‹ BackHN Continuity

Thread

Ask HN: Who's still keeping a DOS machine up because the business depends on it?

297 points · 304 comments · mlaux

  1. freeli · · focus · HN ↗
    A certain nuclear power plant had a Windows NT 4.0 machine running as late as 2007. The reason is interesting.

    The machine's purpose was to report status of the control rods that mitigate nuclear reactions. Basically, "are the rods inserted, and if so, how many / how far?". I want to emphasize that this was reporting only, NOT control.

    The original software was written back in the 80's, when the plant was originally commissioned, for AmigaOS. Of course, it's hard to buy Amigas anymore, and the original one died long ago (nobody remembers when).

    So in the mid '90s, the utility purchased an AmigaOS emulator that ran on Windows NT 4.0, which was current at the time. The emulator (IIRC) was developed by a firm in the UK. The firm went out of business sometime in the late '90s. The control rod monitoring software ran under this emulator on top of NT4.

    Windows NT 4.0 was the last OS to allow the emulation software direct access to the physical hardware that produced the status signal. Later versions of Windows abstracted the hardware access away, and the monitoring software broke. Because the emulation company had gone belly up, there was no way to fix the incompatibility.

    So the utility had a choice: get new hardware/software certified (by NRC?), or keep doing what they were doing with the software (and hardware) that they had. They chose the latter.

    So this is how, in 2007, during a tour of the facility, I stumbled across a Pentium 1 system running an AmigaOS emulator on Windows NT 4.0 that was responsible for displaying the status of the control rods of a nuclear power plant.

    Spare hardware for this setup was purchased off of eBay and stocked on an adjacent shelf.

    1. CobaltFire · · focus · HN ↗
      Having worked on nuclear plants (as a reactor operator) around that time this doesn't surprise me in the least.

      Thats far more advanced than the systems I worked with, one of which reported rod position via resistance measurement on a brushed cylinder (one for angular and one for depth).

      Cleaning and calibrating those was a constant maintenance item every time the reactor was shut down.

    2. kccqzy · · focus · HN ↗
      Did they not need NRC recertification when they moved from a physical machine running AmigaOS to an AmigaOS emulator?
      1. freeli · · focus · HN ↗
        That is an advanced question best asked of the folks in charge of the plant. At the time I was just trying to figure out how to explain to the IT auditors why there was no antivirus software on this piece of crap.
        1. CursedSilicon · · focus · HN ↗
          Could you skirt around it and just remark "there are no viruses for AmigaOS"

          (Probably not literally true. But functionally true in the sense that they were likely transmitted via infected floppy disks, of which there'd be virtually none left in the wild in 2007)

          1. freeli · · focus · HN ↗
            It wasn't the AmigaOS running in the emulator that they were worried about, it was the Windows system running the emulator. (Not that the average IT auditor there could have understood the difference.)
            1. M95D · · focus · HN ↗
              How would a virus get in there?
              1. EvanAnderson · · focus · HN ↗
                If it were a newer version of NT I'd be concerned about USB media, but being NT 4.0 and not supporting USB it's imminently more capable of being air-gapped than later versions. (I recall a fun Ed Skoudis quote-- "At best, an air gap is a high-latency connection". Evidence Stuxnet.)
              2. jabl · · focus · HN ↗
                The auditor probably doesn't know nor care. "Every windows machine runs antivirus" is a checkbox item, zero thought involved.
          2. kamma4434 · · focus · HN ↗
            Hello, my name is Lamer Exterminator, pleased to make your acquaintance.

            <a href="https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Lamer_Exterminator" rel="nofollow">https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Lamer_Exterminator

          3. rcxdude · · focus · HN ↗
            Depends. A lot of these audits are quite prescriptive and don&#x27;t leave much room for actually thinking about the problem. There is often some kind of mechanism for &#x27;this is sufficiently segregated it doesn&#x27;t matter that it&#x27;s utterly out of date&#x27; but then usually some awkward rules develop that prevent some things from being put into that category. More subtly you can get whether the thing even exists as a thing that the audit cares about, and that often depends on the framing (embedded software is often invisible here but it needs to not look too much like a general-purpose OS even though it often is).

            (Also, in my experience, what the auditors think the rules are and what is written down can often be divergent and even contradictory)

            1. rrr_oh_man · · focus · HN ↗
              &gt; Also, in my experience, what the auditors think the rules are and what is written down can often be divergent and even contradictory

              Sounds interesting, could you elaborate?

              1. rcxdude · · focus · HN ↗
                This is pretty universal in my experience any time you have inspectors&#x2F;auditors intended to enforce a set of rules. The most common case is that they just miss some rule: they can be hard to properly map from what you&#x27;re seeing to the rules reliably, so different auditors will miss different things (so you can get a sign off from one and then another highlights an actual contradiction).

                The next level is that the rules are kind of vague or unclear and so different auditors will have different interpretation of it. You can try to fight it but ultimately the auditor is who needs to sign off on it. This is also why switching auditors can be a right pain.

                Then you get interpretations which are flat out contradicted by the rules. Sometimes this is necessary to make the rules work (there&#x27;s some blanket rule that&#x27;s impractical to impossible to apply literally, so the auditors contort some interpretation that&#x27;s more workable), sometimes it&#x27;s just incompetence, and when it&#x27;s wrong enough to matter sometimes it&#x27;s easier to just go along with it than try to escalate the issue with the auditor.

                You can also get situations where the auditor has their own pet rules, which aren&#x27;t written down anywhere, but they will become much more adversarial if they are not followed (sometimes they&#x27;ll outright tell you what they are, sometimes it&#x27;s a guessing game).

    3. gerdesj · · focus · HN ↗
      &quot;Windows NT 4.0 machine running as late as 2007&quot;

      lol. I know a ... factory, that had a BBC model B (with a rather complicated wiring loom) still doing a job around that time.

      The IT supplier at the same factory went to a museum in Cambs. around late &#x27;90s, early &#x27;00s to ask if they could buy an exhibit because something had failed locally. The museum gave them the part.

      That was just aerospace and nothing fancy like your nuke plant!

    4. icedchai · · focus · HN ↗
      I&#x27;m curious, how did the hardware present itself? It couldn&#x27;t have been an Amiga Zorro card since it would&#x27;ve been impossible to get that into a PC. Did it connect over a serial or parallel port?
      1. freeli · · focus · HN ↗
        I recall it being some custom ISA card with connectors on the back. The emulation software had drivers that interfaced directly with the card.
        1. icedchai · · focus · HN ↗
          Interesting! So they were able to port the hardware but not the software for whatever reason?
          1. ErroneousBosh · · focus · HN ↗
            If it&#x27;s what I suspect it might be, it was probably a generic IO card with maybe a bunch of 8255 PIOs on.
    5. TMWNN · · focus · HN ↗
      &gt;So this is how, in 2007, during a tour of the facility, I stumbled across a Pentium 1 system running an AmigaOS emulator on Windows NT 4.0 that was responsible for displaying the status of the control rods of a nuclear power plant.

      Vernor Vinge&#x27;s A Deepness in the Sky depicts a human society thousands of years in the future, in which pretty much all software has already been written; it&#x27;s just a matter of finding it. So programmer-archaeologists search archives and run code on emulators in emulators in emulators as far back as needed. &lt;<a href="https:&#x2F;&#x2F;web.archive.org&#x2F;web&#x2F;20231114211656&#x2F;http:&#x2F;&#x2F;www.garethrees.org&#x2F;2013&#x2F;06&#x2F;12&#x2F;archaeology&#x2F;" rel="nofollow">https:&#x2F;&#x2F;web.archive.org&#x2F;web&#x2F;20231114211656&#x2F;http:&#x2F;&#x2F;www.gareth...&gt;

      (Heck, recently I migrated a VM to its third hypervisor. It began as a physical machine a quarter century ago.)

    6. ikidd · · focus · HN ↗
      NT4.0 in 2007? That wasn&#x27;t even very late. I was replacing NT4 servers into the early 10s. Car dealerships were terrible for keeping that crap around.
      1. justin66 · · focus · HN ↗
        Interestingly, there are a few places that will sell you a warrantied and new desktop or rackmount PC with a Windows NT 4.0 license. I imagine buyers of their systems are often in similar predicaments, not sure who else would buy these.

        <a href="https:&#x2F;&#x2F;nixsys.com&#x2F;products&#x2F;nx370-t90" rel="nofollow">https:&#x2F;&#x2F;nixsys.com&#x2F;products&#x2F;nx370-t90

        There are some things I don&#x27;t understand about the OP&#x27;s constraints (are you sure you can&#x27;t run that Amiga VM on a newer version of Windows, or better yet, run that Amiga-based software on one of the currently supported Amiga VMs?). But they can probably pretty easily keep going as they&#x27;re going with this software until some other, more significant thing in that plant becomes fully obsolete and the place is shut down.

    7. DoctorDabadedoo · · focus · HN ↗
      I wonder if there is push in the public sector for open source software&#x2F;hardware for cases like this.

      I completely get the decisions over time here, but it&#x27;s unsettling having a relevant piece of software (reports are important too!) working on with parts from ebay, in 50 years time they might be gone.

      1. NegativeK · · focus · HN ↗
        I&#x27;ve dreamt of governments hiring devs with promises of full time OSS work. It _might_ get some people over the lower salaries of government work. But I overheard a state CIO once say &quot;We configure, we don&#x27;t create&quot;.

        That&#x27;s to say nothing about opinions of open source that rival early 2000s Microsoft.

        For old ass critical software and hardware, the org can always have a backlog of hardware and contingency plans (paying someone to fix the hardware, paying someone to create a fully certified and modern solution..) for when they start running out of parts.

      2. [deleted] · · focus · HN ↗

        [deleted]

    8. Froedlich · · focus · HN ↗
      A friend works for an airline as a flight simulator tech. Their entire software stack, including the compiler and OS, is FAA-certified.

      Then their ancient Honeywell(?) mainframes reached end-of-life they scouted for compatible hardware, of which there was none. The cost of certifying new software, plus the time involved, was astronomical. So, after consulting with the FAA, they paid a hardware company to clone the ancient mainframes in modern silicon. The FAA signed off on it, and they had all-new computers - much smaller than the originals - running the old stack.

      1. betaby · · focus · HN ↗
        That&#x27;s interesting. That means there are fewer checks for hardware than software?
        1. soulofmischief · · focus · HN ↗
          Hardware is more amenable to static analysis than running programs which may receive an arbitrary number of inputs and express an arbitrary number of possible intermediate states.

          I am interested in how firmware is treated, since perhaps in the case of these old machines it&#x27;s small enough to be analyzable or at least cloned bit-for-bit.

        2. hulitu · · focus · HN ↗
          Software &quot;engineers&quot; like to abstract things. This doesn&#x27;t pay well e with reliability.
          1. jagged-chisel · · focus · HN ↗
            You have inspired a blog post. World, be warned!
      2. zx8080 · · focus · HN ↗
        It&#x27;s _very_ hard to believe some company to simply &quot;clone the mainframe&quot; into chip. Mind sharing any link to this effort?
        1. vincent-manis · · focus · HN ↗
          When Xerox established PARC, they asked the assembled scientists what computer they wanted. The majority view was a DEC PDP-10 KA10, with the BBN memory management unit that let it run Tenex (the ancestor of DEC TOPS-20). Xerox couldn&#x27;t really buy a competitor&#x27;s mainframe, so they built MAXC (maximum access computer), which was a complete emulation of the Tenex machines.
          1. zem · · focus · HN ↗
            very apt that xerox parc was full of tenex engineers!
          2. fsckboy · · focus · HN ↗
            &gt;MAXC (maximum access computer), which was a complete emulation of the Tenex machines.

            Compuserve also had a software dependency on the PDP-10 and Decsystem 20, and when those machines were no longer available they bought a company making clones so they could continue to manufacture them for themselves. The company they bought, Microsolutions, was Mark Cuban&#x27;s first startup.

            making clones of mainframes (IBM&#x27;s) had been a big area of intellectual property litigation, but also facing monopolization investigations, IBM had to allow them. They were referred to as &quot;plug compatibles&quot;.

            1. FrankWilhoit · · focus · HN ↗
              The clone hardware manufacturer was Systems Concepts. Microsolutions was a software play -- I think they had something to do with trying to port 1022&#x2F;1032.
        2. znpy · · focus · HN ↗
          Meh, old architectures are relatively simple and you can get 95% of those via fpga softcores (some freely available, some paid) and run them on fpga. The rest can be implemented by a proper ee team.
        3. theodric · · focus · HN ↗
          I mean...there&#x27;s some precedent. The XKL TOAD (&quot;Ten On A Desk&quot;) implements the PDP-10 instruction set, and will happily run TOPS-10&#x2F;TOPS-20. LCM had one doing just that.

          <a href="https:&#x2F;&#x2F;www.computerhistory.org&#x2F;collections&#x2F;catalog&#x2F;102773832&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.computerhistory.org&#x2F;collections&#x2F;catalog&#x2F;10277383... <a href="https:&#x2F;&#x2F;www.twenex.org&#x2F;?network" rel="nofollow">https:&#x2F;&#x2F;www.twenex.org&#x2F;?network

          1. hapless · · focus · HN ↗
            XKL is still in business (<a href="https:&#x2F;&#x2F;xkl.com&#x2F;" rel="nofollow">https:&#x2F;&#x2F;xkl.com&#x2F;)

            as far as i know the control plane on their equipment is still a pdp-10 compatible

          2. DonHopkins · · focus · HN ↗
            It&#x27;s tempting to write a PDP-10 emulator for the Atari ST called TOAST.

            FWIW I&#x27;m developing &quot;tiny-titan&quot;, a stand-in for Cambridge&#x27;s Titan mainframe that talks to Heinz Lemke&#x27;s 1972 PIXIE program over an emulated version of Neil Wiseman&#x27;s PDP-7 &lt;=&gt; Titan link. It doesn&#x27;t emulate Titan itself, just the conversation PIXIE had with it, so the unmodified 1972 PDP-7 code dials home and uploads its drawings.

            <a href="https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Titan_(1963_computer)" rel="nofollow">https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Titan_(1963_computer)

            &gt;Titan was the prototype of the Atlas 2 computer developed by Ferranti and the University of Cambridge Mathematical Laboratory in Cambridge, England. It was designed starting in 1963, and in operation from 1964 to 1973.

            <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=49407938">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=49407938

            <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=40617894">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=40617894

            Flight of the PIXIE - Yuja Wang:

            <a href="https:&#x2F;&#x2F;www.youtube.com&#x2F;watch?v=jDrqR9XssJI" rel="nofollow">https:&#x2F;&#x2F;www.youtube.com&#x2F;watch?v=jDrqR9XssJI

            UNIVERSITY MATHEMATICAL LABORATORY, CAMBRIDGE: Cambridge Supervisor - Planning Document 10 Software for the Titan&#x2F;PDP-7 link:

            <a href="https:&#x2F;&#x2F;cucps.soc.srcf.net&#x2F;titan&#x2F;supplan&#x2F;pd10.htm" rel="nofollow">https:&#x2F;&#x2F;cucps.soc.srcf.net&#x2F;titan&#x2F;supplan&#x2F;pd10.htm

            Here is a photo of Heinz Lemke operating PIXIE with the light pen and 340 display on the PDP-7 (also seen in the video above):

            <a href="https:&#x2F;&#x2F;www.facebook.com&#x2F;groups&#x2F;779220482206901&#x2F;posts&#x2F;6297725037023057&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.facebook.com&#x2F;groups&#x2F;779220482206901&#x2F;posts&#x2F;629772...

            1. theodric · · focus · HN ↗
              Fascinating stuff; thank you for sharing. Can I follow your work somewhere??
              1. DonHopkins · · focus · HN ↗
                Thanks! I&#x27;m in the process of bailing from Medium, and I&#x27;m moving my stuff to a reimplemention of HyperTIES, the hypermedia browser I developed for NeWS in 1987-1990 at the University of Maryland Human Computer Interaction Lab, and I&#x27;m dogfooding it to publish all my other stuff:

                <a href="https:&#x2F;&#x2F;hyperties.org" rel="nofollow">https:&#x2F;&#x2F;hyperties.org

                Ostensibly the site is about HyperTIES itself, but I&#x27;m publishing other stuff there too like a PDP-7 emulator!

                <a href="https:&#x2F;&#x2F;hyperties.org&#x2F;databases&#x2F;pixie&#x2F;pixie-live&#x2F;" rel="nofollow">https:&#x2F;&#x2F;hyperties.org&#x2F;databases&#x2F;pixie&#x2F;pixie-live&#x2F;

                Here&#x27;s a part of the demo I was giving at EduCom in October 1988 at the Sun booth on the trade show floor, across from the NeXT booth, where Steve Jobs and Bill Joy came by. Because he had shaved his beard, I didn&#x27;t realize it was Bill Joy when I was showing him a demo of his head popping up! He took it pretty well though, better than Jobs.

                <a href="https:&#x2F;&#x2F;hyperties.org&#x2F;databases&#x2F;playground&#x2F;sun-founders-big-heads&#x2F;" rel="nofollow">https:&#x2F;&#x2F;hyperties.org&#x2F;databases&#x2F;playground&#x2F;sun-founders-big-...

                Here&#x27;s a paper looking back at HyperTIES:

                <a href="https:&#x2F;&#x2F;hyperties.org&#x2F;databases&#x2F;hyperties&#x2F;a-look-back&#x2F;" rel="nofollow">https:&#x2F;&#x2F;hyperties.org&#x2F;databases&#x2F;hyperties&#x2F;a-look-back&#x2F;

          3. anthk · · focus · HN ↗
            I&#x27;d happily run ITS on that.
        4. mitxela · · focus · HN ↗
          Custom chips aren&#x27;t as expensive as you think. About a few million dollars for the design and a hundred thousand chips, way out of reach for a hobbyist, but accessible to large enough companies. Just because it&#x27;s opaque to us software people doesn&#x27;t mean it&#x27;s not a real industry you can buy things from.
          1. realo · · focus · HN ↗
            And all that expensive engineering is still less costly AND faster (!!) than a new software certification.

            Cannot refrain myself from asking why ...

            1. ianjbutler · · focus · HN ↗
              Situation: Software-1 on Platform-1, both certified.

              Time-evolution: P1 is deprecated, replaced by uncertified P2, but S1 remains certified.. just nowhere certified to run yet.

              Solution: There&#x27;s another software S2 which originally vouched for P1, itself still certified, which can still be used to certify P2.

              Counterfactual?: If S1 were deprecated in favor of new S3.. there&#x27;d be no plan to certify it!

              The problem: None of this actually makes any sense! But we&#x27;re trying to fake due diligence. Everyone knows the hardware&#x2F;platforms kinda need to be certified with respect to each other anyway, but if we did it that way it would all be even more expensive an time-consuming.

            2. mitxela · · focus · HN ↗
              Doesn&#x27;t seem crazy to me. Which one do you suppose needs more proof of correctness: a cake recipe, or the oven you bake the cake in? The recipe has to be correct or the cake won&#x27;t work, but the oven just has to hold a temperature.
              1. realo · · focus · HN ↗
                That &quot;just&quot; is quite the load-bearing seam ...

                Particularly when the task here is &quot;just&quot; to measure some rod positions in a constrained 3D space ...

              2. starky · · focus · HN ↗
                Ovens vary greatly. There is no consistency in how even the heat is in the space, the airflow through the space, how much and how fast the temperature varies around the set temperature, etc. These things all do affect how things bake up and often people have to tweak recipes for their specific oven.

                In a case where something is safety critical the computer is super important as very subtle errors could cause catastrophic consequences. This is why you get into things like running software on 3+ computers concurrently depending on how fail-safe something has to be.

        5. flyinghamster · · focus · HN ↗
          It could be an FPGA. Given enough gates, and the know-how to program them, you can make an FPGA emulate anything. Speed and efficiency could be better or worse, but if you&#x27;re targeting old hardware, better is likely.
        6. jasomill · · focus · HN ↗
          IBM released the PC XT&#x2F;370[1], built around a pair of 68000s and an 8087 with custom microcode to emulate System&#x2F;370 instructions, in 1983.

          It&#x27;s not hard to imagine a similar system fabricated around an open or licensed processor core today being well within the budget of a major airline today.

          Software emulation would no doubt be less expensive, but there could have been regulatory reasons for building plug-compatible hardware.

          [1] <a href="https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;PC-based_IBM_mainframe-compatible_systems#Personal_Computer_XT&#x2F;370" rel="nofollow">https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;PC-based_IBM_mainframe-compati...

      3. fsckboy · · focus · HN ↗
        &gt;Then their ancient Honeywell(?) mainframes...

        <a href="https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;GE-600_series" rel="nofollow">https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;GE-600_series from the 36-bit era which turned out to be a sweet-spot for Lisp; also &quot;famous&quot; for running Multics (old joke flipped: &quot;which was many of whatever unix is one of&quot;)

        GE sold it&#x27;s division to Honeywell, and from there to Group Bull (French) and then to NEC (Japan)

        1. DonHopkins · · focus · HN ↗
          Moltix would have been a better name than OpenClaw.
        2. jasomill · · focus · HN ↗
          Also immortalized as the name of the &quot;gecos&quot; field in the UNIX passwd(5) file, described in the v7 man page[1] as &quot;GCOS job number, box number, optional GCOS user-id&quot; (GCOS = GECOS after the Honeywell acquisition).

          [1] <a href="https:&#x2F;&#x2F;man.freebsd.org&#x2F;cgi&#x2F;man.cgi?query=passwd&amp;apropos=0&amp;sektion=5&amp;manpath=Unix+Seventh+Edition&amp;format=html" rel="nofollow">https:&#x2F;&#x2F;man.freebsd.org&#x2F;cgi&#x2F;man.cgi?query=passwd&amp;apropos=0&amp;s...

      4. bitwize · · focus · HN ↗
        There&#x27;s a mechanical tank simulator at the Swiss Military Museum that was built in the 1970s and used for actual service before being retired and becoming a museum piece:

        <a href="https:&#x2F;&#x2F;www.youtube.com&#x2F;watch?v=AcQifPHcMLE" rel="nofollow">https:&#x2F;&#x2F;www.youtube.com&#x2F;watch?v=AcQifPHcMLE

        The simulator has a simulated cockpit for the user, which controls an armature with a camera attached that is piloted around a miniature battlefield environment and provides a video feed to the cockpit. A &quot;foot&quot; on the armature senses terrain elevation changes, which are then supplied as movement feedback to the simulated tank cockpit. All of this was controlled by a 1970s mainframe, for which replacement parts were unavailable so it was replaced, in the museum exhibit, with a Raspberry Pi.

        It looks like hardware emulation was NOT used; rather, they translated the original program from paper printouts to a modern programming language: <a href="https:&#x2F;&#x2F;www.raspberrypi.com&#x2F;news&#x2F;simulate-driving-a-1970s-tank-with-raspberry-pi&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.raspberrypi.com&#x2F;news&#x2F;simulate-driving-a-1970s-ta...

    9. vincent-manis · · focus · HN ↗
      This reminds me of the apocryphal story of the IBM System&#x2F;360 running a 1410 emulator that ran an IBM 705 simulator that ran a business-critical application.
      1. genxy · · focus · HN ↗
        Which is why we should target VMs directly. Then that VM can be brought forward to new platforms rather than emulating the entire machine, not that emulating the entire machine is bad. One could argue that the emulation stack you outline was made possible by putting in the work to make simple, fully specified and documented hardware.
      2. JdeBP · · focus · HN ↗
        Not wholly apocryphal. The U.K.&#x27;s air traffic control ran, and possibly still is running, on an IBM 4381 substituting for an IBM 9020.

        * <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=49763972">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=49763972

        They&#x27;ve reportedly already tried, and failed, to replace it with a more modern system.

    10. slicktux · · focus · HN ↗
      Was this status indicator simple vertical bars that were black and white and displayed on an old CRT Monitor? Almost looks like black and white terminal vertical bars (like Alsamixer)?
    11. tombert · · focus · HN ↗
      I find it deeply upsetting that anything important for a nuclear power plant is using an OS without protected memory.
      1. M95D · · focus · HN ↗
        Protected against what?
        1. tombert · · focus · HN ↗
          Just another program poking memory it’s not supposed to. Not even necessarily maliciously.
          1. JdeBP · · focus · HN ↗
            That AmigaDOS emulation will almost certainly never run another program. (-:

            Far more concerning from a RISKS point of view is the spare parts being physically in the same place as the live machine.

          2. thesuperbigfrog · · focus · HN ↗
            &gt; Just another program poking memory it’s not supposed to. Not even necessarily maliciously.

            What other program? Most DOS versions were not multi-tasking beyond &quot;terminate-and-stay-resident&quot; (TSR) programs like mouse drivers.

            Whatever application you ran on DOS was THE application your computer was running.

            1. LocalH · · focus · HN ↗
              We&#x27;re not talking about DOS here. This is AmigaOS, a fully preemptively multitasked OS from day one. No memory protection, but unless your code is running on bare metal like demos and games, there are other tasks running.

              Top parent of this thread is talking about a package for AmigaOS being run on a bespoke emulator (as the Unusable Amiga Emulator of the 90s wasn’t really a thing that could be used for that)

        2. Peanuts99 · · focus · HN ↗
          Bit flips from cosmic radiation. Pretty common.
          1. throawayonthe · · focus · HN ↗
            they probably mean <a href="https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Memory_protection" rel="nofollow">https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Memory_protection actually
      2. wat10000 · · focus · HN ↗
        You don&#x27;t need protected memory if your program is the only thing running. Plenty of microcontrollers have no protected memory and get used in safety critical applications.
    12. ptek · · focus · HN ↗
      If it&#x27;s still running I wonder what they are going to do about the year 2038.
      1. mitxela · · focus · HN ↗
        Set the date back to 1980 and sticky tape over the corner of the screen where the date is displayed.
    13. sajithdilshan · · focus · HN ↗
      This is crazy. Why on earth wouldn’t the respective government spend money to modernize a critical infrastructure like a nuclear power plant?

      This is how we would end up with nuclear disasters, not because the technology is bad, but purely because of mismanagement and human negligence.

      1. onion2k · · focus · HN ↗
        This is crazy. Why on earth wouldn’t the respective government spend money to modernize a critical infrastructure like a nuclear power plant?

        Safety and reliability come from understanding the system. Something that&#x27;s old but that you know everything about is far safer than something new. This risk is that the people who know move on, or the sources of replacement parts stop working, or that other things around the system change. Then the risk curve inverts and you find the old system more of a liability than a asset.

        Almost always people choose to update things either too early or too late. Knowing when to do something is hard.

        1. sajithdilshan · · focus · HN ↗
          That’s pure negligence. It’s not like the people that have the know how disappear suddenly . It’s the responsibility of the management to make sure the knowledge transferred to new generation.

          I guess that kind of thinking is what led to the collapse of ancient civilisations like why even bother to improve anything and let everything decay and die out

          1. somenameforme · · focus · HN ↗
            You can only say such things with hindsight. In the moment, nobody knows what the future will hold. Take the space program in the US for instance. In 1969 we landed a man on the Moon. We&#x27;d repeat that several times until 1972. At that point Nixon made a speech which implied various unpleasant things about space&#x27;s future, but he&#x27;d be out of office, disgraced, a couple of years later, so how big a deal could it have been anyhow?

            I think almost nobody from that era would have believed you if you told them that more than 50 years later not a single human would have traveled beyond low Earth orbit, and that we&#x27;d now be struggling to recreate what we did in 1969. Furthermore a significant chunk of the world doesn&#x27;t even believe we landed on the Moon anymore, no doubt in part because of this apparent anachronism.

            It&#x27;s not like there was any sort of collective or even singular decision to just let things die out. I mean sure Nixon did his thing intentionally, but even as a President in the golden years of the US, he was still just one man.

            1. ac29 · · focus · HN ↗
              &gt; I think almost nobody from that era would have believed you if you told them that more than 50 years later not a single human would have traveled beyond low Earth orbit

              Four people went around the moon earlier this year (leaving earth&#x27;s orbit for the first time since &#x27;72)

          2. onion2k · · focus · HN ↗
            It’s the responsibility of the management to make sure the knowledge transferred to new generation.

            That&#x27;s just lazy thinking, and probably a sign you&#x27;ve never been a manager. For all the responsibility to lie with management you&#x27;d have to be leading people who enthusiastically do what they&#x27;re asked to do, raise problems, document things, follow processes, and make sure everything is handed over to the next person when they leave.

            That&#x27;s not how people are. They&#x27;ll have times when they&#x27;re unmotivated, underpaid, grumpy, over-worked so they miss things, etc. That&#x27;s when the organisational tech debt starts piling up, and there&#x27;s nothing a manager can do to stop it except manage it as best they can even though they&#x27;re under the same pressure, with the same lack of motivation and crap pay as everyone else.

            It&#x27;s so easy to think you can fix it just by keeping on top of it and micromanaging where it starts to show up. It doesn&#x27;t work that way.

            1. jagged-chisel · · focus · HN ↗
              &gt; … underpaid … over-worked

              These two (and many others) are well within management’s purview.

              &gt; … there&#x27;s nothing a manager can do … [emphasis added]

              Right, but Management (capitalized and plural) can. A manager should report, and management should fix - if not, it’s management’s fault.

              1. onion2k · · focus · HN ↗
                The Management of a company is a group of managers. There&#x27;s no real difference between the group and the collective.

                The fact that you&#x27;re willing to absolve an individual manager but still believe Management can fix the problems is a big part of the problem. The Management usually includes the last person in the chain who has the ultimate decision making power. If you assume that when I said &#x27;a manager&#x27; I meant that person, it should be fairly obvious that even they don&#x27;t have unlimited budget or unlimited time, and they can only try to fix problems they hear about. Within those constraints Management are still going to find fixing systemic problems hard.

                It&#x27;s very easy to look at something with hindsight and think the outcome should have been predicted and corrected. If you look at the real world you&#x27;ll see that just isn&#x27;t the case. Personally, I wish we had a lot more people applying some systems thinking approaches to at least consider the second- and third-order impacts of their decisions but I imagine that won&#x27;t ever happen. It makes me sad because it&#x27;s actually really interesting.

          3. jodrellblank · · focus · HN ↗
            Basically everything collapses as far as it is allowed to, and the collapse is slowed only by:

            - profit, if a system generates it, people will keep the system running.

            - dilligence, usually driven by personal idealism, and unrewarded.

            - legal or financial penalties, or insurance costs.

            - it has collapsed to a temporarily stable state for now.

            For another comment I was looking at the Grenfell Tower fire in the UK around 2017 and the people who lived there had been raising fire risks for years and the landlord (management organization) and the council had been ignoring them, and ignoring the fire department. The companies which replaced the cladding on the tower with flammable cladding were choosing the cheaper flammable option and pointing fingers as well. And during the fire, the fire service had never dealt with such a big fire and didn&#x27;t have a truck with a long ladder, didn&#x27;t have extended-breathing gear, had radio problems, water pressure problems from the local water company (who deny that).

            This kind of backstory is typical for disasters, and for IT outages - and I&#x27;ve taken to believing that if something &quot;should work&quot; but wasn&#x27;t tested recently then you should expect that it doesn&#x27;t work. This is a common saying in backups (you need to test restoring), but it seems to apply everywhere. Backup internet connections that don&#x27;t have enough bandwidth for the company to keep running. Disaster recovery sites that share resources with the production site. &#x27;Disaster recovery&#x27; that recovered into a remote site, but they couldn&#x27;t do CAD work remotely over their slow connection so it was still disastrous. Multiple power feeds but they were cross-wired so one failing still functionall took down everything.

            If knowledge transfer &quot;should be happening&quot; but it&#x27;s not critical to a job, or it&#x27;s not profitable, or it&#x27;s not legally required and audited, then it isn&#x27;t happening. Subject to the dilligent idealist employee mentioned above who are temporary in the long view. Management&#x27;s involvement seems not to arrange the larger system to effectively shoulder responsibility, but rather find ways to avoid personal blame while cutting costs beyond the point where everything that needs to happen keeps happening.

      2. cromka · · focus · HN ↗
        If it&#x27;s not broken, don&#x27;t fix it.

        Same reason why MTA in NYC still operates subway using 100 y&#x2F;o signaling hardware on most of the lines.

        In a way, your comment and the responses you get is a perfect allegory to inexperienced vs experienced engineering.

        1. sajithdilshan · · focus · HN ↗
          &gt; If it&#x27;s not broken, don&#x27;t fix it.

          I understand that way of thinking for a small business computer system. Not for a critical infrastructure. Also if people actually thought about like that we would still be in stone age, like why invent something new or use a new technology? Keep on using rocks to crack nuts and kill animals

          1. sokoloff · · focus · HN ↗
            I think you can imagine the difference between “I did some work and made this thing that is clearly better, but we might have a few kinks to work out” and “I did some work, and if I did it perfectly, it’s just as good as the old thing, but we might have a few kinks to work out.”
          2. pezezin · · focus · HN ↗
            I agree with you. First, &quot;broken&quot; is not a binary, it might not be broken but it might not work well either. Second, sooner or later everything breaks, and you better be ready for when that happens.
        2. mitxela · · focus · HN ↗
          Their 100 y&#x2F;o hardware is built from stuff that&#x27;s still produced though. We still make relays (not identical ones but ones that perform the same function), wires, and mechanical levers. The system&#x27;s behavior is not encoded in the relays but in the connections between them. If you had a CPU made of separate transistors you could replace burned out transistors with any future transistors but if you had one made of chips you&#x27;d need those exact chips that were out of production.

          Replacing the relays in old telephone switches is a problem because they use so many weirdly specific types of relays - but those systems are only found in museums now. I believe track control uses fairly ordinary DPDT, etc., relay designs.

        3. jodrellblank · · focus · HN ↗
          But similar reasoning is why Canadian trams are worse than other countries, and it&#x27;s not &quot;good experienced engineering&quot;. In this nearly hour long rant by NotJustBikes[1] the section I&#x27;ve linked is about the technology and how the transit authority will not move on from 100 year old track technology which makes everything worse for customers. There are junctions where tram drivers have to stop and look at the track to make sure the junction is correctly set because the single-point switching is less reliable than modern designs. Or the driver has to stop the tram and get out to use a stick to move the track and change the junction because they aren&#x27;t electrified. And then pass through junctions as slowly as 10km&#x2F;h because the old track design has higher risk of derailment than modern designs.

          The designs for the electrified track switches were made by one company which was sold, re-sold, and then burned down and the designs lost, and there isn&#x27;t anywhere else to buy them because nowhere else uses such old track design anymore, so not only is Toronto struggling to buy parts to continue electrifying the manual junctions, it&#x27;s struggling to custom-make enough replacement parts to keep the aging electric switches working faster than they fail.

          And they were using trolley poles to connect to the overhead power lines instead of Pantographs until 2017, 50-100 years after everywhere else, which meant a) they couldn&#x27;t get enough power through them to run air conditioning, and b) they are more likely to fall off the power line and the tram stops and the driver has to get out and reconnect them, and c) their newer trams now have to have custom dual-power connections to go through older parts of the network, and d) the carbon shoes on the trolley poles wear out quicker which means the trams are dirtier and taken out of service for maintenance more often in the wet which is when people want to use trams more.

          [1] <a href="https:&#x2F;&#x2F;youtu.be&#x2F;HhQxNHrD6fA?t=2311" rel="nofollow">https:&#x2F;&#x2F;youtu.be&#x2F;HhQxNHrD6fA?t=2311

          1. cromka · · focus · HN ↗
            OK, but the context here is IT in mission critical infrastructure, like energy or banking. These industries will not jump on the latest technology and will drag their feet for as long as possible, and for good reasons.

            Also, I happen to be familiar with NotJustBikes, watch regularly. I don&#x27;t see this as the same kind of problem. What you explained is clearly BROKE. What we&#x27;re talking about works just fine and migration to newer technology doesn&#x27;t provide advantages outside easier maintenance. It can&#x27;t be justifies by costs, either.

        4. Spooky23 · · focus · HN ↗
          A friend discovered that one of the more modern pieces of equipment instrumenting those old signals was an ancient WYSE terminal from the late 90s that had been bricked over during a station project.

          They moved a booth or something and the compartment it was stuffed in was missed during the cleanout. The thing was working for at least 20 years and may still be there!

          I worked with a client that had a cash disbursement system working on an ancient dBase 16-bit application. They had a very difficult to change process that required multiple transactions because the system couldn&#x27;t represent the dollar amounts appropriately.

      3. cube00 · · focus · HN ↗
        &gt; Why on earth wouldn’t the respective government spend money to modernize a critical infrastructure like a nuclear power plant?

        Same reason they don&#x27;t modernize health care infrastructure. It&#x27;s too expensive, people die if they get it wrong and they get voted out of office for their troubles.

      4. mitxela · · focus · HN ↗
        Now you know why &quot;nuclear power may have been dangerous in the past, but with modern technology it&#x27;s completely safe and Chernobyl will never happen again&quot; is not a good argument.
        1. idiotsecant · · focus · HN ↗

          [dead]

        2. sajithdilshan · · focus · HN ↗
          Chernobyl didn’t happen because of technological blunder or even human negligence. It happened because poverty caused by communism in Soviet Union had to use old outdated (not the modern nuclear technology at that time) graphite tips in carbon rods because it was cheap and also kept it as a secret from the facility operators giving them a false sense of trust on the kill switch.

          Chernobyl is the perfect example to not use outdated old technology. Had they used the modern western technology at that time to upgrade their nuclear reactors the kill switch would have prevented the whole disaster instead of increasing the neutrons make the core a nuclear bomb.

          Next time educate yourself with facts before making a fool out of yourself

          1. lukan · · focus · HN ↗
            &quot;Had they used the modern western technology&quot; ... &quot;Next time educate yourself with facts before making a fool out of yourself&quot;

            But you are aware that this thread is about a reactor in the west, that &quot;updated&quot; their certified hardware to a VM instead running on windows NT?

            1. mitxela · · focus · HN ↗
              Everyone knows that all technology newer than Windows 2.0 will never be obsolete!
          2. HPsquared · · focus · HN ↗
            Chernobyl was very much not &quot;old&quot;, it was a more modern design than the PWRs which are built today. Chernobyl Unit 4 was also basically brand new, only 3 years old at the time of the disaster. The RBMK design dates from the 60s, whereas the PWR is from the 40s.
          3. jodrellblank · · focus · HN ↗
            &gt; old outdated

            Wikipedia&#x27;s pages on Chernobyl say that construction started in 1972 and the problem with the control rods causing an initial spike of power was discovered in 1983 ?

            [1] <a href="https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Chernobyl_Nuclear_Power_Plant" rel="nofollow">https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Chernobyl_Nuclear_Power_Plant

            [2] <a href="https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Chernobyl_disaster#Accident_sequence" rel="nofollow">https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Chernobyl_disaster#Accident_se... (search &#x27;Ignalina nuclear power plant&#x27;)

      5. philipallstar · · focus · HN ↗
        &gt; This is how we would end up with nuclear disasters, not because the technology is bad, but purely because of mismanagement and human negligence.

        I&#x27;m pretty sure constant upgrading would be more likely to cause disasters.

        1. VBprogrammer · · focus · HN ↗
          I can only imagine how much less reliable a modern JavaScript Electron app would be in this role...
      6. IG_Semmelweiss · · focus · HN ↗
        Lindy&#x27;s law:

        For non-perishable things - i.e technologies, ideas, books, institutions - the expected remaining lifespan is roughly proportional to how long they have already survived

        Time acts as a filter: what has already withstood a long stretch of disorder is more robust, so the longer it lasts, the longer it is expected to last.

        The old nuclear software running on mainframes have passed the test of time. The new software, has yet to.

        Nassim Taleb talks about this at length in his book, Antifragile.

      7. carlosjobim · · focus · HN ↗
        There is no reason a more modern system would be better in any aspect.
      8. sgarland · · focus · HN ↗
        Because what they have works well enough to be NRC-certified, and they have enough spare parts to comfortably outlast the rated lifetime of the reactor.

        Relevant: <a href="https:&#x2F;&#x2F;www.joelonsoftware.com&#x2F;2000&#x2F;04&#x2F;06&#x2F;things-you-should-never-do-part-i&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.joelonsoftware.com&#x2F;2000&#x2F;04&#x2F;06&#x2F;things-you-should-...

      9. elzbardico · · focus · HN ↗
        Frankly, if not for the issue of components aging I would trust 1970s PDP-11 or even a PC-XT running MS-DOS a lot more than a modern system. This vintage&#x27;s hardware was extremely mature and simple to understand and operate. No Ghz buses, no multiple levels of caching, no speculative execution and long pipelines.

        DOS was a single task operating system. Once you proved such a system could run for days, months and years, there&#x27;s no reason for it not to function 50 years later other than component failure.

    14. throwaway2037 · · focus · HN ↗
      This is a great post. How does someone write software that needs to run for ~50 years where the hardware will need to be replaced with non-equivalent, newer hardware? If I were facing this issue today, I might start with an OS that has excellent emulation. Example: Can I run 32-bit MS Windows 95 via emulation on a variety of current 64-bit OSes, like MS Windows, Linux, AIX, HP-UX, etc. If yes, then we can assume(?) this emulation will remain relatively stable even if we upgrade our hardware later. Maybe I am overthinking the whole problem: Can VMs do exactly what I want today? Will VMs running ancient OSes, such as 32-bit MS Windows 95, continue to be stable&#x2F;viable in the future? I am unsure.
      1. dmos62 · · focus · HN ↗
        &gt; how does someone write software that needs to run for ~50 years where the hardware will need to be replaced with non-equivalent, newer hardware?

        Make it open-source, or don&#x27;t buy without source.

        1. booty · · focus · HN ↗
          It&#x27;s interesting to think about this in the context of parent poster&#x27;s story about the Amiga emulator in the nuclear power plant.

          Or, more broadly, in the context of any situation where the software is closely coupled to a specific operating system and&#x2F;or hardware.

          Having the source code would have helped tremendously, but might not have been sufficient because of the hardware story and the regulatory approval factor.

        2. jmalicki · · focus · HN ↗
          You don&#x27;t need source anymore. Have Claude Code look at the binary and write a new program.
          1. esafak · · focus · HN ↗
            I wouldn&#x27;t rely on that for mission critical systems.
      2. jl6 · · focus · HN ↗
        &gt; How does someone write software that needs to run for ~50 years where the hardware will need to be replaced with non-equivalent, newer hardware?

        Some ideas:

        Write it in a popular language&#x2F;ecosystem, stick rigidly to well-defined APIs, use commodity hardware, flatten out any malignant cleverness, maintain documentation on why every part does the thing it does, and make the source code readily available.

        This is based on working with some very old systems, and each point above is the opposite of something that made life harder.

        1. inopinatus · · focus · HN ↗
          Unfortunately, “popular language&#x2F;ecosystem” includes JavaScript and PHP.

          I’d go for “universal and timeless”, which has meant C for several decades now. There is, I’d concede, a reasonable chance that Rust obtains that label in our lifetimes.

          1. cozzyd · · focus · HN ↗
            And worse for posterity, Python
          2. asa400 · · focus · HN ↗
            Yeah agreed. Popular is a good first approximation, but to be more precise I think you want tools where the incentives in the community reward stability over features that require breakage, which would include languages and runtimes like Erlang and Clojure.

            Neither is popular when compared to for example Python or PHP, but they both have cultures that care about stability in the core runtime and the libraries. Most folks probably don’t know that about Erlang and maybe think it’s some new whiz-bang thing, but Erlang is incredibly stable and well supported by a dedicated team that has been doing it for years and years at this point. I don’t know if Erlang will be more or less popular in 20 years but it 100% will be around and be receiving updates, I would put money on it.

          3. very-old-sw · · focus · HN ↗
            My C programs from a few decades ago, before namespaces were invented, no longer compile. However, the old executables still execute. The old C compilers are available but not supported; ChatGPT warns to expect trouble. Perhaps maybe there are compatibility switches that work correctly. Using them would require changing the makefiles.
        2. brudgers · · focus · HN ↗
          The Amiga was a popular ecosystem.
          1. jl6 · · focus · HN ↗
            And as a result it&#x27;s very well emulated, making it very likely that Amiga code can still be run in 50 years&#x27; time.
            1. brudgers · · focus · HN ↗
              Today. That was not true a few years ago.
              1. badsectoracula · · focus · HN ↗
                I remember Amiga emulators (notice the plural) going all the way back to when i was in high school - and that was around 1999-2001 or so.
                1. brudgers · · focus · HN ↗
                  That was about the time frame of the commercial Windows NT emulator mentioned up thread. There was a market for them.

                  Today’s landscape is shaped by the pandemic. In between, there were many years of impracticality.

        3. OCTAGRAM · · focus · HN ↗
          Perl was popular
      3. ninalanyon · · focus · HN ↗
        Make sure that you have as thorough a specification of what the system is supposed to do as you can.

        Then define the version control system and the build process, specifying the dependencies, and so on.

        Think about any opaque blobs in the system and try to eliminate them so that you have plain text source code so that no tools are needed to read the code.

        Make sure that the build process runs entirely locally and never fetches anything from outside.

        Simplify everything, use only tools and languages that are well understood and supported.

        The real problems are not strictly technical but social: how do you prevent loss of the code, the tools, the specification, how do you maintain the expertise needed to maintain it. How do you ensure that all those things that are obvious to you now are written down in all their gory detail so that your great grandchildren will not apply their new and different preconceived ideas to the system?

        Document all this on paper as well as electronic storage, make sure that version ids are recorded on every page as well as being available to the user of the machine or program.

        In the industry in which I worked for the last thirty years of my career it was not uncommon to have things come back for repair after fifty years use and to be able to consult the original drawings and bill of materials so that exact replacement parts could be made.

        1. rrr_oh_man · · focus · HN ↗
          What is this industry, if I may ask?
          1. ninalanyon · · focus · HN ↗
            Electricity distribution, mainly transformers from 10 kVA to 500 MVA and more.

            It takes a long time to design and a lot of material to make a big transformer and they last for decades. They are critical infrastructure so when one fails you want it replaced or repaired quickly but they are too expensive (millions of dollars&#x2F;pounds&#x2F;euros) to keep a spare unit idle for decades and the lead time for a new large power transformer might be six months or even longer. So repair makes sense, especially if it can be done on site because moving a big metal box full of oil, steel, and copper that weighs hundreds of tonnes is a major logistical exercise.

            This isn&#x27;t something that can be done by a company that &#x27;moves fast and breaks things&#x27; and disappears next year.

            1. throwaway2037 · · focus · HN ↗
              Hat tip for the first hand details. I sound like a broken record at this point: Posts like make are the secret sauce of HN. It is the main reason why I come back time and time again.

              There must be some extremely salty machinists that get bizarre part requests after breakage for some transformer from 1950. That could make a very cool YouTube video series: Following these machinists and repair people as their repair very old transformers.

              1. ninalanyon · · focus · HN ↗
                Transformers are pretty simple machines, no moving parts so there aren&#x27;t all that many complicated bits except in the tap changer. But what is there has to be just right and a lot of the critical details are made of paper.

                But of course many such transformers are connected to equally old generators and they are a bit more challenging as far as making replacement parts is concerned, huge turbines for instance.

      4. ndsipa_pomu · · focus · HN ↗
        I&#x27;d recommend not having it so dependent on the hardware and choose an OS that is relatively hardware agnostic (e.g. Linux). Also, ensure that the software is open source and if compiled, has an open source toolchain to do so.

        Though people often decry it (due to the many, many footguns), writing something in Shell&#x2F;BASH will make it trivial to move to newer machines.

      5. cozzyd · · focus · HN ↗
        Write it in C or Fortran.
        1. very-old-sw · · focus · HN ↗
          50 years ago, fortran iv had the &quot;extended range of a do loop&quot;. You could jump out of a loop execute some code, then jump back in. Therefore 2 loops could execute the same out-of-loop code. It was useful; preprocessors like Flecs used it to emulate missing control structures.

          ChatGPT says, &quot;likely to need manual conversion&quot;. So no Fortran hasn&#x27;t been stable. In another post I showed that C hasn&#x27;t either.

      6. brudgers · · focus · HN ↗
        run for ~50 years where the hardware will need to be replaced

        If it needs to run for fifty years, specify hardware that has a long support cycle such as Mil-Spec.

        That’s why the Z80 was around for so long and why so many companies in the 80’s and 90’s still deigned around it. (1)

        If you let programmers drive system design, winding up with an “Amiga” in your certified design is a more probable outcome…

        (1) there’s a moderate chance that new hardware that can run Z80 code will be around fifty years from now.

      7. steveBK123 · · focus · HN ↗
        &gt; How does someone write software that needs to run for ~50 years

        You in a lot of ways have to respect the ability to have done this in the first place, compared to todays slopware which manages to break within 1-2 mandatory OS update cycles.

      8. pianopatrick · · focus · HN ↗
        Wasn&#x27;t there some idea that went like &quot;if something has been around for x years, it will likely be around for x more years&quot;?

        Maybe follow that. It&#x27;s 2026 right now. What way of writing code would have worked 50 years ago (1976) that still works today?

        Well, C, SQL and Lisp were all around 50 years ago and still exist today.

        In terms of hardware, 50 years ago there was intel 8080. apparently code for that can still work via emulation today.

        So if you wrote C for low level, Lisp for high level, and compiled the software to run in an Intel 8080 emulator, that combo would likely still work in 50 years.

        1. veqq · · focus · HN ↗
          Lindy effect
        2. OCTAGRAM · · focus · HN ↗
          C is very different C. There is C where programmer rushes to call fork(), just because he likes the idea of entering room once and exiting room twice. And this program has got excuse for his behavior. He has fork() in POSIX standard. So programming is using fork() here and there even if not strictly needed. Using fork()&#x2F;exec() instead of more portable posix_spawn(). Using fork()&#x2F;accept() instead of multithreading.

          Then it becomes impossible to introduce database connection pool. Well, probably possible, but in single-process multithread server this is BSc grade job, and in multi-process server this is PhD grade job. libmysqlserver and others maintain some context near to the socket, in opaque way. Hard to pass context between processes. At least, hard to return used connection back to pool in main process. Proxy is also not an easy walk.

          On client side although Windows NT had POSIX layer, and XP&#x2F;2003 still had Interix SFU. But Windows Vista broke SFU. But then Vista has got SUA. But SUA was not binary compatible, required recompilation. And as of Windows 10 there was surely no SUA. Was it dropped in Windows 8? Windows 10 has got WSL eventually, but there was a gap between SUA and WSL. And deploying Windows application with SFU, SUA or WSL part is not easy walk. Writing installer is MSc grade job.

          Then comes iPhone OS and Android. They are POSIX OSes. Kind of. But spawning external processes is prohibited or not desirable. This is what was blocking LaTeX adoption on mobiles.

          1. pianopatrick · · focus · HN ↗
            Well I think if you were doing the 1976 way you might not even have multi processing or multi threading. Just a single process with a single thread. And so you don&#x27;t have a database connection pool, you just have a single database connection and do one query at a time maybe.

            That may not work for network connected software with lots of requests per second. But such software did not exist too much in 1976 either as there was not very much networking going on.

            1. jasomill · · focus · HN ↗
              There were absolutely multiuser computer systems processing transactions from thousands of users in 1976.

              As for networking, both the ARPANET and Ethernet predate 1976, though neither were ubiqutitous and most high-volume networking would have been mainframes and related hardware connected via leased lines.

      9. chasd00 · · focus · HN ↗
        This was one of the promises of Java. You write your application and then you get a virtual machine (JVM). As time goes on you only maintain the virtual machine while the application remains the same.
        1. OCTAGRAM · · focus · HN ↗
          The funny thing happened and verified this promise. There were several architects working on IBM System Object Model (SOM). In 1996-1997 many good things ended, and SOM was terminated. But the work was so good that two architects did not stop and wrote the book: Putting Metaclasses to Work (1998). That book has got reference implementation in Java. So we have IBM SOM as closed source binary and we have Java source codes.

          IBM SOM executes on Windows 10. I have checked Visual Age for C++ Direct2SOM extensions, OpenDoc for Windows. Very good. 32-bit i386, but otherwise runnable, usable.

          And Java is hard to build, hard to execute on modern Java toolkit. Java seemingly had no List, and authors made their own List, but when Java also got its List, that breaks the build. When building problems are resolved, runtime problems come. Original Java was seemingly fine with Property key being object, but modern Java only wants strings. And Property-based dictionaries are all around. PMtW is about building VMT, and there is multiple class inheritance in PMtW model, not matching Java&#x27;s comparably limited OOP. So PMtW is building dictionaries for methods to support what is described in book, and foundational Java class is malfunctioning.

          I did not finish this road, don&#x27;t know so what does it take after all to run Java code from 1998 on modern Java toolkit. So far looks pathetic compared to Win32 programming.

        2. throwaway2037 · · focus · HN ↗

              &gt; As time goes on you only maintain the virtual machine while the application remains the same.
          
          &quot;only&quot; is doing some heavy lifting here. A modern VM is probably more complex than a kernel.
      10. OCTAGRAM · · focus · HN ↗
        DOS emulation is available more widely than Win32 emulation, and there is HX DOS Extender. I would try sticking to Win32 dlls runnable in HX DOS Extender. rundll32 or some other exe host. HX DOS Extender has no paging support and has problem loading multiple exe having no relocation info to the very same 4Mb base address they all usually pretend. DLL should have relocation.

        I thought &quot;but what is the problem to generate EXE with relocation?&quot; and tried GCC GNAT (from 2017), and GCC said no. EXE and DLL formats are very much the same, but GCC is completely unable to generate relocatable EXE. A very suprising discovery. More recent toolkits became aware that adding relocation to EXE is not a rocket science, just do the same like in DLL. But these recent toolkits may call APIs that HX DOS Extender does not support yet.

      11. jasomill · · focus · HN ↗
        Even if VMs do not, whole-system emulators surely will.

        But Windows 95 would be a poor choice, as you&#x27;d be stuck emulating a bunch of very specific aspects of both Windows (non-Unicode APIs, 16-bit application support, etc.) and the PC archictecture (BIOS, A20 gate, etc.) that exist only to maintain backwards compatibility.

        If Windows is a requirement, you&#x27;d be better off building against something like the subset of Win32 APIs that has been stable since Windows Server 2003 and ideally testing against Wine, contributing patches as necessary.

        If it were me, though, and it was something that required a general-purpose, non-realtime OS, and wasn&#x27;t so performance-sensitive as to require deep integration with platform-specific APIs, my first thought is to target a Linux-compatible subset of FreeBSD, which should be enough to get you most of POSIX and then some, plus a full-featured GUI if necessary, portable between two open-source OSes that run on a wide variety of hardware.

      12. esaym · · focus · HN ↗
        Use Perl
    15. justin66 · · focus · HN ↗
      To me the funny part of this story is that they used to show you this warning as part of the EULA when installing Windows NT 4, which I remember joking about:

      NOTE ON JAVA SUPPORT. THE PRODUCT MAY CONTAIN SUPPORT FOR PROGRAMS WRITTEN IN JAVA. JAVA TECHNOLOGY IS NOT FAULT TOLERANT AND IS NOT DESIGNED, MANUFACTURED, OR INTENDED FOR USE OR RESALE AS ONLINE CONTROL EQUIPMENT IN HAZARDOUS ENVIRONMENTS REQUIRING FAIL-SAFE PERFORMANCE, SUCH AS IN THE OPERATION OF NUCLEAR FACILITIES, AIRCRAFT NAVIGATION OR COMMUNICATION SYSTEMS, AIR TRAFFIC CONTROL, DIRECT LIFE SUPPORT MACHINES, OR WEAPONS SYSTEMS, IN WHICH THE FAILURE OF JAVA TECHNOLOGY COULD LEAD DIRECTLY TO DEATH, PERSONAL INJURY, OR SEVERE PHYSICAL OR ENVIRONMENTAL DAMAGE. Sun Microsystems, Inc. has contractually obligated Microsoft to make this disclaimer.

      Also:

      The machine&#x27;s purpose was to report status of the control rods that mitigate nuclear reactions. Basically, &quot;are the rods inserted, and if so, how many &#x2F; how far?&quot;. I want to emphasize that this was reporting only, NOT control.

      It would take a whole lot more context to make this somehow comforting. :D

      1. SenHeng · · focus · HN ↗
        &gt; It would take a whole lot more context to make this somehow comforting. :D

        This is this fascinating 6 part documentary about the Chernobyl incident explaining how it was caused by bad control rods. But the main point is that control rods prevent the facility from going boom, so be glad it’s not the AmigaOS emulator on a NT machine handling it.

        1. dh2022 · · focus · HN ↗
          LOL at “Chernobyl accident was caused by bad control rods”. This seems to imply other control mechanisms worked, when in fact plant engineers could not even monitor the plant operations. They had malfunctioning Geiger counters. Also - plant engineers had no idea how much water was flowing through the nuclear core cooler. Monitors for the temperature of before mentioned water did not exist even on a whiteboard.
    16. the__alchemist · · focus · HN ↗
      It is wild to me that you would use any GPOS for something like this instead of dedicated firmware for the task. This is evoking similar reactions to when I read articles about infrastructure being hacked remotely: Something must have taken a wrong turn with the architecture design for this to happen!
    17. rkagerer · · focus · HN ↗
      Nothing wrong with this.

      If it ain&#x27;t broke, don&#x27;t &#x27;fix&#x27; it.

      1. mikeweiss · · focus · HN ↗
        Just make sure that its well isolated from the Internet!!
    18. dahart · · focus · HN ↗
      &gt; A certain nuclear power plant had a Windows NT 4.0 machine running as late as 2007.

      To put this in perspective, NT 4 was released in 1996, 11 years before 2007. That’s roughly the same as someone running Windows 10 today, which a lot of people still do. The Pentium 1 was only 14 years old at most. These parts of the system shouldn’t be surprising.

      The AmigaOS and software from the 80s are of course the older more interesting bits, but for critical infrastructure and safety, shouldn’t we expect and design for our hardware and software to last a long time, and not try to keep up with tech fads every decade? I feel like the main problem isn’t hardware or software that’s old, but that there wasn’t a longevity plan.

      It’s always been an interesting question how to write software that will last a hundred years. Maybe with AI this is the first time in history that planning to port &amp; upgrade to new hardware every 5-10 years seems totally reasonable.

      1. driverdan · · focus · HN ↗
        &gt; That’s roughly the same as someone running Windows 10 today

        While true the situation is different. Hardware and software moved a lot faster in the 90&#x27;s and early 2000&#x27;s. Everything has matured, is far more standardized, and moves more slowly now. Hardware from 11 years ago when Win10 was released isn&#x27;t that different from today&#x27;s hardware. Same goes for Win10 and Win11.

        1. dahart · · focus · HN ↗
          There might be a seed of truth there, but FWIW, I’m not very convinced by that. CPU speed development has slowed down a bit for sure, but software development is going faster than ever. GitHub and NPM and Python 3 and Rust all didn’t exist in 2007. CUDA was first released that year. LLMs weren’t being used. At the start of 2007, the latest Windows version was Windows 5, one more than Windows 4. Almost same as today. There isn’t a Windows 12 yet, while Windows 6 was released in 2007. So the pace of major Windows versions might be slightly slower. OTOH, the OS is much bigger than it used to be and it gets more frequent updates and point releases now than it did in 2007.
          1. throwawaysoxjje · · focus · HN ↗
            &gt; At the start of 2007, the latest Windows version was Windows 5, one more than Windows 4

            Windows 2000 (NT 5.0) was released in 1999. Vista was NT 6, and released in 2006.

            1. dahart · · focus · HN ↗
              Where do you find 2006? My googling says NT 6 was released in early 2007, so I meant that on Jan 1 2007, Win 5 was still current. <a href="https:&#x2F;&#x2F;simple.wikipedia.org&#x2F;wiki&#x2F;Windows_NT_6.x" rel="nofollow">https:&#x2F;&#x2F;simple.wikipedia.org&#x2F;wiki&#x2F;Windows_NT_6.x

              It wouldn’t make a huge difference to me if 6 was released either 6 months earlier or 6 months later. In 2007, NT4 was only 1 major version behind for most people; adoption takes time. The broad timing of major versions being 4-5 years apart didn’t change until Windows 11, and we don’t know if that’s an outlier yet, but we do know that Microsoft has been changing the Windows release strategy, with more frequent updates. <a href="https:&#x2F;&#x2F;endoflife.date&#x2F;windows" rel="nofollow">https:&#x2F;&#x2F;endoflife.date&#x2F;windows

    19. throwaway27448 · · focus · HN ↗
      How on earth are these massive pieces of infrastructure relying on software they don&#x27;t have the code to? i&#x27;m just utterly confused how these things happen.
    20. collingreen · · focus · HN ↗
      That must have been a crazy moment for you when you first saw it and a big sigh moment for whomever had to explain it to you the first time. Thanks for sharing this; it made me smile!
    21. vkazanov · · focus · HN ↗
      I grew up in a little post soviet republic, in a small town with a big nuclear power plant.

      Coincidently, that&#x27;s where my father was working as a programmer until the shutdown of the plant.

      Anyways, he was maintaining a bunch of systems related to collecting data from environment monitoring sensors around the plant. In mid 2000s or so he showed me some data collecting machines using what looked like DOS text UI that mentioned being written in Leningrad, 1989 or 1988.

      The software was running in an emulator on Linux, which my father used to replace original x86-compatible machines runninh dos.

      Pretty sure thr whole thing was running for quite a while since my family moved elsewhere.

    22. jasomill · · focus · HN ↗
      The Amiga thing is funny, but NT 4.0 was still receiving security updates until the end of 2006, so seeing it in 2007 wouldn&#x27;t be much different than seeing Windows 10 today.

      I&#x27;m curious what changed in Windows 2000 that would have broken the emulator, though, as direct hardware access in any version of Window NT requires a driver, and I don&#x27;t recall any major breaking changes to the driver architecture between NT 4 and Vista.

    23. nycdotnet · · focus · HN ↗
      Up until a few years ago the Metrocard machines in New York City were NT4.
    24. natas · · focus · HN ↗
      I wish there was some picts.
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.