AADL语言
语法学习笔记
知识点梳理 · 语法详解 · 应用举例 · 易错提示
参考标准:SAE AS5506B / ISO/IEC/IEEE 26553
编制日期:2026年9月
一、AADL概述与核心概念
1.1 什么是AADL
AADL(Architecture Analysis & Design Language)是由SAE标准化的嵌入式实时系统架构建模语言。它的核心定位是:在系统设计的早期阶段,用形式化的方式描述系统的架构,并支持定量分析。
AADL的三个核心能力:
- ****结构描述:****定义系统的组件层次、接口、连接关系
- ****属性标注:****为组件附加时序、资源、安全等语义属性
- ****形式化分析:****基于模型进行调度性、延迟、安全性等定量分析
1.2 核心设计思想
1.2.1 组件-连接器范式
AADL将系统抽象为组件(Component)和连接(Connection)的组合。组件是功能的封装单元,连接定义组件间的交互关系。
★ 类比理解:组件像C语言中的struct,连接像struct之间的指针引用。
1.2.2 类型-实现分离
这是AADL最重要的设计思想之一。每个组件都可以定义Type(类型)和Implementation(实现):
- Type:定义组件的外部接口(端口、特征),是对外契约
- Implementation:定义组件的内部结构(子组件、连接),是实现细节
-- Type: 只定义接口
thread MyThread
features
Input : in data port DataT;
Output : out data port DataT;
end MyThread;
-- Implementation: 定义内部结构
thread implementation MyThread.impl
subcomponents
Calc : subprogram Calculate;
connections
c1 : port Input -> Calc.In;
c2 : port Calc.Out -> Output;
end MyThread.impl;
★ 好处:同一个Type可以有多种Implementation。例如先做一个软件实现,后续可以替换为FPGA硬件实现,接口不变。
1.2.3 属性可扩展性
AADL通过Property Set机制支持语义扩展。语言本身定义了基本结构,领域特定的语义通过属性附加。这使得AADL既能描述通用架构,又能支持特定领域的分析需求。
★ 例如:Timing_Properties属性集添加了Period、Deadline等时序属性,使AADL模型支持调度性分析。
二、包与属性集
2.1 包(Package)
包是AADL的命名空间和组织单元,所有构件定义必须放在包内。
package MySystem
public
-- 所有定义放在这里
end MySystem;
包可以引用其他包中定义的类型:
with Timing_Properties;
with Deployment_Properties;
package MySystem
public
-- 可以使用Timing_Properties中的属性
end MySystem;
⚠ 易错点:with语句必须在package声明之前,否则编译报错。
2.2 属性集(Property Set)
属性集定义一组相关的属性。AADL标准库包含多个预定义属性集:
|-----------------------|------------|-------------------------------------------------|
| 属性集 | 用途 | 常用属性 |
| Timing_Properties | 时序行为 | Period, Deadline, Compute_Execution_Time |
| Deployment_Properties | 部署绑定 | Actual_Processor_Binding, Actual_Memory_Binding |
| Memory_Properties | 内存资源 | Memory_Size, Data_Size |
| Hardware_Properties | 硬件特性 | Processing_Capacity, Bandwidth |
| SEI_Properties | 安全相关 | Security_Level |
三、数据构件(Data)
3.1 基本语法
Data构件用于定义数据类型,是最基础的构件。
data SensorData
end SensorData;
3.2 数据属性
通过属性为Data指定大小、类型等信息:
data SpeedValue
properties
Data_Size => 32; -- 32位数据
end SpeedValue;
data PositionValue
properties
Data_Size => 64; -- 64位数据
end PositionValue;
3.3 应用举例:伺服驱动器数据类型
package ServoDataTypes
public
data SpeedCmd
properties
Data_Size => 32;
end SpeedCmd;
data PositionFB
properties
Data_Size => 64;
end PositionFB;
data PWMOutput
properties
Data_Size => 16; -- PWM占空比,16位精度
end PWMOutput;
data PulseCount
properties
Data_Size => 32; -- QEI脉冲计数值
end PulseCount;
end ServoDataTypes;
四、子程序构件(Subprogram)
4.1 基本语法
Subprogram定义可调用的过程或函数,支持参数传递。
subprogram SubprogramName
features
Param1 : in parameter DataType1;
Param2 : out parameter DataType2;
end SubprogramName;
4.2 参数方向
|------------|------------|---------------|
| 方向 | 含义 | 说明 |
| in | 输入参数 | 调用方传入,被调用方只读 |
| out | 输出参数 | 被调用方写入,返回给调用方 |
| in out | 输入输出 | 双向传递 |
4.3 应用举例:PID计算子程序
subprogram PID_Calculate
features
SetPoint : in parameter SpeedCmd; -- 目标值
Feedback : in parameter SpeedCmd; -- 反馈值
Kp : in parameter SpeedCmd; -- 比例系数
Ki : in parameter SpeedCmd; -- 积分系数
Kd : in parameter SpeedCmd; -- 微分系数
Output : out parameter SpeedCmd; -- 控制输出
properties
Compute_Execution_Time => 50 .. 150 us;
end PID_Calculate;
★ Subprogram的执行时间属性用于流分析中计算子程序延迟。
五、线程构件(Thread)
5.1 核心概念
Thread是AADL中最核心的执行单元,表示可独立调度的并发执行流。每个线程有自己的执行上下文和调度属性。
5.2 基本语法
thread ThreadName
features
-- 端口声明
InputPort : in data port DataType;
OutputPort : out data port DataType;
properties
-- 调度属性
Dispatch_Protocol => Periodic;
Period => 1 ms;
Compute_Execution_Time => 100 .. 300 us;
Deadline => 1 ms;
Priority => 5;
end ThreadName;
5.3 调度协议详解
Dispatch_Protocol是线程最关键的属性,决定线程何时被触发执行:
|------------|--------------|--------------|
| 协议 | 触发方式 | 适用场景 |
| Periodic | 按固定周期触发 | 控制环、周期采样 |
| Sporadic | 事件触发,有最小间隔 | 中断处理、异常响应 |
| Aperiodic | 事件触发,无间隔约束 | 后台任务、日志记录 |
| Timed | 在指定绝对时间触发 | 时间同步任务 |
⚠ 易错点:Periodic线程的Deadline通常<=Period。如果Deadline>Period,调度性分析时可能导致不可调度。
5.4 关键时序属性
|------------------------|------------------|---------------|
| 属性 | 含义 | 取值示例 |
| Period | 执行周期 | 1 ms, 500 us |
| Compute_Execution_Time | 执行时间范围(最坏/最好) | 100 .. 300 us |
| Deadline | 截止期(从触发到完成的最大时间) | 1 ms |
| Priority | 调度优先级(数值越大优先级越高) | 5, 10 |
★ Compute_Execution_Time的范围格式为 最好情况..最坏情况,调度性分析使用最坏情况值(WCET)。
5.5 应用举例:伺服驱动器控制线程
-- 电流环线程(最高优先级,最快周期)
thread CurrentLoop
features
TorqueCmd : in data port SpeedCmd;
CurrentFB : in data port SpeedCmd;
CurrentOut : out data port SpeedCmd;
properties
Dispatch_Protocol => Periodic;
Period => 50 us;
Compute_Execution_Time => 20 .. 50 us;
Deadline => 50 us;
Priority => 9;
end CurrentLoop;
-- 速度环线程
thread SpeedLoop
features
SpeedCmd : in data port SpeedCmd;
SpeedFB : in data port SpeedCmd;
TorqueCmd : out data port SpeedCmd;
properties
Dispatch_Protocol => Periodic;
Period => 500 us;
Compute_Execution_Time => 50 .. 100 us;
Deadline => 500 us;
Priority => 8;
end SpeedLoop;
-- 位置环线程
thread PositionLoop
features
PosCmd : in data port PositionFB;
PosFB : in data port PositionFB;
SpeedCmd: out data port SpeedCmd;
properties
Dispatch_Protocol => Periodic;
Period => 1 ms;
Compute_Execution_Time => 100 .. 200 us;
Deadline => 1 ms;
Priority => 7;
end PositionLoop;
★ 三环PID的优先级分配原则:周期越短优先级越高。电流环50us > 速度环500us > 位置环1ms。
六、进程构件(Process)
6.1 核心概念
Process是线程和数据的容器,用于组织相关的执行单元。Process本身不直接执行,它包含的线程才是实际执行单元。
6.2 基本语法
process ProcessName
components
ThreadInst : thread ThreadType;
DataInst : data DataType;
connections
c1 : port ThreadInst.Out -> ThreadInst2.In;
end ProcessName;
6.3 应用举例:运动控制进程
process MotionControl
components
CurrLoop : thread CurrentLoop;
SpdLoop : thread SpeedLoop;
PosLoop : thread PositionLoop;
connections
-- 位置环输出 -> 速度环输入
c1 : port PosLoop.SpeedCmd -> SpdLoop.SpeedCmd;
-- 速度环输出 -> 电流环输入
c2 : port SpdLoop.TorqueCmd -> CurrLoop.TorqueCmd;
end MotionControl;
★ Process内的connections定义内部线程间的数据流,形成级联控制链路。
七、系统构件(System)
7.1 核心概念
System是顶层构件,封装整个系统。它可以包含Process、Processor、Memory、Bus、Device等所有类型的构件实例。
7.2 应用举例:伺服驱动器系统
system ServoDrive
components
-- 软件构件
MotionCtrl : process MotionControl;
DI_Module : process DI_Process;
Comm : process Communication;
-- 硬件构件
MCU : processor HPM6E80;
Flash : memory InternalFlash;
RAM : memory InternalRAM;
ECAT : bus EtherCAT_Bus;
-- 访问连接(软件访问硬件)
a1 : access MotionCtrl -> MCU;
a2 : access DI_Module -> MCU;
a3 : access Comm -> MCU;
a4 : access MotionCtrl -> RAM;
a5 : access Comm -> ECAT;
properties
-- 部署绑定:所有进程绑定到MCU
Actual_Processor_Binding =>
(applies to MotionCtrl, DI_Module, Comm => MCU);
end ServoDrive;
八、硬件构件
8.1 处理器(Processor)
processor HPM6E80
properties
Processing_Capacity => 600 MHz;
Scheduler => {Rate_Monotonic};
end HPM6E80;
8.2 内存(Memory)
memory InternalFlash
properties
Memory_Size => 2048 Kbytes;
end InternalFlash;
memory InternalRAM
properties
Memory_Size => 512 Kbytes;
end InternalRAM;
8.3 总线(Bus)
bus EtherCAT_Bus
properties
Bandwidth => 100 Mbps;
end EtherCAT_Bus;
8.4 设备(Device)
device GPIO_Port
features
DI_Input : in event data port PulseData;
DO_Output : out event data port Boolean;
end GPIO_Port;
九、端口与连接
9.1 三种端口类型
端口是构件对外交互的接口,AADL定义了三种端口类型:
|-----------------|--------------|-------------------|--------------|
| 端口类型 | 通信方式 | 特点 | 典型应用 |
| Data Port | 同步 | 发送方和接收方需同时就绪,数据覆盖 | 周期同步数据交换 |
| Event Port | 异步 | 仅通知事件发生,不携带数据,可排队 | 中断通知、事件触发 |
| Event Data Port | 异步 | 事件+数据,可排队 | 异步数据传输 |
⚠ 易错点:Data Port是覆盖语义------如果接收方未及时读取,新数据会覆盖旧数据。如果需要排队语义,应使用Event Data Port。
9.2 端口方向
- in:输入端口,接收数据
- out:输出端口,发送数据
- in out:双向端口
9.3 端口连接(Port Connection)
端口连接用于构件间的数据/事件传递:
connections
c1 : port Source.OutputPort -> Target.InputPort;
应用举例:
process ControlProcess
components
Sensor : thread SensorReader;
Control : thread ControlLoop;
connections
c1 : port Sensor.SensorData -> Control.Feedback;
end ControlProcess;
9.4 访问连接(Access Connection)
访问连接用于构件对共享资源的访问:
connections
a1 : access ProcessInstance -> ProcessorInstance;
a2 : access ProcessInstance -> MemoryInstance;
a3 : access ProcessInstance -> BusInstance;
★ 端口连接传递数据,访问连接建立资源使用关系。两者不能混用。
十、属性系统
10.1 属性关联语法
属性通过=>操作符关联到构件:
thread MyThread
properties
Dispatch_Protocol => Periodic;
Period => 1 ms;
Compute_Execution_Time => 100 .. 300 us;
end MyThread;
10.2 属性值单位
|------------------------|-------------|---------------|
| 属性 | 值类型 | 单位示例 |
| Period | 时间 | ms, us, ns |
| Compute_Execution_Time | 时间范围 | 100 .. 300 us |
| Priority | 整数 | 1, 5, 10 |
| Data_Size | 位数 | 8, 16, 32, 64 |
| Memory_Size | 字节数 | 512 Kbytes |
| Processing_Capacity | 频率 | 600 MHz |
| Bandwidth | 速率 | 100 Mbps |
⚠ 易错点:Compute_Execution_Time是范围值(最好..最坏),不是单个值。写Period => 100 .. 300 us是语法错误。
10.3 部署绑定属性
properties
-- 将进程绑定到处理器
Actual_Processor_Binding =>
(applies to Process1, Process2 => MCU);
-- 将数据绑定到内存
Actual_Memory_Binding =>
(applies to SharedData => RAM);
十一、流规范(Flow)
11.1 三种流类型
流规范描述数据在系统中的传播路径,是端到端延迟分析的基础:
|-------------|------------|-----------------------|--------------|
| 流类型 | 含义 | 语法 | 对应场景 |
| Source Flow | 数据进入系统的起点 | flow source InputPort | 传感器输入、外部中断 |
| Path Flow | 数据在系统内部的传播 | flow path In -> Out | 经过多个线程处理 |
| Sink Flow | 数据离开系统的终点 | flow sink OutputPort | 执行器输出、PWM |
11.2 应用举例:DI输入到PWM输出的完整流路径
-- 1. 源流:GPIO中断输入
thread DI_Handler
features
GPIO_In : in event data port PulseData;
PulseCount : out data port PulseCount;
flow sources
DI_Source : flow source GPIO_In;
end DI_Handler;
-- 2. 路径流:位置环处理
thread PositionLoop
features
PulseIn : in data port PulseCount;
SpeedCmd : out data port SpeedCmd;
flow paths
Pos_Path : flow path PulseIn -> SpeedCmd;
end PositionLoop;
-- 3. 路径流:速度环处理
thread SpeedLoop
features
SpeedIn : in data port SpeedCmd;
TorqueCmd : out data port SpeedCmd;
flow paths
Spd_Path : flow path SpeedIn -> TorqueCmd;
end SpeedLoop;
-- 4. 路径流:电流环处理
thread CurrentLoop
features
TorqueIn : in data port SpeedCmd;
CurrentCmd: out data port SpeedCmd;
flow paths
Cur_Path : flow path TorqueIn -> CurrentCmd;
end CurrentLoop;
-- 5. 汇流:PWM输出
thread PWM_Output
features
CmdIn : in data port SpeedCmd;
PWM_Out: out data port PWMOutput;
flow sinks
PWM_Sink : flow sink PWM_Out;
end PWM_Output;
★ 完整端到端流路径:DI_Source -> Pos_Path -> Spd_Path -> Cur_Path -> PWM_Sink。分析工具会沿此路径计算端到端延迟。
十二、模式(Mode)
12.1 基本概念
Mode用于描述系统在不同运行状态下的行为切换。例如伺服驱动器有"运行"、"停止"、"故障"等不同模式,每种模式下线程的行为可能不同。
12.2 基本语法
thread MotorThread
features
Cmd : in data port SpeedCmd;
modes
Running : initial mode;
Stopped : mode;
Fault : mode;
mode transitions
Running - Cmd == 0 -> Stopped;
Stopped - Cmd /= 0 -> Running;
Running - Fault_Detected -> Fault;
Fault - Reset_Cmd -> Stopped;
end MotorThread;
★ Mode使得同一个线程在不同状态下可以有不同的执行时间、优先级等属性,用于建模降级运行等场景。
十三、附件机制(Annex)
13.1 基本概念
Annex是AADL的扩展机制,允许在标准语言之上附加领域特定的语义。Annex内容放在{! !}分隔符内。
13.2 EMV2(错误模型附件)
EMV2是最常用的Annex,用于安全性建模:
thread SensorThread
annex EMV2 {**
-- 错误行为定义
error behavior
events
sensor_failure : error event;
states
operational : initial state;
failed : state;
transitions
operational - sensor_failure -> failed;
end error behavior;
-- 错误传播
component error behavior
propagations
Output : out error propagation;
end component error behavior;
**};
end SensorThread;
★ EMV2支持FTA(故障树分析)和FMEA(故障模式与影响分析),是航空航天、汽车电子安全认证的关键工具。
十四、综合应用实例
14.1 完整模型:伺服驱动器DI模块
以下是一个完整的DI模块AADL模型,涵盖本章所有知识点:
with Timing_Properties;
with Deployment_Properties;
with Memory_Properties;
package DI_Module_Spec
public
-- ===== 数据类型 =====
data PulseData
properties Data_Size => 32;
end PulseData;
data CounterValue
properties Data_Size => 32;
end CounterValue;
data LevelStatus
properties Data_Size => 8;
end LevelStatus;
-- ===== 子程序 =====
subprogram QEI_Decode
features
ChA : in parameter PulseData;
ChB : in parameter PulseData;
Count : out parameter CounterValue;
Direction : out parameter LevelStatus;
properties
Compute_Execution_Time => 5 .. 15 us;
end QEI_Decode;
-- ===== 线程 =====
thread DI_Interrupt_Handler
features
GPIO_In : in event data port PulseData;
PulseCount : out data port CounterValue;
flow sources
DI_Source : flow source GPIO_In;
properties
Dispatch_Protocol => Periodic;
Period => 100 us;
Compute_Execution_Time => 10 .. 30 us;
Deadline => 100 us;
Priority => 10;
end DI_Interrupt_Handler;
thread DI_Scan
features
SON_In : in data port LevelStatus;
ALM_In : in data port LevelStatus;
LIMIT_In : in data port LevelStatus;
HOME_In : in data port LevelStatus;
ESTOP_In : in data port LevelStatus;
DI_Status : out data port LevelStatus;
properties
Dispatch_Protocol => Periodic;
Period => 500 us;
Compute_Execution_Time => 20 .. 40 us;
Deadline => 500 us;
Priority => 4;
end DI_Scan;
-- ===== 进程 =====
process DI_Process
components
IRQ_Handler : thread DI_Interrupt_Handler;
Scanner : thread DI_Scan;
end DI_Process;
-- ===== 处理器 =====
processor HPM6E80
properties
Processing_Capacity => 600 MHz;
Scheduler => {Rate_Monotonic};
end HPM6E80;
-- ===== 系统 =====
system DI_System
components
DI : process DI_Process;
MCU : processor HPM6E80;
connections
a1 : access DI -> MCU;
properties
Actual_Processor_Binding =>
(applies to DI => MCU);
end DI_System;
end DI_Module_Spec;
14.2 模型分析要点
14.2.1 调度性分析
对上述模型中的两个线程进行调度性验证:
|----------------------|------------|--------------|---------------|
| 线程 | 周期 | WCET | 利用率 |
| DI_Interrupt_Handler | 100us | 30us | 30/100 = 0.30 |
| DI_Scan | 500us | 40us | 40/500 = 0.08 |
| 合计 | | | U = 0.38 |
n=2时Liu-Layland界限 = 2*(2^(1/2)-1) = 0.828。U=0.38 < 0.828,可调度。
14.2.2 端到端延迟分析
DI中断到脉冲计数输出的延迟:
- DI_Interrupt_Handler等待时间:最多100us(周期)
- 执行时间:最多30us(WCET)
- 总延迟:100 + 30 = 130us
十五、常见错误与注意事项
15.1 语法常见错误
|--------------|--------------------------|--------------------------------|
| 错误类型 | 错误示例 | 正确写法 |
| 遗漏end语句 | thread T ... (无end) | end T; |
| 属性值单位错误 | Period => 1; | Period => 1 ms; |
| 执行时间写为单值 | Compute_Exec => 100 us; | Compute_Exec => 50 .. 100 us; |
| 端口方向遗漏 | Port1 : data port DataT; | Port1 : in data port DataT; |
| with语句位置错误 | package P ... with X; | with X; package P ... |
| 连接箭头方向错误 | port A -> B (在access中) | access A -> B |
15.2 建模常见错误
- 线程周期设置不合理:控制环周期应远大于执行时间,建议至少5倍以上裕量
- 优先级分配不当:周期越短的线程优先级应越高(RMS原则)
- 遗漏部署绑定:线程必须绑定到处理器,否则调度性分析无法进行
- Data Port误用:需要排队语义时应使用Event Data Port而非Data Port
- 流规范不完整:端到端分析需要Source->Path->Sink完整链路
15.3 学习 重点
- 先掌握Data、Thread、Process三个核心构件,再扩展到其他构件
- 重点理解端口类型区别(Data Port vs Event Port vs Event Data Port)
- 动手在OSATE2中编写模型,通过编译验证加深理解
- 结合伺服驱动器项目实际建模,将每个功能模块映射为AADL构件
- 学习调度性分析和端到端延迟分析的计算方法,理解属性的工程含义