Index: trunk/BNC/src/PPP/pppEphPool.cpp
===================================================================
--- trunk/BNC/src/PPP/pppEphPool.cpp	(revision 10953)
+++ trunk/BNC/src/PPP/pppEphPool.cpp	(revision 11047)
@@ -20,4 +20,5 @@
 #include "pppInclude.h"
 #include "pppClient.h"
+#include "bncephuser.h"
 
 using namespace BNC_PPP;
@@ -26,9 +27,28 @@
 //
 /////////////////////////////////////////////////////////////////////////////
+// Bad, outdated and unhealthy ephemerides are never used. Ephemerides from
+// RINEX navigation files (post-processing) never pass bncEphUser's checks and
+// stay "unchecked", so the health flag and the plausibility of the satellite
+// distance are checked here directly as well.
+/////////////////////////////////////////////////////////////////////////////
 void t_pppEphPool::putEphemeris(t_eph* eph) {
-  if (eph && (eph->checkState() != t_eph::bad ||
-              eph->checkState() != t_eph::unhealthy ||
-              eph->checkState() != t_eph::outdated))  {
-    _satEphPool[eph->prn().toInt()].putEphemeris(_maxQueueSize, eph);
+  if (!eph) {
+    return;
+  }
+  int iPrn = eph->prn().toInt();
+  if (iPrn == 0) { // satellite number out of range
+    delete eph;
+  }
+  else if (eph->checkState() == t_eph::unhealthy || eph->isUnhealthy()) {
+    _satEphPool[iPrn].setUnhealthy(eph);
+  }
+  else if (eph->checkState() == t_eph::unchecked && !bncEphUser::radialDistanceOk(eph)) {
+    LOG << "bad ephemeris " << eph->prn().toString() << ' ' << string(eph->TOC())
+        << " - implausible satellite distance, ignored" << endl;
+    delete eph;
+  }
+  else if (eph->checkState() != t_eph::bad &&
+           eph->checkState() != t_eph::outdated) {
+    _satEphPool[iPrn].putEphemeris(_maxQueueSize, eph);
   }
   else {
@@ -87,4 +107,23 @@
     delete eph;
   }
+}
+
+// A newer ephemeris declaring the satellite unhealthy: rejecting it alone
+// would leave the older, healthy ephemerides in the pool, and the satellite
+// would still be used with them - so they are all discarded, and the
+// satellite stays unused until a newer healthy ephemeris arrives.
+/////////////////////////////////////////////////////////////////////////////
+void t_pppEphPool::t_satEphPool::setUnhealthy(t_eph* eph) {
+  if (_ephs.empty() || eph->isNewerThan(_ephs.front())) {
+    if (!_ephs.empty()) {
+      LOG << "unhealthy ephemeris " << eph->prn().toString() << ' ' << string(eph->TOC())
+          << " - older ephemerides of this satellite discarded" << endl;
+    }
+    for (unsigned ii = 0; ii < _ephs.size(); ii++) {
+      delete _ephs[ii];
+    }
+    _ephs.clear();
+  }
+  delete eph;
 }
 
