The BMP180 driver had no public init method and never called
readCalibrationCoefficients() from anywhere -- _calCoeff ran at the
C++ in-class member-initializer defaults (all zeros) at runtime.
Consequence chain:
- computeB5(UT) short-circuited via 0/0 (Cortex-M7 SDIV with
SCB->CCR.DIV_0_TRP=0 returns 0 silently -- system_stm32f7xx.c does
not enable the trap)
- getPressure() always tripped the `if (B4 == 0)` guard, returning
the I2C-error sentinel (post-AUDIT-C17: INT32_MIN; pre-: 255)
- health watchdog at main.cpp:758 fired ERROR_BMP180_COMM every
main-loop iteration because last_bmp_check was only updated on the
success path, so the 15 s rate-limit never engaged once the check
started failing
- error_count > 10 latched system_emergency_state = true (per the
MCU-N1 fix), driving SAFE-MODE within ~25 s of every boot
Fix:
- Added BMP180::begin() public method: probes chip ID, then reads the
11 factory cal coefficients (registers 0xAA..0xBE step 2). Returns
true only on full success; false on chip-ID mismatch or any I2C
failure mid-loop.
- main.cpp BAROMETER INIT calls myBMP.begin() with up to 3 retries
(50 ms backoff) and sets a file-scope bmp180_operational flag.
Altitude-baseline loop now gated on success -- failure path leaves
RADAR_Altitude at 0.0f instead of letting pow(negative, fractional)
propagate NaN into gps_data telemetry.
- Health watchdog gates BMP180 check on bmp180_operational AND
updates last_bmp_check regardless of the error path. A single bad
pressure reading no longer tight-loops into SAFE-MODE; legit sensor
failure now takes the intended ~150 s (10 errors x 15 s) before
the MCU-N1 latch trips, giving the operator time to intervene.
Verification:
- new test_audit_cal_bmp180_begin.c, 3/3 PASS:
T1 every coefficient loaded in order with correct signed/unsigned types
T2 chip-mismatch and I2C-fail short-circuit semantics correct
T3 regression demo: zero-cal computeB5 returns 0 for any UT (the
silent-fail mode); datasheet cal reproduces 15.0 C
- full MCU regression 33/33 PASS (was 32/32; +1 new test, 0 regressions)
Bug introduced in 5fbe97f (initial upload of the driver from the
Arduino enjoyneering79 BMP180 library -- the begin()/init pattern from
the upstream Arduino version was lost in the STM32 port). Latent until
this audit cycle.
43 lines
990 B
Plaintext
43 lines
990 B
Plaintext
# Build artifacts
|
|
*.o
|
|
*.dSYM/
|
|
|
|
# Test binaries (built by Makefile)
|
|
# TESTS_WITH_REAL
|
|
test_bug1_timed_sync_init_ordering
|
|
test_bug3_timed_sync_noop
|
|
test_bug4_phase_shift_before_check
|
|
test_bug5_fine_phase_gpio_only
|
|
test_bug9_platform_ops_null
|
|
test_bug10_spi_cs_not_toggled
|
|
test_bug15_htim3_dangling_extern
|
|
|
|
# TESTS_MOCK_ONLY
|
|
test_bug2_ad9523_double_setup
|
|
test_bug6_timer_variable_collision
|
|
test_bug7_gpio_pin_conflict
|
|
test_bug8_uart_commented_out
|
|
test_bug14_diag_section_args
|
|
test_gap3_emergency_stop_rails
|
|
|
|
# TESTS_STANDALONE
|
|
test_bug12_pa_cal_loop_inverted
|
|
test_bug13_dac2_adc_buffer_mismatch
|
|
test_audit_c17_bmp180_sentinel_and_cast
|
|
test_audit_cal_bmp180_begin
|
|
test_gap3_iwdg_config
|
|
test_gap3_temperature_max
|
|
test_gap3_idq_periodic_reread
|
|
test_gap3_emergency_state_ordering
|
|
test_gap3_overtemp_emergency_stop
|
|
test_gap3_health_watchdog_cold_start
|
|
|
|
# TESTS_WITH_PLATFORM
|
|
test_bug11_platform_spi_transmit_only
|
|
|
|
# TESTS_WITH_CXX
|
|
test_agc_outer_loop
|
|
|
|
# Manual / one-off test builds
|
|
test_um982_gps
|