Commit graph

63238 commits

Author SHA1 Message Date
Xiang Xiao
d5d134bc79 fs/aio: raise the default AIO_LISTIO_MAX so LTP keeps passing
The new CONFIG_FS_AIO_LISTIO_MAX option defaults to 10 and lio_listio()
now rejects nent > {AIO_LISTIO_MAX} with EINVAL.  The LTP release pinned
by apps/testing/ltp (20230516) submits 256 requests in a single batch from
conformance/interfaces/lio_listio/2-1.c, so ltp_interfaces_lio_listio_2_1
now fails on every configuration that enables CONFIG_TESTING_LTP
(sim:citest, rv-virt:citest, sim:posix_test):

  lio_listio/2-1.c Error at lio_listio() 22: Invalid argument

The EINVAL check itself is required by POSIX, so keep it and raise the
default instead; the limit no longer costs memory because the requests are
linked through the aiocb's own lio_link.

While here, keep _POSIX_AIO_LISTIO_MAX at its POSIX-mandated value of 2
and let AIO_LISTIO_MAX carry the configurable implementation limit.

Signed-off-by: Xiang Xiao <xiaoxiang@xiaomi.com>
2026-09-14 17:12:49 -03:00
Xiang Xiao
74d2c2d119 fs/aio: use list_clear_node() to mark non-batch requests
aio_fsync()/aio_read()/aio_write()/lio_listio() initialized
aiocbp->lio_link with list_initialize(), which makes the node
self-referential (prev = next = &node).  aio_signal() tests
list_in_list(&lio_link) to detect lio_listio batches, so it wrongly
entered the lio_listio completion path for every standalone AIO
operation and notified through the uninitialized
lio_sigevent/lio_sigwork.

With CONFIG_SIG_EVTHREAD=y, garbage lio_sigevent.sigev_notify ==
SIGEV_THREAD caused nxsig_notification() to queue &lio_sigwork.work
onto the low-priority work queue with garbage func/value.  After the
aiocb was freed, the dangling work_s was dispatched with worker=NULL,
crashing in work_dispatch().

Fix: initialize lio_link with list_clear_node() (prev = next = NULL)
so list_in_list() returns false for non-lio_listio operations and
aio_signal() skips the lio_listio path.

While there, reject a NULL aiocbp in aio_fsync(): POSIX Issue 6 no
longer defines a NULL special case, and the old DEBUGASSERT() panicked
debug builds.

Co-developed-by: dengwenqi <dengwenqi@xiaomi.com>
Co-developed-by: fangxinyong <fangxinyong@xiaomi.com>
Signed-off-by: fangxinyong <fangxinyong@xiaomi.com>
Signed-off-by: dengwenqi <dengwenqi@xiaomi.com>
Signed-off-by: Xiang Xiao <xiaoxiang@xiaomi.com>
2026-09-14 17:12:49 -03:00
Xiang Xiao
3b3e97e4a8 fs/aio: add internal aio_read/aio_write to avoid lio_link overwrite
lio_listio() links each aiocbp->lio_link into its batch list before
submitting the I/O, but submitted the operations through the public
aio_read()/aio_write(), which re-initialized lio_link and destroyed
the list membership.  With an aiocb pre-filled with garbage (as in
ostest), the completion path then walked an invalid list.

Extract aio_read_internal()/aio_write_internal() that skip the
lio_link setup; aio_read()/aio_write() initialize lio_link (and
reject a NULL aiocbp) before calling the internal functions, while
lio_listio() calls the internal functions directly to preserve its
own lio_link setup.  For entries that are not part of a batch,
lio_listio() self-initializes lio_link instead.

Signed-off-by: Xiang Xiao <xiaoxiang@xiaomi.com>
2026-09-14 17:12:49 -03:00
Xiang Xiao
7142c0a19e fs/aio: initialize lio_link in aio_fsync()
aio_fsync() never initialized aiocbp->lio_link, but the reworked
aio_signal() tests list_in_list(&lio_link) on every completion.  With
an uninitialized (or zero-filled) lio_link the behavior was
unpredictable; initialize the node so standalone fsync operations are
self-consistent.

Signed-off-by: tengshuangshuang <tengshuangshuang@xiaomi.com>
2026-09-14 17:12:49 -03:00
Xiang Xiao
41f29b32e9 libc/aio: loop in aio_suspend() until a listed request completes
aio_suspend() checked the completion status once and then performed a
single sigtimedwait().  Any SIGPOLL delivered by an unrelated AIO
operation (one not referenced by 'list') woke the caller even though
none of the awaited requests had completed, and with a timeout the
remaining wait time was not preserved either.

Re-check the completion status after every wakeup and continue
waiting, recomputing the remaining time from the absolute deadline so
that the full timeout is honored.

Signed-off-by: wushenhui <wushenhui@xiaomi.com>
2026-09-14 17:12:49 -03:00
Xiang Xiao
4cec501584 fs/aio: fix aio_read/aio_write return values per POSIX
Per POSIX, aio_read() and aio_write() must return -1 and set errno to
EINVAL when the request cannot be queued (aio_reqprio < 0,
aio_offset < 0), and the error must also be retrievable via
aio_error().  Conversely, when queuing fails with a bad file
descriptor, the error belongs to the asynchronous operation: the
functions must return 0 and report EBADF through aio_error().

- Merge the offset/reqprio checks and return ERROR with errno set,
  after storing the result in aio_result for aio_error().
- Drop the aio_fildes < 0 early return: a closed descriptor is now
  caught by fcntl()/aio_queue() and reported through aio_result with
  the function returning OK.
- aio_error(): report -EINVAL (failed validation) through errno
  instead of returning it as an error value.

Signed-off-by: tengshuangshuang <tengshuangshuang@xiaomi.com>
2026-09-14 17:12:49 -03:00
Xiang Xiao
b7d6c8ff41 fs/aio: fix aioc use-after-free and aio_cancel() issues
aioc_decant() frees the AIO container and detaches the aiocbp.  The
I/O workers (aio_read_worker, aio_write_worker, aio_fsync_worker)
called it before signaling completion, so aio_signal() and any code
touching the container afterwards ran on freed memory.  Additionally,
if the caller closed the file early the detached container could be
reused with a stale file reference.  Move aioc_decant() to after
aio_signal() and use aioc->aioc_aiocbp directly in the workers.

aio_cancel() also had two problems: with no aiocbp it looped over
g_aio_pending with a do/while that skipped the list re-entry check, so
a failed work_cancel() on an already running I/O caused an endless
loop; and an invalid fildes only checked 'fildes < 0' instead of
validating the descriptor, so a closed fd was not reported as EBADF.
Use a for-loop that always advances and validate the descriptor with
file_get()/file_put().

Co-developed-by: wushenhui <wushenhui@xiaomi.com>
Signed-off-by: wushenhui <wushenhui@xiaomi.com>
Signed-off-by: tengshuangshuang <tengshuangshuang@xiaomi.com>
2026-09-14 17:12:49 -03:00
Xiang Xiao
2f4d017bb6 fs/aio: add configurable AIO_LISTIO_MAX limit
lio_listio() never validated 'nent' against {AIO_LISTIO_MAX}, so a
batch larger than the documented limit was silently accepted, and the
hard-coded _POSIX_AIO_LISTIO_MAX value of 2 was too small for real
workloads (LTP uses 10 entries per call).

Add the FS_AIO_LISTIO_MAX Kconfig option (default 10), use it for
_POSIX_AIO_LISTIO_MAX in include/limits.h, validate 'nent' in
lio_listio(), and report the limit through sysconf(_SC_AIO_LISTIO_MAX).

Signed-off-by: tengshuangshuang <tengshuangshuang@xiaomi.com>
2026-09-14 17:12:49 -03:00
Xiang Xiao
1ea86e65fd aio: make the lio_listio() prototype match POSIX
POSIX declares lio_listio() as:

  int lio_listio(int, struct aiocb *restrict const [restrict], int,
                 struct sigevent *restrict);

Update the prototype in include/aio.h (and the implementation and
libc.csv entry) accordingly, and drop the parameter names from the
other aio_* prototypes for consistency.

Signed-off-by: guoshichao <guoshichao@xiaomi.com>
2026-09-14 17:12:49 -03:00
Xiang Xiao
d2489101ac fs/aio: skip lio_link teardown for failed submissions in LIO_WAIT mode
When a queued operation fails immediately (bad fd, EINVAL, or a failed
aio_read/aio_write submission), lio_listio() unconditionally deleted
the aiocbp from the request list.  In LIO_WAIT mode (or when no sig was
requested) the lio_link nodes were never linked into the list, so
list_delete() corrupted memory and crashed.

Only unlink the node when it was actually linked, i.e. when
mode == LIO_NOWAIT and a sigevent was provided.

Signed-off-by: tengshuangshuang <tengshuangshuang@xiaomi.com>
2026-09-14 17:12:49 -03:00
Xiang Xiao
2466219100 fs/aio: guard against all-NULL aiocb lists in lio_listio()
When lio_listio() is called with LIO_NOWAIT and a non-NULL sig, and no
I/O could be queued (or all entries are LIO_NOP/NULL), the completion
notification dereferences a NULL aiocbp picked from an empty iteration,
crashing nxsig_notification().

Scan the list for any non-NULL entry before delivering the
notification, and skip it entirely when the list contains only NULL
entries.

Signed-off-by: zhengyu16 <zhengyu16@xiaomi.com>
2026-09-14 17:12:49 -03:00
Xiang Xiao
ad364be818 fs/aio: rework lio_listio() with a lock-protected request list
Previously, lio_listio() called aio_read()/aio_write() to submit the
I/O and only then initialized the per-request notification state
(aio_priv based), so a worker thread could complete an operation before
that state was set up (thread-unsafe), and the completion notification
hijacked the per-request sigevent machinery.

Rework the implementation: lio_listio() now links every aiocb of the
batch into a list (lio_link) before any I/O is submitted.  When an
operation completes, aio_signal() removes its node from the list under
aio_lock() and delivers the lio_listio completion notification only
when the list becomes empty.  The unused aio_priv field is replaced by
the lio_link/lio_sigevent/lio_sigwork fields in struct aiocb.

Co-developed-by: wushenhui <wushenhui@xiaomi.com>
Signed-off-by: wushenhui <wushenhui@xiaomi.com>
Signed-off-by: Xiang Xiao <xiaoxiang@xiaomi.com>
2026-09-14 17:12:49 -03:00
Xiang Xiao
f35993c638 fs/aio: move lio_listio() to fs/aio
lio_listio() submits I/O through the internal aio_read/aio_write
helpers and is only built when CONFIG_FS_AIO is enabled.  Keeping it in
libs/libc splits one subsystem across two directories and forces fs/aio
to export internal interfaces to the libc build.

Move the file (and its two build system entries) from libs/libc/aio to
fs/aio so that the whole AIO implementation lives in one place.

Signed-off-by: Xiang Xiao <xiaoxiang@xiaomi.com>
2026-09-14 17:12:49 -03:00
raiden00pl
f114f8a5d2 boards/qemu: enable line-buffered NTFC writes
enable line-buffered NTFC writes for qemu targets

Signed-off-by: raiden00pl <raiden00@railab.me>
2026-09-14 23:48:49 +08:00
raiden00pl
a23c593534 boards/sim/citest: enable line-buffered NTFC writes
Exercise the new NTFC line-buffered transport mode in simulator CI.

Signed-off-by: raiden00pl <raiden00@railab.me>
2026-09-14 23:48:49 +08:00
raiden00pl
8f4a5b2bd3 .github/workflows/build.yml: bump NTFC to 0.0.3
Install the published NTFC 0.0.3 package from PyPI instead of the
temporary upstream main dependency.

Keep the retry loop and fail the job when all installation attempts are
exhausted.

Signed-off-by: raiden00pl <raiden00@railab.me>
2026-09-14 23:48:49 +08:00
Jukka Laitinen
885bdef4c3 arch/arm/src/imxrt/imxrt_usbdev.c: Fix nxstyle issues
Some checks are pending
MemBrowse Memory Report / changes-filter (push) Waiting to run
MemBrowse Memory Report / load-targets (push) Waiting to run
MemBrowse Memory Report / identical (push) Blocked by required conditions
MemBrowse Memory Report / analyze (push) Blocked by required conditions
Add blank lines, fix alignment and add braces to switch-case

Signed-off-by: Jukka Laitinen <jukka.laitinen@tii.ae>
2026-09-14 11:03:40 -03:00
Jukka Laitinen
5ec9e6c663 arch/arm/src/imxrt/imxrt_start.c: Fix nxstyle issues
Fix alignment, add blank lines and add braces where missing.

Signed-off-by: Jukka Laitinen <jukka.laitinen@tii.ae>
2026-09-14 11:03:40 -03:00
Jukka Laitinen
2651e2d7f0 arch/arm/src/imxrt/imxrt_serial.c: Fix nxstyle issues
Fix alignment in multiple places

Signed-off-by: Jukka Laitinen <jukka.laitinen@tii.ae>
2026-09-14 11:03:40 -03:00
Jukka Laitinen
ce37887dde arch/arm/src/imxrt/imxrt_ocotp.c: Fix nxstyle issues
Add a missing blank line

Signed-off-by: Jukka Laitinen <jukka.laitinen@tii.ae>
2026-09-14 11:03:40 -03:00
Jukka Laitinen
2a3f06b7bd arch/arm/src/imxrt/imxrt_lpspi.c: Fix nxstyle issues
Add braces to switch-case

Signed-off-by: Jukka Laitinen <jukka.laitinen@tii.ae>
2026-09-14 11:03:40 -03:00
Jukka Laitinen
61b81b63a9 arch/arm/src/imxrt/imxrt_lpi2c.c: Fix nxstyle issues
Add blank lines, fix alignment and add braces to switch-case

Signed-off-by: Jukka Laitinen <jukka.laitinen@tii.ae>
2026-09-14 11:03:40 -03:00
Jukka Laitinen
11e2f01296 arch/arm/src/imxrt/imxrt_irq.c: Fix nxstyle issues
Fix alignment issues

Signed-off-by: Jukka Laitinen <jukka.laitinen@tii.ae>
2026-09-14 11:03:40 -03:00
Jukka Laitinen
ec2faf8dc1 arch/arm/src/imxrt/imxrt_allocateheap.c: Fix nxstyle issues
Add a missing blank line

Signed-off-by: Jukka Laitinen <jukka.laitinen@tii.ae>
2026-09-14 11:03:40 -03:00
Darryl Ring
bc11615732 arch/arm/stm32: Fix includes
Some checks are pending
MemBrowse Memory Report / changes-filter (push) Waiting to run
MemBrowse Memory Report / load-targets (push) Waiting to run
MemBrowse Memory Report / identical (push) Blocked by required conditions
MemBrowse Memory Report / analyze (push) Blocked by required conditions
Remove extra includes sections and quote include arm_internal.h.

Signed-off-by: Darryl Ring <darryl@bluerobotics.com>
2026-09-14 09:07:46 +08:00
Darryl Ring
401ea88622 boards/arm/stm32h5/disco-h563zi: Add netnsh config
Add an NSH config that also adds networking support and some basic
networking utilities.

Signed-off-by: Darryl Ring <darryl@bluerobotics.com>
2026-09-14 09:07:46 +08:00
Darryl Ring
b5bb6f33df arch/arm/stm32h5: Use MDIO bus
Copy the MDIO bus changes from the STM32H7 port.

Assisted-by: Claude:claude-sonnet-5
Signed-off-by: Darryl Ring <darryl@bluerobotics.com>
2026-09-14 09:07:46 +08:00
Lingao Meng
89c4b8ccaf arch/sim: Add runtime HCI socket target option
Some checks are pending
Build Documentation / build-html (push) Waiting to run
MemBrowse Memory Report / changes-filter (push) Waiting to run
MemBrowse Memory Report / load-targets (push) Waiting to run
MemBrowse Memory Report / identical (push) Blocked by required conditions
MemBrowse Memory Report / analyze (push) Blocked by required conditions
Allow sim HCI socket users to select the host-side HCI target at runtime
with --bt-dev.  Passing --bt-dev=hciN overrides CONFIG_SIM_HCISOCKET_DEVID
for the BlueZ HCI user channel, while omitting the option keeps the existing
configured default behavior.

Also allow --bt-dev=/path/to/socket to connect to an H:4 stream exposed
through a Unix-domain socket.  This lets sim applications use a controller
provided by another host process or by a UART-to-Unix-socket bridge without
requiring BlueZ raw HCI privileges for the NuttX process.

Use host-side output for early --bt-dev parse errors, since NuttX stdio is
not initialized before nx_start().

Document the BlueZ and Unix socket modes, including the capability
requirements for BlueZ and the socat bridge example for Unix socket mode.

Testing:

  Host: Ubuntu 22.04 x86_64
  Board/config: sim:bthcisock

  Style checks:

    git diff --check HEAD~2..HEAD
    PATH=/home/mi/bsim-auto-test/.venv/bin:$PATH \
      ./tools/checkpatch.sh -c -u -m -g HEAD~2..HEAD

  Clean build:

    make distclean
    ./tools/configure.sh -l -a ../../nuttx-apps sim:bthcisock
    kconfig-tweak --file .config --set-val STACK_USAGE_WARNING 0
    make olddefconfig
    make -j16

  Invalid runtime argument smoke test:

    ./nuttx --bt-dev=invalid

  Verified the command exits with status 1 and reports the invalid target
  without crashing before nx_start().

  Unix socket HCI smoke test:

    socat -d -d UNIX-LISTEN:/tmp/hci.sock,fork,reuseaddr \
      /dev/ttyACM2,b1000000,raw,echo=0,crtscts=1
    printf 'ifconfig\nbt bnep0 info\npoweroff\n' | \
      timeout 20s ./nuttx --bt-dev=/tmp/hci.sock

  Verified the sim registers the Bluetooth network device as bnep0 and
  bt bnep0 info reads the controller state through the Unix-socket HCI
  path, including BDAddr aa:bb:cc:dd:ee:ff from the attached controller.

Assisted-by: OpenAI Codex
Signed-off-by: Lingao Meng <menglingao@xiaomi.com>
2026-09-13 18:31:59 -03:00
Lingao Meng
6c147f8484 arch/sim: Fix HCI socket watchdog lifetime
Start the simulated HCI socket receive watchdog only after the host HCI
socket has been opened successfully.  The previous code armed the watchdog
immediately after driver registration, before the Bluetooth stack opened the
driver and before the device had a valid host fd.

Cancel the watchdog on close/free and close any opened host fd during
allocation-failure cleanup.  This keeps the polling path tied to the actual
socket lifetime and prevents the watchdog from polling an invalid host fd.

Testing:

  Host: Ubuntu 22.04 x86_64
  Board/config: sim:bthcisock

  Style checks:

    git diff --check HEAD~2..HEAD
    PATH=/home/mi/bsim-auto-test/.venv/bin:$PATH \
      ./tools/checkpatch.sh -c -u -m -g HEAD~2..HEAD

  Clean build:

    make distclean
    ./tools/configure.sh -l -a ../../nuttx-apps sim:bthcisock
    kconfig-tweak --file .config --set-val STACK_USAGE_WARNING 0
    make olddefconfig
    make -j16

  Default startup smoke test:

    printf 'poweroff\n' | timeout 10s ./nuttx

  Verified the sim still reaches NSH and powers off cleanly.  When no
  host HCI controller is available through the default BlueZ target, the
  board reports sim_bthcisock_register() failure and continues booting;
  no invalid-fd watchdog crash occurs.

Assisted-by: OpenAI Codex
Signed-off-by: Lingao Meng <menglingao@xiaomi.com>
2026-09-13 18:31:59 -03:00
Lingao Meng
598a1035a0 arch/sim: Add BabbleSim discrete time support
Add support for using a BabbleSim PHY as the monotonic time source for
the Linux sim target.  When CONFIG_SIM_BSIM_TIME is enabled, the sim
host build links a small host-side time helper against the BabbleSim
PhyCom and Util libraries.  The helper joins the BabbleSim PHY wait
protocol and advances NuttX monotonic time through PB_MSG_WAIT requests
instead of Linux wall-time sleeps.

A SIM binary built with CONFIG_SIM_BSIM_TIME enabled joins BabbleSim time
at startup.  Runtime options allow the test runner to select the
BabbleSim simulation id, PHY id, and device number:

  --sim-bsim-sid=<simulation-id>
  --sim-bsim-pid=<phy-id>
  --sim-bsim-dev=<device-number>

Keep the integration inside the sim host time path rather than exposing
a new application API.  RTC/realtime reads still use the host realtime
clock; the BabbleSim source is used only for monotonic time after the sim
has joined the PHY.  The Kconfig option depends on the sleep based
walltime mode and is disabled for SMP and non-Linux hosts.

The build requires BSIM_COMPONENTS_PATH for headers and either
BSIM_OUT_PATH or BSIM_LIBS_DIR for shared libraries.  The path checks are
skipped for clean, distclean, clean_context, and context targets so a
tree with CONFIG_SIM_BSIM_TIME enabled can still be cleaned without
exporting the BabbleSim environment first.

Document the configuration, build environment, runtime options, and the
requirement that the BabbleSim PHY process is started separately by the
test runner.

Testing:

  Host: Ubuntu 22.04 x86_64
  Board/config: sim:nsh

  Style check:

    git diff --check

  Default sim build and smoke test:

    ./tools/configure.sh -l -a ../nuttx-apps sim:nsh
    make -j16
    printf 'help\npoweroff\n' | timeout 20s ./nuttx

  BabbleSim-enabled build:

    kconfig-tweak --file .config \
      -e SIM_WALLTIME_SLEEP \
      -d SIM_WALLTIME_SIGNAL \
      -e SIM_BSIM_TIME
    make olddefconfig
    BSIM_OUT_PATH=/tmp/bsworld/build/babblesim/bsim \
    BSIM_COMPONENTS_PATH=/tmp/bsworld/build/babblesim/bsim/components \
      make -j16

  Verified actual BabbleSim PHY time integration without a controller by
  starting bs_2G4_phy_v1 and running NSH usleep through the PHY wait
  barrier:

    bs_2G4_phy_v1 -s=<sid> -D=1 -defmodem=BLE_simple -nodump
    printf 'usleep 1000000\npoweroff\n' | \
      ./nuttx --sim-bsim-sid=<sid> \
              --sim-bsim-pid=2G4 \
              --sim-bsim-dev=0

  The same 1 second simulated sleep completed in 19 ms wall time when no
  handbrake device was present.  With handbrake registered as device 1:

    bs_2G4_phy_v1 -s=<sid> -D=2 -defmodem=BLE_simple -nodump
    bs_device_handbrake -s=<sid> -p=2G4 -d=1 -pp=50000 -r=1

  the same NuttX usleep test completed in 985 ms wall time.  A shorter
  200 ms check showed the same behavior: 27 ms without handbrake and
  172 ms with handbrake.  This verifies that NuttX sim time advances
  through the BabbleSim PHY and that the handbrake affects the NuttX sim
  device.

  Also verified make distclean succeeds after CONFIG_SIM_BSIM_TIME was
  enabled and without exporting BSIM_COMPONENTS_PATH.

  BSWorld out-of-tree native BLE examples:

    ./tools/configure.sh -l /path/to/bsim-auto-test/tests/nuttx/native_ble/source/advertiser/config
    make -j16
    exodus --tarball -o /path/to/bsim-auto-test/tests/nuttx/native_ble/source/advertiser/prebuilt/nuttx.tgz nuttx
    ./tools/configure.sh -l /path/to/bsim-auto-test/tests/nuttx/native_ble/source/scanner/config
    make -j16
    exodus --tarball -o /path/to/bsim-auto-test/tests/nuttx/native_ble/source/scanner/prebuilt/nuttx.tgz nuttx
    pytest tests/nuttx/native_ble -q --no-ellisys

Assisted-by: OpenAI Codex
Signed-off-by: Lingao Meng <menglingao@xiaomi.com>
2026-09-13 18:31:59 -03:00
Marco Casaroli
a402aaccb4 Documentation: Point the buildroot links at the repository that still exists.
bitbucket.org/nuttx/buildroot returns 404, as does every other repository
under that Bitbucket organisation.  The buildroot that still carries the
NuttX toolchain, ldnxflat included, is github.com/patacongo/buildroot.

Thirty three files carried the dead address, most of them as a "Bitbucket
download site" for a board's toolchain.  There are no downloads to offer, so
those now name the repository, and the surrounding prose says so.

The other dead Bitbucket addresses are left alone: nuttx/nuttx, nuttx/tools,
nuttx/uclibc and nuttx/nxwidgets need a decision each about what replaces
them, which is not this patch.  patacongo/obsoleted is still there.

Assisted-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
2026-09-13 18:29:40 -03:00
Marco Casaroli
6f75c032eb Documentation, tools/ci: Say where the NXFLAT tools actually come from.
The download link is dead: bitbucket.org/nuttx/buildroot is gone, and the
buildroot that still carries ldnxflat is github.com/patacongo/buildroot.

The instructions were also more than is needed.  mknxflat came in tree with
PR #19600, so only ldnxflat has to be built, and an ordinary arm-none-eabi
GCC compiles and links NXFLAT modules: a board does not have to select
CONFIG_ARM_TOOLCHAIN_BUILDROOT to use them.  What ldnxflat does need is a
binutils source and build tree, because it reads its input through libbfd.

The CI test list said mknxflat is what the container lacks.  It is in tree
now; ldnxflat is the one that is missing.

Assisted-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
2026-09-13 18:29:40 -03:00
Marco Casaroli
50a735bf86 libs/libc/machine/arm: Relocate FDPIC function descriptors.
A function pointer under FDPIC is not a code address.  Because each
PT_LOAD segment is placed independently, a pointer has to carry the data
base its callee will need, so it is a two-word descriptor: the entry
point, and the base to install in the PIC register before branching.
R_ARM_FUNCDESC_VALUE says "the thing you are patching is such a
descriptor", and R_ARM_FUNCDESC says "manufacture one and give me its
address".

Both need state a relocation cannot carry.  A descriptor's second word is
the *object's* data base, from DT_PLTGOT, and R_ARM_FUNCDESC carves
descriptors from a pool whose cursor has to survive from one relocation
to the next.  up_relocate() is handed only a relocation, a resolved
symbol and an address to patch.

arch_data is the existing channel for exactly this -- RISC-V already uses
it to remember a HI20 relocation while its LO12 partner is processed --
but nothing has ever put loader state into it: it is declared zeroed and
written only by up_relocate() itself.  So ARCH_ELFDATA_INIT and
ARCH_ELFDATA_FINI are added, seeding the block from the loadinfo before
the relocation loop and reading the cursor back after.  Both default to
nothing, so an architecture that does not define them is unaffected, and
RISC-V's use of arch_data is untouched.  libelf_relocatedyn() walks both
dynamic tables under one arch_data, so the cursor spans the whole object.

The addend handling is the part that is easy to get wrong.  REL format
keeps the addend in place, in the word about to become the entry point,
and a pointer to a static function is referenced through its *section*
symbol -- the value is the section base and the offset, including the
Thumb bit, is entirely in the addend.  Dropping it yields an even address
and the core faults trying to execute it as ARM code.

The GOT written into a descriptor is the loading object's own, even for
an imported function, which is what makes a callback work: when the base
firmware's qsort() calls back into a module's comparison function, the
module needs its own data base in the PIC register.

libelf_relocatedyn()'s imported-symbol path needed a change to suit.  It
stores the resolved address directly and never calls up_relocate(), which
cannot produce a two-word descriptor, so under FDPIC the resolved value
now goes through up_relocate() and the relocation type decides what to
write.

Implemented for armv7-m and armv8-m, the profiles FDPIC targets; the
other ARM variants gain the arch_data block but no new relocations.
Built and booted mps3-an547:picostest and lm3s6965-ek:qemu-nxflat, the
ELF PIC and NXFLAT users of this code, both unchanged.

Assisted-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
2026-09-13 16:03:32 -03:00
Huang Qi
4e196729e7 arch/risc-v: Add CLIC interrupt threshold support
Some checks are pending
Build Documentation / build-html (push) Waiting to run
MemBrowse Memory Report / changes-filter (push) Waiting to run
MemBrowse Memory Report / load-targets (push) Waiting to run
MemBrowse Memory Report / identical (push) Blocked by required conditions
MemBrowse Memory Report / analyze (push) Blocked by required conditions
and documentation it

Signed-off-by: Huang Qi <huangqi3@xiaomi.com>
2026-09-13 08:31:16 -03:00
Abhishek Mishra
0577a674e7 boards/risc-v/esp32c3: add ESP32-C3 SuperMini support
Add board files, nsh/usbnsh/gpio/wifi configs, and documentation
with V1601 pinout photos.

Assisted-by: Cursor:Grok-4.6
Signed-off-by: Abhishek Mishra <mishra.abhishek2808@gmail.com>
2026-09-13 08:29:50 -03:00
raiden00pl
5a209a853e sched/wqueue: restore -ENOENT from work_cancel() for unqueued work
Some checks are pending
MemBrowse Memory Report / changes-filter (push) Waiting to run
MemBrowse Memory Report / load-targets (push) Waiting to run
MemBrowse Memory Report / identical (push) Blocked by required conditions
MemBrowse Memory Report / analyze (push) Blocked by required conditions
work_cancel() used to return -ENOENT when the work structure was not
in the queue, and callers depend on that: aio_cancel() tears down the
AIO container (file_put() + aioc_free()) only when work_cancel()
reports success, because a work item that is not queued may already be
executing on a worker thread (see the comment in fs/aio/aio_cancel.c).

Since commit 6f72f5481d ("sched/wqueue: Refactor delayed and periodical
workqueue") work_cancel() returns OK unconditionally, and commit
d2e01b9055 ("sched/wqueue: harden custom queue lifecycle") kept that
behaviour and dropped -ENOENT from the function documentation.  Under
SMP the LTP aio_cancel tests then free the aio container and its file
while the lpwork thread is still executing aio_write_worker() on it,
which ends in a page fault in file_write() (f_inode == NULL) and a
panic.

Return -ENOENT again when the work is not queued, and document it.
For the synchronous variant "not queued" alone does not tell whether
the callback is running: the worker scan does, so report OK when a
running callback was found and waited for, and -ENOENT only when the
work was neither queued nor running.

Assisted-by: Claude Code
Signed-off-by: raiden00pl <raiden00@railab.me>
2026-09-13 11:31:41 +08:00
wangjianyu3
221a4b2e4c boards/risc-v/qemu-rv: switch rv-virt pnsh/pnsh64 to nxinit entrypoint
Follow-up to the previous commit, which switched every flat-build
rv-virt nsh defconfig from nsh_main to nxinit (init_main) but left
pnsh and pnsh64 (CONFIG_BUILD_PROTECTED=y) on nsh_main. Under protected
build nxinit's "console sh" service failed to start:
posix_spawnp("sh") resolves through the kernel-space binfmt "builtin"
loader / BINFS, but the kernel-space g_builtins/g_builtin_count table
those rely on was never populated -- CONFIG_BUILD_PROTECTED links
apps/builtin/builtin_list.c only into the user blob (nuttx_user), and
nothing called the boardctl(BOARDIOC_BUILTINS) hand-off NuttX has
provided for this since release 8.1.

With that hand-off now issued by apps/system/nxinit early in init_main()
(nuttx-apps, "system/nxinit: register g_builtins with the kernel under
PROTECTED build"), pnsh/pnsh64 can use nxinit like every other
flat-build rv-virt nsh defconfig. Apply the same minimal
nxinit-essential delta used for the 23 configs switched previously.

Verified on rv-virt:pnsh: `ps` shows init_main as the parent with sh
as its Running child, `ls /bin` lists the builtins, and `hello` runs
(see the PR description for logs).

Assisted-by: opencode-agent/claude-sonnet-5
Signed-off-by: wangjianyu3 <wangjianyu3@xiaomi.com>
2026-09-13 11:15:24 +08:00
wangjianyu3
9bca43a07b boards/risc-v/qemu-rv: switch rv-virt flat nsh defconfigs to nxinit entrypoint
Switch every rv-virt (qemu-rv) flat-build defconfig whose init entry
point was nsh_main to nxinit (init_main): citest, citest64, fb, fb64,
flats, flats64, leds, leds64, leds64_rust, leds64_zig, libcxx,
libcxx64, lvgl64_vector, netnsh, netnsh64, netnsh64_smp, netnsh_smp,
nsh, nsh64, python, smp, smp64, virt_nsh (23 configs; pnsh/pnsh64 are
switched in the following commit). nsh now runs as a "console sh"
service started by init.rc instead of being the top-level init task,
matching boards/arm/qemu-armv7a, boards/arm64/qemu-armv8a and
boards/sim. elf (elf_main) and the 11 kernel-build configs (which use
CONFIG_INIT_FILEPATH) are out of scope and untouched.

Each switched defconfig gains only the nxinit-essential keys
(regenerated with make savedefconfig): CONFIG_INIT_ENTRYPOINT="init_main",
CONFIG_SYSTEM_NXINIT=y and its deps (CONFIG_EXPERIMENTAL,
CONFIG_LIBC_EXECFUNCS, CONFIG_SCHED_CHILD_STATUS), and
CONFIG_ETC_ROMFS=y/CONFIG_FS_ROMFS=y to ship init.rc via ROMFS.

Add boards/risc-v/qemu-rv/rv-virt/src/etc/init.d/init.rc registering a
"console sh" service (guarded by CONFIG_SYSTEM_NSH), shipped via ROMFS
in both the Make (RCSRCS, only when CONFIG_ETC_ROMFS && CONFIG_SYSTEM_NXINIT)
and CMake (nuttx_add_romfs()) builds, matching qemu-armv7a/qemu-armv8a.
rc.sysinit and rcS are left in place: on rv-virt both are empty
license-only shells still referenced unconditionally by boards/Board.mk
for the kernel-build and pnsh/pnsh64 configs.

CONFIG_FS_BINFS=y is added with a binfs mount at CONFIG_PATH_INITIAL
(pre-existing "/system/bin") in
qemu_rv_boardinit.c:board_late_initialize() (gated on CONFIG_FS_BINFS,
so the block and the CONFIG_PATH_INITIAL reference compile out when
binfs is not selected).
Rationale: nxinit resolves the "sh" service via posix_spawnp() ->
exec_spawn() -> load_module(); with CONFIG_LIBC_ENVPATH that walks $PATH
via envpath_next() and stat()s each "$dir/sh" candidate, so it never
reaches the builtin binfmt loader unless a real directory entry exists.
CONFIG_PATH_INITIAL is left at its pre-existing "/system/bin"; mounting
binfs there (rather than repointing PATH) makes "sh" resolvable while
keeping the defconfig delta minimal. This never surfaced under nsh_main,
which runs nsh_consolemain() inline without spawning by relative path.
Equivalent to the binfs mount already present in boards/sim's
sim_bringup.c (which mounts at /bin, its own PATH_INITIAL).

smp and smp64 additionally re-enable binfmt: their CONFIG_DEFAULT_SMALL=y
default pulls in CONFIG_BINFMT_DISABLE=y, which blocks
CONFIG_LIBC_EXECFUNCS (thus CONFIG_SYSTEM_NXINIT) and would otherwise
fail to link with "undefined reference to init_main". Same fix
boards/sim used for its affected configs.

citest/citest64 also carry their pre-existing explicit
CONFIG_INIT_STACKSIZE value (3072/4096) over to
CONFIG_SYSTEM_NSH_STACKSIZE: under nxinit "sh" is a separate spawned
child sized by SYSTEM_NSH_STACKSIZE, which otherwise dropped to the
2048 default and overflowed (citest64 crashed running `ps`). Every
other switched config that had an INIT_STACKSIZE override already had a
matching SYSTEM_NSH_STACKSIZE one.

All 23 switched configs were booted (not just compiled) and show
init_main as the parent with sh as its Running child in `ps` (see the
PR description for logs).

Assisted-by: opencode-agent/claude-sonnet-5
Signed-off-by: wangjianyu3 <wangjianyu3@xiaomi.com>
2026-09-13 11:15:24 +08:00
yushuailong
e37509e00a sched/clock: Fix timekeeping adjtime convergence.
Clamp each wall-clock adjustment in both positive and negative directions, then subtract the applied amount from the remaining adjustment. This makes adjtime converge to zero and prevents large negative adjustments from slewing the clock in the wrong direction.

Assisted-by: OpenAI Codex
Signed-off-by: yushuailong <yyyusl@qq.com>
2026-09-13 11:12:56 +08:00
yushuailong
5db3aa9e93 sched/clock: Avoid duplicate adjtime implementation.
CLOCK_TIMEKEEPING already provides a software-based adjtime implementation. Exclude the generic adjtime state and entry point when timekeeping is enabled, while retaining clock_adjtime support for PTP clocks.

Assisted-by: OpenAI Codex
Signed-off-by: yushuailong <yyyusl@qq.com>
2026-09-13 11:12:56 +08:00
yushuailong
d81a3a4d07 sched/spawn: Propagate scheduler setup errors
spawn_execattrs() discards the return value from nxsched_set_scheduler(). As a result, an invalid scheduling policy or parameter is silently ignored and the spawn operation continues with the original scheduling configuration.

Store and return the result from nxsched_set_scheduler() so that the caller can tear down the child task when applying the requested scheduler attributes fails. Update the function comments to describe the existing error return behavior.

Assisted-by: OpenAI Codex
Signed-off-by: yushuailong <yyyusl@qq.com>
2026-09-13 10:29:49 +08:00
yushuailong
4a34293263 sched: Centralize sporadic parameter validation
Sporadic scheduling parameters are processed independently by sched_setparam(), sched_setscheduler(), and pthread_create(). The three paths currently validate different subsets of the parameters.

In particular, pthread_create() does not validate sched_ss_max_repl and only requires the replenishment period to be greater than the budget, while the scheduler interfaces enforce the implementation's 50 percent duty-cycle limit.

Add nxsched_validate_sporadic() to validate the common parameters and convert the replenishment period and budget to ticks. Use it from all paths that directly initialize or update sporadic scheduler state.

Express the duty-cycle check using division to avoid overflow when doubling a clock_t value.

Assisted-by: OpenAI Codex
Signed-off-by: yushuailong <yyyusl@qq.com>
2026-09-13 10:29:49 +08:00
yushuailong
22d5ee5b2b sched/sched: Validate priority before applying sporadic parameters.
nxsched_set_param() applied the sporadic parameters and restarted the
replenishment timer in set_sporadic_param() before nxsched_reprioritize()
rejected an out-of-range priority with EINVAL, leaving stale sporadic
state (e.g. a truncated hi_priority) behind on failure.

Validate sched_priority up front so the error path is atomic.

Assisted-by: OpenAI Codex
Signed-off-by: yushuailong <yyyusl@qq.com>
2026-09-13 10:29:49 +08:00
yushuailong
eab468dcb2 sched/sched: Fix inverted sporadic parameter validation.
Commit 2ec7d90eba refactored sched_setparam() into set_sporadic_param()
but moved the apply logic into the former reject branch without
inverting the condition.  As a result sched_setparam() rejects valid
sporadic parameters (repl >= 2 * budget) with EINVAL and accepts
invalid ones, tripping the DEBUGASSERT in sched_sporadic.c or wrapping
the replenishment calculation.

Invert the condition to match process_sporadic() in sched_setscheduler.c.

Fixes: 2ec7d90eba ("sched_setparam.c: coverity HIS_metric_violation: RETURN")
Assisted-by: OpenAI Codex
Signed-off-by: yushuailong <yyyusl@qq.com>
2026-09-13 10:29:49 +08:00
likun17
7a0e839ca4 drivers/sensors: fix nxstyle errors in sensor.c
Running `./tools/checkpatch.sh -g` on this file reported seven pre-existing
style errors.  Fix them so that the file passes nxstyle cleanly:

 - Add the missing blank line after the declarations in sensor_lock(),
   sensor_unlock(), sensor_update_interval() and sensor_generate_timing().
 - Indent the SNIOC_GET_EVENTS and SNIOC_FLUSH case labels with six spaces
   like the other twelve case labels of the same switch.
 - Drop the two extra spaces in front of the poll_notify() call in
   sensor_poll().

Whitespace only, no functional change: the file is byte identical once all
whitespace is stripped.

Signed-off-by: likun17 <likun17@xiaomi.com>
2026-09-13 10:29:08 +08:00
likun17
29a536f53e drivers/sensors: add resistance, conductivity, energy and charge types
Cover the remaining electrical quantities so that they do not have to fork
into driver private namespaces later.  Add SENSOR_TYPE_RESISTANCE (Ohm),
SENSOR_TYPE_CONDUCTIVITY (S/m), SENSOR_TYPE_ENERGY (J) and
SENSOR_TYPE_CHARGE (C), the last two matching the native unit of the
accumulator registers in power and energy monitors.

Signed-off-by: likun17 <likun17@xiaomi.com>
2026-09-13 10:29:08 +08:00
likun17
cd225a0e56 drivers/sensors: add voltage, current and power sensor types
uORB has no type for electrical quantities, so power monitors can only use
the legacy character drivers, which are deprecated and report their values
in three incompatible unit systems.  Add SENSOR_TYPE_VOLTAGE,
SENSOR_TYPE_CURRENT and SENSOR_TYPE_POWER with their message structs in SI
units (V, A, W).

Signed-off-by: likun17 <likun17@xiaomi.com>
2026-09-13 10:29:08 +08:00
Peter van der Perk
ad176ac47f arch/arm/imxrt: fix nxstyle alignment in imxrt_clockconfig_ver2.c
Some checks failed
MemBrowse Memory Report / changes-filter (push) Has been cancelled
MemBrowse Memory Report / load-targets (push) Has been cancelled
MemBrowse Memory Report / identical (push) Has been cancelled
MemBrowse Memory Report / analyze (push) Has been cancelled
Fix nxstyle issues

Signed-off-by: Peter van der Perk <peter.vanderperk@nxp.com>
2026-09-11 12:54:06 -03:00
Peter van der Perk
94a5e23714 arch/arm/src/imxrt: keep the boot ROM's XIP FlexSPI clock setting
When executing in place from flash, the XIP FlexSPI clock must not be
reconfigured during the initial clock setup. The boot ROM configures the
clock for its flash read sequence, and changing it before the board installs
a suitable high-speed read sequence can break instruction fetch. The board's
flash setup may reconfigure the clock afterward.

Signed-off-by: Peter van der Perk <peter.vanderperk@nxp.com>
2026-09-11 12:54:06 -03:00
Arnav Sharma
33df5a8e58 boards/arm/samv7/same70-qmtech: disable FAT LFN in mcuboot-loader
The mcuboot-loader image overflows its flash region once the FAT deferred-delete change is applied. Long filename support is not needed by the bootloader, which boots from flash areas and never opens FAT files by long name, so disable CONFIG_FAT_LFN to reclaim the space while keeping short filename support intact.

Signed-off-by: Arnav Sharma <2006arnavsharma@gmail.com>
2026-09-11 10:55:25 -03:00