Apache NuttX is a mature, real-time embedded operating system (RTOS) https://nuttx.apache.org/
Find a file
Marco Casaroli f8c0bc77fb arch/risc-v: Recover from a user fault without a kernel stack.
In CONFIG_BUILD_PROTECTED, a user task that touches memory it does not
own must be terminated on its own.  The rest of the system must keep
running.  riscv_fault_handler() already does this: it checks for a fault
taken from U-mode, sets TCB_FLAG_FORCED_CANCEL and changes the exception
return to _exit(SIGSEGV) in privileged mode.  But the whole block was
inside #ifdef CONFIG_ARCH_KERNEL_STACK.  Configurations that do not
select that symbol, such as rv-virt:pnsh and rv-virt:pnsh64, fell
through to PANIC_WITH_REGS().  A contained user-space bug stopped the
whole system.

Only the last line of the block needs a kernel stack:

    running_regs()[REG_SP] = tcb->xcp.ktopstk;

because xcp.ktopstk exists only with one.  Narrow the guard to that
assignment, so the rest compiles in all configurations.  arm64 already
does the same in arm64_fatal_handler().

It is correct to leave REG_SP unchanged.  In riscv_exception_common.S
the switch to the kernel stack at exception entry is also inside
#ifdef CONFIG_ARCH_KERNEL_STACK.  Without a kernel stack, the exception
frame goes on the user stack and REG_SP holds the user SP.
dispatch_syscall() already runs on that stack, so the kernel runs all
system calls of this task there, exit() included.  Running _exit on it
after a fault is the same case and adds no new exposure.  The stack also
stays mapped until the scheduler switches away, because a build without
a kernel stack cannot select CONFIG_ARCH_ADDRENV
(riscv_exception_common.S has an #error for that combination).

No behaviour change in other builds.  The recovery runs only when the
saved STATUS_PPP is clear, that is, when the fault came from U-mode.  In
CONFIG_BUILD_FLAT, tasks run at kernel privilege (M-mode, or S-mode on
the nsbi configurations), so STATUS_PPP is set and the panic path stays
the same.  CONFIG_BUILD_KERNEL configurations select ARCH_KERNEL_STACK
through ARCH_ADDRENV, so their code does not change.

Tested on QEMU with examples/sandbox and ostest.  On rv-virt:pnsh and
rv-virt:pnsh64 a forbidden read or write of kernel memory now kills
only the offending task, with status 2816 (SIGSEGV).  The shell and an
unrelated thread keep running.  Before this change the same access
caused a PANIC.  ostest exits with status 0 on both, before and after
this change.  rv-virt:knsh still builds, and its riscv_exception.o
differs only in the __LINE__ value of the PANIC call.

Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
2026-10-08 15:50:39 -03:00
.github build(deps): bump docker/setup-buildx-action from 4.3.0 to 4.4.1 2026-09-21 16:28:50 +08:00
arch arch/risc-v: Recover from a user fault without a kernel stack. 2026-10-08 15:50:39 -03:00
audio audio: limit the buffer count guard to shared ring requests 2026-08-05 07:58:53 +02:00
binfmt binfmt: Update the TLS pid when exec() swaps the pids. 2026-10-07 21:55:25 +08:00
boards arch/arm/rtl8730e: add I2C master driver support 2026-10-08 15:49:34 -03:00
cmake cmake/nuttx_add_romfs.cmake: Improved process_all_directory_romfs function 2026-10-05 18:42:56 +08:00
crypto crypto: fix chacha constants under GCC 15. 2026-09-20 08:22:11 -03:00
Documentation Documentation: Describe the per-object wait lists of the scheduler. 2026-10-08 15:50:03 -03:00
drivers drivers/net/telnet: Send a bare carriage return as CR NUL. 2026-10-08 13:29:50 +08:00
dummy
fs fs/inode: Name the inode tree lock in the comments, not g_inode_sem. 2026-10-08 15:50:03 -03:00
graphics graphics/nxterm: consume SGR escape sequences 2026-08-23 10:46:02 +08:00
include arch/mips/pic32mz: add PHY ioctls and link interrupts to the Ethernet driver. 2026-10-08 09:53:45 -03:00
libs libs/libc: Generate the system symbol tables in the CMake build. 2026-10-08 14:24:56 -03:00
mm mm/iob: fix CONFIG_NET_TIMESTAMPING typo in iob_alloc 2026-09-19 16:36:47 -03:00
net net/netdev: add NETDEV_TX_STAMP and handle SIOCETHTOOL ETHTOOL_GET_TS_INFO 2026-09-28 12:53:24 -03:00
openamp cmake: Use NUTTX(_DIR/_BIN_DIR) instead CMAKE(_SRC_DIR/_BIN_DIR) 2026-08-09 11:13:08 -03:00
pass1 tools: fix stale archive members surviving a Kconfig-driven CSRCS change 2026-07-28 21:26:03 -03:00
sched sched: Remove the names of task lists that no longer exist from comments. 2026-10-08 15:50:03 -03:00
syscall fs: add chroot() syscall 2026-09-20 22:27:38 +08:00
tools tools/nxflat: Leave ARM unwind tables out of an NXFLAT module. 2026-09-28 16:45:09 -03:00
video video/videomode: Fix EDID parsing and formatting of video mode dumps 2026-08-29 11:09:11 -03:00
wireless wireless/bluetooth: Validate Number Of Completed Packets event. 2026-09-25 10:35:51 +02:00
.asf.yaml github: master branch protection tune. 2025-05-07 18:37:13 -05:00
.codespell-ignore-lines arch/arm/ra8m1: Add GPT timer support 2026-10-01 23:12:10 +08:00
.codespellrc zbus: Add linker support and documentation for the zbus port 2026-09-21 08:40:14 -03:00
.editorconfig .editorconfig: fix character encoding property specification 2025-11-28 19:12:13 +08:00
.gitignore boards/risc-v/eic7700x: Adopt the common board layout. 2026-08-19 01:40:57 +08:00
.gitmessage docs/contributing: Add a commit message template 2025-06-03 17:33:24 +08:00
.mcp.json arch/risc-v/eic7700x: Describe and configure the pads. 2026-09-28 16:19:01 +08:00
.pre-commit-config.yaml
.yamllint
AUTHORS AUTHORS: add Jorge Guzman 2026-08-25 08:43:13 -04:00
CMakeLists.txt cmake: reconfigure when .config changes 2026-09-14 18:40:45 -03:00
CONTRIBUTING.md contributing: Add requirement for 'Assisted-by' commit field 2026-07-12 09:42:28 +08:00
INVIOLABLES.md
Kconfig arm/nrf54l: add Bluetooth SoftDevice Controller support 2026-10-02 15:37:12 -03:00
LICENSE libs/libdsp: Add Matrix operations 2026-07-11 14:55:59 -03:00
Makefile !boards: enforce secure ROMFS passwd and TEA key setup 2026-07-09 22:41:11 +08:00
NOTICE
README.md ci/testing: Add MemBrowse Integration 2026-06-18 12:07:41 -03:00
ReleaseNotes

POSIX Badge License Issues Tracking Badge Contributors GitHub Build Badge Documentation Badge MemBrowse

Apache NuttX is a real-time operating system (RTOS) with an emphasis on standards compliance and small footprint. Scalable from 8-bit to 64-bit microcontroller environments, the primary governing standards in NuttX are POSIX and ANSI standards. Additional standard APIs from Unix and other common RTOSs (such as VxWorks) are adopted for functionality not available under these standards, or for functionality that is not appropriate for deeply-embedded environments (such as fork()).

For brevity, many parts of the documentation will refer to Apache NuttX as simply NuttX.

Getting Started

First time on NuttX? Read the Getting Started guide! If you don't have a board available, NuttX has its own simulator that you can run on terminal.

Documentation

You can find the current NuttX documentation on the Documentation Page.

Alternatively, you can build the documentation yourself by following the Documentation Build Instructions.

The old NuttX documentation is still available in the Apache wiki.

Supported Boards

NuttX supports a wide variety of platforms. See the full list on the Supported Platforms page.

Contributing

If you wish to contribute to the NuttX project, read the Contributing guidelines for information on Git usage, coding standard, workflow and the NuttX principles.

License

The code in this repository is under either the Apache 2 license, or a license compatible with the Apache 2 license. See the License Page for more information.