fix: four real firmware defects found in adversarial review
rd03e.c: RD03E_FRAME_LEN was 5 but the frame's own documented layout (header + gesture + distance_lo + distance_hi + footer[2]) is 6 bytes. The footer check read buf[i+3], colliding with the distance high byte at that same index — so every frame that validated at all was forced to have distance_cm = lo | 0x5500 (~218m) regardless of what the sensor reported. Distance readings were garbage 100% of the time, not intermittently. mems_mic.c: i2s_del_channel() was missing on 2 of 3 init failure paths, leaking the channel handle. bmp280.c: the I2C bus/device handles leaked on 4 of 5 init failure paths; added a fail label that releases both. app_main.c: sensors now init before Wi-Fi bring-up, matching the rationale sensor_driver.h already documents (a hanging sensor bus must not be able to block network bring-up). rtlsdr_experimental.c: rtlsdr_exp_stop() waited 500ms before usb_host_uninstall(), but the daemon task blocks up to 1000ms inside usb_host_lib_handle_events() before re-checking its running flag — the delay must exceed that or teardown races a live daemon task. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
@@ -122,6 +122,8 @@ esp_err_t bmp280_init(void) {
|
||||
err = i2c_master_bus_add_device(s_bus, &dev_cfg, &s_dev);
|
||||
if (err != ESP_OK) {
|
||||
ESP_LOGE(TAG, "i2c_master_bus_add_device failed: %s", esp_err_to_name(err));
|
||||
i2c_del_master_bus(s_bus);
|
||||
s_bus = NULL;
|
||||
return err;
|
||||
}
|
||||
|
||||
@@ -129,7 +131,7 @@ esp_err_t bmp280_init(void) {
|
||||
err = read_regs(REG_CHIP_ID, &chip_id, 1);
|
||||
if (err != ESP_OK) {
|
||||
ESP_LOGE(TAG, "chip id read failed: %s", esp_err_to_name(err));
|
||||
return err;
|
||||
goto fail;
|
||||
}
|
||||
if (chip_id != CHIP_ID_EXPECTED) {
|
||||
ESP_LOGW(TAG, "unexpected chip id 0x%02x (want 0x%02x) -- check wiring/address", chip_id, CHIP_ID_EXPECTED);
|
||||
@@ -139,18 +141,25 @@ esp_err_t bmp280_init(void) {
|
||||
}
|
||||
|
||||
err = write_reg(REG_RESET, RESET_MAGIC);
|
||||
if (err != ESP_OK) return err;
|
||||
if (err != ESP_OK) goto fail;
|
||||
vTaskDelay(pdMS_TO_TICKS(10)); // datasheet: allow >= 2ms after reset
|
||||
|
||||
err = read_calibration();
|
||||
if (err != ESP_OK) {
|
||||
ESP_LOGE(TAG, "calibration read failed: %s", esp_err_to_name(err));
|
||||
return err;
|
||||
goto fail;
|
||||
}
|
||||
|
||||
s_ready = true;
|
||||
ESP_LOGI(TAG, "BMP280 init ok (chip id 0x%02x)", chip_id);
|
||||
return ESP_OK;
|
||||
|
||||
fail:
|
||||
i2c_master_bus_rm_device(s_dev);
|
||||
s_dev = NULL;
|
||||
i2c_del_master_bus(s_bus);
|
||||
s_bus = NULL;
|
||||
return err;
|
||||
}
|
||||
|
||||
// Bosch datasheet 3.11.3 double-precision reference compensation formulas,
|
||||
|
||||
Reference in New Issue
Block a user