SITL: NAK unknown commands in simulated TSYS01

ArduSub sets BARO_EXT_BUS 1, so AP_Baro::init probes for an MS5611 at
address 0x77 on bus 1 - where the SITL I2C bus places the simulated
TSYS01.  The MS5611 driver reads eight PROM words (commands 0xA0..0xAE)
but the simulator only understands 0xA0..0xAA; commands 0xAC and 0xAE
fell through the switch without filling the response buffer and the
transfer was reported as successful, so the driver ran its PROM CRC
check over uninitialised stack bytes.  Valgrind reports this and fails
any --valgrind autotest run; worse, roughly one boot in sixteen the
garbage passes the CRC-4 check and a phantom MS5611 barometer is
registered using TSYS01 PROM data as calibration.

Fail the transfer instead, as a real device would NAK.  The driver then
sees zeroes for words 6 and 7 and the CRC check fails deterministically,
so the MS5611 probe is always cleanly rejected.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
Peter Barker
2026-07-22 18:49:35 +10:00
committed by Andrew Tridgell
co-authored by Claude Fable 5
parent 8078d288a5
commit d2143bb46e
@@ -75,6 +75,12 @@ int SITL::TSYS01::rdwr(I2C::i2c_rdwr_ioctl_data *&data)
}
break;
}
default:
// NAK commands we do not understand. The MS5611 probe
// sends us prom reads for words 6 and 7 (0xAC and 0xAE);
// failing the transfer here ensures the response buffer
// is not returned uninitialised.
return -1;
}
return 0;
}
@@ -106,6 +112,9 @@ int SITL::TSYS01::rdwr(I2C::i2c_rdwr_ioctl_data *&data)
break;
case Command::READ_ADC:
AP_HAL::panic("bad READ_ADC");
default:
// NAK commands we do not understand
return -1;
}
return 0;
}