A flight control software wcet analysis method based on function scheduling sequence list

CN122838243APending Publication Date: 2026-09-29XIAN FLIGHT SELF CONTROL INST OF AVIC
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510356689.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-25
Publication Date
2026-09-29

AI Technical Summary

Technical Problem

该方法的测量结果强依赖于技术人员的工程经验,并且往往需要长时间的测试用例设计才能得到结果

Benefits of technology

[0022]本发明提供一种基于函数调度序列表的飞控软件WCET分析方法,由飞控软件架构特征总结出了一套标准化的WCET分析流程,通过将影响因素排列组合的定量分析方式简化了测量工作复杂度,也降低了测试用例设计的工作量,避免了传统方法中依赖专家经验直接进行WCET分析的主观性影响,一定程度上提高了WCET分析结果的准确性。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122838243A_ABST
    Figure CN122838243A_ABST
Patent Text Reader

Abstract

The application provides a WCET analysis method of a flight control software based on a function scheduling sequence list, which comprises the following steps: firstly, determining the number of allocated time slices and the task set contained in each time slice through a task planning table in an operating system; for the task set in each time slice, determining the potential maximum path function set that can be called in the same time period according to the call period and the starting point planned in the corresponding function scheduling sequence list; then, performing influence factor analysis on the functions involved in the function set to determine a plurality of possible maximum execution paths, measuring the execution time of each path, and taking the maximum value of the execution time as the worst execution time value of the time slice. The application designs a WCET analysis method of a flight control software based on a function scheduling sequence list in a civil aircraft flight control software, standardizes the analysis process of manual dynamic WCET measurement, simplifies the complexity of measurement work, reduces the workload of test case design, and improves the accuracy of WCET analysis results.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application belongs to the field of embedded flight control software technology for civil aircraft, and specifically relates to a WCET analysis method for flight control software based on function scheduling sequence lists. Background Technology

[0002] Flight control software, as a safety-critical software component of civil aircraft avionics, is required to complete millisecond-level task processing within a specified timeframe. If the task processing time exceeds this limit, it could lead to catastrophic consequences such as system failure. To ensure safe system operation, the software must meet real-time requirements. The primary observation parameter for verifying the real-time performance of software is the worst-case execution time (WCET). In the civil aircraft airworthiness standard DO-178C, WCET is also listed as one of the targets that high-level software must meet.

[0003] Currently, the common method for dynamically measuring WCET is to directly identify several possible maximum execution paths based on the engineering experience of technical personnel, and repeatedly run the test to obtain the longest execution time as the measured WCET value. This method heavily relies on the engineering experience of technical personnel and often requires extensive test case design to obtain results.

[0004] As the complexity of flight control software increases and the differences in flight control software architecture between military and civilian aircraft grow, it becomes increasingly difficult to determine the maximum execution path directly based on the engineering experience of technical personnel. Test cases also become difficult to design as the software size and the number of signals increase. Therefore, a quantitative method is needed to narrow down the possible maximum execution path range, reduce testing costs, and improve the accuracy of measurement results. Summary of the Invention

[0005] To address the aforementioned technical problems, this application provides a WCET analysis method for flight control software based on a function scheduling sequence list, the method comprising:

[0006] Step 1: Analyze the time slices allocated to each task in the task planning table to determine the number of time slices and the set of tasks within each time slice;

[0007] Step 2: For each set of tasks within a time slice, identify all included function scheduling sequence lists. Based on the planned call cycles and start points within the function scheduling sequence lists, determine the set of the maximum potential path functions that can be called within the same time period.

[0008] Step 3: Based on the set of potential maximum path functions, confirm the functions contained in the time slice, list and filter the influencing factors, and determine multiple possible maximum execution paths by permutation and combination of the influencing factors;

[0009] Step 4: Perform additional processing on the Cache and NVM in the software runtime environment, and measure the execution time of each path in Step 3 by instrumentation. The maximum time is the worst execution time value of that time slice.

[0010] Preferably, the flight control software uses TTOS as its operating system; the mission planning table contains multiple hard real-time time slices, and each time slice contains one or more missions.

[0011] Preferably, each task is composed of a function scheduling sequence list, which includes the called function, the calling cycle, and the starting point. When the time reaches the "calling cycle", the corresponding function is called after a delay of the "starting point".

[0012] Preferably, step 2 includes:

[0013] The potential maximum path function set can be one or more sets. It is obtained by calculating the least common multiple of the sum of the call cycles and starting points of all functions in the entire function scheduling sequence list. When the time cycle reaches an integer multiple of the least common multiple, all functions in the set will be called. This set is the potential maximum path function set.

[0014] Preferably, step 2 further includes:

[0015] If the least common multiple of the sum of the function call cycle and the starting point is much greater than the actual flight time, then select multiple sets of function call cycles and starting points according to the actual function function and calculate the least common multiple that are relatively close to each other to obtain multiple sets of potential maximum path functions.

[0016] Preferably, the functions included in the entire time slice are: input interface, input processing, signal monitoring, signal voting, control law, zeroing data storage, fault record reading, fault reset, output interface, output processing, EICAS alarm, architecture monitoring, fault recording, state transition, and pbit testing.

[0017] Preferably, the influencing factors of the functions included in the time slice are: system control related functions include idle status, working mode, and state transition; redundancy management related functions include bus validity and signal redundancy validity; maintenance related functions include maintenance status, maintenance function, fault record, and pbit test enable.

[0018] Preferably, the processing of the Cache and NVM includes:

[0019] If the system does not time out after the cache is closed, then all caches in the software will be closed. Otherwise, when measuring the execution time of the corresponding path, the measurement duration and number of times will be increased, and the worst time value will be taken as the final measurement time value to reduce the impact of cache hit rate on time. Instrumentation of fault records in the software will enable NVM read and write operations to be in the maximum load state in each cycle, so that the NVM operation execution time is the longest.

[0020] Preferably, the measurement method for software instrumentation is to call the timer function provided by the TTOS operating system before and after the path start function and the path termination function respectively, and the execution time of the path is obtained by subtracting the return values ​​of the two functions.

[0021] This application has the following technical effects:

[0022] This invention provides a WCET analysis method for flight control software based on function scheduling sequence lists. A standardized WCET analysis process is summarized from the characteristics of the flight control software architecture. By simplifying the measurement complexity through quantitative analysis of the permutation and combination of influencing factors, the workload of test case design is also reduced. This avoids the subjective influence of relying on expert experience to directly conduct WCET analysis in traditional methods, and improves the accuracy of WCET analysis results to a certain extent. Attached Figure Description

[0023] Figure 1 A flowchart of the WCET analysis method for flight control software based on a function scheduling sequence list provided in this application embodiment.

[0024] Figure 2 Example diagram of the method for calculating a single set of potential maximum path functions within a time slice provided in the embodiments of this application;

[0025] Figure 3 An example diagram illustrating the method for calculating multiple sets of potential maximum path functions within a time slice, as provided in the embodiments of this application. Detailed Implementation

[0026] It should be noted that with the widespread application of function scheduling sequence lists in civil aircraft flight control software architecture, a software cycle execution environment with highly deterministic function call timing is provided for software operation. By specifying the function call cycle and start time, the function can be called at a defined time period to achieve the software function. Therefore, a standardized and quantitative maximum execution path analysis method can be summarized to improve the accuracy of WCET analysis results.

[0027] Please see Figure 1, in the TTOS time-sharing partitioned operating system adopted by the flight control software, multiple time slices are pre-allocated to each task through the task planning table, and real-time performance requires that the running duration of tasks in each time slice in each time cycle does not exceed the allocated time length. Therefore, the number of time slices and the task set contained in each time slice should be determined first.

[0028] Each task is a main function as an entry. In the main function, each function in the function scheduling sequence table is called sequentially according to the planned period and start point through cyclic operations. The data type of the function scheduling sequence table is a structure, and the structure members are respectively composed of a function pointer with a return value of VOID, a calling period of data type UINT32, and a start point of data type UINT32.

[0029] If the value of the calling period is A and the value of the start point is B (B < A), it means that the function pointed to by the function pointer is called after a delay of B beats every A time cycles, so the timing of different function calls in the task is different. Furthermore, in civil aircraft flight control software, all logical functions adopt the model-based design method, the model only generates one functional function, and there is no control coupling relationship between each functional function, which are only called sequentially through the function scheduling sequence table. Therefore, for the combination of as many functions as possible called in the same time cycle, one or more groups of potential maximum path function sets formed are possible maximum execution paths.

[0030] Most of the called potential maximum path function sets have internal branch structures. Excitations from different influencing factors will lead to differences in the executed branches and affect the actual execution time. Therefore, it is necessary to determine the influencing factors corresponding to each potential maximum path function set. Generally, the influencing factors that have a great impact on time include the following three categories: influencing factors related to system control functions include air-ground status, working mode, and status transition; influencing factors related to redundancy management functions include bus validity and signal redundancy validity; influencing factors related to maintenance functions include maintenance status, maintenance functions, fault records, and pbit test enable. Multiple paths can be obtained by permuting and combining the determined influencing factors. After eliminating the paths that cannot be reached, the set of maximum execution paths to be measured can be obtained.

[0031] For measurement, it is first necessary to set the external excitation of the software separately to meet the path activation conditions, and then additional processing is required for Cache and NVM. If the system does not time out after Cache is disabled, all Caches in the software are disabled; otherwise, when measuring the execution time of the corresponding path, the measurement duration and times are increased, and the worst time value is taken as the final measured time value to reduce the impact of Cache hit ratio on the time. Instrument fault recording enable is set in the software so that NVM read and write operations are respectively in the maximum load state in each cycle, and the execution time of NVM operations is the longest.

[0032] The Lib_Msl_ReadTimer function provided by the TTOS operating system is instrumented before the start function and after the end function on the path. The function returns the time corresponding to the timer in microseconds. The execution time of the path can be obtained by subtracting the return values ​​of the two functions.

[0033] In particular, since the flight control software adopts a dissimilar dual-redundant processor architecture, with different processors in the command branch and monitoring branch executing the tasks within the software and verifying the results with each other, it is necessary to insert staking on the processors of the two branches and measure the WCET value corresponding to each branch.

[0034] Please see Figure 2 and Figure 3 Because the flight control software design incorporates load balancing, multiple functions are called sequentially based on their start points when they reach their corresponding scheduling cycles, rather than being called simultaneously. Therefore, calculation is required.

[0035] The set of potentially maximum path functions that are invoked simultaneously. Since not all functions may be invoked at the same time under normal circumstances, the set of potentially maximum path functions may consist of a single set or multiple sets.

[0036] Figure 2 In the example of a single set of potential maximum path functions, taking a function scheduling sequence table containing six different scheduling timing functions A, B, C, D, E, and F as an example, the [function name, call period, starting point] are [A, 1, 0], [B, 2, 0], [C, 2, 1], [D, 4, 1], [E, 4, 2], and [F, 8, 2].

[0037] Function A, with a call cycle of 1, is called every time, and therefore must be called within the worst-case execution path. Functions B, C, D, E, and F, with call cycles greater than 1, are called every 2 times, 1 time after 2 times (i.e., every 3 times), 1 time after 4 times (i.e., every 5 times), 2 time after 4 times (i.e., every 6 times), and 2 time after 8 times (i.e., every 10 times), respectively. The least common multiple of the number of call cycles is 60, meaning that all functions A, B, C, D, E, and F will be called every 60 times. The time slice contains only one set of functions with the potential maximum path. When analyzing influencing factors, it is necessary to consider the various effects of all functions in the set being called.

[0038] Figure 3 In the example of multiple sets of potential maximum path functions, taking a function scheduling sequence table containing six different scheduling timing functions A, B, C, D, E, and F as an example, the [function name, call period, start point] are [A, 4, 1], [B, 8, 1], [C, 8, 2], [D, 80, 1], [E, 80, 2], and [F, 80, 4], respectively.

[0039] The least common multiple of all function call counts is 464,946, with each count lasting 12.5 ms. Therefore, all functions would be called simultaneously every 97 hours. This value is much larger than the actual flight time, indicating that it's impossible for all functions to be called simultaneously during flight. In this case, it's necessary to select multiple sets of functions based on their call functions and calculate the closest least common multiple for each. Figure 3 (There are 3 groups in total), and then the influencing factors are analyzed and the paths are determined. The longest time value in all paths is the corresponding WCET value.

Claims

1. A WCET analysis method for flight control software based on function scheduling sequence lists, characterized in that, The method includes: Step 1: Analyze the time slices allocated to each task in the task planning table to determine the number of time slices and the set of tasks within each time slice; Step 2: For each set of tasks within a time slice, identify all included function scheduling sequence lists. Based on the planned call cycles and start points within the function scheduling sequence lists, determine the set of the maximum potential path functions that can be called within the same time period. Step 3: Based on the set of potential maximum path functions, confirm the functions contained in the time slice, list and filter the influencing factors, and determine multiple possible maximum execution paths by permutation and combination of the influencing factors; Step 4: Perform additional processing on the Cache and NVM in the software runtime environment, and measure the execution time of each path in Step 3 by instrumentation. The maximum time is the worst execution time value of that time slice.

2. The method according to claim 1, characterized in that, The flight control software uses the TTOS operating system; the mission planning table contains multiple hard real-time time slices, and each time slice contains one or more missions.

3. The method according to claim 1, characterized in that, Each task consists of a function scheduling sequence list, which contains the called function, the call cycle, and the start point. When the time reaches the "call cycle", the corresponding function is called after a delay of the "start point" time.

4. The method according to claim 1, characterized in that, Step 2 includes: The potential maximum path function set can be one or more sets. It is obtained by calculating the least common multiple of the sum of the call cycles and starting points of all functions in the entire function scheduling sequence list. When the time cycle reaches an integer multiple of the least common multiple, all functions in the set will be called. This set is the potential maximum path function set.

5. The method according to claim 4, characterized in that, Step 2 also includes: If the least common multiple of the sum of the function call cycle and the starting point is much greater than the actual flight time, then select multiple sets of function call cycles and starting points according to the actual function function and calculate the least common multiple that are relatively close to each other to obtain multiple sets of potential maximum path functions.

6. The method according to claim 1, characterized in that, The functions included in the entire time slice are: input interface, input processing, signal monitoring, signal voting, control law, zeroing data storage, fault record reading, fault reset, output interface, output processing, EICAS alarm, architecture monitoring, fault recording, state transition, and pbit testing.

7. The method according to claim 1, characterized in that, The influencing factors of the functions included in the time slice are as follows: system control related functions include idle / ground status, working mode, and state transition; redundancy management related functions include bus validity and signal redundancy validity; maintenance related functions include maintenance status, maintenance functions, fault records, and pbit test enable.

8. The method according to claim 1, characterized in that, The processing of the cache and NVM includes: If the system does not time out after the cache is closed, then all caches in the software will be closed. Otherwise, when measuring the execution time of the corresponding path, the measurement duration and number of times will be increased, and the worst time value will be taken as the final measurement time value to reduce the impact of cache hit rate on time. Instrumentation of fault records in the software will enable NVM read and write operations to be in the maximum load state in each cycle, so that the NVM operation execution time is the longest.

9. The method according to claim 1, characterized in that, The method for measuring software instrumentation is to call the timer function provided by the TTOS operating system before and after the path start function and the end function respectively, and the execution time of the path is obtained by subtracting the return values ​​of the two functions.