Commit Graph
226 Commits
Author SHA1 Message Date
Peter BarkerandClaude Opus 4.8 466d712d7d AP_Param: avoid variable-length arrays in parameter conversion
convert_old_parameter(), convert_class() and _convert_parameter_width()
each declared a stack buffer sized by type_size() of a runtime parameter
type.  type_size() can return zero (AP_PARAM_NONE/GROUP, or an unknown
type), which makes the array a zero-length VLA - undefined behaviour -
and VLAs are non-standard C++ in any case.

Replace the VLAs with an object of a union of every storable parameter
type.  Such an object is large enough to hold any single parameter value
without assuming which type is largest, and is correctly aligned for the
typed accesses made through the AP_Param pointer.

The buffer's size had also been used as a length: in
_convert_parameter_width() as the EEPROM read length, and in
convert_old_parameter() and convert_class() as the same-type copy
length.  The union is not exactly the size of the value it holds, so
size those operations with type_size() explicitly, preserving the
lengths the VLAs gave.  Using sizeof() on the union instead would read
past the stored parameter, and in the two copy cases write up to
sizeof(Vector3f) bytes into a destination which may be as small as one
byte.

This clears the clang-scan-build core.VLASize findings.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-08-04 10:15:20 +10:00
Peter BarkerandClaude Opus 4.8 95f0a91c8d AP_Param: make fgets buflen semantics match C's fgets
buflen now includes the space required for the null terminator, so up
to buflen-1 characters are returned.  Previously fgets could write
buf[buflen], one byte beyond the caller-nominated length.  All
in-tree callers passed sizeof(buf)-1 to compensate, but
posix_compat's apfs_fgets forwards its C-style size argument
directly, so a caller supplying a size-byte buffer could have that
buffer overrun by one byte on an over-long line.

Update callers to pass the full buffer size; usable capacity is
unchanged.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-07-23 17:37:00 +10:00
LachlanConn aca90d95be AP_Param: Purge param_overrides from default_list
Remove any default_list entries that are superseded by param_overrides.
Constructors (e.g. SRV_Channels) can call add_default() before
param_overrides is populated, leaving stale nodes that would cause
check_default() to shadow the correct override value.
2026-06-02 16:08:20 +10:00
Thomas Watson e0bf41659d AP_Param: expand get_param_by_index index
In some cases the index can be more than a `uint8_t` so just use the
underlying type in the `ConversionInfo`.

This is a no compiler output change.
2025-12-04 11:52:13 -06:00
Thomas Watson 2f68aee9d5 AP_Param: fix spelling of sentinel
The correct spelling was used in some status messages. No
compiler-output change, this is all variable renames.
2025-11-23 14:58:51 -06:00
Peter Barker 661d2eab5b AP_Param: remove unused find_object method
historical method, unused for some time
2025-10-18 10:03:31 +01:00
Peter Barker 1feb625797 AP_Param: improve diagnostics in SITL when parameter name too long 2025-10-14 09:17:13 -05:00
Andrew Tridgell ee96030e6a AP_Param: fixed data race in param creation
this should properly fix the issue Peter raises in this PR:

https://github.com/ArduPilot/ardupilot/pull/30897

note that I'm avoiding a mutex as the load() is expensive
2025-08-15 11:04:16 +10:00
Peter Barker 82c82b12a2 AP_Param: fully-initialise parameter table on addition
so on a scripting restart everything gets reset
2025-08-06 17:39:31 +10:00
Peter Barker 2f11b022bc AP_Param: clear hidden flag when filling parameter in
if parameters are not created in index order then we end up with perfectly valid parameters which are hidden from the GCS
2025-08-06 17:39:31 +10:00
Andrew Tridgell 5370da33b6 AP_Param: ensure flags is filled in for find()
top level parameters don't have flags, but we need to fill in the
flags return field as otherwise we can refuse to set a parameter based
on it being internal and the allow_set_via_mavlink() check
2025-08-04 09:03:07 +10:00
Iampete1 07c3985846 AP_Param: convert_class allow recursing over subgroups 2025-07-22 10:33:55 +10:00
Andrew Tridgell 9601b2a763 AP_Param: fixed find_by_name()
the >= 0 for strncasecmp was incorrect
2025-07-17 09:39:31 +10:00
Iampete1 a83191cbf3 AP_Param: add_param rework find_by_name and token compare to find with pointer compare 2025-07-15 10:27:20 +10:00
Iampete1 a562b113ee AP_Param: check for duplicate names when adding scripting params 2025-07-08 10:03:42 +10:00
Peter Barker af6100f0f9 AP_Param: add option to ignore PARAM_SET 2025-05-20 13:32:16 +10:00
Peter Barker 9ba277a900 AP_Param: disallow setting of readonly/internal parameters via mavftp 2025-05-12 13:01:02 +10:00
Peter Barker 70e9a90ac5 AP_Param: remove superfluous linefeed from panic strings
panic adds this within the HAL layer.
2024-12-14 10:06:13 +11:00
Peter Barker efba110ef9 AP_Param: correct maximum-length parameter sanity check
need to take into account addition of (eg.) _X suffix for VECTOR3F parameters
2024-11-20 15:07:45 +11:00
Peter Barker 06b763ca94 AP_Param: add and use global NaNf float value 2024-09-26 19:26:59 +10:00
Andrew Tridgell faf769d8cd AP_Param: throw error if we lose parameters
if we can't save a parameter due to the queue size not being large
enough then there is a coding error, likely the code trying to save
large numbers of parameters while armed
2024-08-20 09:30:22 +10:00
Iampete1 838fbc2b3b AP_Param: Fix ENABLE_DEBUG enabled error with no embedded param 2024-07-30 08:51:09 +10:00
Andrew Tridgell ae8ee5325c AP_Param: added get_eeprom_full()
for arming check
2024-06-18 10:29:55 +10:00
Andrew Tridgell 6bd2be548b AP_Param: use NEW_NOTHROW for new(std::nothrow) 2024-06-04 09:20:21 +10:00
muramura ddae068657 AP_Param: Summarize the type definitions settings 2024-05-21 09:46:32 +10:00
Iampete1 cd0bdda93d AP_Param: add convert_bitmask_parameter_width method 2024-04-17 22:15:22 +01:00
Peter Barker 684b621b8c AP_Param: move serial_manager parameters up to base class 2024-02-29 12:12:19 +11:00
Peter Barker 079ffb4a40 AP_Param: add comments around G2 parameter conversion 2024-02-27 21:13:39 +11:00
Peter Barker dd628b025f AP_Param: remove unused old_top_element param from convert_class 2024-02-27 10:37:45 +11:00
Peter Barker f2e9e84278 AP_Param: simplify g2 object conversion 2024-02-27 10:37:45 +11:00
Andy Piper 1ba5898b82 AP_Param: remove unused variable 2024-02-22 14:40:55 +11:00
Andrew Tridgell df45140a56 AP_Param: fixed build of CubeOrange-periph 2024-02-15 13:41:29 +11:00
Andrew Tridgell 08468904db AP_Param: fixed cygwin build
the cygwin build is not generating binaries failing with:

   undefined reference to `AP_Param::load_param_defaults(char const volatile*, int, bool)

there is a 2nd problem that the CI test for cygwin doesn't fail when
the build fails. That will be addressed separately
2024-02-15 13:41:29 +11:00
Andrew Tridgell 5130f93c03 AP_Param: fixed setting of defaults for dynamic param trees
when we load a VARPTR subtree we need to re-scan the parameter
defaults file from @ROMFS/defaults.parm in case there are defaults
applicable to this subtree
2024-02-03 07:45:51 +11:00
Andrew Tridgell e039ff2a30 AP_Param: don't enable param backup on all boards
this fixes an issue with resetting of parameters when going between
4.4.x and 4.5.x on MatekH743, and on any other board using flash
storage where the storage size has increased from 16k to 32k between
4.4.x and 4.5.x

The problem is that when you update to 4.5.x the parameter code stored
a backup of parameters in the StorageParamBak storage region which is
in the last section of storage. When you downgrade to 4.4.x the
AP_FlashStorage::load_sector() code tries to load this data and gets
an error as it is beyond the end of the available 16k storage. This
triggers an erase_all() and loss of parameters
2024-01-28 08:42:57 +11:00
Andrew Tridgell 50b95c81ca AP_Param: whitespace fix 2024-01-23 15:00:30 +11:00
Tim Tuxworth 4919ae8f59 AP_Param: added convert_centi_parameter() 2024-01-23 15:00:30 +11:00
Peter Barker 6ce4dfea57 AP_Param: use ROMFS API for defaults file parsing if no AP_FileSystem 2024-01-18 21:44:15 +11:00
Peter Barker bd2d0100cd AP_Param: include defaulkts-file-parsing when AP_PARAM_DYNAMIC_ENABLED 2024-01-18 21:44:15 +11:00
Peter Barker 27fa5f8d2c AP_Param: use @ROMFS/defaults.parm rather than apj_tool for defaul parms 2024-01-17 18:28:48 +11:00
Iampete1 daf8aeeadc AP_Param: check dynamic param tables are avalable before adding a param 2023-11-28 11:22:43 +11:00
Andrew Tridgell 4f0ba39b64 AP_Param: fixed parameter defaults array length handling
we need to add up the total for all comma separated parameter files
2023-08-22 11:07:30 +10:00
Ryan Friedman 33c1e23e55 AP_Param: Use math header function names for type punning
Signed-off-by: Ryan Friedman <ryanfriedman5410+github@gmail.com>
2023-06-05 09:09:13 +10:00
Ryan Friedman e6f523dad1 AP_Param: Use explicit type instead of auto for crc
Signed-off-by: Ryan Friedman <ryanfriedman5410+github@gmail.com>
2023-06-05 09:09:13 +10:00
Ryan Friedman c382eb192a AP_Param: Switch from type punning to defined behavior
* This was undefined behavior in the C++ standard
* Use the safer options in AP_Common
* Removes a compiler warning

Signed-off-by: Ryan Friedman <ryanfriedman5410+github@gmail.com>
2023-06-05 09:09:13 +10:00
Peter Barker fd10c5e9e1 AP_Param: replace HAVE_FILESYSTEM_SUPPORT with backend defines 2023-05-17 09:40:39 +10:00
Iampete1 6cd5cf8195 AP_Param: print length of defaults list as part of key dump 2023-01-24 10:16:56 +11:00
Iampete1 49d23e16df AP_Param: rework embedded defualts list as no longer needed 2023-01-24 10:16:56 +11:00
Iampete1 02af134ba6 AP_Param: allow defualt values to be given by const float var 2023-01-24 10:16:56 +11:00
Peter Barker 37b54a7c9c AP_Param: correct compilation when debugging enabled
Correct passing through ov varargs from macro
2023-01-11 13:55:36 +11:00