AirspyHF+
A memory-hardened Rust/nusb driver remains behind the existing C ABI. Applications keep the public call surface while ownership and asynchronous lifetime move into typed state.
AIRSPYHF+ · AIRSPY R2 / MINI · LPC4370
The host drivers and device firmware were rebuilt so capture, DMA, USB transfer, callback delivery, recovery, and shutdown are visible state transitions rather than a chain of blocking assumptions.
ONE RADIO PATH, THREE REBUILT LAYERS
A memory-hardened Rust/nusb driver remains behind the existing C ABI. Applications keep the public call surface while ownership and asynchronous lifetime move into typed state.
A readable hardened host driver presents the Airspy R2 and Mini stream without hiding transfer generations, callback state, cancellation, or device loss.
M4 capture/DMA work and M0 USB forwarding coordinate through explicit queues, recovery, telemetry, and a ten-bank SRAM capture ring tested on physical radios.
THE TEN-BANK TURN
A two-buffer design treats a late USB consumer as an emergency. Ten independently owned banks turn the same event into measurable queue depth. Capture can continue while earlier banks wait, and the firmware can report exactly which boundary is congested.
The important change is not merely “more buffers.” Each bank has one legal state, one current owner, and one generation. A completion from an earlier stream cannot silently free a bank that has already been reused by a later stream.
THE STREAM AS A STATE MACHINE
FAILURE BECOMES DATA
Transfers, samples, overruns, drops, gaps, recoveries, and queue high-water survive beyond one log line.
Late completions are distinguishable from current work after restart, retune, cancellation, or device recovery.
Shutdown wakes blocked producers and consumers into an explicit terminal state instead of depending on a timeout or spin.
The host cannot deliver into a callback context after ownership has ended.
THE VERIFICATION LADDER
Undefined behavior and invalid lifetime probes.
Interleavings across stream state and asynchronous completion.
State invariants under bounded nondeterministic paths.
Address, undefined-behavior, and thread-oriented executable checks.
Bank transitions, recovery, telemetry, and control/bulk coordination.
AirspyHF+, Airspy R2, and Mini behavior exercised against hardware.
WHAT IS PARTICULAR ABOUT THIS WORK
The HF+ rewrite can replace the host library beneath existing callers.
The Airspy One driver makes setup, streaming, callback, error, and teardown followable as ordinary code.
Bank identity, generation, counters, and recovery cross the USB boundary instead of being invented independently on each side.
The result remains a radio stream compatible with the software people already use.
THE PUBLIC OBJECT
The stack does not ask congestion, cancellation, device loss, or recovery to disappear. It gives each one a place in the protocol, and it makes every buffer prove who owns it before samples move again.
Open the hardened Airspy work ↗