3 ms·
An excuse to link one of my favorite NASA/Honeywell slideshows: https://c3.ndc.nasa.gov/dashlink/static/media/other/ObservedFailures1.html https://c3.ndc.nasa.
by falcolas 2y ago
An excuse to link one of my favorite NASA/Honeywell slideshows:
https://c3.ndc.nasa.gov/dashlink/static/media/other/ObservedFailures1.html https://c3.ndc.nasa.gov/dashlink/static/media/other/Observed...
The long story short is that there are byzantine failure methods which prevent a 50 year computer. A sample:
- Capacitors can act as bullets
- Forced air cooling creating water
- The smaller the parts, the greater the chance they'll transmute to another part. Even, or especially in solid state parts.
- Digital isn't (i.e. 1 isn't really full voltage, and 0 isn't really no voltage).
- Thermal expansion matters, even for ICs on a board.
- Wire length, and the position of sensors on that wire, matters.
A 50 year computer would probably have to be one in which each part can and is replaced on a schedule. And the faster the computer is, the more often parts would need to be replaced. Additionally, if we want 100% uptime there would also have to be sufficient redundancies to ensure that the computer could continue operating during failures or replacements of components.
- mjevans 2y agoThe 'survivor bunker' control computer that has maintenance every 5, even 10, years does have a different specification than one that must survive untouched, 'mothballed', for 50+ years and still work properly. In both cases I would prefer a standard modular interface, ideally a presently popular one like USB-A since I doubt it'll be a while before that's completely phased out. Even then it'll be someone's hobby project to have a not-quite off the shelf adapter.
- tuatoru 2y agoSo much for exploring space beyond the solar system, then. If it takes more than a hundred years to get anywhere, all your automated control systems are dead.
- Pet_Ant 2y agoThey are talking about individual components and what _can_ happen. What you can in these cases is a whole other layer of engineering. You want multiple redundancies. With concensus of independent units running. So have something like 15 guidance computers. 5 running (so that each has 2 back-ups) and their output goes to concensus to determine the actual action. Of course the concensus mechanism will need redundancy so maybe each concensus mechanism controls between 0-25% of the throttle... It's all doable. It's just hard.
- LorenPechtel 2y agoA lot of their failures were "redundant" systems that weren't truly redundant.
- hi-v-rocknroll 2y agoDon't use tantalum or electrolytic capacitors, lead-free solder, BGA-packaged ICs, exposed (non-stainless) steel, paper, or plastic, and most problems are mitigated by design. And use good halogen- and bromine-free fiberglass PCBs. There isn't anything to wear out or replace in such a properly-designed machine of modern design and manufacturing. If manufactured correctly, boards can be entirely encapsulated under an inert, dry atmosphere such that there won't be any moisture or oxygen to attack components over time. Basically, it would be able to last physically for centuries. The main sources of fragility would be the power supply and the permanent storage device such as an SSD or HDD. The former is generic enough to be trivial to retrofit. The latter could use SLC, RS/Turbo coding, and write minimization and buffering to extend the life beyond ordinary expected lifecycle.