Svc/FileWorker/docs/sdd.md
Svc::FileWorker is an active F' component used for writing and reading files on the filesystem. Other components needing to read or write files may use this component to perform large/slow file operations without missing their deadlines.
| Name | Description | Validation |
|---|---|---|
| FileWorker-001 | FileWorker shall provide an async interface to read contents from a file and return the data in a client-provided buffer | Unit Test |
| FileWorker-002 | FileWorker shall provide an interface to write contents to a file passed in from a client-provided buffer | Unit Test |
| FileWorker-003 | FileWorker shall handle receiving read-done signals while in improper state | Unit Test |
| FileWorker-004 | FileWorker shall handle cancel for reads | Unit Test |
| FileWorker-005 | FileWorker shall validate the inputs to its read, write, and verify port handlers and report malformed inputs via an event and a failure status rather than asserting | Unit Test |
| State | Description |
|---|---|
| IDLE | FileWorker is ready to accept requests for transfer |
| READING | In the read process |
| WRITING | In the write process |
| Kind | Port Name | Port Type | Usage |
|---|---|---|---|
| async input | writeIn | Svc.FileWrite | Initiates a file write |
| output | writeDoneOut | Svc.SignalDone | File write has completed |
| async input | readIn | Svc.FileRead | Initiates a file read |
| output | readDoneOut | Svc.SignalDone | File read has completed |
| guarded input | cancelIn | Svc.CancelStatus | Cancels a current operation |
| async input | verifyIn | Svc.VerifyStatus | Initiates a verification of a file against an expected CRC checksum |
| output | verifyDoneOut | Svc.SignalDone | File verification results |
Each *In port handler validates its arguments before performing any file operation. Malformed inputs — such as an empty path, an invalid (null or zero-length) buffer, a write offset past the end of the buffer, or a path too long for the filename buffer — are reported by emitting an InvalidInput warning event and returning INVALID_INPUT to the client, rather than triggering an FW_ASSERT. This ensures that invalid, externally supplied (e.g. ground-commanded) inputs are surfaced to operators as telemetry instead of causing an assertion failure.
Calling component passes in a buffer for writing to file, the file location is path, and the offset to start writing at.
InvalidInput event and return INVALID_INPUTCalling component passes in a file path path to read and a buffer for client to read from
InvalidInput event and return INVALID_INPUTReadFailedFileSize and return FAILED_FILE_SIZE, setting state to IDLEInvalidInput event and return INVALID_INPUT