On using formal methods for safe and robust robot autonomy