RTLinux will be treated with open source FUD. Doesn't matter if you escrow it or not - a single licensing slip would be a security breach. Since you can't successfully argue that this is specious, you're done before you start.
It's impossible to understand the way this plays out without seeing it up close. I don't know how it is in all DoD contractors, but the lifespan of an actual programmer in the one I saw was five years. If you tried to stay technical, you'd get a PIP and be laid off in the next round unless you made yourself indispensable to the customer. Doing that is tantamount to a life sentence - you have to actively politick to get on another program and that's unlikely.
Charge numbers are life or death.
You might be left alone if you got an advanced degree and published certain sorts of papers. And if you do stay technical, you'll be subject to death marches.
And of course it's all processes optimized for maximum paperwork; waterfall and crushing technical debt. Each action item is budgeted and when the budget runs out, you're done regardless.
You are expected to angle towards program management to feed the beast. Even then , it's still "up or out."
From https://en.wikipedia.org/wiki/Lockheed_Martin_F-35_Lightning...
Integrity-178B is the DO-178B–compliant version of Integrity. It is used in several military jets such as the B-2, F-16, F-22 and F-35, as well as the commercial airframes Airbus A380. Its kernel's design guarantees bounded computation times by eliminating features such as dynamic memory allocation.
The auditing and security engineering capabilities have allowed it to obtain the EAL6 rating by the NSA.
Integrity-178B has a unique feature: an EAL6 rating.
https://en.wikipedia.org/wiki/Integrity_%28operating_system%...
EAL6: Semiformally Verified Design and Tested
This sounds ridiculous. Surely it would be very easy to get as many programmers as they wanted for whatever tech they need with the 1 trillion USD that they have.
It would be fine if C++ was the best tool for the job, but I suspect it isn't. If it is not the best tool for the job, then whatever is gained in "programmer availability" is lost in productivity, correctness, reliability or whatever metric a fighter jet's software development is measured against.
Furthermore, this whole IT industry fetish with hiring for a particular programming language is completely misguided. Domain knowledge is usually the bottleneck. I'd expect that to be even more so in flight or sensor software.
You want real time, you want a minimal OS and you probably want some of the nicer type capabilities over c.
http://www.stroustrup.com/JSF-AV-rules.pdf
Here's the link that gets posted in all of these conversations. A strict subset of C++ is exactly what's been used.
But that's probably a personal bias, one that's been hard-earned. It's a way of leveraging the decades of mistakes made by those folks - and aid for by previous employers.
A "'C' with classes" approach is probably a good one - but I'd hate to find some subtle template or Boost bug in mid flight...
This is all IMO, but an approach like Bruce Powell Douglass "Doing Hard Time' is a pretty good way to satisfy the "systems engineer" customers for UML charts and still have rigorous development.
UML is quite the anti-pattern and Rose is kind of awful but this should be a compromise that can work. CASE tools have gone out of fashion.
I'm not sure how much benefit that would bring, especially since dynamic dispatch is probably not encouraged. As for templates I'm not much of a c++ guy but wouldn't most template errors exist at compile time?
I think dynamic dispatch would be more permissible than you might think. You end up doing it in c manually in complicated code bases, might as well let the compiler dou the heavy lifting.
The use of C++ is a (non)reaction to the explosion of pet language systems. It got coded into whatever documentation was in process at the time, and probably cannot be changed.
That's not the experience of very wealthy Silicon Valley companies, who not only can pay much better than government defense contractors, but offer other incredible perks - yet still can't get all the talent they need.
The F-35's reason for existence is its software. Other existing aircraft are faster, can carry more, fly further, or be more stealthy. The F-35's value statement is that its pilots will know more about what's going on around it than any other combat aircraft, for the next ten or fifteen years.
COTS stuff is used at the base layers of military avionics. LynxOS is used under the hood of the Army's very successful CAAS helicopter avionics system.
Also, performance is extremely important for this application. If the plane is a little slow, a little too easy to track, the computer a little slow, then the pilots die, the people they are defending are bombed and killed, the battle is lost, and maybe the war too. It's not a place to compromise performance to save money and use COTS, even if it was a available.