When an unprivileged task takes a fault the system cannot recover from, it now gets a fatal SIGSEGV and only that task ends. A fault in privileged code still panics. What decides it is the interrupted context, not the cause: the saved PS says whether the fault was taken in User Mode. A list of causes would leave every cause off the list as a way for a user task to stop the machine, and there are many -- a divide by zero, a privileged instruction, a load/store error, and an illegal instruction, which is how a refused fetch from kernel text arrives on this chip (TRM v1.8 p.699: a denied external-memory access is answered with 0xdeadbeaf instead of trapping). PS.UM is clear in a kernel thread, in a system call made on the user's behalf and in an interrupt handler, so those still panic. If the recoverable-fault dispatcher is enabled it still gets first refusal on causes 28, 29 and 20, the only ones re-executing can help. esp32s3_userfault_abort() records the exception frame as the task's context, dispatches SIGSEGV, and returns the redirected frame, so the vector's RFE resumes the task in the signal trampoline, whose default action exits it. CONFIG_ESP32S3_USERFAULT_ABORT enables it, default y wherever there is an unprivileged world, and selects SIG_DEFAULT and SIG_SIGKILL_ACTION. Verified on an ESP32-S3 DevKitC with a WROOM-2 module, esp32s3-devkit:kernel_oct: a user task that writes through NULL, reads a wild address, divides by zero, calls into a buffer of garbage or branches into kernel text is terminated on its own, while an unrelated task keeps running. Stack overflow is not contained. On the windowed ABI it faults inside the window overflow handler and arrives as a double exception with PS.UM already clear; guard pages are the answer, and separate work. Assisted-by: Claude Code:claude-opus-5-5 Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com> |
||
|---|---|---|
| .github | ||
| arch | ||
| audio | ||
| binfmt | ||
| boards | ||
| cmake | ||
| crypto | ||
| Documentation | ||
| drivers | ||
| dummy | ||
| fs | ||
| graphics | ||
| include | ||
| libs | ||
| mm | ||
| net | ||
| openamp | ||
| pass1 | ||
| sched | ||
| syscall | ||
| tools | ||
| video | ||
| wireless | ||
| .asf.yaml | ||
| .codespell-ignore-lines | ||
| .codespellrc | ||
| .editorconfig | ||
| .gitignore | ||
| .gitmessage | ||
| .mcp.json | ||
| .pre-commit-config.yaml | ||
| .yamllint | ||
| AUTHORS | ||
| CMakeLists.txt | ||
| CONTRIBUTING.md | ||
| INVIOLABLES.md | ||
| Kconfig | ||
| LICENSE | ||
| Makefile | ||
| NOTICE | ||
| README.md | ||
| ReleaseNotes | ||
Apache NuttX is a real-time operating system (RTOS) with an emphasis on standards compliance and small footprint. Scalable from 8-bit to 64-bit microcontroller environments, the primary governing standards in NuttX are POSIX and ANSI standards. Additional standard APIs from Unix and other common RTOSs (such as VxWorks) are adopted for functionality not available under these standards, or for functionality that is not appropriate for deeply-embedded environments (such as fork()).
For brevity, many parts of the documentation will refer to Apache NuttX as simply NuttX.
Getting Started
First time on NuttX? Read the Getting Started guide! If you don't have a board available, NuttX has its own simulator that you can run on terminal.
Documentation
You can find the current NuttX documentation on the Documentation Page.
Alternatively, you can build the documentation yourself by following the Documentation Build Instructions.
The old NuttX documentation is still available in the Apache wiki.
Supported Boards
NuttX supports a wide variety of platforms. See the full list on the Supported Platforms page.
Contributing
If you wish to contribute to the NuttX project, read the Contributing guidelines for information on Git usage, coding standard, workflow and the NuttX principles.
License
The code in this repository is under either the Apache 2 license, or a license compatible with the Apache 2 license. See the License Page for more information.