11.07.2015 Views

BarrSlides_FINAL_SCRUBBED.pdf?utm_content=bufferb9206&utm_medium=social&utm_source=twitter

BarrSlides_FINAL_SCRUBBED.pdf?utm_content=bufferb9206&utm_medium=social&utm_source=twitter

BarrSlides_FINAL_SCRUBBED.pdf?utm_content=bufferb9206&utm_medium=social&utm_source=twitter

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

TOYOTA’S DEFECTIVE SOFTWARE PROCESSFMEA was incomplete; single points of failure are present! Because: Toyota didn’t adopt a formal safety processPeer reviews not done on OS code and ESP-B2 code! Because: Toyota didn’t perform code reviews; used non-standard OSEKToyota’s own “power train” coding standard not enforced! Because: Toyota didn’t follow through with software suppliersWatchdog supervisor doesn’t detect most task’s deaths! Generally costs less to push the limits than upgrade to faster CPUNo EDAC protection against hardware bit flips46! Generally costs less to make memory chips without EDACIf confident, why let NASA believe there was EDAC?

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!