-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathindex.xml
More file actions
5062 lines (5010 loc) · 475 KB
/
index.xml
File metadata and controls
5062 lines (5010 loc) · 475 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
352
353
354
355
356
357
358
359
360
361
362
363
364
365
366
367
368
369
370
371
372
373
374
375
376
377
378
379
380
381
382
383
384
385
386
387
388
389
390
391
392
393
394
395
396
397
398
399
400
401
402
403
404
405
406
407
408
409
410
411
412
413
414
415
416
417
418
419
420
421
422
423
424
425
426
427
428
429
430
431
432
433
434
435
436
437
438
439
440
441
442
443
444
445
446
447
448
449
450
451
452
453
454
455
456
457
458
459
460
461
462
463
464
465
466
467
468
469
470
471
472
473
474
475
476
477
478
479
480
481
482
483
484
485
486
487
488
489
490
491
492
493
494
495
496
497
498
499
500
501
502
503
504
505
506
507
508
509
510
511
512
513
514
515
516
517
518
519
520
521
522
523
524
525
526
527
528
529
530
531
532
533
534
535
536
537
538
539
540
541
542
543
544
545
546
547
548
549
550
551
552
553
554
555
556
557
558
559
560
561
562
563
564
565
566
567
568
569
570
571
572
573
574
575
576
577
578
579
580
581
582
583
584
585
586
587
588
589
590
591
592
593
594
595
596
597
598
599
600
601
602
603
604
605
606
607
608
609
610
611
612
613
614
615
616
617
618
619
620
621
622
623
624
625
626
627
628
629
630
631
632
633
634
635
636
637
638
639
640
641
642
643
644
645
646
647
648
649
650
651
652
653
654
655
656
657
658
659
660
661
662
663
664
665
666
667
668
669
670
671
672
673
674
675
676
677
678
679
680
681
682
683
684
685
686
687
688
689
690
691
692
693
694
695
696
697
698
699
700
701
702
703
704
705
706
707
708
709
710
711
712
713
714
715
716
717
718
719
720
721
722
723
724
725
726
727
728
729
730
731
732
733
734
735
736
737
738
739
740
741
742
743
744
745
746
747
748
749
750
751
752
753
754
755
756
757
758
759
760
761
762
763
764
765
766
767
768
769
770
771
772
773
774
775
776
777
778
779
780
781
782
783
784
785
786
787
788
789
790
791
792
793
794
795
796
797
798
799
800
801
802
803
804
805
806
807
808
809
810
811
812
813
814
815
816
817
818
819
820
821
822
823
824
825
826
827
828
829
830
831
832
833
834
835
836
837
838
839
840
841
842
843
844
845
846
847
848
849
850
851
852
853
854
855
856
857
858
859
860
861
862
863
864
865
866
867
868
869
870
871
872
873
874
875
876
877
878
879
880
881
882
883
884
885
886
887
888
889
890
891
892
893
894
895
896
897
898
899
900
901
902
903
904
905
906
907
908
909
910
911
912
913
914
915
916
917
918
919
920
921
922
923
924
925
926
927
928
929
930
931
932
933
934
935
936
937
938
939
940
941
942
943
944
945
946
947
948
949
950
951
952
953
954
955
956
957
958
959
960
961
962
963
964
965
966
967
968
969
970
971
972
973
974
975
976
977
978
979
980
981
982
983
984
985
986
987
988
989
990
991
992
993
994
995
996
997
998
999
1000
<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
<title>Xenithya的博客</title>
<link>https://xenithya.github.io/</link>
<description>Recent content on Xenithya的博客</description>
<generator>Hugo -- gohugo.io</generator>
<language>en-us</language>
<copyright>Xun Yingya</copyright><atom:link href="https://xenithya.github.io/index.xml" rel="self" type="application/rss+xml" /><item>
<title>Dsp_logical_cmd_error</title>
<link>https://xenithya.github.io/p/dsp_logical_cmd_error/</link>
<pubDate>Tue, 16 Dec 2025 10:46:48 +0800</pubDate>
<guid>https://xenithya.github.io/p/dsp_logical_cmd_error/</guid>
<description><h1 id="dsp裸机nbg-u8类型运行错误---深度技术分析与解决方案">DSP裸机NBG U8类型运行错误 - 深度技术分析与解决方案
</h1><h2 id="一问题概述">一、问题概述
</h2><h3 id="症状">症状
</h3><ul>
<li><strong>错误日志</strong>:<code>[0x0]gcpnna_patch_network_outputs[409], output logical in cmd is NULL, output 1, slice=0</code></li>
<li><strong>数据类型依赖</strong>:仅在U8类型NBG出现,INT16类型正常</li>
<li><strong>平台依赖</strong>:仅在DSP裸机出现,RT-Thread操作系统下正常</li>
</ul>
<h3 id="关键观察">关键观察
</h3><ol>
<li>同一代码库,不同数据类型表现不同</li>
<li>同一平台,有/无操作系统表现不同</li>
<li>用户的修复(添加Canary保护)有效解决问题</li>
</ol>
<hr>
<h2 id="二根本原因分析">二、根本原因分析
</h2><h3 id="21-结构体定义回顾">2.1 结构体定义回顾
</h3><div class="highlight"><div class="chroma">
<table class="lntable"><tr><td class="lntd">
<pre tabindex="0" class="chroma"><code><span class="lnt"> 1
</span><span class="lnt"> 2
</span><span class="lnt"> 3
</span><span class="lnt"> 4
</span><span class="lnt"> 5
</span><span class="lnt"> 6
</span><span class="lnt"> 7
</span><span class="lnt"> 8
</span><span class="lnt"> 9
</span><span class="lnt">10
</span><span class="lnt">11
</span><span class="lnt">12
</span><span class="lnt">13
</span></code></pre></td>
<td class="lntd">
<pre tabindex="0" class="chroma"><code class="language-c" data-lang="c"><span class="line"><span class="cl"><span class="k">typedef</span> <span class="k">struct</span> <span class="n">_pnna_io_patch_info</span> <span class="p">{</span>
</span></span><span class="line"><span class="cl"> <span class="kt">pnna_uint32_t</span> <span class="n">slice_num</span><span class="p">;</span> <span class="c1">// 切片数量
</span></span></span><span class="line"><span class="cl"> <span class="kt">pnna_address_t</span> <span class="o">*</span><span class="n">logical_in_cmd</span><span class="p">;</span> <span class="c1">// 逻辑地址指针数组
</span></span></span><span class="line"><span class="cl"> <span class="kt">pnna_uint32_t</span> <span class="o">*</span><span class="n">physical_in_cmd</span><span class="p">;</span> <span class="c1">// 物理地址指针数组
</span></span></span><span class="line"><span class="cl"> <span class="kt">pnna_uint32_t</span> <span class="o">*</span><span class="n">offsets</span><span class="p">;</span> <span class="c1">// 偏移数组
</span></span></span><span class="line"><span class="cl"> <span class="kt">pnna_uint32_t</span> <span class="o">*</span><span class="n">transformation</span><span class="p">;</span> <span class="c1">// 变换数组
</span></span></span><span class="line"><span class="cl"> <span class="kt">pnna_uint32_t</span> <span class="n">counter</span><span class="p">;</span>
</span></span><span class="line"><span class="cl"> <span class="kt">pnna_uint32_t</span> <span class="n">physical</span><span class="p">;</span>
</span></span><span class="line"><span class="cl"> <span class="kt">pnna_uint8_t</span> <span class="o">*</span><span class="n">logical</span><span class="p">;</span>
</span></span><span class="line"><span class="cl"> <span class="kt">pnna_uint8_t</span> <span class="o">**</span><span class="n">sw_op_buffer</span><span class="p">;</span> <span class="c1">// 软件操作缓冲
</span></span></span><span class="line"><span class="cl"> <span class="n">pnna_buffer</span> <span class="n">buffer</span><span class="p">;</span>
</span></span><span class="line"><span class="cl"> <span class="kt">pnna_uint32_t</span> <span class="n">patch_belong</span><span class="p">;</span>
</span></span><span class="line"><span class="cl"><span class="p">}</span> <span class="kt">gcpnna_io_patch_info_t</span><span class="p">;</span>
</span></span></code></pre></td></tr></table>
</div>
</div><h3 id="22-原有分配代码的问题">2.2 原有分配代码的问题
</h3><p><strong>位置</strong>:<code>gcpnna_create_io_patch_info()</code> 函数 (第1399-1411行)</p>
<div class="highlight"><div class="chroma">
<table class="lntable"><tr><td class="lntd">
<pre tabindex="0" class="chroma"><code><span class="lnt">1
</span><span class="lnt">2
</span><span class="lnt">3
</span><span class="lnt">4
</span></code></pre></td>
<td class="lntd">
<pre tabindex="0" class="chroma"><code class="language-c" data-lang="c"><span class="line"><span class="cl"><span class="c1">// 原代码
</span></span></span><span class="line"><span class="cl"><span class="kt">pnna_uint32_t</span> <span class="n">tmp_size</span> <span class="o">=</span> <span class="k">sizeof</span><span class="p">(</span><span class="kt">pnna_address_t</span><span class="p">)</span> <span class="o">*</span> <span class="n">io_info</span><span class="o">-&gt;</span><span class="n">slice_num</span><span class="p">;</span>
</span></span><span class="line"><span class="cl"><span class="nf">gcOnError</span><span class="p">(</span><span class="nf">gcpnna_user_allocate_memory</span><span class="p">(</span><span class="n">tmp_size</span><span class="p">,</span> <span class="p">(</span><span class="kt">void</span> <span class="o">**</span><span class="p">)</span><span class="o">&amp;</span><span class="n">io_info</span><span class="o">-&gt;</span><span class="n">logical_in_cmd</span><span class="p">));</span>
</span></span><span class="line"><span class="cl"><span class="nf">gcpnna_user_zero_memory</span><span class="p">(</span><span class="n">io_info</span><span class="o">-&gt;</span><span class="n">logical_in_cmd</span><span class="p">,</span> <span class="n">tmp_size</span><span class="p">);</span>
</span></span></code></pre></td></tr></table>
</div>
</div><p><strong>问题根源</strong>:</p>
<h4 id="问题1缺少对齐保护机制">问题1:缺少对齐保护机制
</h4><ul>
<li><strong>原分配大小</strong>:<code>sizeof(pnna_address_t) * slice_num</code> 字节</li>
<li><strong>缺陷</strong>:
<ul>
<li>假设 <code>pnna_address_t</code> = 8字节(64位)</li>
<li>假设 <code>slice_num</code> = 1</li>
<li>分配大小 = 8字节</li>
<li>这是一个最小单位的精确分配</li>
</ul>
</li>
</ul>
<h4 id="问题2内存踩踏buffer-overflow">问题2:内存踩踏(Buffer Overflow)
</h4><ul>
<li>后续代码写入 <code>physical_in_cmd</code>, <code>offsets</code>, <code>transformation</code> 等</li>
<li>这些是独立分配的内存</li>
<li>但在某些条件下(如内存不连续或分配器特性)可能发生越界</li>
</ul>
<h4 id="问题3c66x-dsp硬件对齐要求">问题3:C66X DSP硬件对齐要求
</h4><ul>
<li><strong>C66X DSP</strong>:固定点数字信号处理器</li>
<li>典型对齐要求:
<ul>
<li>普通数据:4字节或8字节对齐</li>
<li>向量操作:16字节或32字节对齐</li>
<li>缓冲指针:可能需要特殊对齐</li>
</ul>
</li>
</ul>
<h4 id="问题4数据类型特异性">问题4:数据类型特异性
</h4><ul>
<li>
<p><strong>INT16数据</strong>:</p>
<ul>
<li>较大的数据块</li>
<li>处理量较少</li>
<li>内存压力小</li>
<li>对齐要求相对宽松</li>
</ul>
</li>
<li>
<p><strong>U8数据</strong>:</p>
<ul>
<li>较小的数据块</li>
<li>需要处理更多元素</li>
<li>内存访问密集</li>
<li>可能触发硬件对齐检查</li>
</ul>
</li>
</ul>
<h3 id="23-裸机-vs-操作系统的差异">2.3 裸机 vs 操作系统的差异
</h3><h4 id="rt-thread正常工作">RT-Thread(正常工作)
</h4><div class="highlight"><div class="chroma">
<table class="lntable"><tr><td class="lntd">
<pre tabindex="0" class="chroma"><code><span class="lnt"> 1
</span><span class="lnt"> 2
</span><span class="lnt"> 3
</span><span class="lnt"> 4
</span><span class="lnt"> 5
</span><span class="lnt"> 6
</span><span class="lnt"> 7
</span><span class="lnt"> 8
</span><span class="lnt"> 9
</span><span class="lnt">10
</span></code></pre></td>
<td class="lntd">
<pre tabindex="0" class="chroma"><code class="language-text" data-lang="text"><span class="line"><span class="cl">应用层
</span></span><span class="line"><span class="cl"> ↓
</span></span><span class="line"><span class="cl">RT-Thread 内存管理层
</span></span><span class="line"><span class="cl"> ├─ 内存对齐检查
</span></span><span class="line"><span class="cl"> ├─ 内存保护机制
</span></span><span class="line"><span class="cl"> ├─ Cache一致性管理
</span></span><span class="line"><span class="cl"> ├─ MMU虚拟地址映射
</span></span><span class="line"><span class="cl"> └─ 内存屏障(barriers)
</span></span><span class="line"><span class="cl"> ↓
</span></span><span class="line"><span class="cl">底层硬件
</span></span></code></pre></td></tr></table>
</div>
</div><p><strong>RT-Thread的保护作用</strong>:</p>
<ul>
<li>系统调用的内存分配器可能有额外的对齐逻辑</li>
<li>可能自动添加了保护页面</li>
<li>MMU可能提供了额外的访问检查</li>
<li>内存屏障确保访问顺序</li>
</ul>
<h4 id="裸机出现错误">裸机(出现错误)
</h4><div class="highlight"><div class="chroma">
<table class="lntable"><tr><td class="lntd">
<pre tabindex="0" class="chroma"><code><span class="lnt"> 1
</span><span class="lnt"> 2
</span><span class="lnt"> 3
</span><span class="lnt"> 4
</span><span class="lnt"> 5
</span><span class="lnt"> 6
</span><span class="lnt"> 7
</span><span class="lnt"> 8
</span><span class="lnt"> 9
</span><span class="lnt">10
</span></code></pre></td>
<td class="lntd">
<pre tabindex="0" class="chroma"><code class="language-text" data-lang="text"><span class="line"><span class="cl">应用层
</span></span><span class="line"><span class="cl"> ↓
</span></span><span class="line"><span class="cl">直接硬件内存操作
</span></span><span class="line"><span class="cl"> └─ 无对齐检查
</span></span><span class="line"><span class="cl"> └─ 无保护机制
</span></span><span class="line"><span class="cl"> └─ 无Cache一致性
</span></span><span class="line"><span class="cl"> └─ 直接物理地址
</span></span><span class="line"><span class="cl"> └─ 无访问限制
</span></span><span class="line"><span class="cl"> ↓
</span></span><span class="line"><span class="cl">底层硬件
</span></span></code></pre></td></tr></table>
</div>
</div><p><strong>裸机的风险</strong>:</p>
<ul>
<li>任何内存错误都直接影响程序</li>
<li>无额外的保护机制</li>
<li>需要驱动代码完全负责对齐和保护</li>
</ul>
<hr>
<h2 id="三用户修复方案的工作原理">三、用户修复方案的工作原理
</h2><h3 id="31-修复代码">3.1 修复代码
</h3><div class="highlight"><div class="chroma">
<table class="lntable"><tr><td class="lntd">
<pre tabindex="0" class="chroma"><code><span class="lnt"> 1
</span><span class="lnt"> 2
</span><span class="lnt"> 3
</span><span class="lnt"> 4
</span><span class="lnt"> 5
</span><span class="lnt"> 6
</span><span class="lnt"> 7
</span><span class="lnt"> 8
</span><span class="lnt"> 9
</span><span class="lnt">10
</span><span class="lnt">11
</span></code></pre></td>
<td class="lntd">
<pre tabindex="0" class="chroma"><code class="language-c" data-lang="c"><span class="line"><span class="cl"><span class="c1">// 修复:添加Canary保护
</span></span></span><span class="line"><span class="cl"><span class="kt">pnna_uint32_t</span> <span class="n">payload_size</span> <span class="o">=</span> <span class="k">sizeof</span><span class="p">(</span><span class="kt">pnna_address_t</span><span class="p">)</span> <span class="o">*</span> <span class="n">io_info</span><span class="o">-&gt;</span><span class="n">slice_num</span><span class="p">;</span>
</span></span><span class="line"><span class="cl"><span class="k">const</span> <span class="kt">pnna_uint32_t</span> <span class="n">canary_bytes</span> <span class="o">=</span> <span class="k">sizeof</span><span class="p">(</span><span class="kt">pnna_uint64_t</span><span class="p">);</span> <span class="c1">// 8字节
</span></span></span><span class="line"><span class="cl"><span class="kt">pnna_uint32_t</span> <span class="n">alloc_size</span> <span class="o">=</span> <span class="n">payload_size</span> <span class="o">+</span> <span class="mi">2</span> <span class="o">*</span> <span class="n">canary_bytes</span><span class="p">;</span> <span class="c1">// +16字节总
</span></span></span><span class="line"><span class="cl">
</span></span><span class="line"><span class="cl"><span class="kt">void</span> <span class="o">*</span><span class="n">alloc_base</span> <span class="o">=</span> <span class="n">PNNA_NULL</span><span class="p">;</span>
</span></span><span class="line"><span class="cl"><span class="nf">gcOnError</span><span class="p">(</span><span class="nf">gcpnna_user_allocate_memory</span><span class="p">(</span><span class="n">alloc_size</span><span class="p">,</span> <span class="p">(</span><span class="kt">void</span> <span class="o">**</span><span class="p">)</span><span class="o">&amp;</span><span class="n">alloc_base</span><span class="p">));</span>
</span></span><span class="line"><span class="cl">
</span></span><span class="line"><span class="cl"><span class="cm">/* 有效载荷位于前缀Canary之后 */</span>
</span></span><span class="line"><span class="cl"><span class="n">io_info</span><span class="o">-&gt;</span><span class="n">logical_in_cmd</span> <span class="o">=</span> <span class="p">(</span><span class="kt">pnna_address_t</span> <span class="o">*</span><span class="p">)((</span><span class="kt">pnna_uint8_t</span> <span class="o">*</span><span class="p">)</span><span class="n">alloc_base</span> <span class="o">+</span> <span class="n">canary_bytes</span><span class="p">);</span>
</span></span><span class="line"><span class="cl"><span class="nf">gcpnna_user_zero_memory</span><span class="p">(</span><span class="n">io_info</span><span class="o">-&gt;</span><span class="n">logical_in_cmd</span><span class="p">,</span> <span class="n">payload_size</span><span class="p">);</span>
</span></span></code></pre></td></tr></table>
</div>
</div><h3 id="32-为什么有效">3.2 为什么有效
</h3><h4 id="机制1内存对齐改善">机制1:内存对齐改善
</h4><div class="highlight"><div class="chroma">
<table class="lntable"><tr><td class="lntd">
<pre tabindex="0" class="chroma"><code><span class="lnt"> 1
</span><span class="lnt"> 2
</span><span class="lnt"> 3
</span><span class="lnt"> 4
</span><span class="lnt"> 5
</span><span class="lnt"> 6
</span><span class="lnt"> 7
</span><span class="lnt"> 8
</span><span class="lnt"> 9
</span><span class="lnt">10
</span><span class="lnt">11
</span><span class="lnt">12
</span></code></pre></td>
<td class="lntd">
<pre tabindex="0" class="chroma"><code class="language-text" data-lang="text"><span class="line"><span class="cl">原分配(8字节):
</span></span><span class="line"><span class="cl">┌──────────────────────────────────┐
</span></span><span class="line"><span class="cl">│ logical_in_cmd (直接分配) │ &lt;- 可能不对齐
</span></span><span class="line"><span class="cl">└──────────────────────────────────┘
</span></span><span class="line"><span class="cl">
</span></span><span class="line"><span class="cl">新分配(24字节):
</span></span><span class="line"><span class="cl">┌──────────────────────────────────────────────────┐
</span></span><span class="line"><span class="cl">│ canary│ logical_in_cmd (偏移+8) │ canary│
</span></span><span class="line"><span class="cl">│ (8B) │ (8B) │ (8B) │
</span></span><span class="line"><span class="cl">└──────────────────────────────────────────────────┘
</span></span><span class="line"><span class="cl"> ↑
</span></span><span class="line"><span class="cl"> 强制对齐到16字节边界
</span></span></code></pre></td></tr></table>
</div>
</div><h4 id="机制2缓冲溢出隔离">机制2:缓冲溢出隔离
</h4><ul>
<li>如果代码尝试越界写入:
<ul>
<li>写入后面缓冲时,会覆盖后Canary,而非其他数据结构</li>
<li>可以检测Canary值来发现溢出</li>
<li>防止了跨越到相邻内存块的污染</li>
</ul>
</li>
</ul>
<h4 id="机制3隐含的内存屏障效应">机制3:隐含的内存屏障效应
</h4><ul>
<li>更大的分配可能改变内存分配器的行为</li>
<li>可能自动添加了保护页面</li>
<li>可能改变了缓存行对齐</li>
</ul>
<h3 id="33-修复有效性评估">3.3 修复有效性评估
</h3><table>
<thead>
<tr>
<th>修复方面</th>
<th>改进</th>
<th>影响</th>
</tr>
</thead>
<tbody>
<tr>
<td>内存对齐</td>
<td>✓✓✓</td>
<td>确保16字节对齐</td>
</tr>
<tr>
<td>缓冲保护</td>
<td>✓✓✓</td>
<td>隔离越界访问</td>
</tr>
<tr>
<td>性能开销</td>
<td>✓</td>
<td>仅增加16字节</td>
</tr>
<tr>
<td>兼容性</td>
<td>✓✓</td>
<td>改善裸机和OS兼容性</td>
</tr>
<tr>
<td>可靠性</td>
<td>✓✓✓</td>
<td>解决U8类型问题</td>
</tr>
</tbody>
</table>
<hr>
<h2 id="四内存释放问题">四、内存释放问题
</h2><h3 id="41-当前释放代码的缺陷">4.1 当前释放代码的缺陷
</h3><p><strong>位置</strong>:<code>gcpnna_destroy_io_patch_info()</code> 函数 (第1461-1473行)</p>
<div class="highlight"><div class="chroma">
<table class="lntable"><tr><td class="lntd">
<pre tabindex="0" class="chroma"><code><span class="lnt">1
</span><span class="lnt">2
</span><span class="lnt">3
</span><span class="lnt">4
</span></code></pre></td>
<td class="lntd">
<pre tabindex="0" class="chroma"><code class="language-c" data-lang="c"><span class="line"><span class="cl"><span class="k">if</span> <span class="p">(</span><span class="n">io_info</span><span class="o">-&gt;</span><span class="n">logical_in_cmd</span> <span class="o">!=</span> <span class="n">PNNA_NULL</span><span class="p">)</span> <span class="p">{</span>
</span></span><span class="line"><span class="cl"> <span class="nf">gcpnna_user_free_memory</span><span class="p">(</span><span class="n">io_info</span><span class="o">-&gt;</span><span class="n">logical_in_cmd</span><span class="p">);</span> <span class="c1">// ❌ 释放的是已偏移的指针!
</span></span></span><span class="line"><span class="cl"> <span class="n">io_info</span><span class="o">-&gt;</span><span class="n">logical_in_cmd</span> <span class="o">=</span> <span class="n">PNNA_NULL</span><span class="p">;</span>
</span></span><span class="line"><span class="cl"><span class="p">}</span>
</span></span></code></pre></td></tr></table>
</div>
</div><h3 id="42-问题剖析">4.2 问题剖析
</h3><div class="highlight"><div class="chroma">
<table class="lntable"><tr><td class="lntd">
<pre tabindex="0" class="chroma"><code><span class="lnt"> 1
</span><span class="lnt"> 2
</span><span class="lnt"> 3
</span><span class="lnt"> 4
</span><span class="lnt"> 5
</span><span class="lnt"> 6
</span><span class="lnt"> 7
</span><span class="lnt"> 8
</span><span class="lnt"> 9
</span><span class="lnt">10
</span><span class="lnt">11
</span></code></pre></td>
<td class="lntd">
<pre tabindex="0" class="chroma"><code class="language-text" data-lang="text"><span class="line"><span class="cl">分配时:
</span></span><span class="line"><span class="cl">alloc_base ──────────────┬──────────────
</span></span><span class="line"><span class="cl"> [canary 8B] │[payload 8B][canary 8B]
</span></span><span class="line"><span class="cl"> ↑
</span></span><span class="line"><span class="cl"> logical_in_cmd = alloc_base + 8
</span></span><span class="line"><span class="cl">
</span></span><span class="line"><span class="cl">释放时应该:
</span></span><span class="line"><span class="cl">gcpnna_user_free_memory(alloc_base); // ✓ 释放原始指针
</span></span><span class="line"><span class="cl">
</span></span><span class="line"><span class="cl">但代码做的是:
</span></span><span class="line"><span class="cl">gcpnna_user_free_memory(logical_in_cmd); // ❌ 释放偏移后的指针
</span></span></code></pre></td></tr></table>
</div>
</div><h3 id="43-后果">4.3 后果
</h3><ol>
<li>
<p><strong>内存泄漏</strong></p>
<ul>
<li>实际分配了24字节</li>
<li>只释放了前8字节(Canary部分)</li>
<li>丢失了后8字节的Canary和管理信息</li>
</ul>
</li>
<li>
<p><strong>分配器崩溃</strong></p>
<ul>
<li>一些内存分配器依赖指针头部的元数据</li>
<li>释放偏移指针会破坏元数据</li>
<li>可能导致后续分配失败</li>
</ul>
</li>
<li>
<p><strong>未定义行为</strong></p>
<ul>
<li>双重释放的风险</li>
<li>堆腐坏(Heap corruption)</li>
</ul>
</li>
</ol>
<hr>
<h2 id="五完整修复方案">五、完整修复方案
</h2><h3 id="51-方案a最小化修复用户当前方案">5.1 方案A:最小化修复(用户当前方案)
</h3><p>仅使用Canary保护,但留下释放问题</p>
<div class="highlight"><div class="chroma">
<table class="lntable"><tr><td class="lntd">
<pre tabindex="0" class="chroma"><code><span class="lnt">1
</span><span class="lnt">2
</span><span class="lnt">3
</span></code></pre></td>
<td class="lntd">
<pre tabindex="0" class="chroma"><code class="language-c" data-lang="c"><span class="line"><span class="cl"><span class="c1">// 优点:简单,立竿见影地解决U8问题
</span></span></span><span class="line"><span class="cl"><span class="c1">// 缺点:留下内存泄漏隐患
</span></span></span><span class="line"><span class="cl"><span class="c1">// 风险:长期运行可能堆崩溃
</span></span></span></code></pre></td></tr></table>
</div>
</div><h3 id="52-方案b完整修复推荐">5.2 方案B:完整修复(推荐)
</h3><h4 id="步骤1扩展结构体">步骤1:扩展结构体
</h4><div class="highlight"><div class="chroma">
<table class="lntable"><tr><td class="lntd">
<pre tabindex="0" class="chroma"><code><span class="lnt"> 1
</span><span class="lnt"> 2
</span><span class="lnt"> 3
</span><span class="lnt"> 4
</span><span class="lnt"> 5
</span><span class="lnt"> 6
</span><span class="lnt"> 7
</span><span class="lnt"> 8
</span><span class="lnt"> 9
</span><span class="lnt">10
</span><span class="lnt">11
</span><span class="lnt">12
</span><span class="lnt">13
</span><span class="lnt">14
</span><span class="lnt">15
</span><span class="lnt">16
</span></code></pre></td>
<td class="lntd">
<pre tabindex="0" class="chroma"><code class="language-c" data-lang="c"><span class="line"><span class="cl"><span class="k">typedef</span> <span class="k">struct</span> <span class="n">_pnna_io_patch_info</span> <span class="p">{</span>
</span></span><span class="line"><span class="cl"> <span class="kt">pnna_uint32_t</span> <span class="n">slice_num</span><span class="p">;</span>
</span></span><span class="line"><span class="cl"> <span class="kt">pnna_address_t</span> <span class="o">*</span><span class="n">logical_in_cmd</span><span class="p">;</span>
</span></span><span class="line"><span class="cl"> <span class="kt">pnna_uint32_t</span> <span class="o">*</span><span class="n">physical_in_cmd</span><span class="p">;</span>
</span></span><span class="line"><span class="cl"> <span class="kt">pnna_uint32_t</span> <span class="o">*</span><span class="n">offsets</span><span class="p">;</span>
</span></span><span class="line"><span class="cl"> <span class="kt">pnna_uint32_t</span> <span class="o">*</span><span class="n">transformation</span><span class="p">;</span>
</span></span><span class="line"><span class="cl"> <span class="kt">pnna_uint32_t</span> <span class="n">counter</span><span class="p">;</span>
</span></span><span class="line"><span class="cl"> <span class="kt">pnna_uint32_t</span> <span class="n">physical</span><span class="p">;</span>
</span></span><span class="line"><span class="cl"> <span class="kt">pnna_uint8_t</span> <span class="o">*</span><span class="n">logical</span><span class="p">;</span>
</span></span><span class="line"><span class="cl"> <span class="kt">pnna_uint8_t</span> <span class="o">**</span><span class="n">sw_op_buffer</span><span class="p">;</span>
</span></span><span class="line"><span class="cl"> <span class="n">pnna_buffer</span> <span class="n">buffer</span><span class="p">;</span>
</span></span><span class="line"><span class="cl"> <span class="kt">pnna_uint32_t</span> <span class="n">patch_belong</span><span class="p">;</span>
</span></span><span class="line"><span class="cl">
</span></span><span class="line"><span class="cl"> <span class="c1">// 新增:保存原始分配指针
</span></span></span><span class="line"><span class="cl"> <span class="kt">void</span> <span class="o">*</span><span class="n">logical_in_cmd_alloc_base</span><span class="p">;</span> <span class="c1">// ✓ 跟踪原始分配
</span></span></span><span class="line"><span class="cl"><span class="p">}</span> <span class="kt">gcpnna_io_patch_info_t</span><span class="p">;</span>
</span></span></code></pre></td></tr></table>
</div>
</div><h4 id="步骤2修改分配代码">步骤2:修改分配代码
</h4><div class="highlight"><div class="chroma">
<table class="lntable"><tr><td class="lntd">
<pre tabindex="0" class="chroma"><code><span class="lnt"> 1
</span><span class="lnt"> 2
</span><span class="lnt"> 3
</span><span class="lnt"> 4
</span><span class="lnt"> 5
</span><span class="lnt"> 6
</span><span class="lnt"> 7
</span><span class="lnt"> 8
</span><span class="lnt"> 9
</span><span class="lnt">10
</span><span class="lnt">11
</span><span class="lnt">12
</span><span class="lnt">13
</span></code></pre></td>
<td class="lntd">
<pre tabindex="0" class="chroma"><code class="language-c" data-lang="c"><span class="line"><span class="cl"><span class="kt">pnna_uint32_t</span> <span class="n">payload_size</span> <span class="o">=</span> <span class="k">sizeof</span><span class="p">(</span><span class="kt">pnna_address_t</span><span class="p">)</span> <span class="o">*</span> <span class="n">io_info</span><span class="o">-&gt;</span><span class="n">slice_num</span><span class="p">;</span>
</span></span><span class="line"><span class="cl"><span class="k">const</span> <span class="kt">pnna_uint32_t</span> <span class="n">canary_bytes</span> <span class="o">=</span> <span class="k">sizeof</span><span class="p">(</span><span class="kt">pnna_uint64_t</span><span class="p">);</span>
</span></span><span class="line"><span class="cl"><span class="kt">pnna_uint32_t</span> <span class="n">alloc_size</span> <span class="o">=</span> <span class="n">payload_size</span> <span class="o">+</span> <span class="mi">2</span> <span class="o">*</span> <span class="n">canary_bytes</span><span class="p">;</span>
</span></span><span class="line"><span class="cl">
</span></span><span class="line"><span class="cl"><span class="kt">void</span> <span class="o">*</span><span class="n">alloc_base</span> <span class="o">=</span> <span class="n">PNNA_NULL</span><span class="p">;</span>
</span></span><span class="line"><span class="cl"><span class="nf">gcOnError</span><span class="p">(</span><span class="nf">gcpnna_user_allocate_memory</span><span class="p">(</span><span class="n">alloc_size</span><span class="p">,</span> <span class="p">(</span><span class="kt">void</span> <span class="o">**</span><span class="p">)</span><span class="o">&amp;</span><span class="n">alloc_base</span><span class="p">));</span>
</span></span><span class="line"><span class="cl">
</span></span><span class="line"><span class="cl"><span class="c1">// ✓ 保存原始指针
</span></span></span><span class="line"><span class="cl"><span class="n">io_info</span><span class="o">-&gt;</span><span class="n">logical_in_cmd_alloc_base</span> <span class="o">=</span> <span class="n">alloc_base</span><span class="p">;</span>
</span></span><span class="line"><span class="cl">
</span></span><span class="line"><span class="cl"><span class="c1">// 有效载荷位于前缀Canary之后
</span></span></span><span class="line"><span class="cl"><span class="n">io_info</span><span class="o">-&gt;</span><span class="n">logical_in_cmd</span> <span class="o">=</span> <span class="p">(</span><span class="kt">pnna_address_t</span> <span class="o">*</span><span class="p">)((</span><span class="kt">pnna_uint8_t</span> <span class="o">*</span><span class="p">)</span><span class="n">alloc_base</span> <span class="o">+</span> <span class="n">canary_bytes</span><span class="p">);</span>
</span></span><span class="line"><span class="cl"><span class="nf">gcpnna_user_zero_memory</span><span class="p">(</span><span class="n">io_info</span><span class="o">-&gt;</span><span class="n">logical_in_cmd</span><span class="p">,</span> <span class="n">payload_size</span><span class="p">);</span>
</span></span></code></pre></td></tr></table>
</div>
</div><h4 id="步骤3修改释放代码">步骤3:修改释放代码
</h4><div class="highlight"><div class="chroma">
<table class="lntable"><tr><td class="lntd">
<pre tabindex="0" class="chroma"><code><span class="lnt">1
</span><span class="lnt">2
</span><span class="lnt">3
</span><span class="lnt">4
</span><span class="lnt">5
</span></code></pre></td>
<td class="lntd">
<pre tabindex="0" class="chroma"><code class="language-c" data-lang="c"><span class="line"><span class="cl"><span class="k">if</span> <span class="p">(</span><span class="n">io_info</span><span class="o">-&gt;</span><span class="n">logical_in_cmd_alloc_base</span> <span class="o">!=</span> <span class="n">PNNA_NULL</span><span class="p">)</span> <span class="p">{</span>
</span></span><span class="line"><span class="cl"> <span class="nf">gcpnna_user_free_memory</span><span class="p">(</span><span class="n">io_info</span><span class="o">-&gt;</span><span class="n">logical_in_cmd_alloc_base</span><span class="p">);</span> <span class="c1">// ✓ 释放原始指针
</span></span></span><span class="line"><span class="cl"> <span class="n">io_info</span><span class="o">-&gt;</span><span class="n">logical_in_cmd_alloc_base</span> <span class="o">=</span> <span class="n">PNNA_NULL</span><span class="p">;</span>
</span></span><span class="line"><span class="cl"> <span class="n">io_info</span><span class="o">-&gt;</span><span class="n">logical_in_cmd</span> <span class="o">=</span> <span class="n">PNNA_NULL</span><span class="p">;</span>
</span></span><span class="line"><span class="cl"><span class="p">}</span>
</span></span></code></pre></td></tr></table>
</div>
</div><hr>
<h2 id="六为什么int16不出问题u8出问题">六、为什么INT16不出问题,U8出问题
</h2><h3 id="61-数据处理流程对比">6.1 数据处理流程对比
</h3><p><strong>INT16流程</strong>:</p>
<div class="highlight"><div class="chroma">
<table class="lntable"><tr><td class="lntd">
<pre tabindex="0" class="chroma"><code><span class="lnt">1
</span><span class="lnt">2
</span><span class="lnt">3
</span><span class="lnt">4
</span><span class="lnt">5
</span><span class="lnt">6
</span><span class="lnt">7
</span><span class="lnt">8
</span><span class="lnt">9
</span></code></pre></td>
<td class="lntd">
<pre tabindex="0" class="chroma"><code class="language-text" data-lang="text"><span class="line"><span class="cl">INT16 NBG
</span></span><span class="line"><span class="cl"> ↓
</span></span><span class="line"><span class="cl">较大数据块(2字节/元素)
</span></span><span class="line"><span class="cl"> ↓
</span></span><span class="line"><span class="cl">处理次数较少
</span></span><span class="line"><span class="cl"> ↓
</span></span><span class="line"><span class="cl">内存访问模式相对宽松
</span></span><span class="line"><span class="cl"> ↓
</span></span><span class="line"><span class="cl">不触发硬件对齐异常
</span></span></code></pre></td></tr></table>
</div>
</div><p><strong>U8流程</strong>:</p>
<div class="highlight"><div class="chroma">
<table class="lntable"><tr><td class="lntd">
<pre tabindex="0" class="chroma"><code><span class="lnt">1
</span><span class="lnt">2
</span><span class="lnt">3
</span><span class="lnt">4
</span><span class="lnt">5
</span><span class="lnt">6
</span><span class="lnt">7
</span><span class="lnt">8
</span><span class="lnt">9
</span></code></pre></td>
<td class="lntd">
<pre tabindex="0" class="chroma"><code class="language-text" data-lang="text"><span class="line"><span class="cl">U8 NBG
</span></span><span class="line"><span class="cl"> ↓
</span></span><span class="line"><span class="cl">较小数据块(1字节/元素)
</span></span><span class="line"><span class="cl"> ↓
</span></span><span class="line"><span class="cl">处理次数众多
</span></span><span class="line"><span class="cl"> ↓
</span></span><span class="line"><span class="cl">内存访问密集
</span></span><span class="line"><span class="cl"> ↓
</span></span><span class="line"><span class="cl">触发硬件对齐检查
</span></span></code></pre></td></tr></table>
</div>
</div><h3 id="62-c66x硬件特性">6.2 C66X硬件特性
</h3><ul>
<li>支持向量操作(SIMD)</li>
<li>对齐访问有严格要求</li>
<li>非对齐访问会:
<ul>
<li>导致性能下降</li>
<li>可能触发异常(某些配置)</li>
<li>在某些内存区域直接失败</li>
</ul>
</li>
</ul>
<h3 id="63-内存分配器的行为差异">6.3 内存分配器的行为差异
</h3><div class="highlight"><div class="chroma">
<table class="lntable"><tr><td class="lntd">
<pre tabindex="0" class="chroma"><code><span class="lnt">1
</span><span class="lnt">2
</span><span class="lnt">3
</span></code></pre></td>
<td class="lntd">
<pre tabindex="0" class="chroma"><code class="language-text" data-lang="text"><span class="line"><span class="cl">分配8字节时:可能返回未对齐指针
</span></span><span class="line"><span class="cl">分配16字节时:分配器倾向于返回16字节对齐指针
</span></span><span class="line"><span class="cl">分配24字节时:更可能满足硬件对齐要求
</span></span></code></pre></td></tr></table>
</div>
</div><hr>
<h2 id="七测试验证建议">七、测试验证建议
</h2><h3 id="71-功能测试">7.1 功能测试
</h3><div class="highlight"><div class="chroma">
<table class="lntable"><tr><td class="lntd">
<pre tabindex="0" class="chroma"><code><span class="lnt">1
</span><span class="lnt">2
</span><span class="lnt">3
</span><span class="lnt">4
</span></code></pre></td>
<td class="lntd">
<pre tabindex="0" class="chroma"><code class="language-c" data-lang="c"><span class="line"><span class="cl"><span class="mf">1.</span> <span class="n">U8</span> <span class="n">NBG单层测试</span><span class="err">:✓</span> <span class="err">已成功</span>
</span></span><span class="line"><span class="cl"><span class="mf">2.</span> <span class="n">U8</span> <span class="n">NBG多层测试</span><span class="err">:需要验证</span>
</span></span><span class="line"><span class="cl"><span class="mf">3.</span> <span class="n">INT16</span> <span class="n">NBG回归测试</span><span class="err">:✓</span> <span class="err">需要确认无破坏</span>
</span></span><span class="line"><span class="cl"><span class="mf">4.</span> <span class="err">混合</span><span class="n">U8</span><span class="o">/</span><span class="n">INT16测试</span><span class="err">:需要验证</span>
</span></span></code></pre></td></tr></table>
</div>
</div><h3 id="72-内存检测">7.2 内存检测
</h3><div class="highlight"><div class="chroma">
<table class="lntable"><tr><td class="lntd">
<pre tabindex="0" class="chroma"><code><span class="lnt">1
</span><span class="lnt">2
</span><span class="lnt">3
</span><span class="lnt">4
</span><span class="lnt">5
</span><span class="lnt">6
</span><span class="lnt">7
</span><span class="lnt">8
</span><span class="lnt">9
</span></code></pre></td>
<td class="lntd">
<pre tabindex="0" class="chroma"><code class="language-c" data-lang="c"><span class="line"><span class="cl"><span class="c1">// 添加Canary检查(调试时)
</span></span></span><span class="line"><span class="cl"><span class="cp">#define CHECK_CANARY(base_ptr, alloc_size) \
</span></span></span><span class="line"><span class="cl"><span class="cp"> do { \
</span></span></span><span class="line"><span class="cl"><span class="cp"> pnna_uint64_t *prefix = (pnna_uint64_t *)base_ptr; \
</span></span></span><span class="line"><span class="cl"><span class="cp"> pnna_uint64_t *suffix = (pnna_uint64_t *)((pnna_uint8_t *)base_ptr + alloc_size - 8); \
</span></span></span><span class="line"><span class="cl"><span class="cp"> if (*prefix != CANARY_VALUE || *suffix != CANARY_VALUE) { \
</span></span></span><span class="line"><span class="cl"><span class="cp"> gcpnna_error(&#34;Canary corrupted! Buffer overflow detected!&#34;); \
</span></span></span><span class="line"><span class="cl"><span class="cp"> } \
</span></span></span><span class="line"><span class="cl"><span class="cp"> } while(0)
</span></span></span></code></pre></td></tr></table>
</div>
</div><h3 id="73-长期运行测试">7.3 长期运行测试
</h3><ul>
<li>100,000+ 次分配/释放循环</li>
<li>监测是否有内存泄漏</li>
<li>监测堆使用趋势</li>
</ul>
<hr>
<h2 id="八总结对比">八、总结对比
</h2><table>
<thead>
<tr>
<th>项目</th>
<th>原代码</th>
<th>修复后</th>
<th>改进</th>
</tr>
</thead>
<tbody>
<tr>
<td><strong>U8支持</strong></td>
<td>❌ 失败</td>
<td>✓ 成功</td>
<td>+100%</td>
</tr>
<tr>
<td><strong>INT16</strong></td>
<td>✓ 成功</td>
<td>✓ 成功</td>
<td>兼容</td>
</tr>
<tr>
<td><strong>裸机</strong></td>
<td>❌ 失败</td>
<td>✓ 成功</td>
<td>+100%</td>
</tr>
<tr>
<td><strong>RT-Thread</strong></td>
<td>✓ 成功</td>
<td>✓ 成功</td>
<td>兼容</td>
</tr>
<tr>
<td><strong>内存对齐</strong></td>
<td>不确定</td>
<td>保证</td>
<td>✓✓✓</td>
</tr>
<tr>
<td><strong>缓冲保护</strong></td>
<td>无</td>
<td>有</td>
<td>✓✓✓</td>
</tr>
<tr>
<td><strong>内存泄漏</strong></td>
<td>无</td>
<td>无(方案B)</td>
<td>安全</td>
</tr>
<tr>
<td><strong>开销</strong></td>
<td>最小</td>
<td>16B增加</td>
<td>&lt;0.1%</td>
</tr>
</tbody>
</table>
<hr>
<h2 id="九建议行动">九、建议行动
</h2><h3 id="立即执行高优先级">立即执行(高优先级)
</h3><ol>
<li>✓ 采用Canary保护方案(已验证有效)</li>
<li>⚠️ 审计所有类似的内存分配代码</li>
</ol>
<h3 id="短期执行中优先级">短期执行(中优先级)
</h3><ol>
<li>扩展结构体,跟踪alloc_base</li>
<li>修改释放代码</li>
<li>添加单元测试</li>
</ol>
<h3 id="长期执行低优先级">长期执行(低优先级)
</h3><ol>
<li>考虑统一的内存管理框架</li>
<li>添加编译时对齐检查宏</li>
<li>文档记录裸机vs OS的差异</li>
</ol>
</description>
</item>
<item>
<title>04V_RTT</title>
<link>https://xenithya.github.io/p/04v_rtt/</link>
<pubDate>Fri, 07 Nov 2025 09:15:41 +0800</pubDate>
<guid>https://xenithya.github.io/p/04v_rtt/</guid>
<description><h2 id="04v-移植-rt-thread">04V 移植 RT-Thread
</h2><p>主要描述过程中遇到的相关问题和相关记录</p>
<h3 id="程序运行到浮点数时系统崩溃">程序运行到浮点数时系统崩溃
</h3><h4 id="总结">总结
</h4><p>浮点数操作会导致系统崩溃由 MMU 初始化失败引发</p>
<h4 id="代码">代码
</h4><div class="highlight"><div class="chroma">
<table class="lntable"><tr><td class="lntd">
<pre tabindex="0" class="chroma"><code><span class="lnt"> 1
</span><span class="lnt"> 2
</span><span class="lnt"> 3
</span><span class="lnt"> 4
</span><span class="lnt"> 5
</span><span class="lnt"> 6
</span><span class="lnt"> 7
</span><span class="lnt"> 8
</span><span class="lnt"> 9
</span><span class="lnt">10
</span><span class="lnt">11
</span><span class="lnt">12
</span><span class="lnt">13
</span><span class="lnt">14
</span><span class="lnt">15
</span><span class="lnt">16
</span><span class="lnt">17
</span><span class="lnt">18
</span><span class="lnt">19
</span><span class="lnt">20
</span><span class="lnt">21
</span><span class="lnt">22
</span></code></pre></td>
<td class="lntd">
<pre tabindex="0" class="chroma"><code class="language-c" data-lang="c"><span class="line"><span class="cl"><span class="cm">/* mmu config */</span>
</span></span><span class="line"><span class="cl"><span class="k">struct</span> <span class="n">mem_desc</span> <span class="n">platform_mem_desc</span><span class="p">[]</span> <span class="o">=</span>
</span></span><span class="line"><span class="cl"><span class="p">{</span>
</span></span><span class="line"><span class="cl"> <span class="p">{</span>
</span></span><span class="line"><span class="cl"> <span class="mh">0x00000000</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="mh">0x00000000</span> <span class="o">+</span> <span class="mh">0x00030000</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="mh">0x00000000</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="n">DEVICE_MEM</span>
</span></span><span class="line"><span class="cl"> <span class="p">},</span>
</span></span><span class="line"><span class="cl"> <span class="p">{</span>
</span></span><span class="line"><span class="cl"> <span class="mh">0x30000000</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="mh">0x30B3FFFF</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="mh">0x30000000</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="n">DEVICE_MEM</span>
</span></span><span class="line"><span class="cl"> <span class="p">},</span>
</span></span><span class="line"><span class="cl"> <span class="p">{</span>
</span></span><span class="line"><span class="cl"> <span class="mh">0x80000000</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="mh">0x80000000</span> <span class="o">+</span> <span class="mh">0x7E000000</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="mh">0x80000000</span><span class="p">,</span>
</span></span><span class="line"><span class="cl"> <span class="n">NORMAL_MEM</span>
</span></span><span class="line"><span class="cl"> <span class="p">},</span>
</span></span><span class="line"><span class="cl"><span class="p">};</span>
</span></span></code></pre></td></tr></table>
</div>
</div><h4 id="参数解析">参数解析
</h4><p><code>platform_mem_desc</code> 数组定义了一系列内存区域的映射规则,供 MMU(内存管理单元)在系统启动时配置页表。数组中的每个结构体(<code>struct mem_desc</code>)通常包含四个关键参数:</p>
<table>
<thead>
<tr>
<th style="text-align: center">序号</th>
<th style="text-align: left">参数名(通常约定)</th>
<th style="text-align: left">示例值</th>
<th style="text-align: left">含义</th>
</tr>
</thead>
<tbody>
<tr>
<td style="text-align: center"><strong>1</strong></td>
<td style="text-align: left"><strong>虚拟地址起始 (<code>vaddr_start</code>)</strong></td>
<td style="text-align: left"><code>0x80000000</code></td>
<td style="text-align: left">CPU 访问该内存区域时使用的<strong>虚拟地址</strong>的起始点。</td>
</tr>
<tr>
<td style="text-align: center"><strong>2</strong></td>
<td style="text-align: left"><strong>虚拟地址结束 (<code>vaddr_end</code>)</strong></td>
<td style="text-align: left"><code>0x80000000 + 0x7E000000</code></td>
<td style="text-align: left">CPU 访问该内存区域时使用的<strong>虚拟地址</strong>的结束点(或紧随其后的地址)。</td>
</tr>
<tr>
<td style="text-align: center"><strong>3</strong></td>
<td style="text-align: left"><strong>物理地址起始 (<code>paddr_start</code>)</strong></td>
<td style="text-align: left"><code>0x80000000</code></td>
<td style="text-align: left">该内存区域在实际硬件上的<strong>物理地址</strong>的起始点。</td>
</tr>
<tr>
<td style="text-align: center"><strong>4</strong></td>
<td style="text-align: left"><strong>内存属性 (<code>attr</code>)</strong></td>
<td style="text-align: left"><code>NORMAL_MEM</code></td>
<td style="text-align: left">定义该内存区域的访问特性和缓存策略。</td>
</tr>
</tbody>
</table>
<h4 id="内存属性总结">内存属性总结
</h4><table>
<thead>
<tr>
<th style="text-align: center">属性宏</th>
<th style="text-align: left">描述</th>
<th style="text-align: left">主要用途</th>
<th style="text-align: left">缓存特性</th>
</tr>
</thead>
<tbody>
<tr>
<td style="text-align: center"><strong><code>DEVICE_MEM</code></strong></td>
<td style="text-align: left">设备内存</td>
<td style="text-align: left">映射外设寄存器、不可缓存的片上 RAM 等。</td>
<td style="text-align: left"><strong>不可缓存</strong>,每次读写直接操作硬件。</td>
</tr>
<tr>
<td style="text-align: center"><strong><code>NORMAL_MEM</code></strong></td>
<td style="text-align: left">普通内存</td>
<td style="text-align: left">映射主存储器(DRAM/SDRAM),存放代码、堆栈、数据等。</td>
<td style="text-align: left"><strong>可缓存</strong>,由缓存机制加速访问。</td>
</tr>
</tbody>
</table>
<h4 id="参数地址说明">参数地址说明
</h4><p>根据 04V 空间地址划分,
&lsquo;0x00000000 - 0x00030000&rsquo; 为 arm 的私有空间
&lsquo;0x30000000 - 0x30B3FFFF&rsquo; 系统共享片上外设配置空间
&lsquo;0x80000000 - 0xFFFFFFFF&rsquo; 为 DDR 空间</p>
<p>不同的板卡需要根据寄存器地址空间说明来配置</p>
<h3 id="定时器校准">定时器校准
</h3><h4 id="计时不准确的问题">计时不准确的问题
</h4><p><strong>问题描述</strong>:</p>
<p>系统中通过 <code>rt_tick_get()</code> 获取的时间与实际时间存在偏差,定时不准确。
分析发现,RT-Thread 内核时钟(tick)由 <code>Generic Timer</code> 提供中断驱动,而定时器频率配置错误导致 tick 周期不正确。</p>
<p><strong>问题原因</strong>:</p>
<ul>
<li><code>gtimer_set_counter_frequency()</code> 中手动设置的 <code>CNT_FREQUENCY</code>(如 10MHz)与实际硬件计数器频率不一致。</li>
<li><code>gtimer_set_load_value()</code> 参数使用了错误的步进值,导致 tick 中断周期计算错误。</li>
</ul>
<h4 id="确认硬件计数器频率">确认硬件计数器频率
</h4><p><strong>操作与分析</strong>:</p>
<p>使用 <code>gtimer_get_counter_frequency()</code> 读取系统实际的定时器频率:</p>
<div class="highlight"><div class="chroma">
<table class="lntable"><tr><td class="lntd">
<pre tabindex="0" class="chroma"><code><span class="lnt">1
</span><span class="lnt">2
</span></code></pre></td>
<td class="lntd">
<pre tabindex="0" class="chroma"><code class="language-c" data-lang="c"><span class="line"><span class="cl"><span class="n">timer_step</span> <span class="o">=</span> <span class="nf">gtimer_get_counter_frequency</span><span class="p">();</span>
</span></span><span class="line"><span class="cl"><span class="nf">rt_kprintf</span><span class="p">(</span><span class="s">&#34;freqency %u MHz</span><span class="se">\n</span><span class="s">&#34;</span><span class="p">,</span> <span class="n">timer_step</span> <span class="o">/</span> <span class="mi">1000000</span><span class="p">);</span>
</span></span></code></pre></td></tr></table>
</div>
</div><p>输出结果为:</p>
<div class="highlight"><div class="chroma">
<table class="lntable"><tr><td class="lntd">
<pre tabindex="0" class="chroma"><code><span class="lnt">1
</span></code></pre></td>
<td class="lntd">
<pre tabindex="0" class="chroma"><code class="language-bash" data-lang="bash"><span class="line"><span class="cl">freqency <span class="m">150</span> MHz
</span></span></code></pre></td></tr></table>
</div>
</div><p><strong>说明</strong>:</p>
<ul>
<li>该值来自 ARM 架构的 <strong>CNTFRQ 寄存器</strong>,表示 <strong>PL1 Physical Timer(Generic Timer)</strong> 的输入时钟频率。</li>
<li>该定时器为 ARM Cortex-A 系列(如 Cortex-A15)内置硬件定时器,与 CPU 主频相关但 <strong>通常经过分频</strong>,即定时器频率 ≤ CPU 主频。</li>
</ul>
<hr>
<h4 id="修复方法">修复方法
</h4><p><strong>修复思路</strong>:</p>
<p>使 RT-Thread 的 tick 中断周期与硬件计数频率严格匹配。</p>
<p><strong>具体修改</strong>:</p>
<ol>
<li>
<p><strong>不再手动设置 CNTFRQ</strong>,保持硬件默认值:</p>
<div class="highlight"><div class="chroma">
<table class="lntable"><tr><td class="lntd">
<pre tabindex="0" class="chroma"><code><span class="lnt">1
</span></code></pre></td>
<td class="lntd">
<pre tabindex="0" class="chroma"><code class="language-c" data-lang="c"><span class="line"><span class="cl"><span class="c1">// gtimer_set_counter_frequency(CNT_FREQUENCY); // 删除此行
</span></span></span></code></pre></td></tr></table>
</div>
</div></li>
<li>
<p><strong>基于实际频率计算 tick 周期:</strong></p>
<div class="highlight"><div class="chroma">
<table class="lntable"><tr><td class="lntd">
<pre tabindex="0" class="chroma"><code><span class="lnt">1
</span><span class="lnt">2
</span></code></pre></td>
<td class="lntd">
<pre tabindex="0" class="chroma"><code class="language-c" data-lang="c"><span class="line"><span class="cl"><span class="n">timer_step</span> <span class="o">=</span> <span class="nf">gtimer_get_counter_frequency</span><span class="p">()</span> <span class="o">/</span> <span class="n">RT_TICK_PER_SECOND</span><span class="p">;</span>
</span></span><span class="line"><span class="cl"><span class="nf">gtimer_set_load_value</span><span class="p">(</span><span class="n">timer_step</span><span class="p">);</span>
</span></span></code></pre></td></tr></table>
</div>
</div></li>
<li>
<p><strong>中断服务函数保持一次重装载:</strong></p>
<div class="highlight"><div class="chroma">
<table class="lntable"><tr><td class="lntd">
<pre tabindex="0" class="chroma"><code><span class="lnt"> 1
</span><span class="lnt"> 2
</span><span class="lnt"> 3
</span><span class="lnt"> 4
</span><span class="lnt"> 5
</span><span class="lnt"> 6
</span><span class="lnt"> 7
</span><span class="lnt"> 8
</span><span class="lnt"> 9
</span><span class="lnt">10
</span><span class="lnt">11
</span></code></pre></td>
<td class="lntd">
<pre tabindex="0" class="chroma"><code class="language-c" data-lang="c"><span class="line"><span class="cl"><span class="kt">void</span> <span class="nf">rt_hw_timer_isr</span><span class="p">(</span><span class="kt">int</span> <span class="n">vector</span><span class="p">,</span> <span class="kt">void</span> <span class="o">*</span><span class="n">parameter</span><span class="p">)</span>
</span></span><span class="line"><span class="cl"><span class="p">{</span>
</span></span><span class="line"><span class="cl"> <span class="nf">rt_hw_interrupt_mask</span><span class="p">(</span><span class="n">GENERIC_TIMER_IRQ_NUM</span><span class="p">);</span>
</span></span><span class="line"><span class="cl"> <span class="nf">arm_gic_clear_pending_irq</span><span class="p">(</span><span class="n">GENERIC_TIMER_ID0</span><span class="p">,</span> <span class="n">GENERIC_TIMER_IRQ_NUM</span><span class="p">);</span>
</span></span><span class="line"><span class="cl"> <span class="nf">arm_gic_clear_active</span><span class="p">(</span><span class="n">GENERIC_TIMER_ID0</span><span class="p">,</span> <span class="n">GENERIC_TIMER_IRQ_NUM</span><span class="p">);</span>
</span></span><span class="line"><span class="cl">
</span></span><span class="line"><span class="cl"> <span class="nf">rt_tick_increase</span><span class="p">();</span> <span class="c1">// 通知RTT系统时间+1tick
</span></span></span><span class="line"><span class="cl"> <span class="nf">gtimer_set_load_value</span><span class="p">(</span><span class="n">timer_step</span><span class="p">);</span> <span class="c1">// 仅在ISR中重装载计数值
</span></span></span><span class="line"><span class="cl">
</span></span><span class="line"><span class="cl"> <span class="nf">rt_hw_interrupt_umask</span><span class="p">(</span><span class="n">GENERIC_TIMER_IRQ_NUM</span><span class="p">);</span>
</span></span><span class="line"><span class="cl"><span class="p">}</span>
</span></span></code></pre></td></tr></table>
</div>
</div></li>
</ol>
<h4 id="校准验证结果">校准验证结果
</h4><p><strong>验证方法</strong>:</p>
<p>同时通过:</p>
<ul>
<li>硬件计数值:<code>gtimer_get_counter()</code></li>
<li>内核tick:<code>rt_tick_get()</code></li>
</ul>
<p>分别计算时间间隔并对比。</p>
<p><strong>验证结果</strong>:</p>
<p>两者计时结果完全一致,表明系统 tick 与硬件定时器周期完全同步,计时准确。</p>
<h4 id="补充说明">补充说明
</h4><table>
<thead>
<tr>
<th>项目</th>
<th>说明</th>
</tr>
</thead>
<tbody>
<tr>
<td><strong>PL1 Physical Timer</strong></td>
<td>ARM Cortex-A 架构(如 A15)内置的 Generic Timer,寄存器包括 CNTFRQ、CNTP_TVAL、CNTP_CTL 等。</td>
</tr>
<tr>
<td><strong>CPU 主频与定时器频率关系</strong></td>
<td>定时器通常由主时钟分频得到,频率可能为主频的 1/2、1/4 等;由 SoC 硬件设计决定。</td>
</tr>
<tr>
<td><strong>准确计时的关键</strong></td>
<td>使用 <code>__get_cntfrq()</code> 获取真实频率,并以此计算每 tick 的装载值。</td>
</tr>
</tbody>
</table>
<div class="highlight"><div class="chroma">
<table class="lntable"><tr><td class="lntd">
<pre tabindex="0" class="chroma"><code><span class="lnt"> 1
</span><span class="lnt"> 2
</span><span class="lnt"> 3
</span><span class="lnt"> 4
</span><span class="lnt"> 5
</span><span class="lnt"> 6
</span><span class="lnt"> 7
</span><span class="lnt"> 8
</span><span class="lnt"> 9
</span><span class="lnt">10
</span><span class="lnt">11
</span><span class="lnt">12
</span><span class="lnt">13
</span><span class="lnt">14
</span><span class="lnt">15
</span><span class="lnt">16
</span><span class="lnt">17
</span></code></pre></td>
<td class="lntd">
<pre tabindex="0" class="chroma"><code class="language-c" data-lang="c"><span class="line"><span class="cl"><span class="kt">int</span> <span class="nf">rt_hw_timer_init</span><span class="p">(</span><span class="kt">void</span><span class="p">)</span>
</span></span><span class="line"><span class="cl"><span class="p">{</span>
</span></span><span class="line"><span class="cl"> <span class="n">timer_step</span> <span class="o">=</span> <span class="nf">gtimer_get_counter_frequency</span><span class="p">();</span>
</span></span><span class="line"><span class="cl"> <span class="nf">rt_kprintf</span><span class="p">(</span><span class="s">&#34;freqency %u MHz</span><span class="se">\n</span><span class="s">&#34;</span><span class="p">,</span> <span class="n">timer_step</span><span class="o">/</span><span class="mi">1000000</span><span class="p">);</span>
</span></span><span class="line"><span class="cl">
</span></span><span class="line"><span class="cl"> <span class="n">timer_step</span> <span class="o">=</span> <span class="n">timer_step</span><span class="o">/</span><span class="n">RT_TICK_PER_SECOND</span><span class="p">;</span>
</span></span><span class="line"><span class="cl"> <span class="nf">gtimer_set_load_value</span><span class="p">(</span><span class="n">timer_step</span><span class="p">);</span>
</span></span><span class="line"><span class="cl">
</span></span><span class="line"><span class="cl"> <span class="nf">rt_hw_interrupt_install</span><span class="p">(</span><span class="n">GENERIC_TIMER_IRQ_NUM</span><span class="p">,</span> <span class="n">rt_hw_timer_isr</span><span class="p">,</span> <span class="n">RT_NULL</span><span class="p">,</span> <span class="s">&#34;tick&#34;</span><span class="p">);</span>
</span></span><span class="line"><span class="cl"> <span class="nf">rt_hw_interrupt_umask</span><span class="p">(</span><span class="n">GENERIC_TIMER_IRQ_NUM</span><span class="p">);</span>
</span></span><span class="line"><span class="cl">
</span></span><span class="line"><span class="cl"> <span class="nf">GenericTimerInterruptEnable</span><span class="p">(</span><span class="n">GENERIC_TIMER_ID0</span><span class="p">);</span>
</span></span><span class="line"><span class="cl"> <span class="nf">GenericTimerStart</span><span class="p">(</span><span class="n">GENERIC_TIMER_ID0</span><span class="p">);</span>
</span></span><span class="line"><span class="cl">