...
The safe state of the system is defined as:
· Telescope Azimuth motion stopped, drives disabled and brakes applied
· Telescope Azimuth Cable Wrap motion stopped and drives disabled
· Telescope Altitude motion stopped, drives disabled and brakes applied
· Coudé Rotator motion stopped, drives disabled and brakes applied
· Enclosure Azimuth motion stopped, drives disabled and brakes applied
· Enclosure Azimuth Cable Wrap motion stopped, drives disabled
· Enclosure Altitude motion stopped, drives disabled and brakes applied
· Aperture Cover closed, motion stopped, and drives disabled
· M1 Mirror Cover closed, motion stopped and drives disabled
· Heat Stop Safety Shutter closed
· Enclosure Jib Crane motion stopped, drives disabled and brakes applied
· Enclosure Enclosure Bridge Crane motion stopped, drives disabled, and brakes applied
· GOS PA&C hazardous motion stopped, drives disabled and brakes applied
· VBI-Blue hazardous motion stopped, drives disabled and brakes applied
· VBI-Red hazardous motion stopped, drives disabled and brakes applied
· VISP hazardous motion stopped, drives disabled and brakes applied.
...
Safety Function | Emergency Stop |
Hazard | avert potential hazards or reduce existing hazards that may arise from malfunctioning of the facility, human error or normal operation |
Triggering Event | human-operated control device |
Priority | Emergency Stop shall take priority over all other control functions. |
Modes | always active |
Reaction | Halt all hazardous motion Block light path |
Safe State | Telescope Azimuth motion stopped Telescope Altitude motion stopped Coudé Rotator motion stopped Enclosure Azimuth motion stopped Enclosure Shutter closed M1 Mirror Cover closed Enclosure Jib Crane motion stopped Enclosure Bridge Crane motion stopped GOS PA&C motion stopped VBI-Blue motion stopped VBI-Red motion stopped VISP motion stopped |
Required Integrity | SIL2 PLc SIL2 (SIL 1 or PL c minimum per IEC 13850) |
All subsystems’ emergency stop devices are combined in logic at the GIC, so that activating any emergency stop device shall cause all GIS-connected subsystems to go to their safe state. In most cases they perform an immediate stop (category 0 or 1 stop as determined by subsystem analysis). The exception is that M1 Mirror Cover and Enclosure Entrance Aperture close (their safe state) in a predetermined sequence.
...