fix: hara risk.asil cross-validation + canonical standard id (v0.38.0) - #66
Closed
SoundMatt wants to merge 3 commits into
Closed
fix: hara risk.asil cross-validation + canonical standard id (v0.38.0)#66SoundMatt wants to merge 3 commits into
SoundMatt wants to merge 3 commits into
Conversation
x-FuSa spec §1.2.5 requires risk.asil to be MUST-derived from S×E×C per
ISO 26262-3:2018 Table 4, but DetermineASIL was only ever applied as a
fallback for an *empty* value — an already-present risk.asil was accepted
verbatim, so a hand-edited or copy-pasted hazard could claim any ASIL
regardless of its own S/E/C inputs with zero findings from `hara show` or
`check` (go-FuSa#62). Add hara.ValidateASIL (wrapped by new engine rule
HARA008, and folded into hara.Validate so `hara show`'s own gap list
surfaces it too) to flag a stored risk.asil that disagrees with the
table, skipping hazards with an incomplete S/E/C rating (HARA002's job)
or no risk.asil set. Verified against this repo's own checked-in
.fusa-hara.json: all 5 hazards' declared ASILs already match their S/E/C.
Separately, x-FuSa spec §2.4.1 requires standard ids to use the
canonical lowercase form ("iso26262") everywhere, never a display string
("ISO 26262") — `hara init`'s default --standard flag value and the
repo's own checked-in .fusa-hara.json still used the legacy display form
(go-FuSa#61). Changed the default to "iso26262", normalised the checked-in
file, and added hara.Load normalisation of a legacy display-string value
for backward compatibility with hand-authored files predating this
convention (an unrecognised id is still passed through verbatim).
Signed-off-by: Matt Jones <matt@jellybaby.com>
Signed-off-by: Matt Jones <47545907+SoundMatt@users.noreply.github.com>
Signed-off-by: Matt Jones <matt@jellybaby.com> Signed-off-by: Matt Jones <47545907+SoundMatt@users.noreply.github.com>
…eck-and-standard-id Signed-off-by: Matt Jones <47545907+SoundMatt@users.noreply.github.com> # Conflicts: # CHANGELOG.md # README.md # docs/tool-safety-manual.md # fusa.go
SoundMatt
force-pushed
the
fix/hara-asil-crosscheck-and-standard-id
branch
from
July 28, 2026 22:19
a1d5040 to
bd4d3fa
Compare
Owner
Author
|
Closing and replacing: my rebase onto main used a plain On branch fix/fmea-tara-paths-and-coverage-quality nothing to commit, working tree clean merge commit (missing DCO sign-off), then I attempted to fix it by amending + force-pushing — force-push is prohibited for this effort. Replacing with a fresh branch built via cherry-pick (no merge commits, no force-push) in a new PR. |
This was referenced Jul 28, 2026
Closed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
HARA008(+ exportedhara.ValidateASIL, folded intohara.Validatesogofusa hara show's own gap list surfaces it) cross-checks every hazard's storedrisk.asilagainstDetermineASIL(severity, exposure, controllability)per ISO 26262-3:2018 Table 4 — previously an already-presentrisk.asilwas accepted verbatim with no auditability, exactly the gap x-FuSa spec §1.2.5's "MUST derive" language exists to prevent.standardnow uses the x-FuSa spec §2.4.1 canonical lowercase id (iso26262) instead of the display string"ISO 26262":hara init's default--standardflag, the repo's own checked-in.fusa-hara.json, andhara.Loadnow normalises legacy display-string values for backward compatibility (unrecognised ids still pass through verbatim, per spec).Closes #62, closes #61.
Test plan
go build ./...go vet ./...go test -race -count=1 ./...(88.6% total coverage)golangci-lint run ./...(0 issues)go generate ./...(no diff).fusa-hara.json(5 hazards) all already have S/E/C-consistent ASILs — HARA008 does not fire against itValidateASILmismatch/match/incomplete-S-E-C/empty-ASIL cases,HARA008engine-rule fire/silent cases,Validateincludes the ASIL mismatch,hara.Loadstandard normalisation (legacy display string, already-canonical, unrecognised passthrough)