Commit graph

136,983 commits

Author SHA1 Message Date
Eve Redero
f232fd6fb1 doc: migration: add how-to for eeprom mac
Add quick explanation on how to implement the new EEPROM
MAC feature.

Signed-off-by: Eve Redero <eve.redero@gmail.com>
Co-authored-by: Pieter De Gendt <pieter.degendt@gmail.com>
2026-03-31 13:51:47 -05:00
Diego Herranz
87898b3612 boards: st: nucleo_c542rc: fix identifier and name in yaml
Fixes twister support and zephyr:board-supported-hw directive
in documentation that was not working.

Signed-off-by: Diego Herranz <diegoherranz@diegoherranz.com>
2026-03-31 13:51:08 -05:00
Valerio Setti
b021871594 Revert "samples: wifi: shell: Avoid circular psa_generate_random() calls"
This reverts commit 70969f88f5.

Signed-off-by: Valerio Setti <vsetti@baylibre.com>
2026-03-31 13:50:34 -05:00
Valerio Setti
e35b29c782 tests: crypto: mbedtls_psa: adjust main stack size
Increase main stack size because when TF-PSA-Crypto is initialized through
psa_crypto_init() the stack being used is the main one not the test one.

Signed-off-by: Valerio Setti <vsetti@baylibre.com>
2026-03-31 13:50:34 -05:00
Valerio Setti
5aa4bd6bbd random: enable Xoshiro post-processing when ENTROPY_NEEDS_POST_PROCESSING
Enabling CONFIG_XOSHIRO_RANDOM_GENERATOR when
CONFIG_ENTROPY_NEEDS_POST_PROCESSING is set, we can support entropy
drivers which are not able to provide large amount of data.

Signed-off-by: Valerio Setti <vsetti@baylibre.com>
2026-03-31 13:50:34 -05:00
Valerio Setti
2752c8c97f modules: mbedtls: improve entropy gathering
Do not depend on "sys_csrand_get()" as this can create runtime deadloops
when CONFIG_PSA_CSPRNG_GENERATOR is also enabled. Instead poll directly
the entropy device if available.

Kconfig-wise enable MBEDTLS_PSA_CRYPTO_LEGACY_RNG also when
ENTROPY_NEEDS_PRNG. This helps when there are entropy drivers (therefore
CONFIG_CSPRNG_ENABLED is set) which can provide only limited amount of
data.

Signed-off-by: Valerio Setti <vsetti@baylibre.com>
2026-03-31 13:50:34 -05:00
Valerio Setti
a28407d9b2 drivers: entropy: mcux: require PRNG on ENTROPY_MCUX_TRNG
According to the note the driver is not able to provide large amount of
data and it can only be used as seed for a RNG. Therefore enable
ENTROPY_NEEDS_PRNG on it.

Signed-off-by: Valerio Setti <vsetti@baylibre.com>
2026-03-31 13:50:34 -05:00
Valerio Setti
2b9e3265c8 drivers: entropy: add new Kconfig ENTROPY_NEEDS_PRNG
This Kconfig is used to signal that the entropy driver needs a PRNG crypto
algorithm on the provided data. The reason is that the driver is not
capable of providing large amount of data in a relatively short amount of
time.

Signed-off-by: Valerio Setti <vsetti@baylibre.com>
2026-03-31 13:50:34 -05:00
Flavio Ceolin
13ba30a323 doc: release/4.4: Add CVE under embargo
Add CVE (2026-5072) under embargo fixed during 4.4 development

Signed-off-by: Flavio Ceolin <flavio.ceolin@gmail.com>
2026-03-31 13:49:41 -05:00
Flavio Ceolin
04c3b11fbe doc: vuln: Add CVE under embargo
Add an entry to CVE-2026-5072

Signed-off-by: Flavio Ceolin <flavio.ceolin@gmail.com>
2026-03-31 13:49:41 -05:00
Flavio Ceolin
1e595d5864 doc: vuln: Add CVE under embargo
Add an entry to CVE-2026-5071

Signed-off-by: Flavio Ceolin <flavio.ceolin@gmail.com>
2026-03-31 13:49:41 -05:00
Flavio Ceolin
4b92d9cc33 doc: release/4.4: Add CVE under embargo
Add CVE (2026-5071) under embargo fixed during 4.4 development.

Signed-off-by: Flavio Ceolin <flavio.ceolin@gmail.com>
2026-03-31 13:49:41 -05:00
Flavio Ceolin
32af96568d doc: release/4.4: Add CVE under embargo
Add CVE (2026-1681) under embargo fixed during 4.4 development.

Signed-off-by: Flavio Ceolin <flavio.ceolin@gmail.com>
2026-03-31 13:49:41 -05:00
Flavio Ceolin
f8713ffcab doc: vuln: Add CVE under embargoo
Add an entry to CVE-2026-1681

Signed-off-by: Flavio Ceolin <flavio.ceolin@gmail.com>
2026-03-31 13:49:41 -05:00
Flavio Ceolin
bc77e9b897 doc: release/4.4: Disclose CVE-2026-1679
Disclose information about published CVE.

Signed-off-by: Flavio Ceolin <flavio.ceolin@gmail.com>
2026-03-31 13:49:41 -05:00
Flavio Ceolin
80c383034b doc: security: Disclose CVE-2026-1679
Disclose information about published CVE.

Signed-off-by: Flavio Ceolin <flavio.ceolin@gmail.com>
2026-03-31 13:49:41 -05:00
Flavio Ceolin
df4c8231c9 doc: vuln: Add CVE under embargo
Add an entry to CVE-2026-5068

Signed-off-by: Flavio Ceolin <flavio.ceolin@gmail.com>
2026-03-31 13:49:41 -05:00
Flavio Ceolin
6e07307786 doc: release/4.4: Add CVE under embargo
Add CVE (2026-5067) under embargo fixed during 4.4 development.

Signed-off-by: Flavio Ceolin <flavio.ceolin@gmail.com>
2026-03-31 13:49:41 -05:00
Flavio Ceolin
b78b47d72e doc: vuln: Add CVE under embargo
Add an entry to CVE-2026-5067

Signed-off-by: Flavio Ceolin <flavio.ceolin@gmail.com>
2026-03-31 13:49:41 -05:00
Flavio Ceolin
c6870d6322 doc: release/4.4: Add CVE under embargo.
Add CVE under embargo fixed during 4.4 development.

Signed-off-by: Flavio Ceolin <flavio.ceolin@gmail.com>
2026-03-31 13:49:41 -05:00
Flavio Ceolin
ef75a302bf doc: vuln: Add CVE under embargo
Add an entry to CVE-2026-5066

Signed-off-by: Flavio Ceolin <flavio.ceolin@gmail.com>
2026-03-31 13:49:41 -05:00
Daniel Leung
23054a97f4 kernel: dynamic stack to cached area if coherence
With kernel coherence enabled, it is possible that the stack has
been allocated on uncached area. This has implications on
performance as memory access is not cached.

This adds a kconfig to force the indicated stack pointer of
the allocated thread stack object to be in cached area.

Signed-off-by: Daniel Leung <daniel.leung@intel.com>
2026-03-31 11:45:30 -04:00
Alberto Escolar Piedras
0986ed8b20 docs: release-notes: 4.4: Add mention of cross-compiling native_sim
Add one point about now being able to cross compile native simulator
based targets.

Signed-off-by: Alberto Escolar Piedras <alberto.escolar.piedras@nordicsemi.no>
2026-03-31 10:36:56 -05:00
Sebastiaan Merckx
03bff638ac net: dns: dns_sd: fix incorrect use of buffer size
The functions that add DNS records (PTR, SRV, TXT, AAAA, A) all use a
buf_size argument which represents the size of the whole buffer, not the
remaining size. The higher function that calls these did not provide the
correct argument: it passed the remaining size in the buffer.

Signed-off-by: Sebastiaan Merckx <sebastiaan.merckx@verhaert.com>
2026-03-31 10:36:36 -05:00
Sylvio Alves
a3c6d7a3d4 modules: mbedtls: add missing zephyr_generated_headers dependency
Mbed TLS libraries are external CMake targets created via
add_library()/add_subdirectory(), not zephyr_library(). They
link against zephyr_interface for include paths but miss the
automatic add_dependencies on zephyr_generated_headers that
zephyr_library() targets receive.

This causes a build race condition where generated headers
like heap_constants.h may not exist when Mbed TLS sources
compile, resulting in a fatal error when x509_crt.c includes
zephyr/kernel.h through the POSIX sys/socket.h shim.

Add an explicit dependency on zephyr_generated_headers for
all Mbed TLS library targets.

Signed-off-by: Sylvio Alves <sylvio.alves@espressif.com>
2026-03-31 10:35:40 -05:00
alperen sener
6d137ae015 bluetooth: host: defer IRK resolving list update to scan/adv start
Stop scheduling bt_id_add() as workqueue work during settings load.
Mark keys BT_KEYS_ID_PENDING_ADD only, then flush them synchronously
in start_scan(), adv_start_legacy()/bt_le_ext_adv_start(),
bt_conn_le_create and bt_conn_le_create_auto when
BT_DEV_ID_PENDING is set.

We don't necessarily need to update resolving list in controller
unless actively start using it, also eliminates a race where a
workqueue-issued bt_id_add() blocks on HCI while bt_keys_clear()
concurrently zeroes the same key slot.

Signed-off-by: alperen sener <alperen.sener@nordicsemi.no>
2026-03-31 10:34:08 -05:00
Jiafei Pan
ac48cb5df1 soc: imx93: add enet clock initialization
If Zephyr is booted from U-Boot, ENET clock has been initialized by
U-Boot and it works, but if Zephyr is booted by using SPSDK runner,
ENET clock is not initialized and ENET will not work, so adding ENET
clock initialization in Zephyr to fix this issue.

Fixes: #106398

Signed-off-by: Jiafei Pan <Jiafei.Pan@nxp.com>
2026-03-31 10:29:57 -05:00
Sylvio Alves
53c8eccf91 soc: espressif: fix ulp_shm memory region overlap
The ulp_shm DTS node at 0x3bf0 overlapped with the last
16 bytes of the ulp_ram region (0x0..0x3c00) on both
ESP32-C5 and ESP32-C6.

Move ulp_shm to 0x3c00, right after ulp_ram, and shift
lp_rtc from 0x3c00 to 0x3c10 (shrinking it by 16 bytes
from 0xf8 to 0xe8) to make room. All other regions
(retainedmem, ipc_shm, mbox0) keep their addresses.

Update LP core linker scripts to stop subtracting
shared mem size from the ram segment length, since
ulp_shm is now outside the coprocessor reservation.

Signed-off-by: Sylvio Alves <sylvio.alves@espressif.com>
2026-03-31 10:29:02 -05:00
Ivan Iushkov
b9c4d724b4 lib: net_buf: inline several simple functions
This commit aims to slightly improve performance of
Zephyr-based applications by inlining often-used functions.

net_buf is used by different subsystems and applications so
performance of this library affects performance of many other
modules and it is important to keep its implementation efficient
and robust.

The following functions were moved from buf_simple.c to net_buf.h:
- net_buf_simple_headroom() - it was already used by some of inlined
functions which made inlining less efficient
- net_buf_simple_tailroom() and net_buf_simple_max_len() that do
very basic size calculations

Signed-off-by: Ivan Iushkov <ivan.iushkov@nordicsemi.no>
2026-03-31 10:27:20 -05:00
Szymon Janc
2f5145b34f test: bluetooth: tester: Fix GAP/CONN/DCON/BV-05-C test
For GAP/CONN/DCON/BV-05-C PTS expects IUT to fail operation
if the peer does not support Central Address Resolution.

In Test Set there is ALT to start undirected advertising instead
but PTS interpretation is that IUT shall reject directed request
regardless and may then later on follow up with underected
advertising (which PTS doesn't validate). To keep this simple
just reject here.

Signed-off-by: Szymon Janc <szymon.janc@codecoup.pl>
2026-03-31 10:26:54 -05:00
Pete Johanson
db021d2d52 manifest: Update ADI HAL module
Pull in updated ADI HAL for SPI driver fixes for MAX32 RV32 cores.

Signed-off-by: Pete Johanson <pete.johanson@analog.com>
2026-03-31 10:26:07 -05:00
Pete Johanson
c7d65aa6d2 tests: drivers: spi: Set up SPI testing for MAX32690 RV32
Necessary setup for doing SPI loopback testing on MAX32690EVKIT RV32 core,
to verify that peripheral on the secondary core.

Signed-off-by: Pete Johanson <pete.johanson@analog.com>
2026-03-31 10:26:07 -05:00
Pete Johanson
de02f0079a dts: adi: max32: Fixed interrupt numbers for MAX32690 RV32 core
Corret the RV32 core interrupt numbers for MAX32690 specific peripherals,
to allow proper interrupt usage with those peripherals.

Signed-off-by: Pete Johanson <pete.johanson@analog.com>
2026-03-31 10:26:07 -05:00
Yangbo Lu
1be0d9a58b drivers: ethernet: dsa_tag_netc: validate RX tag before using
The RX tag length and port index in the tag should be validated
before using.

Signed-off-by: Yangbo Lu <yangbo.lu@nxp.com>
2026-03-31 10:25:39 -05:00
Jamie McCrae
3d5146b5d8 zephyr: arch: arm: cortex_m: linker: Add missing XIP check
Adds a missing check for CONFIG_XIP to be set to use the mapped
partition information, this was wrongly missed from here when it
was added to the other linker files

Signed-off-by: Jamie McCrae <jamie.mccrae@nordicsemi.no>
2026-03-31 10:24:06 -05:00
Benjamin Cabé
f9db084e0c include: drivers: mipi_dbi: document MIPI-DBI driver ops using Doxygen
Use doxygen driver_ops commands to properly document the required/optional
MIPI-DBI driver operations

Signed-off-by: Benjamin Cabé <benjamin@zephyrproject.org>
2026-03-31 10:23:34 -05:00
Jacob Wienecke
99a9e1a284 drivers: hwinfo: rw61x: fix multi-cause reset handling
POWER_GetResetCause() returns an OR'd bitmask since multiple reset
causes can occur simultaneously. The switch statement only matched
a single value, falling through to default and returning 0 when
multiple bits were set. Replace with bitwise checks to accumulate
all active reset flags.

Signed-off-by: Jacob Wienecke <jacob.wienecke@nxp.com>
2026-03-31 10:22:13 -05:00
Stephanos Ioannidis
cf4d0f7247 SDK_VERSION: Use Zephyr SDK 1.0.1
This commit updates SDK_VERSION to point to the Zephyr SDK 1.0.1 release,
which includes critical bug fixes for Xtensa and OpenRISC architectures.

Signed-off-by: Stephanos Ioannidis <root@stephanos.io>
2026-03-30 18:06:16 -05:00
Stephanos Ioannidis
7b9189da7c ci: Switch to CI image v0.29.1
This commit updates the CI workflows to use the CI image v0.29.1, which
includes the Zephyr SDK 1.0.1.

Signed-off-by: Stephanos Ioannidis <root@stephanos.io>
2026-03-30 18:06:16 -05:00
Daniel Leung
1c9adc24ad intel_adsp: doc: update rimage building instructions
Since the SOF module is no longer pulled in via west, we need to
build rimage outside of the Zephyr tree. Update the related doc
of building rimage and image signing to reflect this.

Signed-off-by: Daniel Leung <daniel.leung@intel.com>
2026-03-30 18:05:59 -05:00
Mathieu Choplain
fb06e7e806 include: irq: fix irq_lock() documentation
All lines of a `@warning` paragraph should be contiguous as any empty line
stops the warning block (text that follows the empty line is "normal").

Remove an empty line in the documentation of `irq_lock()` to ensure all
the text intended to be part of a warning does go in the warning block.

Signed-off-by: Mathieu Choplain <mathieu.choplain-ext@st.com>
2026-03-30 15:08:37 -05:00
Tomi Fontanilles
f0641bfbf5 modules: mbedtls: introduce CONFIG_TF_PSA_CRYPTO_USER_CONFIG_FILE
Equivalent of CONFIG_MBEDTLS_USER_CONFIG_FILE for TF-PSA-Crypto.
See the previous commit for an explanation on the implementation.

Signed-off-by: Tomi Fontanilles <tomi.fontanilles@nordicsemi.no>
2026-03-30 15:08:07 -05:00
Tomi Fontanilles
e14946ec90 modules: mbedtls: rework CONFIG_MBEDTLS_USER_CONFIG_FILE
Move it to the top of the Kconfig/header files as it belongs together
with CONFIG_MBEDTLS_CONFIG_FILE.

Do not include it directly in config-mbedtls.h, just define
MBEDTLS_USER_CONFIG_FILE. Mbed TLS's build_info.h takes care of actually
including it.

Make it so that there is no need to enable a boolean Kconfig option
to define CONFIG_MBEDTLS_USER_CONFIG_FILE.
As a result of that, CONFIG_MBEDTLS_USER_CONFIG_ENABLE is deprecated.

To achieve that, the promptless CONFIG_MBEDTLS_USER_CONFIG Kconfig
option is introduced to allow to automatically figure out whether
CONFIG_MBEDTLS_USER_CONFIG_FILE is defined.
This is done to work around the following limitations:
- Kconfig does not allow string Kconfig options to not be defined
(they always default to "").
- The C preprocessor does not allow checking string macros (to check
whether the Kconfig option is an empty string).

Signed-off-by: Tomi Fontanilles <tomi.fontanilles@nordicsemi.no>
2026-03-30 15:08:07 -05:00
Tomi Fontanilles
58d5fad69d modules: mbedtls: bring back and deprecate CONFIG_MBEDTLS_CFG_FILE
c6e6f3e638 removed it without warning,
but it should first be deprecated.

Make it so that it still works for users defining it.
A helper Kconfig option is introduce to `select DEPRECATED` because
selecting Kconfig options from string ones is not allowed.

Signed-off-by: Tomi Fontanilles <tomi.fontanilles@nordicsemi.no>
2026-03-30 15:08:07 -05:00
Lauren Murphy
bfd0c29335 intel_adsp: NOLOAD .noinit
Mark .noinit as NOLOAD to prevent LLEXT heaps included in
snippets-noinit.ld from being marked as PROGBITS.

Fixes #105858

Signed-off-by: Lauren Murphy <lauren.murphy@intel.com>
2026-03-30 15:06:56 -05:00
Ofir Shemesh
218aa7e19f net: dhcpv6: log received address at info level
The DHCPv4 client logs the received address with NET_INFO when an
address is successfully obtained from the server. The DHCPv6 client
had no equivalent log message, making it difficult to confirm that
DHCPv6 address assignment succeeded.

Add a NET_INFO log when a DHCPv6 address is successfully configured,
consistent with the DHCPv4 client behavior.

Signed-off-by: Ofir Shemesh <ofirshemesh777@gmail.com>
2026-03-30 15:06:15 -05:00
Ofir Shemesh
4398087c3e net: config: fix IPv6 event callback not registered for DHCPv6-only setups
In setup_ipv6(), the net management event callback registration was
placed after the early exit for empty CONFIG_NET_CONFIG_MY_IPV6_ADDR.
This means that in DHCPv6-only configurations (no static IPv6 address),
the callback was never registered, and the IPv6 address and lifetime
were never printed when DHCPv6 obtained an address.

This is inconsistent with setup_ipv4(), which correctly registers the
callback before the empty address check, allowing DHCPv4 address
events to be handled even without a static IPv4 address.

Move the event callback registration and router flag check before the
empty address goto, and always include NET_EVENT_IPV6_ADDR_ADD in the
event mask so that DHCPv6 address additions are always captured.

Signed-off-by: Ofir Shemesh <ofirshemesh777@gmail.com>
2026-03-30 15:06:15 -05:00
Ofir Shemesh
b1afb494b0 flash: nxp: align FlexSPI NOR DTS with soc-nv-flash layout
NXP FlexSPI NOR flash nodes were missing the soc-nv-flash child
node expected by Zephyr's flash map API.

Without this child node, DT_MTD_FROM_FIXED_PARTITION resolved to
the FlexSPI memory controller instead of the flash device. Since
the controller has api = NULL, MCUboot could hit a NULL pointer
dereference during boot on Zephyr 4.4.

Fix this by updating the DTS structure to match the soc-nv-flash
convention used by the flash map infrastructure.

Changes:
- add a soc-nv-flash child under each nxp,imx-flexspi-nor node
- move erase-block-size, write-block-size, and partitions into it
- add ranges to flash controller nodes for address translation
- update zephyr,flash to point to the soc-nv-flash child
- add zephyr,flash-controller chosen for the flash driver node
- remove soc-nv-flash.yaml from nxp,imx-flexspi-nor.yaml
- use zephyr,flash-controller in flash CMake XIP decisions
- update FlexSPI XIP Kconfig logic to walk to the grandparent

This keeps the controller and flash device roles separate and
restores correct flash map resolution for MCUboot and XIP logic.

Signed-off-by: Ofir Shemesh <ofirshemesh777@gmail.com>
2026-03-30 15:04:48 -05:00
Krisztian Szilvasi
7ee1146a5b drivers: memc: fix compiler warnings for stm32 ospi psram
shared_multi_heap_add expects the region parameter to be
a non-const parameter; if const is passed, it still discards
it, but generates warnings.

Signed-off-by: Krisztian Szilvasi <krisztian@atym.io>
2026-03-30 15:02:52 -05:00
Jaro Van Landschoot
b85c717d86 drivers: i2s: i2s_mcux_sai: i2s_mcux_write take size argument into account
The size argument was ignored in i2s_mcux_write. This caused unwanted
behaviour when writing data smaller than the configured size.

Signed-off-by: Jaro Van Landschoot <jaro.vanlandschoot@basalte.be>
2026-03-30 15:02:21 -05:00