fix: four real firmware defects found in adversarial review
rd03e.c: RD03E_FRAME_LEN was 5 but the frame's own documented layout (header + gesture + distance_lo + distance_hi + footer[2]) is 6 bytes. The footer check read buf[i+3], colliding with the distance high byte at that same index — so every frame that validated at all was forced to have distance_cm = lo | 0x5500 (~218m) regardless of what the sensor reported. Distance readings were garbage 100% of the time, not intermittently. mems_mic.c: i2s_del_channel() was missing on 2 of 3 init failure paths, leaking the channel handle. bmp280.c: the I2C bus/device handles leaked on 4 of 5 init failure paths; added a fail label that releases both. app_main.c: sensors now init before Wi-Fi bring-up, matching the rationale sensor_driver.h already documents (a hanging sensor bus must not be able to block network bring-up). rtlsdr_experimental.c: rtlsdr_exp_stop() waited 500ms before usb_host_uninstall(), but the daemon task blocks up to 1000ms inside usb_host_lib_handle_events() before re-checking its running flag — the delay must exceed that or teardown races a live daemon task. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
@@ -12,7 +12,7 @@
|
||||
// "simple report" output frames, which need no configuration to start
|
||||
// streaming after power-up.
|
||||
//
|
||||
// Simple report frame, as reconstructed (5 bytes total):
|
||||
// Simple report frame, as reconstructed (6 bytes total):
|
||||
// [0] 0xAA frame header
|
||||
// [1] gesture code raw value, meaning not confirmed against an
|
||||
// official datasheet — reported as-is in
|
||||
@@ -36,7 +36,7 @@ static const char *TAG = "rd03e";
|
||||
|
||||
#define RD03E_RX_BUF_SIZE 512
|
||||
#define RD03E_SCRATCH_SIZE 256
|
||||
#define RD03E_FRAME_LEN 5
|
||||
#define RD03E_FRAME_LEN 6
|
||||
|
||||
static const uint8_t FRAME_HEADER = 0xAA;
|
||||
static const uint8_t FRAME_FOOTER[2] = { 0x55, 0x55 };
|
||||
@@ -116,7 +116,7 @@ esp_err_t rd03e_read(sensor_reading_t *out, size_t max_out, size_t *out_count) {
|
||||
if (buf[i] != FRAME_HEADER) {
|
||||
continue;
|
||||
}
|
||||
if (memcmp(&buf[i + 3], FRAME_FOOTER, 2) != 0) {
|
||||
if (memcmp(&buf[i + 4], FRAME_FOOTER, 2) != 0) {
|
||||
continue; // not a real header byte, or a corrupted frame
|
||||
}
|
||||
latest.gesture = buf[i + 1];
|
||||
|
||||
Reference in New Issue
Block a user