Current status of the project
Meta Model#
The meta model defines middleware-independent metadata for the definition and generation of standardized function APIs. Catalogue/interface metadata, for example metadata originating from COVESA VSS or an extended catalogue, is separated from function-specific configuration and runtime state where applicable.
The current core interface types are Data, Parameter, Scheduling, and a candidate Error interface. The model also defines common enumerations, runtime companion information for data quality, execution-result semantics, and cross-cutting modelling rules.
For Data and Parameter interfaces, name is the unique interface identifier.
The value follows the canonical hierarchical naming convention and therefore a
separate path property is not used.
Enum Type Description#
The meta model defines common enum types used by interface properties and runtime information.
Enum |
Values |
Purpose |
|---|---|---|
ASIL |
|
Safety classification used where an interface or runnable is safety-relevant. |
DataQuality |
|
Runtime qualifier values. |
Direction |
|
Function-relative direction of a Data interface. |
RunType |
|
Activation type of a runnable. |
ProtectionType |
|
Abstract protection requirement. Concrete middleware protection details are platform/deployment-specific. |
FunctionResult |
|
Generic execution result only. It does not encode function-specific diagnostic causes. |
ErrorSeverity |
|
Functional impact/severity associated with a function-specific Error interface. |
SupervisionType |
|
Types of runnable execution supervision represented by the meta model. |
FunctionResult#
FunctionResult represents the generic outcome of an execution. It shall be
limited to success, failure, or notAvailable and shall not replace
function-specific diagnostic/error interfaces.
An adapter may report a failure it can observe, for example an invocation,
transport, or timeout failure. It shall not synthesize detailed
function-internal diagnostic causes or use FunctionResult as fault-logging
information.
Data Type Description#
Standard Naming Convention: Vehicle.<Domain/Subdomains>.<Signal>
name contains the complete canonical interface identifier, for example
Vehicle.Speed. A separate path property is not used.
Property / Attribute |
Req. |
Datatype |
Description |
Example / Notes |
|---|---|---|---|---|
name |
Yes |
string |
Unique interface or node name based on the canonical VSS path of the Data interface. |
|
dataType |
Yes |
string |
Type of value transported by the interface. |
|
description |
Yes |
string |
Functional meaning of the Data interface. |
Vehicle longitudinal speed |
unit |
Yes |
string |
Engineering unit of the Data interface. |
|
min |
Yes |
number |
Engineering minimum representable value. |
|
max |
Yes |
number |
Engineering maximum representable value. |
|
defaultValue |
Yes |
any |
Default or initialization value, where defined. |
|
resolution |
Yes |
number |
Smallest measurable quantization value, for example for scaling. |
|
precision |
Yes |
number |
Required numeric precision or number of meaningful digits. |
|
FuSa |
Yes |
boolean |
Indicates whether the Data interface is safety-relevant. |
|
ASIL |
No |
enum: ASIL |
Safety classification associated with the Data interface when it is safety-relevant. |
|
minUpdatePeriodMs |
Yes |
uint16 |
Minimum interval between Data updates in milliseconds. |
|
accuracy |
Yes |
string |
Expected measurement or estimation accuracy. |
|
direction |
Yes |
enum: Direction |
Input/output relationship relative to the function using the interface. It shall not be inferred from the VSS sensor/actuator type. |
|
protection |
Yes |
enum: ProtectionType |
Protection requirement for transfer of the Data between the function and its adapter/platform. Detailed realization is binding-specific. |
|
Runtime Data Quality#
qualityCode is runtime companion information and is intentionally separated
from the static Data metadata.
Property |
Datatype |
Generation |
Description |
|---|---|---|---|
qualityCode |
enum: DataQuality |
Separate runtime information |
Runtime quality/validity information accompanying the Data value. Recommended naming is |
A static function specification shall therefore not contain a constant such as
qualityCode: valid as if it were immutable interface metadata.
Parameter Type Description#
Standard Naming Convention: Vehicle.<Domain/Subdomains>.<Parameter>
name contains the complete canonical parameter identifier. A separate
path property is not used.
Property / Attribute |
Req. |
Datatype |
Description |
Example / Notes |
|---|---|---|---|---|
name |
Yes |
string |
Unique parameter name based on the canonical VSS path of the Parameter interface. |
|
dataType |
Yes |
string |
Datatype of the parameter value. |
|
defaultValue |
Yes |
any |
Default parameter value. |
|
description |
Yes |
string |
Meaning and intended usage of the parameter. |
Gain for a calibration map |
unit |
Yes |
string |
Engineering unit where applicable. |
|
tunable |
Yes |
boolean |
Indicates whether the parameter may be tuned/configured after definition. |
|
min |
Yes |
number |
Minimum permitted parameter value, if defined/applicable. |
|
max |
Yes |
number |
Maximum permitted parameter value, if defined/applicable. |
|
dimensions |
No |
array shape |
Shape of an array/map parameter. Omitted for scalars. |
|
Scheduling Type Description#
Standard Naming Convention: <FunctionName>.Init,
<FunctionName>.Step, <FunctionName>.Terminate
Scheduling defines the lifecycle, activation, timing, and execution-supervision contract of a runnable.
Property / Attribute |
Req. |
Datatype |
Description |
Example / Notes |
|---|---|---|---|---|
functionName |
Yes |
string |
Runnable or callable function name. |
|
runType |
Yes |
enum: RunType |
Activation type of the runnable. |
|
description |
Yes |
string |
Purpose and execution intent of the runnable. |
Main cyclic calculation |
cycleTimeMs |
Conditional |
number |
Periodicity of cyclic execution in milliseconds. |
Required when |
implementedASIL |
Yes |
enum: ASIL |
ASIL level for which this runnable/execution is implemented. |
|
previousRunnableRef |
No |
string |
Runnable that must precede this runnable when an ordering constraint exists. |
|
schedulingPolicy |
No |
string |
Scheduling mechanism or constraint. |
|
supervision |
Yes |
object |
Defines whether execution supervision is required and which supervision types/configuration apply. |
|
stackSizeBytes |
No |
uint32 |
Required stack size when relevant for deployment/integration. |
Platform/deployment-specific |
executionResult |
Yes |
enum: FunctionResult |
Generic result returned/reported for function execution. |
|
Execution Supervision#
The supervision object indicates whether runtime execution monitoring is required. If supervision is required, one or more monitoring types are selected and the corresponding configuration is supplied.
Property |
Req. |
Datatype |
Description |
|---|---|---|---|
supervision.required |
Yes |
boolean |
Indicates whether execution supervision is required for the runnable. |
supervision.type |
Conditional |
enum[] |
Required when |
supervision.alive |
Conditional |
object |
Required when |
supervision.deadline |
Conditional |
object |
Required when |
supervision.logical |
Conditional |
object |
Required when |
Alive Supervision#
Property |
Req. |
Datatype |
Description |
|---|---|---|---|
minIndications |
No |
uint32 |
Minimum allowed number of alive indications in the reference cycle. |
maxIndications |
No |
uint32 |
Maximum allowed number of alive indications in the reference cycle. |
referenceCycleMs |
No |
number |
Reference cycle used to evaluate alive indications. |
Deadline Supervision#
Property |
Req. |
Datatype |
Description |
|---|---|---|---|
minExecutionTimeMs |
No |
number |
Optional minimum execution-time boundary. |
maxExecutionTimeMs |
Yes |
number |
Maximum allowed execution time for deadline supervision. |
Logical Supervision#
Property |
Req. |
Datatype |
Description |
|---|---|---|---|
predecessorRefs |
No |
string[] |
References to runnables expected before the supervised runnable. |
successorRefs |
No |
string[] |
References to runnables expected after the supervised runnable. |
Note
The top-level SupervisionType enum additionally contains none and
combined. The current supervision.type property in the YAML directly
lists alive, deadline, and logical.
Error Type Description#
The Error interface is currently marked as candidate. It represents
function-specific diagnostic/error information and is separated from the
generic FunctionResult. It shall not be confused with ECU-specific DTC or
event-memory configuration.
Standard Naming Convention:
<FunctionName>.<ErrorName>.ErrorStatus
Property / Attribute |
Req. |
Datatype |
Description |
Example / Notes |
|---|---|---|---|---|
name |
Yes |
string |
Function-specific Error interface name. |
|
dataType |
Yes |
string |
Datatype of the exposed Error interface. |
|
description |
Yes |
string |
Meaning of the Error and its trigger scenario. |
Range error due to implausible input |
severity |
Yes |
enum: ErrorSeverity |
Functional impact/severity associated with the Error. |
|
maturationTimeMs |
Yes |
number (ms) |
Time the Error condition must persist before it is asserted/logged by the underlying middleware. |
|
resetTimeMs |
Recommended |
number |
De-maturation/reset time before clearing the Error. |
|
resetCondition |
Recommended |
string |
Condition that clears the Error. |
Input valid for a defined duration |
dependencyRefs |
No |
string[] |
Related upstream Error interfaces that may propagate/trigger this Error. |
|
fallbackBehavior |
No |
string |
Function-level fallback/degradation behavior associated with the Error. |
|
raisesSafetyReactionRefs |
No |
string[] |
References to safety reactions associated with this Error. |
|
Modeling Rules#
The following cross-cutting rules apply to the meta model.
Rule |
Definition |
|---|---|
MR-001 |
VSS sensor/actuator type and function input/output direction are different concepts. Direction shall be assigned per function-interface usage. |
MR-002 |
Runtime quality shall not be populated as a static constant in a function specification. Quality information shall be transported/represented at runtime. |
MR-003 |
Generic |
MR-004 |
Protection indicates a requirement at function-configuration level; concrete middleware-specific protection realization belongs to platform/deployment binding. |
MR-005 |
Unknown metadata shall remain |
Meta Model File#
Version 0.4
1# *******************************************************************************
2# Copyright (c) 2026 ZF Friedrichshafen AG
3#
4# See the NOTICE file(s) distributed with this work for additional
5# information regarding copyright ownership.
6#
7# This program and the accompanying materials are made available under the
8# terms of the Apache License Version 2.0 which is available at
9# https://www.apache.org/licenses/LICENSE-2.0
10#
11# SPDX-License-Identifier: Apache-2.0
12#
13# Contributors:
14# Saran Gundlapalli - Error handling added
15# *******************************************************************************
16
17metamodel:
18 name: Eclipse-autoapiframework-Metamodel
19 version: 0.4.0
20 scope: Middleware-independent metadata for definition and generation of standardized function APIs. Catalogue/interface metadata (fro e.g., from VSS) is separated from function-specific configuration and runtime state where applicable.
21 intent: Core interface types and essential metadata are required for standardized API definition and generation.
22
23 enums:
24
25 ASIL:
26 - QM
27 - A
28 - B
29 - C
30 - D
31
32 DataQuality:
33 description: Runtime qualifier values. DataQuality is defined by the metamodel and the attribute qualityCode is not static metadata of a data interface instance.
34 values:
35 - uninitialized
36 - invalid
37 - valid
38
39
40 Direction:
41 - input
42 - output
43
44 RunType:
45 - init
46 - cyclic
47 - event
48 - terminate
49
50 ProtectionType:
51 description: Abstract protection requirement. Concrete middleware protection profile and binding details may be defined during platform/deployment configuration.
52 values:
53 - none
54 - complement
55 - other
56
57 FunctionResult:
58 description: Generic execution result only. It shall not encode function-specific diagnostic causes. Detailed errors are exposed through "Error interfaces".
59 values:
60 - success
61 - failure
62 - notAvailable
63
64 ErrorSeverity:
65 - information
66 - warning
67 - degraded
68 - shutdown
69
70 SupervisionType:
71 - none
72 - alive
73 - deadline
74 - logical
75 - combined
76
77 interfaceTypes:
78
79 Data:
80 description: Runtime data interfaces exchanged between applications or systems. Semantic properties may originate from VSS or an extended catalogue. Direction and protection are resolved for the function usage/configuration and are not intrinsic properties of the canonical VSS node.
81
82 properties:
83 name:
84 mandatory: true
85 datatype: string
86 description: Unique interface or node name. Based on canonical VSS path of the data interface - Vehicle.<Domain/Subdomains>.<Signal>
87 example: Vehicle.Speed
88
89 dataType:
90 mandatory: true
91 datatype: string
92 description: Type of value transported by the interface.
93 examples:
94 - float
95 - uint8
96 - uint16
97 - boolean
98
99 description:
100 mandatory: true
101 datatype: string
102 description: Functional meaning of the data interface.
103
104 unit:
105 mandatory: true
106 datatype: string
107 description: Engineering unit of the data interface.
108 example: km/h
109
110 min:
111 mandatory: true
112 datatype: number
113 description: Engineering minimum representable value. Null if not yet defined or not applicable.
114
115 max:
116 mandatory: true
117 datatype: number
118 description: Engineering maximum representable value. Null if not yet defined or not applicable.
119
120 defaultValue:
121 mandatory: true
122 datatype: any
123 description: Default or initialization value, where defined. Null if not yet defined or not applicable.
124
125 resolution:
126 mandatory: true
127 datatype: number
128 description: Smallest measurable quantization value - meant for scaling etc.
129
130 precision:
131 mandatory: true
132 datatype: number
133 description: Required numeric precision/number of meaningful digits.
134
135 FuSa:
136 mandatory: true
137 datatype: boolean
138 description: Indicates if the data interface is safety relevant or not.
139
140 ASIL:
141 mandatory: false
142 datatype: enum
143 enumRef: ASIL
144 description: Safety classification associated with the data interface when it is safety-relevant.
145
146 minUpdatePeriodMs:
147 mandatory: true
148 datatype: uint16
149 description: Minimum interval between data updates in milliseconds.
150
151 accuracy:
152 mandatory: true
153 datatype: string
154 description: Expected measurement or estimation accuracy.
155 example: ±0.2 km/h
156
157 direction:
158 mandatory: true
159 datatype: enum
160 enumRef: Direction
161 description: Input/output relationship relative to the function using the interface. This shall not be inferred from the VSS sensor/actuator type.
162 example: input
163
164 protection:
165 mandatory: true
166 datatype: enum
167 enumRef: ProtectionType
168 description: Protection requirement for transfer of the data between the function and its adapter/platform. Detailed realization is binding-specific.
169 example: complement
170
171 runtimeCompanion:
172 qualityCode:
173 generatedAsSeparateRuntimeInformation: true
174 recommendedNaming: "<DataPath>.Qualifier"
175 datatype: enum
176 enumRef: DataQuality
177 description: Runtime quality/validity information accompanying the value. It is not a static metadata value such as min,max etc.
178 example: Vehicle.Speed.Qualifier
179
180 Parameter:
181 description: Calibration and configuration interface.
182
183 properties:
184 name:
185 mandatory: true
186 datatype: string
187 description: Unique parameter name. Based on canonical VSS path of the parameter - Vehicle.<Domain/Subdomains>.<Parameter>
188 example: Vehicle.Brake.Gain
189
190 dataType:
191 mandatory: true
192 datatype: string
193 description: Datatype of the parameter value.
194 examples:
195 - float
196 - float[]
197 - uint8
198 - boolean
199
200 defaultValue:
201 mandatory: true
202 datatype: any
203 description: Default parameter value.
204
205 description:
206 mandatory: true
207 datatype: string
208 description: Meaning and intended usage of the parameter.
209
210 unit:
211 mandatory: true
212 datatype: string
213 description: Engineering unit where applicable.
214
215 tunable:
216 mandatory: true
217 datatype: boolean
218 description: Indicates whether the parameter may be tuned/configured after definition.
219
220 min:
221 mandatory: true
222 datatype: number
223 description: Minimum permitted parameter value, if defined/applicable.
224
225 max:
226 mandatory: true
227 datatype: number
228 description: Maximum permitted parameter value, if defined/applicable.
229
230 dimensions:
231 mandatory: false
232 datatype: any with array indicated via []
233 description: Shape of an array/map parameter. Omitted for scalars; e.g. [10] for a one-dimensional breakpoint vector and [7, 10] for a 7x10 map.
234 example: Vehicle.Brake.GainMap[10]
235
236 Scheduling:
237 description: Lifecycle, activation, timing and execution-supervision contract of a runnable.
238
239 properties:
240 functionName:
241 mandatory: true
242 datatype: string
243 description: Runnable or callable function name.
244 namingConvention:
245 - "<FunctionName>.Init"
246 - "<FunctionName>.Step"
247 - "<FunctionName>.Terminate"
248
249 runType:
250 mandatory: true
251 datatype: enum
252 enumRef: RunType
253 description: Activation type of the runnable.
254
255 description:
256 mandatory: true
257 datatype: string
258 description: Purpose and execution intent of the runnable.
259
260 cycleTimeMs:
261 mandatory: conditional
262 condition: "runType == cyclic"
263 datatype: number
264 description: Periodicity of cyclic execution in milliseconds.
265
266 implementedASIL:
267 mandatory: true
268 datatype: enum
269 enumRef: ASIL
270 description: ASIL level for which this runnable/execution is implemented.
271
272 previousRunnableRef:
273 mandatory: false
274 datatype: string
275 description: Runnable that must precede this runnable when an ordering constraint exists.
276
277 schedulingPolicy:
278 mandatory: false
279 datatype: string
280 description: Scheduling mechanism or constraint, e.g. preemptive/non-preemptive.
281
282 supervision:
283 mandatory: true
284 datatype: object
285
286 properties:
287
288 required:
289 mandatory: true
290 datatype: boolean
291
292 type:
293 mandatory: conditional
294 condition: required == true
295 datatype: enum[]
296 values:
297 - alive
298 - deadline
299 - logical
300
301 alive:
302 mandatory: conditional
303 condition: type contains alive
304 datatype: object
305 properties:
306 minIndications: {datatype: uint32, mandatory: false}
307 maxIndications: {datatype: uint32, mandatory: false}
308 referenceCycleMs: {datatype: number, mandatory: false}
309
310 deadline:
311 mandatory: conditional
312 condition: type contains deadline
313 datatype: object
314 properties:
315 minExecutionTimeMs: {datatype: number, mandatory: false}
316 maxExecutionTimeMs: {datatype: number, mandatory: true}
317
318 logical:
319 mandatory: conditional
320 condition: type contains logical
321 datatype: object
322 properties:
323 predecessorRefs: {datatype: "string[]", mandatory: false}
324 successorRefs: {datatype: "string[]", mandatory: false}
325
326 stackSizeBytes:
327 mandatory: false
328 datatype: uint32
329 description: Required stack size when relevant for deployment/integration.
330
331 executionResult:
332 mandatory: true
333 datatype: enum
334 enumRef: FunctionResult
335 description: Generic result returned/reported for function execution. The adapter may report a failure indication it can observe (e.g. due to invocation/transport/timeout). It shall not synthesize detailed function-internal diagnostic causes nor reports any errors for fault logging.
336
337 Error:
338 status: candidate
339 description: Function-specific diagnostic/error interface, separated from the generic FunctionResult. This model is a candidate for later standardization and shall not be confused with ECU-specific DTC/event-memory configuration.
340
341 properties:
342 name:
343 mandatory: true
344 datatype: string
345 description: Function-specific error interface name. Standard canonical form - <FunctionName>.<ErrorName>.ErrorStatus
346 example: WheelSpeedCalc.RangeError.ErrorStatus
347
348 dataType:
349 mandatory: true
350 datatype: string
351 description: Datatype of the exposed error interface.
352 examples:
353 - boolean
354 - enum
355
356 description:
357 mandatory: true
358 datatype: string
359 description: Meaning of the error and its trigger scenario.
360
361 severity:
362 mandatory: true
363 datatype: enum
364 enumRef: ErrorSeverity
365 description: Functional impact/severity associated with the error.
366
367 maturationTimeMs:
368 mandatory: true
369 datatype: number in milliseconds
370 description: Time the error condition must persist before the error is asserted/logged by the underlying middleware.
371
372 resetTimeMs:
373 mandatory: false
374 recommendation: recommended
375 datatype: number
376 description: De-maturation/reset time before clearing the error.
377
378 resetCondition:
379 mandatory: false
380 recommendation: recommended
381 datatype: string
382 description: Condition that clears the error.
383
384 dependencyRefs:
385 mandatory: false
386 datatype: "string[]"
387 description: Related upstream error interfaces that may propagate/trigger this error.
388
389 fallbackBehavior:
390 mandatory: false
391 datatype: string
392 description: Function-level fallback/degradation behavior associated with the error.
393
394 raisesSafetyReactionRefs:
395 mandatory: false
396 datatype: "string[]"
397 description: References to safety reactions associated with this error - <SafetyCondition>.SafetyConditionStatus.
398
399 modelingRules:
400 - id: MR-001
401 rule: >-
402 VSS sensor/actuator type and function input/output direction are different
403 concepts. Direction shall be assigned per function-interface usage.
404
405 - id: MR-002
406 rule: >-
407 Runtime quality shall not be populated as a static constant in a function
408 specification. Quality information shall be transported/represented at runtime.
409
410 - id: MR-003
411 rule: >-
412 Generic FunctionResult shall be limited to execution outcome and shall not
413 replace function-specific diagnostic/error interfaces.
414
415 - id: MR-004
416 rule: >-
417 Protection indicates a requirement at function configuration level; concrete
418 middleware specific protection realization belongs to platform/deployment binding.
419
420 - id: MR-005
421 rule: >-
422 Unknown metadata shall remain null according to the consuming schema/tool
423 and shall not be replaced with invented plausible values.
History#
Version |
Author |
Description of Changes |
Impact |
|---|---|---|---|
0.2.0 |
Gundlapalli Saran |
First release of Meta Model specification. |
Baseline |
0.3.0 |
Thomas Pfleiderer |
Signal protection attribute, FunctionResult enum, and typo corrections. |
Functional enhancement |
0.4.0 |
Gundlapalli Saran |
Updated Data and Parameter metadata; separated runtime quality information; moved function-relative direction/protection to Data; added FuSa handling, execution supervision, generic execution-result semantics, candidate Error interface, and modelling rules. |
Architectural and functional enhancement |
Examples#
Example function specifications based on this meta model: