Assumptions of Use¶
The SEooC contract with the integrator. Each AoU is a claim taktora makes about the integrator’s environment or process. The integrator MUST validate every AoU before claiming any ASIL for a taktora-hosted item.
The integrator supplies a diverse, independent Element B monitor of equivalent ASIL B(D) capability that observes taktora’s outputs and forces safe state on detected omission or value failure.
|
Element A (taktora) and Element B (monitor) run on independent CPU cores or independent SoCs, with independent power and clock domains where feasible.
|
The integrator implements the receiver side of taktora’s heartbeat
protocol and the safe-state forcing path with reaction time at most
|
The host OS provides MMU-enforced address-space isolation between processes and a deterministic scheduling discipline (real-time class or deadline-based scheduling). |
The integrator pins the SC process to dedicated CPU core(s) and configures it under SCHED_FIFO or SCHED_DEADLINE; QM processes are excluded from those cores.
|
The integrator validates that the assumed hazards (Loss of cyclic safety-criti... (AHZ_0001), Erroneous safety-critical c... (AHZ_0002)) and assumed safety goals (Prevent unintended terminat... (ASG_0001), Prevent silent corruption o... (ASG_0002)) match the result of their own HARA. The FTTI of 100 ms is confirmed or replaced.
|
The integrator’s application logic enters a defined safe state on
receipt of
|
The integrator’s own
|
The integrator confirms that the host OS kernel, libc, iceoryx2 runtime, and Rust toolchain are qualified to at least ASIL B(D). Taktora does not qualify these — they sit below taktora in the stack.
|