5 ms·
I worked with David Cutler and he very much did what he described doing. Others on the kernel team followed similar practices. There is code Dave and I modifi
by bryanwi 2y ago
I worked with David Cutler and he very much did what he described doing. Others on the kernel team followed similar practices. There is code Dave and I modified together where we then sat and audited it together.
This was all code in the heart of an OS - thread switching, interrupt dispatch, synchronization mechanisms - things where even the most rare and exotic error might actually occur and cause a disaster.
But some hazard/cost computation is needed. There was an article in the '90s about a team doing software for an arm for space work (maybe on the shuttle) - they were hyper careful. I figured out that if all of windows had been made at that rate out of code output it would take 100 years to finish and would cost several trillion dollars. Not long after that that space arm suffered some kind of software failure, in space. Wasn't for want of effort by the dev team.
Remember that many errors arise from things outside the code you wrote/studied - some other code corrupted something, buggy behavoir in hardware, and so forth.
As for coding by hand, simulating by hand, flow graphing by hand, I don't think those were all that unusual, just one person took it to extremes and wrote about it.