Twelve months of safety-parameter changes in ArduPilotand what a drone integrator had to review
If you ship a drone built on ArduPilot, every update pulls in changes to the parameters your safety case depends on. We scanned one year of ArduPilot master to see how often that happens.
2025-09-28 → 2026-09-28 · master at a11f7351
Nothing broke. Everything moved.
Scanned areas: geofence, battery failsafe, arming checks, remote ID, flight termination, speed limits, obstacle avoidance, and the failsafe and return-to-launch parameters of Copter, Plane and Rover.
Units changed, and names with them
Multicopter return-to-launch, waypoint, loiter and avoidance parameters moved from centimetres and centidegrees to metres and degrees, and were renamed on the way: RTL_ALT became RTL_ALT_M, WPNAV_SPEED became WPNAV_SPD. Each commit ships an automatic conversion of stored values. A parameter file, a production script or a technical document that uses the old name or unit does not convert itself.
One bitmask changed meaning
ARMING_CHECK (checks to run) was replaced by ARMING_SKIPCHK (checks to skip). Skipping one check no longer disables the others, and new checks are on by default. For an integrator, "our pre-arm configuration" now means something different on paper.
The altitude fence got a reference frame
New parameters FENCE_ALT_MAX_TP and FENCE_ALT_MIN_TP set whether altitude limits are measured above home, sea level, the EKF origin or terrain (default: above home). The 120 m height limit of an EU class C1 or C2 drone usually lives in this fence.
Not a defect. A decision.
The changes are documented, reviewed and, where it matters, converted automatically. The point is the other side: each one lands on a manufacturer who has to decide, with evidence, whether its certified configuration and technical file still hold.
- Return to launch4
- Speed limits3
- Failsafe (RC / GCS / EKF)2
- Geofence2
- Flight termination1
- Remote ID1
- Arming checks1
- Battery failsafe1
- Obstacle avoidance1
16 commits. Each line links to its proof.
"Changes the configuration": a parameter was added, removed, renamed, re-scaled or given a new default. "Metadata only": documented ranges, values or labels changed; they guide ground-station editors but are not enforced by the firmware.
| Date · commit | Change | Effect |
|---|---|---|
| 2025-10-22 2a1bee26f | Return to launch · Coptercopter: pasram docs: fix range on `RTL_CONE_SLOPE`
| Metadata only |
| 2025-10-23 9ff7b9c34 | Failsafe (RC / GCS / EKF) · Copterglobal: add Range to EKF failsafe param doc
| Metadata only |
| 2025-10-23 27f6e9f20 | Flight terminationglobal: add Range to pin number param doc
| Metadata only |
| 2025-11-22 f29b062e4 | Remote IDAP_OpenDroneID: rename EnforceArming to EnforcePreArmChecks (NFC)
| Metadata only |
| 2025-12-04 436047600 | Arming checksAP_Arming: turn ARMING_CHECK into ARMING_SKIPCHK
| Changes the configuration |
| 2026-01-13 6f0033af0 | Failsafe (RC / GCS / EKF) · CopterArduCopter: fix spelling in FS_EKF_ACTION
| Metadata only |
| 2026-01-23 5e32cdffc | Return to launch · CopterCopter: RTL params moved to class and use meters
| Changes the configuration |
| 2026-01-26 9064927ed | Battery failsafeAP_BattMonitor: change "None" failsafe action to "Warn only"
| Metadata only |
| 2026-02-02 262876c60 | Speed limitsAC_Loiter: re-scale parameters to meters
| Changes the configuration |
| 2026-02-12 936baff2e | Speed limitsAC_WPNav: moved tradHeli default Loiter params and added condition for Trad Heli defaults
| Changes the configuration |
| 2026-02-24 6991d8e30 | Speed limitsAC_WPNav: convert params to meters
| Changes the configuration |
| 2026-03-04 6eda48015 | Obstacle avoidanceAC_Avoid: ANGLE_MAX converted to ANG_MAX
| Changes the configuration |
| 2026-03-24 bd4e7e299 | GeofenceAC_Fence: added FENCE_ALT_TYPE
| Changes the configuration |
| 2026-03-24 fe483aa8a | GeofenceAC_Fence: specify alt frame for min and max fences separately
| Changes the configuration |
| 2026-08-03 9ec17d025 | Return to launch · CopterCopter: RTL_CONE_SLOPE param desc gets angles
| Metadata only |
| 2026-09-08 a1f32da0b | Return to launch · PlanePlane: Quadplane: add a loiter stage in VTOL land approach with a loiter time of `Q_RTL_PAUSE_TIME`
| Changes the configuration |
Deterministic, and reproducible.
For every commit in the window that touched the scanned areas, we parsed the parameter definitions before and after the commit and compared default value, documented range, values, bitmask and units, resolving constants and enumerations to their numeric values. A removal and an addition with similar names in the same commit are shown as a rename.
Limits. This scan covers parameter definitions only. It does not see a behavioural change in code that does not touch a parameter, such as a new condition inside a failsafe routine. That is what checking each change against a rule document is for. Nothing here is a legal assessment of any product.
Run this on your own firmware.
TraceGuard checks every firmware change against your own safety rules, inside your CI. Your code never leaves your infrastructure: it runs on your runner, with your model endpoint. We are looking for three design partners.