No send observed
Outgoing GCS HEARTBEAT messages are recorded at the sender.
20 / GROUND CONTROL STATION · HEARTBEAT · FAILSAFE
Stop sending the ground station’s heartbeat while keeping the vehicle’s telemetry visible. Replay the autopilot’s GCS heartbeat failsafe, inspect its configured LAND response, then restore heartbeat transmission.
Predict: can you still receive telemetry while the vehicle considers its ground station unavailable? Does restoring the heartbeat automatically restore Guided flight?
The autopilot monitors ground-control-station heartbeats. Its configured timeout is 3 seconds; the recorded status message shows when the failsafe was actually reported.
FS_GCS_ENABLE = 5 requests landing on GCS failsafe. The companion requests the initial flight; it sends no LAND command in the heartbeat-loss case.
GCS → vehicle heartbeats are suppressed for 8 seconds. Vehicle → recorder telemetry continues on the same local TCP connection. This tests a missing message stream, not radio propagation.
A simulated quadrotor runs the flight software and built-in dynamics. Status text, mode, altitude and landing state remain distinct observations; the browser does not run the failsafe.
Information boundary: the visible heartbeat age is host time since the last recorded GCS send, not time since the autopilot received it. The flight scene shows received autopilot estimates; there is no independent physical truth or simulated wireless range.
MISSING HEARTBEAT → REPORTED FAILSAFE → OBSERVED RESPONSE
These are separate real SITL executions. Buttons control replay and inspection.
Drag to orbit · scroll to zoom. The GCS and directional paths illustrate local messages, not radio coverage.
One cursor follows recorded sends and received evidence.
Outgoing GCS HEARTBEAT messages are recorded at the sender.
Received vehicle messages have their own receipt times.
SENDER AGE / RECORDED DETECTION
Sawtooth: host time since the last outgoing GCS heartbeat. Dashed line: the configured 3-second timeout for context. Crossing that line here does not create a failsafe event.
RECEIVED FLIGHT RESPONSE
Height is received GLOBAL_POSITION_INT relative altitude. A LAND mode report and a failsafe report are separate from the later on-ground and disarmed evidence.
AUTOPILOT STATUS / OBSERVED MESSAGES
| Receipt / s | Severity | Text |
|---|
COMPANION REQUESTS / EXECUTION
| Request | Sent / s | Response | Completion |
|---|
Imported metadata is untrusted provenance. Validation establishes internal consistency, not authenticity of the runtime.
TWO FRESH RUNS / COMPLETE-RECORD RESULTS
The table includes complete-run outcomes, including events beyond the current cursor. Only outgoing GCS heartbeat transmission changes during the observation window.
| Recorded case | GCS failsafe | Telemetry during suppression | Mode after restoration | Landing decision / outcome |
|---|
PREDICT · INSPECT · EXPLAIN
Suppress GCS heartbeats, then inspect recent vehicle telemetry. Which direction is missing, and who detects that absence?
Inspect the failsafe text, the mode report and the request table. The loss run contains no companion LAND command.
Restore the heartbeat, inspect the clear report and continue to landing. Clearing the failsafe does not itself request a return to Guided mode.
METHOD PROFILE / HEARTBEAT MONITORING
GCS heartbeat failsafe is an autopilot mechanism for detecting a missing ground-station heartbeat after contact has been established. The response is selected by explicit ArduPilot parameters, here a fixed timeout and LAND.
MAVLink HEARTBEAT is directional: the ground station and vehicle each emit their own messages. Continuing to receive the vehicle’s heartbeat does not imply it is receiving the ground station’s heartbeat.
The visible terminal and antenna illustrate those roles. The actual experiment uses isolated local TCP, one built-in SITL quadrotor and sampled telemetry. No radio geometry, packet-loss distribution or physical hardware is represented.
Run npm run record:failsafe, then import the produced JSON file. The optional recorder owns an isolated simulated autopilot; this webpage sends no flight commands.
Primary sources: ArduPilot GCS failsafe, MAVLink heartbeat protocol and SITL simulator. Experiment assumptions and results are documented alongside the recorder.