EDBT 2026 Demo / reviewers in the wild / expert
Andy J. Wellings
dblp:w/AndyJWellings · also Andrew J. Wellings
· DBLP profile ↗
97ranked-venue papers
10as first author
1since 2021 · last 2021
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 33 · 2 first-author · 1 since 2021Software engineering, systems software and programming languages · 22 · 2 first-authorApplied, interdisciplinary, general and emerging computing · 16 · 2 first-authorTheory of computation · 5Computer networks · 1
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Computer architecture, parallel and distributed computing, and storage systems
17 papers |
Embedded and real-time systems · 59% Parallel and multicore computing · 16% Cloud and datacenter computing · 16% | |
| Software engineering, system software, and programming languages
6 papers |
Runtime systems and virtual machines · 73% Concurrent programming · 14% Programming languages and type systems · 12% |
Topics — the 30 heaviest of 39, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Embedded and real-time systems
real-time scheduling |
0.9 | 13 | 2021 | Priority Assignment on Partitioned Multiprocessor Systems With Shared Resources · IEEE Trans. Computers 2021 Garbage Collection for Flexible Hard Real-Time Systems · IEEE Trans. Computers 2010 Hard Real-Time Hybrid Garbage Collection with Low Memory Requirements · RTSS 2006 |
Parallel and multicore computing
multiprocessor system |
0.5 | 1 | 2021 | Priority Assignment on Partitioned Multiprocessor Systems With Shared Resources · IEEE Trans. Computers 2021 |
Embedded and real-time systems › real-time scheduling › priority scheduling
priority assignment |
0.5 | 1 | 2021 | Priority Assignment on Partitioned Multiprocessor Systems With Shared Resources · IEEE Trans. Computers 2021 |
Cloud and datacenter computing › resource management
shared resource management |
0.5 | 1 | 2021 | Priority Assignment on Partitioned Multiprocessor Systems With Shared Resources · IEEE Trans. Computers 2021 |
Runtime systems and virtual machines
garbage collection |
0.2 | 2 | 2010 | Garbage Collection for Flexible Hard Real-Time Systems · IEEE Trans. Computers 2010 Hard Real-Time Hybrid Garbage Collection with Low Memory Requirements · RTSS 2006 |
Runtime systems and virtual machines › garbage collection
real-time garbage collection |
0.2 | 2 | 2010 | Garbage Collection for Flexible Hard Real-Time Systems · IEEE Trans. Computers 2010 Hard Real-Time Hybrid Garbage Collection with Low Memory Requirements · RTSS 2006 |
Storage systems › flash and SSD › flash memory management
garbage collection |
0.1 | 1 | 2010 | Garbage Collection for Flexible Hard Real-Time Systems · IEEE Trans. Computers 2010 |
Embedded and real-time systems › real-time scheduling
schedulability analysis |
0.1 | 3 | 2005 | Cost Monitoring and Enforcement in the Real-Time Specification for Java - A Formal Evaluation · RTSS 2005 Effective Analysis for Engineering Real-Time Fixed Priority Schedulers · IEEE Trans. Software Eng. 1995 Mode Changes In Priority Pre-Emptively Scheduled Systems · RTSS 1992 |
Embedded and real-time systems
real-time programming languages |
0.1 | 1 | 2006 | Programming Execution-Time Servers in Ada 2005 · RTSS 2006 |
Embedded and real-time systems › real-time scheduling › schedulability analysis
response time analysis |
0.1 | 4 | 1998 | Real-Time Scheduling in a Generic Fault-Tolerant Architecture · RTSS 1998 Analysing APEX applications · RTSS 1996 Effective Analysis for Engineering Real-Time Fixed Priority Schedulers · IEEE Trans. Software Eng. 1995 |
Distributed systems
fault tolerance |
0.1 | 2 | 2000 | Replica Determinism and Flexible Scheduling in Hard Real-Time Dependable Systems · IEEE Trans. Computers 2000 GUARDS: A Generic Upgradable Architecture for Real-Time Dependable Systems · IEEE Trans. Parallel Distributed Syst. 1999 |
Hardware reliability and fault tolerance
fault-tolerant architecture |
0.0 | 2 | 1999 | GUARDS: A Generic Upgradable Architecture for Real-Time Dependable Systems · IEEE Trans. Parallel Distributed Syst. 1999 Real-Time Scheduling in a Generic Fault-Tolerant Architecture · RTSS 1998 |
Concurrent programming
memory models |
0.0 | 1 | 2011 | The Safety-Critical Java Memory Model: A Formal Account · FM 2011 |
Embedded and real-time systems › real-time scheduling
fixed-priority scheduling |
0.0 | 2 | 1996 | Analysing APEX applications · RTSS 1996 Effective Analysis for Engineering Real-Time Fixed Priority Schedulers · IEEE Trans. Software Eng. 1995 |
Embedded and real-time systems
real-time communication |
0.0 | 2 | 1996 | An Efficient and Practical Local Synchronous Bandwidth Allocation Scheme for the Timed-Token MAC Protocol · INFOCOM 1996 Analysing Real-Time Communications: Controller Area Network (CAN) · RTSS 1994 |
Programming languages and type systems › concurrent programming languages
concurrent object-oriented programming |
0.0 | 1 | 2000 | Integrating object-oriented programming and protected objects in Ada 95 · ACM Trans. Program. Lang. Syst. 2000 |
Programming languages and type systems
extensibility |
0.0 | 1 | 2000 | Integrating object-oriented programming and protected objects in Ada 95 · ACM Trans. Program. Lang. Syst. 2000 |
Distributed systems › replication › state machine replication
active replication |
0.0 | 1 | 2000 | Replica Determinism and Flexible Scheduling in Hard Real-Time Dependable Systems · IEEE Trans. Computers 2000 |
Distributed systems
distributed scheduling |
0.0 | 1 | 2000 | Replica Determinism and Flexible Scheduling in Hard Real-Time Dependable Systems · IEEE Trans. Computers 2000 |
Embedded and real-time systems
real-time operating systems |
0.0 | 2 | 1999 | Formal development of a real-time kernel · RTSS 1997 GUARDS: A Generic Upgradable Architecture for Real-Time Dependable Systems · IEEE Trans. Parallel Distributed Syst. 1999 |
Embedded and real-time systems › real-time embedded systems
hard real-time systems |
0.0 | 1 | 2006 | Hard Real-Time Hybrid Garbage Collection with Low Memory Requirements · RTSS 2006 |
Concurrent programming › atomicity
atomic operations |
0.0 | 1 | 1997 | Implementing Atomic Actions in Ada 95 · IEEE Trans. Software Eng. 1997 |
Embedded and real-time systems › real-time operating systems
real-time kernel |
0.0 | 1 | 1997 | Formal development of a real-time kernel · RTSS 1997 |
Internet architecture and protocols › resource reservation
synchronous bandwidth allocation |
0.0 | 1 | 1996 | An Efficient and Practical Local Synchronous Bandwidth Allocation Scheme for the Timed-Token MAC Protocol · INFOCOM 1996 |
Wireless networking › multiple access protocols
timed token protocol |
0.0 | 1 | 1996 | An Efficient and Practical Local Synchronous Bandwidth Allocation Scheme for the Timed-Token MAC Protocol · INFOCOM 1996 |
Embedded and real-time systems › real-time scheduling › soft real-time scheduling
soft deadline scheduling |
0.0 | 1 | 1995 | Dual Priority Scheduling · RTSS 1995 |
Embedded and real-time systems › real-time communication
controller area network |
0.0 | 1 | 1994 | Analysing Real-Time Communications: Controller Area Network (CAN) · RTSS 1994 |
Embedded and real-time systems › real-time scheduling › priority scheduling
preemptive priority scheduling |
0.0 | 1 | 1993 | The use of preemptive priority-based scheduling for space applications · RTSS 1993 |
Embedded and real-time systems › real-time scheduling › fixed-priority scheduling
fixed-priority preemptive scheduling |
0.0 | 1 | 1992 | Mode Changes In Priority Pre-Emptively Scheduled Systems · RTSS 1992 |
Embedded and real-time systems › real-time scheduling › adaptive real-time scheduling
mode change |
0.0 | 1 | 1992 | Mode Changes In Priority Pre-Emptively Scheduled Systems · RTSS 1992 |
Methods — techniques the papers use, named apart from their topics
schedulability analysis · 0.5slack-based priority ordering · 0.5dual priority scheduling · 0.3reference counting · 0.1sporadic server · 0.1mark-and-sweep · 0.1mark and sweep · 0.1deferrable server · 0.1extended timed automata · 0.1UPPAAL model checking · 0.1response time analysis · 0.0RTL · 0.0PVS · 0.0worst-case achievable utilization analysis · 0.0
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2021 | Priority Assignment on Partitioned Multiprocessor Systems With Shared ResourcesabstractDriven by industry demand, there is an increasing need to develop real-time multiprocessor systems which contain shared resources. The Multiprocessor Stack Resource Policy (MSRP) and Multiprocessor resource sharing Protocol (MrsP) are two major protocols that manage access to shared resources. Both of them can be applied to Fixed-Priority Preemptive Scheduling (FPPS), which is enforced by most commercial real-time systems regulations, and which requires task priorities to be assigned before deployment. Along with MSRP and MrsP, there exist two forms of schedulability tests that bound the worst-case blocking time due to resource accesses: the traditional ones being more widely adopted and the more recently developed holistic ones which deliver tighter analysis. On uniprocessor systems, there are several well-established optimal priority assignment algorithms. Unfortunately, on multiprocessor systems with shared resources, the issue of priority assignment has not been adequately understood. In this article, we investigate three mainstream priority assignment algorithms-Deadline Monotonic Priority Ordering (DMPO), Audsley's Optimal Priority Assignment (OPA), and Robust Priority Assignment (RPA), in the context of partitioned multiprocessor systems with shared resources. Our contributions are multifold: First, we prove that DMPO is optimal with the traditional schedulability tests. Second, two counter examples are given as evidence that DMPO is not optimal with the tighter holistic schedulability tests. Third, we then analyze the pessimism arising from the adoption of OPA and RPA with the holistic tests. Lastly, we propose a Slack-based Priority Ordering (SPO) algorithm that minimises such pessimism, and has polynomial time complexity. Comprehensive experiments show that SPO outperforms (i.e., results in a larger number of schedulable systems) DMPO, OPA, and RPA in general with the holistic schedulability tests, by up to 15 percent. With the theoretical contributions, this paper is a useful guide to priority assignment in real-time partitioned multiprocessor systems with shared resources. Shuai Zhao 0004, Wanli Chang 0001, Weichen Liu 0001, Nan Guan, Alan Burns 0001, Andy J. Wellings |
IEEE Trans. Computers | 7 |
| 2020 | A complete run-time overhead-aware schedulability analysis for MrsP under nested resources
Shuai Zhao 0004, Jorge Garrido, Alan Burns 0001, Andy J. Wellings, Juan Antonio de la Puente |
J. Syst. Softw. | 5 |
| 2020 | Development Automation of Real-Time Java: Model-Driven Transformation and SynthesisabstractMany applications in emerging scenarios, such as autonomous vehicles, intelligent robots, and industrial automation, are safety-critical with strict timing requirements. However, the development of real-time systems is error prone and highly dependent on sophisticated domain expertise, making it a costly process. This article utilises the principles of model-driven engineering (MDE) and proposes two methodologies to automate the development of real-time Java applications. The first one automatically converts standard time-sharing Java applications to real-time Java applications, using a series of transformations. It is in line with the observed industrial trend, such as for the big data technology, of redeveloping existing software without the real-time notion to realise the real-time features. The second one allows users to automatically generate real-time Java application templates with a lightweight modelling language, which can be used to define the real-time properties—essentially a synthesis process. This article opens up a new research direction on development automation of real-time programming languages and inspires many research questions that can be jointly investigated by the embedded systems, programming languages as well as MDE communities. Wanli Chang 0001, Shuai Zhao 0004, Andy J. Wellings, Jim Woodcock 0001, Alan Burns 0001 |
ACM Trans. Embed. Comput. Syst. | 4 |
| 2019 | From Java to real-time Java: a model-driven methodology with automated toolchain (invited paper)abstractReal-time systems are receiving increasing attention with the emerging application scenarios that are safety-critical, complex in functionality, high on timing-related performance requirements, and cost-sensitive, such as autonomous vehicles. Development of real-time systems is error-prone and highly dependent on the sophisticated domain expertise, making it a costly process. There is a trend of the existing software without the real-time notion being re-developed to realise real-time features, e.g., in the big data technology. This paper utilises the principles of model-driven engineering (MDE) and proposes the first methodology that automatically converts standard time-sharing Java applications to real-time Java applications. It opens up a new research direction on development automation of real-time programming languages and inspires many research questions that can be jointly investigated by the embedded systems, programming languages as well as MDE communities. Wanli Chang 0001, Shuai Zhao 0004, Andy J. Wellings, Alan Burns 0001 |
LCTES | 4 |
| 2019 | SCJ-Circus: Specification and refinement of Safety-Critical Java programs
Alvaro Miyazawa, Ana Cavalcanti 0001, Andy J. Wellings |
Sci. Comput. Program. | 3 |
| 2017 | New schedulability analysis for MrsPabstractIn this paper we consider a spin-based multi-processor locking protocol, named the Multiprocessor resource sharing Protocol (MrsP). MrsP adopts a helping-mechanism where the preempted resource holder can migrate. The original schedulability analysis of MrsP carries considerable pessimism as it has been developed assuming limited knowledge of the resource usage for each remote task. In this paper new MrsP schedulability analysis is developed that takes into account such knowledge to provide a less pessimistic analysis than that of the original analysis. Our experiments show that, theoretically, the new analysis offers better (at least identical) schedulability than the FIFO non-preemptive protocol, and can outperform FIFO preemptive spin locks under systems with either intensive resource contention or long critical sections. The paper also develops analysis to include the overhead of MrsP's helping mechanism. Although MrsP's helping mechanism theoretically increases schedulability, our evaluation shows that this increase may be negated when the overheads of migrations are taken into account. To mitigate this, we have modified the MrsP protocol to introduce a short non-preemptive section following migration. Our experiments demonstrate that with migration cost, MrsP may not be favourable for short critical sections but provides a better schedulability than other FIFO spin-based protocols when long critical sections are applied. Shuai Zhao 0004, Jorge Garrido, Alan Burns 0001, Andy J. Wellings |
RTCSA | 4 |
| 2017 | Safety-Critical Java: level 2 in practiceabstractSummary Safety‐Critical Java (SCJ) is a profile of the Real‐Time Specification for Java that brings to the safety‐critical industry the possibility of using Java. SCJ defines three compliance levels: Level 0, Level 1 and Level 2. The SCJ specification is clear on what constitutes a Level 2 application in terms of its use of the defined API but not the occasions on which it should be used. This paper broadly classifies the features that are only available at Level 2 into three groups: nested mission sequencers, managed threads and global scheduling across multiple processors. We explore the first two groups to elicit programming requirements that they support. We identify several areas where the SCJ specification needs modifications to support these requirements fully; these include the following: support for terminating managed threads, the ability to set a deadline on the transition between missions and augmentation of the mission sequencer concept to support composibility of timing constraints. We also propose simplifications to the termination protocol of missions and their mission sequencers. To illustrate the benefit of our changes, we present excerpts from a formal model of SCJ Level 2 written inCircus, a state‐rich process algebra for refinement. Copyright © 2016 John Wiley & Sons, Ltd. Matt Luckcuck, Andy J. Wellings, Ana Cavalcanti 0001 |
Concurr. Comput. Pract. Exp. | 2 |
| 2017 | Safety-critical Java for embedded systemsabstractSummary This paper presents the motivation for and outcomes of an engineering research project on certifiable Java for embedded systems. The project supports the upcoming standard for safety‐critical Java, which defines a subset of Java and libraries aiming for development of high criticality systems. The outcome of this project include prototype safety‐critical Java implementations, a time‐predictable Java processor, analysis tools for memory safety, and example applications to explore the usability of safety‐critical Java for this application area. The text summarizes developments and key contributions and concludes with the lessons learned. Copyright © 2016 John Wiley & Sons, Ltd. Martin Schoeberl, Andreas Engelbredt Dalsgaard, René Rydhof Hansen, Stephan Korsholm, Anders P. Ravn, Juan Ricardo Rios, Tórur Biskopstø Strøm, Hans Søndergaard, Andy J. Wellings, Shuai Zhao 0004 |
Concurr. Comput. Pract. Exp. | 9 |
| 2017 | A Distributed Stream Library for Java 8abstractJava 8 has introduced new capabilities such as lambda expressions and streams which simplify data-parallel computing. However, as a base language for Big Data systems, it still lacks a number of important capabilities such as processing very large datasets and distributing the computation over multiple machines. This paper gives an overview of the Java 8 Streams API and proposes extensions to allow its use in Big Data systems. It also shows how the API can be used to implement a range of standard Big Data paradigms. Finally, it compares performance with that of Hadoop and Spark. Despite being a proof-of-concept implementation, results indicate that it is a lightweight and efficient framework, comparable in performance to Hadoop and Spark, and is up to 5 times faster for the largest input sizes tested. Yu Chan, Andy J. Wellings, Ian Gray, Neil C. Audsley |
IEEE Trans. Big Data | 2 |
| 2016 | Modelling and Verifying a Priority Scheduler for an SCJ Runtime EnvironmentabstractSafety-Critical Java (SCJ) is a version of Java suitable for programming real-time safety-critical systems; it is the result of an international standardisation effort to define a subset of the Real-Time Specification for Java (RTSJ). SCJ programs require the use of specialised virtual machines. We present here the result of our verification of the scheduler of the only SCJ virtual machine up to date with the standard and publicly available, the icecap HVM. We describe our approach for analysis of (SCJ) virtual machines, and illustrate it using the icecap HVM scheduler. Our work is based on a state-rich process algebra that combines Z and CSP, and we take advantage of well established tools. Leo Freitas, James Baxter 0001, Ana Cavalcanti 0001, Andy J. Wellings |
IFM | 4 |
| 2016 | A Formal Model of the Safety-Critical Java Level 2 Paradigm
Matt Luckcuck, Ana Cavalcanti 0001, Andy J. Wellings |
IFM | 3 |
| 2016 | A Java-Based Real-Time Reactive Stream FrameworkabstractThis paper presents a framework for real-time reactive stream processing. The approach is to extend the proposed Java 9 Reactive Streams model and integrate it with the Real-Time Specification for Java. The approach leverages a real-time version of the Java 8 Stream processing framework. Our approach addresses the major issue when using Reactive Streams in real-time: there is no way to set the timeout. Our evaluation shows there is significant improvement in the predictability of stream processing with our framework over that of one implemented using regular Java. Haitao Mei 0001, Ian Gray, Andy J. Wellings |
ISORC | 3 |
| 2016 | Architecting Time-Critical Big-Data SystemsabstractCurrent infrastructures for developing big-data applications are able to process -via big-data analytics- huge amounts of data, using clusters of machines that collaborate to perform parallel computations. However, current infrastructures were not designed to work with the requirements of time-critical applications; they are more focused on general-purpose applications rather than time-critical ones. Addressing this issue from the perspective of the real-time systems community, this paper considers time-critical big-data. It deals with the definition of a time-critical big-data system from the point of view of requirements, analyzing the specific characteristics of some popular big-data applications. This analysis is complemented by the challenges stemmed from the infrastructures that support the applications, proposing an architecture and offering initial performance patterns that connect application costs with infrastructure performance. Pablo Basanta-Val, Neil C. Audsley, Andy J. Wellings, Ian Gray, Norberto Fernández García |
IEEE Trans. Big Data | 3 |
| 2015 | Improving the predictability of distributed stream processors
Pablo Basanta-Val, Norberto Fernández García, Andy J. Wellings, Neil C. Audsley |
Future Gener. Comput. Syst. | 3 |
| 2014 | Circus Models for Safety-Critical Java ProgramsabstractSafety-critical Java (SCJ) is a restriction of the real-time specification for Java to support the development and certification of safety-critical applications. The SCJ technology specification is the result of an international effort from industry and academia. In this paper, we present a formalization of the SCJ Level 1 execution model, formalize a translation strategy from SCJ into a refinement notation and describe a tool that largely automates the generation of the formal models. Our modelling language is part of the Circus family; at the core, we have Z, communicating sequential processes and Morgan's calculus, but we also use object-oriented and timed constructs from the OhCircus and Circus Time variants. Our work is an essential ingredient for the development of refinement-based reasoning techniques for SCJ. Frank Zeyda, Lalkhumsanga Lalkhumsanga, Ana Cavalcanti 0001, Andy J. Wellings |
Comput. J. | 4 |
| 2014 | Introduction to the Special Issue on Java Technologies for Real-Time and Embedded Systems: JTRES 2012abstractEmbedded systems are deployed on a broad diversity of processors, architectures and operating systems. We require higher-level programming languages and specialised tools to help design, produce and maintain real-time embedded software. The Java environment's characteristics such as portability, reuse and modular composability makes it especially valuable for developing embedded systems. The interest in real-time Java by both the academic research community and commercial industry has been motivated by the need to manage the complexity and costs associated with continually expanding embedded real-time software systems. Embedded software frequently needs to comply with real-time constraints, which makes it particularly complex. The size of embedded applications is growing significantly each year; many of today's embedded systems are very large, having millions of lines of code. The Workshop on Java Technologies for Real-Time and Embedded Systems (JTRES) is dedicated to research on Java for embedded real-time systems. JTRES 2012, the 10th workshop in the series, was organised in Copenhagen, Denmark. The goal of the workshop was to gather researchers working on real-time and embedded Java to identify the challenging problems that still need to be solved in order to assure the success of real-time Java as a technology, and to report results and experiences gained by researchers. While in previous workshops, much of the work in real-time distributed, embedded and real-time Java has focused on the Real-time Specification for Java as the underlying base technology; in this edition, the focus has been on critical systems and software productivity. It is essential that the production of real-time embedded systems takes advantage, not only of the Java language but also tools, frameworks and methods that enable higher software productivity. This special issue of Concurrency and Computation: Practice and Experience contains three invited papers from JTRES 2012. These papers have been expanded and carefully peer reviewed. The papers highlight topics of special interest: very resource-constrained systems, resource consumption, and tools for analysing, debugging and testing critical systems. Critical real-time and embedded systems have stringent timing requirements and are often very constrained in their use of resources. The Safety-Critical Java for Low-End Embedded Platforms 1 paper presents a time and memory-constrained embedded platforms (i.e. 16 kB RAM and 256 kB flash), with a bare metal kernel implementing hardware objects. The implementation includes a hardware-based Java virtual machine, which can be easily ported to embedded platforms having a C compiler, while the bare metal approach eliminates the need for a resource-consuming operating system or C-library. The authors, Søndergaard, Korsholm and Ravn, have evaluated the platform with an implementation of the Safety-Critical Java profile. For real-time and embedded systems, limiting the consumption of time and memory resources is often an important part of the requirements. The prediction of bounds on the consumption of both time and memory resources is crucial. For critical systems, the bounds of needed resources must be known in advance (i.e. during the development process). The paper Making Resource Analysis Practical for Real-Time Java 2 by Kersten et al. presents a tool, called ResAna that makes it possible to analyse Real-Time Java systems to determine the loop bounds, heap size bounds and stack size bounds. This tool, in addition to performing generally application analyses, allows the analysis to be applied to the development of the Java (real-time) virtual machine. In general, visual debugging greatly improves programme understanding and cycle development times of general (non-real-time) applications. However, debugging and tracing critical systems often requires low-level hardware support and online debugging, which is troubleshooting and requires specialised tools. In JI.Fi : Visual Test and Debug Queries for Hard Real-Time 3, Blanton et al. introduce a visual test and debug framework for hard real-time Java applications. This framework, called Ji.Fi is built on the Jive platform and the Fiji VM. It provides high-level debugging support over low-level execution traces. Ji.Fi provides both powerful visualisations and real-time centric temporal query support. To ensure the preservation of the real-time characteristics of the application being tested and debugged, this framework logs only relevant application and virtual machine level events (e.g. synchronisation and modifications of threadÂťs priorities or states). This results in a visualisation infrastructure whose performance is uniform and quantifiable, and which is suitable for hard real-time systems. As editors, we thank the authors for contributing to this special issue, and also extend our gratitude to all the reviewers whose dedication ensured a good selection of articles and made this special issue possible. M. Teresa Higuera-Toledano, Andy J. Wellings |
Concurr. Comput. Pract. Exp. | 2 |
| 2013 | A Schedulability Compatible Multiprocessor Resource Sharing Protocol - MrsPabstractLock-based resource sharing protocols for single processor systems are well understood and supported in programming languages and in Real-Time Operating Systems. In contrast, multiprocessor resource sharing protocols are less well developed with no agreed best practice. In this paper we propose a new multiprocessor variant of a protocol based on the single processor priority ceiling protocol. The distinctive nature of the new protocol is that tasks waiting to gain access to a resource must service the resource on behalf of other tasks that are waiting for the same resource (but have been preempted). The form of the protocol is motivated by the desire to link the protocol with effective schedulability analysis. The protocol is general purpose, but is developed in this paper for partitioned fixed priority systems with the sporadic task model. Two methods of supporting the protocol are described, as is a prototype `proof of concept' implementation for one of these schemes. Alan Burns 0001, Andy J. Wellings |
ECRTS | 2 |
| 2013 | Supporting lock-based multiprocessor resource sharing protocols in real-time programming languagesabstractSUMMARY Lock‐based resource sharing protocols for single processor systems are well understood and supported in programming languages such as Ada and the Real‐Time Specification for Java, and in Real‐Time Operating Systems, such as those that conform to the Real‐Time POSIX standard. In contrast, multiprocessor resource sharing protocols are still in their infancy with no agreed best practices, and yet current real‐time programming languages and operating systems claim to be suitable for multiprocessor applications. This paper reviews the currently available multiprocessor resource allocation policies and analyzes their applicability to the main industry standard real‐time programming languages. It then proposes a framework that allows programmers to define and implement their own locking policy. A prototype implementation of the framework for Ada is presented and evaluated. Copyright © 2012 John Wiley & Sons, Ltd. Shiyao Lin, Andy J. Wellings, Alan Burns 0001 |
Concurr. Comput. Pract. Exp. | 2 |
| 2013 | The Safety-Critical Java memory model formalisedabstractAbstract Safety-Critical Java (SCJ) is a version of Java for real-time programming, restricted to facilitate certification of implementations of safety-critical systems. Its development is the result of an international effort involving experts from industry and academia. What we provide here is, as far as we know, the first formalisation of the SCJ model of memory regions. We use Hoare and He’s unifying theories of programming (UTP), enabling the integration of our theory with refinement models for object orientation and concurrency. In developing the SCJ theory, we also make a contribution to UTP by providing a general theory of invariants (an instance of which is used in the SCJ theory). The results presented here are a first essential ingredient to formalise the novel programming paradigm embedded in SCJ, and enable the justification and development of formal reasoning techniques based on refinement. Ana Cavalcanti 0001, Andy J. Wellings, Jim Woodcock 0001 |
Formal Aspects Comput. | 2 |
| 2013 | Safety-critical Java programs from Circus models
Ana Cavalcanti 0001, Frank Zeyda, Andy J. Wellings, Jim Woodcock 0001 |
Real Time Syst. | 3 |
| 2012 | Asynchronous event handling and Safety Critical JavaabstractSUMMARY Over the last few years, the Java Community Process (under the auspices of Java Specification Request 302) has been developing a subset of Java augmented by the Real‐Time Specification for Java (RTSJ) for use in safety critical systems. The concurrency model supported by Safety Critical Java (SCJ) relies almost exclusively on an event‐based model rather than on a thread‐based model. This paper reviews the advantages and disadvantages of the two models and gives the pragmatic reasons that SCJ has adopted the former model. It describes the SCJ approach and gives a simple example of how it can be used, illustrating the difference in style between the RTSJ and SCJ code. The paper then considers the compatibility of the SCJ model with the RTSJ. It argues that by basing the SCJ classes on the RTSJ'sBoundAsyncEventclass, some inconsistencies exist between the SCJ and the RTSJ models. Furthermore, some of the optimizations that are possible when mapping handlers to server threads are inhibited, even though the programming restrictions necessary for these optimizations are imposed by the SCJ specification. A revised model is presented that has a slightly more complicated API but is more consistent with the RTSJ and allows the optimizations. However, there is a resulting increase in the necessary run‐time support, particularly for multiprocessor implementations. Copyright © 2011 John Wiley & Sons, Ltd. Andy J. Wellings, Minseong Kim 0002 |
Concurr. Comput. Pract. Exp. | 1 |
| 2011 | The Safety-Critical Java Memory Model: A Formal Account
Ana Cavalcanti 0001, Andy J. Wellings, Jim Woodcock 0001 |
FM | 2 |
| 2011 | The Safety-Critical Java Mission Model: A Formal Account
Frank Zeyda, Ana Cavalcanti 0001, Andy J. Wellings |
ICFEM | 3 |
| 2011 | Multiprocessors and Asynchronous Event Handling in the Real-Time Specification for JavaabstractThe Real-Time Specification for Java (RTSJ) is silent on multiprocessor issues. It attempts not to preclude multiprocessor implementations but provides no direct support. Many areas of the RTSJ leave an implementation considerable freedom on how it provides the defined functionality. One such area is the asynchronous event handling (AEH) model. Events are fired and associated handlers are scheduled for execution in response; handlers have defined scheduling parameters and deadlines. The primary goal of the AEH model is to support a lightweight real-time concurrency model. Hence handlers, in general, do not have dedicated threads. Rather, the implementation is responsible for ensuring that all handlers meet their deadlines. Typically real-time threads are assigned to execute handlers by the implementation. This paper discusses the issues associated with implementing the AEH model on multiprocessor systems. The emphasis here is on achieving a lightweight model. A model is lightweight if it is able to meet the deadlines of all handlers with as few as possible real-time threads. In the RTSJ this is made more complicated because asynchronous event handlers are allowed to suspend themselves (for example, by waiting on a monitor condition). Such handlers are called blocking handlers. Most of an implementation's freedom comes from being able to optimize the support for those handlers that do not block. The paper first examines all possible releasing sequences of non-blocking handlers on multiprocessor systems. Based on this, it proposes an efficient and scalable AEH mapping model for multiprocessor systems, which limits the number of real-time threads even in the worst case while retaining the schedulability of the system. The proposed model is then examined to prove its safety and liveness requirements using a model checking tool, UPPAAL. The verification and simulation results of the model indicate that the safety and liveness requirements are satisfied. Most importantly, this paper derives the proposed model's greatest lower and least upper bounds of real-time threads required to execute a given number of non-blocking handlers. The greatest lower bound is equal to the number of processors, and the least upper bound is equal to the number of processors times that of the priority levels in the system. In the model, the number of real-time threads required to execute a given number of non-blocking handlers is restricted to between these two bounds depending on the releasing sequence of handlers. Even in the worst case, the model requires the least upper bound of real-time threads which is, in most cases, considerably less than the actual number of handlers in the system. This, in turn, enables the proposed model to be efficient and scalable by reducing time and space overheads, compared with a traditional 1:1 AEH mapping model where each handler is mapped to a single thread. Minseong Kim 0002, Andy J. Wellings |
Comput. J. | 2 |
| 2011 | Applying fixed-priority preemptive scheduling with preemption threshold to asynchronous event handling in the RTSJabstractAbstract The primary goal of asynchronous event handlers (handlers for short) in the Real‐Time Specification for Java (RTSJ) is to have a lightweight concurrency mechanism. The emphasis here is on ‘lightweightness’ which should be achieved by having fewer real‐time threads (servers for short) to execute more handlers. However, it is generally unclear how to efficiently map handlers to servers. In this paper we first define the worst case scenario that demands the least upper bound of servers for self‐suspending and non‐self‐suspending handlers. Based on the worst case scenarios, it is proved that the number of servers required to execute a given number of non‐self‐suspending handlers depends on the number of priority levels, and not on the number of handlers. It is also shown that each self‐suspending handler is required to have its own server to prevent unbounded priority inversion. Based on these results we also propose to adapt the notion of preemption threshold to further minimize the number of priority levels in the system. We have extended the non‐self‐suspending asynchronous event handling (AEH) implementation to support the fixed‐priority scheduling with preemption threshold on an existing RTSJ implementation to show that the number of servers can be further decreased while feasibly scheduling a set of non‐self‐suspending handlers, regardless of the number of the handlers or the priority levels in the system. Copyright © 2010 John Wiley & Sons, Ltd. Minseong Kim 0002, Andy J. Wellings |
Concurr. Comput. Pract. Exp. | 2 |
| 2011 | A model-based development approach for the verification of real-time Java codeabstractAbstract Many real‐time systems are safety‐and security‐critical systems and, as a result, tools and techniques for verifying them are extremely important. Simulation and testing such systems can be exceedingly time‐consuming and these techniques provide only probabilistic measures of correctness. There are a number of model‐checking tools for real‐time systems. Although they provide formal verification for models, we still need to implement these models. To increase the confidence in real‐time programs written in real‐time Java, this paper proposes a model‐based approach to the development of such programs. First, models can be mechanically verified, to check whether they satisfy particular properties, by using current real‐time model‐checking tools. Then, programs can be derived from the model by following a systematic approach. We introduce a timed automata to RTSJ Tool (TART), a prototype tool to automatically generate real‐time Java code from the model. Finally, we show the applicability of our approach by means of four examples: a gear controller, an audio/video protocol, a producer/consumer and the Fischer protocol. Copyright © 2011 John Wiley & Sons, Ltd. Niusha Hakimipour, Paul A. Strooper, Andy J. Wellings |
Concurr. Comput. Pract. Exp. | 3 |
| 2010 | An Admission Control Protocol for Real-Time OSGiabstractIn previous work we motivated the need for using the OSGi Framework with the RTSJ to develop real-time systems. We found a number of issues with using these technologies together. One of the issues we discovered was unbounded dynamism caused by the absence of admission control. Components can be uninstalled, installed and updated without regulation. This means that it is impossible to guarantee resources to components. In this paper, we propose a solution to the unbounded dynamism problem by providing an admission control protocol for real-time OSGi. We also provide a priority assignment approach to support temporal isolation. The combination of admission control and temporal isolation ensure that it is safe to update components or install components into the system in terms of guaranteeing resources to components. We show the practicality of our admission control protocol by implementing a prototype and measuring the execution time overhead incurred when performing a component install with admission control. Thomas Richardson 0003, Andy J. Wellings |
ISORC | 2 |
| 2010 | TART: Timed-Automata to Real-Time Java ToolabstractIn previous work, we have proposed a model based approach to developing real-time Java programs from timed automata. This approach allows us to verify the timed automata model mechanically by using current real-time model checking tools. Programs are then derived from the model by following a systematic approach. TART (timed automata to RTSJ Tool) is a prototype tool to support this approach. This paper presents TART, including its limitations, and discusses its application on four examples. Niusha Hakimipour, Paul A. Strooper, Andy J. Wellings |
SEFM | 3 |
| 2010 | Focus Section EditorialabstractInternationally each year, thousands of PhDs are awarded in Computer Science and related disciplines. While many result in conference and journal publications, one of the main thesis components, the literature review, is often not published. In recognition of the potential value of these underutilized resources,Software Practice and Experience has dedicated this Focus Section to the publication of papers based on the literature reviews that appeared in PhD theses awarded during 2008. All the submissions were subject to the Journal's normal review process and the best three papers appear here. Most software projects nowadays involve multiple developers often at multiple geographically distributed sites. Successful project development requires that these developers have a common awareness of the state of the project tasks, artefacts, and the activities of the project developers. The first paper of this Focus Section is taken from the PhD of Inrah Omoronyia entitled ‘Sharing Awareness during Distributed Collaborative Software Development’. It presents a comparison of awareness needs, and reviews how they are supported in current tools and techniques. The advent of multicore/manycore architectures, grid computing, and cloud computing has spurred much renewed interest in parallel programming activities. The second paper is taken from the PhD of Horacio Gonzalez-Velez entitled ‘Adaptive Structured Parallelism’. It presents a survey of the skeletal frameworks, which are commonly used patterns of parallel computations, communication, and coordination. These frameworks provide the control flow, nesting, resource monitoring, and portability for parallel programs. In recent years, there has been an explosion of information that is stored in databases of one form or another. Statistical Databases are databases that are used for statistical analysis purposes. They can contain potentially sensitive data and, therefore, raise significant security concerns for protecting the privacy of individuals. The final paper of this Focus Section is taken from the PhD work of Ebaa Fayyoumi entitled ‘Novel Micro-Aggregation Techniques for Secure Statistical Databases’. It surveys the fields of Statistical Disclosure Control and Micro-Aggregation techniques, which are both areas fundamentally important for ensuring that individual responses cannot be extracted from any captured data. R. Nigel Horspool, Andy J. Wellings |
Softw. Pract. Exp. | 2 |
| 2010 | Garbage Collection for Flexible Hard Real-Time SystemsabstractHard real-time systems always choose not to use garbage collection in order to avoid its unpredictable executions. Much effort has been expended trying to build predictable garbage collectors which can provide both temporal and spatial guarantees. Unfortunately, most existing work leads to systems that cannot easily achieve a balance between temporal and spatial performances. Moreover, the scheduling of garbage collectors has not been integrated into modern real-time scheduling frameworks, which makes the benefits provided by the advancement of scheduling techniques very difficult to obtain. This paper argues that the existing design criteria for real-time garbage collectors do not reflect the unique requirements of flexible hard real-time systems. As a part of our design criteria, a new performance indicator is proposed to describe the capability of a real-time garbage collector to achieve a better balance between temporal and spatial performances. A hybrid garbage collection algorithm is designed accordingly which also uses dual priority scheduling algorithm to reclaim spare capacity while guaranteeing deadlines. Yang Chang, Andy J. Wellings |
IEEE Trans. Computers | 2 |
| 2010 | Efficient asynchronous event handling in the real-time specification for JavaabstractThe Real-Time Specification for Java (RTSJ) is becoming mature. It has been implemented, formed the basis for research and used in serious applications. Some strengths and weaknesses are emerging. One of the areas that requires further elaboration is asynchronous event handling (AEH). The primary goal for handlers in the RTSJ is to have a lightweight concurrency mechanism. Some implementation will, however, simply map a handler to a real-time thread and this results in undermining the original motivations and introduces performance penalties. However it is generally unclear how to map handlers to real-time threads effectively. Also the support for nonblocking handlers in the RTSJ is criticized as lacking in configurability as implementations are unable to take advantage of them. This article, therefore, examines the AEH techniques used in some popular RTSJ implementations and proposes two efficient AEH models for the RTSJ. We then define formal models of the RTSJ AEH implementations using the automata formalism provided by the UPPAAL model checking tool. Using the automata models, their properties are explored and verified. In the proposed models, blocking and nonblocking handlers are serviced by different algorithms. In this way, it is possible to assign a real-time thread to a handler at the right time in the right place while maintaining the fewest possible threads overall and to give a certain level of configurability to AEH. We also have implemented the proposed models on an existing RTSJ implementation, jRate and executed a set of performance tests that measure their respective dispatch and multiple-handler completion latencies. The results from the tests and the verifications indicate that the proposed models require fewer threads on average with better performance than other approaches. Minseong Kim 0002, Andy J. Wellings |
ACM Trans. Embed. Comput. Syst. | 2 |
| 2010 | Measuring and policing blocking times in real-time systemsabstractIn real-time systems, the execution-time overrun of a thread may lead to a deadline being missed by the thread or even others threads in the system. From a fault tolerance perspective, both execution time overruns and deadline misses can be considered timing errors that could potentially cause a failure in the system's ability to deliver its services in a timely manner. In this context, the ideal is to detect the error in the system as soon as possible, so that the propagation of the error can be limited and error recovery strategies can take place with more accurate information. The run-time support mechanism usually deployed for monitoring the timing requirements of real-time systems is based on deadline monitoring, that is, the system calls specific application code whenever a deadline is violated. Recognizing that deadline monitoring may not be enough for providing an adequate level of fault tolerance for timing errors, major real-time programming standards, like Ada, POSIX and the Real-Time Specification for Java (RTSJ), have proposed different mechanisms for monitoring the execution time of threads. Nevertheless, in order to provide a complete fault tolerance approach for timing errors, the potential blocking time of threads also has to be monitored. In this article, we propose mechanisms for measuring and policing the blocking time of threads in the context of both basic priority inheritance and priority ceiling protocols . The notion of blocking-time clocks and timers for the POSIX standard is proposed, implemented and evaluated in the open-source real-time operating system MaRTE OS. Also, a blocking time monitoring model for measuring and policing blocking times in the RTSJ framework is specified. This model is implemented and evaluated in the (RTSJ-compliant) open-source middleware jRate, running on top of MaRTE OS. Osmar Marchi dos Santos, Andy J. Wellings |
ACM Trans. Embed. Comput. Syst. | 2 |
| 2010 | A framework for flexible scheduling in the RTSJabstractThis article presents a viable solution to introducing flexible scheduling in the Real-Time specification for Java (RTSJ), in the form of a flexible scheduling framework. The framework allows the concurrent use of multiple application-defined scheduling policies, each scheduling a subset of the total set of threads. Moreover, all threads, regardless of the policy under which they are scheduled, are permitted to share common resources. Thus, the framework can accommodate a variety of interworking applications (soft, firm, and hard) running under the RTSJ. The proposed approach is a two-level scheduling framework, where the first level is the RTSJ priority scheduler and the second level is under application control. This article describes the framework's protocol, examines the different types of scheduling policies that can be supported, and evaluates the proposed framework by measuring its execution cost. A description of an application-defined Earliest-Deadline-First (EDF) scheduler illustrates how the interface can be used. Minimum backward-compatible changes to the RTSJ specification are discussed to motivate the required interface. The only assumptions made about the underlying real-time operating system is that it supports preemptive priority-based dispatching of threads and that changes to priorities have immediate effect. Alexandros Zerzelidis, Andy J. Wellings |
ACM Trans. Embed. Comput. Syst. | 2 |
| 2009 | Refactoring Asynchronous Event Handling in the Real-Time Specification for JavaabstractThe primary goal for asynchronous event handling (AEH) in the Real-Time Specification for Java (RTSJ) is to have a lightweight concurrency mechanism. However the RTSJ neither provides a well-defined guideline on how to implement AEH nor requires the documentation of the AEH model used in the implementation. Also the AEH API in the RTSJ are criticized as lacking in configurability as they do not provide any means for programmers to have fine control over the AEH facilities, such as the mapping between real-time threads and handlers. For these reasons, it needs the refactoring of its application programming interface (API) to give programmers more configurability. This paper, therefore, proposes a set of AEH related classes and interfaces to enable flexible configurability over AEH components. We have implemented the refactored configurable AEH API using the new specifications on an existing RTSJ implementation and this paper shows that it allows more configurability for programmers than the current AEH API in the RTSJ does. Consequently programmers are able to specifically tailor the AEH subsystem to fit their applicationspsila particular needs. Minseong Kim 0002, Andy J. Wellings |
ECRTS | 2 |
| 2009 | Thread-Local Scope Caching for Real-time JavaabstractThere is increasing convergence between the fields of parallel and embedded computing. The demand for more functionality in embedded devices means that complex multicore architectures will be used. In order to promote scalability and obtain predictability, on-chip processor-local private memory subsystems will be used. Whilst at the hardware level this is technical feasible, the more pressing problem is how such memory is presented to the programmer and how its local access is policed.In this paper we illustrate how Java augmented by the Real-time Specification for Java can be used to present the abstraction of a thread-local scoped memory area. We show how to enforce access to the memory area to a single real-time thread. We implement the model on the JOP multiprocessor system and report on our experiences. Andy J. Wellings, Martin Schoeberl |
ISORC | 1 |
| 2008 | Multiprocessors and the Real-Time Specification for JavaabstractCurrently, the Real-Time Specification for Java (RTSJ) is silent on multiprocessor issues It attempts not to preclude multiprocessor implementations but provides no direct support. This paper discusses the issues that need to be addressed if the RTSJ is to be better defined for execution on a multiprocessor system. It proposes new dispatching and allocation models. Issues of cost enforcement, interrupts affinity and processor failure are covered. Andy J. Wellings |
ISORC | 1 |
| 2008 | Run Time Detection of Blocking Time Violations in Real-Time SystemsabstractThe run-time support mechanism usually deployed for monitoring the timing requirements of real-time systems is based on deadline monitoring, i.e., the system calls specific application code whenever a deadline is violated. However, from a fault-tolerance point-of-view, deadline miss is the final error in a chain of errors that results from some fault in the execution of one or more threads. Recognising this, major real-time programming standards, like Ada, POSIX and the RTSJ, have proposed different mechanisms for monitoring the execution time of threads. Nevertheless, in order to provide a complete fault-tolerance approach against timing errors, the potential blocking time of threads also has to be monitored. In this paper, we propose a mechanism for monitoring the blocking time of threads in the context of both basic priority inheritance and priority ceiling protocols. We also implement and evaluate the mechanism with the definition of blocking-time clocks and timers (extending the POSIX standard), via the modification of the open-source operating system MaRTE OS. Osmar Marchi dos Santos, Andy J. Wellings |
RTCSA | 2 |
| 2008 | Implementation of a constant-time dynamic storage allocatorabstractAbstract This paper describes the design criteria and implementation details of a dynamic storage allocator for real‐time systems. The main requirements that have to be considered when designing a new allocator are concerned with temporal and spatial constraints. The proposed algorithm, called TLSF (two‐level segregated fit), has an asymptotic constant cost,O(1), maintaining a fast response time (less than 200 processor instructions on a x86 processor) and a low level of memory usage (low fragmentation). TLSF uses two levels of segregated lists to arrange free memory blocks and anincomplete searchpolicy. This policy is implemented with word‐size bitmaps and logical processor instructions. Therefore, TLSF can be categorized as a good‐fit allocator. The incomplete search policy is shown also to be a good policy in terms of fragmentation. The fragmentation caused by TLSF is slightly smaller (better) than that caused by best fit (which is one of the best allocators regarding memory fragmentation). In order to evaluate the proposed allocator, three analyses are presented in this paper. The first one is based on worst‐case scenarios. The second one provides a detailed consideration of the execution cost of the internal operations of the allocator and its fragmentation. The third analysis is a comparison with other well‐known allocators from the temporal (number of cycles and processor instructions) and spatial (fragmentation) points of view. In order to compare them, a task model has been presented. Copyright © 2007 John Wiley & Sons, Ltd. Miguel Masmano, Ismael Ripoll, Jorge Real, Alfons Crespo, Andy J. Wellings |
Softw. Pract. Exp. | 5 |
| 2007 | Integrating Priority Inheritance Algorithms in the Real-Time Specification for JavaabstractPriority inversion and priority inheritance protocols for bounding blocking time are well-understood topics in realtime systems research. The two most commonly used priority inheritance protocols are basic priority inheritance and priority ceiling emulation. Although both are supported in POSIX, Ada and the Real-Time Specification for Java (RTSJ), little has been written about the consequences of using both protocols concurrently in the same program. The assumption is usually that only one is in force at any particular time. For large real-time systems, this assumption may not be valid. This paper provides motivation for why a mixture of the two can occur and illustrates that this can result in the raising of unwanted asynchronous exception. This has led the Technical Interpretation Committee for the RTSJ to propose a new version of the priority ceiling emulation protocol that will enable it to work in harmony with basic priority inheritance. The protocol is described and we use the UPPAAL tool to explore formal properties using model checking Andy J. Wellings, Alan Burns 0001, Osmar Marchi dos Santos, Benjamin M. Brosgol |
ISORC | 1 |
| 2007 | Cost enforcement in the real-time specification for Java
Osmar Marchi dos Santos, Andy J. Wellings |
Real Time Syst. | 2 |
| 2006 | Real-Time Memory Management: Life and TimesabstractAs real-time and embedded systems become increasingly large and complex, the traditional strictly static approach to memory management begins to prove untenable. The challenge is to provide a dynamic memory model that guarantees tight and bounded time and space requirements without overburdening the developer with memory concerns. This paper provides an analysis of memory management approaches in order to characterise the tradeoffs across three semantic domains: space, time and a characterisation of memory usage information such as the lifetime of objects. A unified approach to distinguishing the merits of each memory model highlights the relationship across these three domains, thereby identifying the class of applications that benefit from targeting a particular model. Crucially, an initial investigation of this relationship identifies the direction future research must take in order to address the requirements of the next generation of complex embedded systems. Some initial suggestions are made in this regard and the memory model proposed in the real-time specification for Java is evaluated in this context Andrew Borg, Andy J. Wellings, Christopher D. Gill, Ron Cytron |
ECRTS | 2 |
| 2006 | Getting More Flexible Scheduling in the RTSJabstractThis paper illustrates how the real-time specification for Java (RTSJ) can be modified to allow applications to implement more flexible scheduling. The proposed approach is a two-level scheduling mechanism where the first level is the RTSJ priority scheduler and the second level is under application control. Minimum, backward-compatible changes to the RTSJ specification are discussed to motivate the required interface. The only assumptions made about the underlying real-time operating system are that it supports pre-emptive priority-based dispatching and that changes to priorities have immediate effect. Alexandros Zerzelidis, Andy J. Wellings |
ISORC | 2 |
| 2006 | Programming Execution-Time Servers in Ada 2005abstractMuch of the research on scheduling schemes is prevented from being used in practice by the lack of implementations that provide the necessary abstractions. An example of this is the support of execution-time servers. Apart for a single mechanism (the sporadic server), which is defined in the POSIX standard, these important building blocks are not available to the system developer. Over the last few years, we have been developing the mechanisms necessary to construct execution-time servers from within an Ada context. Versions of these have now been incorporated in the Ada 2005 standard. In this paper, we show how the mechanisms can be used to construct the deferrable and sporadic servers Alan Burns 0001, Andy J. Wellings |
RTSS | 2 |
| 2006 | Hard Real-Time Hybrid Garbage Collection with Low Memory RequirementsabstractReal-time garbage collection algorithms are usually criticised for their high memory requirements. Even when consuming nearly 50% of CPU time, some garbage collectors ask for at least twice the memory as really needed. This paper explores the fundamental reason for this problem and proposes a new performance indicator for the evaluation of real-time garbage collection algorithms. Use of this performance indicator motivates an algorithm that combines both reference counting and mark-and-sweep techniques. In the presence of our collector, a garbage collected hard real-time system can achieve the correct balance of time-space tradeoff with less effort. In order to provide both temporal and spatial guarantees needed by a hard real-time application, an offline analysis is developed and integrated into the response time analysis framework. Moreover, the use of dual priority scheduling of the garbage collection tasks allows spare capacity in the system to be reclaimed whilst guaranteeing deadlines Yang Chang, Andy J. Wellings |
RTSS | 2 |
| 2005 | Temporal Isolation in Ravenscar-JavaabstractRavenscar-Java is a subset of Java (augmented by the real-time specification for Java) targeted at high-integrity real-time systems. It has recently been extended to support multiple applications of mixed criticality on the same Java platform. A two level scheduling model is used to achieve temporal isolation between applications. This paper presents the general schedulability analysis for the approach, describes how the approach can be implemented using standard real-time POSIX facilities, illustrates how the analysis can be modified to take into account the implementation, and uses the prototype implementation to evaluate the accuracy of the analysis models. Andy J. Wellings |
ISORC | 2 |
| 2005 | Integrating Hybrid Garbage Collection with Dual Priority SchedulingabstractIn this paper, we propose an approach to integrate a hybrid garbage collection algorithm (a combination of reference counting and mark-and-sweep techniques) into the current response time analysis framework for real-time systems. Instead of collecting garbage incrementally, we put most GC work into a periodic real-time thread, namely the GC thread, which is scheduled according to the dual priority scheduling method. More importantly, we can perform schedulability analysis (response time analysis) for all the real-time threads including the GC thread. Yang Chang, Andy J. Wellings |
RTCSA | 2 |
| 2005 | Cost Monitoring and Enforcement in the Real-Time Specification for Java - A Formal EvaluationabstractThe real-time specification for Java (RTSJ) provides an integrated approach to scheduling periodic threads and monitoring their CPU execution time. It defines a cost enforcement model whereby a periodic thread is suspended when it consumes more CPU time (budget) than it requested. However, the support for this model is optional and it is generally not given by most implementations. Consequently, this aspect of the specification has not been rigorously evaluated. In this paper we define a formal model of the RTSJ cost monitoring and enforcement approach using the extended timed automata formalism provided in the UPPAALtool. Using the model, properties are explored and it is shown that whilst implementations that conform to the RTSJ specification are free from potential deadlock, the specification allows an implementation, under certain circumstances, to give a periodic thread more than its CPU budget in one period. These circumstances are detailed and a correction to the RTSJ specification is suggested to remove this anomaly. Osmar Marchi dos Santos, Andy J. Wellings |
RTSS | 2 |
| 2005 | Ravenscar-Java: a high-integrity profile for real-time JavaabstractAbstract For many, Java is the antithesis of a high‐integrity programming language. Its combination of object‐oriented programming features, its automatic garbage collection, and its poor support for real‐time multi‐threading are all seen as particular impediments. The Real‐Time Specification for Java has introduced many new features that help in the real‐time domain. However, the expressive power of these features means that very complex programming models can be created, necessitating complexity in the supporting real‐time virtual machine. Consequently, Java, with the real‐time extensions as they stand, seems too complex for confident use in high‐integrity systems. This paper presents a Java profile for the development of software‐intensive high‐integrity real‐time systems. This restricted programming model removes language features with high overheads and complex semantics, on which it is hard to perform timing and functional analyses. The profile fits within the J2ME framework and is consistent with well‐known guidelines for high‐integrity software development, such as those defined by the U.S. Nuclear Regulatory Commission. Copyright © 2005 John Wiley & Sons, Ltd. Jagun Kwon, Andy J. Wellings, Steve King 0001 |
Concurr. Pract. Exp. | 2 |
| 2005 | Guidelines for a graduate curriculum on embedded software and systemsabstractThe design of embedded real-time systems requires skills from multiple specific disciplines, including, but not limited to, control, computer science, and electronics. This often involves experts from differing backgrounds, who do not recognize that they address similar, if not identical, issues from complementary angles. Design methodologies are lacking in rigor and discipline so that demonstrating correctness of an embedded design, if at all possible, is a very expensive proposition that may delay significantly the introduction of a critical product. While the economic importance of embedded systems is widely acknowledged, academia has not paid enough attention to the education of a community of high-quality embedded system designers, an obvious difficulty being the need of interdisciplinarity in a period where specialization has been the target of most education systems. This paper presents the reflections that took place in the European Network of Excellence Artist leading us to propose principles and structured contents for building curricula on embedded software and systems. Paul Caspi, Alberto L. Sangiovanni-Vincentelli, Luís Almeida 0001, Albert Benveniste, Bruno Bouyssounouse, Giorgio C. Buttazzo, Ivica Crnkovic, Werner Damm, Jakob Engblom, Gerhard Fohler, Marisol García-Valls, Hermann Kopetz, Yassine Lakhnech, François Laroussinie, Luciano Lavagno, Giuseppe Lipari, Florence Maraninchi, Philipp Peti, Juan Antonio de la Puente, Norman Scaife, Joseph Sifakis, Robert de Simone, Martin Törngren, Paulo Veríssimo, Andy J. Wellings, Reinhard Wilhelm, Tim A. C. Willemse, Wang Yi 0001 |
ACM Trans. Embed. Comput. Syst. | 25 |
| 2004 | A Real-Time Isolate Specification for Ravenscar-JavaabstractThe Ravenscar-Java profile is defined for high-integrity real-time Java programs. However, it only supports one application at any instance. This paper proposes an extended Ravenscar-Java that supports multiple applications with mixed integrity levels Andy J. Wellings |
ISORC | 2 |
| 2004 | The Real-Time Specification for Java: Current Status and Future WorkabstractThe Real-Time Specification for Java is now about two years old. It has been implemented, formed the basis for research and used in serious applications. Some strengths and weaknesses are becoming clear. This paper reviews the current status of the specification, outlines the challenges ahead and discusses areas where there is likely to be future design work Peter C. Dibble, Andy J. Wellings |
ISORC | 2 |
| 2004 | Cost Enforcement and Deadline Monitoring in the Real-Time Specification for JavaabstractModem real-time programming languages and operating systems provide support for monitoring the amount of CPU time a thread consumes. However, no system in widespread use fully integrates this monitoring with the scheduling facilities. The real-time specification for Java (RTSJ) provides an integrated approach to scheduling periodic threads and monitoring their CPU execution time. It supports a cost enforcement model whereby a periodic thread is suspended when it consumes more time than it requested. Version 1.0 of the RTSJ is under specified and it is difficult to understand the full model. This paper clarifies the position and defines the conditions under which a real-time thread is resumed. The model presented is the one that is fully defined in version 1.0.1 of the RTSJ. Unfortunately, version 1.0.1 of the specification will not have a general model for handling cost enforcement and deadline monitoring for all schedulable objects. This paper proposes extensions to the RTSJ that allow the cost enforcement model and deadline monitoring model to be consistently applied across all schedulable objects, and for it to be fully integrated with scheduling Andy J. Wellings, Gregory Bollella, Peter C. Dibble, David Holmes |
ISORC | 1 |
| 2004 | Replication Management in Reliable Real-Time Systems
Luís Miguel Pinho, Francisco Vasques, Andy J. Wellings |
Real Time Syst. | 3 |
| 2003 | A Real-Time RMI Framework for the RTSJabstractThe Real-Time Specification for Java (RTSJ) provides a platform for the development of real-time applications. However, the RTSJ does not take the distribution requirements of real-time applications into consideration. As distribution in Java is often implemented using Java's Remote Method Invocation (RMI), a real-time version of RMI between RTSJ implementations can provide a platform for writing distributed real-time systems. This paper describes a Real-Time RMI (RT-RMI) framework that supports timely invocation of remote objects. The thread classes defined by the RTSJ are used to provide the client and server threading mechanisms. The memory model of the RTSJ is considered to ensure that threads correctly use memory areas and avoid memory leaks in the absence of the garbage collector. New classes are developed to control the threads used throughout the invocation and to provide new semantics for remote objects that can be invoked in a timely fashion. Andrew Borg, Andy J. Wellings |
ECRTS | 2 |
| 2003 | Gain Time Reclaiming in High Performance Real-Time Java SystemsabstractThe run-time characteristics of Java, such as high frequency of method invocation, dynamic dispatching and dynamic loading, make Java more difficult than other object-oriented programming languages, such as C++, for conducting Worst-Case Execution Time (WCET) analysis. To offer a more flexible way to develop object-oriented real-time applications in the realtime Java environment without loss of predictability and performance, we propose a novel gain time reclaiming framework integrated with WCET analysis. This paper demonstrates how to improve the utilisation and performance of the whole system by reclaiming gain time at run-time. Our approach shows that integrating WCET with gain time reclaiming can not only provide a more flexible environment, but it also does not necessarily result in unsafe or unpredictable timing behaviour. Erik Yu-Shing Hu, Andy J. Wellings, Guillem Bernat |
ISORC | 2 |
| 2003 | Predictable Memory Utilization in the Ravenscar-Java ProfileabstractIn this paper, we present the Ravenscar-Java profile from the perspective of memory utilization. This restricted programming model removes language features with high overheads and complex semantics, on which it is hard to perform various static analyses. Several classes in the RTSJ are refined, and a few new classes are added, which all result in a compact, yet powerful and predictable computational model for the development of software-intensive high integrity real-time systems. We provide rationales behind the decisions we have made on the use of memory areas and other language features that can have an effect on the predictability of memory utilization. After that, some analysis approaches are discussed in terms of how they can be developed and beneficially used. Jagun Kwon, Andy J. Wellings, Steve King 0001 |
ISORC | 2 |
| 2003 | XRTJ: An Extensible Distributed High-Integrity Real-Time Java Environment
Erik Yu-Shing Hu, Andy J. Wellings, Guillem Bernat |
RTCSA | 2 |
| 2003 | Evaluating the Expressive Power of the Real-Time Specification for Java
Andy J. Wellings, Peter P. Puschner |
Real Time Syst. | 1 |
| 2001 | A Profile for High-Integrity Real-Time Java ProgramsabstractThe paper defines a simple subset of tasking and object oriented features of the Real-Time Specification for Java that support high-integrity real time applications. The subset has been chosen to facilitate the development of efficient applications whose temporal behavior needs to be exactly predictable. Peter P. Puschner, Andy J. Wellings |
ISORC | 2 |
| 2000 | Portable worst-case execution time analysis using Java Byte CodeabstractAddresses the problem of performing worst-case execution time (WCET) analysis of Java Byte Code (JBC), which may be generated from different compilers and from different source languages. The motivation for the framework presented is to provide WCET analysis which is portable and therefore more likely to be used in an industrial context. Two issues are addressed in this paper: how to extract data flow and control flow information from JBC programs, and how to provide a compiler-/language-independent mechanism to introduce WCET annotations in the source code. We show that an annotation mechanism based on calls to a static class with empty methods result in similar code when generated by Java or Ada compilers. Guillem Bernat, Alan Burns 0001, Andy J. Wellings |
ECRTS | 3 |
| 2000 | Techniques to increase the schedulable utilization of cache-based preemptive real-time systems
José V. Busquets-Mataix, Daniel Gil, Pedro J. Gil, Andy J. Wellings |
J. Syst. Archit. | 4 |
| 2000 | State restoration in Ada 95: a portable approach to supporting software fault tolerance
Patrick Rogers, Andy J. Wellings |
J. Syst. Softw. | 2 |
| 2000 | Replica Determinism and Flexible Scheduling in Hard Real-Time Dependable SystemsabstractFault-tolerant real-time systems are typically based on active replication where replicated entities are required to deliver their outputs in an identical order within a given time interval. Distributed scheduling of replicated tasks, however, violates this requirement if on-line scheduling, preemptive scheduling, or scheduling of dissimilar replicated task sets is employed. This problem of inconsistent task outputs has been solved previously by coordinating the decisions of the local schedulers such that replicated tasks are executed in an identical order. Global coordination results either in an extremely high communication effort to agree on each schedule decision or in an overly restrictive execution model where on-line scheduling, arbitrary preemptions, and nonidentically replicated task sets are not allowed. To overcome these restrictions, a new method, called timed messages, is introduced. Timed messages guarantee deterministic operation by presenting consistent message versions to the replicated tasks. This approach is based on simulated common knowledge and a sparse time base. Timed messages are very effective since they neither require communication between the local scheduler nor do they restrict usage of on-line flexible scheduling, preemptions and nonidentically replicated task sets. Stefan Poledna, Alan Burns 0001, Andy J. Wellings, Peter Barrett |
IEEE Trans. Computers | 3 |
| 2000 | Integrating object-oriented programming and protected objects in Ada 95abstractIntegrating concurrent and object-oriented programming has been an active research topic since the late 1980's. There is a now a plethora of methods for achieving this integration. The majority of approaches have taken a sequential object-oriented language and made it concurrent. A few approaches have taken a concurrent language and made it object-oriented. The most important of this latter class is the Ada 95 language, which is an extension to the object-based concurrent programming language Ada 83. Arguably, Ada 95 does not fully integrate its models of concurrency and object-oriented programming. For example, neither tasks nor protected objects are extensible. This article discusses ways in which protected objects can be made more extensible. Andy J. Wellings, Bob Johnson, Bo Ingvar Sandén, Jörg Kienzle, Thomas Wolf 0013, Stephen Michell |
ACM Trans. Program. Lang. Syst. | 1 |
| 1999 | Implementing mode changes with shared resources in AdaabstractThe ability to support mode changes is a desirable feature for many real-time systems in which the functionality provided may vary as the mission progresses. The addition and deletion of tasks, the change of task profiles, the coherent management of resources and, at the same time, the required timeliness guarantee is an exercise of coordination of activities in a real-time system. In this paper we suggest how to safely implement mode changes in Ada, taking resource management into account. We consider the hypothesis of Ada allowing dynamic ceilings for protected objects and then show how to plan the mode change so that during the transition, tasks do not use the resources inconsistently. Jorge Real, Andy J. Wellings |
ECRTS | 2 |
| 1999 | GUARDS: A Generic Upgradable Architecture for Real-Time Dependable SystemsabstractThe development and validation of fault-tolerant computers for critical real-time applications are currently both costly and time consuming. Often, the underlying technology is out-of-date by the time the computers are ready for deployment. Obsolescence can become a chronic problem when the systems in which they are embedded have lifetimes of several decades. This paper gives an overview of the work carried out in a project that is tackling the issues of cost and rapid obsolescence by defining a generic fault-tolerant computer architecture based essentially on commercial off-the-shelf (COTS) components (both processor hardware boards and real-time operating systems). The architecture uses a limited number of specific, but generic, hardware and software components to implement an architecture that can be configured along three dimensions: redundant channels, redundant lanes, and integrity levels. The two dimensions of physical redundancy allow the definition of a wide variety of instances with different fault tolerance strategies. The integrity level dimension allows application components of different levels of criticality to coexist in the same instance. The paper describes the main concepts of the architecture, the supporting environments for development and validation, and the prototypes currently being implemented. David Powell, Jean Arlat, Ljerka Beus-Dukic, Andrea Bondavalli, P. Coppola, Alessandro Fantechi, Eric Jenn, Christophe Rabéjac, Andy J. Wellings |
IEEE Trans. Parallel Distributed Syst. | 9 |
| 1998 | Real-Time Scheduling in a Generic Fault-Tolerant ArchitectureabstractPrevious ultra-dependable real-time computing architectures have been specialised to meet the requirements of a particular application domain. Over the last two years, a consortium of European companies and academic institutions has been investigating the design and development of a Generic Upgradable Architecture for Real-time Dependable Systems (GUARDS). The architecture aims to be tolerant of permanent and temporary, internal and external, physical faults and should provide confinement or tolerance of software design faults. GUARDS critical applications are intended to be replicated across the channels which provide the primary hardware fault containment regions. In this paper, we present our approach to real-time scheduling of the GUARDS architecture. We use an extended response-time analysis to predict the timing properties of replicated real-time transactions. Consideration is also given to the scheduling of the inter-channel communications network. Andy J. Wellings, Ljerka Beus-Dukic, David Powell |
RTSS | 1 |
| 1998 | Distributed Atomic Actions in Ada 95abstractThis paper discusses the development of a distributed asynchronous atomic action scheme for Ada 95. The scheme makes use of many unique Ada 95 features including protected objects, asynchronous transfer of control and the distributed systems annex. We present the packages which implement the local and global action support and illustrate their use in a (partial) implementation of the FZI production cell problem. We also discuss a number of variations of the model and how these might be included. Finally, we discuss how the distribution model used in Ada 95 has influenced our design. Stuart E. Mitchell, Andy J. Wellings, Alexander B. Romanovsky |
Comput. J. | 2 |
| 1998 | Requirements for a COTS software component: A case study
Ljerka Beus-Dukic, Andy J. Wellings |
Requir. Eng. | 2 |
| 1997 | Formal development of a real-time kernelabstractThe formal development of a simple real time operating system kernel is described. The kernel provides a set of operations that allows a restricted Ada 95 tasking model to be supported, suitable for fixed priority real time systems. The requirements for the kernel are expressed in terms of the computational model using RTL, and the abstract specification of the kernel is validated against this. The development of an implementation from this specification is then described, with the PVS proof system used to verify each step in the development process. Simon Fowler 0002, Andy J. Wellings |
RTSS | 2 |
| 1997 | An Action-Based Formal Model for Concurrent Real-Time SystemsabstractAbstract Action systems are a formalism for representing concurrent behaviours, based on interleaved atomic actions. We show how this model can be used to represent time-consuming, pre-emptible actions with real-time constraints. A development procedure is described which captures the steps programmers typically undertake in the design of real-time multi-tasking systems. Colin J. Fidge, Andy J. Wellings |
Formal Aspects Comput. | 2 |
| 1997 | Synchronous sessions and fixed priority scheduling
Alan Burns 0001, Andy J. Wellings |
J. Syst. Archit. | 2 |
| 1997 | Implementing Atomic Actions in Ada 95abstractAtomic actions are an important dynamic structuring technique that aid the construction of fault-tolerant concurrent systems. Although they were developed some years ago, none of the well-known commercially-available programming languages directly support their use. This paper summarizes software fault tolerance techniques for concurrent systems, evaluates the Ada 95 programming language from the perspective of its support for software fault tolerance, and shows how Ada 95 can be used to implement software fault tolerance techniques. In particular, it shows how packages, protected objects, requeue, exceptions, asynchronous transfer of control, tagged types, and controlled types can be used as building blocks from which to construct atomic actions with forward and backward error recovery, which are resilient to deserter tasks and task abortion. Andy J. Wellings, Alan Burns 0001 |
IEEE Trans. Software Eng. | 1 |
| 1996 | An Efficient and Practical Local Synchronous Bandwidth Allocation Scheme for the Timed-Token MAC ProtocolabstractThis paper is concerned with deadline guarantees of synchronous messages with deadlines equal to periods, in a timed token ring network such as FDDI where the timed token medium access control (MAC) protocol is used. The timed token protocol guarantees a bounded access time and an average bandwidth for synchronous traffic. However, this guarantee alone, though necessary, is insufficient for guaranteeing the transmission of synchronous messages before their deadlines. To ensure timely delivery, the synchronous bandwidth must be carefully allocated to individual nodes. We propose and analyse an efficient and practical local synchronous bandwidth allocation (SBA) scheme. The new scheme performs better than any previously published as it calculates the synchronous bandwidth such that during the message period, the total synchronous transmission time definitely available (when judged only by local information) is exactly equal to the transmission time required. Our scheme also differs significantly from previously reported ones by explicitly taking into account the synchronous bandwidth allocation for message sets whose minimum message deadlines (D/sub min/) are less than twice the target token rotation time (TTRT), and consequently can apply to any synchronous message set (with D/sub min/>TTRT). The feasibility of the allocations produced by the proposed scheme and the worst case achievable utilisation of the scheme are also discussed. Sijing Zhang, Alan Burns 0001, Andy J. Wellings |
INFOCOM | 3 |
| 1996 | Analysing APEX applicationsabstractThe next generation of civil aircraft may be produced using Integrated Modular Avionics (IMA). A component of IMA is APEX, a standard operating system interface. This supports a two-level scheduling scheme consisting of fixed priority scheduling within a statically generated cyclic schedule. This paper illustrates how APEX applications can be analysed for their response times and shows that there is potential for a large amount of release jitter. Neil C. Audsley, Andy J. Wellings |
RTSS | 2 |
| 1996 | Programming Replicated Systems in Ada 95abstractThis paper considers the programming of passive (cold and warm standbys) and active replicated systems in Ada 95. We show that it is relatively easy to develop systems which act as standbys using the facilities provided by the language and the Distributed Systems Annex. Arguably, active replication in Ada 95 can be supported in a manner which is transparent to the application. However, this is implementation-dependent, requires a complex distributed consensus algorithm (or a carefully chosen subset of the language to be used) and has little flexibility. We therefore consider two extensions to the Distributed Systems Annex to help give the application programmer more control. The first is a via a new categorization pragma which specifies that a RCI package can be replicated in more than one partition. The second is through the introduction of a coordinated type which has a single primitive operation. Objects which are created from extensions to coordinated types can be freely replicated across the distributed system. When the primitive operation is called, the call is posted to all sites where a replica resides, effectively providing a broadcast (multicast) facility. We also consider extensions to the partition communication subsystem which implement these new features. Andy J. Wellings, Alan Burns 0001 |
Comput. J. | 1 |
| 1996 | Synchronisation, Concurrent Object-Oriented Programming and the Inheritance Anomaly
Stuart E. Mitchell, Andy J. Wellings |
Comput. Lang. | 2 |
| 1996 | Combining Static Worst-Case Timing Analysis and Program Proof
Roderick Chapman, Alan Burns 0001, Andy J. Wellings |
Real Time Syst. | 3 |
| 1995 | Dual Priority SchedulingabstractIn this paper, we present a new strategy for scheduling tasks with soft deadlines in real-time systems containing periodic, sporadic and adaptive tasks with hard deadlines. In such systems, much of the spare capacity present is due to sporadic and adaptive tasks not arriving at their maximum rate. Offline methods of identifying spare capacity such as the Deferrable Server or Priority Exchange Algorithm are unable to make this spare capacity available as anything other than a background service opportunity for soft tasks. Further, more recent methods such as dynamic Slack Stealing require computationally expensive re-evaluation of the available slack in order to reclaim such spare capacity. By comparison, the Dual Priority approach presented in this paper provides an efficient and effective means of scheduling soft task in this case. Robert I. Davis 0001, Andy J. Wellings |
RTSS | 2 |
| 1995 | Fixed Priority Pre-emptive Scheduling: An Historical Perspective
Neil C. Audsley, Alan Burns 0001, Robert I. Davis 0001, Ken Tindell, Andy J. Wellings |
Real Time Syst. | 5 |
| 1995 | Analysis of Hard Real-Time Communications
Ken Tindell, Alan Burns 0001, Andy J. Wellings |
Real Time Syst. | 3 |
| 1995 | Engineering a Hard Real-time System: From Theory to PracticeabstractAbstract More and more programmers find their software being used in performance critical applications. Unfortunately, they have limited techniques at their disposal to help guarantee this particular aspect of their programs. There has been considerable activity in recent years on developing analysis techniques for hard real‐time systems. Inevitably these techniques make simplifying assumptions so as to reduce the complexity of the problem to be solved. For example hard real‐time schedulability analysis techniques often assume that the timing properties of the underlying kernel can be accounted for by incorporating extra execution time into the application tasks. Furthermore, they assume that the application task structure is very simple and uniform. This paper considers the implications of using these techniques in the analysis of a typical single processor application, the attitude and orbital control system (AOCS) for the Olympus satellite. The paper outlines a common approach for estimating the response times for tasks, and then extends the scheduling equations so that they can be used in the engineering of realistic real‐time systems. Alan Burns 0001, Andy J. Wellings |
Softw. Pract. Exp. | 2 |
| 1995 | Effective Analysis for Engineering Real-Time Fixed Priority SchedulersabstractThere has been considerable activity in recent years in developing analytical techniques for hard real-time systems. Inevitably these techniques make simplifying assumptions so as to reduce the complexity of the problem to be solved. Unfortunately this leads to a gap between theory and engineering practice. The paper presents new analysis that enables the costs of the scheduler (clock overheads, queue manipulations and release delays) to be factored into the standard equations for calculating worst-case response times. As well as predicting the true behavior of realistic systems, the analysis also allows free parameters, such as clock interrupt rate, to be determined.> Alan Burns 0001, Ken Tindell, Andy J. Wellings |
IEEE Trans. Software Eng. | 3 |
| 1994 | Analysing Real-Time Communications: Controller Area Network (CAN)abstractThe increasing use of communication networks in time-critical applications presents engineers with fundamental problems with the determination of response times of communicating distributed processes. Although there has been some work on the analysis of communication protocols, most of this is for idealised networks. Experience with single-processor scheduling analysis has shown that models which abstract away from implementation details are at best very pessimistic, and at worst lead to an unschedulable system being deemed schedulable. In this paper, we derive an idealised scheduling analysis for the CAN real-time bus, and then study two actual interface chips to see how the analysis can be applied.> Ken Tindell, H. Hanssmon, Andy J. Wellings |
RTSS | 3 |
| 1994 | HRT-HOOD: A Structured Design Method for Hard Real-Time Systems
Alan Burns 0001, Andy J. Wellings |
Real Time Syst. | 2 |
| 1994 | An Extendible Approach for Analyzing Fixed Priority Hard Real-Time Tasks
Ken Tindell, Alan Burns 0001, Andy J. Wellings |
Real Time Syst. | 3 |
| 1994 | STRESS: a Simulator for Hard Real-time SystemsabstractAbstract The STRESS environment is a collection of CASE tools for analysing and simulating the behaviour of hard real‐time safety‐critical applications. It is primarily intended as a means by which various scheduling and resource management algorithms can be evaluated, but can also be used to study the general behaviour of applications and real‐time kernels. This paper describes the structure of the STRESS language and its environment, and gives examples of its use. Neil C. Audsley, Alan Burns 0001, Mike F. Richardson, Andy J. Wellings |
Softw. Pract. Exp. | 4 |
| 1993 | The use of preemptive priority-based scheduling for space applicationsabstractIn January 1991, the European Space Agency commissioned a study into the practicality of using process-based scheduling techniques in an on-board application environment, with Ada as the implementation language. The short paper summarizes the results of that study.> C. M. Bailey, E. Fyfe, Tullio Vardanega, Andy J. Wellings |
RTSS | 4 |
| 1992 | Mode Changes In Priority Pre-Emptively Scheduled SystemsabstractIt is noted that in many hard real-time systems, the set of functions that a system is required to provide may change over time. One way of providing this change is to allow currently running hard real-time tasks to be deleted or changed, or new tasks to be added. The authors define this change as a mode change, and seek to guarantee a priori the timing constraints of all tasks across the change from one mode to another. The authors derive a scheduling theory for static priority preemptive scheduling that can be used to make such guarantees. The schedulability test discussed could easily be incorporated into engineering support tools. The authors also discuss some of the approaches that could be taken to extend the analysis to cope with more complex and interesting scheduling problems, and to handle distributed hard real-time systems.> Ken Tindell, Alan Burns 0001, Andy J. Wellings |
RTSS | 3 |
| 1992 | Allocating Hard Real-Time tasks: An NP-Hard Problem Made Easy
Ken Tindell, Alan Burns 0001, Andy J. Wellings |
Real Time Syst. | 3 |
| 1991 | Priority Inheritance and Message Passing Communication: A Formal Treatment
Alan Burns 0001, Andy J. Wellings |
Real Time Syst. | 2 |
| 1991 | Criticality and Utility in the Next Generation
Alan Burns 0001, Andy J. Wellings |
Real Time Syst. | 2 |
| 1991 | The Design of an Operating System for a Scalable Parallel Computing EngineabstractAbstract There are substantial benefits to be gained from building computing systems from a number of processors working in parallel. One of the frequently‐stated advantages of parallel and distributed systems is that they may be scaled to the needs of the user. This paper discusses some of the problems associated with designing a general‐purpose operating system for a scalable parallel computing engine and then describes the solutions adopted in our experimental parallel operating system. We explain why a parallel computing engine composed of a collection of processors communicating through point‐to‐point links provides a suitable vehicle in which to realize the advantages of scaling. We then introduce a parallel‐processing abstraction which can be used as the basis of an operating system for such a computing engine. We consider how this abstraction can be implemented and retain the ability to scale. As a concrete example of the ideas presented here we describe our own experimental scalable parallel operating‐system project, concentrating on the Wisdom nucleus and the Sage file system. Finally, after introducing related work, we describe some of the lessons learnt from our own project. Paul Baden Austin, Kevin Murray 0001, Andy J. Wellings |
Softw. Pract. Exp. | 3 |
| 1990 | The Notion of Priority in Real-Time Programming Languages
Alan Burns 0001, Andy J. Wellings |
Comput. Lang. | 2 |
| 1989 | Dynamic change management and AdaabstractAbstract Many large real‐time systems are expected to have a long, non‐stop operational life. It cannot, however, be assumed that the code that initially started executing will remain appropriate for the complete lifetime of the system. Indeed it will more likely be the case that the system will be subject to evolutionary change. This can reflect bug fixes, the addition of new functionality, or redeployment of the original code. We introduce in this paper the term Dynamic change management to represent the process of controlling the modification of executing software. The Ada language will increasingly be used to program non‐stop systems. Unfortunately dynamic modifications to Ada programs appear to be invalid in terms of the Ada Language Reference Manual. This paper discusses dynamic change management within the context of distributed Ada execution. Our intention is not to provide a methodology within which such changes can take place; we believe this to be too difficult at the current time. Rather we wish to provide a focus for discussion of this important future problem area. However, we do offer a useful classification of software components, and suggest how change can be effected—the approach to be taken depending upon the structure of the component being replaced. The flexibility of dynamic change management depends upon the initial granularity of distribution and deployment. We also attempt to define rules for legally changing running Ada programs. Although this paper focuses on the Ada language, many of the issues are of general concern. Alan Burns 0001, Andy J. Wellings |
J. Softw. Maintenance Res. Pract. | 2 |
| 1988 | Issues in the design and implementation of a distributed operating system for a network of transputers
Kevin Murray 0001, Andy J. Wellings |
Microprocess. Microprogramming | 2 |
| 1985 | The PULSE Distributed File SystemabstractAbstract A network of powerful personal computers, linked by a high‐speed local area network, is being seen increasingly as an alternative to a traditional centralized time‐sharing operating system. The PULSE project is investigating how such a system may be constructed to give the benefits of a self‐sufficient personal computer to each user without losing the facilities for communication and sharing of data inherent in centralized systems. In particular, a distributed file system has been built which provides a single global UNIX UNIX is a trademark of Bell Laboratories. ‐like hierarchy, with a consistent appearance when accessed from any machine. Replicated copies of files are maintained to improve reliability, increase performance, and enable each machine to run stand‐alone, albeit with reduced facilities. G. M. Tomlinson, D. Keeffe, I. C. Wand, Andy J. Wellings |
Softw. Pract. Exp. | 4 |