4 ms·
Yes. C/C++ is used over Ada just for familiar syntax. The coding standards used for safety-critical projects limit the features into a tiny safe subset, Essent
by Nokinside 5y ago
Yes.
C/C++ is used over Ada just for familiar syntax. The coding standards used for safety-critical projects limit the features into a tiny safe subset, Essentially DSL.
Linters and code checkers and static analyzers check the code more thoroughly than the compiler does.
For example, all memory is allocated during initialization. No allocation or reallocation from the heap afterward. That's why you see in the weapon specs familiar magic numbers like can track 256 targets simultaneously.
Commerical code analyzers used in the military, aviation, etc. are good but expensive. I have used https://www.absint.com/astree/index.htm https://www.absint.com/astree/index.htm
JOINT STRIKE FIGHTER AIR VEHICLE C++ CODING STANDARDS FOR THE SYSTEM DEVELOPMENT AND DEMONSTRATION PROGRAMDocument Number2RDU00001 Rev C December 2005
https://www.stroustrup.com/JSF-AV-rules.pdf https://www.stroustrup.com/JSF-AV-rules.pdf
- zurn 5y agoAda and C++ are worlds apart, how is it possible to come so close as to be "just syntax" with static analyzers and their known limitations? Unless we are talking about all programming languages being "just syntax" for a turing machine...
- OnlyOneCannolo 5y agoI think they're saying that the switch was justified because the workforce is no longer familiar with Ada.
- Jtsummers 5y agoMore importantly the workforce is familiar with C/C++, how it’s listed on so many job listings. Which is kind of sad as a requirement. A programmer who can’t become productive with Ada after a few weeks (productive, not masterful) is not the kind of programmer anyone should be hiring for any job. The syntax is (almost) dead simple, for a reason.
- OnlyOneCannolo 5y agoEdit: Retracting my whole comment for being wrong.
- Jtsummers 5y agoThose jobs require competence from most contributors. Mastery from a few. And you can teach mastery to non-incompetent people, most of the time. Also, most jobs that Ada would be used for aren't time critical (in the sense of "Oh god oh god oh god we've got to ship yesterday!", unless it's F-35, which fortunately didn't use Ada because that would've saved them a lot of heartache). They program in 2-5 years for the project so 1 month to competency and then additional OJT from more experienced (with Ada and the system) over the rest of the time will produce mastery.
- OnlyOneCannolo 5y agoTrue. I take back what I wrote for being too reductive. Well said.
- jnwatson 5y agoI would doubt there are enough masters of C++ to fill an airplane.
- Nokinside 5y ago> Ada and C++ are worlds apart, Yes. But as I said, programmers use just tiny subset of the language. Subsets are with additional checks are semantically very similar. Very dumped down code. > being "just syntax" for a turing machine.. If you insist, I would describe them as intermediate representations for the back-ends for a non-Turing equivalent language (after all semantic checking). Compilers parse text, check it matches the syntax, do some semantic checks, and then output native code (unless they transpile). When you write safety-critical code you can buy tools that make more far more checks to the semantics than the compiler and prevent the use of some constructs. Ada has SPARK that is integrated better. For example, the tool I mention can prove that if code has no run-time errors or divisions by zero. It's essentially non-Turing equivalent language. I would prefer Ada/Spark over C, but it don't matter that much, so I have always used C with tooling.
- deleted 5y ago[deleted]
- cmrdporcupine 5y agoStatic analyzers have come a long long way in the last 10 years. I don't know what they've done, but you could get a long way just by forbidding all dynamic allocation.
- pyuser583 5y agoCould expand on this? I’ve heard it a lot. What advances have happened?
- Raphael_Amiard 5y agoAs said in another comment, that's completely and demonstrably false. As soon as a coding standard for C/C++ doesn't completely forbid the use of pointers (which is completely impossible at least in C), then it will be much more unsafe than Ada (or other alternatives like Rust). You can have - very painfully - near pointer free programming in C++, but it requires the use of high level constructs (smart pointers, RAII, etc) that most if not all safety critical standards forbid the use of. Some people like the Frama-C people are trying to make programming in - a restricted an enhanced subset of - C, safe. They're basically doing Ada/SPARK with annotations in C, and it's horribly painful. So, despite its informed and documented appearances, your comments are spreading misinformation about what it's like to program in C/C++ for safety critical systems.
- Nokinside 5y agoAstrée static analysis tool detects invalid pointer dereferences. It can give false alarms but it always detects errors. It does this buy using abstract interpretation on the semantics. It's essentially partial execution.
- ajxs 5y agoHere's a very telling quote regarding the choice of programming language from a software team manager from the JSF project: "Ada was seen as the technically superior and more robust language, but concern over the ability to successfully staff the software engineers required to develop the massive amounts of safety critical software caused the F-35 team to carefully look and finally to choose C and C++ for the implementation of safety critical software." - John H. Robb, Senior Manager of the F-35 Joint Strike Fighter Air Vehicle Software team at Lockheed Martin Aeronautics Fort Worth[1] [1]https://web.archive.org/web/20111219004314/http://journal.thedacs.com:80/issue/53/158 https://web.archive.org/web/20111219004314/http://journal.th...