The guard here contradicted the comment above it, which allows a send if
either the transmit buffer is empty or the frame fits in it. Testing
!tx_pending() instead of tx_pending() inverted that: a frame was dropped
when the buffer was empty but too small, and sent unconditionally
whenever a transmit was already pending.
Writes do not block, so sending unconditionally with insufficient space
wrote as much of the frame as would fit and discarded the rest, putting
a truncated frame on the wire. The write return values were ignored, so
the caller was told the whole frame had been sent.
The empty-buffer case exists upstream only because a blocking write
could push out a frame bigger than the buffer. ArduPilot has no blocking
writes, so require the frame to fit and drop it otherwise.