Commit graph

63465 commits

Author SHA1 Message Date
Jukka Laitinen
4682ad992f boards/arm/imxrt/imxrt1180-evk: Fix FCB struct layout for flexspi_nor_config_s
The flexspi_nor_config_s was missing four fields, resulting the fields after the
missing ones being read from wrong positions.

Align the struct properly according to the reference manual.

Signed-off-by: Jukka Laitinen <jukka.laitinen@tii.ae>
2026-09-23 11:24:44 +08:00
Jukka Laitinen
bf840595f7 arch/arm/imxrt: Fix EDMA_ALIGN for Cortex-M33 in imxrt_edma_ver2.c
Small fix to compile imxrt_edma_ver2.c correctly also for M33.

Signed-off-by: Jukka Laitinen <jukka.laitinen@tii.ae>
2026-09-23 11:24:44 +08:00
Jukka Laitinen
e0f2c881bf arch/arm/imxrt: Add missing imxrt118x IRQ 238/239 definitions
On imxrt1180 there are 240 IRQs. Add the missiong ones:

  IRQ 238  ECAT   EtherCAT Reset out (ECAT_RESET_OUT pin-mux signal)
  IRQ 239  EdgeLock  EdgeLock interrupt

Signed-off-by: Jukka Laitinen <jukka.laitinen@tii.ae>
2026-09-23 11:24:44 +08:00
Alan Carvalho de Assis
6d04a124c2 wireless/bluetooth: Fix bad aligment
This PR fixes the bad aligment reported by nxstyle.

Signed-off-by: Alan C. Assis <acassis@gmail.com>
2026-09-22 10:07:09 -03:00
Alan Carvalho de Assis
9d12f6ccc6 wireless/bluetooth: Validate the L2CAP header on the first ACL fragment.
bt_conn_receive() read the 4-octet L2CAP header out of the first fragment
of a PDU without checking that 4 octets had been received, and then
computed the outstanding length by subtracting the fragment length from
the declared PDU length.

Two problems follow.  A fragment shorter than the header was parsed from
whatever happened to follow it in the buffer.  And a fragment carrying
more data than the PDU it declares made the subtraction wrap, because
conn->rx_len is 16 bits: the connection was then left expecting up to
65535 further octets, holding the partial PDU and accumulating later
fragments against an expectation that could never be satisfied.

Check that the fragment is long enough to hold a header before reading
it, and that it does not exceed the PDU it declares before computing what
remains.  Drop the fragment and reset the reassembly state otherwise.

Ref: Core v6.0, Vol 3, Part A, 3.1 (B-frame format)
Ref: Core v6.0, Vol 4, Part E, 5.4.2 (HCI ACL Data packets)
Testing: builds for sim:bluetooth with Make; every commit in this series
verified to build individually.  Not yet exercised at runtime - the
scriptable controller adds the truncated and oversized fragment cases
separately.

Signed-off-by: Alan C. Assis <acassis@gmail.com>
Assisted-by: Claude Code Opus 5
2026-09-22 10:07:09 -03:00
Royyan Zahir
44a3873222 arch/arm/imxrt: add a CAAM-backed /dev/random driver
The part has a hardware random number generator and nothing registers
it, so up_randompool_initialize() is never seeded from hardware. There
is no CAAM, TRNG or RNG driver anywhere in arch/arm/src/imxrt, and the
RT117x headers describe the block only as an address-map comment.

imxrt_caam.c brings up job ring zero and instantiates the RNG state
handle when the boot ROM has not, retrying with a longer entropy sample
until the self test passes. imxrt_rng.c registers /dev/random and
/dev/urandom on top, and is the i.MX9 driver's sibling: same health
checks, same FIPS 140-2 continuous test, same refusal to return a short
read and call it entropy.

The instantiation descriptor posts no job ring completion, so the state
handle is what reports it, and the ring is taken back to a known state
to latch it. Job ring zero is started and the cache and watchdog bits
set first: RDSTA and JRSTART both read zero out of reset on this part.

Scoped to RT117x, which is the family that carries CAAM.

Built for imxrt1170-evk:nsh with the driver on, and for imxrt1060-evk:nsh
to confirm the shared clock-gate header still builds without it.

Run on an FMU-v6X-RT (i.MX RT1176): /dev/random and /dev/urandom both
return, the first read after a cold boot included, and five consecutive
reads are distinct.

Signed-off-by: Royyan Zahir <royzah@gmail.com>
2026-09-22 09:37:17 -03:00
raiden00pl
6255f2a474 stm32l5: Fix nxstyle errors in drivers and board LEDs
Correct switch and declaration indentation, separate declarations from code,
and wrap a long comment in the SPI driver. Fix the timer driver and both
STM32L5 board LED implementations checked by the commonization PR.

These are formatting changes only.

Signed-off-by: raiden00pl <raiden00@railab.me>
2026-09-22 09:21:35 -03:00
raiden00pl
93a40354c0 arch/arm/stm32l5: Use common Cortex-M33 USART support
Select STM32_HAVE_IP_USART_M33_V3 and drop the family serial and
low-level console sources in favor of the common Cortex-M33 v3
implementation. Provide the USART clock and RCC gate definitions in
stm32_rcc_m33.h.

Add the LPUART BRR computation (256 * fCK / baud) to the common serial
and low-level console code, taken from the STM32L5 driver.

Signed-off-by: raiden00pl <raiden00@railab.me>
Assisted-by: Claude Code
2026-09-22 09:21:35 -03:00
raiden00pl
6e7ea6019e arch/arm/stm32l5: Use common Cortex-M33 core support
Enable STM32_COMMON_M33 for STM32L5 and drop the family reset, NVIC,
SysTick, idle, and heap sources in favor of the common Cortex-M33 v1
implementation.

Rename the family RCC header to stm32_rcc_m33.h for the common RCC
dispatch and define STM32_PRIMARY_SRAM_SIZE for the common heap
allocator.

Signed-off-by: raiden00pl <raiden00@railab.me>
Assisted-by: Claude Code
2026-09-22 09:21:35 -03:00
raiden00pl
cc8c7d0769 arch/arm/stm32l5: Use common Cortex-M33 GPIO and EXTI drivers
Select STM32_HAVE_IP_GPIO_M33_V1 and STM32_HAVE_IP_EXTI_M33_V1 and
drop the family GPIO and EXTI sources and headers in favor of the
common Cortex-M33 v1 implementation.

Define both EXTI register banks and retain the named bit definitions.
Use shared line and selector helpers without per-line conditionals.
Clear each GPIO selector with the same byte mask, as the H5 driver does.
Cover both 32-bit banks and H5 line inventories for later migration.

The common EXTI driver also routes the selected port through EXTICR,
which the family driver never programmed, so GPIO interrupts now work
on ports other than GPIOA.

Signed-off-by: raiden00pl <raiden00@railab.me>
Assisted-by: Claude Code
2026-09-22 09:21:35 -03:00
Felipe Moura
e4cc7b7258 boards/esp32s3: the LSM6DS3TR-C INT1 is a level, not an edge
The FIFO watermark flag is a level: it stays high until the worker
actually drains the FIFO below the threshold.  Configuring INT1 as RISING
made that a race the driver could lose permanently.

lsm6ds3trc_interrupt() disables its IRQ on entry and re-enables it after
the worker has run.  With an edge trigger, if the line is still high when
the IRQ is re-enabled -- which is precisely what happens whenever a drain
does not take the FIFO below the watermark -- there is no new low-to-high
transition left to detect, and the line goes mute forever.  Observed as a
board that serviced exactly one watermark after boot and then never
again, reproducible 2 out of 2 reflashes.

ONHIGH matches the physical meaning of the pin and is immune to it: a
level trigger re-asserts on its own for as long as the condition holds,
and the disable/enable pairing around servicing is what stops that from
live-locking.

Validated with more than 900 consecutive drains (~100 min) including real
sleep -> GPIO-wake -> resume transitions, the exact case that used to
wedge.

Signed-off-by: Felipe Moura <moura.fmo@gmail.com>
Assisted-by: Claude:claude-opus-5
2026-09-22 09:21:08 -03:00
dechao_gong
b120999159 Documentation/platforms/arm/rtl8730e: update board doc and add gpio config
- Switch board image directive from .. image:: to .. figure:: with
  :scale: 50 % and a caption line, matching the format used by other
  Ameba board docs (rtl8721dx, rtl8721f).
- Move rtl8730e_evb.png from img/ subdirectory to the same level as
  index.rst, consistent with other boards.
- Add gpio configuration section describing the three registered pins
  (PB19 output /dev/gpio0, PB20 input /dev/gpio1, PB11 interrupt
  /dev/gpio2), usage examples and pin encoding notes.
- Add GPIO to the "Supported in this NuttX port" feature list.

Signed-off-by: dechao_gong <dechao_gong@realsil.com.cn>
Assisted-by: Claude <noreply@anthropic.com>
2026-09-22 09:18:16 -03:00
dechao_gong
7e34d1c6b4 arch/arm/ameba: add GPIO driver for RTL8730E (AmebaSmart CA32)
Wire the shared ameba_gpio driver to the RTL8730E CA32 core.

The CA32 replaces the vendor CA32 OS as BL33; the SDK startup that
normally initialises GPIO_PORTx[] never runs under NuttX.  The three
GPIO port base addresses are patched at runtime inside
rtl8730e_gpio_initialize() before any ROM GPIO function is called.
GPIO_INTStatusGet and GPIO_INTStatusClearEdge are absent from the
RTL8730E ROM and are provided as static inline helpers in the new
ameba_gpio_chip.h.

Key changes:
- ameba_gpio_chip.h (new): chip parameters, split AMEBA_APBPERIPH_GPIO
  / AMEBA_APBPERIPH_GPIO_CLK bits, inline INTStatus helpers
- ameba_gpio.c: add AMEBA_APBPERIPH_GPIO_CLK fallback macro so chips
  with separate periph/clock enable bits work without driver changes
- Make.defs: enable ameba_gpio.c + rtl8730e_flash_stubs.c + lib_rom.a
  under CONFIG_AMEBA_GPIO; consolidate flash_stubs into GPIO||FLASH_FS
- ameba_board.mk: remove duplicate lib_rom.a (Make.defs is authoritative)
- rtl8730e_flash_stubs.c: make _strcmp weak; delegate Pinmux_Config to
  lib_rom.a's _Pinmux_Config so GPIO pad mux is configured correctly
- Kconfig: source common/ameba/Kconfig to expose CONFIG_AMEBA_GPIO
- dramboot.ld: include .sramdram.only.data in .data so GPIO_PORTx[] is
  copied to RAM by the normal arm_data_initialize() path
- scripts/Make.defs: extend --no-warn-mismatch to GPIO and WiFi configs
- rtl8730e_gpio.c (new): pin table (PB19 output /dev/gpio0, PB20 input
  /dev/gpio1, PB11 falling-edge interrupt /dev/gpio2) + GPIO_PORTx patch
- configs/gpio/ (new): defconfig for GPIO example verification
- nxstyle.c: add _Pinmux_ to mixed-case whitelist (ROM symbol)

Hardware verified on RTL8730E CA32:
- PB19 output write 0/1, readback matches
- PB20 input reads PB19-driven level
- PB11 falling-edge interrupt triggers correctly

Signed-off-by: dechao_gong <dechao_gong@realsil.com.cn>
Assisted-by: Claude <noreply@anthropic.com>
2026-09-22 09:18:16 -03:00
Daniel P. Carvalho
1f9793b7b5 arch/arm/stm32h7: fix the period of the PPS output.
The interval and the width of the pulse train of the PPS output were
programmed as the number of increments of the system time minus one,
but the MAC takes them as they are. Each period was one increment (10 ns
with HCLK at 200 MHz) shorter than a second, so the pulses came 10 ns
early each second, about 36 us in an hour, and the output drifted away
from the system time.

Program the interval and the width without subtracting one.

On a run of 8.2 hours against a grandmaster clock the pulse moved 0.29 ms
ahead of the system time, which is 10 ns per second, while the system time
stayed within 1 us of the grandmaster. With the change, a run of 11 hours
showed no drift of the pulse against the system time, within 3 us per hour
on samples of 1 ms of resolution.

Signed-off-by: Daniel P. Carvalho <danieloak@gmail.com>
Assisted-by: Claude:claude-sonnet-5
2026-09-22 09:17:40 -03:00
Felipe Moura
89b8c5fc7f espressif: stop double-counting light sleep in the system clock
esp_pmstandby() fed up_step_idletime() the sleep duration it *asked* for
(time_in_us) rather than the one it actually got (rtc_diff_us), and did so
unconditionally.  Both halves are wrong.

esp_pm_light_sleep_start() already stalls and restores the systimer
itself, but only where SOC_SLEEP_SYSTIMER_STALL_WORKAROUND is defined --
esp32c3 and esp32p4.  On every other SoC, esp32s3 included, the systimer
keeps counting straight through light sleep, so the time is already in
the clock and stepping it again adds it twice.

Measured on an esp32s3-xiao: over 54 min with 1919 light sleeps totalling
454.7 s, the monotonic clock ran 443.2 s fast -- 0.97 of the time slept,
i.e. counted exactly twice, leaving the clock 13.8% fast.  Anything that
reconstructs wall time from CLOCK_MONOTONIC inherits that error; for this
collar it corrupted every IMU sample timestamp.

Invisible until light sleep started happening for real, because a board
that never sleeps never steps the clock.

Note for upstream: the risc-v copy here only switches to the measured
duration and does not gate on SOC_SLEEP_SYSTIMER_STALL_WORKAROUND.  The
two should be reconciled before this is proposed -- it is kept as-is so
the asymmetry is visible rather than silently decided.

Signed-off-by: Felipe Moura <moura.fmo@gmail.com>
Assisted-by: Claude:claude-opus-5
2026-09-22 19:30:21 +08:00
Felipe Moura
c4c9eab46f sensors/lsm6ds3trc: recover from a failed FIFO drain instead of wedging
A single failed burst read of FIFO_DATA_OUT was enough to take the board
down.

The drain path gave up on error, unlocked and returned, leaving the FIFO
above its watermark.  INT1 is level triggered on exactly that condition,
so the line stayed asserted, the worker was re-entered the instant the
IRQ was re-enabled, failed again, and that hot loop starved every other
task until the board wedged -- console cut off mid-line, no crash dump.
Observed killing a board within seconds of the first failure.

Fix: if the read fails, empty the FIFO through Bypass and restore the
previous mode bits, which deasserts INT1.  That costs one batch of
samples and acquisition resumes on the next watermark.  Restoring the
saved bits rather than recomputing them preserves the FIFO-only ODR set
by fifo_configure().

Losing a batch is a far better outcome than losing the board.

The underlying cause of these timeouts on esp32s3 was light sleep cutting
the transfer in half; that is fixed separately in esp32s3_i2c.c.  This
commit is the driver recovering gracefully from a failed read whatever
its cause, which it was not before.

Assisted-by: Claude:claude-opus-5
Signed-off-by: Felipe Moura <moura.fmo@gmail.com>
2026-09-22 13:50:01 +08:00
Felipe Moura
08ee713b4d sensors/lsm6ds3trc: move the FIFO drain buffer off the stack
The worker declared its drain buffer as int16_t raw[FIFO_MAX_WORDS], and
FIFO_MAX_WORDS scales with CONFIG_SENSORS_LSM6DS3TRC_FIFO_WATERMARK.

At the Kconfig default watermark of 8 that is 192 bytes and nobody ever
noticed.  At the watermark this collar uses, 250, it is 6000 bytes inside
an 8192-byte HPWORK stack -- 73% of it, before the call frame and the
whole I2C stack underneath.  Any board raising the watermark walks into a
stack overflow in a shared work queue, which is about the worst place to
find one.

Allocated once at registration so the drain path stays allocation-free,
and the driver fails registration cleanly if it cannot get the memory.

Assisted-by: Claude:claude-opus-5
Signed-off-by: Felipe Moura <moura.fmo@gmail.com>
2026-09-22 13:50:01 +08:00
Felipe Moura
159ef8105b sensors/lsm6ds3trc: reset the sensor before arming its interrupt
lsm6ds3trc_register() attached the INT1 handler without ever putting the
sensor into a known state, which made every reboot a coin toss.

The LSM6DS3TR-C has its own supply and its own reset.  An MCU reset --
watchdog, RTS pin, esptool, a plain "reboot" -- does not reset it, so it
comes back still holding whatever the previous session configured: for
this driver, INT1_CTRL.INT1_FTH still set and a FIFO still over its
watermark, i.e. INT1 already asserted at registration time.

With the (correct) ONHIGH level trigger, arming an already-active line
storms immediately.  The board then wedges during bring-up with no
console output and no crash dump -- it looked like a boot that stopped
right after Wi-Fi init and never reached NSH.  That symptom cost a long
detour: it was blamed in turn on a stuck I2C bus, on corrupted NVS/Wi-Fi
calibration, and finally on a failing USB-serial adapter, because the one
thing that reliably cleared it was unplugging the board -- which is
simply the only way to power-cycle the *sensor*.

SW_RESET (CTRL3_C bit 0) clears INT1_CTRL and FIFO_CTRL back to 0, which
deasserts INT1.  It self-clears in ~50 us; poll for it rather than
assume, and retry the write a few times, since the bus has been seen to
return -EIO on the very first transaction after a cold boot.

Carry on if the reset never takes.  An unreset sensor risks the storm
this exists to prevent, but refusing to register leaves the application
with no /dev/uorb/sensor_accel0 at all, which is fatal to it -- a single
-EIO here took the whole collar down once.  Losing the sensor to guard
against a maybe-storm is the wrong trade.

Assisted-by: Claude:claude-opus-5
Signed-off-by: Felipe Moura <moura.fmo@gmail.com>
2026-09-22 13:50:01 +08:00
Felipe Moura
3d267aab2a espressif/esp_irq.c: fix up_disable_irq()/up_enable_irq() for GPIO IRQs
esp_gpio_irq() registers per-pin GPIO interrupts through
gpio_isr_handler_add(), never through esp_setup_irq(), so
esp_get_handle() never finds them and up_disable_irq()/up_enable_irq()
silently no-op for any GPIO-derived irq number. Fall back to
esp_gpioirqdisable()/esp_gpioirqenable() (translating irq back to a
pin via ESP_IRQ2PIN()) when the normal interrupt-matrix lookup misses.

This surfaced through drivers/sensors/lsm6ds3trc_uorb.c: its ISR
schedules a worker to drain the sensor's FIFO over I2C and disables
its own IRQ until the worker re-enables it, so a level-triggered
source (e.g. a PM GPIO wake source left in level mode) doesn't
refire continuously and starve every task, HPWORK included, before
the worker ever gets to run. That disable/enable only works now that
up_disable_irq()/up_enable_irq() actually do something for GPIO irqs.

Signed-off-by: Felipe Moura <moura.fmo@gmail.com>
Assisted-by: Claude:claude-sonnet-5
2026-09-22 13:50:01 +08:00
David Vidrie Leon
074c8e3034 arch/arm/stm32h5: add missing I2C2/I2C4 pin remap options
Add 8 missing AF4 I2C2/I2C4 pin remap defines to
stm32h56xxx_pinmap.h, per ST's datasheet. Needed by boards that wire
I2C2/I2C4 to these pins; without them such configs fail to compile.

Reduced from a larger internal patch; the stm32_i2c.c part of that
patch is already upstream, so only this pinmap gap remained.

Co-authored-by: David Vidrie Leon <davidvidrie@geotab.com>
Signed-off-by: Marwan Madkour <marwanmadkour@geotab.com>
2026-09-22 13:32:10 +08:00
Felipe Moura
66831010e5 esp32s3/esp32s3_i2c.c: hold off light sleep for the duration of an I2C transfer
Light sleep gates the APB clock the I2C peripheral runs on.  A transfer
in flight stops mid-message and never raises its completion interrupt, so
the caller blocks in i2c_sem_waitdone() until ESP32S3_I2CTIMEOTICKS
expires and gets -ETIMEDOUT for a bus that was working perfectly.

The caller is what causes it.  Blocking in i2c_sem_waitdone() is exactly
what makes the idle task runnable, and the idle task is what decides to
sleep -- so the longer the transfer, the likelier it is to be cut in half
by its own wait.  Nothing about this is driver-specific.

Seen on an esp32s3-xiao reading an LSM6DS3TR-C FIFO: 6000 bytes in one
transaction, some 135 ms of bus time at 400 kHz, failing with -110 over
and over.  A WHO_AM_I probe and the FIFO status read, both short, never
failed once in the same runs -- only the long burst did.

The consequences went well past one failed read.  With the FIFO left
undrained the sensor's level-triggered INT1 stayed asserted, the worker
was re-entered the moment the IRQ was re-enabled, and that hot loop
starved every other task until the board wedged with no console output
and no crash dump.

pm_stay(PM_IDLE_DOMAIN, PM_IDLE) is the lightest lock that suffices:
greedy_governor_checkstate() walks up from PM_NORMAL and stops at the
first state holding a wakelock, so a stay at PM_IDLE keeps the domain out
of PM_STANDBY and PM_SLEEP while still allowing the plain WFI idle.
There is no early return between the stay and the relax.

Validated over 3 h 45 of continuous acquisition across two sessions:
wakes and drains stayed 1:1 (302/302, then 375/375), zero I2C failures of
any kind, and light sleep itself unaffected -- 11.8% of wall time asleep
in both, median sleep 2.08 s.

Signed-off-by: Felipe Moura <moura.fmo@gmail.com>
Assisted-by: Claude:claude-opus-5
2026-09-22 13:31:30 +08:00
yushuailong
166f17746c libc/elf: Always free the module symbol table on removal.
libelf_uninit() only called libelf_freesymtab() when the module had an
uninitializer.  But the exported symbol table is built by
libelf_insertsymtab() for every loaded module, and nothing in the tree
sets modinfo.uninitializer anymore:  modules have registered their
teardown through .fini_array since a9cb28cd23.  The condition is
therefore always false and every rmmod()/dlclose() leaks the exports
array together with the strdup-ed symbol names.

Call libelf_freesymtab() unconditionally, and clear the exports
pointers next to it instead of under a vestigial procfs guard that
dates back to the removed module initializer field.

Assisted-by: OpenAI Codex
Signed-off-by: yushuailong <yyyusl@qq.com>
2026-09-22 13:29:57 +08:00
yushuailong
a9683532b5 libc/elf: Free the registry entry when removing a module.
libelf_remove() takes the module out of the registry but never frees
the registry entry, so every successful rmmod()/dlclose() leaks
sizeof(struct module_s), the name included.  The lib_free() call was
dropped by e9550783d3 when the removal path was reworked.

Free the entry after the registry lock is released.

Assisted-by: OpenAI Codex
Signed-off-by: yushuailong <yyyusl@qq.com>
2026-09-22 13:29:57 +08:00
Felipe Moura
7c02367483 esp32s3/esp32s3_idle.c: report light-sleep time to the PM statistics
/proc/pm/state0 reported a flat 0 s in its SLEEP column on a board that
was demonstrably light-sleeping, because this port never told the PM core
it had slept.

pm_stats() (drivers/power/pm/pm_changestate.c) splits the time since the
last transition into dom->wake[state] or dom->sleep[state] depending on
whether the state it is handed is PM_RESTORE.  up_idlepm() called
esp_pmstandby() and carried straight on, so every second -- including the
ones spent in light sleep -- was billed to wake[].  The statistics
CONFIG_PM_PROCFS advertises were simply never true here.

Read from an esp32s3-xiao that had just spent 89 s in PM_STANDBY:

  DOMAIN0                   WAKE           SLEEP          TOTAL
  standby                  89s  83%        0s   0%       89s  83%

Only PM_STANDBY needs this.  PM_SLEEP is deep sleep and does not return
at all -- the chip resets -- so there is nothing to attribute on its way
back.

pm_changestate(domain, PM_RESTORE) is the documented way to say this: it
skips the driver prepare/veto phase, records the statistic, notifies
drivers of the restore, and deliberately does not overwrite the domain's
state, so the domain stays in PM_STANDBY as it should.

Signed-off-by: Felipe Moura <moura.fmo@gmail.com>
Assisted-by: Claude:claude-opus-5
2026-09-22 13:29:13 +08:00
Felipe Moura
d31609d8dd esp32s3/esp32s3_idle.c: unwedge the PM state machine after the first wakeup
up_idlepm() put the domain back in PM_NORMAL with pm_changestate() but
left its local oldstate holding whatever it was before sleeping, usually
PM_STANDBY.  The pm_checkstate() below then returned PM_STANDBY again,
the "newstate != oldstate" test compared PM_STANDBY against a stale
PM_STANDBY, and the whole block was skipped -- including the
esp_pmstandby() call that is the only thing in here that ever sleeps.

So after the very first wakeup the board reported PM_NORMAL essentially
forever, and light-slept only when something else happened to perturb
oldstate, such as an application taking and releasing a PM_IDLE wakelock
around a transmission window.

Measured on the esp32s3-xiao collar before this fix: 4.1 s of actual
light sleep in 2 h of near-total idleness, a 1780:1 awake-to-asleep
ratio.  After it: ~13.5% of wall time asleep, thousands of sleeps, no
storms.

The dead "newstate = PM_NORMAL" assignment that used to sit here was
presumably meant to be this; it is overwritten by pm_checkstate() a few
lines below and never had any effect.

Note that fixing this is what exposed two further bugs that had been
dormant behind a board that never slept: the systimer double-count in
esp_pmstandby(), and I2C transfers being cut in half by sleep.  Both are
fixed in their own commits.

Signed-off-by: Felipe Moura <moura.fmo@gmail.com>
Assisted-by: Claude:claude-opus-5
2026-09-22 13:29:13 +08:00
yushuailong
9c84989322 sched/module: Increase /proc/modules line buffer.
Increase MOD_LINELEN from 64 to 256 so complete /proc/modules lines fit the formatting buffer on 64-bit targets.

Assisted-by: OpenAI Codex
Signed-off-by: yushuailong <yyyusl@qq.com>
2026-09-22 13:27:42 +08:00
yushuailong
3ff1a5d203 sched/irq: Fix nxstyle declaration spacing.
Add the required blank line between the intcount declaration and the
following statement.

Assisted-by: OpenAI Codex
Signed-off-by: yushuailong <yyyusl@qq.com>
2026-09-22 13:27:42 +08:00
yushuailong
0c3b431f1e sched/irq: Fix a line buffer overread in /proc/irqs.
irq_callback() passed snprintf()'s would-have-written length to
procfs_memcpy(). If an IRQ line exceeded IRQ_LINELEN, the copy could read
beyond the formatting buffer.

Use procfs_snprintf() so the copy is limited to the bytes actually written.

Assisted-by: OpenAI Codex
Signed-off-by: yushuailong <yyyusl@qq.com>
2026-09-22 13:27:42 +08:00
yushuailong
b8f4213b60 sched/module: Fix a line buffer overread in /proc/modules.
modprocfs_callback() formatted each line into line[64] with snprintf()
and passed snprintf()'s return value, the length the line would have
had, to procfs_memcpy() as the source length.  A module name longer
than a few characters therefore made the copy read past the end of
the line buffer and hand kernel heap memory to the reader, and grew
totalsize by the difference.

Use procfs_snprintf(), which returns the length actually written, as
the other procfs entries already do.

Assisted-by: OpenAI Codex
Signed-off-by: yushuailong <yyyusl@qq.com>
2026-09-22 13:27:42 +08:00
Abhishek Mishra
a31f7b7988 Documentation/math: explain that KissFFT is a small FFT library
Follow-up to apache/nuttx#20194. The KissFFT page only described how
NuttX vendors the package. State that it is a small open-source FFT
implementation used in many embedded projects.

Signed-off-by: Abhishek Mishra <mishra.abhishek2808@gmail.com>
2026-09-22 00:11:08 +08:00
Daniel P. Carvalho
267408861c arch/arm/stm32h7: timestamp the transmitted frames in hardware.
Support STM32_ETH_TIMESTAMP_TX on the STM32H7, as the legacy STM32 do,
with the timestamp returned through SO_TIMESTAMPING.

When a packet socket asks for the transmit timestamp of a frame, keep a
copy of the frame and ask the MAC to timestamp it in the descriptor. When
the transmission is done, take the timestamp from the descriptor and give
the copy back to the network stack with it, that delivers it to the error
queue of the socket. The MAC writes the timestamp over the address of the
buffer in the descriptor, so the driver keeps the buffer of these
descriptors. The copies that still wait for their timestamp are released
when the interface goes down.

With a PTP daemon using the peer-to-peer delay mechanism against a
grandmaster clock, the path delay measured was between 9.0 and 9.1 us.

Signed-off-by: Daniel P. Carvalho <danieloak@gmail.com>
Assisted-by: Claude:claude-sonnet-5
2026-09-21 21:45:01 +08:00
Ulaş Sertan Kemeç
4ed4442e2f Documentation/am67: Document the netnsh configuration on t3-gem-o1.
Record the vhost-net link in the board's Peripheral Support list and
describe the netnsh configuration alongside nsh, including how to bring
the interface up on both sides.

Assisted-by: Claude Code:claude-opus-5
Signed-off-by: Ulaş Sertan Kemeç <sertan.usk@gmail.com>
2026-09-21 10:40:13 -03:00
Ulaş Sertan Kemeç
bcd811e959 boards/arm/am67/t3-gem-o1: Add netnsh configuration.
nsh plus networking over the rptun/virtio-net link to the A53: enables
DRIVERS_VHOST_NET with the buffer sizing the link needs (IOB pool and chains,
NET_LL_GUARDSIZE covering the ethernet and virtio-net headers) and ICMP
sockets for ping.  Also gives CI an in-tree configuration that compiles the
vhost-net driver.

Verified on t3-gem-o1: ifup, then ping from the peer with 0% loss.

Assisted-by: Claude Code:claude-fable-5
Signed-off-by: Ulaş Sertan Kemeç <sertan.usk@gmail.com>
2026-09-21 10:40:13 -03:00
Ulaş Sertan Kemeç
fa935ecae1 drivers/vhost: Add vhost-net, a device-role virtio network driver.
Implements the device end of virtio-net, so a peer running the stock
virtio-net driver sees this side as a network card, and registers a netdev
lowerhalf.

Ring layout follows the peer's numbering: vq[0] is its RX queue, which we fill
to transmit, and vq[1] its TX queue, which we harvest.  No features are
negotiated, so every frame carries the zeroed legacy virtio_net_hdr.

Peer buffers are reached by raw 64-bit address through an arch-provided
translation window -- the AM67 RAT, identity mapping elsewhere -- splitting
copies that straddle it.

Also gives DRIVERS_VHOST a prompt; it was promptless and so unselectable
without a driver forcing it.

Verified on t3-gem-o1 against an unmodified Linux virtio_net: eth0 registers,
ifup brings it to RUNNING, and the peer pings it 5/5 at 0.27 ms and 60/60 with
0% loss.

Assisted-by: Claude Code:claude-fable-5
Signed-off-by: Ulaş Sertan Kemeç <sertan.usk@gmail.com>
2026-09-21 10:40:13 -03:00
Ulaş Sertan Kemeç
c77c981850 drivers/vhost: Add vhost_get_vq_buffers_pa().
vhost_get_vq_buffers() converts descriptor addresses through the shared-memory
I/O region, which truncates silently when the CPU cannot address all of the
peer's memory -- a 32-bit remote core against a 64-bit host, where
metal_phys_addr_t is 32-bit and Linux posts buffers above 4 GB.

Returns the raw 64-bit address and length instead, so class drivers can
translate through platform window hardware.  Completion is unchanged.

Assisted-by: Claude Code:claude-fable-5
Signed-off-by: Ulaş Sertan Kemeç <sertan.usk@gmail.com>
2026-09-21 10:40:13 -03:00
Jorge Guzman
ceace2e05d boards/linum-stm32h753bi: Add zbus board configuration
Adopt the zbus message bus on the linum-stm32h753bi (first adopter
board):

- scripts/flash.ld: include the iterable sections common fragments
  (2 lines: common-rom.ld inside .text, common-ram.ld inside .data).
- configs/zbus/defconfig: board configuration enabling zbus with all
  observer types, the zbus example and its cmocka test suite
  (./tools/configure.sh linum-stm32h753bi:zbus).
- Board documentation: describe the new configuration.

Validated on hardware: the 16-test cmocka suite passes twice in the
same boot and the zbus example produces the expected output.

Assisted-by: Claude Code
Signed-off-by: Jorge Guzman <jorge.gzm@gmail.com>
2026-09-21 08:40:14 -03:00
Jorge Guzman
bbfb229e1f zbus: Add linker support and documentation for the zbus port
NuttX-side support for the zbus message bus port (apps/system/zbus in
nuttx-apps), built on the link-time iterable sections infrastructure
added in a companion PR:

- include/nuttx/linker/common-rom.ld and common-insert.ld: register the
  zbus channel, observer and channel observation iterable sections
  (ITERABLE_SECTION blocks guarded by CONFIG_ZBUS, no-op otherwise) for
  the include and the zero-touch INSERT modes respectively;
  common-ram.ld: note that zbus needs no RAM sections.
- Documentation/applications/system/zbus: Sphinx documentation for the
  zbus application, with the upstream Zephyr diagrams (Apache-2.0).
- .codespellrc: skip the reused zbus SVG diagrams (embedded base64
  raster data trips the spell checker).

Assisted-by: Claude Code
Signed-off-by: Jorge Guzman <jorge.gzm@gmail.com>
2026-09-21 08:40:14 -03:00
Royyan Zahir
72928d5dec arch/arm64: AES using the Armv8 Cryptography Extension.
NuttX emits no AES instruction on any arm64 core. There is no runtime
feature dispatch in arch/arm64, so every AES goes through crypto/rijndael.c
or crypto/aes.c, and the table-driven one indexes memory with key-dependent
values, so its timing follows the cache.

Provide aes_cypher() for ECB, CBC and CTR built on AESE, AESD and the
MixColumns pair, and register it with /dev/crypto as a hardware driver
alongside the existing stm32h7, sam34 and esp32 modules.

ID_AA64ISAR0_EL1.AES is read on every call, which returns -ENOTSUP rather
than trapping on a core without the extension.

Verified against the NIST SP 800-38A appendix F vectors for ECB-128,
ECB-256, CBC-128, CBC-192 and CTR-128, encrypt and decrypt, in place and
out of place.

Signed-off-by: Royyan Zahir <royzah@gmail.com>
2026-09-21 18:43:36 +08:00
dechao_gong
16632c7d55 boards/arm/rtl8730e: commit platform_autoconf.h for CI
platform_autoconf.h is a hand-maintained minimal header that provides the
SDK #defines required by the fwlib sources compiled during PREBUILD.  Unlike
the other Ameba ICs (which use ameba_gen_autoconf.sh to regenerate it from
SDK menuconfig), RTL8730E uses a static file because the amebasmart SDK
does not ship a pre-generated autoconf and running menuconfig in CI is not
feasible.

The file was previously gitignored along with all other prebuilt/ artifacts,
so CI had no platform_autoconf.h on a clean clone, causing:
  fatal error: platform_autoconf.h: No such file or directory

Fix: add !platform_autoconf.h exception to prebuilt/.gitignore and track
the file in git.  Local clean build verified (nuttx.bin 550 KB generated).

Signed-off-by: dechao_gong <dechao_gong@realsil.com.cn>
Assisted-by: Claude <noreply@anthropic.com>
2026-09-21 18:43:22 +08:00
dechao_gong
0c3839973b arch/arm/ameba: fix CI failures in RTL8730E port
Two CI issues in the RTL8730E (AmebaSmart CA32) port:

1. PREBUILD used $(ARCHOPTIMIZATION) which injects --param=min-pagesize=0
   on GCC>=12.  arm-none-eabi-gcc in CI does not recognise this flag.
   Fix: replace $(ARCHOPTIMIZATION) with explicit -Os -ffunction-sections
   -fdata-sections in both the fwlib and wifi PREBUILD loops, matching the
   pattern already used by the other Ameba ICs (rtl8721dx/8720f/8721f).

2. boards/arm/rtl8730e/rtl8730e_evb/configs/nsh/defconfig was out of sync
   with `make savedefconfig` output (missing CONFIG_ARCH_CHIP_RTL8730E_CA32,
   wrong ordering of several NETUTILS options, and redundant entries that
   are auto-selected by Kconfig).  Regenerated with olddefconfig+savedefconfig.

Signed-off-by: dechao_gong <dechao_gong@realsil.com.cn>
Assisted-by: Claude <noreply@anthropic.com>
2026-09-21 18:43:22 +08:00
dechao_gong
d8224051e7 arch/arm/ameba: fix nxstyle and cmake-format issues in RTL8730E port
Fix all nxstyle and cmake-format violations found by CI checkpatch:

- tools/nxstyle.c: add whitelist entries for SDK mixed-case symbols
  (CPU_, Diag, TRNG_, System_, vPort) used in amebasmart stubs
- arch/arm/src/rtl8730e/rtl8730e_serial.c: fix block comment lengths,
  long lines (replace Unicode arrows with ASCII), align inline comments
- arch/arm/src/rtl8730e/rtl8730e_flash_stubs.c: fix long lines and
  missing blank line after declaration
- arch/arm/src/rtl8730e/rtl8730e_wifi_stubs.c: rename nDeviceId to
  device_id, add Public Functions section header
- arch/arm/src/rtl8730e/rtl8730e_memorymap.h: fix block comment lengths
  and inline comment column alignment
- arch/arm/src/rtl8730e/hardware/rtl8730e_loguart.h: wrap long comment
- arch/arm/src/common/ameba/ameba_os_wrap.c: add missing blank lines
  after declarations
- boards/arm/rtl8730e/rtl8730e_evb/src/rtl8730e_bringup.c: add missing
  blank line after extern declaration
- arch/arm/src/rtl8730e/CMakeLists.txt: apply cmake-format
- boards/arm/rtl8730e/rtl8730e_evb/src/CMakeLists.txt: apply cmake-format

Signed-off-by: dechao_gong <dechao_gong@realsil.com.cn>
2026-09-21 18:43:22 +08:00
dechao_gong
080e3b3539 Documentation/platforms/arm/rtl8730e: add RTL8730E documentation
Add SoC-level and board-level RST documentation for RTL8730E:

- SoC doc: highlights, ATF boot chain, memory map, vendor SDK info,
  build/flash commands, and supported features
- Board doc: rtl8730e_evb features, nsh configuration guide,
  Wi-Fi STA/AP commands, SMP verification, and license exceptions

Signed-off-by: dechao_gong <dechao_gong@realsil.com.cn>
Assisted-by: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-09-21 18:43:22 +08:00
dechao_gong
1f819e5b4b boards/arm/rtl8730e: add rtl8730e_evb board support
Add the rtl8730e_evb (RTL8730E Evaluation Board) with an nsh configuration
that demonstrates the RTL8730E baseline feature set:

- Dual-core SMP (CONFIG_SMP=y, CONFIG_SMP_NCPUS=2)
- Wi-Fi station and SoftAP via wapi
- DHCP client (wlan0) and DHCP server (wlan1/AP mode)
- littlefs persistent storage at /data on SPI NOR flash
- iperf2 TCP/UDP throughput measurement
- NSH console over the LOG-UART

Board formerly named ca32-evb; renamed to follow the rtlXXXX_evb
convention used by all other Ameba boards.

Signed-off-by: dechao_gong <dechao_gong@realsil.com.cn>
Assisted-by: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-09-21 18:43:22 +08:00
dechao_gong
c4ddd5add7 arch/arm/ameba: implement CMake build for RTL8730E (AmebaSmart CA32)
Replace the CMake skeleton with full SDK build machinery, mirroring
the make-side ameba_board.mk.  RTL8730E differs from the KM4-based
ICs in three ways that prevent a direct include(ameba_board.cmake):
- No SDK autoconf / image2 ldscript generation: the board uses its own
  dramboot.ld and a static prebuilt platform_autoconf.h
- No NP firmware build: KM0/KM4 are prebuilt blobs in prebuilt/
- No -mcmse: CA32 is ARMv7-A, not Cortex-M33; uses -DCONFIG_ARM_CORE_CA32

The ameba_build_lib() helper (adapted from ameba_board.cmake) compiles
SDK sources with an isolated flag set into libameba_fwlib.a and
libameba_wifi.a, avoiding NuttX header conflicts.

Key additions:
- libameba_fwlib.a: arch.c + log.c + sscanf_minimal.c always; IPC for
  WiFi/FlashFS; ameba_flash_ram.c for FlashFS
- lib_rom.a linked for GPIO or FlashFS (GPIO_Init, Pinmux_Config, etc.)
- libameba_wifi.a + prebuilt WHC host libs for WiFi
- VFS1 geometry extracted from platform_autoconf.h via
  target_compile_definitions (set_property(SOURCE) has scope issues in
  NuttX's include()-based CMake structure)
- `flash` target calls ameba_smart_flash.sh

Verified: gpio (1186 targets) and nsh (1530 targets) configs both
build cleanly; /data mounts at correct 2 MB partition size.

Signed-off-by: dechao_gong <dechao_gong@realsil.com.cn>
Assisted-by: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-09-21 18:43:22 +08:00
dechao_gong
4416660ce2 arch/arm/ameba: enable SMP on AmebaSmart CA32 (RTL8730E)
RTL8730E has dual Cortex-A32 cores (CA32) in the AP domain.  Core1 is
powered off by default and requires an explicit HSYS power-on sequence
before ATF SP_MIN can service the PSCI CPU_ON call.  Without it, SP_MIN
writes the entry point to the mailbox and times out waiting for Core1 to
poll it.

Add rtl8730e_core1_power_on() that mirrors SDK smp.c:rtk_core1_power_on():
assert reset, assert isolation, two-stage power-on with up_udelay() for
correct 50/50/500/50 us timing, then release isolation and reset.  Call it
from up_cpu_start() before psci_cpu_on().

Enable CONFIG_SMP / CONFIG_SMP_NCPUS=2 / CONFIG_ARM_PSCI in the nsh
defconfig.

Enabling SMP also exposed a latent WHC skb alignment bug: the Realtek
WHC WiFi driver keeps the AP/NP DDR views coherent with by-VA
DCache_Clean/Invalidate at SKB_CACHE_SZ (64 on RTL8730E) granularity,
which requires every skb buffer to be cache-line aligned.  The port had
omitted CONFIG_MM_DEFAULT_ALIGNMENT (defaulting to 8; the 8721Dx parts
set 32), so heap-allocated skb buffers were unaligned and the cache
maintenance spilled onto the neighbouring skb struct, corrupting its
immutable buf pointer (seen as skb->buf = 0x05 and a TX memcpy data
abort on "renew wlan0").  This was harmless on single core -- the
non-shareable DDR mapping made the stray maintenance a no-op -- but the
SMP shareable mapping plus real dual-core concurrency turned it into a
hard fault.  Set CONFIG_MM_DEFAULT_ALIGNMENT=64 in the nsh defconfig.

Hardware verified on RTL8730E (C-cut): /proc/cpuinfo shows both processor 0
and processor 1; getprime 2 completes two concurrent threads in ~573 ms
(same as single-thread), confirming true parallel execution across both cores.
"renew wlan0" now obtains a DHCP lease (192.168.1.101) without faulting.

Assisted-by: Claude Sonnet 4.6 <noreply@anthropic.com>
Signed-off-by: dechao_gong <dechao_gong@realsil.com.cn>
2026-09-21 18:43:22 +08:00
dechao_gong
7b5861122f arch/arm/ameba: use the real efuse WiFi MAC on AmebaSmart
On AmebaSmart the standard WHC_API_WIFI_GET_MAC_ADDR pull API times out:
the KM4 NP firmware snapshot linked into this image does not register a
handler for it, so wifi_get_mac_address() blocks ~12s per call and cannot
be used to fill the netdev MAC.

The NP does, however, PUSH its real efuse MAC to the host at wifi-on time
via WHC_API_SET_NETIF_INFO, which lands in the host-side
lwip_wlan_set_netif_info() glue.  Previously that glue discarded the
address and ameba_wifi_get_mac() synthesised a random locally-administered
MAC, which then diverged from the MAC the NP actually associates with (the
NP's 802.11 RX filter drops unicast frames addressed to the random MAC, so
DHCP OFFERs never arrive).

Cache the pushed efuse MAC in lwip_wlan_set_netif_info() and return it from
ameba_wifi_get_mac(); the random MAC remains only as a fallback for the
window before the NP has pushed.  ameba_wifi_connect() then mirrors it to
the NP with wifi_set_mac_address() so both sides agree.  The per-IC guard
uses CONFIG_AMEBASMART, not CONFIG_ARCH_CHIP_RTL8730E: these files are
compiled by the board PREBUILD step with the vendor SDK autoconf, where
NuttX Kconfig symbols are invisible.  The other Ameba parts keep their
working GET_MAC efuse path unchanged.

Verified end to end: ifconfig shows the real Realtek OUI MAC
(00:e0:4c:..), association and DHCP complete in a single round.

Signed-off-by: dechao_gong <dechao_gong@realsil.com.cn>
2026-09-21 18:43:22 +08:00
dechao_gong
f156812c0c arch/arm: add Realtek AmebaSmart (RTL8730E) CA32 support
Add NuttX support for the Realtek AmebaSmart (RTL8730E) running on the
CA32 (Cortex-A32) application core, with the KM4/KM0 cores kept as
vendor firmware (KM4 acts as the WiFi network processor over WHC IPC).

Stage 1 bring-up, hardware verified:

  - CA32 boot / exception vectors / MMU + page allocator / heap
  - LOGUART console (RX via KM0-owned IPC + shared memory)
  - IRQ controller, timer, serial
  - On-chip SPI NOR flash MTD -> littlefs mounted at /data
  - WHC-host WiFi netdev (STA): scan / connect / DHCP, verified end to
    end (association -> 4-way -> DHCP -> ping, bidirectional TCP)

IC-agnostic Ameba glue is shared from arch/arm/src/common/ameba via a
relative VPATH entry (matching the rtl8721dx pattern), which also avoids
the empty mkdeps --dep-path that a leading-":" VPATH entry produced and
which intermittently broke parallel .ddc dependency generation.

The FIP packaging / flash image assembly is driven by
common/ameba/tools/ameba_smart_flash.sh from the board scripts.

Vendor blobs and build artefacts under the board prebuilt/ directory are
kept out of the tree via prebuilt/.gitignore.

Signed-off-by: dechao_gong <dechao_gong@realsil.com.cn>
2026-09-21 18:43:22 +08:00
Justin Hammond
8e05ffaab8 boards/risc-v/eic7700x: Enable the reset procfs entry.
Makes /proc/reset available, so which peripherals are held can be read
while the board is running rather than only for the eight lines the
startup report names.

RESET_PROCFS depends on FS_PROCFS_REGISTER, which neither board set.
Without it the symbol is dropped when the configuration is regenerated
and the entry never appears, which is silent: the defconfig still reads
as though the feature were on.

Assisted-by: Claude:claude-opus-5
Signed-off-by: Justin Hammond <justin@dynam.ac>
2026-09-21 16:29:12 +08:00
Justin Hammond
a763b873b4 arch/risc-v/eic7700x: Name the reset lines through procfs.
Implements get_line, so /proc/reset names all 324 lines and gives the
register and bit each lives in.  The framework asks status() for the
asserted state.

The names do not survive compilation: they live in the enumeration, so
without a table a listing gives only numbers, and working back from one
to a peripheral means counting through the header.  The table costs
about 8 KiB and is built only when the procfs entry is.

The ids are sparse, 324 lines across a space of 1952, so the table is
sorted by id and searched rather than indexed, and an id naming no line
returns -ENODEV.  The framework skips those, which is what leaves the
listing dense.

Assisted-by: Claude:claude-opus-5
Signed-off-by: Justin Hammond <justin@dynam.ac>
2026-09-21 16:29:12 +08:00
Justin Hammond
7fe77bf1d7 boards/risc-v/eic7700x: Report the reset lines at startup.
A peripheral held in reset reads like one that is absent, and the boot
loader does not leave the same lines released on every board or every
boot.  One line at startup says how much is held:

  reset: 324 lines, 117 held

Beside the clock tree's line and for the same reason: the summary is
worth seeing on every boot, and the detail belongs in /proc where it can
be read when it is wanted.

The driver's error output is enabled, matching the clock driver.  Info
level is not, since nothing at that level prints on a healthy boot.

Assisted-by: Claude:claude-opus-5
Signed-off-by: Justin Hammond <justin@dynam.ac>
2026-09-21 16:29:12 +08:00