Comma Three Devkit
comma.ai
comma.ai
btw if anyone’s wondering what they’re talking about regarding end-to-end, this article explains it:
https://developer.nvidia.com/blog/deep-learning-self-driving...
This is basically the "rsync as Dropbox" approach to augmenting your car with a hacky version of automatic cruise control, with a bonus lawsuit should you ever be in a crash significant enough to warrant the attention (think paralysis).
I used the v1 of this device for ~1 year, and since then driving has never felt the same. It was sooo much less annoying to do regular commutes when the device took control for even 90% of the trip. This was true even though I still paid attention to the road and had hands ready to take the wheel.
Given that in the US there is around 1 fatality per 100 million miles driven, I don't think "millions" of miles driven with Comma is anywhere near enough to say anything about its safety record.
The stock "automatic cruise control" is most cars is far worse and far more dangerous than Comma, and those companies aren't getting taken down by lawsuits. At the end of the day, the driver is responsible for the operation of the vehicle. Comma is a tool the driver can use, and one that undoubtedly makes driving safer for themselves and other vehicles on the road.
1: https://data.consumerreports.org/wp-content/uploads/2020/11/...
But watching people nitpick various variants of electric crossover SUVs, I realize I would probably like just about all of them because none of my cars have been anything like that up to now.
So I keyed in my other two cars to see if I could put the comma into it and alas I cannot. They are 2013 and 2016 models respectively.
And yes the system in the Mach E is brand new:
https://www.caranddriver.com/news/a32896537/fords-driver-ass...
Is that a downside? Anyone who's ever struggled with hardware driver problems knows that the more hardware configurations your software (notionally) supports, the more likely you are to have show-stopping bugs.
In a home PC, some reliability is arguably a fair trade-off for versatility. Not in a car.
What does the cost and number of supported vehicles have to do with whether or not the software is hacky? (Hint: nothing; it has nothing to do with it.)
> The stock "automatic cruise control" is most cars is far worse and far more dangerous than Comma
That's a pretty extraordinary claim to make without presenting any evidence.
> one that undoubtedly makes driving safer for themselves and other vehicles on the road.
Ditto.
The front page of the Comma website claims "millions" of miles have been driven using it; given that in the US there's about 1 fatality per 100 million miles driven, I don't think we have anywhere near enough data to make any claims about Comma's safety. It may actually be safer, but I don't think we have a way to know that yet.
And also, given that Comma supports several different vehicles, I suspect that we'll have to consider its safety record on a per-make (and in some cases possibly per-model) basis, not on the system as a whole, in order to compare apples to apples.
They cutely dodged NHTSA's regulatory ire by shipping a "dash cam" that happens to run software you can install which makes it semi-autonomous... even though said software is made by the same company that ships the "dash cam". NHTSA isn't stupid, so I'm curious what it will take for this loophole to eventually be properly closed.
Sadly, safety is a lot like security. When it's done well, it's invisible, but when it's done poorly...
It's not very useful on city streets or curvy mountain roads, the places where it shines are freeways and stop and go traffic -- the boring driving.
It has been quite reliable, most of the kinks have been worked out and they have enough users that there are not any serious bugs on the standard releases. I have reported minor bugs and had them fixed in a matter of days, which is always amazing for an OSS project. If you have an uncommon car there can be tuning issues from time to time. There is also a fairly strong user community on Discord that can help you troubleshoot things.
It works best on Toyotas and Hyundais, Honda and Subarus are a little worse, and the other manufacturers is really hit or miss--there may be individual models where someone got it working.
It is not a consumer product, you need to be somewhat capable of troubleshooting the occasional issue, reading documentation, dealing with occasional quirks etc.
I have a car that isn't even the best for Comma because of steering limits (Honda CRV), and on road trips I've been able to not touch the steering wheel or accelerator/brake for 30+ minutes on open stretches of the 101. You'd think it doesn't matter all that much, but it saves so much energy. A 4 hour drive feels like a 1 hour drive. Monitoring that the car is driving sensibly uses far less energy than actually driving.
And as you say, in bumper to bumper traffic it is just amazing. I was in a 2.5 (!) hour backup between LA and San Diego a few weeks ago and Comma did 99% of the driving. And the only times I had to take over were when other frustrated drivers were doing insane things out of boredom or anger that endangered me. Computers don't get frustrated or angry! The aggravation saved on that one trip paid for the cost.
I'm kind of pissed because I bought it in the last few months and now they've come out with another one. There should be a trade-in and upgrade program.
I don't see what's some awesome about this new one, to be honest. I'd like the next one to add blind spot sensors for cars that don't have them.
I have no insight into any of the proprietary work in this space, so I have no idea whether this is unique or commonplace. But it certainly isn't confidence inspiring, particularly as a cyclist.
[1]: https://github.com/commaai/openpilot/blob/de0ce142ae51cf9c85...
But that alone is bloodchilling: it terrifies me, as a pedestrian and cyclist, to think that stuff like this is probably controlling the pieces of machinery that could kill me in a split second.
The safety code has a limit on steering ramp rate and a max torque limit. The driver can easily overpower the torque limit, and the ramp rate limit means it won't suddenly jerk.
The python code I think is temporary, they ultimately want to do end-to-end models that do both perception and control (rather than a model to do perception and traditional controller to do control). If that effort fails I think they would probably replace the python code, the current stuff is definitely amateurish.
See more info about their safety model in the safety architecture section of this blog post.
https://comma-ai.medium.com/how-to-write-a-car-port-for-open...
Are these limits baked into the cars at some level beneath Comma, or do they rely on the same physical layers and networks? It makes perfect sense to me that the car has its own limits; my concern is that installing Comma takes the car outside of its expected operating parameters and that I have no real way of verifying whether those limits are still in place.
https://comma-ai.medium.com/how-to-write-a-car-port-for-open...
Any safety limits like on the eps firmware stays intact and aren't bypassed.
if (frame % 10) == 0:
can_sends.append(make_can_msg(1648, b'\x00\x00\x00\x40\x00\x00\x50\x00', 1))
can_sends.append(make_can_msg(1649, b'\x10\x10\xf1\x70\x04\x00\x00\x00', 1))
...
I know the identifiers etc are probably hard to catalog, but that is all the more reason to give things symbolic names and maybe even avoid having to specify those IDs repeatedly.Supported cars have most signals defined in a dbc file, the mapping from name to id and bytes. See https://github.com/commaai/opendbc
This results in much cleaner car abstraction layers: https://github.com/commaai/openpilot/blob/de0ce142ae51cf9c85...
That being said, I do still see some "magical" looking constants and dictionary keys here[1], as well as lots of small numbers later in the file. I think it would be confidence-inspiring to have those better documented as well.
Edit: I found some more magic-looking bytestrings in the Volkswagen support here[2].
[1]: https://github.com/commaai/openpilot/blob/de0ce142ae51cf9c85...
[2]: https://github.com/commaai/openpilot/blob/de0ce142ae51cf9c85...
Also sometimes there are fixed values in the message that we’ve only observed as static data. Ironically that makes it impossible to reverse engineer what they mean. So those just have to be labeled as hardcoded value.
Those are actually magic. Those are the ECU firmware identifiers from the manufacturer that are used by openpilot to recognize which car it’s connected to.
Autopilot is iOS. Openpilot is Android.
Far more devices running Android than iOS in the world. And unlike consumer tech, the average car on the road is over 12 years old.
So there's a long window of opportunity where we might see more people choose to upgrade their current vehicles to self-driving, versus those choosing to buy new vehicles with inbuilt self-driving hardware.
Comma almost certainly won't get widespread adoption until it has enough miles driven on it (at least a billion?) for people to have enough data to start talking about its safety record. So that means it'll be stuck in the realm of enthusiasts for quite a long time.
If it does prove itself, though, I agree with you that it could be a game-changer for people who have recent enough cars to be supported, but not have their own driver-assist systems. And that's probably a lot of cars, and a lot of people.
[0] Although, with the exploding batteries debacle...
I think safety has already been proven, and I don't think that's preventing widespread adoption at all. It's not like most people even know about this product. It's currently being purposely kept down-low in order to only attract a certain type of tech savvy person who is more likely contribute to the project in some way (pull requests, bug reports) or at a type of person who at least won't need heavy hand holding. A large mainstream consumer audience for a dev kit is too much for them to handle, and would just be a distraction.
From what I can tell, it doesn't have 360 vision of your car, but only the front and back of the device.
The installer of both hardware and software ends up being responsible for the use of the system in a way that is much more legally clear than other automation systems or even consumer software. Deliberate and informed choices are made by entities completely outside the plausible influence of developers.
It could get tricky in cases where the installer is not the end user.
I really want to agree with you, all evidence says you are right — but then I see any 30 seconds of geohot, speaking a mile a minute and saying about 40 things that would give any lawyer a heart attack, assertively antagonising _everyone_ and piling on the least politically correct way of seeing things. Either he’s the Top-Gun of walking the fine legal line, or he’s incredibly lucky. Inexplicably, lucky seems more likely.