Zephyr 4.5.0 (Working Draft)

We are pleased to announce the release of Zephyr version 4.5.0.

Major enhancements with this release include:

Infineon TriCore support

Zephyr now supports the Infineon TriCore architecture.

New driver classes

Zephyr 4.5 adds several new driver APIs, including:

  • Clock Monitor for runtime observation of clock frequency

  • LIN for the Local Interconnect Network automotive serial bus

New subsystems

Zephyr 4.5 adds several new subsystem APIs, including:

  • Precision timing for shared checked time arithmetic, clock operations, and PI control

  • Video for controlling video drivers

An overview of the changes required or recommended when migrating your application from Zephyr v4.4.0 to Zephyr v4.5.0 can be found in the separate migration guide.

The following sections provide detailed lists of changes by component.

API Changes

Removed APIs and options

  • Architectures

    • ARM

      • CONFIG_PLATFORM_SPECIFIC_INIT

      • z_arm_platform_init()

    • RISC-V

      • CONFIG_EXTRA_EXCEPTION_INFO

    • x86

      • CONFIG_SSE

      • CONFIG_SSE_FP_MATH

    • Xtensa

      • CONFIG_XTENSA_BACKTRACE_EXCEPTION_DUMP_HOOK

  • Bluetooth

    • Controller

      • CONFIG_BT_CTRL_ADV_ADI_IN_SCAN_RSP

    • Host

      • The CONFIG_BT_RECV_CONTEXT choice and its options CONFIG_BT_RECV_WORKQ_SYS and CONFIG_BT_RECV_WORKQ_BT have been removed. The host now always processes low-priority HCI packets on the dedicated Bluetooth RX workqueue (the former CONFIG_BT_RECV_WORKQ_BT behavior). See the migration guide.

      • Selected Host work items have moved from the system workqueue to the dedicated Bluetooth RX workqueue. Application callbacks reached from those work items now run in the Bluetooth RX thread. See the migration guide for affected callback families.

      • The CONFIG_BT_HCI_RAW_H4 and CONFIG_BT_HCI_RAW_H4_ENABLE Kconfig options have been removed. They have had no effect since Zephyr 4.2, where the HCI raw layer switched to using H:4 packet encoding for all buffers unconditionally. Applications still setting these options can simply drop them.

      • CONFIG_BT_AUTO_PHY_UPDATE, replaced by the BT_AUTO_PHY_CENTRAL and BT_AUTO_PHY_PERIPHERAL choices

      • _bt_gatt_ccc

      • BT_GATT_CCC_INITIALIZER

      • CONFIG_BT_CONN_TX_MAX

      • CONFIG_BT_FIXED_PASSKEY

      • bt_passkey_set()

      • BT_PASSKEY_INVALID

    • Mesh

      • CONFIG_BT_MESH_BLOB_IO_FLASH_WITH_ERASE

      • CONFIG_BT_MESH_BLOB_IO_FLASH_WITHOUT_ERASE

    • Services

      • CONFIG_BT_DIS_MANUF

      • CONFIG_BT_DIS_MODEL

  • Boards

    • Dropped the following deprecated board aliases:

      • arduino_uno_r4_minima

      • arduino_uno_r4_wifi

      • esp32c6_devkitc

      • esp32_devkitc_wroom/esp32/procpu

      • esp32_devkitc_wroom/esp32/appcpu

      • esp32_devkitc_wrover/esp32/procpu

      • esp32_devkitc_wrover/esp32/appcpu

      • neorv32

      • panb511evb

      • raytac_an54l15q_db/nrf54l15/cpuapp

      • scobc_module1

      • xiao_esp32c6

    • The following boards have been deprecated and renamed:

      • adafruit_metro_rp2350/rp2350b/m33 to adafruit_metro_rp2350/rp2350b/m33_0

      • motion_2350_pro/rp2350a/m33 to motion_2350_pro/rp2350a/m33_0

      • motion_2350_pro/rp2350a/hazard3 to motion_2350_pro/rp2350a/hazard3_0

      • beetle_rp2350/rp2350a/m33 to beetle_rp2350/rp2350a/m33_0

      • beetle_rp2350/rp2350a/hazard3 to beetle_rp2350/rp2350a/hazard3_0

      • pico2_spe/rp2350a/m33 to pico2_spe/rp2350a/m33_0

      • pico_plus2/rp2350b/m33 to pico_plus2/rp2350b/m33_0

      • pico_plus2/rp2350b/hazard3 to pico_plus2/rp2350b/hazard3_0

      • rpi_pico2/rp2350a/m33 to rpi_pico2/rp2350a/m33_0

      • rpi_pico2/rp2350a/m33/w to rpi_pico2/rp2350a/m33_0/w

      • rpi_pico2/rp2350a/m33/mcuboot to rpi_pico2/rp2350a/m33_0/mcuboot

      • rpi_pico2/rp2350a/m33/w/mcuboot to rpi_pico2/rp2350a/m33_0/w/mcuboot

      • rpi_pico2/rp2350a/hazard3 to rpi_pico2/rp2350a/hazard3_0

      • xiao_rp2350/rp2350a/m33 to xiao_rp2350/rp2350a/m33_0

      • xiao_rp2350/rp2350a/hazard3 to xiao_rp2350/rp2350a/hazard3_0

      • rp2350_zero/rp2350a/m33 to rp2350_zero/rp2350a/m33_0

      • rp2350_zero/rp2350a/hazard3 to rp2350_zero/rp2350a/hazard3_0

      • rp2350b_core/rp2350b/m33 to rp2350b_core/rp2350b/m33_0

      • rp2350b_core/rp2350b/hazard3 to rp2350b_core/rp2350b/hazard3_0

      • w5500_evb_pico2/rp2350a/m33 to w5500_evb_pico2/rp2350a/m33_0

      • w6100_evb_pico2/rp2350a/m33 to w6100_evb_pico2/rp2350a/m33_0

      • w6300_evb_pico2/rp2350a/m33 to w6300_evb_pico2/rp2350a/m33_0

  • Build system

    • CONFIG_BUILD_NO_GAP_FILL

    • cmake/app/boilerplate.cmake

    • Board revision Kconfig fragments named <board>_<revision>.conf, replaced by <board>_<revision>_defconfig

    • Pattern expansion in zephyr_code_relocate(FILES ...), replaced by file(GLOB ...)

    • The CMake flash, debug, debugserver, attach and rtt targets, replaced by the corresponding west commands

    • The WEST_DIR build system variable

    • The ZephyrUnittest CMake package, replaced by find_package(Zephyr COMPONENTS unittest)

  • CAN

    • bus-speed

    • bus-speed-data

  • Comparator

    • nxp,enable-output-pin, nxp,use-unfiltered-output, nxp,high-speed-mode, nxp,enable-sample, nxp,filter-count, nxp,filter-period and nxp,window-mode properties of nxp,kinetis-acmp

  • Counter

    • CONFIG_COUNTER_MAXIM_DS3231

    • prescaler property of nxp,lptmr

  • hawkBit

    • <zephyr/mgmt/hawkbit.h>

  • Devicetree

    • zephyr,memory-region-mpu

  • Ethernet

  • Debug

    • The experimental CONFIG_ASSERT_CUSTOM_HEADER option and its zephyr_custom_assert.h include hook have been removed without a deprecation period, per the experimental API policy. Applications that need to customize assertion handling should override the weak zassert hooks (zassert_fail/zassert_vprint/zassert_post_action) instead.

  • LLEXT

    • llext_get_fn_table, replaced by llext_get_fn_table_entry

  • Mbed TLS

    • CONFIG_MBEDTLS_MD

    • CONFIG_MBEDTLS_LMS

    • CONFIG_MBEDTLS_TLS_VERSION_1_2

    • CONFIG_MBEDTLS_DTLS

    • CONFIG_MBEDTLS_TLS_VERSION_1_3

    • CONFIG_MBEDTLS_TLS_SESSION_TICKETS

    • CONFIG_MBEDTLS_CTR_DRBG_ENABLED

    • CONFIG_MBEDTLS_HMAC_DRBG_ENABLED

  • MCUboot

  • MCUmgr

    • CONFIG_MCUMGR_GRP_OS_INFO_HARDWARE_INFO_SHORT_HARDWARE_PLATFORM

  • Networking

    • CONFIG_NET_TC_SKIP_FOR_HIGH_PRIO

    • CONFIG_NET_SOCKETS_POLL_MAX

    • CONFIG_NET_TEST_PROTOCOL, together with the samples/net/sockets/tcp sample that was its only system under test.

    • CONFIG_NET_GPTP_CLOCK_ACCURACY_*

    • net_ipv6_set_hop_limit()

    • net_if_ipv4_get_netmask()

    • net_if_ipv4_set_netmask()

    • net_if_ipv4_set_netmask_by_index()

    • openthread_state_changed_cb_register()

    • openthread_state_changed_cb_unregister()

    • openthread_start()

    • openthread_api_mutex_lock()

    • openthread_api_mutex_try_lock()

    • openthread_api_mutex_unlock()

    • struct openthread_state_changed_cb

    • TLS_CREDENTIAL_SERVER_CERTIFICATE

    • start_11r_roaming

    • IEEE802154_HW_SLEEP_TO_TX

  • Nordic

  • POSIX

    • CONFIG_POSIX_READER_WRITER_LOCKS

  • Random

    • CONFIG_CTR_DRBG_CSPRNG_GENERATOR

    • CONFIG_CS_CTR_DRBG_PERSONALIZATION

  • Shell

    • kernel log_level, replaced by log enable

  • SPI

  • Stream Flash

    • stream_flash_erase_page()

  • Tracing

    • The _track_list_k_* object tracking list heads, SYS_PORT_TRACK_NEXT() and include/zephyr/tracing/tracking.h. Object tracking now enumerates objects through the object core framework.

  • ZTest

    • CONFIG_ZTEST_SHUFFLE_SUITE_REPEAT_COUNT

    • CONFIG_ZTEST_SHUFFLE_TEST_REPEAT_COUNT

  • West sign support for imgtool, which was deprecated in Zephyr 4.0, has been removed.

  • The scripts/logging/dictionary/log_parser_uart.py dictionary logging script, which was deprecated in Zephyr 4.3, has been removed. Use scripts/logging/dictionary/live_log_parser.py instead.

  • The --skip-rebuild option of west flash, west debug and the other commands that invoke a runner, which was deprecated in Zephyr 4.3, has been removed. Use --no-rebuild instead.

Deprecated APIs and options

New APIs and options

New Boards

New Shields

New Drivers

New Samples

Libraries / Subsystems

  • Crypto

    • Added AES CFB and OFB cipher mode support.

  • Mbed TLS

    • Mbed TLS was updated to version 4.1.1. Release notes can be found here.

    • TF-PSA-Crypto was updated to version 1.1.1. Release notes can be found here.

    • Added CONFIG_TF_PSA_CRYPTO_DISPATCH_DIR, which enables TF-PSA-Crypto to use custom implementations of crypto operation dispatch. This makes hardware acceleration of cryptographic operations possible by using an accelerator-aware dispatch implementation.

  • TF-M

  • DFU

  • Management

    • Added the Firmware Over-the-Air over HTTP library, a firmware-over-the-air client that downloads an MCUboot image over HTTP or HTTPS straight into the secondary slot, with optional resume, redirect following, SHA-256 verification and a fota shell command.

  • LoRa / LoRaWAN

  • Networking

    • Added tracking of local ports bound through offloaded sockets (CONFIG_NET_SOCKETS_OFFLOAD_PORT_TRACKING). Offloaded sockets bind in the offload engine, outside the net_context layer, so net_context_port_in_use() could not see them. The socket layer now tracks those bindings and provides net_socket_port_in_use() to check both native and offloaded ports. mDNS probe port selection and DNS-SD service checks use this new function.

  • Management

    • MCUmgr

  • Networking

    • CoAP

      • The CoAP server accepts an observe registration that carries an empty token, which RFC 7641 allows, and keys the observer on the endpoint and that empty token.

  • Secure Storage

    • The psa_its_get*() functions now return PSA_ERROR_INVALID_SIGNATURE or PSA_ERROR_DATA_CORRUPT for an entry that fails authentication or is malformed, instead of PSA_ERROR_GENERIC_ERROR.

    • The ITS operations that modify an entry are now serialized, and discarding an entry that cannot be read back is logged as a warning.

    • psa_its_get() called with a data_size of 0 now reports whether the entry exists and is valid instead of always returning PSA_SUCCESS.

  • Multimedia Pipeline

    • Introducing Multimedia Pipeline (mpipe), a new subsystem for building multimedia applications out of reusable elements - sources, transforms and sinks - linked together into a pipeline. It lets an application describe the media flow it wants instead of driving each audio, video or display device itself.

  • Video

    • Introducing a video subsystem that inherits all the function names previously in video drivers.

  • Zbus

  • __assert

    • __ASSERT_ON define has been removed.

Devicetree

Other notable changes

  • ADC

    • STM32 ADC driver (st,stm32-adc): when CONFIG_ADC_STM32_VREFINT_CALIBRATE is enabled, adc_ref_internal() may return a measured scale instead of DT vref-mv. Any ADC named by an st,stm32-vref io-channels property can take that measurement; the result is cached SoC-wide. See the migration guide ADC section.

    • STM32G4 SoC dtsi files now describe the extra VREFINT inputs that exist in silicon: st,stm32-vref vref3 (ADC3, G491 and up), vref4 and vref5 (ADC4/ADC5, G473 and up). Nodes stay disabled; boards enable the instance they use. ADC2 has no VREFINT mux.

  • Bluetooth

    • CONFIG_SYSTEM_WORKQUEUE_PRIORITY is no longer forced to a cooperative priority by CONFIG_BT alone. Only the components that submit work to the system workqueue require it now, so a build without any of them, such as an HCI raw image driving an external controller, can select a preemptible priority again (GitHub #119123).

  • Build system

    • The minimum required CMake version has been raised to 3.28.0, a version satisfied by the CMake package in the Ubuntu 24.04 LTS package repositories. See the migration guide for options if your distribution ships an older version.

    • The hardening tool (west build -t hardenconfig) now sources its recommendations from a schema-validated YAML database instead of a CSV file: profiles in scripts/kconfig/hardening.yaml and per-subsystem hardening.yaml fragments living next to the Kconfig files they relate to. Every recommendation now carries a rationale, displayed in the report, and may reference CWE/CVE entries; recommendations are grouped into profiles (base and strict, selectable with -DHARDENCONFIG_PROFILE=); integer recommendations can express minimum/maximum constraints; JSON output and a failing exit code are available for CI use; and out-of-tree databases can be layered with -DHARDENCONFIG_EXTRA_SOURCES=. The database is validated in CI against the actual Kconfig tree so entries can no longer go stale.

  • Kernel

    • The object core framework no longer keeps registry state inside the objects it tracks. Statically defined objects are enumerated in place and objects initialized at run time are referenced from a bounded registry, so a kernel object may be declared on a stack, embedded in freed memory or initialized again without corrupting the registry. Objects in stack storage are not tracked.

    • CONFIG_SCHED_CPU_MASK no longer depends on CONFIG_SCHED_SIMPLE. CPU affinity masks are now supported on all three scheduler backends: SCHED_SIMPLE (O(N) list scan), SCHED_SCALABLE (O(N) red/black tree walk), and SCHED_MULTIQ (O(P·N) per-priority bucket scan). See the updated SMP documentation for per-backend performance notes.

    • CONFIG_SCHED_CPU_MASK_PIN_ONLY now enforces the one-CPU-bit invariant at both the API boundary (cpu_mask_mod()) and at queue time (thread_runq()). Calling k_thread_cpu_mask_clear(), k_thread_cpu_mask_enable_all(), or k_thread_cpu_mask_disable() in PIN_ONLY mode triggers an assertion failure. Use k_thread_cpu_pin() to reassign a thread to a different CPU.

  • Timer

    • With CONFIG_SYSTEM_CLOCK_SLOPPY_IDLE enabled, a driver may no longer stop its time base as soon as no timeout is pending, if that breaks sys_clock_cycle_get_32() / sys_clock_cycle_get_64(). Those must keep counting while the CPU runs. Stopping the time base is permitted only from sys_clock_idle_enter(), where sys_clock_idle_exit() is guaranteed to follow.

    • Tickless system-timer drivers can now be built on a shared implementation header, drivers/timer/system_timer_generic.h, which owns the tick accounting each driver previously open-coded: the cycle-to-tick conversion, the announce baseline, the tick-aligned deadline and the counter wrap and range handling. A driver reduces to a few cycle-domain primitives, a cycle-counter read plus an absolute-compare arm. See the migration guide for how to use it (GitHub #115844).

  • Networking

    • The DHCPv4 client now takes the leased address, the lease’s DNS servers and the gateway it installed off the interface on every path that gives a lease up, and waits about ten seconds before restarting after a refused request or a declined address.

  • Wi-Fi

    • Removed the samples/net/wifi/test_certs/rsa2k enterprise test certificates (DES-encrypted private keys). Use rsa2k_no_des instead.

    • The connection result event can now say that the access point rejected the authentication or the association, through the new WIFI_STATUS_CONN_AUTH_REJECT and WIFI_STATUS_CONN_ASSOC_REJECT values, and wifi_status carries the raw IEEE 802.11 status and reason codes behind the failure. The supplicant fills these in, and the Wi-Fi shell prints them with the connection and disconnection results. (GitHub #116704)

    • The ESP32 Wi-Fi driver gained 802.11k/v/r and MBO support, all off by default. CONFIG_ESP32_WIFI_11KV_SUPPORT turns on 802.11k and 802.11v, CONFIG_ESP32_WIFI_MBO_SUPPORT turns on MBO on top of them, and CONFIG_ESP32_WIFI_11R_SUPPORT turns on 802.11r. The wifi 11k and wifi 11v_btm_query shell commands now work on ESP32 while the station is associated, and CONFIG_ESP32_WIFI_SIGNAL_CHANGE_EVENT raises NET_EVENT_WIFI_SIGNAL_CHANGE when the signal of the connected access point weakens, for an application that decides when to roam.

    • The transmit power ceiling properties in wifi-tx-power-2g.yaml and wifi-tx-power-5g.yaml are no longer required and now carry conservative defaults, so a board that has not been characterised errs on the side of transmitting too little rather than exceeding a regulatory limit. Boards that have measured their own limits continue to state them explicitly, so no board changes behaviour.

    • P2P gained shell commands to set the local device name and to query the current P2P status, backed by the new WIFI_P2P_SET_DEV_NAME and WIFI_P2P_STATUS wifi_p2p_op operations. The corresponding device_name and status members were added to wifi_p2p_params, along with the new WIFI_P2P_STATUS_BUF_SIZE buffer-size macro.

  • MCUboot

    • SB_CONFIG_BOOT_SIGNATURE_KEY_FILE now accepts a comma-separated list of key files, embedding the public half of each in the MCUboot bootloader. When more than one key is given, MCUboot accepts an image signed with any of them – the typical use is a development bootloader that boots both development- and production-signed images, while production bootloaders embed only the production key. The first entry is the key the application is signed with and the rest are verification-only public keys. See Signing Binaries.

    • Espressif boards no longer force overwrite-only mode and unsigned images under sysbuild. They now build a swap-using-offset MCUboot with rollback and an RSA-2048 signed application, and the shared Espressif partition tables no longer reserve a scratch partition. See the migration guide.

  • NXP

    • The NXP LPC DTSI files have been reorganized from the flat dts/arm/nxp/lpc/ directory into per-series subdirectories (lpc11u6x/, lpc51u68/, lpc54xxx/, lpc55xxx/, lpc84x/). See the migration guide for how to update out-of-tree board includes.

    • The NXP Kinetis DTSI files have been reorganized from the flat dts/arm/nxp/kinetis/ directory into per-series subdirectories (k2x/, k32lx/, k6x/, k8x/, ke1xf/, ke1xz/, kl2x/, kv5x/, kwx/). See the migration guide for how to update out-of-tree board includes.

    • The NXP MCX DTSI files have been reorganized from the flat dts/arm/nxp/mcx/ directory into per-series subdirectories (mcxa/, mcxc/, mcxe/, mcxl/, mcxn/, mcxw/). See the migration guide for how to update out-of-tree board includes.

    • The NXP i.MX RT DTSI files have been reorganized from the flat dts/arm/nxp/imxrt/ directory into per-series subdirectories (imxrt10xx/, imxrt11xx/, imxrt5xx/, imxrt6xx/, imxrt7xx/, imxrt118x/). See the migration guide for how to update out-of-tree board includes.

  • Arm

    • The non-secure variant of

      Arm Musca-S1 (v2m_musca_s1/musca_s1/ns) has been removed due to TF-M removing platform support for this board.

    • As a consequence of the above, the secure variant of Arm Musca-S1 (v2m_musca_s1) has been deprecated. This is to avoid a confusing state of partial support.

Trusted Firmware-A

  • CONFIG_TFA_BUILD_FIP is introduced to configure FIP (Firmware Image Package) generation. FIP generation is by default disabled, but can be enabled by setting CONFIG_TFA_BUILD_FIP=y in prj.conf or for custom boards, in the board’s <board>_defconfig file.