| FazBrowse GitHub Viewer | Trending | | Home |
| Tools: [Download Repo ZIP] [Original HTTPS Page] |
Sorry, something went wrong.
🔎 FLASH Analysispx4_fmu-v5x [Total VM Diff: 896 byte (0.04 %)] FILE SIZE VM SIZE
-------------- --------------
+0.0% +896 +0.0% +896 .text
+69% +196 +69% +196 uavcan_posix::FirmwareVersionChecker::shouldRequestFirmwareUpdate()
+7.8% +120 +7.8% +120 UavcanNode::Run()
+0.1% +104 +0.1% +104 g_cromfs_image
+13% +92 +13% +92 SystemChecks::checkAndReport()
+0.1% +92 +0.1% +92 [section .text]
-99.8% +58 -99.8% +58 [34 Others]
+1.0% +40 +1.0% +40 Commander::handle_command()
+4.0% +40 +4.0% +40 UavcanNode::UavcanNode()
+27% +36 +27% +36 SystemChecks::SystemChecks()
+212% +34 +212% +34 uavcan_posix::FirmwareVersionChecker::~FirmwareVersionChecker()
+0.2% +32 +0.2% +32 uORB::compressed_fields
+2.3% +28 +2.3% +28 Commander::dataLinkCheck()
+5.1% +28 +5.1% +28 UavcanNode::~UavcanNode()
[NEW] +16 [NEW] +16 __orb_uavcan_firmware_update
+5.4% +12 +5.4% +12 Commander::landDetectorUpdate()
+17% +12 +17% +12 SystemChecks::updateParamsImpl()
+1.6% +8 +1.6% +8 Commander::arm()
+2.2% +8 +2.2% +8 Commander::disarm()
-3.6% -8 -3.6% -8 Commander::checkForMissionUpdate()
-2.4% -20 -2.4% -20 HealthAndArmingChecks::~HealthAndArmingChecks()
-6.4% -32 -6.4% -32 uavcan::Array<>::push_back()
+0.0% +938 [ = ] 0 .debug_abbrev
+0.1% +112 [ = ] 0 .debug_aranges
+0.1% +332 [ = ] 0 .debug_frame
+0.1% +25.1Ki [ = ] 0 .debug_info
+0.1% +3.51Ki [ = ] 0 .debug_line
+150% +3 [ = ] 0 [Unmapped]
+0.1% +3.51Ki [ = ] 0 [section .debug_line]
+0.1% +2.85Ki [ = ] 0 .debug_loclists
+0.1% +370 [ = ] 0 .debug_rnglists
+0.1% +4.19Ki [ = ] 0 .debug_str
-1.2% -3 [ = ] 0 .shstrtab
-0.0% -57 [ = ] 0 .strtab
[DEL] -11 [ = ] 0 CSWTCH.799
[NEW] +11 [ = ] 0 CSWTCH.801
+0.1% +27 [ = ] 0 [section .strtab]
-20.0% -16 [ = ] 0 ___ZN3Ekf20controlGravityFusionERKN9estimator9imuSampleE_veneer
+100% +16 [ = ] 0 __memcpy_veneer
[NEW] +29 [ = ] 0 __orb_uavcan_firmware_update
-7.0% -113 [ = ] 0 uavcan::Array<>::push_back()
+0.0% +48 [ = ] 0 .symtab
[DEL] -32 [ = ] 0 CSWTCH.799
[NEW] +32 [ = ] 0 CSWTCH.801
-14.3% -16 [ = ] 0 Commander::Commander()
+100% +16 [ = ] 0 Commander::checkForMissionUpdate()
-25.0% -16 [ = ] 0 Commander::manualControlLossModeSwitch()
+100% +16 [ = ] 0 Commander::offboardControlCheck()
+33% +16 [ = ] 0 Commander::updateParamsImpl()
-50.0% -32 [ = ] 0 EKFGSF_yaw::fuseVelocity()
-50.0% -16 [ = ] 0 HealthAndArmingCheckBase::updateParams()
-25.0% -32 [ = ] 0 RcvTopicsPubs::init()
-25.0% -16 [ = ] 0 SystemChecks::checkAndReport()
+20% +16 [ = ] 0 SystemChecks::~SystemChecks()
+67% +32 [ = ] 0 UavcanNode::UavcanNode()
-102.1% -48 [ = ] 0 [13 Others]
+0.5% +64 [ = ] 0 [section .symtab]
-40.0% -32 [ = ] 0 ___ZN3Ekf20controlGravityFusionERKN9estimator9imuSampleE_veneer
+33% +16 [ = ] 0 ___ZNK3px46atomicIbE4loadEv_veneer
-25.0% -16 [ = ] 0 ____errno_veneer
+50% +16 [ = ] 0 __dq_rem_veneer
+67% +32 [ = ] 0 __memcpy_veneer
[NEW] +48 [ = ] 0 __orb_uavcan_firmware_update
+39% +3.12Ki [ = ] 0 [Unmapped]
+0.1% +41.4Ki +0.0% +896 TOTAL
FILE SIZE VM SIZE
-------------- --------------
+0.0% +800 +0.0% +800 .text
+69% +196 +69% +196 uavcan_posix::FirmwareVersionChecker::shouldRequestFirmwareUpdate()
+0.1% +136 +0.1% +136 g_cromfs_image
+7.8% +120 +7.8% +120 UavcanNode::Run()
+13% +92 +13% +92 SystemChecks::checkAndReport()
+0.1% +88 +0.1% +88 [section .text]
+1.0% +40 +1.0% +40 Commander::handle_command()
+4.0% +40 +4.0% +40 UavcanNode::UavcanNode()
+27% +36 +27% +36 SystemChecks::SystemChecks()
+212% +34 +212% +34 uavcan_posix::FirmwareVersionChecker::~FirmwareVersionChecker()
+0.2% +32 +0.2% +32 uORB::compressed_fields
+2.3% +28 +2.3% +28 Commander::dataLinkCheck()
+5.1% +28 +5.1% +28 UavcanNode::~UavcanNode()
[NEW] +16 [NEW] +16 __orb_uavcan_firmware_update
+5.4% +12 +5.4% +12 Commander::landDetectorUpdate()
+17% +12 +17% +12 SystemChecks::updateParamsImpl()
+1.6% +8 +1.6% +8 Commander::arm()
-3.6% -8 -3.6% -8 Commander::checkForMissionUpdate()
-2.4% -20 -2.4% -20 HealthAndArmingChecks::~HealthAndArmingChecks()
-4.7% -20 -4.7% -20 param_reset_specific
-6.4% -32 -6.4% -32 uavcan::Array<>::push_back()
-100.1% -38 -100.1% -38 [56 Others]
+0.0% +938 [ = ] 0 .debug_abbrev
+0.1% +112 [ = ] 0 .debug_aranges
+0.1% +312 [ = ] 0 .debug_frame
+0.1% +24.9Ki [ = ] 0 .debug_info
+0.1% +3.42Ki [ = ] 0 .debug_line
+250% +5 [ = ] 0 [Unmapped]
+0.1% +3.41Ki [ = ] 0 [section .debug_line]
+0.1% +2.65Ki [ = ] 0 .debug_loclists
+0.1% +354 [ = ] 0 .debug_rnglists
-33.3% -1 [ = ] 0 [Unmapped]
+0.1% +355 [ = ] 0 [section .debug_rnglists]
+0.1% +4.19Ki [ = ] 0 .debug_str
+0.4% +1 [ = ] 0 .shstrtab
-0.0% -57 [ = ] 0 .strtab
[DEL] -11 [ = ] 0 CSWTCH.799
[NEW] +11 [ = ] 0 CSWTCH.801
+0.1% +27 [ = ] 0 [section .strtab]
[NEW] +29 [ = ] 0 __orb_uavcan_firmware_update
-7.0% -113 [ = ] 0 uavcan::Array<>::push_back()
+0.0% +48 [ = ] 0 .symtab
[DEL] -32 [ = ] 0 CSWTCH.799
[NEW] +32 [ = ] 0 CSWTCH.801
-14.3% -16 [ = ] 0 Commander::Commander()
+100% +16 [ = ] 0 Commander::checkForMissionUpdate()
-25.0% -16 [ = ] 0 Commander::manualControlLossModeSwitch()
+100% +16 [ = ] 0 Commander::offboardControlCheck()
+33% +16 [ = ] 0 Commander::updateParamsImpl()
+100% +16 [ = ] 0 ConstLayer::containedAsBitset()
+100% +16 [ = ] 0 ConstLayer::contains()
-33.3% -16 [ = ] 0 ConstLayer::store()
+25% +16 [ = ] 0 DynamicSparseLayer::DynamicSparseLayer()
+100% +32 [ = ] 0 EKFGSF_yaw::fuseVelocity()
-50.0% -16 [ = ] 0 HealthAndArmingCheckBase::updateParams()
-25.0% -32 [ = ] 0 RcvTopicsPubs::init()
-25.0% -16 [ = ] 0 SystemChecks::checkAndReport()
+20% +16 [ = ] 0 SystemChecks::~SystemChecks()
+25% +16 [ = ] 0 UavcanNode::UavcanNode()
-106.9% -80 [ = ] 0 [13 Others]
+0.1% +16 [ = ] 0 [section .symtab]
[NEW] +48 [ = ] 0 __orb_uavcan_firmware_update
+50% +16 [ = ] 0 _buffer
+72% +3.22Ki [ = ] 0 [Unmapped]
+0.1% +40.9Ki +0.0% +800 TOTAL
Updated: 2026-08-10T09:55:38 |
Sorry, something went wrong.
|
Claude review on behalf of @dakejahl Blocker — _updating_nodes insert does not de-dupe (firmware_version_checker.hpp / shouldRequestFirmwareUpdate) Blocker — table full still starts an update but stops tracking it Concern — no clear on update failure / node loss → permanent arm deny Concern — uavcan_firmware_update published every Run (~3 ms) (uavcan_main.cpp) Nit — UavcanFirmwareUpdate.msg comment Nit — title |
Sorry, something went wrong.
|
Claude review on behalf of @dakejahl Dedupe, the fixed cap, the publish rate, and the msg comment are all addressed. The "no clear on node loss" concern is still open, and the rewrite introduces two new defects. Blocker — zero unique ID aliases two nodes to one entry (firmware_version_checker.hpp, shouldRequestFirmwareUpdate) Blocker — no recovery path; a lost node grounds the vehicle Recommended fix for both — key by NodeID in a fixed bitset, clear on offline Concern — unchecked new, silent failure (firmware_version_checker.hpp) Nits
|
Sorry, something went wrong.
|
Claude review on behalf of @dakejahl Zero-UID guard is placed wrong (firmware_version_checker.hpp:120-125) Unchecked new (firmware_version_checker.hpp:186-188) prearmed not covered (uavcan_main.cpp:758) Nits
|
Sorry, something went wrong.
…ing (#28089) * feat: track Node updates * feat: prevent arming while updating * fix: used make format * fix: added dedup logic & use dynamic list * fix: cleaned up arming_blocker * feat: add circuit breaker for arming_blocker * chore: used make format * fix: fix some formating issues * chore: make format again * fix: implemented requested changes (cherry picked from commit 985aa09) Assisted-by: GitHub Copilot:gpt-6-astra Backport-note: Adapt to release/1.18 without importing unrelated NFS support.
…ing (#28089) * feat: track Node updates * feat: prevent arming while updating * fix: used make format * fix: added dedup logic & use dynamic list * fix: cleaned up arming_blocker * feat: add circuit breaker for arming_blocker * chore: used make format * fix: fix some formating issues * chore: make format again * fix: implemented requested changes (cherry picked from commit 985aa09) Assisted-by: GitHub Copilot:gpt-6-astra Backport-note: Adapt to release/1.18 without importing unrelated NFS support.
| Back | FazBrowse Home | New Git URL |
Solved Problem
UAVCAN firmware updates could be initiated while the vehicle was armed, causing nodes to reboot into their bootloader mid-flight. Conversely, there was no mechanism to prevent arming while a firmware update was already in progress, which could leave safety-critical nodes in a non-operational state during flight.
Solution
Two complementary protections are added:
1. No update initiation while armed
FirmwareVersionChecker::shouldRequestFirmwareUpdate() returns false immediately when the vehicle is armed. This prevents any node from being queued for a BeginFirmwareUpdate request during flight. The armed state is propagated from UavcanNode via actuator_armed uORB subscription → UavcanServers::setArmed() → FirmwareVersionChecker::setArmed().
2. Arming blocked while update is in progress
FirmwareVersionChecker tracks nodes under update in a dynamically-sized linked list (List<UpdatingNode *>) keyed by the node's 128-bit hardware unique ID, removing any fixed cap on the number of concurrently updating nodes. A node is added when shouldRequestFirmwareUpdate() returns true and removed when it returns false (CRCs match after reboot → update complete). Dynamic allocation is used intentionally here: firmware updates only occur before arming, so nodes are added and removed exclusively during the pre-arm phase. This state is published via a new uavcan_firmware_update uORB topic — only when pending_updates changes state, to avoid unnecessary bus traffic — and consumed by SystemChecks::checkAndReport() in commander, which blocks arming with a preflight failure while any update is pending.
Changelog Entry
Feature: UAVCAN firmware updates are now blocked while armed, and arming is blocked while a UAVCAN node firmware update is in progress.
Alternatives
Test Coverage
Manual: verified on bench with a UAVCAN node with mismatched firmware → arming is blocked until update completes, and no update is sent while armed.
Context
The update lifecycle tracked by _updating_nodes covers the full path: node detected (CRC mismatch) → BeginFirmwareUpdate sent and confirmed → node in bootloader downloading firmware → node reboots with new firmware (CRC match). Arming is blocked for the entire duration.