Hi everyone.
I have the pleasure of announcing the availability of Eclipse ThreadX version 6.5.2.202603.
This is the largest release the project has shipped since it moved to the Eclipse Foundation. It brings two new Arm ports, a new component, a new board example, and 35 security advisories across five components. Five things stand out:
- A Cortex-R52 port, with matching support for ThreadX modules, validated on Armv8-R silicon as well as on the Arm AEM FVP.
- ZoneX, a new component of the suite: a deterministic partitioning hypervisor for Armv8-R that runs at EL2 and gives each partition a statically declared slice of memory and of time.
- A RISC-V64 board example for Erbium, the 16-hart platform of the OpenHW Foundation's CORE-ET project.
- Thirty-five security advisories, every one of them with a CVE, across ThreadX, FileX, NetX Duo, GUIX and USBX.
- Greatly extended Windows simulator support, with native Win32 and Win64 ports, now covering ThreadX, FileX, NetX Duo and USBX.
Underneath all of that, how we validate the suite has changed. FileX, GUIX and LevelX now gate their dev branches on the full regression suite and on coverage rather than on a subset; toolchains and SDKs are pinned by commit instead of fetched from floating branches, and dependencies are checked out at a known commit so two runs a week apart compile the same thing. Less visible than a new port, but it is what the rest of this release rests on.
The user guides are also attached to each release now, as PDFs in A4 and US Letter.
Contributing organisations
Many thanks to 10xEngineers (@akifejaz), AiNekko (@AFOliveira), Arm China (@cpussw01), Causal Security (@cipher-creator), DPHI Space (@Sawii00), Google (@alieissa and @AmmarOkla12772, through Summer of Code), Logic Elements (@jiri-novotny), Rockwell Automation (@mzgrebnak), and STMicroelectronics (@rahmanih).
Independent contributors
Twelve people contributed code on their own account: @EdouardMALOT, @francdoc, @hefanbo, @miracoli, @ntfreak, @parsley, @pnfd, @prashit-vora, @tinic, @Winstonllllai, @yf13, and @Yves57.
Reported by
Twenty-one of the thirty-five advisories in this release were reported from outside the project. Our thanks to @Kimdir01 and @adawn0106, who reported five each, and to @afldl, @cipher-creator of Causal Security and @EdouardMALOT, who reported two each. Our thanks also to @acorn421, @COOOkies4U, @enitmar of SecMate, @leginwos, @max-r-b, @Microsvuln, @SounLabs, @tinic, and @Yves57 of Wormsensing, and to @wsparks-vc of VulnCheck, who coordinated one of the TLS 1.3 disclosures.
Reporting a defect clearly, with the limits of the claim stated, is what lets it be triaged accurately rather than over- or under-rated. Several of these reports did exactly that.
New Contributors
We have 17 this time. Not too bad for summer months! Welcome to
@AFOliveira, @COOOkies4U, @cpussw01, @divyanshisingh987456321, @francdoc, @hefanbo, @Jaxc, @miracoli, @ntfreak, @parsley, @pnfd, @prashit-vora, @rahmanih, @Sawii00, @tinic, @yf13, and @Yves57.
Release OverviewThreadXThe largest ThreadX release in years. Nine vulnerabilities in the Module Manager are fixed, a Cortex-R52 port arrives validated on silicon, and a Cortex-M52 port joins it. The Arm ports now build with LLVM/Clang under a CI check, Windows simulator support is complete, and the POSIX and FreeRTOS compatibility layers have their first regression suites.
Full release notes:
https://github.com/eclipse-threadx/threadx/releases/tag/v6.5.2.202603_relSecurity advisories:
https://github.com/eclipse-threadx/threadx/security/advisoriesNetX DuoDominated by security and by TLS 1.3 correctness. Thirteen vulnerabilities are fixed across the X.509 parser, the TLS 1.3 handshake, the WebSocket client, the Web HTTP server and the MQTT client, four of them critical and reachable before authentication. A series of TLS 1.3 fixes brings the implementation into line with RFC 8446, and the OpenSSL interoperability suite has been rebuilt.
Full release notes:
https://github.com/eclipse-threadx/netxduo/releases/tag/v6.5.2.202603_relSecurity advisories:
https://github.com/eclipse-threadx/netxduo/security/advisoriesUSBXThree out-of-bounds reads in the host classes are
fixed, each reached by a device
reporting a length larger than the buffer the host sized for it. The host classes no longer trust a device's own lengths. Four APIs are flagged as deprecated.
Full release notes:
https://github.com/eclipse-threadx/usbx/releases/tag/v6.5.2.202603_relSecurity advisories:
https://github.com/eclipse-threadx/usbx/security/advisoriesFileXAn out-of-bounds write in fault-tolerant log replay is fixed, Windows simulator support is completed with native Win32 and Win64 ports, and the regression
suite sits behind real gates for the first time.
Full release notes:
https://github.com/eclipse-threadx/filex/releases/tag/v6.5.2.202603_relSecurity advisories:
https://github.com/eclipse-threadx/filex/security/advisoriesLevelXNOR flash correctness. Four fixes address uninitialised state and unchecked parameters in the extended cache and in the block reclaim and erase-search paths, each with a regression test that reproduces the fault it fixes.
Full release notes:
https://github.com/eclipse-threadx/levelx/releases/tag/v6.5.2.202603_relGUIXAlmost entirely about the code that parses untrusted input. Nine vulnerabilities are fixed across the binary resource loader and the JPEG and PNG decoders, seven of them heap out-of-bounds writes or reads. The resource loader now knows how long its resource is, which closes a class of defect rather than one instance of it.
Full release notes:
https://github.com/eclipse-threadx/guix/releases/tag/v6.5.2.202603_relSecurity advisories:
https://github.com/eclipse-threadx/guix/security/advisoriesSampleXA board target is now something you copy rather
than something you invent. A generic BSP framework replaces the per-board scaffolding; four targets are built on it, and every toolchain and SDK is pinned.
Much of this came through Google Summer of Code. @alieissa contributed the NXP i.MX RT1064-EVK target with its three demos and Renode CI, along with the STM32F767ZI BSP refactor and its NetX Duo echo demo. @AmmarOkla12772 contributed the ThreadX monitor and primitives showcase for the NUCLEO-F401RE, and the network-connected environmental station demo. Between them, that is half the targets in this release and two of its demos. Our thanks to them both, and to Google for supporting their work.
Full release notes:
https://github.com/eclipse-threadx/samplex/releases/tag/v6.5.2.202603_relZoneXThe first release of ZoneX, a deterministic partitioning hypervisor for Armv8-R and a new component of the suite. It runs at EL2, gives each partition a statically declared slice of memory and of time, and treats a partition overrunning its slice as a fault rather than as scheduling pressure.
It ships as v0.1.0.202603 rather than 6.5.2.202603 because it is pre-production software and is versioned on its own line until it reaches a true 1.0, at which point it will join the suite's version numbering.
Full release notes:
https://github.com/eclipse-threadx/zonex/releases/tag/v0.1.0.202603_rel =====
Of course, now that v6.5.2 is out there, work is starting on v6.5.3!
Best Regards,
Frédéric DESBIENS
Project Lead | Eclipse ThreadX
Senior Manager —
Embedded Systems, IoT, and Open Hardware Programs | Eclipse Foundation
Mastodon: @fdesbiens@xxxxxxxxxxxxxxxxxxxxx
Eclipse Foundation: The Community for Open Innovation and Collaboration