daniel-p-carvalho opened a new issue, #20452:
URL: https://github.com/apache/nuttx/issues/20452

   ### Description / Steps to reproduce the issue
   
   Since 19b4911d7f ("arch: remove up_current_regs in common code"), the MIPS
   interrupt handlers save the interrupted context into
   `g_running_tasks[this_cpu()]->xcp.regs` on entry, but nothing in the MIPS
   interrupt path updates `g_running_tasks[]` after a context switch. The only
   writers are `nx_start()` (Idle task) and `up_exit()` (sets it to NULL).
   
   Consequences:
   
   * Every interrupt copies the interrupted context into the TCB that
     `g_running_tasks[]` points to (the Idle task), not the TCB of the task
     that was really interrupted.
   * After any task or thread exits, `g_running_tasks[]` stays NULL, no context
     is saved on interrupt entry any more, and the next context switch restores
     stale registers. The crash dump path also uses `g_running_tasks[]`, so the
     resulting exception usually faults again inside `PANIC()`.
   
   On PIC32MZ this was confirmed on hardware (PIC32MZ-W1 board): the system
   crashed right after the network initialization thread exited. It is fixed
   for PIC32MZ in #20450 by setting `g_running_tasks[this_cpu()] = this_task()`
   before `pic32mz_decodeirq()` returns, as the ARM and RISC-V handlers do.
   
   The same pattern is present in these handlers, which I cannot test (no
   hardware):
   
   * `arch/mips/src/pic32mx/pic32mx_decodeirq.c`
   * `arch/mips/src/mips32/mips_doirq.c`
   * `arch/mips/src/jz4780/jz4780_decodeirq.c`
   
   Steps to reproduce on an affected board: enable a feature whose thread exits
   after boot (e.g. `CONFIG_NETINIT_THREAD=y`), or run any NSH builtin as a
   separate task, and wait for the next context switch after it exits.
   
   ### On which OS does this issue occur?
   
   [OS: Linux]
   
   ### What is the version of your OS?
   
   Ubuntu Linux x86_64
   
   ### NuttX Version
   
   master
   
   ### Issue Architecture
   
   [Arch: mips]
   
   ### Issue Area
   
   [Area: Kernel]
   
   ### Verification
   
   - [x] I have verified before submitting the report.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to