diff --git a/.bazelignore b/.bazelignore index fbcb4bd3..9698c9a1 100644 --- a/.bazelignore +++ b/.bazelignore @@ -23,3 +23,11 @@ bazel/rules/rules_score/examples/seooc bazel/rules/rules_score/examples/some_other_library # Separate local Bazel module (system integrator demo, depends on @seooc//) bazel/rules/rules_score/examples/integrator +# minimal is a separate local Bazel module too, but its :doc_sources filegroup +# is still loaded directly from the parent workspace (rules_score_doc). Only +# ignore its own convenience symlinks, whose targets loop back into this +# directory and would otherwise trip a symlink-cycle error during globbing. +bazel/rules/rules_score/examples/minimal/bazel-bin +bazel/rules/rules_score/examples/minimal/bazel-minimal +bazel/rules/rules_score/examples/minimal/bazel-out +bazel/rules/rules_score/examples/minimal/bazel-testlogs diff --git a/.github/skills/rules-score/SKILL.md b/.github/skills/rules-score/SKILL.md index 5d9a5bd6..4a11627d 100644 --- a/.github/skills/rules-score/SKILL.md +++ b/.github/skills/rules-score/SKILL.md @@ -40,7 +40,7 @@ Use this skill to coordinate; open the specialized skill for the actual work: | `.trlc` requirement records, `ScoreReq` model, traceability, `assumed_system_requirements` / `feature_requirements` / `component_requirements` / `assumptions_of_use` | **score-requirements** | | PlantUML diagrams, `architectural_design` / `unit` / `unit_design` / `component` / `dependable_element` structure, architecture/API/sequence validations | **score-architecture** | | GoogleTest `lobster-tracing` + Given-When-Then, `test_case_coverage.lock.yaml`, attaching tests | **score-testing** | -| FMEA, `FailureMode` / `ControlMeasure` / FTA, `fmea` / `dependability_analysis` | **score-safety-analysis** | +| FMEA, `FailureMode` / `SafetyMeasure` / FTA, `safety_analysis` / `dependability_analysis` | **score-safety-analysis** | --- @@ -59,7 +59,7 @@ with a traceability report. | Architectural Design | `architectural_design` | score-architecture | | Units & Components | `unit`, `unit_design`, `component` | score-architecture | | Tests & Coverage | `tests` attr, `test_case_coverage_lock` | score-testing | -| Dependability Analysis | `fmea`, `dependability_analysis` | score-safety-analysis | +| Dependability Analysis | `safety_analysis`, `dependability_analysis` | score-safety-analysis | | SEooC assembly | `dependable_element` | this skill | ### Hierarchy @@ -182,7 +182,7 @@ FMEA, cross-module `deps`, and test-case coverage — see 3. **Implementation & tests** → back each `unit` with a `cc_library` + `cc_test`; annotate tests with `lobster-tracing` + Given-When-Then; add `test_case_coverage_lock` on components. *(score-testing)* -4. **Safety analysis** → add `fmea` (FailureMode + ControlMeasure + FTA) and wrap it in a +4. **Safety analysis** → add `safety_analysis` (FailureMode + SafetyMeasure + FTA) and wrap it in a `dependability_analysis`. *(score-safety-analysis)* 5. **Assemble** → allocate `CompReq` to `component(requirements=…)` and `FeatReq` to `dependable_element(requirements=…)`; wire `architectural_design`, `components`, diff --git a/.github/skills/score-requirements/SKILL.md b/.github/skills/score-requirements/SKILL.md index d2b21fcf..304f0591 100644 --- a/.github/skills/score-requirements/SKILL.md +++ b/.github/skills/score-requirements/SKILL.md @@ -42,7 +42,7 @@ Bazel build/test rules. ## Not for - Architecture diagrams, `unit` / `component` / `dependable_element` structure → **score-architecture** -- FMEA / FailureMode / ControlMeasure / FTA safety analysis → **score-safety-analysis** +- FMEA / FailureMode / SafetyMeasure / FTA safety analysis → **score-safety-analysis** - Test annotation and coverage → **score-testing** - End-to-end SEooC assembly / choosing which skill to use → **rules-score** @@ -243,7 +243,8 @@ component-internal requirements with no feature-level parent. ### Assumptions of Use (AoU) -`AoU` extends `ControlMeasure` and captures conditions the integrating project must satisfy. +`AoU` extends `RequirementSafety` (not `SafetyMeasure`) and captures conditions the integrating +project must satisfy, via its own independent, optional `root_causes` field. The `assumptions_of_use` rule accepts raw `.trlc` **or** `.rst` files carrying `aou_req` directives (converted to TRLC automatically). diff --git a/.github/skills/score-safety-analysis/SKILL.md b/.github/skills/score-safety-analysis/SKILL.md index df766ad2..9bb18f59 100644 --- a/.github/skills/score-safety-analysis/SKILL.md +++ b/.github/skills/score-safety-analysis/SKILL.md @@ -1,6 +1,6 @@ --- name: score-safety-analysis -description: "Step-by-step workflow for creating or extending a FMEA-based safety analysis in TRLC format for S-CORE software components. Use when asked to: add failure modes, create FTA diagrams, add control measures, or validate the safety analysis traceability chain. Covers clustering, FailureMode records, FTA PlantUML files, ControlMeasure records, BUILD wiring, and trlc validation." +description: "Step-by-step workflow for creating or extending a FMEA-based safety analysis in TRLC format for S-CORE software components. Use when asked to: add failure modes, create FTA diagrams, add mitigations, or validate the safety analysis traceability chain. Covers clustering, FailureMode records, FTA PlantUML files, Mitigation records, BUILD wiring, and trlc validation." argument-hint: "interface or component name to analyse" --- @@ -23,7 +23,7 @@ argument-hint: "interface or component name to analyse" - Adding new failure modes to an existing safety analysis - Creating FTA diagrams for root-cause decomposition -- Defining ControlMeasure / AoU records for identified root causes +- Defining Mitigation / CompReq / AoU records for identified root causes - Validating the full traceability chain before a review of a safety analysis ## Key Files and Locations @@ -32,9 +32,9 @@ argument-hint: "interface or component name to analyse" score//dependability/ ├── safety_analysis/ │ ├── failure_modes.trlc # FailureMode records (one per unique root-cause cluster) -│ ├── control_measures.trlc # ControlMeasure / PreventiveMeasure / AoU records +│ ├── safetymeasures.trlc # Mitigation / AoU / CompReq records │ ├── fta_.puml # One FTA diagram per FailureMode -│ └── BUILD # fmea() rule — must list all .puml in fta_files filegroup +│ └── BUILD # safety_analysis() rule — must list all .puml in fta_files filegroup ├── assumed_system/ │ └── aous.trlc # AoU records (caller obligations) └── requirements/ @@ -64,7 +64,7 @@ than inventing it. Only once the failure modes, causes, and measures are decided, transcribe them into the files below (Steps 1–5). This is mechanical: one `FailureMode` per decided effect, one FTA per failure -mode, one measure record per `$BasicEvent`, matching aliases, BUILD wired, `trlc` clean. +mode, one measure record per `$RootCause`, matching aliases, BUILD wired, `trlc` clean. ## Authoring guidance: performing the FMEA @@ -85,16 +85,15 @@ safety goal?"* Dismiss low-relevance models with a short rationale. worst-case terms relative to the safety goal. Then build the FTA top-down to **actionable root causes**: `$OrGate` (default) when any single cause suffices; `$AndGate` only when all must co-occur (a fault *and* a failed safety mechanism — this justifies lower residual risk). Decompose -until each `$BasicEvent` is something you can place a measure on. +until each `$RootCause` is something you can place a measure on. -**Step 3 — one measure per root cause**, chosen by *when* it acts: +**Step 3 — one measure per root cause**, chosen by *who* closes it: -| Type | Use when it… | Acts | -|------|--------------|------| -| `PreventiveMeasure` | removes the cause so the fault cannot occur | before | -| `ControlMeasure` | detects/handles the fault at runtime (plausibility check, monitor) | during | -| `Mitigation` | reduces severity/probability after occurrence | after | -| `AoU` | can only be guaranteed by the **integrator/caller** | at integration | +| Type | Use when it… | Closed via | +|------|--------------|------------| +| `Mitigation` | the SEooC itself provides a dedicated safety measure (with a mandatory `justification`) | `root_causes` | +| `CompReq` | a normal, implemented-and-tested component requirement already closes it | `derived_from` | +| `AoU` | can only be guaranteed by the **integrator/caller** | `root_causes` (optional) | Use an `AoU` to **push an obligation outward** when the SEooC cannot close a cause itself; it must be forwarded to the integrating project. Record *why* a measure is sufficient (AND-gate argument, @@ -128,19 +127,22 @@ ScoreReq.FailureMode { ## Step 2 — Create FTA Diagrams (`fta_.puml`) -One `.puml` file per `FailureMode` record. The `$TopEvent` alias **must** equal the fully-qualified TRLC record name (`.`). +Use `$FailureMode(name, fm1, fm2="", ..., fm8="")` to link the diagram's top-level node +directly to the `FailureMode` record(s) it covers — `fm1` is mandatory, up to +`fm8` may be given, each a fully-qualified `.` name. +`fm1` also doubles as the node's connection point for gates. ```plantuml @startuml !include fta_metamodel.puml -$TopEvent("", ".") +$FailureMode("", ".", ".") $OrGate("OG1", ".") -$BasicEvent("", ".", "OG1") -$BasicEvent("", ".", "OG1") +$RootCause("", "", "OG1") +$RootCause("", "", "OG1") @enduml ``` @@ -149,37 +151,40 @@ $BasicEvent("", ".", "OG1") | Procedure | Purpose | `connection` points to | |-----------|---------|------------------------| -| `$TopEvent(name, alias)` | Top failure mode | — (root, no connection) | +| `$FailureMode(name, fm1, fm2, ..., fm8)` | Top failure mode; `fm1`..`fm8` are `FailureMode` FQNs it covers | — (root, no connection); `fm1` is the alias used by child gates | | `$OrGate(alias, connection)` | Any child sufficient | parent alias | | `$AndGate(alias, connection)` | All children required | parent alias | -| `$BasicEvent(name, alias, connection)` | Root cause / leaf | enclosing gate alias | +| `$RootCause(name, alias, connection)` | Root cause / leaf — `alias` must be a **plain TRLC identifier** (no dotted `Package.Name`) | enclosing gate alias | | `$IntermediateEvent(name, alias, connection)` | Intermediate cause | parent gate alias | | `$TransferInGate(name, alias, connection)` | Link to sub-tree | parent alias | **Rules:** -- `$BasicEvent` alias = `.` — this IS the traceability link. -- Build bottom-up in the file: `$TopEvent` first, then gates, then `$BasicEvent` leaves. -- The same `ControlMeasure` alias may appear in multiple FTAs (shared root cause). +- `$RootCause` alias is a plain identifier; the `puml_cli` FTA parser auto-generates a `fta_events.trlc` stub (imported as `_fta`) containing a `RootCause` record named after that alias — `Mitigation`/`CompReq`/`AoU` records reference it explicitly (e.g. `root_causes = [sample_safety_analysis_fta.JustBadLuck]`); there is no implicit name-matching. +- Build top-down in the file: `$FailureMode` first, then gates, then `$RootCause` leaves. +- The same `$RootCause` alias may appear in multiple FTAs (shared root cause). - `$OrGate` is the default for independent root causes; use `$AndGate` only when all causes must co-occur. -## Step 3 — Write ControlMeasure Records (`control_measures.trlc`) +## Step 3 — Write Mitigation Records (`safetymeasures.trlc`) -For every `$BasicEvent` alias in every FTA, define a matching record: +For every `$RootCause` alias in every FTA that isn't already closed by a `CompReq` or `AoU`, +define a matching `Mitigation` record. `root_causes` and `justification` are both +**mandatory**, and `root_causes` must reference the generated `RootCause` stub(s): ```trlc -ScoreReq.ControlMeasure { - safety = ScoreReq.Asil.B - description = "Normative measure text" - version = 1 +ScoreReq.Mitigation { + safety = ScoreReq.Asil.B + description = "Normative measure text" + justification = "Why this measure is sufficient to close the root cause" + version = 1 + root_causes = [.] } ``` -Other available types (same pattern, different semantics): -- `ScoreReq.PreventiveMeasure` — prevents the failure from occurring -- `ScoreReq.Mitigation` — reduces severity/probability after occurrence -- `ScoreReq.AoU` — assumption the caller must satisfy; add `mitigates = ""` field +Other ways to close a root cause: +- `ScoreReq.CompReq` — closes it via `derived_from`, referencing the `RootCause` stub alongside any `FeatReq`/`AssumedSystemReq`/`AoU` it also derives from +- `ScoreReq.AoU` — assumption the caller must satisfy; does **not** extend `SafetyMeasure` and has its own independent, optional `root_causes` field (no `justification` required) -**Rule:** `.` in TRLC must match the `$BasicEvent` alias verbatim. +**Rule:** every `$RootCause` alias must be referenced by at least one `Mitigation.root_causes`, `CompReq.derived_from`, or `AoU.root_causes` — this is validated by `bazel test` on the owning `dependability_analysis` target. ## Step 4 — Update BUILD @@ -199,22 +204,24 @@ filegroup( ## Step 5 — Validate -**Pass criteria:** zero errors in `failure_modes.trlc`, `control_measures.trlc`, `aous.trlc`. +**Pass criteria:** zero errors in `failure_modes.trlc`, `safetymeasures.trlc`, `aous.trlc`. Pre-existing RSL union-type errors (`expected identifier, encountered '['`) are a known trlc v2 / RSL version mismatch — ignore if they appear only in the tooling RSL, not in component files. **Traceability chain that must be complete:** ``` FailureMode.interface → public_api interface name -FailureMode record → $TopEvent alias -$BasicEvent alias → ControlMeasure / AoU record name +FailureMode record → $FailureMode fm1..fm8 arguments +$RootCause alias → Mitigation.root_causes / CompReq.derived_from / AoU.root_causes ``` ## Common Mistakes | Mistake | Fix | |---------|-----| -| `$BasicEvent` alias does not match any TRLC record | Ensure `.` is spelled identically in both places | +| `$RootCause` alias is dotted (`Pkg.Name`) | Use a plain identifier — dotted aliases are rejected for root causes | +| `$FailureMode` fm1..fm8 argument does not match any TRLC record | Ensure `.` is spelled identically in both places | +| A root cause (`$RootCause`) is not referenced by any `Mitigation`/`CompReq`/`AoU` | Add an explicit reference to the generated `.` `RootCause` stub | | New `.puml` not in BUILD `fta_files` | Add the file path to the `srcs` list | -| AoU added to `control_measures.trlc` | AoUs belong in `aous.trlc`; both extend `Measure` so the FTA alias still resolves | +| AoU added to `safetymeasures.trlc` | AoUs belong in `aous.trlc`; `AoU` does not extend `SafetyMeasure`, it has its own independent `root_causes` field | | Wrong RSL used for trlc validation | Always pass the tooling RSL as the first directory argument | diff --git a/bazel/rules/rules_score/BUILD b/bazel/rules/rules_score/BUILD index 47792d8e..9b08f4ec 100644 --- a/bazel/rules/rules_score/BUILD +++ b/bazel/rules/rules_score/BUILD @@ -38,7 +38,7 @@ exports_files([ "templates/section_page.template.rst", "templates/unit.template.rst", "templates/component.template.rst", - "templates/fmea.template.rst", + "templates/safety_analysis.template.rst", "templates/puml_diagram.template.rst", ]) @@ -88,13 +88,13 @@ py_binary( visibility = ["//visibility:public"], ) -# FMEA page assembler: builds the failure-mode-centric fmea.rst body in-process -# via the extended TRLCRST library and the FTA chains JSON from puml_cli. +# Safety-analysis page assembler: builds the failure-mode-centric safety_analysis.rst body +# in-process via the extended TRLCRST library and the FTA chains JSON from puml_cli. py_binary( - name = "fmea_assembler", - srcs = ["src/fmea_assembler.py"], + name = "safety_analysis_assembler", + srcs = ["src/safety_analysis_assembler.py"], imports = ["src"], - main = "src/fmea_assembler.py", + main = "src/safety_analysis_assembler.py", visibility = ["//visibility:public"], deps = [ "@trlc//tools/trlc_rst:trlc_rst_lib", diff --git a/bazel/rules/rules_score/README.md b/bazel/rules/rules_score/README.md index 36b58507..86d11612 100644 --- a/bazel/rules/rules_score/README.md +++ b/bazel/rules/rules_score/README.md @@ -28,7 +28,7 @@ for safety related automotive software. | `architectural_design` | `ArchitecturalDesignInfo` | | `unit` | `UnitInfo`, `CertifiedScope` | | `component` | `ComponentInfo` | -| `fmea` | `AnalysisInfo` | +| `safety_analysis` | `AnalysisInfo` | | `glossary` | `SphinxSourcesInfo` | | `dependability_analysis` | `DependabilityAnalysisInfo` | | `dependable_element` | HTML documentation zip (Sphinx) | @@ -137,21 +137,21 @@ and collects requirement + architecture + test lobster sources. --- -## `fmea` +## `safety_analysis` ```starlark -fmea( - name = "my_fmea", +safety_analysis( + name = "my_safety_analysis", failuremodes = [":failure_modes"], - controlmeasures = [":control_measures"], root_causes = ["fta.puml"], + safetymeasures = [":safetymeasures"], arch_design = ":my_design", ) ``` -**`bazel build`** — generates `fmea.rst` (merged FM / CM / FTA sections), +**`bazel build`** — generates `safety_analysis.rst` (merged FM / Safety Measures / FTA sections), runs `lobster-trlc` on TRLC inputs, and extracts FTA events from `.puml` -diagrams into `fta.lobster`. Build-only; traceability validation is done +diagrams into `fta_events.trlc`. Build-only; traceability validation is done by the wrapping `dependability_analysis` test. --- @@ -212,7 +212,7 @@ dependable_element( ```starlark dependability_analysis( name = "my_da", - fmea = [":my_fmea"], + safety_analysis = [":my_safety_analysis"], arch_design = ":my_design", ) ``` diff --git a/bazel/rules/rules_score/docs/_assets/SeoocExample_FTA.puml b/bazel/rules/rules_score/docs/_assets/SeoocExample_FTA.puml index a3b3853e..49638e68 100644 --- a/bazel/rules/rules_score/docs/_assets/SeoocExample_FTA.puml +++ b/bazel/rules/rules_score/docs/_assets/SeoocExample_FTA.puml @@ -15,15 +15,15 @@ !include fta_metamodel.puml -$TopEvent("SampleFailureMode takes over the world", "SampleLibrary.SampleFailureMode") +$FailureMode("SampleFailureMode takes over the world", "SampleLibrary.SampleFailureMode") $OrGate("OG1", "SampleLibrary.SampleFailureMode") $IntermediateEvent("SampleFailureMode is Angry", "IEF", "OG1") -$BasicEvent("Just bad luck", "SampleLibrary.JustBadLuck", "OG1") +$RootCause("Just bad luck", "JustBadLuck", "OG1") $AndGate("AG2", "IEF") -$BasicEvent("No More Cookies", "SampleLibrary.NoMoreCookies", "AG2") -$BasicEvent("No More Coffee", "SampleLibrary.NoMoreCoffee", "AG2") +$RootCause("No More Cookies", "NoMoreCookies", "AG2") +$RootCause("No More Coffee", "NoMoreCoffee", "AG2") @enduml diff --git a/bazel/rules/rules_score/docs/_assets/fta_metamodel.puml b/bazel/rules/rules_score/docs/_assets/fta_metamodel.puml index 770f7a54..fe509e78 100644 --- a/bazel/rules/rules_score/docs/_assets/fta_metamodel.puml +++ b/bazel/rules/rules_score/docs/_assets/fta_metamodel.puml @@ -29,8 +29,37 @@ sprite $transferin $connection !endprocedure diff --git a/bazel/rules/rules_score/docs/_assets/lobster_report_assembly.puml b/bazel/rules/rules_score/docs/_assets/lobster_report_assembly.puml index 55f1137e..5753cf99 100644 --- a/bazel/rules/rules_score/docs/_assets/lobster_report_assembly.puml +++ b/bazel/rules/rules_score/docs/_assets/lobster_report_assembly.puml @@ -33,7 +33,7 @@ skinparam rectangle { BorderColor<> #6A1B9A } -rectangle "A: Per-level .lobster files\n(Feature/Component Req, Unit Test,\nCoverage, Architecture, Public API,\nFailure Modes, Control Measures,\nRoot Causes)" <> as A +rectangle "A: Per-level .lobster files\n(Feature/Component Req, Unit Test,\nCoverage, Architecture, Public API,\nFailure Modes, Safety Measures,\nRoot Causes)" <> as A rectangle "B: expand_template\nformat_lobster_block() per level\n(emit_empty=strict in release)" <> as B rectangle "de_traceability_config" <> as conf diff --git a/bazel/rules/rules_score/docs/_assets/rules_score_overview.puml b/bazel/rules/rules_score/docs/_assets/rules_score_overview.puml index bddea3e9..ae3d48b9 100644 --- a/bazel/rules/rules_score/docs/_assets/rules_score_overview.puml +++ b/bazel/rules/rules_score/docs/_assets/rules_score_overview.puml @@ -45,7 +45,7 @@ component "unit" <> as unit component "component" <> as comp ' ── Safety Analysis rules ───────────────────────────────────────────────────── -component "fmea" <> as fmea +component "safety_analysis" <> as safety_analysis component "dependability_analysis" <> as da ' ── Documentation rules ─────────────────────────────────────────────────────── @@ -56,7 +56,7 @@ component "dependable_element" as de unit_design --> unit : <> -arch --> fmea : <> +arch --> safety_analysis : <> arch --> de : <> feat_req --> aou : <> @@ -65,7 +65,7 @@ feat_req --> de : <> comp_req --> comp : <> comp_req --> aou : <> -fmea --> da : <> +safety_analysis --> da : <> da --> de : <> aou --> de : <> diff --git a/bazel/rules/rules_score/docs/_assets/safety_analysis_doc_pipeline.puml b/bazel/rules/rules_score/docs/_assets/safety_analysis_doc_pipeline.puml index 21884adf..dfa4e9b4 100644 --- a/bazel/rules/rules_score/docs/_assets/safety_analysis_doc_pipeline.puml +++ b/bazel/rules/rules_score/docs/_assets/safety_analysis_doc_pipeline.puml @@ -14,7 +14,7 @@ @startuml safety_analysis_doc_pipeline ' Component view of the FMEA build: input artifacts (authored + tooling -' defaults) flow through three in-process tool actions of the ``fmea`` rule into +' defaults) flow through three in-process tool actions of the ``safety_analysis`` rule into ' the generated files, the providers, and finally the Sphinx staging tree. skinparam linetype ortho @@ -42,73 +42,76 @@ skinparam component { ' ── Input artifacts ────────────────────────────────────────────────────────── package "Authored by the component team" { - rectangle "failuremodes.trlc\n(FailureMode records)" <> as fm_trlc - rectangle "controlmeasures.trlc\n(ControlMeasure records)" <> as cm_trlc - rectangle "fta_*.puml\n(root_causes attr)" <> as fta_puml + rectangle "failuremodes.trlc\n(FailureMode records)" <> as fm_trlc + rectangle "safetymeasures.trlc\n(Mitigation/AoU/CompReq)" <> as sm_trlc + rectangle "fta_*.puml\n(root_causes attr)" <> as fta_puml } package "Tooling defaults (rules_score / ScoreReq)" { rectangle "ScoreReq *.rsl\n(spec attr)" <> as rsl rectangle "fta_metamodel.puml\n(on PlantUML include path)" <> as meta - rectangle "fmea.template.rst\n({body})" <> as tmpl - rectangle "fm/cm lobster\nconfigs" <> as lcfg + rectangle "safety_analysis.template.rst\n({body})" <> as tmpl + rectangle "fm/safetymeasures lobster\nconfigs" <> as lcfg } -' ── fmea rule: three tool actions ──────────────────────────────────────────── -package "fmea rule actions" { +' ── safety_analysis rule: three tool actions ──────────────────────────────────────────── +package "safety_analysis rule actions" { component "puml_cli (FTA mode)\n--fta-output-dir\n[crate: puml_fta]" <> as puml - component "fmea_assembler\n[lib: TRLCRST]" <> as asm - component "lobster-trlc x2" <> as ltrlc + component "safety_analysis_assembler\n[lib: TRLCRST]" <> as asm + component "lobster-trlc x4" <> as ltrlc } ' ── Generated files ────────────────────────────────────────────────────────── package "Generated files" { rectangle "fta_*.puml\n(authored, symlinked)" <> as puml_inl - rectangle "fta_chains.json" <> as chains - rectangle "root_causes.lobster" <> as rc_lob - rectangle "fmea.rst" <> as fmea_rst - rectangle "failuremodes.lobster\ncontrolmeasures.lobster" <> as fmcm_lob + rectangle "fta_events.trlc\n(FtaFailureMode/RootCause stubs)" <> as fta_events + rectangle "safety_analysis.rst" <> as safety_analysis_rst + rectangle "failuremodes.lobster\nsafetymeasures.lobster\nfta_failure_modes.lobster\nfta_root_causes.lobster" <> as fmcm_lob } ' ── Providers ──────────────────────────────────────────────────────────────── -rectangle "SphinxSourcesInfo\n────────────────\nsrcs: fmea.rst\ndeps: fmea.rst\naux_srcs: fta_*.puml" <> as ssi -rectangle "AnalysisInfo.lobster_files\n────────────────\nfailuremodes.lobster\ncontrolmeasures.lobster\nroot_causes.lobster" <> as ai +rectangle "SphinxSourcesInfo\n────────────────\nsrcs: safety_analysis.rst\ndeps: safety_analysis.rst\naux_srcs: fta_*.puml" <> as ssi +rectangle "AnalysisInfo.lobster_files\n────────────────\nfailuremodes.lobster\nsafetymeasures.lobster\nfta_failure_modes.lobster\nfta_root_causes.lobster" <> as ai +rectangle "SafetyAnalysisProviderInfo\n────────────────\nfailuremodes, safetymeasures,\nfta_events, spec" <> as tpi ' ── Downstream rules + staging ─────────────────────────────────────────────── -component "dependability_analysis" <> as da +component "dependability_analysis\n(+ root-cause coverage check)" <> as da component "dependable_element" <> as de -rectangle "dependability_analysis/\n dfa.rst <- toctree\n fmea.rst <- toctree\n fta_*.puml (.. uml::)" <> as stage +rectangle "dependability_analysis/\n dfa.rst <- toctree\n safety_analysis.rst <- toctree\n fta_*.puml (.. uml::)" <> as stage ' ── Edges: inputs -> tools ─────────────────────────────────────────────────── fta_puml --> puml : parse macro calls -chains --> asm +fta_events --> asm fm_trlc --> asm -cm_trlc --> asm +sm_trlc --> asm rsl --> asm : import resolution tmpl --> asm fm_trlc --> ltrlc -cm_trlc --> ltrlc +sm_trlc --> ltrlc +fta_events --> ltrlc rsl --> ltrlc lcfg --> ltrlc ' ── Edges: tools -> generated ──────────────────────────────────────────────── -fta_puml --> puml_inl : symlinked beside fmea.rst +fta_puml --> puml_inl : symlinked beside safety_analysis.rst meta --> stage : on PlantUML include path -puml --> chains -puml --> rc_lob -asm --> fmea_rst +puml --> fta_events +asm --> safety_analysis_rst ltrlc --> fmcm_lob ' ── Edges: generated -> providers ──────────────────────────────────────────── -fmea_rst --> ssi +safety_analysis_rst --> ssi puml_inl --> ssi -rc_lob --> ai fmcm_lob --> ai +fm_trlc --> tpi +sm_trlc --> tpi +fta_events --> tpi ' ── Edges: providers -> downstream -> staging ──────────────────────────────── ssi --> da : merge SphinxSourcesInfo ai --> da : merge lobster_files +tpi --> da : merge for root-cause\ncoverage check da --> de de --> stage : symlink srcs + aux_srcs\n(aux not indexed in toctree) diff --git a/bazel/rules/rules_score/docs/_assets/seooc_flow.puml b/bazel/rules/rules_score/docs/_assets/seooc_flow.puml index ba783425..cbeecc2b 100644 --- a/bazel/rules/rules_score/docs/_assets/seooc_flow.puml +++ b/bazel/rules/rules_score/docs/_assets/seooc_flow.puml @@ -37,7 +37,7 @@ rectangle "Unit Design Diagrams\n(.puml / .rst)" <