IEEE Transactions on Software Engineering · 2001 · 178 citations · 5 references
EngineeringVerificationSoftware EngineeringSpacecraft Attitude ControlConcurrent SystemFormal VerificationAerospace RoboticsSpace RoboticsSystems EngineeringRuntime VerificationProcedural AbstractionConcurrent ProgrammingComputer EngineeringPlan Execution ModuleFormal AnalysisComputer ScienceProgram AnalysisAutomationMechanical SystemsFormal MethodsConcurrency TheoryExecutive Support LanguageRobotics
NASA’s New Millennium Remote Agent includes a multithreaded plan execution module that uses the domain‑specific language ESL to build reactive control mechanisms for autonomous spacecraft. The study applies the finite state model checker SPIN to formally analyze this multithreaded plan execution module. The authors translated the ESL services for managing interacting parallel goal‑and‑event driven processes into SPIN’s PROMELA language and used SPIN to perform the analysis. The analysis uncovered five previously unknown concurrency errors, including a major design flaw that caused a deadlock in flight, and prompted the adoption of procedural abstraction in SPIN.
The paper documents an application of the finite state model checker SPIN to formally analyze a multithreaded plan execution module. The plan execution module is one component of NASA's New Millennium Remote Agent, an artificial intelligence-based spacecraft control system architecture which launched in October of 1998 as part of the DEEP SPACE 1 mission. The bottom layer of the plan execution module architecture is a domain specific language, named ESL (Executive Support Language), implemented as an extension to multithreaded COMMON LISP. ESL supports the construction of reactive control mechanisms for autonomous robots and spacecraft. For the case study, we translated the ESL services for managing interacting parallel goal-and-event driven processes into the PROMELA input language of SPIN. A total of five previously undiscovered concurrency errors were identified within the implementation of ESL. According to the Remote Agent programming team, the effort has had a major impact, locating errors that would not have been located otherwise and, in one case, identifying a major design flaw. In fact, in a different part of the system, a concurrency bug identical to one discovered by this study escaped testing and caused a deadlock during an in-flight experiment, 96 million kilometers from Earth. The work additionally motivated the introduction of procedural abstraction in terms of inline procedures into SPIN.
5
Constructing compact models of concurrent Java programs
James C. Corbett · 1998 · 47 citations · Full text
Plan Execution for Autonomous Spacecraft
Barney Pell · 2002 · 17 citations