1144 Commits
Author SHA1 Message Date
Atul Akella a0ec4fc2c7 remoteproc_virtio: guard null notify and check return status
rpvdev->notify is called from four places in this file: virtqueue
notify, set_status, set_features, and write_config. None guarded
against notify being NULL, valid when no mailbox is configured, and
none checked the returned status. Add a shared rpvdev_notify()
helper used at all four sites: skip when notify is NULL, log a
warning via metal_log on nonzero return. Exported notify signature
is unchanged, per discussion in issue #343.

Assisted-by: Claude <noreply@anthropic.com>
Signed-off-by: Atul Akella <atul.akella@gmail.com>
2026-09-28 10:33:45 +02:00
Ben Levinsky 22ddff1a4e remoteproc: Validate resource table entry bounds
Resource offsets from a copied firmware table are dereferenced without
bounds checks when no I/O region is present. Handlers can then access
memory beyond the table through a VDEV's flexible vring array.

Reject a NULL table, validate offset-array arithmetic, and require
every entry to remain inside the table before dispatch. Check fixed
sizes, VDEV vrings and config data, and vendor lengths using
overflow-safe subtraction.

Signed-off-by: Ben Levinsky <ben.levinsky@amd.com>
Assisted-by: Codex:GPT-5
2026-09-22 18:50:37 +02:00
Ben Levinsky 4d412df37f remoteproc: Validate virtqueue alignment
The remote resource table controls the vring alignment, which is used
for pointer rounding without validation. vring_init() rounds the used
ring address with a ~(align - 1) mask, so a zero alignment leaves a
NULL used ring that is dereferenced later.

Reject a zero alignment before calculating the vring size and before
storing the vring metadata taken from the resource table.

Signed-off-by: Ben Levinsky <ben.levinsky@amd.com>
Assisted-by: Codex:GPT-5
2026-09-22 18:50:37 +02:00
Ben Levinsky d0e5e0d376 proxy: Validate retarget read response length
_read() converts the peer-provided unsigned data length to a signed
integer and bounds it only against the caller's buffer size. Large
values can bypass that comparison or make memcpy() read beyond the
fixed response buffer.

Reject nonpositive destination sizes, retain the peer length as an
unsigned value, and clamp it to both the response payload capacity and
the caller's buffer before copying.

Signed-off-by: Ben Levinsky <ben.levinsky@amd.com>
Assisted-by: Codex:GPT-5
2026-09-21 09:54:50 +02:00
Ben Levinsky f7c918bf07 rpmsg: rpc: Validate client request lengths
The RPC client copies caller-provided parameters into a fixed-size
stack buffer without checking whether the complete request fits.
Oversized requests can therefore overwrite the caller's stack frame.

Reject requests that exceed the remaining parameter capacity before
copying them, validate nonempty parameter pointers, and document the
public API limit.

Signed-off-by: Ben Levinsky <ben.levinsky@amd.com>
Assisted-by: Codex:GPT-5
2026-09-21 09:54:50 +02:00
Ben Levinsky 49780d11b4 rpmsg: rpc: Validate client reply lengths
The RPC client reads the reply ID and status without checking that the
remote message contains the fixed reply header. It also passes the
total message length to callbacks that receive a parameters pointer,
making the reported length include the header bytes.

Reject replies shorter than the fixed header and pass callbacks only
the number of bytes that follow it.

Signed-off-by: Ben Levinsky <ben.levinsky@amd.com>
Assisted-by: Codex:GPT-5
2026-09-21 09:54:50 +02:00
Ben Levinsky 2b7013e733 proxy: Validate retarget write length
_write() copies a caller-controlled length into a fixed-size stack
buffer without checking that the RPC header and payload fit. Negative
lengths also become large unsigned memcpy() sizes, and the stdout NUL
terminator is written one byte beyond its intended position.

Reject invalid lengths before constructing the request. Include the
optional terminator in the capacity check and place the terminator
immediately after the copied payload.

Signed-off-by: Ben Levinsky <ben.levinsky@amd.com>
Assisted-by: Codex:GPT-5
2026-09-21 09:54:50 +02:00
Ben Levinsky 372048d49d rpmsg: rpc: Validate and initialize server requests
The RPC callback does not receive the request length, so it may
inspect bytes beyond a short message. Those bytes currently come from
an uninitialized stack buffer. A message shorter than the function ID
can also make the dispatch path read uninitialized data.

Reject messages that do not contain a complete function ID and
zero-initialize the request buffer so callbacks never consume stale
stack contents from bytes omitted by the remote peer.

Signed-off-by: Ben Levinsky <ben.levinsky@amd.com>
Assisted-by: Codex:GPT-5
2026-09-21 09:54:50 +02:00
Francesco Valla 80284e3ac0 virtqueue: add writable buffer helper
An application at device side might need to know if a buffer has been
marked as device-writable by the driver.
An example is the virtio SPI protocol, in which the direction of an
half-duplex communication can be determined by the device only by
checking if the buffer containing the data is writable or not.

Add a simple helper to test if a buffer is device-writable, that is,
if the VRING_DESC_F_WRITE flag is present on it.

Signed-off-by: Francesco Valla <francesco@valla.it>
2026-09-21 09:51:59 +02:00
Ben Levinsky 3ea751021e remoteproc: avoid wrapping loader offset comparison
Replace the non-seekable loader offset comparison that used offset + len
with an overflow-safe equivalent.

This preserves existing behavior for normal ranges while avoiding a
wraparound case when deciding whether required image data is contiguous
with the current chunk.

Signed-off-by: Ben Levinsky <ben.levinsky@amd.com>
2026-09-21 09:50:11 +02:00
Ben Levinsky 28b0a020c6 remoteproc: bound ELF section name lookups
Make ELF section-name lookup validate sh_name before reading from the
loaded section string table.

Skip malformed section names whose sh_name offset is outside the table
or whose string is not NUL-terminated within the remaining table bytes.
Use bounded comparison for valid candidates so .resource_table lookup
cannot read past the loaded string table.

Signed-off-by: Ben Levinsky <ben.levinsky@amd.com>
2026-09-21 09:50:11 +02:00
Ben Levinsky 08a45aca33 remoteproc: track loaded ELF section string-table size
Store the loaded section string-table size in the ELF image information
for both ELF32 and ELF64 images.

Keeping the size alongside the string-table pointer allows later section
name lookups to validate sh_name offsets against the actual loaded table
bounds.

Signed-off-by: Ben Levinsky <ben.levinsky@amd.com>
2026-09-21 09:50:11 +02:00
Ben Levinsky 872a4fcae7 remoteproc: harden ELF section string-table range checks
Use overflow-safe range validation before copying the ELF section string
table from the firmware image.

The section string-table offset and size are read from untrusted section
headers. Validate that the full table is present in the current image
chunk without relying on wrapping offset arithmetic.

Signed-off-by: Ben Levinsky <ben.levinsky@amd.com>
2026-09-21 09:50:11 +02:00
Ben Levinsky 8d245caca2 remoteproc: check ELF program and section table sizes
Use checked multiplication when computing ELF program and section header
table sizes from e_phnum/e_phentsize and e_shnum/e_shentsize.

Also replace wrapping offset-plus-length range checks with overflow-safe
image chunk validation before allocation and memcpy. Malformed firmware
images with impossible table sizes now fail with -RPROC_EINVAL.

Signed-off-by: Ben Levinsky <ben.levinsky@amd.com>
2026-09-21 09:50:11 +02:00
Ben Levinsky f3b110faff remoteproc: validate ELF header shape before table loading
Reject malformed ELF headers before using program or section table
metadata from the firmware image.

Validate the ELF class, ELF header size, program header entry size,
section header entry size, and section string-table index. Release an
image-info object allocated by this call if validation fails, while
leaving caller-owned objects untouched.

Signed-off-by: Ben Levinsky <ben.levinsky@amd.com>
2026-09-21 09:50:11 +02:00
Ben Levinsky 2ad0328fe6 remoteproc: add checked arithmetic helpers
Add generic checked addition, subtraction, and multiplication helpers
with consistent input validation across builtin and fallback
implementations.

Add a generic range-containment helper which reports arithmetic
overflow separately from non-containment. This lets the ELF loader
distinguish malformed ranges from data absent from the current image
chunk.

Signed-off-by: Ben Levinsky <ben.levinsky@amd.com>
2026-09-21 09:50:11 +02:00
Atul Akella 1e2cae3a2e docs: clarify release_cb initialization requirement
Document that callers must zero-initialize the endpoint structure
before calling rpmsg_create_ept, including the release_cb field.

Fixes #659

Signed-off-by: Atul Akella <atul.akella@gmail.com>
2026-09-10 10:28:15 +02:00
Sipke Vriend 2b172cef30 github actions:README: add some new lines and code block for clarity
Multiple lines of text are concatenated so use a code block for the
supported targets so they are on individual lines.

Signed-off-by: Sipke Vriend <sipke@direktembedded.com>
2026-09-09 19:10:47 +02:00
Sipke Vriend c0359e4ae5 github actions:README: use shell block for commands in Markdown files
Use the markdown shell block instead of prepending $ to command so that
users can copy the block, as supported in github and IDEs.

Signed-off-by: Sipke Vriend <sipke@direktembedded.com>
2026-09-09 19:10:47 +02:00
Sipke Vriend bb45852c58 README: use shell block for commands in Markdown files
Use the markdown shell block instead of prepending $ to command so that
users can copy the block, as supported in github and IDEs.

Signed-off-by: Sipke Vriend <sipke@direktembedded.com>
2026-09-09 19:10:47 +02:00
Chirag Shilwant 2e83e405d3 rpmsg: virtio: Change release_rx_buffer_nolock() return type to void
The function unconditionally returns true and neither call site
checks the return value. Remove the dead return and change the
return type to void.

Fixes: commit b32187e4fb ("openamp: change rx/tx buffer hold flag to count")

Signed-off-by: Chirag Shilwant <c-shilwant@ti.com>
2026-09-09 19:09:56 +02:00
Chirag Shilwant c2c26fce51 rpmsg: Fix RPMSG_BUF_INDEX macro to use parameter
The macro body references 'rp_hdr' instead of using the declared
parameter 'rphdr'. This causes the macro to ignore its argument and
always reference whatever 'rp_hdr' variable exists in the calling
scope. Fix by using the parameter name in the macro body.

Fixes: commit b32187e4fb ("openamp: change rx/tx buffer hold flag to count")

Signed-off-by: Chirag Shilwant <c-shilwant@ti.com>
2026-09-09 19:09:56 +02:00
Bill Mills 4ae383d32d CI: print disk freespace at the start and end of each job
Print the freespace so we can monitor how close we are to overflow.
Also allow manual trigger for main CI action.

Signed-off-by: Bill Mills <bill.mills@linaro.org>
2026-08-26 11:51:32 +02:00
Arnaud Pouliquen f171a36eb2 README: clarify Assisted-by tag guidance for AI-assisted contributions
Update the README contribution guidelines to document a consistent
Assisted-by tag format for AI-assisted patches.

Signed-off-by: Arnaud Pouliquen <arnaud.pouliquen@foss.st.com>
2026-07-29 18:36:14 +02:00
Arnaud Pouliquen cda8c64317 CI: install pip packages before exporting zephyr cmake package
Since Zephyr 4.0, the command west packages pip --install must be run
before west zephyr-export.

Without this order, an error can occur when running west zephyr-export.

ModuleNotFoundError: No module named 'jsonschema'

Signed-off-by: Arnaud Pouliquen <arnaud.pouliquen@foss.st.com>
2026-07-21 09:09:37 +02:00
Arnaud Pouliquen 4098a2c5bd CI: Update to Zephyr 4.4 to fix cmake dependency
Zephyr 4.3 does not properly support CMake 4.x.
The command "west sdk install" fails because of some Zephyr CMake files.

The issue has been fixed in Zephyr 4.4. Upgrade to Zephyr 4.4
instead of trying to apply a temporary fix for Zephyr 4.3.

Signed-off-by: Arnaud Pouliquen <arnaud.pouliquen@foss.st.com>
2026-07-21 09:09:37 +02:00
Shichun Ma 9ff23a10ce virtio: fix NULL pointer dereference in virtqueue_notification
Add a NULL check for vq before dereferencing it in
virtqueue_notification() to prevent a crash when vq is NULL.

Signed-off-by: Shichun Ma <masc2008@gmail.com>
2026-07-15 16:49:34 +02:00
Bill Mills 23d4c5d7a5 ReadTheDocs: eliminate the files no longer needed.
We now use the "git checkout command" in the RTDs project settings.
This means we will use the .readthedocs.yaml and conf.py from the
openamp-docs repo and no longer need these files in the submodules.

See openamp-docs/.readthedocs.yaml for details.

Signed-off-by: Bill Mills <bill.mills@linaro.org>
2026-06-02 14:11:56 +02:00
Jiaqi Yao 6def5356b8 README: remove deprecated cache options
Remove the split dcache CMake options from the README.

The options were removed by d183f24 after being deprecated in favor of
WITH_DCACHE. Document only WITH_DCACHE as the supported way to enable
cache operations for vrings, buffers and resource table.

Signed-off-by: Jiaqi Yao <yaojiaqi@lixiang.com>
2026-05-21 17:08:53 +02:00
Andrew Davis 468343399c cmake: Rename platform example cmake files
There is nothing "zynqmp" specific in these files, rename them to generic
ARM names. Having only "zynqmp" files in platforms as before might give
the impression only ZynqMP platforms are supported by this project.

Signed-off-by: Andrew Davis <afd@ti.com>
2026-05-11 18:06:55 +02:00
Andrew Davis dc65de1e01 cmake: Remove unused CMake variable PROJECT_PROCESSOR
This CMake variable is unused, looks to be copied over from libmetal CMake
files. Remove it.

Signed-off-by: Andrew Davis <afd@ti.com>
2026-05-11 18:06:55 +02:00
Andrew Davis e2ba0839a7 cmake: Remove unused CMake variables MACHINE and PROJECT_MACHINE
These were used when this repo contained machine specific examples.
With those moved to the openamp-system-reference project, these CMake
variables are now unused. Remove them.

Signed-off-by: Andrew Davis <afd@ti.com>
2026-05-11 18:06:55 +02:00
Arnaud Pouliquen 5bcc7c0401 release: open-amp 2026.04.0
Set library version to 1.10.0

Signed-off-by: Arnaud Pouliquen <arnaud.pouliquen@foss.st.com>
Signed-off-by: Ed Mooring <ed.mooring@gmail.com>
Signed-off-by: Tanmay Shah <tanmay.shah@amd.com>
v2026.04.0
2026-05-04 09:19:08 +02:00
Arnaud Pouliquen 89dea1d7a5 rpmsg: remove deprecated rpmsg_virtio API
The following configuration are deprecated since more than 2 years
(v2024.05):
- rpmsg_virtio_get_status
- rpmsg_virtio_get_features
- rpmsg_virtio_read_config
- virtio_write_config
- rpmsg_virtio_create_virtqueues
- rpmsg_virtio_delete_virtqueues

Signed-off-by: Arnaud Pouliquen <arnaud.pouliquen@foss.st.com>
2026-04-27 13:52:30 +02:00
Arnaud Pouliquen cfc300505e virtio: remove deprecated VIRTIO_DRIVER/DEVICE_ONLY support
The following configuration are deprecated since more than 2 years
(v2024.05):
- VIRTIO_DRIVER_ONLY
- VIRTIO_DEVICE_ONLY

Signed-off-by: Arnaud Pouliquen <arnaud.pouliquen@foss.st.com>
2026-04-27 13:52:30 +02:00
Arnaud Pouliquen 00a3c0d3f7 README: Fix URL format
Converted the openamp-system-reference URL to a markdown link for
better readability.

Signed-off-by: Arnaud Pouliquen <arnaud.pouliquen@foss.st.com>
2026-03-31 08:57:01 +02:00
Sipke Vriend 4a6835e34a doxygen: remove superfluous Doxyfile
file used by doxygen is doc/Doxyfile.in so remove the Doxyfile file
from root folder to avoid confusion.

Signed-off-by: Sipke Vriend <sipke@direktembedded.com>
2026-03-31 08:52:06 +02:00
Sipke Vriend da42e0cff6 doxygen: remove obsolete options
PERL_PATH and MSCGEN_PATH are no longer used, so remove from Doxyfile.in
to avoid warning:
to avoid warning
warning Tag 'PERL_PATH' ... has become obsolete.
warning: Tag 'MSCGEN_PATH' ... has become obsolete.

Signed-off-by: Sipke Vriend <sipke@direktembedded.com>
2026-03-31 08:52:06 +02:00
Sipke Vriend c876e31706 doc: add maintainers file to doxygen document generation
to provide access to maintainers information for this repository add it
to the input source files.

Signed-off-by: Sipke Vriend <sipke@direktembedded.com>
2026-03-31 08:52:06 +02:00
Li Zhiyuan 62b2888111 remoteproc: clear bitmap in remoteproc_shutdown()
Clear the allocated bitmap in `remoteproc_shutdown()` to
prevent resource table parsing failures on repeated remoteproc
starts.

Signed-off-by: Li Zhiyuan <doitysf@hotmail.com>
2026-02-25 08:53:15 +01:00
Arnaud Pouliquen 59e843f3ef CI: Fix compliance check folder bypass
On GitHub, this check is tagged as "Required."
However, if a PR only affects the following folders:.github, docs,
scripts, or cmake, the check is not executed (to avoid false positives),
resulting in the status "execution pending" + "required" on GitHub.

This commit forces the execution of the check but bypasses the
compliance.xml test when the PR only affects the listed folders.

If at least one update affects other folders, the compliance check
runs as usual.

In addition, the cmake folder is removed from the list, as there is
no reason to skip compliance tests on it.

Signed-off-by: Arnaud Pouliquen arnaud.pouliquen@foss.st.com
2026-01-26 15:04:34 +01:00
Arnaud Pouliquen 10768d0c6f CI: Update to Zephyr 4.3 and use default associated sdk
- bump to Zephyr 4.3
- use west packages pip --install
- use "west sdk install" command to install the expected sdk version.
- only install arm-zephyr-eabi compiler as build tested only on
  arm targets

Signed-off-by: Arnaud Pouliquen <arnaud.pouliquen@foss.st.com>
2025-12-17 19:07:54 +01:00
Arnaud Pouliquen be5770f305 lib: remoteproc: Fix remoteproc_remove_virtio
The code contains redundant checks with both metal_assert(vdev) and if
(!vdev).
Moreover, if the assert is disabled, it may lead to dereferencing a null
pointer.
We should not rely on asserts for API validation. Instead, replace the
assert with an error message.

Signed-off-by: Arnaud Pouliquen <arnaud.pouliquen@foss.st.com>
2025-12-05 15:48:10 +01:00
Arnaud Pouliquen e8866ee7df release: open-amp 2025.10.0
Set library version to 1.9.0

Signed-off-by: Arnaud Pouliquen <arnaud.pouliquen@foss.st.com>
Signed-off-by: Ed Mooring <ed.mooring@gmail.com>
Signed-off-by: Tanmay Shah <tanmay.shah@amd.com>
v2025.10.0
2025-11-03 10:51:10 +01:00
Ed Mooring 28ccd6b7b5 README: Remove references to apps directory and generated applications
These applications have been moved to the openamp-system-reference.
Signed-off-by: Ed Mooring <ed.mooring@gmail.com>
2025-11-03 10:50:50 +01:00
Arnaud Pouliquen a399378a5d virtio: remove deprecated virtio_describe() function
The function is deprecated since more than 2 years, remove it.

Signed-off-by: Arnaud Pouliquen <arnaud.pouliquen@foss.st.com>
2025-10-20 14:27:25 +02:00
Arnaud Pouliquen d183f24ea0 cmake: remove deprecated cache options
Remove the following CMake options and associated definitions that have
been deprecated for over two years:
- WITH_DCACHE_VRINGS
- WITH_DCACHE_BUFFERS
- WITH_DCACHE_RSC_TABLE
- VIRTIO_CACHED_RSC_TABLE
- VIRTIO_CACHED_BUFFERS
- VIRTIO_CACHED_VRINGS

Signed-off-by: Arnaud Pouliquen <arnaud.pouliquen@foss.st.com>
2025-10-20 14:27:25 +02:00
Arnaud Pouliquen f819642829 remoteproc virtio: Fix documentation
The function rproc_virtio_wait_remote_ready does not return a value.
Remove the related @return field from the documentation.

Signed-off-by: Arnaud Pouliquen <arnaud.pouliquen@foss.st.com>
2025-10-17 09:22:37 +02:00
Deep Chordia b42e8443b9 lib: remove CACHE_* macros
- removes CACHE_FLUSH macro clashing with internal QNX definition
- also removes CACHE_INVALIDATE macro for consistency

Signed-off-by: Deep Chordia <dchordia@blackberry.com>
2025-10-17 09:15:52 +02:00
Sipke Vriend 6db90ebfcd doxygen: define vring memory layout using table
review requested to use a table rather than a code snippet to define
the memory layout, so convert proposed struct to a table with
definition, size and description and explanation of padding between
available and used structures.

Signed-off-by: Sipke Vriend <sipke@direktembedded.com>
2025-10-16 11:20:37 +02:00