Measurement-based timing analysis of applications written in ANSI-C

Bernhard Rieder · reposiTUm (TU Wien) · 2009

of Aplications written in ANSI-C Since the development of the rst electronic engine control systems the applications of electronic systems in cars have steadily increased.Currently there is a shift from mechanical safety-critical systems to networks of safety-critical embedded real-time systems which provide the potential for increased functionality and huge monetary savings.The increased functionality comes at the cost of increased complexity.The applications running in a modern luxury car come close to a total of 100 million lines of source code, distributed over networks of 70-100 microprocessor electronic control units (ECU) from dierent vendors.To minimize errors in the design standardized architectures like AUTOSAR and communication buses like FlexRay or CAN are used to ensure the interoperability of modules.Model-checkers, verication and proling tools are used to analyze the software of individual modules.The aspect of time is often underrated and many faults of control systems are a direct result of timing errors.During the last years a few timing analysis tools have emerged.Some of them use formal methods to calculate the execution-time of a task-based on a processor model, other tools use measurements to determine an estimate for the worstcase execution-time (WCET).Hybrid WCET analysis tools combine static analysis of the application source code, which makes this part of the analysis hardware independent, with execution-time measurements carried out on the target hardware to generate a hardware specic timing model of the analyzed application.This work extends the hybrid timing analysis approach introduced during the MoDECS project to support loops, function calls and control-ow in logic AND and OR expressions which are required to measure the execution-time of industrial real-time applications.The revised hybrid WCET analysis approach comprises the following steps: Static analysis is used on the ANSI-C source code to examine the program structure.C is commonly used in the implementation of control systems and the use of a high level language as input makes the analysis platform independent.During the static analysis functions are identied and either expanded like C++ inline functions or analyzed in a separate analysis run.Loops are also detected in this analysis step and checked for input data dependency.When required, which is when the number of iterations or the control-ow within the loop body depends on input data, the loop bound is determined using model checking.Last but not least additional control-ow paths which are generated by C short-circuiting of logic AND and OR expressions are analyzed and added to the control-ow graph.Control Flow Graph (CFG) Partitioning is used to automatically split programs into smaller program segments (PS) which can be analyzed with reasonable eort.Test Data Generation is used to generate test data to cover all paths within a program segment.Paths that are not covered by random test data are examined using model checking.Model checking is an expensive process but it can be used to generate test data to force the execution of a specic path within a program segment or to identify infeasible paths.Execution Time Measurements are used on all paths within each program segment except the paths identied as infeasible during the test data generation.This produces a timing prole containing the worst-case execution-time for each program segment. Worst Case Execution Time (WCET) Calculation uses the structural information gained during the static analysis to combine the execution-times of individual program segments into a WCET bound for the whole analyzed application. * This has been contributed together with Ingomar Wenzel during the MoDECS project [WRKP05].

Read the paper · More papers on PaperTik