summaryrefslogtreecommitdiff
path: root/common
AgeCommit message (Collapse)Author
2026-06-04Release 6.5.1.202602 preparation (#267)Frédéric Desbiens
* Updated version number constants * Updated port version strings --------- Co-authored-by: Copilot <[email protected]>
2026-06-04fix(hid): fixed memory leak and double-free in keyboard/mouse/remote_control ↵Frédéric Desbiens
client lifecycle (#265) PR #262 introduced per-instance UX_HOST_CLASS_HID_CLIENT allocation in client_search.c. However, keyboard/mouse/remote_control activate handlers already embed a UX_HOST_CLASS_HID_CLIENT inside their own combined allocation (e.g. UX_HOST_CLASS_HID_CLIENT_KEYBOARD), override hid->hid_client with the embedded copy, and then free the entire combined struct (as 'keyboard_instance', the first field) during deactivation. This created two bugs: 1. Memory leak: the per-instance copy from client_search was abandoned when activate handlers replaced hid->hid_client with their embedded copy. 2. Double-free / UX_MEMORY_CORRUPTED: deactivate.c freed hid->hid_client after calling the handler, but for keyboard/mouse/remote_control the deactivate handler had already freed the entire combined allocation (which contains the embedded hid_client), causing a second free of a pointer into the middle of a now-freed block. Fix: - keyboard/mouse/remote_control activate: free the per-instance copy from client_search before overriding hid->hid_client with the embedded one. - keyboard/mouse/remote_control deactivate: null hid->hid_client after freeing the combined struct, signalling that cleanup is done. - deactivate.c: re-check hid_client != NULL after calling the handler before freeing; keyboard/mouse/remote_control will have nulled it, simple clients will not. - keyboard/mouse ACTIVATE_WAIT error paths (standalone): null hid->hid_client after freeing the combined struct so that the generic cleanup in entry.c skips the already-freed pointer. - entry.c standalone ACTIVATE_WAIT error: guard the free with a NULL check to safely handle both cases. Discovered while investigating test failures introduced by PR #262. All 430 tests pass after this fix. Co-authored-by: Copilot <[email protected]>
2026-06-04fix(hid): Store client instance per-device instead of per-class (#262)Kajtek Lau
* fix(hid): Store client instance per-device instead of per-class * Address review feedback on per-instance HID client copy Three issues fixed, discovered during maintainer review: 1. Memory leak in standalone activation error path (entry.c): _ux_host_class_hid_client_activate_wait() set hid_client to NULL without freeing the per-instance copy allocated in client_search. The HID_ENUM_ERROR handler destroys the hid struct without freeing hid_client, so the copy was leaked on every standalone activation failure. Fixed by freeing hid_client before clearing it. 2. Variable declared inside if-block (client_search.c): hid_client_instance was declared inside the if (status == UX_SUCCESS) block, which is a C99 feature. USBX targets C89/C90 embedded toolchains. Moved to the top of the function with other locals. 3. Trailing whitespace throughout both changed files: The PR introduced trailing spaces on most comment-block lines. Reverted all affected lines to their original whitespace. Co-authored-by: Copilot <[email protected]> --------- Co-authored-by: Frédéric Desbiens <[email protected]> Co-authored-by: Copilot <[email protected]>
2026-06-04Fixed standalone locking bugs in HID host idle get/set (#264)Frédéric Desbiens
Two issues discovered while reviewing and fixing thread-safety issues in the new ux_host_class_hid_protocol_get/set functions (PR #244). 1. idle_get.c: wrong operator acquires no lock in standalone mode Line 104 used '&= ~UX_HOST_CLASS_HID_FLAG_LOCK' (the release/clear operation) instead of '|= UX_HOST_CLASS_HID_FLAG_LOCK' (acquire/set). The preceding check correctly returns UX_BUSY when the flag is set, but the follow-on line then immediately clears it instead of setting it. The net effect is that the HID instance is never actually locked in UX_HOST_STANDALONE mode, making the mutual-exclusion check a no-op. 2. idle_set.c: standalone path used a blocking spin-loop The standalone branch called _ux_host_class_hid_idle_set_run() in a do/while loop, blocking the caller until the transfer completed. This is inconsistent with every other inline HID control-transfer function (idle_get, report_get, report_set, protocol_get, protocol_set) which all use the direct UX_DISABLE/UX_RESTORE atomic flag pattern and return UX_BUSY if the instance or device endpoint is already locked. Replaced with the same inline standalone locking pattern used by the other functions: atomic HID FLAG_LOCK acquire, atomic DEVICE_FLAG_LOCK acquire with AUTO_DEVICE_UNLOCK + UX_TRANSFER_STATE_RESET, and an AUTO_WAIT check at completion consistent with idle_get behavior. Co-authored-by: Copilot <[email protected]>
2026-06-04Added optional device HID protocol change callback and host HID protocol ↵MAY
get/set API (#244) This pull request adds host-side HID API functions to get and set the HID protocol (boot vs. report mode), and introduces an optional device-sidecallback invoked when the protocol changes. New features - Added host-side APIs ux_host_class_hid_protocol_set() and ux_host_class_hid_protocol_get() with error-checking wrappers (_uxe_ variants). - Added optional device-side callback ux_device_class_hid_set_protocol_callback, invoked when the host changes the active protocol. - Added a comprehensive test to verify the new protocol callback functionality. Bug fixes (host-side protocol get/set) 1. DMA buffer safety (protocol_get): The received byte is now written into a cache-safe allocated buffer instead of the caller's USHORT* directly. Stack memory is not DMA-safe on cache-incoherent embedded targets, and writing 1 byte into a USHORT* yields incorrect results on big-endianplatforms. Follows the same pattern as ux_host_class_hid_idle_get. 2. Missing device protection semaphore (both functions): In RTOS mode, ux_device_protection_semaphore is now acquired before submitting the transfer, in addition to the HID instance semaphore. All other HID control transfer functions (idle_get, idle_set) take both semaphores; omitting it allowed concurrent callers to corrupt the shared transfer_request fields. 3. Missing standalone locking (both functions): Added proper UX_HOST_STANDALONE support using UX_DISABLE/UX_RESTORE to atomically check and setUX_HOST_CLASS_HID_FLAG_LOCK and UX_DEVICE_FLAG_LOCK, and set UX_TRANSFER_FLAG_AUTO_DEVICE_UNLOCK + UX_TRANSFER_STATE_RESET on the transfer request before initiating. Follows the idle_get inline standalone pattern. Co-authored-by: Frédéric Desbiens <[email protected]> Co-authored-by: Copilot <[email protected]>
2026-06-04Implemented a bugfix for control transfer requests parsing (#218)SeanHowsonAdvCo
* No longer using request_value to get request type. * Removal of shift. * Fix GET/SET_DESCRIPTOR routing for class-defined descriptor types When a host sends GET_DESCRIPTOR or SET_DESCRIPTOR with bmRequestType set to STANDARD but requests a class-defined descriptor type (e.g. HID Report 0x22 or Physical 0x23), the request must be routed to the class layer rather than handled as a standard USB request. Per USB HID 1.11 section 7.1.1, HID stacks legitimately issue GET_DESCRIPTOR with bmRequestType=STANDARD | INTERFACE | IN for class descriptors. The previous fix (checking request_type != STANDARD) broke this path: (0x81 & 0x60) == 0x00 was seen as standard and the request would be stalled. The new condition explicitly checks: 1. request is GET_DESCRIPTOR or SET_DESCRIPTOR 2. bmRequestType type field is STANDARD 3. bDescriptorType (high byte of wValue) is in the USB-IF class-reserved range 0x21..0x2F Requests with bmRequestType already set to CLASS or VENDOR, and standard descriptors (bDescriptorType < 0x21, e.g. BOS 0x0F) or vendor descriptors (>= 0x40), are left unchanged and follow their normal dispatch path. Also fix (UINT) to (ULONG) cast, matching the declared type of request_type. Suggested-by: ABOUSTM <https://github.com/ABOUSTM> --------- Co-authored-by: Frédéric Desbiens <[email protected]> Co-authored-by: Copilot <[email protected]>
2026-06-02Removed unimplemented and stale API prototypes (#259)MAY
This commit cleans up header declarations by removing API and test prototypes that have no corresponding implementation in the repository. Impact: - No runtime behavior change. - Compile/link surface is cleaner and more accurate for users and tests.
2026-04-17Merge pull request #257 from ayedm1/default_value_protectionFrédéric Desbiens
Added default value protection for line coding parameters in serial Host classes
2026-04-14Merge pull request #253 from ayedm1/host_sim_uninit_user_apiFrédéric Desbiens
Added missing uninitialize macro in simulator host header (HOST SIM)
2026-03-25Add default value protection for line coding parameters in serial Host classesMAY
Add preprocessor guards to allow customization of default line coding parameters. Summary of Changes: - Wrapped default line coding constants (RATE, STOP_BIT, PARITY, DATA_BIT) with #ifndef guards in CDC ACM, GSER, and Prolific host class headers - This allows users to define custom default values before including these headers in (ux_user.h) - Updated Prolific activation code to use DEFAULT constants instead of hardcoded values for consistency and better maintainability Files Modified: - common/usbx_host_classes/inc/ux_host_class_cdc_acm.h - common/usbx_host_classes/inc/ux_host_class_gser.h - common/usbx_host_classes/inc/ux_host_class_prolific.h - common/usbx_host_classes/src/ux_host_class_prolific_activate.c
2026-03-05Merge branch 'dev' into cdc_acm_device_break_reqMAY
2026-03-05Merge branch 'dev' into host_sim_uninit_user_apiMAY
2026-03-05Fixed issue where pointer size was used instead of buffer size in ↵Frédéric Desbiens
ux_host_class_hid_report_item_analyse
2026-03-05Updated version number constantsFrédéric Desbiens
2026-03-05Updated copyright headers and removed trailing whitespaceFrédéric Desbiens
2026-03-04HOST SIM: Add missing uninitialize macro in simulator host headerMAY
2026-03-03Merge pull request #228 from ayedm1/refer_to_ux_internal_definesv6.5.0.202601_preFrédéric Desbiens
Improved code to leverage the ux internal macros instead of using direct tx struct fields
2026-03-03Merge pull request #246 from ayedm1/device_storage_load_eject_mediaFrédéric Desbiens
Added START STOP (load/eject) request support to Device MSC
2026-03-02Merge pull request #251 from ayedm1/fix_rndis_linx_enumerationFrédéric Desbiens
Fixed Linux enumeration for device RNDIS
2026-02-26Fix RNDIS linux enumerationMAY
2026-02-24Merge pull request #247 from ayedm1/uninit_dcd_simFrédéric Desbiens
Added uninitialize API to the DCD Simulator Controller Driver
2026-02-23Merge pull request #252 from ↵Frédéric Desbiens
BerninaInternationalAG/create_mutex_before_memory_allocation Modified logic to create mutex before calling _ux_utility_memory_allocate
2026-02-16create mutex before calling _ux_utility_memory_allocateLaurent Soest
When compiling with UX_ENABLE_DEBUG_LOG the call to _ux_utility_memory_allocate requires the system mutex.
2026-02-10device cdc acm support break requestMAY
- Implements handling of UX_SLAVE_CLASS_CDC_ACM_SEND_BREAK in the CDC ACM control request path. - Ensures break state is cleared on class deactivation to avoid carrying state across disconnect/reset cycles. - Minor comment/whitespace cleanups in touched headers/sources. - Testing: Build-only / compilation sanity/send break request. (no new automated tests added).
2026-02-09DCD Simulator Controller Driver: Add uninitializes APIMAY
- Adds _ux_dcd_sim_slave_uninitialize() to free the simulated slave DCD controller instance, clear DCD bindings, and return the DCD to UX_UNUSED (idempotent if already unused). - Registers the new uninitialize source in CMakeLists.txt. - Updates simulator headers to export ux_dcd_sim_slave_uninitialize (and ux_hcd_sim_host_uninitialize) and does minor whitespace/style cleanup in the simulator header blocks.
2026-02-09Device MSC: add START STOP (load/eject) request supportMAY
- Add mass-storage “removable media” support by tracking per-LUN prevent/allow medium removal and loaded/ejected status. - Introduce an optional per-LUN callback to handle SCSI START STOP UNIT (including load/eject and power-condition fields). - Extend storage constants (media types, sense keys/codes, power conditions, prevent flags) to support the new behavior and improve readability (explicit hex values). - Initialize new per-LUN state on activation (default: medium removal allowed, medium loaded) and wire the new callback through storage initialization. - Includes minor formatting/comment cleanups and version banner updates to 6.4.6. SCSI Block Commands – 4 (SBC-4)
2026-01-20Refer to ux internal marco instead of using direct txMAY
2026-01-15check for NULL packet before using the pointerLaurent Soest
If the queue is empty we need the check here.
2026-01-14Updated hotfix version constantFrédéric Desbiens
2026-01-12Updated version number constantsv6.4.5.202504_relFrédéric Desbiens
2026-01-12Merge commit from forkFrédéric Desbiens
fix (host/storage): prevent stack overflow from infinite partition recursion
2026-01-12Merge pull request #227 from ayedm1/abort_host_hid_out_endpointFrédéric Desbiens
Terminate the hid host interrupt out endpoint on deactivate
2025-12-21Cleanup hid device class filesMAY
2025-12-05Terminate the hid out interrupt out endpoint on deactivateMAY
2025-12-02Merge pull request #226 from ayedm1/fix_ci_compilaltionFrédéric Desbiens
Fix CI compilation issue
2025-12-01Fix CI compilation issueMAY
2025-11-29refer to UX prefix to avoid compilation issue in standalone modeMAY
2025-11-27Merge pull request #220 from ayedm1/fix_compilation_issue_when_debug_log_enabledFrédéric Desbiens
Improvement of UX_ENABLE_DEBUG_LOG option
2025-11-27Merge pull request #219 from ayedm1/add_check_hid_out_ep_abortFrédéric Desbiens
Add check for optional device hid out endpoint
2025-11-27Fix compilation issue when debug log option is enabledMAY
expose UX_ENABLE_DEBUG_LOG option in ux_user_sample.h
2025-11-27Add check for optional device hid out endpointMAY
2025-11-26fix typo ALIGNMENT -> ALIGNMENTMAY
2025-11-20fix (host/storage): prevent stack overflow from infinite partition recursionHaithem Rahmani
- Add a partition entry counter (ux_host_class_storage_mounted_partitions_count) and a configurable maximum (UX_HOST_CLASS_STORAGE_MAX_PARTITIONS_COUNT) to limit the number of partition entries processed during mounting. - Counter is incremented for every partition entry, and checked both before and during the partition parsing loop. - If the limit is exceeded, the function aborts and returns UX_HOST_CLASS_STORAGE_ERROR_MEDIA_NOT_READ. - This prevents stack overflow and infinite recursion in case of malformed or cyclic MBR/EBR partition tables. - Default partition entry limit set to 8 by default for safety and compatibility with typical devices. Fixes CVE-2025-55095 Signed-off-by: Haithem Rahmani <[email protected]>
2025-10-02Fixed a regression related to HID report descriptors. (#210)Frédéric Desbiens
2025-09-29Fixed integer comparisons of different signedness.Frédéric Desbiens
2025-09-29Merge pull request #178 from Nictrla/terminate-hid-endpointFrédéric Desbiens
Terminate the hid interrupt out endpoint on deactivate
2025-09-29Merge pull request #205 from ayedm1/fix_ux_system_initialize_error_checkingFrédéric Desbiens
fix ux_system_initialize error checking flag
2025-09-29Updated version number and added build number and hotfix.Frédéric Desbiens
2025-09-29Merge commit from forkFrédéric Desbiens
Add bounds check for sampling frequency in audio descriptor parsing
2025-09-29Merge commit from forkFrédéric Desbiens
add bounds checks for sampling frequency type to identify the right alternate setting