4 ms·
That's the price of making complex, real-world hardware systems fail-safe. By fail-safe, I don't mean 'never fail' but, more literally, fail in a way that remai
by NamTaf 3y ago
That's the price of making complex, real-world hardware systems fail-safe. By fail-safe, I don't mean 'never fail' but, more literally, fail in a way that remains safe for all other systems interfacing with the failing one.
Proving that it fails safely requires a mountain of effort and documentation, but it's required because failure doesn't just lead to some speculative CPU bugs leaking a password or to a browser crash, it leads to many people dying.
- rglullis 3y agoTo add to your point, the accident in Greece this summer that killed 50+ kids was attributed to human error that could've been avoided if they had upgraded their signalling system like it was promised decades ago.
- ExoticPearTree 3y agoI get that, but still, it is not like we don't have experience with making fail-safe things that we can draw from. And once you get a station + track fitted with the new system you just copy/paste; so I can understand a higher cost in the beginning for the proof of concept, but after that everything should be very cheap.
- arethuza 3y ago"you just copy/paste" Aren't we talking about physical signalling kit - no copying and pasting? 272 stations and ~400km of track - a lot of which is pretty difficult to access?
- IshKebab 3y agoHe obviously meant copy and pasting the design. What did you think he meant?
- arethuza 3y agoI have no idea - that's why I was asking. I've been responsible for installing systems that had the same "design" into multiple physical locations - hundreds of physical devices at each location. Having a common design does help but it doesn't help that much as most of the problems are with the physical realities of each location - and what I did was much simpler and less critical than signalling.
- NamTaf 3y agoAhhhh! "just" - the magic word! It is not ever 'just'. This isn't copying code. This isn't building identical silicon for multiple end users. This is more like trying to add additional threads to something that is not embarrassingly parallel. What you're saying is like saying 'why can't you just make all of my computer programs run on all 32 of my CPU cores?'. And even if you minimise the increasing complexity added by expanding the system, waterfall-style design (which is absolutely the most appropriate approach when dealing with these sorts of projects) front-end loads a frankly Herculean amount of risk management into the process because you want to make sure that's all absolutely square and true before you progress to implementation. Lastly, it's worth noting that with systems this complex, a lot of the detail is bespoke because the number of complicating input variables the system is exposed to necessarily requires a relatively bespoke solution. Yes, the idea of e.g. ETCS being ETCS is going to hold, but how that works in reality, how it ties in to all of the other legacy systems, etc. will mean that you can't for example just take ETCS-equipped train A and and drop it into ETCS-equipped network B.
- ExoticPearTree 3y agoI was thinking that only the track sensors and traffic lights along the way need to be upgraded and the drivers would just drive trains as usual and they would be sequenced on a shorter distance/time between trains. I forgot that trains also have to be connected to the new system.