AIRSPYHF+ · AIRSPY R2 / MINI · LPC4370

Every sample buffer
has an owner.

The host drivers and device firmware were rebuilt so capture, DMA, USB transfer, callback delivery, recovery, and shutdown are visible state transitions rather than a chain of blocking assumptions.

ONE RADIO PATH, THREE REBUILT LAYERS

Compatibility outside. Explicit machinery inside.

HOST / RUST

AirspyHF+

A memory-hardened Rust/nusb driver remains behind the existing C ABI. Applications keep the public call surface while ownership and asynchronous lifetime move into typed state.

HOST / C++

Airspy One

A readable hardened host driver presents the Airspy R2 and Mini stream without hiding transfer generations, callback state, cancellation, or device loss.

DEVICE / LPC4370

Capture firmware

M4 capture/DMA work and M0 USB forwarding coordinate through explicit queues, recovery, telemetry, and a ten-bank SRAM capture ring tested on physical radios.

THE TEN-BANK TURN

Unused SRAM became time the radio could spend surviving congestion.

0FREE
1DMA
2READY
3USB
4FREE
5FREE
6FREE
7FREE
8FREE
9FREE

A two-buffer design treats a late USB consumer as an emergency. Ten independently owned banks turn the same event into measurable queue depth. Capture can continue while earlier banks wait, and the firmware can report exactly which boundary is congested.

The important change is not merely “more buffers.” Each bank has one legal state, one current owner, and one generation. A completion from an earlier stream cannot silently free a bank that has already been reused by a later stream.

THE STREAM AS A STATE MACHINE

Acquire. Publish. Transfer. Return.

  1. 01ADC fills a bankDMA owns the bank until hardware completion names the exact generation.
  2. 02Firmware publishes readinessThe bank enters the ready queue once; queue high-water and overrun counters remain observable.
  3. 03USB takes ownershipThe M0 side forwards a named bank rather than reading whatever memory happens to be current.
  4. 04Host transfer completesThe driver delivers samples to the callback under a stream generation and bounded cancellation law.
  5. 05Bank returns freeOnly the matching completion may release it. Stop, reset, loss, and recovery terminate or advance the generation.

FAILURE BECOMES DATA

A radio can say why continuity broke.

Absolute counters

Transfers, samples, overruns, drops, gaps, recoveries, and queue high-water survive beyond one log line.

Generations

Late completions are distinguishable from current work after restart, retune, cancellation, or device recovery.

Closed queues

Shutdown wakes blocked producers and consumers into an explicit terminal state instead of depending on a timeout or spin.

Callback lifetime

The host cannot deliver into a callback context after ownership has ended.

THE VERIFICATION LADDER

The same ownership law was attacked at every scale.

RUST MEMORY MODELMiri

Undefined behavior and invalid lifetime probes.

CONCURRENCY MODELLoom

Interleavings across stream state and asynchronous completion.

BOUNDED PROOFKani

State invariants under bounded nondeterministic paths.

NATIVE HOSTSanitizers

Address, undefined-behavior, and thread-oriented executable checks.

FIRMWARE MODELQueue tests

Bank transitions, recovery, telemetry, and control/bulk coordination.

PHYSICAL ENDPOINTReal radios

AirspyHF+, Airspy R2, and Mini behavior exercised against hardware.

WHAT IS PARTICULAR ABOUT THIS WORK

It improves a radio without requiring the radio ecosystem to move first.

Same ABI

The HF+ rewrite can replace the host library beneath existing callers.

Readable host path

The Airspy One driver makes setup, streaming, callback, error, and teardown followable as ordinary code.

Firmware and host agree

Bank identity, generation, counters, and recovery cross the USB boundary instead of being invented independently on each side.

Ordinary samples leave

The result remains a radio stream compatible with the software people already use.

THE PUBLIC OBJECT

A fast stream becomes an accountable stream.

The stack does not ask congestion, cancellation, device loss, or recovery to disappear. It gives each one a place in the protocol, and it makes every buffer prove who owns it before samples move again.

Open the hardened Airspy work ↗