Apache NuttX is a mature, real-time embedded operating system (RTOS) https://nuttx.apache.org/
Find a file
Marco Casaroli d5b4edd761 binfmt/fdpic: Run constructors, and bind the PLT relocation table.
Two gaps that both fail quietly.

DT_INIT_ARRAY and DT_FINI_ARRAY were ignored entirely.  A C++ module with
any global object therefore loaded, resolved every symbol and ran, with all
of its globals left as .bss reading back zero -- no fault, no log, just
wrong answers.  Both arrays are now walked per object and in dependency
order: an object joins the load's list before the DT_NEEDED walk appends its
own dependencies, so walking that list backwards constructs a library before
the module that needs it, and destruction mirrors it.

Constructors run in whichever task called the loader, before the module's
own task exists, so the FDPIC register does not already hold the object's
data base the way it does once the module is running.  fdpic_callfn()
installs it around each call.  That is safe only because the firmware
reserves the register; being preempted mid-constructor is harmless, since
the register is part of the saved context.

DT_JMPREL was not parsed at all.  Which table an imported function's
descriptor lands in is a linker decision -- -z now puts it in DT_REL, and
without it the same entry goes to DT_JMPREL -- so a module linked the second
way loaded cleanly and then branched to an unrelocated address on its first
call into the firmware.  The symptom is an INVSTATE UsageFault escalated to
a HardFault: no console, no crash dump.  There is no lazy resolver here, so
an unwalked table is not deferred work; both are now bound eagerly, and
nothing is lost by that because a module carries a handful of relocations.

The two tables are not walked identically, which is the part worth
remembering.  In DT_REL the word being overwritten is the addend, and
dropping it breaks a static function reached through its section symbol.  In
DT_JMPREL that same word is the lazy-binding bootstrap -- the address of the
entry's own PLT resolution stub, with a GOT half of -1 -- and adding it to
the resolved symbol value produces an arbitrary address that faults exactly
like the bug this change fixes.  An eager binder overwrites the descriptor
outright.

The descriptor pool is sized from relsize + pltrelsz rather than relsize
alone, so an R_ARM_FUNCDESC in the PLT table cannot run off the end of the
allocation.  GNU ld does not appear to emit that combination -- an
address-taken function is not a call and so never becomes a PLT relocation
-- but the failure it would cause is heap corruption, and the guard is two
additions.

An object declaring RELA PLT relocations is refused rather than misread:
nothing here reads RELA, whose entries are twelve bytes rather than eight.

Assisted-by: Claude Code:claude-opus-4-8
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
2026-08-01 12:23:27 +02:00
.github build(deps): bump actions/setup-python from 6 to 7 2026-07-27 13:34:36 -04:00
arch binfmt/fdpic: Add an FDPIC ELF module loader. 2026-08-01 12:23:27 +02:00
audio tools: fix stale archive members surviving a Kconfig-driven CSRCS change 2026-07-28 21:26:03 -03:00
binfmt binfmt/fdpic: Run constructors, and bind the PLT relocation table. 2026-08-01 12:23:27 +02:00
boards boards: drop the keyboard options that the driver change made stale 2026-08-01 11:13:37 +08:00
cmake cmake: Omit default priority ELF symbol. 2026-07-27 14:30:42 +08:00
crypto tools: fix stale archive members surviving a Kconfig-driven CSRCS change 2026-07-28 21:26:03 -03:00
Documentation Documentation: describe the contract for writing a keyboard driver 2026-07-31 11:02:20 -03:00
drivers gpio: Fix GPIO expanders warnings 2026-08-01 11:15:11 +08:00
dummy
fs fs: enforce permission checks when opening IPC pseudo-inodes 2026-07-30 09:48:10 +08:00
graphics tools: fix stale archive members surviving a Kconfig-driven CSRCS change 2026-07-28 21:26:03 -03:00
include binfmt/fdpic: Run constructors, and bind the PLT relocation table. 2026-08-01 12:23:27 +02:00
libs binfmt/fdpic: Add an FDPIC ELF module loader. 2026-08-01 12:23:27 +02:00
mm mm/ubsan: fix signed inline value decoding 2026-07-30 12:52:17 +02:00
net tools: fix stale archive members surviving a Kconfig-driven CSRCS change 2026-07-28 21:26:03 -03:00
openamp tools: fix stale archive members surviving a Kconfig-driven CSRCS change 2026-07-28 21:26:03 -03:00
pass1 tools: fix stale archive members surviving a Kconfig-driven CSRCS change 2026-07-28 21:26:03 -03:00
sched sched/sched: Fix uninitialized sporadic params returned by nxsched_get_param() 2026-08-01 11:19:50 +08:00
syscall sched/group: add getresuid, getresgid, setreuid, and setregid 2026-07-30 09:48:10 +08:00
tools arch/arm/rtl8721f: bring up minimal NSH (P1) 2026-07-30 17:04:14 +08:00
video tools: fix stale archive members surviving a Kconfig-driven CSRCS change 2026-07-28 21:26:03 -03:00
wireless tools: fix stale archive members surviving a Kconfig-driven CSRCS change 2026-07-28 21:26:03 -03:00
.asf.yaml github: master branch protection tune. 2025-05-07 18:37:13 -05:00
.codespell-ignore-lines arch/arm: Reserve r10 via ARCHCFLAGS and hoist the PIC module flags. 2026-07-24 23:09:08 +08:00
.codespellrc binfmt/fdpic: Add an FDPIC ELF module loader. 2026-08-01 12:23:27 +02:00
.editorconfig .editorconfig: fix character encoding property specification 2025-11-28 19:12:13 +08:00
.gitignore git: Specify multiple build directories in .gitignore. 2026-05-20 03:06:58 +08:00
.gitmessage docs/contributing: Add a commit message template 2025-06-03 17:33:24 +08:00
.pre-commit-config.yaml pre-commit: enable codespell checks 2025-05-05 12:34:39 +08:00
.yamllint
AUTHORS AUTHORS: add Eren Terzioglu 2026-05-20 15:17:00 +08:00
CMakeLists.txt cmake: Do not link an executable to detect the compiler. 2026-07-25 22:52:39 +08:00
CONTRIBUTING.md contributing: Add requirement for 'Assisted-by' commit field 2026-07-12 09:42:28 +08:00
INVIOLABLES.md
Kconfig sched/misc/assert: Add CONFIG_SCHED_DUMP_TASKS and CONFIG_SCHED_DUMP_STACK 2026-06-09 08:04:54 -04:00
LICENSE libs/libdsp: Add Matrix operations 2026-07-11 14:55:59 -03:00
Makefile !boards: enforce secure ROMFS passwd and TEA key setup 2026-07-09 22:41:11 +08:00
NOTICE
README.md ci/testing: Add MemBrowse Integration 2026-06-18 12:07:41 -03:00
ReleaseNotes Documentation: move ReleaseNotes 2023-09-26 20:41:00 +08:00

POSIX Badge License Issues Tracking Badge Contributors GitHub Build Badge Documentation Badge MemBrowse

Apache NuttX is a real-time operating system (RTOS) with an emphasis on standards compliance and small footprint. Scalable from 8-bit to 64-bit microcontroller environments, the primary governing standards in NuttX are POSIX and ANSI standards. Additional standard APIs from Unix and other common RTOSs (such as VxWorks) are adopted for functionality not available under these standards, or for functionality that is not appropriate for deeply-embedded environments (such as fork()).

For brevity, many parts of the documentation will refer to Apache NuttX as simply NuttX.

Getting Started

First time on NuttX? Read the Getting Started guide! If you don't have a board available, NuttX has its own simulator that you can run on terminal.

Documentation

You can find the current NuttX documentation on the Documentation Page.

Alternatively, you can build the documentation yourself by following the Documentation Build Instructions.

The old NuttX documentation is still available in the Apache wiki.

Supported Boards

NuttX supports a wide variety of platforms. See the full list on the Supported Platforms page.

Contributing

If you wish to contribute to the NuttX project, read the Contributing guidelines for information on Git usage, coding standard, workflow and the NuttX principles.

License

The code in this repository is under either the Apache 2 license, or a license compatible with the Apache 2 license. See the License Page for more information.