M6 ServiceReady Reference Platform

Objective

The final demonstration: the same conceptual mixed-criticality system - one contract suite, demonstrated across at least two heterogeneous target realizations. That is the ServiceReady proof.

                  GoMyRobotOS
                      │
          ┌───────────┼───────────┐
          │           │           │
        Flight     Autonomy     Services
        RTEMS       RTEMS       Linux
          │           │           │
          └───────────┼───────────┘
                      ▼
               GoMyRobotGuard
                      ▼
             GoMyRobotVerify
                      ▼
             GoMyRobotAssure

Scope

  • multi-partition reference system (flight + autonomy + services)

  • boot, isolation, and recovery behavior verified as a system, not per partition

  • GoMyRobotGuard observing the domains and executing contractual recovery, with recovery claims quantified per fault class (Guard independence Stage 2)

  • Verify/Assure fed automatically (M5 pipeline now operating on the whole system)

  • cross-target demonstration: same conceptual system on two or more targets from {x86-64, NG-ULTRA, HPSC}

Deliverables

  • the ServiceReady reference deployment

  • cross-target demonstration record (which targets, which contract set, which gates passed)

  • evidence graph for the full system (reference instance)

Tests / acceptance gate

The same conceptual mixed-criticality system is demonstrated across heterogeneous targets.

“Same conceptual system”: one contract suite, identical IR, different backends. At least two target realizations must be demonstrated - this is the floor; three would be the research ideally (M4 having contributed HPSC data).

Current status

Planned (final stage; requires M1-M5 foundations).

Known limitations

  • ServiceReady is a reference platform outcome, not a product launch claim; mission adoption is out of scope of the milestone.

  • The Services (Linux) domain’s image comes from the BSP pipeline (Yocto/OpenEmbedded where applicable), M6 demonstrates the managed partition behavior of that domain, not Linux support claims beyond the contract fields.