I’d be interested to hear your thoughts on the failure of FM.
Also perhaps you could augment this article with a bit of discussion on liveness vs. safety properties? My understanding was that for purposes of most embedded / RT systems there’s no need to reason about liveness since properties of the form “gets work done before time T” are safety properties, as opposed to the less useful liveness property “always gets work done eventually”. I didn’t see anything in your article that is technically a liveness property, but could be wrong of course…
Hi Victor-
I’d be interested to hear your thoughts on the failure of FM.
Also perhaps you could augment this article with a bit of discussion on liveness vs. safety properties? My understanding was that for purposes of most embedded / RT systems there’s no need to reason about liveness since properties of the form “gets work done before time T” are safety properties, as opposed to the less useful liveness property “always gets work done eventually”. I didn’t see anything in your article that is technically a liveness property, but could be wrong of course…
John