Skip to content

ORCA2Sat Requirements

Richard Arthurs edited this page Jul 22, 2018 · 15 revisions

CCP OBC Requirements

This document outlines the design and implementation requirements of the OBC for ORCA2Sat.

Each requirement has an ID for tracking. Requirements are referred to as DRs, meaning "design requirements." Requirements can reference other requirements for clarity, but should stand on their own. Requirements should follow the EARS syntax, which basically just means that they are concise, clear, and encapsulate only the required information to determine their scope.

To add an unknown item, please tag it as todo: and wrap with [ ].

Conditions or signals can be defined as all caps such as OFF_STATE and can be used in requirements. They must have a DR that defines them.

Headings for requirements sections are H3, which use a ### prefix.

Design requirement IDs are H4, #### prefix.


Hardware

OBC.HW.MEM.1

The OBC will have enough nonvolatile storage to save 7 days of telemetry logs and flags with 40 % magin.

OBC.HW.RTC.1

The OBC will have a realtime clock with minimum 1 second resolution.

OBC.HW.RTC.2

The RTC will start counting at 0 upon the first system power-on (shortly after deployment from the p-pod).

OBC.HW.RTC.3

The RTC shall be provided with a backup power source good for at least 7 days of backup power at the beginning of the mission.

OBC.HW.RTC.4

[removed]

OBC.HW.RTC.5

The RTC shall communicate with the OBC over an SPI interface.

OBC.HW.RTC.6

The RTC shall have a customizable alarm with an ALERT pin that will go HIGH when the alarm triggers. The OBC will configure the alarm to generate the ALERT signal at some point (defined in seconds) in the future. The OBC can also cancel an alarm.

OBC.HW.FF.1

The OBC shall conform to the UVIC backplane standard and will be a single blade.


State Handling

OBC.STATE.SAFE.1

This is the STATE_SAFE condition. The following conditions will trigger entry into SAFE mode:

  • A WD_RESET
  • RTC time not incrementing
  • No command received in 2 days

OBC.STATE.SAFE.2

The STATE_SAFE condition is entered automatically upon WD reset or after any power cycle of the OBC.

OBC.STATE.SAFE.3

In STATE_SAFE, the following tasks will run:

  • BMS checker
  • temperature logger
  • [todo: others]
  • BEACON_TX

In STATE_SAFE, the following tasks will be suspended:

  • payload operations
  • time-scheduled commands

OBC.STATE.SAFE.4

In STATE_SAFE, the BEACON_TX task shall be executed. BEACON_TX will do the following:

  • if power level permits, send out a standard telemetry packet 10 times with 5 seconds between packets, once every 5 minutes [todo: determine actual times]. This is used

OBC.STATE.SAFE.5

STATE_SAFE can be exited into:

  • STATE_READY by a command from the ground
  • STATE_LOW_POWER upon battery SoC dropping below [todo: level]

OBC.STATE.LP.1

This is the STATE_LOW_POWER condition. The following conditions will trigger entry into this state:

  • battery SoC below 30 %
  • command from the ground

Low Power

OBC.LP.1

The OBC shall have a LOW_POWER state that suspends all substantial activity [todo: define this better] and places the MCU in a low power state with wakeup conditions that are consistent with OBC.LP.2.

Note: this will probably use tickless idle

OBC.LP.2

The LOW_POWER state can be exited on the following conditions:

  • RTC ALERT
  • Message received over the radio

OBC.LP.3

The OBC shall utilize the FreeRTOS idle task hook to place itself in a lower power mode as frequently as possible.


General Software

OBC.SW.RTOS.1

The OBC shall run FreeRTOS version 10. Unless a critical bug fix comes out, the version will not be upgraded during the life of the project.

OBC.SW.WD.1

A task with maximum priority will be created to pet the external watchdog. It will be configured to run 2x as fast as the watchdog expires, nominally. This task can be suspended in an operation known as a WD_RESET.

OBC.SW.RTC.1

This is the RTC_ERROR condition.

If the RTC ceases to function, a 1 second timer shall be started and used to increment the epoch. This will be driven by a state machine in the RTC driver. The 1 second timer will be used to increment the onboard epoch instead of the hardware RTC until the RTC_ERROR condition is cleared from the ground.

OBC.SW.IF.1

Interface drivers (CAN, SPI, I2C) shall be designed not to lock up. They must all have timeouts and report error codes if timeouts fail. All internal error registers will be checked in the driver functions.

OBC.SW.IF.2

All interface drivers will be protected from multiple accesses by a FreeRTOS mutex.

OBC.SW.IF.3

If upstream functions receive an error code from a driver, they must be able to continue operation. They shall log the error code and revert to default values.


Health Checking

Note: the interval for these items should be the same so they can nicely go into one task.

OBC.SW.HCHK.1

A check every [todo: interval] will ensure that the RTC time is incrementing. If RTC is not incrementing, STATE_SAFE will be invoked and RTC_ERROR will be invoked.

OBC.SW.HCHK.2

Flag file entries will be checked for consistency against the OBC's onboard flag struct. If they are not the same, the mismatch shall be logged as an error and STATE_SAFE entered. This check will occur at [todo: interval].


Filesystem

OBC.FS.1

The OBC shall implement a file system for access to nonvolatile storage. The filesystem will allow creation, deletion and retrieval of files.

OBC.FS.2

Two categories of files will be used. Log files will contain timestamped data. Flag files will be persistent and will contain backups of system configuration parameters.

OBC.FS.3

All entries to log files will be automatically timestamped with the mission epoch at time of write.

OBC.FS.4

An estimate of space remaining on the file system will be available by command.

OBC.FS.5

A new set of log files will be created every 24 hours.

OBC.FS.6

If there is insufficient space on the filesystem to support a write, the oldest set of log files will be deleted and a message logged.

OBC.FS.7

The filesystem shall have a convenient, printf-style API for writing to telemetry log files.

OBC.FS.9

The chosen filesystem library shall provide error checks and codes.

OBC.FS.10

If a filesystem operation does not succeed, it shall not be reattempted. An error will be logged. A filesystem clean operation will be executed. A detected failure of a filesystem clean will not trigger another filesystem clean operation (this prevents loops).

OBC.FS.11

The number of failed filesystem operations will be logged. If it reaches 5 since last hard reset, an attempt will be made to log the error. Then a WD_RESET will be invoked. The stdtelem error code will be set to FS_CRITICAL_ERR.


Telemetry

OBC.TELEM.1

The OBC telemetry packet will consist of the following fields:

  • stdtelem_error_code
  • [todo: add other things]

OBC.TELEM.2

The stdtelem_error_code is a prioritized error code that is kept in context without nonvolatile memory, with the idea being that it can be invoked even if external flash is not working.

It has the following fields, with priority 10 being highest (most urgent or critical) priority FS_CRITICAL_ERR - 10


Command Handling

OBC.CMD.TO.1

Upon receiving a command from the ground, a software timer shall be reset. The timer shall have an expiry period of 2 days. If the timer expires, STATE_SAFE will be entered.

OBC.CMD.FS.1

WIPE_AND_RESET command shall completely erase all nonvolatile memory and then issue a WD_RESET to promote re-generation of flag files.

OBC.CMD.RTC.1

The ability for the RTC_ERROR status flag to be cleared from the ground will be present.

OBC.CMD.RTC.2

A command shall be provided to read the current RTC epoch, regardless of RTC_ERROR status.


Operational Requirements

This is a placeholder for operational requirements.

OBC.OPS.FS.1

Upon detecting FS_CRITICAL_ERR stdtelem_error_code, the ground crew will issue WIPE_AND_RESET command to the satellite after attempting to downlink data.