Field report · 28 September 2026

Twelve months of safety-parameter changes in ArduPilotand what a drone integrator had to review

If you ship a drone built on ArduPilot, every update pulls in changes to the parameters your safety case depends on. We scanned one year of ArduPilot master to see how often that happens.

2025-09-28 → 2026-09-28 · master at a11f7351

531commits touched the scanned safety areas
16changed how a safety parameter is defined
42parameters affected, 16 renamed or re-scaled
9commits change how a configuration is written
What stands out

Nothing broke. Everything moved.

Scanned areas: geofence, battery failsafe, arming checks, remote ID, flight termination, speed limits, obstacle avoidance, and the failsafe and return-to-launch parameters of Copter, Plane and Rover.

01

Units changed, and names with them

Multicopter return-to-launch, waypoint, loiter and avoidance parameters moved from centimetres and centidegrees to metres and degrees, and were renamed on the way: RTL_ALT became RTL_ALT_M, WPNAV_SPEED became WPNAV_SPD. Each commit ships an automatic conversion of stored values. A parameter file, a production script or a technical document that uses the old name or unit does not convert itself.

02

One bitmask changed meaning

ARMING_CHECK (checks to run) was replaced by ARMING_SKIPCHK (checks to skip). Skipping one check no longer disables the others, and new checks are on by default. For an integrator, "our pre-arm configuration" now means something different on paper.

03

The altitude fence got a reference frame

New parameters FENCE_ALT_MAX_TP and FENCE_ALT_MIN_TP set whether altitude limits are measured above home, sea level, the EKF origin or terrain (default: above home). The 120 m height limit of an EU class C1 or C2 drone usually lives in this fence.

04

Not a defect. A decision.

The changes are documented, reviewed and, where it matters, converted automatically. The point is the other side: each one lands on a manufacturer who has to decide, with evidence, whether its certified configuration and technical file still hold.

  • Return to launch4
  • Speed limits3
  • Failsafe (RC / GCS / EKF)2
  • Geofence2
  • Flight termination1
  • Remote ID1
  • Arming checks1
  • Battery failsafe1
  • Obstacle avoidance1
Every change, commit by commit

16 commits. Each line links to its proof.

"Changes the configuration": a parameter was added, removed, renamed, re-scaled or given a new default. "Metadata only": documented ranges, values or labels changed; they guide ground-station editors but are not enforced by the firmware.

Date · commitChangeEffect
2025-10-22
2a1bee26f
Return to launch · Coptercopter: pasram docs: fix range on `RTL_CONE_SLOPE`
  • RTL_CONE_SLOPE documented range: 0.5 10.0 → 0 10.0
Metadata only
2025-10-23
9ff7b9c34
Failsafe (RC / GCS / EKF) · Copterglobal: add Range to EKF failsafe param doc
  • FS_EKF_THRESH documented range: none → 0.0 1.0
  • FS_EKF_THRESH documented values: 0.6:Strict, 0.8:Default, 1.0:Relaxed → 0:Disabled, 0.6:Strict, 0.8:Default, 1.0:Relaxed
  • FS_EKF_THRESH documented range: none → 0.6 1.0
Metadata only
2025-10-23
27f6e9f20
Flight terminationglobal: add Range to pin number param doc
  • AFS_HB_PIN documented range: none → -1 127
  • AFS_TERM_PIN documented range: none → -1 127
Metadata only
2025-11-22
f29b062e4
Remote IDAP_OpenDroneID: rename EnforceArming to EnforcePreArmChecks (NFC)
  • DID_OPTIONS documented bitmask: 0:EnforceArming, 1:AllowNonGPSPosition, 2:LockUASIDOnFirstBasicIDRx → 0:EnforcePreArmChecks, 1:AllowNonGPSPosition, 2:LockUASIDOnFirstBasicIDRx
Metadata only
2025-12-04
436047600
Arming checksAP_Arming: turn ARMING_CHECK into ARMING_SKIPCHK
  • ARMING_CHECK default 1 → ARMING_SKIPCHK default 0 renamed
Changes the configuration
2026-01-13
6f0033af0
Failsafe (RC / GCS / EKF) · CopterArduCopter: fix spelling in FS_EKF_ACTION
  • FS_EKF_ACTION documented values: 0:Report only, 1:Switch to Land mode if current mode requires posti… → 0:Report only, 1:Switch to Land mode if current mode requires posit…
Metadata only
2026-01-23
5e32cdffc
Return to launch · CopterCopter: RTL params moved to class and use meters
  • RTL_ALT cm, range 30–300000, default 1500 → RTL_ALT_M m, range 0.30–3000, default 15 renamed · re-scaled
  • RTL_ALT_FINAL cm, range 0–1000, default 0 → RTL_ALT_FINAL_M m, range 0–10, default 0 renamed · re-scaled
  • RTL_CLIMB_MIN cm, range 0–3000, default 0 → RTL_CLIMB_MIN_M m, range 0–30, default 0 renamed · re-scaled
  • RTL_SPEED cm/s, range 0–2000, default 0 → RTL_SPEED_MS m/s, range 0–20, default 0 renamed · re-scaled
Changes the configuration
2026-01-26
9064927ed
Battery failsafeAP_BattMonitor: change "None" failsafe action to "Warn only"
  • BATT_FS_CRT_ACT documented values: {Copter}0:None,1:Land,2:RTL,3:SmartRTL or RTL,4:SmartRTL or Land,5:… → {Copter}0:Warn only,1:Land,2:RTL,3:SmartRTL or RTL,4:SmartRTL or La…
  • BATT_FS_LOW_ACT documented values: {Copter}0:None,1:Land,2:RTL,3:SmartRTL or RTL,4:SmartRTL or Land,5:… → {Copter}0:Warn only,1:Land,2:RTL,3:SmartRTL or RTL,4:SmartRTL or La…
Metadata only
2026-02-02
262876c60
Speed limitsAC_Loiter: re-scale parameters to meters
  • LOIT_ACC_MAX cm/s/s, range 100–981, default 500 → LOIT_ACC_MAX_M m/s/s, range 1–9.81, default 5 renamed · re-scaled
  • LOIT_BRK_ACCEL cm/s/s, range 25–250, default 250 → LOIT_BRK_ACC_M m/s/s, range 0.25–2.5, default 2.5 renamed · re-scaled
  • LOIT_SPEED cm/s, range 20–3500, default 1250 → LOIT_SPEED_MS m/s, range 0.20–35, default 12.5 renamed · re-scaled
Changes the configuration
2026-02-12
936baff2e
Speed limitsAC_WPNav: moved tradHeli default Loiter params and added condition for Trad Heli defaults
  • LOIT_BRK_ACC_M default now depends on the build: 1.25 or 2.5 (was 2.5 in this file)
  • LOIT_SPEED_MS default now depends on the build: 30 or 12.5 (was 12.5 in this file)
Changes the configuration
2026-02-24
6991d8e30
Speed limitsAC_WPNav: convert params to meters
  • WPNAV_ACCEL cm/s/s, range 50–500, default 250 → WPNAV_ACC m/s/s, range 0.50–5.00, default 2.5 renamed · re-scaled
  • WPNAV_ACCEL_C cm/s/s, range 0–500, default 0 → WPNAV_ACC_CNR m/s/s, range 0–5.00, default 0 renamed · re-scaled
  • WPNAV_ACCEL_Z cm/s/s, range 50–500, default 100 → WPNAV_ACC_Z m/s/s, range 0.50–5.00, default 1 renamed · re-scaled
  • WPNAV_SPEED cm/s, range 10–2000, default 1000 → WPNAV_SPD m/s, range 0.10–20.00, default 10 renamed · re-scaled
  • WPNAV_SPEED_DN cm/s, range 10–500, default 150 → WPNAV_SPD_DN m/s, range 0.10–10.00, default 1.5 renamed · re-scaled
  • WPNAV_SPEED_UP cm/s, range 10–1000, default 250 → WPNAV_SPD_UP m/s, range 0.10–10.00, default 2.5 renamed · re-scaled
Changes the configuration
2026-03-04
6eda48015
Obstacle avoidanceAC_Avoid: ANGLE_MAX converted to ANG_MAX
  • AVOID_ANGLE_MAX cdeg, range 0–4500, default 1000 → AVOID_ANG_MAX deg, range 0–45, default 10 renamed · re-scaled
Changes the configuration
2026-03-24
bd4e7e299
GeofenceAC_Fence: added FENCE_ALT_TYPE
  • FENCE_ALT_FRAME added default Location::AltFrame::ABOVE_HOME
Changes the configuration
2026-03-24
fe483aa8a
GeofenceAC_Fence: specify alt frame for min and max fences separately
  • FENCE_ALT_FRAME default Location::AltFrame::ABOVE_HOME → FENCE_ALT_MAX_TP default Location::AltFrame::ABOVE_HOME renamed
  • FENCE_ALT_MIN_TP added default Location::AltFrame::ABOVE_HOME
Changes the configuration
2026-08-03
9ec17d025
Return to launch · CopterCopter: RTL_CONE_SLOPE param desc gets angles
  • RTL_CONE_SLOPE documented values: 0:Disabled,1:Shallow,3:Steep → 0:Disabled,1:Shallow (45deg),3:Steep (72deg)
Metadata only
2026-09-08
a1f32da0b
Return to launch · PlanePlane: Quadplane: add a loiter stage in VTOL land approach with a loiter time of `Q_RTL_PAUSE_TIME`
  • Q_RTL_PAUSE_TIME added s, range 0–10, default 0
Changes the configuration
Method

Deterministic, and reproducible.

For every commit in the window that touched the scanned areas, we parsed the parameter definitions before and after the commit and compared default value, documented range, values, bitmask and units, resolving constants and enumerations to their numeric values. A removal and an addition with similar names in the same commit are shown as a rename.

Limits. This scan covers parameter definitions only. It does not see a behavioural change in code that does not touch a parameter, such as a new condition inside a failsafe routine. That is what checking each change against a rule document is for. Nothing here is a legal assessment of any product.

For manufacturers

Run this on your own firmware.

TraceGuard checks every firmware change against your own safety rules, inside your CI. Your code never leaves your infrastructure: it runs on your runner, with your model endpoint. We are looking for three design partners.