Commit graph zephyr/drivers
Author SHA1 Message Date
Andrej Butok
839b525e14 hwinfo: nxp: unify driver naming
- Unify the naming of all NXP hwinfo drivers to use a consistent
  HWINFO_NXP_* Kconfig prefix and hwinfo_nxp_*.c source file naming,
  replacing the previous inconsistent mix of symbols.
- Consolidate the per-driver Kconfig fragments into a single
  Kconfig.nxp file.
- No functional change.

Signed-off-by: Andrej Butok <andrey.butok@nxp.com>
2026-08-12 13:09:50 -04:00
Liam Ogletree
73837c12e7 drivers: flash: Unify runtime PM log messages
Propagates #113545 to flash drivers.

Signed-off-by: Liam Ogletree <liam.ogletree@cirrus.com>
2026-08-12 13:09:27 -04:00
Sergei Ovchinnikov
24c6f18c36 drivers: mfd: npm10xx: use _SAFE slist walk macro in events_handler
Using the unsafe walk might result in some handlers being silently dropped
when one of the callbacks removes itself from the list breaking the loop.
Use the safe walk instead to avoid this.

Signed-off-by: Sergei Ovchinnikov <sergei.ovchinnikov@nordicsemi.no>
2026-08-12 13:09:17 -04:00
Hsiu-Chi Tsai
0ecc5d7a93 drivers: i2s: esp32: return the TX block when the DMA fails
Two TX paths take a block off the queue, record it in mem_block, and
then return without giving it back when the DMA call fails: the start
in i2s_esp32_tx_start_transfer(), and the restart in
i2s_esp32_tx_compl_transfer(). transferring is never set either, so
nothing downstream treats the stream as owning anything, and the next
attempt overwrites mem_block. The slab drains one block per failure.

i2s_esp32_rx_callback() already meets the identical failure at its own
restart and frees the block, clears mem_block and mem_block_len, and
stops. Do on TX what RX already does, at both sites.

Requeuing would not be equivalent: k_msgq_put() appends, so a retry
would play the block after samples that were queued later.

Both TX blocks reach the driver through i2s_write(), which does not
reject NULL, so both sites check before freeing. RX needs no check:
its block comes straight from k_mem_slab_alloc().

Both sites also clear dma_pending explicitly, so the failure state
they leave behind does not depend on the stop path clearing it.

Fixes #115504

Signed-off-by: Hsiu-Chi Tsai <hctsai@linux.com>
2026-08-12 13:06:59 -04:00
Mark Wang
8e9533fb09 drivers: usb: udc: mcux: report VBUS detection capability
The MCUX EHCI and IP3511 hs controllers can detect VBUS state before
udc_enable (which pulls up DP) is called when the underlying MCUX USB
device hal drivers are built with USB_DEVICE_CONFIG_DETACH_ENABLE.
Set the can_detect_vbus capability accordingly so the USB device stack
can rely on hardware VBUS detection when available.

Signed-off-by: Mark Wang <yichang.wang@nxp.com>
2026-08-12 13:06:40 -04:00
Keith Short
0f521cd8df soc: ite: Add deep sleep time measurement support for ITE ECs
Track the time spent in deep doze / sleep states on ITE EC SoCs
(IT8xxx2, IT51xxx) by capturing the 32.768 kHz free-run timer timestamp
before entering deep sleep and accumulating elapsed cycles upon waking.

Add ite_ec_clock_get_sleep_ticks() to convert total deep-sleep cycles
to kernel ticks.

Signed-off-by: Keith Short <keithshort@google.com>
Assisted-by: Antigravity:gemini-1.5-pro
2026-08-12 13:00:41 -04:00
Keith Short
f968be4a80 soc: ite: it8xxx2: Rename ite_ec_timer_block_idle
Rename ite_ec_timer_block_idle() to ite_it8xxx2_timer_block_idle() to
reflect that this DMA clock synchronization idle check is specific to
the IT8XXX2 SoC family. Remove the unnecessary header guard around its
prototype in soc_timer.h.

Signed-off-by: Keith Short <keithshort@google.com>
Assisted-by: Antigravity:gemini-1.5-pro
2026-08-12 13:00:41 -04:00
Hake Huang
2c132efaf0 drivers: entropy: mcux_trng: fix buffer overflow on odd lengths
TRNG_GetRandomData() writes random data in 32-bit word granularity.
With TRNG_SW_HEALTH_TESTS enabled, the SDK always copies full words,
overflowing a caller buffer whose length is not a multiple of four.
This clobbered the guard byte in tests/drivers/entropy/api on
mimxrt685_aud_evk.

Use a bounce word for an unaligned prefix, pass the aligned bulk
directly to the SDK, and use the bounce word for the remaining tail.
This avoids unaligned SDK stores and buffer overruns while preserving
a single SDK call for the common aligned, four-byte-multiple case.

Fixes #115591

Signed-off-by: Hake Huang <hake.huang@nxp.com>
2026-08-12 12:59:28 -04:00
Aksel Skauge Mellbye
5404dda994 drivers: wifi: siwx91x: Correctly limit SSID length
SSIDs have a maximum length of 32 bytes, and the buffer used
by the HAL has this size. Ensure the length field matches the
data stored in the buffer.

The HAL does not expect the buffer to be null terminated, so
it is safe to use strnlen to compute the length.

Signed-off-by: Aksel Skauge Mellbye <aksel.mellbye@silabs.com>
2026-08-12 12:59:05 -04:00
Hsiu-Chi Tsai
0d82dbbe72 drivers: i2s: esp32: reject an unsupported trigger direction
i2s_esp32_trigger_check() validates the direction for I2S_DIR_BOTH and
then does not validate it for either single direction. The BOTH branch
checks all four pointers and returns -ENOSYS when the instance does not
have both directions; the I2S_DIR_RX and I2S_DIR_TX branches read
->configured straight out of a stream that may not exist.

The instantiation macro gives a direction the devicetree does not
describe a null conf and a null data, so on an instance that enables
only one direction, triggering the other one dereferences NULL rather
than returning an error.

Add the guard the BOTH branch already has, and return the same -ENOSYS
for the same reason: the hardware this instance describes cannot do
what the caller asked. -EINVAL a few lines below stays for a direction
that is not one of the enumerators, which is a different mistake.

Signed-off-by: Hsiu-Chi Tsai <hctsai@linux.com>
2026-08-12 12:57:27 -04:00
Hsiu-Chi Tsai
ea7af2e597 drivers: i2s: esp32: cancel the deferred TX timer on stop
The deferred-completion timer is started when the TX queue runs dry and
CONFIG_I2S_ESP32_ALLOWED_EMPTY_TX_QUEUE_DEFERRAL_TIME_MS is non-zero,
but nothing ever cancels it. If it is still armed when the stream ends,
it fires afterwards and runs the completion path against whatever state
the device is in by then. After a DROP that is a device already back in
READY, and the block it consumes belongs to the next stream.

Cancel it in i2s_esp32_tx_stop_transfer(), which is the one boundary
every path that ends TX ownership goes through: DROP, a fatal callback,
a completed STOP or DRAIN, and the rollback when starting the second
direction of an I2S_DIR_BOTH transfer fails. Putting it in the trigger
cases instead would miss the callback paths.

k_timer_stop() is marked ISR-safe and stopping an inactive timer is a
documented no-op, so both contexts this helper runs in are fine. The
timer's own expiry function ends by calling this helper, so it can also
stop itself; that is safe because the abort of an in-flight timeout is
suppressed on the announcing CPU, and the timer is one-shot, so nothing
re-arms.

It does not wait for an expiry function already running on another CPU.
That is not stated in the API documentation, only in the implementation,
and k_timer_cleanup() cannot be used here because it asserts it is not
called from an ISR. This does not make the situation worse than leaving
the timer armed, but it is not a full barrier either.

Fixes #115505

Signed-off-by: Hsiu-Chi Tsai <hctsai@linux.com>
2026-08-12 12:57:19 -04:00
Fin Maaß
530e47b9d3 dts: bindings: ethernet: mdio: infineon: xmc4xxx: use snps,dwmac-mdio
As per our documentation, we have to
reuse bindings from Linux, there they use
"snps,dwmac-mdio", so let's use the same one
here in zephyr.

Signed-off-by: Fin Maaß <info@finmaass.de>
2026-08-12 09:47:10 -07:00
Fin Maaß
4de795958d drivers: ethernet: infineon: xmc4xxx: allign devicetree structure
Allign the devicetree structure of the wch ethernet
nodes wich the other existing nodes, that also use the
Synopsys Designware IP.

With that also move the "mdi-port-ctrl" from the
mdio node to the ethernet node, wich is now the
parent of the mdio node.

Signed-off-by: Fin Maaß <info@finmaass.de>
2026-08-12 09:47:10 -07:00
Fin Maaß
2b254cf94c drivers: ethernet: wch: allign devicetree structure
Allign the devicetree structure of the wch ethernet
nodes wich the other existing nodes, that also use the
Synopsys Designware IP.

Signed-off-by: Fin Maaß <info@finmaass.de>
2026-08-12 09:47:10 -07:00
Fin Maaß
82fc84fca0 dts: bindings: ethernet: mdio: wch: use snps,dwmac-mdio
As per our documentation, we have to
reuse bindings from Linux, there they use
"snps,dwmac-mdio", so let's use the same one
here in zephyr.

Signed-off-by: Fin Maaß <info@finmaass.de>
2026-08-12 09:47:10 -07:00
Fin Maaß
ef6cd990e6 dts: bindings: ethernet: mdio: nxp: s32: use snps,dwmac-mdio
As per our documentation, we have to
reuse bindings from Linux, there they use
"snps,dwmac-mdio", so let's use the same one
here in zephyr.

Signed-off-by: Fin Maaß <info@finmaass.de>
2026-08-12 09:47:10 -07:00
Fin Maaß
f7c505e058 dts: bindings: ethernet: mdio: nxp: qos: use snps,dwmac-mdio
As per our documentation, we have to
reuse bindings from Linux, there they use
"snps,dwmac-mdio", so let's use the same one
here in zephyr.

Signed-off-by: Fin Maaß <info@finmaass.de>
2026-08-12 09:47:10 -07:00
Fin Maaß
13fe0a115e dts: bindings: ethernet: mdio: esp32: use snps,dwmac-mdio
As per our documentation, we have to reuse bindings from Linux, there
they use "snps,dwmac-mdio", so let's use the same one here in zephyr.
The esp32 itself is not in Linux, but the ethernet IP from Synopsys is.

Signed-off-by: Fin Maaß <info@finmaass.de>
2026-08-12 09:47:10 -07:00
Fin Maaß
7db1cfdc66 dts: bindings: ethernet: mdio: stm32: use snps,dwmac-mdio
As per our documentation, we have to reuse bindings from Linux, there
they use "snps,dwmac-mdio", so let's use the same one here in zephyr.

Signed-off-by: Fin Maaß <info@finmaass.de>
2026-08-12 09:47:10 -07:00
John Batch
df98114028 drivers: adc: infineon: hppass: Refactor ADC register access
Updates the HPPASS SAR ADC driver to remove PDL runtime calls where
possible and replace with direct register operations instead.  Calls to
Cy_HPPASS_SAR_Init() and Cy_HPPASS_SAR_CrossTalkAdjust() are retained to
manage hardware calibration that isn't well documented in hardware
documentation.

Aligns the ADC driver with the new HPPASS MFD driver by removing AC
startup sequence that is now managed by MFD driver for all HPPASS
devices.

Assisted-by: Github Copilot:claude-opus-4.7
Signed-off-by: John Batch <john.batch@infineon.com>
2026-08-12 09:41:36 -07:00
Eva Klejmova
ed742007ec dts: arm: nxp: rt7xx: add MICFIL node support
Add the MICFIL devicetree node for the RT7xx common DTSI and
update MCUX SYSCON clock control.

Signed-off-by: Eva Klejmova <eva.klejmova@nxp.com>
2026-08-12 09:40:51 -07:00
Camille BAUD
530022cbf1 bluetooth: bflb: Harmonize interrupts settings where possible
Pick IRQs from DTS when possible

Signed-off-by: Camille BAUD <mail@massdriver.space>
2026-08-12 10:03:22 -04:00
Camille BAUD
33579adbfe drivers: bluetooth: wifi: Add BLE and WIFI support for BL616CL
Add support for BLE and WIFI on BL616CL.
Harmonize WiFi6 Blob/HW pair.

Signed-off-by: Camille BAUD <mail@massdriver.space>
2026-08-12 10:03:22 -04:00
Flavio Ceolin
0d65ce46dd drivers: fuel_gauge: reject oversized len
The userspace verifiers for fuel_gauge_get_props() and
fuel_gauge_set_props() declared two variable-length arrays sized by the
caller-supplied len argument:

  union fuel_gauge_prop_val k_vals[len];
  fuel_gauge_prop_t k_props[len];

Both VLAs were allocated before any validation, including before the
K_SYSCALL_DRIVER_FUEL_GAUGE() object check. Fix it removing the kernel
copy of these data. That is safe becasue there is no embbeded pointers.

Signed-off-by: Flavio Ceolin <flavio@hubble.com>
2026-08-11 20:56:21 -04:00
Muhammad Waleed Badar
0449ece02e drivers: input: virtio: add Kconfig choice for device type
Add INPUT_VIRTIO_DEVICE_TYPE choice (tablet/keyboard) to select the
VIRTIO input device type at build time instead of hardcoding tablet.

Update qemu/cortex_a53, qemu/riscv64, and qemu/x86 board.cmake to
pick virtio-keyboard-device/-pci when keyboard is selected.

Signed-off-by: Muhammad Waleed Badar <walid.badar@gmail.com>
2026-08-11 20:56:13 -04:00
Mohamed Azhar
882d6507be drivers: spi: microchip: Update g1 driver
Updated to complete peripheral transfer on TXC
Fixed dummysize calculation for multi-buffer transfers

Signed-off-by: Mohamed Azhar <mohamed.azhar@microchip.com>
2026-08-11 20:55:54 -04:00
Holt Sun
efa8637ac7 soc: nxp: keep mcux lptmr as an explicit per-SoC default
The MCUX LPTMR system-timer driver previously defaulted to enabled
whenever the /chosen/zephyr,system-timer node was compatible with
nxp,lptmr. On SoCs whose devicetree points zephyr,system-timer at an
LPTMR instance (e.g. frdm_mcxw71/mcxw716c), this forced every build,
including non-power-management builds, to select the 32.768 kHz LPTMR
and disable the Cortex-M SysTick. Tests that rely on the high-resolution
SysTick clock (tests/kernel/timer/timer_api) then failed because the
1024 tick/s LPTMR does not provide the required timing resolution.

Restore the explicit per-SoC policy: the generic driver no longer
defaults MCUX_LPTMR_TIMER on, and each SoC opts in on its own terms.
MCXW7xx, KE1xF and MCXC enable the LPTMR only when power management is
enabled (default y if PM); i.MX95 and i.MX952 M7 enable it only when the
LPTMR is not claimed by the counter driver (default y if
!COUNTER_MCUX_LPTMR). This keeps SysTick as the system timer for plain
builds while preserving the low-power LPTMR configuration for PM builds.

Update the 4.5 migration guide accordingly.

Fixes #115491

Signed-off-by: Holt Sun <holt.sun@nxp.com>
2026-08-11 20:54:32 -04:00
Benjamin Cabé
365ebbd28a drivers: ethernet: move NETC internal header next to its drivers
include/zephyr/drivers/ethernet/nxp_imx_netc.h only holds definitions
shared between the NXP i.MX NETC Ethernet and DSA drivers, which both
live under drivers/ethernet. Move the header to the NETC driver
directory so that it is no longer part of the public include tree.

Assisted-by: Claude:fable-5
Signed-off-by: Benjamin Cabé <benjamin@zephyrproject.org>
2026-08-11 17:03:16 -04:00
Hsiu-Chi Tsai
38e1dd9ee6 drivers: dma: esp32: refuse an oversized reload before resetting
dma_esp32_reload() resets the channel and rebuilds the descriptor list
before it can discover that the transfer does not fit. When it does not,
the list is memset to zero and -EINVAL returned, so a reload that was
refused has already destroyed the transfer that was configured before
it.

Compare the requested size against the pool the descriptors can cover
first, and return before the reset. The walk keeps its own check as a
backstop.

Signed-off-by: Hsiu-Chi Tsai <hctsai@linux.com>
2026-08-11 17:02:38 -04:00
Hsiu-Chi Tsai
51d753dd26 drivers: dma: esp32: bound the descriptor walks by the array
Three loops over desc_list took their limit from
CONFIG_DMA_ESP32_MAX_DESCRIPTOR_NUM while the exhaustion check beneath
them uses ARRAY_SIZE() of the same array. The two agree today, because
that is what sizes the array, but they are two statements of one fact
and only one of them follows the array if it ever changes.

Use ARRAY_SIZE() in all three. No behaviour change.

Signed-off-by: Hsiu-Chi Tsai <hctsai@linux.com>
2026-08-11 17:02:38 -04:00
Hsiu-Chi Tsai
626b0ca6d2 drivers: dma: esp32: do not stop a direction twice on a M2M channel
dma_esp32_stop() handled a memory-to-memory channel by disabling and
stopping both directions, and then fell straight into the per-direction
block, which stopped one of them a second time. There was no return and
no else between the two.

A memory-to-memory channel still carries a dir of DMA_RX or DMA_TX from
dma_esp32_config_rx() or dma_esp32_config_tx(), so one of the two arms
always matched.

The second stop is redundant in the driver's intended control flow.
Nothing here measures what the hardware does with a repeated stop, so
this is not offered as an equivalence: a M2M channel now takes one
interrupt disable and one stop per direction instead of two for one of
them. It is worth removing on its own terms, because the function reads
as though the two blocks are alternatives when they are not, and any
step added to the stop sequence later would be duplicated silently.

Chain the branches, which is what dma_esp32_start() directly above
already does with the same three cases.

Fixes #115503

Signed-off-by: Hsiu-Chi Tsai <hctsai@linux.com>
2026-08-11 17:02:38 -04:00
Hsiu-Chi Tsai
e221690000 drivers: dma: esp32: derive the channel pointer after the bounds check
Five entry points formed the channel pointer from the caller's index
before validating it:

	struct dma_esp32_channel *dma_channel =
		&config->dma_channel[channel];

	if (channel >= config->dma_channel_max) {
		LOG_ERR("Unsupported channel");
		return -EINVAL;
	}

Nothing is dereferenced before the check, so no wrong memory is read
today, but forming a pointer more than one past the end of an array is
undefined behaviour in C. It also gives the compiler licence to assume
the index is in range, and the thing it would be assuming away is the
check on the very next line.

dma_esp32_reload() went one step further and computed desc_iter from the
unvalidated pointer too.

Move each derivation below its check. Behaviour is unchanged for every
in-range channel; for an out-of-range one the driver no longer forms a
pointer the standard leaves undefined.

Signed-off-by: Hsiu-Chi Tsai <hctsai@linux.com>
2026-08-11 17:02:38 -04:00
Hsiu-Chi Tsai
eb05655b95 drivers: dma: esp32: stop dereferencing one past the descriptor array
dma_esp32_config_descriptor() and dma_esp32_reload() both walk desc_list
with a pointer that advances once per iteration, and both then test for
descriptor exhaustion by dereferencing that pointer after the loop has
ended. The loop bound equals the array size, so a loop that runs to
completion leaves the pointer one past the last element and the test
reads out of bounds. In dma_esp32_reload() the error branch then writes
there as well.

config->dma_channel is an array of struct dma_esp32_channel, so the
memory just past one channel's desc_list is that channel's remaining
members or the next channel's. That memset lands in a live neighbouring
object rather than in padding.

There is a second consequence in dma_esp32_config_descriptor(). If the
out-of-bounds read happens to yield zero, the function reports success
while desc_list[N - 1].next still points at desc_list + N, so the
hardware is handed a chain that runs off the end of the array. Whether
the caller gets -EINVAL or a corrupt chain depends on the bytes that
happen to follow.

Compare the pointer against the end of the array instead. A loop that
breaks early exits with desc_iter below the end, and a loop that ran out
of descriptors exits with it exactly at the end, so the comparison
answers the same question the dereference was trying to answer without
forming an access. Comparing against one past the end is well defined.

dma_esp32_reload() also gains the whole-array clear that
dma_esp32_config_descriptor() already performs on this path, in place of
the single out-of-bounds descriptor it used to clear. Leaving a half
built chain behind on an error return serves no purpose.

Fixes #115502

Signed-off-by: Hsiu-Chi Tsai <hctsai@linux.com>
2026-08-11 17:02:38 -04:00
Laurie Fay
890c2e7e6b drivers: pinctrl: migrate musca-b1 pinctrl driver
This commit migrates the existing pinmux driver for the musca-b1
board to the newer pinctrl API. The new implementation also fixes
a bug in the original pinmux driver which would have selected
alternative function 2 instead of ALTF1 as desired.

The musca-s1 pinmux driver has been left as this board is
deprecated.

Signed-off-by: Laurie Fay <Laurie.Fay@arm.com>
2026-08-11 17:01:15 -04:00
Jordan Yates
7b304fc341 modem: cellular: don't run NULL script
Don't attempt to run a `NULL` periodic script, and add assertions into
`modem_chat` to raise the issue if this does occur.

Signed-off-by: Jordan Yates <jordan@embeint.com>
2026-08-11 17:01:04 -04:00
Martin Hubáček
aa439fcfd5 drivers: sensor: tmp112: add one-shot conversion mode
The TMP112 can stay in shutdown (SD) mode and perform a single
conversion on demand via the one-shot (OS) bit. This is the lowest
idle-current mode and suits battery-powered designs that sample
infrequently.

Expose this mode through the conversion-rate property: setting it to 0
keeps the sensor shut down and triggers a one-shot conversion on every
sample_fetch call, blocking until the OS bit reads back as 1 (typ.
10 ms per datasheet 7.4.3) or a timeout elapses. The same mode can be
selected at runtime by setting a 0 Hz sampling frequency through
sensor_attr_set().

Because a new value (0) is prepended to the conversion-rate enum, the
device-tree enum index no longer maps directly onto the CR register
field, so the init path subtracts one for the periodic rates.

Tested on an nRF54L15-DK with a TMP112 over I2C: the periodic rates are
unchanged and conversion-rate = 0 returns correct readings on demand
while the sensor is held in shutdown between fetches.

Assisted-by: Claude:claude-opus-4.8
Signed-off-by: Martin Hubáček <martin.hubacek@hardwario.com>
2026-08-11 17:00:24 -04:00
Darcy Lu
1dc6b06076 drivers: spi: add spi master driver for RTS5817
The RTS5817's SPI is based on snps,designware-spi, but it's not
entirely the same, so DW spi drivers cannot be used directly.

The rts5817 spi driver uses some DW spi code:
1. pin_ctrl is handled in the spi_dw.c code initialization.
2. Several APIs defined in spi_dw.h is used by spi_rts5817.c.

Signed-off-by: Darcy Lu <darcy_lu@realsil.com.cn>
2026-08-11 17:00:12 -04:00
Darcy Lu
79ba774b61 drivers: spi: dw: Add write to the RX_SAMPLE_DLY register
This commit adds an API for writing to the RX_SAMPLE_DLY register,
and also adds the `__maybe_unused` attribute to APIs such as
aux_reg_* and reg_*, so that these APIs can be used in other drivers
that based on snps,designware-spi

Signed-off-by: Darcy Lu <darcy_lu@realsil.com.cn>
2026-08-11 17:00:12 -04:00
Jukka Rissanen
a33f4fbcd9 net: dns: Use net_sockaddr_storage for address storage
Wrap stored DNS addresses (resolver servers, dispatcher local
address, addrinfo results, mDNS server) in unions with a storage
sibling. Use storage-sized buffers for recv, server compare/copy,
and management event payloads.

Assisted-by: Cursor:composer-2.5
Signed-off-by: Jukka Rissanen <jukka.rissanen@nordicsemi.no>
2026-08-11 13:44:14 -04:00
Pieter De Gendt
42e9e42d52 drivers: spi: nxp_lpspi: Don't print unintialized variable
Remove the unintialized variable from a DBG print to prevent compiler
warnings when the log level is set to debug.

Signed-off-by: Pieter De Gendt <pieter.degendt@basalte.be>
2026-08-11 13:43:50 -04:00
Etienne Carriere
626b1ea89a drivers: bluetooth: hci: ipm_stm32: Get interrupts from the DT
Get interrupt configuration from the devicetree. The interrupts NVIC IDs
must match the value expected (defined) in the HAL. Interrupts priority
is also set from the 0 instead of being hard coded to 0.

Signed-off-by: Etienne Carriere <etienne.carriere@st.com>
2026-08-11 13:43:40 -04:00
JaeHwan Jin
615e0c306f drivers: adc: add TI ADCxx1C family ADC driver
Add support for the Texas Instruments ADC081C021/027, ADC101C021/027
and ADC121C021/027 single-channel I2C ADCs. The six parts share one
register map and differ only in the resolution of the left aligned
conversion result, so one driver handles all of them.

Signed-off-by: JaeHwan Jin <jaehwan.jin@rakwireless.com>
2026-08-11 13:42:37 -04:00
Aksel Skauge Mellbye
3a6406439c drivers: serial: silabs: Only clear processed flags
In interrupt handlers, only clear interrupt flags that have been
processed. This fixes a race condition where an interrupt that was
raised after flags were read for processing was prematurely
cleared without the corresponding action being taken.

When this condition was met, irq_tx_complete() never reported that
transmission was complete, while err_check() failed to report errors.

Signed-off-by: Aksel Skauge Mellbye <aksel.mellbye@silabs.com>
2026-08-11 07:50:00 -04:00
Qiankun Li
bea1ce8eab drivers: wifi: nxp: fix NULL pointer dereference in net_get_if_ip_addr
net_get_if_ip_addr() dereferences config.ip.ipv4 without NULL check.
When STA interface has never been brought up (dormant since init),
this pointer is NULL. On RT1060, the NULL dereference reads ITCM
code memory at address 0x4, returning a non-zero value that is
misinterpreted as a valid IP address, causing is_sta_ipv4_connected()
to incorrectly return true and breaking MEF host sleep wakeup.

The system does not crash because address 0x00000000 on RT1060 maps
to ITCM (Instruction Tightly Coupled Memory), which contains valid
relocated code (.itcm_text_reloc section). Reading from this region
is a legal memory access at the hardware level, so no HardFault or
MemManage fault is triggered.

Add NULL check for ipv4 pointer before accessing unicast address.

Signed-off-by: Qiankun Li <qiankun.li@nxp.com>
2026-08-11 07:49:25 -04:00
Tim Lin
495064f899 drivers/smbus: it51xxx: Add host notify support
The feature is available on smbus0-smbus2 and can be enabled through
smbus_config. When a host notify command is received, the driver
generates an interrupt and reports the notifying SMBus address through
the registered callback.

Signed-off-by: Tim Lin <tim2.lin@ite.corp-partner.google.com>
2026-08-11 07:48:48 -04:00
Krzysztof Chruściński
fbe8357d21 drivers: serial: nrfx_uarte: Fix calculation of an internal variable
bounce_buf_swap_len variable is used when mode that uses TIMER to
count RX bytes was used. Macro for calculating that variable was
invoked with incorrect argument as UARTE_US_TO_BYTES was applied
to baudrate argument. Because of that
CONFIG_UART_NRFX_UARTE_BOUNCE_BUF_SWAP_LATENCY was in fact not
applied.

Signed-off-by: Krzysztof Chruściński <krzysztof.chruscinski@nordicsemi.no>
2026-08-11 07:48:37 -04:00
Yiren Guo
42b52d571e drivers: input: gt911: clamp reported touch point count
The touch point count comes from the device status register and is only
masked to 0..15, while the point array is sized to
CONFIG_INPUT_GT911_MAX_TOUCH_POINTS (1..5). A malfunctioning or
malicious device on the bus can therefore overflow the stack buffer.
Clamp the value to the configured maximum.

Signed-off-by: Yiren Guo <guoyr_2013@hotmail.com>
2026-08-11 07:46:56 -04:00
Shuai Ma
538c93148d drivers: flash: esp32: use relative timeout when locking async mutex
The asynchronous read/write/erase handlers passed
K_TIMEOUT_ABS_SEC(CONFIG_ESP_FLASH_ASYNC_TIMEOUT) to k_mutex_lock().
That macro builds an absolute deadline measured from system boot
rather than a relative timeout. Once the system uptime exceeds
CONFIG_ESP_FLASH_ASYNC_TIMEOUT seconds the deadline always lies in
the past, k_mutex_lock() fails immediately and every flash operation
returns -ETIMEDOUT without ever being submitted.

Use K_SECONDS() so that the configured value is honoured as a
relative timeout, matching the Kconfig help text.

Signed-off-by: Shuai Ma <malin719426@gmail.com>
2026-08-11 07:46:29 -04:00
Ren Chen
18a1109730 drivers: spi: it8xxx2: correct sspi clock query
This change corrects sspi clock query for it8xxx2 register
v2. Additionally, the spi clock must be turned on when
setting ssck equal to sspi_clock.

Signed-off-by: Ren Chen <Ren.Chen@ite.com.tw>
2026-08-11 07:46:20 -04:00
Zafer SEN
7b60792023 drivers: gnss: ignore padded empty GSV satellite entries
Update the NMEA0183 GSV parser to tolerate receivers that
pad the final GSV sentence with empty satellite fields.

Trim trailing satellite entries with an empty PRN before
validating the destination buffer size and processing
satellite data.

Signed-off-by: Zafer SEN <zafersn93@gmail.com>
2026-08-11 07:45:57 -04:00