Make sure that IPv4 address parsing works as expected.
Assisted-by: Claude:claude-sonnet-4.6
Signed-off-by: Jukka Rissanen <jukka.rissanen@nordicsemi.no>
(cherry picked from commit d1b52d078f)
Make sure we will not overflow the ipaddress buffer if
port number is given.
Signed-off-by: Jukka Rissanen <jukka.rissanen@nordicsemi.no>
(cherry picked from commit 1c8d19a51f)
Do not read OTP related to HSE trimming when TF-M is embedded since
TF-M does yet not allow non-secure world from accessing SoC OTPs.
Use the default HSE trimming value instead.
Signed-off-by: Etienne Carriere <etienne.carriere@st.com>
(cherry picked from commit 9ee6c03ac7)
dns_unpack_answer() validated only the fixed RR header size and
accepted any rdlength, even one extending past the end of the packet.
TXT and SRV consumers in resolve.c then read up to rdlength bytes from
the message buffer, causing an out-of-bounds read on a truncated or
crafted response.
Reject any RR whose declared rdata extends past dns_msg->msg_size at
the single chokepoint in dns_unpack_answer(), so all current and
future RR consumers are covered.
Signed-off-by: Flavio Ceolin <flavio@hubblenetwork.com>
(cherry picked from commit 58b46c81c6)
Once `rx_full` has been set, the modem is instructed to no longer send
data on that DLCI channel until we notify the modem that the channel is
able to receive more data. This happens in the RX callback which drains
the pipe.
Currently the amount of free space required in the ring buffer to
release the flow control condition is hardcoded to
`CONFIG_MODEM_CMUX_MTU`. While this value is fine for the DLCI1 and
DLCI2 channels (which have buffers created as
`CONFIG_MODEM_CMUX_MTU + N` bytes large), the user pipes with size
`MODEM_CELLULAR_USER_PIPE_BUFFER_SIZES` are typically much smaller. This
lead to the flow control condition never being released on the user
pipe DLCI channels once it was set.
Fix the issue by limiting the threshold to the capacity of the ring
buffer, so that if the buffer is completely empty we will always release
the flow control condition.
Signed-off-by: Jordan Yates <jordan@embeint.com>
(cherry picked from commit 4679c69889)
CONFIG_NUM_IRQS is a promptless symbol so setting it is not trivial. Add a
pointer to the documentation page which explains how to do it in the STM32
section of the 4.4 migration guide related to CONFIG_NUM_IRQS changes.
Signed-off-by: Mathieu Choplain <mathieu.choplain-ext@st.com>
(cherry picked from commit 0ac4d66410)
Increase the minimum residency value to 1.5ms since the minimum threshold
is 1070us and depends on max-hs-startup-time (default value: 780us).
Therefore, a safe margin is 1500us to support other values for
max-hs-startup-time.
Signed-off-by: Ali Hozhabri <ali.hozhabri@st.com>
(cherry picked from commit 418c5d6c8e)
Calculate the future time correctly to avoid negative value for "value_ms".
Register the pm_policy_event when HAL_RADIO_TIMER_SetRadioTimerValue
returns success.
Signed-off-by: Ali Hozhabri <ali.hozhabri@st.com>
(cherry picked from commit 2e933d3fec)
Handle repetition and adaptive health test errors for STM32WB09 properly.
Resetting Health error flags is not enough. See also RM0505 §14.7.11
Signed-off-by: Ali Hozhabri <ali.hozhabri@st.com>
(cherry picked from commit a2d701976b)
Avoid entering low power mode while waiting for an event to be
generated by TRNG interrupt when CONFIG_PM_S2RAM is set.
Signed-off-by: Ali Hozhabri <ali.hozhabri@st.com>
(cherry picked from commit 59ccf80915)
Ensure Zephyr post build sequence is run when TF-M is embedded
on a STM32 target since TF-M/STM can install its regression.sh
script which must be processed by running STM postbuild.sh
to be functional.
This change fixes an issue where running 'west build' on an
already built project, or running 'west flash' makes the
regression.sh script to be reinstalled raw from TF-M source tree
(platform/target/ext/stm/...) without being updated trough
postbuild.sh script.
Signed-off-by: Etienne Carriere <etienne.carriere@st.com>
(cherry picked from commit d1eb4ccdc5)
Add a bounds check to prevent a chunk from being written outside the
buffer.
Signed-off-by: Michael Zimmermann <michael.zimmermann@sevenlab.de>
(cherry picked from commit 158df8d088)
Update Zephyr fork of MCUboot to revision:
6d3b3d2c38ab20c242e5b9abb04d050086383eb2
Brings following Zephyr relevant fixes:
- 6d3b3d2c Version bump for v2.4.0
- f58e96a0 bootutil: zephyr: link to `mbedTLS` only when
`CONFIG_MBEDTLS_BUILTIN`
- 16996904 bootutil: Fix format string in swap_run function log
Signed-off-by: Jamie McCrae <jamie.mccrae@nordicsemi.no>
Enable CONFIG_DAC as this test references the driver DT spec structure
and therefore needs the driver built as it is the one instantiating it.
The test builds in typical platforms because the use of the structure is
being optimized out at build time.
But when this is not the case, the test fails to link.
The issue can be reproduced with for ex.
```
cmake -GNinja -DBOARD=native_sim/native ../tests/lib/devicetree/api_ext/ \
-DCONFIG_NO_OPTIMIZATIONS=y
ninja
```
But will fail for other boards with the default configuration intree.
Signed-off-by: Alberto Escolar Piedras <alberto.escolar.piedras@nordicsemi.no>
(cherry picked from commit 8d9859e2e9)
Fixes a few occurrences of "maybe uninitialized" variables that are
flagged when -Wmaybe-uninitialized is enabled. Seen when running e.g.
./scripts/twister -p mps2/an385 -T tests/net/lib/coap_server/common
in "--coverage" mode.
Signed-off-by: Benjamin Cabé <benjamin@zephyrproject.org>
(cherry picked from commit 2f558a5249)
The comment is correct, the code was wrong. Each chunk can be 64 bytes of
data, but they also have 4 byte headers. So to be able to read 255 chunks
with 64 bytes of data each, The buffer has to be 255 * 68.
Signed-off-by: Michael Zimmermann <michael.zimmermann@sevenlab.de>
(cherry picked from commit c98321cbfe)
ESP32-C2 and ESP32-C3 implement the zifencei extension (fence.i)
but their device trees declared only "i", "m", "c", "zicsr".
Adding zifencei selects rv32im_zicsr_zifencei/ilp32, the atomic-free
multilib, fixing illegal instruction faults on picolibc paths that
touch stdio locking.
Signed-off-by: Sylvio Alves <sylvio.alves@espressif.com>
(cherry picked from commit 8c34f6fd9f)
Fixes not erasing the first sector when using swap using offset mode
Signed-off-by: Jamie McCrae <jamie.mccrae@nordicsemi.no>
(cherry picked from commit 9da5c07615)
Fixes wrongly having an extra map entry for this response
Signed-off-by: Jamie McCrae <jamie.mccrae@nordicsemi.no>
(cherry picked from commit a64883ef5d)
Without the trailing underscore, the link gets rendered raw, and is not
clickable.
Signed-off-by: Reto Schneider <reto.schneider@husqvarnagroup.com>
(cherry picked from commit 110ba3ec16)
Adds IRK update call to internal bt_le_adv_start_ext. And rename it to
adv_start_ext to prevent confusion with public functions.
There are two paths to start ext advertising:
- bt_le_adv_start can start extended advertising if enabled by calling
internal bt_le_adv_start_ext else it starts legacy advertisements.
- bt_le_ext_adv_start specifically starts extended advertisements.
This commit misses the first path for ext advertisement:
6d137ae015
Signed-off-by: Alperen Sener <alperen.sener@nordicsemi.no>
(cherry picked from commit 246050f7f9)
Fixes an issue whereby the buffer was not checked to be valid
before resetting it
Signed-off-by: Jamie McCrae <jamie.mccrae@nordicsemi.no>
(cherry picked from commit 6f363ec6f7)
The ULPI PHY interface driver (phy_ulpi_itf.c) was only being compiled
for STM32F7X and STM32H7X series, causing build failures on other series
that use external ULPI PHYs, such as STM32F4X boards with ULPI PHYs.
Add missing F2/F4 series to the build condition alongside the existing
F7/H7 series checks. This ensures the ULPI interface driver is compiled
for any F2/F4/F7/H7 board that has a ULPI PHY node in its devicetree.
An alternative approach removing the series checks entirely and just
checking CONFIG_DT_HAS_USB_ULPI_PHY_ENABLED was considered, however
there was a concern that the ULPI interface may have different clock
control bits on other series.
This fixes build failures like "undefined reference to
__device_dts_ord_XXX__stm32_phy" when building for STM32F4 boards with
external ULPI PHYs (e.g., adi_sdp_k1). The build failures were
introduced in commit 8b8321d184.
Assisted-by: Claude:claude-sonnet-4-5
Signed-off-by: Maureen Helm <maureen.helm@analog.com>
(cherry picked from commit 7f777c04e5)
Improve the coordinate and address alignment logic in the CO5300
display driver. The driver now properly aligns the framebuffer
address according to the addr_align property from device tree,
in addition to ensuring coordinates are even values.
Signed-off-by: Kate Wang <yumeng.wang@nxp.com>
(cherry picked from commit 4626c0eb2a)
Add soc-nv-flash child nodes to the six NXP FlexSPI boards
not yet converted: mimxrt595_evk, mimxrt685_evk, vmu_rt1170
(mx25um51345g), and mimxrt1050_evk, mimxrt1060_evk,
mimxrt1062_fmurt6 (hyperflash).
Update FlexSPI NOR and HyperFlash drivers to read
write_block_size from the soc-nv-flash node. Remove
soc-nv-flash.yaml from hyperflash and mx25um51345g
bindings.
Signed-off-by: Ofir Shemesh <ofirshemesh777@gmail.com>
(cherry picked from commit 4e59810ffa)
The checks validating RA, NS and NA packets content on input were not
correct - packets should be dropped in case any of those checks failed,
however current logic was invalid, causing other checks to be ignored as
long as the ICMPv6 code was correct (i. e. 0).
Apart from fixing the logic, split the single convoluted if condition
into separate if checks for better readability.
Signed-off-by: Robert Lubos <robert.lubos@nordicsemi.no>
(cherry picked from commit 095f064c94)
Add a few new tests covering the bug discovered in ND packet
headers validation on input. Packets with invalid hop limit
should be dropped instead of silently being passed through only
if the ICMPv6 code is correct.
Signed-off-by: Robert Lubos <robert.lubos@nordicsemi.no>
(cherry picked from commit 137d08f879)
Combine the Cortex-M7 ENET workaround updates into one commit.
- clear CACHE_ENET on i.MX RT11xx Cortex-M7 for ERR050396
- disable ETH_NXP_ENET_USE_DTCM_FOR_DMA_BUFFER by default on Cortex-M7
- keep the final Kconfig condition independent of
DT_HAS_NXP_ENET1G_ENABLED
This avoids touching the same Kconfig and SoC files in follow-up
commits while preserving the intended behavior for PR #106679.
Validation:
- branch history squashed so workaround files are updated once
in the series
Signed-off-by: Hake Huang <hake.huang@nxp.com>
(cherry picked from commit a4cd6a3ba4)
Handle both RX frame and RX buffer interrupts in the NXP ENET driver.
This matches the MCUX HAL interrupt handling and avoids leaving RX work
queued behind an unhandled RX buffer interrupt source.
Validation:
- built samples/net/dhcpv4_client for mimxrt1170_evk@B/mimxrt1176/cm7
with boards/nxp/mimxrt1170_evk/dts/nxp,enet1g.overlay
- verified MCUX HAL uses RX frame and RX buffer interrupts together
Signed-off-by: Hake Huang <hake.huang@nxp.com>
(cherry picked from commit 99bb98e561)
Add test entries for ESP32-S3 default SPIRAM and octal
80 MHz configurations. Move harness config to common
section to avoid duplication.
Signed-off-by: Sylvio Alves <sylvio.alves@espressif.com>
(cherry picked from commit d95d79dc93)
Place mspi_timing_by_mspi_delay text and rodata in IRAM/DRAM.
This file contains PSRAM and flash timing tuning functions
that must not run from flash during MSPI clock reconfiguration.
Signed-off-by: Sylvio Alves <sylvio.alves@espressif.com>
(cherry picked from commit 31377905f2)
Resuming the device involves hardware accesses including register
writes, so we need to acquire the semaphore lock first to avoid
interference with other cores also using the RNG.
Signed-off-by: Sarah Renkhoff <sarah.renkhoff@gmail.com>
(cherry picked from commit 95ff84434f)
After restoring ili9xxx driver original behavior of setting BGR mode
(Red/Blue color channels swap) by default, this panel appears to
require it to be disabled according to testing by the community.
https://github.com/zephyrproject-rtos/zephyr/pull/106859#
issuecomment-4191115676
Signed-off-by: Abderrahmane JARMOUNI <git@jarmouni.me>
Signed-off-by: Eve Redero <eve.redero@gmail.com>
(cherry picked from commit b3a1487629)
commit 9b2593b8c5 has changed the internal
ili9xxx driver color config from setting BGR mode (Blue-Red channels
swap, not pixel format byte-swap) by default, to conditioning it on the
use of PIXEL_FORMAT_BGR_565 (ILI9XXX_PIXEL_FORMAT_BGR565 in devicetree),
but without updating all boards/shields to use
ILI9XXX_PIXEL_FORMAT_BGR565 to preserve their old config.
Then commit 69e353904c replaced
ILI9XXX_PIXEL_FORMAT_BGR565 to PANEL_PIXEL_FORMAT_BGR565.
Later, commit b13d9a0510 renamed
PANEL_PIXEL_FORMAT_BGR565 to PANEL_PIXEL_FORMAT_RGB565X, and defined it
as "Byte swapped version of the PIXEL_FORMAT_RGB_565 format", which is
different from how it was interpreted by ili9xxx devices (B/R channel
swapped format).
The fix for this mess is:
- separate BGR mode (B/R channel swap) setting for ili9xxx from pixel
format,
- restore the initial driver config that sets BGR mode by default, in
order to not break in-tree and out-of-tree panels that relied on that
behavior,
- introduce a DT property that allows disabling BGR mode.
A bonus enhancement is to set BGR mode in ili9xxx driver outside
set_orientation() function, since they are unrelated.
Fixes https://github.com/zephyrproject-rtos/zephyr/issues/105521
Signed-off-by: Abderrahmane JARMOUNI <git@jarmouni.me>
(cherry picked from commit d9b7fcd16f)
Provide qualification scope summary and link to design listing.
Signed-off-by: Szymon Janc <szymon.janc@codecoup.pl>
(cherry picked from commit 9834ca4ef2)
Enable RTC_ALARM and RTC_CALIBRATION in rtc_api tests for stm32h7s*
based ST boards: stm32h7s78_dk and nucleo_h7s3l8.
Signed-off-by: Etienne Carriere <etienne.carriere@st.com>
(cherry picked from commit 0b3b601e75)
Set rtc DT alias to leverage Zephyr generic RTC support on this board.
Signed-off-by: Etienne Carriere <etienne.carriere@st.com>
(cherry picked from commit 2c33e04d09)
Set rtc DT alias to leverage Zephyr generic RTC support for this board.
Signed-off-by: Etienne Carriere <etienne.carriere@st.com>
(cherry picked from commit 4c438607eb)
Enable STM32 backup domain access on H7RS series when accessing some
RTC alarm configuration registers that otherwise would be read as 0.
Signed-off-by: Etienne Carriere <etienne.carriere@st.com>
(cherry picked from commit bf56fb5142)
The HTTP server sample uses server certificate with ecdsa-with-SHA256
signature, the currently configured ciphersuite using RSA signature
is wrong for this sample. Therefore, fix the configuration to use ECDSA
instead.
Also update the maximum eventfd count, the allocation currently fails in
the server.
Signed-off-by: Robert Lubos <robert.lubos@nordicsemi.no>
(cherry picked from commit cc500b036e)
Initialize `transfer_count`, `is_write`, and `byte_mode` variables to
prevent potential use of uninitialized variables.
Signed-off-by: Fabian Blatz <fabianblatz@gmail.com>
(cherry picked from commit 04cfca3141)
Fixed a logic bug in the ESP32 Ethernet DMA RX datapath.
See #107201.
Signed-off-by: Johannes Berndorfer <johannes@berndorfer.com>
(cherry picked from commit 2764de5c7d)
Avoid accessing the packet after sending it, as the driver may
have already unreferenced or freed it. Use iface argument instead
of calling net_pkt_iface() on a potentially freed packet when
updating packet statistics.
Signed-off-by: Tim Pambor <tim.pambor@codewrights.de>
(cherry picked from commit aaed8332a6)
Avoid accessing the packet after sending it, as the driver may
have already unreferenced or freed it. Store the iface before
sending instead of calling net_pkt_iface() on a potentially
freed packet when updating packet statistics.
Signed-off-by: Tim Pambor <tim.pambor@codewrights.de>
(cherry picked from commit 3159c53e8e)
Avoid accessing the packet after sending it, as the driver may
have already unreferenced or freed it. Store the iface before
sending instead of calling net_pkt_iface() on a potentially
freed packet when updating packet statistics.
Signed-off-by: Tim Pambor <tim.pambor@codewrights.de>
(cherry picked from commit 0223e5e3ec)
Avoid accessing the packet after sending it, as the driver may
have already unreferenced or freed it. Store the iface before
sending instead of calling net_pkt_iface() on a potentially
freed packet when updating packet statistics.
Signed-off-by: Tim Pambor <tim.pambor@codewrights.de>
(cherry picked from commit 09c8578c66)
Avoid accessing the packet after sending it, as the driver may
have already unreferenced or freed it. Store the iface before
sending instead of calling net_pkt_iface() on a potentially
freed packet when updating packet statistics.
Signed-off-by: Tim Pambor <tim.pambor@codewrights.de>
(cherry picked from commit 86e21665d4)