Generated reference › Check Static Upper Bound — Control Systems/Model Verification
kind: generated#block#control-systems-model-verification

Check Static Upper Bound — Control Systems/Model Verification

Control_Systems/Model_Verification/Check_Static_Upper_Bound · 1 input / 1 output port(s) at insert · exports to Python, MATLAB, Java, Rust, C, C++, VHDL, Verilog, SystemVerilog, PLC Structured Text

Description#

The block's own DESCRIPTION_HTML, rendered verbatim — the same text the config dialog's info panel and the library navigator show. Fix a wrong sentence in the block's .cpp (R-D9), never here.

Check Static Upper Bound

Control Systems / Model Verification

Verifies that a signal never rises above a constant ceiling, and publishes the verdict as a signal: y = 1 where the entry passes, y = 0 where it fails. The test is u ≤ max when Include Maximum is on and u < max when it is off. Applied entry by entry, so a matrix signal is checked element for element.

Ports

  • Input – the signal u under test, of any size [m,n].
  • Output – the verdict y, of the SAME size [m,n]: one 1.0/0.0 flag per entry of u. The block never reshapes a signal.

Parameters

  • Maximum – scalar, the ceiling the signal is held to. A per-entry bound sized like the input is not implemented and is reported rather than broadcast from its first entry; for a bound that varies per entry or over time, use Check Dynamic Upper Bound, which takes it on a port.
  • Include Maximum – whether a sample sitting exactly ON the bound passes.
    • on – the test is u ≤ max (the default).
    • off – the test is u < max, so the bound itself fails.
  • Enabled – whether a failing sample is REPORTED. It does not change the output signal: an entry that fails still reads 0 with this off, which is what Simulink's counterpart does.
    • on – a failure is logged once per run, with the block's path and the time it first happened (the default).
    • off – the block computes its verdict silently.
  • Stop When Assertion Fails – whether a reported failure also ends the run.
    • on – the run stops at the first failing sample and is marked failed (the default).
    • off – the run continues and the failure is a warning.
    Ignored entirely when Enabled is off.
  • Sampling Time (s) – zero or less inherits the solver's rate; a positive value runs the block at that period.

Code export

All ten targets: Python, MATLAB, Java, Rust, C, C++, VHDL, Verilog, SystemVerilog and PLC Structured Text. The bound and the choice of versus < are baked into the generated code at export time rather than exposed as tunable parameters, matching the other comparison blocks. Only the VERDICT SIGNAL is exported: Enabled and Stop When Assertion Fails have no meaning in a deployed core, which has no simulation to stop, so a core computes the flag and leaves acting on it to whatever consumes the signal.

Simulink bridge

Import and export, mapped to simulink/Model Verification/Check Static Upper Bound. "Maximum" to max and "Include Maximum" to max_included, "Enabled" to enabled and "Stop When Assertion Fails" to stopWhenAssertionFail, all as plain pass-through values, so the round trip is lossless. The block always sets Simulink's export to on: ICore's block always has its verdict output, whereas Simulink's grows one only when that box is ticked, so importing a block with it unticked reports the difference rather than silently dropping the port. The Simulink counterpart has no SampleTime parameter, so "Sampling Time (s)" does not cross – the block runs at the surrounding Simulink rate.

Notes

  • Algebraic, with no signal state. The only state is a one-shot latch so that a failing run logs its complaint once rather than once per sample.
  • Not linear, and so deliberately carries no state space – model reduction reports it as unmergeable rather than absorbing a comparison.
  • The comparison is one-sided: only the UPPER side is checked, and an arbitrarily large NEGATIVE input passes. Pair it with Check Static Lower Bound, or use Check Static Range, to bound both sides.

Code facts#

FactValue
registered typeControl_Systems/Model_Verification/Check_Static_Upper_Bound
familyControl_Systems/Model_Verification
solver environment classICoreBlock_0_Control_Systems_1_Model_Verification_2_Check_Static_Upper_Bound
sourcesrc/ICoreSDK/ICoreBlockLibrary/Blocks/Control_Systems/Model_Verification/Check_Static_Upper_Bound/ICoreBlock_0_Control_Systems_1_Model_Verification_2_Check_Static_Upper_Bound.cpp
headersrc/ICoreSDK/ICoreBlockLibrary/Blocks/Control_Systems/Model_Verification/Check_Static_Upper_Bound/ICoreBlock_0_Control_Systems_1_Model_Verification_2_Check_Static_Upper_Bound.h
default size on canvas80 × 80 px
ports at insert1 in, 1 out
code generators implementedPython, MATLAB, Java, Rust, C, C++, VHDL, Verilog, SystemVerilog, PLC Structured Text

Ports#

#DirectionSignal typeDescription label
1inICoreDouble
2outICoreDouble

Ports the constructor creates. A block whose port list changes with its configuration adds or removes ports at load time; the count above is the one a freshly inserted block has.

Configuration variables#

Config variableDefaultSimulink parameter
Maximum0max
Include Maximumon%~%off~~onmax_included
Enabledon%~%off~~onenabled
Stop When Assertion Failson%~%off~~onstopWhenAssertionFail

Every block also carries Sampling Time (s) from ICoreBlockSolverEnvironment: zero or less inherits the solver's rate, a positive value runs the block at that period.

supportSupport::Both
Simulink pathsimulink/Model Verification/Check Static Upper Bound
port-count rulePortsParam::None
SampleTime parameterno — the counterpart defines none; the rate stays on the ICore side
always setexport = on
ICore configSimulink parameterValue translation
Maximummaxpasses through
Include Maximummax_includedpasses through
Enabledenabledpasses through
Stop When Assertion FailsstopWhenAssertionFailpasses through

Caveat (shown to the user): the block runs at the surrounding Simulink rate; "Sampling Time (s)" does not cross. ICore's block always carries its verdict output, so the bridge pins Simulink's "export" to on

Catalog contract: src/ICoreSDK/ICoreCoder/ICoreCommandSystem/SimulinkBridge/ICoreSimulinkBlockCatalog.h

Description vs code#

The checker has a blind spot here — it could not resolve something (a grouped port bullet, a computed config name), which is reported and never counted as a pass. A reader has to settle it:

  • B0 every stimulus in the sample errored — cross-checks skipped

The verdict above is tools/docs/check_block_descriptions.py (P7.1), which compares LISTS. It cannot read a sentence: "stateless" on a block with a state, an initial-value semantic the recursion does not implement, a "not synthesizable" caveat the HDL banner contradicts. That is the agent audit (P7.3) on BLOCK_DESCRIPTION_AUDIT.md, and this tool's green is not a substitute for one.

File banner (developer view)#

The top comment of the block's .cpp — the maths, the realization and the export strategy, addressed to whoever changes it. It must not contradict the description above (P7.5).

Check Static Upper Bound -- verifies a signal stays at or below a constant ceiling y = 1 where the entry passes the test, 0 where it does not. The test is u <= max with "Include Maximum" on and u < max with it off. Applied entry by entry, so the output keeps the input's size.

The verdict SIGNAL and the ASSERTION are two separate things, and only the first crosses into generated code:

  • the signal is what the output port carries, what the ten backends emit, and what code

export verification compares;

  • the assertion is a simulator-side diagnostic -- "Enabled" decides whether a failure is

reported at all, "Stop When Assertion Fails" whether it also ends the run. Verified against Simulink R2026a: toggling enabled there leaves the exported assertion signal bit-identical, so ICore keeping the two apart matches the reference rather than diverging from it.

Code export: the bound and the comparison are inlined as export-time constants, per language. The two assertion controls are NOT exported -- a deployed core has no simulation to stop.

Sample results#

No stimulus produced a sampled output in this rig — Check Static Upper Bound failed at t = 1.000000 s: ICore Blocks/Home/Check Static Upper Bound. That is a fact about the single-block rig, not a verdict on the block: an offline batch fit, a block whose output only appears at onSolverFinish, or one that needs a driven environment cannot be exercised alone.

Category unsampled · sample time 0.1 · 60 steps · commit ccf005c8 · produced by docsSample --out <folder> --steps 60

Sample data: docs/generated/samples/Control_Systems__Model_Verification__Check_Static_Upper_Bound.json