Replace the three read-modify-write operations on the RX descriptor
address word with one read and write producing the same value.
Assisted-by: Claude:opus-4.8
Signed-off-by: Benjamin Cabé <benjamin@zephyrproject.org>
get_status() indexed the channel table before validating the
channel and accepted a channel equal to the channel count, reading
one past the array. Validate first with an exclusive bound like
the other entry points.
Assisted-by: Claude:fable-5
Signed-off-by: Benjamin Cabé <benjamin@zephyrproject.org>
In the memory-to-memory path the RX configuration result was
immediately overwritten by the TX call, so a failed RX descriptor
setup was reported as success.
Assisted-by: Claude:fable-5
Signed-off-by: Benjamin Cabé <benjamin@zephyrproject.org>
A priority equal to the table size passed the check and read one
entry past the priority table.
Assisted-by: Claude:fable-5
Signed-off-by: Benjamin Cabé <benjamin@zephyrproject.org>
ll_i2s_dma_busy() returned true when the transmitter was idle (TX
empty and not busy), the opposite of its name, its H7 branch and
what both callers expect. A STOP or DRAIN issued mid-transfer
disabled the stream immediately, while one issued when idle parked
the stream in STOPPING forever. Return the negated expression.
Assisted-by: Claude:fable-5
Signed-off-by: Benjamin Cabé <benjamin@zephyrproject.org>
The millisecond timeout was multiplied by the external clock
frequency in 32-bit arithmetic, overflowing for timeouts above
131 seconds and programming a much shorter period than requested.
Do the conversion in 64-bit.
Assisted-by: Claude:fable-5
Signed-off-by: Benjamin Cabé <benjamin@zephyrproject.org>
In the zero-copy TX path, nxp_wifi_internal_tx() copies the Ethernet
header into the outbuf structure but keeps the original ETH header
net_buf attached to the net_pkt. This wastes one tx_buf slot per
packet while it sits in the WMM queue waiting to be transmitted.
Under heavy TX backpressure (e.g. during roaming with continuous
traffic), this doubles the effective tx_buf consumption per queued
packet, leading to premature tx_buf pool exhaustion.
After copying the ETH header, use net_pkt_frag_del() to release the
first fragment when it contains exactly the ETH header. The payload
fragment remains attached and the cursor position is unaffected since
it already points past the ETH header.
Assisted-by: WChat:Claude
Signed-off-by: Maochen Wang <maochen.wang@nxp.com>
The counter API declares optional clock calibration ops in signed
parts-per-billion, but the Kinetis RTC counter driver did not
implement them, so counter_set/get_calibration returned -ENOSYS.
Implement them using the RTC Time Compensation Register. TCR[7:0]
configures the number of 32.768 kHz cycles per second as
(32768 - value) with value a two's-complement -128..+127, so a
positive value shortens the second and speeds the counter up,
matching the counter API sign convention. TCR[15:8] (CIR, interval
minus one) is kept at 0 to compensate every second, giving
ppb = value * 1e9 / 32768 (~30518 ppb per LSB, range ~+/-3.9M ppb).
set() rejects out-of-range values with -EINVAL and get() reports the
programmed (quantized) TCR/CIR value so a set()/get() round-trips at
the hardware resolution. The register is double buffered and safe to
write while the counter runs. Compensation counts oscillator cycles,
so the ops return -ENOTSUP when the prescaler runs from the LPO
clock.
Validated on frdm_k64f with tests/drivers/counter/counter_basic_api
(CONFIG_COUNTER_CALIBRATION=y): suite passes including the new
set/get calibration case sweeping +/-200000 ppb.
Link: K64 Sub-Family Reference Manual Rev.2 - ch44 RTC_TCR (44.2.4)
Signed-off-by: Holt Sun <holt.sun@nxp.com>
The write loop read the retained row state from digit_buf[py] but
stored the updated segment back to digit_buf[y], so only the first
row of the shadow buffer was ever updated and later partial writes
merged against stale row data. Store at the loop index.
Assisted-by: Claude:fable-5
Signed-off-by: Benjamin Cabé <benjamin@zephyrproject.org>
The HSYNC polarity was computed from the vsync-active timing
property, a copy-paste from the VSYNC line above, so a panel with
different sync polarities got the wrong HSYNC polarity. Use
hsync-active.
Assisted-by: Claude:fable-5
Signed-off-by: Benjamin Cabé <benjamin@zephyrproject.org>
flash_si32_valid_range() returns bool, but the write alignment
checks returned -EINVAL, which converts to true and marks
misaligned writes as valid. An odd size then made the write loop
read one byte past the source buffer. Return false as the other
checks do.
Assisted-by: Claude:fable-5
Signed-off-by: Benjamin Cabé <benjamin@zephyrproject.org>
The API table referenced ad405x_adc_read_async, which does not exist;
the function is adc_ad405x_read_async, so builds with
CONFIG_ADC_ASYNC failed.
Assisted-by: Claude:fable-5
Signed-off-by: Benjamin Cabé <benjamin@zephyrproject.org>
num_channels is a count and channels are used as 0-based CC indices,
but both guards used '>', letting channel == num_channels index one
element past the valid range. Use '>='.
Assisted-by: Claude:fable-5
Signed-off-by: Benjamin Cabé <benjamin@zephyrproject.org>
Valid channels are 0 to MAX31790_CHANNEL_COUNT - 1, but both checks
used '>', accepting channel 6 and addressing registers beyond the
per-channel ranges. Use '>='.
Assisted-by: Claude:fable-5
Signed-off-by: Benjamin Cabé <benjamin@zephyrproject.org>
The clock source mux update used the encoded field width (in bits)
directly as the clear mask, so only part of a multi-bit source field
was cleared and stale select bits could survive. Convert the width to
a bit mask with BIT_MASK().
Assisted-by: Claude:fable-5
Signed-off-by: Benjamin Cabé <benjamin@zephyrproject.org>
The memcpy used sizeof(pin_cfg), reading a whole pinctrl_soc_pin from
a single pinmux array element and past the end for the last pin. Use
sizeof(pin_cfg.pinmux).
Assisted-by: Claude:fable-5
Signed-off-by: Benjamin Cabé <benjamin@zephyrproject.org>
The PIN_POSEL case AND-ed the two disjoint bit masks, producing 0, so
the old POC0/POCSEL0 values were never cleared and could not be set
back to zero. OR the masks, matching the POC2/POC3 cases.
Assisted-by: Claude:fable-5
Signed-off-by: Benjamin Cabé <benjamin@zephyrproject.org>
The invalid divider-combination path returned !EINVAL, which is 0, so
rejected FRQCR combinations were reported as success without
programming the register. Return -EINVAL.
Assisted-by: Claude:fable-5
Signed-off-by: Benjamin Cabé <benjamin@zephyrproject.org>
The async completion path handed the driver data pointer to
spi_smartbond_pm_policy_state_lock_put(), which expects the device and
forwards it to pm_device_runtime_put(). Pass dev, as every other call
site does.
Assisted-by: Claude:fable-5
Signed-off-by: Benjamin Cabé <benjamin@zephyrproject.org>
The FIRC async div1 case was guarded by a misspelled
FSL_FEATURE_FSL_FEATURE_SCG_HAS_FIRCDIV1 macro that never exists, so
the clock was compiled out on every SoC and rate queries returned
-EINVAL. Use the correct feature macro name.
Assisted-by: Claude:fable-5
Signed-off-by: Benjamin Cabé <benjamin@zephyrproject.org>
The fallback condition used ||, which is always true for two different
constants, so every interrupt was forced to IOAPIC_LOW delivery and a
requested IOAPIC_FIXED mode was discarded. Use &&.
Assisted-by: Claude:fable-5
Signed-off-by: Benjamin Cabé <benjamin@zephyrproject.org>
Four functions validated the pin index with '>' against
ARRAY_SIZE(pin_pint_id), letting pin == ARRAY_SIZE read one element
past the end of the array. Use '>=', matching nxp_pint_pin_enable().
Assisted-by: Claude:fable-5
Signed-off-by: Benjamin Cabé <benjamin@zephyrproject.org>
The STM32F413/F423 PLL configuration merged the R divider and post-R
divider into one macro argument due to a missing comma, so
LL_RCC_PLL_ConfigDomain_SAI() received four arguments instead of five
and the branch did not compile when selected.
Assisted-by: Claude:fable-5
Signed-off-by: Benjamin Cabé <benjamin@zephyrproject.org>
The SPI1 rate query passed an SPI clock-source selector to
LL_RCC_GetUARTClockFreq(), returning a bogus frequency. Call
LL_RCC_GetSPIClockFreq() like the other SPI cases and the mp1/mp2
drivers.
Assisted-by: Claude:fable-5
Signed-off-by: Benjamin Cabé <benjamin@zephyrproject.org>
The APB2 timer clock computed its rate from apb1_clock while testing
the APB2 prescaler, so APB2 timers reported APB1's frequency whenever
the prescaler exceeded the threshold. Use apb2_clock, as the H7RS
branch and every sibling series driver do.
Assisted-by: Claude:fable-5
Signed-off-by: Benjamin Cabé <benjamin@zephyrproject.org>
icm40627_init() logged a failed bus check through an undeclared
'config' pointer and a nonexistent bus.bus member, breaking the build
when the driver is compiled. Point LOG_ERR_DEVICE_NOT_READY at the
underlying I2C bus device.
Assisted-by: Claude:fable-5
Signed-off-by: Benjamin Cabé <benjamin@zephyrproject.org>
The SENSOR_CHAN_DIE_TEMP case sat inside the CONFIG_MPU9250_MAGN_EN
guard, so temperature reads returned -ENOTSUP with the magnetometer
disabled even though the register is always fetched.
Assisted-by: Claude:fable-5
Signed-off-by: Benjamin Cabé <benjamin@zephyrproject.org>
The angle conversion divided by 65635 instead of the 16-bit full
scale 65535, and raw_val * 36000 overflows signed 32-bit for large
readings. Use 65535 and widen to uint32_t.
Assisted-by: Claude:fable-5
Signed-off-by: Benjamin Cabé <benjamin@zephyrproject.org>
CFG2 was written with the CFG1 bit pattern so the AGAINMAX/AGAINL
bits were never programmed, and the 128x case loaded the CFG2
register value (20) into the lux gain instead of TSL2540_AGAIN_S128
(140).
Assisted-by: Claude:fable-5
Signed-off-by: Benjamin Cabé <benjamin@zephyrproject.org>
The 2000G A3-A5 OTP addresses jumped from 0x29 to 0x30-0x32 instead
of continuing at 0x2A-0x2C, pointing at the wrong registers.
Assisted-by: Claude:fable-5
Signed-off-by: Benjamin Cabé <benjamin@zephyrproject.org>
The GPIO_INPUT branch wrote adp5585_pin_output into the direction
register, so pins requested as inputs were driven as outputs.
Assisted-by: Claude:fable-5
Signed-off-by: Benjamin Cabé <benjamin@zephyrproject.org>
The phase3 clamp tested phase0, so phase3 could overflow its one-byte
register field. Test phase3.
Assisted-by: Claude:fable-5
Signed-off-by: Benjamin Cabé <benjamin@zephyrproject.org>
uart_silabs_async_rx_buf_rsp() returned -EBUSY/-EACCES without
releasing the irq_lock taken at entry, leaving interrupts disabled.
Unlock before the early returns.
Assisted-by: Claude:fable-5
Signed-off-by: Benjamin Cabé <benjamin@zephyrproject.org>
eusart_async_rx_buf_rsp() returned -EBUSY/-EACCES without releasing
the irq_lock taken at entry, leaving interrupts disabled. Unlock
before the early returns.
Assisted-by: Claude:fable-5
Signed-off-by: Benjamin Cabé <benjamin@zephyrproject.org>
The enum index guard used '>' against ARRAY_SIZE, allowing a read one
element past the end of baud_settings[]. Use '>='.
Assisted-by: Claude:fable-5
Signed-off-by: Benjamin Cabé <benjamin@zephyrproject.org>
The button callback runs only for buttons whose status bit is set but
reported value 0, so presses were never delivered. Report 1 like the
renesas_rx_ctsu driver.
Assisted-by: Claude:fable-5
Signed-off-by: Benjamin Cabé <benjamin@zephyrproject.org>
The reconfigure path detected an auto_sr change but programmed the
old value, so the attribute never took effect. Pass the new value.
Assisted-by: Claude:fable-5
Signed-off-by: Benjamin Cabé <benjamin@zephyrproject.org>
The dual-frequency assertion placed '== 0' inside the DT_INST_PROP
property-name argument. Move the comparison outside the macro call,
matching the assertion below it.
Assisted-by: Claude:fable-5
Signed-off-by: Benjamin Cabé <benjamin@zephyrproject.org>
Replace fixed retry polling (~500 us) with WAIT_FOR() and a configurable
idle timeout defaulting to 1 s, so slow PHY bring-up on some platforms
can complete before read/write operations fail with -ETIMEDOUT
Signed-off-by: Venkatesh Odela <venkatesh.odela@amd.com>
Default to the larger MTU when using a nRF93M1, the default size fails
to boot `samples/net/cellular_modem` due to dropped frames.
Signed-off-by: Jordan Yates <jordan@embeint.com>
Move the PPP instance pointer from the `struct modem_cellular_data`
object to `struct modem_cellular_config`. The pointer is automatically
discovered in the `MODEM_CELLULAR_DEFINE_INSTANCE` macro through
`&MODEM_CELLULAR_INST_NAME(ppp, inst)`, which works for all in-tree
modems.
As a result, there are no longer any fields in
`struct modem_cellular_data` that are set at compile time. This saves
~4kB on ROM (for nRF93M1) as the variable no longer needs to exist in
`.data`.
Signed-off-by: Jordan Yates <jordan@embeint.com>
Move the specification of the chat delimiter and filter strings to the
vendor configuration strings. This is a step towards removing all
compile time field setting of the `struct modem_cellular_data` object
in drivers.
Signed-off-by: Jordan Yates <jordan@embeint.com>
The `lex10q1` driver was merged without any tests, and therefore no
longer compiles. Fix the driver, and add tests.
Signed-off-by: Jordan Yates <jordan@embeint.com>
Add AT+QENG="servingcell" to the Quectel EG25-G periodic script and decode
the LTE serving-cell report into the generic network-status event, so
consumers receive cell identity (MCC/MNC/CI/PCI/TAC), EARFCN, band and
RSRP/RSRQ rather than only registration state and RSSI.
The handler fills struct cellular_evt_network_status and reports it via
modem_cellular_emit_network_status(). Only the LTE report is decoded;
other radio access technologies use a different field layout and a shorter
report (state SEARCH/LIMSRV) is ignored via an argument-count guard.
Signed-off-by: Paulo Santos <pauloxrms@gmail.com>
Route the nrf93m1 %BCINFO handler through
modem_cellular_emit_network_status() so the periodic poll raises
CELLULAR_EVENT_NETWORK_STATUS_CHANGED only when the serving cell differs
from the last report.
Signed-off-by: Paulo Santos <pauloxrms@gmail.com>
Cache the last reported serving-cell status and add an optional
get_network_status driver op plus cellular_get_network_status(), so it can
be read on demand rather than only through the
CELLULAR_EVENT_NETWORK_STATUS_CHANGED callback. The snapshot is returned
under the API lock; -ENODATA before the first report or after a
registration change until the next poll, -ENOSYS where unimplemented.
modem_cellular_emit_network_status() stores the latest status and emits the
event only when it changed, ignoring signal quality (rsrp/rsrq) so periodic
pollers do not re-fire it on signal fluctuation. The cache is dropped on a
registration change so a stale serving cell is not reported after
re-registering.
Signed-off-by: Paulo Santos <pauloxrms@gmail.com>
Add an optional `period_ms` argument to the `read` command of adc shell
that makes the `read` command periodcially read and print until any key is
pressed.
Signed-off-by: Aric Radzin <aric.radzin@gmail.com>