nxsig_abnormal_termination() popped the thread's pthread cleanup
handlers in the kernel, so in the protected and kernel builds a process
could get its own code called with kernel privilege by raising a fatal
signal. POSIX runs cleanup handlers on pthread_exit() and on acting upon
a cancellation; termination by a signal is as if by _exit(), which runs
none.
Signed-off-by: Royyan Zahir <royzah@gmail.com>
Add the blank line required by nxstyle between the local declaration and the following statement in task_restart().
Signed-off-by: yushuailong <yyyusl@qq.com>
Kernel threads use the statically allocated g_kthread_group. If initialization of the first kernel thread fails, the common error path currently passes that static object to kmm_free(), corrupting the kernel heap.
Only free dynamically allocated task groups and detach the failed group from the TCB before returning.
Assisted-by: OpenAI Codex
Signed-off-by: yushuailong <yyyusl@qq.com>
group_kill_children() marks the task group as exiting, but task restart reuses that same group. Leaving the flag set causes later group shutdown to skip child termination and changes cancellation behavior for threads created after the restart.
Clear GROUP_FLAG_EXITING after the old child threads have been removed so the reused group starts in its normal state.
Assisted-by: OpenAI Codex
Signed-off-by: yushuailong <yyyusl@qq.com>
Add support for high-cycle flash which can be used for EEPROM emulation.
Assisted-by: Claude:claude-opus-5.5
Signed-off-by: Darryl Ring <darryl@bluerobotics.com>
Select the cache line size from either ARMV7M_DCACHE_LINESIZE or
ARMV8M_DCACHE_LINESIZE, so the driver can also be used with D-cache
enabled on the i.MX RT1180 Cortex-M33.
Also fix the imxrt1180-evk USB DMA allocator alignment. Pad the header
to the 32-byte DMA alignment, so that the buffer remains aligned.
Signed-off-by: Jukka Laitinen <jukka.laitinen@tii.ae>
Fix the usb phy pll bring-up sequence to match the imxrt1170 and
imxrt1180 RM:
1 enable the reference clock for the pll
2 enable the pll regulator
3 release the phy from reset
4 power up the pll
5 configure the pll_sic[pll_div_sel]
Signed-off-by: Jukka Laitinen <jukka.laitinen@tii.ae>
Use Floyd cycle detection on the mutex wait-for chain so only threads that actually participate in a cycle are reported. This avoids omitting the last cycle member and incorrectly including threads that merely lead into a deadlock.
Also handle empty output buffers and document truncation semantics.
Assisted-by: OpenAI Codex
Signed-off-by: yushuailong <yyyusl@qq.com>
Any ecall below CONFIG_SYS_RESERVED reached the context switch and signal
return paths from U-mode: a process could crash the kernel or return to
S-mode through a signal return nobody dispatched.
Signed-off-by: Royyan Zahir <royzah@gmail.com>
Any svc below CONFIG_SYS_RESERVED reached the context switch and signal
return paths from EL0: a process could crash the kernel or return to
EL1 through a signal return nobody dispatched.
Signed-off-by: Royyan Zahir <royzah@gmail.com>
STM32G0B1 devices provide SPI2, but their chip configuration does not
select STM32_HAVE_SPI2. Since STM32_SPI2 depends on that capability,
an explicit CONFIG_STM32_SPI2=y request is dropped by Kconfig.
Select the capability for STM32G0B1 so boards can enable the existing
SPI2 driver. SPI2 remains disabled unless requested. Other chip
families and the driver implementation are unchanged.
The STM32G0B1 datasheet DS13560, section 3.23, documents SPI2:
https://www.st.com/resource/en/datasheet/stm32g0b1re.pdf
Verified before/after configuration on STM32G0B1RE and STM32G0B1CE,
with STM32G071RB as an unchanged control. The same one-line fix is
included in the Golgi STM32G0B1CE firmware build 7248, whose build and
hardware acceptance were recorded on September 25, 2026.
Assisted-by: Codex:GPT-6
Signed-off-by: jsanchez-2g <jsanchez@2g-eng.com>
Describe the GPT timer support on the RA8M1 platform page and the
Arduino shield header's D2-D13 GPIO mapping on the EK-RA8M1 board page,
including the ek-ra8m1:timer-gpio configuration used to test them.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Assisted-by: Claude:claude-sonnet-5
Signed-off-by: leocafonso <leocafonso@gmail.com>
Register GPT0 (32-bit) as /dev/timer0 and GPT9 (16-bit) as /dev/timer1
during bring-up.
Register the Arduino Uno shield header's D2-D5 as inputs and D6-D13 as
outputs through the generic GPIO expander driver, as /dev/gpio0-3 and
/dev/gpio4-11.
Add the ek-ra8m1:timer-gpio configuration (nsh plus both GPT channels,
the GPIO support above, and apps/examples/gpio and
apps/examples/timer_gpio), used to validate the GPT timer driver on
hardware with an oscilloscope.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Assisted-by: Claude:claude-sonnet-5
Signed-off-by: leocafonso <leocafonso@gmail.com>
Add the General PWM Timer (GPT) as a generic timer, registered as
/dev/timerN through the upper-half timer driver. GPT0-7 are 32-bit,
GPT8-13 are 16-bit, and the timeout can be changed while running.
Give each ICU event used by GPT its own enum value instead of a
__COUNTER__-based macro, since the latter can hand out a different
number at every use.
Live period changes to the same prescaler now reload through GTPBR
(the buffered period register) instead of stopping the counter,
matching Renesas's own FSP driver, and fix a hardware-confirmed bug
where an uninitialized GTPBR silently corrupted the period after the
first cycle.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Assisted-by: Claude:claude-sonnet-5
Signed-off-by: leocafonso <leocafonso@gmail.com>
The LPSPI_CCR register is write only in imxrt1180. Therefore, the existing
modifyreg32 calls can't be used to set the fields. Use direct putreg8
writes to update the PCSSCK, SCKPCS, DBT and SCKDIV.
Signed-off-by: Jukka Laitinen <jukka.laitinen@tii.ae>
At imxrt_lpspibus_initialize the code tried to read IMXRT_LPSPI_CR to
detect whether the SPI is already initialized. This doesn't work on
imxrt118x, if the LPSPI clock is still gated. But the gate is
opened only during the initialization. So this is a chicken-egg
problem.
Instead of reading the register, just have an "initialized" flag in
priv.
Signed-off-by: Jukka Laitinen <jukka.laitinen@tii.ae>
The table index and the nesting depth were checked by DEBUGASSERT only,
and arm64 and risc-v let the first number past the table through.
Signed-off-by: Royyan Zahir <royzah@gmail.com>
pgalloc() is a syscall in a kernel build. Its start was checked by
DEBUGASSERT only and its end not at all, so a user task could map pages
past ARCH_ADDRENV_VEND.
Signed-off-by: Royyan Zahir <royzah@gmail.com>
The check CI job runs nxstyle over the whole file once it is touched,
and mmcsd_ioctl()/mmcsd_iocmd() carried pre-existing violations: case
labels and their blocks were indented one level too shallow, and four
argument continuation lines exceeded 78 columns. Reindent the two
switch bodies and rewrap the long call sites (local buffer variables
for the CMD8/18/25 data pointers, operand-per-line for the CMD23
ternary). No functional change.
Signed-off-by: rikaken2004 <244897142+rikaken2004@users.noreply.github.com>
The non-DMA data paths discard the return value of SDIO_RECVSETUP in
mmcsd_readsingle() and mmcsd_readmultiple() and of SDIO_SENDSETUP in
mmcsd_writesingle(), mmcsd_writemultiple() and the CMD56 read/write
helpers, so when the lower half fails to set up the transfer the
driver still issues CMD17/18/24/25/56 and the failure only surfaces
later as an unrelated-looking transfer timeout. The DMA paths in the
same functions all check SDIO_DMARECVSETUP/SDIO_DMASENDSETUP, cancel
the transfer and propagate the error, so mirror that handling on the
non-DMA paths.
Signed-off-by: rikaken2004 <244897142+rikaken2004@users.noreply.github.com>
clock_get_sched_ticks() stored the value of read_seqbegin(), a
uint32_t, in an unsigned int and passed it back to read_seqretry().
Where int is 16 bits the copy is truncated, so once the 32-bit
sequence number passes 65535 read_seqretry() always reports a change
and the loop never ends. The sequence advances once per tick, so after
65536 ticks (11 minutes at 100 Hz) the next caller, the timer interrupt
itself, spins forever with interrupts disabled and the system stops.
Seen on the CDP1802 (16-bit int): NSH stopped answering after 55
minutes at 20 Hz. AVR has the same problem. hrtimer's readers of the
same lock already use uint32_t. Don't assume int is 32-bit :-D
Signed-off-by: Alan Carvalho de Assis <acassis@gmail.com>
Assisted-by: Claude Opus 5.5 (claude-opus-5-5)
O_DIRECTORY, O_NOFOLLOW, O_NOATIME, O_CLOEXEC, __O_SYNC, O_PATH and
__O_TMPFILE are defined as shifts by 16 to 22 bits. Where int is 16
bits (AVR, for example), these shifts exceed the width of the type:
GCC evaluates them to 0, and the -Wshift-count-overflow warning is not
shown because include/ is a system include directory. The oflags
argument of open() is an int, so it could not carry those bits anyway.
As a result, on arch with int equal 16-bit opendir() opens directories
without O_DIRECTORY, so opening a mount point such as /proc fails with
ENOENT, and O_CLOEXEC and O_NOFOLLOW have no effect.
When UINT_MAX is 0xffff, use the unused bits 2 to 4 for O_DIRECTORY,
O_CLOEXEC and O_NOFOLLOW, define O_NOATIME and __O_SYNC as 0 (O_SYNC
falls back to O_DSYNC), and leave O_PATH and O_TMPFILE undefined, so
that code which needs them fails to build instead of silently opening
with the wrong flags; nothing in the tree uses them. _O_MAXBIT becomes
15. On bigger systems (32-bit, 64-bit) keep the original bit shift.
Signed-off-by: Alan Carvalho de Assis <acassis@gmail.com>
Assisted-by: Claude Opus 5.5 (claude-opus-5-5)
A stopped oscillator sets OS in the seconds register and leaves stale
time behind, which the driver returned as the time. Return -EAGAIN, as
it already does before it is enabled, so the clock starts unset instead
of wrong. Setting the time clears OS.
Signed-off-by: Royyan Zahir <royzah@gmail.com>
Document -I, -d, -x and -n, the operators the tool now registers from
the model, how outputs and inputs are handled, and a hostfs example
that runs the hello-world sine model from NSH.
Signed-off-by: Abhishek Mishra <mishra.abhishek2808@gmail.com>
The chip page did not say which build modes the ESP32-S3 supports, how a
KERNEL build uses the MMU, or what happens when user code takes a fault.
Add a section for that, with the console messages of a fault and the
options CONFIG_ESP32S3_USERFAULT_ABORT and CONFIG_ESP32S3_PAGEFAULT.
On the board page, kernel_oct said the shell needs the full path of a
program, but /system/bin is in PATH. Say that instead, describe the
isolation of a process, and show how ostest and sandbox check it. Also
add a section for ksta_softap, which had none.
Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
Under FDPIC an .init_array or .fini_array entry is a code address, but a
C function pointer is a function descriptor. crt0 called each entry
through a function pointer, so it read the constructor's first
instructions as a descriptor and jumped to garbage.
Call each entry with fdpic_call() and the data base from fdpic_base(),
which is the module's own. Without CONFIG_FDPIC both are a direct call,
as before.
Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
DT_REL and DT_JMPREL hold the link-time address of their table, and the
loader read the table at that value as a file offset. The two are equal
only when the segment that holds it starts at file offset 0. An object
linked with its text at file offset 0x1000, as the tree's gnu-elf.ld does,
had its relocations read from padding, so none were applied and the
module called through unrelocated pointers.
Translate the address through the PT_LOAD headers first.
Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
An architecture that sets CONFIG_ARCH_USE_DATA_HEAP gives a loaded module
its data from up_dataheap_memalign(), because the ordinary heap is not where
that data belongs there. The ELF loader honours it for every object but an
FDPIC one: an FDPIC object places its writable segment on its own, and that
allocation, and the two places that free it, still use lib_memalign() and
lib_free(). Its text already comes from the text heap.
So an FDPIC module's data goes to the data heap too, and back to it when the
module is unloaded or removed.
On mps3-an547, which sets both heaps, fdpicxip loaded the data of its two
instances at 0x1007220 and 0x104e480, in the ordinary heap. With this change
they are at 0x21000000 and 0x21000180, in the SRAM2 data heap, and both
instances run. In a protected build the difference matters: there the
ordinary heap is kernel memory, and the module takes a data access violation
on its first access to its data.
Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
set_intr_wrapper() allocates a new intr_handle_data_t from the kernel
heap each time the Wi-Fi driver calls it, and the driver calls it on
every esp_wifi_start() -- twice per start on esp32s3 -- not only the
first time. clear_intr_wrapper() is a no-op, so the IRQ still holds the
handle from the previous start: esp_set_handle() refuses to replace it
with -EINVAL, the return value is ignored, and the new block is lost.
Any application that stops and restarts Wi-Fi to save power therefore
loses a few bytes of kernel heap per cycle, without bound.
Look up the vector descriptor first, then reuse the handle already
registered for the IRQ and only allocate and register one when there is
none. A failed descriptor lookup no longer touches the registered
handle.
The same code is present in the esp32, esp32s2, esp32s3, esp32c3 and
esp32c6 Wi-Fi adapters; all five are fixed the same way.
Signed-off-by: Felipe Moura <moura.fmo@gmail.com>
Assisted-by: Claude Opus 5.5 <noreply@anthropic.com>
A negative channel passed both checks, and TPM took one past the end,
so a caller could write FlexIO and TPM registers it does not own. TPM
also dropped the error and reported success.
Signed-off-by: Royyan Zahir <royzah@gmail.com>
There were some bits erroneously copied from imx9. For IMXRT1180, the
GPIO_AD* and GPIO_AON* pads should have SRE, DSE, PUE, PUS and ODE bits
on SW_PAD_CTL_PAD register.
The GPIO_EMC_*, GPIO_SD_*, GPIO_B1_* and GPIO_B2_* have a bit different fields,
PDRV, PULL and ODE.
Signed-off-by: Jukka Laitinen <jukka.laitinen@tii.ae>
There was a mismatched EXTERN definition for ver3 in imxrt_periphclks.h,
and the extern definitions should be there in imxrt_clockconfig_ver3.h
Signed-off-by: Jukka Laitinen <jukka.laitinen@tii.ae>
Two files each defined the same 16 byte constant, KSTACK_ALIGNMENT and
SIGTRAMP_STACK_ALIGN. Use STACKFRAME_ALIGN, which arch/xtensa/include/irq.h
already gives as 16, with the STACKFRAME_ALIGN_DOWN() of nuttx/irq.h.
STACK_ALIGNMENT is not the name to use here. It is TLS_STACK_ALIGN when
CONFIG_TLS_ALIGNED is set, which is the alignment of a thread stack and not
of a frame.
Assisted-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
The PMS grants and refuses physical addresses, so it never sees an access
that no MMU entry translates. The cache answered such an access with zeros
and raised nothing, and the task carried on with a value it never should
have had.
Enable EXTMEM_MMU_ENTRY_FAULT and route the Cache Invalid Access interrupt
to the handler that already serves the PMS monitors. An unprivileged task
that makes the access is terminated with SIGSEGV; a privileged one still
panics. The latch is level triggered, so it is cleared with the others.
Read the cause before the clear, so the log tells the two apart: a PMS
violation is a refused translation, an MMU entry fault is an access that was
never translated.
Give the kernel_oct configuration the addresses that examples/sandbox needs
to name its targets.
Assisted-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
Reporting a fault can itself fault. syslog reaches memory the fault being
reported may have made unreachable, so esp32s3_pagefault_dispatch() is
re-entered from inside its own _alert() and never returns, and the console
fills with the same half-printed line forever. Found under Espressif's QEMU,
where PSRAM never initialises and the kernel build needs it; the board's
PSRAM works, so hardware does not take this path.
A fault repeating at the same address and PC is not helped by reporting it
again, so the dispatcher tries three times and then halts with interrupts
off. esp32s3_userfault_abort() clears the count through
esp32s3_pagefault_clear_repeat(): reaching it means the fault was contained,
so only unbroken recursion stops the machine, and three probes at one
address do not halt a healthy system.
Verified under QEMU: 12,958,521 bytes of output in 60 s before, four reports
and a halt after. On an ESP32-S3 DevKitC, esp32s3-devkit:kernel_oct, three
identical sandbox probes in one boot are all contained.
Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
When an unprivileged task takes a fault the system cannot recover from, it
now gets a fatal SIGSEGV and only that task ends. A fault in privileged code
still panics.
What decides it is the interrupted context, not the cause: the saved PS says
whether the fault was taken in User Mode. A list of causes would leave every
cause off the list as a way for a user task to stop the machine, and there
are many -- a divide by zero, a privileged instruction, a load/store error,
and an illegal instruction, which is how a refused fetch from kernel text
arrives on this chip (TRM v1.8 p.699: a denied external-memory access is
answered with 0xdeadbeaf instead of trapping). PS.UM is clear in a kernel
thread, in a system call made on the user's behalf and in an interrupt
handler, so those still panic. If the recoverable-fault dispatcher is
enabled it still gets first refusal on causes 28, 29 and 20, the only ones
re-executing can help.
esp32s3_userfault_abort() records the exception frame as the task's context,
dispatches SIGSEGV, and returns the redirected frame, so the vector's RFE
resumes the task in the signal trampoline, whose default action exits it.
CONFIG_ESP32S3_USERFAULT_ABORT enables it, default y wherever there is an
unprivileged world, and selects SIG_DEFAULT and SIG_SIGKILL_ACTION.
Verified on an ESP32-S3 DevKitC with a WROOM-2 module,
esp32s3-devkit:kernel_oct: a user task that writes through NULL, reads a wild
address, divides by zero, calls into a buffer of garbage or branches into
kernel text is terminated on its own, while an unrelated task keeps running.
Stack overflow is not contained. On the windowed ABI it faults inside the
window overflow handler and arrives as a double exception with PS.UM already
clear; guard pages are the answer, and separate work.
Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
Separate the world split from the protected user image, give WORLD1 its own
vector table and its own PMS permissions -- including the PSRAM -- clean up
the user cache-MMU windows, and stop keeping the page pool mapped.
Folds in:
xtensa/esp32s3: separate the world split from the protected user image
xtensa/esp32s3: give the unprivileged world its own vector table
xtensa/esp32s3: give the unprivileged world its permissions
xtensa/esp32s3: clean up the user cache-MMU windows
xtensa/esp32s3: stop keeping the page pool mapped
xtensa/esp32s3: give the PSRAM its own PMS permissions
Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
- Add conditional includes for both 117x/118x headers in hardware/imxrt_ocotp.h
- Add CHIP_ID and UNIQUE_ID addresses in imxrt118x_ocotp.h
- Remove access to those timing registers which don't exist on imxrt117x,
which don't exist on that chip, in imxrt_ocotp_initialize.
Signed-off-by: Jukka Laitinen <jukka.laitinen@tii.ae>
Implement the same initial clock configuration as what imxrt1176 has. Make an own table
for PLL and root clock configurations for m33 and m7 targets. For the PLLs the code still
only supports configuring the ARM_PLL.
The difference to imxrt1176 is, that instead of just boolean .enable field, this table
uses an .action field with 3 states: CONFIGURE, DISABLE and IGNORE. The reason is,
that some root clocks can't be just forcefully stopped, but need a root-clock-specific
sequence. This is solved by just leaving these clocks marked as IGNORE, so they retain
their current state.
Specifically, disabling the SEMC and NETC roots by M33 will prevent the M7 from booting.
Also FLEXSPI shouldn't be touched, if the code is being executed from there.
Also add a function for enabling 24 MHz oscillator clock, and an extendable function to
enable the clock sources based on the clock configuration table.
Assisted-by: Claude Code
Signed-off-by: Jukka Laitinen <jukka.laitinen@tii.ae>