fix: four real firmware defects found in adversarial review

rd03e.c: RD03E_FRAME_LEN was 5 but the frame's own documented layout
(header + gesture + distance_lo + distance_hi + footer[2]) is 6 bytes.
The footer check read buf[i+3], colliding with the distance high byte at
that same index — so every frame that validated at all was forced to have
distance_cm = lo | 0x5500 (~218m) regardless of what the sensor reported.
Distance readings were garbage 100% of the time, not intermittently.

mems_mic.c: i2s_del_channel() was missing on 2 of 3 init failure paths,
leaking the channel handle.

bmp280.c: the I2C bus/device handles leaked on 4 of 5 init failure paths;
added a fail label that releases both.

app_main.c: sensors now init before Wi-Fi bring-up, matching the rationale
sensor_driver.h already documents (a hanging sensor bus must not be able to
block network bring-up).

rtlsdr_experimental.c: rtlsdr_exp_stop() waited 500ms before
usb_host_uninstall(), but the daemon task blocks up to 1000ms inside
usb_host_lib_handle_events() before re-checking its running flag — the
delay must exceed that or teardown races a live daemon task.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
Indiana
2026-07-27 15:47:21 +00:00
parent 825f6aa510
commit 31f3f91801
5 changed files with 38 additions and 18 deletions

View File

@@ -73,6 +73,8 @@ esp_err_t mems_mic_init(void) {
err = i2s_channel_init_std_mode(s_rx_chan, &std_cfg);
if (err != ESP_OK) {
ESP_LOGE(TAG, "i2s_channel_init_std_mode failed: %s", esp_err_to_name(err));
i2s_del_channel(s_rx_chan);
s_rx_chan = NULL;
free(s_sample_buf);
s_sample_buf = NULL;
return err;
@@ -81,6 +83,8 @@ esp_err_t mems_mic_init(void) {
err = i2s_channel_enable(s_rx_chan);
if (err != ESP_OK) {
ESP_LOGE(TAG, "i2s_channel_enable failed: %s", esp_err_to_name(err));
i2s_del_channel(s_rx_chan);
s_rx_chan = NULL;
free(s_sample_buf);
s_sample_buf = NULL;
return err;