33 ms·
The C++ standard for the F-35 Fighter Jet [video]
PDF: https://www.stroustrup.com/JSF-AV-rules.pdf https://www.stroustrup.com/JSF-AV-rules.pdf
- mwkaufma 10mo agoTL;DR - no exceptions - no recursion - no malloc()/free() in the inner-loop
- jandrewrogers 10mo agoi.e. standard practice for every C++ code base I've ever worked on
- DashAnimal 10mo agoWhat industry do you work in? Modern RAII practices are pretty prevalent
- jandrewrogers 10mo agoWhat does RAII have to do with any of the above?
- WD-42 10mo ago0 allocations after the program initializes.
- nicoburns 10mo agoRAII doesn't necessarily require allocation?
- Gupie 10mo agoOpen a file in the constructor, close it in the destructor. RAII with 0 allocations.
- dh2022 10mo agostd::vector<int> allocated and freed on the stack will allocate an array for its int’s on the heap…
- usefulcat 10mo agoI've heard that MSVC does (did?) that, but if so that's an MSVC problem. gcc and clang don't do that. https://godbolt.org/z/nasoWeq5M https://godbolt.org/z/nasoWeq5M
- menaerus 10mo agoWDYM? Vector is an abstraction over dynamically sized arrays so sure it does use heap to store its elements.
- aw1621107 10mo agoI think usefulcat interpreted "std::vector<int> allocated and freed on the stack" as creating a default std::vector<int> and then destroying it without pushing elements to it. That's what their godbolt link shows, at least, though to be fair MSVC seems to match the described GCC/Clang behavior these days.
- deleted 10mo ago[deleted]
- Gupie 10mo agoSure, but my point was that RAII doesn't need to involve the heap. Another example would be acquiring abd releasing a mutex.
- tialaramex 10mo agoRAII doesn't imply allocating. My guess is that you're assuming all user defined types, and maybe even all non-trivial built-in types too, are boxed, meaning they're allocated on the heap when we create them. That's not the case in C++ (the language in question here) and it's rarely the case in other modern languages because it has terrible performance qualities.
- jjmarr 10mo agoStack "allocations" are basically free.
- grougnax 10mo agoNo. And they're unsafe. Avoid them at all costs.
- nmhancoc 10mo agoNot an expert but I’m pretty sure no exceptions means you can’t use significant parts of std algorithm or the std containers. And if you’re using pooling I think RAII gets significantly trickier to do.
- theICEBeardk 10mo agohttps://en.cppreference.com/w/cpp/freestanding.html https://en.cppreference.com/w/cpp/freestanding.html to see the parts you can use.
- DashAnimal 10mo agoWell if you're using the standard library then you're not really paying attention to allocations and deallocations for one. For instance, the use of std::string. So I guess I'm wondering if you work in an industry that avoids std?
- jandrewrogers 10mo agoI work in high-scale data infrastructure. It is common practice to do no memory allocation after bootstrap. Much of the standard library is still available despite this, though there are other reasons to not use the standard containers. For example, it is common to need containers that can be paged to storage across process boundaries. C++ is designed to make this pretty easy.
- astrobe_ 10mo agoAnd what does "modern" has to do with it anyway.
- Cyan488 10mo agoThis is common in embedded systems, where there is limited memory and no OS to run garbage collection.
- criddell 10mo agoGarbage collection in C++?
- wiseowise 10mo agoThat’s hardly 90% of C++.
- bluGill 10mo agoLarge parts of the standard library malloc/free.
- elteto 10mo agoIf you compile with -fno-exceptions you just lost almost all of the STL. You can compile with exceptions enabled, use the STL, but strictly enforce no allocations after initialization. It depends on how strict is the spec you are trying to hit.
- vodou 10mo agoNot my experience. I work with a -fno-exceptions codebase. Still quite a lot of std left. (Exceptions come with a surprisingly hefty binary size cost.)
- theICEBeardk 10mo agoApparently according to some ACCU and CPPCon talks by Khalil Estel this can be largely mitigated even in embedded lowering the size cost by orders of magnitude.
- Espressosaurus 10mo agoYeah. I unfortunately moved to an APU where code size isn't an issue so I never got the chance to see how well that analysis translated to the work I do. Provocative talk though, it upends one of the pillars of deeply embedded programming, at least from a size perspective.
- Taniwha 10mo agoyup, same for any real time code, new/malloc/free/delete use hidden mutexes and can cause priority inversion as a result - heisenbugs, that audio/video dropout that happens rarely and you can't quite catch - best to code to avoid them
- AnimalMuppet 10mo agoThey also can simply fail, if you are out of memory or your heap is hopelessly fragmented. And they take an unpredictable amount of time. That's very bad if you're trying to prove that you satisfy the worst-case timing requirement.
- thefourthchime 10mo agoI've worked on a playout system for broadcast television. The software has to run for years at a time and not have any leaks, We need to send out one frame of television exactly on time, every time. It is "C++", but we also follow the same standards. Static memory allocation, no exceptions, no recursion. We don't use templates. We barely use inheritance. It's more like C with classes.
- EliRivers 10mo agoI worked on the same for many years; same deal - playout system for broadcast, years of uptime, never miss a frame. The C++ was atrocious. Home-made reference counting that was thread-dangerous, but depending on what kind of object the multi-multi-multi diamond inheritance would use, sometimes it would increment, sometimes it wouldn't. Entire objects made out of weird inheritance chains. Even the naming system was crazy; "pencilFactory" wasn't a factory for making pencils, it was anything that was made by the factory for pencils. Inheritance rather than composition was very clearly the model; if some other object had function you needed, you would inherit from that also. Which led to some object inheriting from the same class a half-dozen times in all. The multi-inheritance system given weird control by objects on creation defining what kind of objects (from the set of all kinds that they actually were) they could be cast to via a special function, but any time someone wanted one that wasn't on that list they'd just cast to it using C++ anyway. You had to cast, because the functions were all deliberately private - to force you to cast. But not how C++ would expect you to cast, oh no! Crazy, home made containers that were like Win32 opaque objects; you'd just get a void pointer to the object you wanted, and to get the next one pass that void pointer back in. Obviously trying to copy MS COM with IUnknown and other such home made QueryInterface nonsense, in effect creating their own inheritance system on top of C++. What I really learned is that it's possible to create systems that maintain years of uptime and keep their frame accuracy even with the most atrocious, utterly insane architecture decisions that make it so clear the original architect was thinking in C the whole time and using C++ to build his own terrible implementation of C++, and THAT'S what he wrote it all in. Gosh, this was a fun walk down memory lane.
- webdevver 10mo ago
- tialaramex 10mo agoForbidding recursion is pretty annoying. One of the nice things that's on the distant horizon for Rust is an explicit tail recursion operator perhaps named `become`. Unlike naive recursion, which as this video (I haven't followed the link but I'm assuming it is Laurie's recent video) explains risks stack overflow, optimized tail recursion doesn't grow the stack. The idea of `become` is to signal "I believe this can be tail recursive" and then the compiler is either going to agree and deliver the optimized machine code, or disagree and your program won't compile, so in neither case have you introduced a stack overflow. Rust's Drop mechanism throws a small spanner into this, in principle if every function foo makes a Goose, and then in most cases calls foo again, we shouldn't Drop each Goose until the functions return, which is too late, that's now our tail instead of the call. So the `become` feature AIUI will spot this, and Drop that Goose early (or refuse to compile) to support the optimization.
- tgv 10mo agoIn C, tail recursion is a fairly simple rewrite. I can't think of any complications. But ... that rewrite can increase the cyclomatic complexity of the code on which they have some hard limits, so perhaps that's why it isn't allowed? And the stack overflow, of course.
- AnimalMuppet 10mo agoI don't know that it's just cyclomatic complexity. I think it at least part of it is proving that you meet hard real-time constraints. Recursion is harder to analyze that way than "for (i = 0; i < 16; i++) ... " is.
- zozbot234 10mo agoThe tail recursion operator is a nice idea, but the extra `become` keyword is annoying. I think the syntax should be `return as`: it uses existing keywords, is unambiguous and starts with `return` which tail recursion is a special case of.
- tialaramex 10mo ago
- krashidov 10mo agoHas anyone else here banned exceptions (for the most part) in less critical settings (like a web app)? I feel like that's the way to go since you don't obscure control flow. I have also been considered adding assertions like TigerBeetle does https://github.com/tigerbeetle/tigerbeetle/blob/main/docs/TIGER_STYLE.md https://github.com/tigerbeetle/tigerbeetle/blob/main/docs/TI...
- mwkaufma 10mo agoLots of games, and notably the Unreal Engine, compile without exceptions. EASTL back in the day was in part written to avoid the poor no-exception support in Dinkumware STL and STLport.
- jesse__ 10mo agoBasically all high profile engine teams I know of ban exceptions. They're worse than useless
- tonfa 10mo agoGoogle style bans them: https://google.github.io/styleguide/cppguide.html#Exceptions https://google.github.io/styleguide/cppguide.html#Exceptions
- fweimer 10mo agoMost large open-source projects ban exceptions, often because the project was originally converted from C and is just not compatible with non-local control flow. Or the project originated within an organization which has tons of C++ code that is not exception-safe and is expected to integrate with that. Some large commercial software systems use C++ exceptions, though. Until recently, pretty much all implementations seemed to have a global mutex on the throw path. With higher and higher core counts, the affordable throw rate in a process was getting surprisingly slow. But the lock is gone in GCC/libstdc++ with glibc. Hopefully the other implementations follow, so that we don't end up with yet another error handling scheme for C++.
- msla 10mo agoAt that point, why not write in C? Do they think it's C/C++ and not understand the difference? > no recursion Does this actually mean no recursion or does it just mean to limit stack use? Because processing a tree, for example, is recursive even if you use an array, for example, instead of the stack to keep track of your progress. The real trick is limiting memory consumption, which requires limiting input size.
- mwkaufma 10mo agoFor a long time, at least in MS and Intel, the C++ compilers were better than the C compilers.
- mwkaufma 10mo agoRe: recursion. She explains in her video. Per requirements, the stack capacity has to be statically verifiable, and not dependent on runtime input.
- drnick1 10mo agoYou may still want to use classes (where they make sense), references (cleaner syntax than pointers), operator overloading, etc. For example, a linear algebra library is far nicer to write and use in C++.
- jesse__ 10mo agoFunction overloading is nice, too
- billforsternz 10mo agoSemi serious idea: A lot of people (including me) write C++ but it's basically C plus a small set of really ergonomic and useful C++ features (eg references). This should be standardised as a new language called C+
- zeroc8 10mo agoThat probably would see more success than the monster they've created. I've been out of the C++ world for a while, but I hardly recognize the language anymore.
- pton_xd 10mo agoThat's standard in the games industry as well. Plus many others like no rtti, no huge dependencies like boost, no smart pointers, generally avoid ctors / dtors, etc.
- petermcneeley 10mo agoThis is basically video games prior to 2010
- mwkaufma 10mo agoRelax the dynamic-memory restriction to "limit per-event memory allocation to the bump allocator" and it's still mostly true for many AAA/AAAA games I work on today.
- petermcneeley 10mo agoDevelopers have gotten lazy. Im glad to here where you are they are at least still trying.
- mwkaufma 10mo agoNah I'm lazy, too.
- petermcneeley 10mo agobut_you_were_the_chosen_one.jpeg
- bigyabai 10mo ago[flagged]
- bluGill 10mo agoMost of their reasoning doesn't apply to my problem space.
- jacquesm 10mo agoIt probably does! It is just that in your problem space the price of failure is low enough that you can get away with it. But most experienced programmers tend to stick to a very rigid subset of simple and reliable constructs and stay as far away from any architecture astronaut inspired features as they can.
- barfoure 10mo agoDo avionics in general subscribe to MISRA C/C++ or do they go even further with an additional (or different) approach?
- fallingmeat 10mo agocoding standard is a part of the story. mainly it comes down to level of rigor and documenting process and outcomes for audit ability. DO-178c
- 4gotunameagain 10mo agoDepends on the region. MISRA is widely adopted, and then there are the US MIL standards, ECSS for european aerospace stuff, do-178C for aviation..
- westurner 10mo ago/?hnlog awesome-safety-critical From https://news.ycombinator.com/item?id=45562815 https://news.ycombinator.com/item?id=45562815 : > awesome-safety-critical: https://awesome-safety-critical.readthedocs.io/en/latest/ https://awesome-safety-critical.readthedocs.io/en/latest/ From "Safe C++ proposal is not being continued" (2025) https://news.ycombinator.com/item?id=45237019 https://news.ycombinator.com/item?id=45237019 : > Safe C++ draft: https://safecpp.org/draft.html https://safecpp.org/draft.html Also there are efforts to standardize safe Rust; rust-lang/fls, rustfoundation/safety-critical-rust-consortium > How does what FLS enables compare to these [unfortunately discontinued] Safe C++ proposals?
- pacoWebConsult 10mo agoDO-178c is not a coding standard, it's a process standard. Projects following DO-178c processes would adopt a coding standard as a part of the process, reviewing software deliverables adhere to those standards.
- stackghost 10mo agoDepends on the company in my experience. I've seen some suppliers that basically just wire up the diagram in Matlab/simulink and hit Autocode. No humans actually touch the C that comes out. Honestly I think that's probably the correct way to write high reliability code.
- jandrewrogers 10mo agoFor those interested, the F-35 (née Joint Strike Fighter) C++ coding standards can be found here, all 142 pages of it: https://www.stroustrup.com/JSF-AV-rules.pdf https://www.stroustrup.com/JSF-AV-rules.pdf
- tgv 10mo agoFrom quickly glancing over a couple of pages, that looks sensible. Which makes me curious to see some exceptions to the "shall" rules. With a project of this size, that should give some idea about the usefulness of such standards.
- OhNoNotAgain_99 10mo ago[dead]
- extraduder_ire 10mo agoThe first time I came across this document, someone was using it as an example how the c++ you write for an Arduino Uno is still c++ despite missing so many features.
- msla 10mo agoInteresting they're using C++ as opposed to Ada.
- raffael_de 10mo agoInteresting font choice for the code snippets. I wonder if that's been chosen on a whim or if there is a reason for not going with mono space.
- nikanj 10mo agoIn 1994 C++ compilers were buggy, and a modernization of the C++ allowed features list is still stuck in a committee somewhere?
- thenobsta 10mo agoI wonder how these compare to high frequency training standards. It seems like they'd have similar speed/reliability/predictability requirements in the critical paths.
- perbu 10mo agoJFS-CPP bans exceptions because you would lose control over the execution of the problem. The HFT crowds didn't like it because you'd add 10ns to a function call. At least before we had zero-cost exceptions. These days, I suspect the HFT crowd is back to counting microseconds or milliseconds as trades are being done smarter, not faster.
- clanky 10mo agoThere are at least some HFT players who actually use exceptions to avoid branches on the infrequent-but-speed-critical execution path: https://youtu.be/KHlI5NBbIPY?si=VjFs7xVN0GsectHr https://youtu.be/KHlI5NBbIPY?si=VjFs7xVN0GsectHr
- ltbarcly3 10mo agoPaging our Ada fanboys! You're missing it!
- __patchbit__ 10mo agoIf in 1994 Joe Armstrong and Alan Kay were to list 7 alternative languages to C++ for programming fighter jets, what would they have done?
- semiinfinitely 10mo agoeven with 90% of c++ features banned, the language remains ~5x larger than every other programming language
- pjmlp 10mo agoCheck C# 10, Python 3.14, D, Haskell,...
- metaltyphoon 10mo agoI don't consider C# a very large language. Most of what has been added removed boilerplate code. Swift, a much younger language, is way more complicated IMO
- pjmlp 10mo agoSomeone doing maintenance work on C# project might find code going all the way back to C# 1.0. Also improvements to low level programming, being done since C# 7, a few semantic changes, aren't for removing boilerplate code. Then since a language is useless without its standard library, there have beem plenty of changes on how to do P/Invoke, COM interop, development of Web applications, and naturally knowing in what release specific features were introduced.
- xinem10 10mo ago[dead]
- kaluga 10mo agoThe “90% ban” isn’t about hating C++ — it’s about guaranteeing determinism. In avionics, anything that can hide allocations, add unpredictable control flow, or complicate WCET analysis gets removed. Once you operate under those constraints, every language shrinks to a tiny, fully-auditable subset anyway.
- grougnax 10mo agoThey could use 100% of Rust
- accelbred 10mo agoNo they could not. Rusts standard library heavily uses dynamic memory allocation and panics, for example. MISRA C:2025 Addendum 6 covers MISRA rules that still apply to Rust, as an example of how one would restrict Rust in safety-critical contexts.
- steveklabnik 10mo agoIn safety critical contexts, you're not usually using the standard library. Or at least, you're using core, not alloc or std. Panics can still exist, of course, but depending on the system design you probably don't want them either, which is a bit more difficult to remove but not the end of the world. I hadn't seen that addendum though yet, that's very cool!
- accelbred 10mo agoYeah, for work stuff where we follow MISRA conventions, its easiest to use no_std and ban using third-party crates as runtime dependencies.
- time4tea 10mo agoa = a; // misra Actual code i have seen with my own eyes. (Not in F-35 code) Its a way to avoid removing an unused parameter from a method. Unused parameters are disallowed, but this is fine? I am sceptical that these coding standards make for good code!
- msla 10mo agoEspecially since there is a widely recognized way to ignore a parameter: (void) a; Every C programmer beyond weaning knows that.
- stefan_ 10mo agoI'm sure thats disallowed for the C-style cast.
- daringrain32781 10mo agoC++17 has the [[maybe_unused]] attribute.
- cpgxiii 10mo agoFwiw, unused-cast-to-void is a case that GCC and Clang ignore when using -Wno-old-style-cast, which is what most projects prohibiting C-style casts are going to be using (or whatever the equivalent their compiler provides).
- deleted 10mo ago[deleted]
- time4tea 10mo agoThe point really was that the unused method parameter should in almost all cases be removed, not that some trick should be used to make it seem used, and this is the wrong trick!
- addaon 10mo agoSometimes. But sometimes you have a set of functions that are called through function pointers that need the same signature, and one or more of them ignore some of the arguments. These days I’d spell that __attribute__((unused)); but it’s a perfectly reasonable case.
- geophph 10mo agoLaurieWired is an awesome follow on YouTube!
- jamal-kumar 10mo agoHer ARM assembly tutorial series is really excellent
- manoDev 10mo agoYou mean fighters ARE coded in C++? My god
- GoblinSlayer 10mo ago"Launching nuclear rockets" just became literal.
- fweimer 10mo agoI think the late Robert Dewar once quipped that modern jet fighters aren't safety-critical applications because the aircraft disintegrates immediately if the computer system fails.
- anonymousiam 10mo agoThe same is true for the software that runs many satellites. Use of the STL is prohibited. The main issue is mission assurance. Using the stack or the heap means your variables aren't always at the same memory address. This can be bad if a particular memory cell has failed. If every variable has a fixed address, and one of those addresses goes bad, a patch can be loaded to move that address and the mission can continue.
- Thaxll 10mo agoCan't this be done at runtime? Like the underlying calls can black list hardware address on read/write faults?
- amluto 10mo agoIf you have memory to spare and are using hardware with an MMU, you can remap your logical address to a different page. Linux can do this, but only for user memory.
- anonymousiam 10mo agoThis assumes that the operating system can run. If the memory corruption impacts the OS, then it may be impossible to recover. As the systems (and software) have become more complex, keeping these Mission Assurance best practices becomes more important, but the modern generation of developers sometimes loses sight of this. A good example of what I'm talking about is a program that I was peripherally involved with about 15 years ago. The lead wanted to abstract the mundane details from the users (on the ground), so they would just "register intent" with the spacecraft, and it would figure out how to do what was wanted. The lead also wanted to eliminate features such as "memory dump", which is critical to the anomaly resolution process. If I had been on that team, I would have raised hell, but I wasn't, and at the time, I needed that team lead as an ally.
- d-lisp 10mo agoWow, but how did they deal with anomalies ? I mean, even when I have the codebase readily accessible and testable in front of my eyes, I never trust the tests to be enough ? I often spot forgotten edge cases and bugs of various sort in C/embedded projects BECAUSE I run the program, can debug and spot mem issues and whole a lot of other things for which you NEED to gather the most informations you can in order to find solutions ?
- dzonga 10mo agoI guess a bigger conversation could be had in regards to: what leads to better code in terms of understandability & preventing errors Exceptions (what almost every language does) or Error codes (like Golang) are there folks here that choose to use error codes and forgo Exceptions completely ?
- jandrewrogers 10mo agoThere isn't much of a conversation to be had here. For low-level systems code, exceptions introduce a bunch of issues and ugly edge cases. Error codes are cleaner, faster, and easier to reason about in this context. Pretty much all systems languages use error codes. In C++, which supports both, exceptions are commonly disabled at compile-time for systems code. This is pretty idiomatic, I've never worked on a C++ code base that used exceptions. On the other hand, high-level non-systems C++ code may use exceptions.
- dzonga 10mo agothanks for the explanation.
- bluGill 10mo agoWhat you wrote is historically correct, but new analisys shows exceptions are faster that error codes if you actually check the error codes. Of course checking error codes is tedious and so often you don't. Also is micro benchmarks error codes are faster and only when you do more complex benchmarks do exceptions show up as faster.
- jandrewrogers 10mo agoThe performance benefits of exceptions are not borne out in practice in my experience relative to other error handling mechanisms. It doesn't replicate. But that is not the main reason to avoid them. Exceptions have very brittle interaction with some types of low-level systems code because unwinding the stack can't be guaranteed to be safe. Trying to make this code robustly exception-safe requires a lot of extra code and has runtime overhead. Using exceptions in these kinds of software contexts is strictly worse from a safety and maintainability standpoint.
- bri3d 10mo agohttps://web.archive.org/web/20111219004314/http://journal.thedacs.com:80/issue/53/158 https://web.archive.org/web/20111219004314/http://journal.th... (referenced, at least tangentially, in the video) is a piece from the engineering lead which does a great job discussing Why C++. The short summary is "they couldn't find enough people to write Ada, and even if they could, they also couldn't find enough Ada middleware and toolchain." I actually think Ada would be an easier sell today than it was back then. It seems to me that the software field overall has become more open to a wider variety of languages and concepts, and knowing Ada wouldn't be perceived as widely as career pidgeonholing today. Plus, Ada is having a bit of a resurgence with stuff like NVidia picking SPARK.
- pyuser583 10mo agoYeah I find myself wishing it would take off again. I’m sure I’m idealizing it, but at least I’m not demonizing it like folks did back in the day.
- ecshafer 10mo agoI've always strongly disliked this argument of not enough X programmers. If the DoD enforces the requirement for Ada, Universities, job training centers, and companies will follow. People can learn new languages. And the F35 and America's combat readiness would be in a better place today with Ada instead of C++.
- blub 10mo agoThe exact opposite of what you suggest already happened: Ada was mandated and then the mandate was revoked. It’s generally a bad idea to be the only customer of a specific product, because it increases costs. > And the F35 and America's combat readiness would be in a better place today with Ada instead of C++ What’s the problem with the F35 and combat readiness? Many EU countries are falling over each-other to buy it.
- KolmogorovComp 10mo ago> Many EU countries are falling over each-other to buy it They are not buying it for its capabilities though, but to please their US ally/bully which would have retaliated economically otherwise. See the very recent Swiss case were theirs pilots had chosen another aircraft (the french Rafale), only to be disavowed by their politics later on.
- factorialboy 10mo agoIsn't the F35 program considered a failure? Or am I confusing it with some other program?
- TimorousBestie 10mo agoThe research and development effort went way over budget, the first couple rounds of production were fraught with difficulty, and the platform itself has design issues from being a “one-size-fits-all” compromise (despite also having variants for each service). I haven’t heard anything particularly bad about the software effort, other than the difficulties they had making the VR/AR helmet work (the component never made it to production afaik).
- themafia 10mo agoThey oxygen delivery system fails and has left pilots hypoxic. https://www.nwfdailynews.com/story/news/local/2021/08/02/f-35-pilot-breathing-system-concerns-u-s-house-subcommittee/5414460001/ https://www.nwfdailynews.com/story/news/local/2021/08/02/f-3... The electrical system performs poorly under short circuit conditions. https://breakingdefense.com/2024/10/marine-corps-reveals-what-went-wrong-in-2023-missing-f-35-saga/ https://breakingdefense.com/2024/10/marine-corps-reveals-wha... They haven't even finished delivering and now have to overhaul the entire fleet due to overheating. https://nationalsecurityjournal.org/the-f-35-fighters-2-big-problems-that-wont-go-away/ https://nationalsecurityjournal.org/the-f-35-fighters-2-big-... This program was a complete and total boondoggle. It was entirely the wrong thing to build in peace time. It was a moonshoot for no reason other than to mollify bored generals and greedy congresspeople.
- tsunagatta 10mo agoThe F-35 was in development hell for a while for sure, but it’s far from a failure. See the recent deals where it’s been used as a political bargaining chip; it still ended up being a very desirable and capable platform from my understanding.
- fl7305 10mo ago
- FpUser 10mo agoHer point about exceptions vs error codes was that one failed to catch exception of particular and and things went south meanwhile if we instead "catch" error code all will be nice and dandy. Well one might fail to handle error codes just as well. That is of course not to say that exceptions and error codes are the same.
- chairmansteve 10mo agoAhhh. They use C++..... That explains all the delays on the F-35....,
- smlacy 10mo agoYou think a fighter jet should run Ruby on rails instead?
- zenlot 10mo agoNo jet should be on rails.
- da_chicken 10mo agoWhat about the launch rail on an aircraft carrier?
- riku_iki 10mo agowhat would be so obviously better choice of language in your opinion?
- throwaway2037 10mo agoYou raise a good point. No trolling: I wonder what languages they seriously considered? Example: I am sure the analysis included C in the mix. Also, I wonder if they considered compiler extensions. Example: Since C doesn't have destructors, maybe you could add a compiler extension to add the defer keyword to allow people to schedule object destruction. Even when they decided upon C++, I am sure there was a small holy war to decide what features were allowed. When they started the JSF programmed in the 1990s, C++ compilers were pretty terrible!
- riku_iki 10mo agoMy recollection is that traditionally they used Ada for avionics, but per some internet claims they had difficulties to hire enough Ada programmers for such large projects, so switched to C++.
- don-code 10mo ago> All if, else if constructs will contain either a final else clause or a comment indicating why a final else clause is not necessary. I actually do this as well, but in addition I log out a message like, "value was neither found nor not found. This should never happen." This is incredibly useful for debugging. When code is running at scale, nonzero probability events happen all the time, and being able to immediately understand what happened - even if I don't understand why - has been very valuable to me.
- torben-friis 10mo agoI like rust matching for this reason: You need to cover all branches. In fact, not using a default (the else clause equivalent) is ideal if you can explicitly cover all cases, because then if the possibilities expand (say a new value in an enum) you’ll be annoyed by the compiler to cover the new case, which might otherwise slip by.
- uecker 10mo agoAnd I like using enums in C ;-) The compiler tells you to cover all branches. https://godbolt.org/z/bY1P9Kx7n https://godbolt.org/z/bY1P9Kx7n
- rundev 10mo agoThe compiler also tells you that even if you cover all enum members, you still need a `default` to cover everything, because C enums allow non-member values.
- torben-friis 10mo agoRust is a bit smarter than that, in that it covers exhaustiveness of possible states, for more than just enums: fn g(x: u8) { match x { 0..=10 => {}, 20..=200 => {}, } } That for example would complain about the ranges 11 to 19 and 201 to 255 not being covered. You could try to map ranges to enum values, but then nobody would guarantee that you covered the whole range while mapping to enums so you’d be moving the problem to a different location. Rust approach is not flawless, larger data types like i32 or floats can’t check full coverage (I suppose for performance reasons) but still quite useful.
- djfobbz 10mo agoI wonder if Lockheed Martin has an Electron based future fighter in the works?
- greenavocado 10mo agoThe C++ standard for the F-35 fighter jet prohibits ninety percent of C++ features because what they are actually after is C with destructors. I was just thinking about how to write C in a modern way today and discovered GLib has an enormous about of useful C++ convieniences in plain C. Reading through the JSF++ coding standards I see they ban exceptions, ban the standard template library, ban multiple inheritance, ban dynamic casts, and essentially strip C++ down to bare metal with one crucial feature remaining: automatic destructors through RAII. When a variable goes out of scope, cleanup happens. That is the entire value proposition they are extracting from C++, and it made me wonder if C could achieve the same thing without dragging along the C++ compiler and all its complexity. GLib is a utility library that extends C with better string handling, data structures, and portable system abstractions, but buried within it is a remarkably elegant solution to automatic resource management that leverages a GCC and Clang extension called the cleanup attribute. This attribute allows you to tag a variable with a function that gets called automatically when that variable goes out of scope, which is essentially what C++ destructors do but without the overhead of classes and virtual tables. The heart of GLib's memory management system starts with two simple macros: g_autofree and g_autoptr. The g_autofree macro is deceptively simple. You declare a pointer with this attribute and when the pointer goes out of scope, g_free is automatically called on it. No manual memory management, no remembering to free at every return path, no cleanup sections with goto statements. The pointer is freed whether you return normally, return early due to an error, or even if somehow the code takes an unexpected path. This alone eliminates the majority of memory leaks in typical C programs because most memory management is just malloc and free, or in GLib's case, g_malloc and g_free. The g_autoptr macro is more sophisticated. While g_autofree works for simple pointers to memory, g_autoptr handles complex types that need custom cleanup functions. A file handle needs fclose, a database connection needs a close function, a custom structure might need multiple cleanup steps. The g_autoptr macro takes a type name and automatically calls the appropriate cleanup function registered for that type. This is where GLib shows its maturity because the library has already registered cleanup functions for all its own types. GError structures are freed correctly, GFile objects are unreferenced, GInputStream objects are closed and released. Everything just works. Behind these macros is something called G_DEFINE_AUTOPTR_CLEANUP_FUNC, which is how you teach GLib about your own types. You write a cleanup function that knows how to properly destroy your structure, then you invoke this macro with your type name and cleanup function, and from that moment forward you can use g_autoptr with your type. The macro generates the necessary glue code that connects the cleanup attribute to your function, handling all the pointer indirection correctly. This is critical because the cleanup attribute passes a pointer to your variable, not the variable itself, which means for a pointer variable it passes a double pointer, and getting this wrong leads to crashes or memory corruption. The third member of this is g_auto, which handles stack-allocated types. Some GLib types like GString are meant to live on the stack but still need cleanup. A GString internally allocates memory for its buffer even though the GString structure itself is on the stack. The g_auto macro ensures that when the structure goes out of scope, its cleanup function runs to free the internal allocations. Heap pointers, complex objects, and stack structures all get automatic cleanup. What's interesting about this system is how it composes. You can have a function that opens a file, allocates several buffers, creates error objects, and builds complex data structures, and you can simply declare each resource with the appropriate auto macro. If any operation fails and you return early, every resource declared up to that point is automatically cleaned up in reverse order of declaration. This is identical to C++ destructors running in reverse order of construction, but you are writing pure C code that works with any GCC or Clang compiler from the past fifteen years. The foundation beneath all this is GLib's memory allocation functions. The library provides g_malloc, g_new, g_realloc and friends which are drop-in replacements for the standard C allocation functions. These functions have better error handling because g_malloc never returns NULL. If allocation fails, the program aborts with a clear error message. This might sound extreme but for most applications it is actually the right behavior. When malloc returns NULL in traditional C code, most programmers either do not check it, check it incorrectly, or check it but then do not have a reasonable recovery path anyway. GLib acknowledges this reality and makes the contract explicit: if you cannot allocate memory, the program terminates cleanly rather than stumbling forward into undefined behavior.
- zerofor_conduct 10mo agoprogram like a fighter pilot? that makes no sense.
- rramadass 10mo agoAUTOSAR's free pdf file Guidelines for the use of the C++14 language in critical and safety-related systems (defined as an update to MISRA C++ 2008) - http://www.autosar.org/fileadmin/standards/R18-10_R4.4.0_R1.5.0/AP/AUTOSAR_RS_CPP14Guidelines.pdf http://www.autosar.org/fileadmin/standards/R18-10_R4.4.0_R1.... Note that both MISRA and AUTOSAR's guidelines have been combined into a single standard "MISRA C++ 2023" which has been updated for C++17. Breaking Down the AUTOSAR C++14 Coding Guidelines - https://www.parasoft.com/blog/breaking-down-the-autosar-c14-coding-guidelines-for-adaptive-autosar/ https://www.parasoft.com/blog/breaking-down-the-autosar-c14-...
- flamedoge 10mo agosurprised not that strict about types. i remember google doesn't allow unsigned?
- xvilka 10mo agoTime to rewrite it in Rust.
- grougnax 10mo agoThey should use Rust
- zeroc8 10mo agoIt's not quite there yet: https://ferrocene.dev/en?ref=blog.pictor.us https://ferrocene.dev/en?ref=blog.pictor.us
- _rpxpx 10mo agoA very jovial discussion of systems that have killed millions of innocent people. Maybe you could do the same treatment of Nazi gas chambers or something for the next video?
- lan321 10mo agoWeird link to gas chambers.. Do you think 'genocides' will go down if we bring first world militaries to third world standards?
- _rpxpx 10mo agoI think Israel would find it harder to kill children, yes. In my view a good thing.
- hyperbolablabla 10mo agoTechnology is not evil, the people wielding it are. It's a little disingenuous and dare I say insensitive to make this analogy.
- _rpxpx 10mo agoDisingenuous is making a bald statement like that about a very long and involved debate in philosophy. Suggest you read around the subject a bit first before making such haughty comments... Could start here: https://plato.stanford.edu/entries/technology/ https://plato.stanford.edu/entries/technology/ https://bpb-us-e2.wpmucdn.com/sites.uci.edu/dist/a/3282/files/2018/01/Heidegger_TheQuestionConcerningTechnology.pdf https://bpb-us-e2.wpmucdn.com/sites.uci.edu/dist/a/3282/file...
- gcr 10mo agoLaurie’s work is so good! The other videos on her channel talk about reverse engineering, obfuscation, compilers, etc Highly recommend checking her other videos out if you like this
- t1234s 10mo agoWhat compiler is used to build the production F35 code? Something off the shelf or developed by LM?
- mainecoder 10mo agoDid they really have to tell their programmers this ? (see Page 52) AV Rule 174 (MISRA Rule 107) The null pointer shall not be de-referenced.
- jandrewrogers 10mo agoThere are old idioms in C where null pointers are intentionally dereferenced to induce the expected outcome. Not the best way to write that code because beyond being less explicit about intent it also isn't guaranteed to work. The rule is likely speaking to this code.
- AnimalMuppet 10mo agoI've done it, I think more than once. I was getting to a point in the code. I could tell by a log statement or some such. But I didn't know in what circumstances I was getting there - what path through the code. So I put in something like char *p = 0; *p = 1; in order to cause a core dump. That core dump gave me the stack trace, which let me see how I got there. But I never checked that in. If I did, I would expect a severe verbal beating at the code review. Even more, it never made it into release.
- constantcrying 10mo agoCommercial jet airliners, which in all likelihood you have flown with, have system controllers which intentionally dereference the null pointer. Yes, I have seen the code, the intention was an integrity check at startup, which computed a checksum of the memory, which included the value stored at address zero.
- accelbred 10mo agoThe rule isnt there to say "don't do this". It's there to say "you must prove that this holds true, in any circumstance".
- arein3 10mo agoShe said it could be estimated how many cycles it takes to complete a calculation, but there are a lot of different paths which take different cycles. How does the code work with timing? It counts cycles?
- constantcrying 10mo agoMajor commercial airliners have system controllers where the measuring is done as follows: Write into the code some instruction which flips some output bit, hook the system up to a test rig and then get an oscilloscope. With the oscilloscope measure how long it takes between bit flips. The instructions for the measurements get commented out for the final release. Yes, I have done this. By the way, these measurements of course have to be part of the certification.
- arein3 10mo agoAnd it is tested with inputs that would go trough all the code branches right? Does it have an upper limit for the longest run, or all branches have to have the same duration? I'm asking because I am curious if the function execution time being a constant is part of the program working correctly (scheduling). Somewhat related to how early programs worked correctly for 4.77 MHz and faster clock on CPU would break the program https://en.wikipedia.org/wiki/Turbo_button https://en.wikipedia.org/wiki/Turbo_button I am working in free time on code for a controller that has to do time sensitive operations (actuate a solenoid/injector for a couple milliseconds) and I am thinking on how to correctly trigger the code so that the timing is accurate.
- mrobot 10mo agoThe Mystery Of Why The F35 Is Loud Overengineered and Doesn’t Work Has Been Solved It Was Written In C++