From 867b006861d4ea887d1f17a79d84b4455a392c91 Mon Sep 17 00:00:00 2001 From: Lorenz Meier Date: Wed, 3 Feb 2021 21:38:50 +0100 Subject: [PATCH] IO safety button: Latch to disabled state As hardware buttons are not particularly reliable and the user flow is to disable safety then arm, then disarm via software / remote, it makes sense to make the button safety state itself sticky and require it to be reset via software. --- src/modules/px4iofirmware/safety.c | 13 +++++++++---- 1 file changed, 9 insertions(+), 4 deletions(-) diff --git a/src/modules/px4iofirmware/safety.c b/src/modules/px4iofirmware/safety.c index 9239460e36..65c229e8b5 100644 --- a/src/modules/px4iofirmware/safety.c +++ b/src/modules/px4iofirmware/safety.c @@ -104,7 +104,7 @@ safety_check_button(void *arg) safety_button_pressed = BUTTON_SAFETY; /* - * Keep pressed for a while to arm. + * Keep pressed for a while to disable safety. * * Note that the counting sequence has to be same length * for arming / disarming in order to end up as proper @@ -118,7 +118,9 @@ safety_check_button(void *arg) counter++; } else if (counter == ARM_COUNTER_THRESHOLD) { - /* switch to armed state */ + /* switch to safety off state - the system still needs to be + * fully armed by the operator + */ atomic_modify_or(&r_status_flags, PX4IO_P_STATUS_FLAGS_SAFETY_OFF); counter++; } @@ -129,8 +131,11 @@ safety_check_button(void *arg) counter++; } else if (counter == ARM_COUNTER_THRESHOLD) { - /* change to disarmed state and notify the FMU */ - atomic_modify_clear(&r_status_flags, PX4IO_P_STATUS_FLAGS_SAFETY_OFF); + /* we are not switching out of the armed state + * as a stuck button could cause this during + * normal operation. The system needs to be + * disarmed by software + */ counter++; }