<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>open-DO</title>
	<atom:link href="http://www.open-do.org/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.open-do.org</link>
	<description>Toward a cooperative and open framework for the development of certifiable software</description>
	<lastBuildDate>Fri, 03 Feb 2012 16:13:41 +0000</lastBuildDate>
	
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Certification, Safety and Security at ERTS 2012</title>
		<link>http://www.open-do.org/2012/02/03/certification-safety-and-security-at-erts-2012/</link>
		<comments>http://www.open-do.org/2012/02/03/certification-safety-and-security-at-erts-2012/#comments</comments>
		<pubDate>Fri, 03 Feb 2012 15:06:10 +0000</pubDate>
		<dc:creator>Yannick Moy</dc:creator>
				<category><![CDATA[Events]]></category>
		<category><![CDATA[formal]]></category>

		<guid isPermaLink="false">http://www.open-do.org/?p=1918</guid>
		<description><![CDATA[We are now leaving the Embedded Real Time Systems and Software conference which was held in Toulouse for the last 3 days. The conference has been expanding since the last occurrence in 2010, with more international presence, many German companies in particular, and a large number of companies from the automotive industry (maybe this is [...]]]></description>
			<content:encoded><![CDATA[<p>We are now leaving the <a href="http://www.erts2012.org">Embedded Real Time Systems and Software conference</a> which was held in Toulouse for the last 3 days. The conference has been expanding since the last occurrence in 2010, with more international presence, many German companies in particular, and a large number of companies from the automotive industry (maybe this is related? <img src='http://www.open-do.org/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> ).</p>

<p>I was particularly interested in the increasing concern over techniques to address safety and security. Safety is not new in avionics/aerospace, but security is, and both safety and security are quite new for automotive. The key to understanding these concerns is the recent release of new safety certification in both avionics (DO-178C) and automotive (ISO-26262). Both put some emphasis (not at the same level, as one could expect) on static analysis and formal techniques.</p>

<p>Like two years ago, there were many presentations of work on formal methods and modelling, with many formal methods applying to modelling. Next episode in two years! </p>]]></content:encoded>
			<wfw:commentRss>http://www.open-do.org/2012/02/03/certification-safety-and-security-at-erts-2012/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Open-DO session at ERTS 2012</title>
		<link>http://www.open-do.org/2012/01/31/open-do-at-erts-2012/</link>
		<comments>http://www.open-do.org/2012/01/31/open-do-at-erts-2012/#comments</comments>
		<pubDate>Tue, 31 Jan 2012 09:49:07 +0000</pubDate>
		<dc:creator>Jamie Ayre</dc:creator>
				<category><![CDATA[Open-DO News]]></category>

		<guid isPermaLink="false">http://www.open-do.org/?p=1864</guid>
		<description><![CDATA[Many thanks to the organisers of the ERTS 2012 (Embedded Real-Time Software and Systems) conference for including a session linked to the Open-DO initiative. There will be 4 talks on the morning of Thursday February 2:

	Integrating Formal Program Verification with Testing (Cyrille Comar, Johannes Kanig and Yannick Moy) 

	Compilation of Heterogeneous Models: Motivations and Challenges [...]]]></description>
			<content:encoded><![CDATA[<p>Many thanks to the organisers of the <a href="http://www.erts2012.org/">ERTS 2012</a> (Embedded Real-Time Software and Systems) conference for including a session linked to the Open-DO initiative. There will be 4 talks on the morning of Thursday February 2:</br>

	<li>Integrating Formal Program Verification with Testing (Cyrille Comar, Johannes Kanig and Yannick Moy) </li>

	<li>Compilation of Heterogeneous Models: Motivations and Challenges (Matteo Bordin, Tonu Naks, Andres Toom and Marc Pantel)</li>

	<li>Formalization and Comparison of MCDC and Object Branch Coverage Criteria (Cyrille Comar, Jerome Guitton, Olivier Hainque, Thomas Quinot)</li>

	<li>Agility &#038; Lean for Avionic Software Development (<a href="http://emmanuelchenu.blogspot.com/">Emmanuel Chenu</a>)</li></br>

For more information on the event and to register, please visit<a href="http://www.erts2012.org/"> http://www.erts2012.org/</a></p>

]]></content:encoded>
			<wfw:commentRss>http://www.open-do.org/2012/01/31/open-do-at-erts-2012/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Prove Your Plane Now!</title>
		<link>http://www.open-do.org/2012/01/13/prove-your-plane-now/</link>
		<comments>http://www.open-do.org/2012/01/13/prove-your-plane-now/#comments</comments>
		<pubDate>Fri, 13 Jan 2012 13:54:02 +0000</pubDate>
		<dc:creator>Yannick Moy</dc:creator>
				<category><![CDATA[Certification]]></category>
		<category><![CDATA[Open-DO News]]></category>
		<category><![CDATA[Papers and Slides]]></category>
		<category><![CDATA[formal methods]]></category>

		<guid isPermaLink="false">http://www.open-do.org/?p=1911</guid>
		<description><![CDATA[The DO-333 is now available! (ok, that&#8217;s not free: 215$ for an electronic version, or 300$ for a hard copy, pfew!)


Under this amazingly explicit name is hiding the formal methods supplement for DO-178C. Or, said otherwise, the document that allows you, as a developer of avionics software, to replace tests/reviews/analyses by formal methods. Or you, [...]]]></description>
			<content:encoded><![CDATA[<p>The <a href="http://www.rtca.org/onlinecart/product.cfm?id=499">DO-333</a> is now available! (ok, that&#8217;s not free: 215$ for an electronic version, or 300$ for a hard copy, pfew!)
</p>

<p>Under this amazingly explicit name is hiding the formal methods supplement for DO-178C. Or, said otherwise, the document that allows you, as a developer of avionics software, to replace tests/reviews/analyses by formal methods. Or you, as a provider of techniques and tools for formal methods, to find customers in the avionics market. Ah yes, because the new version of the certification standard for avionics software, DO-178C, has been also issued at the same time. So that starts today!
</p>

<p>Here is what the abstract of this doc says:</p>

<p><em>This supplement identifies the additions, modifications and substitutions to
DO-178C and DO-278A objectives when formal methods are used as part of a
software life cycle, and the additional guidance required. It discusses those
aspects of airworthiness certification that pertain to the production of
software, using formal methods for systems approved using DO-178C.</em></p>

<p><em>
Formal methods are mathematically-based techniques for the specification,
development and verification of software aspects of digital systems. The
mathematical basis of formal methods consists of formal logic, discrete
mathematics and computer-readable languages. The use of formal methods is
motivated by the expectation that, as in other engineering disciplines,
performing appropriate mathematical analyses can contribute to establishing the
correctness and robustness of a design.</em></p>
]]></content:encoded>
			<wfw:commentRss>http://www.open-do.org/2012/01/13/prove-your-plane-now/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Executable Annotations for C Programs</title>
		<link>http://www.open-do.org/2012/01/09/executable-annotations-for-c-programs/</link>
		<comments>http://www.open-do.org/2012/01/09/executable-annotations-for-c-programs/#comments</comments>
		<pubDate>Mon, 09 Jan 2012 11:49:16 +0000</pubDate>
		<dc:creator>Yannick Moy</dc:creator>
				<category><![CDATA[Open-DO News]]></category>
		<category><![CDATA[Related Initiatives]]></category>
		<category><![CDATA[Formal verification]]></category>
		<category><![CDATA[Hi-Lite]]></category>

		<guid isPermaLink="false">http://www.open-do.org/?p=1908</guid>
		<description><![CDATA[The Frama-C platform, which integrates static analysis and formal proof of C programs, now has a plug-in for run-time execution of annotations. In particular, preconditions and postconditions written using the E-ACSL subset of the ACSL annotation language for C can now be executed thanks to this plug-in. This is a great move in the direction [...]]]></description>
			<content:encoded><![CDATA[<p>The Frama-C platform, which integrates static analysis and formal proof of C programs, now has <a href="http://frama-c.com/eacsl.html">a plug-in for run-time execution of annotations</a>. In particular, preconditions and postconditions written using the E-ACSL subset of the ACSL annotation language for C can now be executed thanks to this plug-in. This is a great move in the direction of better integration of proofs and tests for C programs!
</p>

<p>As far as I know, this is the first attempt at defining a common annotation language for tests and static analysis / proof for C. The annotation languages for C that I know of cannot be executed: Microsoft&#8217;s widely used <a href="http://msdn.microsoft.com/en-us/library/ms235402.aspx">Standard Annotation Language</a>, the annotation language used by the <a href="http://www.eschertech.com/products/ecv.php">Escher C Verifier</a> or the one from Microsoft&#8217;s <a href="http://research.microsoft.com/en-us/projects/vcc/">VCC</a>.
</p>

<p>Note that an important difference between this annotation language and others is that it uses mathematical semantics for operations in annotations. So an addition in annotations cannot overflow. In practice, they are using the GMP library for mathematical integers. Try it for yourself by downloading/installing <a href="http://frama-c.com/download.html">Frama-C</a> and <a href="http://frama-c.com/download/e-acsl/e-acsl-0.1.tar.gz ">this plug-in</a>!
</p>]]></content:encoded>
			<wfw:commentRss>http://www.open-do.org/2012/01/09/executable-annotations-for-c-programs/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>code.NASA</title>
		<link>http://www.open-do.org/2012/01/05/code-nasa/</link>
		<comments>http://www.open-do.org/2012/01/05/code-nasa/#comments</comments>
		<pubDate>Thu, 05 Jan 2012 08:11:19 +0000</pubDate>
		<dc:creator>Jamie Ayre</dc:creator>
				<category><![CDATA[In the Press]]></category>
		<category><![CDATA[Open Source]]></category>
		<category><![CDATA[Open-DO News]]></category>
		<category><![CDATA[Related Initiatives]]></category>

		<guid isPermaLink="false">http://www.open-do.org/?p=1905</guid>
		<description><![CDATA[An interesting new website added to the family of NASA websites. code.NASA, according the website, NASA &#8220;&#8230;will continue, unify, and expand NASA’s open source activities. The site will serve to surface existing projects, provide a forum for discussing projects and processes, and guide internal and external groups in open development, release, and contribution.&#8221;

More information can [...]]]></description>
			<content:encoded><![CDATA[<p>An interesting new website added to the family of NASA websites. <a href="http://code.nasa.gov/">code.NASA</a>, according the website, NASA &#8220;&#8230;will continue, unify, and expand NASA’s open source activities. The site will serve to surface existing projects, provide a forum for discussing projects and processes, and guide internal and external groups in open development, release, and contribution.&#8221;</p>

<p>More information can be found at:</br></br>

<a href="http://open.nasa.gov/blog/2012/01/04/the-plan-for-code/ ">http://open.nasa.gov/blog/2012/01/04/the-plan-for-code/ </a></br></br>

I particularly like the call for participation &#8211; &#8220;Will your code someday escape our solar system or land on an alien planet? We’re working to make it happen, and with your help, it will.&#8221;</p>]]></content:encoded>
			<wfw:commentRss>http://www.open-do.org/2012/01/05/code-nasa/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Prove &amp; Fly!</title>
		<link>http://www.open-do.org/2011/12/14/prove-fly/</link>
		<comments>http://www.open-do.org/2011/12/14/prove-fly/#comments</comments>
		<pubDate>Wed, 14 Dec 2011 13:51:40 +0000</pubDate>
		<dc:creator>Yannick Moy</dc:creator>
				<category><![CDATA[Certification]]></category>
		<category><![CDATA[Events]]></category>
		<category><![CDATA[formal methods]]></category>
		<category><![CDATA[Hi-Lite]]></category>
		<category><![CDATA[theorem proving]]></category>

		<guid isPermaLink="false">http://www.open-do.org/?p=1894</guid>
		<description><![CDATA[On December 5-6, I participated in the 2nd workshop on Theorem Proving in
Certification, in Cambridge (UK). This turned out to be even more interesting than last year&#8217;s program promised.

The goal of the workshop is to clarify under which conditions theorem proving
can be applied in the context of DO-178C Formal Methods Supplement (hence Prove &#038; Fly!):

	extent [...]]]></description>
			<content:encoded><![CDATA[<p>On December 5-6, I participated in the <a href="http://www.cl.cam.ac.uk/~mjcg/FMStandardsWorkshop.html">2nd workshop on Theorem Proving in
Certification</a>, in Cambridge (UK). This turned out to be even more interesting than last year&#8217;s program promised.</p>

<p>The goal of the workshop is to clarify under which conditions theorem proving
can be applied in the context of DO-178C Formal Methods Supplement (hence <em>Prove &#038; Fly!</em>):
<ul>
	<li>extent of verifications performed</li>
        <li>cost/benefit compared to testing</li>
	<li>characteristics of a technique/tool to be called <em>theorem proving</em></li>
	<li>tool qualification needs</li>
</ul></p>

<p>The workshop was organized around a common challenge (<em>gear nose challenge</em>) which all participants were
invited to address from different angles. The challenge was to compute the
velocity of the nose gear of a plane while on the ground.
This was made even more interesting by the need to comply with a small
certification standard (<em>Tamarack standard</em>). Both the challenge and the certification standard were
created by Jeff Joyce from CSL.</p>

<p>Besides sharing the strategy we follow in project Hi-Lite, and showing how it applied to the common challenge, 
I was very interested in the discussions we had over tool qualification and the alternate objectives to coverage in DO-178C, 
when using formal verification instead of testing. An interesting shared opinion was that the automatic prover does not need to 
be qualified if it generates a trace that can be double-checked independently by a theorem prover (based on a small set of induction rules). 
For example, <a href="http://www.divms.uiowa.edu/~astump/papers/fast-proof-checking-smt09.pdf">that&#8217;s the case for CVC3</a>.
In the discussion on alternate objectives to coverage, Jeff Joyce clearly stated that the underlying goal is to detect incompleteness
of specifications, or equivalently (from the opposite point of view) unintended functionalities. During the discussion, it appeared that
we may be able to use either model checking to perform a symbolic coverage analysis, or information given by automatic provers stating which
hypotheses (and thus source code constructs) were used in proofs, but for example not concolic testing which is based on source code.   
</p> 

<p>Many of these subjects will need to be further explored as DO-178C is adopted in new projects and tools based on formal methods are applied in this context. 
In particular, I look forward to the evolutions of the Tamarack standard and new solutions to the gear nose challenge.
Hot news: Open-DO will host the workshop forge and wiki to support these evolutions. <img src='http://www.open-do.org/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> 
</p>]]></content:encoded>
			<wfw:commentRss>http://www.open-do.org/2011/12/14/prove-fly/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Non-intrusive Code Coverage</title>
		<link>http://www.open-do.org/2011/11/16/non-intrusive-code-coverage/</link>
		<comments>http://www.open-do.org/2011/11/16/non-intrusive-code-coverage/#comments</comments>
		<pubDate>Wed, 16 Nov 2011 08:04:03 +0000</pubDate>
		<dc:creator>Jamie Ayre</dc:creator>
				<category><![CDATA[Agile/Lean Programming]]></category>
		<category><![CDATA[Certification]]></category>
		<category><![CDATA[In the Press]]></category>
		<category><![CDATA[Open Source]]></category>

		<guid isPermaLink="false">http://www.open-do.org/?p=1870</guid>
		<description><![CDATA[In his recent Embedded Computing Design article, Ben Brosgol discusses &#8220;Non-intrusive code coverage for safety-critical software&#8221; and more specifically how a &#8220;tool that derives precise source-level coverage metrics from execution trace data for a non-instrumented program&#8221; can really help with DO-178B evidence requirements. Abstract below with a link to the the full article&#8230;

Certification standards such [...]]]></description>
			<content:encoded><![CDATA[<p>In his recent <a href="http://embedded-computing.com/">Embedded Computing Design</a> article, Ben Brosgol discusses &#8220;Non-intrusive code coverage for safety-critical software&#8221; and more specifically how a &#8220;tool that derives precise source-level coverage metrics from execution trace data for a non-instrumented program&#8221; can really help with DO-178B evidence requirements. Abstract below with a link to the the full article&#8230;</p>

<p>Certification standards such as DO-178B for avionics require evidence that the system source code is completely exercised by tests derived from requirements. Traditional tools obtain the coverage data for a test run through code instrumentation, but this complicates analysis since the code being exercised is not the code that will finally execute.  A solution to this problem is provided by a combination of two new tools, one for target emulation and one for coverage analysis. GNATemulator translates target object code into native host instructions, with the resulting code running on the host. This approach is efficient (target code is not being interpreted dynamically) and convenient (a significant amount of development can be conducted without an actual target board). Running on an instrumented version of GNATemulator, the GNATcoverage tool non-intrusively provides coverage data at both the source and object levels. At the object code level the tool performs instruction and branch coverage. At the source code level it provides statement coverage, decision coverage, and Modified Condition/Decision Coverage (MC/DC), performing the necessary analysis when MC/DC cannot be deduced from object branch coverage, and fully supports all levels of DO-178B safety certification.</p>

<p><a href="http://embedded-computing.com/non-intrusive-code-coverage-safety-critical-software">http://embedded-computing.com/non-intrusive-code-coverage-safety-critical-software </a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.open-do.org/2011/11/16/non-intrusive-code-coverage/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Ada Connection 2011 &#8211; An Overview of DO-178C/ED-12C</title>
		<link>http://www.open-do.org/2011/10/26/do-178c-overview/</link>
		<comments>http://www.open-do.org/2011/10/26/do-178c-overview/#comments</comments>
		<pubDate>Wed, 26 Oct 2011 20:18:38 +0000</pubDate>
		<dc:creator>Jamie Ayre</dc:creator>
				<category><![CDATA[Events]]></category>
		<category><![CDATA[Videos]]></category>

		<guid isPermaLink="false">http://www.open-do.org/?p=1860</guid>
		<description><![CDATA[From the Ada Connection 2011 talks, Dewi Daniels from Verocel gives an overview of DO-178C/ED-12C

]]></description>
			<content:encoded><![CDATA[<p>From the <a href="http://conferences.ncl.ac.uk/adaconnection2011/" target="_blank">Ada Connection 2011</a> talks, Dewi Daniels from Verocel gives an overview of DO-178C/ED-12C</p>

<iframe width="480" height="274" src="http://www.youtube.com/embed/_G53ma0vX30" frameborder="0" allowfullscreen></iframe>]]></content:encoded>
			<wfw:commentRss>http://www.open-do.org/2011/10/26/do-178c-overview/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>NASA&#8217;s drive towards open source</title>
		<link>http://www.open-do.org/2011/10/26/nasas-drive-towards-open-source/</link>
		<comments>http://www.open-do.org/2011/10/26/nasas-drive-towards-open-source/#comments</comments>
		<pubDate>Wed, 26 Oct 2011 07:45:40 +0000</pubDate>
		<dc:creator>Jamie Ayre</dc:creator>
				<category><![CDATA[In the Press]]></category>
		<category><![CDATA[Open Source]]></category>

		<guid isPermaLink="false">http://www.open-do.org/?p=1857</guid>
		<description><![CDATA[An excellent interview in Military Embedded Systems this week looking at NASA&#8217;s drive towards open source software. Sharon Hess interviews Ray O&#8217;Brien, Chief Technology Officer for Information Technology at NASA Ames Research Center. In it, O&#8217;Brien discusses NASA&#8217;s OSS policy, projects, and the advantages they are seeing from interacting with the OSS community.]]></description>
			<content:encoded><![CDATA[An <a href="http://www.mil-embedded.com/articles/id/?5338">excellent interview in Military Embedded Systems</a> this week looking at NASA&#8217;s drive towards open source software. Sharon Hess interviews Ray O&#8217;Brien, Chief Technology Officer for Information Technology at NASA Ames Research Center. In it, O&#8217;Brien discusses NASA&#8217;s OSS policy, projects, and the advantages they are seeing from interacting with the OSS community.]]></content:encoded>
			<wfw:commentRss>http://www.open-do.org/2011/10/26/nasas-drive-towards-open-source/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Ada Connection 2011 &#8211; Real Time Longevity</title>
		<link>http://www.open-do.org/2011/10/25/real-time-longevit/</link>
		<comments>http://www.open-do.org/2011/10/25/real-time-longevit/#comments</comments>
		<pubDate>Tue, 25 Oct 2011 22:23:47 +0000</pubDate>
		<dc:creator>Jamie Ayre</dc:creator>
				<category><![CDATA[Agile/Lean Programming]]></category>
		<category><![CDATA[Events]]></category>
		<category><![CDATA[Videos]]></category>

		<guid isPermaLink="false">http://www.open-do.org/?p=1850</guid>
		<description><![CDATA[From the Ada Connection 2011 talks, Frederic Pinot from Ansaldo STS talks about his experiences developing real-time systems for high-speed rail.

]]></description>
			<content:encoded><![CDATA[<p>From the <a href="http://conferences.ncl.ac.uk/adaconnection2011/" target="_blank">Ada Connection 2011</a> talks, Frederic Pinot from Ansaldo STS talks about his experiences developing real-time systems for high-speed rail.</p>

<iframe width="480" height="274" src="http://www.youtube.com/embed/-0OSvFSQcw8" frameborder="0" allowfullscreen></iframe>]]></content:encoded>
			<wfw:commentRss>http://www.open-do.org/2011/10/25/real-time-longevit/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

