5 ms·
See my other comment. C/C++ is used over Ada just for familiar syntax. From a safety perspective, the choice of language is inconsequential. With C/C++ the co
by Nokinside 5y ago
See my other comment.
C/C++ is used over Ada just for familiar syntax. From a safety perspective, the choice of language is inconsequential. With C/C++ the code analyzers used must do more work than with Ada but not that much.
All safety-critical code uses just a tiny subset of the language. It's like programming in a different language. Line-by-line coder reviews are a must.
- pjmlp 5y agoI guess Toyota forgot to get those line-by-line coder reviews. https://users.ece.cmu.edu/~koopman/pubs/koopman14_toyota_ua_slides.pdf https://users.ece.cmu.edu/~koopman/pubs/koopman14_toyota_ua_...
- erikw 5y agoThe linked PDF doesn't seem to mention anything related specifically to C++. It says that it is possible for bit flips to affect software. They then suggest that Toyota should have used the following practices: • “Near-perfect” software • Design out single points of failure • Justify real time scheduling with analysis • Watchdog timers that have real “bite” • Good software architecture • Good safety culture This seems like mostly good concrete advice, although I think we can all agree that simply creating "near-perfect software" is a goal, not a solution. If you read up on Toyota's unintended breaking legal issues, it appears that it was most likely driver error, as Toyota did not issue a firmware change to the affected vehicles, and no software problems were ever identified.
- MaxBarraclough 5y ago> From a safety perspective, the choice of language is inconsequential. Citation very much needed. Some safety-critical projects choose to use Ada over C or C++, despite that there are far fewer Ada programmers out there, and that there are fewer development tools for Ada. The people running those projects presumably disagree with you. We know that the choice of language is very consequential regarding cybersecurity. The many foot-guns of C and C++ are the root of a significant fraction of security vulnerabilities. Saying that these same foot-guns are of no consequence in safety-critical software seems like a remarkable claim. This document [0] explicitly disagrees with your position that language is of little consequence. (Not to gloss over that it appears to have been funded by AdaCore, who are of course motivated to reach that conclusion.) [0] See especially page 12: (PDF) https://www.adacore.com/uploads/techPapers/Controlling-Costs-with-Software-Language-Choice-AdaCore-VDC-WP.PDF https://www.adacore.com/uploads/techPapers/Controlling-Costs...
- Raphael_Amiard 5y ago> C/C++ is used over Ada just for familiar syntax. From a safety perspective, the choice of language is inconsequential. With C/C++ the code analyzers used must do more work than with Ada but not that much. That is completely and utterly false despite the millions (billions ?) invested in trying to make sound & safe static analysis tools for C/C++. I know you're trying to push that message but it couldn't be further from the truth. The nature of C & C++ is such that you cannot avoid unsafety, even with very restricted subsets. Disclaimer: I work on Ada tools, but have also worked on C/C++ tools. I have also studied MISRA C and worked on such static analyzers for C & C++.
- Nokinside 5y agoHave you studied: https://www.absint.com/astree/index.htm https://www.absint.com/astree/index.htm