Check Static Upper Bound — Control Systems/Model Verification
Control_Systems/Model_Verification/Check_Static_Upper_Bound · 1 input / 1 output port(s) at insert · exports to Python, MATLAB, Java, Rust, C, C++, VHDL, Verilog, SystemVerilog, PLC Structured Text
Description#
The block's own DESCRIPTION_HTML, rendered verbatim — the same text the config dialog's info panel and the library navigator show. Fix a wrong sentence in the block's .cpp (R-D9), never here.
Check Static Upper Bound
Control Systems / Model Verification
Verifies that a signal never rises above a constant ceiling, and publishes the verdict as a signal: y = 1 where the entry passes, y = 0 where it fails. The test is u ≤ max when Include Maximum is on and u < max when it is off. Applied entry by entry, so a matrix signal is checked element for element.
Ports
- Input – the signal u under test, of any size [m,n].
- Output – the verdict y, of the SAME size [m,n]: one 1.0/0.0 flag per entry of u. The block never reshapes a signal.
Parameters
- Maximum – scalar, the ceiling the signal is held to. A per-entry bound sized like the input is not implemented and is reported rather than broadcast from its first entry; for a bound that varies per entry or over time, use Check Dynamic Upper Bound, which takes it on a port.
- Include Maximum – whether a sample sitting exactly ON the bound
passes.
- on – the test is u ≤ max (the default).
- off – the test is u < max, so the bound itself fails.
- Enabled – whether a failing sample is REPORTED. It does not
change the output signal: an entry that fails still reads 0 with this off, which
is what Simulink's counterpart does.
- on – a failure is logged once per run, with the block's path and the time it first happened (the default).
- off – the block computes its verdict silently.
- Stop When Assertion Fails – whether a reported failure also ends
the run.
- on – the run stops at the first failing sample and is marked failed (the default).
- off – the run continues and the failure is a warning.
- Sampling Time (s) – zero or less inherits the solver's rate; a positive value runs the block at that period.
Code export
All ten targets: Python, MATLAB, Java, Rust,
C, C++, VHDL, Verilog, SystemVerilog and
PLC Structured Text. The bound and the choice of ≤ versus
< are baked into the generated code at export time rather than
exposed as tunable parameters, matching the other comparison blocks. Only the
VERDICT SIGNAL is exported: Enabled and Stop When Assertion Fails
have no meaning in a deployed core, which has no simulation to stop, so a core
computes the flag and leaves acting on it to whatever consumes the signal.
Simulink bridge
Import and export, mapped to simulink/Model Verification/Check Static
Upper Bound. "Maximum" to max and "Include Maximum" to
max_included, "Enabled" to enabled and "Stop When
Assertion Fails" to stopWhenAssertionFail, all as plain
pass-through values, so the round trip is lossless. The block always sets
Simulink's export to on: ICore's block always has its
verdict output, whereas Simulink's grows one only when that box is ticked, so
importing a block with it unticked reports the difference rather than silently
dropping the port. The Simulink counterpart has no
SampleTime parameter, so "Sampling Time (s)" does not cross –
the block runs at the surrounding Simulink rate.
Notes
- Algebraic, with no signal state. The only state is a one-shot latch so that a failing run logs its complaint once rather than once per sample.
- Not linear, and so deliberately carries no state space – model reduction reports it as unmergeable rather than absorbing a comparison.
- The comparison is one-sided: only the UPPER side is checked, and an arbitrarily large NEGATIVE input passes. Pair it with Check Static Lower Bound, or use Check Static Range, to bound both sides.
Code facts#
| Fact | Value |
|---|---|
| registered type | Control_Systems/Model_Verification/Check_Static_Upper_Bound |
| family | Control_Systems/Model_Verification |
| solver environment class | ICoreBlock_0_Control_Systems_1_Model_Verification_2_Check_Static_Upper_Bound |
| source | src/ICoreSDK/ICoreBlockLibrary/Blocks/Control_Systems/Model_Verification/Check_Static_Upper_Bound/ICoreBlock_0_Control_Systems_1_Model_Verification_2_Check_Static_Upper_Bound.cpp |
| header | src/ICoreSDK/ICoreBlockLibrary/Blocks/Control_Systems/Model_Verification/Check_Static_Upper_Bound/ICoreBlock_0_Control_Systems_1_Model_Verification_2_Check_Static_Upper_Bound.h |
| default size on canvas | 80 × 80 px |
| ports at insert | 1 in, 1 out |
| code generators implemented | Python, MATLAB, Java, Rust, C, C++, VHDL, Verilog, SystemVerilog, PLC Structured Text |
Ports#
| # | Direction | Signal type | Description label |
|---|---|---|---|
| 1 | in | ICoreDouble | — |
| 2 | out | ICoreDouble | — |
Ports the constructor creates. A block whose port list changes with its configuration adds or removes ports at load time; the count above is the one a freshly inserted block has.
Configuration variables#
| Config variable | Default | Simulink parameter |
|---|---|---|
Maximum | 0 | max |
Include Maximum | on%~%off~~on | max_included |
Enabled | on%~%off~~on | enabled |
Stop When Assertion Fails | on%~%off~~on | stopWhenAssertionFail |
Every block also carries Sampling Time (s) from ICoreBlockSolverEnvironment: zero or less inherits the solver's rate, a positive value runs the block at that period.
Simulink bridge#
| support | Support::Both |
| Simulink path | simulink/Model Verification/Check Static Upper Bound |
| port-count rule | PortsParam::None |
SampleTime parameter | no — the counterpart defines none; the rate stays on the ICore side |
| always set | export = on |
| ICore config | Simulink parameter | Value translation |
|---|---|---|
Maximum | max | passes through |
Include Maximum | max_included | passes through |
Enabled | enabled | passes through |
Stop When Assertion Fails | stopWhenAssertionFail | passes through |
Caveat (shown to the user): the block runs at the surrounding Simulink rate; "Sampling Time (s)" does not cross. ICore's block always carries its verdict output, so the bridge pins Simulink's "export" to on
Catalog contract: src/ICoreSDK/ICoreCoder/ICoreCommandSystem/SimulinkBridge/ICoreSimulinkBlockCatalog.h
Description vs code#
The checker has a blind spot here — it could not resolve something (a grouped port bullet, a computed config name), which is reported and never counted as a pass. A reader has to settle it:
B0every stimulus in the sample errored — cross-checks skipped
The verdict above is
tools/docs/check_block_descriptions.py(P7.1), which compares LISTS. It cannot read a sentence: "stateless" on a block with a state, an initial-value semantic the recursion does not implement, a "not synthesizable" caveat the HDL banner contradicts. That is the agent audit (P7.3) on BLOCK_DESCRIPTION_AUDIT.md, and this tool's green is not a substitute for one.
File banner (developer view)#
The top comment of the block's .cpp — the maths, the realization and the export strategy, addressed to whoever changes it. It must not contradict the description above (P7.5).
Check Static Upper Bound -- verifies a signal stays at or below a constant ceiling y = 1 where the entry passes the test, 0 where it does not. The test is u <= max with "Include Maximum" on and u < max with it off. Applied entry by entry, so the output keeps the input's size.
The verdict SIGNAL and the ASSERTION are two separate things, and only the first crosses into generated code:
- the signal is what the output port carries, what the ten backends emit, and what code
export verification compares;
- the assertion is a simulator-side diagnostic -- "Enabled" decides whether a failure is
reported at all, "Stop When Assertion Fails" whether it also ends the run. Verified against Simulink R2026a: toggling
enabledthere leaves the exported assertion signal bit-identical, so ICore keeping the two apart matches the reference rather than diverging from it.Code export: the bound and the comparison are inlined as export-time constants, per language. The two assertion controls are NOT exported -- a deployed core has no simulation to stop.
Sample results#
No stimulus produced a sampled output in this rig — Check Static Upper Bound failed at t = 1.000000 s: ICore Blocks/Home/Check Static Upper Bound. That is a fact about the single-block rig, not a verdict on the block: an offline batch fit, a block whose output only appears at onSolverFinish, or one that needs a driven environment cannot be exercised alone.
Category unsampled · sample time 0.1 · 60 steps · commit ccf005c8 · produced by docsSample --out <folder> --steps 60
Sample data: docs/generated/samples/Control_Systems__Model_Verification__Check_Static_Upper_Bound.json