textual-notation-of-model/packages/features/aebs/aebs_evidence.sysml

1 view(s) · 127 declared member(s) Jump to source ↓

view aebsNominalEvidenceAssuranceViewsource ↓

ViewpointselectedArgumentationAssuranceViewpoint (ArgumentationAssuranceViewpoint)
ConcernargumentationAssuranceConcern
RenderasTreeDiagram
ExposesDE4SDV_AEBSNominalEvidence::*
Sourcetextual-notation-of-model/packages/features/aebs/aebs_evidence.sysml:312
diagram-aebsNominalEvidenceAssuranceView.svg
«view» aebsNominalEvidenceAssuranceView expose DE4SDV_AEBSNominalEvidence::* «item def» CoordinatorRiskTelemetry «item def» NativeInterventionDiagnostic «item def» DriverOverrideSample «item def» DriverWarningRequest «item def» EmergencyBrakingRequest doc Direct nominal-path AEBS braking demand. This contract is distinct from EmergencyInterventionRequest and MinimumRiskManoeuvreRequest. No MRM request is produced or selected by the bounded 009B composition. «item def» EgoMotionObservation «item def» NominalGateCommand «item def» MapPosePair «item def» BrakingLifecycleState «item def» NominalObservationSet «item def» NominalEvaluation «port def» RiskTelemetryOutput items riskTelemetry : CoordinatorRiskTelemetry «port def» RiskTelemetryInput items riskTelemetry : CoordinatorRiskTelemetry «port def» InterventionDiagnosticOutput items interventionDiagnostic : NativeInterventionDiagnostic «port def» InterventionDiagnosticInput items interventionDiagnostic : NativeInterventionDiagnostic «port def» OverrideSampleInput items overrideSample : DriverOverrideSample «port def» WarningRequestOutput items warningRequest : DriverWarningRequest «port def» WarningRequestInput items warningRequest : DriverWarningRequest «port def» BrakingRequestOutput items brakingRequest : EmergencyBrakingRequest «port def» BrakingRequestInput items brakingRequest : EmergencyBrakingRequest «port def» EgoMotionInput items egoMotion : EgoMotionObservation «port def» EgoMotionOutput items egoMotion : EgoMotionObservation «port def» GateCommandOutput items gateCommand : NominalGateCommand «port def» GateCommandInput items gateCommand : NominalGateCommand «port def» MapPosePairOutput items mapPosePair : MapPosePair «port def» MapPosePairInput items mapPosePair : MapPosePair «port def» LifecycleStateOutput items lifecycleState : BrakingLifecycleState «port def» LifecycleStateInput items lifecycleState : BrakingLifecycleState «part def» NativeAutowareAEBRole doc Uses the pinned Autoware AEB implementation for target processing, RSS collision assessment, and the exact intervention diagnostic tuple only. ports riskTelemetryOut : RiskTelemetryOutput interventionDiagnosticOut : InterventionDiagnosticOutput «part def» NominalAEBSCoordinatorRole doc Bounded integration role. It derives warning requests from native RSS telemetry, requires a fresh source-stamped false override sample, recognizes only the exact native intervention tuple, emits the direct nominal-path braking request, and releases after continuously fresh held stop evidence. This is not the complete conceptual intervention-decision or emergency-intervention-coordination responsibility. ports riskTelemetryIn : RiskTelemetryInput interventionDiagnosticIn : InterventionDiagnosticInput overrideSampleIn : OverrideSampleInput egoMotionIn : EgoMotionInput warningRequestOut : WarningRequestOutput brakingRequestOut : BrakingRequestOutput lifecycleStateOut : LifecycleStateOutput «part def» NominalVehicleCommandGateRole doc Receives the coordinator-owned nominal control command with emergency handling disabled. The bounded composition does not select an MRM path. ports brakingRequestIn : BrakingRequestInput gateCommandOut : GateCommandOutput «part def» IndependentScenarioEvidenceObserverRole doc Preserves collector-monotonic observations, source stamps, runtime graph identity, and map poses. Replay checks the exact intervention tuple, override freshness, sole nominal publisher, no MRM publishers, continuously fresh stop evidence, and oriented footprint separation for the retained run. ports warningRequestIn : WarningRequestInput interventionDiagnosticIn : InterventionDiagnosticInput overrideSampleIn : OverrideSampleInput brakingRequestIn : BrakingRequestInput egoMotionIn : EgoMotionInput gateCommandIn : GateCommandInput mapPosePairIn : MapPosePairInput lifecycleStateIn : LifecycleStateInput «part def» NominalMovingVehicleTargetBench parts nativeAEB : NativeAutowareAEBRole coordinator : NominalAEBSCoordinatorRole nominalGate : NominalVehicleCommandGateRole evidenceObserver : IndependentScenarioEvidenceObserverRole ports overrideSampleIn : OverrideSampleInput egoMotionIn : EgoMotionInput mapPosePairIn : MapPosePairInput exhibit states brakingLifecycle «requirement def» NominalEvidenceContractRequirement «requirement» evidenceContractWarningLead : NominalEvidenceContractRequirement doc EC-AEBS-009B-01; System 2 evidence contract; method: retained evaluator replay. subject bench : NominalMovingVehicleTargetBench require constraints doc The replayed collector-monotonic warning request shall precede the exact native intervention diagnostic by at least 0.8 s. «requirement» evidenceContractFreshOverrideClear : NominalEvidenceContractRequirement doc EC-AEBS-009B-02; System 2 evidence contract; method: source-stamp and receipt-freshness analysis. subject bench : NominalMovingVehicleTargetBench require constraints doc Nominal 009B intervention evidence shall include a source-stamped false override sample that remains within the 0.2 s freshness bound at intervention. Conscious true override behavior is deferred to INC-AEBS-009D. «requirement» evidenceContractNominalBrakingPath : NominalEvidenceContractRequirement doc EC-AEBS-009B-03; System 2 evidence contract; method: runtime-graph and command replay. subject bench : NominalMovingVehicleTargetBench require constraints doc Runtime graph evidence shall periodically sample the coordinator as the sole nominal gate-input publisher and no MRM publishers from the accepted pre-intervention topology snapshot through verified-stop release, reject any contradictory sample, and reject any sampling gap above 1.0 s; the observed direct EmergencyBrakingRequest shall follow the paired exact native intervention diagnostic. «requirement» evidenceContractVerifiedStopRelease : NominalEvidenceContractRequirement doc EC-AEBS-009B-04; System 2 evidence contract; method: source-stamped odometry and lifecycle replay. subject bench : NominalMovingVehicleTargetBench require constraints doc Braking shall remain latched until each ego-odometry source stamp is replayed against a collector stamp from the same ROS clock and remains within 0.2 s, speed stays at or below 0.1 m/s for at least 0.5 s, and no receipt gap exceeds 0.2 s; release shall be absorbing for the one-shot scenario and independent of diagnostic retention. «requirement» evidenceContractIndependentNoncollision : NominalEvidenceContractRequirement doc EC-AEBS-009B-05; System 2 evidence contract; method: retained map-pose oriented-footprint analysis. subject bench : NominalMovingVehicleTargetBench require constraints doc For the retained run, replay shall compute the oriented footprint relation from preserved map poses, reject overlap or touching, require positive then opening separation, and require a fresh footprint relation covering release. «part» bench : NominalMovingVehicleTargetBench ports ^overrideSampleIn : OverrideSampleInput ^egoMotionIn : EgoMotionInput ^mapPosePairIn : MapPosePairInput exhibit states ^brakingLifecycle «verification def» NominalMovingVehicleTargetVerification doc Defines execution of the pinned Autoware software in a simulated moving-target environment, collects observations independently, replays the evidence contract, and returns a native verification verdict. The execution is a combined test-and-analysis verification method; it is not product validation, regulatory compliance evidence, or type-approval evidence. actions collectData processData evaluateData subject verifiedBench : NominalMovingVehicleTargetBench objective verify evidenceContractWarningLead verify evidenceContractFreshOverrideClear verify evidenceContractNominalBrakingPath verify evidenceContractVerifiedStopRelease verify evidenceContractIndependentNoncollision features verdict : VerdictKind = evaluateData.verdict «verification» nominalMovingVehicleTargetVerification : NominalMovingVehicleTargetVerification actions ^collectData ^processData ^evaluateData subject verifiedBench :> bench objective verify ^evidenceContractWarningLead verify evidenceContractFreshOverrideClear verify evidenceContractNominalBrakingPath verify evidenceContractVerifiedStopRelease verify evidenceContractIndependentNoncollision verification methods test analyze features ^verdict : VerdictKind = evaluateData.verdict «part» nominalVerificationSystem perform actions nominalMovingVehicleTargetVerification ::> nominalMovingVehicleTargetVerification «comment» These dependencies record relevance to draft System 1 product-requirement candidates only. They are neither verify nor satisfy relationships. The product candidates remain too broad to claim complete verification from this one bounded simulated scenario. «concern» physicalStructureConcern : PhysicalStructureConcern subject ref stakeholders systemsEngineer : SystemsEngineer reviewer : OpenSourceReviewer require constraints ^doc Reviewer question: What physical hardware, software, and mechanical elements make up the candidate system, and in which internal roles are they used? «concern» argumentationAssuranceConcern : ArgumentationAssuranceConcern doc Evidence-based assurance claims and their supporting argumentation. require constraints ^doc Reviewers need claims, arguments, evidence, and gaps linked in an assurance argument for the increment.

Hover a model element for details open raw SVG.

Source

1/*2 * DE4SDV INC-AEBS-009B nominal moving-vehicle-target evidence slice.3 *4 * This model records the bounded verification composition and evidence obligations5 * exercised by the executable bench. Its native verification case verifies only6 * the measurable System 2 evidence contracts defined here. Relevance links to7 * draft System 1 product-requirement candidates are neither verification nor8 * satisfaction claims. The model does not claim complete conceptual realization,9 * physical brake performance, regulatory compliance, certification,10 * homologation, or type approval.11 */1213package DE4SDV_AEBSNominalEvidence {14  private import VerificationCases::*;15  private import VerificationMethodKind::*;16  private import DE4SDV_AEBSNeedsRequirements::Features::AEBS::NeedsRequirements::*;17  private import SAF_Viewpoints::*;18  private import DE4SDV_Stakeholders::*;19  private import Views::*;202122  item def CoordinatorRiskTelemetry;23  item def NativeInterventionDiagnostic;24  item def DriverOverrideSample;25  item def DriverWarningRequest;26  item def EmergencyBrakingRequest {27    doc /*28     * Direct nominal-path AEBS braking demand. This contract is distinct from29     * EmergencyInterventionRequest and MinimumRiskManoeuvreRequest. No MRM30     * request is produced or selected by the bounded 009B composition.31     */32  }33  item def EgoMotionObservation;34  item def NominalGateCommand;35  item def MapPosePair;36  item def BrakingLifecycleState;37  item def NominalObservationSet;38  item def NominalEvaluation;3940  port def RiskTelemetryOutput {41    out item riskTelemetry : CoordinatorRiskTelemetry;42  }43  port def RiskTelemetryInput {44    in item riskTelemetry : CoordinatorRiskTelemetry;45  }46  port def InterventionDiagnosticOutput {47    out item interventionDiagnostic : NativeInterventionDiagnostic;48  }49  port def InterventionDiagnosticInput {50    in item interventionDiagnostic : NativeInterventionDiagnostic;51  }52  port def OverrideSampleInput {53    in item overrideSample : DriverOverrideSample;54  }55  port def WarningRequestOutput {56    out item warningRequest : DriverWarningRequest;57  }58  port def WarningRequestInput {59    in item warningRequest : DriverWarningRequest;60  }61  port def BrakingRequestOutput {62    out item brakingRequest : EmergencyBrakingRequest;63  }64  port def BrakingRequestInput {65    in item brakingRequest : EmergencyBrakingRequest;66  }67  port def EgoMotionInput {68    in item egoMotion : EgoMotionObservation;69  }70  port def EgoMotionOutput {71    out item egoMotion : EgoMotionObservation;72  }73  port def GateCommandOutput {74    out item gateCommand : NominalGateCommand;75  }76  port def GateCommandInput {77    in item gateCommand : NominalGateCommand;78  }79  port def MapPosePairOutput {80    out item mapPosePair : MapPosePair;81  }82  port def MapPosePairInput {83    in item mapPosePair : MapPosePair;84  }85  port def LifecycleStateOutput {86    out item lifecycleState : BrakingLifecycleState;87  }88  port def LifecycleStateInput {89    in item lifecycleState : BrakingLifecycleState;90  }9192  part def NativeAutowareAEBRole {93    doc /*94     * Uses the pinned Autoware AEB implementation for target processing, RSS95     * collision assessment, and the exact intervention diagnostic tuple only.96     */97    port riskTelemetryOut : RiskTelemetryOutput;98    port interventionDiagnosticOut : InterventionDiagnosticOutput;99  }100101  part def NominalAEBSCoordinatorRole {102    doc /*103     * Bounded integration role. It derives warning requests from native RSS104     * telemetry, requires a fresh source-stamped false override sample,105     * recognizes only the exact native intervention tuple, emits the direct106     * nominal-path braking request, and releases after continuously fresh held107     * stop evidence. This is not the complete conceptual intervention-decision or108     * emergency-intervention-coordination responsibility.109     */110    port riskTelemetryIn : RiskTelemetryInput;111    port interventionDiagnosticIn : InterventionDiagnosticInput;112    port overrideSampleIn : OverrideSampleInput;113    port egoMotionIn : EgoMotionInput;114    port warningRequestOut : WarningRequestOutput;115    port brakingRequestOut : BrakingRequestOutput;116    port lifecycleStateOut : LifecycleStateOutput;117  }118119  part def NominalVehicleCommandGateRole {120    doc /*121     * Receives the coordinator-owned nominal control command with emergency122     * handling disabled. The bounded composition does not select an MRM path.123     */124    port brakingRequestIn : BrakingRequestInput;125    port gateCommandOut : GateCommandOutput;126  }127128  part def IndependentScenarioEvidenceObserverRole {129    doc /*130     * Preserves collector-monotonic observations, source stamps, runtime graph131     * identity, and map poses. Replay checks the exact intervention tuple,132     * override freshness, sole nominal publisher, no MRM publishers, continuously133     * fresh stop evidence, and oriented footprint separation for the retained run.134     */135    port warningRequestIn : WarningRequestInput;136    port interventionDiagnosticIn : InterventionDiagnosticInput;137    port overrideSampleIn : OverrideSampleInput;138    port brakingRequestIn : BrakingRequestInput;139    port egoMotionIn : EgoMotionInput;140    port gateCommandIn : GateCommandInput;141    port mapPosePairIn : MapPosePairInput;142    port lifecycleStateIn : LifecycleStateInput;143  }144145  part def NominalMovingVehicleTargetBench {146    port overrideSampleIn : OverrideSampleInput;147    port egoMotionIn : EgoMotionInput;148    port mapPosePairIn : MapPosePairInput;149150    part nativeAEB : NativeAutowareAEBRole;151    part coordinator : NominalAEBSCoordinatorRole;152    part nominalGate : NominalVehicleCommandGateRole;153    part evidenceObserver : IndependentScenarioEvidenceObserverRole;154155    bind overrideSampleIn = coordinator.overrideSampleIn;156    bind overrideSampleIn = evidenceObserver.overrideSampleIn;157    bind egoMotionIn = coordinator.egoMotionIn;158    bind egoMotionIn = evidenceObserver.egoMotionIn;159    bind mapPosePairIn = evidenceObserver.mapPosePairIn;160161    flow from nativeAEB.riskTelemetryOut.riskTelemetry162      to coordinator.riskTelemetryIn.riskTelemetry;163    flow from nativeAEB.interventionDiagnosticOut.interventionDiagnostic164      to coordinator.interventionDiagnosticIn.interventionDiagnostic;165    flow from nativeAEB.interventionDiagnosticOut.interventionDiagnostic166      to evidenceObserver.interventionDiagnosticIn.interventionDiagnostic;167    flow from coordinator.warningRequestOut.warningRequest168      to evidenceObserver.warningRequestIn.warningRequest;169    flow from coordinator.brakingRequestOut.brakingRequest170      to nominalGate.brakingRequestIn.brakingRequest;171    flow from coordinator.brakingRequestOut.brakingRequest172      to evidenceObserver.brakingRequestIn.brakingRequest;173    flow from coordinator.lifecycleStateOut.lifecycleState174      to evidenceObserver.lifecycleStateIn.lifecycleState;175    flow from nominalGate.gateCommandOut.gateCommand176      to evidenceObserver.gateCommandIn.gateCommand;177178    exhibit state brakingLifecycle {179      doc /*180       * armed enters brakingLatched only after the exact native diagnostic and a181       * fresh false override evaluation. brakingLatched enters182       * releasedAfterVerifiedStop only after speed <= 0.1 m/s is continuously183       * observed with gaps <= 0.2 s for >= 0.5 s. The release state is absorbing184       * for this one-shot scenario and does not depend on diagnostic clearing.185       */186      state armed;187      state brakingLatched;188      state releasedAfterVerifiedStop;189    }190  }191192  requirement def NominalEvidenceContractRequirement;193194  requirement evidenceContractWarningLead : NominalEvidenceContractRequirement {195    doc /* EC-AEBS-009B-01; System 2 evidence contract; method: retained evaluator replay. */196    subject bench : NominalMovingVehicleTargetBench;197    require constraint {198      doc /* The replayed collector-monotonic warning request shall precede the exact native intervention diagnostic by at least 0.8 s. */199    }200  }201202  requirement evidenceContractFreshOverrideClear : NominalEvidenceContractRequirement {203    doc /* EC-AEBS-009B-02; System 2 evidence contract; method: source-stamp and receipt-freshness analysis. */204    subject bench : NominalMovingVehicleTargetBench;205    require constraint {206      doc /* Nominal 009B intervention evidence shall include a source-stamped false override sample that remains within the 0.2 s freshness bound at intervention. Conscious true override behavior is deferred to INC-AEBS-009D. */207    }208  }209210  requirement evidenceContractNominalBrakingPath : NominalEvidenceContractRequirement {211    doc /* EC-AEBS-009B-03; System 2 evidence contract; method: runtime-graph and command replay. */212    subject bench : NominalMovingVehicleTargetBench;213    require constraint {214      doc /* Runtime graph evidence shall periodically sample the coordinator as the sole nominal gate-input publisher and no MRM publishers from the accepted pre-intervention topology snapshot through verified-stop release, reject any contradictory sample, and reject any sampling gap above 1.0 s; the observed direct EmergencyBrakingRequest shall follow the paired exact native intervention diagnostic. */215    }216  }217218  requirement evidenceContractVerifiedStopRelease : NominalEvidenceContractRequirement {219    doc /* EC-AEBS-009B-04; System 2 evidence contract; method: source-stamped odometry and lifecycle replay. */220    subject bench : NominalMovingVehicleTargetBench;221    require constraint {222      doc /* Braking shall remain latched until each ego-odometry source stamp is replayed against a collector stamp from the same ROS clock and remains within 0.2 s, speed stays at or below 0.1 m/s for at least 0.5 s, and no receipt gap exceeds 0.2 s; release shall be absorbing for the one-shot scenario and independent of diagnostic retention. */223    }224  }225226  requirement evidenceContractIndependentNoncollision : NominalEvidenceContractRequirement {227    doc /* EC-AEBS-009B-05; System 2 evidence contract; method: retained map-pose oriented-footprint analysis. */228    subject bench : NominalMovingVehicleTargetBench;229    require constraint {230      doc /* For the retained run, replay shall compute the oriented footprint relation from preserved map poses, reject overlap or touching, require positive then opening separation, and require a fresh footprint relation covering release. */231    }232  }233234  part bench : NominalMovingVehicleTargetBench;235236  verification def NominalMovingVehicleTargetVerification {237    doc /*238     * Defines execution of the pinned Autoware software in a simulated moving-target239     * environment, collects observations independently, replays the evidence240     * contract, and returns a native verification verdict. The execution is a241     * combined test-and-analysis verification method; it is not product242     * validation, regulatory compliance evidence, or type-approval evidence.243     */244    subject verifiedBench : NominalMovingVehicleTargetBench;245246    objective nominalEvidenceObjective {247      verify evidenceContractWarningLead;248      verify evidenceContractFreshOverrideClear;249      verify evidenceContractNominalBrakingPath;250      verify evidenceContractVerifiedStopRelease;251      verify evidenceContractIndependentNoncollision;252    }253254    action collectData {255      @VerificationMethod{ kind = test; }256      doc /* The independent scenario observer collects typed runtime observations and provenance from the configured bench. */257      out item retainedObservations : NominalObservationSet;258    }259260    action processData {261      @VerificationMethod{ kind = analyze; }262      doc /* The repository validator reconstructs typed observations and independently replays the evaluator against the controlled scenario contract. */263      in item retainedObservations : NominalObservationSet = collectData.retainedObservations;264      out item replayedEvaluation : NominalEvaluation;265    }266267    action evaluateData {268      @VerificationMethod{ kind = analyze; }269      doc /* The replayed outcome and evidence-contract results are mapped to the verification verdict without treating a stored success label as evidence. */270      in item replayedEvaluation : NominalEvaluation = processData.replayedEvaluation;271      out verdict : VerdictKind;272    }273274    return verdict : VerdictKind = evaluateData.verdict;275  }276277  verification nominalMovingVehicleTargetVerification278    : NominalMovingVehicleTargetVerification {279    @VerificationMethod{ kind = (test, analyze); }280    subject verifiedBench :> bench;281  }282283  part nominalVerificationSystem {284    perform nominalMovingVehicleTargetVerification;285  }286287  /*288   * These dependencies record relevance to draft System 1 product-requirement289   * candidates only. They are neither verify nor satisfy relationships. The290   * product candidates remain too broad to claim complete verification from291   * this one bounded simulated scenario.292   */293  dependency warningEvidenceRelevantToWarningCandidate294    from evidenceContractWarningLead to reqProvideCollisionWarning;295  dependency overrideClearRelevantToBrakingCandidate296    from evidenceContractFreshOverrideClear to reqCommandEmergencyBraking;297  dependency overrideClearRelevantToOverrideCandidate298    from evidenceContractFreshOverrideClear to reqAllowDriverOverride;299  dependency brakingPathRelevantToBrakingCandidate300    from evidenceContractNominalBrakingPath to reqCommandEmergencyBraking;301302  concern physicalStructureConcern : PhysicalStructureConcern {303    subject;304    stakeholder systemsEngineer : SystemsEngineer;305    stakeholder reviewer : OpenSourceReviewer;306  }307308  concern argumentationAssuranceConcern : ArgumentationAssuranceConcern {309    doc /* Evidence-based assurance claims and their supporting argumentation. */310  }311312  view aebsNominalEvidenceAssuranceView {313    viewpoint selectedArgumentationAssuranceViewpoint : ArgumentationAssuranceViewpoint {314      frame argumentationAssuranceConcern;315    }316317    expose DE4SDV_AEBSNominalEvidence::*;318    render asTreeDiagram;319  }320}321