Commit graph

126,787 commits

Author SHA1 Message Date
BUDKE Gerson Fernando
0ddb8e40f2 lib: json: Fix escape sequence unescaping during decoding
Fix the JSON library to properly unescape sequences during decoding.
Previously, escape sequences like \n, \t, \" etc were validated but
not converted back to their actual character representations during
decoding, causing backslash duplication with each encode/decode cycle.

This fix modifies decode_string_buf() to properly handle escape
sequence unescaping and ensures strings maintain their original
content across multiple encode/decode cycles.

Signed-off-by: BUDKE Gerson Fernando <gerson.budke@leica-geosystems.com>
2025-11-08 10:22:50 +02:00
Wojciech Jablonski
70961e26be drivers: mm: Fix vm region range check
Checking virtual range is incorrect because size + 1 addresses are
considered: size + starting address (that is also part of an
allocation). Hence the last address of the range is impossible to map

Signed-off-by: Wojciech Jablonski <wojciech.jablonski@intel.com>
2025-11-08 10:22:09 +02:00
Troels Nilsson
22fe7680f8 Bluetooth: Controller: Various fixes for CIS termination handling
Handling of CIS termination had several issues, most notably:

- it depended on allocating a termination node from the general rx
  node pool, causing asserts if the pool was exhausted
- CIS established events was not always generated when required,
  potentially causing CIS Centrals to get stuck without being able
  to create any new CISes
- Cancelling a CIS Create procedure only worked correctly if the
  CIS Create was currently active and happened to belong to the
  same CIS
- CIG state handling often (always?) assumed a CIG with only one CIS

ll_conn_iso_stream now has a dedicated termination node, same as
ll_conn and ll_sync_iso_set

LLCP statemachine for Cis Create procedure has been reworked to ensure
a notification node for CIS Established is available as early as possible.
In addition, it should now always be sent when needed

Introduced ull_central_iso_all_cises_terminated() to check if all CISes
in a CIG has been terminated (or not created yet) - which is now
used for updating the CIG state

ull_cp_cc_cancel() now takes the CIS to cancel as an argument so
it doesn't end up canceling an entirely different CIS Create procedure;
In addition it now works for queued procedures as well

Flushing a (central) CIS Create procedure in LLCP will now properly
generate a CIS Established event (with an error)

Signed-off-by: Troels Nilsson <trnn@demant.com>
2025-11-08 10:22:00 +02:00
Zhaoxiang Jin
6a0ddc3ca1 west: update hal_nxp to fix I2S run issue on MCXN947
Rollback SAI driver to fix I2S issues on MCXN947 in Zephyr.

Signed-off-by: Zhaoxiang Jin <Zhaoxiang.Jin_1@nxp.com>
2025-11-08 10:21:48 +02:00
Jan Behrens
1ec2eae70e boards: st: OpenOCD Fix for WB55 Based Boards
Fixes the openocd configuration for nucleo_wb55rg, stm32wb55mm_dk
and stm32wb55mmg.

Signed-off-by: Jan Behrens <jan.behrens@navimatix.de>
2025-11-08 10:21:38 +02:00
Declan Snyder
92fe40405e soc: nxp: rt118x: Move container header in tree
Instead of gluing to the one in the HAL which is not very flexible to
configure, define the container header in the zephyr SOC code. This
fixes the bug of CONFIG_NXP_FLEXSPI_ROM_RAMLOADER not working.

Signed-off-by: Declan Snyder <declan.snyder@nxp.com>
2025-11-08 10:21:28 +02:00
Pieter De Gendt
96d0957378 tests: nvmem: Test _OR for missing cells
Add a test case where missing cells result in empty structs.

Signed-off-by: Pieter De Gendt <pieter.degendt@basalte.be>
2025-11-08 10:21:19 +02:00
Pieter De Gendt
71a5f1d08e include: zephyr: nvmem: Fix _OR macros
Checking if a node has nvmem-cells is not sufficient, we need to check if
the idx or name exists.

Signed-off-by: Pieter De Gendt <pieter.degendt@basalte.be>
2025-11-08 10:21:19 +02:00
Charles Dias
feae71600e boards: shields: st_lcd_dsi_mb1835: set LTDC pixel-format
Set zephyr_lcd_controller pixel-format to PANEL_PIXEL_FORMAT_ARGB_8888
to match the driver configuration.

Signed-off-by: Charles Dias <charlesdias.cd@outlook.com>
2025-11-07 21:23:07 -05:00
Charles Dias
097f009348 samples: input: draw_touch_events: avoid avoid OOB writes
When CROSS_DIM doesn’t evenly divide the panel WIDTH/HEIGHT, the last
tile on the right/bottom edge can extend past the display bounds.

Fix by clipping the edge tiles.

Signed-off-by: Charles Dias <charlesdias.cd@outlook.com>
2025-11-07 21:23:07 -05:00
Pete Johanson
112871afa4 tests/kernel/context: Properly idle on MAX32 family
Make sure MAX32_ON_ENTER_CPU_IDLE_HOOK is disabled for the context test, so
the CPU will actually idle with WFI and not return before the timer
expires for test_cpu_idle test.

Signed-off-by: Pete Johanson <pete.johanson@analog.com>
2025-11-07 16:12:48 -05:00
Eric Ocasio
0d6e4040f5 pmci: mctp: Fix MCTP USB packet buffer deallocation pointer issue
Explicitly set rx_pkt pointer to NULL after free'ing it.

Fixes zephyrproject-rtos/zephyr#98688

Signed-off-by: Eric Ocasio <eric.ocasio@nxp.com>
2025-11-07 21:25:29 +02:00
Ruibin Chang
3bdf10308b soc/ite/it8xxx2: make ARCH_IRQ_VECTOR_TABLE_ALIGN constant
The IQR vector table changed size since a825e01 and it is
causing issues with downstream applications, for example,
data stored in bin specific field is shifted by
the ARCH_IRQ_VECTOR_TABLE_ALIGN, so I make
ARCH_IRQ_VECTOR_TABLE_ALIGN constant.

Signed-off-by: Ruibin Chang <Ruibin.Chang@ite.com.tw>
2025-11-07 21:25:18 +02:00
Lucien Zhao
9da1b3cba1 boards: nxp: frdm_mcxe31b: add zephyr,shell-uart node
Add missing zephyr,shell-uart device tree node to enable
shell functionality.

Signed-off-by: Lucien Zhao <lucien.zhao@nxp.com>
2025-11-07 19:25:29 +02:00
Szymon Janc
d660d38fca Bluetooth: MPL: Fix NULL pointer dereference in on_obj_selected
Track may not have next track and thus this must be checked before
trying to match ID.

This was affecting following qualification test cases:
GMCS/SR/MCP/BV-38-C
GMCS/SR/MCP/BV-39-C
GMCS/SR/MCP/BV-40-C

Signed-off-by: Szymon Janc <szymon.janc@codecoup.pl>
2025-11-07 19:24:42 +02:00
Ali Hozhabri
85830bf48d boards: 96boards: carbon: Increase main stack size when using Bluetooth
Increase main stack size when MBEDTLS_INIT is enabled to avoid stack
overflow as it consumes 1536 bytes.

Signed-off-by: Ali Hozhabri <ali.hozhabri@st.com>
2025-11-07 19:23:36 +02:00
Jordan Yates
3ad0946ce7 doc: tfm: document output files
Document the useful output files that exist, which files they are
constructed from, and what they can be used for.

Update other sections that are no longer correct with changes.

Signed-off-by: Jordan Yates <jordan@embeint.com>
2025-11-07 19:23:26 +02:00
Jordan Yates
74a23eacd5 modules: tf-m: generate tfm_merged.bin from tfm_merged.hex
Since `tfm_merged.bin` now contains BL2, it can only be used for the
same purposes as `tfm_merged.hex` (intial firmware loading). Therefore
it should be using the confirmed images that `tfm_merged.hex` does.

Since the only difference between the two files with that change is now
the output format, we can directly generate `tfm_merged.bin` from
`tfm_merged.hex` with `objcopy` instead of going through `mergehex.py`.

Signed-off-by: Jordan Yates <jordan@embeint.com>
2025-11-07 19:23:26 +02:00
Jordan Yates
db339e46b5 modules: tf-m: generate tfm_s_zephyr_ns_signed.bin
Generate a binary version of `tfm_s_zephyr_ns_signed.hex` with objcopy.
This file is valid for performing OTA upgrades, unlike `tfm_merged.bin`,
which contains BL2.

Signed-off-by: Jordan Yates <jordan@embeint.com>
2025-11-07 19:23:26 +02:00
Jordan Yates
15e8305ce9 modules: tf-m: remove S_NS_CONFIRMED_HEX_FILE
`S_NS_CONFIRMED_HEX_FILE` was never generating a confirmed file, just
the same file contents as `S_NS_HEX_FILE`. Since no logic needs a
confirmed merge of `tfm_s.hex` and `zephyr.hex`, just remove the logic
instead of fixing it.

Signed-off-by: Jordan Yates <jordan@embeint.com>
2025-11-07 19:23:26 +02:00
Jordan Yates
2219a875b2 modules: tf-m: fix CMake formatting
Fix formatting errors that cause CI to complain.

Signed-off-by: Jordan Yates <jordan@embeint.com>
2025-11-07 19:23:26 +02:00
Jordan Yates
c127388eaf scripts: build: mergehex: fix --output-bin
Stop `--output-bin` from consuming the first trailing argument that
should have been in `input_files`.

Signed-off-by: Jordan Yates <jordan@embeint.com>
2025-11-07 19:23:26 +02:00
Łukasz Stępnicki
3f90574ad3 soc: nordic: vpr: align ESF_SW_IRQ_SIZEOF when new exception debug is used
There is new exception debugging mechanism for RISC-V which needs
additional member in arch_esf structure. VPRs handle stacking
partially in hw so exact position of some stack members needs
to be at the end of arch_esf, so explicit padding is needed.
Aligned also ESF_SW_IRQ_SIZEOF when exception debug is used.

Signed-off-by: Łukasz Stępnicki <lukasz.stepnicki@nordicsemi.no>
2025-11-07 19:22:58 +02:00
Benjamin Cabé
1078e59a13 boards: stm32n6570_dk: Remove invert-y property from LVGL pointer input
Removed the invert-y property from the LVGL pointer input configuration
as it's causing the touch events to be "flipped" vertically.

Confirmed that this gets samples/subsys/display/lvgl back to correctly
detecting touch events, and for good measure tested
samples/subsys/input/draw_touch_events which keeps working as expected
(like it should since it's not using the LVGL pointer input ;-))

Fixes zephyrproject-rtos/zephyr#98933

Signed-off-by: Benjamin Cabé <benjamin@zephyrproject.org>
2025-11-07 19:22:49 +02:00
Pieter De Gendt
be0f5b0dc7 drivers: syscon: Cleanup some doxygen return commands
Documenting return values with doxygen should use the retval tags.

Signed-off-by: Pieter De Gendt <pieter.degendt@basalte.be>
2025-11-07 19:22:40 +02:00
Tomasz Chyrowicz
6a4af2486d mcumgr: img_mgmt: Fix minor issues
Fix a few typos inside img_mgmt.c file.

Signed-off-by: Tomasz Chyrowicz <tomasz.chyrowicz@nordicsemi.no>
2025-11-07 19:22:29 +02:00
Julien Racki
dbcfb77ce3 boards: stm32: stm32n6570_dk: Reduce the Tx clock signal skew
Reduce the Tx clock signal skew to 1ns
as it caused around 30% packet loss during ping
on some boards.

Signed-off-by: Julien Racki <julien.racki-ext@st.com>
2025-11-07 08:25:29 -05:00
Pavel Vasilyev
bb006dc971 bluetooth: mesh: Increase BT RX Stack Size for PB-GATT
Increase BT RX Thread Stack Size which is needed for successfull
provisioning over PB-GATT.

Output from `kernel thread stacks` shell command:
```
BT RX WQ (real size 4096): unused 1408 usage 2688 / 4096 (65 %)
```

Fixes #98521

Signed-off-by: Pavel Vasilyev <pavel.vasilyev@nordicsemi.no>
2025-11-07 08:25:22 -05:00
Etienne Carriere
bd943a0ffa checkpatch: ignore COMPARISON_TO_NULL
Ignore COMPARISON_TO_NULL since it conflicts with Zephyr coding
guidelines main rule 85:
  The controlling expression of an if statement and the
  controlling expression of an iteration-statement shall have
  essentially Boolean type

Link: https://docs.zephyrproject.org/latest/contribute/coding_guidelines
Signed-off-by: Etienne Carriere <etienne.carriere@st.com>
2025-11-07 08:24:21 -05:00
Charles Hardin
5c7ce0950e drivers: ethernet: lan9250: check for errors during the init calls
During board bringup the spi interface was not working as expected
and the lna9250 driver should have errored early when the chip was
not detected and reset but ended up busy waiting on setup. So, this
will error out on the init path when the chip can not be reset at
the driver instance.

Signed-off-by: Charles Hardin <ckhardin@gmail.com>
2025-11-07 08:22:06 -05:00
Vinayak Kariappa Chettimada
c102a8e30e Bluetooth: Controller: Add BT_HCI_VS_FATAL_ERROR_SUPPORT
Add BT_HCI_VS_FATAL_ERROR_SUPPORT Kconfig to allow
out-of-tree Controllers to control Zephyr HCI Vendor-
Specific Fatal Error event support.

Signed-off-by: Vinayak Kariappa Chettimada <vich@nordicsemi.no>
2025-11-07 06:58:27 -05:00
farsin NASAR V A
36465ec3c4 tests: drivers: uart: Added uart test files
Added sam_e54 overlay file for uart_errors test project
Added sam_e54 platform allow in testcase.yaml

Signed-off-by: farsin NASAR V A <farsin.nasarva@microchip.com>
2025-11-07 06:57:39 -05:00
Szymon Janc
184f053bca tests: Bluetooth: Tester: Fix NULL pointer dereference
PA sync can be terminated before BIG sync is stopped. This results
in ps_sync being NULL and thus crash in stop callback. Simply store
address needed by BTP events and don't rely on pa_sync.

Signed-off-by: Szymon Janc <szymon.janc@codecoup.pl>
2025-11-07 06:52:03 -05:00
Aksel Skauge Mellbye
28edc26cc0 modules: hal_silabs: Simplify HFRCO frequency selection
Recent versions of the HAL rely on interpreting the HFRCO frequency
selection as a plain integer in preprocessor comparisons. The
adaptation layer in Zephyr created a C expression that was not
possible to evaluate by the preprocessor. Simplify the logic to
directly passing the devicetree value to the driver.

This slightly changes the behavior of the code by no longer accepting
arbitrary frequencies and mapping them to the closest HFRCO band.
However, the binding documentation already states that the frequency
should match the band.

Signed-off-by: Aksel Skauge Mellbye <aksel.mellbye@silabs.com>
2025-11-07 06:51:31 -05:00
Aksel Skauge Mellbye
e6cb52e8a5 dts: arm: silabs: Remove CMU clock controller node for HFRCO
The CMU clock controller node for HFRCO was wrongly interpreted
as a PLL reference clock. This prevented configuring the HFRCO
in open-loop mode. Since the node isn't used for anything,
remove it as a minimal stopgap solution.

Signed-off-by: Aksel Skauge Mellbye <aksel.mellbye@silabs.com>
2025-11-07 06:51:31 -05:00
Lyle Zhu
27c245a44d Bluetooth: Classic: RFCOMM: Fix NULL pointer access issue
When received the DLC disconnect request, after prime the DLC
disconnect response, the DLC will be cleared and the `dlc->session`
is cleared. If the no DLC is linked in current session, the idle
timer of the session will be scheduled.

In current implementation, the `dlc->session` is used to get the
session pointer, but it is invalid in this time. And the unexpected
fault occurs.

Fix the issue by getting the session pointer from parameter of the
function `rfcomm_handle_disc()` instead of `dlc->session`.

Fix issue #99035.

Signed-off-by: Lyle Zhu <lyle.zhu@nxp.com>
2025-11-07 06:50:42 -05:00
Martin Hoff
b38054bbae devicetree: fix DT_SPI_DEV_HAS_CS_GPIOS macro
This fix ensures that the implementation matches the documented
behavior, where the macro return 1 when the cs-gpios property has
an entry matching the reg address of the child device.

This restores the behavior of the devicetree init API prior to
<a60f93d742>, which accidentally
introduced this issue by relying on the `DT_SPI_DEV_HAS_CS_GPIOS`
macro, which has deviated from its documented behavior ever since
it was originally introduced 6 years ago.

Signed-off-by: Martin Hoff <martin.hoff@silabs.com>
Co-authored-by: Aksel Skauge Mellbye <aksel.mellbye@silabs.com>
2025-11-07 10:27:58 +02:00
Anas Nashif
4e9a4e385a cpu_load: rename conflicting API
We have two places defining cpu_load_get() and trying to the same thing,
one is a core kernel feature supported on all architecture, the other is
part of debug, requires tracing and supported only on a subset of
architectures. Both deliver different results and accuracy.

While we figure our how to merge those into one API and with the
advanatges of both, rename the API so there is no confusion about what
is being used.

Fixes #97845

Signed-off-by: Anas Nashif <anas.nashif@intel.com>
2025-11-07 10:27:50 +02:00
Ulrich KAMDEM
f2428c68ff boards: st: nucleo_u385rg_q: change arduino_spi to spi1
According to user manual(UM3062, table 16), arduino_spi is connected
to spi1 instead of spi3.

Enable spi1 node and affect the SPI_NSS pin with I/O function
to do the chip select.

Remove i2c3 to avoid conflict with PA7 pin.

Move the status property of dac1 node to maintain consistency
in the ordering of node properties.

NB: The SPI_NSS pin is not listed as an alternate function
for SPI1 in the user manual (UM3062, Table 17).

Signed-off-by: Ulrich KAMDEM <kamdemulricharmel@gmail.com>
2025-11-06 16:36:12 -05:00
Ulrich KAMDEM
49c15bc8d8 tests: drivers: nucleo_u385rg_q: update i2c tests drivers
Enable and add pinctrl for the I2C3 node, and disable the SPI1 node
since it is enabled by default on this board (via the Arduino connector),
which causes a conflict with the I2C3 pinctrl configuration.

Signed-off-by: Ulrich KAMDEM <kamdemulricharmel@gmail.com>
2025-11-06 16:36:12 -05:00
William Tambe
926efb8fc1 xtensa: fix error: use of undeclared identifier 'intenable2'
This is likely a miss from:
df40dff6fb arch: xtensa: clean up interrupt handling

Signed-off-by: William Tambe <williamt@cadence.com>
2025-11-06 16:30:43 -05:00
Seppo Takalo
74bea00174 modem: cmux: Don't set flow-control too easily
Only track the available buffer space, if
CONFIG_MODEM_CMUX_MSC_FC_THRESHOLD is configured.
When less than required amount fit into the ringbuffer,
indicate the RX buffer is full.

Otherwise, only mark RX buffer full when incoming data is being
dropped.

When RX buffer is detected to be full, send Modem Status Command
with flow-controll bit set.

Flow control is released once the incoming buffer has at least
MODEM_CMUX_MTU bytes free again.

Fixes #98644

Signed-off-by: Seppo Takalo <seppo.takalo@nordicsemi.no>
2025-11-06 16:30:13 -05:00
Daniel DeGrasse
5575d3b238 drivers: flash: flash_mspi_nor: indicate support for flash page layout
Flash MSPI NOR driver already has support for flash page layout, but did
not select the Kconfig symbol indicating so. Add the selection so
drivers can use the page layout api.

Signed-off-by: Daniel DeGrasse <ddegrasse@tenstorrent.com>
2025-11-06 16:28:58 -05:00
Abderrahmane JARMOUNI
12f5e5bd0e doc: develop: twister: fix titles underline inconsistency
Fix underline inconsistency of titles of level 4 by replacing + with -.

Signed-off-by: Abderrahmane JARMOUNI <git@jarmouni.me>
2025-11-06 16:25:44 -05:00
Loic Domaigne
6750f4a5d6 doc: services: logging: add limitation when using logging thread name
Add a note about a limitation when using deferred logging + thread name
together with dynamically allocated struct k_thread. This limitation has
been raised in issue #95077.

Signed-off-by: Loic Domaigne <tech@domaigne.com>
2025-11-06 14:02:51 -05:00
Loic Domaigne
1b0950035e drivers: crypto: crypto_ataes132a fix missing count check
Coverity reported an untrusted loop bound caused by a missing check on
the count value in ataes132a_send_command() for the response received
from the device.  As per datasheet section 6.1, count should be at least
3 bytes (1 byte for count, and 2 bytes for the 16 bits CRC).

While I'm expecting this condition to be very rare, it doesn't hurt to
implement a proper checking and report an error if count<3.

Coverity CID: 434625

Signed-off-by: Loic Domaigne <tech@domaigne.com>
2025-11-06 14:02:39 -05:00
Pavel Vasilyev
cce11a5e2b tests: bsim: bluetooth: mesh: Fix brg duplicate filtering test
Add delay to avoid missed packet by tester.

This fixes brg_subnet_duplicate_filtering test.

Signed-off-by: Pavel Vasilyev <pavel.vasilyev@nordicsemi.no>
2025-11-06 14:01:29 -05:00
Pavel Vasilyev
1ab799f872 tests: bsim: bluetooth: mesh: Fix pb_cancel test
Enable retransmissions of Generic Provisioning PDUs. This should fix
pb_cancel test where provisionee fails to receive Link Open PDU due to
parallel PB-GATT advertisement, but since Link Open PDU is not
retransmitted, test fails.

Signed-off-by: Pavel Vasilyev <pavel.vasilyev@nordicsemi.no>
2025-11-06 14:01:29 -05:00
Valerio Setti
f60f04d7dc doc: release-notes: notify about Mbed TLS version upgrade
Add a note about Mbed TLS version upgrade from 3.6.4 to 3.6.5.
Update also the CVE list accordingly.

Signed-off-by: Valerio Setti <vsetti@baylibre.com>
2025-11-06 14:01:29 -05:00
Valerio Setti
f6d24f7aa4 manifest: mbedtls: bump to 3.6.5
Update Mbed TLS revision from 3.6.4 to 3.6.5.

Signed-off-by: Valerio Setti <vsetti@baylibre.com>
2025-11-06 14:01:29 -05:00