Boeing Flies on 99% Ada
archive.adaic.com
archive.adaic.com
She worked at the Boeing San Diego office, which is quite beautiful.
If you have the kind of skills to write Open GL in Ada for Boeing, then you're not the kind of person who's depending on having rote-learn some latest tech (J2EE, RoR, Node, Go, whatever) and only can get jobs looking for that.
That's a special sort of hell.
I have a possible explanation on this. A lot of people only know Ada in passing, from classes. For someone fluent in another language typically derived from C, the syntax is very new and frustrating initially. People normally comfortable with coding in their preferred language become newbies again, making a lot of frustrating mistakes. And they hate Ada for it.
I've seen several persons being forced into using Ada for a longer time. Geek types, including two long haired ones. They all hated it initially, but after a while they all come to appreciate and enjoy it. Two of them ended up contributing to GNAT. The cross-over time is roughly around 6 months of full time work with Ada, so more than what you get from a class.
So I guess Ada is different enough to be frustrating at first, and most people don't use it long enough to come over the initial shock and appreciate the good sides of the language. They just hate it, and stay with the "Ada is bondage" meme. Too bad.
For any one interested in large software system design and languages, I recommend looking at the "Rationale for the design of the Ada programming language" book. Even if you don't like the result ;) it's an interesting analysis of the challenge of doing large, safety critical system software IMHO. Just read the latest version, the intial one (though interesting) is now dated and made some wrong bets, like using synchronous tasks as the base for concurrency because there was hope that a formal model enabling proving behavior would develop around it, and that never happened.
Until then Turbo Pascal and Modula-2 served me pretty well.
I don't regret learning 'C'. We had our own safety standards.
C safety is a oxymoron, which is only enforcable with externals tools.
I also don't regret learning C. It provided me a path to jump into C++ and use its features to close its C underpinnings into a dungeon, as much as possible.
'C' safety is anything but an oxymoron. i don't even consider it all that difficult. It's an absolute pain the neck, but nobody said this is easy :)
1: yes, I know this was done on purpose but the lack of adoption of Ada EVEN AFTER there was free compilers available show that (IMHO) it was a mistake.
I got out of that space though. I do mobile application development now.
As in: "for every line of code a functional programmers writes" he'll write 5 blog posts and 10 HN comments on why functional programming is better, how currying, functional composition, monads, etc, work etc...
Thanks for sharing the anecdote with us. :)
[1] http://en.wikipedia.org/wiki/Capability_Maturity_Model_Integ...
[2] http://boeing.mediaroom.com/2011-10-26-Boeing-Huntsville-Sit...
As a side note on terminology, QA means a very different thing in the aerospace industry. The function of QA in this world is to witness the tests and attest that we did indeed run the test as written. Usually in the form of stamping a printed procedure as it is followed. This mirrors the process used to test the mechanical and electrical parts. The testing of the software is called verification and validation testing not QA.
I beg to differ.
I started my career working for a CMM level 5 software services company. One of the first shocks I received after I entered the web industry was total lack of discipline here. There was barely any documentation in the web industry- No way to keep a track of a impact of a particular change, no design notes, not even a change log of whom to call in case something goes wrong, in the CMM level 5 firm we would have think of roll back scenarios even before we worked on the code.
In the web industry I saw, the idea of roll back planning didn't even appear to people. Yet the way I saw, a little documentation would have the whole team sane, and avoided more 50% of fire fighting we did on weekends.
Rules are boring, but when something large is at stake it generally is worth the process.
It's all about finding the right place on the curve, and not being behind it. Add huge amounts of process to most web projects, and yeah, they might turn out a bit better, but they'll cost too much for what the customer wants to pay.
You're right though in that too many web projects have virtually no process or rules, and that's not good either.
We wrote it in MISRA C instead of Ada, purely for personal reasons.
Sadly our industry only regards security as a cost that is often imposed by external processes.
It will only charge at large when companies start to be made accountable for their software, like in other industries.
In this regard the industry is still at its infancy.
Get over it.
Consider every time Word crashes and work is lost. There are billions of Word users out there, mostly being paid to use it. How much does that cost over the course of a year?
And the accumulated frustration from unreliable software, causing loss of productivity, resistance to change, stress... How much does that cost?
There are trade-offs to be made.
Get over it.
Releasing a virus is a tort at best. Cracking a site is a tort at best, and both are probably criminal behavior. Yes, I have this bias.
I've read enough history to know that there have been times when such interlopers ended up as heads on pikes outside city walls. Seems extreme to be sure, but still....
I am a great admirer of C.A.R. Tony Hoare, but virus writers and system crackers give him a "bootleggers and Baptists" common cause with them.
Software should be handled the same way.
However people learned to buy "shoes that explode at random week days" and now we have a quality mess.
One compelling reason behind the extensive pre-testing was Boeing's desire to meet the Federal Aviation Agency's (FAA's) Extended Twin Operations (ETOPS) standards ahead of schedule. The original ETOPS rule was drafted in 1953 to protect against the chance of dual, unrelated engine failures. Unless a newly designed and produced aircraft has at least three engines, it usually had to wait, sometimes as long as four years, before the FAA and the Joint Airworthiness Authorities (JAA) will allow it to fly more than one hour from an airport; after a time, the new aircraft is deemed a "veteran" and is allowed to fly three hours away. A shortened trial period would drastically increase Boeing's sales."
It hadn't occurred to me that a 777 is always three hours away from an Airport. I'll have to look more closely on the map.
Ref: http://aviationweek.com/awin/faa-extends-777-etops-approval
At 3 hours, it's mostly the Southern Ocean that's off-limits.
I had no idea Boeing was subsidizing Midway Island in order to provide an ETOPS alternate airport.
Also, 5.5 hour ETOPS? That's crazy long!
And don't forget about alternates!
Ada is not in the hype anymore. It is getting more and more difficult (and expensive) to have developers with a good knowledge in Ada.
In my current society, some projects are still in Ada, but the quality of the code is becoming lower and lower, with a lot of type cast. It seems people are thinking in C (C++) and are painfully writing their ideas in Ada.
(Working on some flight management software, I found a bug in our version of GCC. It's free software, right? So I could just fix it? Or even upgrade to a newer version? That would have meant re-certifying the compiler, so it was easier to work around the bug.)
In practice, I do see a lot avionics code written in Ada. I see a lot written in C. I see a lot written in C++. I haven't seen much else. I would guess a roughly even split between Ada and C or C++, with either C or C++ being increasingly favored for new clean sheet projects.
Have you seen level A software written using C++?
Me neither. I can imagine that would be harder than just using DO-178, as the auditors are used to dealing with it.
Have you seen level A software written using C++?
Not personally. I have heard of a level A flight controls project that was planning to use C++, and was in the process of getting their C++ compiler (GCC C++, I believe) certified. I don't know how it turned out.
The only toolchain I can think of that is Ada only is Adacore.
https://www.linkedin.com/groups/Which-is-Major-Programming-l...
Having had a lot of my undergrad CS classes in Ada (in Toulouse France, the home of Airbus) I get nostalgic every time I see a post mentioning Ada on HN.
I did a little bit of Ada programming, and one of the distinct features it has is you can't do anything clever without being extremely explicit about it. This language has the most aggressive type-correctness checking I have ever seen. When you finally get your code to compile, it's likely that it will work reliably.
I don't think Ada is that strict.
Also, at least back then, Ada has no garbage collection, so you know what latencies are.
It doesn't do any of the fancy/confusing inference stuff that Haskell does in order to verify that type conversions/transformations progress along the intended paths, but instead requires you to be very explicit about what you're doing.
E.g. (1) Trying to read something from stdin is a minor challenge, because of how Strings are usually fixed-length and don't interoperate with special arbitrary-length strings. (2) If you want to do dynamic memory stuff yourself, you need to declare your packages as such (with the intent of this showing up during reviews and thus leading to the code being more thoroughly scrutinized.) (3) It allows for creating special sub-types of primitives, like integers of a limited/well-speicified range, so that they can be put into APIs intead of ordinary machine/compiler-dependent integers. (4) Conditions (in IFs and such) don't (by default) short-circuit evaluate, and you have to use speical key words if you want short-circuit evaluation. And the list goes on..
All in all, Ada is quite enjoyable imho. It allows you to write code without thinking too much about it, since you won't be missing (many) corner cases.
On the other hand of course all of this results in more work, which can feel tedious to some - but at least it's not the mind-boggling "what is this *?!" strictness that has you pulling your hairs out in confusion/desperation, that usually accompanies Haskell.
No casting.
Probably rather alien to the HN crowd ;)
The only fully automated lines are 1 and 14.
First real success was Meteor line 14 driverless metro in Paris: Over 110 000 lines of B models were written, generating 86 000 lines of Ada. No bugs were detected after the proofs, neither at the functional validation, at the integration validation, at on-site test, nor since the metro lines operate (October 1998). The safety-critical software is still in version 1.0 in year 2007, without any bug detected so far.
From: http://rodin.cs.ncl.ac.uk/Publications/fm_sc_rs_v2.pdf
|bool foo(bool i, bool j) {
2| return i ||
1| j;
|}
|
|void main() {
1| foo(true, false);
1| foo(false, false);
|}
It'll give an execution count on each statement, and logical expression operands count as separate statements. I've found that when this is used in conjunction with a test suite to ensure that the tests cause every code path to be executed, the code becomes remarkably free of bugs.But, for Avionics and Space System, Ada is a well known, and continues to be a well known implementation language.
On the other hand, failure is much less of an option when it comes to things like avionics, so much more focus is placed on reliability. In these cases that price starts looking like a bargain, if the use of Ada isn't already mandated (which it probably is).
It's quite interesting how these Pascal derivatives seem to find their niche in high-reliability or real-time applications, although I don't quite understand why. That may have been part of the reason why I didn't get the job.
Range limited types, e.g.
Type Day = (0..7);
Days = (monday,tuesday,wednesday,thursday,friday,
saturday,sunday);http://programmers.stackexchange.com/questions/153266/what-o...
According to comments there, some modern aircraft run an RTOS (real time operating system) on top of the bare hardware, which then lets you run Ada or C code. Those mentioned include VxWorks[1] for the Boeing 787 and Integrity[2] used by the Airbus A380.
[1] http://en.wikipedia.org/wiki/VxWorks
[2] http://en.wikipedia.org/wiki/Integrity_(operating_system)
Reminds me of the joke:
> At a recent real-time Java conference, the participants were given an awkward question to answer:
> "If you had just boarded an airliner and discovered that your team of programmers had been responsible for the flight control software, how many of you would disembark immediately?"
> Among the forest of raised hands only one man sat motionless. When asked what he would do, he replied that he would be quite content to stay aboard. With his team's software, he said, the plane was unlikely to even taxi as far as the runway, let alone take off.
Reminds me of a joke I was once told by a QA consultant:
His colleague was on his way to deliver a revision of software which had been extensively tested and many serious bugs discovered and fixed. The software was so important that it was to be delivered in person by the consultant on a laptop to the customer.
On the walkway to the plane, he happened to glance up and see the aeroplane he was about to board was an Airbus. In fact the very revision that had the same software he'd just been testing and had found to be full of bugs.
Oh no.
Suddenly getting very cold feet and desperately thinking of a way not to get on the plane he takes a drastic step and deliberately drops and destroys the laptop with the software he was going to deliver.
Happy now he returns to the office and declares 'well, that's a shame - but I think I'll take the train next time'
- was told to me as a true story, and you never know...
By what measure did they consider Ada "too immature" I wonder? It's one of the oldest languages, an open international standard, and has been through several major updates over three decades. On the surface there are few if any languages that claim more maturity than that.
There's essentially just the AdaCore implementation that costs $$$, the GPL'd AdaCore implementation that requires you to publish your source code (because of the libraries) and then there's some unsupported GCC implementation.
I like Ada, and I would like to see it gain more market share. If it had, things like Rust and Go may have been superfluous. But the way things are, I just don't see it happening. Unless you're some big enterprise Ada is essentially a non-option, due to licensing, and if you're a big enterprise it's essentially a non-option since there's very few devs around for it. And so it remains an obscure language used in very niche applications (albeit with great success there?).
dons asbestos pants in expectation of anti eclipse comments!
Both Ada Core and Atego provide IDEs.
I think the problem is, there is so much momentum built up around Ada and C usage in the avionics world that there just isn't the infrastructure and culture built up around better languages, so it's hard to make the switch. Even if you have to write a brand new codebase for some small avionics project, how do you justify the expense of doing it all in OCaml when there is already certified compilers and support for Ada?
It ought to happen, though.
Or just their website and intranet maybe?
Likewise the compiler has to generate CPU instructions,the opcodes and operands of which are embedded in the code generator as binary data. That is code that isn't in ADA either.
There's also no reason it can't be used to write a compiler and there's probably several Ada compilers written in Ada. I'm not sure what you mean about binary data having to be embedded in the code generator; you can easily generate arbitrary binary data from almost any language.
I disagree, Ada has fantastic tools for writing these sorts of code; you can precisely define data types down to the bit level and their precise locations and endianess in memory. Have a look at pages 50-68 of [1] to see these in action. you don't have to know Ada to be able to see what's being defined, and that's it exactly matches the specification of the memory mapped IO registers. Some reference c code is given, but there is no guarantee that the compiler will do what you want; the Ada language does guarantee it.
[1] http://cs.anu.edu.au/student/comp4330/Lectures/RTES-03%20Int...