The always-on timer has an alarm comparator, but the RTC driver did not
use it: rp23xx_rtc.c implemented only up_rtc_initialize(),
up_rtc_time() and up_rtc_settime().
Add the alarm and an RTC lower half for /dev/rtc0:
- rp23xx_rtc_setalarm(), rp23xx_rtc_cancelalarm() and
rp23xx_rtc_rdalarm() on the ALARM_TIME registers and the POWMAN
timer interrupt.
- An RTC lower half with rdtime, settime, setalarm, setrelative,
cancelalarm and rdalarm, registered by the common board bringup.
The comparator asserts while the time is past the alarm time, not on
a transition. So the interrupt handler disables the alarm before it
does anything else; clearing only the status makes the interrupt
repeat. The arming sequence is the one of
powman_timer_enable_alarm_at_ms() in the Pico SDK.
Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
Indent the flash MTD block as nxstyle wants. Whitespace only; git diff
-w is empty.
Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
The board set LDELFFLAGS to "-r -e main" after it included Toolchain.defs.
This replaced the flags that Toolchain.defs sets for a loadable module.
With CONFIG_FDPIC, a module then links as a relocatable object and not as
an FDPIC shared object. A module that names a library does not link at
all: "attempted static link of dynamic object".
9ed93c6b1e moved these flags into Toolchain.defs for all boards, and
dae3b8e551 removed the same lines from mps3-an547. Remove them here
too.
Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
The OTP, read-only (UID, flash size, package) and high-cycle data (EDATA)
flash areas only accept 16/32-bit accesses and return a bus error
otherwise (RM0481 Table 77). The manual requires the MPU to disable local
cacheability for them (RM0481 7.3.2); with the ICACHE enabled and no such
region, reading them raises a precise bus error.
Until now this was worked around piecemeal: the driver disabled the
ICACHE around stm32_get_uniqueid() and the OTP and EDATA word reads, and
nucleo-h563zi mapped the 4 KB OTP/RO area non-cacheable in its board
code. Other reads, for example stm32_otp_read() or an application
reading the OTP on another board, still raised a precise bus error when
the ICACHE was enabled.
Map 0x08fff000-0x09017fff, which covers the three contiguous areas, as
Normal non-cacheable and execute-never with a single MPU region before
the ICACHE is enabled. STM32_ICACHE now selects ARM_MPU so that
stm32_mpuinitialize() has reset and enabled the MPU by then.
Remove the nucleo-h563zi OTP region in the same commit: the Armv8-M MPU
faults on an address that matches more than one region, so keeping both
would make OTP and UID reads fault on that board.
Assisted-by: Claude:claude-sonnet-5-5
Assisted-by: Claude:claude-opus-5-5
Signed-off-by: Ricardo Maurizio Paul <ricardopaul@geotab.com>
board.h gains GPIO_SCI0_RX/TX (P610/P609, SCI0 pin group 3), needed to
exercise CONFIG_RA_SCI0_UART on this board at all -- previously only
SCI9's console pins existed.
The new serial-test defconfig builds on nsh with SCI0 enabled as
/dev/ttyS1 with its FIFO (CONFIG_RA_SCI0_FIFO, measured on hardware as
the best overrun-resistant setting: TTRG=15, RXTRG=0), 1024-byte RX/TX
ring buffers (up from the 256-byte default, to better absorb bursts
during testing), CONFIG_SERIAL_TERMIOS + apps/system/stty (to change
its baud rate live), and apps/examples/serialblaster + serialrx
pointed at it, for exercising the SCI_B driver's FIFO/overrun-recovery
paths independently of the SCI9 console.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Assisted-by: Claude:claude-sonnet-5
Signed-off-by: leocafonso <leocafonso@gmail.com>
Add stm32h7s8-dk board support for nsh running out of internal flash,
including LEDs and user button.
Signed-off-by: Peter Barada <peter.barada@gmail.com>
Select the cache line size from either ARMV7M_DCACHE_LINESIZE or
ARMV8M_DCACHE_LINESIZE, so the driver can also be used with D-cache
enabled on the i.MX RT1180 Cortex-M33.
Also fix the imxrt1180-evk USB DMA allocator alignment. Pad the header
to the 32-byte DMA alignment, so that the buffer remains aligned.
Signed-off-by: Jukka Laitinen <jukka.laitinen@tii.ae>
Register GPT0 (32-bit) as /dev/timer0 and GPT9 (16-bit) as /dev/timer1
during bring-up.
Register the Arduino Uno shield header's D2-D5 as inputs and D6-D13 as
outputs through the generic GPIO expander driver, as /dev/gpio0-3 and
/dev/gpio4-11.
Add the ek-ra8m1:timer-gpio configuration (nsh plus both GPT channels,
the GPIO support above, and apps/examples/gpio and
apps/examples/timer_gpio), used to validate the GPT timer driver on
hardware with an oscilloscope.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Assisted-by: Claude:claude-sonnet-5
Signed-off-by: leocafonso <leocafonso@gmail.com>
There were some bits erroneously copied from imx9. For IMXRT1180, the
GPIO_AD* and GPIO_AON* pads should have SRE, DSE, PUE, PUS and ODE bits
on SW_PAD_CTL_PAD register.
The GPIO_EMC_*, GPIO_SD_*, GPIO_B1_* and GPIO_B2_* have a bit different fields,
PDRV, PULL and ODE.
Signed-off-by: Jukka Laitinen <jukka.laitinen@tii.ae>
The PMS grants and refuses physical addresses, so it never sees an access
that no MMU entry translates. The cache answered such an access with zeros
and raised nothing, and the task carried on with a value it never should
have had.
Enable EXTMEM_MMU_ENTRY_FAULT and route the Cache Invalid Access interrupt
to the handler that already serves the PMS monitors. An unprivileged task
that makes the access is terminated with SIGSEGV; a privileged one still
panics. The latch is level triggered, so it is cleared with the others.
Read the cause before the clear, so the log tells the two apart: a PMS
violation is a refused translation, an MMU entry fault is an access that was
never translated.
Give the kernel_oct configuration the addresses that examples/sandbox needs
to name its targets.
Assisted-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
When an unprivileged task takes a fault the system cannot recover from, it
now gets a fatal SIGSEGV and only that task ends. A fault in privileged code
still panics.
What decides it is the interrupted context, not the cause: the saved PS says
whether the fault was taken in User Mode. A list of causes would leave every
cause off the list as a way for a user task to stop the machine, and there
are many -- a divide by zero, a privileged instruction, a load/store error,
and an illegal instruction, which is how a refused fetch from kernel text
arrives on this chip (TRM v1.8 p.699: a denied external-memory access is
answered with 0xdeadbeaf instead of trapping). PS.UM is clear in a kernel
thread, in a system call made on the user's behalf and in an interrupt
handler, so those still panic. If the recoverable-fault dispatcher is
enabled it still gets first refusal on causes 28, 29 and 20, the only ones
re-executing can help.
esp32s3_userfault_abort() records the exception frame as the task's context,
dispatches SIGSEGV, and returns the redirected frame, so the vector's RFE
resumes the task in the signal trampoline, whose default action exits it.
CONFIG_ESP32S3_USERFAULT_ABORT enables it, default y wherever there is an
unprivileged world, and selects SIG_DEFAULT and SIG_SIGKILL_ACTION.
Verified on an ESP32-S3 DevKitC with a WROOM-2 module,
esp32s3-devkit:kernel_oct: a user task that writes through NULL, reads a wild
address, divides by zero, calls into a buffer of garbage or branches into
kernel text is terminated on its own, while an unrelated task keeps running.
Stack overflow is not contained. On the windowed ABI it faults inside the
window overflow handler and arrives as a double exception with PS.UM already
clear; guard pages are the answer, and separate work.
Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
Separate the world split from the protected user image, give WORLD1 its own
vector table and its own PMS permissions -- including the PSRAM -- clean up
the user cache-MMU windows, and stop keeping the page pool mapped.
Folds in:
xtensa/esp32s3: separate the world split from the protected user image
xtensa/esp32s3: give the unprivileged world its own vector table
xtensa/esp32s3: give the unprivileged world its permissions
xtensa/esp32s3: clean up the user cache-MMU windows
xtensa/esp32s3: stop keeping the page pool mapped
xtensa/esp32s3: give the PSRAM its own PMS permissions
Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
Implement the same initial clock configuration as what imxrt1176 has. Make an own table
for PLL and root clock configurations for m33 and m7 targets. For the PLLs the code still
only supports configuring the ARM_PLL.
The difference to imxrt1176 is, that instead of just boolean .enable field, this table
uses an .action field with 3 states: CONFIGURE, DISABLE and IGNORE. The reason is,
that some root clocks can't be just forcefully stopped, but need a root-clock-specific
sequence. This is solved by just leaving these clocks marked as IGNORE, so they retain
their current state.
Specifically, disabling the SEMC and NETC roots by M33 will prevent the M7 from booting.
Also FLEXSPI shouldn't be touched, if the code is being executed from there.
Also add a function for enabling 24 MHz oscillator clock, and an extendable function to
enable the clock sources based on the clock configuration table.
Assisted-by: Claude Code
Signed-off-by: Jukka Laitinen <jukka.laitinen@tii.ae>
Add board support for the EK-RA8M1 evaluation kit with nsh and
nsh-leds configurations, linker script, LED support and bring-up.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Signed-off-by: leocafonso <leocafonso@gmail.com>
Add CMake build support for the stm32l476vg-disco board by introducing
board and source CMakeLists.txt files.
This allows the stm32l476vg-disco:nsh configuration to build successfully
with the CMake build system.
Fixes: #20366
Signed-off-by: Ahmed Ashraf NourEldeen <a.programmer55559@gmail.com>
Publishes /proc/pinctrl on both boards, which lists every pad with the
function it currently carries. The startup banner counts how many pads
differ from their reset values, once, at boot; this answers the same
question at any later moment, which is what is wanted when a driver has
just reconfigured a pad and the result is not what was expected.
PINCTRL_PROCFS depends on FS_PROCFS_REGISTER, the entry registering
itself at run time rather than being one of the built in ones. Neither
board set it, and without it the symbol is dropped when the configuration
is regenerated and the entry never appears, which is silent: the
defconfig still reads as though the feature were on.
Assisted-by: Claude:claude-opus-5
Signed-off-by: Justin Hammond <justin@dynam.ac>
Log one line from board start up with the pad count and how many differ
from their reset defaults, through eic7700x_pinctrl_count(). A helper
holds its locals so nothing stays on the stack for the bring up that
follows.
Turn the pinctrl driver's error output on for both boards, so a refused
pad write says why rather than merely failing.
Assisted-by: Claude:claude-opus-5
Signed-off-by: Justin Hammond <justin@dynam.ac>
A module's D-Space is separate from its I-Space, so its read-only data is not
at a fixed offset from its text. GCC assumes that it is and loads a string
literal PC-relative, which reads I-Space at run time. A module could
therefore carry no string and reach no static.
lm3s6965-ek has had -mno-pic-data-is-text-relative in its own Make.defs since
2021 (issue #3737), and the CMake build gives it to every PIC configuration,
so the flag moves to where it belonged and the board's copy goes. That copy
also probed for GCC older than 4.9.4, which NuttX no longer supports. Clang
has no such option, hence the guard.
Assisted-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
Suppress the peer notifications while a ring keeps delivering work, batch
the receive completions into one kick per burst and drop the redundant
txdone signal from the transmit path. Validate the peer controlled frame
lengths, accept descriptor chains on both lanes, keep every ring access on
the upper half's work thread so the interrupt context callbacks stay lock
free, and prefer the MAC from the configuration space, falling back to the
Kconfig address or a random one.
Signed-off-by: zhanghongyu <zhanghongyu@xiaomi.com>
kernel_oct targets a WROOM-2 N32R8V: octal flash, and 8 MB of PSRAM for the
page pool. The defaults size the pool for that part, with 8 pages of 64 KiB
for each of the text, data and heap regions, so 1.5 MB per process. fork()
duplicates the address environment, so a parent and a child need 3 MB at once
and a module with 2 MB of PSRAM cannot do it.
kernel_n8r2 sizes the same build for such a module. Each region is 2 pages,
so a process takes 384 KiB and a fork() peaks at 768 KiB, inside a 1.5 MB pool
placed at 0x80000 to leave the start of the PSRAM alone.
The flash is quad and runs in DIO mode, so this configuration also exercises
the CONFIG_ESP32S3_FLASH_MODE_OCT guard in kernel-space.ld from the quad side,
which kernel_oct cannot.
This is tight by construction. ostest has 115 KiB of text against a 128 KiB
text region. A larger program needs a module with more PSRAM, not a larger
pool.
Verified on an ESP32-S3-DevKitC with an N8R2 module, 8 MB flash in DIO mode
and 2 MB of embedded quad PSRAM. ostest reports "Parent and child had
independent memory" and exits with status 0.
Assisted-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
The page pool is carved out of the PSRAM that user processes run from, and
the external memory permissions are indexed by physical address, so a
permanent kernel window onto the pool is a window onto every process, which
no permission setting can close.
Stop mapping the pool. The kernel reaches a pool page through a small
scratch region instead, mapped for one operation and invalidated afterwards.
esp32s3_pgmap() takes a slot, esp32s3_pgunmap() releases it, and
ARCH_KMAP_VBASE and ARCH_KMAP_NPAGES describe the region. Two slots are
enough, because the deepest user is up_addrenv_fork(), which holds a source
and a destination page at once.
Assisted-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
The common Xtensa BUILD_KERNEL support needs the chip to say what it can do
and where its memory goes.
The chip selects the address environment options it now implements, keeps the
kernel and user heaps apart, and the linker scripts separate kernel from user
text and data so the two worlds can be given different permissions.
kernel_oct configures a board for it, with the user-program layout and the
boot ROMFS a kernel build loads its programs from. The ROMFS placeholder is
rebuilt with the image, the generated copy is ignored, and the programs are
given stack sizes and room for a fork() child.
Assisted-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
Give the ESP32-S3 the arch_addrenv_t machinery that BUILD_KERNEL needs: a
per-process page directory built from the 64 KiB MMU pages of the chip, with
allocation, teardown, and the vaddr-to-paddr translation that the kernel uses
to reach a user buffer.
The MMU, PMS and WCL primitives are exposed as an arch API first, because the
address environment code and the protected user split both need them and
neither owns them.
Assisted-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
The protected kernel linker (kernel-space.ld) placed the octal (OPI)
flash bring-up helpers -- esp_rom_spiflash / esp_rom_opiflash_*,
spi_flash_oct_flash_init, mmu_hal, mspi_timing_*, bootloader_flash*,
efuse_hal/efuse_utility, esp_mmu_map and esp32s3_spi_timing -- in mapped
flash. During configure_cpu_caches() / spi_flash_init_chip_state() in
__start these run while the flash mapping is being reconfigured, which
faults (illegal instruction) on octal-flash modules such as the
ESP32-S3-WROOM-2. Quad-flash parts never exercise the OPI path, so the
problem was latent.
Place those functions in .iram0.text (mirroring the flat sections
script) so they are safe to execute during flash reconfiguration.
Assisted-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
The TRDC (Trusted Resource Domain Controller) configuration should be completely
driven by the board configuration, and not hard-coded:
- Add tables for the current GPIO configuration and MDA configuration.
- Fix the GPIO configurations for M7; previously GPIO access from M7 was
denied because of secure/nonsecure setting.
Signed-off-by: Jukka Laitinen <jukka.laitinen@tii.ae>
Add NSH bringup for the Espressif ESP8684-DevKitM. The nsh defconfig
uses a 26 MHz XTAL, 4 MB flash, and debug features for the MINI-1 module.
Assisted-by: Claude:claude-opus-5
Signed-off-by: Marcio Ribeiro <marcio.ribeiro@espressif.com>
Add linker scripts and shared board drivers reused by ESP32-C2 boards,
and wire common Kconfig into the board configuration tree.
Assisted-by: Claude:claude-opus-5
Signed-off-by: Marcio Ribeiro <marcio.ribeiro@espressif.com>
Recently the nxstyle became more restrictive so it got some issues
that used to be ignored in the pass.
Signed-off-by: Alan C. Assis <acassis@gmail.com>
The X11 mouse emulation driver (arch/sim/src/sim/sim_mouse.c) is built
and fed by the X11 event loop whenever CONFIG_SIM_MOUSE=y, but nothing
ever called sim_mouse_initialize(), so /dev/mouse0 was never registered
and applications could not read any mouse reports. Since nothing
referenced sim_mouse.o, the linker did not even pull it in and the
build failed with "undefined reference to `sim_mouseevent'".
Call sim_mouse_initialize(0) from sim_bringup(), next to the existing
touchscreen and keyboard initialization.
Tested with sim:nsh + CONFIG_SIM_X11FB, CONFIG_SIM_MOUSE and
CONFIG_SIM_KEYBOARD: /dev/mouse0 is now listed and reports left, middle
and right button state plus pointer motion.
Signed-off-by: Alan C. Assis <acassis@gmai.com>
Assisted-by: Claude Opus 5.5 (1M context)
Expose the RTL8730E general-purpose UARTs through the shared Ameba
serial driver (arch/arm/src/common/ameba/ameba_uart.c) by adding the
chip-specific glue, build wiring and a board port table. The change is
gated by CONFIG_AMEBA_UART (default disabled); the LOG-UART keeps the
console and /dev/ttyS0.
Chip glue (ameba_uart_chip.h) supplies the three UART controller
register bases, GIC IRQ numbers (SPI 50/51/52 -> NuttX IRQ 82/83/84),
APB clock masks and pin-mux codes. The board registers UART0-2 as
/dev/ttyS1-3 at 115200 8N1; UART3 is reserved for Bluetooth. Pads are
picked from the EVB break-out (the UART crossbar maps each controller to
many pads, so this is purely a board choice).
Also fix an RX-timeout interrupt storm in the shared driver: the
RX-timeout status (LSR bit9) is latched and is not cleared by draining
the RX FIFO, so on a level-triggered GIC (RTL8730E) the ISR must
explicitly write TOICF, matching the vendor SDK serial_api.c. The
extra register write is harmless on the NVIC-based M33 Ameba parts and
was regression-tested on them.
Signed-off-by: dechao_gong <dechao_gong@realsil.com.cn>
Assisted-by: Claude <noreply@anthropic.com>
Under sustained dual-core critical-section traffic (e.g. several UART
ISRs) the two Cortex-A32 cores live-lock trading failed STREX. The
generic critical-section lock g_cpu_irqlock (an LDREX/STREX spinlock)
and the plain non-atomic bitmap g_cpu_irqset are defined back-to-back
in sched/irq/irq_csection.c and land in the same 64-byte cache line.
The A32 exclusive monitor reserves a full cache line, so one core's
ordinary store to g_cpu_irqset clears the other core's LDREX
reservation on g_cpu_irqlock.
Separate the two symbols onto their own cache lines in the board link
script, leaving the generic scheduler source untouched (relies on the
toolchain emitting per-object -fdata-sections).
Signed-off-by: dechao_gong <dechao_gong@realsil.com.cn>
Assisted-by: Claude <noreply@anthropic.com>
Add an initial port for the AIFoundry Erbium Minion core running on the
public ET-platform system emulator (erbium_emu). NuttX boots directly
from a firmware ELF at 0x40000200, runs in machine mode on hart 0 with
SMP disabled, and parks secondary harts before they touch memory.
The chip layer provides startup, PLIC interrupts, the UART0 console
driver and the machine timer. Context switching, FPU save/restore,
heap, idle and timer handling reuse the common RISC-V code. Atomics use
interrupt masking because the core does not implement the A extension.
Erbium implements the F extension but executes fdiv/fsqrt and FENCE.I
in microcode, which a standalone image does not provide. The board build
files pass -mno-fdiv to GCC when the FPU is enabled, so those operations
use software helpers. Startup initializes the FPU without the common
FENCE.I sequence, and the board configurations disable the dynamic ELF
loader, which also relies on FENCE.I.
Add minion:nsh and minion:ostest configurations, Make and CMake
support, CMake CI build entries, and a host script that runs prebuilt
images in the emulator and checks the console and OS test results.
Tested with emulator revision 836a4ab600e9 and xPack GCC 14.3.0: both
configurations build with Make and CMake, ostest exits with status 0
including the FPU tests, and the NSH console, procfs, timer and UART
receive paths work. Silicon, SMP, protected builds and reboot are not
covered by this initial port.
Signed-off-by: Afonso Oliveira <afonso.oliveira707@gmail.com>
A MIMXRT1176 flight controller built to the Pixhawk FMUv6X-RT standard, so
the port also covers the NXP MR-VMU-RT1176.
Board data comes from PX4, which already carries it as a NuttX board config:
the clock tree, the LPUART1 pinmux, and the Macronix octal flash
configuration block the boot ROM reads at offset 0x400.
The board ships with the PX4 bootloader in the first 128 KB of QSPI, so the
image links at 0x30020000 and is loaded by it rather than written to the
flash base. The console is CDC/ACM as on teensy-4.x, so a USB cable is the
only thing needed to run NuttX here.
Signed-off-by: Royyan Zahir <royzah@gmail.com>
The flexspi_nor_config_s was missing four fields, resulting the fields after the
missing ones being read from wrong positions.
Align the struct properly according to the reference manual.
Signed-off-by: Jukka Laitinen <jukka.laitinen@tii.ae>
Correct switch and declaration indentation, separate declarations from code,
and wrap a long comment in the SPI driver. Fix the timer driver and both
STM32L5 board LED implementations checked by the commonization PR.
These are formatting changes only.
Signed-off-by: raiden00pl <raiden00@railab.me>
Select STM32_HAVE_IP_GPIO_M33_V1 and STM32_HAVE_IP_EXTI_M33_V1 and
drop the family GPIO and EXTI sources and headers in favor of the
common Cortex-M33 v1 implementation.
Define both EXTI register banks and retain the named bit definitions.
Use shared line and selector helpers without per-line conditionals.
Clear each GPIO selector with the same byte mask, as the H5 driver does.
Cover both 32-bit banks and H5 line inventories for later migration.
The common EXTI driver also routes the selected port through EXTICR,
which the family driver never programmed, so GPIO interrupts now work
on ports other than GPIOA.
Signed-off-by: raiden00pl <raiden00@railab.me>
Assisted-by: Claude Code
The FIFO watermark flag is a level: it stays high until the worker
actually drains the FIFO below the threshold. Configuring INT1 as RISING
made that a race the driver could lose permanently.
lsm6ds3trc_interrupt() disables its IRQ on entry and re-enables it after
the worker has run. With an edge trigger, if the line is still high when
the IRQ is re-enabled -- which is precisely what happens whenever a drain
does not take the FIFO below the watermark -- there is no new low-to-high
transition left to detect, and the line goes mute forever. Observed as a
board that serviced exactly one watermark after boot and then never
again, reproducible 2 out of 2 reflashes.
ONHIGH matches the physical meaning of the pin and is immune to it: a
level trigger re-asserts on its own for as long as the condition holds,
and the disable/enable pairing around servicing is what stops that from
live-locking.
Validated with more than 900 consecutive drains (~100 min) including real
sleep -> GPIO-wake -> resume transitions, the exact case that used to
wedge.
Signed-off-by: Felipe Moura <moura.fmo@gmail.com>
Assisted-by: Claude:claude-opus-5