Commit graph zephyr/drivers
Author SHA1 Message Date
Sergei Ovchinnikov
2a3558986e drivers: otp: add OTP driver for nPM10 Series PMICs
Nordic's nPM10 Series PMICs feature one-time-programmable UICR to configure
some of the control registers' reset values changing PMIC's startup
behaviour.

Signed-off-by: Sergei Ovchinnikov <sergei.ovchinnikov@nordicsemi.no>
2026-09-26 08:40:43 +02:00
Etienne Carriere
a2838a7412 soc: st: stm32: Integrate STM32 PSA Crypto drivers for hash and AES
Define configuration symbols for enabling STM32 PSA Crypto Drivers.
CONFIG_USE_STM32_HAL_PSA_CRYPTO_DRIVERS is experimental, it is
disabled by default.

CONFIG_USE_STM32_HAL_PSA_CRYPTO_DRIVERS is a generic config switch
to embed or not STM32 PSA Crypto Drivers. Config switches are defined
per hardware resources in STM32 SoCs:
- CONFIG_USE_STM32_HAL_PSA_CRYPTO_DRIVERS_AES for STM32 AES
- CONFIG_USE_STM32_HAL_PSA_CRYPTO_DRIVERS_CRYP for STM32 CRYP
- CONFIG_USE_STM32_HAL_PSA_CRYPTO_DRIVERS_SAES for STM32 SAES
- CONFIG_USE_STM32_HAL_PSA_CRYPTO_DRIVERS_HASH for STM32 HASH

Enabling of one of those latter are conditioned to the presence
of a related enabled node in the DT and prevents the node is
integrated in the Zephyr native crypto framework.

STM32 RNG is out of scope since Zephyr integration of PSA Crypto
makes the PSA Crypto library to rely on the already existing STM32
entropy driver.

Update manifest to sync on the STM32 HAL module that provides
PSA Crypto drivers implementation for STM32 HASH and AES/CRYP/SAES
(transparent key).

Signed-off-by: Etienne Carriere <etienne.carriere@st.com>
2026-09-26 08:40:37 +02:00
David Jewsbury
92c0d6e55f mspi: dw: support the nRF MSPI elastic buffer
The elastic buffer is part of the GPIOHSPADCTRL and used by
the NRF-MSPI peripheral when in controller mode. It is used
to compensate for PVT variation on the pad and is only
supported on port 2 for MSPI00/01. It uses a feedback clock
which encounters a replica delay. This is then fed into the
EB where the core can sample it after some configured delay.

This commit ads support for this for the nrf-mspi peripheral,
configuring it when the user calls mspi_dev_config() as the
configuration of the EB will depend on the configuration of
the SPI mode. Currently, a polarity of 1 isn't supported but
this will be added at a later commit once documentation has
made it to the nrf7120 datasheet on how to use it properly.

Asserts are also added to check the DTS configuration as a
miss-configured elastic buffer can cause unexpected problems.

Signed-off-by: David Jewsbury <david.jewsbury@nordicsemi.no>
2026-09-26 08:40:25 +02:00
David Jewsbury
3e2210615b mspi: dw: add a vendor hook for device configuration
Allow for vendor specific device configuration. The hook is called at
the end of a successful device configuration and receives the same
parameter mask and configuration as the driver.

Signed-off-by: David Jewsbury <david.jewsbury@nordicsemi.no>
2026-09-26 08:40:25 +02:00
David Jewsbury
c7dc17c5d3 mspi: dw: add a devicetree property for the RX sample delay
Allow the user to set an initial RX sample delay in devicetee
as this is something that can be fixed once based on your
hardware.

Signed-off-by: David Jewsbury <david.jewsbury@nordicsemi.no>
2026-09-26 08:40:25 +02:00
David Jewsbury
e8159efa1a mspi: dw: write the RX sample delay when enabling XIP
RX sample delay may not be set if non-XIP transfer haven't
happened yet.

Signed-off-by: David Jewsbury <david.jewsbury@nordicsemi.no>
2026-09-26 08:40:25 +02:00
Zayne Stites
e695de10c5 drivers: i3c: dw: reject a CCC payload with length but no buffer
dw_i3c_do_ccc dereferences payload->ccc.data whenever ccc.data_len says
there is data - the broadcast path hands it to write_tx_fifo and the
direct path reads the defining byte out of it.  The direct path also
hands each targets.payloads[i].data to the command buffer.  None of
them check for NULL.

i3c_do_ccc is a syscall, and its handler only range-checks a buffer when
it's non-NULL, so a non-zero length with no buffer gets past
verification and faults the kernel.

Reject both on entry, before the mutex is taken.  i3c_stm32 and
i3c_renesas_ra already reject the ccc.data case this way.

Signed-off-by: Zayne Stites <Zayne.Stites@infineon.com>
Assisted-by: Claude:claude-opus-5
2026-09-26 08:39:54 +02:00
Marcin Niestroj
e7a6bc04ef drivers: serial: reclaim empty completed async RX buffers
The async RX helper returns immediately when no bytes are pending. This
leaves completed buffers with no received data outside the free pool. The
consumer cannot reclaim them by polling for data. If every buffer reaches
that state, the UART cannot obtain a buffer to restart reception.

Run the existing ordered reclaim loop before checking pending_bytes. This
keeps read-cursor updates in the consumer context. It adds no
interrupt-masked sections to producer callbacks. Preserve zero-length
claims as side-effect free.

Signed-off-by: Marcin Niestroj <m.niestroj@emb.dev>
2026-09-26 08:39:45 +02:00
Kazem Firouzmandi
f0f181ad8a drivers: display: uc81xx: add UC8253 grayscale support
Add optional four-level grayscale output for UC8253 controllers using
PIXEL_FORMAT_L_8. Convert luminance values into the controller's two
RAM planes and retain full-plane state so fragmented writes can be
combined before refreshing the panel.

Add devicetree properties for enabling grayscale, selecting the plane
mapping, and configuring CCSET and TSSET for individual profiles.

Tested on an nRF54L15 DK with a Good Display GDEY037T03 panel using
the display API and LVGL in monochrome and grayscale modes.

Signed-off-by: Kazem Firouzmandi <kazem.firouzmandi@gmail.com>
2026-09-26 08:39:40 +02:00
Julien Racki
db9633c835 drivers: flash: stm32: xspi: Set a default timeout in the init fast path
When CONFIG_STM32_APP_IN_EXT_FLASH and CONFIG_XIP are enabled, XSPI
initialization is skipped because the bootloader
has already configured it.
Therefore in this fast path HAL_XSPI_Init() is not called and the
timeout value stays at 0.

This PR fixes the fast path and initialize the timeout to
HAL_XSPI_TIMEOUT_DEFAULT_VALUE.

Signed-off-by: Julien Racki <julien.racki-ext@st.com>
2026-09-26 01:13:36 +02:00
Remi Buisson
404c91bd1d drivers: sensor: icm566xx: Fix icm56686 high fsr
Only high fsr is supported by icm56686 driver.

Signed-off-by: Remi Buisson <remi.buisson@tdk.com>
2026-09-26 01:05:31 +02:00
Ibrahim Abdalkader
73e96d5b44 drivers: video: stm32_dcmi: enable the DMA FIFO when the DT asks for it
The FIFO threshold in the dmas features cell, documented in the binding,
is ignored by dma_stm32_zcfg_to_halcfg() which always selects direct
mode.

Direct mode writes every word to memory as it arrives, which is too slow
for destinations such as external SDRAM. The DCMI overruns and capture
never completes.

Enable the FIFO when the DT asks for a full threshold. This driver
transfers words, and full is the only threshold the hardware accepts at
that size, so boards asking for 1/4, 1/2 or 3/4 cannot use the FIFO at
all and keep direct mode as before.

Signed-off-by: Ibrahim Abdalkader <i.abdalkader@gmail.com>
2026-09-26 01:05:12 +02:00
Ibrahim Abdalkader
d802b66e34 drivers: disk: sdmmc_stm32: set the burst length through DMA config
The HAL config helper now maps source_burst_length and dest_burst_length,
so ask for the 4 beat bursts instead of writing MemBurst and PeriphBurst
after the call.

Signed-off-by: Ibrahim Abdalkader <i.abdalkader@gmail.com>
2026-09-26 01:05:12 +02:00
Ibrahim Abdalkader
c899e2c305 drivers: video: stm32_dcmi: request the memory burst through the DMA config
Ask for a 4 beat burst on the memory side with dest_burst_length instead
of leaving it equal to the data size.

Note this has no effect on its own, the burst bits are only written to
the stream when the FIFO is enabled, which it is not yet on any board.

Signed-off-by: Ibrahim Abdalkader <i.abdalkader@gmail.com>
2026-09-26 01:05:12 +02:00
Ibrahim Abdalkader
e93e7cf1f8 drivers: dma: stm32: map burst length in the DMA config helper
dma_stm32_zcfg_to_halcfg() hardcoded MemBurst and PeriphBurst to single
transfers and ignored source_burst_length and dest_burst_length, so a
driver asking for a burst through the DMA API silently got none and had
to write the HAL fields itself after the call. Derive both from the
burst length and the data size instead.

Signed-off-by: Ibrahim Abdalkader <i.abdalkader@gmail.com>
2026-09-26 01:05:12 +02:00
Johan Hedberg
e3f93c99f1 Bluetooth: HCI: cyw208xx: Free the RX buffer of a packet that does not fit
A received packet longer than the buffer allocated for it was logged
and dropped, but the buffer was never freed, so every such packet cost
the pool one buffer for good.

Build-tested with the peripheral_hr sample on
cyw920829m2evk_02/cyw20829b0lkml. Not run on hardware.

Assisted-by: Claude:claude-fable-5-1
Signed-off-by: Johan Hedberg <johan.hedberg@silabs.com>
2026-09-26 01:04:35 +02:00
Johan Hedberg
0fec868057 Bluetooth: HCI: cyw208xx: Do not send the asset's commands via the Host
wiced_bt_dev_vendor_specific_command() exists for the btstack-integration
asset to link, and sent the asset's vendor commands with the Host's
bt_hci_cmd_alloc() and bt_hci_cmd_send(), ignoring the completion
callback. Neither of the asset's callers is reached: the driver's
wiced_bt_stack_init_internal() drops the post stack initialization
callback that would enable the sleep mode, which
cyw208xx_bt_enable_low_power_mode() does instead, and the only caller of
cybt_prm_download(), cybt_patchram_download.c, is not part of the build.

Report the command as unsupported instead. This was the driver's last
use of a Host API, so a build without a Host, such as the hci_uart
sample, now links.

Build-tested with the peripheral_hr and hci_uart samples on
cyw920829m2evk_02/cyw20829b0lkml, the latter with an overlay choosing
the UART. Not run on hardware.

Assisted-by: Claude:claude-fable-5-1
Signed-off-by: Johan Hedberg <johan.hedberg@silabs.com>
2026-09-26 01:04:35 +02:00
Johan Hedberg
2b59014b3d Bluetooth: HCI: cyw208xx: Configure the controller from open()
Reset the controller, download its firmware, set the public address and
enable the low power mode from within open(), through the HCI lockstep
helper and the driver's own send path, instead of implementing the
setup() driver API op on top of the Host's bt_hci_cmd_send_sync(). The
public address comes from bt_hci_get_public_addr(), which gives
BT_ADDR_ANY when none has been set, so the controller's hard-coded
default address is still always overridden. The responses are consumed
in the driver's receive path by feeding received packets to the helper
before they are delivered.

The platform task resets the controller every time it is started, so
open() restores the helper's initial command allowance with
bt_hci_lockstep_reset() before it sends the first command: the reset
controller allows one command again without announcing it.

The firmware blocks are sent from a static command buffer sized for the
longest HCI command, to keep it off the stack of the thread that opens
the driver; the caller serializes open().

A failing or unanswered command fails open() with an error instead of
failing the Host's HCI initialization later, and is logged by the
helper. open() then shuts the platform task down again, as close()
does, since a failed open() is not followed by close(), and a platform
task that fails to start makes open() return -EIO instead of the
asset's positive result code. open() moves below close() for that.

The raw send path is factored out of send() so that it serves both the
send() op and the helper. It takes the packet with its packet indicator
instead of pulling the indicator off the buffer, so a buffer that could
not be sent is returned to the caller unmodified.

The driver no longer selects BT_HCI_SETUP. BT_AIROC still selects it
for every AIROC part, because the H4 extension of the UART-attached
ones implements the setup hook, and the Host treats a missing setup()
op as nothing to do.

Build-tested with the peripheral_hr sample on
cyw920829m2evk_02/cyw20829b0lkml. Not run on hardware.

Assisted-by: Claude:claude-opus-5-5
Signed-off-by: Johan Hedberg <johan.hedberg@silabs.com>
2026-09-26 01:04:35 +02:00
Johan Hedberg
02f556780e Bluetooth: HCI: nxp: Configure the controller from open()
Send the vendor-specific initialization commands, the calibration data,
the sleep configuration and the public address, from within open(),
through the HCI lockstep helper and the driver's own send path, instead
of implementing the setup() driver API op on top of the Host's
bt_hci_cmd_send_sync(). The public address comes from
bt_hci_get_public_addr(). The responses are consumed in the driver's
receive path by feeding received packets to the helper before they are
delivered.

Without a Host the helper function for these commands returned success
without sending anything, and setup() was not called there in the first
place, bt_enable_raw() opening the driver only, so a controller-only
build left the controller without its calibration data, sleep
configuration and address. They are now sent in every build, and the
driver no longer selects BT_HCI_SETUP.

A failing or unanswered command, or a failed HCI start, fails open()
with an error instead of failing the Host's HCI initialization later,
and open() then unregisters the receive callback again, as close()
does, since a failed open() is not followed by close(). open() moves
below close() for that. The helper's command allowance is restored at
every open() and after the controller's own reset that follows the
annex 55 calibration data, as neither reset announces one. The stale
comment claiming the address command gets no Command Complete goes: it
already went through bt_hci_cmd_send_sync(), which waits for one.

The raw send path is factored out of send() so that it serves both the
send() op, which keeps intercepting the vendor commands it handles
locally, and the helper.

Build-tested with the peripheral_hr sample on frdm_mcxw71 (public
address) and frdm_rw612 (calibration data and automatic sleep). Not run
on hardware.

Assisted-by: Claude:claude-fable-5-1
Signed-off-by: Johan Hedberg <johan.hedberg@silabs.com>
2026-09-26 01:04:21 +02:00
Johan Hedberg
c4359e581e Bluetooth: HCI: spi_st: Configure the BlueNRG controller from open()
Send the BlueNRG ACI configuration commands, the link-layer-only mode
and the public address, from within open(), through the HCI lockstep
helper and the driver's own SPI send path, instead of implementing the
setup() driver API op on top of the Host's bt_hci_cmd_send_sync(). The
public address comes from bt_hci_get_public_addr(). The responses are
consumed in the driver's receive thread by feeding received packets to
the helper before they are delivered.

That also replaces the second way the driver had of sending the
link-layer-only command: in a controller-only build it called the raw
bt_send() from inside its own open(), before the transport was open to
its user, and left the response to reach the application. Both build
types now share one path, and the driver no longer selects
BT_HCI_SETUP.

A failing or unanswered command fails open() with an error instead of
failing the Host's HCI initialization later, and is logged by the
helper. open() stops the receive thread, aborting it if it does not
exit, and resets the controller when it fails after having started
them, which also covers the existing boot timeout, since a failed
open() is not followed by close(). open() moves below close() for that,
without other changes.

The raw send path is factored out of send() and takes the device, so
that it serves both the send() op and the helper.

Build-tested on disco_l475_iot1 (st,hci-spi-v1) with the peripheral_hr
and hci_uart samples, and on nucleo_l476rg with the x_nucleo_bnrg2a1
shield (st,hci-spi-v2) with peripheral_hr. Not run on hardware.

open() takes the controller out of reset through its reset line on
every call, so it also restores the helper's initial command allowance
with bt_hci_lockstep_reset(): the controller allows one command again
without announcing it.

Assisted-by: Claude:claude-fable-5-1
Signed-off-by: Johan Hedberg <johan.hedberg@silabs.com>
2026-09-26 01:04:02 +02:00
Johan Hedberg
fbc4a69439 Bluetooth: HCI: stm32wba: Set the public address from open()
Write the public address into the controller from within open(), taking
it from bt_hci_get_public_addr(), instead of implementing the setup()
driver API op. The command goes through BleStack_Request() as before,
so no Host command API was involved and nothing else changes in how it
is sent.

The address is now also set in controller-only builds, where the driver
did not select BT_HCI_SETUP and bt_enable_raw() would not have called
setup() anyway: with no public address to set, which is always the case
there, it is the one derived from the device UID, as before. The driver
no longer selects BT_HCI_SETUP.

A failure to set the address fails open() instead of the Host's HCI
initialization later. open() then closes what it had opened, since a
failed open() is not followed by close(). open() moves below close()
and the address functions for that, without other changes.

Build-tested on nucleo_wba55cg with the peripheral_hr and hci_uart
samples. Not run on hardware.

Assisted-by: Claude:claude-fable-5-1
Signed-off-by: Johan Hedberg <johan.hedberg@silabs.com>
2026-09-26 01:03:45 +02:00
Hsiu-Chi Tsai
42fe88386f drivers: sensor: adi: ad2s1210: reject a partial resolution-gpios
resolution-gpios is read as two lines, RES0 and RES1, through
GPIO_DT_SPEC_INST_GET_BY_IDX_OR() with an empty fallback, while
have_resolution_pins only checks that the property exists. A node with
one entry, or with one of the two set to <0>, builds and then fails at
init with -ENODEV because that spec has no port.

Make both a build error. Omitting the property stays valid, the binding
says the pins may be hard-wired.

Signed-off-by: Hsiu-Chi Tsai <hctsai@linux.com>
2026-09-26 01:03:28 +02:00
Benjamin Cabé
dbe5e34495 cmake: emu: qemu: use -nic for on-board ethernet NICs
QEMU rejects -device for NICs built into the emulated machine (lan9118,
stellaris, cadence_gem), so QEMU failed to start on those boards with
networking enabled. Let these drivers select ETH_NIC_MODEL_ONBOARD and
configure such NICs with -nic instead.

Assisted-by: Claude:opus-5.5
Signed-off-by: Benjamin Cabé <benjamin@zephyrproject.org>
2026-09-26 00:59:45 +02:00
Alain Volmat
44952d6a3b gpio: mfxstm32l152: set I2C_INIT_PRIORITY for init priority
The MFXSTM32L152 dependency is the availability of the i2c so
set its init priority to I2C_INIT_PRIORITY instead of having
an hardcoded value as before.

Signed-off-by: Alain Volmat <alain.volmat@foss.st.com>
2026-09-26 00:57:28 +02:00
Benjamin Cabé
ca3537b553 drivers: display: qemu_ramfb: Map the framebuffer Normal-NC on ARM
K_MEM_CACHE_NONE is Device memory on ARM and ARM64, which faults on the
unaligned stores that the row memcpy() in display_fb_write() makes whenever
an update area is not 4-pixel aligned, so map the framebuffer Normal
non-cacheable there instead.

It is also much faster: on qemu_cortex_a53, 20 full-screen display_write()
calls at 600x400 ARGB8888 drop from ~770 us to ~180 us per frame.

Signed-off-by: Benjamin Cabé <benjamin@zephyrproject.org>
Assisted-by: Claude:opus-5.5
2026-09-26 00:57:14 +02:00
Vignesh Pandian
807c496f8c drivers: gpio: infineon: use standard init priority
Update the Infineon GPIO driver to use the standard
CONFIG_GPIO_INIT_PRIORITY instead of the generic
CONFIG_KERNEL_INIT_PRIORITY_DEVICE. This ensures the GPIO driver
initializes before peripherals that depend on it.

Signed-off-by: Vignesh Pandian <vignesh@aerlync.com>
2026-09-26 00:56:11 +02:00
Benjamin Cabé
1263266b61 drivers: lora: gate the native backend on the radios it drives
The native backend only has drivers for SX1261/SX1262, the STM32WL
sub-GHz radio and LR1121, but unlike the LoRa Basics Modem entry its
choice entry has no dependency on them, so selecting it on a board with
another radio builds with no driver at all. Depend on those radios.

Signed-off-by: Benjamin Cabé <benjamin@zephyrproject.org>
Assisted-by: Claude:opus-5.5
2026-09-26 00:53:54 +02:00
Raffael Rostagno
eaabae5145 drivers: ieee802154: esp32: PM support
Add PM support for IEEE 802.15.4 by taking a PM lock on the sensitive
radio paths: transmit, CCA and energy scan. Add a work task to release
the lock once the radio reports sleep, as the MAC interrupt only puts
the radio to sleep after the completion callbacks return, so the state
is not final in ISR context.

Disable the IEEE802154_RX_ON_WHEN_IDLE capability when the light sleep
option is enabled. This is pending future review and is necessary to
avoid radio switching while attaching.

Assisted-by: Grok:4.6
Signed-off-by: Raffael Rostagno <raffael.rostagno@espressif.com>
2026-09-26 00:53:44 +02:00
Flavio Ceolin
bd936c30d8 drivers: sensor: grow_r502a: drop stale RX buffer on timeout
transceive_packet() left the RX interrupt enabled after a receive
timeout, so late bytes were written through rx_buf.data into the stack
frame of the function that had already returned.

Signed-off-by: Flavio Ceolin <flavio@hubble.com>
2026-09-26 00:52:17 +02:00
Flavio Ceolin
96968fac22 drivers: sensor: grow_r502a: bound RX packet length
The packet length from the sensor header was passed to uart_fifo_read()
without checking it against the receive buffer, letting a declared body
larger than the buffer overflow the caller's stack packet.

Signed-off-by: Flavio Ceolin <flavio@hubble.com>
2026-09-26 00:52:17 +02:00
Lucien Zhao
89989182c7 drivers: pinctrl: imx: support the RT266x combined PIO register
RT266x uses a single combined IOMUXC PIO register per pad, with the
mux-mode and pad configuration in the same register. Add an
SOC_SERIES_IMXRT266X path that combines both into one write so the pad
config does not clobber the mux-mode, and translates the driver-private
input-enable flag to the hardware IBENA bit.

Signed-off-by: Lucien Zhao <lucien.zhao@nxp.com>
2026-09-26 00:51:55 +02:00
Lucien Zhao
d89c0fc6e3 drivers: gpio: add nxp,imx-gpio-v2 driver for RT266x
Add a GPIO driver for the NXP i.MX GPIO controller used on RT266x, with
the new compatible nxp,imx-gpio-v2.

The driver (gpio_mcux_gpio.c) handles:

  - Combined IOMUXC PIO pad register, where mux selector and pad
    attributes (pull enable/select, input buffer, open-drain) share one
    read-modify-write register.  The driver sets the attribute bits and
    delegates the mux write to pinctrl_configure_pins().
  - Optional LPCG clock gate at init.  Instances without a gate (always-
    on power domains) simply omit the clocks property.
  - Per-pin TrustZone access control via PCNS, granting non-secure access
    before configuring each pin.
  - Dual-channel interrupt routing: GICLR/GICHR direct each pin's
    interrupt to one of the two NVIC lines, selected by irq-output-select.

The binding nxp,imx-gpio-v2 follows the same property set as other NXP
IOMUXC-based GPIO bindings: pinmux phandle list, optional clocks, and
irq-output-select.

Signed-off-by: Lucien Zhao <lucien.zhao@nxp.com>
2026-09-26 00:51:55 +02:00
Lucien Zhao
c0cf760527 drivers: serial: mcux_lpuart: configure an owned clock root
Let an LPUART instance describe its own clock source. When the node names
a "source" clocks entry, apply it with clock_control_configure() before
the peripheral clock is ungated, so the root's mux and dividers come from
devicetree rather than from a board C file. The cells are opaque here and
are interpreted by the clock controller.

Fetch that entry by name rather than by index. The families sharing this
driver spell their other clocks entries differently, and most of their
nodes carry no clock-names at all, so a node that already names its
entries can append "source" without disturbing them while the gate entry
stays at index 0 for every node that names nothing.

An instance that names no "source" entry behaves as before.

Signed-off-by: Lucien Zhao <lucien.zhao@nxp.com>
2026-09-26 00:51:55 +02:00
Lucien Zhao
ea59c4c03c drivers: clock_control: add the nxp,imx-ccm-rev3 controller
Add a clock controller for the i.MX CGU rev3 hardware. It programs each
clock root's mux and dividers from devicetree at init and reports rates
through the clock-control API.

One device is instantiated per nxp,imx-ccm-rev3 node, with the root list
built from that node's own children, so an SoC whose CCM is a single
block and one that splits it per subsystem take the same code path. A
root's HAL identifier comes from its nxp,root-id property rather than
being derived from its reg, so no per-SoC numbering rule lives here.

A root marked nxp,preconfigured is skipped in the init loop: the SoC
bring-up programs it earlier in boot, so re-programming it here would
duplicate that work and, for a root feeding the running CPU or a live
bus, re-write a clock the core is running from.

Signed-off-by: Lucien Zhao <lucien.zhao@nxp.com>
2026-09-26 00:51:55 +02:00
Aary Patil
f370f61e67 drivers: pinctrl: mediatek: add MT8188 pin controller
Add the pin controller for the MT8188, with the full pin table and the
devicetree macros that turn a pinmux property into a pin and function pair.

The register window is mapped with device_map() at PRE_KERNEL_1 priority 0
rather than reached through its physical address.  There is no struct
device to hang DEVICE_MMIO off, because pinctrl_configure_pins() is called
from other drivers' init before any pin controller device would exist, but
the window still has to be mapped rather than assumed; a static
mmu_regions.c entry would do the same job less portably and only on arm64.

The cluster directory goes on the include path here because the pinctrl
framework includes pinctrl_soc.h, which this commit adds.

Co-authored-by: Felix Freimann <felix.freimann@mediatek.com>
Signed-off-by: Aary Patil <aary.patil@mediatek.com>
2026-09-26 00:51:04 +02:00
Aary Patil
a1e1918c45 drivers: serial: mediatek: add MT8188 UART driver
Add the UART driver for MediaTek MT8188, giving the Genio boards a
console.  Register access is split into a shared core and a small
per-SoC instantiation layer, so other MediaTek SoCs can reuse the core.

The driver is instantiated for every enabled node rather than a fixed
instance, and takes its gate clock from the infra-ao controller.

Co-authored-by: Felix Freimann <felix.freimann@mediatek.com>
Signed-off-by: Aary Patil <aary.patil@mediatek.com>
2026-09-26 00:51:04 +02:00
Aary Patil
159d13b211 drivers: clock_control: mediatek: add MT8188 infra-ao clocks
Add the gate clock controller for the MT8188 infra always-on subsystem,
which the UARTs and the other infra peripherals depend on.

Register access is split into a shared core and a per-controller gate
table, so further MediaTek clock controllers can reuse the core.

A BUILD_ASSERT ties the gate table to CLK_INFRA_AO_NR_CLK.  The table is
indexed by the CLK_INFRA_AO_* identifiers, so a mismatch between the two
would otherwise silently operate the wrong gate.

Co-authored-by: Felix Freimann <felix.freimann@mediatek.com>
Co-authored-by: Andrew Perepech <andrew.perepech@mediatek.com>
Signed-off-by: Aary Patil <aary.patil@mediatek.com>
2026-09-26 00:51:04 +02:00
Aary Patil
c94ae0579f drivers: mediatek: key the audio DSP drivers off devicetree
Both drivers depended on the SoC family symbol, which now also covers
the Arm cpuclusters on the same dies, so they were offered where the
hardware they drive does not exist.

Both are already devicetree driven: the interrupt controller iterates
mediatek,adsp_intc instances, and the timer reads its registers and its
interrupt out of the ostimer nodes.  Depend on the nodes instead, which
is what the Kconfig style guide asks for and what leaves the drivers
independent of how the SoC tree is arranged.

The timer names the 64-bit node because that is the one with a binding;
both ostimer nodes are present on every audio DSP board.

Signed-off-by: Aary Patil <aary.patil@mediatek.com>
2026-09-26 00:51:04 +02:00
Aary Patil
3f180298ee soc: mediatek: declare the SoC family the way the model expects
soc.yml names this family mt8xxx, so the hardware model v2 symbol for it is
SOC_FAMILY_MT8XXX.  The tree used SOC_FAMILY_MTK, which names no family
present in soc.yml, and never set the SOC_FAMILY string at all.

Rename the symbol and add the missing default.  No functional change: the
only references are inside soc/mediatek and the two audio DSP driver
Kconfig files.

Signed-off-by: Aary Patil <aary.patil@mediatek.com>
2026-09-26 00:51:04 +02:00
Kapil Bhatt
545fb948fe drivers: wifi: nrf_wifi: Fix vif_lock init and unlock paths
vif_lock was initialised in nrf_wifi_if_start_zep() while that same
function held it. k_mutex_init() clears the owner and lock count and
re-initialises the wait queue, so the lock was silently dropped
mid-function and any thread pending on it was left unwakeable. It was
also the only initialiser, so the first lock on boot ran on a mutex
that had never been set up. Initialise it once in
nrf_wifi_if_init_zep(), which runs from net_if_init() before any
net_if_up().

Fix three wrong goto targets while at it. nrf_wifi_if_start_zep()
unlocked from checks that run before the lock is taken, and
nrf_wifi_if_stop_zep() did the same when k_mutex_lock() failed; the
promiscuous-mode branches of nrf_wifi_if_set_config_zep() skipped the
unlock entirely.

Signed-off-by: Kapil Bhatt <kapil.bhatt@nordicsemi.no>
Assisted-by: Cursor:Opus-5
2026-09-26 00:46:13 +02:00
Kapil Bhatt
cb6a7b8800 drivers: wifi: nrf_wifi: Guard set_if_callbk_fn as the module declares it
The callback was assigned under CONFIG_NRF70_SYSTEM_MODE while the
nrf_wifi module both declares and dispatches it under NRF70_STA_MODE ||
NRF70_RAW_DATA_RX.

Signed-off-by: Kapil Bhatt <kapil.bhatt@nordicsemi.no>
2026-09-26 00:46:13 +02:00
Kapil Bhatt
99ea67e2ec drivers: wifi: nrf_wifi: Fix raw TX with controlled-port dormant logic
A station went operational on carrier ON, which is at association, so
the IP stack transmitted during the 4-way handshake and the TX path had
to drop those frames. Wait for the controlled port instead; EAPOL is
unaffected as it flows out-of-band through nrf_wifi_wpa_tx_control_port().

Injection has neither an association nor a controlled port, so keep the
interface operational for it, gated on the carrier to match the
CARR_STATE_ON check in nrf_wifi_if_send(). Read txinjection_mode from
the FMAC VIF context, since a driver-side copy would go stale across
down/up and MODE_SET_DONE.

Move the decision into nrf_wifi_iface_operational() and let callers just
request a re-evaluation. Start and stop clear the per-session state,
because net_if_up() and net_if_down() leave the dormant flag as they
found it.

Take vif_lock for the oper-state decision. The handler reads
txinjection_mode through rpu_ctx, and nrf_wifi_fmac_dev_rem_zep() frees
that context before clearing the pointer, so a handler in flight could
dereference freed memory. nrf_wifi_if_stop_zep() frees under vif_lock,
so holding it for the read serialises the two.

Signed-off-by: Kapil Bhatt <kapil.bhatt@nordicsemi.no>
Assisted-by: Cursor:Opus-5
2026-09-26 00:46:13 +02:00
Jordan Yates
dff077f83f modem: cellular: ignore non-periodic script results
In `AWAIT_REGISTERED` and `REGISTERED`, ignore script results from
non-periodic scripts. These can be triggered through functions like
`modem_cellular_get_signal`.

This prevents the periodic script timing being influenced by unrelated
API calls and `MODEM_COMMS_CHECK_RESULT` events being output for
non-periodic script runs.

Signed-off-by: Jordan Yates <jordan@embeint.com>
2026-09-26 00:46:00 +02:00
Jordan Yates
10b1e675ca modem: cellular: optional pointer associated with events
Transition the event pipe to a `msgq`, adding an optional pointer to
the event metadata. The pointer is then available in the event handlers
as `data->event_ptr`. Use this in `modem_cellular_chat_callback_handler`
so that script result handling can know which script it was that
succeeded or failed.

Signed-off-by: Jordan Yates <jordan@embeint.com>
2026-09-26 00:46:00 +02:00
Jordan Yates
1f393fc6f8 modem: cellular: warn on dropped events
Output a warning if a modem event is dropped by the delegator.

Signed-off-by: Jordan Yates <jordan@embeint.com>
2026-09-26 00:46:00 +02:00
Richard Mc Sweeney
d9a6241ce3 drivers: serial: Infineon UART TX done interrupt
Added a TX done interrupt check so that device SUSPEND has the
opportunity to run again once the UART has completed its
transmission. Otherwise the scheduler does not run pm_state_set
again, and the app would stay in runtime-idle mode.

Assisted-by: Claude:claude-opus-4.8
Signed-off-by: Richard Mc Sweeney <Richard.McSweeney@infineon.com>
2026-09-26 00:45:32 +02:00
Richard Mc Sweeney
69229e1a26 drivers: serial: add Infineon UART pm_action
Added pm_action suspend/resume/turn_on routine for UART

Assisted-by: Claude:claude-opus-4.8
Signed-off-by: Richard Mc Sweeney <Richard.McSweeney@infineon.com>
2026-09-26 00:45:32 +02:00
Richard Mc Sweeney
13c06b315f drivers: serial: end Infineon DMA consistently
dma_tx.buf_len doubles as the transfer-in-progress flag that uart_tx()
tests to reject an overlapping transfer, but it was only cleared on the
successful DMA completion. An abort, a TX timeout or a DMA error left it
set, so every later uart_tx() returned -EBUSY for good. Clear it on each
path that ends a transfer.

dma_rx.buf_len has the same role and the same gap: rx_enable() left it
set when the DMA configuration failed, and the mid-stream rearm in the
RX callback discarded its return value, leaving RX dead with the runtime
PM reference still held and no event delivered to the application.
Release both buffers and end the session on those paths as well.

Assisted-by: Claude:claude-opus-4.8
Signed-off-by: Richard Mc Sweeney <Richard.McSweeney@infineon.com>
2026-09-26 00:45:32 +02:00
Richard Mc Sweeney
9fdf332c02 drivers: serial: reject overlapping Infineon UART async TX
ifx_cat1_uart_async_tx() overwrote the transfer descriptor and
reconfigured the DMA channel even when a previous transfer was still
in flight, corrupting the running transfer. Return -EBUSY while
buf_len is non-zero so a second uart_tx() is rejected while a transfer
is ongoing, as the UART async API requires.

Assisted-by: Claude:claude-opus-4.8
Signed-off-by: Richard Mc Sweeney <Richard.McSweeney@infineon.com>
2026-09-26 00:45:32 +02:00
Richard Mc Sweeney
992af4d355 drivers: serial: reprogram Infineon UART divider on baud change
ifx_cat1_uart_set_baud() reprogrammed the peripheral clock divider
while it was still enabled, so a new baud rate could be applied to a
running divider. Disable the divider, set the new value, then
re-enable it; a failed set leaves the register unchanged, so the
re-enable restores the previous rate.

Assisted-by: Claude:claude-opus-4.8
Signed-off-by: Richard Mc Sweeney <Richard.McSweeney@infineon.com>
2026-09-26 00:45:32 +02:00