Supply the Compute core's half of the framework: the resource map for
SLEEPCON0, the power_domain describing CPU0 (the VDD2 rails, the XIP
hand-over hooks and the SYSCON0 DSP stall) and power_mode_desc entries for
deep sleep and deep sleep retention. Both entry points call
power_enter_common(), so this module contributes facts only.
The map is where this domain's SLEEPCFG layout is stated. Most of its
entries are shared modules that only power down once both SLEEPCONs have
voted them down, which is what lets the Sense core keep running while
Compute sleeps.
Note what the keep sets do not contain. Neither mode holds up anything on
the Sense core's account -- not sense_main_clk, not comn_main_clk, not FRO2
and not CPU1's SRAM partitions. Every one of those has a vote field in both
SLEEPCONs or both PMCs, and the PMC ANDs the two cores' power-down votes
(RM 27.3.2.2), so a keep vote from CPU0 would override whatever CPU1
decides about a resource CPU0 is not using -- which is what RM 12.5.2 Table
167 forbids. CPU1 casts its own run-bank votes for what it runs from. What
CPU1 has no field for at all is the one case CPU0 must cover, and that
arrives at entry through peer_needs, filtered by res_vote_exclusive.
Two shared resources are claimed here, and they are not exceptions to that
rule: they are resources CPU0 genuinely uses itself, and CPU1 goes on
voting both of them down.
* VDDN_COM, through COMPUTE_KEEP_XIP_RES, when the image is XIP. CPU0 then
fetches from XSPI flash, which sits in that domain, so letting it reach
retention across a window that returns brings CPU0 back to a flash
controller and an external device that have both lost their configuration
-- and the fetch that discovers it, along with the fault handler it would
vector to, is itself in flash. power_xip_resume() puts the XSPI instances
back the way it found them, but only the domain staying powered makes
that restore mean anything. comn_main_clk, which clocks the same block,
is not claimed with it: the clock comes back from the run bank early
enough that the first fetch is already clocked. A non-XIP Compute image
drops the claim.
* Whatever feeds the PLLs the modes keep, through the new res_clock_tree
hook. CLKCTL2 selects each PLL's reference between FRO1_DIV8 and the
system oscillator, and the board picks, so compute_res_clock_tree() reads
the select rather than assuming one; a PLL kept powered with its
reference gone comes back with no input and leaves CPU0 without a main
clock.
Both gaps were invisible while an earlier revision had CPU0 casting keep
votes on CPU1's behalf: those proxy votes happened to cover CPU0's own
needs. Removing them is what made the two claims necessary, and each is now
stated where the reason for it lives.
Two details are specific to Compute, both about the power-down-ready
handshake SLEEPCON waits for before letting the PMC drop a clock:
* FRO0 and FRO1 have control bits in SLEEPCON0 only, so no other domain
can hold them up and their ready really does arrive. Clear the ignore
bits so SLEEPCON waits for it. A clock kept alive never powers down, so
its bit is left untouched.
* FRO2 and LPOSC are shared with Sense and arbitrated between the two
domains, so their ready may never arrive. Ignore it -- but only when
Compute is the first domain going down (PMC0 STATUS DSSENS clear); if
Sense is already in deep sleep it has released its vote and the
handshake completes on its own.
Signed-off-by: Zhaoxiang Jin <Zhaoxiang.Jin_1@nxp.com>
The two CM33 cores enter the same family of low-power modes but differ in
which PMC/SLEEPCON block they drive, which rails they may collapse and
which resources they must retain. Writing that out per core duplicates the
entry sequence and lets the copies drift. Describe the differences as data
instead and keep exactly one copy of the sequence.
A mode is described by what it needs, not by the register bits that encode
it:
enum power_resource one scalar per thing that can be powered
struct power_request the set of resources a mode needs
res_deps[] resource -> the resources it depends on
power_resolve() closes a request over res_deps
power_res_map[] resource -> (register, mask), per domain
power_commit() one loop, one polarity flip
power_resources.h names the resources and the request type;
power_resources.c holds res_deps[] and power_resolve(), so the RM 31.2 /
Table 329 dependency rules are stated once and an illegal combination is
unrepresentable rather than repaired after the fact. power_regmap.h holds
the register enumeration, the PWR_MAP() helper and the PDSLEEPCFG0/1 half
of the map, which is shared between the domains: PMC0 and PMC1 are two
slots of one block, so the two cannot drift apart on it.
power_domain.h defines struct power_domain for the per-core facts (resource
map, SLEEPCON rail, LDO vsel mask, XIP and DSP-stall hooks, regulator ops)
and struct power_mode_desc for the per-mode facts (full-DSR, the requested
resources, PMIC mode). Which PMC and SLEEPCON instance a core drives is not
one of those facts: a core's CMSIS device header defines only its own
instances, so SOC_PMC / SOC_SLEEPCON are macros selected by the domain
Kconfig symbol -- the same symbol CMakeLists uses to pick which domain
module to compile -- rather than fields every domain would fill with the
only legal value.
power_common.c implements power_enter_common(dom, mode). One loop over
enum power_resource projects the resolved request onto SLEEPCFG and
PDSLEEPCFG0-5, voting down every resource the request does not name as
RM 31.5.2 requires -- a core that leaves a shared resource's bit at 0 to be
safe defeats the other core's power-down -- with the "1 means powered down"
inversion happening once, in that loop. Regulator programming goes through
power_regulator_ops, defaulting to power_ldo_regulator_ops, so the planned
PMIC supply can be added without touching either domain. The request is
gathered by power_keepalive_collect(), which also adds what no individual
mode should have to remember:
* the SLEEPCON rail of RM 31.3.3;
* LPOSC, for every mode that returns. LPOSC clocks the PMC itself, so it
is what steps the power-up sequence a wake-up event kicks off. Its vote
field is in both SLEEPCONs and the PMC ANDs the two, so when neither
domain is clocking anything from it both vote it down and it really goes
away -- and then no wake-up event can bring either core back, whatever
else was kept.
It is not a resource one domain holds up for the other; both need it to
return at all, so both claim it and the aggregate holds. DPD and FDPD are
excluded: they come back through a reset the PMC drives off its own
always-on path;
* whatever the board's clock tree makes the request imply, through the new
optional res_clock_tree hook on struct power_domain. A kept PLL is the
case that needs it -- the PLL is only useful if its reference is still
there, and which clock that is was chosen by the board. The hook runs
before the dependency closure, so what it returns is closed over too, and
it reads clock selects rather than power votes: a select is a fact about
how the board wired itself up at boot, while the votes are what this code
is in the middle of deciding.
That function is also the seam where device runtime PM will later
contribute its own requirements.
A following commit hooks the sequence into pm_state_set(); the poweroff
modes are layered on after that.
Signed-off-by: Zhaoxiang Jin <Zhaoxiang.Jin_1@nxp.com>
The XSPI controller hosting an XIP image sits in the V2COMP domain, which
collapses for both deep sleep and deep sleep retention. Without a
hand-over the first instruction fetch after wakeup reads a dead XSPI and
hardfaults.
Add power_xip_suspend() / power_xip_resume(): quiesce the flash, drop the
caches that lose their contents and tear the XSPI down before the window,
then rebuild it on resume ahead of the next fetch. Caches are disabled
inner level first, so XCACHE write-backs still drain through a live XSPI,
and re-enabled outer level first. The reset sequence follows the SDK's
XSPI_ResetSfmAndAhbDomain(), including its six-NOP settling delays. Which
interface hosts the image is resolved at build time from the XSPI nodes'
devicetree windows, accepting either the secure or the non-secure alias.
Everything runs from RAM, since the flash it operates on is the one the
code would otherwise execute from. These are pure helpers; a following
commit wires them into the low-power entry path.
SOC_MIMXRT7XX_PM_XIP_HANDOVER is internal, defaulting on for XIP builds
(FLASH_MCUX_XSPI_XIP) with PM.
Signed-off-by: Zhaoxiang Jin <Zhaoxiang.Jin_1@nxp.com>
An SRAM partition has to stay powered across a low-power window exactly
when the linked image occupies it, and what the image occupies is fixed at
link time. Compute that set as a compile-time constant from devicetree
rather than carry a hand-maintained mask that silently drifts from the
memory map.
The main SRAM is one contiguous 7.5 MB window of 30 partitions P0-P29,
each powered through PMC PDSLEEPCFG2 (array) and PDSLEEPCFG3 (periphery)
where bit n is partition Pn. Occupancy comes from DT_CHOSEN(zephyr_sram),
the RAM linker region holding data, bss, noinit, stacks, the kernel heap
and the libc malloc arena -- so the result does not depend on runtime
allocation -- from DT_CHOSEN(zephyr_flash), which holds text and rodata
and is off-chip on an XIP build but on-chip for a core that executes from
SRAM, plus every status-okay zephyr,memory-region node inside the window.
Mapping an address to a partition takes care. The window is mirrored at
four aliases sharing their low 24 bits, so those bits give the offset once
an address is known to be on-chip; but deciding on-chip needs more,
because off-chip memories declared as memory-regions collide there --
PSRAM at 0x0800_0000 shares the top nibble of the 0x0000_0000 alias and
PSRAM2 at 0x7000_0000 masks to offset 0. Each address is therefore tested
inside its 256 MB alias slot, requiring both a top nibble of 0-3 and an
in-window offset. An off-chip zephyr,flash falls out of the union by the
same test, so the XIP case needs no special casing.
This covers everything the linker places, not a raw write to a partition
the image never declared; such a partition can lose power, so an
application using one must declare it as a zephyr,memory-region. The
header is standalone with no PM dependency; the power framework and the
board's second-core boot path start consuming it in following commits.
Signed-off-by: Zhaoxiang Jin <Zhaoxiang.Jin_1@nxp.com>
The power-domain-soc-state-change node in the cm33_cpu0 devicetree needs
the generic power domain driver behind it, but POWER_DOMAIN has no default,
so the driver is not built and the node is silently inert: the devicetree
describes the power cycling that Deep Sleep Retention requires and nothing
acts on it.
Default POWER_DOMAIN to y whenever device PM is on, the same way
soc/nxp/rw does.
Signed-off-by: Zhaoxiang Jin <Zhaoxiang.Jin_1@nxp.com>
A dual-core build shares headers between the two images, in particular
the second core's generated image header, but that directory was not on
the include path so the includes did not resolve.
Add CONFIG_SECOND_CORE_MCUX_REMOTE_DIR to the SoC include directories
when it is set.
Signed-off-by: Zhaoxiang Jin <Zhaoxiang.Jin_1@nxp.com>
Adds initial SoC-level support for the Microchip
PIC32CK SG series, including SoC definition files.
Signed-off-by: Hariharan Arumugam <hariharan.arumugam@microchip.com>
Add self-contained QEMU virtual SoCs for the AURIX tc3x (TC1.6.2P)
and tc4x (TC1.8P) cores under a single soc/qemu/tricore directory,
selected per board via SOC_QEMU_TC3X / SOC_QEMU_TC4X. This lets the
architecture be exercised under qemu-system-tricore without any
silicon or HAL dependency; ENDINIT and the watchdog are handled by
the arch weak stubs, which QEMU does not model.
Signed-off-by: Parthiban Nallathambi <parthiban@linumiz.com>
The ADSP family and both series symbols select
CACHE_CAN_SAY_MEM_COHERENCE unconditionally, but that symbol is only
defined under CACHE_MANAGEMENT, so a build that turns cache management
off aborts on an unsatisfiable select. Guard the three selects with the
dependency they need.
Signed-off-by: Benjamin Cabé <benjamin@zephyrproject.org>
Assisted-by: Claude:opus-5
The CAT1C PDL flash driver (cy_flash_srom.c) places its SROM scratch
buffers with CY_SECTION_SHAREDMEM, which resolves to
__attribute__((section(".cy_sharedmem"))). The generic Cortex-M linker
script used by CAT1C (xmc7200) has no output section for ".cy_sharedmem",
so once that source is built the section is an orphan. Under the default
ORPHAN_SECTION_WARN the link still succeeds, but the linker places this
must-be-SRAM scratch into read-only flash, so the first write faults at
runtime rather than producing a build error.
Anchor it in the noinit region via zephyr_linker_sources(NOINIT), the
same way soc/infineon/cat1a already places its .cy_sharedmem buffers.
The buffers are write-before-read SRAM scratch, so noinit (NOLOAD) is
correct and needs no zeroing or load image.
Assisted-by: AI (GitHub Copilot)
Signed-off-by: Bill Waters <bill.waters@infineon.com>
Legacy GPPI helper has been removed with nrfx 4.6.
Signed-off-by: Adam Kondraciuk <adam.kondraciuk@nordicsemi.no>
Signed-off-by: Michał Stasiak <michal.stasiak@nordicsemi.no>
Setting symbol default value without 'configdefault', or without
explicit 'if' checks of dependencies, results in dependency weakening.
In this case, CACHE_MANAGEMENT is redefined and set to the given
default value even if dependencies D/ICACHE are not enabled.
Also remove CACHE_MANAGEMENT enabling from ARC-SEM and ARC-EM as they do
no actually have cache.
Signed-off-by: Abderrahmane JARMOUNI <git@jarmouni.me>
AM13E shares the IOMUX/PINCM interface with MSPM0. Add a thin
pinctrl_soc.h wrapper that includes the MSPM0 common header.
Signed-off-by: Aman Lachhiramka <a-lachhiramka@ti.com>
Add support for Six301 radio crypto. The low-level crypto operations
needed by the radio are performed in the HAL, and require a glue
layer to get access to OS primitives. Implement this glue in
modules/hal_silabs.
Introduce a soc-specific crypto management driver that exposes the
crypto peripherals from devicetree and implements device lifecycle
management.
Signed-off-by: Aksel Skauge Mellbye <aksel.mellbye@silabs.com>
Rename the Kconfig option to SOC_VENDOR_SILABS_DEVICE_IS_MODULE
to match the guidelines requiring all Kconfig symbols in soc/
to have specific prefixes.
Signed-off-by: Aksel Skauge Mellbye <aksel.mellbye@silabs.com>
Rename to SOC_FAMILY_SILABS_S2_XG* to reflect that they are
sub-options for the silabs_s2 SoC family, abiding by the
naming policy for Kconfig options in soc/.
Signed-off-by: Aksel Skauge Mellbye <aksel.mellbye@silabs.com>
Rename the Kconfig option to SOC_VENDOR_SILABS_HAS_RADIO to
match the guidelines requiring all Kconfig symbols in soc/
to have specific prefixes.
Signed-off-by: Aksel Skauge Mellbye <aksel.mellbye@silabs.com>
Since this driver can and will also be used for series 1, move it one level
up into the respective if-guard.
Signed-off-by: Michael Zimmermann <michael.zimmermann@sevenlab.de>
Signed-off-by: Aksel Skauge Mellbye <aksel.mellbye@silabs.com>
The STM32F730 series is very similar to STM32F723.
The main difference is the smaller flash memory size.
Signed-off-by: Eve Redero <eve.redero@gmail.com>
The CMake code was hardcoding a filename, which it should never
have done. This moves the configuration to Kconfig instead, where
it can be freely updated by users
Signed-off-by: Jamie McCrae <jamie.mccrae@nordicsemi.no>
__NRF_TFM__ is defined out of tree, so soc.c selects the secure or
non-secure address of a peripheral from NRF_APPLICATION and __ZEPHYR__
instead. soc.h still used __NRF_TFM__ to pick the address of the antenna
switch control register, leaving the two files disagreeing on how a
secure build is identified.
Use !defined(__ZEPHYR__) for the same purpose. The selection is
unchanged in all three cases: a TF-M build does not define __ZEPHYR__
and takes the secure address; a secure Zephyr build does not define
CONFIG_TRUSTED_EXECUTION_NONSECURE and also takes the secure address;
a non-secure Zephyr build defines both and takes the non-secure
address.
Signed-off-by: Chaitanya Tata <Chaitanya.Tata@nordicsemi.no>
Assisted-by: Claude:claude-opus-5
wicr_setup() compares each WICR word against its intended value and
skips the write when they already match, to limit MRAM wear. The
comparison was done before the CONFIGNVR page was unlocked, but the page
permissions gate reads as well as writes, so every read returned
0xFFFFFFFF and no word ever matched. All ten words were rewritten to
MRAM on every boot.
Unlock the page before the loop so the comparison sees the stored
contents. Also wait for MRAMC to report ready before reading a written
value back and before locking the page again.
Signed-off-by: Chaitanya Tata <Chaitanya.Tata@nordicsemi.no>
Assisted-by: Claude:claude-opus-5
Before starting communication with the Wi-Fi core, the antenna switch
(ANTSW) needs to be steered towards WLAN. This has to happen before the
LMAC processor is kickstarted in soc_early_init_hook(), which runs before
the GPIO driver is available (and, for TF-M, in the secure image), so
GPIO hogs or the GPIO driver cannot be used here.
Describe the steering line in devicetree through a new
nordic,nrf71-wifi-antsw node instead of hardcoding the pin, and drive it
in soc_early_init_hook() using NRF_DT_GPIOS_TO_PSEL with the nrf_gpio
HAL. Going through the HAL keeps the access on the P0 alias that matches
the build's security state, so it works in both secure and non-secure
builds.
The steering is sequenced after the antenna switch is powered
(pwr_antswc) and before the Wi-Fi core is kickstarted. A build assertion
enforces that steering is only configured when pwr_antswc is present, so
the switch is never steered without being powered.
Signed-off-by: Chaitanya Tata <Chaitanya.Tata@nordicsemi.no>
Assisted-by: Claude:claude-opus-4.8
The antenna switch power (pwr_antswc, via the PWR_ANTSWC register) was
enabled after wifi_setup() had already kickstarted the Wi-Fi core. Move
it ahead of the Wi-Fi boot so the switch is powered before the core
starts using it.
Signed-off-by: Chaitanya Tata <Chaitanya.Tata@nordicsemi.no>
Assisted-by: Claude:claude-opus-4.8
lld reports its synthetic .symtab, .strtab and .shstrtab sections as
orphans when linking with --orphan-handling=warn, which is the default
LINKER_ORPHAN_SECTION_WARN setting. Give them output section
descriptions under CONFIG_LLVM_USE_LLD, as the arm, arm64, riscv and
x86 linker scripts already do.
Assisted-by: Claude:claude-fable-5-1
Signed-off-by: Anas Nashif <anas.nashif@intel.com>
Add the PM_STATE_SUSPEND_TO_RAM case to pm_state_set, entering via
arch_pm_s2ram_suspend with rp2350_s2ram_off as the callback: power down
the domains via POWMAN (keeping XIP cache and SRAM bank0/1 on) and
execute WFI. On resume, pm_state_exit_post_ops clears the debug-power
override set right before the power-down (it must be cleared on the
resume path, since a real wake resumes into arch_pm_s2ram_suspend()'s
caller rather than returning from rp2350_s2ram_off(), so clearing it
there would never run) and reconfigures the clocks.
SysTick is powered down along with the rest of the switched core, so
hook the RP2350 up to the generic system-timer low-power companion
interface (CONFIG_SYSTEM_TIMER_LPM_COMPANION_HOOKS) instead of
reimplementing timer restart locally: z_sys_clock_lpm_enter() arms a
POWMAN alarm for the requested timeout and z_sys_clock_lpm_exit()
reports the elapsed time from the POWMAN timer, both added to
rp2350_powman.c. Selecting CONFIG_SYSTEM_TIMER_RESET_BY_LPM makes the
cortex_m_systick driver reprogram SysTick from scratch on exit, so no
SoC-specific restart hook is needed.
Clock restoration is delegated to clock_control_rpi_pico_reconfigure(),
factored out of the rpi_pico clock_control driver's init function rather
than reimplementing a fixed XOSC/PLL_SYS/clk_ref/sys/peri sequence in
power.c: this restores every devicetree-declared clock at the board's
actual configured rates, not just a hardcoded subset, and keeps a single
source of truth between cold boot and S2RAM resume.
Signed-off-by: Gabriel Germano <gabriel.lucasgermano@gmail.com>
Add rp2350_powman.{h,c}: a SoC-level POWMAN wakeup/timer API so
applications no longer touch POWMAN registers directly. It calibrates
the LPOSC against the frequency counter (the RP2350 LPOSC is ~28 kHz,
not the 32768 Hz assumed by the pico HAL, which would make the AON
timer alarm fire ~8x late), selects it as the 1 kHz tick source
(idempotently, so the timer count is not reset each entry), arms
alarm/GPIO wakeups (GPIO with a chip-range guard), decodes the last
wakeup source, and reports whether a switched-core power-down
occurred.
Signed-off-by: Gabriel Germano <gabriel.lucasgermano@gmail.com>
Add pm_s2ram_mark_set/pm_s2ram_mark_check_and_clear, which mark the
POWMAN BOOT0..3 registers with the resume trampoline's boot vector in
RAM, letting the bootrom branch there after SWCORE is powered back up
instead of doing a cold boot. Enable HAS_PM_S2RAM_CUSTOM_MARKING and
build the file when CONFIG_PM_S2RAM is enabled. Also restore the core
CPU state that the SWCORE power-down clears before the (FP-active)
context restore: besides VTOR, re-enable all coprocessors (FPU
CP10/CP11, GPIO CP0, CP4) via runtime_init_per_core_enable_coprocessors,
and rebuild the exception and IRQ priorities via
z_arm_exc_setup()/z_arm_interrupt_init(). Without this the kernel
faults non-deterministically when resuming from deep sleep.
Add a raspberrypi,pico-powman devicetree binding and node so the
POWMAN base address used for the BOOT0..3/SCRATCH0 registers comes
from devicetree, matching this SoC family's convention, rather than
being hardcoded. The node intentionally overlaps the existing vreg
node's address: RP2350 folds VREG_AND_CHIP_RESET into POWMAN, unlike
RP2040, so the two nodes describe the same physical block from
different logical angles. Access those registers via
sys_write32()/sys_read32() rather than raw volatile pointer
dereferences.
Signed-off-by: Gabriel Germano <gabriel.lucasgermano@gmail.com>
Implement pm_state_set/pm_state_exit_post_ops for the RUNTIME_IDLE and
SUSPEND_TO_IDLE states via a plain WFI with IRQs disabled during
sleep. Enable HAS_PM and build power.c when CONFIG_PM is enabled.
Gate HAS_PM on ARM, since this PM code depends on CMSIS and ARM
intrinsics and would not build for the Hazard3 (RISC-V) variant of
this SoC series.
Signed-off-by: Gabriel Germano <gabriel.lucasgermano@gmail.com>
Add tpm0, tpm1, and tpm2 nodes to the KL25Z base devicetree and
configure the clock initialization in the SoC setup code to allow
PWM functionality using the kinetis-tpm driver.
Signed-off-by: Gabriel Ivo <gabriel.bozi@usp.br>
The eSPI virtual UART channel cannot receive host traffic once the fast
clock (FMCLK) to the eSPI_SIF module stops, so the chip drops incoming
data as soon as it enters Sleep or Deep Sleep. Setting the
ESPI_FMCLK_ENSLP field of ENSLP_CTL keeps that clock running in those
states.
Add the fast-clk-to-espi-sleep-support property to describe the series
that implement the field, set it on npcx4, and gate the register write
on the new CLOCK_CONTROL_NPCX_ESPI_FMCLK_IN_SLEEP option, which is only
selectable when the property is present and both ESPI_PERIPHERAL_UART
and PM are enabled.
Assisted-by: Copilot:claude-opus-5
Signed-off-by: Jun Lin <CHLin56@nuvoton.com>
The PMC register at offset 0x003 is named ENSLP_CTL (Enable in Sleep
Control) in the datasheets; the struct field and its bit macros carried
the ENIDL_CTL name, which belongs to no register in this block. Rename
the field and the NPCX_ENIDL_CTL_* macros in both the npcxn and npckn
variants.
Out-of-tree code uses the old names, so keep them working: ENIDL_CTL
becomes a second member of an anonymous union covering the same byte,
and the bit macros get aliases. No functional change.
Assisted-by: Copilot:claude-opus-5
Signed-off-by: Jun Lin <CHLin56@nuvoton.com>
With USE_SWITCH=y, a context restore can be preempted by an
interrupt. This interrupt may switch contexts, pushing a second
stack frame on top of the frame that was part-restored.
If this frame is later restored by a cooperative
arm_m_switch call, and this restore is preempted, a third frame
is pushed on top. In the kernel.memory_protection.sys_sem test,
the stars happen to align so that the idle thread overflows its
stack.
Increasing the idle stack size unblocks CI. A more long term
fix will be needed later.
Signed-off-by: Laurie Fay <Laurie.Fay@arm.com>
Derive SYS_CLOCK_HW_CYCLES_PER_SEC from devicetree.
This allows to override the system clock frequency.
Signed-off-by: TOKITA Hiroshi <tokita.hiroshi@gmail.com>
cavstool.py needs Python, which is often unavailable on products, and
running it without -l (log-only mode) takes over the audio PCI device
(unbinding the kernel driver, driving HDA/IPC directly) to load
firmware, none of which is wanted when the goal is just to observe the
mtrace debug-window log slot on a device where the firmware is already
being booted and driven by the normal kernel driver, e.g. to catch a
crash or hang while a library/module is being loaded.
mtracetool is a small, dependency-free C program that only mmaps BAR4
read-only and polls the debug window descriptor table for the mtrace
slot, roughly equivalent to cavstool.py -l but without the Python
dependency, so it can run alongside a live driver/firmware stack. It
builds as a static binary, is easy to push to any test rig (including
via adb to a rooted Android device) and dumps the slot's full current
content the moment it's found before following newly appended bytes
live, re-arming itself if the slot disappears across a DSP reset.
Note that with the default CONFIG_LOG_MODE_DEFERRED, log messages only
reach the mtrace window once a background thread later flushes them, so
capturing a genuine DSP deadlock/hang (as opposed to a clean panic) may
need CONFIG_LOG_MODE_IMMEDIATE=y as well, since a hung thread can strand
the most recent log lines in an internal queue where no amount of
external polling can see them. This is documented in the tool's built-in
help and header comment.
Signed-off-by: Peter Ujfalusi <peter.ujfalusi@linux.intel.com>
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Add a -m/--mtrace option to cavstool.py to observe logs produced by the
mtrace logging backend (log_backend_adsp_mtrace.c), similar to how -l
shows the winstream backend (log_backend_adsp.c) output.
The mtrace backend writes to a debug-window slot organized as a ring
buffer with a host read pointer and a DSP write pointer. The reader is
strictly passive: it tracks its own cursor and never advances the host
read pointer, leaving the primary mtrace client (running on the host
CPU) in full control of when a log has been consumed and the buffer can
be reused. This allows cavstool.py to be run in parallel with the Linux
kernel SOF driver on the same system without disturbing it. This is
especially useful to debug early boot failures.
Like -l, the option does not load firmware, unload the running driver,
or drive IPC.
Signed-off-by: Kai Vehmanen <kai.vehmanen@linux.intel.com>
After rename of TFM_NRF_MRAMC_SERVICE to SOC_NRF7120_TFM_MRAMC_SERVICE
in trusted firmware module, the CMake option passed to TF-M build was
not updated. This commit passes the updated cmake option.
Updated to match the change in TF-M module:
f8772fc
Signed-off-by: Robert Robinson <robert.robinson@nordicsemi.no>
Add #ifdef for ll_pwr_set_wake_up_line_polarity_* functions that don't
exist on F1-like power controller.
This fixes a compilation and CI issue.
Signed-off-by: Guillaume Gautier <guillaume.gautier-ext@st.com>
__rodata_region_end closed before the linker-collected rom
sections, so device API structures, which live in an iterable
rom section, fell outside it. arch_buffer_validate() accepts a
read only within that region, so passing a pointer into a driver
API structure to a syscall was rejected and the calling thread
killed.
Assisted-by: Claude:opus-5
Signed-off-by: Sylvio Alves <sylvio.alves@espressif.com>
Enable RISCV_SOC_SYSCALL_CLOSE_ECALL on the esp32c5 hpcore. A
PMP stack guard fault taken while the syscall ECALL exception is
open is reported asynchronously on this core and locks it up,
so a user-mode application that drives a granted service deep
enough resets the chip instead of being killed.
With the exception closed before the syscall body runs, the same
overflow is reported as a stack overflow and only the offending
application is reclaimed.
Assisted-by: Claude:opus-5
Signed-off-by: Sylvio Alves <sylvio.alves@espressif.com>
Enable RISCV_SOC_HAS_SYSCALL_INTMASK and
RISCV_USER_STRING_NLEN_VALIDATE on the esp32c5 hpcore and provide
soc_syscall.h with the SOC_SYSCALL_INTMASK macro. It raises the
CLIC preemption threshold (mintthresh) to its maximum on syscall
entry so no interrupt is taken while the ECALL exception is
open, avoiding the lockup reset, while leaving mstatus.MIE set
as the kernel expects. The per-context threshold is restored on
exit by the SoC context save/restore hooks, so the default is
gated on those hooks and on switching through ECALL.
Assisted-by: Claude:opus-5
Signed-off-by: Sylvio Alves <sylvio.alves@espressif.com>
Disable the CPU access-permission filter in hardware_init(). It
gates the CPU's own bus access per security mode and defaults
the user-mode permissions to deny, so a user thread fetching
from flash is silently blocked with no architectural fault.
Save the CLIC mcause and mintthresh per thread in the SoC
context hooks and, on restore, force mcause.interrupt to match
the entry type of the trap being returned from, clearing mpil
for exception-saved frames. Writing the saved mcause back
verbatim leaves a mismatched mret whenever a thread interrupted
in user mode is resumed from an ecall-entered trap, after which
the next trap from user mode locks the core up (CPU_LOCKUP).
Two busy user threads under time slicing reproduce it within a
second; the same entry-type matching already fixes it on the
esp32p4.
Assisted-by: Claude:opus-5
Signed-off-by: Sylvio Alves <sylvio.alves@espressif.com>