ML20203K894

From kanterella
Jump to navigation Jump to search
Rev 0 to Software Verification & Validation Final Rept
ML20203K894
Person / Time
Site: San Onofre  Southern California Edison icon.png
Issue date: 06/19/1996
From: Michel R, Nadaud J, Pommier A
SOUTHERN CALIFORNIA EDISON CO.
To:
Shared Package
ML20203K553 List:
References
S0123-606-1-367, S0123-606-1-367-1-R0, S123-606-1-367, S123-606-1-367-1-R, NUDOCS 9803050268
Download: ML20203K894 (52)


Text

______ __ _- ______ _ -

ENCLOSURE 8 SOFTWARE VERIFICATION AND VAllDATION FINAL REPORT

gll,G,,P Radiation Monitoring System l J Pssp I fjkll %p- - . . . -

BO R Ja gecrica

,I p[

ljx g necevtocou h c1 e pg81019%

  • h~ I SHERLECOPY Shhare Verification and Validation Final Report l1 a agg , grg Wr$ <

J.Nedaud Date: 19/06/96 Visa:

.. Ch(k D.Canesaa Date: 19/06/96 , Visa:

$ $ $ f(,gM -Ap fM L Chapelot Date: 19/06/96 _ Visa:

INTERNAL DISPATCHING EXTERNAL DISPATCHING J.Nadaud F. Schulcz MGP instruments Inc.

D. Canossa F. Chiosta B. Laisne A. Pommier G. Ruaro J.L Gourone R. Michel Number of pages : 51 B 97 10-15 Update + SCE Comments aW A* A dH SE00 -

19,6.96 A Original edition M.F. 4* 0 C""

P Ind. Date . odification number & designation f M.F. Signatures LT L74L" W ",,74 = ~* y"==,, m m 110834 BA

fsyNannanesMGP Radiation Monitoring System Software Verification and Validation Final Report p2 Update Table Index/Date Modified chapters Origin and designation of the modification Written by B 1Cv97 NM 1 Added Systern speedcatons and test documents.

2 Added IEC880fulfinment reference.

. 4 Q. Purpura comments (changed a wrfung wtth . by a development and =,

56.5.7.59,6.10 V&V summary update.

6.8 Added clartreaton on systern inte7aten.

6.10 Removed parameter sets from the software list.

6 AnomaY summary update.

7 Reorgantred tNs secton.

. Added software complexWy analyss and top 4own picture.

. Anommy history anaysis update.

. Added fault densey anaYss.

  • Operational history update; added ope a'onal anomay's table and rate of failure table.
  • Added fature anaYsis.

. Added common mode faBure chapter.

. Update of overal software quality assessment.

8.1 Software revison update, gL ;"L'**.* = C*g **y** " *' O' *' == ,, , m 110834 BA

o 3 .

s. .

Radiation Monitorha System Software Vermcation and Validation Final Report p3 Table ofcontent

1. Purpose............................................................................................................................4
2. R eferenee documents ... ....... ........ .................... ........................... ............. .... ...... ..... .......... 5
3. Definitions........................................................................................................................5 3.1. Abbr eviation s . . .. . . .... .. . .. . ... . . ... . ... . .. ........ ................ ....... .... ....... ... ........ .. . . . .. . ...... .. . . 5 3.2. Acronym s & N otation s ...... ...... . .... ........ .. .. .... . ............. ................. .. ....... ........... ... 5 3.3. Classifcation of documents ...... .......................................................................... 6
4. Summary of all life-cycle V&V tasks .................................................................................. 7
5. Sum mary of task results.. ........................... .. ... ...................... ........... ................. ................ 9 5.1. Software development history............................................................................. 9 5.2. I n tr od uction . .. .. . .. . . . . .. . . .. .. . .. . .. . . .. .. . . . . . .. . . . . .. . . . .. .. .. ...... . . . .. . .. .. . . .. .. .. . . . .. . .. . .. . .. . . . .. . . ... .

5.3 M anagement phase ........................... .. ... .................. ...... ........... ....... ..... . ........... 10

5. 4. Con cep t phase . . .. . . . .. . . . . . .. . . . . . . .... . . . . . . . . . . .. . .. . .. . . . ...... . . . .. . . . . .. . . . ... . . . .. . . . . . ... ... . . ... . . . . . . . . . 1 1
5. 5. M odel pha se .. . .. .. . .. ... . . .. . .. . . . ... . . .. . . .. .. . .. .. . . . . . . . . ... .. . . .... . . . .. . . . . ... . . .. .. . . . . . . . . . .. ... . .. . . ... .. . 1 1 5.6. Hoquirements phase...................... ............................................................. ........ 13 5.7. De sig n phas e . . . . . .. .. ... . . . ... .. . .. .... .. . ... . .. . . .. . . . . . . . . . . . .... . . . ... . ... .. . . ... . .. ... ... .. ......... . ... . ... .. 1 6 5.8 I mplementation phase ..... ....... .. ...... ...... .................. ..... ............ ........................... 19 5.9.Testphase..........................................................................................................20 5.1 0. Dellvery phase .... . .... . . .. .. . .... . . . .. . .. . .. . . . . . .. . .. .. . . . . . . ... . ..... . . .. . . . . ..... . . . .. . ... . . . .. .... . . . .. .. . . 22
6. Summary of anomalies and resolutions ............................................................................ 25
7. Assessment of overall software cuality ............................................................................. 33 7.1. Software complexity................................ ..... ................... ........... ..... .................... 33 7.2. Assessment by anomaly history analysis............................................................ 34 7.2.1. LPU/ Base software ... ........... .............................. .......... ......................... 34 7.2.2. LP U/lc software ................................................................................... 35 7.2.3. LP U/l O software . .. . . .. . . .. .. . . . .. . . .. . .. . .. . ... ... . . . .. .. .... . . . . .. ..... . . .. ... . . . . ... . .. . . . .. . ... 36 7.2.4. LP U/PI PS software ......... ........................................................ ........ ...... 37 7.2.5. LPU/SAS software ........................ ................................. ....................... 38 7.2.8. LPU/SI software ................................................ .................................... 39 7.2.7. DU/ Base software ................................. ....... ........................................ 40 7.2.8. DU/ Application software ....................................................................... 41
7. 3 Fa ult density .. .... . . ... .. . . . . .. . . . ... .. .. .. .. ... . . . . . . . . . . ... . . ..... .. . ... .. ... . . .. .. . .. .. .. .... ... . .. .... . .. . ... .. 4 2 7.4. Assessment by operational history ..................................................................... 43 7.5. Fallure analysis ............. ......................... . .......................... .................................. 46 7.6. Common mode f allure .......... .... . . ......... ............................ ....................... .......... 48 7.7. Assessment of overall software quality ............................................................... 49
8. Con & sion & R ecommendation s .... . ... ..... ....... . ............ ...................................... ............... 50 8,1. R e sults Su mm ary ................. ...... .. . ..... . . . .. ....... ........... ......... ... ....................... ... ... 50 8.2. Recom mend ation s ...... ........................ .. ............. .......... ........... .......... ......... ......... 51 n.

n "' .

%.- ._ ...w

. .a .w .

110834 BA

MGP alan m a n Radiation Monitoring System Software Verification and Vahdation Final Report p4

1. Purpose This final report includes a summary of Software Verification and Validation actMties and results for the whole RAMSYS software project.

The report is organized to facilitate evaluation of the quality of RAMSYS softwares, and of the software Verification and Validation program itself.

The table below identifies what softwares and associated documents are covered by this report:

LPU/ Bass U'U.lo LPU10 LPU/ PIPS LPU/SAS LPU/Si DU/ Base DU/Appti Software AD 562 568 631 564 665 563 560 661 Parameter Set /D N/A 600 648 601 602 599 N/A 603 System 45179 45179 45179 45179 45179 45179 45179 15179 Speclocations 458% 45866 45866 45866 45866 45866 45066 45866 Software 45180 45180 45180 45180 45180 45180 45182 45182 Requirement 45758 45758 45758 45758 45758 Specincades 45100 111490 45186 45198 45184 Parameter Table 45504 45504 45504 45504 45504 45504 45505 45505 45509 111492 45507 45511 45500 ecttware Test Files 46630 46631 46631 46631 46631 46631 46632 46632 46635 111496 46634 16636 46633 j Softwve Design 4b181 45101 45181 45181 45181 45181 45183 45183 DesesIpti" 45759 45759 45759 45759 45759 l

45191 111491 45187 45199 45185 integration TestFile 46673 46674 46674 46674 46674 46674 46702 46703 110682 110682 110682 110682 1106=,

46687 111493 46682 46697 45677 Programming Files 110512 110512 110512 110512 110512 110512 110512 110512 (modules) 110516 110516 110516 110516 110516 110516 110514 110514 110403 110519 110519 110519 110519 110519 110518 46706 46689 111498 46604 46609 46679 System ITF 110836 110836 110836 110836 110836 110836 110836 110836 l

Component Test 110218 110219 110219 110219 110219 110219 111223 111223 File 111227 111495 111225 111226 111224 111309 111309 integration Test 46675 46676 46676 46676 46676 46676 46704 46705 Reports 110683 110683 110683 110683 110683 46888 111494 46683 46698 45678 Software Test 46637 46638 46638 46638 46638 46638 46639 46639 R* Ports 46642 111497 46641 46643 46640 System lTR 110837 110837 110837 110837 110837 110837 110837 110837 l

SCF 110520 46691 111500 46686 46701 46681 110521 46708 LSD 110407 46690 111499 46685 467 46680 110535 46707 W.,2",", ,;;'O"O,7,,'0 7,= ,*,,*, A"""* " O *',", = = , _ 110834 BA l

$.MlP Software Verification and Validation Final Report Radsstion Monitorina system p5

/

2. Reference documents L1. MGPLRAMSYS SDP.45202 Software OmlopmentPlan t.L MGPLRAMSYS SOP. 46800 RMS SrecMc Qualityassurance Plan 2.3. MGPLRAMSYS SQAP. 45203 Software Quality Assurance Plan L4. MGPLRAMSYS SWP.44120 Software VAVPlan Lt. MGPLEAMSYS SVVTP.110835 Software VAV Toof Plan Ls. MGPLRAMSYS lEC 56011ts41 IEC 880 tumilment for the RAMSYS software development l

4

3. Definitions 3.1. Abbreviations DU Display Unit (LDU or ROU) lC lonization Chamber

. lEC Intemational Electrotechnical Commission l0 input Ouput LDU LocalUsplay Unit LPU LocalProcessing Unit MASS Maintenance and Setup Software for wunoows (non safety related)

MGPl MGPInstruments SA (Lamanon)

PIPS Passivated Implanted Planar Silicon OA QuaHtyAssurance RDU Remote Display Unit MGP Instruments Radiation Monitanng System RAMSYS 5AS Spectrum AnalyzerSystem SI S&oon SVLV Software Vertlication and Validation VLv Venncatinn and Validation 3.2. Acronyms & Notations Common Software components that are common to LPUs and DUs softwares DM Department Manager DUIAppll Software corrtoonents specmc to the DU rpplication software DUlBase Software coi+arents specmc to the DU base software LPUIAppll Software components common to LPU application softwares LPUlBase Software components specmc to the LPU base software LPUICommon Software components common to LPU softwares (base and applications)

OTATJ 70%l;=,*,,,"4""'*h*" "

" L",,,, ,, ,,,, . 110834 BA

--__m.. _ . . . - . __ - .m. -.., ,

3n'MGP

..l: anmunen Radlavon Monitoring System Software Verification and Validation Final Report pe 3.3. Classification of documents English ATF Acceptance Test Plan PTA Plan ce Test d'Acceptauon ATR Acceptance Test Report RTA Rapport de Test d' Acceptation CVR C Programming Rules RPC R6gles de Programmation en C CTF Component Test File DTU Dossierder Tests Unstatres LSD Ust of Software Documents LDL Uste des Documents Logiciels PT Parameter Table TP Table des Param6ttes R Report CR Compte Rendu SCF Software Change F6le DSL Dossier de sum Logiciel SDD Software Design Descnptions ADG Analyse Organique G6n6 tale ADD

  • Analyse Organique DetallI6e SDP Software Development Plan PDL Plan de D6veloppement Logiciel ITF lntegration Test File DIL Dossier d1ntegration du Logiciel ITR lntegration Test Report RIL Rapport d1ntegraDon du Logic'el SITF System integration Test File DIS Dossier dlntegraDon Systeme SITR System Integration Test Report Ris Rapport d1nt6prabon Systeme SMF Software Manufactunng File DFL Dossier de Fabncation du Logiciel SOAP Software Quality Assurance Plan POL Plan de Qualit6 Logicie!

PF Programming File (Source Code DP Dossier de Programmavon ou Ustinge) topiciel _

SRS Software Requirements AF Analyse Fonctionnelle Specifications STF Software Test File DEL Dossier d'Essais Logiciels STR Software Test Report REL Rapport dEssais Logiciels SVVP Software VLV Plan PVL Plan de V&V dulogiciel SVVFR Software VLV Final Report RFVVL Rapport Finalde V&V du Logiciel SVVTP Software V&V T00l Plan MVVL M6thodes de V& V du Logiciel TS Technicat Specriscation ST Sp6cification Technique D0%"7A% %"*T ="4"*= J'O ;; 7., O ,,,,, . 110834 BA l

$' \\ anmanenMGP

~

Radiation Monttoring System Software Verification and Validation Final Report p7

4. Summary of all life-cycle V&V tasks i

Tasks that have to be performed are specified in 2.3. MGPLRAMSYS SOAP.45203 and in 2.4.

MGPLEAMsYS SVVP = 46120 documents.

The next table summarizes for alllife-cycle of every software the tasks to be performed.

(

Phase Tasks Management

  • Software Development Plan development and review;

. Software Quality Assurance Plan development and review; e C Programming Rules development and review;

  • Software V&V Plan development and review; Software Conficuration and Management Plan development and review;
  • IEC 880 fulfil 8 ment documentation development and review; Concept
  • System Requirements Specifications development and review;

. RAMSYS protocc! Technical Specifications c;evelopment and review; I Model

  • List of Software Documents development and approval; l

!

  • Software Change File development and approval;
  • Software delivery w.h acknowledgment form;
  • Standard parameter set delivery with acknowledgment form; Requirements
  • Software Requirements Specifications development and review; Parameter Table Technical Specifications development and review;
  • Software Test File development and review; U f. C 7 b " M .".7 d U l " " ~,~ Z O m 110834 BA

" M9_P _ Radiatkus Monhodna System Software Verification and Validatson Final Report pa Phase Tasks Design . Software Design Descriptions development and review;

. Integration Test File development and review; implementation . Component Test File and Report development and review;

  • System Integration Test Fl!e development and review; Test . Software Integration Test Rsport development and review;

. Software Test Report development and review;

. System Integration Test Report development and review; Delivery . Programming file (source code) check in; e Ust of Software Documents development and approval;

  • Software Change File development and approval;

. Software delivery with acknowledgment form;

. Standard parameter set delivery with at,knowledgment form;

. Software Manufacturing File development and review; Wh.hWM;70.TI~JOhA e 110834 BA

Radiation Monttorino System Software Verification and Validation Final Report p9

5. Summary of task results 5.1. Software development history Here is a brief presentation of the evolution of the scftware from concept to ilnal checkout.

1993 RAMSYS concept definition, development team and QA organization February 1994 RAMSYS Software V&V definition (SVVP)

February //u(y 1994 Software Requirements Specifications for DU, LPU/ PIPS, LPU/SAS, LPU/SI.

October 1994 Model softwares delivery for hardware testing (DU, LPU/ PIPS, LPU/SAS, LPU/SI).

June //uly1995 LPUSC and LPUSO Software Requirements Specifications.

AprWMay1995 First fully tested software delivery (LPU/ PIPS, LPU/SAS, LPU/SI).

August 1995 Fully tested DU software delivery.

December 1995 Fully tested LPUSO software delivery February 1996 Fully tested LPUSC software delivery 5.2. Introduction For each of the project phases, a table summarizes all V&V tasks that have been performed with associated date.

Each task contains the following information:

o.w: nevww or oerrvwy saw.

sonwm e.mponent which component is reisied to the task.

ID: oocument identirer.

Vmim Vmion (from A to Z) and wnting language (French by default, or Enghsh r a A ionows -

the versson)

Label; oocunJd or software name.

Task: V1V task type; can be a document review, a change review (RExxxx for software change and oExxxx for document change with xxxx as the revww number) or a regular update.

  • M, ::" ".ta'.'*.'O'll",a::.~s.'.10:::~,.',1*".."';::" Uhs - 110834 BA

$' anonumersMGP Radiation Monitorin0 System Software Verification and Validation Final Report p 10 ~

5.3. Management phase This phase gathers the documentation that describes the project organization.

Date Suttware y mm ds :ompareers 93 11 10 Lommon 45202 A Software Devernment Plan (S(Y) lReyww 93 11 16 Common 45203 A l Software Quality Assurance Plan (SOAP) lRevew 9441 06 Common 4$880 A lC P,isc., a-g Hudes (CPR) lRevew 9442 28 Common 46120 A l Software VA V Plan (SVVP) lRevww 944341 Common 452u3 B l Software Quahty Assurance Plan (SQ4P) lReyww 94-O'r16 Common 46120 8 l Software VA V Plan (SWP) lRevow 9446-16 Common 110405 AA l Con /puraton Management Pan (SCMP) lRevww 94-06-22 Common 46120 C l Software VA V Plan (SWP) lRevew 44 11 21 Common 45202 B l Software Deveepment Pasn (SDP) lRevow i

94 11 28 Common 45203 CA l Software Quahty Assurance Plan (SOAP) lRevww l 9542 20 Common 46120 DA l Software VA V Pan (SWP) lRevow l 9642 28 Common 46203 DA l Software Quahty Assurance Pan (SOAP) lReyww 964310 Common 110835 A lVA V TooIPsan (SWTP) lRevow 964316 Common 45203 EA l Software Quahty Assurance PAan (SCAP) lRevow 9643-31 Common 46120 EA l Software VA VPlan (SWP) lRevow 9W542 Coe mon 45203 FA l Software Quahty Assurance Plan ($dAP) lRevow 954721 Common 45203 GA l Software Quakty Asswance Pian (SOAP) lRevow 96 07 21 Common 46120 F A l Software VA V Paan (SWP) lReyww 95-06-22 Common 45860 8 jC P,cy. a-s Auw (CPR) lRevww 9641 24 Common 112641 AA llEC 890 Fuhtiment lRevww 97 10 14 Common 110405 BA l Con /quracon Management Plan (SCMP) lReyww l The Software V&V Plan document had been changed 5 times. The main concern has to be able to fulfill the American IEEE standards as well as the European IEC recommendations.

The Software V&V Plan finally meets the IEEE standard while another document, the IEC 880 fulfillment, describes how the RAMSYS development met the IEC 880 standard.

The Software OA Plan changed slightly to integrate customer comments.

1 l

MO'I"",w".L'."O""Z " 74.~O~EE"JO. s. = % 110834 BA

$, is anamnersMGP Radiation Monttoring Sytm Software Vertfication and Validat!on Final Report p 11 5.4. Concept phase This is the project definition phase with system requirements.

W 9442 16 (Common 45866 AA Protocot Speoticataons lReyww l 9544 28 l Common 45179 BA System Speciteatens (SAS) lRevew l

  1. A6-06 (Common 45666 BA ProtocoISpouhcarsons lRevew]

9641 30 jCommon 45179 CA System Specttscatons (SAS) lN15068 l l g711 l Common 45179 OA System Specifscarsons (SAS) lDE10024 l The system specifications were available at the project start. Changes were made to integrate comments from customers (no specifications were changed on version CA),

5.5, Model phase This is the software model delivery phase for intemal purpose (hardware adjustments),

s, 94 4 19 DU/Appt 603 A Standartf Parameter Set Update 94 4 29 LPO/PLPS 601 A l Standard Parameter Set lupdate R10 25 DU/Apot 46707( lust d software documents (LSD) l Update

% 10 25 DU/ App 6 46708 A ' l Software Change Fee (SCF) l Update

% 10 25 DU/Apph 661 A lSottnere Delivery l Update R10-25 DuBase 110635 A lbst of software cocements (LSD) (Update l 41025 DthSane 110621 A lSottnere Change FW (SCF) l Update l R10 25 DUSase 660 A l Software Dohery l Update 94-10 25 LPUSaee 110407 A lbst of software documents (LSD) l Update l

l R ic25 LPuSase 110520 A lSorrware Change Fbe (SCF) { Update R10w25 LPUSame 662 A {$ottware Dehvene l Update

% 10 25 LPU/ PIPS 46685 A lbst of sottware ducuments (LSD) l Update

% 10 25 LPU/ PIPS 46686 A lSobere Change Fde (SCF) l Update R10 25 LPU/P PS 664 A lSovrwere Dohery l Update 41025 LPU/SAS 46700 A just of softnero documents (LSD) l Update 94 10 25 LPU/SAS 46701 A l Software Change F# (SC/) l Update

% 10 25 LPU/SAS 665 A l Software Detrvery l Update R10 25 LPU!Se 46680 A lust of sot' ware documents (LSD) l Update

~

94-10 25 LPU/Si 46681 A l Software Change F# (SCF) l Update R10 25 LPU/Sa 563 A lSottware De6very lUpcate 41109 LPU/SAS 46700 B

' lbst of software documents (LSD) (Update R1109 LPU/SAS 46701 8 lSohste Change F# (SCF) jupdate R1149 LPU/SAS 665 B ' l Software Denvery l Update R1241 LPU$AS 46700 C ' just et software documents (LSD) l Update R1241 LPU/SAS 46701 C (So/tware Change F# (SCF) l Update R12ci LPu/SAS 565 C 1 Software Delivery l Update 41241 LPU/SAS 602 A p'rancard Parameter Set l Update C = . =.="s%:::.7;J. :.T!::.T.::::::. m ~ 110834 BA

$' ,d annaarsMGP Rsdistoon Monttorina System Software Verification and Validation Final Report p 12 sor,were '

Deer y mm .0, ?omporwr, l

W1242 UU/Atph 46701 0 t or sonware cocuments (LbO> L4date \

% 1242 DU/Atta 467063 l Software Chanpo FM (SCF) lUrsate 94 1242 DU/Agg4 bei B l Software Dekvery lUtdate R1242 WU/ PIPS 4%M B lbst of software documents (LSD) lUtdate 94-12-02 LPU/P6PS 4 %86 B l Software Champo FWe (SCO l Update 4 1242 LPU/P6PS %4B l Software Dekvery l Update R1242 LPU,% 4%80 B lbst of sottrare documents (LSD) l Update R1242 LPU/$s 4%8iB lSorrware Change Fue (SCO lUpsate

% 1242 LPuS %B l Software Debery lUtdate R1216 DU/Acce 46707 C lbst of softwa o accuments (LSD> lutdate R1216 DU/ App 6 467DB C lSotrware Change fe (SCO l Update W1216 DU/Atsk 661 C l Software Dohvory lUpaa'e 95 h 13 DU/Arge 46707 D lbst at sotrware documents (LSD) l Update 9 % 1 13 DU/Apph 46708 0 l$ottware Change ('We (SCO lUponte Mt.13 DU/Apph 661 O lSorrmare C#very lVpcate 60113 LPU/P6PS 4%85 C lust of pottware documerits ,LSD) r lUpoate 9 % 1 13 LPU/ PIPS 46686 C lSo/rware Chanpa fue (SCFJ lUpcate 96-01 13 LPU/ PIPS 664 C l Software De# wry lUpanie 9M217 LPU/SAS 46700 0 lbst of sotrware cocuments (LSO) l Update 95-02 17 LPu$AS 46701 D l Software Change Fh (SCO l Update 9 % 2 17 LPUISAS MSD l Software De#very lUrdate 9 % 2 20 LPus 46680 C lbst of software accuments (LSD) lUposte 9542-20 LPU.% 4%81 C l Software Change FMSCF) lUp0 ate 6 02-20 LPu% '43 C lSofrwem De#very l Update 6 02-22 _ DU/Apph 46707 E lbst of software documents (LSD) l Update ,

60222 ~ DU/Apph 46708 E l Software Change fee tSCO lL44 ate ,

95 4 22 Dd/ App 6 661 E l Software Deewry l Update 95 M 29 LPU.% 40M0 D lust at software aocunents (LS0) l Update]

95 4 29 LPu% 46681 D l Software Change Fue (SCO lUpdat L 9 % 3-29 LPU/Se 663 D lSohware Dehwry lUpda e 95 M 13 DU/ Base 110535 B lbst of software documents (LSD) lUpos to 95 M 13 Datase 110521 B lSottware Change Fde (SCO lUpdf.to 9 % 4 13 DGBase MOB l Software Deevery lUpd ate 9 % $19 DU;Apph 46707 F lust of sonware documents (LSD) lUp ate

, 95419 DGApok 46708 F l Software Change FWe (SCO lUplate 95 4 19 DusApok fi61 F l Software Dehvery lUplate For model delivery, the software Change file, and list of software doCiments have been released to ease software follow up. These software versions have nc t been operational at customer sites.

n ~

% ,-. e .- .= -~. .- . % e . -.- . -. ~ " e""" 110834 BA

. w ". .m.  %

g4annewenMGP Radiation Monitortno Systern Software Verification and Validation Final Report p 13 5.6. Requirements phase This gathers Software Requirements Specifications (SRS), Parameter Tables (PT) and Software Test Res (STF),

itatr bottewaar

'y tretts 6 ottessorerte 9111 17 LPU/ Common 4b180 A catsons (585) lReyww M4216 DU/ Common 45162 A l$recihcatons (SAS) lReyww M4217 LPU/Si 45164 AA lSpecshcapons (SAS) lRevew 944310 LPU Common 4%04 AA lMmeter Tate (PT) lRevow I4701 LPU/SAS 45196 AA lStocshcatons (SAS) lRevew M46-01 LPU/SAS 4%11 AA l Parameter TaNe (PD lRevew D1417 LPU/ Common 45160 B lStocrocarsons (SAS) l Review 40629 LPU/ Common 45%4 BA lParamew Tatvr (PD lRevww 94 07 27 DU/ Common 45182 B l$secshcstons (aAS) lRevww M 07 27 DU/ Common 4%05 AA l Parameter Tate (PD lReyww H 07 27 LPU/ PIPS 45160 AA lSpecircabons (SAS) lRevww M4127 LPuPIPS 4%0F AA l Parameter Tath (PD lReyww 5442t) LPU4ane 4M30 A l Test F#e (STO lReyww 9740 27 LPU/Apph 4%31 A l Test fee (STD lRevww

% 11 25 LPuBase 4%30 B l Test Fm (S TO lReyww R1241 LPU/SAS 45198 BA lSem ' anons (SAS) lRevow 41201 LPU/SAS 4M11 BA lPG ow Tate (PD lReyww R12 01 (PU/S6 699 A lSta, ctartf Parameter Set lRevow 41216 LPU/SAS 4M36 A l Test F# ($TF) lReyww M-12 22 LPGApph 45758 A lAlpon Am in#erface Specshestons (SAS) _ lRevww 41222 LPU$ame 4M30 0 l Test F# (STF) lRE4203 4 12-22 LPU/ Common 4%04 CA lParameest TaNe (PD lReyww 4 12 22 LPU/ PIPS 45166 BA lSsecencenons (SAS) lRevww

! 41222 LPGPIPS 4%07 BA l Parameter Tatse (PD lRevww

% 12 22 LPU/S6 45164 BA lStoorAcanons (SAS) lRevww

% t2-22 LPU/S6 45506 AA lParanneter Tate (PD lReyww 9 % 1 11 LPU/Conwnon 45160 C lSpeev6 canons (SAS) lRE4203 95-01 12 LPU/ PIPS 4M34 A l Test Fe (STF) lRevww 9 % 2 14 LPUiApph 4M31 B l Test fee ($ TF) lReyww 9542-14 LPOS 4M33 A l Test F4 (STO lReyww 954341 @UW 46633 8 l Test Fde (STO lRevww 9 % 3-13 LPuS 45164 CA lSpeerncaeons (SAS) lRevww 9 % 3 13 LPikSe 45506 BA l Parameter Tate (PD lRevow 9 % 447 DU/ Common 45162 C lStece6catons (SAS) lRevww 954447 DGCommon 4%05 BA l Parameter Tate (PD lReyww 954447 LPU!SAS 45198 CA lSpecrocanons (SAS) lRevww 9 % 4-07 LPu'SAS 45511 CA l Parameter TaNe (PD lRevww 95-04-18 LPU/Cornmon 45504 DA l Parameter Taus (PD lRevow 9%418 LPUPIPS 45186 CA lSpecshcahons (SAS) lRevow 9%41B LPU/PtPS 45607 CA l Parameter TaNe (PD lReyww 9544-25 LPU/^m 45i80 D lStocrheabons (SAS) lRE4320 9 % 4-25 LPU/Corunon 45504 EA l Parameter TaNo (PD lRE4320 RL::::%=.=l"O,.' 0:,=::~M~!;;r.:';::::.m - 110834 BA

gwarmaersMGP Radttion Monitoring Syncm YoftwaTe Verification and Validation Final Report p 14 Daer Software l y mm et ompornw 9 Wars LPU/ Base 4%30 D l Test Fe (S TO RE 4320 9 % 5 12 DU/ Common 4%32 A l Test F#e (STD lReyww 60517 LPU/S %9B lStarxtarit Parameter Set l Review

'M9 LPU/ App 6 4M31 C l Test Fde (S TO lRevww

'sI631 LPU/SAS 45198 DA lSpoofcates (SAS) lRevww 60531 LPU/SAS 45511 DA l Parameter TaNe (PT) lRevww 6Ot>4 LPUAC 4%09 AA l Parameter TaNe (PD lReyww 95w47 LPUAC 45190 A lSpearcarens (SAS) lRevww Wofe12 DU/ Common 4M32 B l Test Fue ($TF) l Review 6($14 LPU/ PIPS 45186 DA lSpeufcatons (SAS) lReyww 95 4 14 LPU/S 4bi64 DA lSpect/carms (SAS) lRevww b5 4 21 LPUAC 4%35A l Test Fde ($TO lRevww 60121 LPUAO 111490 AA lSpeedcatens (SAS) lRevew 60721 LPUho 111492 AA l Parameter TaNe (PT) lRevww 9 % 7 27 LPU/ Base 46630 E l Test F#e (S TF) lRE4478 95 4 22 LPO40 111496 AA l Test Fke (STO lReyww e5 4 23 LPU/ Common 45180 E lSpecifcarms (SAS) lRE4501 9 % 8 23 LPU/ common 4%04 FA l Parameter Taue (PD lRE4501 95 4 23 LPU/ PIPS 45196 EA lSanc,6carms tSRS) lRE4bO1 9 % 8-23 LPU/ PIPS 45501 DA l Parameter TaNo (PD lRE4501 95 4 23 LPU/S 45184 EA lSpecircalms (SAS) lRE4501 9 % 8-23 LPU/Si 4%06 CA lPammeter TaNe (PT) lRE4501 95 4 27 LPU/SAS 45196 EA lSpecrocahons tSASJ lRE4501 96 W 27 LPU/SAS 45511 EA (Parameter TaNe (PD lRE4501 6 1042 DU/ Common 45182 D lSpecAarons (SRS) lRE4501 6 1042- DU/Cornmon 45505 CA l Parameter TaNo (PD lRE4501 6 1042 DU/ Common 46632 C l Test F#e (S TO lRE4501 6 1042 LPU/ App 6 46631 D l Teet F#e (STF) lRE4501 610C @U/SAS 40636 B l Test F#e (STF) lRE4501 61N4 T 'U/SAS 40733 A lSpectrurn Compressm TS (TS) lRevww 610 is 30/S 46633 C l Test Fee (S TF) lRE4501 W1420 90/Apph 457b8 B lAlgontryn interface Speatescons (SRS) lRevww 61030 LPU/ PIPS 4M34 8 l Test F#e (STF) lRE4501 61109 LPuaC 45190 B lSpeancaoons (SAS> Inev=w 6114$ LPUAC 4%09 BA l Parameter Tabe (PD lRavww 61116 LPUMC 46M5 B l Test F#e (S TO lRevww 61212 LPU/ Common 45504 GA l Parameter TaNe (PD lRE4683 6 12-12 LPU/ PIPS 45186 FA lSpect4 cates (SRS) lRE4663 61212 LPU/PlPS 45507 EA l Parameter TaNe (PD lRE4683 61220 LPU/Apph 45768 C lAbmityn Antwface Specircates (SRS) lRE4683 95 12 21 LPU/SAS 45198 F A l$pecshcaDons (SAS) lRE4683 61221 LPU/SAS 4%11 FA l Parameter TaNe iPD lRE46&3

n. -.m . ~- . ~

% - e - m ., = - ., .. - -.. . - - - s .o  % 110834 BA

PaMGP kannuers Radiation Monitoring System Software VoTification and Validation Final Report p 15 N

M41126 LPU!SAS 46636 C Q Test FM (S TF) lRE4683 M4245 LPU40 111490 BA ISpecs6carons (SAS) lRE4737 R45 LPunO 111492 BA l Para neter TaNo (PD lRE4737 M-0248 LPU. PIPS 46634 C l Test Fe (S TO lRE4683 M42 27 DU/Comrmn 46182 E lSpeer6 canons (SAS) lRE4772 M42 27 DUR,ommon 45505 DA l Parameter TaNe (PD lRE4772 M42 27 DWCommon 46td2 D l Test Ne (STF) lRE4772 M-0346 LPUAO 111490 BA l Test Fh (STF) lRE473/

MM23 LPGArp 46631 E l Test he ($ TF) lRE4845 Wh23 LPU/ Common 45160 F l$, secs 4cabons (SAS) lRE484$

M-04 24 LPO40 111490 CA lSpecthcanons (SAS) lDE9088 M 0543 LPGPIPS 4$186 GA lSpecthcanons (SAS) lDE9088 M403 LPU/SAS 45198 GA lSpecshcanons (SAS) lDE9088 96 6 03 LPUS 45164 FA lSpecr6 cations (SAS) lDE9068 9648 30 LPU/sAS 46638 0 l Test F# (S TF) lRE4997 9G4902 LPUlAppii 4663s F l Test Fe (STF) lRE4997 97 4 16 LPO4hase 466M F l Test F# (J7F) lRE4997 974711 LPU/Canmon 45160 G lSpeerncaeans (SRS) lDE10024 974711 LPU/ Common 4$504 HA l Parameter TaNo (PD lDE10024 97 07 16 DU/ Common 45182 F l Spec #6 canons (SAS) lDE10024 97 07 16 Ducommon 45506 EA l Parameter TaNo (PT) {DE10024 970715 DUCommon 4%32 E l Test Th (STF) lDE10024 974716 LPU'Ard 46631 G l Test Feie (STF) (DE10024 974715 LPu10 111496 CA l Test Fw (STF) lDE10024 97 07 16 LPU/5AS 45511 GA l Parameter Tate (PD lRE5290 ,

97 07 15 LPU/SAS 46636 E l Test Fh (S7F) lRE5290 97 07 16 LPO/Sa 46506 DA l Parameter TaNe (PD lDE10024 31 06 10 LPUAC 45190 C lSpeerkatsons (SAS) lRES290 9148-10 LPUSC 46635 C l7est he (STF) {RE5290 97 4 25 LPGPnPS 46634 D l Test fu (S TF) lRE6290 Specifications have been modified throughout the project life, based upon customer requests, or based upon anomalies.

M W .*. b ~ J m" ". 7 0 .*"". 7 E ~ E ~ L*" O  % 110834 BA

iyMGP d ensmanes R*distion Monitoring Syst:rn Software Verification and Vahdation Final Repott = p 16 5.7. Design phase This is the software design phase that ends up with Software Design Descriptions (SDD), Integration Test Files (ITF) and Programming Files (PF) with source Code.

Onte softwarr ymm6 'omponer,

, l 944T 05 LPU/Lommon 45181 A lDesyn Desenpta (SDD) Review 9446-20 LPU/ Base 46673 A lintegrata Test fue (trF) lRevow 9449-0$ DGCommon 45183 A lDesyn Desenpre (SDD) l Review R1D25 Common 110512 A (Sowce Code (PF) lReyww 4 10-25 DU/Apph 46706 A lSowce Coos (PF) l Update

% )4 25 DU/ Base 110518 A lSowce Code (PF) lUpdato ki425 DU/ Common 110514 A l Source Code (PF) lRevow 941425 LPU/Apph 110519 A l Source Coos (PF) l Review n1425 LPU/ Base 110403 A l Source Code (PF) l Update 941425 LPueCommon 110516 A l Source Code (PF) lRevww

% 10 25 LPU/PlPS 46684 A l Source Code (PF) l Update l W10 25 LPui&AS 46699 A lSowce Code (PF) l Update 9410$25 LPuS 46679 A l Source Code (PF) (Uposte R1143 LPU/SAS 466998 l Source Coos (PF) jupdate 94 11 22 LPU/Apph 46674 A polograta Test WWe (ITF) lRevww

% i2-01 Common 110512 0 ISource Code (PF) lRevww

%1241 LPU/ App 6 110519 B lSowce Code (PS lRevow 941241 LPUSase 110403 B l Source Code (PF) l Update

% 12 01 LPU/ Common 110516 B l Source Cooe (PS lRevww

% 12-01 LPU/SAS 46899 C l Source Code (PS l Update S4-1242 DU/Appb 46706 B lSowce Code (PF) l Update 41242 LPU/PIPr., 46664 B l Source Code (PF) l Update

%1242 LPU/S 46679 B (Sowce Code (PF) IUpdate 94-1246 DU/ Common 110514 B l Source Cooe (PF) Revww

% 12 16 DGApp6 46706 C (Source Code (PM Update 99111 LPU/ Common 45161 B lOesyn Desenpoon (SDD) Revww 9M1 13 Common 110512 C (Source Code (PF) Revow 9M1 13 DU/Apph 46706 D l Source Code (PF) Update 9M1 13 LPU/ App 6 110519 C l Source Code (PS Revww 95-01 13 LPucom non 110516 C l Source Code (PF) Revww 9 % ) 13 LPGPLPS 46684 C l Source Cose (PF) UMate 95-01 16 LPU/ Base 110403 C l Source Code (PF) Uponte 9542 10 LPusAS 45199 AA lDesgn Desenpoon (SDD) Revew 9M217 LPU/SAS 46099 0 ISource Code (PS Update 95-02-20 LPO S 46679 C l Source Code (PS UL 3 ate 9 % 2 22 DU/Appu 46706 E l Source CO (PF) Update 96-03-03 LPU/ PIPS 45181 A lDespn Descnota (SDD) Reyww 9M346 DU/ Common 45183 B lDesen Desenpta (SDD> Revew 99329 LPUsApph 110519 D l Source Code (PF) Revow 95-03 29 LPGS 46679 D l Source Code (PF) Update

= = ; L % ';' g 7 4 7 4 J ~ ;"; , C ,, . m 110834 BA

h ierumme's Radiation Monitoring S>Cm

_ Software Verification and Validation Final Report p 17 Date Software y mm tt :omponer 954443 LPtJ/Ss 461Bb AA Desyt Desenprat (500) Revow 6 04-03 LPU/S4 46677 A pniepreta Test he (ITD lRevww 64447 LPU/PtPS 46682 A pniegrata TestIve(I79 lReyww 6 44-13 Cortanon 110612 O l Source Code (PO lRevew 95 M 13 DU/ Base 110$18 B l Source Code (PO l Update 60413 DU/Comrnon 110514 C lSotare Code (PF) lRevww 6 04-14 LPU/SAS 46697 A pnieprat :wt Tess Ide (ITH lRevww MM18 LPU/ PIPS 46684 D l Source Code (PF) l Update 9W21 DU/Apph 4870JT pntegrata Test De (ITi) lRevow MM21 DU/ Base 46702 A pnteprison Test Afe(ITF) lRevww 6 04-24 LPU/SAS 45199 BA lDesgo Desutstat (SOD) lRevww eM2$ LPU/ Common 45181 C lDesyt Descnota (SDO) - lRevew 60$45 DU/ Common 45183 C lDesyt Desongtm (S001 lRevow 96 4 % 9 @U/Bau 110403 D l Source Code (PD lRE4320 6 0549 LPU/ Common 110616 D l Source Code (PF) lRevow -

95 M 19 Common 110512 E lSottee Code (PD {Revww 9646 19 DU/ App 6 46706 F l Source Code (PF) l Update 96 M 19 LPU/Apph 11b19 E lSourts Code (PD lRevow 60519 @U/ Common 110516 E l Source Code (PD lReyww 954619 LPU/ PIPS 46664 E l Source Code (PF) l Update _

MM19 @U/SAS 46699 E lSotice Code (PO lUp1ao 60619 WGS6 46679 E l Source Code (PF) lL4xsa6 9546 06 LPusAS 45199 CA lDesgn Desenpson (SDO) lRevow 60744 DU/Apph 46706 O lSotree Code (PF) l Update 95 M 26 DU/ Common 45183 D lDesyt Desenpaon (SDO) lRE4601 60642 Common 110612 F l Source Code (PF) lRE4478 6 08-02 LPU/ Base 110403 E l Source Code (PS lRE4478 60643 Du9ase 110518 C lSosses Code (PF) lRE4478 954843 DJ/ Common 110514 D lSotste Code (PF) lRevww 6 08-21 LPU/lO 111491 AA lDeegn Desenpta (SDO) lRevww 95 M 23 LPU/Apph 46674 8 pnsepracon Test fWe trTF) lRE4501 96 4 31 LPU/lO 111498 A l Source Code (PF) l Update 6 0944 Common 110$12 O lSossee Code (PF) lRevww ~

6 0946 LPU/ Common 110516 F l Source Code (PF) lRE4501 954910 LPU/Apph 110682 A MJpont*rn Arusprate Test lWe (ITO lRevow E M 13 LPU/ Common 45181 D lDeset Descrocon (S001 lRE4501 MM27 @U/SAS 45199 DA lDesen Descnota (SDO) lRE4601 DU/Apph 46706 H l Source Code (PS lRE4501 6 i0 02 ]

6 1042_ @U/SAS 46699 F lSotree Code (PF) lRE4501 61020 LPU/Sa 46677 6 pntegrate Test /We (17F) lRevow 6 10-24 LPUPLPS 45187 8 JDesyt Descnota (SO01 lRE4501 61024 LPU/Sa 4518$ BA lDesyt Desenpbon (SDD) lRE4501 61025 LPU/Apph 110$19 F l Source Code (PF) lRevow W11 13 LPtkAppb 45759 A Mlpodthm Desyn Desenptat (SDO) lRE4601 61113 LPU/lc 45191 A lDesyn Desenate (SDD) lRevew 61113 LPullC 46667 A pntepmpon Test (de (ITO lRevev_

61128 LFonO 111493 A pntegrarm Test fue ttTF) lReyww ETI30 LPU/ PIPS 46684 F lSotsce Code (PD lILE4501

%.....~%...~..e----e.-

m ,.m - .w - - - w.. % 110834 BA l

(

1 I

. ,'MGP

>I emners Radistuon Monitoring System Softwaro Verification and Validation Final Report p 18

]

Date SoNewarr vmm4 :orrwwrm l W1212 LPU/ PIPS 45187 C lDesyn Descnota (S001 RL4683 W12 21 LPU/S 46079 F l Source Code (PF) lRE4501 6 12-22 LPU,Ap(* 45759 B lAgranthm Desyn Desenpta (SDD) lRE4M3 9641 09 LPUiAppt 110519 O lSome Code (PF) l Renew 96-01 26 LPU/SAS 45199 EA lDesyn Desenpra (SDD) lRE4M3 40126 LPU/SAS 46699 O l Source Code (PFJ lRE4683 60245 LPU/ Common 110516 G l Source Code (PO lRE46a3 96-02 07 LPUAC. 46689 A l Source Code (PF) l Update 50219 LPU/lo 111491 BA lDesyn Desenpoon (SDD1 lRE4737 50221 DU/ Common 45183 E lDespn Desenpra (SDO) lRE4772 60222 LPU/ PIPS 46684 G l Source Code (PFJ lRE4683 9642 27 QU/ Common t10514 E l Source Code (PF) lRE4772 96 03 19 DU/Apph 46706l l Source Code (PD lRE4772 40327 LPuno 111498 B l Source Code (PF) lr4E4737 964424 LPU/Apph 110519 H l Source Code (PF) lRE4645 9644-24 LPUAC 46689 B l Source Code (PF) _ lRE4845 96-04-24 LPU/SAS 46069 H l Source Code (PF) ~ lRE4845 5 0541 LPU/SAS 45199 F A lDesyn Desenpoor (SODI lDE9088 964fr21 LPU/ PIPS 46684 H {So ece Code (PF)

. {RE4645 96 06 14 LPU/SAS 45199 GA {Desen Desenpre (SDD) lRE4997 96-0945 Common 110512 H l Source Code (PF) lRE4997 44S45 LPU/SAS 46699 J { Source Code (PF) lRE4997 97 03 13 Common 110512 J l Source Code (PF) lRE4997 97 03 25 D0 App 4 46706 J l Source Code (PF) {RE4997 9743-25 DUSame 110518 D {Some Code iPF) lRE4997 9746-19 LPU/ Base 110403 F l Source Code (PF) lRE4997 97 07 11 LPU/ Common lDeson Desenpoon (SDD) "l N Y0024 45181y 974715 bu/ Common 4518' lDeson Desenpoon (SDD) lDE10024 974715 LPU/ PIPS 4M ( lDeson Desenpre (SDD) lDE10024 97 07 15 LPU/Si 45185 CA {Desen Desenpoon (SDD) lDE10024 97 07 29 LPU/SAS 45199 HA lDesgn Desenpta (SDD) lRES290 97 06 12 LPUAC 45191 B l Des 9n Desenpoon (SDD) lREE290

}71409 LPUMC 46689 C l Source Code (PD lRE5290 971409 LPt!CAS 46699 K l Source Code (PF) lEEI5290 Design docurnentation has followed the specifications as required by tht, software life cycle.

.,--e. . - . - "w"."m"."- w - -

~--.

% .- .i - - .~ 110834 BA I

gdansanaurrsMGP Radiation Monitoring System

_ Software Verification and Validation Final Report p 1g 5.8. Implementation phase This phase generates Component Test Files (CTF) and System Integration Test File l (SITF).

l l

Isatc Sottware ymmet :omporwv1 l 944447 W U/Appt 110219 A Component Test FM (CTF) lReyww 94 10 14 @ u/r$ase 110218 A l Component Test FM (CTF) lRevew 94 12 14 @ u/ Base 110218 8 l Component Test FM (CTO lRevow VA4433 LPU/De 111224 A l Component Test FM (CTF) lRevow 954447 LPU/HPS 111226 A l Component Test FM (CTF) lRevow 9'A4-19 DU/Conwnon 111223 A l Component Test F# (CTF) lRevow bA4 24 LPU/SAS 111226 A l Component Test Fh (CTF) lRevww 9A4-25 COCommon 111309 A 3 Component test Aeport (CTR) lRevow 9'A4 26 Common 110636 AA System Arepretson Test Fe ($1TF) lReyww VA610 Common 11DB36 BA System snreprepon Test Fw ($/TF) lRevow 9$4610 Common 110837 AA $ystem Ansepratson Test c eport (StTR) lReyww 9f M 31 WU/lo 111495 A Component Test FW (CTF) lRevow W1120 LPU/IC 111227 A Component Test FM (CTF) lRevww 9(r02 20 LPulto 111495 0 Component Test FM (CTF) lRE4737 l '9T47 29 LPU/$AS 111226 B Component Test FW (CTF) lRES290 The Component Test Filo gathers test descriptions (plan) and tebt reports. For tne Display Unit (DU), the document has been split out in two (file in CTF and report in CTR)

> because of the size of the document.

System integration tests have been designed to check network integraticn of the different devices.

L T.si"."M .k" X"47.70 ~ M J"ZTm.=% 110834 BA r

MG

$" ytiasumann'P s Radiation Monitonna bystem Software Vertfication and Validation Final Report p 20 5.9. Test phase Test phase consists of conducting integration and validation tests.

Integration tests are defined during the design phase in the Integration Test Files (ITF) and reported in Integration Test Reports (ITR).

Validation tests are defined during the requiroments phase in the Software Test File (STF), and reported in Softwaro Test Reports (STR).

1 41110 U/ Base 46676 A rep arm Test Retxrt (ITH) Revew 94 11 22 lLPGApp6 46678 A lintegrason Testhetxrt(ITR) lRevww R1125 lLPU/ Base 46637 A l Test Aepest ISTR) lRevow 60106 lLPU/ Base 46637 B l Test Aaport (STM) lRE4203 60214 lLPU/ App 6 46638 A l Test Aeport(STM) lReyww IS4443 lLPU/Si 46678 A lIntegrarm Test Aeport (ITR) LPOS lRevew 9544 03 lLPu/Si 46640 A l Test Report (STA) lRevww 9544-07 lLPU/ PIPS 46683 A lhtegrata Test Apport #TR) lRevew 9544 18 lLPU/ Paps 46641 A l Test Aeport (STR) lRevww 9544 27 lDU/ App 6 46705 A linsegrabon Test Report (ITR) lRevww 95444 ~ 46704 A lintegrafm VeDeport #TH) Peyww MTI'lDUSase'LPU/SAS 46698 A lintegrate Test Report (tTH) lRevww l

954544 LPU$ase 46637 C l Test Repor3fTR) lRE4320 Qh4518 LPU/SAS 46643 A 1 Test Aspat(STR) l Red ~

654)S-29 LPG App 6 46638 B l Test Report (STR) lRevww 9546-12 DU/ Common 46639 A l Test Aeport (STR) lRevew 550642 DOComnm 46639 0 l Test Ascort (STR) lRE4478 60642 LPU$ase 46637 D l Test Aaport (STR) lRE4478 61042 DU/Cornmon 46639 C l Test Report (STR) lRE4501 6 1042 LPGApph 46638 C l Test Report (STR) lRE4501 l 6 1042 LPu/SAS 46643 8 l Test Report (STR) lRE4 bot i

v510-20 OGCornmon 46639 0 l Test Aaport(STR) lRE4601 6 10-20 LPU/Li 46678 8 lintegraban Test Aeport #TA)LPOS lRE4501 6 i0 24 LPuPIPS 46683 B lIntegramon Test Report #1A1 lRE4bO I 9510$27 LPG Appe 110683 A [AJponttwn blegrapon Test Aeport(/TR) lRevww 61028 LPU/Apph 46676 B lbleprecon Test Report #TR) lRE4601 61107 LPGPIPS 46641 B l Test Aeport (STR) lRE4501 9C.1107 LPU/Ss 46640 B l Test Regutt (S TR) lRE4501 61129 LPU/IO 111444 A lIntegranon Test Report #7R) lRevww 61130 LPU/IC 46688 A lintegraban Test Aaport #7R) lReve*

61241 LPU/IO 111497 AA l Test Aeport (STR) lRevew

=L7hn :,,';::::,=,*,=,,~A*- ' :" La% e. ,,,, m ,,, 11o834 BA

)

ipdMGP enmnaan Rad? ton Monitoring System Software Verification and Validation Final Report p 21 paer '

sorense y mm + 'omponen M 116 LPU/ Age 110683 B Alporrtern intepreta Test Aeport (11 Al lRE4683 60115 LPUNIPS 4%83 C lIntegretson Test Aepcrt (ITA) lRE4683-40126 LPU/SAS 4%960 llntegrarm Test Aeport(tTA) lRE4683

(#641 26 LPUSAS 4%43 C l Test Aeport (S 7Al lRE4683 M4245 LPUAC 46642 A l Test Aeport ($ TA) lReyww 50248 LPUSIPS 46641 C ' I >;f Aeport ($ TA) lRE4G83 40227 DU/ Common 4%39 E }est Heport (S TA) lRE4TT2 964345 LPuno it1497 BA Test Aeport (S TA) lRE4T37 4 64-24 LPU/Acc4 4W36D Test Aeport (STA) lRE4845 60942 LPUiApte 4M38 E Test Aeport(STA) lRE4997-

^

44943 LPU$AS 46643 0 Test Aeport (S TA> lRE4997 914&19 LPU/ Base 4%37 E Test Aeport (STA) lRE4927 974115 DU/ Common 4%39 G Test Aeport (S TA) lDE10024 914715 LPU/Apph 46636 F Test Aeport(STA> lDEiD024 974717 LPuno 111497 CA Test Aeport (S TA>

^

lDE10CC4 9146-21 LPUAC 46642 8 Test Aaport(STA) IPL5290 971448 LPU/ PIPS 46641 O Test Aepcet (STA) RE5290 971448 LPU/SAS 4%43 E Test Aeport ($ TA) RE5293 91 12 03 DU/ Common 4%39 F Test Aeport(STA) RE4997 Integration test have been perforrned at least once, if a software change did not affect l the sofmare design (architecture), Integration tests were not repeated following the change.

Software validation (STR) has been inade each time prior to softw&re delivery.

I

' 110834 BA 4 L " *.*i b ~ J M " 7 0 . %=1"JOL~m s .

1

3 MGP J 4 amaganum Radiation Monitoring Systern Software Verification and Validation Find Report p 22 3.10. Delivery phase i

Software deliveries to the production department are traced on a form with acknowledgment when the software is received.

Software Change Files (SCF) include Chango descriptions from one version to another.

The List of Software Document lists for every software version all related documentation identifiers with release numbers.

r) vemm a es,cr ..

110407 8 ust of software docunents (LSD) UpaaYe 94 12 01 SPU/sase 941241 lLPU$ase 110520 B Sorrwure Change N (SCF) Update F 1241 lLPUSaoe M2B Software Deewy ' Update 110407 C ust of software doewnents (LSD) Update 60116 lLPO4ase 110520 C Sotru 2re Change F# (SCF) Update 60116 lLPU$ase 9 % 1 16 lLPUSane M2C So'inere Dehwy Update 6 02-20 l Common 46671 A Software Manufactunng FW (SM/) Revew 44585 D ust d nortnure doctr:t1ts (LSD) Update 60418 lLPU/ PIPS 9644,18 lLPGPIPS 46686 O Software Change M (SCF) Update M4O Software Dokwy Update 954414 lLPU/PtPP 9 % 509 lLPU/ Base 110407 D bst of software aocasnants (LSD) RE4320 9$4649 lLPUSame 110520 0 Software Ctange Fh (SCF) RE4320 9 % 549 lLPu9aes 662 O Software Deewy U$1e 601 B StandartiParainerer Set Update 9%518 lLPuPIPS 940519 LPU/ PIPS 4M85 E ust of sotrware documents (LSD) Update 9 % 519 LPU/ PIPS 4MB6 E Sottners Change Fde (SCF) Update 95 4 19 LPU/ PIPS 664 E Software De#wy Update 9H5-19 LPu!SAS 46700 E ust d sotrware docunents (LSD) Update 60519 LPuSAS 46701 E Sorrmare Change Fee (SCF) Update 60$19 LPU/SAS MSE Software Deewy Update 6 05-19 LPU/S4 46680 E ust of software docunents (LSD) Update 60519 LPU/Si 46681 E Software Change Fde (SCF) Update 95 4 19 LPU/G4 M3E Sotraere Deewy Update 9 % S 22 LPU/SAS 602 B Standartf Parameter Set Update 9 % 7 04 DurApph 46707 G Ost d software documents (LSD) Update 9M7 04 DU/Apph 46706 O Sottners Change Fde (SCE) Up' tate Er 04 DuiApph 661 G Sottnere De#wy update 9 % 6-02 LPuBase 110407 E ust of sottware docunents (LSD) RE4478 9%B-02 LPutano 110520 E Sottware Change Fde (SCF) RE4478 6 06-02 LPuBase 662 E Software Dekvery RE4478 6 % 643 Dusase 110535 C ust d software documents (LSD) RE4478 9$06-03 Dusase 110521 C Software Change fue (SCF) RE4478 6 0643 DU4ase %0C Sotruste Dekwy RE4478 61602 DuiApph 46707 H Ost d sot' ware documents (LSD) RE4501 6 1042 DG Apph 46706 H Software Change F#e (SCF) RE4501 61M2 DUIApp6 661 H Software De#wy RE4501 61002 DU/ App 6 603 B $!andarty Pararnerer Set Uposte __

61002 LPutAS 46700 F Ost of software docunents (LSD) RE4501 6 1042 LPu/SAS 46701 F Software Change Fde (SCF) RE4501 61042 LPU/SAS MSF Software De#very RE4501 T M%*"'h".h"* Wo.;f,,i" ,*,",,"A*"*",",4*'O O ea, s, , m 110834 BA

g*'NasmenenMGP Radiaton Monitoring Systern

_ Software Verification and Validation Final Report p 23 1

qate Settwarc ) Versses Latet o Tai yMm6 :omperwen , h 61130 LPU/KPS 4W5F List of software documents (LSD) lRE4501 96-11 30 LPU.A *S 46686 F Sot' ware Ch.ange Fde (SCF) lRE4501 961241 LPU/P6PS 564 F Sonware Dehvery lRE4501 ~

95 12 11 Comrnon 46671 B Software ManufawW Fde (SMF) lRE4501 95-12 13 LPUAO 111499 A List of sonware documents (LSO) ] Update 95 12 13 LPunO 111500 A Software Change F#e (SCF) l Update 61213 LPunO 631 A Software Dehvery l Update W12 21 L?UG 46680 F Last of software documents (LSO) lRE4501 61221 LPUG 46681 F Software Change F#e (SCF) lRE4501 61221 LPU G 563 F Sorrware Dehvery (RE4501 WC126 LPunO 648 A Standard Parameter Fet l Update 964247 1.PUAC 46690 A tsst of software documents (LSO) l Update

% 424.7 LPUAC 46691 A Sottware Change Fde (SCF) l Update 96024'1 LPU'tC 568 A Software Desrvery l Update 96 02 14 LPUAC 600 A Standard Parameter Set l Update 96-02-22 LPU/ PIPS 46685 G Last of software document- (LSO) lRE4683 50222 LPU/ PIPS 46686 G Software Change Fde (SCF) lRE4683 9642 23 LPU/PIPC 5e4 G Software Oshwory lRE4683 50223 LPUISAS 46700 G Lot of software cocuments (LSO) lHE4683 9642 23 LPU/SAS 46701 G Software Change F#e(SCF) lRE4681 9602-23 LPU/SAS 665 G Software Dehvery lRE4683 96-02 27 OU/Apph 467074 tot of software documunts (LSO) (RE4T72 40227 DU/Apph 46706i Software Change F#e (SCF) lRE4772 9G 4 27 DU/Apph 561 i Software Dehvery lRE4772 504-2d LPUAC 46690 B Lest of software documents (LSO) lRE4845 964424 LPUAC 46691 B Software Change FJe (SCF) lRE4845 96-04-24 LPullO 111499 8 Last of software documents (LSO) RE4737 9604-24 t/Uno 111500 B Software Change F#e (SCF) RE4737 96-04 24 LPU/SAS 46700 H Lest of software documents (LSO) RE4845 96-04 24 LPU/SAS 467Qi H Software Change Fde (SCF) RE4845 6 04-29 LPUAC 568 B Software Deavery RE4845 M 0503 LPUMO 631 B C h Dehvery RE4737 kW7 LPU/SAS 565 H Sotrware Dehvery RE4845 96 05-29 DU/Apph 603 C Standard Parameter Set RE4772 40619 Common i10834 AA VA V FaialReport (SVVFR) Review 96-06-F LPU/ PIPS 46685 H Last of software documents (LSO) RE4845 96-06 2i LPU/ PIPS 46686 H Software Change F#e (SCF) RE4845

% 06-21 LPU/PtPS 564 H So6twaro thrhvery Rh4645 96 07 21 r LPU/bi 46680 G List of software cocuments (LSO) RE4845 4 07-21 LDUG 466P1 G Software Change F#e (SCF) RE4845 M i-22 LPUG 563 G Software Dehvory RE4845 b09-05 LPV/SAS 46700 J Last of sonware documents (LSO) RE4997

~96-09-05 LPOSAS 46701 J Software Change Fde (SCF) RE4997 960945 LPU/3AS ) 565 J Sonware Dehvery RE4997

= no . -

, w . .-,. .#

m= 2 ns - -

. .ao."

% 110834 BA

g2reamussMGP ,. Radiabon Mo sitoring Systern

_ Software Verification and Vudation Final Report p 24 Date sotthare ) Versoon q taket = Tas ymm6 ?cmponerl 97 4 21 LPU/Se 466% 1 jtest of software documents (LSO) lRE4997 /

97 33-f

  • LPU/S4 46681 H l Software Change FM (SCF) lRE4997 97&It LPU/S 563 H l Software Dehvory lRE4997-9743-25 DO Apph 46707 J lLast of software documents (LSO) lRE4997 9143-25 OU/Apph 46700 J l Software Change Fe (SCF) lRE4w97 l 97 4 25 DU/ App 4 561 J l Software Dehvery lRE4997

~

97 03-25 DU/ Base 110535 D lLast of sottware documents (LSO) lRE4997 97 4 25 OU/ Base 110521 O lSorrware Change fue (SCF) lRE4997 97 4 25 OU/ Base 560 O lSorrware Douvery lRE4997 970442 LPU/tO 111499 C . lLest of software documents (LSO) lRE4997 97 04 02 LPU/to 111500 C l Software Change Fde (SCF) lRE4997 97 04-02 LPultO 631 C l Software Dehvory lRE4997 9746-19 LPGBase 110407 F lLast of software documents (LSO) lRE4997 97 06-19 LPU/ Base 110520 F l Software Change Fde (SCF) lRE4997 97 06 19 LPU/ Base 562 F lSota are Dehvery lRE4997.

97 f ' 17 Common 46611 C l Software Manutscran Fde (SMF) lDE10024 FOB-25 LPU/tC 46690 C kJst of software documents (LSO) lRE5290 97 08-25 LPU/1C 46S91 C l Software Change Fh (SCF) lRES290 l 9748-25 LPU/ PIPS 46685 J lLast of software docur7ents (LSO) lRE5290 l l 97 4 25 LPUlf"PS 46686 J Software Change fue (SCF) lRE5290 l 97 10 09 Common 46671 D Software Manufactunng Fde (SMF) lRE5290 97 1049 LPultC 568 C Software De#very lRE5290 l 97 1409 LPU/ PIPS 564 J Software Dehvery lRE5290 97 1049 LPU/SAS 46700 K LJsf of software documents (LSO) lRE5290 97 10-09 LPU/SAS 46701 K Software Change fue (SCF) lRE5250 97 1009 LPU/SAS $65 K Software De#very jRESO90 971015 dommon 110834 BA V4 V Fatal Recorf (SWFH) lRE5290

% - - . - -,-**** -*~ ~ - -

% .- - - ,- - ._ . w .w m s , = % 110834 BA

giannungsgMGP _

Radiation Monitoring System Software Verification and Validation Final Report p 25

6. Summary of anomalies and resolutions Each anomaly found during the development has a unique identifier (number). A database from which the next table has been edited, allows the generation of cross.

reference to the anomaly reports. Anomaly reports are in document control and available to MGP instruments (Lamanon and Atlanta).

This table summarizes all anoma'ies that were found during the product life. This tabks includes the following information:

. the anomaly ilumber which is a unique number that identifies the ancmaly;

. the phase from which the anomaly was found;

. for each concemed software, the version that corrects the anomaly;

. the current status of the anomaly: Open (in progress), Done (closed successfully),

Delayed (may be corrected in a future change), Canceled (no impact on the software);

  • the anomaly description;

. the date (day / month / year) of the anomaly detection; a week number during the year of the anomaly resolution;

. seriousness el the anomaly (J = jamming, N = non jamming, I - improvement).

  1. Phase L L L L L L D D Steque Descrtption D M Y Week s P P P P P P U U E U U U U U U l l R

I I l l i l E A h B S P S I I a p y a l l A C o e p s e P S e 1 N e S I E s

106 Model A Done Uo Broadcastmg 25 5 94 2 J 107 Model F Done Buner ses-test disatiled 27 9 94 18 N 3 Model O Done Digital output command 20 to 94 2 J 109 Modet D Done Maxenum measurement screen 3 12 94 2 N 111 Model c Done Parameter 1751 lault reportmg 5 12 94 2 N 112 Modei B F Done PD wnen gooig from maintenance to normal mode 5 12 94 15 N Buner ACK to do N the alarm level goes down 6 12 94 15 N

( 113 Modet F Done 4

114 Model E Done Waiung up the screen ty ACK button vnthout screen 6 12 94 N changing 115 Model E Done Report standby mode on measurement screen 5 12 94 6 N 116 Modet E Done Test resay 6 12 94 6 J 117 Model F Done Enemal commands from ROU to LDU 7 12 94 15 J 118 Modet E Done Topology error and LPU status reporting 14 12 94 7 N 119 Model 8 Done Topologytmamtenance taun 14 12 94 6 i 120 Desagn D Done Wamme correcten in source code 13 12 94 2 N 121 Desagn B D Done Wamme correcten in source code 14 12 94 2 N 122 Design G i Done Wammo correcten m source code 14 12 94 2 N 123 Desyi DlDone Source code samptricaton 14 12 94 2 1 5 A., """""O.7,2::".':'.'.'J::*~, 0:"::""*"'0";"'=O. - 110834 BA

qMGP, d ananmenm R*d'toon Monttoring System l

l

_Softwaro Vorification and Validation Final Report p 26 i l

t I

e Phase L L L L L L D D 6tatus Desuption D M Y Week s P P P P P P U U E U U U U U U t / R I

I I I I I I B A B S P 9 1 1 a p 8 a i i A C O e p s e P 8 e i N e 8 I E s

8 124 Model A A A A Done Statby command 21 7 94 2 N 125 Model B B C A Done Measurement unet management 20 to 94 2 N 126 Model B B C A Done EEPROM prob 6em 16 11 94 2 J 127 Model B B C A Dore Relay rwed drmng 16 11 94 2 J 128 Model C C D A Done Changed Cumulated te Rate of enance measurement 16 11 94 2 N 129 Model B C C D A Done Keep tautts when goeng from maintenance to rmrmal rnode 17 11 94 2 N 131 Model C C D A Done Round algonthm output values 14 12 94 2 N 134 Model C C D A Done Historcal wnting protecton 15 12 94 2 N 136 Model D Done No dead trne correcJon d aJtector m tauft 9 12 94 Ab N

~D7 Mooel D Done Probsem W unknown measurement board type in EEPROM 16 12 94 45 J 138 Model F Done Broadcasing grotem dunng ruualtzaton 21 12 94 15 N 140 Model F Done Automate screen change 12 12 94 6 N 141 Test C Done Set network speed to default value W bad parameter tab 6e 21 12 94 47 N 142 Model C Done Fdter advance counter 12 12 94 2 N 143 Modet C C D D Done Bypass on relay 14 12 94 2 J 145 Model D B Done Problem W network speed set to 115Kbpc 26 10 94 15 J 146 Desagn D Done Warrung correcton m source code 21 12 94 2 N 147 Desen D Done Waming correcton in source code 21 12 94 2 N 148 Desgn D Done Wartung correcuon en source code 21 12 94 2 N 150 Modet E Done Display analog input m 4-20mA lormat 22 12 94 5 N 153 Model B F Done Bus error d bad hardware contguraten 22 12 94 17 J 154 Test C Done Normal mode swttefung after bad program download 5 1 95 1 N 155 Deson C Done Check dead trne parameter valdsty 21 12 94 2 N 166 Desen C D Done Check analog oput type val @ty 20 12 94 2 N Removed analog output on curnutated measurement 20 12 94 2 N 157 Desgn C C D A Done 158 Model F Done Sound problem W intermrttent buzzer 10 3 95 15 N B E Dona Aca parameter reset command 9 1 95 6 i i60 Modei Done Remove electncal test event W no error 10 1 95 2 1 162 Desgn C Add a sequencer (state macrune) 10 1 95 8 4 163  % E Done E Dore Replace the use of parameter 64 by the counter $105 10 1 95 7 4 167 Model F Done Manage parameter Sti) (output state) 10 1 95 18 1 168 Model Done Change gasn and electncal test range 11 1 95 2 N 169 Model D Done include spectrum transfer duraten in dead trne calculaten 11 1 95 2 N 170 Model D Done Address error m degraded mode 13 1 95 2 J 171 Model Done Bad electncal test on Ngh counting rate 12 1 95 6 N 172 Mooel D Remove parameter tauft it maxrnum counung < 10000 cps 13 1 95 6 N 173 Model D Done Operate reuy on in bypass mode 17 1 95 2 N, 176 Model D Done Done irwerted measurement and fitter satura: son rtag 18 1 95 2 N 1 77 Desgn D Done Add sodiri cartrutge change command 19 1 95 6 N 178 Desgn D Commar.d code fdtenng 20 1 95 18 N 179 Modet O E E E B F Done

n. - -

m e - -

. - . %.e.,in.

.,e- . e. - . - - . - - ,--.,- .".~'.e.

- . ,  % 110834 BA l

1MGP

&annuman Rcdiation Monitoring System Software Verification and Validation Final Report p 27 i

e Phase L L L L L L 0 D Status Description D M y week s P P P P P P U U E U U U U U U l l A l l l l l I I E A t E S P 5 l l a p e l l A C O s p g

s P S e i N e S l E s

0 180 Mooet D Done po218 mornum effcsency has to be >= 0 20 1 95 6 N 141 Moosa C Done Add countog with electreal test fault event 20 1 95 4 1 1 82 Mooet D Done Problem d reference peak searcrung aies too sman 18 1 95 6 N 183 Desen D Done Aod rate of change m SA/N16C and SA/N16L algonthrns 23 1 95 4 J 164 Test C D D A Done Probism m *C to 'F converson 23 1 95 6 J T85 Mooet E Done Add flag and sequercer state reportmg 25 1 95 5 N 186 Model D Done Protsem a flow rate una cWierent than Vh 25 1 95 4 N 188 Mooet D Done Jammme probiem m Beta aigonthrn calculaton 25 1 95 4 J 189 Mooel D B Done Aod diagnosa event m case of a CPij excepton 26 1 95 19 e 190 Test C D D A Done Overtonded processor probiem a mamtenance mode 27 1 95 4 N swnchmg 191 MoceT E Done Bargraph omploy hmned to 10e9 30 1 95 7 N 192 tenpa C Done . Ognal output and temperature put probism when booteg 30 1 95 6 N 193 tmot C Done Bad countmo threshold for Je4 w management 30 1 95 6 J 194 Impi C Done Bad mm countog management on tow range 31 1 95 6 N 195 trnpl C Done Dead tune calculation now on both ranges for low range 1 2 95 6 N 196 Test B E Done Add saave address on comrn error event 2 2 95 6 N 197 Model D E Done Flow rate a!gornhm wah two saopes matead of 1 1 2 95 14 4 199 Test H Done Green l'ght may tum off for 1/2 a second sometrnes 8 2 95 3 N 200 empi 201 Impi 0

C D D A Done Done Pb ounne flow rate algonthm t.amiuaton Parameter tauft # ex1omat test swnctung 9

10 2

2 90 95

[ 6 N

N 202 trnpi C D Done Dead tm.e 8ag not grven to the COUNT algornhm 10 2 95 6 J 204 Model C D D A Dono Bad temperature mn when bootog 13 2 sd 7 J l

201 Test F Done Display speed unprovement 14 2 95 16 4 200 Test F Done Mamtenance mode ownching wanout event M 2 95 14 N 210 Model E Done Add automate gem adiustment 31 1 95 13 1 211 Model D E Done Flow rate faun management on users oetinabte range 15 2 95 8 1 212 feet B Done Communcason taults between a Du and as slaves 15 2 95 14 J 213 Model D Done Possedny to enter a temperature onset > '

' 17 2 95 7 J (THC1405416) 214 Model B Dono Segnal m event tint the Du goes m maintenance mrA 17 2 95 5 N 215 Test D Done Bad analog mput smoothog 24 2 95 9 N 216 Test C Done Claray merophonc management m the SRS 22 2 95 11 N 218 Test C Done vonage threshold to be updated m the SRS 24 2 95 11 N 219 Test C Done Parameter taun casatcaton m the SRS anc PT 22 2 95 11 N 220 Test D B Done Stop bootmo d Wiie- 4 rutanzaton fadure 17 2 95 16 8 221 Test D Ocne Removed electncavoptcal test threshoid 22 2 95 15 J 222 Modet E C Done Assocate comm diagnosa counters to one hnk (not to all 15 2 95 31 N links) 223 Test F Done Report on LED whch RDU e beeping 1 3 M' 19 1 224 Test F Done Problem on sequencer trners 1 3 95 9 J w--- . e - . -. ~ """ " -*

110834 BA-

% = n,= . . .-- w . s.

3denusneersMGP Ridiation Monitoring Syst*rn i Software Verification and Validation Final Report p 28

  1. Phase L L L L L LU 0 Status Description D M Y Weet a P P P P P P U U E U U U U U U i i R I I I I I I B A I B B P S I 1 a p a l l A C o e p

, g a P S e i N e 5 I t 8

8 225 Test F Done Probiern when 2 sequencers are rurnng concunently 2 3 95 9 J 226 Model F Done Display SATURATION d r tasurernent saturaten 3 3 95 15 N 227 Test B Done Network porturbatu a i one slave es unplugged 2 3 95 14 N 229 Modei O B Done Add a cornrn trneen parameter 3 3 95 12 4 230 Model B Done Display software release at the boot 3 3 95 17 1 233 Model D E E E B Done Ada counters to detect parameter change 7 3 95 18 N 234 Model H Dono Add a Inp pomt ednen screen 7 3 95 30 N 235 Model E Done Bad measurement wru6e reference peak not found 8 3 95 12 N 238 Test B F Done Real trne mterrupt prob 6em 9 3 95 14 N 239 Model B Oone The Du stays m cxamtn error for too long 9 3 95 14 J

~

242 Test F Done Data broadcastmo taAre 13 3 95 16 J 243 Mooel H Done After automatic screen change, go back to default scride.~ .3 3 95 30 i

~

T45 Model G Dona AAow channel associaton for N13 apphcaten 15 3 95 26 6 246 Model E E E F Done Add alarm natch acknowledgment 20 3 95 18 N 247 Test H Done Alarm reportog probeern a bad channel associaten 16~3 95 30 N Eest B Done Problem on safety wntmo protecten 28 3 95 13 N 251 Model E Done Removed spectnsn transfer events 28 3 95 18 4 252 Test H Done The DU has to be reset it no screen has been enabled i 29 3 95 30 N 253 Test F Done Short relay actrvaton when m bypass mode 30 3 95 15 N 255 Model D D E F Done Ottset in analog output channel number 30 3 95 14 N 256 Test H Done Problem on exiernal comrnanas through a LPU 6 4 95 30 1 257 Test F Done Operate rouy is deactivated 11 maintenance and bypass i 5 4 95 15 J 258 Test F Done Operate LED tast batniong 4 4 95 14 J 260 Test F Done Display bad characters at the end of LPU status messages 5 4 95 16 N 263 Test F Done Probeem on Du bypass when real alarms 6 4 95 15 J 266 Test B F Done Probeern ci comrnuncaten error propagaton to 4 95 15 J 267 Model E Done trror on cumulated spectrurn dead time calculaton 10 e wo 15 N 269 Test B F Done Watchdog actnraton d at too long 11 4 95 15 N 271 Design D B D)ne Check frame length before CRC calculaten 11 4 95 20 N 273 Test F Done Possenhty to loose a state broadcasted by the Du 14 4 95 20 N 274 Test D Done Problem W Nter advance on otemal flow meter 13 4 95 15 N 275 Test D E Done Bad flow rate grven to the algonthms 13 4 95 15 J 277 Test D Done Add event on too many successive futer advances 13 4 95 15 1 278 Test F Done Probam on S: ave ROU on SPLR200 monnor 12 4 95 15 J 279 Test D D E Done Reset agonthm status at the ntialitaten 13 4 95 15 N 200 Test E Done Acquisiten threshold bad default value 11 4 95 15 N 281 Test F Done Processor overload ng when SAS without CM board is 11 4 95 36 N booting 282 rest F Done Protsem m 4-20 mA analog outpu display 14 4 95 15 N 283 Tes' F Done No error signaHM3 m stave status d comm crror 14 4 95 16 N 284 Test H Done Relay sett<:hecking unprovement 14 4 95 30 N n,. - - .

% w.m. .

w.-e a m.m

.,-*"."' or.o s- 110834 BA N ,

gisamnuesMGP Ragw Udnitonna System Softwaro Verification and Validation Final Report p 29 s Phase L L L L L L D D States Description D M Y week s P P P P P P U U E U U U U U U l I R I I I I I I B A '

B S P S I l a p a i I A C D s p $

g e P S e 1 N

e 8 l E s

s 285 Test B F Done No emn error W two intenredate OU 14 4 95 19 N 238 Test F Dow The trreshold a stdl vmbie even d out of screen range i 18 4 95 16 N 289 Test O Done Bad mSv corwerson n SVGAM algonthm 18 4 95 16 N 290 Test F Oone The DU does not update as thresholds when a change 18 4 95 16 N~

occurred 291 Modet E Done Alsow SA_ COMB algonthm negatue coetteents 20 4 95 16 e 292 Test E Done the clear event command cleared the spectrum database i 20 4 95 16 N 297 Modet B Oone uane the spectrum transfer feascie for 1E chanreis 24 4 95 17 N 296 Mot,et B Ooru, End of trame timeoJt can be set for one knk 24 4 95 17 N 301 Modet O E E E B F Oone Aernovo events W degraded mode 25 4 95 20 N 302 Model E E E Dane th histoncal ovenoad W 1 e cycle 9 5 95 20 J 303 Modet E E cone Countmo bss on hegh counting rate 16 5 95 20 N 304 Model F Done Pb vntn commands assocated with intamal flags 17 5 95 20 N 306 Model E E E Done output emutaten enab6ed a parameter a 1 17 5 95 20 N 307 Modet F Done Duiptay masks on communcrton screen on 2 degrts 27 3 95 20 1 300 Modet F Done Disotay channe* name wrth 8 characters 18 5 95 20 N 300 test F Done PD on analog rput comrare functon for sequencer 18 5 95 20 J 312 Model G Oone Bad digrtal input reporting (5096I 5118) 2 6 95 26 N 315 Model F F F Done Problem on retease latch command address (2836) 7 6  % 38 N 316 Requer G Oone Anow reiay actrvaten on intomat test status 7 6 95 30 N 317 Test G Oone Problem witn retay self<:heckmg functon 7 6 95 26 N 318 feet si C Done Detete software 10 si program download 3 5 95 31 N 320 Modet F Done Make dead trne avadable on database spectra 12 6 95 36 N 326 Model F Done Problem a ret peak searchmo area too large and Co60 13 6 95 36 N 327 Model G Oone Buzzy actrvaten prob 6em after acknowtedgment 13 6 95 26 N 331 Requr H Oone Removed integrated measurement screen 15 6 95 30 N 332 Model H Oone Disc" ved wweT.snt 0/O. Totskzer e comm) 15 6 95 30 6 334 Model A Done Dor- , - :emperature correcten for the trst 1/2 hour 15 6 95 27 J 335 Model A Done Repe _ " it dunno LPU rubahzaten 22 6 95 27 N 336 Modet A Done Oftss. ag change 22 6 95 27 J

}

f 340 Model A Done Chamber test and HV controt rnprovement 29 6 95 27 1 341 Model F F F Done No acquessuon reset after standby rnode on SAS 3 7 95 39 N 344 Model H Oone Problem on totattzer screen 3 7 95 28 J 345 Modet i Done Allow revidual scale for every cnannet 6 7 95 11 1 346 Modet A Done improved the measurement tittenng by the aQanthm 0 7 95 32 N 348 Design H Oone Update tauft labets 7 7 95 28 N

~

349 Opera. E C Done Comm proelem W two knks are used 10 7 95 31 J 351 Modet H Oone Screen can be trozen for a specsts screen saver 9 6 95 32 J cor'figuraten 352 Requr F F F A H Oone Add Botg urm (CIS629246) 12 7 95 39 1 354 Requer H Oone Add standby trede to ing the relays 27 7 95 32 N t

n. . =, . - .in.

%.e.e-.-w.~..-."""**"*"'"~~ -m = = -.  % 110834 BA

4 C MGP Q Eanunnams Rrdiation Monitoring Systrm Software Verification and Validation Final Report p 30 i e i Phase L L L L L L D D Status Desenption D M Y Week s PPP PPP UU E UUU UUU l f R I

~

I I I l l l 8 A \

8 8 P S i l a p h l

- a l l ACO s p g l s P S e i N e S 1 E s

8 3w Test C Done Unknowm event i there is no apphcaton software 1 8 95 31 N 356 Test C Done Don 1 anow normal mode command W no apphcaten software 1 8 95 31 N 359 Requer F F F Done Algonthm memory anocaton extenson 9 8 95 39 i 360 Reque F F F Done Aner standby mode, reset a!i algontnms 9 8 95 39 6 362 Model F F F Oone Set analog output to 0 W mvahd measurement 11 8 95 37 N 364 Requw F Done SAAODE change + delete cartrego etwrge command 21 8 95 37 N 365 Model F Done Problem when Beta algontnm sonais tad parameters 22 8 95 43 N 366 Requr F B Done Add XRANGE and RELEASE agarmms 4 9 95 48 4 367 Modet F F F Oone Probum found on histoncal dates 30 8 95 38 N 369 Test M Oone Bad buzzer status reportmg dunng rutatuaton 7 8 95 36 N 370 Modet H Done No reset of icht latch 16 8 95 37 N 371 Test H Done Black screen W screen setup change 8 8 95 36 N 372 Test H Done French term to be corrected 10 8 95 36 N 373 Model F F F Done Add negatrve value management m analog output 14 9 95 39 N 374 Raqur F Done Segio accumacn mode for portabte SAS 25 9 95 39 6 376 Desen F F F Done Add otemai test P122reportng on relay 26 9 95 39 N 377 Reque F Oone Posstehty to dsable electncal test d voltage =0 27 9 95 39 N 379 Model A Done Omable chamber test W background current too hgh 18 8 95 45 4 382 Requr i Done Add relay release latch command 24 10 95 11 N 385 Operat i Done Allow the DU to go back automatcally on a default screen 17 10 95 11 1 389 Operat i Done Report a commurucaten error with a slave 17 to 95 11 l 390 Operat X Delayed stop -m stonna m database i an alarm appears 17 10 ,95 1 392 Modet G Done Corrected hardware gain caculaten formula 26 to 95 45 N 395 Modet A Oone Correct a resistor with the temperature 6 11 95 45 l 396Operat G Done Averaging of the channet to key coefts for the database 1 11 95 45 t 397 Operat G Oone 11 ret peak not fourus, use the last vahd one 2 11 95 51 i MB Cperat I Done A DU that reports cruy channet B rutiahzes nsett on channel 9 11 95 11 N A

399 Desgn G Oone Pb on compressen W adterential vatue=0x8000000 10 11 95 45 N 400 Operat G Done Spectrum stonng overlappmg m the database 1 11 95 45 N 401 Operat G Done Smgte mode dgetal oput rwerson for portabee SAS 17 11 95 45 N 402 Reque G Done IODE sigonthm .vy,sment 17 11 95 50 t 410 Operal G Oone Reference peak searctung unprovement 20 11 95 6 4 411 Requr G Oone Aod a new Beta algonthm (BETA 2) 5 12 95 6 1 413 MGPt i Done Pb witn a relay tault at the rutiahzaton 7 12 E' 49 N 414 Reque G Done Add ALPHA agoritnm . .4 95 2 1 416 Requr B Oone Slow down the samphng treguency to meet the MTBF E6 10 95 1 1 417 Requit G Done Non knearrty of tne cnannet to Kev relaten 12 12 95 4 4 418 Operat G Done Problem on Beta algontnm W uCuce and no Inter advance 15 12 95 6 J reset 419 Reque G Done Trapezoidai metnoc can be enabled for every singie window 18 12 95 4 I nr- ,. - . - .m

= - - mm .

e

- .-~.~.

m - - ur -

e.. s - 110834 BA

fyNannennunMGP Radiation Monitoring System Software Verification and Validation Final Report p 31 s Phase I. L L L L LD D Status Desertpbon D M Y week s PPP P P PU U E UUU U U U l l R I I I I I I D A '

0 B S P S 1 1 a p a l l A C O s p s e P S e I w e S I E s

S 420 Requer B Done Extend nb of agital oputs from 8 to 16 2 1 96 6 6 425 Modet G G G Done Possbisty to defne a r egative low range varue 9 1 96 3 1 426 Operat X X X X Delayed Add hysteress on temperatu o control 9 1 96 6 429 Requa B Done Allow analog anput converson mto process vanable 22 1 96 6 1 Associate agital input with alarm levets or tauft '

430 Reque 3 Done 22 1 96 6 6 434 Requr G Done Electreal te manual adlustmern 18 12 95 51 6 438 7est 6 Done Lght may be biuming aner release latch command 4 3 96 11 N 439 Test i Done improve vertcal scale casplay 4 3 96 11 4 442 Requer G H H B B Done Report mantenance mode on relay 22 3 96 13 6 443 Test H Done Dont add the counting from the standby mooe 26 3 96 14 J 446 operat H Done Posstakty to disable electncal test W voltage =0 26 3 96 13 6 450 MGPt X Delayed Smooth ordy the searching area of the cumulated spectrum 10 4 96 6 452 tmpt X Delayed Add standby mode reporting 9 5 96 N l 454 MGPl H Done increased fdter advance fault trnecut 19 6 96 9625 I l 457 MGPt J Done Detay flow taum W slow flow meter 26 6 96 9741 I l 4t8 MGPi J J Done Avoid mvahd measurement fluctuaten on no tcw 26 6 96 9636 6 4$9 MGPL D Done Wntting prob 6em wrth MASS on 1E channets with double 10 5 96 9712 N l access 461 MGPl F H J J C C D J Done Clock stop on pinuary 1,2000 6 8 96 9713 N l l 462 Operat J CLne improve peak search m case of sight peak collapse 8 8 96 9634 I l 463 MGPl J Done improve peak tocation accuracy 9 7 96 9634 4 465 MGPt J Done Be sure that database es automatcally cleared after 20 8 96 9634 i producten 470 Model J Done Allow fdter taun reset on PNGM 12 7 96 9741 i l 412 Model X X X X X Delayed Add a reference peak morutonng parameter 21 10 96 9731 4 l 473 Model F 0 Done Accurex kr* cannot be set to 1200 bauds 22 10 96 9713 1 l 477 Modet C Done Process commands cunng rutiahzaten 20 12 96 9734 I l 479 Model J Done Add GPM unit on flow channel 18 11 96 9712 N l 480 Op;Rm D Done DUs reset W trne synchronisaten ccmrnand on SR DU 14 11 96 9712 J l 481 Operat F 0 Done Added mto for norHrutlah28d 17 and W1tchdog events 22 1 97 9713 4 l 483 Modet X Delayed Comm prob:em wnh speedic 485 board (Palo verde) 10 1 97 N l 484 Test J Dnne Add event m the DU when tno-pont changes 20 2 97 9712 1 l 486 MGPt J Done Du screen changes on low range switchmg 1 7 3 97 9713 1 487 MGPl J Done improve the way status is displaye t on measurement 12 3 97 9713 I s,:reens 489 Op.Rm K Done Change NP threshold for N13 tram 25% to 20% (N16 12 3 97 9731 1 conformrty)

. ., -., -n.-v-.n -.c.,%.

% nu , - e

-- - -w-,

-.  % 110834 BA l

1MGP

\\m Radiation Monttoring System Software Verification and Validation Final Repcrt p 32 s Phase L L L L L L D D Statue Descripton D M Y Weet s P P P P P P U U E U U U U U U l l R 9 I I I I I E A I E S P S 1 1 e p a l l A C O s p 8 g

a P S e i N e S I E s

s 490 Test J Done PD on highest measurement reporting on analog outputs 20 3 97 9712 N 491 MGPl C Done Hoh vonage change possab6e when LPU is runnog 26 3 97 9734 V 492 MGPl X X X X X X Delayed Load params trorn FLASH f RAM toss (dograded mode) 3 4 97 ll 493 MGPt K Done Use fut gam range (0.81.6) tor gem correction 3 4 97 9731 ll 494 MGPs C Done Senal possame saturation dunno enamber test 3 4 97 9734 0 496 OpAn X X Open The watchdog resets the DU wthout known reason 8 4 97 N 499 MGPi K Done uponne PN value in the spectrum 23 4 97 9731'T 500 MGPt K Done Does not report analog input tault 23 4 97 9731 , N

, 503 MGPl K Done Dont amow wmdows en the last channels 19 6 97 9731 t 505 MGPl G Open unk sammmg a saturaten on the 2 links at 57 Kbps 18 9 97 N 507 MGPI X j Open Mari alue of SMOD is va6d only on start up after a change 28 4 97 lI w , - , - .._ -

%e.a ,ei.-,..i--.,%

- .- - -.,o - - m 3 - 110834 BA i

MGP

'amannen Rad

  • tion Monitoring System Software Verification and Validation Final Report p 33
7. Assessment of overall software quality 7.1. Software complexity The software complexity has been taken in consideration since the beginning of the project using the IEC 880 recommendations. The complexity analysis is reported in the chapter 4.3 of the document referenced as 2.6. MGPLRAMSYS LEC 880-112641.

Below is the software top-down approach with the dependency between each module.

Each module is referenced by a programming file number. Each software is referenced by a software number.

RAMSYS common mocues 110$12 l

05

'* '"" "4""""_]

I

'""*' ?"" "

,, o

+ + o + + u + +

DUBase DU' Apoe LPJBase f.PU1C LPW10 LPUPIPS 46700 46689 46684 LPUSASliPU$i 43699 46679 I

_ 110618 __

110403 110496 g e u = - - = -

b " 6 ...""* " J O * = E ""* P O " L % e 110834 BA t

s . - - .

g MGP ngennnen Radiation Monttonna System Software Verification and Validation Final Report p 34 7.2. Assessment by anomaly history analyris The graphs below show the number of anomaly reports that were generated month by month. There are sorted by type for every software:

. Improvement means that it c'.,ncerns a p'oposition to improve the software or to add a function (new needs).

. Non-jamming means that the anomaly does not affect the software operation it can be a specific configuration that does not work as expected.

. Jamming means that the software functionality can be affected by the anomaly.

7.2.1. LPU/ Base software vusnu.

M t t tiIItillIIIIIIIIII1IIIIIIIIIIlllttt'tItIIII I _

l The last jamming anomaly found in July 1995 was about a communication problem.

Since then this software which runs on every LPU works correctly.

Me , h"_7,,,9,,,, 70 L""*" " ~ "**',", =m ., m 110834 BA V\ '

g. \annenersMGP Radiation Monitorina SysOn 8:!;warc Verification and Validation Final Report p 35 7.2.2. LPU/IC software bm  : w ie 4

u ___ --

1 _ . _ _ _ . _ . _ _ . _ . _ . _ . . _ _ . _ _ ___ _. .._ . _ _ _

a u .- . ..---_ _ _ .

tJ t -

1 -

&&-- - - 1 - 1 1 - t - _ 1 - t .

I 1 l IIIlllllItttttsIIIIIIIIistittilittittttttill Except some improvemer.t: that were made to the product lately, no anomaly has been found since July 1995.

4 of the 6 Jamming anomalies are common to all LPUs.

l ML""".".LT 74%70."*"""'"~JOL"*0 m 110834 BA

_________u

3<MGP ennunes Software Verification and Validation Final Report Radiadon Monitonng System p 36 7.2.3. LPU/lO software wum em e

u s -

u - -

i - .

u i , - , I_ , ,

IIIIIll[tiIIIIIIIlllIIIIIIIIIllltiIIIIIII]I i l

No anomaly has been reported for the LPU/lO specific part and onY one from common part. This is because this software was relear J lately and thus did not integrate anomalies from common software components except the year 2000 problem.

The improvements were made to enhance product capabilities.

I L71TJr.L as 7M174.7"" "O %"""'"O. . w 110834 BA

g' nammananMGP R*diation Monitoring System Software Verification and Validation Final Report p 37 7.2.4. LPU/ PIPS software

, LPU,M S s~

~

l .

e .

i e i __ ,. . ._ _

.. B IIIIIllittiI!!!IIllitIII!!!!!illttilltItiill L' 'L' '

The jamming anomaly found in December 1995 concemed the Beta algorithm that provided a wrong measurement in a special configuration (bad pCi/cc unit management). The product appears to be stabilized.

6 of the 10 Jamming anomalies are common to all LPUs.

O C 'l"" J" ~m 7 4 % 7 0 ~ O ~ J O L ~ . - 110834 BA

^ .~

$)MGP anneerrs Software Verification and Validation Final Report Radiabon MoMonna Sysran p 38 7.2.5. LPU/SAS software lC wu.us L ~.

w 1

L._

j .__ .._ _ _ - _ . . . . . _ . _ . _ _ _ _ . _ . _ ._ _ _ . . _ _

t

i. - _ . . __.

I 1 8 14- 8 . -e

% I i t t t t

__ el l n1 2 _

111111111 55 IIIItillit..aIttililiitttitttil l This software has been operational for a significant amount of time, and it appears to be stabilized. The last jamming anomaly found in March 1996 was about the standby mode that affected the counting in the channels.

6 of 11 Jamming anomalies are common to all LPUs, I

f O"6.b~ML7d7,01~iOOL~m .- 110834 BA

g.rl,MGP, nanoner Radiation Monitoring System Software Verification and Validation Final Report p 39 7.2.6. LPU/S1 software i .- truisi i

s _. . , .

t i

. m5

' tiilllllIttttttttilliattltttiliglistillftlll No anomaly has been found since October 1990 except the year 2000 problem.

6 o' the 9 Jamming anomalies are common to ah LPUs.

" T A"".". M = i" M .". 7.fS =*" G "" % E O. % %

% s - 110834 BA

g MGP neannners Fladiation Monitoring System software Verification and Validation Final Report p 40 7.2.7. DU/ Base software DGSase

? _

l-8 gg p- --

=n E= .. .

g IIIttillIIIIII!!EllitIII!!! 11lll111:51 Int lt l The DU/ Base software is stabilized since August 1995. However, an anomaly concerning date/ time synchronization broadcasting on protected DU (network writing disabling function) has been found in November 1996.

I ML'*ll"b~JML70=T"TO"ZO .m 110834 BA e

g.\.MGP, anmne Radiaten Monitoring system Software Vertfication and Validation Final Report p 41 7.2.8. DU/ Application software DwAppel em 3 N

33 -- - --. _ _ _

,8

, El E1El MiB @ ND G E fr h IIII!!llIIIttilItilliIIIIIIIIllittillitttill Various anomaly reports with different degree of severity were generated during the test phases of this prodJct. Since then only minor anomalies were found. The last anomaly dated November 1996 was concerning a display problem with GPM units.

ETA""."MJM%70.*.""O"*'"m""*'O L% - 110834 BA

MG gbanimane,P, R*diation Monitoring Systxm Software Verification and Validation Final Report p 42 7.3. Fault density This picture shows the number of iiiw :? mde for each module and software of the project.

6" uss l I

l i

.o 2o l l l 1

m7 l a2s I i

\pph Common 11022 6798 l 1 see 24ss7 l l l I

l

{ iss24 l l

l

    • " I l l I

sian l l l 1

90118 source code lines for the project 22102 l Totnl une num**s l l l l b" E7 b~==.7ME70 ~ ~"'~1T.~ L"""A . w 110834 BA

gsusannessMGP Radiation Morutonna System Software Vertfication and Validation Final Report p 43 The following table shows the ratio of anomalies versus the number of lines of code for each software. This includes jamming and non jamming anomalies but excludes improvements.

Software name Software number Nb knes of cooo ND anomahes found FauR Oensny (FeuR per rt of bnes)

LPU/Sase 562 9625 14 0.00145 LPU/S1 563 22102 41 0.00186 LPU/P/PS 564 28388 44 0.00155 LPU/SAS 565 31377 55 0.00175

'LPU/lc 568 24667 18 0.00073 LPU/lO 637 19924 1 0.00005 DU/Sase 560 14580 29 0.00199 DU/ App // 561 40220 83 0.00206 7.4. Assessment by operational history The purpose of this chtpter is to provide the operating experier:ce for the LPU and DU softwares at the time of SWFR release.

We remind that LPU is a product line of processing units to be dedicated to different detectors; for example:

. LPullC is attached to gamma radiation measurement using ionization chambers;

. LPU/lO is attached to process measurement using analog and digital input interfaces;

. LFU/ PIPS is attached to padculate or gas monitoring;

. LPU/SAS is attached to spectrometry applications using Nal detectors;

. LPUISI is attached to gamma radiation measurement using silicon detectors.

All the LPU have the same base software.

l Variations are coming from the interface board (to detector) and from the application software.

Both Remote Display Units (RDU) and Local Display Units (LDU) use the same base software and the same application software.

L"C"Mr '"* 74,*=0" " " *"'_" "" " L% ,, _ 110834 BA

gdananarsMGP Radiation Monitorina System Software Verification and Validation Final Report p 44 The following table provides:

. the list of the different sites where the software is operational, e the operating experience which is:

(number of software in operation) x (number of days in operation)

- Site LPU/ Base LPU/IC LPU/lO LPU/ PIPS LPU/SAS LPU/SI DU Base and Appli Ringhals (Sweeden) , 61494 0 0 11895 19525 30074 89682 l Barseback (Sweeden) 8874 2958 0 0 5916 0 2958 l Technicatome (France) 6996 0 2915 1166 0 2915 583 l 3 Loviisa (Finland) 11316 0 0 0 11316 0 0 l Kosloduy (Bulgaria) 4184 0 0 0 4184 0 8368 l Olkiluoto (Finland) 1286 0 0 0 0 1286 1286 l PAKS (Hungaria) 2332 2332 0 0 0 0 2332 l North Anna (USA) 1586 0 0 0 1586 0 1586 l Cnstal RNet (USA) 898 0 0 0 898 0 449 l Curnulated experience 98968 5290 2915 13061 43425 34275 107244 l (nb of days)

In addition to these installed system, MGP instruments in Lamanon and in Atlanta exercised and tested the software extensively using the actual hardware in addition to the typical bench testing. This testing has been conducted from the end of 1994 up to present. Only 6 jamming and non-jamming anomalies have been detected on-site during operationallife:

  1. Phase L L L L L L D D Status Desenption D M Y Week S P P P P P P U U E U U U U U U / / R

/ / / / / / B A [g B S P S I 1 a p a i l A c o e p 5 s P S e i M e S I E S

S 349 Operat E C Done Comm probiern d two lirts are used 10 7 95 31 J 396 Operat i Done A DU that reports only channel B inflaalizes itsett on channel 9 11 95 11 4 A

400 Operat G Done Spectrum stonno overtapping m the catabase 1 11 95 45 N 401 Operat G Oone Scngte mode digrtal enput enverson for portable SAS 17 11 95 45 N 418 Operat G Done Prot *rm cn Beta algonthm W uCucc and no filter advance 15 12 95 6 J reset 480 Operat D Done DU's reset d trne s,i riv. zisten command on SR DU 14 11 96 9712 J 496 Op:Ran X X Open The watchdog resets the DU wunout known reason 8 4 97 N

' Putisceaan, resucian 110834 BA meme partese sont conn venees, sad ease de nos swees u

. = _ _ _- -. . _ . .

3iananannMGP Radiatiort W%ii,9 System Software Verification and Validation Final Report p 45 The following table shows the rate of failure during operationallife for each software. It is based on jamming and non-jamming (to be conservative) anomalies found during on site -

operation.

software Sofhvars operatonal Number of Tsme between todure name numte exponence anomenos ocuri)

(hours) found LPU/ Base 562 2 375 184 1 2 375 184 LPU/Si 563 822 600 0 > 822 600 LPU/ PIPS 564 313 464 1 313 464 LPU/SAS 565 1 042 200 2 521 100 LPU/lC 568 126 960 0 > 126 960 LPU/lO 631 69 960 0 > 69 960 DU/Basc 560 2 573 856 3 857 952 DU/Appil 561 2 573 856 2 1 286 928

  • ~ 7h~ M %70.*.""."."."41~40 h% s- 110834 BA

-~

$LMGPkassauwes Software Verification and Validation Final Report Radiation Monitonna Systern p 46 7.5. Failure analysis The following table is an analysis of possible failure and resolution that applies to RAMSYS softwares. It shows whc.t kino of failure may occur (software or hardware and description), when this failure may occur (on a cyclic or random basis or at a certain time), how the software takes care of the failure (fault alarm, event...) and how the software detects the failure, punkts Type; 7g, 4Com y - When * ; "e Act en f Q , gest description '

b 'gik 'M.*n@N  % /b.w :t

- - - A::$

Aa Hard CPU Bus error Excepton fattware taun . %ta + Reset CPU excepton l

AE Soft CPU Address error Excepton Software faut + Event + Roset CPU excepton l M Soft CPU ruuakzaten taun Except.A Software faut + Event + Reset CPU excepton l A8 Soft Program ladure Cycic Event + Reset Loss of watchdog controi l AA Soft Urrecoverabie program snet Software tauft + i,.asntenance Too many successrve reboots taAre mode M Soft EPRoM Software damage init + Cyclac Software faun + maintenance CRC controt moos

  1. ,5 Soft FLASH Software damage inft + Cyr$c Software fault + marntenance CRC control nude An boft FLASH backup trut + Cycho Software tauft + mamtenance Fue redundancy control mode An Hard RTC clock trut Board Fault + RTC tault event + Write and read back register maintenance mode An Hard Communcaton trners trut Board Fault + Trner tautt event + Wrne and read back regtster maintenance moda 00 Hard Analog output init DAC tault + mantenance mode Check penpheral E5 7Ti,; wiivas access DU Soft Resource aAocaten trut Software fault + Detaded event + Check resource allocaten maintsnance mode (static memory, semaphores, finite state machines)

DU Hard RAM irut + Cycic RAM tautt + mantenance mode Wrtte and read back each memory ced AALPUs Hard RAM trut RAM taut + masntenance mode Wnte ar d read back each memory ce5 M LPUs Hard PtA on CM board Ina Board taut + PtA taun event + Wnte and read back register except maintenance mode LPUllo AA LPUs Hard EEPROM on CM board inst + at eacn Board tault + PIA tauft event + CRC control except access marntenance mode LPUMO LPutto Hard Digrtalinput Board trut Board taun + VIA tault event + wnto and read back m maintenance mode if both OlB penpheral registers (VIA6522) and AIB boards tailed LPU/tO Hard Analog input Board inct Board tauft + PIA tauft ever$t + Wnte and read back m maintenance mode if both DIB peripheral registers (PIAS821) and AIB boards failed LPU/ PIPS Hard CM/PtPS board trut Board tault + PTM tault event + Wnte and read back m maintenance mode peripheral registers l (PTM6840) n- - . = .-r

.. .- - -. n~ ,e ,= m -

110834 BA m . . . .- s I

I

4EIMGP,

%Edenmane Wdiation Monttonna systern software Verification and Validation Final Report p 47 Y

LPU/SAS Hard Spectrum memory ina Board taun , SPT memory fault Crock togester access, then event + maintenance mode wrne and read back the whow memory LPUG H2d CMS tr ard inn Board taun + PTM taun event + Wrne and read back an mairanance mode peripheral regators (PTM6840)

As Soft Cnhcal parameter damage trwt

  • Cycic Software faun + degraded mode Fue redundancy control AXLPUs Hard RAM Cycic RAM taun Wnte and read back each memory ceO As Hard Watchdog Cychc Watchdog faun Sqnal duraton control As Hard Power suppey (+5v, +15V Cycic Power tauft Check voltage values and.15V) (thresholds are parameters)

Aa except Hard Process temperature Cyche Temperaturu tault Check temperature values LPUAo (thresholds are parame'ers)

LPuSC Hard Total acquisacn process inn + cycho + Probe taun Process a tuu chamber test on command LPUAC, Hard Detector Cyche Counu ) or current tauft Check background minrni-n, LPU/ PIPS, and detector maximum actMty LPU/SAS, (current or counts)

LPU/Si LPU/ PIPS, Hard Probe connenen Irvt + Cyche Probe fautt Electronc checkmg LPU/SAS.

LPUISi, LPUAC LPU/ PIPS, Hard Acquenen electronc trut + Cyche + Test tautt Test by sendmg puises to the LPU/SAS on command electronic LPU/S4 Hard Total acquistuon process Irvt + Cycho + Acquisacn taun Opteal test by sendmg hgn to on command the detector LPU/SAS Mard Total acquesnon process Cychc Acquisiten taun Look for a reference peak.

Check counung, pea';

resoluhon (detector), and pic location.

LPU/SAS Hard Probe enft Cyche Acquisacn faun Check reference peak ontt, correct R by using software and electronic correcten.If

  • nore

. is no way to correct it, out the und in fault.

LPU/ PIPS Hard Fiber rrechanam At each foter Fdter lautt Check that the motor is advance running correctly LPUAC Hard Analog power supply (+2, Cycle Acquisiten tauft + Event Check vonage vatues 12, 5 and HV) (thresholds are parameters)

LPUAC Hard Ottset entt Cycte Acquisacn faun + Event Try to correct the ottset and signal a fault if not possible All LPUs Soft Processor loadmg Cyctc Faun Check that 40% of the processing time remair's tme n.--,.-- -

%-.-en%...-..u,.*'"*"'*'.""""...- -,

- - - 110834 BA

)

~- -

" MGP Radiatbn M&a%6s System Software Verification and Validation Final Report p 48 l

M l soft ovvise ty zero lExcepton Software tauet + Event CPU excephon l

Lou IHwd ugene pna + Cyc6c ugen feuit uomune momeni ree.=nce i I when hght le off ou l Herd Suzzer lina + Cycho Buzzertaun Suaaer current meneurement

] I when buzzer on ou IHerd Reisys IC Relay touet Check contact (open and l lyche cioseco ou lHerd Commune; anon lCyche Communesson teutt Chec* eleve response l& Soft l M Hard Rs486 automenc Cyche Event software watchdog wah ame-sweching mecheruem out (correct *5e problem automanceM M IHerd Laos of power liraerrupt Laos of power event Electroruc chociung with CPU l l reemet M l soft h% overtow lExcephon oversow event CPU m M soft & Unpredmied interrupt Excepton Event CPU excephon Hard 7.6. Common mode failure For safety related application, each monitor operates independently from any other monitor.

Given the channel independence, the only identified common feature is the clock (date &

time) which is managed by an independent hardware component (Dallas).

The date & time module stamps events for maintenance and troubleshooting purposes.

It is further used for archiving data and trending, in most cases, data archiving / trending is accomplished by an extemal recorder or data acquisition system.

Therefore, the date/ time feature does not seem to perform designated safety function.

Consequently, there appears to be no common failure affecting designated safety function identified among independent monitors.

L,.e'." """?P':".".:llll7.7;I,.::.'.""J*" "T.::::lll:.~, . 110834 BA

g MGP Radiasion Monaciirc System Software Verification and Validation Final Report p 49 7.7. Assessment of overall software quality The softwaro as outlined in the governing documents: SOAP, SWP, STF, STR, SDD rnd SRS have met all of the requirements as specified iri these documents.

Software complexity and design goals have been met according to IEEE and IEC standards.

The general trend as evidence by the anomaly history charts demonstrates a clear downward trend.

The number of operating devices grows every year, if the reported anomalies are normalized relative to the operating devices vs time we find 7 operational anomalies total for more than 400 000 days of operation (1 anomaly every 1400 000 hours0 days <br />0 hours <br />0 weeks <br />0 months <br />).

There is no clest basis for comparing the fault densities vs time to other similar software packages. Therefore, objective quantitative classification of the RAMSYS quality is not feasible.

Nevertheless, it is the position of MGPl (based upon its software development '

cumulative experience) that the RAMSYS software is of high quality suitable for safety related application, i

CA ,hM*lL"*7,70,*l"4"""'*'"O"*' L % . ,,, m l110834 BA m -

M MGP ybanmanen Radiabon Monttonna System Software Verification and Validation Final Report p 50

8. Conclusion & Recommendations 8.1. Results Summary The verification (code review) identified the testing of parameters, functions, and/or the features which were included in the test procedures. All modifications to the software have been clearly identified and validated.

The validation of the software was completed according to the requirements of the respective test files. All discrepancies were identified, corrected, and re-validated. There are no known pending discrepancies awaiting resolution.

There is extensive accrued international operating experience in using the referenced -

software packages in various nuclear power plants. In adoltion, channels were extensively tested by MGP instruments Lamanon and Atlanta prior to delivery.

The trend of the reported anomalies has been continuously decreasing compared to the level observed during the commencement of the testing. This fact along with a significant increase in the operating experience provides the required confidence level.

Based upon the completion of the verification activity, the results of the validation activities, and the accumulated operating experience, there is reasonable assurance that the software packages listed hereunder will perform their design function when properly installed and operated, and therefore, are suitable for use in safety related app!! cations.

566 C LPU/IC l

631 C LPUllO l

564 J LPU/ PIPS l l 565 K LPU/SAS l l 563 H LPU/Si l l 560 D LDU, RDU l l 561 J LDU, RDU l l MGP Instruments, SA is committed to maintain software quality. The software life cycle is ever evoMng. Future releases / revisions will accommodate modifications and/or corrections as require j and/or originated by the operating experience of the users, and by continuing improving & testing the P.AMSYS.

L*"*'h ,, f P.**'",,,,",,*, '

T4,T,,,," "*"J*"=h, m 110834 BA l

)

g MGP ~ ~ ~ ~

Software Vertfication and Validation Final Report p 51 l 8.2. Recommendations The recommendation listed below apply in part to future revisions of the existing software packages and in part to the future VW processes associated with new software packages.

a) Limit the number of variables / parameters / features to the absolutely required ones even at the account of the software flexibility. The higher number of variables, the higher the complexity of the software and the higher the probability of undetected deficiency. Consequently, the V&V may be oorwhelming, the burden of proof may exceed available resourcos and schedule constrains, and the confidence in the J software reliability may be challenged.  ;

b) Adhere to ANSI /IEEE guidelines as far as software V&V documentation and execution, in some cases two similar documents in the same category (SRS, SDD, etc...) which were written by two different individuals did not have the same format and/or level of details. i c) Actively pursue feedback from users a; to the performance of the software and adoquacy of the documentation. Mo:Ny / correct Imperfect performance as applicable.

' d) Additional software test and evaluation tools should be considered for testing the effectiveness of the software under development.

e) Incorporate to the maximum degree poss!ble standard software sub-modules /

routines, f) Software is e good as the user can exe::v.4 it. Software user manual /

document:U;. require further improvements. In particular, all entries in the parameter tables require explicit definition and clarification.

g) 3ased upon the number of detected / reported anomalies found during the testing phass, it is recommended that additional 'esources will be allocated during the design phase of the software life cycle to minim'.ze the number of anomalies.

d M,J,",-ll",,;.",,,,,,, ,,,,,M ",,= ,",,"A'*"""' _, '*" :;;;lO;;,3 ,, ,,,, - 110834 3A

--.- ---,. - - - . . , - , , - - . . - --.-- , - . _ . ,