Change the mutations to use `Pmut` and change the define to keep the
non-mutations from accidentally mutating.
All these mutations only touched the diagonals, so no risk of them
having broken symmetry.
Change their define so they don't use the mutable original, only the
name through a const-cast pointer. There are no writes to the covariance
matrix in these files, so nothing else needs changing.
In preparation for changing the regular `P` name to const, in
preparation for auditing the code so that writes to the matrix keep its
necessary numeric properties.
Sadly there is not a better way than a per-file `#define` to make the
switch. Making `P` a reference to `Pmut` substantially changes the
compiler output. Defining `P` in the header file conflicts with other
includes. Doing the rename at the top of each file allows each file to
be fixed independently.
It is the only HAL that sets `-Wframe-larger-than` so it is the only one
where the limit needs modification to fit the EKF.
ChibiOS additionally does not use Clang, so that check can be dropped.
waf does not persist `-j` in the configuration, it's only used for the
command it's specified on. So specifying `-j` to this script never did
anything to limit the number of build processes because the job limit
was only given to configure commands.
Now the script passes the appropriate number of jobs to build as well
as configure commands, so the limit is actually applied.
It's unclear if passing the number of jobs to the configure command
accomplishes a lot, but it doesn't hurt so it's kept.
This reverts commit 6e7367b86f.
These reductions reduce the usage of the Lua stack, which is stored in
the heap. This reverts back to the stock Lua values; some complex
scripts may desire extra locals. There is some increased risk of memory
fragmentation and so forth but presumably such scripts are prepared.
The actual C stack depth can be limited by `LUAI_MAXCCALLS`.
The launch scripts use shell mode to launch all components of the test,
excluding for whatever reason the micro ROS agent, which means the
command is executed as `/bin/sh -c <command>`.
This causes the shutdown signals to go to the shell process, which dies
and leaves the actual component orphaned as `sh` does not do job
control. Therefore each test leaves a copy of the components running.
Future tests then end up talking to past components and the tests hang
up and die.
A previous commit recognized and fixed this problem on the SITL binary,
but it just made the overall failures worse as the past mavproxy and
socat would then be more likely to reconnect to future instances.
Fix by making mavproxy and socat also exec so that there is only ever
one process for them. mavproxy does technically launch subprocesses
which may be left hanging but they should be killed by mavproxy itself
on a clean shutdown.
Future work will disable shell mode so there is no need for the extra
step, and arguments are better handled. This could also set up a
session/process group for mavproxy, assuming it is supported by the ROS
framework, to reduce the chances of its children giving problems.
These are always called together and always called with `P` as the first
argument. `P` must remain symmetric, so merging them removes chances for
bugs and saves flash.
A previous fix to avoid corrupting prints of subnormal floats slightly
changed the setup logic in a way that caused a hang when handling
infinities.
Originally, the implicit mantissa bit was made explicit in the fraction
whenever the number was not subnormal. The previous fix changed it to be
set only when the number was normal, causing different behavior for
infinities and NaNs.
Unfortunately, as an infinity has a fractional component of zero, this
led to entering the main formatting loop with a 0 `prod` to format. This
caues `decimal` to eventually end up at 0, then the digit increment loop
to run forever as subtracting 0 from 0 will never result in a value less
than 0.
Doubly unfortunately, the previous fix for a similar hang to exit when
`decimal` became 0 was not crossed as the 0 `prod` would not allow the
code to proceed past the step to find a nonzero digit and run the check.
Fix by restoring the old mantissa bit explicitization behavior.
This functionality was approximately never used when it existed as an
`@SYS` file, and has been a source of dangerous bugs.
Remove it completely to avoid future problems and save the flash.
The parameter must stay to control handling of `LogMessage` from
peripherals, which were always sent to the GCS.
This functionality was approximately never used when it existed as an
`@SYS` file, so compile it out so it does not suddenly appear.
The parameter must stay to control handling of `LogMessage` from
peripherals, which were always sent to the GCS.
Once the CAN log buffer gets near to full, the check for remaining space
can pass even though there is insufficient space left in the buffer
for the actual log message after formatting.
The space for the tag is correctly measured, so the `snprintf` will
never perform a short write. However, the `vsnprintf` will. Though it
does not write too much, it pushes `_log_pos` past the end of the buffer
as it returns the amount that would be written, rather than the amount
that actually was written.
In this case, the test on the next call of the function aims to reset
`_log_pos` to the start. Unfortunately, as that variable is unsigned,
the subtraction from `LOG_BUFFER_SIZE` will result in a large positive
number, falsely stating that there is enough space. This will also then
give the `snprintf` and `vsnprintf` a large positive space for them to
write into, so they will write past the end of the buffer and corrupt
the heap and crash the system.
Fix by making the variable and comparison properly signed. This will
give a problem if log messages get into the billions of characters, but
this is unlikely to occur.
If the receiver sends less than four channels, the reordering step will
use unspecified data from the input buffer as valid RC input values. The
official minimum channel count from the protocol documentation is two.
There is no risk of a buffer overread or overwrite, it is hard to
believe a user would set up this configuration, and there is a
relatively strong checksum which protects the channel count too.
Therefore, an actual problem is unlikely.
Fix by rejecting packets claiming to have less than four channels. This
fix is zero-cost and removes any risk of garbage from such packets.
Restructuring the P -= KHP calculation to produce a symmetric result is
faster and smaller than forcing it after the fact. Here it is done to avoid
changing the result at all but this could be improved in the future.
Timing of P -= KHP (including forcing symmetry) on H7 is 17us, down from
23. On F4 it is 32us, down from 48.
Update `stateStruct` before calling `ConstrainVariances` as the latter
can change `stateStruct` in rare cases.
The `MagTableConstrain` call will further constrain the states but not
in a way that interacts with `ConstrainVariances`.
This removes the need for the pointer to the first mode, and removes the
undefined behavior resulting from indexing past that first mode and
hoping the others follow (though this is unlikely to pose a problem in
practice).
Saves a few bytes of RAM and flash as the pointer is no longer needed
and code is no longer necessary to set it up.
Also fixes the bounds check condition of that array to match its size so
there is no longer the possibility of indexing one past it.
This removes the need for the pointer to the first flight mode, and
removes the undefined behavior resulting from indexing past that first
flight mode and hoping the others follow (though this is unlikely to
pose a problem in practice).
Saves a few bytes of RAM and flash as the pointer is no longer needed
and code is no longer necessary to set it up.
Also fixes the bounds check condition of that array to match its size so
there is no longer the possibility of indexing one past it.
This removes the need for the pointer to the first flight mode, and
removes the undefined behavior resulting from indexing past that first
flight mode and hoping the others follow (though this is unlikely to
pose a problem in practice).
Saves a few bytes of RAM and flash as the pointer is no longer needed
and code is no longer necessary to set it up.
Also fixes the bounds check condition of that array to match its size so
there is no longer the possibility of indexing one past it.
This removes the need for the pointer to the first flight mode, and
removes the undefined behavior resulting from indexing past that first
flight mode and hoping the others follow (though this is unlikely to
pose a problem in practice).
Saves a few bytes of RAM and flash as the pointer is no longer needed
and code is no longer necessary to set it up.
This removes the need for the pointer to the first flight mode, and
removes the undefined behavior resulting from indexing past that first
flight mode and hoping the others follow (though this is unlikely to
pose a problem in practice).
Saves a few bytes of RAM and flash as the pointer is no longer needed
and code is no longer necessary to set it up.
Also fixes the bounds check condition of that array to match its size so
there is no longer the possibility of indexing one past it.
Unsure if this is a major issue since the next EKF loop would likely call
some fusion function which would do the same things. But better safe than
sorry, and consistency is good.
The debug flag, contrary to its documentation, enables a debug build,
increasing the size of the binary and changing its contents. Fix the
documentation to describe what it actually does.
Then add the same flag as waf to just add symbols without changing the
actual binary.
Python 3.9 is still installed as part of GDB, but 3.12 is the default.
Might need to use native Windows Python in the future, or cross-compile
from Linux.
Remove a bunch of old things which no longer worked properly or weren't
necessary. Also update to pin the actually used compiler like CI. And
add tmux as a way to get "run in terminal window" to work.
GCC 10.2 was removed from the Cygwin repos some time ago, so the
installer silently installed the latest stable version, which is
currently 13.4. Pin that properly so we know what we are getting, at
least until that too disappears.
Does not do anything we don't already have documented, and it was never
used or linked to by e.g. the wiki. Remove as it's just more to become
desynchronized and outdated.
Inexplicably, the offset and delay fields were never filled in the RBOH
message, despite the fact they have always been available and read from
it. Filling these in is necessary for replay to work as the default
delay is not zero, so reading zero in replay causes a difference in the
replayed data. Also fix the comments which falsely say these fields are
not used.
The wait function could never return None. As the `Scheduler_test` is
apparently slightly longer than the timeout, just warn if the process
did not exit to preserve the current behavior. Also make a comment to
come back and fix up later.
It never exited early in the normal case and just burned 100% CPU. It
will be slightly slower in an error case if there is an unexpected early
exit but that is probably worth the simplification.
Pass the documented `/dev/null` sentinel instead of improperly managing
the file handle ourselves.
Remove the `close_fds=True` as that is the default for all Pythons we
care about.
A replay log plainly shows these fields are not zero and are used. They
are filled in by `get_vehicle_position_ned` in
`AP_DAL_Beacon::start_frame`.
Some code sleuthing shows the estimates are the ones generated by the
beeacon system, rather than the vehicle itself.
Setting a count in the packet bigger than the data buffer size could
result in reading past the decoded packet and sending random junk off
the stack. Fix by capping the size to send at the buffer size, as there
is no ability for returning failure at this time. The recieve path is
already protected similarly.
Co-authored-by: quart27219 <nullquart@gmail.com>
Allows vehicles other than Copter to have their own Replay tests.
Semantics are slightly wonky as the autotest program deletes logs at the
start of each given step, i.e. vehicle build or test.
Default to running all vehicles we have tests for now.
If the C header files or the Python generator sources change, then this
causes the generator to rerun, fixed headers to get copied again, and
dependent files to be rebuilt.
`inhibitDelVelBiasStates` becomes false once tilt alignment is complete,
which unlocks processing of states 13-15. If on the ground but tilted a
bit ("not aligned with the gravity vector") in some axis, then
`dvelBiasAxisInhibit[index]` becomes true to stop updates of variance in
that axis.
In this case, according to the comment, the covariances for that axis
state are zeroed to prevent interaction with other states, and the saved
variance from when the inhibit began is restored.
However, this zeroing was done incorrectly by only zeroing the columns
of `nextP`. As it is lower triangular, only covariances to states with a
higher index are in the same column; states with a lower index are
instead in the same row. This skipped zeroing the covariances to the
more important states and led to state divergence on the ground.
Fix by also zeroing the row to zero the lower covariances. Confirmed
that this fixes at least one replay log which showed ground divergence
while tilted. This is possibly a new feature of EKF3, or at least
implemented differently, so EKF2 does not need the same fix.
Tests that fusion of wind estimation and airspeed data is correctly
replayed by the EKF. The test that wind estimation is working is already
handled by `BaroWindCorrection`.
Adding airspeed to Copter is easier than migrating everything to Plane.
Technically fusion of airspeed data is not supported on copters and the
`ARSPD_USE` parameter explicitly recommends against it. But it exists
and works, and this test includes a check that it has continued to work.
So if we break that later, the test will start to fail and we can decide
what to do.