Re: Real world coding standards implementation feedback
On May 21, 1:36 am, peter koch <peter.koch.lar...@gmail.com> wrote:
On 20 Maj, 18:58, ytrem...@nyx.nyx.net (Yannick Tremblay) wrote:
[...]
However, if you are writing say landing software for a
fly-by-wire Airbus, maybe terminating the software and making the
plane impossible to control would not be the correct answer.
Which is why you have redundancy. A possible solution is to have three
systems: two identical systems in a master-slave configuration and an
independent backup system typically with far less features setting in
if both master and slave dies.
Not identical. In avionics, it's typically a requirement that
the two systems in the master-slave configuration be written by
two different, independent teams, and in at least one case I know
of, that they be programmed in different languages.
--
James Kanze (GABI Software) email:james.kanze@gmail.com
Conseils en informatique orient=E9e objet/
Beratung in objektorientierter Datenverarbeitung
9 place S=E9mard, 78210 St.-Cyr-l'=C9cole, France, +33 (0)1 30 23 00 34