Did you know that the Generator Control Units for the Boeing 787 will go
into failsafe mode causing loss of all AC electrical power if they are
left on for more than 248 days?
https://www.federalregister.gov/documents/2015/05/01/2015-10066/airworthine…
This something that could have been prevented with the use of formal
methods. Check this slide presentation from Vermon Tech and
their CubeSat project.
http://lemuria.cis.vermontstate.edu/CubeSat/PUBLIC/SPARK-Frama-C-Day-2017.p…
Brian
--
Brian Lavender
https://www.brie.com/brian/
"There are two ways of constructing a software design. One way is to
make it so simple that there are obviously no deficiencies. And the other
way is to make it so complicated that there are no obvious deficiencies."
Professor C. A. R. Hoare
The 1980 Turing award lecture