A watchdog monitoring method applicable to flight control software
A two-stage lookdog enablement and Machine Check interrupt attachment strategy for flight control software addresses monitoring gaps and interrupt issues, enhancing safety and reliability.
Patent Information
- Application Number
- CN202111592090.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-12-23
- Publication Date
- 2025-07-15
- Estimated Expiration
- 2041-12-23
AI Technical Summary
In the implementation of the flight control software, there are blind spots in which watchdog monitoring is not performed from the computer startup to the operating system loading, and watchdog interrupts are easily blocked or preempted by high priority interrupts, affecting flight safety.
The watchdog monitoring is set up and enabled in stages, and the interrupt is attached to the unmaskable Machine check interrupt source, and functional testing is carried out through reset to ensure the comprehensiveness and unmaskableness of the watchdog monitoring.
It improves the safety and reliability of flight control software, solves the shortcomings of traditional monitoring strategies, and prevents the impact of program abnormalities on aircraft flight safety.
Smart Images

Figure CN114356626B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of airborne embedded software, and particularly relates to a watchdog monitoring method applicable to flight control software. Background Art
[0002] Due to the special requirements of high safety and high reliability for flight control software, watchdog technology is usually adopted to monitor the software execution process. During the software execution process, it is necessary to feed the dog periodically. If the program execution generates an exception or runs away and the dog is not fed within the specified time period, the watchdog alarm will cause a watchdog interrupt, indicating that the system does not feed the dog regularly. The watchdog interrupt will invalidate the current channel (CHV), and record the small frame count and fault code. However, in the commonly used watchdog monitoring method, the watchdog is only enabled when entering the flight control application program, and the watchdog monitoring is not performed on the program execution process from the computer startup to the completion of the operating system loading and before jumping to execute the application program branch. There are potential hazards in the traditional monitoring method. If an exception occurs in the program execution before entering the normal working mode and the watchdog monitoring is not enabled at this time, the watchdog exception signal WDV cannot notify the channel fault logic CHV to fail, and the software cannot invalidate the CPUV through the watchdog interrupt, which will affect the flight safety of the aircraft. And the commonly used watchdog interrupt is hooked on the interrupt controller and treated as an external interrupt. This interrupt is a maskable interrupt. If the interrupt is masked due to coding errors or a higher priority interrupt is triggered, the watchdog cannot complete the monitoring function, which will also affect the flight safety of the aircraft at this time. Summary of the Invention
[0003] Object of the Invention: To provide a watchdog monitoring method applicable to flight control software to solve the monitoring blind area from the computer startup to the completion of the operating system loading and before jumping to execute the application program branch, and the problem of monitoring failure caused by interrupt masking or high priority interrupt triggering in the watchdog monitoring.
[0004] Technical Solution:
[0005] A watchdog monitoring method applicable to flight control software includes:
[0006] Step 1: Perform a first setting on the watchdog and enable the watchdog in the first stage of the flight control software execution, and perform a second setting on the watchdog and enable the watchdog again in the second stage of the flight control software execution, where the first stage is from the computer startup to the completion of the operating system loading and before jumping to execute the application program branch; the second stage is the stage of executing the normal working mode, and the normal working mode is the periodic application of the system.
[0007] Step 2: After the second setting is completed, perform interrupt hookup: Hook the watchdog interrupt to the Machine check interrupt source through the interrupt hookup function provided by the operating system to complete the triggering response hookup of an event-based non-maskable interrupt;
[0008] Step 3: After the interrupt hookup is completed, perform a reset test according to the test judgment condition.
[0009] Further, in Step 1, perform the first setting on the watchdog, specifically: Set the first watchdog bark time, and the first watchdog bark time needs to ensure that the system completes the loading of the operating system.
[0010] Further, in Step 1, perform the second setting on the watchdog, specifically: Set the second watchdog bark time, and the second watchdog bark time needs to ensure that at least one cycle application is completed.
[0011] Further, Step 2 specifically further includes:
[0012] Hook the watchdog interrupt service program to the watchdog interrupt vector source, and the watchdog interrupt service program needs to complete disabling the CHV of this channel, recording the small frame count and the fault code.
[0013] Further, in the case where the CPU is MPC755, its Machine check interrupt is an event-based, non-maskable and imprecise interrupt, and its interrupt vector number is 0x200.
[0014] Further, in Step 3, perform a reset test according to the test judgment condition, specifically:
[0015] If the aircraft is in the ground state, the flight control system needs to perform a power-on test before entering the normal working mode, and perform a reset test on the watchdog during the power-on test.
[0016] Further, in Step 3, perform a reset test on the watchdog, specifically:
[0017] Judge whether to perform this watchdog reset test by reading the watchdog test flag bit stored in the non-volatile memory.
[0018] Further, in Step 3, perform a reset test on the watchdog, specifically:
[0019] When the watchdog test flag bit is true, perform this watchdog reset test.
[0020] Beneficial effects:
[0021] Complete the time setting and enabling of the watchdog monitoring function in stages to meet the special requirements for the safety of the flight control software. According to the special requirements for the safety of the flight control software, the watchdog interrupt is hooked to the Machine check (MCP) interrupt source through the interrupt hooking function provided by the operating system to complete the triggering response hooking of an event-type non-maskable interrupt. During the watchdog test, according to the characteristics of its MCP interrupt source, the reset method is used to meet the requirements of functional testing. This method can solve the deficiencies of traditional watchdog monitoring strategies and improve the safety and reliability of the flight control software. Brief Description of the Drawings
[0022] Figure 1 It is the execution flow chart of the flight control software.
[0023] Figure 2 It is the flow chart of the watchdog test. Detailed Implementation Manner
[0024] The present invention relates to watchdog monitoring and the airborne flight control computer software technology with high safety and high reliability requirements. Specifically, the present invention proposes a method to improve the safety of the flight control software using an optimized watchdog monitoring strategy to solve the problems involved in the above-mentioned watchdog monitoring.
[0025] For the traditional working mode of the flight control computer software, as shown in the appendix Figure 1As shown, its working modes are mainly divided into: maintenance programming mode (boot menu), normal working mode (flight control application), on-board MBIT mode, and flight control computer maintenance and test mode. The watchdog monitoring is usually enabled only in the normal working mode to complete the watchdog monitoring function and prevent the program from running wild. The remaining three working modes are all in the ground state, with less impact on the safety of the aircraft, and have the function of human-computer interaction. If an abnormality occurs during the program operation, obvious human-computer interaction fault information will be output. Therefore, the watchdog function is usually disabled in these three working modes. However, in the normal working mode, the watchdog is generally enabled only when entering the flight control application program. There is no watchdog monitoring for the program execution process from the computer startup to the completion of the operating system loading and before jumping to execute the application program branch. The traditional monitoring method has potential hazards. If an abnormality occurs in the program execution before the normal working mode is executed and the watchdog monitoring is not enabled at this time, the watchdog abnormal signal WDV cannot notify the channel fault logic CHV to fail, which will affect the flight safety of the aircraft. And the commonly used watchdog interrupt is hooked on the interrupt controller and treated as an external interrupt. This interrupt is a maskable interrupt. If there is a coding error to mask this interrupt or a higher-priority interrupt is triggered, the watchdog cannot complete the monitoring function, which will also affect the flight safety of the aircraft at this time. To address the above deficiencies, the present invention proposes a method for improving the safety of flight control software using an optimized watchdog monitoring strategy. It includes: hooking the watchdog interrupt to the MCP interrupt source to complete the trigger response of an event-type non-maskable interrupt; setting and enabling the watchdog monitoring function in stages to meet the special requirements of flight control software safety; during the watchdog test process, according to the characteristics of its MCP interrupt source, using the reset method to meet the requirements of functional testing. This method can solve the deficiencies of the traditional watchdog monitoring strategy and improve the safety and reliability of flight control software.
[0026] The present invention includes the following aspects:
[0027] Set and enable the watchdog monitoring function in stages to meet the special requirements of flight control software safety; that is, perform the first setting and enabling of the watchdog before completing the boot initialization and entering the operating system, and perform the second setting and enabling after completing the operating system initialization and entering the normal working mode (flight control application).
[0028] According to the special requirements of flight control software safety, hook the watchdog interrupt to the Machine check (MCP) interrupt source through the interrupt hooking function provided by the operating system to complete the trigger response hooking of an event-type non-maskable interrupt.
[0029] During the watchdog test, the reset method is used to complete the functional test requirements according to the characteristics of the MCP interrupt source. That is, MCP is an event-type non-maskable and imprecise interrupt. After the interrupt is triggered, if the system is not reset, the operating system cannot guarantee that the interrupt service program will be executed when the interrupt is triggered next time, and the program operation may be abnormal. Therefore, the flight control system should immediately start the soft reset function, re-execute the software, and when executing this watchdog test, read the last test result before reset, skip the watchdog test program, and complete the functional test.
[0030] The present invention will be explained below in conjunction with the accompanying drawings.
[0031] The present invention provides a method for improving the safety of flight control software by using an optimized watchdog monitoring strategy. The watchdog technology is used to monitor the software execution process to prevent the program from being abnormal or running away during the execution process, and the software cannot effectively set the channel fault logic failure. The present invention includes three aspects: segmented setting to enable watchdog monitoring, watchdog interrupt hooking MCP interrupt source and using reset mode to complete watchdog functional test.
[0032] Step 1 Segment monitoring: Follow Figure 1 As shown in the flight control software execution flow, the watchdog monitoring function is completed in two stages. The first stage is from the computer startup to the completion of the operating system loading, before jumping to the application program branch; the second stage is the execution of the normal working mode.
[0033] Exemplarily, for the two-stage watchdog monitoring requirements, the time setting and enabling of the watchdog monitoring function need to be completed in stages. The first stage is to set and enable the watchdog once before completing the boot initialization and entering the operating system. The boot initialization completes the initialization of the basic resources of the computer hardware. The watchdog monitoring function cannot be enabled before the boot initialization is completed. The watchdog barking time can be set to 1s this time. Because the operating system loading completion time is slow, the set barking time should ensure that the loading of the operating system can be completed. While setting the barking time, the watchdog should be enabled to monitor the program execution process from the loading of the operating system to the jump execution application branch. At this time, if the program execution is abnormal, the watchdog abnormal signal WDV will notify the channel fault logic CHV to fail, and the channel will be cut off, which will not affect the flight safety of the aircraft. The second stage is to set and enable the watchdog again before executing the normal working mode (application), and set the watchdog barking time to 50ms to ensure that 50ms can complete a normal working mode cycle application. At this stage, the control system has completed loading and the watchdog interrupt service program should be attached, and then go to step 2.
[0034] Step 2 Interrupt Hooking: Hook the watchdog interrupt to the Machine check (MCP) interrupt source through the interrupt hooking function provided by the operating system to complete the triggering response hooking of an event-type non-maskable interrupt.
[0035] Exemplarily, taking the CPU of the selected model MPC755 as an example, its Machine check (MCP) interrupt is an event-type, non-maskable, and imprecise interrupt. Hooking the watchdog interrupt to this interrupt source can ensure that this interrupt will not be masked due to human error and will not be preempted by high-priority interrupts. Because its interrupt vector number is 0x200, which is only lower than the interrupt source with the interrupt vector number of 0x100 for System reset (system power-down / reset). If a System reset occurs, that is, the system powers down or resets, the watchdog monitoring does not need to be carried out. And at this time, the interrupt service program hooked needs to complete the function of disabling the current channel (CHV) and recording the small frame count and fault code. After completing the watchdog interrupt hooking, proceed to Step 3.
[0036] Step 3 Reset Test: The watchdog test uses the reset method to meet the requirements of functional testing. MCP is an event-type non-maskable and imprecise interrupt. As Figure 2 shown, after triggering this interrupt, the flight control system should start the soft reset function, and the software is re-executed. When executing to this watchdog test, skip the watchdog test program by reading the test result of the previous time before the reset to complete the functional test.
[0037] Exemplarily, the watchdog monitoring is an important monitoring means for the flight control software to prevent program anomalies from affecting the flight safety of the aircraft. As Figure 1 shown, if the aircraft is in the ground state, the flight control system needs to perform a power-on test before entering the normal working mode, and the watchdog needs to be functionally detected during the power-on test. Because the watchdog interrupt has been hooked to the MCP in Step 2, the watchdog detection at this time will trigger the watchdog interrupt, and this interrupt is an imprecise interrupt. If the system is not reset, when this interrupt is triggered next time, the operating system cannot guarantee that the interrupt service program will definitely be executed, and the program operation may be abnormal. Therefore, after the interrupt is triggered, the flight control system should start the soft reset function, and the software is re-executed. When executing to this watchdog test, judge whether to skip this test by reading the watchdog test flag bit stored in the non-volatile memory (NVRAM) and reading the test result of the previous time before the reset, so as to complete the watchdog functional test.
Claims
1. A watchdog monitoring method applicable to flight control software, characterized in that Including: Step 1: Perform a first setting on the watchdog and enable the watchdog in the first stage of the flight control software execution, and perform a second setting on the watchdog and enable the watchdog in the second stage of the flight control software execution. Among them, the first stage is from the computer startup to the completion of the operating system loading and before jumping to execute the application program branch; the second stage is the stage of executing the normal working mode, and the normal working mode is the periodic application of the system. In Step 1, the first setting on the watchdog is specifically: setting the first watchdog bark time, and the first watchdog bark time needs to ensure the completion of the operating system loading of the system. The second setting on the watchdog is specifically: setting the second watchdog bark time, and the second watchdog bark time needs to ensure at least one cycle application; Step 2: After the second setting is completed, perform interrupt hookup: Hook the watchdog interrupt to the Machine check interrupt source through the interrupt hookup function provided by the operating system to complete the triggering response hookup of an event-type non-maskable interrupt. Step 2 specifically further includes: Hooking the watchdog interrupt service program to the watchdog interrupt vector source, and the watchdog interrupt service program needs to complete disabling the CHV of this channel, recording the small frame count and the fault code; After performing the interrupt hookup, perform a reset test according to the test judgment condition; In the case where the CPU is MPC755, its Machine check interrupt is an event-type, non-maskable and imprecise interrupt, and its interrupt vector number is 0x200.
2. The method according to claim 1, wherein In Step 3, performing a reset test according to the test judgment condition is specifically: If the aircraft is in the ground state, the flight control system needs to perform a power-on test before entering the normal working mode, and perform a reset test on the watchdog during the power-on test.
3. The method according to claim 2, wherein In Step 3, performing a reset test on the watchdog is specifically: Judge whether to execute the current watchdog reset test by reading the watchdog test flag bit stored in the non-volatile memory.
4. The method according to claim 3, wherein In Step 3, performing a reset test on the watchdog is specifically: When the watchdog test flag bit is true, execute the current watchdog reset test.
Citation Information
Patent Citations
Method and device for resetting circuit of watchdog
CN101196836A
Method for monitoring computer operating system in starting process
CN104503859A