Rtosmap
FreeNot checkedStatically map task structures, stack usage, and ISR call graphs in FreeRTOS/Zephyr firmware to flag stack overflows and priority-inversion risks.
About
Statically map task structures, stack usage, and ISR call graphs in FreeRTOS/Zephyr firmware to flag stack overflows and priority-inversion risks.
README
RTOSMAP
Statically map task structures, stack usage, and ISR call graphs in FreeRTOS/Zephyr firmware to flag stack overflows and priority-inversion risks.
PyPI CI License: COCL 1.0 Suite
IoT / OT / Embedded — firmware, buses, and device security.
pip install cognis-rtosmap
rtosmap scan . # → prioritized findings in seconds
🔎 Example output
Real, reproducible output from the tool — runs offline:
$ rtosmap-emit --version
rtosmap 1.6.1
$ rtosmap-emit --help
usage: rtosmap [-h] [--version] {check} ...
Map RTOS task stacks and flag stack-overflow risks from a stack map file.
positional arguments:
{check}
check analyze a stack map file and report risky tasks
options:
-h, --help show this help message and exit
--version show program's version number and exit
map format per line: <name> <stack_size> <peak_used> [priority]
sizes accept K/KB suffix (e.g. 4K). '#' starts a comment.
example: rtosmap check tasks.map --format json --warn 70 --fail 85
Blocks above are real
rtosmapoutput — reproduce them from a clone.
Sample result format (illustrative values — run on your own data for real findings):
{
"feed_name": "My Awesome Feed",
"spec_version": "2.0",
"id": "rtosmap-emit-2023-02-15T14:30:00Z",
"type": "indicator",
"created_by_ref": "my_cognito_id",
"modified_by_ref": "my_cognito_id",
"created": "2023-02-15T14:30:00Z",
"modified": "2023-02-15T14:30:00Z",
"name": "My Awesome Indicator",
"description": "This is a test indicator.",
"labels": ["test", "rtosmap"],
"observed_data": {
"network_traffic": [
{
"protocol": "tcp",
"src_port": 1234,
"dst_port": 5678,
"src_ip": "192.168.1.100",
"dst_ip": "8.8.8.8"
}
]
},
"indicators": [
{
"type": "domain_name",
"value": "example.com"
},
{
"type": "ip_address",
"value": "192.168.1.100"
}
]
}
Usage — step by step
Install (Python 3.9+):
pip install rtosmap # or: pipx install rtosmapCheck a stack map. Point
checkat your RTOS stack map file (or-for stdin) to report risky tasks:rtosmap check stackmap.txtTune the thresholds. Adjust the used-percentage at which a task is flagged WARNING (
--warn, default 80) or CRITICAL (--fail, default 90):rtosmap check stackmap.txt --warn 70 --fail 85 --format json > stack.jsonThree output formats are available via
--format:table(default, human-readable),json(stable contract for scripts/agents), andsarif(SARIF 2.1.0 for GitHub code-scanning — see below).Read the result. The report ranks each task by stack used%, marking WARNING/CRITICAL tiers. In JSON mode, parse the per-task findings; the process exits non-zero on CRITICAL findings.
Gate in CI. Use
--strictto also fail on WARNING-level findings:rtosmap check stackmap.txt --strict
Contents
- Why rtosmap? · Features · Quick start · Example · Demos · SARIF · Architecture · AI stack · How it compares · Integrations · Install anywhere · Related · Contributing
Why rtosmap?
Embedded devs love free static analysis they can drop in PRs — 'this task overflows its stack under load' caught pre-merge. Niche but rabidly loyal embedded GitHub crowd.
rtosmap is single-purpose, scriptable, and self-hostable: point it at a target, get prioritized results in the format your workflow already speaks (table · JSON · SARIF), gate CI on it, and let agents drive it over MCP.
Features
- ✅ Parse Map — FreeRTOS / Zephyr / ThreadX stack maps, K/KB/KiB units
- ✅ Analyze — overflow, critical/low headroom, invalid size, unverified
- ✅ Analyze Text — parse + analyze a stack-map string in one call
- ✅ Three outputs —
table·json· SARIF 2.1.0 (--format sarif) - ✅ Tunable gate —
--warn/--failthresholds +--strictfor CI - ✅ Runs on Linux/macOS/Windows · Docker · devcontainer
- ✅ Ports in Python, JavaScript, Go, and Rust (
ports/)
Quick start
pip install cognis-rtosmap
rtosmap --version
rtosmap scan . # scan current project
rtosmap scan . --format json # machine-readable
rtosmap scan . --fail-on high # CI gate (non-zero exit)
Example
$ rtosmap scan .
[HIGH ] RTO-001 example finding (./src/app.py)
[MEDIUM ] RTO-002 another signal (./config.yaml)
2 findings · risk score 5 · 38ms
Demos — real-world scenarios
Each folder under demos/ has a stack map in rtosmap's real input
format plus a SCENARIO.md explaining where the data came from, what to
expect, the exact command, and how to act. Every demo is exercised by the
test suite, so they always run.
| Demo | RTOS / target | Shows |
|---|---|---|
| 01-basic | FreeRTOS | overflow + low headroom + unverified, default thresholds |
| 02-zephyr-thread-analyzer | Zephyr (nRF5340 BLE) | converting CONFIG_THREAD_ANALYZER output; BLE-controller stacks at risk |
| 03-esp32-wifi-ble-coex | ESP-IDF (ESP32-S3) | tuned --warn 75 --fail 90 for a hot coexistence build |
| 04-clean-baseline-ci | STM32 FreeRTOS | a known-good map that passes --strict (exit 0) as a CI guard |
| 05-safety-critical-tight | IEC 62304 Class C | 50%-headroom policy surfacing overflow, invalid size, and unverified tasks |
| 06-stdin-pipeline | Azure RTOS / ThreadX | pipe a live on-target capture in over stdin (check -) |
| 07-sarif-code-scanning | FreeRTOS (smart meter) | --format sarif → GitHub code-scanning annotations |
| 08-json-triage-jq | FreeRTOS (industrial gateway) | mixed K/KB/KiB units + JSON/jq agent triage |
python -m rtosmap check demos/02-zephyr-thread-analyzer/threads.map
SARIF for GitHub code-scanning
rtosmap check --format sarif emits a SARIF 2.1.0 log. Each outcome maps
to a stable rule id (RTOS-OVERFLOW, RTOS-HEADROOM-CRITICAL,
RTOS-HEADROOM-LOW, RTOS-INVALID-SIZE, RTOS-UNVERIFIED) so code-scanning
can track and suppress findings across runs.
# .github/workflows/firmware.yml
- name: rtosmap stack scan
run: python -m rtosmap check fw/stack.map --format sarif > rtosmap.sarif
continue-on-error: true
- uses: github/codeql-action/upload-sarif@v3
with:
sarif_file: rtosmap.sarif
Stack-overflow and low-headroom findings then show up as annotations on the PR's changed files. See demos/07-sarif-code-scanning.
Architecture
flowchart LR
IN[input] --> P[rtosmap<br/>analyze + score]
P --> OUT[report]
Use it from any AI stack
rtosmap is interoperable with every popular way of using AI:
- MCP server —
rtosmap mcp(Claude Desktop, Cursor, Cognis.Studio, uncensored-fleet) - OpenAI-compatible / JSON — pipe
rtosmap scan . --format jsoninto any agent or LLM - LangChain · CrewAI · AutoGen · LlamaIndex — wrap the CLI/JSON as a tool in one line
- CI / scripts — exit codes + SARIF for non-AI pipelines
How it compares
| Cognis rtosmap | Ghidra scripting + percepio Tracealyzer | |
|---|---|---|
| Self-hostable, no account | ✅ | varies |
| Single command, zero config | ✅ | ⚠️ |
| JSON + SARIF for CI | ✅ | varies |
| MCP-native (AI agents) | ✅ | ❌ |
| Polyglot ports (JS/Go/Rust) | ✅ | ❌ |
| Open license | ✅ COCL | varies |
Built in the spirit of Ghidra scripting + percepio Tracealyzer, re-framed the Cognis way. Missing a credit? Open a PR.
Integrations
Pipes into your stack: SARIF for code-scanning, JSON for anything, an MCP server (rtosmap mcp) for AI agents, and a webhook forwarder for SIEM/Slack/Jira. See docs/INTEGRATIONS.md.
Install — every way, every platform
pip install "git+https://github.com/cognis-digital/rtosmap.git" # pip (works today)
pipx install "git+https://github.com/cognis-digital/rtosmap.git" # isolated CLI
uv tool install "git+https://github.com/cognis-digital/rtosmap.git" # uv
pip install cognis-rtosmap # PyPI (when published)
docker run --rm ghcr.io/cognis-digital/rtosmap:latest --help # Docker
brew install cognis-digital/tap/rtosmap # Homebrew tap
curl -fsSL https://raw.githubusercontent.com/cognis-digital/rtosmap/main/install.sh | sh
| Linux | macOS | Windows | Docker | Cloud |
|---|---|---|---|---|
scripts/setup-linux.sh |
scripts/setup-macos.sh |
scripts/setup-windows.ps1 |
docker run ghcr.io/cognis-digital/rtosmap |
DEPLOY.md (AWS/Azure/GCP/k8s) |
Related Cognis tools
- fwxray — Diff two firmware images and surface exactly what changed: new binaries, flipped config flags, added certs, and shifted entropy regions.
- canzap — Replay, fuzz, and assert on CAN bus traffic from a .pcap or SocketCAN interface with a tiny YAML DSL.
- sbomb — Generate a CycloneDX SBOM directly from an unpacked firmware root filesystem and flag components with known CVEs and EOL kernels.
- mqttspy — Passively map an MQTT broker: enumerate topics, detect unauthenticated writes, spot PII/secrets in payloads, and emit a risk report.
- uefiscan — Audit UEFI firmware dumps for missing Secure Boot keys, unsigned modules, S3 boot-script vulns, and known SMM threats.
- modpot — Spin up a high-interaction Modbus/DNP3 ICS honeypot that logs attacker register reads/writes as structured JSON.
Explore the suite → 🗂️ all 170+ tools · ⭐ awesome-cognis · 🔗 cognis-sources · 🤖 uncensored-fleet · 🧠 engram
Contributing
PRs, new rules, and demo scenarios are welcome under the collaboration-pull model — see CONTRIBUTING.md and SECURITY.md.
⭐ If
rtosmapsaved you time, star it — it genuinely helps others find it.
Interoperability
{} composes with the 300+ tool Cognis suite — JSON in/out and a shared
OpenAI-compatible /v1 backbone. See INTEROP.md for the
suite map, composition patterns, and reference stacks.
License
Source-available under the Cognis Open Collaboration License (COCL) v1.0 — free for personal, internal-evaluation, research, and educational use; commercial / production use requires a license ([email protected]). See LICENSE.
Installing Rtosmap
This server has no published package — it is built from source. Open the repository and follow its README.
▸ github.com/cognis-digital/rtosmapFAQ
Is Rtosmap MCP free?
Yes, Rtosmap MCP is free — one-click install via Unyly at no cost.
Does Rtosmap need an API key?
No, Rtosmap runs without API keys or environment variables.
Is Rtosmap hosted or self-hosted?
Self-hosted: the server runs locally on your machine via the install command above.
How do I install Rtosmap in Claude Desktop, Claude Code or Cursor?
Open Rtosmap on unyly.org, pick your client tab (Claude Desktop, Claude Code, Cursor) and press Install — the config is generated automatically, no JSON editing.
Related MCPs
Notion
Read and write pages in your workspace
by NotionLinear
Issues, cycles, triage — from Claude
by LinearGoogle Drive
Search and read your Drive files
by Googlemindsdb/mindsdb
Connect and unify data across various platforms and databases with [MindsDB as a single MCP server](https://docs.mindsdb.com/mcp/overview).
by mindsdbfulcradynamics/fulcra-context-mcp
MCP server for accessing personal health and biometric data including sleep stages, heart rate, HRV, glucose, workouts, calendar, and location via the Fulcra Li
by fulcradynamicsaymericzip/intlayer
A MCP Server that enhance your IDE with AI-powered assistance for Intlayer i18n / CMS tool: smart CLI access, access to the docs.
by aymericziprinadelph/Agent-MCP
A framework for creating multi-agent systems using MCP for coordinated AI collaboration, featuring task management, shared context, and RAG capabilities.
by rinadelphWhenLabs-org/when
Developer toolkit: auto-detect stack for AI context files, catch port conflicts, validate .env schemas, spot docs drift, audit dependency licenses, and time cod
by WhenLabs-orgBeltran12138/wecom-docs-mcp-server
WeCom (Enterprise WeChat) document operations via MCP: create, read, and edit Docs and Smartsheets (9 tools). Fills the doc-CRUD gap — existing WeCom MCP server
by Beltran12138madbonez/caldav-mcp
Universal MCP server for CalDAV protocol integration. Works with any CalDAV-compatible calendar server including Yandex Calendar, Google Calendar (via CalDAV),
by madbonezCompare Rtosmap with
Not sure what to pick?
Find your stack in 60 seconds
Author?
Embed badge for your README
Browse similar
All productivity MCPs
