GPIO_EDGE_RISING was (12 << GPIO_CN_SHIFT), which sets bits 10 and 11
(GPIO_PULLDOWN | GPIO_EDGE_DETECT) instead of the edge type bit 12 that
its comment describes. A pin configured for rising edges therefore also
got the pull-down, and a falling-edge pin with GPIO_PULLDOWN was taken
as a rising-edge pin. Use bit 12.
Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Daniel P. Carvalho <danieloak@gmail.com>
The RX byte count and the EMAC1MAXF limit both include the 4-byte FCS,
but the driver did not account for it:
- RXBUFSZ was programmed with CONFIG_NET_ETH_PKTSIZE, rounded down to
16 bytes (1504 for 1514), so longer frames were split into fragments
and dropped.
- EMAC1MAXF was set to CONFIG_NET_ETH_PKTSIZE, so the MAC rejected
frames longer than CONFIG_NET_ETH_PKTSIZE - 4.
- d_len included the FCS.
Make room for the FCS in the buffers, program RXBUFSZ with the aligned
buffer size and EMAC1MAXF with CONFIG_NET_ETH_PKTSIZE + 4, and remove
the FCS from d_len. The largest ping that got an answer was 1458
bytes; it is now 1472, the full 1500-byte MTU.
Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Daniel P. Carvalho <danieloak@gmail.com>
VIRT_ADDR() converted the DMA buffer addresses to KSEG1, while the
buffers come from g_buffers, which is linked in KSEG0 when the data
memory is cached. Buffers then ended up in the free list under both
aliases. Use the segment g_buffers is linked in instead.
A buffer handed to an RX descriptor may still have dirty D-Cache lines,
at least the free list link written into it. If such a line is evicted
while the DMA writes the frame, it overwrites part of the frame.
Discard the buffer from the D-Cache before giving it to the DMA.
Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Daniel P. Carvalho <danieloak@gmail.com>
After starting an MII management command, the driver executed 16 NOPs
before waiting for the busy flag to clear. The flag is set a few clock
cycles after the command, and when the code runs from the I-Cache the
NOPs end before that: the wait returned at once and phyread() returned
the previous read data. With the L1 cache enabled the PHY was not found
(ID1 read as 0x3000) and the interface never came up.
Poll until the busy flag is set, bounded in case the command has
already completed, before waiting for it to clear. A management frame
lasts 64 MDC cycles, so the flag cannot be missed.
Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Daniel P. Carvalho <danieloak@gmail.com>
pic32mz_bufferinit() appended every buffer to pd_freebuffers without
emptying the list first. On the first ifup the list is empty (the
driver structure was cleared), but on later ones it still holds the
buffers that were free at ifdown. Appending them again truncates the
list and loses buffers, depending on which ones were free. With too few
buffers left the driver could no longer transmit or replace RX buffers,
so after ifdown/ifup the interface stayed up without answering (not
even ARP) until the next ifdown/ifup.
Reproduced with ifdown/ifup from NSH while pinging the board every
10 ms: 3 of 10 cycles left the interface dead before the fix, none
after it. This also happens on cable reconnection with
CONFIG_NETINIT_MONITOR, which takes the interface down and up.
Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Daniel P. Carvalho <danieloak@gmail.com>
The driver had no d_ioctl, so CONFIG_NETDEV_PHY_IOCTL had no effect.
Implement SIOCGMIIPHY, SIOCGMIIREG and SIOCSMIIREG and, with
CONFIG_ARCH_PHY_INTERRUPT, SIOCMIINOTIFY. SIOCMIINOTIFY subscribes
through phy_notify_subscribe() (the board provides arch_phy_irq()) and
enables the PHY link down and auto-negotiation complete interrupts.
This is what CONFIG_NETINIT_MONITOR needs.
The PHY interrupt is implemented for the LAN8720 and LAN8740; add their
interrupt source/mask register bits to mii.h.
Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Daniel P. Carvalho <danieloak@gmail.com>
After a successful auto-negotiation, pic32mz_phyinit() called
pic32mz_phymode() with the negotiated speed and duplex. That function
clears MII_MCR_ANENABLE, so the PHY stayed in a forced mode. The link
keeps working until the cable is removed, but on reconnection the PHY
no longer negotiates and, against an auto-negotiating partner, the link
stays down (seen with a LAN8720A: MCR 0x2100, MSR without link status).
Only force the mode when CONFIG_PIC32MZ_PHY_AUTONEG is not selected.
Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Daniel P. Carvalho <danieloak@gmail.com>
- Close the TX descriptor ring on the last TX descriptor. It used
CONFIG_PIC32MZ_ETH_NRXDESC, so with more RX than TX descriptors the
DMA ran past the TX ring and stopped transmitting after two packets.
- Decrement ETHSTAT.BUFCNT (ETHCON1.BUFCDEC) for each received
descriptor that is processed.
- Drop a received packet instead of asserting when no buffer is free to
replace the one in the RX descriptor.
- Program EMAC1SA0-2 with the MAC address assigned to the device, if
any. The driver only read these registers, which are preloaded with a
factory address on PIC32MZ EC/EF but reset to zero on PIC32MZ-W1.
Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Daniel P. Carvalho <danieloak@gmail.com>
Fix the indentation of a wd_cancel() call and add braces to an empty
while loop, so that the file passes checkpatch.sh. No functional change.
Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Daniel P. Carvalho <danieloak@gmail.com>
Duplicate an address environment into freshly allocated pages mapped at the
same virtual addresses, which is what POSIX fork() is built on. It lives in
arm64_addrenv_mmu.c: an MPU address environment is a set of protection
regions over one physical address space, not a mapping that can be duplicated
at the same virtual addresses. So ARCH_ARM64 selects ARCH_HAVE_FORK only
in a kernel build with ARCH_ADDRENV. The condition repeats the
ARCH_ADDRENV dependency, because a select bypasses depends on.
arm64_fork_stack() then lets the child run at the parent's stack addresses. A
pointer to a stack local taken before fork() must name the same object in the
child that it named in the parent, so the child adopts the parent's stack
geometry rather than being given a relocated copy; the parent's stack is
already in the duplicate, at the parent's address, with its contents. With a
zero offset arm64_fork_reloc() is then the identity, so the register context
needs no further special casing.
Verified on qemu-armv8a:knsh under qemu-system-aarch64: ostest's fork_test
reports "Parent and child had independent memory", and vfork_test passes.
Assisted-by: Claude Code:claude-opus-5
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
jz4780_decodeirq() saves the interrupted context into
g_running_tasks[this_cpu()]->xcp.regs on entry, but nothing updates
g_running_tasks[] after a context switch: every interrupt saves the
context into the Idle task's TCB, and once a task exits (up_exit() sets
the entry to NULL) no context is saved at all and the next context
switch restores stale registers.
Set g_running_tasks[this_cpu()] to this_task() before returning, as
pic32mz_decodeirq() does. This is the same bug that crashed the
PIC32MZ-W1 when the netinit thread exited.
Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Daniel P. Carvalho <danieloak@gmail.com>
pic32mx_decodeirq() saves the interrupted context into
g_running_tasks[this_cpu()]->xcp.regs on entry, but nothing updates
g_running_tasks[] after a context switch: every interrupt saves the
context into the Idle task's TCB, and once a task exits (up_exit() sets
the entry to NULL) no context is saved at all and the next context
switch restores stale registers.
Set g_running_tasks[this_cpu()] to this_task() before returning, as
pic32mz_decodeirq() does. This is the same bug that crashed the
PIC32MZ-W1 when the netinit thread exited.
Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Daniel P. Carvalho <danieloak@gmail.com>
pic32mz_decodeirq() saves the interrupted context to the TCB in
g_running_tasks[], but never updated g_running_tasks[] after a context
switch. It kept pointing at the Idle task from nx_start(), so every
interrupt overwrote the Idle task's saved registers, and after up_exit()
set it to NULL no context was saved at all. The next context switch
then restored stale registers; on PIC32MZ-W1 the system crashed as soon
as the netinit thread exited.
Set g_running_tasks[] to this_task() before returning, as the other
architectures do.
Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Daniel P. Carvalho <danieloak@gmail.com>
Change the imxrt1180-evk M7 NSH configuration to use the SoC memories
more efficiently:
- Place .data, .bss, idle stack and primary heap into DTCM
- Allocate available OCRAM as a secondary heap
- Add a separate .dmamemory section in OCRAM for USB device DMA
allocations
- Place .ramfunc into ITCM, together with hand-picked "hot" functions.
The section is copied to ITCM at boot by the ramfunc copy.
The eDMA accesses DTCM through the SoC's dedicated bus window.
This configuration acts as an example of performance optimization for
imxrt1180 based boards.
Signed-off-by: Jukka Laitinen <jukka.laitinen@tii.ae>
Cortex-M7 core's DTCM is available for other peripherals via a
dedicated address space. If transfers are done to or from the DTCM,
translate addresses to work on this shadow memory region instead, via
which the eDMA can access the DTCM.
This allows using the existing imxrt peripherals, which use DMA, to work
directly even if .data/.bss are located in DTCM.
Signed-off-by: Jukka Laitinen <jukka.laitinen@tii.ae>
Add support for Cortex-M33 code to initialize the M7 TCM memories before
releasing it to run. The TCM has ECC, which needs to be initialized before
the memory is usable for M7.
Specifically, the TCM needs to be initialized sequentially in 64-bit writes.
Use eDMA4 for this; this is the same mechanism which the NXP MCUXpresso SDK
code does.
Split imxrt118x_release_cm7() into imxrt118x_prepare_cm7() and
imxrt118x_start_cm7(). The TCM ECC initialization is done in
imxrt118x_prepare_cm7(), after the M7 has been released from reset and
before the M7 is started. Also reset M7_CFG[TCM_SIZE] to the default
256 KiB ITCM / 256 KiB DTCM layout.
Co-Authored-By: Jukka Laitinen <jukka.laitinen@tii.ae>
Signed-off-by: Jukka Laitinen <jukka.laitinen@tii.ae>
Move the imxrt118x SRC register defintions to an own file. They differ
from the other imxrt chips, and were also scattered between blockctrl
and a common imxrt_src headers.
Signed-off-by: Jukka Laitinen <jukka.laitinen@tii.ae>
Loop devif_poll() until it reports nothing more
to send, matching the batch-drain behaviour of the upper-half CAN
drivers, so a transfer completes on one notification.
Signed-off-by: p-szafonimateusz <p-szafonimateusz@xiaomi.com>
RP23XX_FLASH_MTD_OFFSET and RP23XX_FLASH_MTD_SIZE come from Kconfig.
If the region ends past the end of the flash, the flash wraps the
address around, and an erase or program hits the start of the flash,
where the NuttX image is. For example, a 4M region at 1M does not
fit on the 4M flash of a Raspberry Pi Pico 2.
Read the JEDEC ID at initialization, in QMI direct mode as the Pico
SDK flash_do_cmd() does, and refuse a region that does not fit. The
capacity byte is log2 of the size in bytes. If the ID does not look
valid, warn and do not check.
Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
While the bootrom erases or programs the flash, the QMI is in direct
mode, and an access to the XIP space (flash or PSRAM) gives a bus
fault. The flash MTD driver accessed it in two cases:
- The data to program was in flash or PSRAM. flash_range_program()
read it during the operation. Now the driver copies each such page
to an SRAM buffer first.
- The caller's stack was in PSRAM. This is the normal case with
RP23XX_PSRAM_HEAP_USER, and possible with RP23XX_PSRAM_HEAP_SINGLE.
The operation pushed to that stack. Now the driver switches to a
small SRAM stack for the operation if the stack is in the XIP space.
The operation data is static (SRAM) since the previous commit.
Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
The flash MTD driver disabled interrupts for a whole request. A
multi-block erase or a large write kept them off for seconds.
Erase one 64K block (or one 4K sector where the range is not block
aligned) and program one 256 byte page per step. Enable interrupts and
release the other core between steps. A single block erase is still
long, but that is the limit of the flash.
Also, on SMP:
- Do not send the pause call to the CPU that does the operation.
nxsched_smp_call_single_async() runs it at once on that CPU.
- Keep the isolation data in a static, not on the stack. The other
CPU spins on it while the flash is busy.
Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
After a flash operation the driver called flash_select_xip_read_mode()
with a fixed EBh quad mode and clock divisor 4, and called
flash_enter_cmd_xip() if it "failed". But that ROM function returns
void, so the check read a random r0. The fixed mode and divisor can
also be different from the ones the bootrom found at boot.
The datasheet (5.2.7, 5.4.8.10) and the Pico SDK use a different
method: after a flash boot the bootrom leaves an XIP setup function in
the first 256 bytes of boot RAM. It restores the read mode and clock
divisor found at boot. Boot RAM is not executable, so copy the
function to SRAM once at initialization, and call the copy.
If boot RAM is empty (no flash boot), use flash_enter_cmd_xip(), as
RP23XX_FLASH_MTD_SAFE_XIP does.
Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
The bootrom flash functions reset the QMI window 1 (chip select 1)
registers and the QSPI pads. flash_flush_cache() also discards dirty
XIP cache lines. The flash MTD driver did not save anything, so after
the first erase or program the PSRAM on chip select 1 read garbage,
and PSRAM writes still in the cache were lost.
Do what the Pico SDK hardware_flash library does:
- Clean the XIP cache before the operation. Clean by set/way through
the top of the maintenance window, to avoid erratum RP2350-E11.
- Save the QSPI pads and the five QMI M1 registers before, and write
them back after XIP is restored. Also keep XIP_CTRL.WRITABLE_M1.
rp23xx_psram_restore() was the earlier fix for this, but nothing called
it. Remove it.
Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
The always-on timer has an alarm comparator, but the RTC driver did not
use it: rp23xx_rtc.c implemented only up_rtc_initialize(),
up_rtc_time() and up_rtc_settime().
Add the alarm and an RTC lower half for /dev/rtc0:
- rp23xx_rtc_setalarm(), rp23xx_rtc_cancelalarm() and
rp23xx_rtc_rdalarm() on the ALARM_TIME registers and the POWMAN
timer interrupt.
- An RTC lower half with rdtime, settime, setalarm, setrelative,
cancelalarm and rdalarm, registered by the common board bringup.
The comparator asserts while the time is past the alarm time, not on
a transition. So the interrupt handler disables the alarm before it
does anything else; clearing only the status makes the interrupt
repeat. The arming sequence is the one of
powman_timer_enable_alarm_at_ms() in the Pico SDK.
Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
setup_period() printed the uint8_t slice number with %d, and the
uint32_t frequency, the uint16_t top and the uint32_t divisor with %lu.
Use %u for the two small fields and PRIu32 for the two uint32_t fields.
No build warns about this today, because GCC does not check syslog
format strings. It shows with CONFIG_DEBUG_PWM_INFO only.
Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
Indent the three else blocks and the switch in rp23xx_pwm_ioctl() as
nxstyle wants. Whitespace only; git diff -w is empty.
Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
With -mfdpic and -mlong-calls, GCC turns a call to an imported function
in tail position into "ldr r3, [r9, #off]; bx r3". The GOT slot holds
the address of the function descriptor, so the branch goes to the
descriptor in RAM instead of through it, and the core faults. A normal
call loads the code address and the data base from the descriptor
first. GCC 13.2 and 15.3 both do this.
Only an optimized build makes tail calls. The C++ library of
apps/testing/fs/xipfs then faults in its constructor, which ends in a
call to syslog(), and the test stops at "stage the C++ module".
Pass -fno-optimize-sibling-calls with the other FDPIC flags, in the make
build and the CMake build.
Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
GCC before 14 does not pass --fdpic to the assembler when it compiles
with -mfdpic. The assembler then rejects every FDPIC relocation with
"Relocation supported only in FDPIC mode". The NuttX CI image has GCC
13.2, so the crt0.o of an FDPIC configuration does not build there.
Pass -Wa,--fdpic with -mfdpic, in the make build and the CMake build. A
newer GCC passes the same option itself.
Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
With CONFIG_FDPIC, the CMake build gave the FDPIC options to a loadable
module only. A shared library (DYNLIB) got neither -mfdpic nor the FDPIC
link, but the "-r" link of the non-FDPIC case. So the library was a
relocatable object, and a module that named it in DT_NEEDED did not link:
"multiple definition" and "dangerous relocation".
Give a shared library the same options as a module, as LDMODULEFLAGS and
CMODULEFLAGS in common/Toolchain.defs already do for the make build.
Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
The i.MX95 has five GPIO instances, but g_gpio_base[] only listed the
first four. IMX9_GPIO_BASE(n) indexes this table directly, so any
access to port GPIO5 read one element past the end of the array and
caused a crash.
The table was previously selected on CONFIG_ARCH_CHIP_IMX9_CORTEX_M,
which covers both the i.MX93 M33 and the i.MX95 M7. Since the i.MX93
only has four GPIO instances and does not define IMX9_GPIO5_BASE, key
the five entry table off CONFIG_ARCH_CHIP_IMX95_M7 and keep the four
entry table for the i.MX93 (both the Cortex-A CONFIG_ARCH_CHIP_IMX93
and the Cortex-M CONFIG_ARCH_CHIP_IMX93_M33 variants).
Signed-off-by: Peter van der Perk <peter.vanderperk@nxp.com>
RP23XX_PSRAM_M1_TIMING was the constant 0x61a07102. The comment said
it matched the Pico SDK, but it does not. The SDK computes the timing
from clk_sys and the APS6404 limits (133 MHz SCK, 8 us maximum select,
18 ns minimum deselect). At 150 MHz it gives 0x60242202:
field old SDK
clkdiv 2 2
rxdelay 1 2
max_select 16 18
min_deselect 7 2
select_hold 3 0
The old RX delay samples the read data half a clk_sys cycle earlier
than the SDK does. The constant is also wrong for any other clk_sys.
Compute the fields from BOARD_SYS_FREQ at build time, with the SDK
formula, and stop the build if a field is out of range. The result
is identical to the SDK value at 48, 125, 150, 200, 266 and 300 MHz.
Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
The RP2350 datasheet (12.14.5) says: set DIRECT_CSR.EN, then poll BUSY
until it is low, before the first direct-mode transfer. BUSY stays high
while an XIP transfer is in its cooldown. The Pico SDK waits here too.
rp23xx_psram_detect() did not wait at the two places where it enables
direct mode. It worked on the boards we tested because the cooldown
ended before the first chip select. Add the two waits, and put the
BUSY loop in one RAM-resident helper.
Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
sim_can_work() in sim_cansock.c and sim_canchar.c read a single frame
from the host socket and requeued itself after SIM_CAN_WORK_DELAY
(USEC2TICK(1000), one 10 ms tick with the default sim tick), capping
RX at about 100 frames/s. A burst from the bus was then delivered
over hundreds of milliseconds, and frames from an earlier burst
reached sockets opened later. Loop while frames are available.
Assisted-by: Claude:claude-opus-5-5
Signed-off-by: raiden00pl <raiden00@railab.me>
A module that names a shared library in DT_NEEDED now gets it loaded and
its imports bound against it, rather than being refused.
libelf_insert() does the loading, which is what dlopen() calls anyway: the
library lands in the module registry like anything else, its exports come
back through libelf_getsymbol() -- the same call dlsym() uses -- and a
library named by two modules is loaded once. A bare name is looked for
along LD_LIBRARY_PATH, where dlopen() looks for it. Undefined symbols
resolve against the globally registered symbols first, then the modules
this one depends on, then the table exec() supplied. Nothing here calls
into dlfcn, because this loader is also the kernel's module loader, which
has none.
Each library becomes one of the module's dependencies[], and the dependency
holds it in place of the reference libelf_insert() took. So a library
loaded only for DT_NEEDED is kept by the modules that depend on it, and
libelf_undepend() unloads it with the last of them; one that dlopen() or
insmod also opened stays until that reference goes too.
CONFIG_LIBC_ELF_MAXDEPEND bounds how many libraries a module may name,
which is what it already meant.
Six things had to be fixed to make it work, none of which a build shows.
reldata was a file-scope global. Loading a library from inside
libelf_relocatedyn() makes that function reentrant, so the nested load
overwrote the outer one's relocation offsets and the module resumed binding
with the library's DT_REL. It is now per call.
A cross-object call needs the callee's data base, not the caller's. A
symbol resolved from an FDPIC library comes back as a descriptor, and
R_ARM_FUNCDESC_VALUE was treating it as a code address and pairing it with
the importing module's GOT. It now copies both words, so the library runs
with its own.
An object with no imports has no PLT and so no DT_PLTGOT, but it still has
a GOT and still has to be entered with it. Without the fallback its
descriptors carried a data base of zero and the library read its globals
through a null pointer.
R_ARM_FUNCDESC, a pointer to a descriptor, wrapped a library's descriptor
in a second one. It now stores the library's descriptor as it is.
The flag that says a resolved value is a descriptor was set only for an
import and never cleared, so the next relocation against a symbol of the
module itself took that symbol for a descriptor too. It is cleared there.
libelf_symname() was static, and reading a DT_NEEDED name needs it.
A module with DT_NEEDED is refused where CONFIG_LIBC_ELF_MAXDEPEND is zero,
since that is where the dependency logic is compiled out.
A DT_NEEDED library is one shared instance, its data included, because the
loader returns the object already in the registry. A module started with
exec() is different: that path loads the module afresh each time, so two
running instances have separate data while sharing one copy of the text.
Built for mps3-an547:picostest with CONFIG_FDPIC both ways. Run on
mps2-an500:xipfs under QEMU: fdpicxip solib loads libcounter.so by name out
of DT_NEEDED, two instances share one pinned copy of its text, and the
library is unloaded, and its pin given back, when the second one exits. A
library also opened with dlopen() stays loaded after its DT_NEEDED user
exits, and dlclose() unloads it.
With CONFIG_ARCH_ADDRENV the program runs in its own address space, which
a library libelf_insert() loads cannot reach, so DT_NEEDED is refused
there as before.
Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
An enabled ICACHE does not manage write transactions: it flags cacheable
writes as errors (ICACHE_SR.ERRF), and RM0481 8.4.5 recommends modifying
the memory with the ICACHE disabled. On an STM32H563, erasing and
programming a flash block with the ICACHE enabled leaves ICACHE_SR at
0x6 (BSYENDF and ERRF set).
The ICACHE also keeps serving lines cached before the change. When the
block had been read through the ICACHE just before it was programmed,
up_progmem_write() failed its read-back check with -EIO: the flash held
the new data, with no flash or ECC error flagged, but the read-back hit
the cached erased data. up_progmem_eraseblock() fails its erased-range
check the same way when programmed data of the block is cached.
Disable the ICACHE for the duration of up_progmem_eraseblock() and
up_progmem_write(), and enable it again afterwards if it was enabled on
entry. Disabling it invalidates it, so the refill after re-enabling it
sees the new flash content.
If the ICACHE cannot be re-enabled because its invalidate times out, it
is left disabled, which is safe but slower, and an error is logged.
Assisted-by: Claude:claude-sonnet-5-5
Assisted-by: Claude:claude-opus-5-5
Signed-off-by: Ricardo Maurizio Paul <ricardopaul@geotab.com>
A bootloader may hand over with the ICACHE enabled, and nothing waits for
the invalidate that runs when the ICACHE is disabled. The driver also
polled BUSYF without a bound, so a stuck flag would hang the boot, and it
ignored an invalidate that never finished.
- stm32_enable_icache(): on first use, disable and invalidate the ICACHE
before the associativity and region registers are written (they are
only writable while EN=0), and wait for any pending invalidate before
enabling it (RM0481 8.4.5).
- stm32_disable_icache(): wait for the invalidate that EN=0 starts and
clear BSYENDF and ERRF.
- Bound every BUSYF wait with STM32_ICACHE_BUSY_TIMEOUT. RM0481 gives no
invalidate duration, so the value is a margin, not a measured limit.
- stm32_enable_icache() now returns OK or -ETIMEDOUT instead of void. On
a timeout the ICACHE is left disabled: with BUSYF stuck it would not
cache anything anyway (RM0481 8.4.5). Existing callers ignore the result
and keep working.
- __start: when CONFIG_STM32_ICACHE is not set, disable an ICACHE left on
by a bootloader, so reads of the OTP and UID cannot fault. On an
STM32H563 with the ICACHE left enabled this way, a 16-bit read of the
UID raised a precise bus fault and up_progmem_write() failed its
read-back check with -EIO.
Assisted-by: Claude:claude-sonnet-5-5
Signed-off-by: Ricardo Maurizio Paul <ricardopaul@geotab.com>
stm32_get_uniqueid() and flash_read_eccsafe16() (OTP and EDATA word
reads) disabled the ICACHE around their reads and enabled it again
afterwards, so that the read did not go through the ICACHE. The MPU
region added by the previous commit makes these areas non-cacheable, so
the reads bypass the ICACHE anyway.
Remove the disable/enable pairs. Each pair also invalidated the whole
ICACHE, and flash_read_eccsafe16() did it with interrupts disabled, twice
for every 32-bit OTP read.
The MPU is not applied in the HardFault and NMI handlers (HFNMIENA=0),
so a UID read from those handlers is no longer protected. Nothing in the
tree does that.
Assisted-by: Claude:claude-opus-5-5
Signed-off-by: Ricardo Maurizio Paul <ricardopaul@geotab.com>
The OTP, read-only (UID, flash size, package) and high-cycle data (EDATA)
flash areas only accept 16/32-bit accesses and return a bus error
otherwise (RM0481 Table 77). The manual requires the MPU to disable local
cacheability for them (RM0481 7.3.2); with the ICACHE enabled and no such
region, reading them raises a precise bus error.
Until now this was worked around piecemeal: the driver disabled the
ICACHE around stm32_get_uniqueid() and the OTP and EDATA word reads, and
nucleo-h563zi mapped the 4 KB OTP/RO area non-cacheable in its board
code. Other reads, for example stm32_otp_read() or an application
reading the OTP on another board, still raised a precise bus error when
the ICACHE was enabled.
Map 0x08fff000-0x09017fff, which covers the three contiguous areas, as
Normal non-cacheable and execute-never with a single MPU region before
the ICACHE is enabled. STM32_ICACHE now selects ARM_MPU so that
stm32_mpuinitialize() has reset and enabled the MPU by then.
Remove the nucleo-h563zi OTP region in the same commit: the Armv8-M MPU
faults on an address that matches more than one region, so keeping both
would make OTP and UID reads fault on that board.
Assisted-by: Claude:claude-sonnet-5-5
Assisted-by: Claude:claude-opus-5-5
Signed-off-by: Ricardo Maurizio Paul <ricardopaul@geotab.com>
An ICACHE build with no ICACHE region configured warns about two unused
symbols:
- stm32_icache_setup_region() is only called when one of the
CONFIG_STM32_ICACHE_REGION0..3 options is set, so build it only then.
- 'regval' in stm32_icache_initialize() is only used with
CONFIG_STM32_ICACHE_DIRECT, so declare it only then. The interrupt
block gets its own local variable.
No functional change.
Assisted-by: Claude:claude-sonnet-5-5
Signed-off-by: Ricardo Maurizio Paul <ricardopaul@geotab.com>