From: Eleanor McHugh Date: 2008-04-17T08:11:35+09:00 Subject: Re: Ada vs Ruby On 16 Apr 2008, at 17:57, Phillip Gawlowski wrote: > I'd be interested in the kinds of trade offs have to be made in this > particular problem domain (since I can't speak from experience, and > never claimed to, either, and didn't mean to imply as much). > > I haven't worked on anything more mission critical than CRUD style > apps, > and I can only infer from my knowledge what kind of problems > development > teams face. > > Still, it seems to be that no level of genius can create software as > is > necessary for the Space Shuttle or a more average airplane, without > the > level of testing the NASA or Boeing brings to bear for their software. Oh definitely. Testing that code performs correctly is essential to any embedded development process, as is validating that the code written solves the correct problem. The latter is by far the more difficult though. The guidelines for developing civilian aviation software are documented in RTCA-DO178B (see http://en.wikipedia.org/wiki/DO-178B) which is abstract, non-prescriptive and an excellent alternative to sleeping pills. Numerous concrete processes have emerged to suit how various teams work, but in general the more critical the software then the more that testing will result in hand-analysis of both source and object code. Unit testing will be heavy on white boxing so the majority of tests are likely to be disposable with unit changes but there's lots of fun to be had with unglamorous and time-consuming old- school software engineering (SLOCs, cyclomatic complexity, various forms of test partitioning) that's independent of implementation language or life-cycle methodology. The maintenance of a clear audit trail on requirements and requirement changes is essential for civil certification, so processes which lack effective change control mechanisms are inappropriate. However I've used RAD and Agile approaches (especially evolutionary prototyping) successfully and had them pass certification so the myth that aviation development is always monolithic waterfall is definitely unfounded. In terms of the actual tradeoffs in mission critical systems (aviation or otherwise) most come down to smoothing interaction with external stimuli and breaking up costly computations and database queries into discrete manageable chunks. There's very little genius required, just careful attention to detail and an ability to analyse problem spaces: that's probably why so many physicists, chemists and applied mathematicians end up in this particular discipline. For a theoretical foundation I recommend "Cybernetics" by Norbert Wiener although it's a dense read. Ellie Eleanor McHugh Games With Brains http://slides.games-with-brains.net ---- raise ArgumentError unless @reality.responds_to? :reason