nuttx/arch
Marco Casaroli 802ccef86f xtensa/esp32s3: Abort the faulting user task on an unrecoverable fault.
When an unprivileged task takes a fault the system cannot recover from, it
now gets a fatal SIGSEGV and only that task ends.  A fault in privileged code
still panics.

What decides it is the interrupted context, not the cause: the saved PS says
whether the fault was taken in User Mode.  A list of causes would leave every
cause off the list as a way for a user task to stop the machine, and there
are many -- a divide by zero, a privileged instruction, a load/store error,
and an illegal instruction, which is how a refused fetch from kernel text
arrives on this chip (TRM v1.8 p.699: a denied external-memory access is
answered with 0xdeadbeaf instead of trapping).  PS.UM is clear in a kernel
thread, in a system call made on the user's behalf and in an interrupt
handler, so those still panic.  If the recoverable-fault dispatcher is
enabled it still gets first refusal on causes 28, 29 and 20, the only ones
re-executing can help.

esp32s3_userfault_abort() records the exception frame as the task's context,
dispatches SIGSEGV, and returns the redirected frame, so the vector's RFE
resumes the task in the signal trampoline, whose default action exits it.
CONFIG_ESP32S3_USERFAULT_ABORT enables it, default y wherever there is an
unprivileged world, and selects SIG_DEFAULT and SIG_SIGKILL_ACTION.

Verified on an ESP32-S3 DevKitC with a WROOM-2 module,
esp32s3-devkit:kernel_oct: a user task that writes through NULL, reads a wild
address, divides by zero, calls into a buffer of garbage or branches into
kernel text is terminated on its own, while an unrelated task keeps running.

Stack overflow is not contained.  On the windowed ABI it faults inside the
window overflow handler and arrives as a double exception with PS.UM already
clear; guard pages are the answer, and separate work.

Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
2026-09-29 11:13:47 -03:00
..
arm arch/arm/imxrt: Small cleanups for OCOTP headers 2026-09-29 08:27:28 -03:00
arm64 arch/arm64/imx9: add key store, signing and persistence to the ELE 2026-09-28 21:50:43 +08:00
avr arch, boards, cmake: Build C++ ELF modules without __cxa_atexit. 2026-09-04 15:44:24 -03:00
ceva arch/atomic: remove up_testset in spinlock 2026-09-08 08:58:54 +08:00
dummy
hc
mips arch, boards, cmake: Build C++ ELF modules without __cxa_atexit. 2026-09-04 15:44:24 -03:00
misoc arch, boards, cmake: Build C++ ELF modules without __cxa_atexit. 2026-09-04 15:44:24 -03:00
or1k arch, boards, cmake: Build C++ ELF modules without __cxa_atexit. 2026-09-04 15:44:24 -03:00
renesas nuttx/libc: refine the atomic related Kconfig 2026-08-24 13:20:45 +08:00
risc-v arch/risc-v/espressif: Fix nxstyle issues in esp_serial.c. 2026-09-29 09:10:53 +08:00
sim arch/sim: buffer several mouse reports 2026-09-25 10:36:28 +02:00
sparc arch/atomic: remove up_testset in spinlock 2026-09-08 08:58:54 +08:00
tricore arch/atomic: remove up_testset in spinlock 2026-09-08 08:58:54 +08:00
x86 arch/x86: Add -P to CPP to suppress linemarkers. 2026-09-17 16:21:59 +08:00
x86_64 arch/x86_64: Implement up_addrenv_fork() and provide POSIX fork(). 2026-09-24 18:02:36 -03:00
xtensa xtensa/esp32s3: Abort the faulting user task on an unrecoverable fault. 2026-09-29 11:13:47 -03:00
z16
z80
CMakeLists.txt cmake: Use NUTTX(_DIR/_BIN_DIR) instead CMAKE(_SRC_DIR/_BIN_DIR) 2026-08-09 11:13:08 -03:00
Kconfig arch/xtensa: Provide POSIX fork() on the ESP32-S3. 2026-09-26 11:13:57 -03:00