adxl345_reg_write_mask() OR'd the data argument into the register
without confining it to mask, so callers passing a complemented value
(the INT_MAP routing idiom in adxl345_trigger.c and adxl345_stream.c)
set every bit outside the mask, clobbering unrelated interrupt routing.
AND data with mask before OR'ing it in.
Signed-off-by: Benjamin Cabé <benjamin@zephyrproject.org>
Assisted-by: Claude:fable-5
The streaming callback clamped the read length to the space actually
available in the RTIO buffer but still queued one 6-byte read per
hardware FIFO entry, writing past the end of a truncated allocation.
Bound the loop (and the completion-callback attachment) by the clamped
length, and reset fifo_total_bytes at batch start so an aborted chain
cannot leave a stale write offset behind.
Signed-off-by: Benjamin Cabé <benjamin@zephyrproject.org>
Assisted-by: Claude:fable-5
The pressure fractional part was always scaled with the 3125/128
factor, which is only exact for the 4096 LSB/hPa sensitivity (1260 hPa
full scale). In the 4060 hPa mode (fs = 1, 2048 LSB/hPa) that halved
the decimal part; use 6250/128 there instead.
Signed-off-by: Benjamin Cabé <benjamin@zephyrproject.org>
Assisted-by: Claude:fable-5
fetch_sem is given on every DRDY event, including conversions nobody
waits for (a late DRDY after a fetch timeout, or the single-shot
conversion started on PM resume), so k_sem_take() could return
immediately and the driver would report the previous conversion's data
forever. Discard any stale count before starting a new conversion.
Signed-off-by: Benjamin Cabé <benjamin@zephyrproject.org>
Assisted-by: Claude:fable-5
The +25 C offset was added to val1 after the raw sample had already
been split into integer and fractional parts, so readings below 25 C
produced a positive val1 with a negative val2. Build the value in
micro-Celsius and let sensor_value_from_micro() split it so both
fields carry the same sign.
Signed-off-by: Benjamin Cabé <benjamin@zephyrproject.org>
Assisted-by: Claude:fable-5
Transition the appropriate `MODEM_CELLULAR_COMMON_CHAT_MATCHES` matches
to `MODEM_CELLULAR_OK_CHAT_MATCH_DEFINE` and update the vendor
script implementations to be compatible.
Signed-off-by: Jordan Yates <jordan@embeint.com>
Generates periodic CNV trigger pulses at a configurable rate and duty
cycle to drive ADC conversions, exposed through the standard Zephyr PWM
API. Supports both v1 and v2 register layouts.
CONFIG_PWM_ADI_AXI_PWMGEN is auto-selected when
DT_HAS_ADI_AXI_PWMGEN_ENABLED.
Signed-off-by: Iustin Stolniceanu <iustin.stolniceanu@analog.com>
The flash_stm32h7x driver makes several accesses to properties of the
st,stm32-nv-flash child. Make sure said child exists.
Signed-off-by: Vilhelm Engström <vilhelm.engstrom@tuta.io>
The bank2-flash-size property was introduced as a workaround for the
Cortex-M4 of dual core MCUs cannot access the flash size register. As of
0e41b07309 (drivers : flash: update way to get flash size), this
register is no longer used by the driver. Instead, the size of the
entire flash is derived from the size cell of the corresponding
devicetree node. As this works just as well on the Cortex-M4 as it does
on the Cortex-M7, the bank2-flash-size property is no longer needed.
Signed-off-by: Vilhelm Engström <vilhelm.engstrom@tuta.io>
The changeset in which the removal of LL_GetFLashSize was accounted for
failed to consider that the size cell of the flash nodes on the dual
core MCUs - i.e. the STM32H747, STM32H757, STM32H745 and STM32H755 -
contains the size of a single bank rather than that of the entire flash.
As a result, the driver mistakes the flash mapped at
0x08008000-0x80fffff for a gap between two discontinuous memory banks
rather than a part of bank 1, thereby rendering sectors 4 through 7 of
the latter inaccessible.
Since both banks on the affected MCUs are the same size, simply
multiply said size by 2 to attain the correct total flash size.
Fixes: 0e41b07309 (drivers : flash: update way to get flash size)
Signed-off-by: Vilhelm Engström <vilhelm.engstrom@tuta.io>
Previously, it was possible to have a vsync event happen between the
semaphore reset and the buffer swap call meaning the driver would not
actually wait for the frame to be shown on the LCD before returning
Signed-off-by: André Costa <andre_miguel_costa@hotmail.com>
When converting timeout (in microseconds) to bauds use by the HW
frame timeout use less accurate conversion but one that does not
use 64 bit division. 64 bit division takes a lot of code and time
and shoud be avoided.
Signed-off-by: Krzysztof Chruściński <krzysztof.chruscinski@nordicsemi.no>
adxl355_decoder_decode() reinterprets a raw sample buffer as
struct adxl355_fifo_data first, checking is_fifo at byte offset 0 to
decide whether to route to adxl355_decode_stream(). struct
adxl355_sample declared is_fifo last (after x/y/z/range), so offset 0
of a one-shot sample buffer was actually the low byte of x - real
accelerometer data, not a flag.
With CONFIG_ADXL355_STREAM=y, roughly half of all one-shot reads
(whenever bit 0 of the raw X LSB happened to be set) were misrouted
into adxl355_decode_stream(), which then reads fifo_byte_count and
sample_set_size at offsets 20-22 - past the 20-byte (sizeof(struct
adxl355_sample)) buffer - causing an out-of-bounds read.
Fix this by giving adxl355_sample an is_fifo field at offset 0,
matching adxl355_fifo_data's layout, and have adxl355_read_sample()
explicitly clear it rather than relying on zero-initialization.
Signed-off-by: Dimitrije Lilic <dimitrije.lilic@orioninc.com>
BMA4XX_RTIO_SPI_DEFINE() called SPI_DT_IODEV_DEFINE() with two arguments
where three are required, so the macro could never expand for an instance
on SPI. Pass an operation of 0, matching the SPI_DT_SPEC_INST_GET() call
made for the same node in BMA4XX_CONFIG_SPI().
This went unnoticed because the definition sits behind
COND_CODE_1(DT_INST_ON_BUS(inst, spi), ...) and no in-tree devicetree
describes a bma4xx on a SPI bus.
Assisted-by: Claude:opus-5
Signed-off-by: Benjamin Cabé <benjamin@zephyrproject.org>
The optional delay argument accepted by SPI_CONFIG_DT, SPI_CONFIG_DT_INST,
SPI_DT_SPEC_GET, SPI_DT_SPEC_INST_GET and SPI_CS_CONTROL_INIT was
deprecated in Zephyr 4.3 and is now removed as part of the 4.5 deprecation
removal cycle.
These macros now take a fixed argument list, and the chip select timing is
always derived from the spi-cs-setup-delay-ns and spi-cs-hold-delay-ns
devicetree properties of the SPI device node. The SPI_DEPRECATE_DELAY_WARN
helper and the COND_CODE_0()/IS_EMPTY(__VA_ARGS__) plumbing that only
existed to support the deprecated form are dropped as well.
SPI_DT_IODEV_DEFINE and SPI_DT_INST_IODEV_DEFINE lose their variadic
argument too, since they forwarded it into SPI_DT_SPEC_GET.
The four remaining in-tree callers that still passed the deprecated
argument all passed a delay of 0, so nothing needs to be described in
devicetree for them.
Signed-off-by: Benjamin Cabé <benjamin@zephyrproject.org>
Assisted-by: Claude:opus-5
Add Wi-Fi status support to the ST67W611M1 Wi-Fi driver.
Supported for both interfaces (STA and SoftAP).
Signed-off-by: Eliott Speyser <eliott.speyser@st.com>
Add SoftAP support to the ST67W611M1 Wi-Fi driver.
Add a build test for the ST67W611M1_WIFI_STA_SAP_MODE config.
Also update doc and samples (zperf, wifi/apsta) for the X-NUCLEO-67W61M1
shield according to the SoftAP support.
Signed-off-by: Eliott Speyser <eliott.speyser@st.com>
The transmit buffer and the receive buffer share one register
window. A thread queueing the next transmission can write that
window while the receive interrupt handler reads a frame from
it, and the read then returns corrupted data: the frame
information byte loses its extended-id flag, so the frame is
parsed as standard, matches no exact-match filter and is
silently dropped. Guard the frame write plus transmission
request and the frame read plus buffer release with a
per-instance spinlock, releasing the receive buffer before
invoking the receive callbacks.
Signed-off-by: Sylvio Alves <sylvio.alves@espressif.com>
The endpoint buffers live in the USB DPRAM, which is in the peripheral
(Device) memory region. On Armv8-M (Cortex-M33) Device memory must be
accessed naturally aligned regardless of CCR.UNALIGN_TRP, so an unaligned
half-word or word access raises a UsageFault.
The payload was copied with plain memcpy()/net_buf_add_mem(). picolibc's
Armv7-M memcpy finishes a 3-byte tail (e.g. the 31-byte USB MSC Command
Block Wrapper) with a byte copy followed by a half-word copy at an odd
address, which faults against the DPRAM. RP2040 (Cortex-M0+) is unaffected
because its libc memcpy is byte-wise.
Copy the word-multiple part with memcpy() and the remainder byte by byte.
Fixes#111789
Assisted-by: Claude:claude-opus-5
Signed-off-by: Andreas Petter <Andreas.Petter@mcnetic.de>
Fixed regression related to ethernet for MCUs that only support 10/100M
and lack RGMII.
Signed-off-by: Vinicius Carvalho <carvalho-vinicius@outlook.com>
Suspending the BMM150 resets its registers, which clears the configured
ODR and repetition settings. bmm150_init_chip() suspends the device
before returning, so the settings are already lost by the time the
driver first resumes it.
The resume path currently restores the power and operating modes only,
leaving the device with the reset values instead of the selected
CONFIG_BMM150_PRESET_* settings.
Tested on a BMM150 using the regular preset. Before this change,
REP_XY/REP_Z read back as 0x00/0x00 after resume. With this change,
they read back as 0x04/0x07 after resume.
Restore the configured preset before returning the device to normal
mode. This also ensures the settings are restored after runtime
suspend/resume cycles.
Signed-off-by: Hasan Albinsaid <mail@hasanabs.com>
The controller path in i2c_dw_setup() had three issues around
10-bit addressing:
* addr_master_10bit was only ever set on the 10-bit branch and
never cleared, so once a 10-bit configuration had been
programmed the controller stayed latched in 10-bit mode for
subsequent 7-bit transfers.
* Both check sites used the deprecated I2C_ADDR_10_BITS macro
instead of the current I2C_MSG_ADDR_10_BITS definition.
* The ic_10bitaddr_master programming (dynamic TAR path) was
guarded by an additional I2C_MODE_CONTROLLER check that is
already asserted earlier in the same function, making the
outer branch redundant.
Fix all three by adding an explicit 7-bit clear branch, replacing
I2C_ADDR_10_BITS with I2C_MSG_ADDR_10_BITS, and collapsing the
dynamic TAR block to a straight if/else. No functional change to
the 7-bit default behavior.
Signed-off-by: Shreehari HK <shreehari.hk@alifsemi.com>
The IT51XXX SMBus controller does not support SMBALERT#.
To support this feature, a GPIO interrupt is configured through a
devicetree property and used as the SMBALERT# notification source.
When the GPIO interrupt is triggered, the driver performs the SMBus Alert
Response Address (ARA) procedure to identify and process the alerting
device.
Signed-off-by: Tim Lin <tim2.lin@ite.corp-partner.google.com>
Type-1 enumeration left prefetchable memory as TODO, so 64-bit BARs
behind a PCI-to-PCI bridge were not forwarded. Program prefetch
base/limit (and upper 32 bits) like the existing non-prefetch MEM
window.
Also advance the ECAM allocation offset when region_get_allocate_base()
aligns a Type-1 window, so subsequent BAR allocations start at the
aligned base instead of overlapping the unaligned remainder.
Signed-off-by: Li Wan <wanli@kylinos.cn>
The one-shot RTIO path sent the bare RM3100_REG_MX address, unlike the
bus and streaming paths which OR in REG_READ_BIT. On SPI this clears the
R/W bit, so the device treats the transfer as a write and never shifts
out measurement data, yielding garbage readings.
Signed-off-by: Benjamin Cabé <benjamin@zephyrproject.org>
Assisted-by: Claude:fable-5
ms5607_compensate() yields pressure in mbar * 100 (i.e. Pa), but
channel_get only divided by 100, returning mbar and thus a value 10x
too large for SENSOR_CHAN_PRESS, which is defined in kilopascal. Scale
by 1000 instead, matching the sibling ms5837 driver.
Signed-off-by: Benjamin Cabé <benjamin@zephyrproject.org>
Assisted-by: Claude:fable-5
bme280_submit_sync() always set has_humidity, but the fetch helper only
fills comp_humidity when the chip is a BME280, so an RTIO read of a
BMP280 decoded uninitialized buffer bytes as a valid humidity sample.
Gate the flag on the chip ID so the decoder reports -ENOTSUP/-ENODATA,
matching bme280_channel_get() on the synchronous path.
Signed-off-by: Benjamin Cabé <benjamin@zephyrproject.org>
Assisted-by: Claude:fable-5
bmm350_event_handler() transitions the stream state to BUSY but the
buffer-allocation and read-SQE preparation error paths returned without
restoring it, so a transient RTIO pool exhaustion left the stream stuck
in BUSY and every later DRDY event was ignored. Restore the ON state
before completing the SQE with an error, as the success path does.
Signed-off-by: Benjamin Cabé <benjamin@zephyrproject.org>
Assisted-by: Claude:fable-5
set_mag_odr_osr() suspended the device before validating the caller's
oversampling value, so an invalid value returned -EINVAL with the chip
left in suspend mode, silently stopping measurements. Validate the
arguments first, and restore normal mode if the ODR/performance write
fails.
Signed-off-by: Benjamin Cabé <benjamin@zephyrproject.org>
Assisted-by: Claude:fable-5
channel_get() unconditionally masked the proximity result to 12 bits,
so values read in high-dynamic-output mode (PS_HD = 1), where PS_DATA
is a full 16-bit result, wrapped modulo 4096. Only apply the 12-bit
mask when high dynamic output is disabled.
Signed-off-by: Benjamin Cabé <benjamin@zephyrproject.org>
Assisted-by: Claude:fable-5
VCNL36825T_MPS_PULSES_8 encoded 4 in the 2-bit PS_MPS field at bits
[13:12], which overflowed into the adjacent PS_IT field: the sensor was
programmed for 1 pulse and a doubled integration time. Encode 3 (0b11)
as the datasheet specifies for 8 pulses.
Signed-off-by: Benjamin Cabé <benjamin@zephyrproject.org>
Assisted-by: Claude:fable-5
tma525b_chip_init() only increments retry when a poll fails, and breaks
out of the loop before the increment. retry == 0 is therefore exactly the
case where the controller answered correctly on the very first read, yet
that is the condition used to report failure.
The result is inverted on both sides: a working panel that is ready after
the boot delay makes chip_init() return -ENODEV, so the device is never
ready and the touchscreen is dead, while a panel that never enters
application mode exhausts the loop and is reported as a success, leaving
tma525b_process() to fail forever with no diagnostic. A single call emits
both the "entered application mode" info message and the "failed to enter
application mode" error.
Track the successful exit explicitly instead of inferring it from the
retry counter. This also runs on every PM_DEVICE_ACTION_RESUME.
Signed-off-by: Benjamin Cabé <benjamin@zephyrproject.org>
Assisted-by: Claude:fable-5
bmg160_trigger_init() passed GPIO_INT_EDGE_TO_ACTIVE to
gpio_pin_configure_dt(), which rejects interrupt flags and never set
the pin as an input. Pass GPIO_INPUT instead; interrupt trigger
configuration is already handled in setup_int().
Signed-off-by: Benjamin Cabé <benjamin@zephyrproject.org>
Assisted-by: Claude:fable-5
bmg160_slope_config() computed the range-scaled threshold register
value (any_th_reg_val) but wrote the raw dps value to BMG160_REG_THRES,
so the any-motion threshold was wrong by a factor of 2000/range for any
full-scale range other than 2000 dps. Write the computed register value
instead.
Signed-off-by: Benjamin Cabé <benjamin@zephyrproject.org>
Assisted-by: Claude:fable-5
The threshold conversion was computed in 64-bit arithmetic but
assigned to a uint32_t before the TSL2591_MAX_ADC bounds check, so
results of 2^32 or more wrapped to small values that passed
validation and programmed a wrong interrupt threshold. Keep the
value in a uint64_t until after the check and reject negative
sensor_value inputs, which previously wrapped to huge unsigned
values.
Signed-off-by: Benjamin Cabé <benjamin@zephyrproject.org>
Assisted-by: Claude:fable-5
tsl2591_set_gain updated the cached gain scale (data->again) before
writing CONFIG, so a failed I2C update left the cache diverged from
hardware, skewing lux conversion and thresholds. Cache the new scale
only after a successful write, matching tsl2591_set_integration.
Signed-off-by: Benjamin Cabé <benjamin@zephyrproject.org>
Assisted-by: Claude:fable-5
The exit path of tsl2591_attr_set() unconditionally overwrote ret with
the result of the power-on register update, so failed or unsupported
attribute writes returned 0. Keep the attribute error and only surface
the power-restore result when the attribute operation succeeded.
Signed-off-by: Benjamin Cabé <benjamin@zephyrproject.org>
Assisted-by: Claude:fable-5
The FIFO watermark is a 9-bit value: 8 LSBs in FIFO_SAMPLES plus one
MSB bit in FIFO_CONTROL, so the MSB of the value is bit 8, not bit 9.
Testing BIT(9) meant watermarks of 256..511 sample sets wrapped modulo
256. Matches the Linux IIO adxl367 driver from ADI.
Signed-off-by: Benjamin Cabé <benjamin@zephyrproject.org>
Assisted-by: Claude:fable-5
The DIE_TEMP branches of the stream decoders cast data_out to
struct sensor_q31_data but zeroed it with
sizeof(struct sensor_three_axis_data), writing 8 bytes past the end
of a correctly sized caller buffer. Use the matching sizeof.
Signed-off-by: Benjamin Cabé <benjamin@zephyrproject.org>
Assisted-by: Claude:fable-5
The non-FIFO branch of adxl367_decoder_get_frame_count returned
-ENOTSUP for SENSOR_CHAN_DIE_TEMP even though one-shot reads always
encode temperature data and the decoder can decode it. Report one
frame for DIE_TEMP like the other supported channels.
Signed-off-by: Benjamin Cabé <benjamin@zephyrproject.org>
Assisted-by: Claude:fable-5
The FIFO decode path divided the raw temperature delta by the 54 LSB/C
sensitivity using integer division before applying the 2^23 Q31 scale,
quantizing streamed temperatures to whole degrees. Scale first with an
int64 intermediate, then divide, so fractional degrees are preserved.
Signed-off-by: Benjamin Cabé <benjamin@zephyrproject.org>
Assisted-by: Claude:fable-5
adxl367_attr_set_thresh() always copied activity_th.enable/.referenced
into the threshold passed to the setup helpers, so setting
SENSOR_ATTR_LOWER_THRESH programmed the INACT_EN/INACT_REF bits from
the activity configuration. Select the config source per attribute so
the inactivity path uses cfg->inactivity_th.
Signed-off-by: Benjamin Cabé <benjamin@zephyrproject.org>
Assisted-by: Claude:fable-5
The FIFO entries register counts individual samples, but the 8B and
14B/12B_CHID byte-count computations used fifo_packet_cnt (entries
divided by samples per set) without multiplying back by the number of
samples per set, so only 1/N of the buffered FIFO data was read each
watermark event. Multiply by sample_numb as the 12B branch already does.
Signed-off-by: Benjamin Cabé <benjamin@zephyrproject.org>
Assisted-by: Claude:fable-5
The SENSOR_TRIG_FIFO_FULL case in adxl367_decoder_has_trigger()
tested the FIFO watermark status bit, duplicating the watermark case
and misreporting FIFO full events. Check ADXL367_STATUS_FIFO_OVERRUN
instead, matching the trigger mapping used by the stream code.
Signed-off-by: Benjamin Cabé <benjamin@zephyrproject.org>
Assisted-by: Claude:fable-5
The SENSOR_ATTR_OVERSAMPLING case discarded the return value of
bmc150_magn_attr_set_rep(), so invalid repetition values, unsupported
channels and bus failures were all reported as success.
Signed-off-by: Benjamin Cabé <benjamin@zephyrproject.org>
Assisted-by: Claude:fable-5
gpio_pin_configure_dt() was called with GPIO_INT_EDGE_TO_ACTIVE, which
is an interrupt flag rejected by gpio_pin_configure() (assertion
failure with CONFIG_ASSERT=y) and leaves the pin direction unset.
Configure the pin as a plain input and check the result; edge selection
is already handled by setup_drdy() via
gpio_pin_interrupt_configure_dt().
Signed-off-by: Benjamin Cabé <benjamin@zephyrproject.org>
Assisted-by: Claude:fable-5