µRTE

A domain-modeling framework for embedded software architectures, with an emphasis on functional safety.

Project

µRTE captures requirements, conceptual functions, software, hardware and tests of an embedded control system in a single model. From this model it generates the runtime infrastructure of the software, analyzer reports and documentation.

It grew out of research on safety architectures for multicore microcontrollers by Thomas Barth and Prof. Dr.-Ing. Peter Fromm at Darmstadt University of Applied Sciences and is the subject of Thomas Barth's PhD thesis at TU Dublin. Used in academic projects since 2018 and in industry since 2021, it formed a central element of the software development and safety lifecycle of a product certified according to ISO 25119.

Modeling

One model with five layers: requirements including hazards and safety goals, logical functions, software, hardware and tests. The layers reference each other directly, so there is nothing to synchronize between tools. Each layer has its own diagrams, and the model can be edited in any order.

The modeling language is deliberately narrow. It follows typical embedded control patterns: time-triggered and event-driven activation, signal-based communication, state-dependent execution and explicit hardware mapping. What is handled well elsewhere stays outside: product variants, versioning, the internal logic of software units and test execution.

Code generation

The generator builds the runtime environment around the application: code structure, signals with validation and scaling, activation, memory allocation and protection, error handling and linker description files. Application logic is written in designated blocks of the generated code, which are preserved across regeneration. Requirements and dependencies appear as comments next to the code they concern.

The generated architecture is platform-agnostic. It is bound to bare metal or an RTOS through an OS adapter and scales from single core to multicore.

Analysis and documentation

Before every transformation, a static analyzer checks the model. Errors stop the generation. Warnings cover design, safety, runtime, testing and requirements, including freedom from interference and conflicting integrity levels.

The documentation generator produces an HTML report with every model element, its dependencies and the analyzer findings, in sync with the generated code. In projects it serves as the basis for the safety documentation.

Scope

µRTE is built on the Eclipse Modeling Framework and runs stand-alone or as a plugin in Eclipse-based IDEs.

Platforms

  • Any RTOS or bare metal, bound through an OS adapter
  • Any controller, single core and multicore
  • Any toolchain with C11 or C++14 support
  • Integrations e.g. for PxROS on Infineon AURIX and FreeRTOS on STM32

Software

  • Cyclic and event-driven activation
  • Signals with validation, status and age
  • System states with state-dependent data flows
  • Error reporting through user-defined macros
  • Human-readable code, user code preserved on regeneration
  • Generated code checked against MISRA

Safety

  • Hazards, safety goals and safety requirements in the model
  • Integrity levels checked for propagation and conflicts
  • Freedom from interference: memory, execution time, peripherals
  • Memory protection sets with generated MPU configuration
  • Not tool-qualified: generated artifacts are verified like hand-written ones

Traceability

  • Requirements linked to functions, software, hardware and tests
  • Test definitions in the model, execution in the test framework of choice
  • One generated report as reference for reviews
  • MCP gateway for LLM clients (pre-development)

Contact

Questions about µRTE: