This is the multi-page printable view of this section. Click here to print.
Component Implementation
1 - McuErrInj Integration Manual
Integration Manual
For
McuErrInj
VERSION: 2.0
DATE: 24-Jul-2017
Prepared By:
Software Group,
Nexteer Automotive,
Saginaw, MI, USA
Location: The official version of this document is stored in the Nexteer Configuration Management System.
Revision History
| Sl. No. | Description | Author | Version | Date | 
| 1 | Initial version | Avinash James | 1.0 | 15-Mar-2017 | 
| 2 | Update to include the tursted function | Avinash James | 2.0 | 24-Jul-2017 | 
Table of Contents
3.2 Global Functions(Non RTE) to be provided to Integration Project 6
4 Configuration REQUIREMeNTS 7
4.2 Configuration Files to be provided by Integration Project 7
4.3 Da Vinci Parameter Configuration Changes 7
4.4 DaVinci Interrupt Configuration Changes 7
4.5 Manual Configuration Changes 7
5 Integration DATAFLOW REQUIREMENTS 8
5.1 Required Global Data Inputs 8
5.2 Required Global Data Outputs 8
5.3 Specific Include Path present 8
Abbrevations And Acronyms
| Abbreviation | Description | 
|---|---|
| DFD | Design functional diagram | 
| MDD | Module design Document | 
| FDD | Functional Design Document | 
References
This section lists the title & version of all the documents that are referred for development of this document
| Sr. No. | Title | Version | 
|---|---|---|
| 1 | FDD – DF003A McuDiagc | See Synergy subproject version | 
| 2 | Software Naming Conventions | Process 04.04.02 | 
| 3 | Software Coding Standards | Process 04.04.02 | 
Dependencies
SWCs
| Module | Required Feature | 
|---|---|
| None | |
Note : Referencing the external components should be avoided in most cases. Only in unavoidable circumstance external components should be referred. Developer should track the references.
Global Functions(Non RTE) to be provided to Integration Project
InjVrfyCritRegErr() – Function to Inject micro diagnostic error in Critical Registers
InjMcuVltgMonrErr() – Function to Inject micro diagnostic error in Core voltage monitor
InjClkMonrErr() – Function to Inject micro diagnostic error in Clock Monitors
InjOsTmpGenericRtErr () – Function to Inject Temporary Run time error in Operating System
InjOsPrmntGenericRtErr () – Function to Inject Permanent Run time error in Operating System
InjWdgErr () – Function to Watchdog errors
InjFpuErr () – Function to Inject floating point exceptions
InjMemProtnErr () – Function to Inject Memory protection errors
InjModErr () – Function to Inject mode errors
InjMcuRtErr () – Function to Inject Mcu Run Time errors
InjCodFlsEccErr() – Function to Inject Code flash ECC errors
InjRamMemErr( ) – Function to Inject peripheral and local RAM ECC errors
InjEcmMstChkrRtErr(void) () – Function to Inject micro diagnostic error in ECM Master and Slave
InjUkwnStrtUpDetdErr(void) -() – Function to Inject unknown startup
InjIpgRtErr(void) () – Function to Inject Run time IPG errors
InjRtPegErr(void) – Function to Inject Run time Peg errors
InjDataParErr() – Function to Inject Data Parity errors
InjDmaErr() – Function Dma errors
InjMcuDiagcErr() – Function to Inject loss ofmotor control ISR errors
InjAdcErr() – Function to Inject ADC errors
InjProgSeqErr () – Function to inject program sequence errors
InjPbgRtErr () - Function to inject PBG run time errors
InjSwFpuErr () – Function to inject software Floating point error
McuDiagcTestTrustd() – Trusted function call from OS
Configuration REQUIREMeNTS
Build Time Config
| Modules | Notes | |
|---|---|---|
| MCUDIAGCERRINJ | STD_OFF for other builds STD_ON for uDiag test builds | 
Configuration Files to be provided by Integration Project
None
Da Vinci Parameter Configuration Changes
| Parameter | Notes | SWC | 
|---|---|---|
| None | 
DaVinci Interrupt Configuration Changes
| ISR Name | VIM # | Priority Dependency | Notes | 
|---|---|---|---|
| None | 
Manual Configuration Changes
| Constant | Notes | SWC | 
|---|---|---|
| OS Memory protection has to be extended to include the reserved RAM & invalid memory area .Also execution from RAM need to be enabled too as per the settings below | 
(osuint32)0x0100a000UL, /* MPU region 3 */
(osuint32)0x0100bffcUL,
(osuint32)0x03ff00edUL,
(osuint32)0x10020000UL, /* MPU region 4 */
(osuint32)0x10020848UL,
(osuint32)0x03ff00dbUL,
(osuint32)0xfb000000UL, /* MPU region 5 */
(osuint32)0xfebdfffcUL,
(osuint32)0x03ff00d9UL,
(osuint32) 0xF3000000UUL, /* MPU region 6 */
(osuint32) 0xF4000000UL,
(osuint32)0x03ff00dbUL,
(osuint32)&osGlobalShared_StartAddr, /* MPU region Global shared*/
(osuint32)&osGlobalShared_EndAddr,
(osuint32)0x03ff00fbUL,
Integration DATAFLOW REQUIREMENTS
Required Global Data Inputs
Refer DataDict.m file
Required Global Data Outputs
Refer DataDict.m file
Specific Include Path present
Yes
Runnable Scheduling
This section specifies the required runnable scheduling.
| Init | Scheduling Requirements | Trigger | 
|---|---|---|
| McuDiagcInit1 | None | RTE (Init) | 
| Runnable | Scheduling Requirements | Trigger | 
|---|---|---|
| McuDiagcPer1 | None | RTE (2 ms) | 
| ClrErrInjReg_Oper | None | On invocation | 
| ReadErrInjReg_Oper | None | On invocation | 
| StrtErrInjCntr_Oper | None | On invocation | 
| UpdErrInjReg_Oper | None | On invocation | 
Memory Map REQUIREMENTS
Mapping
| Memory Section | Contents | Notes | 
|---|---|---|
| McuErrInj_START_SEC_VAR_INIT_128 | Data section for DMA write | |
| McuErrInjGlobalShared_START_SEC_VAR_CLEARED_32 | Global shared data access | 
* Each …START_SEC… constant is terminated by a …STOP_SEC… constant as specified in the AUTOSAR Memory Mapping requirements.
Usage
| Feature | RAM | ROM | 
|---|---|---|
| None | 
NvM Blocks
None
Compiler Settings
Preprocessor MACRO
None
Optimization Settings
None
Appendix
None
2 - McuErrInj Module Design Document
Module Design Document
For
McuErrInj
Jul 25, 2017
Prepared For:
Software Engineering
Nexteer Automotive,
Saginaw, MI, USA
Prepared By:
Software Group,
Nexteer Automotive,
Saginaw, MI, USAChange History
| Description | Author | Version | Date | 
| Initial Version | Avinash James | 1.0 | 15-Mar-2017 | 
| Added the global functions | Avinash James | 2.0 | 25-Jul-2017 | 
Table of Contents
2 McuDiagc & High-Level Description 6
3 Design details of software module 7
3.1 Graphical representation of McuDiagc 7
4.1 Program (fixed) Constants 8
5 Software Component Implementation 9
5.1.2.2 Store Module Inputs to Local copies 9
5.1.2.3 (Processing of function)……… 9
5.1.2.4 Store Local copy of outputs into Module Outputs 9
5.1.2.5 Store Local copy of outputs into Module Outputs 9
5.2.1.2 Store Module Inputs to Local copies 10
5.2.1.3 (Processing of function)……… 10
5.2.1.4 Store Local copy of outputs into Module Outputs 10
5.2.1.2 Store Module Inputs to Local copies 10
5.2.1.3 (Processing of function)……… 10
5.2.1.4 Store Local copy of outputs into Module Outputs 10
5.2.1.2 Store Module Inputs to Local copies 10
5.2.1.3 (Processing of function)……… 10
5.2.1.4 Store Local copy of outputs into Module Outputs 10
5.2.1.2 Store Module Inputs to Local copies 11
5.2.1.3 (Processing of function)……… 11
5.2.1.4 Store Local copy of outputs into Module Outputs 11
5.4 Module Internal (Local) Functions 11
5.5 GLOBAL Function/Macro Definitions 11
6 Known Limitations with Design 12
Appendix A Abbreviations and Acronyms 14
Introduction
Purpose
Module design document for Micro Controller Diagnostics Error Injection
McuDiagc & High-Level Description
Refer the Design.
Design details of software module
Graphical representation of McuDiagc

Data Flow Diagram
Component level DFD
N/A
Function level DFD
N/A
Constant Data Dictionary
Program (fixed) Constants
Embedded Constants
Local Constants
| Constant Name | Resolution | Units | Value | 
| MCUERRINJ_TESTRSTUKWN_CNT_U32 | 1 | Cnt | |
| SHIFTBYWORD_CNT_U08 | 1 | Cnt | 16U | 
| SHIFTBYBYTE_CNT_U08 | 1 | Cnt | 8U | 
| Refer .m file | 
Global
Currently the FDD has not been updated to show define the global constants. However the header file includes all the necessary global constants
Software Component Implementation
Sub-Module Functions
The sub-module functions are grouped based on similar functionality that needs to be executed in a given “State” of the system (refer States and Modes). For a given module, the MDD will identify the type and number of sub-modules required. The sub-module types are described below.
Init: McuErrInjInit1
Design Rationale
Refer to FDD
Module Outputs
Refer to FDD
Per: McuErrInjPer1
Design Rationale
None
Store Module Inputs to Local copies
Refer to FDD
(Processing of function)………
Refer to FDD
Store Local copy of outputs into Module Outputs
Refer to FDD
Store Local copy of outputs into Module Outputs
Refer to FDD
Server Runnable
ClrErrInjReg_Oper
Design Rationale
Refer FDD
Store Module Inputs to Local copies
Refer FDD
(Processing of function)………
Refer FDD
Store Local copy of outputs into Module Outputs
None
ReadErrInjReg_Oper
Design Rationale
Refer FDD. The function returns a 0 value in the case when the MCUERRINJ is defined as STD_OFF. This is done for static compliance as the actual functional code returns the value of BRAMDAT2 when MCUERRINJ is defined as STD_ON which is encapsulated under the compiler define and when its STD_OFF for the pointer variable to have a default value, we return 0.
Store Module Inputs to Local copies
Refer FDD
(Processing of function)………
Refer FDD
Store Local copy of outputs into Module Outputs
None
UpdErrInjReg_Oper
Design Rationale
Refer FDD
Store Module Inputs to Local copies
Refer FDD
(Processing of function)………
Refer FDD
Store Local copy of outputs into Module Outputs
None
StrtErrInjCntr
Design Rationale
Refer FDD
Store Module Inputs to Local copies
Refer FDD
(Processing of function)………
Refer FDD
Store Local copy of outputs into Module Outputs
None
Interrupt Functions
None
Module Internal (Local) Functions
None
GLOBAL Function/Macro Definitions
GLObAL Function #1
| Function Name | McuDiagcTestTrustd | Type | Min | Max | 
| Arguments Passed | None | |||
| Return Value | N/A | 
Description
Trusted function that performs the tests which need to run in supervisor mode of the processor as some tests needs register access at supervisor level.
GLObAL Functions
InjVrfyCritRegErr()
InjMcuVltgMonrErr()
InjClkMonrErr()
InjOsTmpGenericRtErr ()
InjOsPrmntGenericRtErr ()
InjWdgErr ()
InjFpuErr ()
InjMemProtnErr ()
InjModErr ()
InjMcuRtErr ()
InjProgSeqErr ()
InjPbgRtErr ()
InjRamErr()
InjEcmMstChkrRtErr()
InjUkwnStrtUpDetdErr()
InjIpgRtErr()
InjRtPegErr()
InjDataParErr()
InjDmaErr()
InjMcuDiagcErr()
InjAdcErr()
InjSwFpuErr()
Description
The above list is the list of global functions which are used for error injection which gets defined in multiple FDDs based of the NTC they are trying to set. These global functions are only enabled when the #define MCUDIAGCERRINJ is made STD_ON in the McuDiagcErrInj header file. So, DF003A FDD is the owner of these global functions though they are defined in multiple files. Return type and parameter lists are both void for the above defined ones
Known Limitations with Design
UNIT TEST CONSIDERATION
Abbreviations and Acronyms
| Abbreviation or Acronym | Description | 
|---|---|
| DFD | Design functional diagram | 
| MDD | Module design Document | 
Glossary
Note: Terms and definitions from the source “Nexteer Automotive” take precedence over all other definitions of the same term. Terms and definitions from the source “Nexteer Automotive” are formulated from multiple sources, including the following:
- ISO 9000 
- ISO/IEC 12207 
- ISO/IEC 15504 
- Automotive SPICE® Process Reference Model (PRM) 
- Automotive SPICE® Process Assessment Model (PAM) 
- ISO/IEC 15288 
- ISO 26262 
- IEEE Standards 
- SWEBOK 
- PMBOK 
- Existing Nexteer Automotive documentation 
| Term | Definition | Source | 
|---|---|---|
| MDD | Module Design Document | |
| DFD | Data Flow Diagram | 
References
| Ref. # | Title | Version | 
|---|---|---|
| 1 | AUTOSAR Specification of Memory Mapping (Link:AUTOSAR_SWS_MemoryMapping.pdf) | v1.3.0 R4.0 Rev 2 | 
| 2 | MDD Guideline | EA4 01.00.01 | 
| 3 | Software Naming Conventions.doc | 1.0 | 
| 4 | Software Design and Coding Standards.doc | 2.1 | 
| 5 | FDD – ES002A McuDiagc | See Synergy subproject version | 
3 - McuErrInj Peer Review Checklists
Overview
Summary SheetSynergy Project
Src - McuErrInj
MDD
PolySpace
Integration Manual
Sheet 1: Summary Sheet

Sheet 2: Synergy Project
Sheet 3: Src - McuErrInj
| Rev 1.2 | 8-Jun-15 | |||||||||||||||||||||||
| Peer Review Meeting Log (Source Code Review) | ||||||||||||||||||||||||
| Source File Name: | McuErrInj.c | Source File Revision: | 2 | |||||||||||||||||||||
| Header File Name: | McuErrInj.h | Header File Revision: | ||||||||||||||||||||||
| MDD Name: | McuErrInj Module Design Document.docx | Revision: | 2 | |||||||||||||||||||||
| FDD/SCIR/DSR/FDR/CM Name: | DF003A_McuErrInj_Design | Revision: | 1.2.0 | |||||||||||||||||||||
| Quality Check Items: | ||||||||||||||||||||||||
| Rationale is required for all answers of No | ||||||||||||||||||||||||
| Working EA4 Software Naming Convention followed: | ||||||||||||||||||||||||
| for variable names | Yes | Comments: | ||||||||||||||||||||||
| for constant names | Yes | Comments: | ||||||||||||||||||||||
| for function names | Yes | Comments: | ||||||||||||||||||||||
| for other names (component, memory | Yes | Comments: | ||||||||||||||||||||||
| mapping handles, typedefs, etc.) | ||||||||||||||||||||||||
| All paths assign a value to outputs, ensuring | N/A | Comments: | ||||||||||||||||||||||
| all outputs are initialized prior to being written | ||||||||||||||||||||||||
| Requirements Tracability tags in code match the requirements tracability in the FDD | N/A | Comments: | Not Required | |||||||||||||||||||||
| requirements tracability in the FDD | ||||||||||||||||||||||||
| All variables are declared at the function level. | No | Comments: | ||||||||||||||||||||||
| Global variable used in the error injection code.This wont be a part of the production code as it will be compiled out for regualare builds and available only for the special build testing | ||||||||||||||||||||||||
| Synergy version matches change history | Yes | Comments: | ||||||||||||||||||||||
| and Version Control version in file comment block | ||||||||||||||||||||||||
| Change log contains detailed description of changes | Yes | Comments: | ||||||||||||||||||||||
| and Work CR number | ||||||||||||||||||||||||
| Code accurately implements FDD (Document or Model) | Yes | Comments: | ||||||||||||||||||||||
| Verified no Compiler Errors or Warnings | Yes | Comments: | ||||||||||||||||||||||
| Component.h is included | Yes | Comments: | ||||||||||||||||||||||
| All other includes are actually needed. (System includes | Yes | Comments: | ||||||||||||||||||||||
| only allowed in Nexteer library components) | ||||||||||||||||||||||||
| Software Design and Coding Standards followed: | Version: 2.1 | |||||||||||||||||||||||
| Code comments are clear, correct, and adequate | Yes | Comments: | ||||||||||||||||||||||
| and have been updated for the change: [N40] and | ||||||||||||||||||||||||
| all other rules in the same section as rule [N40], | ||||||||||||||||||||||||
| plus [N75], [N12], [N23], [N33], [N37], [N38], | ||||||||||||||||||||||||
| [N48], [N54], [N77], [N79], [N72] | ||||||||||||||||||||||||
| Source file (.c and .h) comment blocks are per | Yes | Comments: | ||||||||||||||||||||||
| standards and contain correct information: [N41], [N42] | ||||||||||||||||||||||||
| Function comment blocks are per standards and | Yes | Comments: | ||||||||||||||||||||||
| contain correct information: [N43] | ||||||||||||||||||||||||
| Code formatting (indentation, placement of | Yes | Comments: | ||||||||||||||||||||||
| braces, etc.) is per standards: [N5], [N55], [N56], | ||||||||||||||||||||||||
| [N57], [N58], [N59] | ||||||||||||||||||||||||
| Embedded constants used per standards; no | Yes | Comments: | ||||||||||||||||||||||
| "magic numbers": [N12] | ||||||||||||||||||||||||
| Memory mapping for non-RTE code | Yes | Comments: | ||||||||||||||||||||||
| is per standard | ||||||||||||||||||||||||
| All execution-order-dependent code can be | N/A | Comments: | ||||||||||||||||||||||
| recognized by the compiler: [N80] | ||||||||||||||||||||||||
| All loops have termination conditions that ensure | N/A | Comments: | ||||||||||||||||||||||
| finite loop iterations: [N63] | ||||||||||||||||||||||||
| All divides protect against divide by zero | N/A | Comments: | ||||||||||||||||||||||
| if needed: [N65] | ||||||||||||||||||||||||
| All integer division and modulus operations | N/A | Comments: | ||||||||||||||||||||||
| handle negative numbers correctly: [N76] | ||||||||||||||||||||||||
| All typecasting and fixed point arithmetic, | N/A | Comments: | ||||||||||||||||||||||
| including all use of fixed point macros and | ||||||||||||||||||||||||
| timer functions, is correct and has no possibility | ||||||||||||||||||||||||
| of unintended overflow or underflow: [N66] | ||||||||||||||||||||||||
| All float-to-unsiged conversions ensure the. | N/A | Comments: | ||||||||||||||||||||||
| float value is non-negative: [N67] | ||||||||||||||||||||||||
| All conversions between signed and unsigned | N/A | Comments: | ||||||||||||||||||||||
| types handle msb==1 as intended: [N78] | ||||||||||||||||||||||||
| All pointer dereferencing protects against | N/A | Comments: | ||||||||||||||||||||||
| null pointer if needed: [N70] | ||||||||||||||||||||||||
| Component outputs are limited to the legal range | N/A | Comments: | ||||||||||||||||||||||
| defined in the FDD DataDict.m file : [N53] | ||||||||||||||||||||||||
| All code is mapped with FDD (all FDD | N/A | Comments: | ||||||||||||||||||||||
| subfunctions and/or model blocks identified | ||||||||||||||||||||||||
| with code comments; all code corresponds to | ||||||||||||||||||||||||
| some FDD subfunction and/or model block): [N40] | ||||||||||||||||||||||||
| Review did not identify violations of other | Yes | Comments: | ||||||||||||||||||||||
| coding standard rules | ||||||||||||||||||||||||
| Anomaly or Design Work CR created | N/A | Comments: | ||||||||||||||||||||||
| for any FDD corrections needed | ICR 10196 created for making the magic numbers as #defines | |||||||||||||||||||||||
| General Notes / Comments: | ||||||||||||||||||||||||
| Changes only reviewed | ||||||||||||||||||||||||
| Change Owner: | Avinash James | Review Date : | 07/26/17 | |||||||||||||||||||||
| Lead Peer Reviewer: | Krishna Anne | Approved by Reviewer(s): | Yes | |||||||||||||||||||||
| Other Reviewer(s): | ||||||||||||||||||||||||


