Why does an airplane require 100M lines of code?
Why does an airplane require 100M lines of code?
Multiply by all the little and big subsystems, the embedded chips, in-flight entertainment, network gear... 100m SLOC is too low, I think.
where it states that the airbus A380 has more than 100 million lines of code in its avionics systems.
Do these systems not have hard real-time requirements about the execution time and periodicity of tasks which can't be guaranteed by the time-sharing scheduling algorithms in Linux?
It's all about the latency guarantees and that means that you're going to have to inspect each and every path through the code for length. With the complexity of the linux kernel that's a pretty tough job and I suspect that anything lower than a few hundred milliseconds (guaranteed!) is out of the question.
I built a little controller using linux that required hard real time during a long (multiple minutes) of operation and the way I hacked it was to simply disable all interrupts and recover the various drivers as good as possible once that phase was over. It worked well but was mostly deaf to input during that time except for polling one 'stop' switch which would cause the machinery to coast down to a halt after which interrupts would be enabled.
Good enough for tinkering but I certainly would not bet anything in production on that strategy.
Real time is hard, soft real time is hard enough (without guarantees but with a best effort and a very large fraction of the deadlines satisfied), hard real time (no misses at all, guaranteed) is hard for a kernel of any complexity.
They'll definitely build a prototype using Linux but they won't get that certified so it literally 'won't fly', it's just a means to speed up initial development.
Small enough that I could-reimplement it in approximately 3500 lines of code + another 850 for the virtual memory management.
This could only work if the entity paying for the certification had a way of making that money back somehow and I don't see how that could be done.
It would cost a significant amount of money to develop the necessary artifacts and engage the FAA to obtain a certification.
What I think the whole thread above misses is that the economics simply aren't there, cost isn't the limiting factor for the OS licenses for avionics but an extra certification track (especially for a fast moving target) would be, besides, it is not just the OS that gets certified but you will also have to (separately) certify (usually) the hardware that it runs on (unless you're going to use a design that has already been certified).
That means that modifications are expensive and that 'known to be good' trumps 'could be better' or 'could be cheaper in the longer term'.
Someone would have to come up with a very good reason to see open source trump the existing closed source solutions.
In addition, a modular microkernel architecture could use reproducible builds to generate identical binaries from identical source. This would enable binary components to be certified both separately (akin to unit testing) and as an integrated system (mix and match components). This could reduce overall duplication and certification costs, even among competing commercial products derived from seL4 components.
They should be able to keep it under 10M lines pretty easily if they actually cared about bloat.
Think GCC 5 is about 15 million or so now.
Or compare to the Apollo missions and the space shuttle being well under a million.
I'm not saying that it would be easy to redo the entire system from scratch now, I'm just saying that if it was a design goal from the start it wouldn't have been very onerous.
All of these things just add more and more code.