I'm honestly surprised that this kind of thing is running
ANY OS, and not direct hardware control paths. Let alone the fact that they didn't use FB ECC ram... that's even before going down the path of code quality. Not having a safety case for a hardware off or powerdown state... though if they had such a thing, odds are it would have been botched worse than the system to begin with.
Personally, I could never handle the stress of designing or building something like this... I worked in a security software team for a bank for a year, that was about as far as I can get in terms of job stress. Just the same, it seems to me some of these choices were clearly rookie level mistakes that shouldn't have been put in production to control motor vehicles.
I also agree, that it would really make more sense for car mfgs to get together to form some standards for production and core controls. If they're determined to use an actual OS, then it better damned well be the most thoroughly tested OS, running on certified hardware, with certified controls in place.
If you mess up the code in a number of places, people don't die... Tasks that control fast moving and/or heavy machinery, medical devices, etc should have very tight controls in place.... this is the kind of situation where software is and should be treated like an engineering discipline. Most of the time it's more of a craft, this isn't one of them.