I remember talking about it several times over my college career, and for good reason.
To this day when people start talking about software in the loop in a safety context I get extremely twitchy. I don't let that shit happen on my watch.
I remember talking about it several times over my college career, and for good reason.
To this day when people start talking about software in the loop in a safety context I get extremely twitchy. I don't let that shit happen on my watch.
Today, I’d ask about more ways to push the responsibility away from the firmware to stop catastrophic failures. If the debugger pauses the CPU you can’t use the CPU to regulate things. I’ve worked on things where the failure mode can be explosive and it makes dev really harrowing if you can’t rely on hardware interlocks.
They often don't have to know how the nitty-gritty of the HW works. HALs are used everywhere, and some of them abstract a lot away. I've interviewed embedded SWEs that couldn't explain how the tri-state buffers work within GPIO.