ARGOS LAB Start with an idea

20 / GROUND CONTROL STATION · HEARTBEAT · FAILSAFE

The ground station goes quiet.
The autopilot decides.

Stop sending the ground station’s heartbeat while keeping the vehicle’s telemetry visible. Replay the autopilot’s GCS heartbeat failsafe, inspect its configured LAND response, then restore heartbeat transmission.

Predict: can you still receive telemetry while the vehicle considers its ground station unavailable? Does restoring the heartbeat automatically restore Guided flight?

ArduPilot GCS heartbeat failsafe / fixed timeout.

Know the decision rule ↗
Detection / named mechanism
GCS heartbeat failsafe

The autopilot monitors ground-control-station heartbeats. Its configured timeout is 3 seconds; the recorded status message shows when the failsafe was actually reported.

Decision architecture / response
Autopilot-local decision → LAND

FS_GCS_ENABLE = 5 requests landing on GCS failsafe. The companion requests the initial flight; it sends no LAND command in the heartbeat-loss case.

Communication / direction
MAVLink heartbeat ≠ telemetry

GCS → vehicle heartbeats are suppressed for 8 seconds. Vehicle → recorder telemetry continues on the same local TCP connection. This tests a missing message stream, not radio propagation.

Execution / evidence
ArduCopter SITL · recorded replay

A simulated quadrotor runs the flight software and built-in dynamics. Status text, mode, altitude and landing state remain distinct observations; the browser does not run the failsafe.

Information boundary: the visible heartbeat age is host time since the last recorded GCS send, not time since the autopilot received it. The flight scene shows received autopilot estimates; there is no independent physical truth or simulated wireless range.

MISSING HEARTBEAT → REPORTED FAILSAFE → OBSERVED RESPONSE

Two directions. Different evidence.

Loading trace…
RECORDED ARDUPILOT SITL EXECUTIONValidating sends, status and telemetry…

These are separate real SITL executions. Buttons control replay and inspection.

Flight yard / GCS and received vehicle state
No vehicle heartbeatNo landed-state report
→ GCS heartbeat sends← Received vehicle telemetry● Autopilot pose estimate

Drag to orbit · scroll to zoom. The GCS and directional paths illustrate local messages, not radio coverage.

One cursor follows recorded sends and received evidence.

GCS 255:190 → autopilot 1:1
Autopilot 1:1 → recorder 255:190
Time since last GCS send—Recorder clock; not autopilot receipt age.
Reported GCS failsafeNot observedRequires recorded autopilot status.
Vehicle mode / armingUnknownNo vehicle heartbeat received.
Estimated height / above home—No altitude received.

SENDER AGE / RECORDED DETECTION

Silence grows. The autopilot reports.

Sawtooth: host time since the last outgoing GCS heartbeat. Dashed line: the configured 3-second timeout for context. Crossing that line here does not create a failsafe event.

Last GCS heartbeat / exact outgoing record

RECEIVED FLIGHT RESPONSE

LAND is a mode. Landing takes time.

Height is received GLOBAL_POSITION_INT relative altitude. A LAND mode report and a failsafe report are separate from the later on-ground and disarmed evidence.

AUTOPILOT STATUS / OBSERVED MESSAGES

Read the reported state changes.

Recorded STATUSTEXT messages received up to the cursor.
Receipt / sSeverityText
Failsafe observations / exact records

COMPANION REQUESTS / EXECUTION

Who requested the landing?

MAVLink command requests and acknowledgements observed by this cursor.
RequestSent / sResponseCompletion

Request envelope at the cursor
Recording provenance, failsafe parameters and completion criteria

Measured criteria

Imported metadata is untrusted provenance. Validation establishes internal consistency, not authenticity of the runtime.

TWO FRESH RUNS / COMPLETE-RECORD RESULTS

Telemetry can continue while the failsafe acts.

The table includes complete-run outcomes, including events beyond the current cursor. Only outgoing GCS heartbeat transmission changes during the observation window.

Fixed timeout and LAND configuration in both cases. Heartbeat loss is not a full TCP disconnect or a radio-range test.
Recorded caseGCS failsafeTelemetry during suppressionMode after restorationLanding decision / outcome

PREDICT · INSPECT · EXPLAIN

Trace silence through the decision.

01 / TWO DIRECTIONS

The display still updates.

Suppress GCS heartbeats, then inspect recent vehicle telemetry. Which direction is missing, and who detects that absence?

02 / LOCAL RESPONSE

The autopilot chooses LAND.

Inspect the failsafe text, the mode report and the request table. The loss run contains no companion LAND command.

03 / RESTORATION

Contact returns. The mode remains.

Restore the heartbeat, inspect the clear report and continue to landing. Clearing the failsafe does not itself request a return to Guided mode.

METHOD PROFILE / HEARTBEAT MONITORING

Detection, response
and recovery are separate.

GCS heartbeat failsafe is an autopilot mechanism for detecting a missing ground-station heartbeat after contact has been established. The response is selected by explicit ArduPilot parameters, here a fixed timeout and LAND.

MAVLink HEARTBEAT is directional: the ground station and vehicle each emit their own messages. Continuing to receive the vehicle’s heartbeat does not imply it is receiving the ground station’s heartbeat.

The visible terminal and antenna illustrate those roles. The actual experiment uses isolated local TCP, one built-in SITL quadrotor and sampled telemetry. No radio geometry, packet-loss distribution or physical hardware is represented.

GCS / companion 255:190
↓ HEARTBEAT · normally 1 Hz
ArduCopter 1:1 / GCS timeout 3 s
↓ reported GCS failsafe
Configured local response / LAND

↑ vehicle telemetry continues
↓ GCS heartbeat transmission restored
Reported failsafe clears ≠ Guided mode requested
Fixed timeout
The autopilot evaluates its own heartbeat receipt history. The browser shows recorded outgoing sends and received status; it cannot reconstruct the exact internal receipt timestamp from sender age alone.
LAND response
A mode change begins an action. The failsafe landing includes a pause before descent; flight-state and height reports show the actual response over time.
Restored heartbeat
The lost-contact condition can clear while LAND remains active. This experiment issues no automatic return-to-Guided request after restoration.

Record another local execution

Run npm run record:failsafe, then import the produced JSON file. The optional recorder owns an isolated simulated autopilot; this webpage sends no flight commands.

Primary sources: ArduPilot GCS failsafe, MAVLink heartbeat protocol and SITL simulator. Experiment assumptions and results are documented alongside the recorder.