Child nodes:
The propeller motor control is performed by a (standard) control algorithm which can be shown to be mathematically correct, can be specified and implemented by traditional software techniques. In addition, the same software includes a simpler algorithm to check the result of the primary algorithm against.
100% code coverage by test can be achieved:
The safe state for the Collision Avoidance SIF is to remove the power to the propellers in <TBD> secs.