Coordinated exception handling in real-time distributed object systems
Alexander B. Romanovsky, Jianliang Xu, Brian Randell · 1999
layer between the scheduler and concrete operations on objects. This abstract layer can guarantee the system safety requirements, e.g. prevent the building of a system in which blanks and devices can collide, and therefore ease and simplify the task of designing and implementing a scheduler that controls the dynamic execution of CA actions. The proposed structuring framework used in this industry-oriented case study not only helps to precisely express real-time requirements, but also facilitates the tasks of handling time violation and recovering real-time exceptions. The resulted implementation displays clear program structuring and good system extendibility, especially for a complex system that contains concurrent cooperative activities. Our experience indicates that it would be a much more difficult task to design the system at the object level without the use of the CA action abstraction. 7: Conclusions This paper has focused on the topic of exception handling in OO real-time distributed systems. Our solutions are intended to be applicable to a wide set of practical real-time systems that interact with their environments (e.g., the production cell application); such systems typically are incapable of the simple backward recovery that is characteristic of transaction-based systems. The OO exception model developed in this paper extends and improves the models which may be found in sequential OO languages, and the non-concurrent models used in some concurrent OO languages. Our model also includes an approach to specifying real-time behaviour of a system at the level of CA actions. Methods for handling various time-related exceptions are identified. The principal merits of our approach are that it deals with the typical complexity of many industrial real-time systems, in which multiple activities, some competing for shared resources, others cooperating, are going on concurrently, and in which faults can occur, and cannot necessarily be simply masked. It thus emphasises the provision of error recovery, without unduly restricting such error recovery to being backward error recovery — since such a restriction can be quite