Commit graph

136,983 commits

Author SHA1 Message Date
Flavio Ceolin
75dafaf4e8 doc: security: Disclose CVE-2026-5590
Disclose information about published CVE.

Signed-off-by: Flavio Ceolin <flavio.ceolin@gmail.com>
2026-04-07 11:31:44 -05:00
Flavio Ceolin
159c7d424d doc: release/4.4: Add CVE under embargo
Add CVEs - 2026-5068 and 2026-5589 - under embargo fixed during 4.4
development

Signed-off-by: Flavio Ceolin <flavio.ceolin@gmail.com>
2026-04-07 11:31:44 -05:00
Flavio Ceolin
b5589fcc7b doc: vuln: Add CVE under embargo
Add an entry to CVE-2026-5589

Signed-off-by: Flavio Ceolin <flavio.ceolin@gmail.com>
2026-04-07 11:31:44 -05:00
Siratul Islam
df5a54c8fa dts: bindings: add devicetree examples in bindings
Add examples for ZFM-X0 and GT-5X drivers

Signed-off-by: Siratul Islam <email@sirat.me>
2026-04-07 11:31:29 -05:00
Jukka Rissanen
d00e87bfae doc: release-notes: Add wifi information to 4.4
Add information about native wifi stack changes in 4.4.

Signed-off-by: Jukka Rissanen <jukka.rissanen@nordicsemi.no>
2026-04-07 11:30:56 -05:00
Iuliana Prodan
24e7b44384 MAINTAINERS: Add iuliana-prodan and anangl as IPC maintainers
Add myself and Andrzej Głąbek as IPC maintainers.

Signed-off-by: Iuliana Prodan <iuliana.prodan@nxp.com>
2026-04-07 11:30:45 -05:00
Anand Kumar
6bbad0cbc6 kernel: spinlock: use TTAS optimization for non-ticket spinlocks
Replace the pure CAS spin loop with a Test-Test-And-Set (TTAS) pattern
in k_spin_lock() for the non-ticket spinlock path.

The current implementation calls atomic_cas() on every iteration, which
takes exclusive ownership of the cache line even when the compare fails.
Under contention, this generates unnecessary cache coherence traffic as
each spinning CPU invalidates the cache line of all other CPUs.

Use a CAS-first approach: attempt atomic_cas() directly on the first
iteration (no penalty in the uncontended common case), and only fall
back to spinning on atomic_get() reads after the first CAS failure.
The atomic_get() reads from the local cache without bus traffic, and
the expensive atomic_cas() is only re-attempted when the lock appears
free. This significantly reduces cache line bouncing under contention
on multi-core SMP systems.

Fixes: #106616
Signed-off-by: Anand Kumar <anandvtu16158@gmail.com>
2026-04-07 11:30:31 -05:00
Tom Burdick
8f4512a480 soc: psoc edge: Add select for HAS_SEGGER_RTT
Adds the needed select symbol to allow for segger RTT support.

Signed-off-by: Tom Burdick <thomas.burdick@infineon.com>
2026-04-07 08:43:00 -05:00
Robert Lubos
1b43e4f62c modules: openthread: Enable NIST optimisations if ECC is used
W/o MBEDTLS_ECP_NIST_OPTIM enabled DTLS handshakes are considerably
slower, making core Thread functionalities like commissioner/joiner
defunct on slower platforms. Therefore, enable the optimizations if
ECC cryptography is in use.

Signed-off-by: Robert Lubos <robert.lubos@nordicsemi.no>
2026-04-07 08:42:33 -05:00
Cristian Bulacu
2952c2478d net: dns: Forward all DNS packets if callback is installed
This PR enables the DNS packet forwarding without taking into account
the return value of `dns_validate_msg` function.
This is to accomodate scenarios like where ANCOUNT is set to 0, or other
cases in which internal DNS implementation will not validate the
message.

Signed-off-by: Cristian Bulacu <cristian.bulacu@nxp.com>
2026-04-07 08:41:50 -05:00
Nicolas Pitre
184b5a3804 kernel: assert scheduler lock is held in z_unpend_all_locked()
Add a runtime assertion in z_unpend_all_locked() to verify that
_sched_spinlock is actually held by the caller. This catches misuse
early given the function call depth involved.

Extend the availability of z_spin_is_locked() from CONFIG_SMP &&
CONFIG_TEST to also include CONFIG_ASSERT, so the check can be
used in __ASSERT() outside of test builds.

Signed-off-by: Nicolas Pitre <npitre@baylibre.com>
2026-04-07 08:40:28 -05:00
Nicolas Pitre
9cef0da05c kernel: avoid recursive scheduler lock in k_heap_free path
When halt_thread() calls k_thread_perms_all_clear() under
_sched_spinlock, the permission cleanup can trigger k_free() on
dynamic objects. k_heap_free() then calls z_unpend_all() which
attempts to take _sched_spinlock again, causing a recursive lock.

Fix this by introducing k_heap_free_sched_locked() and
k_free_sched_locked() variants that use z_unpend_all_locked()
to operate on the wait queue without re-acquiring the scheduler
lock. The existing z_unpend_all() becomes a wrapper that takes
the lock and delegates to z_unpend_all_locked().

unref_check() gains a sched_locked parameter: the abort path
(clear_perms_cb) passes true to use the locked free variant,
while k_thread_perms_clear() passes false for the normal path.

Fixes #106659

Signed-off-by: Nicolas Pitre <npitre@baylibre.com>
2026-04-07 08:40:28 -05:00
Jjateen Gundesha
0c9fd34a46 drivers: adc: lpadc: fix calibration sequencing with 1us delay
LPADC_DoOffsetCalibration() triggers offset calibration but returns
immediately without waiting for it to complete. If gain calibration
is requested before offset calibration finishes, the hardware silently
rejects it and GCC[RDY] never asserts, causing
LPADC_FinishAutoCalibration() to spin forever at boot (~50% of the
time on affected boards like FRDM-MCXA266).

Fix by replacing LPADC_DoAutoCalibration() with the split HAL API:
  LPADC_PrepareAutoCalibration() + k_busy_wait(1U) +
  LPADC_FinishAutoCalibration()

The 1us busy-wait gives offset calibration sufficient time to complete
on all LPADC platforms before the gain calibration request is issued.
Only the HAS_CTRL_CALOFS path is affected (the path that also calls
DoOffsetCalibration); the HAS_CFG_CALOFS path has no preceding offset
calibration and is left unchanged.

Fixes #105652

Signed-off-by: Jjateen Gundesha <jjateen97@gmail.com>
2026-04-07 08:39:42 -05:00
Pete Johanson
a3962e2290 drivers: spi: MAX32 DMA + RTIO fixes
Correct some behaviors that were broken in the original SPI DMA + RTIO
work:

* Properly fallback to interrupt behavior if no DMA channels are assigned
  to a given SPI peripheral.
* Properly handle held CS lines across transactions when using hardware CS
  control.

Signed-off-by: Pete Johanson <pete.johanson@analog.com>
2026-04-07 08:39:07 -05:00
Shreyas Shankar
785633e585 drivers: interrupt_controller: Fix VIM assert
The VIM IP has a register that informs the maximum
number of interrupts that can be supported.

The ASSERT must check whether the number of IRQs
is LESSER THAN OR EQUAL to above register value,
not a strict equality check.

Signed-off-by: Shreyas Shankar <s-shankar@ti.com>
2026-04-07 08:37:58 -05:00
Hui Bai
3c41969566 samples: net: wifi: Disable CONFIG_ETH_DRIVER for RW612
Disable CONFIG_ETH_DRIVER for RW612 BGA board to align with FRDMRW612
board. The ethernet will be disabled in wifi example by default for
RW612 board. Enable this flag if user wants to use ethernet.

Signed-off-by: Hui Bai <hui.bai@nxp.com>
2026-04-07 08:37:30 -05:00
Hui Bai
a16132d1cd soc: nxp: rw: Fix ethernet init fail issue
Previously, the purpose of disabling AVPLL and TDDR is to save power
consumption in low power. But all examples of RW612 use clock_init()
and disable AVPLL and TDDR without condition check is not proper.
Move disable AVPLL and TDDR to condition when they are not in use.

The ethernet uses TDDR clock and enet is enabled by default for RW612.
Add CONFIG_ETH_DRIVER along with enet and CONFIG_NET_L2_ETHERNET in
clock_init(). If any of the condition is not match, the TDDR clock
will be disabled.

Signed-off-by: Hui Bai <hui.bai@nxp.com>
2026-04-07 08:37:30 -05:00
John Batch
1b75bfd1d4 tests: devicetree: api_ext: removing unneeded platform_exclude
The root cause of the build failure in this test on kit_psc3m5_evk has
been addressed.  The platform_exclude for this board is no longer
necessary.

Signed-off-by: John Batch <john.batch@infineon.com>
2026-04-07 08:36:58 -05:00
John Batch
7796339c41 drivers: clock_control: infineon: fix psc3m5 build error
Updates the legacy HAL version of the Infineon clock control driver to
be excluded for devices not using the legacy HAL based drivers.

This fixes a failure in the libraries.devicetree.api_ext test, which
on PSC3M5 introduces a "fixed-clock" DTS note that causes
DT_HAS_FIXED_CLOCK_ENABLED and SOC_FAMILY_INFINEON_CAT1 to both be
selected.  This results in the HAL based driver being incorrectly
included in the build, causing build errors.

Assisted-by: GitHub Copilot:claude-opus-4.6
Signed-off-by: John Batch <john.batch@infineon.com>
2026-04-07 08:36:58 -05:00
Fengming Ye
a4010304f7 drivers: wifi: nxp: fix build error for custom host platform
Fix build error when independent reset is enabled on custom host.
Add out-of-band reset kconfig option to guard dependency on host GPIO,
so that in-band independent reset can be supported by default.

Signed-off-by: Fengming Ye <frank.ye@nxp.com>
2026-04-07 08:36:27 -05:00
Fengming Ye
edd97145ff west.yml: update hal_nxp to fix build error for wifi on custom host
Update hal_nxp to fix build error for wifi on custom host platform.

Signed-off-by: Fengming Ye <frank.ye@nxp.com>
2026-04-07 08:36:27 -05:00
Tomi Fontanilles
2932d95f96 manifest: mbedtls-3.6: update to 3.6.6
Update Mbed TLS to the just-released 3.6.6 version.

Signed-off-by: Tomi Fontanilles <tomi.fontanilles@nordicsemi.no>
2026-04-07 08:35:56 -05:00
Jianchao Wang
07d2f804a3 Revert "dts: arm64: imx9: remove flexcan CAN FD compatible"
This reverts commit 68475b4886.
Since issue #106238 has been resolved, CAN FD is re-enabled.

Signed-off-by: Jianchao Wang <Jianchao.wang_1@nxp.com>
2026-04-07 08:35:29 -05:00
Jianchao Wang
3855c04157 drivers: can_mcux_flexcan: Ensure that prop_seg is aligned with fsl_flexcan
In the `FLEXCAN_SetTimingConfig` function(fsl_flexcan.c), the following
statement is implemented when the Enhanced Bit Timing Register is enabled:
```
base->ENCBT = CAN_ENCBT_NRJW(pConfig->rJumpwidth) |
              CAN_ENCBT_NTSEG1((uint32_t)pConfig->phaseSeg1 +
                               pConfig->propSeg + 1U) |
              CAN_ENCBT_NTSEG2(pConfig->phaseSeg2);
```
`prop_seg + 1` represents the length of the propagation segment.
- `pConfig->propSeg` = `flexcan_config.timingConfig.propSeg`
- Therefore, flexcan_config.timingConfig.propSeg(can_mcux_flexcan.c) should
  be equal to `data->timing.prop_seg - 1U`.
Fixes: #106238

Signed-off-by: Jianchao Wang <Jianchao.wang_1@nxp.com>
2026-04-07 08:35:29 -05:00
Håkon Amundsen
02b7d68a97 manifest: update hal_nordic revision
Get new version of IronSide SE support package that supports
v23.5.0+28.

Signed-off-by: Håkon Amundsen <haakon.amundsen@nordicsemi.no>
2026-04-07 08:32:57 -05:00
Jamie McCrae
e6b27b3492 dfu: img_util: Fix partition detection
Fixes the logic in detecting which partition is being executed
from, also fixes a test for this feature

Signed-off-by: Jamie McCrae <jamie.mccrae@nordicsemi.no>
2026-04-07 08:32:23 -05:00
Jordan Yates
c010567673 lorawan: services: LITTLE_ENDIAN dependency
Add a `LITTLE_ENDIAN` dependency to `LORAWAN_FRAG_TRANSPORT` due to the
use of bitfields and packed structures in decoding on-air payloads.

Signed-off-by: Jordan Yates <jordan@embeint.com>
2026-04-07 08:31:51 -05:00
Jordan Yates
ae9f38d896 tests: lorawan: frag_decoder: test multi-packet handling
Add tests for the fragment transporter multi packet handling, including
under error conditions.

Signed-off-by: Jordan Yates <jordan@embeint.com>
2026-04-07 08:31:51 -05:00
Jordan Yates
099dd4509f lorawan: services: update fragmented transport parsing
Update the fragmented data transport parsing to always consume complete
control messages, regardless of any validation errors. Simplify the
implementation of this by defining the packets as packed structures.

Signed-off-by: Jordan Yates <jordan@embeint.com>
2026-04-07 08:31:51 -05:00
Jordan Yates
25c395b066 lorawan: services: frag_transport: define status bits
Define status bits as enumerations, instead of using `BIT` directly in
the code.

Signed-off-by: Jordan Yates <jordan@embeint.com>
2026-04-07 08:31:51 -05:00
Pieter De Gendt
fa0c841540 scripts: ci: check_compliance.py: Add doc link to Github annotation
Append the documentation link to Github annotation. This make it easier for
users to go directly to the relevant page from a pull request.

Signed-off-by: Pieter De Gendt <pieter.degendt@basalte.be>
2026-04-07 08:28:45 -05:00
Ofir Shemesh
7bc9e93d3f soc: nxp: imxrt: fix FlexSPI clock after DTS change
After commit b1afb494b0, zephyr,flash points to the
soc-nv-flash child node instead of the
nxp,imx-flexspi-nor controller. This shifts the DTS
hierarchy by one level, so
DT_PARENT(DT_CHOSEN(zephyr_flash)) now returns the
flash controller node, not the FlexSPI bus node.

Use DT_CHOSEN(zephyr_flash_controller) to directly
reference the flash controller, and DT_PARENT of it
to reach the FlexSPI bus where needed.

Signed-off-by: Ofir Shemesh <ofirshemesh777@gmail.com>
2026-04-06 10:36:09 -05:00
Robert Lubos
01bc91bb65 doc: release-notes-4.4: Update release notes for networking
Update release notes for 4.4.0 release with networking subsystem
changes.

Signed-off-by: Robert Lubos <robert.lubos@nordicsemi.no>
2026-04-06 10:34:56 -05:00
Valerio Setti
c03f17d513 manifest: bump Mbed TLS to the official 4.1 release tag
Previous versions of Mbed TLS and related repos were close to the final
release point, but not exactly that. This commit bumps all the repos to
the official release tag:

- Mbed TLS: 4.1.0
- TF-PSA-Crypto: 1.1.0
- mldsa-native: 5772b4f4a0105694b1203abb582273f78fa951b7 (what is being
                pointed to TF-PSA-Crypto at 1.1.0 release tag)

Signed-off-by: Valerio Setti <vsetti@baylibre.com>
2026-04-06 10:34:42 -05:00
Johan Hedberg
a588efe679 soc: silabs: siwx91x: Fix defaults for Bluetooth buffer counts
Having a differing number of ACL buffers available between the host
and controller causes unnecessary "impedance" when communicating over HCI.
The Zephyr Bluetooth host also warns about this during initialization:

  Num of Controller's ACL packets != ACL bt_conn_tx contexts (15 != 3)

Update the default for BT_BUF_ACL_TX_COUNT to match the controller. Also
update BT_BUF_EVT_RX_COUNT and BT_CONN_TX_MAX appropriately. The latter
should generally match TX_COUNT, while the former needs to be at least as
large to deal with Number of Completed Packets events from the controller.

Signed-off-by: Johan Hedberg <johan.hedberg@silabs.com>
2026-04-06 10:34:11 -05:00
Sylvio Alves
1b170ffc2f runners: openocd: fix logger access in classmethod
do_create() is a classmethod and cannot access self.logger.
Use a module-level _logger instead, consistent with core.py
and __init__.py in the runners package.

Signed-off-by: Sylvio Alves <sylvio.alves@espressif.com>
2026-04-06 10:33:17 -05:00
Valerio Setti
5352976d61 doc: migration-guide|release-notes: Mbed TLS bump to v4.1
Add notes related to PRs:
- 104031
- 106089
- 106258
- 106478

Signed-off-by: Valerio Setti <vsetti@baylibre.com>
2026-04-06 10:31:40 -05:00
David J. Leach, Jr.
91f2980f6b drivers: crypto: ataes132a: fix integer overflows in CRC and commands
This commit addresses two integer handling issues in the ataes132a
crypto driver identified by coverity scans.

1. In ataes132a_send_command, added a centralized validation check
   to ensure the 'nparams' value, when combined with the 5-byte
   packet overhead, does not exceed the 8-bit 'count' limit or the
   physical 64-byte command buffer. This prevents a potential wrap-
   around that would cause the chip to receive an invalid length byte.

2. In the Atmel CRC calculation, added an explicit cast to uint16_t
   during the bit-shift operation. This prevents unintended integer
   promotion and satisfies static analysis regarding potential
   overflows during the 16-bit CRC generation.

Fixes #84683
Fixes #84690

Signed-off-by: David J. Leach, Jr. <tasmar@gmail.com>
2026-04-06 10:29:20 -05:00
Marek Matej
149c8b1758 soc: espressif: psram entry mismatch in esp32s3
This fixes the mismatched object name in linker.

Signed-off-by: Marek Matej <marek.matej@espressif.com>
2026-04-04 11:01:00 -05:00
Ashirwad Paswan
38763c33d1 fs: ext2: fix incorrect write length in ext2_inode_write
This commit fixes the bug by ensuring `to_write` is properly bounded.
It is now calculated as the minimum of the remaining requested bytes
(`nbytes - written`) and the remaining space in the current block
(`block_size - block_off`).

Fixes #106276

Signed-off-by: Ashirwad Paswan <ashi06712@gmail.com>
2026-04-04 10:59:13 -05:00
Eden Frosst
29f9ed1711 doc: pm: device_runtime: update return code in example
Code example for `pm_device_runtime_enable` referenced a return value
that does not exist anymore.

Signed-off-by: Eden Frosst <eden.frosst@rbr-global.com>
2026-04-04 10:58:38 -05:00
Andrew Bresticker
1666066082 kernel/sched: fix race in consuming self-directed IPIs
Move signal_pending_ipi() inside the K_SPINLOCK block in
z_get_next_switch_handle(). Calling it after the lock release creates a
window where a CPU can consume its own pending IPI bit via atomic_clear
in signal_pending_ipi(), then silently drop it in
arch_sched_directed_ipi() which skips the calling CPU (i == id).

In configurations where secondary CPUs have a single pinned thread and
take no timer or external interrupts, this can lead to a permanent hang:
the idle CPU can only be woken by IPIs, but no IPIs are pending and no
timeslicing IPIs will be generated since the idle thread is not sliceable.
This was reproduced when running under QEMU with the following sequence
of events observed:

  CPU 0                                  CPU 1
  ─────                                  ─────

                                         Thread calls k_poll(K_MSEC(1))
                                           z_pend_curr():
                                             mark thread PENDING
                                             z_add_timeout(1ms)
                                             do_swap() to idle thread
                                         WFI

  Timer tick fires
  sys_clock_announce():
    slice_timeout(cpu1):
      flag_ipi(BIT(1))
    signal_pending_ipi():
      MSIP[cpu1] = 1

                                         CPU1 wakes from WFI
                                         z_get_next_switch_handle():
                                           acquire _sched_spinlock
                                           next_up() → idle
                                             (thread still PENDING,
                                              timeout hasn't fired yet)
                                           release _sched_spinlock

  Timer tick fires
  sys_clock_announce():
    z_thread_timeout(thread):
      z_unpend_thread(thread)
      z_ready_thread(thread):
        flag_ipi(BIT(1))

                                         signal_pending_ipi():
                                           atomic_clear(pending_ipi)
                                             returns BIT(1)
                                           arch_sched_directed_ipi(BIT(1))
                                             skips self, IPI silently lost
                                         return to idle thread
                                           WFI
                                             thread still on ready queue

Such an interleaving of events is, of course, likely only reproducible in
practice in virtualized environments where (v)CPUs can be descheduled.

With signal_pending_ipi() inside the lock, next_up() and the IPI
dispatch are atomic. Either the concurrent flag_ipi lands before the
lock is acquired (and next_up sees the thread), or it lands after the
lock is released (and the caller dispatches the IPI). There is no
window where a CPU can consume its own bit for a thread it hasn't seen.

Similar races exist in reschedule() and z_reschedule_irqlock() as well.
Although they won't cause the same permanent hang described above, it
can result in unnecessary rescheduling latency. Fix reschedule(), and
add a TODO to z_reschedule_irqlock(); it doesn't not currently take
the sched spinlock.

Signed-off-by: Andrew Bresticker <abrestic@meta.com>
2026-04-04 10:57:11 -05:00
David J. Leach, Jr.
d64b1a4b67 tests: net: ocpp: Fix build warning
Fix a build warning with %d and zassert_equal()

Signed-off-by: David J. Leach, Jr. <tasmar@gmail.com>
2026-04-04 10:55:08 -05:00
David J. Leach, Jr.
e3645486d1 net: ocpp: replace RPC type magic numbers with symbolic constants
Replace the hardcoded WAMP RPC type values used when encoding OCPP
messages with their corresponding symbolic constants.

- Replace '2' with OCP_WAMP_RPC_REQ
- replace '3' with OCP_WAMP_RPC_RESP

This removes magic numbers and improves human readability.

Signed-off-by: David J. Leach, Jr. <tasmar@gmail.com>
2026-04-04 10:55:08 -05:00
David J. Leach, Jr.
a1585cd5e9 net: ocpp: Protect against static analysis issue generation
Static analysis has a difficult time tracing whether a call to
ocpp_send_to_server() needs to initialize sndlock and rspsig because
the message type is set very much earlier in the program logic flow.
Note that coverity is creating a single issue for sndlock and for rspsig
in each function that calls ocpp_send_to_server() without initializing
them.

Adding a NULL test will prevent future static analysis false positives.

Fixes #100026
Fixes #100025
Fixes #100024
Fixes #100017
Fixes #100015
Fixes #100013
Fixes #100011
Fixes #100010
Fixes #100008
Fixes #100006

Signed-off-by: David J. Leach, Jr. <tasmar@gmail.com>
2026-04-04 10:55:08 -05:00
Nikhil Namjoshi
41082f40fc net: Initialize chksum variable to avoid clang build errors
This addresses clang build failure seen in
https://github.com/zephyrproject-rtos/zephyr/runs/69856219528

after PR #106578 was merged.

Signed-off-by: Nikhil Namjoshi <nikhilnamjoshi@google.com>
2026-04-03 14:58:06 -05:00
Anas Nashif
0c82e9c87d boards: realtek: do not set board as default testing platform
Only simulators should be set as default.

Signed-off-by: Anas Nashif <anas.nashif@intel.com>
2026-04-03 14:57:51 -05:00
Carlo Caione
7085ea3a88 MAINTAINERS: Add pdgendt as syscon collaborator
Add pdgendt as collaborator for syscon.

Co-authored-by: Pieter De Gendt <pieter.degendt@gmail.com>
Signed-off-by: Carlo Caione <ccaione@baylibre.com>
2026-04-03 14:57:36 -05:00
Carlo Caione
afa5f2ed38 MAINTAINERS: Add myself as syscon maintainers and ARM64 collaborator
Add myself as syscon maintainer and ARM64 collaborator.

Signed-off-by: Carlo Caione <ccaione@baylibre.com>
2026-04-03 14:57:36 -05:00
Anas Nashif
b7690289ca MAINTAINERS: add label for syscon
Add label for syscon area.

Signed-off-by: Anas Nashif <anas.nashif@intel.com>
2026-04-03 14:57:19 -05:00