Repository navigation
Release v2.3.x contains breaking changes:
Renames (Bazel)
fmea(...) is now safety_analysis(...).
dependability_analysis(fmea = [...]) is now dependability_analysis(safety_analysis = [...]).
The controlmeasures attribute is replaced by safetymeasures. These files hold Mitigation, AoU and CompReq records.
New optional attribute fta_package sets the package name of the generated RootCause records. It defaults to _fta.
unit(...) and component(...) get an optional design_name. Use it when the PlantUML <>/<> name differs from the Bazel target name.
FTA .puml diagrams
$TopEvent(...) is now $FailureMode(name, "Pkg.FailureMode", ...). It accepts up to 8 failure modes per node.
$BasicEvent(name, "Pkg.Alias", conn) is now $RootCause(name, "Alias", conn). The alias is a plain name without a package prefix.
Root causes are generated as TRLC records in fta_events.trlc (package <fta_package>). They are not written by hand.
Each root cause links to the failure modes of the tree it sits under.
TRLC model (ScoreReq)
Removed: ControlMeasure, PreventiveMeasure and Measure.
Removed: the mitigates field on AoU and Mitigation.
Added: RootCause, the abstract SafetyMeasure, and FailureMode-to-RootCause links.
Mitigation no longer extends AssumedSystemReq. It now requires root_causes = [...] and justification.
AoU can have optional root_causes = [...].
CompReq.derived_from can reference a RootCause, unversioned. This makes the CompReq a control measure for that root cause.
CompReq.derived_from may only reference AoUs received from other dependable elements. An element's own AoUs are never a source.
Wiring (BUILD)
A safety_analysis target that an AoU references via root_causes must be listed in the deps of assumptions_of_use.
The same target must also be passed via safetymeasures to safety_analysis(...).
Migration:
BUILD
fmea becomes safety_analysis.
controlmeasures becomes safetymeasures.
dependability_analysis(fmea=...) becomes dependability_analysis(safety_analysis=...).
FTA .puml
$TopEvent becomes $FailureMode.
$BasicEvent(n, "Pkg.Alias", c) becomes $RootCause(n, "Alias", c). The alias is a plain identifier with no package prefix.
TRLC measures
Add import _fta, the generated package. It defaults to the target name plus _fta.
Delete ControlMeasure and PreventiveMeasure records and all mitigates fields.
Convert each former measure:
Mitigation: add root_causes = [_fta.] and justification.
CompReq: add derived_from = [_fta.], with no @Version. Add the safety_analysis target to that component_requirements target's deps.
AoU: add root_causes = [_fta.]. Add the safety_analysis target to the assumptions_of_use deps, and pass the file in safetymeasures.
Coverage
Every $RootCause needs a Mitigation, AoU or CompReq. Otherwise release maturity fails.
Every FailureMode needs a $RootCause under it.