Instrument Software
Architecture:
Design & Implementation
Kylee Fluckiger
CGI FSW Lead
August 27th, 2024
• NASA GODDARD SPACE FLIGHT CENTER • JET PROPULSION LABORATORY •
• L3HARRIS TECHNOLOGIES • BALL AEROSPACE • TELEDYNE • NASA KENNEDY SPACE CENTER
•
• SPACE TELESCOPE SCIENCE INSTITUTE • INFRARED PROCESSING AND ANALYSIS CENTER •
• EUROPEAN SPACE AGENCY • JAPAN AEROSPACE EXPLORATION AGENCY •
CGI System Architecture
• Coronagraph System Architecture is divided into 13 functional domains, the expected behavior of
each of which is described in a functional design document (FDD) that is used to guide FSW
implementation.
2
CGI FSW Functional Capabilities
• Channel • Parameter
– Telemetry data point – Nonvolatile value stored
– Mapped to single source onboard
– Ex: temperature, parameter – Modifiable via command
value, mode state, calculated – Ex: pixel threshold, gain
offset factor, min/max values
• Monitor • Command
– Condition for fault protection – Input to FSW to initiate some
– Ex: trigger if voltage exceeds behavior
some value for 2 or more – Ex: power hardware, perform
seconds move, close Zernike loop,
halt image taking
3
CGI FSW Complexity
• High instrument code
Functional
Description # Req’s #
#
Param
# Channels
#
Monito
complexity
Document FSW GND Cmds FSW GND
Domain
s rs – CGI FSW: 104,557 SLOC
ICE and FSW
104 -- 30 -- 371 156 3 – typical: 30,000 – 70,000 SLOC
Infrastructure
FSM 45 -- 21 22 54 24 12 – GSW: 107,000 SLOC
FCM 26 -- 11 21 46 38 19 – FPGA: 60,000 SLOC
EXCAM 49 -- 17 28 174 93 27
LOCAM 38 -- 10 11 153 67 14 • Embedded linear algebra
DM 58 -- 18 14 90 56 28 required
PAM 45 -- 14 232 443 158 4
– modified Eigen template
Thermal 28 -- 1 295 450 142 71
Acquisition &
library [1]
38 -- 6 71 130 3 --
Tracking
• Code reuse
Alignment &
24 100 7 65 65 3 --
Calibration – FP, telemetry, slice interfaces,
LOWFSC 75 2 20 20 88 40 20 parameter table
HOWFSC 18 19 1 83 92 -- --
Tech Demo Data 5 14 0 8 8 -- -- • Command and telemetry
553 135 2,179 810 dictionary management
TOTALS 165 883 198
688 2,989
• Sequence engine autocoding
for PAM
• Camera class inheritance for 4
CGI FSW Overview
• C++ language • NASA class C software
• VxWorks real-time – “necessary for the science
operating system (RTOS) return from a single (non-
• LEON4 processor on GR740 primary) instrument”
board • Complies with strict JPL
– radiation-hardened FSW coding standards
• Single-core software design – based on automotive MISRA
C
– additional cores bring
additional complexity – increases safety and
reliability of code
• Developed over 5+ years – prohibits use of dynamic
memory allocation and
recursive functions, among
others 5
CGI FSW Execution
Architecture
Roma
n
Behavioral Wavefront iFSW
Sensing & Control
Commands State • fault
& Machines protection
Focus Control • telemetry &
Groun Parameters ACQ, AAC, Loop EVRs
d LOWFSC…
• parameters
Telemetr Functional Zernike Control
y • MRAM & DDR2
State Loop • ACS
Machines disturbance
FCM, LOCAM, PACE handling
PAM…
6
CGI FSW Development Process
• GitHub
– Feature branches, merge into
dev branch, release on
master
– Pull requests with reviewers
enforced
• Jenkins
– Continuous integration tool
– Simics used for hardware
emulation in testing
• Static code analysis
– Coverity
– CodeSonar
7
CGI FSW Testing
• Functional testbed
(FTB) venues
– enable both FSW
development and
V&V
– unit testing
• Written test VAP = verification activity plan
FFT = full functional test
procedures (VAPs TVAC = thermal vacuum test
and PBATs)
– regression testing
• Telemetry data
system (TDS) and Jira Anomaly Report Burndown
Grafana 8
CGI FSW Resource Utilization
• Memory
– SDRAM: 119 MB / 256 MB
– DDR2: 854 MB / 4 GB
– MRAM: 26 MB / 32 MB
• HK Packet Throughput (bps)
– Max: 100 K
– Avg: 27.2 K
– Allotted: 1 M
• Sci Packet Throughput (bps)
– Max: 1.76 M
Margin on utilization helps prevent starvation of critical – Avg: 125 K
processes such as fault protection and software watchdog
reset. – Allotted: 60 M
9
CGI FSW Issues Encountered
• Dictionary inconsistencies • Incorrect or missing
– Autocoding FSW encouraged asynchronous behavior
• Resource contention – Base classes lacked abort
– Shared SpaceWire ports mechanism
– WFSC task demand • State machines can be halted at
any time by FP or ACS
• High and low priorities
disturbance handling
– Priority inversions & deadlock
– Semaphores for resource
• Software bugs locking
– State machine flow errors • Edge cases across all code
paths
– Misuse of types and casting
• Floating point issues – Undesired hardware
responses to asynchronous
commanding required
software solutions 10
CGI FSW Lessons Learned
• Asynchronous behavior • Software documentation
defined clearly and early – Code commenting, diagrams
– Hardware and software can
– Notes on design, unit tests,
incorporate in original design
idiosyncrasies, danger zones
– All requirements, really!
• HOWFSC: GITL or onboard?
• Solid build and test process – Computational gap between
– Releases traced to requirements and capability
requirements and V&V • Single vs multi-core processing
• COTS hardware can cost • Need margin on CPU utilization
more – Onboard HOWFSC required
– Increased number of second processor board
interfaces – Partition software
– Complexity and risk requirements between FSW
introduced further down the and GSW 11
Appendix
• [1] Malloc-Free Pseudoinverse Solver with Eigen C++ Template Library:
[Link]
12