Time Daemon Component Requirements#

Time Daemon Requirements
status: valid
security: NO
safety: ASIL_B
tags: requirements, time_daemon, time_daemon
version: 1

Functional Requirements#

Initialization and Lifecycle#

Component Initialization
status: valid
security: NO
safety: ASIL_B
tags: time_daemon
reqtype: Functional
version: 1

On startup the time_daemon component shall determine its configuration, initialize the configured time synchronization data receiver, time data verification pipeline (synchronization validation, timeout detection, time jump detection), and IPC publisher. If initialization of any of those units fails, the time_daemon shall retry to initialize the respective unit. Overall initialization shall fail if not completed within 20 seconds and shall end the time_slave process.

Component Shutdown
status: valid
security: NO
safety: ASIL_B
tags: time_daemon
reqtype: Functional
version: 1

The time_daemon component shall stop the publishing loop and close plus release any IPC resources (e.g. shared memory mappings) when a stop signal is received.

Data Reception and Validation#

Time Synchronization Data Reception
status: valid
security: NO
safety: ASIL_B
tags: time_daemon
reqtype: Functional
version: 1

The time_daemon component shall receive time synchronization data from time_slave component using the ts_client component for IPC abstraction.

Verification Pipeline#

Synchronization Status Validation
status: valid
security: NO
safety: ASIL_B
tags: time_daemon
reqtype: Functional
version: 1

The time_daemon component shall validate synchronization status based on received time synchronization data.

Synchronization State Stabilization
status: valid
security: NO
safety: ASIL_B
tags: time_daemon
reqtype: Functional
version: 1

The time_daemon component shall not report time jumps during the configured time span (default: 5 seconds) after initial synchronization to avoid spuriously detected time jumps during startup.

Time Jump Detection
status: valid
security: NO
safety: ASIL_B
tags: time_daemon
reqtype: Functional
version: 1

The time_daemon component shall detect time jumps when the master clock timestamp of a gPTP time sync data update differs from the expected value by more than the configured time span (default: 500 microseconds). Both forward and backward time jumps shall be detected.

Timeout Detection
status: valid
security: NO
safety: ASIL_B
tags: time_daemon
reqtype: Functional
version: 1

The time_daemon component shall detect timeout condition when no new time synchronization data is received within the configured time span (default: 3.3 seconds).

Data Publishing#

Time Data Publishing
status: valid
security: NO
safety: ASIL_B
tags: time_daemon
reqtype: Functional
version: 1

The time_daemon component shall publish the verified time synchronization data to the time component linked as a library into client applications.

Published Time Data Content
status: valid
security: NO
safety: ASIL_B
tags: time_daemon
reqtype: Interface
version: 1

The time_daemon component shall include in published time data: the timestamp of the master clock, the corresponding timestamp of the local reference clock, the rate deviation between those two clocks, synchronization status, time jump status, and timeout status.

Also it shall include condensed raw data of the last received Sync/FollowUp pair and the last finished Pdelay measurement.

Time Point Qualifier Production
status: valid
security: NO
safety: ASIL_B
tags: time_daemon
reqtype: Functional
version: 1

The time_daemon component shall determine the time point qualifier (quality indicator) of the published time data from the outcome of the synchronization, time jump and timeout verification checks.

Publish Interval
status: valid
security: NO
safety: ASIL_B
tags: time_daemon
reqtype: Functional
version: 1

The time_daemon component shall publish time data to client applications at a fixed configurable interval (default: 250 milliseconds).

Non-Blocking Access Path
status: valid
security: NO
safety: ASIL_B
tags: time_daemon
reqtype: Functional
version: 1

The time_daemon component shall use a non-blocking, lock-free shared memory access path for receiving time synchronization data and providing published time data to client applications.

Multi-Client Support
status: valid
security: NO
safety: ASIL_B
tags: time_daemon
reqtype: Functional
version: 1

The time_daemon component shall support concurrent non-blocking read access from multiple client applications to the published time data.

Error Handling and Recovery#

Error Reporting
status: valid
security: NO
safety: ASIL_B
tags: time_daemon
reqtype: Functional
version: 1

The time_daemon component shall log messages via the score::mw::log interface when initialization fails (error level), shared memory access fails (error level), verification stage failures occur (warning level), or time synchronization data reception fails (error level).

Time Jump Error Reaction
status: valid
security: NO
safety: ASIL_B
tags: time_daemon
reqtype: Functional
version: 1

The time_daemon component shall continue publishing time data with time jump status set when time jump is detected.

Time Jump Recovery
status: valid
security: NO
safety: ASIL_B
tags: time_daemon
reqtype: Functional
version: 1

The time_daemon component shall clear time jump condition after receiving 2 consecutive valid gPTP frames without time jump.

Timeout Error Reaction
status: valid
security: NO
safety: ASIL_B
tags: time_daemon
reqtype: Functional
version: 1

The time_daemon component shall continue publishing time data with timeout status set when the timeout detection period elapses without receiving new gPTP data.

Platform Abstraction#

Platform Support
status: valid
security: NO
safety: ASIL_B
tags: time_daemon
reqtype: Functional
version: 1

The time_daemon component shall support POSIX and QNX 8.0 SDPplatforms for shared memory access and IPC communication.

Assumption of Use Requirements#

gPTP Shared Memory Availability
status: valid
security: NO
safety: ASIL_B
tags: time_daemon
reqtype: Process
version: 1

The user shall ensure gPTP shared memory is initialized and the time_slave component is running before starting time_daemon. Starting time_daemon without an initialized shared memory region will cause shared memory access failures or reading of stale/uninitialized time data during startup.