Skip to content

fix(mcu): honor AVR PlatformIO registry pins - #1520

Merged
zackees merged 4 commits into
mainfrom
fix/avr-registry-1494
Sep 27, 2026
Merged

zackees merged 4 commits into
mainfrom
fix/avr-registry-1494

Conversation

@zackees

@zackees zackees commented Sep 27, 2026 •

Copy link
Copy Markdown
Member

Summary

  • Resolve AVR and megaAVR platform/package registry aliases through the shared PlatformIO resolver, including core-specific frameworks and compatible toolchain versions.
  • Preserve explicit archive overrides and make requested/resolved package identities visible in build output.
  • Add offline resolver and adapter unit tests plus live-build fixtures for MiniCore, Arduino AVR/megaAVR, ATTinyCore, megaTinyCore, and DxCore.

Validation

  • RED: MiniCore 3.1.2 pin previously selected embedded 2.2.2; GREEN: exact 3.1.2 PlatformIO archive is used.
  • Live builds passed for ATmega8, Nano Every, Uno, ATtiny85, ATtiny1616, and AVR128DA64 with isolated direct daemon. Unpublished MiniCore 3.1.0 fails before compile (registry does not publish 3.1.0; see issue correction comment).
  • soldr cargo test -p fbuild-build-mcu --lib (67 passed)
  • soldr cargo test -p fbuild-library --lib (268 passed)
  • soldr cargo test -p fbuild-build-engine --lib (455 passed)
  • soldr cargo test -p fbuild-core --test platformio_package_resolution (23 passed)
  • Clippy touched crates with -D warnings; fmt and diff checks passed.

Base includes the merged Dylint speedups #1516–#1518.

Closes #1494

Summary by CodeRabbit

  • New Features

    • AVR and megaAVR builds can resolve framework and toolchain packages from registry pins across standard and alternate cores.
    • Added support for additional AVR frameworks, including MicroCore, DxCore, and MegaCore.
    • Explicit package pins take precedence over default toolchain selections.
  • Bug Fixes

    • Corrected framework downloads and validation for alternate AVR cores, including MiniCore.
  • Documentation

    • Updated platform examples to document registry-pinned build configurations.

@coderabbitai

coderabbitai Bot commented Sep 27, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

Warning

Review limit reached

Next included review available in 50 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: Repository: FastLED/fbuild/.coderabbit.yaml

Review profile: CHILL

Plan: Advanced

Run ID: 16a421e0-f3d4-44d1-927f-7e3d091ca2d9

📥 Commits

Reviewing files that changed from the base of the PR and between eb95a26 and 65a1dc0.

📒 Files selected for processing (22)
  • crates/fbuild-build-engine/src/package_override.rs
  • crates/fbuild-build-engine/src/pipeline/context.rs
  • crates/fbuild-build-mcu/src/avr/mod.rs
  • crates/fbuild-build-mcu/src/avr/orchestrator.rs
  • crates/fbuild-core/tests/platformio_avr_resolution.rs
  • crates/fbuild-core/tests/platformio_package_resolution.rs
  • crates/fbuild-library/assets/avr_frameworks.json
  • crates/fbuild-library/src/library/avr_framework.rs
  • crates/fbuild-toolchain/src/toolchain/avr.rs
  • tests/platform/atmega8/README.md
  • tests/platform/atmega8/platformio.ini
  • tests/platform/attiny13/README.md
  • tests/platform/attiny1616/README.md
  • tests/platform/attiny1616/platformio.ini
  • tests/platform/attiny85/README.md
  • tests/platform/attiny85/platformio.ini
  • tests/platform/avr128da64/README.md
  • tests/platform/avr128da64/platformio.ini
  • tests/platform/nano_every/README.md
  • tests/platform/nano_every/platformio.ini
  • tests/platform/uno/README.md
  • tests/platform/uno/platformio.ini

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository: FastLED/fbuild/.coderabbit.yaml

Review profile: CHILL

Plan: Advanced

Run ID: 9bde286a-614b-45a5-af0c-1da9bb13fa38

📥 Commits

Reviewing files that changed from the base of the PR and between 8d42c38 and eb95a26.

📒 Files selected for processing (22)
  • crates/fbuild-build-engine/src/package_override.rs
  • crates/fbuild-build-engine/src/pipeline/context.rs
  • crates/fbuild-build-mcu/src/avr/mod.rs
  • crates/fbuild-build-mcu/src/avr/orchestrator.rs
  • crates/fbuild-core/tests/platformio_avr_resolution.rs
  • crates/fbuild-core/tests/platformio_package_resolution.rs
  • crates/fbuild-library/assets/avr_frameworks.json
  • crates/fbuild-library/src/library/avr_framework.rs
  • crates/fbuild-toolchain/src/toolchain/avr.rs
  • tests/platform/atmega8/README.md
  • tests/platform/atmega8/platformio.ini
  • tests/platform/attiny13/README.md
  • tests/platform/attiny1616/README.md
  • tests/platform/attiny1616/platformio.ini
  • tests/platform/attiny85/README.md
  • tests/platform/attiny85/platformio.ini
  • tests/platform/avr128da64/README.md
  • tests/platform/avr128da64/platformio.ini
  • tests/platform/nano_every/README.md
  • tests/platform/nano_every/platformio.ini
  • tests/platform/uno/README.md
  • tests/platform/uno/platformio.ini
💤 Files with no reviewable changes (1)
  • crates/fbuild-core/tests/platformio_package_resolution.rs

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

AVR and MegaAVR package provisioning now resolves registry pins for supported framework cores and the AVR toolchain. Framework metadata includes PlatformIO archive URLs and checksums. Offline resolver tests and pinned platform fixtures cover package resolution and override behavior.

Changes

AVR and MegaAVR registry package resolution

Layer / File(s) Summary
Framework archive metadata and layout
crates/fbuild-library/assets/avr_frameworks.json, crates/fbuild-library/src/library/avr_framework.rs
Framework entries can provide archive URLs, with GitHub archive URLs used when none are configured. Added mappings and checksums for additional AVR and MegaAVR frameworks. MiniCore uses layout-specific validation paths for matching PlatformIO archive overrides.
Resolve and apply AVR package pins
crates/fbuild-build-engine/src/pipeline/context.rs, crates/fbuild-build-engine/src/package_override.rs, crates/fbuild-build-mcu/src/avr/*, crates/fbuild-toolchain/src/toolchain/avr.rs, crates/fbuild-core/tests/platformio_avr_resolution.rs
Platform resolution now recognizes AVR and MegaAVR platforms and their framework package names. The asynchronous AVR resolver maps supported cores to PlatformIO package aliases, resolves registry overrides, and falls back to environment overrides and package defaults. MegaAVR megatinycore and dxcore select the newer AVR toolchain default. Tests cover mapping, resolved package payloads, URL overrides, and unavailable pins.
Pinned platform fixtures
tests/platform/{atmega8,attiny13,attiny1616,attiny85,avr128da64,nano_every,uno}/*
PlatformIO environments add pinned AVR and MegaAVR platform and framework combinations. Fixture READMEs describe the pins and recorded build-validation status.

Priority: ➖ Normal

Estimated code review effort: 3 (Moderate) | ~25 minutes

Change: Bug fix · Severity of issue fixed: Medium

Sequence Diagram(s)

sequenceDiagram
  participant AvrPlatformSupport
  participant avr_packages
  participant fbuild_core
  participant AvrToolchain
  AvrPlatformSupport->>avr_packages: pass board and environment configuration
  avr_packages->>fbuild_core: resolve platform, framework, and toolchain pins
  fbuild_core-->>avr_packages: return resolved package overrides
  avr_packages->>AvrToolchain: construct toolchain with package override
  avr_packages-->>AvrPlatformSupport: return toolchain and framework
Loading

Merge Risk: ⚪ Minimal · up to eb95a

The reviewed package pins and archive overrides retain their expected behavior. No issue identified here prevents merging after normal checks.

Security Architecture Review

Security architecture risk: 🟡 Moderate · up to eb95a

Registry pins gain exact-version and checksum handling, but project configuration can now select the AVR compiler archive as well as the framework. The build also includes requested package settings and resolved URLs in its output. The risk depends on who may supply configuration and view build logs.

Retained concerns

  • High · security · inferred: Project configuration can now select an arbitrary AVR toolchain archive without a required checksum. If a less-trusted party controls that configuration, the selected host compiler can run with the builder's authority; previously this AVR route used its default toolchain.
  • Medium · security · inferred: Requested package settings and resolved URLs now enter the returned build log without visible redaction. Credential-bearing or signed archive URLs could reach log readers beyond the people authorized to supply them; that readership is not established.
Security review details

Security Blast Radius

  • inferred — A configurable archive can affect the host compiler used for an AVR build, not just framework source files. The independently attackable scope depends on who can submit build configuration and on builder isolation; neither is established here.

Security Findings and Attack Paths

  • inferred — If an attacker can change platform_packages for a build run by a more-privileged builder, a toolchain-atmelavr URL can select an unchecked archive whose compiler is subsequently used. This is a conditional attack path, not a verified exploit.

Trust Boundaries and Controls

  • observed — Registry package selection is restricted to the AVR adapter's supported names and expected platform; direct archive overrides remain a separate, checksum-optional path. Checksums from registry metadata attest to the selected registry payload, not to an independently approved source.

Resilience and Maintainability Implications

  • observed — Install-path locking, staging cleanup and atomic commit protect individual cached packages during repeated or interrupted installation. They do not make the toolchain/framework provisioning pair transactional.

Hardening Proposals

  • proposed — For builds that accept less-trusted project configuration, require an approved source or independently pinned digest for executable toolchain archives, and review the builder's filesystem, network and credential isolation.
  • proposed — Redact URL credentials and signed query values before adding package requests or resolved URLs to returned build output; establish who may read and retain that output.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly and concisely describes the main change: honoring AVR PlatformIO registry pins for MCU builds.
Linked Issues check ✅ Passed PR #1520 addresses the coding requirements in #1494. The AVR orchestrator resolves framework and toolchain registry pins from the board core, including MiniCore, standard AVR, ATTiny, megaAVR, megaTin…
Out of Scope Changes check ✅ Passed The changed implementation, resolver tests, package metadata, toolchain regression test, and live-build fixtures support #1494. The README changes document the registry-pin fixtures and known validati…
Docstring Coverage ✅ Passed Docstring coverage is 85.29% which is sufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 34 functions across 7 files. (14 skipped: 1…
✨ Finishing Touches
📝 Generate docstrings
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@zackees
zackees merged commit cf1724e into main Sep 27, 2026
14 of 15 checks passed
@fastled-project-sync fastled-project-sync Bot moved this to Triage in FastLED Tracker Sep 28, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: Triage

Development

Successfully merging this pull request may close these issues.

fix(mcu): honor AVR framework registry package pins

1 participant