The RP2350 embeds an Arm CryptoCell-style true random number generator: a sampled ring oscillator conditioned by von-Neumann, CRNGT and autocorrelation health tests, presenting 192 bits in the six EHR_DATA words. Add a polling driver that serves those conditioned bits as /dev/random and /dev/urandom. Entropy is drawn rarely (an mbedtls CTR_DRBG seeds once and reseeds occasionally), so a blocking poll is used rather than interrupt plumbing; the hardware health-test failures discard the block and re-arm the source, so only conditioned entropy is returned. A startup self-test gates the source before it is trusted: it draws a sample of the conditioned output and rejects a stuck source (identical consecutive 192-bit blocks), a constant byte, or an absurd run of equal bytes. On failure the source is marked unhealthy and every read returns -EIO, so an entropy consumer fail-stops rather than minting keys on a broken source. (The statistical quality is covered by the hardware VN/CRNGT/autocorr tests; this catches the gross, silent failure modes.) New CONFIG_RP23XX_TRNG selects ARCH_HAVE_RNG, which switches /dev/urandom from the software xorshift PRNG to the hardware source (backing getrandom() and thus any entropy consumer such as mbedtls). Tested on a Raspberry Pi Pico 2 W: /dev/random and /dev/urandom register, the startup self-test passes, a read returns at real ring- oscillator sampling latency (~10 ms / 32 B), two independent samples differ, and mbedtls seeds its CTR_DRBG from /dev/urandom successfully. Assisted-by: Claude (Anthropic Claude Code) Signed-off-by: Ricard Rosson <ricard@groundbits.com> |
||
|---|---|---|
| .github | ||
| arch | ||
| audio | ||
| binfmt | ||
| boards | ||
| cmake | ||
| crypto | ||
| Documentation | ||
| drivers | ||
| dummy | ||
| fs | ||
| graphics | ||
| include | ||
| libs | ||
| mm | ||
| net | ||
| openamp | ||
| pass1 | ||
| sched | ||
| syscall | ||
| tools | ||
| video | ||
| wireless | ||
| .asf.yaml | ||
| .codespell-ignore-lines | ||
| .codespellrc | ||
| .editorconfig | ||
| .gitignore | ||
| .gitmessage | ||
| .pre-commit-config.yaml | ||
| .yamllint | ||
| AUTHORS | ||
| CMakeLists.txt | ||
| CONTRIBUTING.md | ||
| INVIOLABLES.md | ||
| Kconfig | ||
| LICENSE | ||
| Makefile | ||
| NOTICE | ||
| README.md | ||
| ReleaseNotes | ||
Apache NuttX is a real-time operating system (RTOS) with an emphasis on standards compliance and small footprint. Scalable from 8-bit to 64-bit microcontroller environments, the primary governing standards in NuttX are POSIX and ANSI standards. Additional standard APIs from Unix and other common RTOSs (such as VxWorks) are adopted for functionality not available under these standards, or for functionality that is not appropriate for deeply-embedded environments (such as fork()).
For brevity, many parts of the documentation will refer to Apache NuttX as simply NuttX.
Getting Started
First time on NuttX? Read the Getting Started guide! If you don't have a board available, NuttX has its own simulator that you can run on terminal.
Documentation
You can find the current NuttX documentation on the Documentation Page.
Alternatively, you can build the documentation yourself by following the Documentation Build Instructions.
The old NuttX documentation is still available in the Apache wiki.
Supported Boards
NuttX supports a wide variety of platforms. See the full list on the Supported Platforms page.
Contributing
If you wish to contribute to the NuttX project, read the Contributing guidelines for information on Git usage, coding standard, workflow and the NuttX principles.
License
The code in this repository is under either the Apache 2 license, or a license compatible with the Apache 2 license. See the License Page for more information.