Commit graph

25297 commits

Author SHA1 Message Date
raiden00pl
a8ac2e74e0 arch/nrf52: add SAADC external TIMER trigger over PPI
The SAADC internal sample timer only works with a single enabled
channel, so hardware-timed multi-channel scan was not possible.  Add
NRF52_SAADC_TIMER_PPI, a third trigger mode in which a general-purpose
TIMER compare event is routed to TASKS_SAMPLE over PPI.  All enabled
channels are scanned, and the TIMER prescaler allows much lower sample
rates than the internal timer, which is limited to 16MHz/CC with CC in
80..2047.

NRF52_SAADC_CONTINUOUS is no longer tied to the internal timer and
works with either source.  Its EasyDMA buffers now hold
NRF52_SAADC_CONTINUOUS_BUFLEN whole scans rather than that many single
samples, so MAXCNT becomes chan_len * BUFLEN.  Samples are interleaved
scan by scan, so a channel map is built once at configure() time and
passed to the upper half with the batch; the upper half already accepts
a per-sample channel array.  A single-channel configuration produces
the same MAXCNT and the same delivery as before.

Because both features want a PPI channel, add a build-time check that
NRF52_SAADC_PPI_CHANNEL and NRF52_SAADC_CONTINUOUS_PPI_CH differ, and
constrain the latter under the SoftDevice controller like the former.

NRF52_SAADC_CHANNELS gains a default and range for the new mode, and
documents that the internal timer is restricted to one channel.

Assisted-by: Claude Code
Signed-off-by: raiden00pl <raiden00@railab.me>
2026-09-28 11:20:31 +02:00
Justin Hammond
2bd1334ec4 arch/risc-v/eic7700x: Describe the pads through procfs.
Implements the pinctrl get_pad method, so /proc/pinctrl and
PINCTRLC_GETPAD carry what this block is actually holding: each layout's
common fields with their validity bits, and the layout's own fields, the
RGMII and mode-select voltage bits and the oscillator tuning, as
key:value text.

Names every pad and every documented function select in one
PINCTRL_PADNAME() table, so func:2 on S_MODE reads as GPIO94 rather than
as a number.  The names are the manual's own; a pad's name describes its
default function, not its current one.  The table costs about 9 KiB and
is built only with the file that reads it; the name helpers return NULL
without it and the strings stay empty.

Assisted-by: Claude:claude-opus-5
Signed-off-by: Justin Hammond <justin@dynam.ac>
2026-09-28 16:19:01 +08:00
Justin Hammond
830eab5f81 arch/risc-v/eic7700x: Describe and configure the pads.
Every ball on this SoC is shared between several functions, and nothing
in this port could see which function a pad carried or change it.  A
driver that finds nothing cannot tell a dead block from a pad still
pointed somewhere else.

Registers the CLMM pad multiplexer with the pinctrl framework and defines
every pad and every function select the manual documents, across the
straps, JTAG, PCIe, HDMI, Ethernet, I2S, SPI, GPIO, USB, I2C, UART, fan
and MIPI CSI groups.  Writes nothing at start up: a pad only moves when a
driver asks.

eic7700x_pinctrl_count() reports how many pads currently differ from
their reset defaults, which after boot is the set the boot loader and the
drivers have configured; the board start up logs it.

Assisted-by: Claude:claude-opus-5
Signed-off-by: Justin Hammond <justin@dynam.ac>
2026-09-28 16:19:01 +08:00
Marco Casaroli
c9cd9db25f tools/nxflat: Add an Apache-licensed NXFLAT converter.
ldnxflat is the last piece of the NXFLAT toolchain that NuttX cannot carry.
It descends from elf2flt through four sets of copyright holders, so it is GPL
by that descent and not merely by its libbfd dependency.  This is a new
implementation, written from include/nxflat.h, from what binfmt/libnxflat does
with the container, and from the ELF specification.  The relocation arithmetic
is that of libs/libc/machine/arm/armv7-m/arch_elf.c, which the ELF loader runs
on the target for the same relocations, and which brings R_ARM_TARGET1 with
it.

NXFLAT is not an ARM format.  Its loader only adds a base to a 32-bit word, so
the segments, the GOT, the relocation records and the header are common to
every architecture.  An architecture supplies a table entry, an entry-point
convention and a relocation handler; an object for a machine with no entry is
refused by name.

The GOT is built here, because ld -r emits none: one entry per symbol that a
GOT-relative reference names, at the start of D-Space, each with a relocation
record of its own.  An entry may hold a function, which is what makes a
function pointer reached through the GOT work.

Two defects of the out-of-tree tool do not survive.  A GOT entry naming a .bss
object lost its section's address and pointed at the start of D-Space, the GOT
itself, so on lm3s6965-ek:qemu-nxflat the longjmp test panics with PC 0 and
the five tests after it never run.  The alignment gap before .bss went missing
from h_bssend as well, leaving D-Space short.

The tool is built and named like the rest of the toolchain.  Makefile.host
builds it, Unix.mk makes a configuration that sets CONFIG_NXFLAT depend on it
beside mknxflat, and LDNXFLAT points at the tool in the tree rather than one
on PATH.

All eight C modules of apps/examples/nxflat/tests convert and run to
completion under qemu-system-arm -M lm3s6965evb.

Assisted-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
2026-09-27 11:25:12 -03:00
Marco Casaroli
60d01d779f arch/arm: Reach an NXFLAT module's read-only data through the GOT.
A module's D-Space is separate from its I-Space, so its read-only data is not
at a fixed offset from its text.  GCC assumes that it is and loads a string
literal PC-relative, which reads I-Space at run time.  A module could
therefore carry no string and reach no static.

lm3s6965-ek has had -mno-pic-data-is-text-relative in its own Make.defs since
2021 (issue #3737), and the CMake build gives it to every PIC configuration,
so the flag moves to where it belonged and the board's copy goes.  That copy
also probed for GCC older than 4.9.4, which NuttX no longer supports.  Clang
has no such option, hence the guard.

Assisted-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
2026-09-27 11:25:12 -03:00
Royyan Zahir
f7f8107a0a arch/arm64/imx9: add an ELE-backed /dev/random driver.
The i.MX9 has a true random number generator behind the EdgeLock Enclave
and imx9_ele_get_random() to reach it, but nothing registers a character
device for it, so the entropy pool is never seeded from hardware. stm32h7,
nrf52, lpc54xx and rp23xx all provide one; imx9 does not.

imx9_ele.c was built only for CONFIG_IMX9_BOOTLOADER, putting the enclave
out of reach of the application core. It moves behind a new CONFIG_IMX9_ELE
that the bootloader selects, so existing configurations build as before.

A transfer that never lands is silent, so the buffer is prefilled with a
pattern and a block still holding it is refused, as is an all-zero block
and, by the FIPS 140-2 continuous test, a repeat of the one before.

Compiles for imx93-evk:nsh with CONFIG_IMX9_RNG=y.

Signed-off-by: Royyan Zahir <royzah@gmail.com>
2026-09-27 11:02:13 -03:00
zhanghongyu
53ac762e79 drivers/vhost: Optimize vhost-net performance and robustness
Suppress the peer notifications while a ring keeps delivering work, batch
the receive completions into one kick per burst and drop the redundant
txdone signal from the transmit path.  Validate the peer controlled frame
lengths, accept descriptor chains on both lanes, keep every ring access on
the upper half's work thread so the interrupt context callbacks stay lock
free, and prefer the MAC from the configuration space, falling back to the
Kconfig address or a random one.

Signed-off-by: zhanghongyu <zhanghongyu@xiaomi.com>
2026-09-27 18:41:30 +08:00
Marco Casaroli
1bc7cfeeb1 arch/xtensa: Provide POSIX fork() on the ESP32-S3.
up_addrenv_fork() duplicates an address environment into freshly allocated
pages mapped at the same virtual addresses.  The text, data and heap regions
of the source are walked one page at a time and copied into fresh pages hung
off the child's own directory, using the two kmap slots that
CONFIG_ARCH_KMAP_NPAGES reserves for exactly this.

xtensa_fork.c already took both paths:  a child that keeps the parent's stack
addresses needs no relocation, which is what a duplicated address environment
gives it.  Only the hook and the Kconfig default were missing.

fork() is offered on a kernel build, which is the only mode with per-process
address environments.

Verified on an ESP32-S3-WROOM-2 with esp32s3-devkit:kernel_oct.  ostest
reports "Parent and child had independent memory" and exits with status 0.

Assisted-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
2026-09-26 11:13:57 -03:00
Marco Casaroli
ce59fb6e71 xtensa/esp32s3: Reach a page pool page through a scratch mapping.
The page pool is carved out of the PSRAM that user processes run from, and
the external memory permissions are indexed by physical address, so a
permanent kernel window onto the pool is a window onto every process, which
no permission setting can close.

Stop mapping the pool.  The kernel reaches a pool page through a small
scratch region instead, mapped for one operation and invalidated afterwards.
esp32s3_pgmap() takes a slot, esp32s3_pgunmap() releases it, and
ARCH_KMAP_VBASE and ARCH_KMAP_NPAGES describe the region.  Two slots are
enough, because the deepest user is up_addrenv_fork(), which holds a source
and a destination page at once.

Assisted-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
2026-09-26 11:13:57 -03:00
Marco Casaroli
f14e807c11 xtensa/esp32s3: Wire the chip into the kernel build.
The common Xtensa BUILD_KERNEL support needs the chip to say what it can do
and where its memory goes.

The chip selects the address environment options it now implements, keeps the
kernel and user heaps apart, and the linker scripts separate kernel from user
text and data so the two worlds can be given different permissions.

kernel_oct configures a board for it, with the user-program layout and the
boot ROMFS a kernel build loads its programs from.  The ROMFS placeholder is
rebuilt with the image, the generated copy is ignored, and the programs are
given stack sizes and room for a fork() child.

Assisted-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
2026-09-26 11:13:57 -03:00
Marco Casaroli
54419e870d xtensa/esp32s3: Implement per-process address environments.
Give the ESP32-S3 the arch_addrenv_t machinery that BUILD_KERNEL needs:  a
per-process page directory built from the 64 KiB MMU pages of the chip, with
allocation, teardown, and the vaddr-to-paddr translation that the kernel uses
to reach a user buffer.

The MMU, PMS and WCL primitives are exposed as an arch API first, because the
address environment code and the protected user split both need them and
neither owns them.

Assisted-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
2026-09-26 11:13:57 -03:00
Marco Casaroli
54fcbe888b xtensa/esp32s3: add recoverable cache-attribute fault dispatcher (Unit B)
Route the precise cache-attribute permission faults -- Load/Store/InstrFetch
Prohibited (EXCCAUSE 28/29/20) -- from xtensa_user() to a new dispatcher,
esp32s3_pagefault_dispatch().  On a serviced fault the register frame is
returned so the exception vector's RFE re-executes the faulting instruction;
otherwise it declines to the existing panic path.  Gated by
CONFIG_ESP32S3_PAGEFAULT (default n, depends on BUILD_PROTECTED); the build
is unchanged when the option is off.

This is the recoverable-fault primitive the address-environment / demand-paging
work builds on.  Proven on the ESP32-S3-DevKitC WROOM-2:

- A precise LoadProhibited carries a tracking EXCVADDR (the exact faulting
  address), and RFE cleanly re-executes the faulted load on return -- verified
  with CONFIG_ESP32S3_PAGEFAULT_SELFTEST (the identical instruction restarts
  three times, then steps past, and the task resumes with the shell alive).
- ESP32-S3 PMS (World Controller) permission violations are NOT delivered as
  these precise causes; they raise the asynchronous DRAM0/IRAM0 PMS-monitor
  interrupt, so PMS is an isolation (kill) mechanism, not a restartable one.

No regression: esp32s3-devkit:knsh (WROOM-2) boots to nsh and ostest passes
with the option enabled.

Assisted-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
2026-09-26 11:13:57 -03:00
Jukka Laitinen
63208908ac arch/arm/imxrt: Allow serial console in uarts 9-12
iMXRT118x may have up to 12 uarts. Allow setting the console also on those.

Signed-off-by: Jukka Laitinen <jukka.laitinen@tii.ae>
2026-09-26 17:05:47 +08:00
Jukka Laitinen
c64d30dbbc arch/arm/imxrt: Clean up TRDC configuration
The TRDC (Trusted Resource Domain Controller) configuration should be completely
driven by the board configuration, and not hard-coded:

- Add tables for the current GPIO configuration and MDA configuration.
- Fix the GPIO configurations for M7; previously GPIO access from M7 was
  denied because of secure/nonsecure setting.

Signed-off-by: Jukka Laitinen <jukka.laitinen@tii.ae>
2026-09-26 17:05:34 +08:00
Jukka Laitinen
6ef704ee83 arch/arm/imxrt: Fix imxrt118x rgpio compiler warning
Move GPIO_PIN definition from imxrt118x_gpio.h to imxrt_rgpio.h to
remove redefinition warning.

Signed-off-by: Jukka Laitinen <jukka.laitinen@tii.ae>
2026-09-26 17:05:34 +08:00
jsanchez-2g
463d8a71d7 arch/arm/stm32h7: Dump FDCAN Rx/Tx FIFO status registers.
fdcan_dumpregs() printed the Rx FIFO 0 and Tx buffer configuration
registers (RXF0C, TXBC) but not their live status counterparts
(RXF0S, TXFQS), and did not print the Rx FIFO 1 configuration or
status registers (RXF1C, RXF1S) at all.

Add the missing RXF1C configuration line and the RXF0S, RXF1S, and
TXFQS status lines so every configured FIFO/buffer's fill-level
state is visible alongside its configuration, matching the existing
dump grouping.

Convert fdcan_dumpregs() from printf() to ninfo(), matching the
logging convention already used elsewhere in this file
(ninfo/nerr), per upstream review feedback.

Compile-tested: boards/arm/stm32h7/nucleo-h743zi2/configs/socketcan
with CONFIG_STM32_FDCAN_REGDEBUG=y, CONFIG_DEBUG_INFO=y.

Assisted-by: Claude:claude-sonnet-4.5
Signed-off-by: jsanchez-2g <jsanchez@2g-eng.com>
2026-09-26 09:59:13 +08:00
Marcio Ribeiro
25a3aaaa9d arch/risc-v/esp32c2: add ESP32-C2 chip support
Introduce RV32IMC chip architecture with HAL integration and Espressif
common Kconfig for the ESP8684 SoC, including XTAL, UART0 pin range,
and SPI flash clock options.

Assisted-by: Claude:claude-opus-5
Signed-off-by: Marcio Ribeiro <marcio.ribeiro@espressif.com>
2026-09-25 21:08:00 +08:00
Marco Casaroli
5513029711 arch/arm: Build a loadable module and a shared library as FDPIC too.
CONFIG_FDPIC teaches the ELF module path what an FDPIC object is, so an
application built as a module gets -mfdpic -fPIC and the
arm-uclinuxfdpiceabi linker.  The loadable module path, which apps builds
with DYNLIB = y and which apps/Library.mk uses for a shared library, was
left as it was: a -r partial link with the stock linker.  That leaves an
object with no dynamic section, so the loader has nothing to bind an import
to, and there is no way to build a library an FDPIC module can call.

Give that path the same treatment.  CMODULEFLAGS and CXXMODULEFLAGS gain the
FDPIC compiler flags, and LDMODULEFLAGS links a shared object rather than a
partial one.  The entry point is left to the caller, because a module is
entered at _start while a library is only ever called into.

CXXMODULEFLAGS is also defined for the first time.  apps/Library.mk compiles
every C++ source of a shared library with it and no architecture defined it,
so those sources were compiled with no architecture flags at all.

Assisted-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
2026-09-25 09:56:10 -03:00
Austin.Chen
5197329b67 arch/arm/stm32h5: add SDMMC1/SDMMC2 driver
Add the STM32H5 SDMMC1/SDMMC2 lower-half SDIO driver (interrupt-mode and
IDMA transfers, SD/SDIO card mode), following the same structure as the
existing STM32H7 SDMMC driver.

Three fixes were needed to get this actually building, selectable, and
correct:

- The driver checked CONFIG_STM32H5_SDMMC1/CONFIG_STM32H5_SDMMC_IDMA/
  CONFIG_STM32H5_SDMMC_XFRDEBUG, but the real Kconfig symbols selected by
  this chip are the shared CONFIG_STM32_SDMMC1/CONFIG_STM32_SDMMC_IDMA/
  CONFIG_STM32_SDMMC_XFRDEBUG (see arch/arm/src/common/stm32/Kconfig.sdio,
  Kconfig.periph). With the old names the driver silently compiled out.
  Renamed all guards in stm32_sdmmc.c to match. Also fixed a similar typo,
  STM32H5_SRAM3_SIZE -> STM32_SRAM3_SIZE, in the IDMA-reach check.

- arch/arm/src/common/stm32/Kconfig.sdio's STM32_SDMMC_IDMA and the
  SDMMC1/2 SDIO-mode/pull-up options depended on ARCH_CHIP_STM32H7 /
  STM32_COMMON_F7_H7 only. Extended STM32_SDMMC_IDMA to also allow
  ARCH_CHIP_STM32H5, and switched the SDIO-mode/pull-up options to
  STM32_COMMON_F7_H7_H5, matching the pattern already used for other
  STM32H5 peripherals (Ethernet, ADC, SPI, timers).

- stm32_sdmmc.c was only added to Make.defs, not to CMakeLists.txt, so
  the driver would silently be omitted from CMake builds. Added it to
  the same unconditional source list as stm32_exti_gpio.c.

Also ports a fix from a related STM32H7 SDMMC commit
(2cb7b7c03e): stm32_recvdma()'s aligned
IDMA receive path invalidated the destination buffer before the DMA but
never again after it completed, so a speculative cache prefetch into
that buffer between those two points could shadow the freshly-received
data with a stale line. Added the missing post-DMA invalidate, matching
the pattern already used elsewhere on this chip for other DMA-capable
peripherals (e.g. stm32_ethernet.c's RX path).

Needed for a custom STM32H5 board that uses SDMMC1 in SDIO mode with
IDMA to talk to an onboard WiFi module.

Co-authored-by: Liam Howatt <liamhowatt@geotab.com>
Signed-off-by: Marwan Madkour <marwanmadkour@geotab.com>
2026-09-25 18:30:40 +08:00
raiden00pl
425e77e44e arch/nrf52,nrf53,nrf91: fix nxstyle issues
arch/nrf52,nrf53,nrf91: fix nxstyle issues

Signed-off-by: raiden00pl <raiden00@railab.me>
2026-09-25 18:24:36 +08:00
raiden00pl
058da97e95 arm/nrf52,nrf53: fix SAADC channel limit register value
CHLIMIT was written with (limith < 16) | limith, which put the high
limit into the low field and a boolean into bit 0. Shift the high
limit to bits 16-31 and the low limit to bits 0-15.

Assisted-by: Claude Code
Signed-off-by: raiden00pl <raiden00@railab.me>
2026-09-25 18:24:36 +08:00
raiden00pl
574bbf618f arm/nrf52,nrf53,nrf91: fix SPI sndblock ops field
The non-exchange ops table initialized .sndlock, which does not exist
in struct spi_ops_s and fails to compile without CONFIG_SPI_EXCHANGE.

Assisted-by: Claude Code
Signed-off-by: raiden00pl <raiden00@railab.me>
2026-09-25 18:24:36 +08:00
raiden00pl
e5e06d6bde arm/nrf52,nrf53,nrf91: fix PWM driver bugs
- SEQSTARTED0 and STOPPED events were not cleared before waiting for
  them, so the second start or stop returned immediately
- PWM_DECODER_MODE_* shifted 8 instead of shifting to bit 8
- PWM_PSEL_PIN_MASK and PWM_PSEL_PORT_MASK referenced TWI shift names
- PWM_PSEL_CONNECTED described the disconnected state

Assisted-by: Claude Code
Signed-off-by: raiden00pl <raiden00@railab.me>
2026-09-25 18:24:36 +08:00
raiden00pl
c8f699a4e3 arm/nrf52,nrf53,nrf91: fix GPIOTE driver bugs
- set_port_event checked the wrong port when deciding whether the
  PORT interrupt can be disabled
- set_event could pick a free channel instead of the one already
  assigned to the pin
- LATCH registers were cleared by writing zeros
- header declared nrfxx_gpio_set_task for a function defined as
  nrfxx_gpiote_set_task

Assisted-by: Claude Code
Signed-off-by: raiden00pl <raiden00@railab.me>
2026-09-25 18:24:36 +08:00
raiden00pl
f86b05351f arm/nrf52,nrf53,nrf91: fix RTC driver bugs
- setcc/getcc accepted channel index equal to the channel count
- init never marked the instance as in use
- NRFxx_RTC_GETCC called setcc instead of getcc

Assisted-by: Claude Code
Signed-off-by: raiden00pl <raiden00@railab.me>
2026-09-25 18:24:36 +08:00
raiden00pl
d490c80df2 arm/nrf52,nrf53,nrf91: fix TIMER driver bugs
- setcc/getcc accepted channel index equal to the channel count
- init never marked the instance as in use
- TIM_PRESCALER_MASK used the maximum value as the mask

Assisted-by: Claude Code
Signed-off-by: raiden00pl <raiden00@railab.me>
2026-09-25 18:24:36 +08:00
raiden00pl
0942bae6ef arm/nrf54l: add GRTC and tickless scheduling
arm/nrf54l: add GRTC and tickless scheduling

Assisted-by: Codex:GPT-6
Signed-off-by: raiden00pl <raiden00@railab.me>
2026-09-25 10:48:00 +02:00
raiden00pl
04d2c9013c arm/nrf54l: add TIMER support
arm/nrf54l: add TIMER support

Assisted-by: Codex:GPT-6
Signed-off-by: raiden00pl <raiden00@railab.me>
2026-09-25 10:48:00 +02:00
rongbaichuan
00a379c3f7 sched/semaphore: Fix pre-existing nxstyle issues in the touched files
The CI style check runs nxstyle over every file a pull request touches,
so the files changed by the previous two commits have to comply even
where the problems were not introduced here.  504 errors in 25 files are
fixed: whitespace, blank lines, brace placement, switch/case indentation,
label indentation and comment blocks only, with no functional change.

Assisted-by: DeepSeek Harness:deepseek-flash
Signed-off-by: rongbaichuan <rongbaichuan1027@163.com>
2026-09-25 10:37:43 +02:00
rongbaichuan
59d5ce0f31 sched/semaphore: Remove the return value check of nxsem_init/nxmutex_init
nxsem_init(), nxsem_destroy(), nxmutex_init() and nxmutex_destroy()
always return OK, so checking the result only leaves dead code: the
compiler cannot remove it, because these are cross-translation-unit calls
and the nxrmutex_destroy() test is duplicated into every inlined call
site.

Apply the convention already established in commit a47a36bc5b (PR #7473)
to the two definitions which still test the value and to the 54 remaining
call sites. No signature or prototype is changed.

Testing: stm32f103-minimum:nsh builds with -Os without new warnings.

Assisted-by: DeepSeek Harness:deepseek-flash
Signed-off-by: rongbaichuan <rongbaichuan1027@163.com>
2026-09-25 10:37:43 +02:00
Alan Carvalho de Assis
31d3598f6a arch/sim: buffer several mouse reports
sim_mouse registered /dev/mouse0 with room for a single report.  The
X11 event loop handles all pending X events at once every
CONFIG_SIM_X11EVENT_INTERVAL ms, so a quick click (button press and
release in the same period) overwrote the press before the application
could read it, and the click was lost.

Add CONFIG_SIM_MOUSE_BUFFSIZE (default 16) for the number of buffered
reports, like CONFIG_SIM_KEYBOARD_BUFFSIZE for the keyboard.

Assisted-by: Claude Opus 5.5 (1M context)
Signed-off-by: Alan Carvalho de Assis <acassis@gmail.com>
2026-09-25 10:36:28 +02:00
Marco Casaroli
27d621e4c7 arch/x86_64: Let the architecture select ARCH_HAVE_FORK.
Review of #19772 asked for this shape, and it applies to every architecture in
the series.

ARCH_HAVE_FORK described when it was available from inside its own definition,
which put the per-architecture condition somewhere nobody looks.  The
architecture now says so itself.

The condition repeats the ARCH_ADDRENV dependency rather than relying on it,
because a select bypasses depends on:  without that repetition an architecture
could offer fork() where there is no address environment to duplicate.

Assisted-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
2026-09-24 18:02:36 -03:00
Marco Casaroli
95c326704e arch/x86_64: Implement up_addrenv_fork() and provide POSIX fork().
Duplicate an address environment into freshly allocated pages mapped at the
same virtual addresses, which is what POSIX fork() is built on.

x86_64_fork_syscall() then lets the child run at the parent's stack addresses.
A pointer to a stack local taken before fork() must name the same object in
the child that it named in the parent, so the child adopts the parent's stack
geometry rather than being given a relocated copy; the parent's stack is
already in the duplicate, at the parent's address, with its contents.  That
shows up as a zero offset, which also means the copy would have the same
source and destination, so both the copy and the frame-pointer relocation are
skipped.

Build-verified on qemu-intel64:knsh_romfs.  NuttX on qemu-intel64 requires
tsc-deadline and pcid, which TCG does not implement, so it cannot be run on
this host.

Assisted-by: Claude Code:claude-opus-5
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
2026-09-24 18:02:36 -03:00
Royyan Zahir
026f77d940 arch/arm64/imx9: give the ELE a physical address and the cache a virtual one.
The ELE addresses memory physically; cache maintenance takes a virtual
address. Both buffer calls supply one and use it for both, in opposite
directions: get_random() runs up_flush_dcache() on a physical address,
get_key() hands the enclave a virtual one. Both fail silently, and both
are correct only while the two are equal.

Take the virtual address in both, maintain the cache on it, and translate
for the message. get_random() also gains the alignment check get_key()
already has.

Signed-off-by: Royyan Zahir <royzah@gmail.com>
2026-09-24 10:36:52 -03:00
dechao_gong
ec7ee53f6f arch/arm/rtl8730e: add UART character driver support
Expose the RTL8730E general-purpose UARTs through the shared Ameba
serial driver (arch/arm/src/common/ameba/ameba_uart.c) by adding the
chip-specific glue, build wiring and a board port table.  The change is
gated by CONFIG_AMEBA_UART (default disabled); the LOG-UART keeps the
console and /dev/ttyS0.

Chip glue (ameba_uart_chip.h) supplies the three UART controller
register bases, GIC IRQ numbers (SPI 50/51/52 -> NuttX IRQ 82/83/84),
APB clock masks and pin-mux codes.  The board registers UART0-2 as
/dev/ttyS1-3 at 115200 8N1; UART3 is reserved for Bluetooth.  Pads are
picked from the EVB break-out (the UART crossbar maps each controller to
many pads, so this is purely a board choice).

Also fix an RX-timeout interrupt storm in the shared driver: the
RX-timeout status (LSR bit9) is latched and is not cleared by draining
the RX FIFO, so on a level-triggered GIC (RTL8730E) the ISR must
explicitly write TOICF, matching the vendor SDK serial_api.c.  The
extra register write is harmless on the NVIC-based M33 Ameba parts and
was regression-tested on them.

Signed-off-by: dechao_gong <dechao_gong@realsil.com.cn>
Assisted-by: Claude <noreply@anthropic.com>
2026-09-24 21:24:35 +08:00
Marcio Ribeiro
ccf67497c7 arch/risc-v/espressif: keep RTC backup data in DRAM without RTC memory
SoCs such as the ESP32-C2 have no RTC retention memory, so RTC_DATA_ATTR
cannot be used for the persistent RTC time.  Place the backup data in DRAM
on those chips, where the saved time does not survive deep sleep.

Assisted-by: Claude:claude-opus-5
Signed-off-by: Marcio Ribeiro <marcio.ribeiro@espressif.com>
2026-09-24 09:54:28 +02:00
Afonso Oliveira
0b35d45b2c riscv/erbium: Add standalone Minion emulator support.
Add an initial port for the AIFoundry Erbium Minion core running on the
public ET-platform system emulator (erbium_emu). NuttX boots directly
from a firmware ELF at 0x40000200, runs in machine mode on hart 0 with
SMP disabled, and parks secondary harts before they touch memory.

The chip layer provides startup, PLIC interrupts, the UART0 console
driver and the machine timer. Context switching, FPU save/restore,
heap, idle and timer handling reuse the common RISC-V code. Atomics use
interrupt masking because the core does not implement the A extension.

Erbium implements the F extension but executes fdiv/fsqrt and FENCE.I
in microcode, which a standalone image does not provide. The board build
files pass -mno-fdiv to GCC when the FPU is enabled, so those operations
use software helpers. Startup initializes the FPU without the common
FENCE.I sequence, and the board configurations disable the dynamic ELF
loader, which also relies on FENCE.I.

Add minion:nsh and minion:ostest configurations, Make and CMake
support, CMake CI build entries, and a host script that runs prebuilt
images in the emulator and checks the console and OS test results.

Tested with emulator revision 836a4ab600e9 and xPack GCC 14.3.0: both
configurations build with Make and CMake, ostest exits with status 0
including the FPU tests, and the NSH console, procfs, timer and UART
receive paths work. Silicon, SMP, protected builds and reboot are not
covered by this initial port.

Signed-off-by: Afonso Oliveira <afonso.oliveira707@gmail.com>
2026-09-24 15:38:14 +08:00
raiden00pl
95cdd306f0 arm/nrf54l: add initial nrf54l support
add initial nrf54l support (Cortex-M33 only)

Assisted-by: Codex:GPT-6
Signed-off-by: raiden00pl <raiden00@railab.me>
2026-09-24 11:10:46 +08:00
Felipe Moura
3c3afd04bd espressif/esp_pm.c: restore GPIO config after using it as a wake source
Arming a pin as a light-sleep wake source destroyed whatever it was
configured as, permanently.

esp_pm_gpio_wakeup_prepare() has to reconfigure each masked pin to plain
INPUT and hand it to gpio_wakeup_enable(), because the wakeup path only
supports level triggering.  It then never put anything back.  A pin that
was also a normal peripheral interrupt -- a sensor's data-ready line, say
-- came out of the first light sleep with its trigger mode gone and never
interrupted again.  Nothing failed loudly; the device just went silent.

Fixed generically rather than per-board:

  - esp_configgpio() now remembers the last attr applied to each pin, and
    a new esp_getconfiggpio() hands it back.  This is what lets the PM
    code restore a pin without having to know what the pin is for.

  - esp_pm_gpio_wakeup_prepare() saves each masked pin's attr before
    overwriting it, and a new esp_pm_gpio_wakeup_restore() puts it back
    as soon as esp_pm_light_sleep_start() returns.

Tied to the physical sleep/wake cycle deliberately, not to PM state
transitions.  An earlier attempt used a board-level pm_register()/notify()
callback and never fired at all, because the board sits in PM_STANDBY
without transitioning back to PM_NORMAL -- there is no state change to
hang the restore on.  The return from esp_pm_light_sleep_start() is the
one event that always happens exactly once per sleep.

Assisted-by: Claude:claude-opus-5
Signed-off-by: Felipe Moura <moura.fmo@gmail.com>
2026-09-23 08:36:17 -03:00
Daniel P. Carvalho
87f2744e6c arch/arm/stm32h5: fail the PHY initialization when the reset times out.
The driver has the same code as the one of the STM32H7. When the PHY did
not clear the reset bit in time, stm32_phyinit() returned the result of
the last MDIO read. The bus reads all ones when the PHY does not answer
yet, and that read succeeds, so the function returned OK and the driver
went on with its default of 10 Mbps and half duplex, while the PHY could
negotiate 100 Mbps and full duplex.

Return -ETIMEDOUT, so that bringing the interface up fails and the
failure is not hidden.

It builds for nucleo-h563zi:netnsh, but it was not tested on hardware.

Signed-off-by: Daniel P. Carvalho <danieloak@gmail.com>
Assisted-by: Claude:claude-sonnet-5
2026-09-23 08:21:59 +02:00
Daniel P. Carvalho
a4c608c591 arch/arm/stm32h7: do not log the frames of packet sockets as unknown.
A frame that a packet socket consumes was given to pkt_input() and then
logged as "Dropped, Unknown type" because it is neither IP nor ARP. With
a PTP grandmaster on the network that is one warning for each frame, and
the log of RAM fills in seconds, so it hides the messages of the start of
the system.

Do not log the frames of the type of PTP or of IPv6 when packet sockets
are enabled, as the driver of the legacy STM32 does.

Signed-off-by: Daniel P. Carvalho <danieloak@gmail.com>
Assisted-by: Claude:claude-sonnet-5
2026-09-23 08:21:59 +02:00
Daniel P. Carvalho
0a4ab69e52 arch/arm/stm32h7: fail the PHY initialization when the reset times out.
When the PHY did not clear the reset bit in time, stm32_phyinit()
returned the result of the last MDIO read. The bus reads all ones when
the PHY does not answer yet, and that read succeeds, so the function
returned OK and the driver went on with its default of 10 Mbps and half
duplex, while the PHY negotiated 100 Mbps and full duplex. The interface
was up and could not talk to anyone.

Return -ETIMEDOUT, so that bringing the interface up fails and the
failure is not hidden.

Signed-off-by: Daniel P. Carvalho <danieloak@gmail.com>
Assisted-by: Claude:claude-sonnet-5
2026-09-23 08:21:59 +02:00
Ahmed Ashraf NourEldeen
af65d2e04a arch/xtensa/espressif: Add IRQ lookup by interrupt handle.
Add esp_get_irq() to retrieve the IRQ associated with an interrupt
handle.

This allows the ESP OS abstraction to recover the IRQ when freeing an
interrupt from its handle.

The corresponding change in esp-hal-3rdparty is required to use this
API when freeing interrupts.

Related: #20216

Signed-off-by: Ahmed Ashraf NourEldeen <a.programmer55559@gmail.com>
2026-09-23 12:22:26 +08:00
Ahmed Ashraf NourEldeen
162369111e arch/risc-v/espressif: Add IRQ lookup by interrupt handle.
Add esp_get_irq() to retrieve the IRQ associated with an interrupt
handle.

This allows the ESP OS abstraction to recover the IRQ when freeing an
interrupt from its handle.

The corresponding change in esp-hal-3rdparty is required to use this
API when freeing interrupts.

Related: #20216

Signed-off-by: Ahmed Ashraf NourEldeen <a.programmer55559@gmail.com>
2026-09-23 12:22:26 +08:00
Michal Lenc
6431b299cc arch/arm/src/samv7/sam_mcan.c: fix coding style issues
Fix coding style to pass NXstyle check.

Signed-off-by: Michal Lenc <michallenc@seznam.cz>
2026-09-23 11:28:27 +08:00
Michal Lenc
c2595870e5 arch/arm/src/samv7/sam_mcan.c: fix potential false debug assertions
MCAN controller keeps track of empty TX HW FIFO slots in priv->txfsem
semaphore. The semaphore is incremented from TX complete interrupt
and taken before new frame is inserted to the HW FIFO.

There may be a situation when TX HW FIFO is not full but the
semaphore is not yet incremented because the driver didn't handle the
interrupt. I managed to reproduce this issue when sending large
data chunks over CAN bus and keeping the buffers full for most of
the transmission process. This situation leads to the debug assertion
although technically it's not a big issue -> the sending function
waits on the semaphore until it's posted by the interrupt handler.

Moreover, the sanity checks should not be necessary because
mcan_buffer_reserve function will take care of fixing the semaphore
value if it doesn't match with the FIFO.

The entire semaphore logic is a bit weird and probably not
necessary. All we need to do is to check SAM_MCAN_TXFQS register
if there is at least one free slot in the queue. But this would
require a bigger SAMv7 MCAN rewrite, this is rather a hot fix.

Signed-off-by: Michal Lenc <michallenc@seznam.cz>
2026-09-23 11:28:27 +08:00
Jukka Laitinen
d49d3bff9e arch/arm/src/imxrt/hardware/imxrt_gpio.h: Small fix for imxrt118x
Harmonize including the variant specific gpio header in imxrt_gpio.h, correct
a mistake in include paths.

Signed-off-by: Jukka Laitinen <jukka.laitinen@tii.ae>
2026-09-23 11:24:44 +08:00
Jukka Laitinen
bf840595f7 arch/arm/imxrt: Fix EDMA_ALIGN for Cortex-M33 in imxrt_edma_ver2.c
Small fix to compile imxrt_edma_ver2.c correctly also for M33.

Signed-off-by: Jukka Laitinen <jukka.laitinen@tii.ae>
2026-09-23 11:24:44 +08:00
Jukka Laitinen
e0f2c881bf arch/arm/imxrt: Add missing imxrt118x IRQ 238/239 definitions
On imxrt1180 there are 240 IRQs. Add the missiong ones:

  IRQ 238  ECAT   EtherCAT Reset out (ECAT_RESET_OUT pin-mux signal)
  IRQ 239  EdgeLock  EdgeLock interrupt

Signed-off-by: Jukka Laitinen <jukka.laitinen@tii.ae>
2026-09-23 11:24:44 +08:00
Royyan Zahir
44a3873222 arch/arm/imxrt: add a CAAM-backed /dev/random driver
The part has a hardware random number generator and nothing registers
it, so up_randompool_initialize() is never seeded from hardware. There
is no CAAM, TRNG or RNG driver anywhere in arch/arm/src/imxrt, and the
RT117x headers describe the block only as an address-map comment.

imxrt_caam.c brings up job ring zero and instantiates the RNG state
handle when the boot ROM has not, retrying with a longer entropy sample
until the self test passes. imxrt_rng.c registers /dev/random and
/dev/urandom on top, and is the i.MX9 driver's sibling: same health
checks, same FIPS 140-2 continuous test, same refusal to return a short
read and call it entropy.

The instantiation descriptor posts no job ring completion, so the state
handle is what reports it, and the ring is taken back to a known state
to latch it. Job ring zero is started and the cache and watchdog bits
set first: RDSTA and JRSTART both read zero out of reset on this part.

Scoped to RT117x, which is the family that carries CAAM.

Built for imxrt1170-evk:nsh with the driver on, and for imxrt1060-evk:nsh
to confirm the shared clock-gate header still builds without it.

Run on an FMU-v6X-RT (i.MX RT1176): /dev/random and /dev/urandom both
return, the first read after a cold boot included, and five consecutive
reads are distinct.

Signed-off-by: Royyan Zahir <royzah@gmail.com>
2026-09-22 09:37:17 -03:00