new mode called “fault” is added to the set of
modes in the mode class mcStatus. Table 8 states
that a fault is detected if the system remains in the
initializing state for more than 0.6 sec, if the DO1
takes more than 2 sec to power up, or if all three
altimeters have failed for 2 sec. The system
recovers from malfunctions when the pilot presses
Reset. To mark the extensions to Table 2, we have
shaded the four transitions in Table 8 which involve
the mode “fault” and the added constraint for
system transfer from “standby” to “awaitDOIon”