4 ms·
As someone who worked on RTOS systems and now works on autonomy. These things frighten me everyday. What frightens me even more, is the people who work on auto
by agitator 8y ago
As someone who worked on RTOS systems and now works on autonomy.
These things frighten me everyday. What frightens me even more, is the people who work on autonomy without a real grasp on determinism. It's unfortunate that the people who have the most high tech backgrounds (phds in computer vision AI, etc) applicable to autonomy, have never implemented safety critical autonomous systems outside of a research project that tested some aspect of detection or control in a test environment and had to only work once to get a paper published.
For general robotics linux is great. But there is an enormous difference between a robot roaming around your house bumping off walls, and a vehicle carrying a whole family at 70mph.
Most of the linux based systems I have worked with have some form of redundancy, whether it be other chips running linux, or ideally ECU's running an RTOS that perform monitoring, gating, and/or some level of safety fallback control. The RTOS based redundancies often are what provide ASILD. Trusting a single linux processor is what everyone does to get funding, but when you go out and test on public roads with human lives at stake, or start selling a product, you better have some quantitative guarantees other than "It's been fine so far..." That kind of stuff makes me angry.
- crubier 8y agoHaving worked several years on critical embedded systems in aerospace, I would tend to agree with you. But on the other hand, has any Tesla car ever had an accident because of this? At some point, "heavily tested and validated end to end in real-life conditions for years" and "formally proven on a simplified model using reasonable assumptions made by human engineers" become relatively close in terms of how much trust you can put in a system. But somehow we tend to prefer to later. I am not sure if this paradigm is still relevant these days.
- xg15 8y ago> "heavily tested and validated end to end in real-life conditions for years" That seems like a more wordy way to state "It's been fine so far". > "formally proven on a simplified model using reasonable assumptions made by human engineers" I didn't know about that. What kind of formal proofs did they do? Did they involve the linux scheduler?
- BugsJustFindMe 8y agoYou're making a lot of unwarranted negative assumptions and setting up a lot of strawmen here.
- xg15 8y agoWhich ones?
- Qub3d 8y agoThankfully, the critical reactive components of the Tesla vehicles do seem to be run by an RTOS -- spesifically FreeRTOS [0]. [0]: https://youtu.be/KX_0c9R4Fng?t=8m47s https://youtu.be/KX_0c9R4Fng?t=8m47s
- bluefeather 8y agoSpaceX's Linux-based engine controllers at least have a decent amount of redundancy. They're all triple-redundant, and each of the three components consists of two cpu cores running in lockstep that are validated against each other as well.
- kpil 8y agoSignalling and train control systems typically have two independent implementations - full stack: hardware, os, software, different development teams. I guess you'd need three separate implementations to achive some redundancy when you can't just slam the emergency brakes if the systems disagree. (... For some reason, I find it higly demotivating that another team is doing the exact same thing. Maybe I just want to be a snowflake...)