Commit graph

63241 commits

Author SHA1 Message Date
liang.huang
cbe4ceb158 arch/risc-v: preserve ra across ecall for fp-chain backtrace
sys_callN() wraps a bare ecall and calls no other function, so the
compiler treats it as a leaf function: with frame pointers enabled,
it only needs to spill the caller's s0, which it places in what
up_backtrace()'s fp-chain walk assumes is ra's stack slot, while the
real ra slot is never written. sched_backtrace() then misreads that
slot as the return address for this frame, either resolving to a
bogus symbol or, if the adjacent garbage happens to look
out-of-range, terminating the backtrace early.

Add "ra" to the ecall clobber list so the compiler spills/reloads ra
around the ecall like a normal call site, keeping ra and the saved
s0 in their expected slots. Gate this on
CONFIG_FRAME_POINTER && CONFIG_SCHED_BACKTRACE, the only combination
where up_backtrace()'s fp-chain walk is both valid (FRAME_POINTER)
and actually exercised (SCHED_BACKTRACE); other configurations keep
the original "memory"-only clobber and pay no extra cost.

This only fixes the syscall boundary. Leaf functions that do not
cross a syscall (e.g. up_idle()) can still lose their ra slot the
same way and are not addressed here.

Signed-off-by: liang.huang <liang.huang@houmo.ai>
2026-07-16 15:24:12 +08:00
liang.huang
73b3487e70 arch/risc-v: switch to target addrenv when backtracing another tcb
up_backtrace() on a different tcb dereferences that task's own stack
to walk its frame pointer chain, but never selected that task's
address environment first. Under CONFIG_ARCH_ADDRENV each task's
stack lives behind its own page tables mapped at the same fixed
virtual range, so reading tcb->stack_base_ptr without first switching
to that task's addrenv reads whatever physical page the caller's own
mapping of that virtual range happens to point to, not the target
task's real stack. A cross-tid dumpstack of a task running in a
different address environment therefore returns garbage or an
all-zero backtrace instead of failing cleanly or resolving the real
call chain.

Add an addrenv parameter to backtrace() and select the target tcb's
addrenv_own only around the two dereferences that read the target's
saved ra/fp (ra = *(fp - 1), next_fp = *(fp - 2)), then restore the
caller's own addrenv before writing the result into buffer. buffer
belongs to the caller, not the target tcb, so it must always be
written back in the caller's own address environment; writing it
while the target's addrenv is still selected would corrupt the
access instead of fixing it.

Signed-off-by: liang.huang <liang.huang@houmo.ai>
2026-07-16 15:24:12 +08:00
liang.huang
16a4ab53fa arch/risc-v: fix stale ustkptr used for backtrace in kernel stack mode
xcp.ustkptr is only assigned once in up_initial_state() when a task is
created and, since the syscall fast path was optimized in
e6973c764c, is never updated afterwards. up_backtrace() used
"ustkptr != NULL" to decide whether a task is currently blocked
inside a syscall, and *(ustkptr + 1) as the frame pointer to resume
tracing from. Since ustkptr is now a dead value fixed at task
creation time, the check is always true and the "frame pointer" it
derives points at stale data near the initial stack top, unrelated
to where the task is actually blocked.

Use rtcb->flags & TCB_FLAG_SYSCALL together with xcp.sregs, which
dispatch_syscall() maintains precisely across the entire syscall
execution window (including any nested context switches caused by
blocking), to locate the frame pointer/return address saved at
syscall entry instead.

Signed-off-by: liang.huang <liang.huang@houmo.ai>
2026-07-16 15:24:12 +08:00
anjiahao
16df6dc55d boards/stm32f3: nucleo-f302r8:ihm07m1_b16: enable LTO to fit flash
The ihm07m1_b16 (FOC motor control) configuration overflows the
STM32F302R8 64 KiB flash region by ~470 bytes, so it no longer links.
Enable GNU Full LTO (CONFIG_LTO_FULL=y); cross-module dead-code
elimination brings the image back under the limit (flash drops from
~66.0 KiB to ~57.7 KiB, 88%).

Signed-off-by: anjiahao <anjiahao@xiaomi.com>
2026-07-16 08:12:38 +02:00
Matteo Golin
1b6f918c3f docs/audio_rttl: Document the RTTL audio player
Added docs to explain how to use the RTTL audio player, the currently
supported audio sinks and how to add more audio sink support.

Signed-off-by: Matteo Golin <matteo.golin@gmail.com>
2026-07-15 16:15:42 -03:00
raiden00pl
d3d38dc3c6 arch/arm/stm32: SDMMC1/2 depends on SCHED_HPWORK
STM32 SDMMC driver depends on  CONFIG_SCHED_HPWORK

Signed-off-by: raiden00pl <raiden00@railab.me>
2026-07-15 12:25:22 -03:00
raiden00pl
24d64ee8d9 arch/arm/stm32: STM32 I2S depend on AUDIO and SCHED_WORKQUEUE
STM32 I2S depend on AUDIO and SCHED_WORKQUEUE

Signed-off-by: raiden00pl <raiden00@railab.me>
2026-07-15 12:25:22 -03:00
raiden00pl
0f306115be arch/arm/stm32: STM32_SDIO depend on SCHED_HPWORK
STM32_SDIO depend on SCHED_HPWORK

Signed-off-by: raiden00pl <raiden00@railab.me>
2026-07-15 12:25:22 -03:00
anjiahao
745a6e53a4 spawn: allow zero stacksize/priority to use binary loader defaults
posix_spawnattr_init() no longer pre-fills attr->stacksize and
attr->priority (it leaves them zero, as memset already does).  When a
caller does not set them, the binary loader supplies them from the
loaded ELF (binp->stacksize / binp->priority, parsed from the nx_*
symbols), and nxtask_spawn_exec() falls back to the parent priority and
CONFIG_POSIX_SPAWN_DEFAULT_STACKSIZE for the posix_spawn() function-task
path.

This lets an application's stack size and priority embedded as ELF
symbols actually drive the spawned task, instead of being overridden by
the spawnattr defaults.

Signed-off-by: anjiahao <anjiahao@xiaomi.com>
2026-07-15 12:24:44 -03:00
anjiahao
0178ceab19 elf:use elf symbol to parse attribute
Parse application attributes (stacksize, priority, and uid/gid/mode under
CONFIG_SCHED_USER_IDENTITY) from absolute symbols (nx_stacksize,
nx_priority, nx_uid, nx_gid, nx_mode) embedded in the ELF at link time,
falling back to defaults when the symbols are absent.

Signed-off-by: anjiahao <anjiahao@xiaomi.com>
2026-07-15 12:24:44 -03:00
anjiahao
c8b71df614 libelf:support find symbol by symbol name
Add libelf_findsymbol() to locate a symbol in the ELF symbol table by
name, reusing the existing libelf_findsymtab/libelf_readsym/libelf_symname
helpers, and expose its prototype in include/nuttx/lib/elf.h.

Signed-off-by: anjiahao <anjiahao@xiaomi.com>
2026-07-15 12:24:44 -03:00
Ricard Rosson
d89019aa78 arch/rp23xx: apply the same bulk/notify endpoint fixes as rp2040
rp23xx_usbdev.c is a line-for-line copy of the rp2040 USB device driver
and shares all three endpoint-handling defects fixed in the preceding
commits:

  - bulk OUT reads armed with the full request length, overflowing the
    10-bit buffer-control LEN field for large reads (e.g. cdcncm);
  - endpoint requests resubmitted from their own completion callback
    being armed twice, corrupting the data PID;
  - the buffer AVAILABLE bit written together with length/PID instead of
    afterwards.

Port the identical fixes to the RP2350 driver.  The affected functions
are byte-identical to their rp2040 counterparts, so the changes match
verbatim.  These were validated on RP2040 hardware; RP2350 shares the
same USB controller IP and driver, but was not re-tested on silicon.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01AHJRvWeBMTHwzpwjaUg4HW
Signed-off-by: Ricard Rosson <ricard@groundbits.com>
2026-07-15 22:27:03 +08:00
Ricard Rosson
8205f941d6 arch/rp2040: set buffer AVAILABLE bit after the rest of buffer control
Per the RP2040 datasheet section 4.1.2.5.1, when handing a buffer to the
USB controller the AVAILABLE bit must be written after the rest of the
buffer-control register (length and data PID) and after a short delay,
because buffer control crosses from the system clock domain into the USB
clock domain.  Writing everything in a single store risks the controller
acting on a stale length or PID.  rp2040_update_buffer_control() wrote
the whole word, AVAILABLE included, in one access.

Follow the sequence the datasheet (and the Pico SDK) use: write the
control word with AVAILABLE cleared, wait ~12 CPU cycles, then set
AVAILABLE.  The delay covers system clocks up to 12x the 48 MHz USB
clock.

Validated on raspberrypi-pico (RP2040) as part of bringing up cdcncm;
no regression on cdcacm/usbmsc.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01AHJRvWeBMTHwzpwjaUg4HW
Signed-off-by: Ricard Rosson <ricard@groundbits.com>
2026-07-15 22:27:03 +08:00
Ricard Rosson
128ee6087f arch/rp2040: don't re-arm an endpoint request resubmitted from its callback
rp2040_txcomplete() and rp2040_rxcomplete() unconditionally called
rp2040_wrrequest()/rp2040_rdrequest() to start the next transfer after
invoking a request's completion callback.  When that callback resubmits
a request on the same, now-idle endpoint -- which cdcncm and rndis do
from their interrupt/notify completion handlers -- rp2040_epsubmit()
already arms the hardware buffer for it.  The unconditional re-arm in the
completion path then arms the same buffer a second time, toggling the
DATA0/DATA1 PID twice.  The host sees a stale PID and silently discards
the packet as a retransmission, so e.g. the cdcncm NETWORK_CONNECTION /
SPEED_CHANGE notifications never reach the host and the interface stays
NO-CARRIER.

Track whether a request's hardware buffer has already been armed with a
per-request flag (set in rp2040_wrrequest/rp2040_rdrequest, cleared in
rp2040_epsubmit) and skip the redundant re-arm when the completion
callback has already resubmitted.  The in-progress multi-packet case
(transfer not yet complete) still continues normally.

Validated on raspberrypi-pico (RP2040): the cdcncm interrupt-IN
notification is now delivered (confirmed with usbmon) and the host
brings the link up; previously it never was.  This is also the likely
cause of the long-standing rndis control-response timeout on this
controller.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01AHJRvWeBMTHwzpwjaUg4HW
Signed-off-by: Ricard Rosson <ricard@groundbits.com>
2026-07-15 22:27:03 +08:00
Ricard Rosson
cc77be145a arch/rp2040: clamp bulk OUT read length to the endpoint max packet size
rp2040_epread() armed the DPSRAM buffer-control register with the full
usbdev request length.  That length is only correct for requests no
larger than the buffer-control LEN field, which is 10 bits wide (max
1023 bytes).  Class drivers that post larger read requests -- e.g.
cdcncm allocates a 16 KiB NTB read buffer -- overflow LEN: 16384 & 0x3ff
is 0, and the high bits corrupt the neighbouring control flags.  The
controller then sees a zero-length available buffer and completes the
transfer immediately with zero bytes, over and over, so no OUT data is
ever received (cdcncm floods "Wrong NTH SIGN, skblen 0").

The receive path already accumulates a request across multiple packets:
rp2040_rxcomplete() copies each packet, advances xfrd and re-arms via
rp2040_rdrequest() until the request is satisfied or a short packet
arrives.  So the buffer only ever needs to be armed for a single
maximum-size packet.  Clamp nbytes accordingly.  This matches the
transmit path, which already chunks to ep.maxpacket in rp2040_wrrequest.

Bulk classes with small reads (cdcacm, usbmsc) were unaffected because
their request lengths already fit in LEN, which is why the defect only
showed up on cdcncm.

Validated on raspberrypi-pico (RP2040): a CONFIG_NET_CDCNCM device that
previously received nothing now passes traffic in both directions with
0% packet loss.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01AHJRvWeBMTHwzpwjaUg4HW
Signed-off-by: Ricard Rosson <ricard@groundbits.com>
2026-07-15 22:27:03 +08:00
Lwazi Dube
e593ba35a4 arch/mips: Add basic support for MIPS Creator CI20 board
This commit introduces a rudimentary architecture and board port for the
MIPS Creator CI20, featuring the dual core Ingenic JZ4780 SoC (MIPS32).

Included in this initial implementation:
- Basic architectural initialization and startup code for the JZ4780 Core 0.
- Minimal configuration required to execute from RAM.
- Early UART/serial console support for basic debugging and NSH output.
- Minimal board-specific configuration for the CI20 target.
- Console output is routed via UART0 on the expansion header.

This establishes basic support for running NuttX on the MIPS CI20.
Further peripherals, optimization, and extended documentation are left for
future iterations or community contributions.

Build and Runtime Deployment Info:
----------------------------------

The baseline can be configured, compiled using the MIPS MTI toolchain,
and loaded via U-Boot using the following commands (replace
<tftp_dir> with your local TFTP root directory).

./tools/configure.sh -l ci20/nsh
  make CROSSDEV=mips-mti-elf-
  mkimage -A mips -O linux -T kernel -C none -a 0x80000180 -e 0x800004ac \
    -n "nx" -d nuttx.bin <tftp_dir>/nuttx.umg

Note: U-Boot must be properly configured for networking (e.g., valid ipaddr,
serverip, and ethaddr environment variables) to fetch the image over TFTP.

Run this from U-Boot prompt:
  tftp nuttx.umg && bootm $fileaddr

Signed-off-by: Lwazi Dube <lwazeh@gmail.com>
2026-07-15 08:02:55 -03:00
Catalin Visinescu
081e4c478a drivers/: Multiple Drivers Are Registered With World Writable - Part 2
Permissions (Part 2)

Description:

In kernel builds, any unprivileged process running on the NuttX
device can open /dev/efuse and attempt to read/write fuse content.
Reading the fuses may provide valuable information to an attacker
controlling the user process. The write operation, in extreme cases
where the fuse blocks are not locked, may brick the device.

DISCLAIMER: I tried to be strict with the settings, better to relax them
later if it's needed.

This is part of https://github.com/apache/nuttx/issues/19410

See https://github.com/apache/nuttx/issues/19410

Compiles ok.

Signed-off-by: Catalin Visinescu <catalin_visinescu@yahoo.com>
2026-07-15 15:27:28 +08:00
Jacob Dahl
f20cf4aac3 fix(net/igmp): restore General Query handling broken by pointer compare
The group address in the IGMP header is declared as uint16_t grpaddr[2],
so it decays to a pointer.  Comparing it against INADDR_ANY compares the
address of a struct member against 0, which is always false.  The General
Query branch is therefore unreachable and GCC discards it entirely.

Commit 09bb292fa2 ("net/igmp: fix build warning on GCC 12.2.0") replaced
the original

    if (igmp->grpaddr == 0)

with

    if (net_ipv4addr_cmp(igmp->grpaddr, INADDR_ANY) != 0)

but net_ipv4addr_cmp(a, b) expands to (a == b) and INADDR_ANY expands to
((in_addr_t)0), so the emitted comparison is unchanged.  The -Waddress
diagnostic disappeared only because the comparison now originates inside
a macro expanded from a header included via -isystem, and GCC suppresses
warnings from system-header macros.  The defect was hidden, not fixed.

That commit also rewrote the unicast query test from group->grpaddr != 0,
which was well-formed, into the same pointer comparison, making it
unconditionally true.

Convert the header field with net_ip4addr_conv32() once, and compare the
resulting in_addr_t.  The conversion was already being done in the
group-specific branch, so this only hoists it and reuses it.

Impact: a General Query (destination 224.0.0.1, group address 0) is the
periodic query every IGMP querier sends.  It currently falls through to
the group-specific branch, where igmp_grpallocfind() allocates a group
for 0.0.0.0 and schedules a report for it, while joined groups never have
their report timers restarted.  The querier then ages out the membership
and multicast delivery to the device stops.

Signed-off-by: Jacob Dahl <dahl.jakejacob@gmail.com>
2026-07-15 08:46:23 +02:00
liang.huang
adf4a543e3 arch/common: fix host_flags_to_mode() O_RDONLY sentinel collision
host_flags_to_mode() used a trailing 0 entry in modeflags[] as the
loop-termination sentinel. O_RDONLY is defined as 0 and is exactly
modeflags[1], so the loop's termination check fired before ever
comparing that entry, and a bare O_RDONLY open always fell through
to -EINVAL.

Bound the loop by array size (nitems()) instead of a value sentinel.

Signed-off-by: liang.huang <liang.huang@houmo.ai>
2026-07-15 08:41:38 +02:00
Michael Rogov Papernov
073570a103 ci/testing: MemBrowse Doc only change detection fix
Fixed MemBrowse report action to detect DOC only changes based on
comparing the forked point in the master with the PR, and not the
current master.

Signed-off-by: Michael Rogov Papernov <michael@membrowse.com>
2026-07-14 11:03:49 -03:00
raiden00pl
18a288097b boards/arm/stm32{f1,f4}: drop duplicated reset.c/romfs, use common board logic
The board-common stm32_reset.c and stm32_romfs_initialize.c are already
provided by boards/arm/common/stm32. Remove the redundant local copies
from boards

Signed-off-by: raiden00pl <raiden00@railab.me>
2026-07-14 15:05:33 +02:00
Matteo Golin
de4f3bf92c docs/raspberrypi-4b: Add NXDoom configuration docs
Document the features and limitations of the NXDoom configuration.

Signed-off-by: Matteo Golin <matteo.golin@gmail.com>
2026-07-14 10:40:27 +02:00
Matteo Golin
5da1e3eec3 boards/raspberrypi-4b: Added NXDoom configuration
Adds a configuration that allows NXDoom to be played on the Raspberry
Pi 4B, with the WAD file loaded from the SD card and the graphics over
HDMI.

Signed-off-by: Matteo Golin <matteo.golin@gmail.com>
2026-07-14 10:40:27 +02:00
Matteo Golin
472e4f623a boards/raspberrypi-4b: Fix nxinit configuration SD issues
Propagate the solution for SD card bugs to the nxinit configuration,
which also uses the nxinit configuration.

Signed-off-by: Matteo Golin <matteo.golin@gmail.com>
2026-07-14 09:46:33 +08:00
Matteo Golin
6de8c13d99 docs/raspberrypi-4b: Documentation about the SD card updated
Updated the documentation to reflect the fix of buggy SD card behaviour
at the sacrifice of slower performance.

Signed-off-by: Matteo Golin <matteo.golin@gmail.com>
2026-07-14 09:46:33 +08:00
Matteo Golin
b757195daa boards/raspberrypi-4b: Bug fix for broken SD card behaviour
Introduces a fixed configuration for the SD card that does not break for
multi-block transfers.

Signed-off-by: Matteo Golin <matteo.golin@gmail.com>
2026-07-14 09:46:33 +08:00
Matteo Golin
4f90fe351b bcm2711/sdio: Moderate improvement to multi-block transfers
I document the issues encountered with multi-block transfers, namely the
block count failing to be set correctly. Even though I did test with
that issue corrected, it required modifications to the upper-half MMCSD
driver which I am not prepared to test. It also did not fix the time-out
on multi-block transfers, likely because the method of verifying FIFOs
have space to write is finicky. For now, limiting the block count of
transfers resolves the bug!

Signed-off-by: Matteo Golin <matteo.golin@gmail.com>
2026-07-14 09:46:33 +08:00
Matteo Golin
7bf0f26ec2 bcm2711/mailbox: Invalidate cache before read
Cache must be invalidated before the buffer is read since the
VideoCore's write will not invalidate the cache.

Signed-off-by: Matteo Golin <matteo.golin@gmail.com>
2026-07-14 09:46:33 +08:00
liang.huang
170a989ccb libc/builtin: support per-application priority/stacksize under KERNEL build.
nsh_fileapp() could not apply an application's Kconfig-configured
priority/stacksize via posix_spawn() under CONFIG_BUILD_KERNEL, because
the registry table (struct builtin_s / g_builtins[]) was gated on
CONFIG_BUILTIN, which depends on !BUILD_KERNEL. Those settings were
silently ignored in KERNEL builds.

CONFIG_BUILTIN conflates the table with main_t-based dispatch, which is
meaningless under CONFIG_BUILD_KERNEL. Add a hidden derived symbol,
APP_REGISTRY, that tracks table availability independently of dispatch:

  config APP_REGISTRY
          bool
          default y if BUILTIN || BUILD_KERNEL

Switch the guards on the table itself (Make.defs, builtin.h) from
CONFIG_BUILTIN to CONFIG_APP_REGISTRY. Call sites that dereference
builtin->main stay gated on CONFIG_BUILTIN and remain unreachable
under CONFIG_BUILD_KERNEL.

Signed-off-by: liang.huang <liang.huang@houmo.ai>
2026-07-13 15:23:39 -03:00
hanzhijian
34170a4475 drivers/net/w5500: fix wrong variable and d_private assignment
Fix two latent defects in the W5500 Ethernet driver:

1. NETDEV_RXERRORS() references non-existent variables (line 1351):
   In w5500_receive(), the error path uses &priv->dev but the function
   parameter is named self and the device field is w_dev. This compiles
   only because NETDEV_RXERRORS() expands to nothing without
   CONFIG_NETDEV_STATISTICS; enabling statistics breaks the build.

2. d_private set to the device array instead of the instance (line 2069):
   In w5500_initialize(), d_private was set to g_w5500 (the global array)
   instead of self (the current instance). This is harmless for device 0
   (g_w5500 == &g_w5500[0]) but wrong for any devno > 0 — every callback
   that recovers the driver state via dev->d_private would operate on
   device 0's state.

Fixes #19306

Signed-off-by: hanzhijian <hanzhijian@zepp.com>
Author: hanzhijian <hanzhijian@zepp.com>
2026-07-13 15:02:02 -03:00
Jorge Guzman
05832a4e62 Documentation: system: cu: document the cu serial terminal
The cu application page was an empty stub. Document the command:
description, options, escape sequences, configuration dependencies
and limitations.

Also add an rs485 configuration to the linum-stm32h753bi board with
the two on-board RS-485 transceivers (UART4 and USART6) and the cu
terminal enabled, plus a board documentation section showing how to
bridge the console to one of the RS-485 buses with cu. The RS-485
DE pins are handled automatically by the serial driver.

Tested on hardware.

Signed-off-by: Jorge Guzman <jorge.gzm@gmail.com>
2026-07-13 09:35:18 -04:00
hanzhijian
20579ab531 drivers/contactless: fix uninitialized uid leak in mfrc522_read
Fix security issue where uninitialized kernel stack contents could be
leaked to userspace when mfrc522_picc_select() fails.

In mfrc522_read(), the local variable 'uid' was not initialized before
being passed to mfrc522_picc_select(). If the function fails (e.g., due
to bad data on the SPI bus), the uninitialized uid.sak value could pass
the PICC_TYPE_NOT_COMPLETE check, causing snprintf() to copy
uninitialized kernel stack data to the userspace buffer.

Fixes #19417

Signed-off-by: hanzhijian <hanzhijian@zepp.com>
Author: hanzhijian <hanzhijian@zepp.com>
2026-07-13 19:50:57 +08:00
Catalin Visinescu
8d2b71d127 drivers/efuse/efuse: Drivers Registered With World Write Permissions(Part 1)
Description:

In kernel builds, any unprivileged process running on the NuttX device
can open /dev/efuse and attempt to read/write fuse content. Reading the
fuses may provide valuable information to an attacker controlling the user
process. The write operation, in extreme cases where the fuse blocks are
not locked, may brick the device.

This is part of https://github.com/apache/nuttx/issues/19410

Compiles ok.

Signed-off-by: Catalin Visinescu <catalin_visinescu@yahoo.com>
2026-07-13 12:08:01 +02:00
raul_chen
0d2993dd87 Documentation/net: document lower-half driver performance tuning
Add a "Performance tuning" section to the network driver guide covering the
knobs that matter most for throughput on Wi-Fi lower-half drivers whose MAC
runs on a companion core: RX quota as backpressure, keeping the RX thread
priority at or below the vendor packet-delivery task, and capping the TCP
window / send buffer (backed by the shared IOB pool) on lossy wireless paths.

Signed-off-by: raul_chen <raul_chen@realsil.com.cn>
2026-07-13 11:53:26 +02:00
raul_chen
51c8b7158d arch/arm/ameba: fix open-network Wi-Fi association
Connecting to an open AP after having connected to a secured one failed in
pre-auth: the stored passphrase (priv->psk) was kept forever, so a later
open-AP connect was still driven as WPA2 and rejected by the AP.

Clear the stored passphrase on explicit disconnect (SIOCSIWESSID with
flags == 0) only; it is still kept across normal reconnects so a secured
network does not need the key re-entered on every join.  Also set key_id = -1
(non-WEP) instead of leaving the memset-zero default, and print the security
type in the connect log to aid diagnosis.

Signed-off-by: raul_chen <raul_chen@realsil.com.cn>
2026-07-13 11:53:26 +02:00
raul_chen
4a69d77b38 arch/arm/ameba: tune WHC Wi-Fi TCP throughput on both boards
Tune the TCP stack and driver resources for the WHC Wi-Fi data path on both
rtl8720f_evb and pke8721daf (NuttX runs on the application core; the Wi-Fi MAC
runs on a companion core reached over an on-chip IPC):

- Cap the advertised TCP receive window (NET_RECV_BUFSIZE=10000) to about the
  out-of-order reassembly capacity and bound in-flight TX
  (NET_SEND_BUFSIZE=16384).  The stock unbounded window/queue let the peer and
  the local stack burst far more than the Wi-Fi path can smooth, causing
  bursty loss/reordering and RTO stalls (RX), and starving incoming-ACK
  processing so the peer window collapses and spurious retransmits tear the
  link down (TX).
- Keep out-of-order reassembly (NET_TCP_OUT_OF_ORDER) but disable selective
  ACK.  PR #19353 enabled NET_TCP_SELECTIVE_ACK on both boards; on the lossy
  Wi-Fi TX path the sender-side selective-ACK recovery does not reliably
  repair multi-segment holes and stalls TX, so NewReno with out-of-order
  reassembly is used instead -- same steady-state throughput, robust recovery.
- Widen IOB buffers to 512 bytes; the window and out-of-order buffers draw
  from the shared IOB pool at run time and add no static memory.
- Drop the busy-wait retry in the transmit path (the send-buffer cap makes it
  dead code) and lower the forced host TX skb count (skb_num_ap) to 8, which
  covers the NP's transient TX backlog without over-reserving AP heap.

Signed-off-by: raul_chen <raul_chen@realsil.com.cn>
2026-07-13 11:53:26 +02:00
Felipe Moura
cd6ed0dbf9 Documentation/sim: document dropbear configuration
Describe how to build and use the Dropbear SSH server configuration on
the simulator, including host TAP network setup, user creation and the
volatile /tmp host key/passwd caveat.

Signed-off-by: Felipe Moura <moura.fmo@gmail.com>
2026-07-13 09:44:06 +08:00
Felipe Moura
b466c449b8 boards/sim: add dropbear config for local SSH/crypto testing
Add config to use Dropbear in sim environment.

Signed-off-by: Felipe Moura <moura.fmo@gmail.com>
2026-07-13 09:44:06 +08:00
Matteo Golin
c15a3bfc97 docs/audio_tone: Add documentation about the audio tone driver
This commit adds some documentation about the audio tone driver, how to
use it and links to it from the main audio component page. I also added
some back links to other audio docs there for convenience.

Signed-off-by: Matteo Golin <matteo.golin@gmail.com>
2026-07-13 09:42:26 +08:00
simbit18
29c5ae62ad ci/platforms/darwin.sh: fix genromfs installation
fix
Error: Refusing to load formula px4/px4/genromfs from untrusted tap px4/px4.
Run `brew trust --formula px4/px4/genromfs` or `brew trust px4/px4` to trust it.
Error: Process completed with exit code 1.

Homebrew 6.0+ refuses to load formulae from third-party taps unless they
are explicitly trusted ("Refusing to load formula ... from untrusted tap").
Trust each tap non-interactively before installing from it. Without this,
`brew install` aborts before pouring any package (including ccache).
`brew trust` only exists on Homebrew 6.0+; guard it so older versions,
which don't gate untrusted taps, skip it silently.

50161b1f09/Tools/setup/macos.sh (L54-L64)

Signed-off-by: simbit18 <simbit18@gmail.com>
2026-07-12 22:21:24 +02:00
raul_chen
31caf8497b boards/arm: Ameba produce nuttx.bin and derive flash offsets from the SDK layout
Rework the RTL8721Dx / RTL8720F flashable-image handling to match the common
NuttX convention:

- Name the packed application image nuttx.bin (was app.bin) and leave only it
  plus the map files in the top-level build directory; the prebuilt bootloader
  boot.bin stays in the board prebuilt/ directory.  Drop the redundant per-core
  and OTA image copies from the top-level directory.
- Read the boot and application flash offsets from the SDK flash layout
  (platform_autoconf.h) instead of hardcoding them, and write boot.bin and
  nuttx.bin each at its own offset.  A flash-layout change is then tracked
  automatically and no offsets are entered by hand.
- Update the board documentation to match.

Signed-off-by: raul_chen <raul_chen@realsil.com.cn>
2026-07-12 14:23:41 -04:00
Matteo Golin
618119edb7 docs/raspberrypi-4b: Document PWM configuration
Documents the configuration which allows PWM audio.

Signed-off-by: Matteo Golin <matteo.golin@gmail.com>
2026-07-12 09:52:26 +08:00
Matteo Golin
de8db15fad boards/raspberrypi-4b: Add a configuration with PWM audio
This configuration has PWM audio output over the audio jack and built-in
examples to play with it.

Signed-off-by: Matteo Golin <matteo.golin@gmail.com>
2026-07-12 09:52:26 +08:00
Matteo Golin
1971ddd081 boards/raspberrypi-4b: Bring up PWM devices
Brings up PWM interfaces for the RPi4B when enabled.

Signed-off-by: Matteo Golin <matteo.golin@gmail.com>
2026-07-12 09:52:26 +08:00
Matteo Golin
232d254275 bcm2711/oneshot: Implement oneshot timer driver for BCM2711
This commit implements a count-based oneshot timer driver for the
BCM2711 system timers.

Signed-off-by: Matteo Golin <matteo.golin@gmail.com>
2026-07-12 09:52:26 +08:00
Matteo Golin
c511052251 bcm2711/pwm: Implement PWM driver for the BCM2711
Implements the BCM2711 PWM driver. Works for PWM0 and PWM1.

Signed-off-by: Matteo Golin <matteo.golin@gmail.com>
2026-07-12 09:52:26 +08:00
Matteo Golin
9748c760be contributing: Add requirement for 'Assisted-by' commit field
This adds the requirement for the 'Assisted-by' commit field as voted in
the mailing list to the contribution guide. This allows commits created
with generative tooling to be easily filtered/tracked using automated
tooling, and adopts the guidelines from the ASF with semantics similar
to the Linux kernel recommendation.

Signed-off-by: Matteo Golin <matteo.golin@gmail.com>
2026-07-12 09:42:28 +08:00
raiden00pl
c3afd427c4 boards/arm/stm32{l5,u5,wb,wl5,n6,h5}: use stm32 boards common
Wire the remaining STM32 families (L5, U5, WB, WL5, N6, H5) to the shared
boards/arm/common/stm32 board-common directory.

No functional change: these boards do not yet use any shared driver, but the
shared board-common features are now available to the families.

Signed-off-by: raiden00pl <raiden00@railab.me>
2026-07-12 09:35:56 +08:00
raiden00pl
d5b78ed9aa arch/arm/src/stm32: unify pulse count driver into common/stm32
Merge the six near-identical pulse count drivers (two common, plus
the F7/H7/H5/L4 copies) into a single common/stm32/stm32_pulsecount.c.

Signed-off-by: raiden00pl <raiden00@railab.me>
2026-07-12 09:35:51 +08:00
raiden00pl
30c5040547 drivers/timers, sched/clock: use file_get/file_put
fs_getfilep()/fs_putfilep() were renamed to file_get()/file_put().

The PTP clock paths still used the old names, breaking the PTP_CLOCK build.

Signed-off-by: raiden00pl <raiden00@railab.me>
2026-07-11 17:22:07 -04:00