REG NASA-LLIS-0559-1997 Lessons Learned Redundant Verification of Critical Command Timing (1995).pdf
《REG NASA-LLIS-0559-1997 Lessons Learned Redundant Verification of Critical Command Timing (1995).pdf》由会员分享,可在线阅读,更多相关《REG NASA-LLIS-0559-1997 Lessons Learned Redundant Verification of Critical Command Timing (1995).pdf(3页珍藏版)》请在麦多课文档分享上搜索。
1、Lessons Learned Entry: 0559Lesson Info:a71 Lesson Number: 0559a71 Lesson Date: 1997-05-29a71 Submitting Organization: JPLa71 Submitted by: J. Blosiu/D. OberhettingerSubject: Redundant Verification of Critical Command Timing (1995) Abstract: When a new mission software release was uploaded to the spa
2、cecraft, the inflight upload failed to include a software patch that had been written to fix a defective countdown timer. Because an independent “watchdog timer” was planned, but never implemented due to constrained project resources, the thrusters continued to fire after the desired shutdown time a
3、nd the mission was terminated. Recommendations centered on the need for rigorous software configuration management, a watchdog timer to terminate operations, and testbed verification of in-flight software updates.Description of Driving Event: Flight software for a recent mission included a safety fe
4、ature in which the flight computer initiated a command sequence for enabling the thrusters. It also started a countdown timer which limited the duration of the burn. Flight software contained a known defect: whenever numerical computations produced an overflow, the calculations generated false resul
5、ts. When interplanetary mission software was uploaded following conclusion of the first science objective of the mission, the upload failed to include a software patch which had been written to fix the defect.When the thrusters were enabled for a spacecraft pointing maneuver, the flight computer per
6、formed calculations which generated a numeric overflow. A floating point interrupt occurred, and the processor generated erroneous commands affecting various spacecraft functions, including the propulsion subsystem and the countdown timer. With this timer not functioning, the thrusters continued to
7、fire after the desired shutdown time.The 15-minute ground response to the fault allowed the loss of too much fuel to continue the mission. An independent watchdog timer*, redundant with the countdown timer, was planned but Provided by IHSNot for ResaleNo reproduction or networking permitted without
- 1.请仔细阅读文档,确保文档完整性,对于不预览、不比对内容而直接下载带来的问题本站不予受理。
- 2.下载的文档,不会出现我们的网址水印。
- 3、该文档所得收入(下载+内容+预览)归上传者、原创作者;如果您是本文档原作者,请点此认领!既往收益都归您。
下载文档到电脑,查找使用更方便
10000 积分 0人已下载
下载 | 加入VIP,交流精品资源 |
- 配套讲稿:
如PPT文件的首页显示word图标,表示该PPT已包含配套word讲稿。双击word图标可打开word文档。
- 特殊限制:
部分文档作品中含有的国旗、国徽等图片,仅作为作品整体效果示例展示,禁止商用。设计者仅对作品中独创性部分享有著作权。
- 关 键 词:
- REGNASALLIS05591997LESSONSLEARNEDREDUNDANTVERIFICATIONOFCRITICALCOMMANDTIMING1995PDF

链接地址:http://www.mydoc123.com/p-1018206.html