Commit graph

63330 commits

Author SHA1 Message Date
Jukka Laitinen
d4a3d255a4 arch/arm/src/imxrt: Add the clock configuration for iMXRT118x
Port the ccm / clock configuration from iMX93 to iMXRT118x.
Register definitions are generated from RM using AI

Assisted-by: Claude Code:claude-opus-4-7
Signed-off-by: Jukka Laitinen <jukka.laitinen@tii.ae>
2026-09-19 22:38:45 +08:00
Jukka Laitinen
f6aa5c115e arch/arm/src/imxrt/chip.h: Add cache line definitions for Cortex-M33
i.MXRT118x have a Cortex-M33, which is ARMv8-M. Add cache line definitions
for this one.

Signed-off-by: Jukka Laitinen <jukka.laitinen@tii.ae>
2026-09-19 22:38:45 +08:00
Jukka Laitinen
caa09a6557 arch/arm/imxrt: Add imxrt118x irq definitions
Add interrupt numbering for imxrt118x in imxrt118x_irq.h, and support
for more interrupts in imxrt_irq.c and imxrt_clrpend.c.

The interrupt numbers are generated from the Reference Manual by AI

Assisted-by: Claude Code:claude-opus-4-7
Signed-off-by: Jukka Laitinen <jukka.laitinen@tii.ae>
2026-09-19 22:38:45 +08:00
Jukka Laitinen
5095237337 arch/arm/imxrt: Add imxrt118x_memorymap
Add imxrt118x memorymaps as hardware/rt118x/imxrt118x_memorymap.h

Assisted-by: Claude Code:claude-opus-4-8
Signed-off-by: Jukka Laitinen <jukka.laitinen@tii.ae>
2026-09-19 22:38:45 +08:00
Jukka Laitinen
6b0f85b768 arch/arm/imxrt: LPUART DMA fixes
- Only submit and account for a wrapped second TX segment when scatter/gather descriptors
  are available. Without in-memory TCDs, submitting the second segment overwrites the
  active hardware descriptor and incorrectly advances the serial buffer past unsent data.
- Invalidate DMA RX buffer initially

Signed-off-by: Jukka Laitinen <jukka.laitinen@tii.ae>
2026-09-19 22:38:45 +08:00
Jukka Laitinen
b59d3aadf5 arch/arm/imxrt: Allow placing primary ram into TCM in allocateheap
Add support for placing the primary ram into SysTCM on M33 cores or DTCM on M7

Signed-off-by: Jukka Laitinen <jukka.laitinen@tii.ae>
2026-09-19 22:38:45 +08:00
Marcio Ribeiro
80ccc5d9aa arch/risc-v/espressif: pick oneshot TIMG from SoC instance count
Some SoCs have a single timer group, so a hardcoded GROUP_ID of 1
overflowed soc_timg_gptimer_signals and crashed in
periph_rcc_acquire_enter. Guard gptimer group 1 behind
TIMG_LL_GET(INST_NUM) as well.

Assisted-by: Claude:claude-opus-5
Signed-off-by: Marcio Ribeiro <marcio.ribeiro@espressif.com>
2026-09-19 22:33:34 +08:00
Liam Howatt
27d948a27f Documentation/stm32h5: board.h clock defines.
Document the board.h keep-HSI-running-in-stop-mode define
STM32_BOARD_HSIKERON_ENABLE and the USART clock source
selection defines.

Signed-off-by: Liam Howatt <liamhowatt@geotab.com>
2026-09-19 08:52:17 -03:00
Liam Howatt
fa1d52a64d arch/arm/stm32h5: Add USART wake from low power.
Support USART waking from low power modes, allow keeping
HSI running in STOP mode, allow specifying clock source
for USARTs, add some missing register and field definitions.

stm32 common Kconfigs:
Add common STM32 UART config options USARTx_WAKE_FROM_LOW_POWER and USARTx_WUS
for USART to cause wake up from low power modes.

stm32h5 board configs:
Allow board.h to choose the clock source of each USART.
Allow board.h to express that HSI should continue running
in low power modes.

stm32h5 RCC:
Set the clock source for each USART if specified in the
board configs (STM32_RCC_CCIPR1_USARTxSEL).
Keep HSI on in STOP mode if specified in the board configs
(STM32_BOARD_HSIKERON_ENABLE).

stm32h5 serial driver:
Use the new USARTx_WAKE_FROM_LOW_POWER and USARTx_WUS in
stm32h5 serial driver to wake from low power modes.
Use the USART clock source specified by board configs.
Enable FIFOs.
Clear UE bit before initialization.

Co-authored-by: Javier Casas <javiercasas@geotab.com>
Co-authored-by: daniellizewski <daniellizewski@geotab.com>
Signed-off-by: Liam Howatt <liamhowatt@geotab.com>
2026-09-19 08:52:17 -03:00
Liam Howatt
85441f47a8 arch/arm/stm32h5: Fix nxstyle issues in stm32_serial.c.
Fix nxstyle issues in arch/arm/src/stm32h5/stm32_serial.c

Signed-off-by: Liam Howatt <liamhowatt@geotab.com>
2026-09-19 08:52:17 -03:00
Liam Howatt
92376dbac4 arch/arm/stm32h5: Fix duplicate define STM32_OTP_BASE.
STM32_OTP_BASE was defined independently in two separate contributions.
Remove one.

Signed-off-by: Liam Howatt <liamhowatt@geotab.com>
2026-09-19 08:52:17 -03:00
Marcio Ribeiro
35e6c252f4 arch/risc-v/espressif: add line-fitting ADC calibration
Use the HAL line-fitting APIs when curve fitting is not available.

Assisted-by: Cursor:Grok 4.6
Signed-off-by: Marcio Ribeiro <marcio.ribeiro@espressif.com>
2026-09-18 14:18:55 -03:00
wenquan1
1532596f6a net: fix pre-existing coding style issues in timestamp-related files
Fix coding style issues flagged by nxstyle in files touched by the
SO_TIMESTAMPING series. These are pre-existing issues, not introduced
by the SO_TIMESTAMPING patches:

- inet_sockif.c: missing blank lines after declarations
- ipv4_input.c: missing blank line after declaration, bad comment alignment
- can_input.c: bad indentation inside #ifdef block
- getsockopt.c: bad comment block alignment, bad brace alignment
- setsockopt.c: wrong column position of comment
- sim_netdriver.c: missing blank lines after declarations

Signed-off-by: wenquan1 <wenquan1@xiaomi.com>
2026-09-18 20:00:49 +08:00
wenquan1
95f8c54836 arch/sim: support SO_TIMESTAMPING TX in sim netdriver
Add TX timestamp loopback support to the simulator network driver.
When a packet tagged with io_conn (SO_TIMESTAMPING TX) is sent,
the driver clones the packet, generates a software timestamp, and
queues it for loopback through the RX path. The protocol layer
(UDP/PKT) then delivers the timestamp via MSG_ERRQUEUE.

- Add tstampq IOB queue to sim_netdev_s for loopback packets.
- In netdriver_send(), clone timestamped packets with realtime
  clock and notify RX ready.
- In netdriver_recv(), return loopback packets before reading
  from the tap device.

Signed-off-by: wenquan1 <wenquan1@xiaomi.com>
2026-09-18 20:00:49 +08:00
wenquan1
935f830e16 include/sys/socket.h: add SCM_TIMESTAMPNS and SCM_TIMESTAMPING macros
Add missing SCM_TIMESTAMPNS and SCM_TIMESTAMPING control message type
definitions mapped to their corresponding SO_TIMESTAMPNS and
SO_TIMESTAMPING socket options. Also align whitespace of existing
SCM_* definitions for consistency.

Signed-off-by: wenquan1 <wenquan1@xiaomi.com>
2026-09-18 20:00:49 +08:00
wenquan1
cf78962356 net/socket: merge CONFIG_NET_TIMESTAMPING into CONFIG_NET_TIMESTAMP
Consolidate the two separate timestamp Kconfig options into a single
CONFIG_NET_TIMESTAMP option that covers SO_TIMESTAMP, SO_TIMESTAMPNS
and SO_TIMESTAMPING socket options.

Previously CONFIG_NET_TIMESTAMPING was a separate option only used by
PKT sockets for hardware TX/RX timestamps and error queue support.
Since both options guard the same io_time field in iob_s and share
the s_options bitmask, merging them simplifies configuration without
functional impact.

Changes:
- Replace all CONFIG_NET_TIMESTAMPING with CONFIG_NET_TIMESTAMP in
  pkt_input.c, pkt_recvmsg.c, pkt_sendmsg_buffered.c,
  pkt_sendmsg_unbuffered.c, pkt_sockif.c, pkt_netpoll.c, pkt.h,
  setsockopt.c, getsockopt.c
- Simplify iob.h conditional from OR of both to single option
- Remove NET_TIMESTAMPING Kconfig entry, update NET_TIMESTAMP
  description to cover all three socket options

Signed-off-by: wenquan1 <wenquan1@xiaomi.com>
2026-09-18 20:00:49 +08:00
wenquan1
7c87b4586c net/socket: use s_options for SO_TIMESTAMP instead of per-conn field
Remove the redundant `timestamp` field from `udp_conn_s` and use the
existing `s_options` bitmask to track SO_TIMESTAMP/SO_TIMESTAMPNS state.

The socket-level setsockopt/getsockopt already handles SO_TIMESTAMP via
_SO_SETOPT/_SO_GETOPT on s_options. The protocol-level handlers in
inet_sockif.c were intercepting the option before the socket layer,
causing s_options to never be set. This also meant SO_TIMESTAMPNS was
broken since inet_sockif.c only handled SO_TIMESTAMP.

Changes:
- Remove udp_conn_s.timestamp field from udp.h
- Remove SO_TIMESTAMP get/set handlers from inet_sockif.c, letting
  them fall through to the socket-level handler
- Simplify udp_recvfrom.c to call cmsg_store_timestamp() directly,
  which already checks s_options internally
- Align pkt_input.c software timestamp generation with ipv4/can by
  removing per-socket SO_TIMESTAMP option check, only checking
  hardware timestamp capability

Signed-off-by: wenquan1 <wenquan1@xiaomi.com>
2026-09-18 20:00:49 +08:00
wenquan1
238cfa4a31 net/pkt: fix scheduling when receiving MSG_ERRQUEUE
Fix a scheduling issue where MSG_ERRQUEUE readiness was
not properly waking poll waiters in pkt_netpoll.c.


Signed-off-by: wenquan1 <wenquan1@xiaomi.com>
2026-09-18 20:00:49 +08:00
wenquan1
be3446850a net/pkt: support SO_TIMESTAMPING and MSG_ERRQUEUE
Add SO_TIMESTAMPING TX path for PKT sockets. Tagged TX
packets loop back through the driver with io_conn set,
are routed into conn->errahead, and delivered to userspace
via recvmsg(MSG_ERRQUEUE) with SO_TIMESTAMPING cmsg.
Add poll(POLLPRI) notification when errahead is non-empty.


Signed-off-by: wenquan1 <wenquan1@xiaomi.com>
2026-09-18 20:00:49 +08:00
OceanfromXiaomi
28402b9b35 net: add NETDEV_RX_STAMP flag in d_features
Replace compile-time CONFIG_ARCH_HAVE_NETDEV_TIMESTAMP with
a runtime NETDEV_RX_STAMP bit in net_driver_s.d_features.
Drivers providing hardware RX timestamps set the flag at
probe time; the stack checks it at runtime.


Signed-off-by: OceanfromXiaomi <zhaohaiyang1@xiaomi.com>
2026-09-18 20:00:49 +08:00
OceanfromXiaomi
c6878db031 net/utils: extract cmsg_store_timestamp helper
Extract a common cmsg_store_timestamp() helper that checks
SO_TIMESTAMP/SO_TIMESTAMPNS via s_options and appends the
appropriate cmsg. Replaces per-protocol timestamp formatting
in CAN, PKT, and UDP receive paths.


Signed-off-by: OceanfromXiaomi <zhaohaiyang1@xiaomi.com>
2026-09-18 20:00:49 +08:00
OceanfromXiaomi
9a65ffc51d net: move rx timestamp from d_rxtime to iob_s.io_time
Move RX timestamp storage from net_driver_s.d_rxtime into
iob_s.io_time so each IOB carries its own timestamp through
the stack. Remove old iob_trycopyin/iob_copyout timestamp
packing in CAN/PKT/UDP paths. Fix iob_clone_partial to copy
io_time before source pointer advances to NULL.

Signed-off-by: OceanfromXiaomi <zhaohaiyang1@xiaomi.com>
Signed-off-by: wenquan1 <wenquan1@xiaomi.com>
2026-09-18 20:00:49 +08:00
wangjianyu3
f492f136c2 boards/rp2040: switch waveshare nsh/usbnsh configs to nxinit entrypoint
Switch CONFIG_INIT_ENTRYPOINT from nsh_main to nxinit's init_main for
the shell-capable configs (nsh, usbnsh) of waveshare-rp2040-zero and
waveshare-rp2040-lcd-1.28.  nsh now runs as a "console sh" service
started by init.rc instead of being the top-level init task.

Add etc/init.d/init.rc to the shared common/src RCSRCS, gated on
CONFIG_ETC_ROMFS && CONFIG_SYSTEM_NXINIT, so one copy covers both
boards, plus a .gitignore for the etctmp files Board.mk generates from
it.  The four defconfigs also set CONFIG_SYSTEM_NXINIT=y with its
Kconfig deps, CONFIG_ETC_ROMFS=y and CONFIG_FS_ROMFS=y.

nsh_main connected the CDC/ACM gadget itself via
boardctl(BOARDIOC_USBDEV_CDCACM); init_main does not, so the usbnsh
configs would otherwise come up with no USB console.  Run sercon from
init.rc and enable CONFIG_SYSTEM_CDCACM in those two defconfigs to keep
that step.

Assisted-by: Claude:claude-sonnet-5
Signed-off-by: wangjianyu3 <wangjianyu3@xiaomi.com>
2026-09-18 08:47:09 -03:00
Daniel P. Carvalho
9e93888220 stm32/adc: add support for differential mode (DIFSEL) and calibration
Add board-level configuration and driver support for differential input
channels and auto-calibration on STM32 ADC IPv2 and IPv2G4 (STM32F3,
STM32G4), following the STM32H5 architecture pattern requested in review:

- In hardware headers (stm32_adc_v2.h and stm32_adc_v2g4.h), fix register
  comments and define ADC_DIFSEL register shift and masks.
- In stm32_adc_m3m4_v1v2.c:
  - Add difsel field to struct stm32_dev_s initialized from
    BOARD_ADCx_DIFSEL if defined, falling back to ADC_DIFSEL_DEFAULT (0).
  - Configure DIFSEL before enabling the ADC in adc_configure().
  - Fix and enable adc_calibrate() for HAVE_IP_ADC_V2, supporting both
    single-ended calibration (ADCALDIF=0) and differential calibration
    (ADCALDIF=1) based on the channel selection.

Verified on Nucleo-G431KB (single-ended and differential channel 1).

Assisted-by: Gemini:gemini-2.5-pro
Signed-off-by: Daniel P. Carvalho <danieloak@gmail.com>
2026-09-18 08:46:18 -03:00
raiden00pl
ce3dbf6539 drivers/serial/serial.c: fix nxstyle
drivers/serial/serial.c: fix nxstyle

Signed-off-by: raiden00pl <raiden00@railab.me>
2026-09-18 08:36:25 -03:00
raiden00pl
96c5330ea6 drivers/serial: bulk-copy raw output into the TX buffer
uart_writev() queues output one byte at a time via uart_putxmitchar().
Add uart_putxmitbuf() that memcpy()s a whole run into the TX ring buffer
and use it when no per-byte processing is needed (OPOST and ECHO clear,
not a console).  On a full buffer fall back to uart_putxmitchar(), which
keeps the blocking and error handling unchanged.

8 MiB write() to /dev/ttyACM0 on nRF52840: 455 -> 573 KB/s.
Guarded by CONFIG_SERIAL_TXBULK, default !DEFAULT_SMALL.

Assisted-by: Claude Code
Signed-off-by: raiden00pl <raiden00@railab.me>
2026-09-18 08:36:25 -03:00
Liam Howatt
2c7cf5ab03 Documentation/stm32h5: OTP is supported.
Describe the OTP API in stm32h5 platform documentation.

Signed-off-by: Liam Howatt <liamhowatt@geotab.com>
2026-09-18 16:33:48 +08:00
Liam Howatt
65775f26a7 arch/arm/stm32h5: Add OTP support.
Add an API for OTP (one-time programmable) memory on stm32h5.
There are OTP APIs for non-STM32 platforms.
There is no other API for STM32 so far with these names.

Implement it in stm32h563xx_flash.c since the progmem abstraction
also lives there.

int stm32_otp_write(const uint16_t *data, uint16_t len, uint32_t offset);
int stm32_otp_read(uint16_t *data, uint16_t len, uint32_t offset);
The API allows cross-block reads/writes that don't necessarily
start/end at block boundaries.
The type of `data` is uint16_t * to express to the caller that the
pointer should be 2-aligned. The natural size of OTP words is 16 bits.
`len` is uint16_t for no strong reason. Preserve author's work.

uint32_t stm32_otp_getlockstatus(void);
Get a mask of blocks that are locked. A block being locked
is considered as being one-time programmed.

Co-authored-by: Mykhailo Sopiha <mykhailosopiha@geotab.com>
Signed-off-by: Liam Howatt <liamhowatt@geotab.com>
2026-09-18 16:33:48 +08:00
Ulaş Sertan Kemeç
0474b8d406 Documentation/am67: Document eCAP APWM support on t3-gem-o1.
Record the eCAP1 and eCAP2 APWM outputs in the board's Peripheral
Support list.

Assisted-by: Claude Code:claude-opus-5
Signed-off-by: Ulaş Sertan Kemeç <sertan.usk@gmail.com>
2026-09-18 16:25:31 +08:00
Ulaş Sertan Kemeç
986394a56d arch/arm/am67: Add eCAP APWM lower-half driver.
Adds a PWM lower-half using the eCAP modules in APWM mode as single-channel
generators rather than capture units.

start() reprograms the time base only when the frequency changes, so a
duty-only update does not stop or zero a live counter.

t3-gem-o1 registers /dev/ecap1 and /dev/ecap2; output pad selection is left to
the board, as the candidates collide with I2C0.

Verified on t3-gem-o1: examples/pwm runs a 1 kHz, 50% duty train on both
instances and accepts a duty-only change (25% then 75%).  The output pins have
not been measured on copper, as no pad is assigned to them on this board.

Assisted-by: Claude Code:claude-opus-4-8
Signed-off-by: Ulaş Sertan Kemeç <sertan.usk@gmail.com>
2026-09-18 16:25:31 +08:00
Aurora-QIU0
637a53c136 risc-v/espressif: Fix I2C SCL/SDA pin attribute masks.
esp_i2c.c composes the pin attribute masks handed to esp_configgpio()
using the logical OR operator instead of the bitwise OR operator:

    #define SCL_PIN_ATTR (FUNCTION_2 || INPUT_PULLUP || OUTPUT_OPEN_DRAIN)
    #define SDA_PIN_ATTR (FUNCTION_2 || INPUT_PULLUP || OUTPUT_OPEN_DRAIN)

Every operand is a non-zero bit field, so the expression collapses to 1
rather than to the intended combination.  With the encodings defined in
esp_gpio.h the mask must be 171 (0xab):

    FUNCTION_2        (2 << FUNCTION_SHIFT) = 128
    INPUT_PULLUP      (INPUT | PULLUP)      = 9
    OUTPUT_OPEN_DRAIN (OUTPUT | OPEN_DRAIN) = 34

Passing 1 to esp_configgpio() selects input mode only: output and
open-drain remain disabled, the pull-up is not enabled and the function
field does not match, so the pin falls back to plain GPIO function.  The
I2C peripheral signal then never reaches the pads; the bus is left
floating while the transfer state machine still reports completion.

Every other pin attribute mask in this directory (esp_i2c_slave.c,
esp_i2c_bitbang.c, esp_spi.c, esp_twai.c) already uses the bitwise
operator for the same encodings, so esp_i2c.c was the only outlier.

Since this file is modified by this commit, the pre-existing nxstyle
violations reported by the check job are fixed as well, as asked in
CONTRIBUTING.md section 2.1 (adapt all modified files even if you did
not introduce the problem yourself):

* esp_i2c.c:1267      - statement over-indented inside its enclosing
                        block (8 spaces where the block body is at 6)
* esp_i2c.c:1303      - missing blank line after declarations
* esp_i2c.c:1592      - missing blank line after declarations
* esp_i2c.c:1710-1725 - 'case'/'default' labels inside switch(port)
                        sat at the same indent as the brace opening
                        the switch body; they belong one level further
                        in, with the case logic one more level in from
                        the label

Assisted-by: WorkBuddy:DeepSeek-V4.1-Flash
Signed-off-by: Aurora-QIU0 <2170685247@qq.com>
2026-09-18 16:15:14 +08:00
Daniel P. Carvalho
1b172fb8d2 drivers/sensors: add Microchip TC74 temperature sensor driver
Add support for the Microchip TC74 digital temperature sensor using the
Sensor Driver Framework (uORB). The TC74 is an 8-bit I2C temperature
sensor with a measurement range from -40C to +125C and a resolution
of 1C.

The driver registers as a uORB topic (/dev/uorb/sensor_temp<n>) and
polls on the low-priority work queue. It supports dynamic interval
configuration and automatically enters low-power standby mode when
the topic is deactivated.

Validated against a real TC74A5-3.3 on a custom STM32H743BI board.

Assisted-by: Gemini:gemini-3.8-pro
Signed-off-by: Daniel P. Carvalho <danieloak@gmail.com>
2026-09-18 16:04:32 +08:00
Aurora-QIU0
86159f3353 risc-v/espressif: Fix I2C polling wait timeout comparison.
clock_t is an unsigned type unless CONFIG_SYSTEM_TIME64 is selected, as
documented in sys/types.h.  The difference in

    while (current - timeout < 0 && priv->error == 0)

therefore underflows to a large positive value instead of being
negative, the comparison is always false, and the loop body never runs.
status keeps its initial value of zero and the function returns OK
without having waited for the transfer at all.

Because the polling path reports completion immediately, every transfer
looks successful: no timeout is ever raised and register reads return
whatever the RX FIFO happens to contain.  The function is compiled in
under CONFIG_I2C_POLLED, which boards use when the I2C interrupt is not
wired up.

Cast the difference to int32_t to get the intended signed comparison.
The result also stays correct across the counter wrap, as long as the
timeout is shorter than the counter range, which SEC2TICK(10) satisfies.

Since this file is modified by this commit, the pre-existing nxstyle
violations reported by the check job are fixed as well, as asked in
CONTRIBUTING.md section 2.1 (adapt all modified files even if you did
not introduce the problem yourself):

* esp_i2c.c:1267      - statement over-indented inside its enclosing
                        block (8 spaces where the block body is at 6)
* esp_i2c.c:1303      - missing blank line after declarations
* esp_i2c.c:1592      - missing blank line after declarations
* esp_i2c.c:1710-1725 - 'case'/'default' labels inside switch(port)
                        sat at the same indent as the brace opening
                        the switch body; they belong one level further
                        in, with the case logic one more level in from
                        the label

Assisted-by: WorkBuddy:DeepSeek-V4.1-Flash
Signed-off-by: Aurora-QIU0 <2170685247@qq.com>
2026-09-18 15:59:11 +08:00
Felipe Moura
d656cfa930 xtensa/espressif: fix lock-order deadlock in esp_wifi_event_handler()
esp_wifi_event_handler() held esp_wifi_lock() across the whole event
switch, including the esp_wlan_*_hook() calls
(WIFI_EVENT_STA_CONNECTED/_DISCONNECTED, WIFI_EVENT_AP_START/_STOP).
Those hooks reach netdev_lower_carrier_on()/_off(), which take the
per-device netdev_lock().

Every other path into esp_wifi_lock() acquires the two locks in the
opposite order -- the netdev ifdown path holds netdev_lock() around
its own call into esp_wifi_api_stop(), which calls esp_wifi_lock().
An application that disconnects Wi-Fi (wpa_driver_wext_disconnect()
immediately followed by wapi_set_ifdown()) races the resulting
WIFI_EVENT_STA_DISCONNECTED callback against its own ifdown call, and
the two lock orders wedge each other permanently.

Confirmed on real ESP32-S3 hardware (XIAO ESP32-S3,
CONFIG_ESPRESSIF_WIFI + CONFIG_PM + CONFIG_SCHED_TICKLESS): the
disconnecting task and the low-priority work-queue thread each waited
on a mutex held by the other (checked live via JTAG/GDB, not inferred
from code reading alone). Reproduced 4/4 times before this fix, 0/2
after.

Fix: esp_wifi_lock() is now taken only around the specific calls that
reach into the Wi-Fi driver API (esp_wifi_scan_event_parse(),
esp_wifi_set_ps()), never spanning a esp_wlan_*_hook() call --
netdev_lock() first (or absent), esp_wifi_lock() last, on every path.

Signed-off-by: Felipe Moura <moura.fmo@gmail.com>
Assisted-by: Claude:claude-sonnet-5
2026-09-18 15:57:44 +08:00
Alan Carvalho de Assis
c95c546c09 wireless/bluetooth: Fix record stride in descriptor discovery response.
att_find_info_rsp() computed the per-record stride with sizeof(info.i16)
and sizeof(info.i128), but "info" is a union of two pointers, so both
expressions evaluate to the pointer width instead of the size of the
record that the response format selects.  The records are 4 octets for a
16-bit UUID and 18 octets for a 128-bit UUID, so the 128-bit path
advanced by 4 (or 8) octets per iteration while reading an 18-octet
record: handles and UUIDs were parsed from the wrong offsets and the walk
ran past the end of the received PDU.  On 64-bit builds the 16-bit path
was wrong too.

Take the stride from the record structures, and require the response to
carry whole records before walking it, since the loop advances one record
at a time and a partial trailing record would be parsed as a whole one.

Ref: Core v6.0, Vol 3, Part F, 3.4.3.2 (ATT_FIND_INFORMATION_RSP)
Testing: sim:bluetooth builds with Make, no new warnings.  Not yet
exercised at runtime; the scriptable controller that can inject a
malformed Find Information Response is added separately.

Signed-off-by: Alan C. Assis <acassis@gmail.com>
Assisted-by: Claude Code Opus 5
2026-09-18 11:18:36 +08:00
Daniel P. Carvalho
9b9423a638 sched/clock: update wall time on tickless tick and support slew limit PPM
1. nxsched_process_timer: call clock_update_wall_time() under
   CONFIG_CLOCK_TIMEKEEPING so that wall time is updated on timer
   events during tickless operation.

2. clock_timekeeping_get_wall_time: call clock_update_wall_time()
   before sampling the base and counter.

3. clock_timekeeping: allow overriding NTP_MAX_ADJUST with
   CONFIG_CLOCK_ADJTIME_SLEWLIMIT_PPM if configured.

4. Use clock_t consistently for counter values in clock_timekeeping.c.

Signed-off-by: Daniel P. Carvalho <danieloak@gmail.com>
2026-09-18 09:30:22 +08:00
Daniel P. Carvalho
09423194bf arch/arm/stm32: fix compare-match race and zero-period hang in tickless
This patch addresses two issues in the single-timer capture/compare
tickless OS drivers for STM32 families (common m3m4 v1 for F1/F2/F3/F4/G4,
F7, H7, and WB):

1. Zero-period handling: when up_timer_start() is called with a zero or
   negative duration (or period converts to 0 ticks), the driver now
   enables the compare match interrupt and immediately fires an event
   via EGR (CCxG), avoiding missed events or unexpected counter behavior.

2. Compare-match race condition: after programming CCR and enabling the
   compare interrupt, a post-check validates whether the free-running
   counter already reached or passed count + period during register
   configuration. If elapsed, the interrupt is forced immediately via EGR,
   preventing the counter from missing the match and hanging until a full
   32-bit rollover (approx. 71 minutes at 1 MHz).

Verified on real hardware:
- STM32H743ZI (IED R550): validated with ping, sleep, and usleep.
- STM32G431KB (Nucleo-G431KB): validated with uptime, sleep, and usleep.

Signed-off-by: Daniel P. Carvalho <danieloak@gmail.com>
2026-09-18 09:30:22 +08:00
Felipe Moura
877d1537df xtensa/espressif+riscv: fix PM_NORMAL stay leak in idle loop
up_idlepm() (esp32s3_idle.c/esp32_idle.c/esp32s2_idle.c and the
shared risc-v esp_idle.c for esp32c3/esp32c6) has a recovery branch
that forces the domain back to PM_NORMAL when oldstate is not
PM_NORMAL and nothing is currently staying at it:

    pm_stay(PM_IDLE_DOMAIN, PM_NORMAL);
    pm_changestate(PM_IDLE_DOMAIN, PM_NORMAL);
    newstate = PM_NORMAL;

pm_stay() here has no matching pm_relax() anywhere in any of the
four files. The first time this branch runs, the stay count for
PM_NORMAL never returns to 0, and pm_checkstate() (called
unconditionally right after this block) can never recommend
anything deeper than PM_NORMAL again for the rest of uptime -- the
idle loop keeps running, but the governor is permanently pinned at
full power, with no further light or deep sleep.

Confirmed on real ESP32-S3 hardware (XIAO ESP32-S3,
CONFIG_ESPRESSIF_WIFI + CONFIG_PM + CONFIG_SCHED_TICKLESS): reading
g_pmdomains[0] live via JTAG/GDB showed a "system" wakelock stuck at
state=PM_NORMAL, count=1, acquired a few seconds after boot (right
when Wi-Fi coming up briefly moves the domain off PM_NORMAL and this
branch then forces it back). Reproduced 4/4 times before this fix
(never a single PM_STANDBY transition or light-sleep-return log line
across a 40+ minute run), 0/4 after.

The trigger is timing-dependent (whether anything else already
holds PM_NORMAL at the moment this branch runs), which is likely why
it does not reproduce on every single boot.

Fix: release the stay right after the one pm_changestate() call it
exists to force, matching the comment already there ("Keep working
in normal stage") -- a one-shot nudge, not a standing hold.

Touching the switch statement right below the fix in all four files
exposed a pre-existing nxstyle violation (case labels indented level
with the switch's opening brace instead of one level in from it, per
NuttX style); reindented alongside since checkpatch lints the whole
file. esp32s3_idle.c also had two unrelated stray-indented lines
("Perform IDLE mode power management" / up_idlepm()) in up_idle();
fixed those too, same reason.

Signed-off-by: Felipe Moura <moura.fmo@gmail.com>
Assisted-by: Claude:claude-sonnet-5
2026-09-18 09:19:27 +08:00
Ulaş Sertan Kemeç
35b68203ad board/arm/am67/t3-gem-o1: Move EPWM initialization to its own file
Moves EPWM initialization from am67_bringup.c to am67_pwm.c. Initialization
  now requires only a function call in bringup.c.

  Nxstyle checked, builds same.

Signed-off-by: Ulaş Sertan Kemeç <sertan.usk@gmail.com>
2026-09-17 13:10:57 -03:00
Ulaş Sertan Kemeç
7930953874 Documentation/am67: Document EPWM support on t3-gem-o1.
Record the EPWM0 and EPWM1 outputs in the board's Peripheral Support
list.

Assisted-by: Claude Code:claude-opus-5
Signed-off-by: Ulaş Sertan Kemeç <sertan.usk@gmail.com>
2026-09-17 13:10:57 -03:00
Ulaş Sertan Kemeç
c9c6faa23d arch/arm/am67: Add EPWM0/EPWM1 PWM lower-half driver.
Adds a PWM lower-half for EPWM0 and EPWM1, covering both output channels of
each.  The CTRL_MMR EPWM clock enables are unlocked once during board bring-up.

t3-gem-o1 registers /dev/pwm0 and /dev/pwm1 with PWM_NCHANNELS=2.

Verified on t3-gem-o1: all four outputs (EPWM0 A+B, EPWM1 A+B) drive physical
pins, jumpered into a Linux GPIO input -- 50% and 20% duty read back at the
expected sample ratios, and gpiomon timed a 50 Hz half-period at 9.998-10.002
ms.  examples/pwm starts and stops a 1 kHz train cleanly.

Assisted-by: Claude Code:claude-fable-5
Signed-off-by: Ulaş Sertan Kemeç <sertan.usk@gmail.com>
2026-09-17 13:10:57 -03:00
arnavsharma990
2c940407b5 docs: rv-virt: document elf, libcxx64 and virtual LEDs
Document the purpose of the rv-virt elf and libcxx64 configurations and clarify that the LEDs used by leds64 are virtual/log-only and are not backed by a NuttX GPIO controller.

This addresses issue #20174.
2026-09-17 13:04:31 -03:00
Arnav Sharma
493031e7b1 drivers/mtd/mtd_config: fix UAF in mtdconfig_unregister_by_path
mtdconfig_unregister_by_path() opened the device with file_open(),
which runs mtdconfig_open() and therefore holds dev->lock for the
whole lifetime of the temporary file reference.  It then destroyed
the mutex and freed the private device structure while that
reference was still open, so the subsequent file_close() reached
mtdconfig_close(), which performs nxmutex_unlock() on freed memory.
Destroying a held mutex and unlocking it after free corrupt the heap;
on sim this crashes deterministically in the next allocation
(EXC_BAD_ACCESS in mm_malloc).  Both file_close() and
unregister_driver() return values were also discarded and the
function unconditionally returned OK, masking legitimate errors.

Reorder the teardown to close -> unregister -> destroy/free and
propagate errors, so that:

- file_close() (driver close callback and inode release) runs while
  the private device structure is still valid, releasing the
  exclusive access taken by mtdconfig_open(),
- the private structure is destroyed and freed only after
  unregister_driver() succeeds.  On failure the inode (and with it
  i_private) may still be referenced, so freeing would be wrong.
  Returning the error also honors the documented API contract
  (zero on success, negated errno on failure).

This matches the established close -> unregister -> teardown ordering
used by e.g. bchdev_unregister().

Verified with sim:configdata plus a register/unregister lifetime
exercise in examples/configdata: 934706/934706 checks pass with the
fix; with the fix stashed the same run dies with SIGSEGV right after
mtdconfig_unregister_by_path() returns.

Fixes: https://github.com/apache/nuttx/issues/20166
Signed-off-by: Arnav Sharma <2006arnavsharma@gmail.com>
2026-09-17 11:30:34 -03:00
Daniel P. Carvalho
432717c34c net/pkt: clear pending TX IOB reference when poll callback finishes
pkt_poll() records the outgoing IOB in pkt_conn->pendiob so that any
synchronous TX tap or loopback executed during the driver callback can
skip delivering the packet back to the sending socket.

Previously, pendiob was never cleared upon TX completion and would
linger across transmissions as a dangling pointer. Because the IOB
pool is small and recycled quickly (LIFO), a subsequent incoming
packet from the network frequently reused the same IOB buffer address,
causing pkt_in() to drop legitimate RX packets as false self-echoes.

Drop the pendiob reference immediately after callback(dev) returns in
devif_poll_pkt_connections(), ensuring the pointer never outlives the
transmission cycle.

Also fixes a pre-existing nxstyle alignment issue in devif_poll.c
IPv6 version-check block (unrelated nerr() call), since this file is
now touched and CI enforces style on the whole file.

Suggested-by: zhhyu7
Assisted-by: Gemini:gemini-3.8-flash-medium
Signed-off-by: Daniel P. Carvalho <danieloak@gmail.com>
2026-09-17 09:44:19 -03:00
Felix-LJY
9bfeb92038 arch/arm/n32h7: Add N32H762IIL7 BSP
Add complete BSP for the N32H762IIL7 (ARM Cortex-M7 @ 600MHz)
from Nations Technologies. The port includes chip-level and
board-level support, peripheral drivers and documentations.

Completed drivers:
    GPIO, EXTI, RCC, UART, TIM, PWM, ONESHOT, TICKLESS, DMA,
    FLASH (MTD), CAPTURE, USBHS (Device and Host), CORDIC,
    SDMMC (ADMA2, FATFS verified), UID.

Not yet ported: I2C, SPI, ADC, WDT, RTC, DAC, CAN/FDCAN, ETH.

Assisted-by: DeepSeek:deepseek-chat
Signed-off-by: JingYue LIAO <felix-liao@my.swjtu.edu.cn>
2026-09-17 09:39:41 -03:00
Felipe Moura
aa114f0ec0 xtensa/espressif: resync openeth RX/TX descriptor ring on ifup
openeth_receive() (arch/xtensa/src/common/espressif/esp_openeth.c)
tracks the next expected RX descriptor in priv->cur_rx_desc, an int
initialized to 0 exactly once, in esp_openeth_initialize(). QEMU's
esp32s3 machine models the OpenCores MAC's DMA ring pointer as
resetting to descriptor 0 every time RXEN is toggled off and back on
(openeth_disable()/openeth_enable(), called from ifdown()/ifup()), but
nothing rewinds the driver's own index to match. On the very first
bring-up both start at 0, so nothing looks wrong; from the second
ifup() onward the two permanently disagree, openeth_receive() keeps
inspecting the wrong descriptor, finds it still marked "owned by HW"
(e=1), and silently drops the notification. This breaks all inbound
traffic on the interface, not just application sockets -- ARP replies
and ICMP echo replies are RX frames too, so ping breaks identically.

Re-run the same descriptor initialization esp_openeth_initialize()
does at boot -- re-arm every RX/TX descriptor, rewind
cur_rx_desc/cur_tx_desc to 0 -- inside openeth_ifup(), under the same
critical section that already toggles RXEN.

Board-independent code, and open_eth only exists as a QEMU peripheral,
so there is no real-hardware regression risk.

Assisted-by: Claude:claude-sonnet-5
Signed-off-by: Felipe Moura <moura.fmo@gmail.com>
2026-09-17 07:37:01 -03:00
wangjianyu3
324c894bd2 boards/x86/qemu/qemu-i486: Switch nsh/vga_fb from nsh to nxinit.
Aligns the qemu-i486 nsh and vga_fb defconfigs with the nxinit
migration already done for sim, rv-virt and qemu-armv8a:

- CONFIG_INIT_ENTRYPOINT/ENTRYNAME: "nsh_main" -> "init_main"
- CONFIG_SYSTEM_NXINIT=y, plus its dependencies CONFIG_EXPERIMENTAL,
  CONFIG_LIBC_EXECFUNCS, CONFIG_SCHED_HAVE_PARENT and
  CONFIG_SCHED_CHILD_STATUS
- CONFIG_ETC_ROMFS=y (CONFIG_FS_ROMFS was already enabled on both
  configs)
- New boards/x86/qemu/qemu-i486/src/etc/init.d/init.rc, identical in
  content to boards/arm64/qemu/qemu-armv8a/src/etc/init.d/init.rc
  (service console sh + restart_period 1000, started from `on init`
  under CONFIG_SYSTEM_NSH)
- src/Makefile: add init.rc to RCSRCS when CONFIG_ETC_ROMFS and
  CONFIG_SYSTEM_NXINIT are both set, matching qemu-armv8a's
  src/Makefile

This depends on the previous commit ("arch/x86: Add -P to CPP to
suppress linemarkers."): without it, the preprocessed init.rc that
Board.mk feeds to nxinit's parser at build time still contains GNU
linemarker lines and the parser rejects it with -EINVAL at boot. That
arch-level fix is otherwise independent and can be reverted on its
own without affecting other x86 boards.

qemu-i486 is 32-bit x86 with no romfs_img/romdisk_register/
romfs_boot/romfs_stub definitions anywhere under its board directory,
so it does not hit the romfs_img symbol collision that affects
qemu-intel64 (a separate board, tracked separately); i486 goes
straight from a clean ETC_ROMFS build to a working /etc mount.

Verified under QEMU (qemu-system-i386), both configs, host gcc -m32
(CROSSDEV is unset on Linux, ARCH_X86_M32=y already handles -m32):

nsh (-cpu 486 -m 2):
  nsh> ps
    TID   PID  PPID PRI POLICY   TYPE    NPX STATE    EVENT     SIGMASK            STACK COMMAND
      0     0     0   0 FIFO     Kthread   - Ready              0000000000000000 0002024 Idle_Task
      2     2     0 100 FIFO     Task      - Waiting  Semaphore 0000000000000000 0002004 init_main
      3     3     2 100 FIFO     Task      - Running            0000000000000000 0002012 sh
  nsh> mount
    /etc type romfs
    /proc type procfs
  nsh> free
        total       used       free    maxused    maxfree  nused  nfree name
       572784       9680     563104      10048     563104     52      1 Umem

vga_fb (-cpu 486 -m 1024 -vga std -serial stdio -display none): same
init_main/sh parent-child relationship, /etc romfs mounted, `fb`
framebuffer test completes ("Test finished"); free shows
551696/86832/464864 total/used/free (heavier due to LCD framebuffer
allocations, still well clear of CONFIG_RAM_SIZE=1048576).

ostest (third config on this board, INIT_ENTRYPOINT="ostest_main")
is out of scope and left untouched.

Assisted-by: Claude:claude-sonnet-5
Signed-off-by: wangjianyu3 <wangjianyu3@xiaomi.com>
2026-09-17 16:21:59 +08:00
wangjianyu3
877ea4f8d8 arch/x86: Add -P to CPP to suppress linemarkers.
The x86 CPP definition used `gcc -E -x c` without `-P`, unlike every
other arch's Toolchain.defs (arm, risc-v, avr, mips, misoc, or1k, z16,
z80 all pass `-E -P -x c`). Without `-P`, cpp emits GNU linemarker
lines (e.g. `# 0 "file"`) into its preprocessed output.

boards/Board.mk's PREPROCESS macro runs RCSRCS init.rc files through
$(CPP) before feeding them to apps/system/nxinit's parser. The parser
(apps/system/nxinit/parser.c) matches each line against known section
keywords ("on", "service", ...) with strncmp(); a leading linemarker
line does not match any keyword and the parser returns -EINVAL, so
any board that preprocesses an nxinit init.rc under x86 fails to
parse it at boot.

Reproduced independently on the host toolchain: `gcc -E -x c` on a
minimal init.rc emits `# 0 "file"` lines; `gcc -E -P -x c` on the
same input produces clean `service`/`on` lines only.

Assisted-by: Claude:claude-sonnet-5
Signed-off-by: wangjianyu3 <wangjianyu3@xiaomi.com>
2026-09-17 16:21:59 +08:00
AlmAck
20752312ea fs/inode: bound fdlist_extend() against the requested row
fdlist_extend() grows a task group's descriptor table to 'row' rows of
CONFIG_NFILE_DESCRIPTORS_PER_BLOCK entries each, and guards the growth
against OPEN_MAX:

  if (CONFIG_NFILE_DESCRIPTORS_PER_BLOCK * (orig_rows + 1) > OPEN_MAX)

The check sizes the table at orig_rows + 1, which assumes the caller
only ever grows by a single block.  The function then allocates 'row'
rows, so the two agree only for growth by one.

Callers do skip ahead.  fdlist_dup3() asks for
fd2 / CONFIG_NFILE_DESCRIPTORS_PER_BLOCK + 1, fdlist_dupfile() for the
row holding minfd, and fdlist_copy() for the row holding a parent
descriptor it is duplicating.  Any of those can request a row well past
orig_rows + 1.

Such a request passes the check and the function then allocates and
installs a table with more than OPEN_MAX descriptors.  With the defaults
(8 per block, OPEN_MAX 256) a process holding one row that calls
dup2(fd, 400) ends up with 51 rows, or 408 descriptor slots, against a
256 limit.

Check the row actually being requested.  For single-block growth
row == orig_rows + 1 and the comparison is unchanged.

Signed-off-by: AlmAck <gluca86@gmail.com>
2026-09-17 13:50:27 +08:00
Laczen JMS
b54346fb92 espressif-risc-v: simplify code for simpleboot.
Simpleboot on espressif changes the location of irom and drom segments
in the image. Instead of correcting in `map_rom_segments` a routine
is introduced that corrects the load addresses before calling
`map_rom_segments`.

Signed-off-by: Laczen JMS <laczenjms@gmail.com>
2026-09-17 13:49:53 +08:00