Commit Graph
73949 Commits
Author SHA1 Message Date
Thomas Watson d317bfaf2e AP_NavEKF3: mark covariance matrix mutation in PosVelFusion
Change the mutations to use `Pmut` and change the define to keep the
non-mutations from accidentally mutating.

All these mutations only touched the diagonals, so no risk of them
having broken symmetry.
2026-09-22 11:56:43 +10:00
Thomas Watson 2125137117 AP_NavEKF3: pin P references in non-writing files to const
Change their define so they don't use the mutable original, only the
name through a const-cast pointer. There are no writes to the covariance
matrix in these files, so nothing else needs changing.
2026-09-22 11:56:43 +10:00
Thomas Watson c114fb1254 AP_NavEKF3: name covariance matrix as mutable
In preparation for changing the regular `P` name to const, in
preparation for auditing the code so that writes to the matrix keep its
necessary numeric properties.

Sadly there is not a better way than a per-file `#define` to make the
switch. Making `P` a reference to `Pmut` substantially changes the
compiler output. Defining `P` in the header file conflicts with other
includes. Doing the rename at the top of each file allows each file to
be fixed independently.
2026-09-22 11:56:43 +10:00
Thomas Watson af0282d4ef AP_NavEKF: make stack frame size check specific to ChibiOS
It is the only HAL that sets `-Wframe-larger-than` so it is the only one
where the limit needs modification to fit the EKF.

ChibiOS additionally does not use Clang, so that check can be dropped.
2026-09-22 11:56:43 +10:00
Peter Barker 8f21583d17 autotest: seed the packet loss in MAVFTPGapReadMAVProxy
Unseeded, MAVProxy draws the lost packets from fresh entropy on every run,
so a failure could not be reproduced. A fixed seed loses the same packets
each time; it still leaves gaps to fill.
2026-09-22 11:10:46 +10:00
Peter Barker fb21a79dee autotest: widen what the FTP listing tests ask for
The listing tests only ever listed a directory they had just made, so the
paths they used were all of one shape. The bug where listing the root
dropped every file lived through all of them because no test named the
root, which is the first thing a file browser asks for.

Cover the shapes a client actually sends: a directory with nothing in it,
and "." for the directory the vehicle was started in.

The long-name test also only listed without times, where the boundary of
what fits a packet sits eleven bytes further out. Run it both ways, with
names either side of the boundary a listing with times has, so that
dropping an entry which no longer fits still cannot end the listing.
2026-09-22 11:10:46 +10:00
Peter Barker f02295ae6e autotest: run the FTP listing tests MAVProxy has caught up with
These three were skipped pending MAVProxy fixes: continuing a directory
listing from the listing's own state rather than by mutating the last
operation sent, and taking a listing entry's size from the end of the
entry. MAVProxy master now does both, so rather than skipping them
outright they ask MAVProxy whether it can do this and return early if it
cannot.
2026-09-22 11:10:46 +10:00
Peter Barker 06559fb9df autotest: check the lossy FTP listing test lists every entry
The test set 50% receive loss and then waited only for "Total size",
which a listing that gave up part-way through would still print. Wait for
the total the files actually add up to instead.

Give every file a different size while doing so: with all of them the same
the total is just a count, so a listing which lost one page and repeated
another still reached it.
2026-09-22 11:10:46 +10:00
Peter Barker 13b6dc0887 autotest: cover MAVProxy's side of FTP listing with times
MAVFTPListDirectoryWithTimeMAVProxy checks times are asked for by
default and rendered in local time, and that "ftp set list_time 0"
turns them off again. MAVFTPListDirectoryUnknownTimeMAVProxy checks a
file whose time the autopilot does not know shows as "-" rather than as
a date; its directory holds one file, because a listing is printed in
readdir order and an expect for one entry cannot sit behind another.

MAVFTPListDirectoryFallbackMAVProxy makes the timestamped replies
disappear with the module's own pkt_loss_rx and requires the plain
listing to complete once the loss is lifted - the fallback is the whole
point of the new opcode and nothing else exercises it.
MAVFTPListDirectoryLossyRetry drops half the replies and requires the
listing to finish, as it has no retransmit of its own.

MAVFTPListDirectoryWithTimeMAVProxyTabInName is the timestamped
counterpart of the existing tab test, which takes the size and the time
from the end of the entry rather than the size from the front.

That existing test now asks for a plain listing explicitly: against a
MAVProxy which knows the opcode it would otherwise get a time it is not
expecting.

All are skipped, as they need a MAVProxy which is not released yet.
2026-09-22 11:10:46 +10:00
Peter Barker fb032423eb autotest: check @MAV_LOG against what the FTP spec asks of it
The spec says a virtual directory is named with an @ prefix, that the
recipient maps it to the underlying filesystem, and that a path which is
not there is NAKed FileNotFound. Check each of those: the alias lists what
the log directory holds, a path below it resolves both with and without
the trailing slash the spec's own example carries, an unknown path below
it is NAKed FileNotFound, and a file read through the alias gives back
what was written.
2026-09-22 11:10:46 +10:00
Peter Barker d437708812 Tools: add @MAV_LOG build option
@MAV_LOG has no class of its own to find in the symbol table, so it is
detected by its prefix string, which only the backend table row puts in the
binary. That row is also only built where logs go to a filesystem, so the
option depends on Logging.
2026-09-22 11:10:46 +10:00
Peter Barker bc4a6f05a6 AP_Filesystem: add the @MAV_LOG virtual directory
MAVFTP defines @MAV_LOG as the flight-stack-independent location for log
files, so that a GCS can find them without being told where a particular
board keeps them. QGroundControl asks for it before anything else, and
falls back to guessing per-firmware paths when it is not there.

It is an alias rather than a filesystem of its own: the backend table
gains a root, and where a row carries one the resolver rewrites a path
under that prefix to sit under that directory before handing it to the
filesystem which serves it. @MAV_LOG points at the local filesystem, under
whatever directory this board logs to, following a custom log directory
the same way AP_Logger_File does.

The rewritten path has to hold the root as well as the path, so the buffer
is sized for the longest path an FTP listing stats - the longest path a
request can carry, a separator and a 255 byte name - underneath the longest
log directory a board has, and a static_assert holds boards to that. A
path too long to rewrite is refused with ENAMETOOLONG before any filesystem
sees it, rather than being truncated into the name of some other file.

That buffer is not on the stack, where every path-based call would pay for
it. It is allocated the first time an alias is used and kept, and a
semaphore is held around each backend call which uses it. rename, the one
call with two paths alive at once, allocates a second buffer for its new
path and frees it afterwards. Paths which are not aliases take neither the
semaphore nor a buffer.

An alias can't sit on LittleFS for now, and @MAV_LOG is not built where
LittleFS is the local filesystem; forcing it on is a build error. LittleFS
holds its lock from opendir() to closedir(), so the semaphore, held across
each call, would be released before that lock, which ChibiOS mutexes do not
allow, and a thread listing an alias directory would wait for the semaphore
while holding the lock another thread holding the semaphore could be
waiting for.

rename now compares the filesystems which serve its two paths rather than
their table rows, since an alias shares its filesystem with other paths,
and sets EXDEV when they differ.

A prefix now has to be the whole of a path's first component, so that
"@MAV_LOG_backup" is not served as "_backup" under the log directory. This
is not particular to the alias: "@SYSfoo" used to be served by @SYS as
"foo", and is now the local file of that name. Nothing in the tree relied
on the old behaviour.

@MAV_LOG, and the alias support with it, is only built where the logs go
to a filesystem at all.
2026-09-22 11:10:46 +10:00
Peter Barker 645c39f65b GCS_MAVLink: correct the note on the hardcoded ListDirectoryWithTime opcode
The opcode landed upstream in mavlink/mavlink#2491, so what keeps the
value hardcoded is the bundled definitions rather than anything upstream.
2026-09-22 11:10:46 +10:00
Peter Barker d21c0babed autotest: check a timed FTP listing sends a skip entry for a tab
A name containing a tab must come back from ListDirectoryWithTime as a bare
skip entry, with the names around it still listed, while a plain listing
still sends it as it is.
2026-09-22 11:10:46 +10:00
Peter Barker 0848b31ea1 GCS_MAVLink: send a skip entry for a name with a tab in a timed listing
A tab separates the fields of a listing entry, so a name containing one
cannot be represented. The MAVFTP spec (mavlink-devguide#738) has such an
entry sent as a skip entry, which keeps entry offsets consistent, and
ListDirectoryWithTime follows List Directory in this. Plain listings are
left sending the name as they always have.
2026-09-22 11:10:46 +10:00
Peter Barker 8ad4a29a6f autotest: check FTP directory entries carry a size and time
A listing with times gives a directory the same three fields as a file,
so the listing helper now picks directory entries apart the same way and
the test checks the subdirectory's size and time. The subdirectory gets a
modification time of its own so that an entry carrying some other entry's
time would be caught.
2026-09-22 11:10:46 +10:00
Peter Barker 42277bd175 GCS_MAVLink: report a size and time for directories in FTP listings
The listing format gives every entry a size, and ListDirectoryWithTime
gives every entry a time as well, with the type character the only thing
distinguishing a directory from a file. We emitted a bare "D<name>" for a
directory instead, so a client parsing the documented three fields found
only one.

A directory has no meaningful size, so it is reported as zero. Listing
with times now has to stat a directory as well; one which cannot be
stat'ed is still listed, with its time reported as unknown.

Plain ListDirectory is unchanged: it still emits the bare "D<name>" it
always has, so no existing client sees a different directory entry.

MAVSDK's server already sends these fields and its client parses them.
QGroundControl assumed a directory entry was a bare name; a fix for that
is in hand.
2026-09-22 11:10:46 +10:00
Peter Barker 3e28e00457 autotest: add a test for FTP ListDirectoryWithTime
Lists a directory of files with known sizes and modification times both
with and without times, paging through the listing by entry count as a
GCS does, and checks the entry format, that directories are still bare
D entries, and that a time the autopilot does not know comes back as
the zero the format defines rather than as the FAT epoch.

The listing helpers learn to ask for times; the directory they build
gets modification times to ask about.
2026-09-22 11:10:46 +10:00
Peter Barker 64ef7e1a1e GCS_MAVLink: report an unknown file time as zero in FTP listings
The listing format defines an mtime of zero as "the autopilot does not
know when this file was written", but no filesystem we have ever emits
it. FATFS stamps a file with the FAT epoch, 1980-01-01, when it has no
RTC to ask - and RTC_TYPES defaults to GPS only, so a vehicle which has
not had a fix stamps every file it writes that way. Confirmed on a
ZeroOneX6: every file on the card, across dozens of boots, comes back
as 1980-01-01.

Nothing at or before the FAT epoch is a real modification time, so send
the zero the format defines and let the client say it does not know.

Done here rather than in AP_Filesystem_FATFS::stat(), whose st_mtime
also reaches LOG_ENTRY.time_utc and the scripting stat() binding.
2026-09-22 11:10:46 +10:00
Julian Oes 19f99239f7 GCS_MAVLink: add support for ListDirectoryWithTime
This extends MAVLink FTP to support the new opcode that allows to list
files with modification time in UTC.

This is according to the new spec in:
https://github.com/mavlink/mavlink-devguide/pull/701

(cherry picked from commit 4bc2447cb676f36bf0d712798beacf1de69440f3)
2026-09-22 11:10:46 +10:00
Peter Barker 5c91607e1b autotest: check the exact trim AHRSTrim saves
The previous thresholds only checked the sign and a 2-degree minimum.
On the ground the pilot's total lean is limited to 10 degrees, split
across both axes by the test's diagonal stick, so the saved trim is
fully determined; check it against that value.
2026-09-22 09:30:40 +09:00
Peter Barker 5bec328c81 Copter: tidy comments and indentation of moved AHRS trimming code
Removes the comment claiming save_trim is a method on RC_Channels, moves
the auto-trim description from auto_cancel to auto_run which it
describes, and drops the extra indentation level auto_start and auto_run
carried over from their previous nesting.

Whitespace and comments only.
2026-09-22 09:30:40 +09:00
Peter Barker c892590775 Tools: update AHRS auto-trim feature symbol for its move into Copter
The auto-trim scheduler task moved from RC_Channels_Copter::auto_trim_run
to Copter::AHRSTrimming::auto_run, so extract_features.py was reporting
AP_COPTER_AHRS_AUTO_TRIM_ENABLED as absent from binaries which have it.
2026-09-22 09:30:40 +09:00
Peter Barker abd0106bbc autotest: add a test for instantaneous trim switch option 2026-09-22 09:30:40 +09:00
d2fe1453cf Copter: move AutoTrim support into Copter object
Co-authored-by: Ayush Suri <vtdlduddn3267@gmail.com>
Co-authored-by: codemaster1104 <akshatshrivastava1823@gmail.com>
2026-09-22 09:30:40 +09:00
yyzh a1ecb8b0ee hwdef: add SVehicle-E2-mini flight controller board 2026-09-22 10:28:26 +10:00
yyzh 332de37f2e bootloaders: add SVehicle-E2-mini bootloader binaries 2026-09-22 10:28:26 +10:00
yyzh 9de61c2614 AP_Bootloader: add board type for SVehicle-E2-mini 2026-09-22 10:28:26 +10:00
Pierre KancirandClaude Opus 5 22287496b9 .github: test_size_comment: post the size table on pull requests
"test size" runs pull request code, so its token is read-only and it
cannot comment.  This runs on workflow_run, from the default branch and
without a checkout, validates the data it is handed and builds the table
itself, so nothing the pull request wrote is posted under the bot's name.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-22 07:55:09 +10:00
Pierre KancirandClaude Opus 5 c7aef45de0 .github: test_size: pin the base commit and upload the size data
Resolve the base branch once per run, so every board compares against the
same commit, and mark the legs that do not succeed.  size-summary.json
goes to test_size_comment.yml; the markdown stays on the run's page.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-22 07:55:09 +10:00
Pierre KancirandClaude Opus 5 08d11f1ca8 Tools: build_tests: name the commits and emit the table as json
The table says which commit it was built from and which it was compared
against, and --json-output writes the same as data for the workflow that
comments it on a pull request.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-22 07:55:09 +10:00
Peter Barker 98b155533c autotest: let the context remove SDCardWPTest's script
SDCardWPTest installed mission_spiral.lua with the non-context
install_example_script() and removed it with a bare
remove_installed_script() thirty lines later, with no try/finally
between them.  Every wait_text() and set_parameter() in that stretch can
raise, and any of them leaves the script installed: the removal is
simply skipped.

That matters more here than for a leaked trick file, because
mission_spiral.lua ends in .lua - lua_scripts.cpp loads every .lua in
scripts/ - so the leftover is picked up and run by the next test to
start a vehicle with scripting enabled.

The test already pushes a context, and the harness pops any the test
leaves behind when it fails, so install_example_script_context() cleans
up on both paths.  Every other install site in Tools/autotest already
uses the _context form.
2026-09-22 07:21:24 +10:00
Peter Barker 9256cd77c5 .github: raise ccache max_size for the macOS builds
pre-commit / ci (push) Canceled after 0s
test Renode / cubeorangeplus-quadplane (push) Canceled after 0s
test scripts / build (astyle-cleanliness) (push) Canceled after 0s
test scripts / build (check_autotest_options) (push) Canceled after 0s
test scripts / build (logger_metadata) (push) Canceled after 0s
test scripts / build (param-file-validation) (push) Canceled after 0s
test scripts / build (param_parse) (push) Canceled after 0s
test scripts / build (python-cleanliness) (push) Canceled after 0s
test scripts / build (shellcheck) (push) Canceled after 0s
test scripts / build (validate_board_list) (push) Canceled after 0s
workflows lint / lint (push) Canceled after 0s
The macOS jobs' working set is 480-560MB, so at ccache.env's 400M default
both evicted objects mid-build - 817 cleanups on sitl, 123 on CubeOrange -
and re-compiled them on the next run. Restoring a cache built from the same
source, they hit 42% (CubeOrange) and 19% (sitl); with the cache large
enough to hold the working set both hit 99.8%.

Add a max-size input to setup-ccache so this is per-job rather than global:
raising it for all jobs would waste the repository's shared 10GB cache
quota on the ~60 jobs that use well under 400M. The two macOS entries grow
by 208MB in total.
2026-09-21 19:25:22 +10:00
Peter Barker 69b3dc83c5 .github: only build copter for the macOS debug build
The macOS workflow built every vehicle twice, once normally and once
with --debug. The second pass doubled build time and, since debug and
non-debug objects don't share ccache entries, overflowed the 400M ccache
limit, so the cache thrashed even when warm.

A single vehicle is enough to check the debug build works on macOS.
Plane, Rover, Sub, Blimp, AntennaTracker and heli no longer get a
--debug (-O0) compile on macOS; each still gets one in its Linux SITL
test workflow.
2026-09-21 19:25:22 +10:00
Andrii Anoshyn e323725412 AP_Terrain: remove legacy terrain generator 2026-09-21 19:22:50 +10:00
Andy Piper 663fc09bb2 hwdef: all TBS_LUCID_H7 variants can contain DPS368 or BMP390 2026-09-21 10:25:35 +10:00
Thomas Watson d25c1668e3 Tools: fix size_compare_branches.py jobs argument
waf does not persist `-j` in the configuration, it's only used for the
command it's specified on. So specifying `-j` to this script never did
anything to limit the number of build processes because the job limit
was only given to configure commands.

Now the script passes the appropriate number of jobs to build as well
as configure commands, so the limit is actually applied.

It's unclear if passing the number of jobs to the configure command
accomplishes a lot, but it doesn't hurt so it's kept.
2026-09-21 10:23:57 +10:00
Peter Barker 0d38ef16d1 Tools: environment_install: add if clauses to avoid churn on add/remove OS
previously adding or removing support for an OS meant changing lines unrelated to that OS.

Add a bit of cruft to the file so that adds/removes are just clean line additions or removal
2026-09-20 14:27:13 -07:00
Clyde McQueen 368dc0c428 autotest: remove rangefinder noise in Sub autotests to eliminate a source of flakiness
pre-commit / ci (push) Canceled after 0s
test scripts / build (astyle-cleanliness) (push) Canceled after 0s
test scripts / build (check_autotest_options) (push) Canceled after 0s
test scripts / build (logger_metadata) (push) Canceled after 0s
test scripts / build (param-file-validation) (push) Canceled after 0s
test scripts / build (param_parse) (push) Canceled after 0s
test scripts / build (python-cleanliness) (push) Canceled after 0s
test scripts / build (shellcheck) (push) Canceled after 0s
test scripts / build (validate_board_list) (push) Canceled after 0s
2026-09-19 20:36:04 +10:00
Amrit kumar Mahto 9165d22419 SITL: use strncpy in SIM_XPlane 2026-09-18 11:23:30 +10:00
Amrit kumar Mahto f1412b0cda AP_HAL_ESP32: use strncpy_noterm in WiFi drivers 2026-09-18 11:23:30 +10:00
Peter Barker 665c0deeec SRV_Channel: remove zero_rc_outputs
superseded by prepare_for_reboot(), which its only caller now uses
2026-09-18 00:10:02 +10:00
Peter Barker 26809186b8 AP_Vehicle: prepare for reboot at the HAL rc output level
ensures that the 0s get to the hardware

significantly reduces the race conditions which might allow a thread to write after values are zeroed
2026-09-18 00:10:02 +10:00
Peter Barker 94f7e038b0 SRV_Channel: prepare for reboot at the HAL rc output level
ensures that the 0s get to the hardware

significantly reduces the race conditions which might allow a thread to write after values are zeroed
2026-09-18 00:10:02 +10:00
Peter Barker 94800d5ae6 AP_HAL_SITL: prepare for reboot at the HAL rc output level
ensures that the 0s get to the hardware

significantly reduces the race conditions which might allow a thread to write after values are zeroed
2026-09-18 00:10:02 +10:00
Peter Barker c05eb925b1 AP_HAL_ChibiOS: prepare for reboot at the HAL rc output level
ensures that the 0s get to the hardware

significantly reduces the race conditions which might allow a thread to write after values are zeroed
2026-09-18 00:10:02 +10:00
Peter Barker 06c6317934 AP_HAL: prepare for reboot at the HAL rc output level
ensures that the 0s get to the hardware

significantly reduces the race conditions which might allow a thread to write after values are zeroed
2026-09-18 00:10:02 +10:00
Peter Barker 985d2f6f6f AP_HAL_Linux: bounds-check channel number in RCOutput write methods
RCOutput_PRU, RCOutput_AioPRU_PB2 and RCOutput_AeroIO wrote into their
channel arrays without checking the channel number; every other Linux
RCOutput backend already does.  On PRU the overrun is particularly
unpleasant as pending[MAX_PWMS] aliases the corked flag, so a write to
channel 12 uncorks the backend and makes the subsequent push() a no-op.

SRV_Channels::output_ch_all() already sweeps 16 channels by default,
so these overruns are reachable today on pxf, erleboard and pocket2.
2026-09-18 00:10:02 +10:00
Peter Barker 8a6d5b2ef7 Sub: prepare for reboot at the HAL rc output level
ensures that the 0s get to the hardware

significantly reduces the race conditions which might allow a thread to write after values are zeroed
2026-09-18 00:10:02 +10:00
Peter Barker 5efdf54920 Revert "hwdef: keep PA15 pulled up in the YJUAV_A6SE_H743 bootloader"
This reverts commit 2f87db990f.

PR #34359 was merged by mistake.  On the bench, with an ESC on
YJUAV_A6SE_H743 output 1, the hold presents a continuous high (full
throttle to a PWM ESC) for about 10.5s after every reset, and for as
long as safety is engaged when output 1 is a motor outside
BRD_SAFETY_MASK, which is Copter's default.  The ESC started to enter
throttle calibration.  Back the change out until the hold can be
chosen per output.
2026-09-18 00:04:45 +10:00