nucleo-g431rb:cansock and b-g431b-esc1:cansock fill their 128 KB of
flash to the last few hundred bytes, and the capability checks overflow
them.
Signed-off-by: Royyan Zahir <royzah@gmail.com>
What each capability guards, the prctl() interface, inheritance through
the task group, and where the checks sit.
Signed-off-by: Royyan Zahir <royzah@gmail.com>
exec_internal(), which posix_spawn(), execve() and exec() all reach,
nxtask_spawn_create() and nxtask_create() check it. nxthread_create()
does not: kernel threads go through it too.
Signed-off-by: Royyan Zahir <royzah@gmail.com>
Opening a block or MTD node, mount() and umount2() need it, and so does
a BCH character node, which checks in its own open(): a node made by
bchdev_register() is a character driver, so the inode type cannot tell
it apart. The checks sit in file_vopen(), nx_mount() and nx_umount2(),
which every path reaches; kernel threads hold every capability.
Signed-off-by: Royyan Zahir <royzah@gmail.com>
A task group holds PR_CAP_RAWIO, PR_CAP_SPAWN and PR_CAP_ADMIN, inherits
them from its creator and can only drop them. Every build: the kernel and
init start with all three, so nothing changes until a task drops one.
CONFIG_SCHED_CAPABILITIES, off with DEFAULT_SMALL, lets a board short of
flash leave the checks out.
Signed-off-by: Royyan Zahir <royzah@gmail.com>
Use init_main as the init entry point and enable SYSTEM_NXINIT with the
/etc ROMFS, so nxinit starts nsh as the console service.
Assisted-by: OpenCode:claude-sonnet-5
Signed-off-by: wangjianyu3 <wangjianyu3@xiaomi.com>
The ioctl passed the erase to the parent unchecked, so an erase from the
last block on reached the next partition. part_erase() already bounds it.
Signed-off-by: Royyan Zahir <royzah@gmail.com>
POSIX.1-2024 adds getlocalename_l(), which returns the name of the
locale of one category of a locale object. NuttX supports only the "C"
locale, so the function returns "C" for every valid category, and NULL
with errno set to EINVAL for an invalid one. It is built with
CONFIG_LIBC_LOCALE, like the other locale functions.
Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
POSIX requires tzset(), but NuttX declared and defined it only with
CONFIG_LIBC_LOCALTIME, so programs that call it do not build without
that option. Without CONFIG_LIBC_LOCALTIME there are no time zones and
local time is UTC, so tzset() has nothing to do.
Declare tzset() always, and add an empty one for builds without
CONFIG_LIBC_LOCALTIME.
Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
posix_spawn() and execve() logged every failed exec at error level. A
shell normally tries a program first: NSH with CONFIG_NSH_FILE_APPS
spawns each command from PATH before its built-in command, and bash
runs a script itself when execve() returns ENOEXEC. So every built-in
NSH command printed
nxposix_spawn_exec: ERROR: exec failed: 2
although nothing was wrong. The caller gets the error code and reports
it if it needs to.
Do not log ENOENT and ENOEXEC. Other errors are logged as before.
Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
Add a note for first-time contributors explaining that building the
simulator locally can help verify the development environment before
submitting changes.
Assisted-by: ChatGPT:GPT-5.6 Luna
Signed-off-by: Vedprakash Rana <vedprakashkumarrana8@gmail.com>
drivers/crypto/pnt calls the Plug&Trust middleware, whose API and types
are mixed case (Se05x_API_*, SE05x_*, kSE05x_*, smStatus_t), so any
change to those files failed the check.
Signed-off-by: Royyan Zahir <royzah@gmail.com>
pnt_se05x_get_data() compared the object size with the buffer even when ReadSize had failed and left it unset.
Signed-off-by: Royyan Zahir <royzah@gmail.com>
This commit adds board support for connecting an external Winbond W25
SPI NOR flash memory via SPI1 on the Nucleo-L432KC:
- Define W25_SPI1_CS on PA11.
- Configure SPI1 chip select and presence detection in stm32_spi.c.
- Add stm32_w25initialize() to initialize SPI1, bind the W25 driver,
and register /dev/mtd0, /dev/mtdblock0 (FTL), and optionally /dev/smart0.
- Call stm32_w25initialize() during bringup when CONFIG_MTD_W25 is enabled.
Assisted-by: gemini-3.8-flash
Signed-off-by: Daniel P. Carvalho <danieloak@gmail.com>
The CS, MOSI and MISO pins can be set to -1 in Kconfig when the board
does not use them, and esp32s3_spi_init() skips a pin when it is
negative. The pins are stored as uint8_t in esp32s3_spi_config_s, so
-1 becomes 255, every "pin >= 0" check is always true, and 255 is
passed to esp_gpiowrite() and esp_configgpio(), which trips their
DEBUGASSERT.
Store these three pins as int8_t so -1 is kept and the existing checks
work.
Fixesapache/nuttx#20186
Assisted-by: Grok Bot
Signed-off-by: Zhaoqi Xu <lzy00419@outlook.com>
The filter expression for CONFIG_STM32_IWDG and CONFIG_STM32_RTC_LSICLOCK
returns "y y" when both are enabled. Comparing that result with "y"
omits stm32_lsi.c, leaving calls to stm32_rcc_enablelsi() unresolved.
Test for a nonempty result instead. Include the helper once when either
or both consumers are enabled, and omit it when neither is enabled.
This changes source selection only, without changing clock or watchdog
policy.
Assisted-by: Codex:GPT-6
Signed-off-by: jsanchez-2g <jsanchez@2g-eng.com>
Provide a complete documentation page for the webclient network utility
in Documentation/applications/netutils/webclient/index.rst, replacing
the previous 7-line placeholder stub.
Includes:
- Architecture overview (NSH wget engine + programmatic C API)
- Key features (HTTP/1.0, HTTP/1.1, chunked encoding, pluggable TLS,
non-blocking I/O, proxy tunneling)
- Detailed Kconfig configuration table and dependencies
- NSH wget syntax, options, and real-world usage examples
- C API reference for simple helpers (wget, wget_post) and the
context-based API (struct webclient_context)
- Complete, runnable C application example for file downloads
Addresses #11081
Signed-off-by: Swatantra Yadav <maverickswatantra@gmail.com>
Use per-instance aligned buffers for memory that SDMMC IDMA cannot
access directly or that does not meet cache alignment requirements.
Copy writes before IDMA and copy successful bounced reads in the
waiting thread. Report the configured capacity through maxrequest.
Keep a positive IDMA RAM allow-list and runtime setup validation.
Invalidate only the actual DMA destination, prioritize errors over
DATAEND, and stop data access before releasing buffer ownership.
Reset an active data path on abort while restoring host bus settings;
clear cancellation state and handle immediate/watchdog-start errors.
This commit contains the STM32H7 driver and its Kconfig changes only.
The preceding commit supplies the common SDIO/MMCSD functionality.
Assisted-by: Codex:GPT-6
Signed-off-by: msli-dev <747640013@qq.com>
Add an optional maxrequest callback at the end of sdio_dev_s. A zero
or unset callback adds no host-specific limit; nonzero values are byte
limits that apply to all request buffers.
Combine the host limit with MMCSD_MULTIBLOCK_LIMIT when splitting
block reads and writes. Reject a host limit smaller than one block and
oversized raw multi-block commands before starting the transfer.
Cancel receive setup after a failed CMD23, attempt CMD12 after failed
open-ended multi-block reads, and propagate stop-command failures.
Keep these generic MMC/SD changes separate from the STM32H7 driver.
Assisted-by: Codex:GPT-6
Signed-off-by: msli-dev <747640013@qq.com>
Every ARCH_CORTEX_A5x config selects ARCH_ARMV8A, and both
Toolchain.defs and cmake/Toolchain.cmake test CONFIG_ARCH_ARMV8A at
the head of the chain, so the -mcpu=cortex-a53/a55/a57/a72 branches
were unreachable and all Cortex-A targets built with plain
-march=armv8-a, losing per-core scheduling/tuning.
Test the specific cores first so -mcpu wins for them; the generic
ARCH_ARMV8A branch still covers cores without a dedicated entry and
keeps the armv8.5-a/MTE handling. Also add the missing cortex-a55
branch to the cmake toolchain for parity with the makefile.
Signed-off-by: rikaken2004 <244897142+rikaken2004@users.noreply.github.com>
A channel number of zero marks an unused slot, as pwm.rst documents.
pwm_start() handed every slot to pwm_update_duty(), which refuses
channel 0, so a caller that fills only some slots, like PX4's tone
alarm, got EINVAL.
Signed-off-by: Royyan Zahir <royzah@gmail.com>
timer_gethandle() accepted any allocated timer in the system, so a
process could set, read or delete another process's timer by its handle.
Accept a handle only from a thread of the owner's process. The expiry
callback runs in interrupt context, where the current task is unrelated,
and is exempt.
Signed-off-by: Royyan Zahir <royzah@gmail.com>
Re-initialize the bus even in the case the bus cannot be re-covered. The
client still has a reference to the bus, and may try to access it again.
If the bus is not initialized or the root clock is off, the access may
cause a crash.
Signed-off-by: Jukka Laitinen <jukka.laitinen@tii.ae>
The I- and D-Caches were disabled, so all code ran from flash through
the prefetch buffer and all data accesses went to SRAM. Enable both
caches in nsh and netnsh, and link the data memory in KSEG0 instead of
KSEG1 so that it goes through the D-Cache (KSEG0 is uncached when the
caches are disabled). CONFIG_BOARD_LOOPSPERMSEC is recalibrated with
calib_udelay for the cached configuration.
CoreMark (XC32 v6.00, -O2) goes from 82.5 to 544.6 iterations/s. The
average ping round trip time drops from 0.74 to 0.56 ms for 64-byte
packets and from 1.92 to 0.93 ms for 1400-byte packets.
Tested on the EV49N51A with XC32: 5000 pings of 1472 bytes at 2 ms
intervals with payload checking, ifdown/ifup cycles, telnet sessions
and CoreMark. With Pinguino GCC: 2000 pings of 1472 bytes and 1000
small pings at 3 ms intervals.
Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Daniel P. Carvalho <danieloak@gmail.com>
Add CONFIG_EV49N51A_PHY_INTERRUPT, which provides arch_phy_irq() with
the LAN8720A nINT output on RK6 as a falling-edge change notification
interrupt. nINT reaches RK6 only through R309, which is not fitted on
the EV49N51A, so the option defaults to off.
With CONFIG_NETINIT_MONITOR the interface now goes down when the cable
is removed and comes back up when it is reconnected.
Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Daniel P. Carvalho <danieloak@gmail.com>
The change notification code assumed the EC/EF layout: the IRQ of an
I/O port was PIC32MZ_IRQ_PORTA plus the port index, and initialization
reset the change notification registers of every port index. The
PIC32MZ-W1 only implements PORTA, PORTB, PORTC and PORTK, its change
notification vectors are PIC32MZ_IRQ_CNA/CNB/CNC/CNK, and the addresses
of the missing ports D-J belong to other peripherals (I2C1 is at the
PORTE address).
Map the port index to its IRQ through a table on the W1, skip the
unimplemented ports during initialization, and pass the port index to
the common handler as its argument instead of deriving it from the IRQ
number. Hide the PORTD-PORTJ interrupt options on the W1.
Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Daniel P. Carvalho <danieloak@gmail.com>
Fix the indentation of two lines that nxstyle reports as bad
alignment. No functional change.
Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Daniel P. Carvalho <danieloak@gmail.com>
- Reset the LAN8720A PHY (nRST on RA14) at boot, after the RMII
reference clock is running.
- Define BOARD_EMAC_MIIM_DIV for a 2.5 MHz MDC.
- Add the netnsh configuration: Ethernet, IPv4, TCP, UDP, ICMP, ping and
telnetd, with the default static address of the network initialization
and a locally administered MAC address (PIC32MZ-W1 has no factory MAC
address).
- Document the Ethernet interface, the RMII reference clock options and
the netnsh configuration.
Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Daniel P. Carvalho <danieloak@gmail.com>
- PIC32MZ-W1 only has the RMII interface and no DEVCFG3, so hide the
PIC32MZ_FMIIEN and PIC32MZ_FETHIO options and define
CONFIG_PIC32MZ_FMIIEN as 0 (RMII), matching DEVCFG1.FMIIEN. The
default of 1 (MII) made the driver skip the RMII reset and speed
setup, so the MAC ran its RMII logic at 10 Mbps.
- Enable ETH_CLK_OUT (EWPLLCON.ETHCLKOUTEN), the 50 MHz RMII reference
clock for the MAC and the PHY, only when the Ethernet MAC is enabled.
- Add PIC32MZ_W1_ETH_EXTREFCLK for boards that clock the PHY and the
MAC from an external 50 MHz oscillator; ETH_CLK_OUT is then left
disabled.
Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Daniel P. Carvalho <danieloak@gmail.com>
CONFIG_ARCH_PERF_EVENTS is on by default for ARMv7-M, but imxrt never
called up_perf_init(), so perf_gettime() read zero and anything timed
with it, rpmsg_ping for one, reported 0 ns. Initialise the counter with
BOARD_CPU_FREQUENCY after the MPU is set up, as samv7 and stm32h7 do.
Assisted-by: Claude:claude-fable-5-1
Signed-off-by: Lourens Naude <lourens@bearmetal.eu>
raspberrypi-pico-2:pm and pimoroni-pico-2-plus:pm enable the PM
standby and dormant states with the greedy governor, suspend to RAM
with the BOARDIOC_RP23XX_SUSPEND boardctl() command, and the RTC alarm.
The console receive pin (GPIO 1) wakes the chip, and the dormant state
is refused for 30 s after boot so that a debugger can attach. The Pico
Plus 2 configuration also adds its PSRAM to the heap.
Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
P1.0 powers the switched core off and keeps the XIP cache and SRAM.
Every peripheral loses its registers, so the chip comes back through
the bootrom and the ordinary boot, not from the WFI. The idle governor
never selects it: an application asks for it with the new
BOARDIOC_RP23XX_SUSPEND boardctl() command (arch/chip/pm.h, handled by
the common rp23xx board_ioctl()).
rp23xx_pm_suspend():
- saves the NVIC, writes a marker to POWMAN SCRATCH0, and arms the
wake: the RP23XX_PM_WAKEUP_GPIO pin in a POWMAN power-up detector,
and the always-on timer alarm for a timed wake. An armed RTC alarm
that comes first powers the chip up itself, so an application can
set the wake with RTC_SET_ALARM. Otherwise the RTC alarm is saved
with the new rp23xx_rtc_savealarm() and given back after the wake
with rp23xx_rtc_restorealarm().
- cleans the XIP cache, with the RP2350-E11 workaround, because the
resume discards it and PSRAM can hold task stacks.
- requests P1.0 and waits in WFI.
On the next boot, __start asks rp23xx_pm_resume_pending() (the marker
and CHIP_RESET.HAD_SWCORE_PD) before .bss and .data are touched. For a
resume it moves to its own stack, because the idle thread still runs on
the idle stack, sets up the hardware with the cold boot code (now
rp23xx_hwinit()), and longjmps back to the suspended thread. The UARTs
are set up from the driver state in RAM, the PSRAM format is applied
again without detection (the part is still in quad mode), the dormant-
wake GPIOs are armed again (the IO bank lost them, and the next dormant
period could then never end), and the time of day is taken from the
always-on timer.
Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
Map the NuttX PM states onto the RP2350 low-power modes:
- PM_STANDBY is the RP2350 SLEEP state: a WFI with the clocks of the
blocks that have no driver in the configuration gated (SLEEP_EN0/1).
- PM_SLEEP is the DORMANT state: clk_sys moves to the crystal
oscillator, the PLLs and then the oscillator stop, and the clock tree
is restored after the wake, as pico-extras does. Only the GPIO
dormant-wake detector can wake the chip, so PM_SLEEP gives the
standby state when no wake GPIO is configured. The wake GPIO also
raises a one-shot interrupt, so that the core leaves its WFI and
restores the PLLs at once. The time of day is taken back from the
always-on timer after the wake.
The dormant state stops the UARTs. A PM_STANDBY wakelock
(pm_staytimeout()) is held for RP23XX_PM_WAKE_HOLD_MS after a dormant
wake and after each character a UART receives. The serial driver
refuses PM_SLEEP in its prepare callback while a UART transmits. A
dormant chip does not answer SWD, so the pm configurations use
PM_GOVERNOR_EXPLICIT_RELAX to stay out of it for a time after boot.
With RP23XX_PM_QUIESCE_PADS, arm_pminitialize() also isolates the
unused pads and holds the blocks with no driver in reset. A floating
bank 0 input settles near 2.2V (erratum RP2350-E9) and its input
buffer then draws a static current in every state.
Also select ARCH_HAVE_PM, and fix the LED PM callbacks of three boards,
which used BOARD_LED where the boards define BOARD_LED1. They did not
build with CONFIG_PM.
Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
Add the blank line after the declarations in up_putc() and in
rp23xx_led_pminitialize() of three boards. Whitespace only.
Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
stat() returned st_ino 0 and readdir() returned d_ino 0 for every file
on a v9fs mount, although 9P identifies each file by its qid path.
Programs that skip directory entries with d_ino 0, or that compare
st_dev and st_ino to find out if two paths are the same file, do not
work on such a mount.
Fold the 64-bit qid path into ino_t the same way for both, so that they
match, and never return 0.
Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
At the end of a directory the 9P server returns no entries.
v9fs_client_convertdir() then failed with -EIO, so readdir() returned
NULL with errno set to EIO at the end of every directory. A program
that checks errno after readdir() reports an I/O error.
Return -ENOENT when the server returns no entries. The VFS turns that
into a clean end of directory. Also check the space for the fixed part
of an entry against the bytes left after head, not against the whole
buffer.
Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
nxstyle reports a missing blank line after a declaration in
v9fs_vfs_ioctl(). No functional change.
Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
The QEMU virt machine has a PL031 RTC at 0x09010000 (SPI 2), which QEMU
sets from the host clock. qemu-armv8a did not register it, so the
system time started at CONFIG_START_YEAR, and files on a host share
(v9fs, hostfs) had times years in the future.
With CONFIG_RTC_PL031, up_rtc_initialize() now registers the PL031 as
the RTC, so the system time starts at the host's time.
The new option QEMU_RTC_PL031_SYNC makes the boot wait (up to a second)
for the RTC second to change. The PL031 counts whole seconds, so
without the wait the time starts up to a second behind the host.
Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
struct pl031_lowerhalf_s always had a struct lower_setalarm_s field,
but rtc.h defines that type only with CONFIG_RTC_ALARM, so the driver
did not compile without alarms. No configuration enabled RTC_PL031, so
nothing caught it. The field is used only by the alarm code; give it
the same condition.
Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
arch_setjmp.S stores d8-d15 only under CONFIG_ARCH_FPU, but it did not
include nuttx/config.h. So setjmp() never saved these registers and
longjmp() never restored them. They are callee-saved (AAPCS64), so a
function that kept a value in one of them could see it change after a
longjmp().
Include nuttx/config.h. The assembly then stores d8-d15, eight bytes
each, at offsets 112 to 176. struct setjmp_buf_s declared them as
eight 4-byte floats, 32 bytes short, so declare them as uint64_t too.
jmp_buf is now 176 bytes with the FPU, and its layout matches the
assembly.
Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
pgalloc() grows a process heap for sbrk(). It extended the address
environment of the running task (addrenv_own). While exec() sets up a
new process, the caller selects the new address environment and
allocates the new process's stack from its heap. When that stack does
not fit in the initial heap, the heap must grow, but the running task is
the caller. For the kernel thread that starts init this was an
assertion; for a user task it would have grown the caller's heap.
Use the selected address environment (addrenv_curr). For a normal sbrk()
it is the same as addrenv_own.
Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
C99 7.16 requires true and false to expand to the integer constants 1
and 0, suitable for use in #if. NuttX defined them as (bool)1 and
(bool)0, so a preprocessor condition such as "#if !true" did not
compile.
Define them as 1 and 0. The values do not change; only their type in
an expression changes, from bool to int, as the standard requires.
Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
<memory.h> declares the memory functions of <string.h>, such as
memcpy() and memset(). It is not in POSIX, but glibc, musl and newlib
provide it, and some programs still include it. On NuttX they failed:
fatal error: memory.h: No such file or directory
Add it. It only includes <string.h>.
Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>