Search NASASearch

Engineering topics

Holloway, Alexandra

Publications and source records attributed to Holloway, Alexandra.

Visual Odometry Thinking While Driving for the Curiosity Mars Rover's Three-Year Test Campaign: Impact of Evolving Constraints on Verification and Validation

Over the first 9 years of the Mars Science Laboratory (MSL) Curiosity rover's surface mission, more than 87\% of its driving has been performed using Visual Odometry (VO). The benefits of using VO during driving are that it minimizes rover position uncertainty and can be used to monitor wheel slip, halting a drive if excessive wheel slip is occurring. The VO implementation on board Curiosity acquires and processes VO images in between drive steps while the rover is stationary. A VO Thinking While Driving (VTWD) flight software capability has been developed which enables the processing of VO images during rover driving, increasing the distance Curiosity can drive with VO in a given time period up to as much as 1.75x total distance. Verification and Validation (V\&V) of the capability has been challenging due to impacts from the COVID-19 pandemic and unavailability of the JPL Mars Yard outdoor test site. The VTWD V\&V test procedures were modified to use a small indoor space with Mars-like terrain. This paper describes the 3 year V\&V effort under challenging conditions to approve the VTWD capability for use on the Curiosity rover.

Rankin, Arturo

Building a lifeboat: MSL’s uplink and installation campaign to restore a failing backup computer

Flight software updates are among the hardest andmost dangerous activities for the Mars Science Laboratory(MSL) Curiosity team. While danger is often mitigated bybackups, fallback strategies, and incremental installation withground-in-the-loop cycles which provide a safety net for theinstallation process, the software update described in this paperwas unable to use many of the common practices due to thenature of the fault addressed by the update. The MSL rover(landed August 2012) encountered a problem with one of itscomputer’s non-volatile storage chips in 2019, requiring a swapto its backup computer and an urgent software upgrade calledR-Hope. R-Hope, a lifeboat to be used in the event of primarycomputer issues, was written, tested, and sent to the rover inlightning speed of just 19 months. Multi-mission and teamcoordination allowed the 49 flight software image files to beuplinked to the rover over a 6-week period, using multiple pathsand backup options for speedy delivery. In the end, the RHopesoftware upgrade returned the computer to operation asa backup flight computer. The flight software transition wasdesigned to impact science return as little as possible, and installationplans included science activities for the majority of MSLinstruments. This paper describes the uplink and installationcampaigns for R-Hope, and discusses the notable lessons learnedby the operations team.

Byrne, DJ

R-Hope: Development Approach to Extreme Non-volatile Memory Reuse Onboard the Curiosity Rover

The MSL Curiosity rover landed on Mars on August~5, 2012. Over time, one of its two computers experienced critical hardware memory failure. This non-volatile NAND flash memory held file system partitions and tunable parameters needed for running rover flight software. The project assembled a design and development team to re-purpose a NOR flash memory hardware chip, only 1.5\% of the size of the NAND, to hold the file systems and parameters. The usable NOR memory required major software changes to accommodate the new limitations of slower access speeds, vastly different physical layout, and smaller size. This presentation discusses the approach, challenges, and outcomes of restoring function to the computer so it can act as a ``lifeboat'' in event of problems with the primary computer.

Peper, Nick

Trust in Collaborative Automation in High Stakes Software Engineering Work

The amount of autonomy in software engineering tools is increasing as developers build increasingly complex systems. Research in other domains shows that too much or too little trust in autonomous tools can have negative consequences, but we are not aware of any study that has investigated trust in autonomous tools in the highly interactive context of a software engineering workplace. We present the results of a ten week ethnographic case study of engineers collaborating with autonomous tools to write flight software at a large national space exploration organization to support high stakes missions. We find that trust in an autonomous software engineering tool in this setting was influenced by four main factors: the tool’s transparency, social context, an organization’s associated processes, and its usability. We outline theoretical implications for future research into trust in autonomous software engineering tools, and practical implications for tool designers and organizations conducting high stakes work with autonomous tools.

Davidoff, Scott

Integration of an Arm Kinematics Hot Patch onboard the Curiosity Rover

NASA's Mars Science Laboratory (MSL) mission has updated the Curiosity rover's flight software multiple times since landing on Mars on August 6, 2012. The most common patching method has been a hot patch, in which running flight software is modified after being copied into RAM from its persistent storage. The latest hot patch to be installed on Curiosity fixed an issue in the robotic arm software that computes generalized inverse kinematics. Additional unit testing performed since the start of the surface mission revealed that this software can sometimes produce erroneous solutions.The cause was identified as numerical instability in a quartic root finder. When the inputs to that solver are not well conditioned, floating-point numerical issuescan cause erroneous roots to be reported. In theory, this could result in the robotic arm turret instruments being commanded to unintended positions, for example, below the terrain surface. Out of approximately 3.7 million unit test cases, 97.2\% of the position errors were below 5 mm. However, there were 16 test cases where theposition error was greater than 20 cm, and the maximum position error was 1.2 meters.The patch was uploaded to Curiosity on sol 2642 (January 11, 2020) after the solution was developed, re-implemented as a hot patch, and validated and verified using Earth-based Curiosity testbeds. A checkout test of the patch was performed on Curiosity on sol 2657, and nominal use of the patch began on sol 2658. In this paper, we describe the steps that led to integrating the arm kinematic hot patch into Curiosity's flight software, from the discovery of the bug to the nominal use of the patch in flight.

Maimone, Mark

Mini-Stamp as a Micro-Display for At-A-Glance Subsystem Information for DSN Links

Operators of the Deep Space Network (DSN) attend to numerous tasks with the overall goal of providing continuous support for the world's deep space missions. This high-stakes operations environment requires operators to understand the state of the Deep Space Network and predict what will happen next. Under the Follow-the-Sun initiative which requires remote operations of the highly complex telecommunications equipment, operators will need to remain aware of the state of the entire network rather than just their own facility, and transitioning fluidly between periods of low activity and periods of high demand. I designed a micro-display for operators to see, at a glance, the state of a Deep Space Network support including its subsystems. Using in-depth user-centered and participatory design techniques to identify information requirements, I designed what I called a Postage Stamp (NTR-49720) for individual operators to be able to maintain awareness of their own assigned supports. However, under Follow the Sun, operators must remain aware of all supports. The area occupied by the Postage Stamp must shrink to allow operators to see the state of the entire system, e.g., via a Big Board posted prominently in the operations room. Micro-displays are tools for mental model re-alignment, helping operators to keep their mental models of how the system works and behaves aligned with the changing state of the complex system. Data-driven micro-displays such as the Postage Stamp and Mini-Stamp display information about the system in a consistent way. Like a traffic light, the format of the micro-display never changes: the operator always knows where to look to find a specific piece of information. The Mini-Stamp always looks like the Mini-Stamp, and all of its data fields always lie in the same place on the micro-display. Real-time data flows through the Mini-Stamp to provide information to the operator.

Holloway, Alexandra

Bringing Back the Social Affordances of the Paper Memo to Aerospace Systems Engineering Work

Model-based systems engineering (MBSE) is a relatively new field that brings together the interdisciplinary study of technological components of a project (systems engineering) with a model-based ontology to express the hierarchical and behavioral relationships between the components (computational modeling). Despite the compelling promises of the benefits of MBSE, such as improved communication and productivity due to an underlying language and data model, we observed hesitation to its adoption at the NASA Jet Propulsion Laboratory. To investigate, we conducted a six-month ethnographic field investigation and needs validation with 19 systems engineers. This paper contributes our observations of a generational shift in one of JPL's core technologies. We report on a cultural misunderstanding between communities of practice that bolsters the existing technology drag. Given the high cost of failure, we springboard our observations into a design hypothesis - an intervention that blends the social affordances of the narrative-based work flow with the rich technological advantages of explicit data references and relationships of the model-based approach. We provide a design rationale, and the results of our evaluation.

design