The flash MTD driver disabled interrupts for a whole request. A
multi-block erase or a large write kept them off for seconds.
Erase one 64K block (or one 4K sector where the range is not block
aligned) and program one 256 byte page per step. Enable interrupts and
release the other core between steps. A single block erase is still
long, but that is the limit of the flash.
Also, on SMP:
- Do not send the pause call to the CPU that does the operation.
nxsched_smp_call_single_async() runs it at once on that CPU.
- Keep the isolation data in a static, not on the stack. The other
CPU spins on it while the flash is busy.
Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
After a flash operation the driver called flash_select_xip_read_mode()
with a fixed EBh quad mode and clock divisor 4, and called
flash_enter_cmd_xip() if it "failed". But that ROM function returns
void, so the check read a random r0. The fixed mode and divisor can
also be different from the ones the bootrom found at boot.
The datasheet (5.2.7, 5.4.8.10) and the Pico SDK use a different
method: after a flash boot the bootrom leaves an XIP setup function in
the first 256 bytes of boot RAM. It restores the read mode and clock
divisor found at boot. Boot RAM is not executable, so copy the
function to SRAM once at initialization, and call the copy.
If boot RAM is empty (no flash boot), use flash_enter_cmd_xip(), as
RP23XX_FLASH_MTD_SAFE_XIP does.
Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
The bootrom flash functions reset the QMI window 1 (chip select 1)
registers and the QSPI pads. flash_flush_cache() also discards dirty
XIP cache lines. The flash MTD driver did not save anything, so after
the first erase or program the PSRAM on chip select 1 read garbage,
and PSRAM writes still in the cache were lost.
Do what the Pico SDK hardware_flash library does:
- Clean the XIP cache before the operation. Clean by set/way through
the top of the maintenance window, to avoid erratum RP2350-E11.
- Save the QSPI pads and the five QMI M1 registers before, and write
them back after XIP is restored. Also keep XIP_CTRL.WRITABLE_M1.
rp23xx_psram_restore() was the earlier fix for this, but nothing called
it. Remove it.
Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
The always-on timer has an alarm comparator, but the RTC driver did not
use it: rp23xx_rtc.c implemented only up_rtc_initialize(),
up_rtc_time() and up_rtc_settime().
Add the alarm and an RTC lower half for /dev/rtc0:
- rp23xx_rtc_setalarm(), rp23xx_rtc_cancelalarm() and
rp23xx_rtc_rdalarm() on the ALARM_TIME registers and the POWMAN
timer interrupt.
- An RTC lower half with rdtime, settime, setalarm, setrelative,
cancelalarm and rdalarm, registered by the common board bringup.
The comparator asserts while the time is past the alarm time, not on
a transition. So the interrupt handler disables the alarm before it
does anything else; clearing only the status makes the interrupt
repeat. The arming sequence is the one of
powman_timer_enable_alarm_at_ms() in the Pico SDK.
Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
Indent the flash MTD block as nxstyle wants. Whitespace only; git diff
-w is empty.
Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
setup_period() printed the uint8_t slice number with %d, and the
uint32_t frequency, the uint16_t top and the uint32_t divisor with %lu.
Use %u for the two small fields and PRIu32 for the two uint32_t fields.
No build warns about this today, because GCC does not check syslog
format strings. It shows with CONFIG_DEBUG_PWM_INFO only.
Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
Indent the three else blocks and the switch in rp23xx_pwm_ioctl() as
nxstyle wants. Whitespace only; git diff -w is empty.
Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
The documentation grew one page at a time, so the tree follows the
history of who wrote what and not the shape of NuttX. Scheduling is
spread over three places, a driver page can sit above the subsystem
that owns it, and the front page lists everything at the same level.
That is a lot to face when all you want to know is where the scheduler
lives.
This change files every page under the code it describes. It is a move,
not a rewrite: outside the ten pages named below, every page keeps the
text that is already in master, and no page's text is deleted.
What it does:
* Groups the table of contents into nine chapters.
* Moves the OS subsystems under os/: scheduling, memory, drivers,
filesystem, networking, IPC, interrupts, libs, time.
* Renames the platform pages to the names the source tree uses, and
derives their tags from the tree instead of by hand.
* Splits guides/ by subject.
* Adds Documentation/redirects.py, with a rule for every page that left
its old path, so old URLs keep working. The redirect page also carries
a link's #anchor across to the new page.
Ten pages have text that is new or rewritten. Nine of them are the
landing page of a chapter, which has to exist for the new structure:
index the front page
os/index OS Design
os/scheduling/index Scheduling
os/interrupts/index Interrupts
os/ipc/index IPC
os/time/index Time and timers
about/index About
developing/index Developing NuttX
ReleaseNotes/index Release notes
The tenth is os/libs/libbuiltin, the only page here with technical
content: libs/libbuiltin/ had no page at all. Five SVG diagrams come
with these pages, hand-written XML with no editor metadata.
Nothing outside Documentation/ is touched.
How it was checked:
* Sphinx builds with -W: no warnings, and no document left outside a
toctree.
* A script, offered in the PR, proves the narrow claim this rests on.
For every page outside the ten named above it erases what a move
touches -- link target, path, tag line, toctree block, table border --
from the whole old text and the whole new text, and requires the two
to be byte for byte identical. It also requires every sentence of a
deleted page to turn up somewhere, and every page that left its old
path to have a redirect, from a URL that existed, to where its content
went. It exits non-zero and names the page if any of that is not true,
and it tests added pages too, so forgetting to declare one cannot make
it pass.
* An independent audit checked 133 factual claims on these ten pages
against the tree, one shell command per claim: 130 confirmed, 1
refuted and fixed here, 2 not checkable.
* tools/checkpatch.sh is clean over the range.
The diff is large because moving a page changes every link that points
to it. Most of it is pure renames, and board pages that gained one tag
line.
Assisted-by: Claude:claude-opus-5
SMARTFS_DIRENT_RESERVED uses bits that overlap S_ISUID, S_ISGID, and S_ISVTX. smartfs_stat_common() currently clears only S_IFMT, allowing reserved directory-entry flags to appear in st_mode and ls output as setuid and setgid bits. Preserve only SMARTFS_DIRENT_MODE when constructing st_mode.
Assisted-by: GPT-5.6 Sol
Signed-off-by: Abhishek Mishra <mishra.abhishek2808@gmail.com>
With -mfdpic and -mlong-calls, GCC turns a call to an imported function
in tail position into "ldr r3, [r9, #off]; bx r3". The GOT slot holds
the address of the function descriptor, so the branch goes to the
descriptor in RAM instead of through it, and the core faults. A normal
call loads the code address and the data base from the descriptor
first. GCC 13.2 and 15.3 both do this.
Only an optimized build makes tail calls. The C++ library of
apps/testing/fs/xipfs then faults in its constructor, which ends in a
call to syslog(), and the test stops at "stage the C++ module".
Pass -fno-optimize-sibling-calls with the other FDPIC flags, in the make
build and the CMake build.
Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
GCC before 14 does not pass --fdpic to the assembler when it compiles
with -mfdpic. The assembler then rejects every FDPIC relocation with
"Relocation supported only in FDPIC mode". The NuttX CI image has GCC
13.2, so the crt0.o of an FDPIC configuration does not build there.
Pass -Wa,--fdpic with -mfdpic, in the make build and the CMake build. A
newer GCC passes the same option itself.
Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
gnu-elf.ld.in named neither .rel.plt nor .got.plt, and the linker placed
them where its FDPIC code does not expect them.
It merged .rel.plt into .rel.dyn but still set DT_JMPREL as if .rel.plt
came last, so the loader bound each PLT slot with the symbol of another
relocation. And .got.plt came after .got: the offsets that the linker
gave the local function descriptors did not match where it put them, and
the first call through one jumped into data.
A module without a PLT has neither section, so neither problem showed
until a module called its imports through a PLT.
Give .rel.dyn and .rel.plt output sections of their own, and put .got.plt
first in .got, both as in the linker's own script. Only CONFIG_FDPIC
changes.
Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
With CONFIG_FDPIC, the CMake build gave the FDPIC options to a loadable
module only. A shared library (DYNLIB) got neither -mfdpic nor the FDPIC
link, but the "-r" link of the non-FDPIC case. So the library was a
relocatable object, and a module that named it in DT_NEEDED did not link:
"multiple definition" and "dangerous relocation".
Give a shared library the same options as a module, as LDMODULEFLAGS and
CMODULEFLAGS in common/Toolchain.defs already do for the make build.
Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
libelf_findsymtab() accepted only a SHT_SYMTAB section. A shared object
that strip has processed has no SHT_SYMTAB: only its SHT_DYNSYM remains.
With CONFIG_DEBUG_SYMBOLS the application build strips each module in
bin/, so every FDPIC module that it builds fails to load with "No symbols
in ELF file".
Use the dynamic symbol table of a shared object when it has no other
symbol table. It holds every symbol that the object imports or exports,
which is what the loader looks up. An object with SHT_SYMTAB still uses
it.
Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
The board set LDELFFLAGS to "-r -e main" after it included Toolchain.defs.
This replaced the flags that Toolchain.defs sets for a loadable module.
With CONFIG_FDPIC, a module then links as a relocatable object and not as
an FDPIC shared object. A module that names a library does not link at
all: "attempted static link of dynamic object".
9ed93c6b1e moved these flags into Toolchain.defs for all boards, and
dae3b8e551 removed the same lines from mps3-an547. Remove them here
too.
Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
exec() swaps the pids of the caller and the new task, so that the new
program keeps the pid of the caller. exec_swap() changes tcb->pid and
group->tg_pid. But getpid() and gettid() read the copies in TLS,
tg_info->ta_pid and tl_tid, and exec_swap() does not change them. So
getpid() in the new program returns the pid that the caller has now, and
kill(getpid(), sig) sends the signal to the caller.
Make exec_swap() update both copies for both tasks. The address
environment of the new task is current in exec_swap(). The TLS of the
caller is in the address environment of the caller, so exec_swap()
selects that environment for the update of the caller.
Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
The i.MX95 has five GPIO instances, but g_gpio_base[] only listed the
first four. IMX9_GPIO_BASE(n) indexes this table directly, so any
access to port GPIO5 read one element past the end of the array and
caused a crash.
The table was previously selected on CONFIG_ARCH_CHIP_IMX9_CORTEX_M,
which covers both the i.MX93 M33 and the i.MX95 M7. Since the i.MX93
only has four GPIO instances and does not define IMX9_GPIO5_BASE, key
the five entry table off CONFIG_ARCH_CHIP_IMX95_M7 and keep the four
entry table for the i.MX93 (both the Cortex-A CONFIG_ARCH_CHIP_IMX93
and the Cortex-M CONFIG_ARCH_CHIP_IMX93_M33 variants).
Signed-off-by: Peter van der Perk <peter.vanderperk@nxp.com>
RP23XX_PSRAM_M1_TIMING was the constant 0x61a07102. The comment said
it matched the Pico SDK, but it does not. The SDK computes the timing
from clk_sys and the APS6404 limits (133 MHz SCK, 8 us maximum select,
18 ns minimum deselect). At 150 MHz it gives 0x60242202:
field old SDK
clkdiv 2 2
rxdelay 1 2
max_select 16 18
min_deselect 7 2
select_hold 3 0
The old RX delay samples the read data half a clk_sys cycle earlier
than the SDK does. The constant is also wrong for any other clk_sys.
Compute the fields from BOARD_SYS_FREQ at build time, with the SDK
formula, and stop the build if a field is out of range. The result
is identical to the SDK value at 48, 125, 150, 200, 266 and 300 MHz.
Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
The RP2350 datasheet (12.14.5) says: set DIRECT_CSR.EN, then poll BUSY
until it is low, before the first direct-mode transfer. BUSY stays high
while an XIP transfer is in its cooldown. The Pico SDK waits here too.
rp23xx_psram_detect() did not wait at the two places where it enables
direct mode. It worked on the boards we tested because the cooldown
ended before the first chip select. Add the two waits, and put the
BUSY loop in one RAM-resident helper.
Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
sim_can_work() in sim_cansock.c and sim_canchar.c read a single frame
from the host socket and requeued itself after SIM_CAN_WORK_DELAY
(USEC2TICK(1000), one 10 ms tick with the default sim tick), capping
RX at about 100 frames/s. A burst from the bus was then delivered
over hundreds of milliseconds, and frames from an earlier burst
reached sockets opened later. Loop while frames are available.
Assisted-by: Claude:claude-opus-5-5
Signed-off-by: raiden00pl <raiden00@railab.me>
A module that names a shared library in DT_NEEDED now gets it loaded and
its imports bound against it, rather than being refused.
libelf_insert() does the loading, which is what dlopen() calls anyway: the
library lands in the module registry like anything else, its exports come
back through libelf_getsymbol() -- the same call dlsym() uses -- and a
library named by two modules is loaded once. A bare name is looked for
along LD_LIBRARY_PATH, where dlopen() looks for it. Undefined symbols
resolve against the globally registered symbols first, then the modules
this one depends on, then the table exec() supplied. Nothing here calls
into dlfcn, because this loader is also the kernel's module loader, which
has none.
Each library becomes one of the module's dependencies[], and the dependency
holds it in place of the reference libelf_insert() took. So a library
loaded only for DT_NEEDED is kept by the modules that depend on it, and
libelf_undepend() unloads it with the last of them; one that dlopen() or
insmod also opened stays until that reference goes too.
CONFIG_LIBC_ELF_MAXDEPEND bounds how many libraries a module may name,
which is what it already meant.
Six things had to be fixed to make it work, none of which a build shows.
reldata was a file-scope global. Loading a library from inside
libelf_relocatedyn() makes that function reentrant, so the nested load
overwrote the outer one's relocation offsets and the module resumed binding
with the library's DT_REL. It is now per call.
A cross-object call needs the callee's data base, not the caller's. A
symbol resolved from an FDPIC library comes back as a descriptor, and
R_ARM_FUNCDESC_VALUE was treating it as a code address and pairing it with
the importing module's GOT. It now copies both words, so the library runs
with its own.
An object with no imports has no PLT and so no DT_PLTGOT, but it still has
a GOT and still has to be entered with it. Without the fallback its
descriptors carried a data base of zero and the library read its globals
through a null pointer.
R_ARM_FUNCDESC, a pointer to a descriptor, wrapped a library's descriptor
in a second one. It now stores the library's descriptor as it is.
The flag that says a resolved value is a descriptor was set only for an
import and never cleared, so the next relocation against a symbol of the
module itself took that symbol for a descriptor too. It is cleared there.
libelf_symname() was static, and reading a DT_NEEDED name needs it.
A module with DT_NEEDED is refused where CONFIG_LIBC_ELF_MAXDEPEND is zero,
since that is where the dependency logic is compiled out.
A DT_NEEDED library is one shared instance, its data included, because the
loader returns the object already in the registry. A module started with
exec() is different: that path loads the module afresh each time, so two
running instances have separate data while sharing one copy of the text.
Built for mps3-an547:picostest with CONFIG_FDPIC both ways. Run on
mps2-an500:xipfs under QEMU: fdpicxip solib loads libcounter.so by name out
of DT_NEEDED, two instances share one pinned copy of its text, and the
library is unloaded, and its pin given back, when the second one exits. A
library also opened with dlopen() stays loaded after its DT_NEEDED user
exits, and dlclose() unloads it.
With CONFIG_ARCH_ADDRENV the program runs in its own address space, which
a library libelf_insert() loads cannot reach, so DT_NEEDED is refused
there as before.
Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
Each was an out-of-line function in libc around one bit operation and a
range check. The kernel calls them on its signal paths, often with a
constant signal number, where the check folds away.
Move them into the header as static inline. sigaddset(), sigdelset()
and sigismember() stay in libc and call them as before.
Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
Add an ICACHE section to the STM32H5 platform page. With
CONFIG_STM32_ICACHE the OTP, read-only and EDATA flash areas are mapped
non-cacheable with an MPU region, so they can be read like any other
memory.
The MPU is not applied in the HardFault and NMI handlers (HFNMIENA=0),
so these areas must not be read from NMI or HardFault context: with the
ICACHE enabled such a read raises a bus fault.
Assisted-by: Claude:claude-sonnet-5-5
Signed-off-by: Ricardo Maurizio Paul <ricardopaul@geotab.com>
The ICACHE driver now maps the OTP, read-only and EDATA flash areas
non-cacheable with an MPU region. Say so in the peripheral support
table.
Assisted-by: Claude:claude-opus-5-5
Signed-off-by: Ricardo Maurizio Paul <ricardopaul@geotab.com>
An enabled ICACHE does not manage write transactions: it flags cacheable
writes as errors (ICACHE_SR.ERRF), and RM0481 8.4.5 recommends modifying
the memory with the ICACHE disabled. On an STM32H563, erasing and
programming a flash block with the ICACHE enabled leaves ICACHE_SR at
0x6 (BSYENDF and ERRF set).
The ICACHE also keeps serving lines cached before the change. When the
block had been read through the ICACHE just before it was programmed,
up_progmem_write() failed its read-back check with -EIO: the flash held
the new data, with no flash or ECC error flagged, but the read-back hit
the cached erased data. up_progmem_eraseblock() fails its erased-range
check the same way when programmed data of the block is cached.
Disable the ICACHE for the duration of up_progmem_eraseblock() and
up_progmem_write(), and enable it again afterwards if it was enabled on
entry. Disabling it invalidates it, so the refill after re-enabling it
sees the new flash content.
If the ICACHE cannot be re-enabled because its invalidate times out, it
is left disabled, which is safe but slower, and an error is logged.
Assisted-by: Claude:claude-sonnet-5-5
Assisted-by: Claude:claude-opus-5-5
Signed-off-by: Ricardo Maurizio Paul <ricardopaul@geotab.com>
A bootloader may hand over with the ICACHE enabled, and nothing waits for
the invalidate that runs when the ICACHE is disabled. The driver also
polled BUSYF without a bound, so a stuck flag would hang the boot, and it
ignored an invalidate that never finished.
- stm32_enable_icache(): on first use, disable and invalidate the ICACHE
before the associativity and region registers are written (they are
only writable while EN=0), and wait for any pending invalidate before
enabling it (RM0481 8.4.5).
- stm32_disable_icache(): wait for the invalidate that EN=0 starts and
clear BSYENDF and ERRF.
- Bound every BUSYF wait with STM32_ICACHE_BUSY_TIMEOUT. RM0481 gives no
invalidate duration, so the value is a margin, not a measured limit.
- stm32_enable_icache() now returns OK or -ETIMEDOUT instead of void. On
a timeout the ICACHE is left disabled: with BUSYF stuck it would not
cache anything anyway (RM0481 8.4.5). Existing callers ignore the result
and keep working.
- __start: when CONFIG_STM32_ICACHE is not set, disable an ICACHE left on
by a bootloader, so reads of the OTP and UID cannot fault. On an
STM32H563 with the ICACHE left enabled this way, a 16-bit read of the
UID raised a precise bus fault and up_progmem_write() failed its
read-back check with -EIO.
Assisted-by: Claude:claude-sonnet-5-5
Signed-off-by: Ricardo Maurizio Paul <ricardopaul@geotab.com>
stm32_get_uniqueid() and flash_read_eccsafe16() (OTP and EDATA word
reads) disabled the ICACHE around their reads and enabled it again
afterwards, so that the read did not go through the ICACHE. The MPU
region added by the previous commit makes these areas non-cacheable, so
the reads bypass the ICACHE anyway.
Remove the disable/enable pairs. Each pair also invalidated the whole
ICACHE, and flash_read_eccsafe16() did it with interrupts disabled, twice
for every 32-bit OTP read.
The MPU is not applied in the HardFault and NMI handlers (HFNMIENA=0),
so a UID read from those handlers is no longer protected. Nothing in the
tree does that.
Assisted-by: Claude:claude-opus-5-5
Signed-off-by: Ricardo Maurizio Paul <ricardopaul@geotab.com>
The OTP, read-only (UID, flash size, package) and high-cycle data (EDATA)
flash areas only accept 16/32-bit accesses and return a bus error
otherwise (RM0481 Table 77). The manual requires the MPU to disable local
cacheability for them (RM0481 7.3.2); with the ICACHE enabled and no such
region, reading them raises a precise bus error.
Until now this was worked around piecemeal: the driver disabled the
ICACHE around stm32_get_uniqueid() and the OTP and EDATA word reads, and
nucleo-h563zi mapped the 4 KB OTP/RO area non-cacheable in its board
code. Other reads, for example stm32_otp_read() or an application
reading the OTP on another board, still raised a precise bus error when
the ICACHE was enabled.
Map 0x08fff000-0x09017fff, which covers the three contiguous areas, as
Normal non-cacheable and execute-never with a single MPU region before
the ICACHE is enabled. STM32_ICACHE now selects ARM_MPU so that
stm32_mpuinitialize() has reset and enabled the MPU by then.
Remove the nucleo-h563zi OTP region in the same commit: the Armv8-M MPU
faults on an address that matches more than one region, so keeping both
would make OTP and UID reads fault on that board.
Assisted-by: Claude:claude-sonnet-5-5
Assisted-by: Claude:claude-opus-5-5
Signed-off-by: Ricardo Maurizio Paul <ricardopaul@geotab.com>
An ICACHE build with no ICACHE region configured warns about two unused
symbols:
- stm32_icache_setup_region() is only called when one of the
CONFIG_STM32_ICACHE_REGION0..3 options is set, so build it only then.
- 'regval' in stm32_icache_initialize() is only used with
CONFIG_STM32_ICACHE_DIRECT, so declare it only then. The interrupt
block gets its own local variable.
No functional change.
Assisted-by: Claude:claude-sonnet-5-5
Signed-off-by: Ricardo Maurizio Paul <ricardopaul@geotab.com>
Marks DTC as supported in the peripheral table (normal mode only, used
by SCI) and documents the SCI driver features: the per-instance
FIFO/DTC mutual exclusion and the measured overrun-margin trade-off
between them, termios TCGETS/TCSETS support (tested up to 2 Mbps), and
TIOCGICOUNT's frame/overrun/parity counters. Adds SCI0's pinout and
the new serial-test config to the EK-RA8M1 board page.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Assisted-by: Claude:claude-sonnet-5
Signed-off-by: leocafonso <leocafonso@gmail.com>
board.h gains GPIO_SCI0_RX/TX (P610/P609, SCI0 pin group 3), needed to
exercise CONFIG_RA_SCI0_UART on this board at all -- previously only
SCI9's console pins existed.
The new serial-test defconfig builds on nsh with SCI0 enabled as
/dev/ttyS1 with its FIFO (CONFIG_RA_SCI0_FIFO, measured on hardware as
the best overrun-resistant setting: TTRG=15, RXTRG=0), 1024-byte RX/TX
ring buffers (up from the 256-byte default, to better absorb bursts
during testing), CONFIG_SERIAL_TERMIOS + apps/system/stty (to change
its baud rate live), and apps/examples/serialblaster + serialrx
pointed at it, for exercising the SCI_B driver's FIFO/overrun-recovery
paths independently of the SCI9 console.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Assisted-by: Claude:claude-sonnet-5
Signed-off-by: leocafonso <leocafonso@gmail.com>
Adds the Data Transfer Controller (DTC) as a generic register-triggered
DMA engine (ra_dtc.c/.h, hardware/ra8m1_dtc.h, CONFIG_RA_DTC, normal
mode only), and generalizes SCI_B's 16-stage FIFO and DTC support from
SCI9-only to every instance (SCI0-4, SCI9): CONFIG_RA_SCIn_FIFO and
CONFIG_RA_SCIn_TXDTC/RXDTC are mutually exclusive, not combinable --
TX DTC moves queued ring-buffer data in the background through
CONFIG_SERIAL_TXDMA, RX DTC moves each byte as it arrives, and measured
on hardware the FIFO's standing multi-byte buffer gives far better
high-baud overrun margin than this one-byte-per-activation RX DTC
design, which also had a real arming bug fixed here (up_rxint()'s old
"first enable" check could never fire, so the DTC was never armed),
alongside a FIFO register-clear/ordering fix. up_ioctl() also gains
TCGETS/TCSETS (baud rate, parity, stop bits), board.h gains SCI0's
GPIO pins (P609/P610) to exercise it on this board, and comments
throughout ra_serial.c/Kconfig are condensed from the narrative
debugging form they accumulated down to the essential fact each one
needs. Tested on hardware: SCI0 and SCI9 simultaneously, FIFO and DTC
independently and mutually exclusive; FIFO (TTRG=15/RTRG=0) holds up
cleanly to 3 Mbps for transfers within the RX ring buffer, well past
RX DTC's ceiling (see below).
A separate, more serious bug was also found and fixed while hardware-
testing the overrun path at high baud: up_erinterrupt() never cleared
its ICU IELSRn.IR flag (RA8M1 User's Manual section 13.5.1 is explicit
that this causes the NVIC to re-enter the handler indefinitely), which
livelocked the whole system on any receive error, in every
configuration, not something specific to this series. Fixed by
clearing it like the other two SCI interrupt handlers already did, by
draining RDR/the FIFO on an error before clearing it (SCIn_ERI fires
instead of SCIn_RXI for every receive error, so data already received
was otherwise never picked up), and by having the RX DTC path also
recognize a byte stuck via CSR.RDRF directly, not just its own
bookkeeping, since its event can be silently dropped by the ICU while
an earlier byte's IR is still pending. Also added CONFIG_SERIAL_
TIOCGICOUNT (frame/overrun/parity counters via the standard
TIOCGICOUNT ioctl), matching stm32's precedent, since nothing in the
generic NuttX serial core surfaces a receive error to an application
otherwise. Confirmed on hardware: nsh on SCI9 stays fully responsive
through a sustained 3 Mbps overrun on SCI0 that previously froze the
whole board.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Assisted-by: Claude:claude-sonnet-5
Signed-off-by: leocafonso <leocafonso@gmail.com>
Add an opt-in STM32N6_DEBUG setting to reopen the debug access port and
secure/non-secure debug at the current BSEC protection level. Enable the
BSEC clock and configure access before clock and memory initialization so
a debugger can attach to a flash-booted development image.
Assisted-by: Codex:GPT-6
Signed-off-by: raiden00pl <raiden00@railab.me>
In the nominal ROM clock configuration, flash boot leaves PLL1 driving
the CPU at 400 MHz. Skipping clock setup when PLL1 is already selected
makes SysTick run twice as fast as the board's 200 MHz configuration
expects.
Switch CPU and system clocks to HSI before reconfiguring PLL1, then apply
the board clock tree.
Remove the incorrect comments claiming CFGR1 and CFGR2 lock after the first
clock switch.
Assisted-by: Codex:GPT-6
Signed-off-by: raiden00pl <raiden00@railab.me>
Add stm32h7s8-dk board support for nsh running out of internal flash,
including LEDs and user button.
Signed-off-by: Peter Barada <peter.barada@gmail.com>
spi_setfrequency() in pic32mz_spi.c rounded the baud rate divisor down,
so the SCK frequency could be higher than the one requested by the
device driver (e.g. 20 MHz requested with a 100 MHz PBCLK2 gave 25 MHz).
A request above PBCLK/2 gave a zero divisor and a division by zero when
computing the actual frequency; the SST26 driver's default of 64 MHz
does that with any peripheral bus clock below 128 MHz.
Round the divisor up instead, so the actual frequency never exceeds the
requested one and the divisor is never zero. Boards whose requested
frequency is not an exact divisor of PBCLK/2 now run SPI at a lower
clock than before.
Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Daniel P. Carvalho <danieloak@gmail.com>