Viewingfire-suppression
version main
·commit dfe72915New versionCompare

STPA completeness

branch main · commit dfe72915

The analysis is AUTHORED; the check is COMPUTED. Modelwrite does not perform STPA, does not infer hazards from a design, and will never claim to. It holds your control structure and analysis as a versioned model, checks completeness and internal consistency, names everything missing, and reports each finding's basis.

The control structure

1 controller · 1 controlled process · 1 control action · 0 feedback signals · 1 hazard · 1 constraint · 2 UCAs · 1 loss scenario

computed over 10 graph nodes and 6 graph edges; the platform holds the authored analysis and checks its completeness - it does not perform STPA

5 findings found.

Unanalysed control actions (1)

Every ControlAction must carry an UnsafeControlAction for each of the four types: not-provided, provided, wrong-timing-or-order, stopped-too-soon-or-applied-too-long.

  • ca-discharge — Discharge suppressant · missing wrong-timing-or-order, stopped-too-soon-or-applied-too-long · carried not-provided, provided

    computed over the UCA nodes that reference ca-discharge; the model carries 2 of the four UCA types (not-provided, provided) and does not carry (wrong-timing-or-order, stopped-too-soon-or-applied-too-long)

Control loops with no feedback (1)

A Controller with a ControlAction and no Feedback path is the classic STPA defect - structurally the same shape as the orphan/isolation the health view reports.

  • controller — Fire Suppression Controller issues ca-discharge but receives no feedback

    computed over the triggers edges of the control structure; controller issues control action(s) ca-discharge but no Feedback signal reports back to it

Hazards with no constraint (1) · constraints reaching no element (1)

Every hazard the analysis names must be mitigated by a constraint; every constraint must reach the design - otherwise it is an aspiration.

  • haz-1 — Uncontrolled fire in protected compartment

    computed over dependency edges labelled Mitigate; haz-1 has no Mitigate edge to a SystemConstraint

  • sc-1 — Suppressant must reach every protected compartment

    computed over the platform's requirement coverage (Satisfy/Refine/Verify/Allocate); sc-1 is a SystemConstraint no design element satisfies

UCAs with no loss scenario (1)

A claim that a UCA could happen, without a causal scenario, is an assertion — a UCA must be explained by a LossScenario.

  • uca-p — Discharge provided when no fire

    computed over reference edges from LossScenario nodes; uca-p is a UCA not referenced by any LossScenario

Trend across baselines (1)

The same counts across the commits of the branch, oldest first. Computed directly over each commit's model - there is no cached trend path to reuse.

commitunanalysedno feedbackhazardsconstraintsUCAstotal
dfe72915 seed platform scenario111115

See the control-structure view · See model health