ML17352A895

From kanterella
Jump to navigation Jump to search
Part 21 Rept Re Unit 3A Sequencers at Turkey Point Plant. Unless Contacted by FP&L to Perform Programming Changes & Subsequent V&V to Sequencer Software,United Controls Plans No Other Evaluation of Defect for Listed Reason
ML17352A895
Person / Time
Site: Turkey Point  NextEra Energy icon.png
Issue date: 11/15/1994
From: Darrin Butler, Camp B, Charlton M
UNITED CONTROLS, INC.
To:
NRC OFFICE OF INFORMATION RESOURCES MANAGEMENT (IRM)
References
REF-PT21-94 NUDOCS 9411210123
Download: ML17352A895 (8)


Text

P R.I C) RIDS PROCESSING, R.IWY'CCELERATED REGULATORY INFORMATION DISTRIBUTION SYSTEM (RIDS)

ACCESSION NBR:9411210123 DOC.DATE: 94/11/15 NOTARIZED: NO DOCKET FACIL:50-250 -Turkey Point Plant, Unit 3, Florida Power and Light C 05000250 50-251 Turkey Point Plant, Unit 4, Florida Power and Light C 05000251 AUTH. NAME AUTHOR AFFILIATION CHARLTON,M. United Controls, Inc.

CAMP,B. United Controls, Inc.

BUTLER,D. United Controls, Inc.

RECIP.NAME RECIPIENT AFFILIATION Document Control Branch (Document Control Desk)

SUBJECT:

.Part 21 rept re Unit 3A sequencers at. Turkey Point Plant.

Unless contacted by FPGL to perform programming changes 6 subsequent VGV to sequencer software,United Controls plans no other evaluation of defect. for listed reason.

DISTRIBUTION CODE: IE19D COPIES RECEIVED:LTR ENCL SIZE:

TITLE: Part 21 Rept (50 DKT)

NOTES RECIPIENT COPIES RECIPIENT COPIES ID CODE/NAME LTTR ENCL ID CODE/NAME LTTR ENCL PD2-2 PD 1 1 CROTEAU,R 1 1 INTERNAL: AEOD/SPD/RAB 1 1 -I LE=CENTER..01 1 1 NRR/DOTS/ATSIB 1 1 NRR/DOTS/TQMB/A 1 1 RES/DSIR/EIB 1 1 RGN1 1 1 RGN2 1 1 RGN3 1 1 RGN4 1 1 RGN5 1 1 SECY/PDR 1 1 EXTERNAL: INPO RECORD CTR 1 1 NOAC SILVER,E 1 1 NRC PDR 1 1 NOTE TO ALL"RIDS" RECIPIENTS:

PLEASE HELP US TO REDUCE iVASTE! CONTACI'THE DOCUXIENTCONTROL DESK, ROOM Pl-37 (EXT. 504-2083 ) TO ELIXIINATEYOUR NAZIE FROiI DISTRIBUTION LISTS I'OR DOCL:MEN'I'S YOU DON"I'EED!

TOTAL NUMBER OF COPIES REQUIRED: LTTR 16 ENCL '16

FROM:UNITED CONTROLS-IN TO: 381 8165151 V 15r 1994 4:43PM ))872 P.81 Llnited L'ontrols

- International, Inc .

1 664 t.itton Drive Stone Mountoin. Ga 30083-1302 Phone: <404) 406-0884 FAX: t404) rt96-7097 November 15, 1994 Document Control Desk U.S. Nuclear Regulatory Commission Washington, DC 20555

Subject:

Notification of the Existence of a Defect per 10 CFR Part 21 United Controls International Inc. was notified on 11-8-94 by the Florida Power and Light Turkey point Plant of a substantial safety hazard involving the Unit 3A sequencer. The sequencers were supplied as nuclear qualified safety related units to FP&L by the United Controls Division of HUB Inc. in October of 1990.

ri '

h Df During safeguards testing at Turkey Point Unit 4 on 11-3-94, the Unit 3A sequencer failed to start its safety injection pump upon receiving a valid Unit 4 safety injection signal. An extensive review of" thh system found no hardware', failures. The defect found is a software logic error that causes a safety injection inhibit signal to "seal in" under certain conditions258ofofthetheauto test mode. This condition is present approximately responding to time, and will prevent the sequencer from properly any safety injection signal.

The software program for the FP&L Sequencers is unique to the Turkey Point units. There are no other facilities affected.

This was the only project ever processed under the United Controls Division of HUB InC. Software QA Program.

The logic error resulted from changes made during validation testing. The changes were necessary to meet the requirements of the electrical power distribution system at the plant, and were not the result of problems with the control system hardware or software. The logic change introduced a very subtle error which caused a safety injection inhibit signal to "seal in" during certain conditions of auto-testing. The logic error escaped detection during the logic review. The test plan for the software included, verifying the proper response to every credible jf Ji) 0't n

't)4ii2iOi23 94iil5 05000250 PDR S

ADQCK

., PDR

~

. FROt1:

Aa UNITED CONTROLS-IN TO: 381 8165151 V 15> 1994 4: 44'872 P. 82 input/output signal combination. The test plan to verify the system would properly respond while in the auto-test mode was developed on the basis that it would be sufficient to check all credible inputs/outputs while the system ran in auto-test. only The test results utilizing this method were as expected. The way the error could have been found, was to have tested every credible combination of inputs/outputs, during each of the sixteen auto-test scenarios.

United Controls has not been involved in any QA and V&V cont rolled programming on the sequencers since 10-1 5-91 . Since programming changes have been made since this date, United Controls is no longer in a position to correct the specific defect without the potential for adversely effecting the existing software. As a result, no further evaluation may be performed by United Controls at this time. Unless contacted by FP&L to perform programming changes and subsequent V&V to the sequencer software, United Controls plans no other evaluation of this defect.

Sincerely, ichael Charlton PE Reviewed: Date:

Camp P sident Wuc>> ) ~ ~ )

Reviewed: Date:

D. ut er A anager

V l4

GENERAL INFORMATION or OTHER EVENT NUMBER: 28033 LICENSEE: UNITED CONTROLS INTERNATIONAL, INC NOTIFICATION DATE: 11/15/94 CITY: STONE MOUNTAIN REGION: 2 NOTIFICATION TIME: 16:43 [ET]

COUNTY: STATE: GA EVENT DATE: 11/03/94 LICENSEg: AGREEMENT: Y EVENT TIME: 12:00[EST]

DOCKET: LAST UPDATE DATE: 11/15/94 NOTIFICATIONS NRC NOTIFIED BY: FACSIMXLE HQ OPS OFFICER: WILLIAM HUFFMAN EMERGENCY CLASS: NOT APPLICABLE 10 CFR SECTION:

CDEF 21.21(b)(2) DEFECTS/NONCOMPLIANCE EVENT TEXT NOTIFICATION OF SEQUENCER DEFECT.

DURING SAFEGUARDS TESTING AT TURKEY POINT ON 11/3/94, THE UNIT 3A SEQUENCER FAILED TO START A SAFETY INJECTION PUMP UPON RECEIVING A VALID SAFETY INJECTION SIGNAL. THE SEQUENCERS AT TURKEY POINT WERE SUPPLIED AS NUCLEAR

'"QUALIFIED SAFETY RELATED UNITS TO FPEcL BY THE UNITED CONTROLS DIVISION OF HUB INC. ON OCTOBER OF 1990.

INVESTIGATION DETERMINED THAT THE PROBLEM WAS THE RESULT OF A SOFTWARE LOGIC ERROR THAT CAUSES A SAFETY INJECTION INHIBIT SIGNAL TO SEAL IN UNDER CERTAIN CONDITIONS OF THE AUTO-TEST MODE. THIS CONDITION IS PRESENT APPROXIMATELY 25% OF THE TIME AND WXLL PREVENT THE SEQUENCER FROM PROPERLY RESPONDING TO ANY SAFETY XNJECTION SIGNAL.

THE SOFTWARE PROGRAM FOR THE FPEcL SEQUENCERS IS UNIQUE TO TURKEY POINT. NO OTHER FACILXTIES ARE AFFECTED.

THE LOGIC ERROR ESCAPED DETECTION DURING THE LOGIC REVXEW. THE TEST PLAN FOR THE SOFTWARE INCLUDED VERIFYING THE PROPER RESPONSE TO EVERY CREDIBLE INPUT/OUTP<JT SIGNAL COMBINATION. THE TEST PLAN TO VERIFY THE SYSTEM WOULD PROPERLY RESPOND WHILE IN THE AUTO-TEST MODE WAS DEVELOPED ON THE BASIS THAT IT WOULD BE SUFFICIENT TO CHECK ALL CREDIBLE INPUTS/OUTPUTS WHILE THE SYSTEM RAN AN AUTO-TEST. THIS WAS DONE SATISFACTORILY. HOWEVER, THERE ARE APPARENTLY SIXTEEN DIFFERENT AUTO-TEST SCENARIOS. THE ONLY WAY TO HAVE DETECTED THE ERROR WOULD HAVE REQUIRED TESTING EVERY CREDIBLE COMBINATION OF INPUTS/OUTPUTS DURING EACH OF THE SIXTEEN AUTO-TEST SCENARIOS.

UNITED CONTROLS HAS NOT BEEN INVOLVED IN ANY QA OR V&V ON THE SEQUENCERS (Continued on next page)

LICENSEE: UNITED CONTROLS INTE PAGE g 2 OF EVENT NUMBER: 28033 SINCE 10/XS/91. BECAUSE PROGRAMMING CHANGES HAVE BEEN MADE SINCE THIS DATE, UNITED CONTROLS IS NO LONGER IN A POSITION TO CORRECT THE SPECIFIC DEFECT WITHOUT A POTENTIAL FOR ADVERSELY AFFECTING EXISTING SOFTWARE.

I CONSEQUENTLY'NITED CONTROLS PLANS NO OTHER EVALUATION OF TH S DEFECT UNLESS CONTACTED BY FPRL TO PERFORM PROGRAMMING CHANGES AND SUBSEQUENT V&V TO THE SEQUENCER SOFTWARE.

A COPY OF THE PART 21 REPORT ON THIS CONDITION HAS BEEN SENT TO NRR/TQMB(HAASS).