4 ms·
Well there is no indication about the severity of these ~800 bugs, but ~800 non-severe bugs in a system this complex is actually pretty good in my opinion.
by laydn 7y ago
Well there is no indication about the severity of these ~800 bugs, but ~800 non-severe bugs in a system this complex is actually pretty good in my opinion.
- Psyladine 7y ago>but ~800 non-severe bugs in a system this complex is actually pretty good in my opinion. "The fly-by-wire flight software for the Saab Gripen (a lightweight fighter) went a step further. It disallowed both subroutine calls and backward branches, except for the one at the bottom of the main loop. Control flow went forward only. Sometimes one piece of code had to leave a note for a later piece telling it what to do, but this worked out well for testing: all data was allocated statically, and monitoring those variables gave a clear picture of most everything the software was doing. The software did only the bare essentials, and of course, they were serious about thorough ground testing. No bug has ever been found in the “released for flight” versions of that code. Henry Spencer henry@spsystems.net" Courtesy of John Carmack
- Roboprog 7y agoInteresting. That’s a different world from the business, or development tool, projects I have ever worked on. Never worked on any real time stuff. Looks like they are very big on using a flat finite state machine model. At least at Saab. I’m guessing they didn’t use C++, either, but who knows.
- scottlocklin 7y agoLooks like another argument in favor of Ada: https://www.sigada.org/conf/sa98/papers/frisberg.pdf https://www.sigada.org/conf/sa98/papers/frisberg.pdf
- kjs3 7y agoYes...this is a big reason why Ada exists.
- kjs3 7y agoNope...definitely not C++. Check out Jovial, Coral-66, MISRA C & sometimes Fortran. More recently, Ada & SPARK. The F-35? C++.
- dingaling 7y agoTwo crashes of Gripens during development led to changes in the flight control software. Now you could argue as to whether those were bugs or requirements deficiencies, but in neither case were the faults caught in preflight testing.
- pc86 7y ago> during development Wasn't the above comment in reply to there being no bugs found in software released for flight?
- 0xffff2 7y agoEither, the Saab "released for flight" claim only applies to fully operational flights, in which case the F-35 is still in development and we haven't seen the "released for flight" version of its software, or test-flight crashes leading to changes in flight software are very strong evidence that the claim is incorrect.
- deleted 7y ago[deleted]
- cameldrv 7y agoYes, but the flight control software is just a tiny part of all of the software in the F-35. You have radars, datalinks, targeting, navigation, optical, sensor fusion, maintenance, weapons, propulsion, and cockpit displays, among others.
- tmpz22 7y agoI wonder if there is any javascript or python anywhere in the F35 software
- Rebelgecko 7y agoI believe the vast majority (if not all) of the code is in C++. They stopped using Ada because it was too hard to find programmers that already knew it
- 3pt14159 7y agoWhy no subroutines? Isn't any function call a subroutine? In any event, I'd love to take a look at that source code. I try my best to keep forward-only control flow, at least at the conceptual level (I.e., I don't eschew loops, but I try to keep data flowing from A to B to C to D without having it go back and check a preceding component for what to do in a given case).
- kjs3 7y agoI think they are lumping subroutine and function calls into the same bucket. Basically, avoid anything that pushes stuff on the stack?
- laydn 7y agoI've worked in a closely related field. The fly-by-wire software is comparatively very small, compared to all software in a modern fighter jet like the F35. Just from the top of my head, you've got, Flight controls, Radar, Comms, NAV, Ident, Electronic warfare, Sensor fusion, Weapons management, mission recording, cockpit avionics, helmet mgmet, etc.