6 ms·
> Nowadays a big plane like the A380 might be expected to have 100M lines of code in its subsystems, Why does an airplane require 100M lines of code?
by hello_there 11y ago
> Nowadays a big plane like the A380 might be expected to have 100M lines of code in its subsystems,
Why does an airplane require 100M lines of code?
- mschuster91 11y agoLinux kernel alone comes in at 15m SLOC. Now add an userland subsystem and you're at 20-30M just for one device. Multiply by all the little and big subsystems, the embedded chips, in-flight entertainment, network gear... 100m SLOC is too low, I think.
- CHY872 11y agoErm, the article I got my numbers from is: http://www.aerospacelab-journal.org/sites/www.aerospacelab-journal.org/files/AL04-10_1.pdf http://www.aerospacelab-journal.org/sites/www.aerospacelab-j... where it states that the airbus A380 has more than 100 million lines of code in its avionics systems.
- georgerobinson 11y agoSorry if this is incredibly ignorant, but I can't believe flight control systems are running Linux? Do these systems not have hard real-time requirements about the execution time and periodicity of tasks which can't be guaranteed by the time-sharing scheduling algorithms in Linux?
- komaromy 11y agoThere are several real-time Linux variants.
- jacquesm 11y agoThere are - to my knowledge, feel free to correct me - no real time linux versions (or even any version of linux) that are currently certified for avionics (DO-178B certification is required for that, there are multiple levels and I don't know of any linux distro (or just the kernel) with that certification).
- komaromy 11y agoAvionics certifications are well past the extent of my knowledge and I will gladly accept your point. I was generally addressing the idea that the need for preemptive scheduling precludes the use of a Linux-like kernel.
- anderspitman 11y agoI've never heard of anyone getting Linux running under hard real time constraints. You can get it pretty good (excellent for real time audio, for example), but can never be 100% sure you're going to meet the deadline. The people I've talked to who tried said by the time you strip out enough of the kernel to approach hard real time, you've lost enough of the advantage of using Linux that you may as well switch to an RTOS.
- jacquesm 11y agoReal time audio only if you use a large enough buffer and a hardware component to clock the data out. It's all about the latency guarantees and that means that you're going to have to inspect each and every path through the code for length. With the complexity of the linux kernel that's a pretty tough job and I suspect that anything lower than a few hundred milliseconds (guaranteed!) is out of the question. I built a little controller using linux that required hard real time during a long (multiple minutes) of operation and the way I hacked it was to simply disable all interrupts and recover the various drivers as good as possible once that phase was over. It worked well but was mostly deaf to input during that time except for polling one 'stop' switch which would cause the machinery to coast down to a halt after which interrupts would be enabled. Good enough for tinkering but I certainly would not bet anything in production on that strategy. Real time is hard, soft real time is hard enough (without guarantees but with a best effort and a very large fraction of the deadlines satisfied), hard real time (no misses at all, guaranteed) is hard for a kernel of any complexity.
- jacquesm 11y agoReal time systems will be running a RTOS: VxWorks or QnX or something equivalent to that. They'll definitely build a prototype using Linux but they won't get that certified so it literally 'won't fly', it's just a means to speed up initial development.
- Kliment 11y agoIs the order of magnitude of lines of code in QNX different from that of linux? At a first approximation, I don't see why it would be.
- jacquesm 11y agoThe QnX kernel is very small compared to the Linux kernel. Small enough that I could-reimplement it in approximately 3500 lines of code + another 850 for the virtual memory management.
- Kliment 11y agoWow, I had no idea. Since their source is closed and untouchable I had no way to check either. Is there any reason there aren't several certified open RTOSes around?
- jacquesm 11y agoI don't know if there aren't any open certified RTOS's around, but I can explain the 'why' part easily: if you pay for the certification of an open RTOS then everybody that can use one will say 'thank you' for the effort and that's that, since the certification would apply to any and all copies of that particular version. So you're essentially paying for the privilege of cutting your competitors a break. This could only work if the entity paying for the certification had a way of making that money back somehow and I don't see how that could be done.
- walterbell 11y ago
- Dylan16807 11y ago3/4 of that 15M is drivers and filesystems you won't be using, and this is not including the entertainment systems. They should be able to keep it under 10M lines pretty easily if they actually cared about bloat.
- CHY872 11y agoA complicating factor is that you really should include your compiler as part of your codebase (if you're doing lots of formal method work, you will usually do it on the source code, and the compiler can invalidate all of the guarantees you carefully program in), and this will be millions of lines of code (where you can't simply factor a tonne out). Think GCC 5 is about 15 million or so now.
- oldmanjay 11y agoit's always easy when you're not the one making the changes on the system you don't understand. is there a name for that? I feel like it's a common enough thing people do that it should have a catchy name.
- Dylan16807 11y agoEh. To say that something that used to be mechanical should be possible with a mere few million lines of code seems pretty obvious to me. Or compare to the Apollo missions and the space shuttle being well under a million. I'm not saying that it would be easy to redo the entire system from scratch now, I'm just saying that if it was a design goal from the start it wouldn't have been very onerous.
- deleted 11y ago[deleted]
- icegreentea 11y agoBecause each discrete component that you can eliminate (and replace with code) is a weight saving. Because once you tip over a point in complexity, you just keep adding more code to guard against more edge cases - edge cases you can't avoid because they involve crashing into mountains. Because you want to offload as much possible effort from the cockpit crew, while still allowing them full control over the automated feature All of these things just add more and more code.