5 ms·
(n.b. The project looks awesome, and it’s awesome that it’s written in Rust and working well. Great job folks!) I’ve been the managing functional safety engine
by foundry27 3y ago
(n.b. The project looks awesome, and it’s awesome that it’s written in Rust and working well. Great job folks!)
I’ve been the managing functional safety engineer for several safety-critical real-time embedded systems and safety-related components/SEooCs (including a RTOS), and something stood out to me after reading through the repository: This is not a safety-critical operating system, despite the project’s claim.
There was clearly requirements engineering and verification work done, and the authors are under absolutely no obligation to publish the requirements and methodologies. But there’s no safety manual / integrator’s guide provided, no evidence of any qualitative or quantitative safety analysis or modelling at any abstraction level having been performed, no evidence of a safety concept, and no evidence of a safety case. I recognize that this is likely intended as a PoC from the description of it being exploratory to produce a “Lessons Learned” report, but the website for the ESA initiative that’s driving this development claims that “The design of the system will be guided to support potential future qualification activities”. If that was done, there should be evidence of some of all of those work products, because that’s how you support future qualification. You cannot retroactively sprinkle safety on top of a system that hasn’t been designed with safety in mind.
- f1shy 3y agoA little bit like the famous saying in court: “It is not how safe you made it, it’s about how much you can prove you made it safe!”
- deleted 3y ago[deleted]
- SteelPh0enix 3y agoHey, one of the devs of Aerugo here! Thanks for feedback! You are absolutely right - at current state, this is not a safety-critical OS, however the project doesn't claim that explicitly - it's "safety-critical applications oriented". It's a small detail, but you're right to point it out. The lack of mentioned documents is due to the fact that this RTOS was not qualified for any criticality. And this is due to our resource constraints for this project - ESA provided us with a year of time and funds for ~2 full-time developers. It would be physically impossible to create this project from scratch (as we did) and qualify it, even for crit C, in that timeline. We would love to do a follow-up activity on Aerugo, and one of our ideas was the qualification (maybe not for Crit A, but B would be nice for an RTOS). However, that's a thing for the future, and we don't know what exactly will happen next with Aerugo yet - we're working on it. I'd also like to point out that we have designed this system with safety in mind - we've been regularly analyzing potentially problematic design choices and code with that in mind (especially unsafe code and functions). There is a ground for criticality qualification, it just needs a lot of work to make it a fact. PS: We do intend to release our "Lessions Learned" report in near future to the public!
- aknfffn 3y agoI’d love to learn more about this — can you recommended any resources for building something from the ground up with the relevant safety-critical considerations? Appreciate any pointers
- foundry27 3y agoLate reply, I know, but I would highly recommend skimming through “Embedded Software Development for Safety-Critical Systems” by Chris Hobbs. I think it does a good job at getting people thinking about how they can start adopting a safety mindset for their projects, what techniques are applicable, and what common pitfalls are.
- kejaed 3y agoHere’s a decent textbook that covers the software side in aerospace (DO-178): https://www.amazon.ca/Developing-Safety-Critical-Software-Practical-Compliance/dp/143981368X https://www.amazon.ca/Developing-Safety-Critical-Software-Pr... You can read up on the system safety side in documents like ARP5754 and ARP4761 and hardware side in DO-254.
- westurner 3y agoawesome-safety-critical > Software safety standards lists DO-178C and also DO-278: https://awesome-safety-critical.readthedocs.io/en/latest/#software-safety-standards https://awesome-safety-critical.readthedocs.io/en/latest/#so...
- fallingmeat 3y agoSomeone who spent that much time at CMC would know! I also love her book.
- kejaed 3y agoI learned lots, worked with some great people, and even certified a thing or two!