Assumed HARA — Hazards and Safety Goals¶
Illustrative Hazard Analysis and Risk Assessment driving the FFI argument. Integrators MUST run their own HARA per ISO 26262-3 §6; the entries below are assumed inputs (AOU_0006).
Assumed Hazards¶
E/S/C ratings are illustrative for a typical electromechanical actuator. ASIL is determined per ISO 26262-3 Table 4.
Control loop silently halted by QM-grade subsystem corrupting executor state in the same address space.
|
Output computed from corrupted shared-memory channel written by a QM-grade subsystem (stray pointer, buffer overflow, intentional compromise of a non-critical dependency).
|
Assumed Safety Goals¶
Safety goals are the top-level functional intent that addresses the hazards. Each ASG carries the ASIL of its source hazard.
Assumed Safety Goal: Prevent unintended termination of the safety-critical cyclic computation ASG_0001
|
Prevent unintended termination of the safety-critical cyclic computation by lower-integrity software co-hosted in the same item.
|
Prevent silent corruption of safety-critical input/output data by lower-integrity software co-hosted in the same item.
|