This is the multi-page printable view of this section. Click here to print.

Return to the regular view of this page.

Component Implementation

1 - VrfyCritReg_IntegrationManual

Integration Manual

For

VrfyCritReg

VERSION: 4.0

DATE: 22-May-2017

Prepared By:

Software Group,

Nexteer Automotive,

Saginaw, MI, USA

Location: The official version of this document is stored in the Nexteer Configuration Management System.

Revision History

Sl. No.DescriptionAuthorVersionDate
1Initial versionSankardu Varadapureddi1.014-Jan-2016
2Updated to “ Critical register” checks at init and periodic functionsSelva Sengottaiyan214-Apr-2016
3Updated for micro diag special build parameterAvinash James3.020-Feb-2017
4Added support for MCAl write verify featureAvinash James4.022-May-2017

Table of Contents

1 Abbrevations And Acronyms 4

2 References 5

3 Dependencies 6

3.1 SWCs 6

3.2 Global Functions(Non RTE) to be provided to Integration Project 6

4 Configuration REQUIREMeNTS 7

4.1 Build Time Config 7

4.2 Configuration Files to be provided by Integration Project 7

4.3 Da Vinci Parameter Configuration Changes 7

4.4 DaVinci Interrupt Configuration Changes 7

4.5 Manual Configuration Changes 7

5 Integration DATAFLOW REQUIREMENTS 8

5.1 Required Global Data Inputs 8

5.2 Required Global Data Outputs 8

5.3 Specific Include Path present 8

6 Runnable Scheduling 9

7 Memory Map REQUIREMENTS 10

7.1 Mapping 10

7.2 Usage 10

7.3 NvM Blocks 10

8 Compiler Settings 11

8.1 Preprocessor MACRO 11

8.2 Optimization Settings 11

9 Appendix 12

Abbrevations And Acronyms

AbbreviationDescription
DFDDesign functional diagram
MDDModule design Document

References

This section lists the title & version of all the documents that are referred for development of this document

Sr. No.TitleVersion
1FDD : CM111A_VrfyCritReg _DesignSee Synergy sub project version
2Software Naming ConventionsProcess 4.04.02
3Software Design and Coding StandardsProcess 4.04.02

Dependencies

SWCs

ModuleRequired Feature
None

Global Functions(Non RTE) to be provided to Integration Project

CritRegIninChk--- Needs to be trusted function because it needs to run in supervisor mode

CritRegPerChk--- Needs to be trusted function because it needs to run in supervisor mode

Configuration REQUIREMeNTS

Build Time Config

ModulesNotes
MCUDIAGCERRINJ

STD_ON for micro diagnostic special build

STD_OFF for all other builds

Configuration Files to be provided by Integration Project

CDD_VrfyCritReg_Cfg.c

CDD_VrfyCritReg_Cfg_private.h

Da Vinci Parameter Configuration Changes

ParameterNotesSWC
/Nexteer/VrfyCritReg/VrfySysCritRegInitSignallist

System Critical registers with 32 bit Access that needs to checked at Init

function

/Nexteer/VrfyCritReg/VrfySysCritRegPerSignallistSystem Critical registers with 32 bit Access that needs to checked periodically
/Nexteer/VrfyCritReg/VrfyCritReg32bitPerSignallistCritical registers with 32 bit Access that needs to checked periodically
/Nexteer/VrfyCritReg/VrfyCritReg32bitInitSignallistCritical registers with 32 bit Access that needs to checked at Initialisation
/Nexteer/VrfyCritReg/VrfyCritReg16bitPerSignallistCritical registers with 16 bit Access that needs to checked periodically
/Nexteer/VrfyCritReg/VrfyCritReg16bitInitSignallistCritical registers with 32 bit Access that needs to checked at Initialisation
/Nexteer/VrfyCritReg/VrfyCritReg8bitPerSignallistCritical registers with 8 bit Access that needs to checked periodically
/Nexteer/VrfyCritReg/VrfyCritReg8bitInitSignallistCritical registers with 32 bit Access that needs to checked at Initialisation

Note:

Refer the CM010 RH850 Static Register Evaluation.xlsm for configuration of critical registers

Refer the Appendix below for the steps involved in generating “Da Vinci Configuration files needed for critical register check “ from the Script.

DaVinci Interrupt Configuration Changes

ISR NameVIM #Priority DependencyNotes
None

Manual Configuration Changes

ConstantNotesSWC
None

Integration DATAFLOW REQUIREMENTS

Required Global Data Inputs

None

Required Global Data Outputs

None

Specific Include Path present

Yes.

Runnable Scheduling

This section specifies the required runnable scheduling.

InitScheduling RequirementsTrigger
VrfyCritRegInit1NoneRTE (Init)
RunnableScheduling RequirementsTrigger
VrfyCritRegPer1NoneRTE (10ms)
VrfyCritRegPer2NoneRTE (100ms)
MCalReadVrfyFailFltInfo_OperNoneOn invocation

Memory Map REQUIREMENTS

Mapping

Memory SectionContentsNotes
None

* Each …START_SEC… constant is terminated by a …STOP_SEC… constant as specified in the AUTOSAR Memory Mapping requirements.

Usage

FeatureRAMROM
None

Table 1: ARM Cortex R4 Memory Usage

NvM Blocks

MCalWrVrfyRegFltInfoStorg Compiler Settings

Preprocessor MACRO

None.

Optimization Settings

None.

Appendix

Steps to generate CDD_VrfyCritReg_Cfg:

  1. Run CriticalRegisterGenerator.py (Script will be placed along with Excel RH850 Static Register Evaluation)

  2. The input for this Generator tool is the Excel Sheet RH850 Static Register Evaluation

  3. OUTPUT Generated will be “CDD_VrfyCritReg_Cfg.arxml “ and rename it as “EPS_VrfyCritReg_ecuc.arxml” or corresponding .arxml name that matches project

2 - VrfyCritReg_MDD

Module Design Document

For

VrfyCritReg

May 24, 2017

Prepared For:

Software Engineering

Nexteer Automotive,

Saginaw, MI, USA

Prepared By:

Selva Sengottaiyan

Nexteer Automotive,

Saginaw, MI, USA
Change History

DescriptionAuthorVersionDate
Initial VersionSankardu Varadapureddi114-Jan-2016
Updated to “ Critical register” checks at init and periodic functionsSelva Sengottaiyan214-Apr-2016
Updated to include support for MCAL write verify failuresAvinash James324-May-2017


Table of Contents

1 Introduction 5

1.1 Purpose 5

1.2 Scope 5

2 VrfyCritReg High-Level Description 6

3 Design details of software module 7

3.1 Graphical representation of VrfyCritReg 7

3.2 Data Flow Diagram 7

3.2.1 Component level DFD 7

3.2.2 Function level DFD 7

4 Constant Data Dictionary 8

4.1 Program (fixed) Constants 8

4.1.1 Embedded Constants 8

5 Software Component Implementation 9

5.1 Sub-Module Functions 9

5.1.1 Init: VrfyCritRegInit1 9

5.1.1.1 Design Rationale 9

5.1.1.2 Module Outputs 9

5.1.2 Per: VrfyCritRegPer1 9

5.1.2.1 Design Rationale 9

5.1.2.2 Store Module Inputs to Local copies 9

5.1.2.3 (Processing of function)……… 9

5.1.2.4 Store Local copy of outputs into Module Outputs 9

5.2 Server Runables 9

5.3 Interrupt Functions 9

5.4 Module Internal (Local) Functions 9

5.4.1 Local Function #2 9

5.4.1.1 Description 9

5.5 GLOBAL Function/Macro Definitions 10

6 Known Limitations with Design 11

7 UNIT TEST CONSIDERATION 12

Appendix A Abbreviations and Acronyms 13

Appendix B Glossary 14

Appendix C References 15

Introduction

Purpose

Scope

VrfyCritReg High-Level Description

Refer to FDD

Design details of software module

Graphical representation of VrfyCritReg

Data Flow Diagram

Refer FDD

Component level DFD

Function level DFD

Constant Data Dictionary

Program (fixed) Constants

Embedded Constants

Refer .m file

Local Constants

Constant NameData TypeValue
SYSCRITREGFLT_CNT_U08uint82
CRITREGFLT_CNT_U08uint81
NOFLT_CNT_U08uint80
SHIFTBYBYTE_CNT_U08uint88
VRFYCRITREGMCALFLT_CNT_U08uint84

Software Component Implementation

Sub-Module Functions

Init: VrfyCritRegInit1

Design Rationale

Refer FDD

Module Outputs

None

Per: VrfyCritRegPer1

Design Rationale

Refer FDD

Store Module Inputs to Local copies

None

(Processing of function)………

Refer FDD

Store Local copy of outputs into Module Outputs

None

Per: VrfyCritRegPer2

Design Rationale

Refer FDD

Store Module Inputs to Local copies

None

(Processing of function)………

Refer FDD

Store Local copy of outputs into Module Outputs

None

Server Runables: MCalReadVrfyFailFltInfo_Oper

Design Rationale

Refer FDD

Store Module Inputs to Local copies

None

(Processing of function)………

Refer FDD

Store Local copy of outputs into Module Outputs

None

Interrupt Functions

None

Module Internal (Local) Functions

Local Function #1

Function NameSysCritReg<Register Short Name>IninChkTypeMinMax
Arguments PassedNA
Return Value&SysRegsOk_Uls_T_lgcbooleanFALSETRUE

Description

Set ' SysRegsOk_Uls_T_lgc to FALSE if CPU System Register values are not equal to expected values. This is configured to be called from trusted function because it needs to run in supervisor mode

Local Function #2

Function NameSysCritReg<Register Short Name>PerChkTypeMinMax
Arguments PassedNA
Return Value&SysRegsOk_Uls_T_lgcbooleanFALSETRUE

Description

Set ' SysRegsOk_Uls_T_lgc to FALSE if CPU System Register values are not equal to expected values. This is configured to be called from trusted function because it needs to run in supervisor mode

GLOBAL Function/Macro Definitions

Global Function #1

Function NameCritRegPerChkTypeMinMax
Arguments PassedNA
Return ValueNtcParamInfo_Cnt_T_u08uint80U2U

Description

Set ' NtcParamInfo_Cnt_T_u08 to 1 if CPU Non System Register values are not equal to expected values. Set ' NtcParamInfo_Cnt_T_u08 to 2 if CPU System Register values are not equal to expected values. Set ' NtcParamInfo_Cnt_T_u08 to 0 if none of the above conditions are true. This is configured as a trusted function because it needs to run in supervisor mode

Global Function #2

Function NameCritRegInitChkTypeMinMax
Arguments PassedNA
Return ValueNtcParamInfo_Cnt_T_u08uint80U2U

Description

Set ' NtcParamInfo_Cnt_T_u08 to 1 if CPU Non System Register values are not equal to expected values. Set ' NtcParamInfo_Cnt_T_u08 to 2 if CPU System Register values are not equal to expected values. Set ' NtcParamInfo_Cnt_T_u08 to 0 if none of the above conditions are true. This is configured as a trusted function because it needs to run in supervisor mode

Global Function #3

Function NameSysCritRegIninChkTypeMinMax
Arguments PassedNA
Return ValueSysRegsOk_Uls_T_lgcbooleanFALSETRUE

Description

Set ' SysRegsOk_Uls_T_lgc to FALSE if CPU System Register values are not equal to expected values. This is configured to be called from trusted function because it needs to run in supervisor mode

Global Function #4

Function NameSysCritRegPerChkTypeMinMax
Arguments PassedNA
Return ValueSysRegsOk_Uls_T_lgcbooleanFALSETRUE

Description

Set ' SysRegsOk_Uls_T_lgc to FALSE if CPU System Register values are not equal to expected values. This is configured to be called from trusted function because it needs to run in supervisor mode

Known Limitations with Design

UNIT TEST CONSIDERATION

None

Abbreviations and Acronyms

Abbreviation or AcronymDescription

Glossary

Note: Terms and definitions from the source “Nexteer Automotive” take precedence over all other definitions of the same term. Terms and definitions from the source “Nexteer Automotive” are formulated from multiple sources, including the following:

  • ISO 9000

  • ISO/IEC 12207

  • ISO/IEC 15504

  • Automotive SPICE® Process Reference Model (PRM)

  • Automotive SPICE® Process Assessment Model (PAM)

  • ISO/IEC 15288

  • ISO 26262

  • IEEE Standards

  • SWEBOK

  • PMBOK

  • Existing Nexteer Automotive documentation

TermDefinitionSource
MDDModule Design Document
DFDData Flow Diagram

References

Ref. #TitleVersion
1AUTOSAR Specification of Memory Mapping (Link:AUTOSAR_SWS_MemoryMapping.pdf)v1.3.0 R4.0 Rev 2
2MDD GuidelineSoftware Engineering Process 04.04.02
3Software Naming Conventions.docSoftware Engineering Process 04.04.02
4Software Design and Coding Standards.docSoftware Engineering Process 04.04.02
5FDD : CM111A_VrfyCritReg_DesignSee Synergy sub project version

3 - VrfyCritReg_Review


Overview

Summary Sheet
Synergy Project
Source Code
PolySpace


Sheet 1: Summary Sheet
























Rev 1.28-Jun-15

Peer Review Summary Sheet


























Synergy Project Name:


kzshz2: Intended Use: Identify which component is being reviewed. This should be the Module Short Name from Synergy Rationale: Required for traceability. It will help to ensure this form is not attaced to the the wrong change request. CM111A_VrfyCritReg_Impl
Revision / Baseline:


kzshz2: Intended Use: Identify which Synergy revision of this component is being reviewed Rationale: Required for traceability. It will help to ensure this form is not attaced to the the wrong change request. CM111A_VrfyCritReg_Impl_4.2.0

























Change Owner:


kzshz2: Intended Use: Identify the developer who made the change(s) Rationale: A change request may have more than one resolver, this will help identify who made what change. Change owner identification may be required by indusrty standards. Avinash James
Work CR ID:


EA4#12744





























kzshz2: Intended Use: Intended to identify at a high level to the reviewers which areas of the component have been changed. Rationale: This will be good information to know when ensuring appropriate reviews have been completed. Modified File Types:















































































































































































kzshz2: Intended Use: Identify who where the reviewers, what they reviewed, and if the reviewed changes have been approved to release the code for testing. Comments here should be at a highlevel, the specific comments should be present on the specific review form sheet. Rationale: Since this Form will be attached to the Change Request it will confirm the approval and provides feedback in case of audits. ADD DR Level Move reviewer and approval to individual checklist form Review Checklist Summary:






















































Reviewed:































N/AMDD


YesSource Code


YesPolySpace









































N/AIntegration Manual


N/ADavinci Files








































































Comments:






























































































General Guidelines:
- The reviews shall be performed over the portions of the component that were modified as a result of the Change Request.
- New components should include FDD Owner and Integrator as apart of the Group Review Board (Source Code, Integration Manual, and Davinci Files)
- Enter any rework required into the comment field and select No. When the rework is complete, review again using this same review sheet and select Yes. Add date and additional comment stating that the rework is completed.
- To review a component with multiple source code files use the "Add Source" button to create a Source code tab for each source file.
- .h file should be reviewed with the source file as part of the source file.





















Sheet 2: Synergy Project

Peer Review Meeting Log (Component Synergy Project Review)



















































Quality Check Items:




































Rationale is required for all answers of No










New baseline version name from Summary Sheet follows








Yes
Comments:



naming convention





































Project contains necessary subprojects








Yes
Comments:










































Project contains the correct version of subprojects








Yes
Comments:










































Design subproject is correct version








Yes
Comments:











































General Notes / Comments:

















































































LN: Intended Use: Identify who were the reviewers and if the reviewed changes have been approved. Rationale: Since this Form will be attached to the Change Request it will confirm the approval and provides feedback in case of audits. KMC: Group Review Level removed in Rev 4.0 since the design review is not checked in until approved, so it would always be DR4. Review Board:


























Change Owner:

Avinash James


Review Date :

06/16/17
































Lead Peer Reviewer:


Matt Leser


Approved by Reviewer(s):



Yes































Other Reviewer(s):










































































Sheet 3: Source Code






















Rev 1.28-Jun-15
Peer Review Meeting Log (Source Code Review)

























Source File Name:


CDD_VrfyCritReg.c

Source File Revision:


9
Header File Name:


CDD_VrfyCritReg.h

Header File Revision:


kzshz2: Intended Use: Identify which version of the source file is being review. Rationale: Required for traceability between source code and review. Auditors will likely require this. 2

























MDD Name:

VrfyCritReg_MDD.docx

Revision:
3

























FDD/SCIR/DSR/FDR/CM Name:




CM111A_VrfyCritReg_Design

Revision:
4.1.0


























Quality Check Items:



































Rationale is required for all answers of No









Working EA4 Software Naming Convention followed:















































for variable names







N/A
Comments:

















































for constant names







N/A
Comments:

















































for function names







N/A
Comments:

















































for other names (component, memory







N/A
Comments:










mapping handles, typedefs, etc.)




































All paths assign a value to outputs, ensuring








N/A
Comments:









all outputs are initialized prior to being written





































Requirements Tracability tags in code match the requirements tracability in the FDD








N/A
Comments:









requirements tracability in the FDD





































All variables are declared at the function level.








N/A
Comments:
























Synergy version matches change history





kzshz2: Intended Use: Indicate that the the versioning was confirmed by the peer reviewer(s). Rationale: There have been many occassions where versions were not updated in files and as a result Unit Test were referencing wrong versions. This often time leads to the need to re-run of batch tests.


Yes
Comments:



and Version Control version in file comment block





































Change log contains detailed description of changes








Yes
Comments:



and Work CR number











Initial version
























Code accurately implements FDD (Document or Model)








Yes
Comments:
















ICR need to be created for the missing functionality
























Verified no Compiler Errors or Warnings


KMC: Intended Use: To confirm no compiler errors or warnings exist for the code under review (warnings from contract header files may be ignored). Rationale: This is needed to ensure there will be no errors discovered at the time of integration. A Sandox project should be used; QAC can find compiler errors but not warnings.





Yes
Comments:
















































Component.h is included








N/A
Comments:
























All other includes are actually needed. (System includes








Yes
Comments:









only allowed in Nexteer library components)





































Software Design and Coding Standards followed:











Version:

























Code comments are clear, correct, and adequate







Yes
Comments:
2.1








and have been updated for the change: [N40] and













all other rules in the same section as rule [N40],






















plus [N75], [N12], [N23], [N33], [N37], [N38],






















[N48], [N54], [N77], [N79], [N72]














































Source file (.c and .h) comment blocks are per







Yes
Comments:










standards and contain correct information: [N41], [N42]





































Function comment blocks are per standards and







Yes
Comments:










contain correct information: [N43]





































Code formatting (indentation, placement of







Yes
Comments:










braces, etc.) is per standards: [N5], [N55], [N56],













[N57], [N58], [N59]














































Embedded constants used per standards; no







N/A
Comments:










"magic numbers": [N12]





































Memory mapping for non-RTE code







N/A
Comments:










is per standard





































All execution-order-dependent code can be







N/A
Comments:










recognized by the compiler: [N80]





































All loops have termination conditions that ensure







Yes
Comments:










finite loop iterations: [N63]





































All divides protect against divide by zero







N/A
Comments:










if needed: [N65]





































All integer division and modulus operations







N/A
Comments:










handle negative numbers correctly: [N76]





































All typecasting and fixed point arithmetic,







Yes
Comments:










including all use of fixed point macros and













timer functions, is correct and has no possibility






















of unintended overflow or underflow: [N66]














































All float-to-unsiged conversions ensure the.







N/A
Comments:










float value is non-negative: [N67]





































All conversions between signed and unsigned







N/A
Comments:










types handle msb==1 as intended: [N78]





































All pointer dereferencing protects against







N/A
Comments:










null pointer if needed: [N70]





































Component outputs are limited to the legal range







N/A
Comments:










defined in the FDD DataDict.m file : [N53]





































All code is mapped with FDD (all FDD







Yes
Comments:










subfunctions and/or model blocks identified













with code comments; all code corresponds to






















some FDD subfunction and/or model block): [N40]













































Review did not identify violations of other








Yes
Comments:









coding standard rules





































Anomaly or Design Work CR created








N/A
Comments: List Anomaly or CR numbers









for any FDD corrections needed











ICR created to have match model with the exisiting implementation













EA4#12274



































General Notes / Comments:
















































NVM PIM updated with the fault info PIM































LN: Intended Use: Identify who were the reviewers and if the reviewed changes have been approved. Rationale: Since this Form will be attached to the Change Request it will confirm the approval and provides feedback in case of audits. KMC: Group Review Level removed in Rev 4.0 since the design review is not checked in until approved, so it would always be DR4. Review Board:


























Change Owner:

Avinash James


Review Date :

06/16/17
































Lead Peer Reviewer:


Matt Leser


Approved by Reviewer(s):



Yes































Other Reviewer(s):










































































Sheet 4: PolySpace






















Rev 1.28-Jun-15
Peer Review Meeting Log (QAC/PolySpace Review)


























Source File Name:


CDD_VrfyCritReg.cSource File Revision:


9

Source File Name:






CDD_VrfyCritReg_Cfg.c







Source File Revision:


1

Source File Name:















Source File Revision:






























EA4 Static Analysis Compliance Guideline version:







01.02.00







Poly Space version:


Windows User: eg. 2013b 2013b
Polyspace sub project version:




Windows User: eg. TL108a_PolyspaceSuprt_1.0.0 Not released


























Quality Check Items:




































Rationale is required for all answers of No



































Contract Folder's header files are appropriate and





kzshz2: Intended Use: Identify that the contract folder contains only the information required for this component. All other variables, constants, function prototypes, etc. should be removed. Rationale: This will help avoid unit testers having to considers object not used. It will also avoid having other files required for QAC.


Yes
Comments:




function prototypes match the latest component version







































100% Compliance to the EA4 Static AnalysisYes
Comments:





Compliance Guideline





























Are previously added justification and deviation








Yes
Comments:





comments still appropriate






































Do all MISRA deviation comments use approved








Yes
Comments:





deviation tags






































Cyclomatic complexity and Static path count OK






Creager, Kathleen: use Browse Function Metrics, STCYC and STPTH

Yes
Comments:





for all functions in the component per Design














and Coding Standards rule [N47]

































































































General Notes / Comments:























Misra warning 21.1 reviewed and it is ok.

8.10 - 2 warnings exisit for the trusted function as the tool doesn’t create stubs for the functions defined in local include































LN: Intended Use: Identify who were the reviewers and if the reviewed changes have been approved. Rationale: Since this Form will be attached to the Change Request it will confirm the approval and provides feedback in case of audits. KMC: Group Review Level removed in Rev 4.0 since the design review is not checked in until approved, so it would always be DR4. Review Board:


























Change Owner:

Avinash James


Review Date :

06/16/17
































Lead Peer Reviewer:


Matt Leser


Approved by Reviewer(s):



Yes































Other Reviewer(s):