robotics//drone//autopilot

An autopilot is the onboard software and computer that estimates a drone's state and closes its control loops, from motor commands up to missions, and it is what turns a frame with four motors into an aircraft that holds position in the wind, follows waypoints and lands itself when something goes wrong. The open stacks **PX4** (on the NuttX RTOS) and **ArduPilot** (on ChibiOS) run on flight controllers of the **Pixhawk** family, built around an STM32 Cortex-M at a few hundred MHz; **Betaflight** serves racing drones.


An autopilot is the onboard software and computer that estimates a drone's state and closes its control loops, from motor commands up to missions, and it is what turns a frame with four motors into an aircraft that holds position in the wind, follows waypoints and lands itself when something goes wrong. The open stacks PX4 (on the NuttX RTOS) and ArduPilot (on ChibiOS) run on flight controllers of the Pixhawk family, built around an STM32 Cortex-M at a few hundred MHz; Betaflight serves racing drones.

The autopilot loop architecture runs each loop at the rate its dynamics demands, faster the further inside it sits, as a cascade. Motor commutation runs at tens of kHz in each ESC. The IMU is read and filtered at 1 kHz from an internal sample rate of several kHz, low delay being the point. Attitude and rate control run at about 500 Hz for a loop bandwidth of tens of Hz. The estimator (an EKF) runs at 100 to 250 Hz, because its covariance update is expensive and GNSS and barometer arrive more slowly anyway. Position and velocity control run at about 50 Hz, since translation is slower than rotation. Planning and obstacle avoidance run at 1 to 10 Hz on a companion computer that sends setpoints to the autopilot at 20 to 50 Hz. Two rules produce those numbers: sample 10 to 30 times faster than the closed-loop bandwidth you want, and remember that every millisecond of delay costs phase.

The PX4 control architecture makes the cascade concrete: proportional on position, PID on velocity, proportional on attitude, PID on angular rate, then the motor mixer. Betaflight in acro mode closes only the rate loop, at several kHz, and the pilot is the outer loop.

The autopilot EKF carries about 24 states (attitude, velocity, position, gyro and accelerometer biases, magnetic field, wind) and fuses each delayed GNSS fix at its own timestamp before projecting forward with the IMU (delayed measurements).

Both stacks are developed in simulation with the code that flies: software-in-the-loop against Gazebo, logs replayed through new estimators, faults injected (X-in-the-loop testing).

The link-loss failsafe is the plan for when the radio goes quiet: hold position, return home or land, configurable together with failsafes for low battery, GNSS loss and geofence breach. In a fleet their collective effect matters: fifty drones returning home at once by the same route are a new problem (fail-safe design).

Telemetry and commands travel over MAVLink; the fast loops never leave the vehicle.