Apache NuttX is a mature, real-time embedded operating system (RTOS) https://nuttx.apache.org/
Find a file
Marco Casaroli e499b9f174 arch/arm: carry CONTROL over to the fork child on Cortex-M
In a protected build arm_svcall.c treats the caller's CONTROL as part of
the saved system call state: it stores it in xcp.syscall[].ctrlreturn on
entry and restores it from there on SYS_syscall_return.  All three
Cortex-M profiles do this -- armv6-m, armv7-m and armv8-m each define the
field in arch/arm/include/<arch>/irq.h and use it symmetrically.

arm_fork_direct() copied sysreturn and excreturn to the child but not
ctrlreturn.  The child's TCB comes from kmm_zalloc(), so the field was
zero, and CONTROL == 0 is nPRIV clear: the child returned to user space
privileged while its parent returned unprivileged.  The child ran out its
life with the MPU restrictions its parent is under silently lifted, which
is the isolation BUILD_PROTECTED exists to provide.

Nothing faults, and that is why this survived.  CONTROL == 0 also selects
MSP, which sounds like it should crash immediately, but NuttX already
runs Cortex-M threads on MSP -- the parent's saved value is 0x1, nPRIV
set and SPSEL clear -- so the two differ only in the privilege bit and
there is no stack change to trip over.  Privileged code then passes every
test unprivileged code passes, so ostest cannot see it either.

Measured on an RP2350 (Cortex-M33) in BUILD_PROTECTED, breaking at the
nxtask_start_fork() call in arm_fork_direct() during task_fork_test:
parent ctrlreturn 0x00000001, child ctrlreturn 0x00000000.  With this
change both read 0x00000001.

BUILD_FLAT is unaffected: without CONFIG_LIB_SYSCALL, nsyscalls is 0 and
the whole block is skipped.  armv7-a and armv7-r are unaffected too; they
carry cpsr instead, and that is already copied.

Assisted-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
2026-07-28 20:30:51 +08:00
.github build(deps): bump actions/setup-python from 6 to 7 2026-07-27 13:34:36 -04:00
arch arch/arm: carry CONTROL over to the fork child on Cortex-M 2026-07-28 20:30:51 +08:00
audio drivers/efuse/efuse: Drivers Registered With World Write Permissions(Part 1) 2026-07-13 12:08:01 +02:00
binfmt elf:use elf symbol to parse attribute 2026-07-15 12:24:44 -03:00
boards boards/rp23xx: add missing rp23xx_st7735.c LCD board glue 2026-07-28 10:16:12 +08:00
cmake cmake: Omit default priority ELF symbol. 2026-07-27 14:30:42 +08:00
crypto crypto: add CRYPTO_AES_CTR_SSH variant (128-bit big-endian counter) 2026-07-16 15:42:10 +08:00
Documentation documentation: mention PIO4IOE IO Expander 2026-07-28 10:18:01 +08:00
drivers drivers/usbdev/cdcncm: send TX immediately, not after a tick-quantized delay 2026-07-28 12:39:39 +02:00
dummy build: add initial cmake build system 2023-07-08 13:50:48 +08:00
fs fs/vfs: Add ioctldir for volume ioctls via the mountpoint directory. 2026-07-25 07:28:22 -03:00
graphics drivers/: Multiple Drivers Are Registered With World Writable - Part 2 2026-07-15 15:27:28 +08:00
include drives/ioexpander: add support to PI4IOE IO Expander 2026-07-28 10:18:01 +08:00
libs libc/time: Fix POSIX timezone string parsing. 2026-07-25 19:54:18 +08:00
mm arch/mips: Add basic support for MIPS Creator CI20 board 2026-07-15 08:02:55 -03:00
net net/sixlowpan: Fix protosize to 16-bit 2026-07-28 10:19:05 +08:00
openamp openamp: fix CMake dcache option 2026-05-10 15:03:24 +02:00
pass1 Makefile: Remove make depend files by make distclean 2026-02-16 16:27:57 +01:00
sched sched/sched_critmonitor: remove duplicate preemption start block 2026-07-28 16:04:50 +08:00
syscall syscall: fcntl param3 type to uintptr_t 2026-04-27 12:01:55 -03:00
tools tools/nxstyle: add a script to check a whole tree at once 2026-07-28 02:43:24 +08:00
video video: fix EDID standard timing decode 2026-07-17 15:00:50 -03:00
wireless drivers/: Multiple Drivers Are Registered With World Writable - Part 2 2026-07-15 15:27:28 +08:00
.asf.yaml github: master branch protection tune. 2025-05-07 18:37:13 -05:00
.codespell-ignore-lines arch/arm: Reserve r10 via ARCHCFLAGS and hoist the PIC module flags. 2026-07-24 23:09:08 +08:00
.codespellrc arch/arm/rp23xx: Add hardware TRNG driver for /dev/random. 2026-07-25 15:06:56 +08:00
.editorconfig .editorconfig: fix character encoding property specification 2025-11-28 19:12:13 +08:00
.gitignore git: Specify multiple build directories in .gitignore. 2026-05-20 03:06:58 +08:00
.gitmessage docs/contributing: Add a commit message template 2025-06-03 17:33:24 +08:00
.pre-commit-config.yaml pre-commit: enable codespell checks 2025-05-05 12:34:39 +08:00
.yamllint feat: add a GitHub action to lint the YAML files 2020-12-15 09:52:04 -06:00
AUTHORS AUTHORS: add Eren Terzioglu 2026-05-20 15:17:00 +08:00
CMakeLists.txt cmake: Do not link an executable to detect the compiler. 2026-07-25 22:52:39 +08:00
CONTRIBUTING.md contributing: Add requirement for 'Assisted-by' commit field 2026-07-12 09:42:28 +08:00
INVIOLABLES.md INVIOLABLES.md: Fix a simple alignment and change occurrences of Nuttx 2020-09-03 01:33:05 +08:00
Kconfig sched/misc/assert: Add CONFIG_SCHED_DUMP_TASKS and CONFIG_SCHED_DUMP_STACK 2026-06-09 08:04:54 -04:00
LICENSE libs/libdsp: Add Matrix operations 2026-07-11 14:55:59 -03:00
Makefile !boards: enforce secure ROMFS passwd and TEA key setup 2026-07-09 22:41:11 +08:00
NOTICE Remove the double blank line from source files 2022-02-20 20:10:14 +01:00
README.md ci/testing: Add MemBrowse Integration 2026-06-18 12:07:41 -03:00
ReleaseNotes Documentation: move ReleaseNotes 2023-09-26 20:41:00 +08:00

POSIX Badge License Issues Tracking Badge Contributors GitHub Build Badge Documentation Badge MemBrowse

Apache NuttX is a real-time operating system (RTOS) with an emphasis on standards compliance and small footprint. Scalable from 8-bit to 64-bit microcontroller environments, the primary governing standards in NuttX are POSIX and ANSI standards. Additional standard APIs from Unix and other common RTOSs (such as VxWorks) are adopted for functionality not available under these standards, or for functionality that is not appropriate for deeply-embedded environments (such as fork()).

For brevity, many parts of the documentation will refer to Apache NuttX as simply NuttX.

Getting Started

First time on NuttX? Read the Getting Started guide! If you don't have a board available, NuttX has its own simulator that you can run on terminal.

Documentation

You can find the current NuttX documentation on the Documentation Page.

Alternatively, you can build the documentation yourself by following the Documentation Build Instructions.

The old NuttX documentation is still available in the Apache wiki.

Supported Boards

NuttX supports a wide variety of platforms. See the full list on the Supported Platforms page.

Contributing

If you wish to contribute to the NuttX project, read the Contributing guidelines for information on Git usage, coding standard, workflow and the NuttX principles.

License

The code in this repository is under either the Apache 2 license, or a license compatible with the Apache 2 license. See the License Page for more information.