A Flight-Safety Proof Does Not Solve a Corridor Deadlock

SANDO’s formal collision guarantee addresses uncertain moving obstacles in unmapped airspace. A reported Open-RMF deployment problem shows the different operational challenge of getting robots to yield, reserve scarce space and continue making progress.

By Nia Okafor · disclosed fictional OMIKINA AI editorial persona · No human review recorded

Published

AI-persona disclosure

Fictional OMIKINA AI editorial persona; not a human reporter and does not possess human security credentials or firsthand experience.

AI-generated story-specific editorial illustration for A Flight-Safety Proof Does Not Solve a Corridor Deadlock.
AI-generated story-specific editorial illustration; not documentary evidence.

Key points

  • SANDO is reported to provide a mathematical collision-avoidance guarantee for a UAV in an unknown dynamic environment, contingent on knowing a maximum obstacle speed.

    Sources: S1

  • An Open-RMF user operating in a semiconductor fabrication facility reports repeated negotiations and loss of progress when robots meet in narrow bidirectional corridors, despite side bays and experiments with higher-level coordination.

    Sources: S2

  • The comparison separates two safety properties that can be confused in practice: avoiding contact with a moving hazard and ensuring that a fleet can allocate a constrained passage without indefinite waiting.

    Sources: S1 · S2

Two hazards, two kinds of assurance

A formal guarantee can be powerful without being universal. MIT’s SANDO planner is described as generating collision-free UAV trajectories in unmapped environments containing obstacles that may move unpredictably. Its stated premise is narrower than an all-purpose autonomy claim: the planner needs the maximum speed an obstacle could reach. From that bound, it represents the region an obstacle could occupy over time, builds a time-sensitive safety corridor outside those regions, and repeatedly reforms the flight path as the vehicle moves.

Sources: S1

The Open-RMF material describes a different failure mode. A user says its mobile robots operate in narrow, bidirectional semiconductor-facility corridors, with side bays in some locations and no alternative route in others. When robots approach from opposite directions, the user reports repeated negotiations and situations in which they stop making progress. This is not evidence of a collision in that deployment, nor is it a published result about Open-RMF’s capabilities. It is evidence that a fleet operator is encountering an unresolved coordination problem under a specific layout and configuration.

Sources: S2

The crucial distinction is between safety in the sense of non-contact and liveness in the sense of eventual movement. SANDO’s reported proof concerns collision avoidance under its motion-bound assumption. The corridor report asks whether robots can decide who enters, who yields, and where one waits so that shared space is released. A system can be conservative enough to prevent contact yet still leave both parties waiting; conversely, assigning an order to traverse a corridor does not itself establish that vehicle motion will remain collision-free.

Sources: S1 · S2

Sources: S1 · S2

What SANDO’s proof actually buys

SANDO’s design is aimed at an exposure that is acute for flight: a path that looks clear at planning time can become dangerous while the UAV is in motion. The reported method monitors and groups dynamic obstacles, uses their maximum velocity to bound their possible future position, constructs connected safe regions in three-dimensional space, and optimizes a path within that corridor. The researchers report collision avoidance in simulations and in test flights using onboard sensing and computation.

Sources: S1

That mechanism directly reduces uncertainty from obstacle motion, but it does so by turning an uncertain future into a bounded one. The safety statement therefore depends on the supplied maximum-speed information being appropriate for the obstacle behavior encountered. The supplied material does not establish how the system behaves if that bound is wrong, if sensing fails to detect an obstacle, or if vehicle-control limits prevent execution of the replanned path. Those are limits of the evidence packet, not findings that the system necessarily fails in those cases.

Sources: S1

SANDO also uses a heat-map planner to steer away from obstacle-dense areas and seeks a fast path after identifying its safe corridor. That is an efficiency strategy inside a collision-safe formulation. It should not be read as evidence that the system resolves competition among independent agents with incompatible goals, priority policies, or commitments to occupy a scarce route. The evidence instead frames its central task as a single UAV reacting safely while discovering a dynamic environment.

Sources: S1

Sources: S1

A corridor is a resource, not merely an obstacle field

The fleet scenario makes the dependency concrete. In a one-robot-wide corridor, the safety of each robot’s local motion depends on a shared decision about admission and traversal order. Side bays can create places to yield, but the user’s account indicates that their presence alone has not produced reliable coordination. The operator says it has tried an arbiter above RMF, changes to the traffic cost function, and local multi-agent path-finding-based joint planning, while still being unsure what should change.

Sources: S2

Inference: the reported deadlock-like behavior is most usefully treated as a resource-allocation and recovery problem before it is treated as a trajectory-optimization problem. An admission rule can prevent opposing robots from committing to a passage at the same time; a yielding rule can specify which robot retreats or waits; and a recovery rule can break a stalled negotiation. This inference follows from the operator’s description of bidirectional single-robot corridors, yielding bays, and repeated negotiations, rather than from a documented Open-RMF recommendation.

Sources: S2

That inference does not establish that an explicit reservation mechanism is required by Open-RMF, or that cost-function tuning and joint planning cannot solve the deployment’s problem. The supplied forum post asks precisely whether existing planning and negotiation can handle passing, whether reservation is advisable, and whether the proposed approaches are appropriate. It provides no maintainer response, navigation graph, reproducible case, software configuration, or measured outcome. A design decision should therefore not be presented as settled platform guidance.

Sources: S2

Sources: S2

Prevention needs a recovery path

The broader system lesson is that prevention controls should be paired with a defined response when their assumptions no longer hold. For SANDO, the reported control is frequent replanning within time-varying safe corridors as obstacles move. For the corridor case, the stated operational symptom is that negotiation can repeat without progress. The relevant recovery question is not only whether the robots avoid each other, but how the fleet detects a stalled state, selects a robot to yield, and restores usable capacity without creating a new conflict.

Sources: S1 · S2

What would change this assessment is specific evidence on both sides: a formal liveness or deadlock-freedom property for the relevant Open-RMF configuration; a reproducible corridor graph showing bay locations, robot footprints, timing and negotiation traces; and results after a defined admission or yielding policy. For SANDO, the most decision-relevant additions would be the exact assumptions behind its safety proof, including sensing and vehicle-execution conditions, plus trials that test those boundaries. Until then, the prudent reading is narrow: SANDO offers reported formal protection against a bounded-motion collision threat, while the fleet report exposes an unproven operational need to make shared-corridor progress recoverable.

Sources: S1 · S2

Sources: S1 · S2

Why it matters

Robotics buyers and operators should not collapse “formally safe” into “operationally reliable.” A collision-avoidance proof can materially reduce physical risk under defined assumptions, while a fleet still needs policies and recovery mechanisms for contention over space. Evaluating both properties separately makes it easier to identify which exposure a proposed control actually reduces.

Sources: S1 · S2

Sources

  1. 'SANDO' system ensures a robot's flight path will remain collision-free in uncharted territory — Tech Xplore Robotics ·
  2. Guidance on robot coordination in narrow bidirectional corridors with yielding bays — Open Robotics Discourse ·

Editorial standards · Corrections