Current status of the project

time line of the project

Meta Model#

The meta model defines middleware-independent metadata for the definition and generation of standardized function APIs. Catalogue/interface metadata, for example metadata originating from COVESA VSS or an extended catalogue, is separated from function-specific configuration and runtime state where applicable.

The current core interface types are Data, Parameter, Scheduling, and a candidate Error interface. The model also defines common enumerations, runtime companion information for data quality, execution-result semantics, and cross-cutting modelling rules.

For Data and Parameter interfaces, name is the unique interface identifier. The value follows the canonical hierarchical naming convention and therefore a separate path property is not used.

Enum Type Description#

The meta model defines common enum types used by interface properties and runtime information.

Table 1 Meta Model Enum Types#

Enum

Values

Purpose

ASIL

QM, A, B, C, D

Safety classification used where an interface or runnable is safety-relevant.

DataQuality

uninitialized, invalid, valid

Runtime qualifier values. qualityCode is runtime information and is not a static Data property value.

Direction

input, output

Function-relative direction of a Data interface.

RunType

init, cyclic, event, terminate

Activation type of a runnable.

ProtectionType

none, complement, other

Abstract protection requirement. Concrete middleware protection details are platform/deployment-specific.

FunctionResult

success, failure, notAvailable

Generic execution result only. It does not encode function-specific diagnostic causes.

ErrorSeverity

information, warning, degraded, shutdown

Functional impact/severity associated with a function-specific Error interface.

SupervisionType

none, alive, deadline, logical, combined

Types of runnable execution supervision represented by the meta model.

FunctionResult#

FunctionResult represents the generic outcome of an execution. It shall be limited to success, failure, or notAvailable and shall not replace function-specific diagnostic/error interfaces.

An adapter may report a failure it can observe, for example an invocation, transport, or timeout failure. It shall not synthesize detailed function-internal diagnostic causes or use FunctionResult as fault-logging information.

Data Type Description#

Standard Naming Convention: Vehicle.<Domain/Subdomains>.<Signal>

name contains the complete canonical interface identifier, for example Vehicle.Speed. A separate path property is not used.

Table 2 Meta Model Data Type#

Property / Attribute

Req.

Datatype

Description

Example / Notes

name

Yes

string

Unique interface or node name based on the canonical VSS path of the Data interface.

Vehicle.Speed

dataType

Yes

string

Type of value transported by the interface.

float, uint8, uint16, boolean

description

Yes

string

Functional meaning of the Data interface.

Vehicle longitudinal speed

unit

Yes

string

Engineering unit of the Data interface.

km/h

min

Yes

number

Engineering minimum representable value. null if not yet defined or not applicable.

0

max

Yes

number

Engineering maximum representable value. null if not yet defined or not applicable.

300

defaultValue

Yes

any

Default or initialization value, where defined. null if not yet defined or not applicable.

0

resolution

Yes

number

Smallest measurable quantization value, for example for scaling.

0.1

precision

Yes

number

Required numeric precision or number of meaningful digits.

0.01

FuSa

Yes

boolean

Indicates whether the Data interface is safety-relevant.

true / false

ASIL

No

enum: ASIL

Safety classification associated with the Data interface when it is safety-relevant.

QM / A / B / C / D

minUpdatePeriodMs

Yes

uint16

Minimum interval between Data updates in milliseconds.

10

accuracy

Yes

string

Expected measurement or estimation accuracy.

±0.2 km/h

direction

Yes

enum: Direction

Input/output relationship relative to the function using the interface. It shall not be inferred from the VSS sensor/actuator type.

input / output

protection

Yes

enum: ProtectionType

Protection requirement for transfer of the Data between the function and its adapter/platform. Detailed realization is binding-specific.

none / complement / other

Runtime Data Quality#

qualityCode is runtime companion information and is intentionally separated from the static Data metadata.

Table 3 Data Runtime Companion#

Property

Datatype

Generation

Description

qualityCode

enum: DataQuality

Separate runtime information

Runtime quality/validity information accompanying the Data value. Recommended naming is <DataPath>.Qualifier, for example Vehicle.Speed.Qualifier.

A static function specification shall therefore not contain a constant such as qualityCode: valid as if it were immutable interface metadata.

Parameter Type Description#

Standard Naming Convention: Vehicle.<Domain/Subdomains>.<Parameter>

name contains the complete canonical parameter identifier. A separate path property is not used.

Table 4 Meta Model Parameter Type#

Property / Attribute

Req.

Datatype

Description

Example / Notes

name

Yes

string

Unique parameter name based on the canonical VSS path of the Parameter interface.

Vehicle.Brake.Gain

dataType

Yes

string

Datatype of the parameter value.

float, float[], uint8, boolean

defaultValue

Yes

any

Default parameter value.

1.0

description

Yes

string

Meaning and intended usage of the parameter.

Gain for a calibration map

unit

Yes

string

Engineering unit where applicable.

bar

tunable

Yes

boolean

Indicates whether the parameter may be tuned/configured after definition.

true / false

min

Yes

number

Minimum permitted parameter value, if defined/applicable.

null where not defined/applicable

max

Yes

number

Maximum permitted parameter value, if defined/applicable.

null where not defined/applicable

dimensions

No

array shape

Shape of an array/map parameter. Omitted for scalars.

[10] for a vector, [7, 10] for a 7x10 map

Scheduling Type Description#

Standard Naming Convention: <FunctionName>.Init, <FunctionName>.Step, <FunctionName>.Terminate

Scheduling defines the lifecycle, activation, timing, and execution-supervision contract of a runnable.

Table 5 Meta Model Scheduling Type#

Property / Attribute

Req.

Datatype

Description

Example / Notes

functionName

Yes

string

Runnable or callable function name.

LSDC.Step

runType

Yes

enum: RunType

Activation type of the runnable.

init, cyclic, event, terminate

description

Yes

string

Purpose and execution intent of the runnable.

Main cyclic calculation

cycleTimeMs

Conditional

number

Periodicity of cyclic execution in milliseconds.

Required when runType == cyclic

implementedASIL

Yes

enum: ASIL

ASIL level for which this runnable/execution is implemented.

QM / A / B / C / D

previousRunnableRef

No

string

Runnable that must precede this runnable when an ordering constraint exists.

SensorFusion.Step

schedulingPolicy

No

string

Scheduling mechanism or constraint.

preemptive / non-preemptive

supervision

Yes

object

Defines whether execution supervision is required and which supervision types/configuration apply.

See Execution Supervision

stackSizeBytes

No

uint32

Required stack size when relevant for deployment/integration.

Platform/deployment-specific

executionResult

Yes

enum: FunctionResult

Generic result returned/reported for function execution.

success / failure / notAvailable

Execution Supervision#

The supervision object indicates whether runtime execution monitoring is required. If supervision is required, one or more monitoring types are selected and the corresponding configuration is supplied.

Table 6 Scheduling Supervision#

Property

Req.

Datatype

Description

supervision.required

Yes

boolean

Indicates whether execution supervision is required for the runnable.

supervision.type

Conditional

enum[]

Required when supervision.required == true. The current property values are alive, deadline, and logical.

supervision.alive

Conditional

object

Required when type contains alive. Supports minIndications, maxIndications, and referenceCycleMs.

supervision.deadline

Conditional

object

Required when type contains deadline. Supports minExecutionTimeMs and mandatory maxExecutionTimeMs.

supervision.logical

Conditional

object

Required when type contains logical. Supports predecessorRefs and successorRefs.

Alive Supervision#

Table 7 Alive Supervision Properties#

Property

Req.

Datatype

Description

minIndications

No

uint32

Minimum allowed number of alive indications in the reference cycle.

maxIndications

No

uint32

Maximum allowed number of alive indications in the reference cycle.

referenceCycleMs

No

number

Reference cycle used to evaluate alive indications.

Deadline Supervision#

Table 8 Deadline Supervision Properties#

Property

Req.

Datatype

Description

minExecutionTimeMs

No

number

Optional minimum execution-time boundary.

maxExecutionTimeMs

Yes

number

Maximum allowed execution time for deadline supervision.

Logical Supervision#

Table 9 Logical Supervision Properties#

Property

Req.

Datatype

Description

predecessorRefs

No

string[]

References to runnables expected before the supervised runnable.

successorRefs

No

string[]

References to runnables expected after the supervised runnable.

Note

The top-level SupervisionType enum additionally contains none and combined. The current supervision.type property in the YAML directly lists alive, deadline, and logical.

Error Type Description#

The Error interface is currently marked as candidate. It represents function-specific diagnostic/error information and is separated from the generic FunctionResult. It shall not be confused with ECU-specific DTC or event-memory configuration.

Standard Naming Convention: <FunctionName>.<ErrorName>.ErrorStatus

Table 10 Candidate Meta Model Error Type#

Property / Attribute

Req.

Datatype

Description

Example / Notes

name

Yes

string

Function-specific Error interface name.

WheelSpeedCalc.RangeError.ErrorStatus

dataType

Yes

string

Datatype of the exposed Error interface.

boolean / enum

description

Yes

string

Meaning of the Error and its trigger scenario.

Range error due to implausible input

severity

Yes

enum: ErrorSeverity

Functional impact/severity associated with the Error.

warning / degraded / shutdown

maturationTimeMs

Yes

number (ms)

Time the Error condition must persist before it is asserted/logged by the underlying middleware.

100

resetTimeMs

Recommended

number

De-maturation/reset time before clearing the Error.

200

resetCondition

Recommended

string

Condition that clears the Error.

Input valid for a defined duration

dependencyRefs

No

string[]

Related upstream Error interfaces that may propagate/trigger this Error.

<SensorTimeout>.ErrorStatus

fallbackBehavior

No

string

Function-level fallback/degradation behavior associated with the Error.

use_substituted_value

raisesSafetyReactionRefs

No

string[]

References to safety reactions associated with this Error.

<SafetyCondition>.SafetyConditionStatus

Modeling Rules#

The following cross-cutting rules apply to the meta model.

Table 11 Meta Model Rules#

Rule

Definition

MR-001

VSS sensor/actuator type and function input/output direction are different concepts. Direction shall be assigned per function-interface usage.

MR-002

Runtime quality shall not be populated as a static constant in a function specification. Quality information shall be transported/represented at runtime.

MR-003

Generic FunctionResult shall be limited to execution outcome and shall not replace function-specific diagnostic/error interfaces.

MR-004

Protection indicates a requirement at function-configuration level; concrete middleware-specific protection realization belongs to platform/deployment binding.

MR-005

Unknown metadata shall remain null according to the consuming schema/tool and shall not be replaced with invented plausible values.

Meta Model File#

Version 0.4

  1# *******************************************************************************
  2# Copyright (c) 2026 ZF Friedrichshafen AG
  3#
  4# See the NOTICE file(s) distributed with this work for additional
  5# information regarding copyright ownership.
  6#
  7# This program and the accompanying materials are made available under the
  8# terms of the Apache License Version 2.0 which is available at
  9# https://www.apache.org/licenses/LICENSE-2.0
 10#
 11# SPDX-License-Identifier: Apache-2.0
 12#
 13# Contributors:
 14#   Saran Gundlapalli - Error handling added
 15# *******************************************************************************
 16
 17metamodel:
 18  name: Eclipse-autoapiframework-Metamodel
 19  version: 0.4.0
 20  scope: Middleware-independent metadata for definition and generation of standardized function APIs. Catalogue/interface metadata (fro e.g., from VSS) is separated from function-specific configuration and runtime state where applicable.
 21  intent: Core interface types and essential metadata are required for standardized API definition and generation.
 22
 23  enums:
 24
 25    ASIL:
 26      - QM
 27      - A
 28      - B
 29      - C
 30      - D
 31    
 32    DataQuality:
 33      description: Runtime qualifier values. DataQuality is defined by the metamodel and the attribute qualityCode is not static metadata of a data interface instance.
 34      values:
 35        - uninitialized
 36        - invalid
 37        - valid
 38
 39
 40    Direction:
 41      - input
 42      - output
 43
 44    RunType:
 45      - init
 46      - cyclic
 47      - event
 48      - terminate
 49    
 50    ProtectionType:
 51      description: Abstract protection requirement. Concrete middleware protection profile and binding details may be defined during platform/deployment configuration.
 52      values:
 53        - none
 54        - complement
 55        - other
 56
 57    FunctionResult:
 58      description: Generic execution result only. It shall not encode function-specific diagnostic causes. Detailed errors are exposed through "Error interfaces".
 59      values:
 60        - success
 61        - failure
 62        - notAvailable
 63      
 64    ErrorSeverity:
 65      - information
 66      - warning
 67      - degraded
 68      - shutdown
 69
 70    SupervisionType:
 71      - none
 72      - alive
 73      - deadline
 74      - logical
 75      - combined
 76
 77  interfaceTypes:
 78
 79    Data:
 80      description: Runtime data interfaces exchanged between applications or systems. Semantic properties may originate from VSS or an extended catalogue. Direction and protection are resolved for the function usage/configuration and are not intrinsic properties of the canonical VSS node.
 81
 82      properties:
 83        name:
 84          mandatory: true
 85          datatype: string
 86          description: Unique interface or node name. Based on canonical VSS path of the data interface - Vehicle.<Domain/Subdomains>.<Signal>
 87          example: Vehicle.Speed
 88
 89        dataType:
 90          mandatory: true
 91          datatype: string
 92          description: Type of value transported by the interface.
 93          examples: 
 94            - float
 95            - uint8
 96            - uint16
 97            - boolean
 98
 99        description:
100          mandatory: true
101          datatype: string
102          description: Functional meaning of the data interface.
103
104        unit:
105          mandatory: true
106          datatype: string
107          description: Engineering unit of the data interface.
108          example: km/h
109
110        min:
111          mandatory: true
112          datatype: number
113          description: Engineering minimum representable value. Null if not yet defined or not applicable.
114
115        max:
116          mandatory: true
117          datatype: number
118          description: Engineering maximum representable value. Null if not yet defined or not applicable.
119
120        defaultValue:
121          mandatory: true
122          datatype: any
123          description: Default or initialization value, where defined. Null if not yet defined or not applicable.
124
125        resolution:
126          mandatory: true
127          datatype: number
128          description: Smallest measurable quantization value - meant for scaling etc.
129
130        precision:
131          mandatory: true
132          datatype: number
133          description: Required numeric precision/number of meaningful digits.
134
135        FuSa:
136          mandatory: true
137          datatype: boolean
138          description: Indicates if the data interface is safety relevant or not.
139
140        ASIL:
141          mandatory: false
142          datatype: enum
143          enumRef: ASIL
144          description: Safety classification associated with the data interface when it is safety-relevant.
145
146        minUpdatePeriodMs:
147          mandatory: true
148          datatype: uint16
149          description: Minimum interval between data updates in milliseconds.
150
151        accuracy:
152          mandatory: true
153          datatype: string
154          description: Expected measurement or estimation accuracy.
155          example: ±0.2 km/h  
156
157        direction:
158          mandatory: true
159          datatype: enum
160          enumRef: Direction
161          description: Input/output relationship relative to the function using the interface. This shall not be inferred from the VSS sensor/actuator type.
162          example: input
163
164        protection:
165          mandatory: true
166          datatype: enum
167          enumRef: ProtectionType
168          description: Protection requirement for transfer of the data between the function and its adapter/platform. Detailed realization is binding-specific.
169          example: complement
170
171      runtimeCompanion:
172        qualityCode:
173          generatedAsSeparateRuntimeInformation: true
174          recommendedNaming: "<DataPath>.Qualifier"
175          datatype: enum
176          enumRef: DataQuality
177          description: Runtime quality/validity information accompanying the value. It is not a static metadata value such as min,max etc. 
178          example: Vehicle.Speed.Qualifier
179
180    Parameter:
181      description: Calibration and configuration interface.
182
183      properties:
184        name:
185          mandatory: true
186          datatype: string
187          description: Unique parameter name. Based on canonical VSS path of the parameter - Vehicle.<Domain/Subdomains>.<Parameter>
188          example: Vehicle.Brake.Gain
189
190        dataType:
191          mandatory: true
192          datatype: string
193          description: Datatype of the parameter value.
194          examples: 
195            - float
196            - float[]
197            - uint8
198            - boolean
199
200        defaultValue:
201          mandatory: true
202          datatype: any
203          description: Default parameter value.
204
205        description:
206          mandatory: true
207          datatype: string
208          description: Meaning and intended usage of the parameter.
209
210        unit:
211          mandatory: true
212          datatype: string
213          description: Engineering unit where applicable.
214
215        tunable:
216          mandatory: true
217          datatype: boolean
218          description: Indicates whether the parameter may be tuned/configured after definition.
219
220        min:
221          mandatory: true
222          datatype: number
223          description: Minimum permitted parameter value, if defined/applicable.
224
225        max:
226          mandatory: true
227          datatype: number
228          description: Maximum permitted parameter value, if defined/applicable.
229
230        dimensions:
231          mandatory: false
232          datatype: any with array indicated via []
233          description: Shape of an array/map parameter. Omitted for scalars; e.g. [10] for a one-dimensional breakpoint vector and [7, 10] for a 7x10 map.
234          example: Vehicle.Brake.GainMap[10]
235
236    Scheduling:
237      description: Lifecycle, activation, timing and execution-supervision contract of a runnable.
238
239      properties:
240        functionName:
241          mandatory: true
242          datatype: string
243          description: Runnable or callable function name.
244          namingConvention:
245            - "<FunctionName>.Init"
246            - "<FunctionName>.Step"
247            - "<FunctionName>.Terminate"
248
249        runType:
250          mandatory: true
251          datatype: enum
252          enumRef: RunType
253          description: Activation type of the runnable.
254
255        description:
256          mandatory: true
257          datatype: string
258          description: Purpose and execution intent of the runnable.
259
260        cycleTimeMs:
261          mandatory: conditional
262          condition: "runType == cyclic"
263          datatype: number
264          description: Periodicity of cyclic execution in milliseconds.
265
266        implementedASIL:
267          mandatory: true
268          datatype: enum
269          enumRef: ASIL
270          description: ASIL level for which this runnable/execution is implemented.
271
272        previousRunnableRef:
273          mandatory: false
274          datatype: string
275          description: Runnable that must precede this runnable when an ordering constraint exists.
276
277        schedulingPolicy:
278          mandatory: false
279          datatype: string
280          description: Scheduling mechanism or constraint, e.g. preemptive/non-preemptive.
281
282        supervision:
283          mandatory: true
284          datatype: object
285
286          properties:
287
288            required:
289              mandatory: true
290              datatype: boolean
291
292            type:
293              mandatory: conditional
294              condition: required == true
295              datatype: enum[]
296              values:
297                - alive
298                - deadline
299                - logical
300
301              alive:
302                mandatory: conditional
303                condition: type contains alive
304                datatype: object
305                properties:
306                minIndications: {datatype: uint32, mandatory: false}
307                maxIndications: {datatype: uint32, mandatory: false}
308                referenceCycleMs: {datatype: number, mandatory: false}
309                
310              deadline:
311                mandatory: conditional
312                condition: type contains deadline
313                datatype: object
314                properties:
315                  minExecutionTimeMs: {datatype: number, mandatory: false}
316                  maxExecutionTimeMs: {datatype: number, mandatory: true}
317
318              logical:
319                mandatory: conditional
320                condition: type contains logical
321                datatype: object
322                properties:
323                  predecessorRefs: {datatype: "string[]", mandatory: false}
324                  successorRefs: {datatype: "string[]", mandatory: false}
325
326        stackSizeBytes:
327          mandatory: false
328          datatype: uint32
329          description: Required stack size when relevant for deployment/integration.
330
331        executionResult:
332          mandatory: true
333          datatype: enum
334          enumRef: FunctionResult
335          description: Generic result returned/reported for function execution. The adapter may report a failure indication it can observe (e.g. due to invocation/transport/timeout). It shall not synthesize detailed function-internal diagnostic causes nor reports any errors for fault logging.
336
337    Error:
338      status: candidate
339      description: Function-specific diagnostic/error interface, separated from the generic FunctionResult. This model is a candidate for later standardization and shall not be confused with ECU-specific DTC/event-memory configuration.
340
341      properties:
342        name:
343          mandatory: true
344          datatype: string
345          description: Function-specific error interface name. Standard canonical form - <FunctionName>.<ErrorName>.ErrorStatus
346          example: WheelSpeedCalc.RangeError.ErrorStatus
347
348        dataType:
349          mandatory: true
350          datatype: string
351          description: Datatype of the exposed error interface.
352          examples:
353           - boolean
354           - enum
355
356        description:
357          mandatory: true
358          datatype: string
359          description: Meaning of the error and its trigger scenario.
360
361        severity:
362          mandatory: true
363          datatype: enum
364          enumRef: ErrorSeverity
365          description: Functional impact/severity associated with the error.
366
367        maturationTimeMs:
368          mandatory: true
369          datatype: number in milliseconds
370          description: Time the error condition must persist before the error is asserted/logged by the underlying middleware.
371
372        resetTimeMs:
373          mandatory: false
374          recommendation: recommended
375          datatype: number
376          description: De-maturation/reset time before clearing the error.
377
378        resetCondition:
379          mandatory: false
380          recommendation: recommended
381          datatype: string
382          description: Condition that clears the error.
383
384        dependencyRefs:
385          mandatory: false
386          datatype: "string[]"
387          description: Related upstream error interfaces that may propagate/trigger this error.
388
389        fallbackBehavior:
390          mandatory: false
391          datatype: string
392          description: Function-level fallback/degradation behavior associated with the error.
393
394        raisesSafetyReactionRefs:
395          mandatory: false
396          datatype: "string[]"
397          description: References to safety reactions associated with this error - <SafetyCondition>.SafetyConditionStatus.
398
399  modelingRules:
400    - id: MR-001
401      rule: >-
402        VSS sensor/actuator type and function input/output direction are different
403        concepts. Direction shall be assigned per function-interface usage.
404
405    - id: MR-002
406      rule: >-
407        Runtime quality shall not be populated as a static constant in a function
408        specification. Quality information shall be transported/represented at runtime.
409
410    - id: MR-003
411      rule: >-
412        Generic FunctionResult shall be limited to execution outcome and shall not
413        replace function-specific diagnostic/error interfaces.
414
415    - id: MR-004
416      rule: >-
417        Protection indicates a requirement at function configuration level; concrete
418        middleware specific protection realization belongs to platform/deployment binding.
419
420    - id: MR-005
421      rule: >-
422        Unknown metadata shall remain null according to the consuming schema/tool
423        and shall not be replaced with invented plausible values.

History#

Table 12 Meta Model History#

Version

Author

Description of Changes

Impact

0.2.0

Gundlapalli Saran

First release of Meta Model specification.

Baseline

0.3.0

Thomas Pfleiderer

Signal protection attribute, FunctionResult enum, and typo corrections.

Functional enhancement

0.4.0

Gundlapalli Saran

Updated Data and Parameter metadata; separated runtime quality information; moved function-relative direction/protection to Data; added FuSa handling, execution supervision, generic execution-result semantics, candidate Error interface, and modelling rules.

Architectural and functional enhancement

Examples#

Example function specifications based on this meta model: