github eclipse-threadx/threadx v6.5.2.202603_rel
Eclipse ThreadX v6.5.2.202603

3 hours ago

This is the largest ThreadX release since the project moved to the Eclipse Foundation. It addresses nine security vulnerabilities in the Module Manager, adds a Cortex-R52 port that has been validated on Armv8-R silicon as well as on the AEM FVP, adds a Cortex-M52 port and a RISC-V64 Erbium board example, brings the Arm ports under an LLVM/Clang build check, completes Windows simulator support, and gives the POSIX and FreeRTOS compatibility layers their first regression suites. It also carries a large number of kernel and port bug fixes, several of which affect long-standing behaviour on Cortex-M, ARMv7-A SMP and RISC-V targets.

We thank contributors from 10xEngineers, AiNekko and Arm China, along with the independent contributors @francdoc, @hefanbo, @ntfreak, @prashit-vora, @SounLabs, @Winstonllllai and @yf13, for their valuable contributions to this release.

Vulnerabilities addressed

This release fixes nine vulnerabilities in the ThreadX Module Manager. They share a shape: a module running in user mode hands the Module Manager a pointer, a name or a size that the manager then used without adequate validation, giving a module the means to read, corrupt or free kernel state it does not own. Where the Module Manager is not used, none of these are reachable.

All nine are fixed in 6.5.2.202603. All affect 6.0.1 through 6.5.1.202602a inclusive, except CVE-2026-95109, which affects 6.1 through 6.5.1.202602a.

CVE-2026-95111 was reported by @SounLabs. The fix for CVE-2026-95108 was contributed by @prashit-vora in #692. The remaining eight were found during an internal review of the Module Manager.

Every advisory ships with a regression test that fails without its fix. You can access advisories for previously addressed vulnerabilities here.

Highlights

New RISC-V64 Erbium board example

ThreadX now ships an Erbium board example for the RISC-V64 GNU port. It runs the standard eight-thread demo in machine mode from MRAM, with the soft-float lp64 ABI and no C library, configuring the machine timer, UART and PLIC without touching any shared port file. (#787, @AFOliveira)

Erbium is the 16-hart RISC-V platform of CORE-ET, an OpenHW Foundation project contributed by Ainekko that pairs many-core 64-bit RISC-V compute with MRAM-based memory for low-power inference at the edge. OpenHW, like ThreadX, is hosted at the Eclipse Foundation.

The board needs its own startup: a partial F extension, 4 KiB trap-vector alignment and a Shakti UART. Bringing it up exposed two races, both fixed here. UART output now waits with interrupts enabled and protects only the final FIFO check and the byte write, and PLIC enable-word updates are protected against interruption. Each ships with a simulator regression test that fails without its fix.

Verified on the erbium_emu simulator, where a 100-million-cycle run reported all eight threads, five thread 0 wakeups and 26 cycles of each semaphore and mutex pair. Erbium silicon is not expected until December 2026, so the simulator is the whole of what can be verified today.

New Cortex-R52 port, validated on silicon

ThreadX now has a Cortex-R52 port, with an Armv8-R AEM FVP example build and a matching Module Manager port. (#579, #639, @fdesbiens)

The port was brought up on NXP S32Z280 silicon, and the bring-up corrected several things that only real hardware shows: an MPU region encoding, the TCM configuration reported by the part, and the data SRAM map. Lazy VFP context switching, nested IRQ handling and nested FIQ handling were each verified on the part — the nested paths had never been entered by any existing test. Per-thread MPU windows, ATCM and BTCM placement, and the cost of a context switch against the memory holding the stack were all measured rather than assumed. (#606, #609, #611–#617, #621, #629–#638, #690, @fdesbiens)

CI now runs the Cortex-R52 images on the Armv8-R AEM FVP, and the port refuses its VFP option without a hard-float ABI rather than miscompiling. (#686, #687, #688, @fdesbiens)

New Cortex-M52 port

A port for the Armv8.1-M Cortex-M52 has been added. (#519, @cpussw01)

LLVM/Clang support across the Arm ports

The Arm ports now build with LLVM, and a CI check keeps them that way. The example builds were brought along with them, which exposed and fixed several that had been broken on Linux, the incomplete Cortex-M0 barriers, and the AArch64 examples, none of which had ever linked with GCC. A matching GCC check now runs in CI, and the module ports and Module Manager C sources are compiled by both — neither had ever been built by any check. (#593–#602, #604, #672, #673, #675, #689, #716, @fdesbiens)

ports_arch is once again the single source of truth for the Cortex-M ports, with consistency checks wired into CI and into release preparation. (#590, #591, #592, @fdesbiens)

Windows simulator support

Windows simulator support is complete, with regression coverage. The win32 and win64 ports no longer enable performance metrics and event trace by default. (#736, @fdesbiens; #676, @ntfreak)

POSIX and FreeRTOS compatibility layers

Both compatibility layers now have regression suites and are built by CI. Along the way: mq_send() no longer leaks the message buffer when the send fails, two call sites no longer fall through their error handler, pthread_self() no longer faults when the caller is not a pthread, and the FreeRTOS layer no longer leaks on the xQueueCreate and static-creation error paths. (#582–#584, #624–#627, @fdesbiens)

RISC-V

Lazy FPU stacking and QEMU functional tests have been added for the RV64 GNU port (#549, @Winstonllllai). The RV32 and RV64 ports were brought into spec compliance, and the RISC-V regression suite now runs in CI against QEMU targets (#691, #698, #717, @akifejaz). A clobbered return address in the RISC-V context save and a trap frame size mismatch in the regression BSP were also fixed. (#696, #708, #773, @fdesbiens)

MISRA build configurations in the regression matrix

The regression matrix now includes MISRA configurations, and the simulator ports, thread create paths and tx_misra.c build cleanly with TX_MISRA_ENABLE defined. Zero trace timestamps in the Linux ports' MISRA builds were fixed. (#742, #746, #747, #749, #751, @fdesbiens)

Optional const-qualified object names

ThreadX object name fields can now be const-qualified behind TX_ENABLE_CONST_NAMES, which is off by default. A build that does not set it gets exactly the types it got before, so this is not a source-breaking change in a patch release. The option is expected to become the default in 6.6. (#761, @fdesbiens)

Other bug fixes

  • Added the missing memory barrier so ARMv7-A SMP schedulers no longer miss preemptions (#704, @fdesbiens)
  • Removed FIFO queueing from the ARMv7-A SMP ports so an ISR can no longer deadlock waiting for protection (#707, @fdesbiens)
  • Added the missing VFP enable field to the Cortex-R5/AC5 thread control block, which VFP builds were writing over the FileX pointer (#715, @fdesbiens)
  • Allowed a BASEPRI-masked interrupt to wake the Cortex-M idle loop from WFI (#711, @fdesbiens)
  • Initialized the suspend status before the non-interruptable suspend in tx_thread_sleep, so a sleep no longer returns a stale error left over from an earlier timed-out suspension (#725, @fdesbiens)
  • Stopped tx_thread_relinquish discarding the rebalance it requests (#758, @fdesbiens)
  • Stopped the Linux and SMP Linux ports losing a mutex wake-up to a suspend signal (#753, #754, @fdesbiens)
  • Stopped the SMP Linux port leaking a critical section on unprotect (#759, @fdesbiens)
  • Refused thread delete and reset while an exit transition is in progress (#724, @fdesbiens)
  • Restored the random stack fill value cleared during thread creation (#732, @fdesbiens)
  • Made the stack analyze binary search require several consecutive fill words, so unwritten holes in a used stack no longer under-report the highest stack pointer, and guarded it against inverted stack pointers (#720, #727, @fdesbiens)
  • Allowed tx_timer_change to be called from tx_application_define (#730, @fdesbiens)
  • Applied R_ARM_RELATIVE relocations at GNU ThreadX module startup (#731, @fdesbiens)
  • Corrected the module kernel stack size so it no longer overstates the usable stack, and fixed the invalid module data pointers in the absolute module load (#699, #701, @fdesbiens)
  • Hardened the module converter utilities against malformed input and fixed a code_buffer leak (#580, #581, @fdesbiens)
  • Fixed the garbage _tx_initialize_unused_memory in the GNU Cortex-A ports (#726, @fdesbiens)
  • Removed the vector table offset register and system stack pointer setup from the Cortex-M low-level initialization (#714, @fdesbiens)
  • Fixed the missing immediate prefix on MOV in the Cortex-M schedulers (#693, @fdesbiens)
  • Added a SysTick counter reset in the Cortex-M ports (#561, @hefanbo)
  • Updated the Cortex-M BASEPRI zero immediates and the Cortex-R4 Thumb bit immediates (#564, #565, @fdesbiens)
  • Fixed VFP issues on the Cortex-R4 and R5 ports (#578, @fdesbiens)
  • Enabled execution profiling for Cortex-R5 (#766, @fdesbiens)
  • Fixed the SMP execution profile total getters (#553, @fdesbiens)
  • Fixed the private-timer timestamp issue on the A5, A7, A9 and R8 ports, and the ARMv8 SMP time sources (#554, #555, @fdesbiens)
  • Replaced the GNU-only dsb/isb 0xF operands with the UAL sy form (#729, @fdesbiens)
  • Masked the SMP remap core maps to silence a false -O2 array bounds error (#728, @fdesbiens)
  • Moved the ARC ISR enter callout onto the system stack (#700, @fdesbiens)
  • Aligned the simulator ports' fake stack pointer so ThreadX no longer performs misaligned ULONG accesses (#705, @fdesbiens)
  • Fixed the incorrect loop bound constant in the IAR file lock support (#695, @fdesbiens)
  • Fixed the nested comment warning in the RX GCC ports (#550, @francdoc)
  • Marked every published ThreadX include directory as SYSTEM so applications no longer get warnings from ThreadX headers (#713, @fdesbiens)
  • Removed the duplicated function body in the Cortex-M4 AC6 port (#589, @fdesbiens)
  • Added ARMv7-A SMP Linux build scripts for A5, A7 and A9 (#674, @prashit-vora)
  • Removed developer machine paths from the shipped project files, and stray binary and generated build artefacts from the source tree (#603, #618, #706, #403, @fdesbiens, @yf13)

Build system, CI and coverage

  • Made the install and build step timeouts inputs of the shared regression workflow template, so a consumer whose steps do more than install and build once can ask for the time it needs without moving everyone else's limit (#790, #791, @fdesbiens)
  • Stopped the RISC-V install pulling a desktop media stack: qemu-system-misc recommends gstreamer, pulseaudio, v4l and a set of codecs, which made a 67-package, 87 MB download out of an install that runs QEMU headless (#789, @fdesbiens)
  • Every build configuration is now instrumented and their coverage merged into one report, with a coverage floor enforced on the merged figure (#665, #667, @fdesbiens)
  • Pinned every GitHub action to a commit SHA, moved them off Node 20, and added the Dependabot configuration the pinned actions need (#660, #662, @fdesbiens)
  • Bumped gcovr off the 4.1 pin it had been held on since 2018, and matched gcov to the compiler that produced the data (#663, #658, @fdesbiens)
  • Allowed the Linux toolchain file to accept a compiler override, and reconfigured the build when the requested compiler changes (#656, #657, @fdesbiens)
  • Revived the Cortex-M build, which had compiled nothing since June (#653, @fdesbiens)
  • Gave several regression tests a bounded wait instead of an open-ended one, so a hang now reports where it stopped instead of consuming a whole run (#640, #644, #645, #646, #649, @fdesbiens)
  • Stopped the test runners reporting an incomplete build as test failures (#709, @fdesbiens)
  • Gave install_riscv.sh the network hardening install.sh already had, and stopped a dead apt mirror taking the whole install down with it (#642, #721, @fdesbiens)
  • Gave the GNU ports a CMake build, which most of them lacked, and added a CMake target for the Linux sample program (#607, #622, @fdesbiens)
  • Normalised the AI disclosure comment to one fixed line per file and added a check that keeps it so, plus a script that counts Assisted-by attributions completely (#740, #762, #775, @fdesbiens)
  • Stopped the version pass skipping ports in silence, and corrected the RISC-V32/IAR port, which a stray letter in its version string had kept out of every release pass since it appeared (#786, @fdesbiens)
  • Added a blame ignore list for the mechanical header and version passes (#763, #782, @fdesbiens)
  • Updated the contribution guide and the security policy, and linked readers to the published documentation (#566, #774, #776, @fdesbiens)

Deprecations

txm_module_object_deallocate and txm_module_object_pointer_get are deprecated. Both are part of the Module Manager surface that the advisories above concern; applications should move off them. (#559, #562, @fdesbiens)

New Contributors

Full Changelog: v6.5.1.202602a_rel...v6.5.2.202603_rel

Don't miss a new threadx release

NewReleases is sending notifications on new releases.