Update the hello_hl78xx sample to showcase low-power operation,
including PSM/eDRX GNSS flows, wake/resume, and event-driven control.
Changes:
- Enable GNSS debug logging overlay.
- Track registration status and PSM/eDRX events in the app.
- Add event handling for:
* LTE RAT and registration status updates
* PSM (+PSMEV), eDRX idle enter/exit, and cell measurements
* GNSS engine ready, start, stop, and mode exit
- Support two GNSS paths:
* LPM path (PSM/eDRX): queue GNSS, wait for PSM, driver wakes,
run GNSS, auto-return to LTE on exit.
* Airplane path: CFUN=4, run GNSS, then user restores CFUN=1.
- Add delayed work to wake the modem for GNSS if needed.
- Improve sem usage to wait for PSM/eDRX, GNSS ready, and exit.
- Refactor labels (app_rerun, app_post_lpm_run) for clarity.
- Clean up logging, comments, and function docs.
- Fix memset targets to clear specific union fields.
- Set GNSS search timeout to 20000 ms in the demo.
- Minor API call cleanups for hl78xx_get_modem_info().
Why:
- Demonstrate practical LPM workflows:
- GNSS during PSM/eDRX without unnecessary CFUN toggles.
- Event-driven wake, register, and send sequences.
- Provide a reference for integrating GNSS into low-power apps.
Impact:
- Sample now depends on low-power events when configured.
- Behavior differs based on Kconfig (PSM/eDRX vs airplane).
- Requires DTS pins and Kconfig enabling for low-power paths.
Signed-off-by: Zafer SEN <zafersn93@gmail.com>
Ensure the modem is awake before sending socket data when low-power
mode is enabled. Add a PSM-aware wake path and a handshake to gate
offload I/O until the modem is ready.
Changes:
- hl78xx_sockets.c:
- Add HL78XX_PSM_WAKEUP_TIMEOUT_SECONDS (default 60 s).
- Add psm_cntrl_sem to socket data and initialize it at startup.
- Implement hl78xx_release_socket_comms() to release the semaphore
when the modem is ready for data after wake/registration.
- Implement hl78xx_send_wakeup_signal() to dispatch RESUME to the
modem state machine.
- Add hl78xx_ensure_modem_awake():
* If registered, return immediately.
* If in PSM/power-down, send wake, wait on psm_cntrl_sem up to the
timeout; on timeout set errno=EAGAIN and fail.
- Call hl78xx_ensure_modem_awake() from offload_sendto() and fail
early if the modem cannot be woken.
- Wrap a verbose post-process LOG_DBG() behind
CONFIG_MODEM_HL78XX_LOG_CONTEXT_VERBOSE_DEBUG.
Why:
- In low-power (PSM/eDRX) the modem may be asleep when the app tries to
send data. This change wakes the modem and blocks until it is ready,
preventing spurious send failures and lost payloads.
Impact:
- Behavior change for offload_sendto() under PSM:
* Returns -1 with errno=EAGAIN if wake times out.
- hl78xx_release_socket_comms() must be called by the core after wake
(done in driver on +CEREG/+KCELLMEAS paths).
Signed-off-by: Zafer SEN <zafersn93@gmail.com>
Add a configurable GNSS processing mode for low-power operation and
teach the GNSS/LTE state machine to run GNSS without unnecessary CFUN
toggling when the RF path is already free in PSM. Improves energy
usage and reduces wake latency.
Kconfig:
- New choice HL78XX_GNSS_REQUEST_PROCESSING_MODE (depends on PSM):
* HL78XX_GNSS_PROCESS_POST_PSM (default).
* HL78XX_GNSS_PROCESS_PRE_PSM.
- Document PRE vs POST behavior and constraints.
Core (hl78xx.c):
- When GNSS is requested in low-power mode, defer to PSM-aware flow:
* PRE‑PSM: start GNSS on PSM entry.
* POST‑PSM: start GNSS after user wake.
- Avoid CFUN=4 when the RF path is already free due to PSM.
- Log intent and return early to skip legacy airplane path.
GNSS TU (hl78xx_gnss.c/.h):
- If PSM is active or just exited, skip CFUN=4 and start GNSS
immediately (RF path free).
- Start GNSS on timeout when RF is free (airplane or PSM), otherwise
queue until free.
- Cancel scheduled power‑down when GNSS actually starts.
- Handle LTE REGISTERED and DEVICE_AWAKE while GNSS is active:
* If LTE reclaims RF, modem auto‑stops GNSS; return to LTE flow.
* If GNSS exit occurs while CFUN=1 (PSM path), auto‑resume LTE
registration; in airplane mode, user restores CFUN=1.
- Clarify state doc: waiting for “RF free (airplane or PSM)” instead of
only airplane.
- Emit HL78XX_GNSS_EVENT_MODE_EXITED with status=false when auto‑stopped
by LTE.
Public API docs (hl78xx_apis.h):
- Document low‑power GNSS paths:
* ENTER: queued, start pre‑ or post‑PSM depending on Kconfig.
* EXIT: auto‑resume LTE in PSM path; airplane path still user‑driven.
Why:
- GNSS can operate while LTE hibernates in PSM; avoiding CFUN toggles
saves energy and time.
- PRE‑PSM maximizes GNSS acquisition window; POST‑PSM delivers fixes at
wake before LTE work.
- Clearer eventing for auto‑stop cases simplifies app logic.
Impact / migration:
- Behavior change for queued GNSS in PSM: CFUN=4 is no longer forced if
PSM already frees the RF path.
- Apps that assumed CFUN=4 during GNSS should rely on events instead.
- Consumers of MODE_EXITED should handle status=false (auto‑stop).
- New Kconfig choice requires MODEM_HL78XX_PSM=y to be effective.
Testing notes:
- Verified PRE‑PSM starts GNSS on PSM entry and cancels power‑down.
- Verified POST‑PSM defers GNSS until wake, then runs before LTE regs.
- Confirmed LTE REGISTERED during GNSS causes clean abort and return to
LTE path.
- Confirmed no CFUN changes when PSM already frees the RF path.
Signed-off-by: Zafer SEN <zafersn93@gmail.com>
Introduce a low-power framework for HL78xx: new states, events, Kconfig
options, URC handlers, GPIO control, and an optional power-down timer.
Includes DTS pins for WAKE/GPIO6/VGPIO and a public wake API.
Board/DTS:
- swir_hl78xx_ev_kit.overlay:
- Add mdm-vgpio, mdm-gpio6, and mdm-wake GPIOs.
Kconfig:
- Add MODEM_HL78XX_POWER_DOWN when eDRX/PSM are both disabled.
- Add choice for power-down policy:
- MODEM_HL78XX_USE_DELAY_BASED_POWER_DOWN (+ delay seconds).
- MODEM_HL78XX_USE_ACTIVE_TIME_BASED_POWER_DOWN (+ active time).
- Tune eDRX defaults and add PTW value knob.
- Adjust PSM defaults (e.g., TAU default 15 minutes).
- Gate legacy sleep-delay settings when power-down is disabled.
Driver core (hl78xx.c/.h):
- New states:
- RUN_PMC_CONFIG_SCRIPT (apply PSM/eDRX/power-down).
- SLEEP (bus closed, UART suspended, wake via RESUME).
- New events (when low-power enabled):
- DEVICE_ASLEEP, DEVICE_AWAKE, LTE_PSMEV_UPDATE.
- +CEREG handler:
- Feed power timers, handle GNSS interplay, release socket comms
after register when low-power is active.
- +PSMEV handler:
- Track ENTER/EXIT, toggle WAKE pin, dispatch sleep/awake events.
- +KCELLMEAS handler:
- Update RSRP, mark registered on valid signal, release comms.
- Carrier-on / await-registered:
- Distinguish PSM entry vs coverage loss, route to SLEEP or retry.
- Avoid iface status run during initial PSM edge cases.
- Sleep state handlers:
- On enter: WAKE=0, release chat, close pipe, suspend UART, give sem.
- On bus closed: decide GNSS pre/post-PSM behavior.
- On resume: WAKE=1, resume UART, reopen pipe, proceed to GNSS or LTE.
- State-table safety:
- Use MODEM_HL78XX_STATE_COUNT for bounds checks.
- Log improvements and explicit state transition trace.
APIs (hl78xx_apis.c / include):
- Add hl78xx_wakeup_modem() to resume from SLEEP (PSM).
Chat/URC (hl78xx_chat.c/.h):
- Enable +KPSMEV URC and +KCELLMEAS URC when low-power is on.
- Provide disable-PMC script when low-power is off.
Config helpers (hl78xx_cfg.c/.h):
- Add PMC enabling and settings application:
- hl78xx_enable_pmc(), hl78xx_psm_settings(), hl78xx_edrx_settings().
- Power-down timer (when enabled):
- Init/cancel/query and feed functions via k_work_delayable.
- Feed timer on dynamic TX path to extend on activity.
- Add hl78xx_is_rsrp_valid() helper.
- Respect CONFIG_MODEM_LOG_LEVEL in cfg TU logging.
Misc:
- Expose hl78xx_release_socket_comms() for post-register gating.
- Guard init-fail path to require WAKE pin when low-power is on.
- Add RUN_PMC_CONFIG_SCRIPT transitions after RAT config.
Why:
- Reduce energy by using PSM/eDRX and a clean SLEEP state with bus and
UART suspended. Optionally power down the modem when DRX features are
disabled. Provide explicit wake and robust PSM detection.
Impact / migration:
- DTS must define WAKE/GPIO6/VGPIO if low-power is enabled.
- New state/event enums added; state table now uses *_STATE_COUNT.
- +KCELLMEAS URC is enabled unless GNSS blocks it (see comments).
- External users can call hl78xx_wakeup_modem() to resume from PSM.
- Power-down policy and delays are configurable via Kconfig.
Testing notes:
- Verified PSMENTER drives WAKE low and transitions to SLEEP.
- Verified RESUME re-opens UART, waits settle time, then proceeds.
- Confirmed GNSS pre/post-PSM flows per config.
- Checked power-down timer feeds on data activity and triggers OFF.
Signed-off-by: Zafer SEN <zafersn93@gmail.com>
Add a sample demonstrating concurrent WiFi scanning and LED blinking
on Pico W and Pico 2 W. A background thread blinks the onboard LED
via the CYW43 GPIO driver while the main thread performs a WiFi scan.
Board overlays provide the led0 alias since the CYW43 GPIO driver
requires the WiFi stack. Includes README.rst documentation and
creates the Raspberry Pi sample category index.
Signed-off-by: John Lin <mcjelcom@gmail.com>
Add CYW43 GPIO child node to the airoc-wifi device node on both
Pico W and Pico 2 W boards. The GPIO controller exposes WL_GPIO0-2
and is available when WIFI_AIROC is enabled.
The LED and aliases are provided by application overlays since the
GPIO driver requires the WiFi stack to be active.
Signed-off-by: John Lin <mcjelcom@gmail.com>
Add a GPIO driver for the Infineon CYW43439 WiFi chip that exposes
WL_GPIO0-2 as standard Zephyr GPIO pins. Pin 0 is the onboard LED
on Raspberry Pi Pico W and Pico 2 W boards.
The GPIO node is a child of the AIROC WiFi device node in the
devicetree. GPIO control is performed via the WHD gpioout iovar,
serialized with a mutex. A shadow register tracks pin state since
the CYW43439 does not support GPIO readback.
Signed-off-by: John Lin <mcjelcom@gmail.com>
This uses the newly introduced Doxygen tags for exposing driver operations
documentation in the public docs.
As haptics_error_callback_t typedef is effectively also used for the
public API of the driver, it's moved outside of the "backend" group.
Signed-off-by: Benjamin Cabé <benjamin@zephyrproject.org>
The qemu_leon3 DTS declares 1GB of SRAM (reg = <0x40000000 0x40000000>)
but the QEMU command line never specified a -m option, so QEMU used its
default of 128MB. This mismatch was silently tolerated until now because
nothing validated the heap's end marker beyond physical RAM.
When CONFIG_COMMON_LIBC_MALLOC_ARENA_SIZE=-1 (the default), the malloc
heap claims the entire declared SRAM (~1GB). The heap end marker chunk
is written at ~1GB offset from the heap base, well beyond QEMU's 128MB
of physical RAM. Those writes are silently lost, leaving the end
marker's LEFT_SIZE field as zero.
Commit bec6349cc7 ("lib: heap: introduce SYS_HEAP_HARDENING tiered
Kconfig") made bidirectional size round-trip checks the default when
CONFIG_ASSERT=y (MODERATE level). The check left_chunk(right_chunk(c))
reads back the end marker's LEFT_SIZE and detects the zero value,
triggering "heap corruption (free chunk linkage)" across many unrelated
tests on this board.
Add -m 1G to the QEMU flags so the emulated RAM matches the declared
DTS size, consistent with how other QEMU boards (arc, riscv32, x86)
already specify their memory.
Signed-off-by: Nicolas Pitre <npitre@baylibre.com>
The nrf52840dk ram_load variant is very tight on RAM. The MCUboot
RAM_LOAD padding section rounds the image size up to the next
power-of-2 boundary, so even a small increase in code or rodata
can double the padding and overflow the RAM region.
The sys_heap hardening code pushes the image just over the 128KB
boundary, causing padding to jump from 128KB to 256KB and
overflowing RAM by ~55KB.
Disable heap hardening for this build. Since CONFIG_ASSERT is off,
the previous __ASSERT-gated heap checks were inactive anyway, so
HARDENING_NONE preserves the same level of validation.
Signed-off-by: Nicolas Pitre <npitre@baylibre.com>
At FULL hardening, trailer canaries on used chunks implicitly guard
adjacent free chunk headers: a sequential buffer overflow must corrupt
the used chunk's trailer before reaching the next header. However,
when a free neighbor's metadata is needed for merging during free(),
the neighbor's header could already have been corrupted by an overflow
from its left used chunk that hasn't been freed yet. For example:
[hdr_U1] [data_U1] [trailer_U1] [hdr_F] [...] [hdr_U2] [trailer_U2]
If data_U1 overflows past trailer_U1 and corrupts hdr_F, freeing U2
would use hdr_F's corrupted size and free-list pointers for merging,
potentially leading to heap structure corruption or arbitrary writes.
Additionally, a corrupted LEFT_SIZE in a used chunk being freed can
point to a fake header crafted inside the left neighbor's data area:
[hdr_U1] [data_U1 ..fake_hdr.. trailer_U1'] [hdr_U2'] [data_U2] ...
| corrupted LEFT_SIZE points
| by overflow to fake_hdr
+<--------------------------+
A determined attacker can make fake_hdr's size field self-consistent
with the corrupted LEFT_SIZE so that the structural round-trip checks
pass. If fake_hdr is marked "used", free_chunk() skips the left
merge and the corruption goes undetected. If marked "free", it
triggers a bogus merge with attacker-controlled free-list pointers.
Both cases are caught by verifying the left used neighbor's canary:
any overflow from the left must pass through trailer_U1 to reach
hdr_U2's LEFT_SIZE field, so the corrupted canary acts as a tripwire
regardless of whether the resulting fake header is marked used or free.
Address this by introducing free_chunk_check() which validates a free
chunk's structural integrity before trusting its header fields. It
consolidates the existing MODERATE-level structural checks (chunk
linkage, used-bit consistency) with a new FULL-level canary
verification of the left used neighbor. Factoring these checks into
a dedicated function lets callers specify @left_trusted according to
context (e.g. the chunk being freed is the left neighbor of the right
merge candidate, so its canary need not be rechecked).
In inplace_realloc()'s shrink path, the freed suffix's left neighbor
is always the chunk being reallocated (used, just validated). This
path inlines only the right merge to avoid the unnecessary left canary
check.
The check is called before every free list removal: in free_chunk()
for left/right merge candidates, in alloc_chunk() when pulling from
a bucket, and in inplace_realloc() before consuming the right
neighbor.
Also give chunk0 a canary trailer so that the left-neighbor canary
check works uniformly for the first free chunk in the heap.
Signed-off-by: Nicolas Pitre <npitre@baylibre.com>
Replace canary-specific test variants with hardening level variants:
- hardening_none: verifies zero-overhead path
- hardening_full: exercises canary + all lower-level checks
No extreme variant is added as the tests already perform explicit
heap validation after each operation.
Signed-off-by: Nicolas Pitre <npitre@baylibre.com>
Replace the standalone SYS_HEAP_CANARIES bool with a tiered
SYS_HEAP_HARDENING choice controlling runtime validation:
NONE (0) - no checks
BASIC (1) - double-free and overflow detection in free/realloc
MODERATE (2) - free list and neighbor consistency checks
FULL (3) - trailer canary on every allocation
EXTREME (4) - exhaustive heap validation on every operation
Default is MODERATE when ASSERT is enabled, BASIC otherwise.
Hardening checks are independent of CONFIG_ASSERT: they use
LOG_ERR + k_panic() instead of __ASSERT so the configured level
is always honored regardless of assertion settings.
Also adds heap logging via LOG_MODULE_REGISTER. This paves the way for
eventual permanent debugging instrumentation.
Signed-off-by: Nicolas Pitre <npitre@baylibre.com>
Factor out the core heap validation logic into z_heap_full_check()
which takes a struct z_heap pointer directly. This allows internal
callers (e.g. alloc_chunk) to validate the heap without needing
the public struct sys_heap wrapper.
sys_heap_validate() becomes a thin wrapper that calls
z_heap_full_check() and then validates runtime stats.
Signed-off-by: Nicolas Pitre <npitre@baylibre.com>
Add canary-enabled test variants to the heap, heap_align, and heap_min
test suites to exercise the heap canary corruption detection feature.
Signed-off-by: Nicolas Pitre <npitre@baylibre.com>
Add optional canary values at the end of each heap allocation to detect
memory corruption. The canary is validated when memory is freed, catching
buffer overflows (writing past allocation) and double-free errors.
The canary is computed from the chunk address and size, XORed with a
magic value. On free, it is checked and then poisoned to detect
double-free attempts.
The canary is stored as trailer data at the end of the chunk rather than
in the header to avoid complicating aligned allocation processing, and
because buffer overflows are most likely to overwrite past the buffer end
anyway.
This adds 8 bytes of memory overhead per allocation and a canary
computation on alloc and validation on free. It is useful for hardening
against memory corruption as well as for chasing bugs during
development. The trailer structure can be readily extended to carry
additional per-allocation metadata if so desired.
Signed-off-by: Nicolas Pitre <npitre@baylibre.com>
The function checks if a chunk is too small to be added to the free list.
The new name better reflects its purpose and the comparison now uses
min_chunk_size() for clarity.
Such chunks are not added to the free list because they would be too
small to be allocatable, and they might be too small to store the free
list pointers. It happens that min_chunk_size() is always >= the free
pointer storage size.
The big_heap() condition short-circuits the comparison with a build-time
constant when undersized chunks cannot occur.
A following commit will rely on this to exclude chunks that are smaller
than min_chunk_size() which will grow to account for trailer data.
Signed-off-by: Nicolas Pitre <npitre@baylibre.com>
Replace chunksz_to_bytes() which took a chunk size with
chunk_usable_bytes() which takes a chunk_id directly. This eliminates
the redundant pattern of chunksz_to_bytes(h, chunk_size(h, c)) and makes
the API clearer by returning actual usable bytes (excluding the header).
Add mem_align_gap() helper to compute alignment padding between the
start of usable chunk memory and the actual memory pointer, using
efficient bit masking. This simplifies sys_heap_usable_size() and
inplace_realloc(). Use these helpers to make runtime stats reporting
reflect actual usable chunk memory (excluding chunk headers), and heap
listener notifications also account for alignment gaps.
Signed-off-by: Nicolas Pitre <npitre@baylibre.com>
This test relied on carefully chosen hardcoded heap sizes that had to
be adjusted per Kconfig combination — exactly the fragile pattern the
build-time heap constants work is eliminating. More importantly, the
test had no way to actually verify that a solo free header was created:
it merely allocated 1 byte from a specific heap size and called
sys_heap_validate(), which only does a general consistency walk.
The solo free header code path is already exercised organically by the
stress tests (test_small_heap, test_fragmentation) which hit all edge
cases including minimal leftover chunks.
Signed-off-by: Nicolas Pitre <npitre@baylibre.com>
Add documentation for zephyr_constants_library() to the build
system overview, explaining how it works, its current users
(offsets.h and heap_constants.h), and how to add new build-time
constants.
Signed-off-by: Nicolas Pitre <npitre@baylibre.com>
Z_HEAP_MIN_SIZE and Z_HEAP_MIN_SIZE_FOR were defined in kernel.h as
hardcoded magic numbers gated by a growing tower of #ifdefs — one
per Kconfig option that happened to affect the heap struct layout.
Every internal change required manually recomputing the constants,
duplicating layout knowledge across files, and praying nobody forgot
to update the #ifdef matrix. This is fragile and unscalable: adding
a single new heap feature (e.g. a chunk canary trailer) would add yet
another dimension to the combinatorial explosion.
Replace this with build-time computation from the actual C structures.
A new lib/heap/heap_constants.c uses GEN_ABSOLUTE_SYM to emit the
correct values into a generated heap_constants.h header via the
zephyr_constants_library() infrastructure. Z_HEAP_MIN_SIZE is
derived through an iterative fixed-point expansion (3 rounds, always
convergent) that mirrors the runtime logic in sys_heap_init().
Big vs small heap determination uses CONFIG_SYS_HEAP_SMALL_ONLY,
CONFIG_SYS_HEAP_BIG_ONLY, and sizeof(void *), mirroring the
big_heap_chunks() logic in heap.h.
Signed-off-by: Nicolas Pitre <npitre@baylibre.com>
Add an optional DEPENDS parameter to zephyr_constants_library() that
lists other constants libraries whose generated headers must be
produced before this library is compiled. This creates proper build
ordering through add_dependencies() on the header-generation targets.
A build test with four constants libraries exercising various
dependency patterns (fan-in, fan-out, diamond) validates this.
Signed-off-by: Nicolas Pitre <npitre@baylibre.com>
Introduce a reusable CMake function that creates an OBJECT library
from a C source file containing GEN_ABSOLUTE_SYM() declarations and
generates a header file from the resulting symbols. This encapsulates
the boilerplate needed for the offsets-style pattern: OBJECT library
creation, LTO prohibition, gen_offset_header.py invocation, and
dependency registration.
Convert the existing offsets.h generation to use this new function.
The zephyr_generated_headers target is moved earlier in CMakeLists.txt
so that subsystem CMakeLists.txt files can register generated headers
via zephyr_constants_library().
Also update gen_offset_header.py to derive the include guard from the
output filename instead of hardcoding __GEN_OFFSETS_H__, and remove the
unused input_name parameter. This allows multiple generated headers to
coexist with distinct include guards.
Signed-off-by: Nicolas Pitre <npitre@baylibre.com>
Clearing the status register in adxl367_thread_cb() introduces
a one-sample latency since any trigger handler invoking
adxl367_get_accel_data() has to wait until the next sample sets the
DATA_READY bit again. To fix this, identify trigger source by
reading status_copy register in adxl367_thread_cb(). This preserves
the status register contents for verification prior to fetching data.
Signed-off-by: Shiril Tichkule <Shiril.Tichkule@analog.com>
Regression when original D8C PLL changes were added results
in an unused variable. This fixes that warning.
Signed-off-by: James Bennion-Pedley <james@bojit.org>
Replace ternary operator with if-else to avoid mixing signed and unsigned
types in the conditional expression. This eliminates the compiler warning
while preserving the original logic.
Fixes#104581
Signed-off-by: Roman Bakshansky <bakshansky@protonmail.com>
Add wait for the calibration process to complete when
releasing the clock if an RC oscillator is used.
Signed-off-by: Adam Kondraciuk <adam.kondraciuk@nordicsemi.no>
This commit is to add DTC transfer feature for both SPI controller mode
and peripheral mode on board RSK-RX130-512KB
Signed-off-by: Minh Tang <minh.tang.ue@bp.renesas.com>
Compress the `struct ina2xx_channels` to only the channels that are
supported. This has the added benefit that trying to access an
unsupported channel (in the driver) is now a compile-time error.
Signed-off-by: Jordan Yates <jordan@embeint.com>
Use `#ifdef`, `#else`, `#endif` to block out implementations, instead
of putting the checks inside an `if`, which results in all the
implementations being indented.
It also makes it much clearer to any user with syntax highlighting
configured, since the unsupported channels are greyed out.
Signed-off-by: Jordan Yates <jordan@embeint.com>
Fix calling `sensor_channel_get` on a channel that is not supported by
the hardware from faulting with a NULL de-reference.
This fixes the following pattern (used by `fuel_guage/composite`):
```
sensor_sample_fetch(dev);
if (sensor_channel_get(dev, chan, val) == -EINVAL) {
printk("Not supported\n");
}
````
Signed-off-by: Jordan Yates <jordan@embeint.com>
This reverts commit ae44e1e7b7.
The only consequence of removing NULL checks is enabling NULL
dereference exceptions. The sensor API is a generic API, a generic
library built on top of that API does not always know which channels a
device supports.
Signed-off-by: Jordan Yates <jordan@embeint.com>
This reverts commit 8340e8c264.
The only consequence of removing NULL checks is enabling NULL
dereference exceptions. The sensor API is a generic API, a generic
library built on top of that API does not always know which channels a
device supports.
Signed-off-by: Jordan Yates <jordan@embeint.com>
Some ARMv6-M and ARMv8-M Baseline cores indeed support MPU
(CPU_HAS_ARM_MPU in soc Kconfig), so the exclusion should
not be based on ARMV6_M_ARMV8_M_BASELINE.
Signed-off-by: Andy Lin <andylinpersonal@gmail.com>
Adds basic support for the "WeActStudio CAN485 DevBoard V1 ESP32", which
has 8 MB of onboard QSPI flash memory, the BOOT and USER buttons on GPIO0,
a digital RGB LED on GPIO4 controlled via SPI2, UART0 as Zephyr console,
UART1 as RS-485 with DE on GPIO17 for Modbus RTU/ASCII, TWAI as CAN 2.0,
and an SD card slot on SPI3. There is an external voltage power supply
that can be measured via a 1:12 divider on ADC0 (SENSOR VP).
Signed-off-by: Stephan Linz <linz@li-pro.net>
The ARM Architecture Reference Manual (DDI 0487) requires a context
synchronization event (ISB) between modifying SVE trap control registers
(CPTR_EL3.EZ, CPTR_EL2.TZ, CPACR_EL1.ZEN) and accessing the
corresponding ZCR_ELx registers: "The effect of the change is guaranteed
to be observable only after a Context synchronization event."
Without the ISB, the processor may still observe the old trap
configuration and generate an UNDEFINED exception on the ZCR write.
This also fixes the EL2 SVE initialization for non-VHE mode
(HCR_EL2.E2H=0): CPTR_EL2 bits [17:16] (ZEN) are RES0 in non-VHE
format and must not be set. SVE trapping at EL2 in non-VHE mode is
controlled by the TZ bit (bit 8) instead. The previous code wrote the
VHE-format ZEN bits which is architecturally UNPREDICTABLE in non-VHE
mode. Match the Linux kernel sequence (arch/arm64/include/asm/el2_setup.h).
Signed-off-by: Nicolas Pitre <npitre@baylibre.com>
Extend the ARM Cortex-M coredump arch block to version 3 with metadata
that provides the offset to the callee_saved struct within k_thread.
This enables the coredump GDB stub to accurately retrieve callee-saved
registers (r4-r11) for non-faulting threads during multi-thread
debugging.
Signed-off-by: Mark Holden <mholden@meta.com>
For adding metadata and verifying images on Infineon Edge devices
switch to using the mcuboot tool imgtool rather than depending on
the Infineon specific edgeprotecttools. For the purposes required
in the Zephyr environment this is more than enough.
Signed-off-by: Laura Carlesso <laura.carlesso@infineon.com>
The arch_dcache_enable() and arch_icache_enable() functions could
cause system crashes when called on caches that were already enabled.
This occurs because arch_dcache_invd_all() invalidates the entire
cache without first flushing dirty data, leading to memory corruption
when the cache was previously enabled.
This scenario happens in cache tests where test setup calls
sys_cache_data_enable(), but the SoC early init hook has already
enabled caches during boot.
Fix by checking the SCTLR register before performing cache operations:
- If D-cache is already enabled, perform clean+invalidate instead of
just invalidate to preserve dirty cache lines
- If I-cache is already enabled, perform invalidate only (no dirty
lines in I-cache)
- If cache is not enabled, proceed with normal enable sequence
This makes the enable functions safe to call multiple times without
risking data corruption or system crashes.
Signed-off-by: Appana Durga Kedareswara rao <appana.durga.kedareswara.rao@amd.com>
relocate_vector_table is called as part of z_arm_reset.
This is considered early-boot code before XIP.
At this stage, Program might not have access to optimized
compiler APIs that reside in FLASH.
Thus, its better for relocate_vector_table to use arch_early_memcpy.
Signed-off-by: Shreyas Shankar <s-shankar@ti.com>