, and the task carried on with a value it never should
have had.

Enable EXTMEM_MMU_ENTRY_FAULT and route the Cache Invalid Access interrupt
to the handler that already serves the PMS monitors.  An unprivileged task
that makes the access is terminated with SIGSEGV;  a privileged one still
panics.  The latch is level triggered, so it is cleared with the others.

Read the cause before the clear, so the log tells the two apart:  a PMS
violation is a refused translation, an MMU entry fault is an access that was
never translated.

Give the kernel_oct configuration the addresses that examples/sandbox needs
to name its targets.

Assisted-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
2026-09-29 11:13:47 -03:00
Marco Casaroli
df782bd1e5 xtensa/esp32s3: Stop an unreportable cache fault from livelocking.
Reporting a fault can itself fault.  syslog reaches memory the fault being
reported may have made unreachable, so esp32s3_pagefault_dispatch() is
re-entered from inside its own _alert() and never returns, and the console
fills with the same half-printed line forever.  Found under Espressif's QEMU,
where PSRAM never initialises and the kernel build needs it; the board's
PSRAM works, so hardware does not take this path.

A fault repeating at the same address and PC is not helped by reporting it
again, so the dispatcher tries three times and then halts with interrupts
off.  esp32s3_userfault_abort() clears the count through
esp32s3_pagefault_clear_repeat(): reaching it means the fault was contained,
so only unbroken recursion stops the machine, and three probes at one
address do not halt a healthy system.

Verified under QEMU: 12,958,521 bytes of output in 60 s before, four reports
and a halt after.  On an ESP32-S3 DevKitC, esp32s3-devkit:kernel_oct, three
identical sandbox probes in one boot are all contained.

Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
2026-09-29 11:13:47 -03:00
Marco Casaroli
802ccef86f xtensa/esp32s3: Abort the faulting user task on an unrecoverable fault.
When an unprivileged task takes a fault the system cannot recover from, it
now gets a fatal SIGSEGV and only that task ends.  A fault in privileged code
still panics.

What decides it is the interrupted context, not the cause: the saved PS says
whether the fault was taken in User Mode.  A list of causes would leave every
cause off the list as a way for a user task to stop the machine, and there
are many -- a divide by zero, a privileged instruction, a load/store error,
and an illegal instruction, which is how a refused fetch from kernel text
arrives on this chip (TRM v1.8 p.699: a denied external-memory access is
answered with 0xdeadbeaf instead of trapping).  PS.UM is clear in a kernel
thread, in a system call made on the user's behalf and in an interrupt
handler, so those still panic.  If the recoverable-fault dispatcher is
enabled it still gets first refusal on causes 28, 29 and 20, the only ones
re-executing can help.

esp32s3_userfault_abort() records the exception frame as the task's context,
dispatches SIGSEGV, and returns the redirected frame, so the vector's RFE
resumes the task in the signal trampoline, whose default action exits it.
CONFIG_ESP32S3_USERFAULT_ABORT enables it, default y wherever there is an
unprivileged world, and selects SIG_DEFAULT and SIG_SIGKILL_ACTION.

Verified on an ESP32-S3 DevKitC with a WROOM-2 module,
esp32s3-devkit:kernel_oct: a user task that writes through NULL, reads a wild
address, divides by zero, calls into a buffer of garbage or branches into
kernel text is terminated on its own, while an unrelated task keeps running.

Stack overflow is not contained.  On the windowed ABI it faults inside the
window overflow handler and arrives as a double exception with PS.UM already
clear; guard pages are the answer, and separate work.

Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
2026-09-29 11:13:47 -03:00
Marco Casaroli
c6b23e3e21 xtensa/esp32s3: Isolate the unprivileged world.
Separate the world split from the protected user image, give WORLD1 its own
vector table and its own PMS permissions -- including the PSRAM -- clean up
the user cache-MMU windows, and stop keeping the page pool mapped.

Folds in:
  xtensa/esp32s3: separate the world split from the protected user image
  xtensa/esp32s3: give the unprivileged world its own vector table
  xtensa/esp32s3: give the unprivileged world its permissions
  xtensa/esp32s3: clean up the user cache-MMU windows
  xtensa/esp32s3: stop keeping the page pool mapped
  xtensa/esp32s3: give the PSRAM its own PMS permissions

Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
2026-09-29 11:13:47 -03:00
Jukka Laitinen
c7080cbdfe arch/arm/imxrt: Small cleanups for OCOTP headers
- Add conditional includes for both 117x/118x headers in hardware/imxrt_ocotp.h
- Add CHIP_ID and UNIQUE_ID addresses in imxrt118x_ocotp.h
- Remove access to those timing registers which don't exist on imxrt117x,
  which don't exist on that chip, in imxrt_ocotp_initialize.

Signed-off-by: Jukka Laitinen <jukka.laitinen@tii.ae>
2026-09-29 08:27:28 -03:00
Jukka Laitinen
9fa22b32c1 arch/arm/imxrt: Add board-specific clock configuration tables for imxrt118x
Implement the same initial clock configuration as what imxrt1176 has. Make an own table
for PLL and root clock configurations for m33 and m7 targets. For the PLLs the code still
only supports configuring the ARM_PLL.

The difference to imxrt1176 is, that instead of just boolean .enable field, this table
uses an .action field with 3 states: CONFIGURE, DISABLE and IGNORE. The reason is,
that some root clocks can't be just forcefully stopped, but need a root-clock-specific
sequence. This is solved by just leaving these clocks marked as IGNORE, so they retain
their current state.

Specifically, disabling the SEMC and NETC roots by M33 will prevent the M7 from booting.
Also FLEXSPI shouldn't be touched, if the code is being executed from there.

Also add a function for enabling 24 MHz oscillator clock, and an extendable function to
enable the clock sources based on the clock configuration table.

Assisted-by: Claude Code
Signed-off-by: Jukka Laitinen <jukka.laitinen@tii.ae>
2026-09-29 18:40:10 +08:00
leocafonso
1515b3fafd arch/arm/ra8m1: Add Renesas RA8M1 chip support
Add initial architecture support for the Renesas RA8M1 (Cortex-M85)
family: clock configuration, GPIO, ICU/IRQ handling, SCI serial,
system timer, option setting and start-up code, plus the Kconfig and
build system integration.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Signed-off-by: leocafonso <leocafonso@gmail.com>
2026-09-29 06:46:52 -03:00
Erik Englund
0fafd0bc7f arch/risc-v/espressif: Fix nxstyle issues in esp_serial.c.
Some checks are pending
Build Documentation / build-html (push) Waiting to run
MemBrowse Memory Report / changes-filter (push) Waiting to run
MemBrowse Memory Report / load-targets (push) Waiting to run
MemBrowse Memory Report / identical (push) Blocked by required conditions
MemBrowse Memory Report / analyze (push) Blocked by required conditions
Indent the case labels of the esp_ioctl() switch one level deeper, as
nxstyle expects, fix the odd indentation of the TIOCSERGSTRUCT case
and add the missing blank lines after declarations.  No functional
change.

Assisted-by: Claude:claude-opus-5-5
Signed-off-by: Erik Englund <erik.englund@gmail.com>
2026-09-29 09:10:53 +08:00
Erik Englund
d0a86138ce arch/risc-v/espressif: Release RS-485 DIR on TX_DONE.
In RS-485 mode the DIR (DE) pin was only released on TX_BRK_IDLE_DONE.
That interrupt is part of the UART break feature (UART_TXD_BRK), which
this driver never enables, so it does not fire after normal data: DIR
stayed asserted after the first transmit and the port never received
again.

TX_DONE is the right event, but the upper half calls txint(false) as
soon as its software buffer is empty, while the last bytes are still
in the FIFO (see #15888), so it has to outlive txint(false):

* txint(false) keeps TX_DONE enabled on an RS-485 port.
* On TX_DONE with the software buffer and TX FIFO empty, the handler
  waits (bounded) for the transmitter to go idle, releases DIR and
  disables TX_DONE.
* txempty() uses uart_hal_is_tx_idle() (FIFO count and FSM state).
  The raw TXFIFO_EMPTY bit only means the FIFO is below its empty
  threshold, so tcdrain() could return with data still in the FIFO.

Same approach as the ESP32-S3 fix in #20389.

Assisted-by: Claude:claude-opus-5-5
Signed-off-by: Erik Englund <erik.englund@gmail.com>
2026-09-29 09:10:53 +08:00
Erik Englund
5dd13b578d arch/risc-v/espressif: Fix dangling else in esp_setup() for RS-485.
The RS-485 tx_idle_num block in esp_setup() ends in a bare "else" that
binds to the next statement, which is now leave_critical_section().  On
an RS-485 port esp_setup() therefore returns with interrupts disabled.

uart_open() hides this behind its own critical section, but a
tcsetattr() that changes the line settings calls esp_setup() through
TCSETS and leaves the calling task running with interrupts off.  On an
ESP32-C3 the system tick stops advancing in that task.

Assisted-by: Claude:claude-opus-5-5
Signed-off-by: Erik Englund <erik.englund@gmail.com>
2026-09-29 09:10:53 +08:00
Max Kriegleder
fe7eff404e arch/xtensa/esp32s3: Release RS-485 DIR on TX_DONE.
In RS-485 mode the driver released the direction (DE) pin only on
TX_BRK_IDLE_DONE. That interrupt belongs to the break feature
(UART_TXD_BRK), which this driver never enables, so it never fired and
DIR stayed asserted after the first transmit. The board then kept driving
the bus and collided with every reply. The interrupt was also never
cleared, so had it fired, the handler would have re-entered forever.

TX_DONE cannot simply replace it: the upper half calls txint(false) as
soon as its software buffer drains, which disabled TX_DONE while the last
bytes were still in the FIFO (see #15888).

* Keep TX_DONE enabled in txint(false) while in RS-485 mode.
* In the handler, on TX_DONE with the software buffer and TX FIFO empty,
  wait (bounded) for the transmitter FSM to go idle so the last stop bit
  is not clipped, release DIR and disable TX_DONE. This is how ESP-IDF's
  RS-485 half-duplex mode handles it.
* Make txempty() use FIFO count and FSM state, as ESP-IDF's
  uart_ll_is_tx_idle() does. The raw TX_DONE bit reads 0 before the
  first transmission and is now cleared by the handler, which would
  make tcdrain() wait for its full timeout.

Tested on an ESP32-S3 board with an SP3485 transceiver (DE/RE on GPIO21)
at 115200 baud, doing Modbus RTU reads against a servo drive: without the
patch every request timed out; with it DIR drops right after the last stop
bit and all reads succeed.

Assisted-by: Claude:claude-opus-5-5
Signed-off-by: Max Kriegleder <max.kriegleder@gmail.com>
2026-09-29 09:09:24 +08:00
Marco Casaroli
3297bbec44 arch/arm/mps: Let user code run modules from the text and data heaps.
In a protected build a module loaded by exec() runs as a user task, and
the loader puts it in the text and data heaps, which on this chip are
SRAM2.  Nothing gave user code access to SRAM2: the region that would have
done so, in arm_addregion(), exists only with CONFIG_MM_REGIONS > 1, and it
is built with mpu_user_intsram(), which on ARMv8-M is execute-never.  So
the module faulted on its first instruction.

The protected build now maps SRAM2 for user code to read, write and
execute when either heap is in use.  Privileged execution stays allowed,
since a kernel module loaded with insmod lands in the same heaps.

On mps3-an547:knsh under QEMU, with CONFIG_ELF, both heaps and the ROMFS
variant of examples/elf, errno faulted on its first instruction with an
instruction access violation at 0x21000001.  Now every module of the
example runs to the end.

Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
2026-09-28 16:46:05 -03:00
Marco Casaroli
b960000dc8 arch/arm/mps: Add a blank line after a declaration.
Whitespace only, and older than the changes that follow.  nxstyle checks
every file a pull request touches in full.

Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
2026-09-28 16:46:05 -03:00
Daniel P. Carvalho
317bfcf67c arch/arm/stm32h7: declare NETDEV_TX_STAMP capability flag
Some checks are pending
MemBrowse Memory Report / changes-filter (push) Waiting to run
MemBrowse Memory Report / load-targets (push) Waiting to run
MemBrowse Memory Report / identical (push) Blocked by required conditions
MemBrowse Memory Report / analyze (push) Blocked by required conditions
Advertise NETDEV_TX_STAMP in dev.d_features during stm32_ethinitialize()
when CONFIG_STM32_ETH_TIMESTAMP_TX is enabled, indicating that the STM32H7
Ethernet driver provides hardware TX timestamping.

Assisted-by: Gemini:gemini-3.8-pro
Assisted-by: Claude:claude-sonnet-5
Signed-off-by: Daniel P. Carvalho <danieloak@gmail.com>
2026-09-28 12:53:24 -03:00
Daniel P. Carvalho
864132395d arch/arm/stm32: declare NETDEV_TX_STAMP capability flag
Advertise the NETDEV_TX_STAMP capability flag in stm32_ethinitialize()
when CONFIG_STM32_ETH_TIMESTAMP_TX is enabled, indicating that the driver
provides hardware TX timestamping.

Assisted-by: Gemini:gemini-3.8-pro
Assisted-by: Claude:claude-sonnet-5
Signed-off-by: Daniel P. Carvalho <danieloak@gmail.com>
2026-09-28 12:53:24 -03:00
Royyan Zahir
68dd87f4df arch/arm64/imx9: add key store, signing and persistence to the ELE
The EdgeLock Enclave offers a key store the mailbox driver did not
reach. A key generated in there is permitted one algorithm and one
usage, and export can be withheld, so the private half has no command
that returns it.

Adds the session, key store and key management services, key generation,
signing by handle, and the storage exchange that makes a key store
outlive a boot. Storage runs the other way round from every other
command: the enclave asks the host to write its key store down and to
give it back, and those requests arrive while a command of this side's
is still outstanding, so the reply tag is what tells them apart.

Two things a port has to know and neither reference nor header says.
Key store commands carry a trailing crc, the exclusive or of every word
including the header, without which the enclave answers rating 0xb9. And
a persistent key lifetime is a statement of intent: the strict flag on
key generation is what writes the key to the store, and without it a
store exported around the key comes back without it.

Every mailbox wait is bounded. An enclave that stops answering must not
take the calling thread with it, and a reply buffer is a kilobyte, which
does not belong on the stack of whatever task asked for a signature.

Tested on an i.MX93: a P-256 key generated in the enclave, signing a
digest whose signature verifies against the returned public half on a
host, and still doing so after the board has been powered off.

Signed-off-by: Royyan Zahir <royzah@gmail.com>
2026-09-28 21:50:43 +08:00
raiden00pl
a8ac2e74e0 arch/nrf52: add SAADC external TIMER trigger over PPI
The SAADC internal sample timer only works with a single enabled
channel, so hardware-timed multi-channel scan was not possible.  Add
NRF52_SAADC_TIMER_PPI, a third trigger mode in which a general-purpose
TIMER compare event is routed to TASKS_SAMPLE over PPI.  All enabled
channels are scanned, and the TIMER prescaler allows much lower sample
rates than the internal timer, which is limited to 16MHz/CC with CC in
80..2047.

NRF52_SAADC_CONTINUOUS is no longer tied to the internal timer and
works with either source.  Its EasyDMA buffers now hold
NRF52_SAADC_CONTINUOUS_BUFLEN whole scans rather than that many single
samples, so MAXCNT becomes chan_len * BUFLEN.  Samples are interleaved
scan by scan, so a channel map is built once at configure() time and
passed to the upper half with the batch; the upper half already accepts
a per-sample channel array.  A single-channel configuration produces
the same MAXCNT and the same delivery as before.

Because both features want a PPI channel, add a build-time check that
NRF52_SAADC_PPI_CHANNEL and NRF52_SAADC_CONTINUOUS_PPI_CH differ, and
constrain the latter under the SoftDevice controller like the former.

NRF52_SAADC_CHANNELS gains a default and range for the new mode, and
documents that the internal timer is restricted to one channel.

Assisted-by: Claude Code
Signed-off-by: raiden00pl <raiden00@railab.me>
2026-09-28 11:20:31 +02:00
Justin Hammond
2bd1334ec4 arch/risc-v/eic7700x: Describe the pads through procfs.
Implements the pinctrl get_pad method, so /proc/pinctrl and
PINCTRLC_GETPAD carry what this block is actually holding: each layout's
common fields with their validity bits, and the layout's own fields, the
RGMII and mode-select voltage bits and the oscillator tuning, as
key:value text.

Names every pad and every documented function select in one
PINCTRL_PADNAME() table, so func:2 on S_MODE reads as GPIO94 rather than
as a number.  The names are the manual's own; a pad's name describes its
default function, not its current one.  The table costs about 9 KiB and
is built only with the file that reads it; the name helpers return NULL
without it and the strings stay empty.

Assisted-by: Claude:claude-opus-5
Signed-off-by: Justin Hammond <justin@dynam.ac>
2026-09-28 16:19:01 +08:00
Justin Hammond
830eab5f81 arch/risc-v/eic7700x: Describe and configure the pads.
Every ball on this SoC is shared between several functions, and nothing
in this port could see which function a pad carried or change it.  A
driver that finds nothing cannot tell a dead block from a pad still
pointed somewhere else.

Registers the CLMM pad multiplexer with the pinctrl framework and defines
every pad and every function select the manual documents, across the
straps, JTAG, PCIe, HDMI, Ethernet, I2S, SPI, GPIO, USB, I2C, UART, fan
and MIPI CSI groups.  Writes nothing at start up: a pad only moves when a
driver asks.

eic7700x_pinctrl_count() reports how many pads currently differ from
their reset defaults, which after boot is the set the boot loader and the
drivers have configured; the board start up logs it.

Assisted-by: Claude:claude-opus-5
Signed-off-by: Justin Hammond <justin@dynam.ac>
2026-09-28 16:19:01 +08:00
Marco Casaroli
c9cd9db25f tools/nxflat: Add an Apache-licensed NXFLAT converter.
ldnxflat is the last piece of the NXFLAT toolchain that NuttX cannot carry.
It descends from elf2flt through four sets of copyright holders, so it is GPL
by that descent and not merely by its libbfd dependency.  This is a new
implementation, written from include/nxflat.h, from what binfmt/libnxflat does
with the container, and from the ELF specification.  The relocation arithmetic
is that of libs/libc/machine/arm/armv7-m/arch_elf.c, which the ELF loader runs
on the target for the same relocations, and which brings R_ARM_TARGET1 with
it.

NXFLAT is not an ARM format.  Its loader only adds a base to a 32-bit word, so
the segments, the GOT, the relocation records and the header are common to
every architecture.  An architecture supplies a table entry, an entry-point
convention and a relocation handler; an object for a machine with no entry is
refused by name.

The GOT is built here, because ld -r emits none: one entry per symbol that a
GOT-relative reference names, at the start of D-Space, each with a relocation
record of its own.  An entry may hold a function, which is what makes a
function pointer reached through the GOT work.

Two defects of the out-of-tree tool do not survive.  A GOT entry naming a .bss
object lost its section's address and pointed at the start of D-Space, the GOT
itself, so on lm3s6965-ek:qemu-nxflat the longjmp test panics with PC 0 and
the five tests after it never run.  The alignment gap before .bss went missing
from h_bssend as well, leaving D-Space short.

The tool is built and named like the rest of the toolchain.  Makefile.host
builds it, Unix.mk makes a configuration that sets CONFIG_NXFLAT depend on it
beside mknxflat, and LDNXFLAT points at the tool in the tree rather than one
on PATH.

All eight C modules of apps/examples/nxflat/tests convert and run to
completion under qemu-system-arm -M lm3s6965evb.

Assisted-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
2026-09-27 11:25:12 -03:00
Marco Casaroli
60d01d779f arch/arm: Reach an NXFLAT module's read-only data through the GOT.
A module's D-Space is separate from its I-Space, so its read-only data is not
at a fixed offset from its text.  GCC assumes that it is and loads a string
literal PC-relative, which reads I-Space at run time.  A module could
therefore carry no string and reach no static.

lm3s6965-ek has had -mno-pic-data-is-text-relative in its own Make.defs since
2021 (issue #3737), and the CMake build gives it to every PIC configuration,
so the flag moves to where it belonged and the board's copy goes.  That copy
also probed for GCC older than 4.9.4, which NuttX no longer supports.  Clang
has no such option, hence the guard.

Assisted-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
2026-09-27 11:25:12 -03:00
Royyan Zahir
f7f8107a0a arch/arm64/imx9: add an ELE-backed /dev/random driver.
The i.MX9 has a true random number generator behind the EdgeLock Enclave
and imx9_ele_get_random() to reach it, but nothing registers a character
device for it, so the entropy pool is never seeded from hardware. stm32h7,
nrf52, lpc54xx and rp23xx all provide one; imx9 does not.

imx9_ele.c was built only for CONFIG_IMX9_BOOTLOADER, putting the enclave
out of reach of the application core. It moves behind a new CONFIG_IMX9_ELE
that the bootloader selects, so existing configurations build as before.

A transfer that never lands is silent, so the buffer is prefilled with a
pattern and a block still holding it is refused, as is an all-zero block
and, by the FIPS 140-2 continuous test, a repeat of the one before.

Compiles for imx93-evk:nsh with CONFIG_IMX9_RNG=y.

Signed-off-by: Royyan Zahir <royzah@gmail.com>
2026-09-27 11:02:13 -03:00
zhanghongyu
53ac762e79 drivers/vhost: Optimize vhost-net performance and robustness
Suppress the peer notifications while a ring keeps delivering work, batch
the receive completions into one kick per burst and drop the redundant
txdone signal from the transmit path.  Validate the peer controlled frame
lengths, accept descriptor chains on both lanes, keep every ring access on
the upper half's work thread so the interrupt context callbacks stay lock
free, and prefer the MAC from the configuration space, falling back to the
Kconfig address or a random one.

Signed-off-by: zhanghongyu <zhanghongyu@xiaomi.com>
2026-09-27 18:41:30 +08:00
Marco Casaroli
1bc7cfeeb1 arch/xtensa: Provide POSIX fork() on the ESP32-S3.
up_addrenv_fork() duplicates an address environment into freshly allocated
pages mapped at the same virtual addresses.  The text, data and heap regions
of the source are walked one page at a time and copied into fresh pages hung
off the child's own directory, using the two kmap slots that
CONFIG_ARCH_KMAP_NPAGES reserves for exactly this.

xtensa_fork.c already took both paths:  a child that keeps the parent's stack
addresses needs no relocation, which is what a duplicated address environment
gives it.  Only the hook and the Kconfig default were missing.

fork() is offered on a kernel build, which is the only mode with per-process
address environments.

Verified on an ESP32-S3-WROOM-2 with esp32s3-devkit:kernel_oct.  ostest
reports "Parent and child had independent memory" and exits with status 0.

Assisted-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
2026-09-26 11:13:57 -03:00
Marco Casaroli
ce59fb6e71 xtensa/esp32s3: Reach a page pool page through a scratch mapping.
The page pool is carved out of the PSRAM that user processes run from, and
the external memory permissions are indexed by physical address, so a
permanent kernel window onto the pool is a window onto every process, which
no permission setting can close.

Stop mapping the pool.  The kernel reaches a pool page through a small
scratch region instead, mapped for one operation and invalidated afterwards.
esp32s3_pgmap() takes a slot, esp32s3_pgunmap() releases it, and
ARCH_KMAP_VBASE and ARCH_KMAP_NPAGES describe the region.  Two slots are
enough, because the deepest user is up_addrenv_fork(), which holds a source
and a destination page at once.

Assisted-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
2026-09-26 11:13:57 -03:00
Marco Casaroli
f14e807c11 xtensa/esp32s3: Wire the chip into the kernel build.
The common Xtensa BUILD_KERNEL support needs the chip to say what it can do
and where its memory goes.

The chip selects the address environment options it now implements, keeps the
kernel and user heaps apart, and the linker scripts separate kernel from user
text and data so the two worlds can be given different permissions.

kernel_oct configures a board for it, with the user-program layout and the
boot ROMFS a kernel build loads its programs from.  The ROMFS placeholder is
rebuilt with the image, the generated copy is ignored, and the programs are
given stack sizes and room for a fork() child.

Assisted-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
2026-09-26 11:13:57 -03:00
Marco Casaroli
54419e870d xtensa/esp32s3: Implement per-process address environments.
Give the ESP32-S3 the arch_addrenv_t machinery that BUILD_KERNEL needs:  a
per-process page directory built from the 64 KiB MMU pages of the chip, with
allocation, teardown, and the vaddr-to-paddr translation that the kernel uses
to reach a user buffer.

The MMU, PMS and WCL primitives are exposed as an arch API first, because the
address environment code and the protected user split both need them and
neither owns them.

Assisted-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
2026-09-26 11:13:57 -03:00
Marco Casaroli
54fcbe888b xtensa/esp32s3: add recoverable cache-attribute fault dispatcher (Unit B)
Route the precise cache-attribute permission faults -- Load/Store/InstrFetch
Prohibited (EXCCAUSE 28/29/20) -- from xtensa_user() to a new dispatcher,
esp32s3_pagefault_dispatch().  On a serviced fault the register frame is
returned so the exception vector's RFE re-executes the faulting instruction;
otherwise it declines to the existing panic path.  Gated by
CONFIG_ESP32S3_PAGEFAULT (default n, depends on BUILD_PROTECTED); the build
is unchanged when the option is off.

This is the recoverable-fault primitive the address-environment / demand-paging
work builds on.  Proven on the ESP32-S3-DevKitC WROOM-2:

- A precise LoadProhibited carries a tracking EXCVADDR (the exact faulting
  address), and RFE cleanly re-executes the faulted load on return -- verified
  with CONFIG_ESP32S3_PAGEFAULT_SELFTEST (the identical instruction restarts
  three times, then steps past, and the task resumes with the shell alive).
- ESP32-S3 PMS (World Controller) permission violations are NOT delivered as
  these precise causes; they raise the asynchronous DRAM0/IRAM0 PMS-monitor
  interrupt, so PMS is an isolation (kill) mechanism, not a restartable one.

No regression: esp32s3-devkit:knsh (WROOM-2) boots to nsh and ostest passes
with the option enabled.

Assisted-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
2026-09-26 11:13:57 -03:00
Jukka Laitinen
63208908ac arch/arm/imxrt: Allow serial console in uarts 9-12
iMXRT118x may have up to 12 uarts. Allow setting the console also on those.

Signed-off-by: Jukka Laitinen <jukka.laitinen@tii.ae>
2026-09-26 17:05:47 +08:00
Jukka Laitinen
c64d30dbbc arch/arm/imxrt: Clean up TRDC configuration
The TRDC (Trusted Resource Domain Controller) configuration should be completely
driven by the board configuration, and not hard-coded:

- Add tables for the current GPIO configuration and MDA configuration.
- Fix the GPIO configurations for M7; previously GPIO access from M7 was
  denied because of secure/nonsecure setting.

Signed-off-by: Jukka Laitinen <jukka.laitinen@tii.ae>
2026-09-26 17:05:34 +08:00
Jukka Laitinen
6ef704ee83 arch/arm/imxrt: Fix imxrt118x rgpio compiler warning
Move GPIO_PIN definition from imxrt118x_gpio.h to imxrt_rgpio.h to
remove redefinition warning.

Signed-off-by: Jukka Laitinen <jukka.laitinen@tii.ae>
2026-09-26 17:05:34 +08:00
jsanchez-2g
463d8a71d7 arch/arm/stm32h7: Dump FDCAN Rx/Tx FIFO status registers.
fdcan_dumpregs() printed the Rx FIFO 0 and Tx buffer configuration
registers (RXF0C, TXBC) but not their live status counterparts
(RXF0S, TXFQS), and did not print the Rx FIFO 1 configuration or
status registers (RXF1C, RXF1S) at all.

Add the missing RXF1C configuration line and the RXF0S, RXF1S, and
TXFQS status lines so every configured FIFO/buffer's fill-level
state is visible alongside its configuration, matching the existing
dump grouping.

Convert fdcan_dumpregs() from printf() to ninfo(), matching the
logging convention already used elsewhere in this file
(ninfo/nerr), per upstream review feedback.

Compile-tested: boards/arm/stm32h7/nucleo-h743zi2/configs/socketcan
with CONFIG_STM32_FDCAN_REGDEBUG=y, CONFIG_DEBUG_INFO=y.

Assisted-by: Claude:claude-sonnet-4.5
Signed-off-by: jsanchez-2g <jsanchez@2g-eng.com>
2026-09-26 09:59:13 +08:00
Marcio Ribeiro
25a3aaaa9d arch/risc-v/esp32c2: add ESP32-C2 chip support
Introduce RV32IMC chip architecture with HAL integration and Espressif
common Kconfig for the ESP8684 SoC, including XTAL, UART0 pin range,
and SPI flash clock options.

Assisted-by: Claude:claude-opus-5
Signed-off-by: Marcio Ribeiro <marcio.ribeiro@espressif.com>
2026-09-25 21:08:00 +08:00
Marco Casaroli
5513029711 arch/arm: Build a loadable module and a shared library as FDPIC too.
CONFIG_FDPIC teaches the ELF module path what an FDPIC object is, so an
application built as a module gets -mfdpic -fPIC and the
arm-uclinuxfdpiceabi linker.  The loadable module path, which apps builds
with DYNLIB = y and which apps/Library.mk uses for a shared library, was
left as it was: a -r partial link with the stock linker.  That leaves an
object with no dynamic section, so the loader has nothing to bind an import
to, and there is no way to build a library an FDPIC module can call.

Give that path the same treatment.  CMODULEFLAGS and CXXMODULEFLAGS gain the
FDPIC compiler flags, and LDMODULEFLAGS links a shared object rather than a
partial one.  The entry point is left to the caller, because a module is
entered at _start while a library is only ever called into.

CXXMODULEFLAGS is also defined for the first time.  apps/Library.mk compiles
every C++ source of a shared library with it and no architecture defined it,
so those sources were compiled with no architecture flags at all.

Assisted-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
2026-09-25 09:56:10 -03:00
Austin.Chen
5197329b67 arch/arm/stm32h5: add SDMMC1/SDMMC2 driver
Add the STM32H5 SDMMC1/SDMMC2 lower-half SDIO driver (interrupt-mode and
IDMA transfers, SD/SDIO card mode), following the same structure as the
existing STM32H7 SDMMC driver.

Three fixes were needed to get this actually building, selectable, and
correct:

- The driver checked CONFIG_STM32H5_SDMMC1/CONFIG_STM32H5_SDMMC_IDMA/
  CONFIG_STM32H5_SDMMC_XFRDEBUG, but the real Kconfig symbols selected by
  this chip are the shared CONFIG_STM32_SDMMC1/CONFIG_STM32_SDMMC_IDMA/
  CONFIG_STM32_SDMMC_XFRDEBUG (see arch/arm/src/common/stm32/Kconfig.sdio,
  Kconfig.periph). With the old names the driver silently compiled out.
  Renamed all guards in stm32_sdmmc.c to match. Also fixed a similar typo,
  STM32H5_SRAM3_SIZE -> STM32_SRAM3_SIZE, in the IDMA-reach check.

- arch/arm/src/common/stm32/Kconfig.sdio's STM32_SDMMC_IDMA and the
  SDMMC1/2 SDIO-mode/pull-up options depended on ARCH_CHIP_STM32H7 /
  STM32_COMMON_F7_H7 only. Extended STM32_SDMMC_IDMA to also allow
  ARCH_CHIP_STM32H5, and switched the SDIO-mode/pull-up options to
  STM32_COMMON_F7_H7_H5, matching the pattern already used for other
  STM32H5 peripherals (Ethernet, ADC, SPI, timers).

- stm32_sdmmc.c was only added to Make.defs, not to CMakeLists.txt, so
  the driver would silently be omitted from CMake builds. Added it to
  the same unconditional source list as stm32_exti_gpio.c.

Also ports a fix from a related STM32H7 SDMMC commit
(2cb7b7c03e): stm32_recvdma()'s aligned
IDMA receive path invalidated the destination buffer before the DMA but
never again after it completed, so a speculative cache prefetch into
that buffer between those two points could shadow the freshly-received
data with a stale line. Added the missing post-DMA invalidate, matching
the pattern already used elsewhere on this chip for other DMA-capable
peripherals (e.g. stm32_ethernet.c's RX path).

Needed for a custom STM32H5 board that uses SDMMC1 in SDIO mode with
IDMA to talk to an onboard WiFi module.

Co-authored-by: Liam Howatt <liamhowatt@geotab.com>
Signed-off-by: Marwan Madkour <marwanmadkour@geotab.com>
2026-09-25 18:30:40 +08:00
raiden00pl
425e77e44e arch/nrf52,nrf53,nrf91: fix nxstyle issues
arch/nrf52,nrf53,nrf91: fix nxstyle issues

Signed-off-by: raiden00pl <raiden00@railab.me>
2026-09-25 18:24:36 +08:00
raiden00pl
058da97e95 arm/nrf52,nrf53: fix SAADC channel limit register value
CHLIMIT was written with (limith < 16) | limith, which put the high
limit into the low field and a boolean into bit 0. Shift the high
limit to bits 16-31 and the low limit to bits 0-15.

Assisted-by: Claude Code
Signed-off-by: raiden00pl <raiden00@railab.me>
2026-09-25 18:24:36 +08:00
raiden00pl
574bbf618f arm/nrf52,nrf53,nrf91: fix SPI sndblock ops field
The non-exchange ops table initialized .sndlock, which does not exist
in struct spi_ops_s and fails to compile without CONFIG_SPI_EXCHANGE.

Assisted-by: Claude Code
Signed-off-by: raiden00pl <raiden00@railab.me>
2026-09-25 18:24:36 +08:00
raiden00pl
e5e06d6bde arm/nrf52,nrf53,nrf91: fix PWM driver bugs
- SEQSTARTED0 and STOPPED events were not cleared before waiting for
  them, so the second start or stop returned immediately
- PWM_DECODER_MODE_* shifted 8 instead of shifting to bit 8
- PWM_PSEL_PIN_MASK and PWM_PSEL_PORT_MASK referenced TWI shift names
- PWM_PSEL_CONNECTED described the disconnected state

Assisted-by: Claude Code
Signed-off-by: raiden00pl <raiden00@railab.me>
2026-09-25 18:24:36 +08:00
raiden00pl
c8f699a4e3 arm/nrf52,nrf53,nrf91: fix GPIOTE driver bugs
- set_port_event checked the wrong port when deciding whether the
  PORT interrupt can be disabled
- set_event could pick a free channel instead of the one already
  assigned to the pin
- LATCH registers were cleared by writing zeros
- header declared nrfxx_gpio_set_task for a function defined as
  nrfxx_gpiote_set_task

Assisted-by: Claude Code
Signed-off-by: raiden00pl <raiden00@railab.me>
2026-09-25 18:24:36 +08:00
raiden00pl
f86b05351f arm/nrf52,nrf53,nrf91: fix RTC driver bugs
- setcc/getcc accepted channel index equal to the channel count
- init never marked the instance as in use
- NRFxx_RTC_GETCC called setcc instead of getcc

Assisted-by: Claude Code
Signed-off-by: raiden00pl <raiden00@railab.me>
2026-09-25 18:24:36 +08:00
raiden00pl
d490c80df2 arm/nrf52,nrf53,nrf91: fix TIMER driver bugs
- setcc/getcc accepted channel index equal to the channel count
- init never marked the instance as in use
- TIM_PRESCALER_MASK used the maximum value as the mask

Assisted-by: Claude Code
Signed-off-by: raiden00pl <raiden00@railab.me>
2026-09-25 18:24:36 +08:00