Apache NuttX is a mature, real-time embedded operating system (RTOS) https://nuttx.apache.org/
Find a file
hujun5 b7b7a4018c spinlock: fix ticket lock corruption in trylock and unlock
Two defects in the CONFIG_TICKET_SPINLOCK paths of spinlock.h:

1. spin_trylock_notrace() passed &lock->owner as the "expected" pointer
   of atomic_cmpxchg().  A failed compare-exchange writes the current
   value of the target object back through that pointer, so a losing
   trylock stores lock->next into lock->owner.  owner then equals next,
   which is the unlocked state: a lock still held by another CPU reports
   itself as free, spin_is_locked() returns false and the lock can be
   taken again.  Every later unlock keeps incrementing owner past next,
   so the ticket of a real waiter never matches and the lock stays
   locked forever.  Keep the expected value in a local variable.

2. spin_unlock() was wrapped in #ifdef __SP_UNLOCK_FUNCTION, a macro
   that is never defined anywhere in the tree.  The function body was
   therefore dead code and spin_unlock() always expanded to
   "do { *(l) = SP_UNLOCKED; } while (0)", which zeroes both ticket
   counters instead of releasing one ticket with
   atomic_fetch_add(&lock->owner, 1).  That drops queued waiters, lets a
   newcomer draw ticket 0 and enter the critical section, and also skips
   the UP_DMB/UP_DSB/UP_SEV release barriers and the
   sched_note_spinlock_unlock() note.  Drop the dead #ifdef so
   spin_unlock() is always the function.

Both were reproduced on qemu-armv7a:smp (cortex-a7 x4) with
CONFIG_TICKET_SPINLOCK=y, where the compare-exchange lowers to native
ldrex/strex.  This confirms the root cause is the C-level aliasing of
the expected pointer, not the atomic implementation.

Refs: https://github.com/apache/nuttx/issues/19808

Signed-off-by: hujun5 <hujun5@xiaomi.com>
2026-09-07 19:19:19 +08:00
.github Documentation: PBKDF2 login docs, board Kconfig, and CI password 2026-08-05 15:26:28 +02:00
arch arch/risc-v/espressif: fix SoftAP-only build of the Wi-Fi event handler 2026-09-07 19:18:45 +08:00
audio audio: limit the buffer count guard to shared ring requests 2026-08-05 16:00:32 +08:00
binfmt tools: fix stale archive members surviving a Kconfig-driven CSRCS change 2026-08-04 00:36:32 +08:00
boards boards/risc-v/hpm6360evk: build fix 2026-08-14 15:30:07 +08:00
cmake !tools/mkpasswd: PBKDF2 host tool and ROMFS passwd build integration 2026-08-05 15:26:28 +02:00
crypto crypto: add CRYPTO_CHACHA20_DJB variant (64-bit counter/nonce) 2026-08-06 17:48:23 +08:00
Documentation Documentation: add NuttX 13.0.1 release notes 2026-08-12 21:53:05 +08:00
drivers drivers/usbdev/cdcacm: fix self-deadlock in cdcuart_txempty() 2026-08-10 22:42:44 +08:00
dummy
fs fs/vfs/fs_read.c: Allow NULL iov_base when CONFIG_ARCH_TEXT_VBASE == 0 2026-09-07 19:18:21 +08:00
graphics tools: fix stale archive members surviving a Kconfig-driven CSRCS change 2026-08-04 00:36:32 +08:00
include spinlock: fix ticket lock corruption in trylock and unlock 2026-09-07 19:19:19 +08:00
libs drivers/serial: add job-control TTY ioctls and libc wrappers 2026-08-06 17:48:04 +08:00
mm mm/ubsan: fix signed inline value decoding 2026-08-04 09:34:08 +08:00
net net/arp: do not resolve an address to another interface's MAC 2026-09-07 19:19:07 +08:00
openamp tools: fix stale archive members surviving a Kconfig-driven CSRCS change 2026-08-04 00:36:32 +08:00
pass1 tools: fix stale archive members surviving a Kconfig-driven CSRCS change 2026-08-04 00:36:32 +08:00
sched sched: Fix stdio initialization of standard streams when buffering is disabled 2026-09-07 19:19:17 +08:00
syscall syscall: add missing memory locking and clock_getres entries 2026-08-10 22:48:05 +08:00
tools tools/cxd56/mkspk: proper resources free on error. 2026-08-15 16:34:51 -03:00
video tools: fix stale archive members surviving a Kconfig-driven CSRCS change 2026-08-04 00:36:32 +08:00
wireless tools: fix stale archive members surviving a Kconfig-driven CSRCS change 2026-08-04 00:36:32 +08:00
.asf.yaml github: master branch protection tune. 2025-05-07 18:37:13 -05:00
.codespell-ignore-lines !boards: Remove NSH_ARCHINIT and board_app_initialize 2026-05-02 18:36:46 +08:00
.codespellrc arch/sim: replace macOS C++ constructor runtime hack with post-link patch 2026-05-19 07:08:55 -03:00
.editorconfig .editorconfig: fix character encoding property specification 2025-11-28 19:12:13 +08:00
.gitignore git: Specify multiple build directories in .gitignore. 2026-05-20 03:06:58 +08:00
.gitmessage docs/contributing: Add a commit message template 2025-06-03 17:33:24 +08:00
.pre-commit-config.yaml pre-commit: enable codespell checks 2025-05-05 12:34:39 +08:00
.yamllint
AUTHORS AUTHORS: add Eren Terzioglu 2026-05-20 15:17:00 +08:00
CMakeLists.txt cmake: Do not link an executable to detect the compiler. 2026-08-03 22:21:10 +08:00
CONTRIBUTING.md docs: Fix typos, formatting, and numbering in README.md and CONTRIBUTING.md. 2026-03-23 12:05:24 +01:00
INVIOLABLES.md
Kconfig sched/misc/assert: Add CONFIG_SCHED_DUMP_TASKS and CONFIG_SCHED_DUMP_STACK 2026-07-04 13:29:32 -04:00
LICENSE !arch/stm32: move stm32l1 and finalize the directory split 2026-07-03 10:27:27 +08:00
Makefile !boards: enforce secure ROMFS passwd and TEA key setup 2026-08-05 15:26:28 +02:00
NOTICE
README.md docs: Fix typos, formatting, and numbering in README.md and CONTRIBUTING.md. 2026-03-23 12:05:24 +01:00
ReleaseNotes Documentation: move ReleaseNotes 2023-09-26 20:41:00 +08:00

POSIX Badge License Issues Tracking Badge Contributors GitHub Build Badge Documentation Badge

Apache NuttX is a real-time operating system (RTOS) with an emphasis on standards compliance and small footprint. Scalable from 8-bit to 64-bit microcontroller environments, the primary governing standards in NuttX are POSIX and ANSI standards. Additional standard APIs from Unix and other common RTOSs (such as VxWorks) are adopted for functionality not available under these standards, or for functionality that is not appropriate for deeply-embedded environments (such as fork()).

For brevity, many parts of the documentation will refer to Apache NuttX as simply NuttX.

Getting Started

First time on NuttX? Read the Getting Started guide! If you don't have a board available, NuttX has its own simulator that you can run on terminal.

Documentation

You can find the current NuttX documentation on the Documentation Page.

Alternatively, you can build the documentation yourself by following the Documentation Build Instructions.

The old NuttX documentation is still available in the Apache wiki.

Supported Boards

NuttX supports a wide variety of platforms. See the full list on the Supported Platforms page.

Contributing

If you wish to contribute to the NuttX project, read the Contributing guidelines for information on Git usage, coding standard, workflow and the NuttX principles.

License

The code in this repository is under either the Apache 2 license, or a license compatible with the Apache 2 license. See the License Page for more information.