Skip to content

arch/arm/src/imxrt: Add rptun backend for the RT117x CM4 over the MU mailbox. - #420

Draft
methodmissing wants to merge 2 commits into
PX4:px4_firmware_nuttx-12.12.0+from
methodmissing:imxrt-rptun
Draft

methodmissing wants to merge 2 commits into
PX4:px4_firmware_nuttx-12.12.0+from
methodmissing:imxrt-rptun

Conversation

@methodmissing

@methodmissing methodmissing commented Sep 28, 2026 •

Copy link
Copy Markdown

Summary

RPTUN backend for the i.MX RT1170 CM4, opt-in through CONFIG_IMXRT_RPTUN. NuttX on the CM7 loads a
CM4 ELF through the LMEM backdoor window, programs the boot vector into IOMUXC_LPSR_GPR0/1,
releases and holds the core through SRC, and exchanges virtqueue kicks over MU-A channel 0. A CM4
lockup resets only the CM4. The board passes name, ELF path, address environment and boot vector to
imxrt_rptun_init() and maps the shared window non-cacheable. Documentation in the second commit.

Related: #421 (OpenAMP length hardening, independent), PX4/PX4-Autopilot#28880 (the
px4_fmu-v6xrt rpmsg variant and CM4 remote that use this).

Impact

  • New feature: YES. Existing feature changed: NO.
  • User: NO unless enabled; then the board calls imxrt_rptun_init() and ships a CM4 image.
  • Build: NO for existing configurations. Hardware: RT117x only, new files plus MU clock-gate macros.
  • Documentation: YES, included. Security: the CM4 is a second bus master; its firmware owns
    containment.
  • Compatibility: NO changes.

Testing

  • Host: macOS, GNU Arm Embedded 9-2020-q2 (gcc 9.3.1), via PX4-Autopilot make px4_fmu-v6xrt_rpmsg.
  • Target: FMU-v6X-RT (i.MX RT1176 rB0), NuttX 12.12 on the CM7, bare-metal rpmsg remote on the CM4.
  • Load, status, ping, stop/start cycles, CM4 hard fault, lockup and hang with the CM7 unaffected.
    tools/checkpatch.sh passes.

To replay on the PX4 branch. The PX4 remote_core command drives the rptun ioctls and prints the
board's register view in the shell. The nsh rptun builtin works on the device node and reports
through NuttX syslog, which this config sends to the LPUART1 debug UART, so its output is visible
there only, not in a MAVLink or USB shell and not in dmesg. rpmsg dump all walks /dev/rpmsg,
absent for an rptun node; use rptun dump.

nsh> remote_core status                            # slice out of reset, state 0xc0de0003, app name
nsh> remote_core ping 100 64                       # 100/100 replies, rtt tens of us
nsh> rptun ping /dev/rptun/cm4 100 64 3 0          # driver ping, payload check, stats on LPUART1
nsh> rptun dump all                                # vring and endpoint state, on LPUART1
nsh> remote_core stop; remote_core start; remote_core ping 10 64
nsh> remote_core fault hardfault                   # no reply, state 0xdead0000 (FAULT), ipsr 3
nsh> remote_core stop; remote_core start; remote_core ping 10 64   # 10/10
nsh> remote_core fault lockup                      # no reply, state 0xdead0000 (FAULT), CM7 alive
nsh> remote_core stop; remote_core start; remote_core ping 10 64   # 10/10
nsh> remote_core fault hang                        # no reply, state stays 0xc0de0003 (rpmsg ready)
nsh> remote_core stop; remote_core start; remote_core ping 100 64  # 100/100

The three faults differ in what the CM4 does: hardfault takes an exception and parks, lockup
faults again inside the handler so the core locks up, and hang spins with interrupts off. In all
three the CM7 shell stays up, SRSR gains no reset cause, and a stop/start cycle recovers the CM4.

Logs after change (new feature, none before), NuttX 46bc73fe11 on PX4 rpmsg-v6xrt, run of
2026-09-28 over the MAVLink shell. The two rptun lines print on LPUART1, hence no output here:

NuttShell (NSH) NuttX-12.12.0
nsh> remote_core status
SRC SRSR 0x08010003 () SRMR 0x000000c0
M4 clock root control 0x00000400 status 0x00000400 (on)
CM4 VTOR from LPSR GPR0/1: 0x20200000 (GPR0 0x00000000 GPR1 0x00002020)
cm4 slice out of reset, SCR 0x00000001, vectors sp 0x20020000 pc 0x1ffe02ed
cm4 state 0xc0de0003 (rpmsg ready), ipsr 0, kicks rx 14, msgs tx 14
cm4 application "basic"
nsh> remote_core ping 100 64
INFO  [remote_core] 100/100 replies, 64 byte payload
INFO  [remote_core] rtt min 27 us, avg 49 us, max 1365 us
nsh> rptun ping /dev/rptun/cm4 100 64 3 0
nsh> rptun dump all
nsh> remote_core stop; remote_core start; remote_core ping 10 64
INFO  [remote_core] 10/10 replies, 64 byte payload
INFO  [remote_core] rtt min 29 us, avg 33 us, max 47 us
nsh> remote_core fault hardfault
ERROR [remote_core] hardfault: no reply within 500 ms
SRC SRSR 0x08010003 () SRMR 0x000000c0
M4 clock root control 0x00000400 status 0x00000400 (on)
CM4 VTOR from LPSR GPR0/1: 0x20200000 (GPR0 0x00000000 GPR1 0x00002020)
cm4 slice out of reset, SCR 0x00000001, vectors sp 0x20020000 pc 0x1ffe02ed
cm4 state 0xdead0000 (FAULT), ipsr 3, kicks rx 14, msgs tx 14
cm4 application "basic"
nsh> remote_core stop; remote_core start; remote_core ping 10 64
INFO  [remote_core] 10/10 replies, 64 byte payload
INFO  [remote_core] rtt min 29 us, avg 35 us, max 47 us
nsh> remote_core fault lockup
ERROR [remote_core] lockup: no reply within 500 ms
SRC SRSR 0x08010003 () SRMR 0x000000c0
M4 clock root control 0x00000400 status 0x00000400 (on)
CM4 VTOR from LPSR GPR0/1: 0x20200000 (GPR0 0x00000000 GPR1 0x00002020)
cm4 slice out of reset, SCR 0x00000001, vectors sp 0x20020000 pc 0x1ffe02ed
cm4 state 0xdead0000 (FAULT), ipsr 3, kicks rx 15, msgs tx 14
cm4 application "basic"
nsh> remote_core stop; remote_core start; remote_core ping 10 64
INFO  [remote_core] 10/10 replies, 64 byte payload
INFO  [remote_core] rtt min 27 us, avg 37 us, max 97 us
nsh> remote_core fault hang
ERROR [remote_core] hang: no reply within 500 ms
SRC SRSR 0x08010003 () SRMR 0x000000c0
M4 clock root control 0x00000400 status 0x00000400 (on)
CM4 VTOR from LPSR GPR0/1: 0x20200000 (GPR0 0x00000000 GPR1 0x00002020)
cm4 slice out of reset, SCR 0x00000001, vectors sp 0x20020000 pc 0x1ffe02ed
cm4 state 0xc0de0003 (rpmsg ready), ipsr 0, kicks rx 14, msgs tx 14
cm4 application "basic"
nsh> remote_core stop; remote_core start; remote_core ping 100 64
INFO  [remote_core] 100/100 replies, 64 byte payload
INFO  [remote_core] rtt min 27 us, avg 47 us, max 581 us

PR verification Self-Check

  • This PR introduces only one functional change.
  • I have updated all required description fields above.
  • My PR adheres to Contributing Guidelines and Documentation.
  • My PR is still work in progress (not ready for review).
  • My PR is ready for review and can be safely merged into a codebase.

…mailbox.

Assisted-by: Claude:claude-fable-5-1
Signed-off-by: Lourens Naude <lourens@bearmetal.eu>
…end.

Assisted-by: Claude:claude-fable-5-1
Signed-off-by: Lourens Naude <lourens@bearmetal.eu>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant