Commit graph

8378 commits

Author SHA1 Message Date
Royyan Zahir
87998e3f61 sched/signal: validate a sigevent where it is registered
A SIGEV_SIGNAL | SIGEV_THREAD_ID timer skipped timer_create's signal
check, and nxsig_notification honoured any thread ID. Add
nxsig_event_valid(): the signal must exist and a SIGEV_THREAD_ID target
must be one of the caller's own threads, as on Linux. timer_create,
gpio, button and phy_notify call it before storing an event, so the
caller gets EINVAL and an expiring timer never fails its DEBUGVERIFY.

Signed-off-by: Royyan Zahir <royzah@gmail.com>
2026-10-09 20:34:16 +08:00
Royyan Zahir
e70cd6bf45 sched: process capabilities
A task group holds PR_CAP_RAWIO, PR_CAP_SPAWN and PR_CAP_ADMIN, inherits
them from its creator and can only drop them. Every build: the kernel and
init start with all three, so nothing changes until a task drops one.
CONFIG_SCHED_CAPABILITIES, off with DEFAULT_SMALL, lets a board short of
flash leave the checks out.

Signed-off-by: Royyan Zahir <royzah@gmail.com>
2026-10-09 09:31:21 -03:00
Marco Casaroli
dcc3b7b384 libs/libc/locale: Add getlocalename_l().
POSIX.1-2024 adds getlocalename_l(), which returns the name of the
locale of one category of a locale object.  NuttX supports only the "C"
locale, so the function returns "C" for every valid category, and NULL
with errno set to EINVAL for an invalid one.  It is built with
CONFIG_LIBC_LOCALE, like the other locale functions.

Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
2026-10-09 20:07:32 +08:00
Marco Casaroli
314348cafe libs/libc/time: Add tzset() for builds without time zones.
POSIX requires tzset(), but NuttX declared and defined it only with
CONFIG_LIBC_LOCALTIME, so programs that call it do not build without
that option.  Without CONFIG_LIBC_LOCALTIME there are no time zones and
local time is UTC, so tzset() has nothing to do.

Declare tzset() always, and add an empty one for builds without
CONFIG_LIBC_LOCALTIME.

Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
2026-10-09 20:07:32 +08:00
raiden00pl
e570885eb7 sensors: add ccs811 eCO2/TVOC driver
Implement the ams CCS811 digital gas sensor

Assisted-by: Claude Code
Signed-off-by: raiden00pl <raiden00@railab.me>
2026-10-09 18:27:21 +08:00
msli-dev
844ef9c678 mmcsd: Honor optional SDIO host request limits.
Add an optional maxrequest callback at the end of sdio_dev_s. A zero
or unset callback adds no host-specific limit; nonzero values are byte
limits that apply to all request buffers.

Combine the host limit with MMCSD_MULTIBLOCK_LIMIT when splitting
block reads and writes. Reject a host limit smaller than one block and
oversized raw multi-block commands before starting the transfer.

Cancel receive setup after a failed CMD23, attempt CMD12 after failed
open-ended multi-block reads, and propagate stop-command failures.
Keep these generic MMC/SD changes separate from the STM32H7 driver.

Assisted-by: Codex:GPT-6
Signed-off-by: msli-dev <747640013@qq.com>
2026-10-09 18:26:12 +08:00
Marco Casaroli
156fb83007 include/stdbool.h: Define true and false as the integer constants 1 and 0.
C99 7.16 requires true and false to expand to the integer constants 1
and 0, suitable for use in #if.  NuttX defined them as (bool)1 and
(bool)0, so a preprocessor condition such as "#if !true" did not
compile.

Define them as 1 and 0.  The values do not change; only their type in
an expression changes, from bool to int, as the standard requires.

Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
2026-10-09 06:08:50 -03:00
Marco Casaroli
f1e89bf11e include/memory.h: Add the legacy <memory.h> header.
<memory.h> declares the memory functions of <string.h>, such as
memcpy() and memset().  It is not in POSIX, but glibc, musl and newlib
provide it, and some programs still include it.  On NuttX they failed:

  fatal error: memory.h: No such file or directory

Add it.  It only includes <string.h>.

Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
2026-10-09 06:08:16 -03:00
Justin Hammond
cc2edca964 sensors/ina226: Add a uORB interface.
The INA226 driver was character mode only, and stayed that way after
everything around it moved, because the sensor framework had no type it
could publish: there was nothing for volts or amps until now.

Add the framework version beside it, in the shape the tree uses for a
part with both.  The old driver is untouched and still builds by
default; the new one replaces it when SENSORS_INA226_UORB is set.

The part publishes three topics, voltage, current and power, from a
single reading that they all share the timestamp of.  Reading once per
topic would put three transfers on the bus for one sample and, worse,
would leave the three values describing three different instants, which
is the wrong property for a power measurement: the product of a voltage
and a current measured at different moments is not the power at either.
The power is computed here rather than read from the part, because the
part's own power register needs its calibration register given a
current scale first, and multiplying two values already in hand does
not.

One worker feeds all three, so it starts when the first topic is
subscribed and stops when the last goes away, and the part is left
powered down until then rather than converting into a void.

Each topic keeps the interval it asked for and the worker runs at the
shortest of them, since one reading serves all three.  Neither is taken
at face value: asking faster than the part converts returns the same
reading twice, and a period shorter than a clock tick rounds down to no
delay at all, which would leave the worker re-queueing itself with the
bus never idle.  Both floors are applied and the caller is told what it
will actually get, which is what the interface is for.

The shunt is rejected if it is zero or negative, which would otherwise
divide by zero on the first reading.

Assisted-by: Claude:claude-opus-5
Signed-off-by: Justin Hammond <justin@dynam.ac>
2026-10-09 13:37:13 +08:00
Marco Casaroli
e0b03614fd drivers/audio: Make tone.h self-contained.
tone_register() takes a struct oneshot_lowerhalf_s *, and the header does not
include the one that defines it.  Including tone.h first therefore creates the
tag in prototype scope, and passing a real oneshot to it fails with the
memorable diagnostic "expected 'struct oneshot_lowerhalf_s *' but argument is
of type 'struct oneshot_lowerhalf_s *'".

Every existing user happens to include nuttx/timers/oneshot.h first, which is
why this has not bitten before.

Tested with a small file that includes nuttx/audio/tone.h first and calls
tone_register().  Before the change, GCC 13.2 gives the warning above and
GCC 15.3 stops with an error.  After the change, both compile it without a
diagnostic.  stm32f103-minimum:audio_tone builds.

Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
2026-10-08 15:53:01 -03:00
Daniel P. Carvalho
81f3d7443d arch/mips/pic32mz: add PHY ioctls and link interrupts to the Ethernet driver.
The driver had no d_ioctl, so CONFIG_NETDEV_PHY_IOCTL had no effect.
Implement SIOCGMIIPHY, SIOCGMIIREG and SIOCSMIIREG and, with
CONFIG_ARCH_PHY_INTERRUPT, SIOCMIINOTIFY.  SIOCMIINOTIFY subscribes
through phy_notify_subscribe() (the board provides arch_phy_irq()) and
enables the PHY link down and auto-negotiation complete interrupts.
This is what CONFIG_NETINIT_MONITOR needs.

The PHY interrupt is implemented for the LAN8720 and LAN8740; add their
interrupt source/mask register bits to mii.h.

Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Daniel P. Carvalho <danieloak@gmail.com>
2026-10-08 09:53:45 -03:00
Marco Casaroli
dcd93b0f67 libs/libc/elf: Load the libraries a module names in DT_NEEDED.
Some checks are pending
Build Documentation / build-html (push) Waiting to run
MemBrowse Memory Report / changes-filter (push) Waiting to run
MemBrowse Memory Report / load-targets (push) Waiting to run
MemBrowse Memory Report / identical (push) Blocked by required conditions
MemBrowse Memory Report / analyze (push) Blocked by required conditions
A module that names a shared library in DT_NEEDED now gets it loaded and
its imports bound against it, rather than being refused.

libelf_insert() does the loading, which is what dlopen() calls anyway: the
library lands in the module registry like anything else, its exports come
back through libelf_getsymbol() -- the same call dlsym() uses -- and a
library named by two modules is loaded once.  A bare name is looked for
along LD_LIBRARY_PATH, where dlopen() looks for it.  Undefined symbols
resolve against the globally registered symbols first, then the modules
this one depends on, then the table exec() supplied.  Nothing here calls
into dlfcn, because this loader is also the kernel's module loader, which
has none.

Each library becomes one of the module's dependencies[], and the dependency
holds it in place of the reference libelf_insert() took.  So a library
loaded only for DT_NEEDED is kept by the modules that depend on it, and
libelf_undepend() unloads it with the last of them; one that dlopen() or
insmod also opened stays until that reference goes too.
CONFIG_LIBC_ELF_MAXDEPEND bounds how many libraries a module may name,
which is what it already meant.

Six things had to be fixed to make it work, none of which a build shows.

reldata was a file-scope global.  Loading a library from inside
libelf_relocatedyn() makes that function reentrant, so the nested load
overwrote the outer one's relocation offsets and the module resumed binding
with the library's DT_REL.  It is now per call.

A cross-object call needs the callee's data base, not the caller's.  A
symbol resolved from an FDPIC library comes back as a descriptor, and
R_ARM_FUNCDESC_VALUE was treating it as a code address and pairing it with
the importing module's GOT.  It now copies both words, so the library runs
with its own.

An object with no imports has no PLT and so no DT_PLTGOT, but it still has
a GOT and still has to be entered with it.  Without the fallback its
descriptors carried a data base of zero and the library read its globals
through a null pointer.

R_ARM_FUNCDESC, a pointer to a descriptor, wrapped a library's descriptor
in a second one.  It now stores the library's descriptor as it is.

The flag that says a resolved value is a descriptor was set only for an
import and never cleared, so the next relocation against a symbol of the
module itself took that symbol for a descriptor too.  It is cleared there.

libelf_symname() was static, and reading a DT_NEEDED name needs it.

A module with DT_NEEDED is refused where CONFIG_LIBC_ELF_MAXDEPEND is zero,
since that is where the dependency logic is compiled out.

A DT_NEEDED library is one shared instance, its data included, because the
loader returns the object already in the registry.  A module started with
exec() is different: that path loads the module afresh each time, so two
running instances have separate data while sharing one copy of the text.

Built for mps3-an547:picostest with CONFIG_FDPIC both ways.  Run on
mps2-an500:xipfs under QEMU: fdpicxip solib loads libcounter.so by name out
of DT_NEEDED, two instances share one pinned copy of its text, and the
library is unloaded, and its pin given back, when the second one exits.  A
library also opened with dlopen() stays loaded after its DT_NEEDED user
exits, and dlclose() unloads it.

With CONFIG_ARCH_ADDRENV the program runs in its own address space, which
a library libelf_insert() loads cannot reach, so DT_NEEDED is refused
there as before.

Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
2026-10-06 17:48:49 -03:00
Marco Casaroli
1eba351585 signal: Inline nxsig_addset(), nxsig_delset() and nxsig_ismember().
Each was an out-of-line function in libc around one bit operation and a
range check.  The kernel calls them on its signal paths, often with a
constant signal number, where the check folds away.

Move them into the header as static inline.  sigaddset(), sigdelset()
and sigismember() stay in libc and call them as before.

Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
2026-10-06 17:45:52 -03:00
raiden00pl
9199e5aa28 sensors/adxl367: add I2C accelerometer support
add adxl367 support

Assisted-by: Codex:GPT-6
Signed-off-by: raiden00pl <raiden00@railab.me>
2026-10-06 14:47:12 -03:00
yushuailong
31f3857cb4 sched: Fix deadlock cycle collection.
Use Floyd cycle detection on the mutex wait-for chain so only threads that actually participate in a cycle are reported. This avoids omitting the last cycle member and incorrectly including threads that merely lead into a deadlock.

Also handle empty output buffers and document truncation semantics.

Assisted-by: OpenAI Codex
Signed-off-by: yushuailong <yyyusl@qq.com>
2026-10-01 23:19:43 +08:00
Alan Carvalho de Assis
1dfa028808 include/fcntl.h: keep open() flags within a 16-bit int
O_DIRECTORY, O_NOFOLLOW, O_NOATIME, O_CLOEXEC, __O_SYNC, O_PATH and
__O_TMPFILE are defined as shifts by 16 to 22 bits.  Where int is 16
bits (AVR, for example), these shifts exceed the width of the type:
GCC evaluates them to 0, and the -Wshift-count-overflow warning is not
shown because include/ is a system include directory.  The oflags
argument of open() is an int, so it could not carry those bits anyway.

As a result, on arch with int equal 16-bit opendir() opens directories
without O_DIRECTORY, so opening a mount point such as /proc fails with
ENOENT, and O_CLOEXEC and O_NOFOLLOW have no effect.

When UINT_MAX is 0xffff, use the unused bits 2 to 4 for O_DIRECTORY,
O_CLOEXEC and O_NOFOLLOW, define O_NOATIME and __O_SYNC as 0 (O_SYNC
falls back to O_DSYNC), and leave O_PATH and O_TMPFILE undefined, so
that code which needs them fails to build instead of silently opening
with the wrong flags; nothing in the tree uses them.  _O_MAXBIT becomes
15. On bigger systems (32-bit, 64-bit) keep the original bit shift.

Signed-off-by: Alan Carvalho de Assis <acassis@gmail.com>
Assisted-by: Claude Opus 5.5 (claude-opus-5-5)
2026-10-01 08:54:02 -03:00
Claude
6e14c8cfe5 net/netdev: add NETDEV_TX_STAMP and handle SIOCETHTOOL ETHTOOL_GET_TS_INFO
Add the NETDEV_TX_STAMP capability flag to d_features, next to the
existing NETDEV_RX_STAMP, so a driver can declare that it delivers
hardware TX timestamps.

SIOCETHTOOL and ETHTOOL_GET_TS_INFO were already defined but not
implemented.  Add struct ethtool_ts_info, with the same layout as
Linux, and handle SIOCETHTOOL in netdev_ioctl.c so that userspace (such
as ptpd) can query the timestamping capabilities of an interface the
same way linuxptp/ptp4l does on Linux:

- ETHTOOL_GET_TS_INFO fills so_timestamping from d_features:
  RX_HARDWARE | RAW_HARDWARE with NETDEV_RX_STAMP, otherwise
  RX_SOFTWARE | SOFTWARE (the stack stamps received packets with
  CLOCK_REALTIME), and TX_HARDWARE | RAW_HARDWARE with NETDEV_TX_STAMP.
  phc_index is -1, tx_types and rx_filters are zero.
- Any other ethtool command is passed to the driver's d_ioctl when
  CONFIG_NETDEV_IOCTL is enabled, otherwise -ENOTTY is returned.

Assisted-by: Claude:claude-sonnet-5
Signed-off-by: Daniel P. Carvalho <danieloak@gmail.com>
2026-09-28 12:53:24 -03:00
Claude
b7001f2d9f include/sys/socket.h: give SOF_TIMESTAMPING_* their Linux values
All SOF_TIMESTAMPING_* flags currently alias 1 << SO_TIMESTAMPING, so
they cannot tell hardware from software or RX from TX.  Give them their
distinct Linux values, and add SOF_TIMESTAMPING_RX_HARDWARE,
SOF_TIMESTAMPING_RX_SOFTWARE and SOF_TIMESTAMPING_SYS_HARDWARE, so that
they can also describe the timestamping capabilities of an interface
(so_timestamping of ETHTOOL_GET_TS_INFO).

This does not change behaviour: setsockopt(SO_TIMESTAMPING) only checks
for a non-zero value and getsockopt() returns 0 or 1, so existing users
and binaries built with the previous values keep working.  The
individual flags are still not honoured.

Assisted-by: Claude:claude-sonnet-5
Signed-off-by: Daniel P. Carvalho <danieloak@gmail.com>
2026-09-28 12:53:24 -03:00
Justin Hammond
ed046adeb4 drivers/usbhost: Tell the host stack which controller a port belongs to.
struct usbhost_roothubport_s carries the number of the controller its port
belongs to, so a port can be named on a system with more than one.
Nothing set it.

Take the number from whoever brings the controller up rather than counting
registrations, which would agree with the name the driver reports only
while controllers are registered in the order they are named.

Assisted-by: Claude:claude-opus-5
Signed-off-by: Justin Hammond <justin@dynam.ac>
2026-09-28 21:45:57 +08:00
Justin Hammond
572b7a0b55 usbhost: Report what a hub is on the port it occupies.
Some host controllers must be told about the hubs in a topology, not only
about the device at the end of it.  xHCI is one: a hub's slot context
carries a hub flag, its downstream port count and the think time of its
transaction translator, and the controller routes to anything behind that
hub using them.

The hub class driver already reads both values from the hub descriptor and
keeps them privately.  Publish them on the hub's own hub port, beside the
speed and function address that already describe the device attached
there.  A driver setting up a device behind a hub finds them on that
device's parent.

They are written before the hub activates any downstream port, so they are
in place before there is anything behind it, and a port with no hub
reports zero ports because the hub class clears each child before use.
Nothing is required to read them.

Fields rather than a driver method: a method would need a null check at
the call site and would define an order it must be called in.  Both are
inside CONFIG_USBHOST_HUB, as struct usbhost_hubport_s's parent pointer
already is.

Multi-TT is not included; it comes from the hub's interface protocol
rather than its descriptor, and driving a multi-TT hub as single-TT costs
bandwidth behind it but is correct.

Assisted-by: Claude:claude-opus-5
Signed-off-by: Justin Hammond <justin@dynam.ac>
2026-09-28 21:45:57 +08:00
zhanghongyu
53ac762e79 drivers/vhost: Optimize vhost-net performance and robustness
Suppress the peer notifications while a ring keeps delivering work, batch
the receive completions into one kick per burst and drop the redundant
txdone signal from the transmit path.  Validate the peer controlled frame
lengths, accept descriptor chains on both lanes, keep every ring access on
the upper half's work thread so the interrupt context callbacks stay lock
free, and prefer the MAC from the configuration space, falling back to the
Kconfig address or a random one.

Signed-off-by: zhanghongyu <zhanghongyu@xiaomi.com>
2026-09-27 18:41:30 +08:00
yushuailong
e5d9960f56 sched/wdog: Reject zero delay in wd_start_next.
wd_start_next() schedules relative to the previous expiration.  A zero
value reuses that expiration, so a callback can immediately reinsert an
already expired watchdog and make wd_expiration() loop without advancing
time.

Reject non-positive delays to guarantee that the next expiration advances.

Assisted-by: OpenAI Codex <noreply@openai.com>
Signed-off-by: yushuailong <yyyusl@qq.com>
2026-09-26 22:18:02 +08:00
Marco Casaroli
7a006e7ef6 binfmt/elf: Load FDPIC modules through the ELF loader.
exec() of an FDPIC module now works.  The loader already places such an
object and binds it; what was missing is everything binfmt has to carry
across from the load to the running task.

The task needs the module's data base in its PIC base register.  binfmt
builds a D-Space for any object with a GOT, taking the base from the .got
section address; an FDPIC object names it in DT_PLTGOT instead, which the
loader has already translated, so the two are the same idea reached by
different routes and both are what up_initial_state() installs.

Constructors are not binfmt's business.  A module carries its own crt0,
which walks .init_array on the task that runs the module and then calls
main, so they run in the module's own context and with its own data base.
For a module that arrives through dlopen(), libelf_insert() walks the array
instead, and it enters each entry through fdpic_invoke() because a
descriptor resolved on the calling task carries the wrong base.

The read-only segment of a module that executes in place is held by a
filesystem pin.  The load takes it, and the module owns it from the point
where nothing can fail any more; it is given back when the task that runs
the module exits.  The pin is held through a reference to the file rather
than a descriptor, because the descriptor belongs to the task that called
the loader and the release happens on another one.

libelf_remove() and libelf_uninit() give back what an FDPIC module holds:
the pin, and the writable segment, while the read-only one is media rather
than an allocation and must not be freed.

Built for mps3-an547:picostest with CONFIG_FDPIC both ways.

Assisted-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
2026-09-26 11:13:30 -03:00
Marco Casaroli
43694933ce libc, sched: Resolve FDPIC descriptors at module callback entry points.
The base firmware and an FDPIC module disagree about what a function
pointer is.  Firmware is not built FDPIC, so to it a pointer is a code
address and it branches there.  A module passes the address of a two word
descriptor instead, because its code and data are placed independently and
a bare code address would leave the callee unable to find its own data.  A
firmware routine that takes a callback therefore branches into the
module's data segment and faults.

So the ten entry points that can be handed a callback by a module resolve
the descriptor before storing or branching to it: qsort, bsearch,
pthread_create, signal, sigaction, task_create and task_create_with_stack,
task_spawn, pthread_once, scandir, and mq_notify and timer_create with
SIGEV_THREAD.

Which one resolves matters as much as that one does.  Resolving twice would
take an already resolved code address for a descriptor and read two words
from the instruction stream, so each pointer is resolved exactly once, at
the outermost point that sees it.  signal() passes its argument through
untouched because sigaction() and then nxsig_action() will resolve it,
which covers a module calling sigaction() directly as well.  qsort() is
split so that the public entry resolves and the recursive implementation
does not.  scandir() resolves its filter but not its comparison function,
which it hands to qsort().

Whether a caller is a module at all is asked of the PIC base register,
which up_initial_state() sets only for a task that has a D-Space.  A plain
kernel task therefore reads zero and is left alone.

SIGEV_THREAD is the case the register cannot answer, because the callback
runs later on a work queue worker that carries no module's base at all.
The base is captured instead when the notification is registered, in the
module's own context, and installed around the call.

All of it is behind CONFIG_FDPIC, which defaults off.  Built for
mps3-an547:picostest both ways; with it off the entry points compile to
what they were.

Assisted-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
2026-09-25 10:46:48 -03:00
rongbaichuan
9c461f03ac sched/semaphore: Correct the return value comment of nxsem_init/nxmutex_init
nxsem_init(), nxsem_destroy(), nxmutex_init(), nxmutex_destroy(),
nxrmutex_init() and nxrmutex_destroy() cannot fail, so promising a
negated errno value on failure documents an error that is never returned.
The coding standard asks the returned value description to identify all
error values of a function, and there are none, so state that OK is
always returned.

Follows "sched/semaphore: Remove the return value check of
nxsem_init/nxmutex_init", which removed the last checks of these values.

Assisted-by: DeepSeek Harness:deepseek-flash
Signed-off-by: rongbaichuan <rongbaichuan1027@163.com>
2026-09-25 10:37:43 +02:00
rongbaichuan
59d5ce0f31 sched/semaphore: Remove the return value check of nxsem_init/nxmutex_init
nxsem_init(), nxsem_destroy(), nxmutex_init() and nxmutex_destroy()
always return OK, so checking the result only leaves dead code: the
compiler cannot remove it, because these are cross-translation-unit calls
and the nxrmutex_destroy() test is duplicated into every inlined call
site.

Apply the convention already established in commit a47a36bc5b (PR #7473)
to the two definitions which still test the value and to the 54 remaining
call sites. No signature or prototype is changed.

Testing: stm32f103-minimum:nsh builds with -Os without new warnings.

Assisted-by: DeepSeek Harness:deepseek-flash
Signed-off-by: rongbaichuan <rongbaichuan1027@163.com>
2026-09-25 10:37:43 +02:00
raiden00pl
c31b87ee1e drivers/ioexpander: add an optional pin PWM operation
Add an ioe_setpwm operation (guarded by CONFIG_IOEXPANDER_PWM) for
expanders that can modulate their outputs, e.g. through a LED driver
engine.

Assisted-by: Claude Code
Signed-off-by: raiden00pl <raiden00@railab.me>
2026-09-24 20:16:12 +08:00
Daniel P. Carvalho
a4c608c591 arch/arm/stm32h7: do not log the frames of packet sockets as unknown.
A frame that a packet socket consumes was given to pkt_input() and then
logged as "Dropped, Unknown type" because it is neither IP nor ARP. With
a PTP grandmaster on the network that is one warning for each frame, and
the log of RAM fills in seconds, so it hides the messages of the start of
the system.

Do not log the frames of the type of PTP or of IPv6 when packet sockets
are enabled, as the driver of the legacy STM32 does.

Signed-off-by: Daniel P. Carvalho <danieloak@gmail.com>
Assisted-by: Claude:claude-sonnet-5
2026-09-23 08:21:59 +02:00
Ulaş Sertan Kemeç
fa935ecae1 drivers/vhost: Add vhost-net, a device-role virtio network driver.
Implements the device end of virtio-net, so a peer running the stock
virtio-net driver sees this side as a network card, and registers a netdev
lowerhalf.

Ring layout follows the peer's numbering: vq[0] is its RX queue, which we fill
to transmit, and vq[1] its TX queue, which we harvest.  No features are
negotiated, so every frame carries the zeroed legacy virtio_net_hdr.

Peer buffers are reached by raw 64-bit address through an arch-provided
translation window -- the AM67 RAT, identity mapping elsewhere -- splitting
copies that straddle it.

Also gives DRIVERS_VHOST a prompt; it was promptless and so unselectable
without a driver forcing it.

Verified on t3-gem-o1 against an unmodified Linux virtio_net: eth0 registers,
ifup brings it to RUNNING, and the peer pings it 5/5 at 0.27 ms and 60/60 with
0% loss.

Assisted-by: Claude Code:claude-fable-5
Signed-off-by: Ulaş Sertan Kemeç <sertan.usk@gmail.com>
2026-09-21 10:40:13 -03:00
Ulaş Sertan Kemeç
c77c981850 drivers/vhost: Add vhost_get_vq_buffers_pa().
vhost_get_vq_buffers() converts descriptor addresses through the shared-memory
I/O region, which truncates silently when the CPU cannot address all of the
peer's memory -- a 32-bit remote core against a 64-bit host, where
metal_phys_addr_t is 32-bit and Linux posts buffers above 4 GB.

Returns the raw 64-bit address and length instead, so class drivers can
translate through platform window hardware.  Completion is unchanged.

Assisted-by: Claude Code:claude-fable-5
Signed-off-by: Ulaş Sertan Kemeç <sertan.usk@gmail.com>
2026-09-21 10:40:13 -03:00
Jorge Guzman
bbfb229e1f zbus: Add linker support and documentation for the zbus port
NuttX-side support for the zbus message bus port (apps/system/zbus in
nuttx-apps), built on the link-time iterable sections infrastructure
added in a companion PR:

- include/nuttx/linker/common-rom.ld and common-insert.ld: register the
  zbus channel, observer and channel observation iterable sections
  (ITERABLE_SECTION blocks guarded by CONFIG_ZBUS, no-op otherwise) for
  the include and the zero-touch INSERT modes respectively;
  common-ram.ld: note that zbus needs no RAM sections.
- Documentation/applications/system/zbus: Sphinx documentation for the
  zbus application, with the upstream Zephyr diagrams (Apache-2.0).
- .codespellrc: skip the reused zbus SVG diagrams (embedded base64
  raster data trips the spell checker).

Assisted-by: Claude Code
Signed-off-by: Jorge Guzman <jorge.gzm@gmail.com>
2026-09-21 08:40:14 -03:00
Matteo Golin
f39b15d28b sched/pthread: Implement pthread_sigqueue
Implements the pthread_sigqueue Linux extension to pthreads. Follows a
similar implementation to sigqueue, except targeting a specific thread
through nxsig_dispatch.

Signed-off-by: Matteo Golin <matteo.golin@gmail.com>
2026-09-21 14:53:26 +08:00
Justin Hammond
0ed5e61bcf drivers/usbhost: Maintain the cache over xHCI data buffers.
The controller moves every byte itself, so on a machine whose caches are
not coherent with it the driver must flush before the controller reads and
invalidate before the processor does.  Data buffers got no maintenance at
all: nothing pushed before an OUT, nothing dropped after an IN.

Cache operations act a whole line at a time, which is unsafe for a buffer
that does not own its lines: invalidating drops whatever else shares the
line, and a writeback lands on top of what the controller has just put
there.  Mass storage passes a 31 byte command block and a 13 byte status
out of its instance structure.  Such a buffer is copied through an aligned
stand-in; anything large comes from a filesystem or from xhci_ioalloc(),
which now rounds its length up as well as aligning its start, so what it
returns owns its last line.

Whether the controller can reach a buffer at all is asked of the platform
through a new dmacapable operation, since it is a property of the system
the controller was fitted into rather than of the controller.  A platform
that does not supply it is taken to accept every address, which is what
existing users have.  A refused buffer gives -EFAULT, which the FAT
filesystem answers by retrying through its own DMA-safe sector buffer.

The device output context is also invalidated before the assigned address
is read out of it; the controller wrote that address, and reading without
invalidating returns whatever the processor had cached.

Compiles to nothing where there is no cache to maintain, and dmacapable is
NULL on PCI, so the existing user is unaffected.

Assisted-by: Claude:claude-opus-5
Signed-off-by: Justin Hammond <justin@dynam.ac>
2026-09-20 22:28:07 +08:00
Abhishek Mishra
2977db2632 fs: add chroot() syscall
Add CONFIG_FS_CHROOT and POSIX chroot(). Store the jail as an
absolute path on the task group, and require euid 0 when user
identity is enabled.

Signed-off-by: Abhishek Mishra <mishra.abhishek2808@gmail.com>
2026-09-20 22:27:38 +08:00
Abhishek Mishra
6c7f604f79 sched: add per-group filesystem jail root
Store the jail as an absolute path on the task group, copy it to
children, and free it when the last member leaves.

Signed-off-by: Abhishek Mishra <mishra.abhishek2808@gmail.com>
2026-09-20 22:27:38 +08:00
Justin Hammond
1757b28b1f drivers/sensors: Use sensor_data_t for the electrical quantities.
The voltage, current, power, resistance and conductivity messages
declare their measurement as float, where every other message in
uorb.h declares it as sensor_data_t.  That type is b16_t under
CONFIG_SENSORS_USE_B16 and float otherwise, so on a fixed point
configuration these five are the only sensors still producing floats.

A driver that computes in sensor_data_t, as the helpers in fixedmath.h
encourage, then assigns a b16_t to a float field: the raw fixed point
integer is stored as a float and the reading is wrong by 65536 with no
diagnostic.

The accumulators keep int64_t.  Energy in uJ and charge in uC are
counts of micro units rather than measurements, and neither is
affected by the fixed point option.

Assisted-by: Claude:claude-opus-5
Signed-off-by: Justin Hammond <justin@dynam.ac>
2026-09-20 09:23:37 -04:00
Abhishek Mishra
b180dc17ae Documentation,drivers/aie: align machine learning docs with current code
The tflm tool registered DEPTHWISE_CONV_2D in nuttx-apps#3773, but the
docs still listed eight operators. Document the unused -C compile path,
that the sim helper uses heap I/O, and the pinned TFLM/CMSIS/NNABLA
versions. Add missing gemmlowp, KissFFT, Ruy, and FlatBuffers pages,
document the AI-engine character driver, and wire it into CMake.

Signed-off-by: Abhishek Mishra <mishra.abhishek2808@gmail.com>
2026-09-19 15:16:18 -03:00
Daniel P. Carvalho
fc9fec46da analog: add ANIOC_COMP_ENABLE and ANIOC_COMP_DISABLE commands
Define standard IOCTL commands to enable and disable analog comparator
devices from user-space applications.

Assisted-by: Gemini:gemini-2.5-pro
Signed-off-by: Daniel P. Carvalho <danieloak@gmail.com>
2026-09-19 22:41:17 +08:00
wenquan1
935f830e16 include/sys/socket.h: add SCM_TIMESTAMPNS and SCM_TIMESTAMPING macros
Add missing SCM_TIMESTAMPNS and SCM_TIMESTAMPING control message type
definitions mapped to their corresponding SO_TIMESTAMPNS and
SO_TIMESTAMPING socket options. Also align whitespace of existing
SCM_* definitions for consistency.

Signed-off-by: wenquan1 <wenquan1@xiaomi.com>
2026-09-18 20:00:49 +08:00
wenquan1
cf78962356 net/socket: merge CONFIG_NET_TIMESTAMPING into CONFIG_NET_TIMESTAMP
Consolidate the two separate timestamp Kconfig options into a single
CONFIG_NET_TIMESTAMP option that covers SO_TIMESTAMP, SO_TIMESTAMPNS
and SO_TIMESTAMPING socket options.

Previously CONFIG_NET_TIMESTAMPING was a separate option only used by
PKT sockets for hardware TX/RX timestamps and error queue support.
Since both options guard the same io_time field in iob_s and share
the s_options bitmask, merging them simplifies configuration without
functional impact.

Changes:
- Replace all CONFIG_NET_TIMESTAMPING with CONFIG_NET_TIMESTAMP in
  pkt_input.c, pkt_recvmsg.c, pkt_sendmsg_buffered.c,
  pkt_sendmsg_unbuffered.c, pkt_sockif.c, pkt_netpoll.c, pkt.h,
  setsockopt.c, getsockopt.c
- Simplify iob.h conditional from OR of both to single option
- Remove NET_TIMESTAMPING Kconfig entry, update NET_TIMESTAMP
  description to cover all three socket options

Signed-off-by: wenquan1 <wenquan1@xiaomi.com>
2026-09-18 20:00:49 +08:00
wenquan1
be3446850a net/pkt: support SO_TIMESTAMPING and MSG_ERRQUEUE
Add SO_TIMESTAMPING TX path for PKT sockets. Tagged TX
packets loop back through the driver with io_conn set,
are routed into conn->errahead, and delivered to userspace
via recvmsg(MSG_ERRQUEUE) with SO_TIMESTAMPING cmsg.
Add poll(POLLPRI) notification when errahead is non-empty.


Signed-off-by: wenquan1 <wenquan1@xiaomi.com>
2026-09-18 20:00:49 +08:00
OceanfromXiaomi
28402b9b35 net: add NETDEV_RX_STAMP flag in d_features
Replace compile-time CONFIG_ARCH_HAVE_NETDEV_TIMESTAMP with
a runtime NETDEV_RX_STAMP bit in net_driver_s.d_features.
Drivers providing hardware RX timestamps set the flag at
probe time; the stack checks it at runtime.


Signed-off-by: OceanfromXiaomi <zhaohaiyang1@xiaomi.com>
2026-09-18 20:00:49 +08:00
OceanfromXiaomi
9a65ffc51d net: move rx timestamp from d_rxtime to iob_s.io_time
Move RX timestamp storage from net_driver_s.d_rxtime into
iob_s.io_time so each IOB carries its own timestamp through
the stack. Remove old iob_trycopyin/iob_copyout timestamp
packing in CAN/PKT/UDP paths. Fix iob_clone_partial to copy
io_time before source pointer advances to NULL.

Signed-off-by: OceanfromXiaomi <zhaohaiyang1@xiaomi.com>
Signed-off-by: wenquan1 <wenquan1@xiaomi.com>
2026-09-18 20:00:49 +08:00
Daniel P. Carvalho
1b172fb8d2 drivers/sensors: add Microchip TC74 temperature sensor driver
Add support for the Microchip TC74 digital temperature sensor using the
Sensor Driver Framework (uORB). The TC74 is an 8-bit I2C temperature
sensor with a measurement range from -40C to +125C and a resolution
of 1C.

The driver registers as a uORB topic (/dev/uorb/sensor_temp<n>) and
polls on the low-priority work queue. It supports dynamic interval
configuration and automatically enters low-power standby mode when
the topic is deactivated.

Validated against a real TC74A5-3.3 on a custom STM32H743BI board.

Assisted-by: Gemini:gemini-3.8-pro
Signed-off-by: Daniel P. Carvalho <danieloak@gmail.com>
2026-09-18 16:04:32 +08:00
Xiang Xiao
144d9dff02 libc: add paths.h, sys/ttydefaults.h and termios IUTF8
Add commonly required POSIX/BSD interfaces that portable command-line
utilities expect but that were missing from the C library:

- include/paths.h: _PATH_DEFPATH and the other standard default paths.
- include/sys/ttydefaults.h: BSD default control-character and terminal
  flag definitions.
- include/termios.h: define the IUTF8 input flag.

Signed-off-by: Xiang Xiao <xiaoxiang@xiaomi.com>
2026-09-15 14:51:15 +02:00
Xiang Xiao
2f4d017bb6 fs/aio: add configurable AIO_LISTIO_MAX limit
lio_listio() never validated 'nent' against {AIO_LISTIO_MAX}, so a
batch larger than the documented limit was silently accepted, and the
hard-coded _POSIX_AIO_LISTIO_MAX value of 2 was too small for real
workloads (LTP uses 10 entries per call).

Add the FS_AIO_LISTIO_MAX Kconfig option (default 10), use it for
_POSIX_AIO_LISTIO_MAX in include/limits.h, validate 'nent' in
lio_listio(), and report the limit through sysconf(_SC_AIO_LISTIO_MAX).

Signed-off-by: tengshuangshuang <tengshuangshuang@xiaomi.com>
2026-09-14 17:12:49 -03:00
Xiang Xiao
1ea86e65fd aio: make the lio_listio() prototype match POSIX
POSIX declares lio_listio() as:

  int lio_listio(int, struct aiocb *restrict const [restrict], int,
                 struct sigevent *restrict);

Update the prototype in include/aio.h (and the implementation and
libc.csv entry) accordingly, and drop the parameter names from the
other aio_* prototypes for consistency.

Signed-off-by: guoshichao <guoshichao@xiaomi.com>
2026-09-14 17:12:49 -03:00
Xiang Xiao
d2489101ac fs/aio: skip lio_link teardown for failed submissions in LIO_WAIT mode
When a queued operation fails immediately (bad fd, EINVAL, or a failed
aio_read/aio_write submission), lio_listio() unconditionally deleted
the aiocbp from the request list.  In LIO_WAIT mode (or when no sig was
requested) the lio_link nodes were never linked into the list, so
list_delete() corrupted memory and crashed.

Only unlink the node when it was actually linked, i.e. when
mode == LIO_NOWAIT and a sigevent was provided.

Signed-off-by: tengshuangshuang <tengshuangshuang@xiaomi.com>
2026-09-14 17:12:49 -03:00
Xiang Xiao
ad364be818 fs/aio: rework lio_listio() with a lock-protected request list
Previously, lio_listio() called aio_read()/aio_write() to submit the
I/O and only then initialized the per-request notification state
(aio_priv based), so a worker thread could complete an operation before
that state was set up (thread-unsafe), and the completion notification
hijacked the per-request sigevent machinery.

Rework the implementation: lio_listio() now links every aiocb of the
batch into a list (lio_link) before any I/O is submitted.  When an
operation completes, aio_signal() removes its node from the list under
aio_lock() and delivers the lio_listio completion notification only
when the list becomes empty.  The unused aio_priv field is replaced by
the lio_link/lio_sigevent/lio_sigwork fields in struct aiocb.

Co-developed-by: wushenhui <wushenhui@xiaomi.com>
Signed-off-by: wushenhui <wushenhui@xiaomi.com>
Signed-off-by: Xiang Xiao <xiaoxiang@xiaomi.com>
2026-09-14 17:12:49 -03:00
likun17
29a536f53e drivers/sensors: add resistance, conductivity, energy and charge types
Cover the remaining electrical quantities so that they do not have to fork
into driver private namespaces later.  Add SENSOR_TYPE_RESISTANCE (Ohm),
SENSOR_TYPE_CONDUCTIVITY (S/m), SENSOR_TYPE_ENERGY (J) and
SENSOR_TYPE_CHARGE (C), the last two matching the native unit of the
accumulator registers in power and energy monitors.

Signed-off-by: likun17 <likun17@xiaomi.com>
2026-09-13 10:29:08 +08:00