<<

ADA Volume 25 USER Number 2 June 2004

JOURNAL Contents Page Editorial Policy for Ada User Journal 40 Editorial 41 News 43 Conference Calendar 77 Forthcoming Events 85 Articles James W Moore “Standardizing the Next Version of Ada” 91 Louise Arkwright “Ada Academic Initiative in Paris” 97 Peter Amey and Adrian J Hilton “Practical Experiences of Safety- and Security-Critical Technologies” 98 Mário Amado Alves “No Pointers, Great Programs” 107 Ada-Europe 2004 Sponsors 110 Ada-Europe Associate Members (National Ada Organizations) Inside Back Cover

Ada User Journal Volumes 25, Number 2, June 2004 40 Editorial Policy for Ada User Journal

Publication Original Papers Commentaries Ada User Journal – The Journal for the Manuscripts should be submitted in We publish commentaries on Ada and international Ada Community – is accordance with the submission software engineering topics. These published by Ada-Europe. It appears guidelines (below). may represent the views either of four times a year, on the last days of individuals or of organisations. Such March, June, September and All original technical contributions are articles can be of any length – December. Copy date is the first of the submitted to refereeing by at least two inclusion is at the discretion of the month of publication. people. Names of referees will be kept Editor. confidential, but their comments will Opinions expressed within the Ada Aims be relayed to the authors at the discretion of the Editor. User Journal do not necessarily Ada User Journal aims to inform represent the views of the Editor, Ada- readers of developments in the Ada The first named author will receive a Europe or its directors. and its use, complimentary copy of the issue of the general Ada-related software Journal in which their paper appears. Announcements and Reports engineering issues and Ada-related We are happy to publicise and report activities in Europe and other parts of By submitting a manuscript, authors grant Ada-Europe an unlimited license on events that may be of interest to our the world. The language of the journal readers. is English. to publish (and, if appropriate, republish) it, if and when the article is Although the title of the Journal refers accepted for publication. We do not Reviews to the Ada language, any related topics require that authors assign copyright to Inclusion of any review in the Journal are welcome. In particular papers in the Journal. is at the discretion of the Editor. any of the areas related to reliable Unless the authors state explicitly A reviewer will be selected by the software technologies. otherwise, submission of an article is Editor to review any book or other taken to imply that it represents publication sent to us. We are also The Journal publishes the following prepared to print reviews submitted types of material: original, unpublished work, not under consideration for publication else- from elsewhere at the discretion of the • Refereed original articles on where. Editor. technical matters concerning Ada and related topics. News and Product Announcements Submission Guidelines Ada User Journal is one of the ways in All material for publication should be • News and miscellany of interest to which people find out what is going on sent to the Editor, preferably in the Ada community. in the Ada community. Since not all of electronic format. The Editor will only accept typed manuscripts by prior • Reprints of articles published our readers have access to resources arrangement. elsewhere that deserve a wider such as the World Wide Web and Prospective authors are encouraged to audience. Usenet, or have enough time to search through the information that can be contact the Editor by email to • Commentaries on matters relating found in those resources, we reprint or determine the best format for to Ada and software engineering. report on items that may be of interest submission. Contact details can be to them. found near the front of each edition. • Announcements and reports of Example papers conforming to conferences and workshops. Reprinted Articles formatting requirements as well as some word processor templates are • Reviews of publications in the While original material is our first available from the editor. There is no field of software engineering. priority, we are willing to reprint (with limitation on the length of papers, the permission of the copyright holder) though a paper longer than 10,000

• Announcements regarding material previously submitted words would be regarded as standards concerning Ada. elsewhere if it is appropriate to give it exceptional. a wider audience. This includes papers Further details on our approach to published in North America that are these are given below. not easily available in Europe. We have a reciprocal approach in granting permission for other publications to reprint papers originally published in Ada User Journal.

Volumes 25, Number 2, June 2004 Ada User Journal 41 Editorial I take pleasure in posting this editorial in the June issue of the Ada User Journal, administratively the first one in the 2004 cycle -- in which we will enjoy the company of larger set of sponsors --, for it marks our success in recovering a great deal of the very annoying delays incurred in the past production schedule. The new arrangement put in place at the beginning of the year seems to be working well: my thanks go to Santiago Urueña, our new News (☺!) editor and to Dirk Craeynest, our former News editor and holder of precious, long-standing experience with the Journal production, for their decisive collaboration in achieving this milestone. We will do our utmost to continue at this pace. This issue of the Journal is especially rich with articles, in addition to featuring the usual wealth of News and Events. We do continue to follow very closely the proceedings of the Ada language revision process: we are grateful to Jim Moore, the convener of WG9, for offering a very comprehensive account of the shape and direction of this very important and very promising effort. Two more contributions proceed directly from the Tutorial programme of the Ada-Europe 2004 conference, held earlier this month in Palma de Mallorca: Peter Amey and Adrian Hilton of Praxis Critical Systems give us some flavour of the tutorial they offered on the production of high-integrity software; Mario Amado Alves, an active member of the Ada user community, provides an outline of his tutorial, which illustrates the Ada foundations for value semantics. As a means to extend the value offered to our readership, we have put in place a plan for reports and summaries from the Ada-Europe tutorial programme to systematically appear in the Journal. The two mentioned contributions inaugurate this new line. Finally, Louise Arkwright of ACT Europe reports on an Academic Program Initiative recently kicked off to extend the Ada awareness in the education arena. We do hope to be able to host more information on this initiative in the future!

Tullio Vardanega Padova June 2004 Email: [email protected]

Ada User Journal Volumes 25, Number 2, June 2004 43 News Santiago Urueña Technical University of Madrid. Email [email protected] At the Ada-Belgium evening event earlier - EAST or the for Contents this year, Pascal Leroy, Senior Software Enhanced Ada SubseT page Engineer with IBM France and chairman Ada-related Events 43 - Positioning Ada with respect to UML of the ISO Ada Rapporteur Group (ARG), and MDA Ada and Education 45 gave a technical overview of the most im- Ada-related Resources 46 portant improvements that are currently - Modeling and Architectural Description Ada-related Tools 48 under consideration for inclusion in Ada with AADL Ada-related Products 58 2005. - HELIOS experience report on the use Ada and 64 of Ada 95 Ada and 66 We are pleased to announce that a copy of References to Publications 66 his presentation is now available on-line - Modeling based on Ravenscar-oriented Ada Inside 67 on the Ada-Belgium web pages. design patterns Ada in Context 67 Check out "What's new on the Ada- - Modeling of concurrent applications Belgium web-pages?" at URL using Petri Nets if you're inter- - Modeling of distributed applications using CORBA ested. [The announcements reported below are a From: Matthew Heaney - Modeling of a CORBA ORB using selection of the many Ada-related events Petri Nets organized by local groups. If you are or- Date: Fri, 07 May 2004 01:39:27 GMT - Issues with the extraction of semantic ganizing such an event, feel free to inform Subject: Re: Ada 2005 presentation at Ada- properties using ASIS us as soon as possible. If you attended one Belgium event now on-line please consider writing a small report for Newsgroups: Jun 14-18 - Ada-Europe the Journal. -- su] comp.lang.ada,fr.comp.lang.ada,be.com 2004 Conference Mar 18 - 11th Ada-Belgium p.programming, nl.comp.programmeren Note that Pascal's presentation includes a From: Dirk Craeynest General Assembly brief summary of the new standard container . Date: 21 Mar 2004 21:43:09 From: Dirk Craeynest Organization: Ada-Europe, /o Dept. of For more detailed information see the lat- Computer Science, K.U.Leuven Date: 16 Feb 2004 21:11:21 +0100 est release (2004-04-29 AI95-00302- Subject: 9th Int.Conf.on Reliable Software Organization: Ada-Belgium, c/o Dept. of 03/03) of the AI-302 draft: Technologies, Ada-Europe 2004 Computer Science, K.U.Leuven comp.lang.ada,fr.comp.lang.ada 2004 20:00, Ada-Belgium Newsgroups: May 27 - Ada and Modeling 9th International Conference on Reliable comp.lang.ada,fr.comp.lang.ada,be.com Software Technologies - Ada-Europe 2004, 14 - 18 June 2004, Palma de p.programming,nl.comp.programmeren From: Laurent Pautet Mallorca, Spain. http://www.ada- Date: Fri, 30 Apr 2004 09:53:27 Ada-Belgium will hold its 11th annual europe.org/conference2004.html General Assembly on Thursday, March Subject: Journee thematique Ada et 18, 2004, 19:00, at the U.L.B., Modelisation Organized, on behalf of Ada-Europe, by Department of Computer Science, To: [email protected] the University of the Balearic Islands, in cooperation with ACM SIGAda (approval Boulevard du Triomphe / Triomflaan, B- [Translated from French:] Ada-France is pending) and Ada-Spain 1050 Brussels. The official convocation glad to announce a one-day thematic is distributed separately to members and event on the subject of Ada and Ada-Europe organizes annual is also available on the Ada-Belgium Modeling. The event will take place at international conferences since the early web-server. Jussieu in room 203 (building 41) on 27 80's. This is the 9th event in the Reliable At 20:00 the General Assembly will be May 2004. The map of the location can be Software Technologies series, previous followed by a technical presentation plus found at: ones being held at Montreux, Switzerland Q&A, by Pascal Leroy from IBM France. www.upmc.fr/FR/info/Venir_UPMC/05 ('96), London, UK ('97), Uppsala, Sweden ('98), Santander, Spain ('99), Potsdam, For logistic reasons, should you wish to [See also "Ada 2005 Presentation" in AUJ Germany ('00), Leuven, Belgium ('01), participate, you should take contact with: 25.1 (Mar 2004), pp.5-6 -- su] Vienna, Austria ('02), Toulouse, France Agusti Canals ([email protected]). From: Dirk Craeynest ('03). The event will include 9 presentations of The 12-page Advance Program brochure 30 minutes each, followed by 15 minutes Date: 4 May 2004 22:57:38 +0200 with full information is available on the for discussion. The presentation will Organization: Ada-Belgium, c/o Dept. of conference web site; the AP contains the mostly focus on issues of applied Computer Science, K.U.Leuven list of accepted papers, as well as a de- modeling as well as on the latest news on Subject: Ada 2005 presentation at Ada- tailed description of the tutorials. Use the Ada technology available to the user Belgium event now on-line "Program" link at the top to either view or community. Newsgroups: download the PDF version or contact the comp.lang.ada,fr.comp.lang.ada,be.com The day event will be closed by the conference chair to request a printed copy p.programming,nl.comp.programmeren General Assembly of the association. of the brochure. [...]

Ada User Journal Volume 25, Number 2, June 2004 44 Ada-related Events

Quick overview - authors from 10 countries: Austria, The aim of an ADL (Architecture - Mon 14 & Fri 18: tutorials China, Czech Republic, France, Description Language) is to formally de- Germany, India, Portugal, Spain, scribe software and hardware architec- - Tue 15 - Thu 17: paper and vendor United Kingdom, and USA tures. Usually, an ADL describes compo- presentation sessions, exhibition Exhibition nents, their interfaces, their structures, Program co-chairs their interactions (structure of data flow - 8 exhibitors already committed: ACT and control flow) and the mappings to - Albert Llamosí, University of the Europe, Aonix, Green Hills, I-Logix, hardware systems. A major goal of such Balearic Islands (UIB), Dept. of LDRA Software Technology, Praxis descriptions is to allow analysis with re- Mathematics and Computer Science, Critical Systems, RainCode, and TNI- spect to several aspects like timing, Spain, [email protected] Europe, others expressed interest safety, reliability, ... This workshop will - Alfred Strohmeier, Swiss Fed. Inst. of - vendor presentation tracks for provide a forum for practitioners and re- Technology in Lausanne (EPFL), exhibitors searchers to discuss recent development Software Engineering Lab, around ADLs. Social evening events […] Switzerland, Topics of interest include (but are not [email protected] Registration limited to): Invited speakers - includes copy of proceedings, - Components, Connectors, Composition published by Springer-Verlag in - S. Tucker Taft, SofCheck Inc., USA. - Semantics, Formalization "Fixing Software Before It Breaks: Lecture Notes in Computer Science Using Static Analysis to Help Solve the series (LNCS) and distributed at event - Verification, Simulation, Test Software Quality Quagmire" - includes coffee breaks, lunches, social - Tools and Development Environments events - Martin Gogolla, University of Bremen, - Standardization Germany. "Benefits and Problems of - three day conference registration in- Formal Methods" cludes conference banquet - Industrial Projects - Antoni Olivé, Universitat Politècnica - early registration discount up to May Deadlines: de Catalunya, Spain. "On the Role of 16, 2004 Submission deadline: 15 March, 2004 Conceptual Schemas in Information - additional discount for academia, Ada- Notification of acceptance: 30 April, System Development" Europe and ACM members 2004 - Steve Vinoski, IONA Technologies, For more info, latest updates, or to get Camera Ready paper: 30 May, 2004 USA. "Can Middleware Be Reliable?" printed brochures, see the conference web For more details about the conference Special session site at: please refer to the WCC Conf. Web site: - Pascal Leroy, IBM France & ISO Ada www.ada-europe.org/conference2004.html http://www.wcc2004.org. Rapporteur Group. "Ada0Y: An Overview" Aug 27 - Workshop on Oct 6-7 - Automotive, Safety Tutorials (full day) Architecture Description & Security und Ada Languages - "Developing a Web Server in Ada with Deutschland Tagung 2004 AWS", Jean-Pierre Rosen Workshop on Architecture Description From: Peter Dencker - "Practical Experiences of Safety and Languages (WADL04). August 27, 2004 Security-Critical Technologies", Peter - Toulouse France. Date: Mon, 26 Apr 2004 12:59:47 Amey & Rod Chapman http://www.laas.fr/FERIA/SVF/WADL04 Subject: Automotive_ Safety & Security und - "Developing Fault-Tolerant, Time- WADL04 is a part of the IFIP WCC Ada Deutschland Tagung 2004, Tagung Critical Systems with AADL, UML, World Computer Congress und CfP and Ada", Bruce Lewis & Ed Colbert August, 22-27, 2004 Toulouse - To: Dirk Craeynest - "Real-Time for Ada http://www.laas.fr/wcc2004/ ", Ben Brosgol Workshop Outline [Translated from German] Herewith we wish to announce the Workshop on Tutorials (half day) The workshop on Architecture "Automotive - Safety & Security 2004" to - "Programming with the Charles Description Languages will be held as be held on 6. – 7. October 2004 Container Library", Matthew Heaney part of the WCC 2004 Conference in to be Toulouse, France, from 22 August to 27 - "Probabilistic Worst Case Execution followed by the Ada-Deutschland Days August 2004. This one-day workshop will Time Analysis", Guillem Bernat on 7. – 8. October in Stuttgart, and also wish - "No Pointers, Great Programs. How to Technical Session. The Technical to invite you to either one of the events or Stay on the Value Semantics Side of Session will describe significant research both at your choice. the Ada Way", Mario Amado Alves as well as innovative development and application. We solicit original papers de- The announcement of the events was first - "Requirements Analysis with Use published on May 22. Cases", Alfred Strohmeier scribing state-of-the-art research and de- velopment in all areas of Architecture Both events are supported by the Working Papers Description Language. In order to fa- Group on Security of the Association on - 4 invited papers and 23 technical papers vorize a closer interaction between aca- Informatics. […] on Application Programming demic and industrial networking research Interfaces, Critical Systems Modeling, communities, both academic research pa- Distributed Systems, Real-Time pers and industrial contributions are wel- Systems, Reflection and XML, come. Scheduling, Static Analysis, and Scope of the Workshop Testing

Volume 25, Number 2, June 2004 Ada User Journal 46 Ada-related Resources

Nov 14-18 SIGAda 2004 Subject: Re: ada+network Ada and Education Newsgroups: comp.lang.ada From: Ricky E. Sward Kuba Malczak wrote: Algorithms and Data > Hi I am new to Ada, could you tell me Date: 7 Feb 2004 11:50:19 -0800 Structures with Ada if in Ada I can write network oriented Subject: CFP for SIGAda 2004 programms? If yes, could you give me Newsgroups: comp.lang.ada From: Claude Kaiser Date: Sat, 7 Feb 2004 15:10:34 +0100 any links to resources connected with Call for Participation - SIGAda 2004 Subject: Re: liste et arbres it? 14-18 November 2004, Atlanta, Georgia, To: [email protected] Sure. Look at: USA [Translated from French:] http://www.rfc1149.net/devel/adasockets Constructing highly reliable software is > I am looking for information on the (sockets. GNAT also has socket library so an engineering challenge that can now be programming of linear lists and tree you can see which you like best) met in many domains. The SIGAda 2004 structures in Ada. Any information on http://libre.act-europe.fr/aws/ (AWS is a conference focuses on how the applica- this regard is welcome. complete framework to develop Web tion of software engineering methods, BATLLE Thierry based applications.) tools and languages interrelate and on 3 Rue André Malraux how features in Ada affect the quality of 81990 LE SEQUESTRE From: Tom Moran the resulting software. Papers that ana- [email protected] Date: Tue, 17 Feb 2004 01:51:16 GMT lyze Ada with respect to these factors or http://thierrybatlle.fr.st Subject: Re: ada+network in comparison to other languages are es- Newsgroups: comp.lang.ada Take a look at the book by Christian pecially welcome. SIGAda 2004 gathers Take a look at www.adaworld.com - Ada industry experts, educators, software en- Carrez and the material of his data structures classes at CNAM: Projects - Ada Internet Projects for a vari- gineers, and researchers interested in de- ety of things. Also veloping, analyzing, and certifying reli- C. CARREZ Structures de données en www.adapower.com/reuse/clawweb.html able, cost-effective software. Technical Java, c++ et Ada 95 (Masson 1997) for a very simple web server. You might or theoretical papers as well as experience http://deptinfo.cnam.fr/Enseignement/ want to use the search at www.adaic.com reports with a focus on Ada are solicited. CycleA/SD/ if you have some specific needs. A brief list of topics include safety and […] Fichiers/bibSDAda.tar.gz high integrity issues, real-time and em- […] Fichiers/Demos_SD.zip Browsing Ada bedded applications, Ada & software en- This information was already posted on gineering education, Ada in other envi- From: Preben Randhol ronments such as XML and .NET, Ada the Ada-France list, where you should find more details. and other languages, metrics, standards, Date: Tue, 17 Feb 2004 11:10:04 analysis, testing, validation, and quality Both the URL of the classes and the ISBN Subject: Re: ada packages assurance. For a more extensive list of of the book can be found by searching the Newsgroups: comp.lang.ada topics visit the SIGAda 2004 web page. web site of Ada-France. Kuba Malczak wrote: Contributions are solicited in six catego- Therein, you can also take a look at the ries: Technical articles, extended ab- material prepared by Feneuille on Ada > Could you tell me if anywhere is stracts, experience reports, workshops, education. something like package browser. I want panels, and tutorials. to browse functions with comments From: Jean-Pierre Rosen about themn, now I must some We openly welcome contributions from package file and look for function that I educators and students. Educator grants Date: Mon, 9 Feb 2004 16:31:45 +0100 want, is any simpliest way ? are available that include conference and Organization: Adalog tutorial registration fees. These fees will Subject: Re: liste et arbres Some choices: also be waived for student authors whose To: Adabrowse, papers are accepted for publication. An > Take a look at the book by Christian http://home.tiscalinet.ch/t_wolf/tw/ada95/ Outstanding Student Paper Award will be Carrez and the material of his data gnathtml (in GNAT), given for the best student contribution to structures classes at CNAM: http://libre.act-europe.fr/GNAT/ the conference, and the winner will re- C. CARREZ Structures de données en AdaDoc, http://adadoc.sourceforge.net/ ceive $500 and an Xbox (TM) video Java, c++ et Ada 95 (Masson 1997) game system. Technical articles or ex- GPS (IDE), http://libre.act-europe.fr/gps/ perience reports from students could fo- Also consider « Algorithmes et structures cus on such projects as comparing appli- de données avec Ada, C++ et Java » by Writing cations implemented in other languages Abdelali Guerid, Pierre Breguet et Henri, and then re-implemented in Ada, mixed published by Röthlisberger (the publisher Modules in Ada language development of applications, for the Technical Universities of the Romandie.). From: Jeff C how Ada is used with XML or .NET ap- Date: Thu, 25 Mar 2004 00:39:00 GMT plications, and/or software engineering This book (and others) is included in the Subject: Re: Ada runtime and Linux Kernel education experiences with Ada. commented Ada bibliography: Module Keynote speakers include Pam http://www.adalog.fr/biblio1.htm Newsgroups: comp.lang.ada Thompson, Director of Software Rohan wrote: Engineering at Lockheed Martin Aeronautics Corporation, and Watts Ada-related Resources > I am in the very early stages of looking Humphrey, Fellow and Research Scientist at writing a Linux kernel module in at the Software Engineering Institute. [...] Network Resources Ada for a University project. I have looked around and it seems to be possi- From: Preben Randhol ble, if tricky. The Big Online Book of Linux Ada Date: Tue, 17 Feb 2004 07:35:28 Programming

Volume 25, Number 2, June 2004 Ada User Journal Ada-related Resources 47

(http://www.vaxxine.com/pegasoft/hom http://marte.unican.es/ with tasking :-))) es/16.html) has some information, and I I would like 2 more things, if you allow have a test module written based on the Ada OpengGL Mailing List me:-) example code there. 1 – Does anybody now where could I Any module would need to avoid any- From: Chip Richards download it (I have received it by thing which used the ada runtime. Date: 9 Apr 2004 08:06:57 GMT email)? Subject: [Announce] Ada OpenGL mailing There are references to pragma http://www.adaic.org/docs/distilled/adadistil list re-started no_run_time but I have found that as led.pdf long as I stear clear of using anything Newsgroups: that requres the runtime there is no comp.lang.ada,comp.graphics.api. The reference was (of course :-) on http://www.adalog.fr/adaweb.htm problem even without the pragma. Several years ago, we hosted a mailing However I would quite like to use ex- list whose focus was the use of the From: Thomas De Contes ceptions and allocate veriables from the OpenGL 3D graphics API from Ada code. heap. The BOBOLAP states: Technical problems forced that list off the Date: Fri, 9 Apr 2004 04:58:06 +0200 "If you have the time, you can always air, but we have established a new list, Subject: Re: distributed objects copy some of the standard Ada pack- and hope to get some discussion going To: [email protected] ages to a separate directory and compile again. The new list's subscription address them into your GNORT project, effec- [Translated from French] Thomas De is: http://www.niestu.com/cgi- Contes wrote: tively creating your own small, custom bin/mailman/listinfo/oglada run-time system." > 2- I have had a play around trying to do Note that unlike many OpenGL discus- "There are two models for Ada concur- this, but am somewhat stumbling in the sions, this one is not focused on game de- rency: multitasking, and distributed dark. Does anybody have any pointers velopers, though we do not exclude them. objects. The latter, distributed objects, to how I go about this? Or indeed any Our initial topics: is beyond the scope of this book. We example Ada linux module code! * First and foremost, any technical dis- focus this discussion on multitasking." Another option is to look at something cussion of using OpenGL with Ada is Does anybody know whether anything like GNAT for RTLinux. welcome. like that exists also for "distributed ob- jects", please? http://rtportal.upv.es/apps/rtl-gnat/ * There currently exist several distinct and partially incompatible thin Ada http://libre.act-europe.fr/ From: Luke A. Guest bindings for OpenGL. We would like Software_Matters/dl-distributed.pdf to get those various groups talking, and Date: Wed, 24 Mar 2004 21:42:57 +0000 The class material by Franco Gasperoni is see if it's possible to unify at least the truly excellent :-))) Subject: Re: Ada runtime and Linux Kernel lowest level. It would seem that a Module consistent interface to this standard API We could as well use them with people Newsgroups: comp.lang.ada would be a Good Thing. that are not versed in informatics! The only thing you need is the system.ads * All of the current bindings have an un- Smart Pointers in Ada file. The rest you don't need and won't mistakeable C flavor. While this is really be able to use for OS level pro- probably unavoidable, and is actually From: Preben Randhol gramming. beneficial for porting existing OpenGL Another feature you *will* require is the apps into Ada, it's less than ideal for Date: Sat, 28 Feb 2004 13:14:44 use of "pragma (some) new development, where one Subject: Re: smart pointers Restrictions(No_Elaboration_Code);" to might wish to work in a more purely Newsgroups: comp.lang.ada force the not to generate things Ada environment. We would like to Jorge Suárez-Solis Rivaya wrote: like functions for arrays, i.e. conversion develop a more Ada-aware interface, functions for indexing. presumably "thicker" without > C++ smart pointers are equivalent to sacrificing performance, but the design Ada smart pointers? Also, use the -gnatdg switch to see what of such an interface is not trivial, nor GNAT is generating and you'll see what I Ada smart pointers: particularly obvious. Come help us mean. http://www.adapower.com/alg/smartp.html design bindings *you* would like to As I remember it, GNORT doesn't exist use. see also: anymore. http://home.earthlink.net/~matthewjheaney/ We invite everyone with an interest in charles/ I also created a gnat.adc file with the fol- these topics to join the list to read and lowing inside it: possibly contribute. Please disseminate Physical Units Checking in this announcement to anyone who might pragma No_Run_Time; Ada pragma Restrictions be interested. And if this is a duplication of some existing effort, let us know. (No_Exceptions); From: Christoph Karl Walter Grein That should be all you need. Ada Concurrency Date: Mon, 10 May 2004 10:46:13 +0200 From: Stephane Carrez Subject: Physical Units Checking From: Jean-Pierre Rosen Newsgroups: comp.lang.ada Date: Thu, 25 Mar 2004 21:06:13 +0100 Organization: Nerim -- xDSL Internet Date: Thu, 1 Apr 2004 19:07:26 +0200 I've uploaded my paper presented at Ada Provider Organization: Adalog Europe 2003 in Toulouse to my home- Subject: Re: Ada runtime and Linux Kernel Subject: Re: distributed objects page: http://home.t-online.de/home/christ- Module To: [email protected] usch.grein/Ada/Dimension.html Newsgroups: comp.lang.ada [Translated from French :] Thomas De You can find there the comparison of four Have a look at MaRTE OS. They have a Contes wrote: (five) methods how to deal with physical minimal GNAT runtime. There are > http://153.103-30-212.9massy1-1-ro-as- types in Ada. probably a lot of ideas to use from their i2-1.9tel.net/~thomas/adadistilled.pdf OS design (entirely in Ada). That’s exactly what I needed to start

Ada User Journal Volume 25, Number 2, June 2004 48 Ada-related Tools

From: Jacob Sparre Andersen expression end allowing its easy The PragmAda Reusable Components are integration. Operator precedence is located at Date: 09 Apr 2004 17:48:58 +0200 expressed in a native way by setting http://home.earthlink.net/~jrcarter010/pra Subject: Expressing physical units priorities controlling association with the gmarc.htm Newsgroups: comp.lang.ada operands. Associations with the left and The mirror at www.adapower.com has not The type system is not _unable_ to ex- right side operands are controlled independently. Commutative operators been updated for some time, and should press physical units. It just has some not be used. limitations in how you can do it. And al-- and their inverses can be optimized when necessary. Especial attention is paid to though I am annoyed by the limitations, I SAL 1.60 still haven't seen a description of how the error handling allowing generating very language can it easier, without in- precise error messages and source code references. Samples from a small console From: Stephen Leake troducing problems outweighing the bene- fits [...]. calculator to a complete tree generator for Ada 95 expressions Date: 05 Apr 2004 21:36:03 -0400 From: Dmitry A. Kazakov illustrate examples of use; Subject: sal 1.60 released Newsgroups: comp.lang.ada 2. The package Date: Sat, 07 Feb 2004 11:29:59 +0100 SAL 1.60 is now released. Subject: Units of measurement for Ada v1.4 Generic_Segmented_Stack provides a Newsgroups: comp.lang.ada specialization of the generic stack One major change is an implementation package; of Grace config_files is now in SAL. Bug fix: the Get procedures will raise Constraint_Error on numeric errors even 3. Random access to generic stacks (Get / SAL (Stephe's Ada Library, or Standard if Machine_Overflows is not true. Put); Ada Library :) is a collection of packages 4. Strings edit facilities; providing data structures; lists, www.dmitry-kazakov.de/ada/units.htm stacks, binary trees, dynamic arrays, etc. From: Preben Randhol 5. Tables management package. Each package is a generic, providing maximum flexibility in the types that may Date: Tue, 10 Feb 2004 15:43:33 Charles - Container Library be used with the package. There are both Subject: Re: Dimension checking in Ada - tagged (polymorphic/dispatching) and From: Matthew Heaney impossible? In C++ it's possible using non-tagged data types, so you can use the templates. one that fits your application best. Date: 10 Mar 2004 11:10:01 -0800 Newsgroups: comp.lang.ada Subject: Re: Lists within Lists or Nested There is also a complete set of packages Preben Randhol wrote: Linked Lists... for spacecraft or robotics math. And lots of other stuff :). > Dmytry Lavrov wrote: Newsgroups: comp.lang.ada http://www.toadmail.com/~ada_wizard/ada/ >> It's possible to do something similar in Charles is moving to tigris.org. The new sal.html for more info. Ada? Have no idea how. URL is: and I have just recently posted the latest re- Ada for Embedded lease of the doubly-linked lists. The sin- Platforms http://home.t-online.de/home/Christ- gly-linked lists will be done in a day or Usch.Grein/Ada/Dimension.html two. From: Jerry Petrey From: Matthew Heaney Ada-related Tools Date: Fri, 05 Mar 2004 16:54:39 -0700 Date: 15 Mar 2004 07:58:33 -0800 Organization: Raytheon Company Simple Components v1.4 Subject: Re: Lists within Lists or Nested Subject: Re: Embedded Tools Linked Lists... Newsgroups: comp.lang.ada From: Dmitry A. Kazakov Newsgroups: comp.lang.ada Carroll-Tech wrote: I have posted the singly- and doubly- > Well, I bought some robotics books (on Date: Sun, 22 Feb 2004 14:01:14 +0100 linked list containers. There are both sale for 1.00$). In it they use a 16f84 Subject: Simple components v1.4 bounded and unbounded forms for each. Microcontroller. That is an Newsgroups: comp.lang.ada Then it dawned on me that I've seen kazakov.de/ada/components.htm many, many job openings for Changes: PragmARC - PragmAda embedded programmers using Ada. And that tells me that Ada is the 1. The packages rooted in Parsers provide Reusable Components "native" language for "some" processor infix expressions syntax analyzers. and that there is a compiler and Parsers can be used for syntax analysis of From: PragmAda Software Engineering libraries/package specs and implemen- infix expressions, i.e. ones containing tation that might help me answer other infix (dyadic), prefix and postfix Date: Sun, 21 Mar 2004 23:12:37 GMT Subject: New Release of the PragmAda questions. operators, brackets, function calls, array So, I guess, for comparative reasons indices etc. The approach presented does Reusable Components Newsgroups: comp.lang.ada and having the books I bought the tar- not require any grammar put down to get is a 16f84 microcontroller. I just generate scanner and analyzer. Nor any PragmAda Software Engineering is proud want to look in the specs and imple- code generation steps are required. An to announce a new release of the mentation of the libraries to program object-oriented approach is used instead. PragmAda Reusable Components. This embedded "things" with Ada. The lexical procedures are dispatching, so release includes Image functions for inte- that implementations may be provided ger types that allow the caller to specify Ada is a high-level language. It is not the through overriding them. Parsers can be the width, base, and zero-filling of the 'native language' (aka machine language) used both for immediate one-pass code image. for any particular processor. There has to interpretation and for parsing tree be a compiler that translates the high level building. Parser automatically detects the Ada statements into the machine code of a

Volume 25, Number 2, June 2004 Ada User Journal Ada-related Tools 49 given processor. Unfortunately, there is C and linkable with MS small-memory- OS/2 version on their website. I wrote not such a compiler for most of the com- model C libraries? I've looked a bit at several Ada programs for OS/2 that are mon 8-bit and 16-bit microprocessors or gnat and GCC, but I can't see how to still in use but the current version of OS/2 microcontrollers such as the PIC 16F84. specify a target like that... (V4.5 convenience pack) crashes when There are for processors such S. Tucker Taft's company, SofCheck, has running any of these programs. I dug out as the 80486, 60040, PowerPC, etc. and an Ada-to-ANSI-C compiler that should a copy of the compiler and it will not run host compilers for Windows machines. It produce C that your C compiler could at all - not the install program, the com- would be nice if there were more cross- process. STT's e-mail address is stt-at- piler or any of my old ada executables - compilers (one that runs on a machine sofcheck-dot-com. (I haven't noted him not even the "Hello world" one liner. Ob- like a PC and generates code for some posting here recently, so I've obsured the viously there is a major mismatch some- other processor) for some of these smaller address.) where - perhaps in the system dlls. microcontrollers but so far that is not the Ok - I know OS/2 is dead but some are case. RR Software has a 16-bit DOS compiler available, if that will run on your target. still running it and my client is one. From: Bernd Trog Randy Brukardt is the contact there Our copies of the compiler are V5.5 circa ([email protected]). 1995. I had heard there was a later ver- Date: 6 Mar 2004 11:47:50 -0800 sion 5.6 maybe. Subject: Re: Embedded Tools Compiler compatible with Newsgroups: comp.lang.ada Is anyone still using this compiler? Was Borland 4.51 there a later version? TIA Try Atmel's AT90S2313. (2kByte Flash, 128 Byte SRAM in a DIL-20 package) From: Vinzent 'Gadget' Hoefler [email protected]> Date: Sat, 21 Feb 2004 14:26:24 GMT You can download a patch for gcc-3.3.2 Subject: Re: Ada & OS/2 here: http://avr-ada.sourceforge.net/ Date: Fri, 07 May 2004 15:06:23 +0200 Subject: Re: Object format Newsgroups: comp.lang.ada If you are new to Ada, I' suggest to try Newsgroups: comp.lang.ada Aonix still owns the rights to the product, compiling some small host-apps first. Henrik Quintel wrote: but I'd guess they'd be hard-pressed to re- build one. You might try contacting Crosscompiler for PocketPC > But I am forced to make use of the them, or try out the old (but much more Borland 4.51 DOS Compiler which recent) version of GNAT that you were From: Wojtek Narczynski produces DOS Executables and DOS pointed to. object files respectively (16 bit). Date: 6 May 2004 15:13:28 -0700 From: Kees de Lezenne Coulander Subject: Re: Pocket PC Bad luck. GNAT is a 32-bit-compiler, Newsgroups: comp.lang.ada even under DOS. The object format Date: Sun, 22 Feb 2004 20:03:23 *must* be incompatible. But perhaps you Subject: Re: Ada & OS/2 > I am trying to find any relevant info for can use djgpp instead of Borland to com- Newsgroups: comp.lang.ada developing for PocketPC 2002 and pile the C(++)-files? djgpp is also based other similar devices in Ada, I have on gcc (BTW, djgpp should be able to I had never heard of an OS/2 version of found a few odds and ends for embed- compile Ada these days, too), so chances the Alsys Ada compiler before, so I can- ded control systems, but nothing that are that ez2load and djgpp have the same not help you in that line of investigation. relates to the consumer handheld de- (or at least an easily convertible) object In general, older OS/2 programs run very vices. file format. well on later incarnations of the . The Convenience packs (v. 4.5) We've been able to build GNAT cross- From: Randy Brukardt incorporate major changes to the kernel, compiler for Sharp Zaurus, tasking and but I would hesitate to blame that without everything was working (passing most Date: Wed, 12 May 2004 15:11:44 -0500 further evidence. ACATS). Zaurus is a nice Linux based Subject: Re: Object format handheld on ARM / XScale. Newsgroups: comp.lang.ada Ada on OS/2 is not dead, though. Gnat on http://www.sharpusa.com/zaurus/ Intel PC started out as an OS/2 program, The 16-bit version of Janus/Ada sup- before Windows NT became the major We never used it for anything commer- ported Borland C compilers back in the PC operating system. Although ACT no cial, though. day. (It's still on one of my machines, be- longer provides ready-made binaries for 16-bit Ada Compiler for cause F-Prot thinks it's a virus! :-) the OS/2 version of the compiler, newer We still sell the 16-bit Janus/Ada compil- versions (up to the current 3.15p) are MS-DOS ers (I believe you'd need the professional available thanks to the efforts of Dave version for this task). They host on DOS Parsons. From: Jeffrey Carter or Windows 95/987/ME. (The DOS Ex- Date: Sat, 15 May 2004 01:43:46 GMT I use gnat 3.14p on OS/2 (v. 4.0) very tender doesn't work on NT/2K/XP, un- Subject: Re: 16-bit Ada for MS-DOS? regularly on fairly large programs and fortunately.) See www.rrsoftware.com or Newsgroups: comp.lang.ada have never had a problem with it. I have drop me a line. so far not moved up to 3.15p (sorry, Victor B. Putz wrote: Dave), but I hope to do that one of these > The platform in use is based on a Nec Compiler for OS/2 days. V53 chip running a proprietary OS, so From: Paul Gnat is of course Ada 95, whereas Alsys the development environment is 16-bit was Ada 83. That in itself should present C (or C++), compiled in small memory Date: Sat, 21 Feb 2004 04:01:07 GMT Organization: BigPond Internet Services no great problems. There are just a few model using MS Visual C++ version minor issues which can be easily fixed. "Old" (the command-line compiler is Subject: Ada & OS/2 Newsgroups: comp.lang.ada But if any Alsys-specific libraries are in- version 8.00c, from 1993 or so), and volved, that would of course be a different linked with several small-model librar- Does anyone know what happened to the matter. ies. Alsys OS/2 Ada compiler (& toolset) after I'm not sure I could even get the change Alsys folded? I know the Win NT & From: Georg Bauhaus

Ada User Journal Volume 25, Number 2, June 2004 50 Ada-related Tools

Subject: Re: Ada & OS/2 [Umbrello UML Modeller is a Unified Newsgroups: comp.lang.ada Newsgroups: comp.lang.ada Modelling Language diagram programme Tom Moran wrote: for KDE. UML allows you to create dia- There is some material at > Can someone point me to an Ada fast http://www.unixos2.org/ada/ grams of software and other systems in a standard format. Umbrello 1.2 is the result FFT code somewhere? In particular for From: Dave Parsons of a hard year's work by a dedicated team 2D real correlations. I have the of developers. New features include im- "fft_pack" (Glassman's algorithm) but Date: Sun, 22 Feb 2004 07:14:52 +0100 proved code generation in more languages it's quite general and can presumably be Organization: CDL (Ada, AS, C++, IDL, Java, JavaScript, improved on. djbfft 0.76 claims to be Subject: Re: Ada & OS/2 , PHP, Python, SQL, XML Schema), the fastest around, but it's set up for Newsgroups: comp.lang.ada undo/redo, a resizeable and zoomable Unix systems and I find it unreadable, or maybe: canvas and more diagram types. It is part and thus untranslatable, C. ftp://ftp.cs.nyu.edu/pub/gnat/3.15p/contrib of KDE 3.2 -- su] Does the FFT have to be written in Ada? /os2/gnat-3.15p-os2-bin-20021124.zip From: Oliver Kellogg How about fast C code and an Ada binding? If this would do, look at FFTW Compiler for OpenVMS Date: 4 Feb 2004 23:08:08 -0800 (www.fftw.org) and my FFTW_Ada Subject: Re: KDevelop 3.0 released binding From: Britt Snodgrass Newsgroups: comp.lang.ada http://privatewww.essex.ac.uk/~sjs/fftw_a Date: 11 Feb 2004 07:06:14 -0800 da/fftwa.html Subject: Re: Gnat for OpenVMS I will add Ada code import soon, but in (not yet modified for the most recent Newsgroups: comp.lang.ada order to use it people will need to compile release of FFTW, but it works with the umbrello from CVS or wait for version previous one). Keith Brown wrote: 1.3 (which won't be released for quite a > Is Gnat for OpenVMS free like Linux or while.) I am looking for people to help Multiprecision Numbers is there a license fee? out with integrating the parser and code generator for true round-trip engineering. A very old GNAT version 3.12p is avail- From: Gautier able at FTP address: Beware that the Ada support is really still Date: Sat, 21 Feb 2004 11:51:07 +0100 cs.nyu.edu/pub/gnat/private/old/openvms/ in development, as can be seen in: Subject: Re: looking for a library to handle http://developer.kde.org/documentation/ big numbers A.C.T. never provided newer public ver- library/cvs-api/kdevelop/html/ Newsgroups: comp.lang.ada sions. If you need it for personal use LangSupportStatus.html DEC....Compaq.....Hewlet-Packard may Evangelista Sami: be willing to provide GNAT as part of the Also, the kdevelop team is looking for > I have to write a program which ma- VMS hobbyist license program (see: active contributors/ maintainers of the nipulates big numbers. I am looking for http://www.openvmshobbyist.com/hobbyist AdaSupportPart: a library which could do this. I have _faq/index.html). http://developer.kde.org/documentation/ found some on the web but I don't library/cvs-api/kdevelop/html/ know which one to choose. so if anyone KDevelop 3.0 unmaintained.html has ever used one and give some hints, Help from the Ada community is much that would be very helpful. From: Keith Brown appreciated. At least there is a site about the various Date: Tue, 03 Feb 2004 19:50:17 -0600 GDS Compiler big number implementations for or in Subject: KDevelop 3.0 released Ada: http://www.chez.com/bignumber/ Newsgroups: comp.lang.ada From: Preben Randhol NB: there is a newer version of my code The Kdevelop 3.0 programming envi- in mathpaqs.zip, URL below (the files ronment was released today. This release Date: Wed, 10 Mar 2004 10:10:50 +0000 are: mupr*.ad*, test_int.adb, includes support for Ada95 among other Subject: GDS Compiler written in Ada test_rsa.adb). languages. This looks like a very exciting Newsgroups: comp.lang.ada www.mysunrise.ch/users/gdm/gsoft.htm development to me (no pun intended). Is I was notified from freshmeat.net today anyone in this group doing any Ada95 about a new project in Ada. AdaImgSvr 0.5 work (or planning to) with KDevelop? This appears to support an IDE and GUI GDS Compiler by Gilles Depeyrot From: Patrice Freydiere development tools for the KDE environ- Aimed at micro-electronic design, GDS Date: Mon, 12 Apr 2004 16:34:01 +0200 ment. For a list of features see the link Compiler allows you to easily develop Subject: AdaImgSvr version 0.5 released. below. Any comments? any GDSII generators (memory, MEMS, Newsgroups: comp.lang.ada http://www.kdevelop.org/index.html?filen devices) of any macrocell for which pa- We are proud to annonce the version 0.5 ame=features.html rametrization can provide flexibility, se- of AdaImgSvr this new release imple- curity, and productivity. Front end views ments : Umbrello UML Modeller and netlist for LVS are generated auto- matically. - MySQL database support From: Martin Krischik Don't know if it is of interest to anybody - Win32 service integration here, but you can have a look. - Linux deamon utilities Date: Wed, 04 Feb 2004 15:03:39 +0100 http://freshmeat.net/projects/gdscompiler/ Subject: Re: KDevelop 3.0 released - Security fixes. Newsgroups: comp.lang.ada Fast Fourier Transform in http://adaimgsvr.sourceforge.net A new Version of "Umbrello UML Ada Enjoy, and feel free for feedbacks Modeller" was released as well: http://uml.sourceforge.net/ From: Dr Steve Sangwine TeXCAD 4.1 Umbrello features an UML to Ada code generator. Date: Fri, 13 Feb 2004 12:36:05 +0000 From: Gautier Subject: Re: fast FFT code Date: Tue, 16 Mar 2004 22:50:00 +0100

Volume 25, Number 2, June 2004 Ada User Journal Ada-related Tools 51

Subject: TeXCAD 4.1 > Hi, - Extended tree view controls with icons Newsgroups: comp.lang.ada Has anyone done texture mapping in and colors and a new event which TeXCAD is a program for drawing or re- Ada with openGL? occurs when node selection changes. touching {picture}s in LaTeX. More info Look into www.adapower.com/schroer - A splitbar implementation. @ Download ogl-src.zip Download from: http://www.mysunrise.ch/users/gdm/texca http://www.konad.de/download.htm d.htm Look into opengl-earth.adb I'm still looking for people interested in There a bitmap of the earth is mapped Florist - POSIX Ada Binding developing the GUI part for other than onto a sphere with 2D texturing. "native" Windows: From: Martin Krischik AdaMagick - ImageMagick - GtkAda Bindings Date: Tue, 06 Apr 2004 10:50:57 +0200 - "native" Mac OS X Subject: Florist for GNAT 20040403 release - ? From: Ali Bendriss Newsgroups: comp.lang.ada A large part of TC is OS & GUI-inde- First snapshot release from Florist for Date: Fri, 12 Mar 2004 10:04:13 GNAT. pendent (all TC.* packages), so it is Subject: AdaMagick "only" a question of windows, menus, To: [email protected] Florist does not need original compiler mouse etc. sources. [Translated from French] I have just New Thick Binding for posted on-line the first « release Binary package for i686, GCC 3.5, SuSE proposal » of a binding towards the C API 9.0 available. [URL: OpenGL of ImageMagick. http://sourceforge.net/projects/gnat-florist --su] From: Luke A. Guest The binding is far from finished, to make it an interesting library it especially lacks mailto://[email protected] Date: Sat, 13 Mar 2004 16:40:30 +0000 the procedures for handling the BLOB http://www.ada.krischik.com Subject: Anyone interested in Ada & (binary large object) data embedded in OpenGL ImageMagick. wxWindows/wxWidgets Newsgroups: comp.lang.ada The object is not that of implementing all Binding Can come to irc.freenode.net #Ada. the functions in ImageMagick, rather to From: Lionel Draghi I've been playing with the original work use ImageMagick as an interface to the by David Holm, and have started to create most used image formats. Date: Tue, 24 Feb 2004 23:32:58 +0100 a thick binding. URL: http://karakush.free.fr/index.html Subject: Re: wxWidgets (wxWindows) I'm usually there. Please, have a look and let me have your Newsgroups: comp.lang.ada feedback. Szymon Guz wrote: Library for BMP/JPG/GIF Any observation is welcome; I would > Do you know if anybody created a expecially value comments on: From: Gautier binding to wxWindows in Ada? * types and constraints Date: Mon, 16 Feb 2004 23:59:42 +0100 Craig Carey: Subject: Re: BMP/JPG/GIF library in Ada? * memory deallocation http://www.ijs.co.nz/code/ada95_wxwind Newsgroups: comp.lang.ada ows_cpp_bindings_unfinished.zip http://www.mysunrise.ch/users/gdm/gsoft.ht * exception handling. m Thanks in advance. Refer to his posting: http://coding.derkeiler.com/Archive/Ada/ Brian Catlin: Gwindows_Extended - comp.lang.ada/2003-10/0587.html > Does anyone have a library for reading, Extension Packages for PS: wxWindows changed name because writing and manipulating image files in on Microsoft demand (see the BMP, JPG, or GIF format? I tried Gwindows Binding http://wxwidgets.org/name.htm). May we searching on AdaPower, but the search From: Frank Piron still consider windows being a common capability doesn't work (nor do a lot of word? the links) Date: Mon, 19 Apr 2004 14:12:31 +0200 Subject: Gwindows_Extended There are BMP (I/O) and GIF (I) in Newsgroups: comp.lang.ada Konada.Db - Oracle Access SVGA.IO in dos_paqs.zip, URL at bot- Library tom. Full Ada, easy to adapt to another Gwindows_Extended contains packages contex as SVGA & DOS. which enrich David Botton's Gwindows From: Frank Piron Binding with state-of-the-art controls. BTW, for PNG there is: Date: Mon, 19 Apr 2004 13:09:02 +0200 http://privatewww.essex.ac.uk/~sjs/png_i Gwindows_Extended is (of course) re- Subject: Konada.Db o/png_io.html leased under the GPL. Newsgroups: comp.lang.ada Some Features of Gwindows_Extended: Konada.Db is an Ada95 library for easy Texture mapping with Ada - Extended list view controls with header and performant Access to Oracle Databases. From: Joachim Schröer , column sorting, coloring at subitem lev Icons at item level, Grid Konada.Db is built on top of Dmitriy Date: Sat, 13 Mar 2004 15:00:38 +0100 appearance and more. Anisimkov's Ada Oci library, an Ada95 Subject: Re: Texture mapping with Ada - Extended toolbars with tooltips, flat Binding to the Oracle Call Interface. Newsgroups: comp.lang.ada buttons, check-style buttons and icon Some features of Konada.Db: Alfredo Macias wrote; support. - Bind and Define Variables are managed by the library, - Multiple Connections,

Ada User Journal Volume 25, Number 2, June 2004 52 Ada-related Tools

- Asynchronous Calls, fixed is valuable information that de- able's address and do a normal subroutine- - Easy to use SQL interface to lob's - serves to be public. The workaround, if call afterwards. But consider this as large objects any, is even more valuable. highly iirc, I don't even know if it's true at all ;) - Documentation and many Examples > There is however a point in reporting such bugs to your distribution ( Someone contributed graph-coloring-op- Konada.Db is licensed under the GPL. etc), since it is sometimes possible to timization-code, I guess it's for automati- Download Konada.Db from: backport fixes from CVS to gnat 3.15p cally deciding which variables to use as http://www.konad.de/download.htm or whatever register-vars (faster than RAM-vars). But Yes. The distribution acts as the front line I'm not sure ;) Reporting Compiler's Bugs of support for all the software therein; if Besides this a bugtracking-system exists you find a bug in any software that came and I'd guess the Ada-component itself From: Sergey with your distro, you normally report it to was improved due to userfeedback. Date: 15 Apr 2004 02:53:59 -0700 the distro. The main reason for this is that Dunno. Subject: Re: Ada compiler distros often patch the software, and the Newsgroups: comp.lang.ada From: Duncan Sands bug may or may not originate from up- Date: Thu, 22 Apr 2004 14:44:44 +0200 Ludovic Brenta wrote: stream. Subject: Re: GCC 3.4 Ada compiler quality? > > Ok, I don't know exactly but the only If it turns out that the bug does come from Newsgroups: comp.lang.ada thing that I can said for certain - it isn't upstream, the maintainer (for Debian that Georg Bauhaus wrote: […] that good. I've tried to compile aws- would be Matthias Klose or myself) will 1.4.0 using 3.2.3. Compilation finished forward the bug to upstream, i.e. re- > It has solved some problems for me well, but regression tests have badly [email protected] or the GCC bugzilla data- having to do with private children, and failed... base. If you *know* that the bug comes with generic formals in certain circum- from upstream, then you help us by sub- stances. > Have you filed problem reports in mitting the bug there as well as in the I find -gnatwa quite useful- GCC's bugzilla? This kind of informa- distro's bug database. The project file support is better tion, if detailed, is very valuable, espe- (though this might affect portabiliy). cially if the problems are regressions Another way in which bug databases are since 3.15p. useful is to permit tracing patches to bugs; I have had problems with the code gener- i.e. by looking at the bug log, you can find ated when using -gnatn, and sometimes I thought it doesn't make much sense, be- out which change to GCC fixed a par- when just using -O2 (mysterious seg- cause everybody over there was (and still) ticular bug. Without this information, it is mentation faults, exception handling fail- saying that you shall stay away from us- very difficult to backport fixes. ing etc). I haven't noticed any regressions ing gcc-ada due to its pre-alpha quality. when compiling without optimisation, I just filed a bunch of bug reports in the > I just received a bunch of very detailed compared to gnat 3.15p. Debian database for GNAT 3.15p. There bug reports for 3.15p. Since 3.15p are several more that I have to file as well. doesn't have a public bug database, I'll The Development of GNAT The steps are to try and reproduce file them in the Debian bug tracking them with GCC 3.2, 3.3 and 3.4. Those system for all to see. Time permitting, From: Ludovic Brenta not fixed should then be tagged upstream I'll do this over this and next weeks. and forwarded to GCC's bugzilla. I will Date: 26 Mar 2004 00:07:29 +0100 From: Ludovic Brenta appreciate any help with this; if you wish Subject: Re: Is 3.15p -still- the latest GNAT to contribute some of your time, please 'p' release? Date: 15 Apr 2004 12:41:48 add information to the bugs in the Debian Newsgroups: comp.lang.ada Subject: Re: Ada compiler database: http://bugs.debian.org/cgi- Newsgroups: comp.lang.ada bin/pkgreport.cgi?pkg=gnat Dale Stanbrough wrote: [about reporting bugs in GCC 3.2.3 to > I was looking at cs.nyu.edu the other bugzilla] Quality of GCC 3.4 day, and the latest Gnat version still seems to be 3.15, which dates from > I think that if you find a bug with 3.2.3, From: Georg Bauhaus Is this -really- the latest release? exists in gcc CVS before reporting it to Date: Thu, 22 Apr 2004 11:57:29 +0000 the gcc people. What is the point of Subject: Re: GCC 3.4 Ada compiler quality? Yes, it is the latest official release, and is telling the gcc developers about bugs Newsgroups: comp.lang.ada still recommended, unless you want to they already fixed? participate in the development of GNAT. It has solved some problems for me hav- [...] This is indeed the policy of GCC devel- ing to do with private children, and with opers; they do not support any version of generic formals in certain circumstances. The future is uncertain to me. ACT has GCC but the latest release (3.3.3 as of said they plan to make additional "p" re- now). I find -gnatwa quite useful leases available, but there is no telling when. Meanwhile, a lot of work has gone Before filing a bug to GCC, you should The project file support is better (though this might affect portabiliy). into the upcoming GCC 3.4. It will be not only check it against the latest release, more stable, offer some features proposed but also make sure that this bug was not From: Adrian Knoth for Ada 2005, as well as some additions introduced by the distribution; i.e. you Date: 21 Apr 2004 18:52:58 GMT to project files and the GNAT.* library. should only file bugs if you use an un- Subject: Re: GCC 3.4 Ada compiler quality? But it does not support tasking on modified GCC. Also, you should search Newsgroups: comp.lang.ada powerpc-*-linux (a show stopper as far as the bug database to see if it has been re- I'd been using the 3.4-cvs for a while. Six I am concerned), and lacks GLADE. ported before. months ago it was fine and did the job. I My recommendation is: stick with 3.15p. Still, if you find a bug in 3.2.3 that is think is is worth upgrading, but I don't If you want to be on the bleeding edge, fixed in 3.3.3, I think you should file it know why ;) IIRC they changed a lot in experiment with GCC 3.4 or, better yet, and close it immediately, and provide any procedure-calls. Instead of pushing the get involved in the development of GCC workaround you know of for the version parameters to the stack and popping them 3.5. Avoid GCC 3.1, 3.2 and 3.3. in question. The fact that this bug was afterwards they're calculating the vari-

Volume 25, Number 2, June 2004 Ada User Journal Ada-related Tools 53

From: Robert I. Eachus come important. But right now, even the should only be used with a support con- 2005 in that is just a guess.) tract. Customers tend to agree with that Date: Sat, 27 Mar 2004 16:42:27 -0500 From: Stephen Leake position. Subject: Re: Is 3.15p -still- the latest GNAT Again, I don't see how this is relevant to 'p' release? Subject: Re: Questions about Ada Core Debian. Newsgroups: comp.lang.ada Technologies > - Since GNAT Pro, as a derivative work > > > You could always contact friends Date: 06 Apr 2004 23:22:27 from GCC, is necessarily distributed who are (or work for) paying customers Newsgroups: comp.lang.ada under the GPL, is the above request not and get a Pro version from them. Ludovic Brenta wrote: an infringement of the GPL? > > This is pirating. I will never encour- > I got some flak[1] about things I wrote In short, the GPL says "If you give some- age such a disrespectful in my draft Debian Policy for Ada [See one a binary, you also have to give them > I thought Gnat was Open Source and also the relevant subsection in the Ada the source". was developed with taxpayer funds on and Linux News section – su.]. While I The GPL does _not_ say "if you give one that basis. No? prepare Draft 2, I would like to get person a binary, you also have to give The situation is much more complex than some information in order to get some everyone else the same binary". So even that. First, having a non-public release of facts straight. Here is a list of questions if ACT was requesting that customers do GNAT is not piracy, whether or not you I have; please answer them only if you not distribute non-public releases, it paid for it. Paying ACT customers are have first-hand knowledge; I am trying would not be violating the GPL encouraged not to redestribute the non- to dispel rumours and spread facts :) - Will ACT make more "p" releases of The latest version of your Debian policy public releases in this way, but there is looks good to me, except for the part nothing that legally prevents them--or GNAT in the future? They told me pri- vately they would, but has anyone else about ACT requesting non-distribution of ACT from doing so. In fact, there have non-public versions. been times when I have been given access heard about a public statement from to such versions--by ACT--either to help ACT? From: Steve decide whether some behavior was a bug, [1] I mean I got *friendly* flak, kind Date: Wed, 07 Apr 2004 04:38:06 or to help fix a bug. In those cases, I have of like error messages from an Ada Subject: Re: Questions about Ada Core disposed of the wavefront (or in one case, compiler :) Technologies I think, 3.12a release) once the problem The last I heard from them on this topic Newsgroups: comp.lang.ada was solved. I didn't do this for legal or (about 6 months ago) was that they had Ludovic Brenta wrote: moral reasons, but because I wanted any not decided. code I publically distributed to compile > - Will ACT make more "p" releases of > Is it too much to ask for a release date GNAT in the future? They told me pri- and run on the current GNAT public re- or time frame? lease. vately they would, but has anyone else Yes, it is too much to ask :) heard about a public statement from On the other hand, if you as a GNAT li- ACT? Is it too much to ask for a re- censee give a copy of the compiler to > - Have ACT really switched their day- lease date or time frame? someone, then report their bugs and to-day development to the FSF? problems to ACT as your own, that is The last I heard is that they have no plans I don't know. I also don't see how this is to stop making tese releases. fraud. relevant to Debian. Which brings us full-circle to the issue of > - Have ACT really switched their day- > The changelogs suggest so, in which to-day development to the FSF? The public releases by ACT. First, AFAIK, case I can suppose they merge selected any contracts involved in the creation of changelogs suggest so, in which case I changes to GNAT Pro in their private can suppose they merge selected GNAT were between the government and repository? New York University. NYU is, I think, a changes to GNAT Pro in their private part owner of ACT. But the public re- I assume they are maintaining at least a repository? leases of GNAT are intended as a public separate branch, if not a separate reposi- Of course ACT will be maintaining their service, and if you check, you should tory, but I really don't know. own site. They have customers that de- download them from NYU, not from > - Will the next GNAT Pro be based on pend on them and they cannot tolerate ACT. ACT is involved in deciding when FSF's GCC, or on ACT's private re- instability. a version of GNAT is stable enough to pository? A few months ago there was an an- warrant becomming a public release. 5.02a is current (released in March 2004). nouncement on the gcc mailing list that If you are familiar with the concept of the It is based on FSF gcc 3.2.3 (that's what ACT would be updating the FSF reposi- Cathedral and the Bazaar, for some soft- gcc --version says). toriy on a regular basis. If I recall cor- ware the cathedral approach is much more As usual, ACT has made no firm stat- rectly, Arnauld Charlet of ACT was made appropriate. Public releases of compilers ments about future plans. responsible for keeping the FSF reposi- are one such case. If you want to put to- tory up to date. > - Does ACT recommend anyone switch to gether several publically available soft- > - Will the next GNAT Pro be based on ware packages into a project, you are GCC instead of GNAT 3.15p? If so, which version of GCC? FSF's GCC, or on ACT's private re- much better served if all of the developers pository? of those packages used the same com- I believe they would say "test it with your piler. If each used different versions of application; use whichever is best for ACT's private repository. Over time the GNAT, or required different versions of you". difference between the two will continue the same libraries, you end up having to > - Does ACT request that customers not to decrease. do a lot more work. distribute copies of GNAT Pro? > - Does ACT recommend anyone switch So as far as I am concerned, it will be nice No. To be specific, there is nothing in the to GCC instead of GNAT 3.15p? If so, when there is a stable GNAT release that support contract that says this. They do which version of GCC? uses the new GCC backend. But I am point out that the non-public releases are ACT doesn't recommend anyone use a 'p' quite content to use 3.15p until such a non-public for a reason; they are more release for serious work. The public re- version is available. (Well, until the issue likely to contain bugs, and therefore leases are primarily released for academic of Ada 2005 compatibility starts to be-

Ada User Journal Volume 25, Number 2, June 2004 54 Ada-related Tools use. Of course the 'p' releases are of good would have just gone to my last complete whereby "restrict" means "requiring a quality and could be used for serious backup. But when it started failing I was separate deal". It seems this is the official work, but ACT does not stand behind able to do one last incremental backup-- interpretation by OSI. I'm liberal so I call them. For that you need to by GNAT Pro. but it took days. Then I had to build a it open source. It does not hurt any other From: Florian Weimer new disk, and apply all the increments. clause of the OSD. Since that disk held the partition I use for The commercial-open source clash is still Date: 07 Apr 2004 17:27:47 +0200 Ada development, I didn't want to change an open issue. Never mind. Just use it. If Subject: Re: Questions about Ada Core any libraries in the middle of all this.) it's commercial, tell the authors. They'll Technologies cut you a fair deal. You'll not have to pay Newsgroups: comp.lang.ada GNADE 1.5.2 - GNAT Ada unless you get rich, and then it doesn't The main development happens on ACT's 95 Database Development hurt you. That's the gist of it. Ignore the infrastructure (after all, they have a far Environment legalese. "Just do it." more extensive test suite (which is partly covered by NDAs and cannot be pub- From: Samuel Tardieu Lex and Yacc for Ada lished), an automated regression tester Date: Wed, 17 Mar 2004 09:16:40 +0100 From: Wurbel based on that test suite, a separate bug Subject: Re: Release of GNADE 1.5.2 Date: Wed, 24 Mar 2004 15:40:49 +0100 tracking system, their own developer Newsgroups: comp.lang.ada Organization: Universite de Toulon et du communication channels &c). [See also same topic in AUJ 24.3 (Sep Var Arnaud Charlet regularly (daily?) merges 2003), and AUJ 24.1 (Mar 2003), p.14 -- Subject: unable to find a downloadable of ACT's changes into the FSF tree. But this su] aflex/ayacc doesn't mean that this tree is the sole ref- The objective of the GNADE project is to Newsgroups: comp.lang.ada erence for development. provide various packages which are al- [See also same topic in AUJ 23.4 (Dec From: Robert I. Eachus lowing Ada 95 applications to access re- 2002) -- su] lational data base products, mainly SQL I'm in search of a lex/yacc equivalent for Date: Tue, 13 Apr 2004 16:54:03 -0400 RDBMS. Ada. After an extensive search on the net, Subject: Re: Questions about Ada Core This release provides the first time a The only tool I found is aflex/ayacc, but I Technologies common build procedure for windows am unable to download it (the server Newsgroups: comp.lang.ada and *unix systems. Additionaly the use of ftp://liege.ics.uci.edu/ seems to reject Stephen Leake wrote: the GPS system of ACT.com has been anonymous connections). taken into account, which means for each > As I said, there is nothing in the cus- component a gps project files has been Any clues? tomer contract with ACT about not created. From: Jeff distributing GNAT. But they do infor- Date: 24 Mar 2004 14:04:10 -0800 mally request it. http://gnade.sourceforge.net/ Subject: Re: unable to find a downloadable Actually, what ACT re- Mneson - Database System of aflex/ayacc quests/recommends is not distributing Newsgroups: comp.lang.ada wavefront versions. Wavefront versions From: Marius Amado Alves > I dont read French, but ayacc/flex is are usually a response to a particular mentioned here and appeare to be ac- problem encountered by a (supported) Date: Tue, 23 Mar 2004 20:39:00 +0000 cessable. user. As such they are less thoroughly Subject: Mneson: persistent untyped graphs http://perso.wanadoo.fr/pascal.obry/con tested than other versions of GNAT. Newsgroups: comp.lang.ada trib.html What about the versions ending in a, not I'm glad to announce the first release of There is also a version at: w? They are betwixt and between. In Mneson, a 100% Ada library for persis- http://www.macada.org/tools.html with general if an a version gets to where it has tent untyped directed graphs of basic val- PDF documentation. a short buglist and no outstanding major ues (integer, string, float). problems, it gets converted to a p (public) From: Craig Carey version pretty quickly. What has been http://www.liacc.up.pt/~maa/mneson Date: Tue, 30 Mar 2004 01:58:22 +1200 going on recently, as I it, is It's open source. Subject: Re: unable to find a downloadable of aflex/ayacc that ACT has versions which perform From: Marius Amado Alves Newsgroups: comp.lang.ada well on some platforms but fail on others. When you have customers with a support Date: Wed, 24 Mar 2004 13:01:01 +0000 The directory has gzipped "Mach-O contract, you can insure that they have a Subject: Re: Mneson: persistent untyped executable ppc" documents instead of variant that runs on the hardware (and graphs Ada 95 files (so implies my GNU OS) that customer uses. Newsgroups: comp.lang.ada 'file.exe' program). It might not be the lat- est and so lack the 'UMASS' extensions. Once the 5.xx versions become stable, [Regarding SDC Conditions, the licensing ACT will stop recommending that the terms of Mneson, There seems to be a merged edited ver- public use 3.15p. Notice that the 5.xx http://www.liacc.up.pt/~maa/mneson] sion of the Yacc Ada parser in this file versions are completely available to the (also Adgoop was updated): If it's non-commercial, just use it. public, just not recommended unless ACT http://www.ijs.co.nz/code/ada95_adagoop has insured that they work in your envi- > I don't find any statements about this _parser.zip ronment. (And of course they are under license. no obligation to test those versions on AYacc would have user's Ada code be non-supported hardware and OS configu- There is some amount of discussion and inside of a case statement inside of a loop rations.) commentary in SDC and OSI fora. statement. As for me, I have been staying with 3.15 > Neither is it on the OSI list as I can see. Adagoop would instead create Ada code because I want the software I write to be It is open source, but no, not OSI-compli- that creates a tree on the heap having as widely distributable as possible. (I just ant. The SDC license breaches clause 6 of nodes that are tagged records, (one for went through a painful process with a the OSD under a certain conservative in- each main Yacc entry). failing disk. If it had failed completely I terpretation of that clause, namely one

Volume 25, Number 2, June 2004 Ada User Journal 56 Ada-related Tools

Adasubst & Adadep Subject: ASIS for GNAT first release Craig Carey wrote: Newsgroups: comp.lang.ada > Has anybody succeed in putting From: Jean-Pierre Rosen I am pleased to say that the ASIS for code inside of a DLL and getting it GNAT effort was successful and I have called by a GNAT Ada 95 main pro- Date: Fri, 27 Feb 2004 13:24:56 +0100 released a first snapshot version for gcc gram (inside of a *.exe file) ?. Organization: Adalog 3.5. Yes, I have about 2 years ago, using Subject: New version of Adasubst/Adadep The Project is looking for maintainers of Delphi 3 and gnat 3.15a1. It took a while Newsgroups: comp.lang.ada other versions (gcc 3.4 and gcc 3.3.1). It's to figure out how to generate the files re- Adasubst 1.2 not that difficult to add A.S.I.S. once you quired by gnat. (.lib-files?). All the tools Added overloaded form of enumeration have compiled your own gcc. needed was available with gnat. I also literals in the dictionary Fixed bug not From: Martin Krischik > Any URLs saying how to put Delphi loaded form. Fixed bug with -P option to Subject: ASIS for GNAT 20040403 release GUIs inside of DLLs? process only the visible parts of nested Date: Sat, 03 Apr 2004 13:10:07 +0200 No. Did this with Delphi 1 in 1995 (called packages/tasks/protected Organization: AdaCL from a VB3 app). Never caused any Adadep 1.2 Newsgroups: comp.lang.ada problems. Autocreate of forms naturally Added number of uses and declaration New snapshot release from A.S.I.S. for won't work. You create an procedural in- kind of each entity in the report. GNAT. terface that call the form-stuff inside the DLL. Download, more information, from This Version contains gnat sources for Adalog's components page: GCC 3.5, GCC 3.4 and GCC 3.3.1. The You should also be able to create an http://www.adalog.fr/compo2.htm first two from today. ActiveX interface that you can use from The following A.S.I.S. tools are bundled: Ada, but all my attempts to do this has ASIS for GNAT: New adabrowse, adadep, adasubst, asistant, resulted in loads of unreadable code that gnatelim, gnatstub. worked but was not reliable. I guess it Project and First Versions leaked memory but I could never find the Binary package for i686, GCC 3.5, SuSE leaks. Do a web-search for a package From: Martin Krischik 9.0 available. called gnatcom. It contains the stuff you need for Ada/COM interfacing. Date: Fri, 12 Mar 2004 17:05:07 +0100 Delphi to Ada Translator Subject: New Project: ASIS for GNAT Sorry for not beeing able to be very pre- Organization: AdaCL From: Jacob Sparre Andersen cise. I really don't remember how I did Newsgroups: comp.lang.ada most of this stuff. I like to announce the beginning of a new Date: 19 Feb 2004 21:44:44 +0100 Project. Subject: Re: Delphi to Ada translator NaturalDocs - Source Code Newsgroups: comp.lang.ada Documentation Generator The Project aims to provide an up to date Szymon Guz wrote: implementations of ASIS = Ada Semantic From: Samuel Tardieu Interface Specification for GNAT based > Do you know any Delphi to Ada Date: Fri, 16 Apr 2004 13:25:18 +0200 on gcc 3.5. The currently available open translator? Subject: NaturalDocs source ASIS implementation is for GNAT To: [email protected] on gcc 2.8.1. There is at least a Pascal to Ada transla- tor, which also (or in a special edition) NaturalDocs est un outil libre permettant The Project is located at sourceforge: accepts Borland Pascal source code. It de générer automatiquement de la docu- http://sourceforge.net/projects/gnat-asis/ may also have been modified to accept mentation pour un grand nombre de lan- Current experinental versions are avail- Delphi source code. gages (similaire à pour ou able via cvs. From: Randy Brukardt Javadoc), dont Ada. From: Arnaud Charlet http://naturaldocs.org/about.html Date: Thu, 19 Feb 2004 14:53:00 -0600 Date: Tue, 16 Mar 2004 14:59:28 +0100 Subject: Re: Delphi to Ada translator Playing Ogg Files Subject: Re: New Project: ASIS for GNAT Newsgroups: comp.lang.ada Newsgroups: comp.lang.ada PasTran does Pascal-to-Ada, of course, From: Preben Randhol and we've done custom versions for vari- Note that having a reliable ASIS working Date: Fri, 5 Mar 2004 09:30:27 +0000 with a particular GNAT version is a lot of ous clients and various Pascals, but we've never had anyone ask for Delphi. We Subject: Re: Ogg and Ada work, and certainly much more than just Newsgroups: comp.lang.ada putting some sources together as you de- could of course do a custom version, but scribed, since there's a very close relation- they would need to be a quite a bit of code Jorge Suárez-Solis Rivaya wrote: ship between the GNAT and ASIS data to translate to make it economic. > I've read in an old post (year 2002) structures. I'm afraid your resulting source From: Gautier about playing ogg files from Ada pro- package will suffer from the same trouble Date: Thu, 19 Feb 2004 22:26:27 +0100 grams. Does anyone know how can I do gcc 3.3 did: frozen Ada sources with a Subject: Re: delphi to ada translator it? moving (incompatible) GCC back-end Newsgroups: comp.lang.ada that compiles but is pretty unreliable. As far as I know there isn't an Ada bind- P2Ada for instance (with the BP2P pre- ing yet. Same comment for glade btw: the glade processor). NB: OO support is ongoing. run time is tightly coupled with the corre- But Chad suggested earlier to: Take a sponding GNAT run time. www.mysunrise.ch/users/gdm/gsoft.htm look at the AdaSDL binding (thick or thin). If I remember correctly SDL From: Martin Krischik From: Leif Holmgren Date: Mon, 23 Feb 2004 22:35:51 +0100 should be able to play Ogg files, but I have never tried it. Date: Sun, 14 Mar 2004 13:04:43 +0100 Subject: Re: delphi to ada translator Organization: AdaCL Newsgroups: comp.lang.ada http://www.libsdl.org

Volume 25, Number 2, June 2004 Ada User Journal Ada-related Tools 57

Ada-MIDI Library - Booch components for indefinite ele- how I can get hold of a more recent ments. GLADE for 3.15p? From: Patrice Freydiere - Trace feature - very handy for CGI (no There are no more recent releases for Date: Mon, 12 Apr 2004 16:36:50 +0200 , no console output). 3.15p. All more recent releases are for Subject: Ada-MIDI library new release paying customers and GNAT 5.x. Newsgroups: comp.lang.ada - Control cdrecord and makeisofs. - Some cvs tools. The bad news is: There might never be A new release of the native MIDI format since act plans a new Annex E based on library for Ada has been posted on http://www.ada.krischik.com PolyORB. http://pfreydiere.free.fr GLADE For GNAT: New While the sources are GPL there are only Feel free for feedbacks distributed to paying customers. The GPL Project says that you must provide the sources to Optical Ballot Scanner anyone you provide binaries to. From: Martin Krischik From: Tom Moran Without a public binary release act does Date: Tue, 09 Mar 2004 02:32:25 GMT Date: Sat, 03 Apr 2004 13:13:14 +0200 not need to provide a public source re- Subject: Ada optical ballot scanner app Organization: AdaCL lease. :-(. Newsgroups: comp.lang.ada Subject: New Project: GLADE for GNAT > Good luck with the project though! I'd I've posted an optical ballot scanner pro- Newsgroups: comp.lang.ada love to see more people using the tech- gram at http://home.comcast.net/~twmoran I like to announce the beginning of a new nology, which beats the alternatives by Project. a long way (in terms of ease of use and It was developed to process images of a flexibility). thousand cards marked by kids last The project whishes to providing an up to Christmas to indicate their toy etc prefer- date implementations of Annex E The current cvs version compiles and ences, for a Christmas toys-for-needy- (Distributed Systems) for GNAT. links. However there seems to be a chance kids undertaking in compiler options so some .o files are The Project is located at sourceforge: not generated. So more work is needed. (www.mytwofrontteeth.org) The images http://sourceforge.net/projects/gnat-glade/ were scanned by an inexpensive batch scanner. It uses an FFT-based algorithm Current experinental versions are avail- Strings_Edit 1.4 based on sample unmarked and fully able via cvs. From: Dmitry A. Kazakov marked ballots so it can do alignment and Since GLADE is a lot more difficult then finding of checkboxes without need for ASIS help would be apreciated. more customization. Source for the main Date: Sat, 07 Feb 2004 11:20:34 +0100 program is also posted, with no restric- From: Martin Krischik Subject: Strings_Edit v1.4 tions. Newsgroups: comp.lang.ada Date: Fri, 16 Apr 2004 08:36:02 +0200 The package Strings_Edit provides I/O Organization: AdaCL AdaCL 4.1.0 - Ada Class facilities. The following I/O items are Subject: Re: New Project: GLADE for supported by the package: Library GNAT Newsgroups: comp.lang.ada * Integer numbers (generic, package From: Martin Krischik Integer_Edit) Dr. Adrian Wrigley wrote: * Floating-point numbers (generic, Date: Sat, 03 Apr 2004 13:05:20 +0200 > How does this relate to the ACT package Float_Edit) Organization: AdaCL GLADE releases? Subject: AdaCL 4.1.0 released. If ACT are working with their own * Roman numbers (the type Roman) Newsgroups: comp.lang.ada sources, fixing bugs for paying custom- * Strings Improvements on existing features. ers, providing them with wavefront re- leases, won't the "Sourceforge http://www.dmitry-kazakov.de/ada/ AdaCL.CGI now support GLADE" always be out of date? Every strings_edit.htm "multipart/form-data" - that allows file time a new release is made by the The new version fixes bugs in processing upload. original authors, you will have to inte- very large numbers. Support for dynamic link libraries - this grate their changes. And will it be pos- will allow the creation of a Debian pack- sible to take the project in a new direc- Crytographic Library age. tion without the sources diverging, gnatprep has been removed. Conditional giving a permanent split? From: Jano compile now done by use of seperate di- Well, the paying customers are allways up Date: Sun, 1 Feb 2004 17:35:00 +0100 rectories - this makes it easier to use the front. What nags me is that ACT has nor Subject: Re: Free cryptographic library for lib if you still want to link staticly. released a "p" for 2 years. So the 3.15p Ada? Newsgroups: comp.lang.ada Abstract: compiler becomes out of date. Only today gcc 3.4 on the gnat list Peter C. Chapin wrote: AdaCL provides library services for ([email protected]) was sug- scriptig in Ada: > I am designing a security sensitive ap- gested for use with G5 PPC. plication and I would like to use Ada to - A text search and replace library. > I am a constant user of GLADE, but develop it. This is something of a - A complete cgi binding. have encountered a major bug. Under hobby project so it is very low budget. certain (common) circumstances, fail- In my application I need to make secure - Execution of external programms inclu- ure of one partition can cause the whole hashes and digital signatures along with sive I/O redirection with program to lock-up - even when the ap- the necessary key management that im- Ada.Text_IO. Unlike GNAT.OS_Lib propriate options are specified in the plies. I'm looking for a free (GPL or AdaCL lets you wait on a given asyn- build. I have not been able to get hold similar license) crypto library written chronous process instead of just the first of a wavefront release where this is entirely in Ada. I don't particularly to end. (said to be) fixed. (all this on versions want to link to a C library since part of - A garbage collector. 3.15p, Intel Linux). Does anyone know the point of using Ada in this case is

Ada User Journal Volume 25, Number 2, June 2004 58 Ada-related Products

specifically to avoid C. > I have always used for writing code > In other case, can anyone suggest me Does such a library exist? I've been and would still be comfortable with another tool for Ada unit test? prowling around on the 'net but so far that. We are happy with AUnit the projects I've turned up are very in- I strongly recommend that you use . We did complete and inactive looking. (VI iMproved). I have some unfinished evaluate VectorCast, I don't remember the It's quite old but I've been using its SHA1 Ada scripts that can be helpful if you want details but my _impression_ was that the and Tiger implementation without any a copy. http://www.vim.org/ possible advantage of being able to problem. It has other digital signatures as I use Vim and here is a screenshot how it change the test script without recompila- well: http://sourceforge.net/projects/adacf/ looks like when I code with my setup: tion was not so big an advantage on fast From: Jeffrey Carter http://www.pvv.org/~randhol/Vim/project hardware. Also we had trouble getting it Date: Sat, 31 Jan 2004 20:10:58 GMT -ada.png to understand our (complex GNAT) com- pilation environment. Subject: Re: Free cryptographic library for (Picture is from Linux, but you can get Ada? the same behaviour in Windows) Newsgroups: comp.lang.ada I use these excellent scripts, all under: Ada-related Products There's an Ada implementation of the http://vim.sourceforge.net/scripts/ : Solitaire algorithm at: script.?script_id=31 ACT - GNAT Pro 5.02a www.schneier.com/code/solitaire-ada.zip script.php?script_id=69 script.php?script_id=58 From: Cyrille Comar Date: Thu, 26 Feb 2004 18:25 From: Jean-Pierre Rosen If you prefer a different IDE there is also: Subject: Announcing Availability of GNAT script.php?script_id=95 Pro 5.02a Date: Tue, 10 Feb 2004 13:18:38 +0100 but I like the project approch more. To: [email protected] Organization: Adalog Subject: Package Debug V2.2 available Controlling the Serial Ports The 5.02a release completes the transition Newsgroups: comp.lang.ada from GNAT3 to GNAT5 for most of the From: Michael Bode GNAT Pro configurations. This is a com- I just released a new version of package Date: 10 Mar 2004 22:28:23 +0100 prehensive enhancement to the GNAT Debug, which contains very useful tracing Subject: Re: Serial port control Windows Pro technology offering multi-language functionalities. and Linux capabilities: Ada, C, C++ (contact our Improvements include: Newsgroups: comp.lang.ada sales department for C and C++ support options). It also offers many new features - Binary tracing of any type (using Erlo Haugen wrote: […] both in the core GNAT compiler streams). > I know that questions like this have technology and in the programming - Tracing objects (traces are performed been asked before. I did some searching environment toolset. For example: through Initialization/Finalization), on Google and found som links, but - greater flexibility in the configurability great for tracing functions that return they were all broken. of the High Integrity Runtimes, complex expressions I need to control a serial port from an Ada program. I need to have control of - fewer restrictions on component repre- - New package Debug.Assert. Adds a sentation clauses, conditionnal trace (tracing only if some the handshake signal (set and clear). assertion fails) and a reentrancy Any good pointers to pack- - a new tool 'gnatclean' for removing detector object (traces when two tasks ages/bindings?? compiler generated files, call the same subprogram at the same Maybe http://home.t- - significant enhancements to gnatpp and time). Note that this is something online.de/home/michael_bode/eigener_mi gnatelim, nearly impossible to check with a st_en.html is useful for you. debugger. - new advanced versions of the gtkada, From: Jerry Petrey glade and asis add-ons - changed license to GMGPL (it was al- ready available freely for any purpose, Date: Tue, 09 Mar 2004 16:01:45 -0700 5.02a contains the latest release of the but it seems easier to use a well known Organization: Raytheon Company GNAT Programming System, GPS 1.4.1, license than trying to invent some new Subject: Re: Serial port control Windows which adds capabilities such as: wordings). and Linux - enhanced editor and source navigation Bug fixes: Newsgroups: comp.lang.ada - improved debugger support None. I have used Stephe Leake's com port - better integration under Windows utilities with great success (with some This package has been publicly available modifications) to control the serial ports - more powerful customization capabili- since 1999. We never received a bug re- on a Windows platform. They can be ties port. found here: - support for duplicated Ada file names Availability: http://www.toadmail.com/~ada_wizard/ad within a project a/win32_com_ports.zip See Adalog's components page: We encourage you to install and start us- http://www.adalog.fr/compo2.htm Ada Unit Test Tool ing this latest version of the GNAT Pro tool suite. As always, for questions, or to Ada Syntax Scripts for Vim From: Simon Wright inform us of issues that you encounter, please let us know through the GNAT From: Preben Randhol Date: 14 Feb 2004 17:11:32 +0000 Tracker report facility or by email at the Subject: Re: debbuger or unit test tool usual [email protected] address. Date: Fri, 30 Apr 2004 18:58:20 +0000 Newsgroups: comp.lang.ada Subject: Re: Recommendations?? Looking ahead to future releases, the next Newsgroups: comp.lang.ada Orvio wrote: major release will be 5.03, which will be available some time early in 2005. This Larry Hazel wrote: again will contain major new functional-

Volume 25, Number 2, June 2004 Ada User Journal Ada-related Products 59 ities, including much more extensive im- New York City and Paris, produces and Wind River Teams with plementation of new features for the new supports the GNAT Pro family of open- version of the Ada standard. source Ada 95 software development en- AdaCore on Platform Safety Critical ARINC 653 for Use In addition, later this year, we will, if vironments. Based on the GNU GCC needed, produce a follow-up release to technology, GNAT is available on more in Boeing 7E7 Common 5.02a, called 5.02a1 that will correct any platforms than any other Ada compiler Core System significant deficiencies found in the and is the only implementation of the 5.02a release. This will be a maintenance complete Ada 95 language. GNAT Pro, Date: Tue, 20 Apr 2004 release only and will not contain any new the professional edition of the GNAT URL: functionality. technology and the premier Ada devel- http://www.gnat.com/pressroom_11.php opment environment on the market, is AdaCore announces local used on enterprise-critical projects en- New York, NY and Alameda, Calif. compassing areas such as low-level com- Wind River Systems, Inc., the global distributor in Australia munications control, high-integrity real- leader in device software optimization time applications and large-scale distrib- (DSO), and AdaCore, the global leader in Date: Mon, 19 Apr 2004 uted systems. Ada 95 solutions and providers of the URL: GNAT Pro Ada development tool suite, http://www.gnat.com/pressroom_09.php ACT - Ada95 Development today announced that AdaCore's GNAT New York, NY - Monday, April 19, 2004 Environment for SGI Pro High-Integrity Edition for AE653 has - AdaCore, leader in Ada 95 technology been selected as the Ada environment for and providers of the GNAT Pro Ada ALTIX Product Line the Wind River Platform for Safety development toolsuite, today announced Date: Tue, 20 Apr 2004 Critical ARINC 653, to be used in the that it has entered into a distribution Boeing 7E7 Dreamliner Program. agreement with Dedicated Systems URL: The Wind River Platform with AdaCore's Australia Pty Ltd, a distributor providing http://www.gnat.com/pressroom_10.php technology will be used on the 7E7's Australia and New Zealand with world- New York, NY. Common Core System, provided by class software and hardware solutions in Smiths Aerospace, which is the backbone the real-time and embedded computing AdaCore, the leader in Ada 95 solutions of the airplane's computers, networks and markets with a special focus on defense and providers of the GNAT Pro Ada de- interfacing electronics. The 7E7 Common and communications. This collaboration velopment tool suite, today announced it Core System comprises approximately 80 will not only provide our Pacific Rim is expanding its support agreement with to 100 applications running simultane- customers with a fully integrated Ada so- Silicon Graphics. The new agreement will ously which will control many of the air- lution for native and cross systems, but include the development and support of plane's avionics and utilities functions. also bring them the high level of customer the GNAT Pro product line on the SGI® attention that is the hallmark of AdaCore. Altix® family of superclusters and serv- Wind River Platform for Safety Critical ers, which feature the 64-bit Intel® ARINC 653 is part of Wind River's Safe "We are pleased to be working with Itanium® 2 processor and the Linux® and Secure Program, which provides fully Dedicated Systems," said Robert Dewar, operating system. integrated device software platforms to President of AdaCore. "This collaboration meet the FAA's stringent safety certifica- allows us to continue the tradition of part- Since its launch just over a year ago, SGI tions. AdaCore's GNAT Pro High nering with our customers and maintain- Altix has become the first Linux OS- Integrity for AE653 was developed spe- ing a close relationship long after the based system to scale to 256 Itanium 2 cifically for Wind River Platform for point of sale." processors in a single system image-and thousands more via clustering-using the Safety Critical ARINC 653. Based on the "AdaCore has a fantastic reputation as a powerful SGI® NUMAflex global Ada programming language, Ada Core's technology leader, providing products and shared-memory architecture. The Altix development tools have been used exten- outstanding customer support. We are ex- architecture handles large data sets with sively in recent years for safety-critical cited to work with them in our territory" ease, giving software developers an op- avionics applications because of its high commented John Salerno, Director of portunity to provide 64-bit Linux applica- levels of portability. With AdaCore's Software Engineering at Dedicated tions to customers in manufacturing, oil GNAT Pro High Integrity now built into Systems. and gas exploration, homeland security, Wind River's Platform for Safety Critical About Dedicated Systems earth and environmental sciences re- ARINC 653, Boeing and its other 7E7 search, and life sciences. suppliers will be able to leverage their Dedicated Systems Australia is a dis- existing software investments and easily tributor in the Australia and New Zealand SGI has a long history of building high- adapt them to be used in the new Real-Time and Embedded Computing performance computing systems that per- Common Core System architecture. Markets with a special Focus on Defence, form well with Ada applications, and has Communications and Automotive appli- worked with AdaCore for nearly a dec- Designed to be the most advanced and cations. They represent world class hard- ade. The SGI Altix server port is the latest efficient commercial airplane in its class ware and software vendors to bring high and most exciting chapter of this story. and predicted to dramatically alter the quality and synergetic products to cus- future of avionics, the Boeing 7E7 AdaCore will continue to provide its Dreamliner will set new standards for en- tomers. Their headquarters are in Premium level service to all SGI custom- Adelaide, South Australia. Key software vironmental responsibility and passenger ers who purchased Ada 95 compiler sup- comfort. Developed to seat 200- to 250- suppliers are: Windriver Systems, Ada port contracts for the MIPS® processor Core Technologies, Programming passengers, the 7E7 will fly between and IRIX® OS-based product family and 3,500 and 8,500 nautical miles at the Research, RTI and KUKA Controls. Key will be developing technology to aid those hardware suppliers are: ELMA, Schroff, same speeds as today's fastest twin-aisle customers choosing to transition from this commercial airplanes - the 777 and 747. Condor Engineering, VMETRO, Sky processor architecture to the new Itanium Computers and Themis. Boeing began offering the new 7E7 to 2 processor-based Altix family. customers in early 2004 and is projecting About AdaCore that it will sell up to 3,500 7E7s over the AdaCore, a privately held company next 20 years. founded in 1994, with major offices in

Ada User Journal Volume 25, Number 2, June 2004 Ada-related Products 61

ACT - GPS 2.0.0 to provide enhanced capabilities for ob- that is incurred by full-blown multiple ject-oriented programming and to better inheritance in languages such as C++. For AdaCore is pleased to announce the im- address the needs of the real-time and supporting this in Ada 2005, the proposal mediate release of GPS 2.0.0. high-integrity communities. There is also is to have a new form of type called an the desire to standardize on certain com- interface type, similar to an abstract GPS, the GNAT Programming System, is mon implementation extensions (e.g., tagged type with no components. A an advanced IDE that streamlines your pragma Assert) and to expand the set of tagged type will be able to inherit from software development process - from the predefined library units. Of course, up- multiple interface types, overriding the initial coding stage through testing, de- ward compatibility is an important re- operations inherited from each of its par- bugging/verification and maintenance. quirement. ent interfaces. Designed by programmers for program- mers, GPS is a new kind of IDE that of- Following is a short overview of a few of Real-Time and High-Integrity Support fers the experience of designing software the key features proposed for the next re- The ARG is also evaluating several pro- in a uniquely comfortable environment. vision of Ada. posals in the real-time and high-integrity The 2.0.0 version is a major release and Mutually Dependent Package areas. These include support for task ter- features many improvements, notably: Specifications mination handlers, timing events, execu- tion-time clocks, alternative task dis- - A more powerful source editor Ada users have long been asking for a way to have mutually dependent types patching policies, and standardization of including the addition of many source the Ravenscar restricted tasking profile. navigation capabilities that can be declared in independent pack- ages. A new form of "with" clause, called New Pragmas - Speed improvements a "limited with" clause, is proposed to ad- Several pragmas that have been supported - Improved customization, in particular: dress this need. The "limited with" clause by GNAT for some time are candidates to allows packages to create weak depend- - A generic interface be added to the Ada standard. Specifi- ences on one another, essentially provid- that can be tailored to your specific cally, pragmas Assert, Unsuppress, ing an incomplete view of each package's CM tools and established procedures No_Return, and Unchecked_Union are all types. This permits two or more sepa- viewed as being generally useful and im- - A Python interpreter integrated in rately compiled types to reference each portant to standardize to improve port- GPS under GNU/Linux, Solaris and other via access components. "Limited ability of Ada programs. Windows for powerful scripting and with" clauses have a natural implementa- extensions tion in source-based compilers such as Predefined Library - Improved font rendering under Linux GNAT, and support for this feature is al- Extensions are also being considered for and Solaris ready available in current versions of the predefined Ada library. Some of the GNAT. new packages being proposed are in the - Support for the IRIX platform Aggregates for Limited Types areas of directory operations, matrix and - C/C++ improvements vector operations, sockets, and for sup- As an example of relaxing restrictions to porting some of the candidate features for - Better handling of C++ classes in en- make existing Ada 95 features more use- tity browser the real-time domain. There is also inter- ful, there is a revision proposal to allow est in defining a standard set of container - Better handling of C/C++ builds. aggregates to be given for limited types. libraries, although that may be addressed Limited aggregates would be permitted in by a separate standards effort, with some AdaCore and Ada 2005 contexts where a copy into a preexisting guidance from the ARG. object is not required, such as an actual As part of the ongoing standardization parameter or in the initialization expres- AdaCore is committed to the next version activities for Ada, the language is re- sion of an object declaration. This feature of Ada, and plans to continue imple- viewed periodically to see if corrections has been implemented in GNAT. menting the new features as the proposals or new features are warranted. This proc- are stablized and approved for the Ada More Contexts for Anonymous Access 2005 revision, as well as to prioritize our ess is carried out under the auspices of the Types International Organization for efforts according to expressed user inter- Standardization ("ISO"), more specifi- Another proposed feature enhancement is est. Prior to official standardization, these cally by the Ada Rapporteur Group to allow the anonymous access type nota- additions to the GNAT Pro technology ("ARG"), a technical committee from tion (used in Ada 95 for access parame- can be activated using a special switch (- ISO's WG9 (the Working Group for Ada). ters) to appear in more contexts, permit- gnatX) provided specifically for enabling The ARG includes Ada compiler imple- ting constants and record components to experimentation with the new features. mentors, users, and other language ex- be designated as "access". This will help Please stay tuned for the implementation perts. The ARG is currently working on a to reduce the need for explicit access type of additional Ada 2005 features to GNAT set of proposed amendments to Ada 95 conversions. This feature has been im- in the coming months. that are likely to become part of a revised plemented in GNAT. language standard scheduled to be com- Java-like Interfaces IPL Announces AdaTest pleted sometime in 2005. For the object-oriented domain there is a Integration with GPS AdaCore is directly involved with the Ada proposal for a simplified multiple inheri- From: "Jamie Ayre" 2005 language amendment process, not tance mechanism. During the design of only by participating in the ARG, but also Date: Tue, 1 Jun 2004 09:59:49 +0200 Ada 95's OOP features there was a con- To: Dirk Craeynest by implementing / testing the new feature scious decision to avoid multiple inheri- proposals as they become stabilized. We tance, because of concern with the dis- Subject: RE: ACT's press releases are also developing and submitting candi- tributed cost that would be imposed on date conformance tests as the new fea- the use of single inheritance. Since that Bath, UK, April 5 2004 - IPL Information tures are implemented. time, a restricted form of multiple inheri- Processing Ltd, suppliers of software The Ada 2005 development process has tance, sometimes called inheritance of testing tools announced that its AdaTEST several main goals. One aim is to remove interfaces, has been used to good effect in 95 product has been integrated with the limitations and to increase the usefulness languages such as Java. This kind of in- GNAT Programming System (GPS) from of existing features. Other objectives are heritance does not impose the overhead AdaCore.

Ada User Journal Volume 25, Number 2, June 2004 62 Ada-related Products

AdaTEST 95 is a tool which allows users (IMA) System with ease," noted Neil boards in the host computer); improved to test Ada software thoroughly and effi- Davidson, Principal Software Engineer, handling and resolution of internal com- ciently. In addition to the facility to gen- Avionic Systems. "We have used object piler errors, as well as improved machine erate test drivers and programmable stubs, oriented UML modeling tools on previous code insertion of 1750A assembly in- AdaTEST 95 users can also measure test programs, however the Hawk program structions into Ada source code. coverage and check static analysis met- presented us with a new challenge of gen- A mature solution for each target, TADS rics. Using Test Support Packages, users erating safety-critical SPARK Ada from a offers classical, Ada specific and target can automatically check global data for UML model." specific compiler optimizations to deliver unexpected corruption. "RtS' extensibility (both OLE automation performance benefits tailored to processor GPS, the GNAT Programming System, is and scripted code generation) enabled us architecture. TADS generates the most an advanced IDE that streamlines the to tailor the tool to meet our needs; we compact code available via highly opti- software development process - from the extended RtS so that we could enter mizing compilation, selective linking and initial coding stage through testing, de- SPARK annotations as part of the UML modularization of the run-time system. bugging/verification and maintenance. design model. We are able to manipulate "Many aerospace, avionics, defense and Designed by programmers for program- SPARK annotations at the design level other customer programs still depend on mers, GPS is a new kind of IDE that of- and then forward generate them as part of TADS safety-critical real-time embedded fers the experience of designing software the source code, ready for SPARK system development," Hash concludes," in a uniquely comfortable environment. Examination. We have gained multiple and DDC-I's philosophy of #1 in The integration of AdaTEST 95 into GPS benefits from this: (a) freeing engineers to Customer Care focuses on providing the means that users can invoke a range of think about the design implications of best possible software tools for every cli- AdaTEST 95 facilities from within the SPARK; (b) eliminating the manual typ- ent, coupled with superior engineering IDE. ing effort traditionally associated with services and customer support." SPARK; (c) automatically observing se- "We are confident that GNAT Pro/GPS mantic rules for the annotations; and (d) DDC-I - DDC-I Releases users will appreciate the fast access to ensuring compliance with our coding AdaTEST 95 which this integration gives standards. These have already translated Updated Version of Proven them," says Ian Gilchrist of IPL. "It is al- into a significant cost benefit on our pro- DACS IDE ways a challenge to improve productivity ject. RtS' extensibility has also allowed in the area of software testing. We believe us to generate a semi-automated MIL- Date: Sat, 5 Jun 2004 16:12:59 +0200 this new facility will significantly lighten STD-498 design document from our Subject: Embedded News from DDC-I - programmers' workloads." UML model." DDC-I Online News "We are delighted that IPL has been able http://www.ddci.com/news_vol5num3.shtml to rapidly integrate AdaTEST 95 into DDC-I - DDC-I Updates Phoenix, AZ Feb 25, 2004 Maintaining GNAT Pro / GPS," says Arnaud Charlet, Sun/Solaris-Hosted TADS the high performance standards of the es- AdaCore's GPS Product Manager. "This Development System tablished DDC-I Ada Compiler System demonstrates the ease of extending GPS (DACS) DDC-I today announced the re- and tailoring it to add new tools, so users Date: Sat, 5 Jun 2004 16:12:59 +0200 lease of Windows-hosted DACS-PC ver- can adapt our IDE to their own needs." Subject: Embedded News from DDC-I - sion 4.7.16 for both DACS-Native and Further information: AdaCore, DDC-I Online News DACS-MAPP variants. www.act-europe.com http://www.ddci.com/news_vol5num3.shtml "Responding conscientiously to customer Phoenix, AZ March 1, 2004 DDC-I is needs has always been a top priority at ARTiSAN - ARTiSAN's pleased to announce the release of a fully DDC-I, and this comprehensive new re- Real-time Studio Selected by updated Sun/Solaris®-hosted TADS Ada lease made originally for the BAE SYSTEMS Development System (TADS). This re- Boeing/Sikorsky Comanche team can lease incorporates the full complement of now deliver the latest improvements to BAE SYSTEMS selected Real-time improvements and enhancements inte- the IDE made for specific customers to Studio for object oriented UML modeling grated during the now-completed TADS every DACS user," explains DDC-I of complex systems on Hawk program for PC/Windows® rehosting development DACS Product Champion Richard Frost. due to tool's flexibility, enabling customi- effort. After releasing TADS-1750A in Hosted on PCs running Windows NT and zation for full SPARK Ada support. November 2003, TADS-i960 and TADS- targeting Windows NT and embedded 68xxx are scheduled for full release in 80x86 cross-targets, the underlying Ada Cheltenham, UK February 18, 2004 March 2004. ARTiSAN Software Tools, a global tool set is based on the DACS-80x86 leader for UML-based, real-time systems "Offering our TADS customers consistent cross development system in use for over and software modeling tools, today an- performance across the full range of hosts 10 years. Fully tested and QAd, the re- nounced that BAE SYSTEMS, a recog- and targets is the best way to support lease comprises customer-requested nized leader in the field of systems, de- changing needs. Whether they plan to re- changes and fixes included in general fense, and aerospace engineering, has se- host using a PC/Windows platform, per- release 4.7.15b and specific patch releases lected ARTiSAN's Real-time Studio form regular program maintenance, port bundled with upgrades and enhancements Professional as their tool of choice for the legacy code using existing Sun/Solaris to the GUI, AID tool, compiler and target object oriented modeling of complex resources or any combination of the linker. systems in UML on the Hawk program above, all variants are now uniform" ex- Generating native Windows NT console primarily due to a key differentiator of the plains DDC-I Senior Software Engineer applications and embedded applications tool - its extensibility. Michael Hash. for Intel Real Mode 186, Flat Mode (386, "BAE SYSTEMS has been using Real- Specific enhancements include: improved 486, 586) and Protected Mode (2/3/4/586) time Studio successfully at a number of compiler symbol management, enhanced from the same integrated environment, the sites for some years. Software engineers internal consistency to facilitate program environment maintains a constant appear- on the Hawk Project use RtS to express linking; enhanced and generalized serial ance regardless of selected target. Users their implementation of a module support communication connectivity of the can easily prototype applications using layer for an Integrated Modular Avionics AdaScope debugger (for better compati- the native system and rebuild them for the bility with standard serial port expander cross target when they are stable.

Volume 25, Number 2, June 2004 Ada User Journal Ada-related Products 63

Specific improvements in v4.7.16 include; dards for easy third-party product inte- ture IT challenges. Our goal for you in- an XML output option in the Ada gration. creased profits." Information Dumper, offering customers Known in the defense and aerospace According to Oest, while consultancy is an easier format to parse for support tools; community for leading-edge ruggedized primarily used to provide support for the addition of NVM functionality to the burn products, Dy 4 Systems SVME/DMV-181 permanent IT contingent in larger organi- tool, alongside current SUROM capabil- SBC combines a processing core based on zations, they can also serve as an ex- ity; the ability for DACS-MAPP and the powerful AltiVec-equipped PowerPC tremely effective remedy to the problems DACS-FM586 to co-exist in single appli- 7410 processor with an unmatched I/O and concerns common at small-to-midsize cation development situations. complement. Two independent 10/100 organizations with fewer resources than "Our main mission remains providing a Ethernet ports provide redundancy and the larger firms. In addition to relieving fully integrated user environment that survivability in a networked system envi- the HR department of recruiting, screen- flawlessly performs every common soft- ronment, alongside two PMC mezzanine ing, and evaluating IT talent, intelligently ware development task, from simple text I/O expansion sites, SCSI, six serial ports outsourcing specific IT design, manage- editing to compiling, linking, executing, and two USB ports. ment, support and upgrade projects can and managing the program li- For military and aerospace development reduce the strain on a limited IT budget. brary, as well as project and user-level requiring stringent DO-178B certification, With a specific focus on high quality tool customization options and project both DDC-I's SCORE® IDE and Dy 4's customer care, Atlas IT offers one point management support," Frost concludes. SVME/DMV-181 provide full DO-178B of contact and a commitment to keep DDC-I SCORE® Product capability. systems running reliably. Additionally, "Dy 4 has seen great interest from cus- Atlas IT can handle virtually any situation Line Support for Dy 4 tomers in using the SVME/DMV-181 for facing your company and IT infrastruc- Systems SVME/DMV-181 applications requiring high-reliability," ture. Whether the project is analysis and Single Board Computer says Mosley. Dy 4 works with leading OS needs evaluation for new systems, a major and software tools vendors, "and we have systems integration, remote monitoring Date: Sat, 5 Jun 2004 15:59:41 +0200 worked closely with them to ensure applications, net connectivity and secu- Subject: Embedded News from DDC-I - SCORE® will support many of the ad- rity, proxy configuration, on-the-spot DDC-I Online News vanced features of their most popular sin- troubleshooting or project management http://www.ddci.com/news_vol5num5.shtml gle board computer." from inception to deployment, Atlas IT Consulting will provide knowledge and Phoenix, Arizona, 20 April 2004 DDC-I support. announced today the availability of a sup- DDC-I - Phoenix-based port package enabling the versatile DDC-I Unveils Atlas IT Atlas IT Consulting offers big business SCORE® integrated development envi- Consulting experience to small businesses of all ronment (IDE) system to target and debug kinds. "The creativity, engineering sup- port and customer service that helped applications for Dy 4 Systems popular Date: Sat, 5 Jun 2004 15:52:32 +0200 Boeing launch the 777 is what were now PowerPC-based SVME/DMV-181 single Subject: Embedded News from DDC-I - offering to every small-to-medium busi- board computer (SBC). DDC-I Online News ness in the greater Phoenix area," Oest http://www.ddci.com/news_vol5num4.shtml "Packed with features to satisfy systems concludes. "Our two decades of real- integrators real-world requirements, a Experienced software developer now de- world experience in aerospace and safety- high level of integration and diverse I/O livers affordable IT consultancy and ser- critical software applications, where sys- capabilities make Dy 4s 181 a target plat- vices for small-to-medium Phoenix-area tem failure is simply not an option, gives form of choice," explains David Mosley, business clients us the tools we need to help every client Engineering Manager and SCORE® In the 21st Century every company re- excel." Product Champion. "We created the 181 quires IT infrastructure to plug into the board support package for SCORE® to wired world of modern business, but even ExcelSoftware - WinA&D & maximize the development options avail- a small scale, single-site network can be able to customers designing products for WinTranslator more than a full-time job to manage. the latest generation of civilian and mili- Whether your company needs help navi- From: Tools tary embedded systems." gating the latest security concerns, devel- Date: Wed, 03 Mar 2004 15:48:33 -0700 The SCORE® Multi-Language Debugger oping improved network reliability, or Subject: UML for Ada support is provided via the Abatron straight advice about configuration and Newsgroups: comp.lang.ada BDI2000 JTAG interface. Using this storage, only one Phoenix-area IT com- Those interested in UML modeling, code JTAG interface means that no debug pany can deliver a truly high-flying global generation and reengineering Ada code to monitor needs to be present on the board experience to the greater Phoenix busi- models can find information at: to support debugging. The application ness community. http://www.excelsoftware.com/umlforada. code in its final form can be easily de- "Outsourcing your business IT challenges html bugged over Ethernet from the host-based to an experienced company can take sig- debugger to the Abatron JTAG device. [Form the web page: WinA&D is a com- nificant risk out of developing and man- prehensive tool for doing system analysis, The first IDE with multi-language, multi- aging your networks and infrastructure," requirements specification, software de- target and multi-host capabilities based on explains Ole Oest, President of parent sign, code generation and custom reports. non-proprietary open system standards, company DDC-I, a Phoenix-based tech- It supports a broad range of methods and SCORE® meets an increasing need to nology company that for over twenty notations including structured analysis combine reusable software components, years has provided software and devel- and design, UML, data modeling and real- often written in different languages, tar- opment services to a veritable "who's time, multi-task design. Version 3.5 adds geting different microprocessors and cre- who" of large industrial clients such as advanced capabilities for modeling and ated on different platforms. The front-end General Dynamics & Honeywell. "With generating Ada 95 code. WinTranslator incorporates project management tools, Atlas IT Consulting we can maximize generates diagrams and dictionary infor- online help, tool activation, numerous ef- productivity for your company by making mation from existing source code. Gener- ficiency features and a universal interface the same talented team working for DDC- ate data models from SQL, UML class for compilers and tools, using open stan- I available to solve your current and fu- models from C++, Java, Delphi and Ada

Ada User Journal Volume 25, Number 2, June 2004 64 Ada and Linux

95 or structure charts from C, Pascal, Newsgroups: comp.lang.ada Second, if I create my own, do you think Basic and . Version 2.2 generates Sergey wrote: it would be better to: rich UML models in WinA&D from Ada > Guys, I'm experienced C++ program- A. Write a thin binding to the C , us- 95 code. Version 2.3 adds sophisticated ing pragmas. comment handling features. -- su] mer and pretty new to Ada. Despite from that I'd like to use Ada for my cur- B. Write a thick binding to the C Xlib McKae Technologies - rent project (it's not a big deal but ...) (don't know how I would go about this). DTraq and I have same questions for you ... C. Port Xlib.c, Xlib.h, etc. to Ada, using I've to use RHEL-3 ( NPTL is the key- sockets. Then I could make some changes From: Marc A. Criley word here ) - a platform where ( as I that would make it more robust (the same Date: Tue, 02 Mar 2004 23:10:47 GMT heard ) gnat-3.15p doesn't do well ( things that the freedesktop.org people are Subject: Announce: DTraq 0.980 is now tasking is completely broken ). RHEL-3 trying to do with available comes with gcc-3.2.3 and contains gnat http://www.freedesktop.org/Software/xcb, Newsgroups: comp.lang.ada as well, but ( been googling a little ) but using Ada, which goes really well I've found that it isn't recommended for with all of their suggestions). [See also "McKae Technologies - First use in production ... So my question - Public Release of DTraq Data Logging what Ada compiler are you guys using I realize this could be a long project, but I and Playback Debugging Tool" in AUJ on RHEL ( or RHL-9 )? am so dissatisfied with GTK's approach 24.4 (Mar 2004), p.213. -- su] that I think a new approach is needed. Be- You have a few alternatives: McKae Technologies announces the re- sides, more experimental projects are lease of DTraq 0.980, an Ada 95 data log- - if you care about "use for production", needed on the 'nix desktop. Copying is a ging and review tool. you should probably get a support con- terrible way to develop software. tract from Ada Core Technologies. That Thanks for any advice! DTraq is a data logging and playback de- way, you get a validated compiler built bugging tool providing near realtime data for RHEL. ACT's support is a little ex- From: Jacob Sparre Andersen logging and analysis to aid debugging and pensive and geared for large development validation. Captured, or 'tapped' data from teams but the quality of support has been Date: 01 Mar 2004 23:16:38 +0100 a program can be viewed live while the excellent. Subject: Re: X11 binding program is running or, since it is being Newsgroups: comp.lang.ada logged to a file, played back or printed - if you don't have $$, you can still use 3.15p if you specify The file out later for off-line review and analysis. playback tools in that no data layout maps to get the old tasking behavior (which is likely to contain the source code for an or byte interpretations or "data dumpers" works fine). This was described on Ada binding to raw X11. need to be manually created. Nor is the comp.lang.ada some time ago. You might be interested in using some- application responsible for converting the - or you can try gcc-3.2.3. Perhaps some- thing like GtkAda instead. GtkAda is a raw binary data to text form before log- one else can comment on how well it thick Ada binding to both X11 and the ging it. DTraq handles all conversion works (or doesn't). Microsoft GUI API (and probably also automatically by scanning the applica- other GUI API's). tion's source code, identifying tapped data Debian policy for Ada items, and extracting the information it From: Jeff C Date: Tue, 02 Mar 2004 00:09:14 needs to properly convert and display the From: Ludovic Brenta Subject: Re: X11 binding logged items-simple scalar items as well Newsgroups: comp.lang.ada as arrays and records. When the layout of Date: 03 Apr 2004 14:08:18 +0200 data items change, rescanning automati- Subject: RFC: Ada policy for Debian There is one that is not a broken link at cally picks up the changes. Newsgroups: comp.lang.ada http://www.adapower.com/lab/adax.html DTraq requires GNAT 3.15p due to its I have written a short document that for- But I agree with the other poster. I rec- reliance on the Ada Semantic Interface malises my "Ada Policy for Debian"; that ommend you go with gtkada instead: Specification (ASIS) and has been vali- is, how I think packages should be laid gtkada.eu.org dated on Red Hat 9 Linux. out. I have posted it on: From: Ludovic Brenta Source and executables are available on http://users.skynet.be/ludovic.brenta/ada- the DTraq home page: policy.html Date: 17 Mar 2004 11:34:25 +0100 http://www.mckae.com/dtraq.html, along This is a request for comments. Please Subject: Re: Xlib Binding or Re- with the comprehensive and up-to-date reply to me privately with your thoughts implementation? user manual -- on this document and I can amend it as Newsgroups: comp.lang.ada www.mckae.com/dtq_common/DTraq.pdf. necessary. My intention is to eventually There is a binding to Xlib, Xt, and Xm include it in Debian; either as documenta- Enjoy! (/Lesstif) called AdaBindX, at tion with package `gnat', or as a separate http://home.arcor.de/hfvogt/programming. Marc A. Criley, McKae Technologies, package. html. It does not have a binding to Xaw, [email protected] the Athena widget set. I am packaging it X11 Bindings right now for Debian, it should be up- loaded later today. Ada and Linux From: Ben Atkin Maintaining AdaCL in Ada and Linux 2.6 Date: 16 Mar 2004 13:20:25 -0800 Subject: Xlib Binding or Re- Debian From: Mark H Johnson implementation? Newsgroups: comp.lang.ada From: Ludovic Brenta Date: Fri, 09 Apr 2004 11:53:56 -0500 Do any of you know of any good, free Date: 18 Mar 2004 01:19:51 +0100 Organization: Raytheon Company Xlib bindings? I have run into a lot of Subject: Re: Ada compiler dead links.

Volume 25, Number 2, June 2004 Ada User Journal Ada and Linux 65

Subject: Re: Xlib Binding or Re- thing is missing, please offer to contribute I don't think it is desirable to skip some implementation? :) versions of AdaCL in Debian, because Newsgroups: comp.lang.ada (You may also be interested in GNUStep, newer versions seem to provide valuable Ben Atkin wrote: which is one pretty good toolkit with UI bug fixes. > > What is it that you don't like about guidelines and a graphical designer, but KDE Binding Gtk? for that you'd have to go to the Objective- C newsgroup. GNUStep has been quite From: Martin Krischik > It isn't Gtk in particular. It's that GUI active in recent months.) libraries for 'nix, other than , don't encourage good GUI design principles. From: Randy Brukardt Date: Wed, 31 Mar 2004 15:14:41 +0200 In fact, if you compile their examples Subject: Re: KDE Anyone? on GTK's website, you will get a bro- Date: Thu, 18 Mar 2004 14:36:52 -0600 Newsgroups: comp.lang.ada Subject: Re: Xlib Binding or Re- ken GUI. By broken I mean that press- Chris wrote: ing Esc doesn't close a box, and implementation? > Does anyone know of a KDE binding pressing Enter in a single-line text field Newsgroups: comp.lang.ada for Ada. I looked on the net and found doesn't cause the default button to be Preben Randhol wrote: someone had started one. Where's it at? pressed and the appropriate action to be > I would rather have Gwindow or Claw Is it active? The post talked about taken. ported to work on Linux and Mac OS, having a fairly substantial binding to That is true, but at least GNOME has than a new library. I don't want to put QT, but it was July 2003. What's hap- published human interface design guide- you off what pened since then? lines which, if followed, lead to this con- I have no objection to a Mac Claw. It’s Well there is QtAda 95: sistency. Xlib doesn't have such guide- not clear to me if the interface of Claw is http://sourceforge.net/projects/qtada lines, it's not even a toolkit. If you mean too Windows-specific. We had considered But the project seems dead. to use Xaw (the Athena widgets) or Xm a system-independent layer that would be (Motif or Lesstif widgets), you won't nec- built on top of classic (Windows) Claw, > How hard is it to bind to C++? I gather essarily have a good GUI either. but to date we haven't bothered because objects complicate things a lot. Would > Plus, GTK programs are full of other the need seems to be met by GTKAda. using a C++ based binding on Linux types of bugs, many of which could be But if anyone wants to persue it, I'd be force me to move to something like prevented by using something other happy to hear from them. Gcc 3.xx based compilers. This is not really a problem (I like playing with than type-unsafe macros, leading to From: Ludovic Brenta experimental sw!), it's simply that spaghetti code. AFAIK there's no firm schedule on This is comp.lang.ada; we do not use Date: 18 Mar 2004 11:22:41 +0100 when the Ada compiler in Gcc 3.xx will type-unsafe macros here :) Subject: Booch Components and AdaCL in be stable. Like I say not a problem, just Debian The designers of GTK+ never intended something I need to account for. for GTK+ applications to be written in C. Newsgroups: comp.lang.ada I don't know. There are quite a few I personally attended a presentation by I have looked at the AdaCL project on pragmas for c++ support but I have not Owen Taylor, a member of the core SourceForge, and I have to say I am quite found and docu or examples which clearly GTK+ team, at FOSDEM 2003. He spe- impressed with the activity that takes state how to use them. One could try the cifically said "Do Not Program In C", and place there. However, the pace of new make a binding to QString and see how it he explained that his employer Red Hat releases is also a concern to me; I already goes. uses Python for all their GUIs. maintain 17 source packages and it would From: Jeff The main (perhaps only) reason why be difficult for me to package a new ver- Date: 31 Mar 2004 15:55:28 -0800 GTK+ itself is written in C is to make it sion of AdaCL every couple of weeks. I Subject: Re: KDE Anyone? easy to write thick bindings to it from just won't have enough time. In addition, Newsgroups: comp.lang.ada high level languages (see if the binary interface to the library http://www.gtk.org/bindings). GtkAda is changes too often, people will be reluctant If you want to do a binding, then you may one such binding, and a pretty good one at to use the library in their programs. The want to check out the C binding at that. binary interface normally changes at qtcsharp.sourceforge.net. QT# is actually every major release; this is reflected in the based upon. > Part of me wants to jump on the GTK soname of the shared library. bandwagon, and help things progress From: Jeff toward a standard. But what I really I can see two solutions to this problem of Date: 30 Mar 2004 09:33:28 -0800 want to progress toward is having well- too frequent releases: Subject: Re: KDE Anyone? designed GUI's. - let somebody else maintain AdaCL in Newsgroups: comp.lang.ada Over and above the thick binding to Debian; this includes not only packaging One possibility may be to use A# with GTK+, GtkAda provides several rich each new version, but also tracking bugs, QT# and . Info about A# is located widgets (canvas and MDI come to mind) being the front-line of support for Debian at and certainly the authors would gladly users, and interacting with the upstream http://www.usafa.af.mil/dfcs/bios/mcc_ht accept your contributions. authors on SourceForge. I could provide ml/a_sharp.html. However, A# appears to assistance to get going. In fact, generally target only Windows. I have no idea how There is also Glade, the graphical UI de- speaking, I would really like it if someone hard it would be to port A# to *nix and signer, which can generate Ada source else stepped up to package more Ada mono. But, it may be easier than creating code. If you're really interested in good software in Debian. a new binding for QT. UI design, you'll probably be much more productive with it than with Athena or - slow down the pace of new releases to, Lesstif. say, one every 2 months. This implies no bug-fix releases (unless absolutely re- I suggest you really have a good look at quired, of course). This implies an auto- GtkAda; you will probably find that it al- mated test suite to ensure top quality of ready provides much more of what you each release (hint: AUnit is already in want than do Xaw or Xm. And if some- Debian).

Ada User Journal Volume 25, Number 2, June 2004 66 Ada and Linux

From: Oliver Kellogg I haven't used the binding, but from what DDC-I Online News - March 2004, Vol- I understand it is rather complete. ume 5, Number 3 - Date: 12 Apr 2004 12:52:14 -0700 From: Szymon Guz [http://www.ddci.com/news_vol5num3.sh Subject: Re: KDE Anyone? tml] A monthly news update dedicated to Newsgroups: comp.lang.ada Date: Wed, 17 Mar 2004 18:40:28 +0100 DDC-I customers & registered subscrib- BTW, it looks like kalyputs and smoke Subject: Re: MFC & Ada ers. have superceded qtc, see: Newsgroups: comp.lang.ada TADS Upgrade Now Available. Offers http://webcvs.kde.org/cgi- Randy Brukardt wrote: Consistent Performance Across Full bin/cvsweb.cgi/kdebindings/kalyptus/ Range of Hosts & Targets for TADS > I would have to ask why you'd want to. Customers http://webcvs.kde.org/cgi- The reason that libraries like Claw and bin/cvsweb.cgi/kdebindings/smoke/ GWindows exist is so that you can Updated Version of Proven DACS IDE. build Windows applications in Ada, Version 4.7.16 Now Available for Both Auto_Text_IO 3.02 with an Ada mindset. You're much DACS-Native and DACS-MAPP better off using one of those libraries Thoughts from Thorkil. Unsigned From: Stephen Leake than MFC with an Ada program, and Numbers in Ada83 (1st of 2 segments) they cover pretty much the same Date: 05 Apr 2004 21:37:08 A Few More Patterns. For "Introducing" ground. (And Claw at least works with Subject: Auto_Text_IO 3.02 released Change all of the Ada compilers for Windows, Newsgroups: comp.lang.ada so you don't have to be locked into a From: jc Auto_Text_IO 3.02 released specific compiler.) Date: Tue, 4 May 2004 13:53:39 -0700 Organization: DDC-I This is just a bug fix release. Yea, I know all that but I have to use the Subject: Real-Time Industry Updates - News Auto_Text_IO is a tool for automatically mfc.dll in Ada programs for my masters from DDC-I generating a Text_IO package for an Ada thesis. To: 4D May 2004 Online News DK package. The Text_IO package contains Put and Get subprograms for all the types DDC-I Online News -May 2004, Volume in the Ada package, based on References to 5, Number 5. Ada.Text_IO. The Put and Get subpro- Publications [http://www.ddci.com/news_vol5num5.sh grams use named notation aggregates tml] A monthly news update dedicated to (although Get does not support the full SPARK cited in NCSP DDC-I customers & registered subscrib- flexibility of Ada source code). This ers. makes it extremely easy to write readable Software Security Report unit tests for the Ada packages, and to SCORE® now supports Dy4 From: Rod Chapman SVME/DMV-181. Supports many of the provide persistent storage in a readable form. advanced features of their most popular Date: 5 Apr 2004 08:00:55 -0700 single board computer. See: Subject: Praxis and SPARK cited in NCSP http://www.toadmail.com/~ada_wizard/ Software Security Report Thoughts from Thorkil - Date, Time and ada/auto_text_io.html Newsgroups: comp.lang.ada Ada (1). The concept of local time can pose challenges for using dates. for more info. Those of you interested in Ada-related From: Jeff C ammunition and news might be interested The Real Power of Retrospection. Read Date: Fri, 13 Feb 2004 03:40:29 GMT in the recent National Cyber Security how an entire company, not just one team, Subject: Re: ELF Header Symbol Extraction Partnership report "Security Across the can experience this. Newsgroups: comp.lang.ada Software Development Life Cycle" here: James Amor wrote: http://www.cyberpartnership.org/init- Ada 95 Books soft.html > Does anyone know of an Ada library From: Preben Randhol that extracts ELF header information The report cites Praxis Critical Systems' from a binary? Anyone got any sugges- "Correctness by Construction" (of which Date: Thu, 5 Feb 2004 15:09:55 +0000 tions on how to do it if I can't find a li- Ada and SPARK are a big part) software Subject: Re: Good book for Ada 95 wanted brary? process as one of very few that can de- Newsgroups: comp.lang.ada liver the quality and defect rate needed for How about something like: present and future secure systems. > Can anyone recommend a book on Ada http://savannah.nongnu.org/projects/bfdada/ 95? I found a lot books but which one (Not really sure of its status) The Appendix to the report also includes is a good one for starting? I have a lot our full "Correctness by Construction" programming experinence with Java or paper, and metrics for various projects, 4 C/C++. Ada and Microsoft of which (all except CDIS) are (or in- clude) SPARK to some extent. Of the on-line books (see http://www.adaworld.com/ or Microsoft Fundation Classes All the best, http://www.adapower.com/): Rod Chapman, SPARK Team, Praxis From: Steve Ada Distilled Critical Systems Date: Mon, 15 Mar 2004 02:48:07 Ada 95: The Craft of Object-Oriented Subject: Re: MFC & Ada Programming Newsgroups: comp.lang.ada DDC-I Online News Object Oriented Programming in Ada 95 Szymon Guz wrote: From: jc Date: Wed, 3 Mar 2004 15:52:00 -0700 Of the books that you have to buy or bor- > does anyone use MFC.dll in Ada pro- row at your library: grams? Subject: Real-Time Industry Updates - News from DDC-I Ada as a Second Language (2nd Edition), AFC is a thin binding to MFC: To: 2D March 2004 Online News DK Norman Cohen. McGraw Hill, 1996. http://www.jswalker.demon.co.uk/jswtech (ISBN 0-07-011607-5) .htm#AFC

Volume 25, Number 2, June 2004 Ada User Journal Ada in Context 67

Programming in Ada 95 (2nd edition), To: [email protected] Date: Thu, 12 Feb 2004 10:08:34 +0000 Joh I have a client that has 4 openings for Ada Subject: Re: Software Quality & Fault n Barnes. Addison-Wesley, 1998. (ISBN Software Engineers in the Dallas, TX area Measurement 0-201-34293-6) [...] Newsgroups: comp.lang.ada Ada 95 for C and C++ Programmers, Job Description: Although it wasn't primarily a compara- tive study, some useful evidence emerged Simon K. Johnston. Addison Wesley, * The job will include development of 1997 (ISBN 0-201-40363-3) from the Lockheed C130J programme new, and modification of existing, and, in particular, the certification effort I would recommend Ada as a Second system software and support software sponsored by the UK MoD on that air- Language (2nd Edition) or Programming components. craft. Relevant papers from Crosstalk in Ada 95 (2nd edition). * Software engineers will work through Journal include: the entire software development life "Correctness by Construction, Better Can Ada Inside cycle from requirements analysis and Also be Cheaper" through integration, test and delivery. http://www.sparkada.com/downloads/Mar ACT develops ejector seat * An object-oriented based, open archi- 2002Amey.pdf tecture with integrated COTS and system for pilots applications are applied in the development of new system software. "Software Static Code Analysis Lessons From: AdaIC Technical Webmaster Learned" by Andy German, QinetiQ * Opportunities exist in several domains Boscombe Down. DoD CrossTalk Date: Thu, 15 Apr 2004 22:22:26 -0500 from device drivers, network communi- Journal, November 2003. Subject: [AdaIC] Ada in use: Ejector seats cations, infrastructure, application http://www.stsc.hill.af.mil/crosstalk/2003/ To: development, tools, simulations, and 11/index.html GUI. The Navy has deployed a new ejector seat Executive summary: C130J (Hercules II) system for pilots, developed in Ada by Required Skills: code, already cleared to DO178 levels A Ada Core Technologies. Read all about it * Bachelors degree in Electrical or B, in a variety of languages from a va- in "Punching Out!" in Military Aerospace Engineering, Computer Engineering, riety of vendors, was reviewed and ex- Technology at http://www.military- Computer Science, amined by a MoD-appointed contractor. aerospace- Residual error rates for Ada were about technology.com/articles.cfm?DocID=411 * Software development experience in an order of magnitude smaller that for C- several of the following areas is As the author notes, "pilot safety is para- based languages. SPARK had signifi- preferred: Ada, Ada-95, Unix, C++, C, cantly lower error rates than Ada. mount [when] the ejection seat becomes GUI design, UML, and Object Oriented the first stage in a multi-layered approach Methodology. to bringing [pilots] down to earth. The Development over Symbian newest system being deployed will save * Knowledge of Solaris architecture and OS lives and money." near-real-time asynchronous operations is desirable for most positions. From: Alexander E. Kopilovich Indirect Information on Ada Usage Date: Fri, 14 May 2004 00:37:00 Ada in Context Subject: Symbian OS (was: Re: Ada used in Date: Sun, 15 Feb 2004 09:06:10 +0100 General Aviation (GA) applications?) Subject: BE-Brussels-belgium-Ada Software Quality Newsgroups: comp.lang.ada with C Measurement Martin Dowie wrote: X-URL: http://job.monster.be/ From: Jean-Pierre Rosen > A "Dummies Guide to porting GNAT" My client is currently searching for an covering both processor and OS would Analyst Programmer with Ada and C Date: Tue, 10 Feb 2004 10:40:40 +0100 be a huge help. I'd love to have Ada Pramming skills for a critical project for Organization: Adalog available for SymbianOS (or it's prede- full life cycle development. A successful Subject: Re: Software Quality & Fault cessor EPOC32). candidate will have at least 3 years ex- Measurement perience in: Being more or less familiar with Symbian Newsgroups: OS (mostly SonyEricsson's flavour - Profile: Ada + C Programming Expert comp.lang.c++,comp.lang.c,comp.lang.a Symbian 7.0, much less Nokia's Series 60 Duties: Collecting user requirements. da,comp.lang.java.advocacy,comp.lang. flavour - Symbian 6.1) I think that any Analysis of requirements and deriving perl.misc guide of porting GNAT will not bring you software requirements. Updating Michael Kelly wrote: near to that aim. Development docs. Modification of Ada > I'm trying to locate information on Actually, current Symbian C++ develop- and C Code. Writing Test Plans. quality measurement studies that have ment toolset consist of C++ compiler Executing Tests. Writing Test Reports been done on projects using C, C++, (usually Metrowerks CodeWarrior is used Human Skills: Social, Ability to work in Ada, Java, and Perl. I'm particularly for Symbian 7.0 and MSVC 6.0 for Sym- mulicultural environment, Proactive and interested in materials regarding fault bian 6.1, although there are SDKs for entrepreneurial, Team worker, Quality measurements. Any pointers would be other compilers, for example, Borland's and Safety minded greatly appreciated. C++ Builder), resource compiler, linker (with addition for resources) - all that Job Requirements: OO, Ada83, Ada95 A famous paper on C vs. Ada is produces an executable for emulator only and ANSI C, Configuration Mgmt tools, "Comparing Development Costs of C and - and emulator itself. Production version Data Modelling Techniques. Ada": of the program (which will be loaded into From: Nick Riccione http://www.adaic.com/whyada/ada-vs- smartphone) has to be compiled and built c/cada_art.html with another toolset, which is GCC-based. Date: Mon, 22 Mar 2004 15:55:30 -0600 From: Peter Amey GNAT for Symbian, but there will be se-

Ada User Journal Volume 25, Number 2, June 2004 68 Ada in Context vere haedaches with GCC versions, and Another approach would be to give the From: Martin Krischik you'll not be able to use the emulator for type itself the "nice" name and regard the development. package name as "noise" used to avoid Date: Wed, 04 Feb 2004 15:13:03 +0100 Then, even if you adapt GNAT for Win- name clashes in large programs. For ex- Subject: Re: Naming convention for dows for use with the emulator, you still ample: classes? Newsgroups: comp.lang.ada be quite restricted, because the emulator package My_Library is has problems with support of tasking - in type Date is private; Peter C. Chapin wrote: Symbian terminology it supports procedure Advance > > Now, this is not the only possible de- "threads", but not "processes". Well, C++ (Item : in out Date; sign pattern. For example, you can have development on emulator has the same : in Integer); the equivalent of "friends" in C++ by limitation, so I just warn you that you ... declaring two tagged types in the same should not expect too much from Ada end My_Library; package. The previous notation is no tasking on emulator (if you aren't going to Then I might with My_Library and use more applicable to this pattern. develop better emulator). My_Library and do: > Yes, I see that. Coupling two classes by But all that is less than half of work, I Today : Date; defining them in the same package pro- think - because there are mountains of ... vides some interesting options. APIs for Symbian (and many of them dif- Advance(Today, 100); fer significantly between Symbian's fla- You should also remember that in Ada the vours). And it will be quite serious work The second approach seems natural but I concept of "protected" is implemented by to provide Ada bindinds even for most notice that the Charles component library child packages not child classes. needed APIs. (As you can expect, those uses the first approach and it seems to From: Georg Bauhaus mented, and the source code is not avail- my program I do: Date: Wed, 4 Feb 2004 14:57:02 +0000 able after EPOC32 R5). package Vector is new Subject: Re: Naming convention for Actually I thought that RR Software's Charles.Vectors.Unbounded classes? Janus/Ada might be more proper thing (Index_Type => Natural, Newsgroups: comp.lang.ada (than GNAT) for targetting at Symbian, Element_Type => Storage_Type); Unless I have missed it there is another and several times I tempted to tell Randy Then I declare things to be style which uses plural for packages and about this opportunity... but there is a lot Vector.Container_Type and use proce- singular for types. Thus you can have: of work, and perhaps small chances that dures like Vector.Append and package Dates is that work will be compensated by sales. If Vector.Insert, etc. Now I'm building my type Date is ...; there were interest and some funding from own abstract type and I find myself waf- one of smartphone vendors that use or fling... should I use my intended name for and then: plan to use Symbian (Nokia, SonyErics- the package or for a type inside the pack- Dates.operation (today, ...); son, Siemens, Samsung, etc. ... I'm not age? Is there some kind of "best practice" sure about Motorola) - it will be another for this? Or am I off in the weeds here? From: Jeffrey Carter matter, but they still are trying to push Date: Wed, 04 Feb 2004 19:01:28 GMT Java (without much success, though - as From: Jeffrey Carter Subject: Re: Naming convention for far as I can see). Date: Wed, 04 Feb 2004 00:27:18 GMT classes? Subject: Re: Naming convention for Newsgroups: comp.lang.ada classes? Naming Convention for Ada Peter C. Chapin wrote: Classes Newsgroups: comp.lang.ada Some people are very attached to one ap- > Okay, so in other words either approach proach or the other. is considered acceptable by the com- From: Peter C. Chapin munity at large. It's a matter of style. At The two approaches you mention are least that's the impression I get from Subject: Naming convention for classes? called "use unfriendly" and "use friendly", your reply. Does that sound like a fair Date: Tue, 03 Feb 2004 23:52:28 respectively. There are arguments for and assessment? Newsgroups: comp.lang.ada against both approaches. Ada's standard To a large degree, yes, but as other replies I'm a C++ person learning my way around packages are use friendly. For example, package Ada.Strings.Unbounded declares have shown, there are cases where the Ada. Naturally I tend to think about things use-unfriendly approach does not work. in a C++ way and that leads me to various type Unbounded_String. questions. I notice, for example, that there If you create use friendly packages, you From: Jean-Pierre Rosen seems to be two (at least) somewhat dif- should not consider the package name to ferent ways to name classes in Ada. The be noise. "Ada.Strings.Unbounded" is not Date: Wed, 4 Feb 2004 09:57:06 +0100 first way gives the class name to a pack- just noise. Subject: Re: Naming convention for age producing the following effect. classes? One approach is to use appropriate suf- Newsgroups: comp.lang.ada package Date is fixes to create useful names: type Object is private; Since you said you were comming from a package Date_Handling is procedure Advance C++ background, let me explain some type Date_Info is private; (Item : in out Object; things you must understand first. procedure Advance Step : in Integer); Ada has a so-called "building blocks" ap- (Date : in out Date_Info; ... proach. Each feature provides a well-de- Num_Days : in Positive); end Date; fined functionality, and the user builds the The I can create Date objects by first Note that with this approach the reader features he needs by assembling those withing Date and then doing can tell that you're advancing a date by a building blocks. For example, packages number of days without any comments. provide encapsulation. Derived types pro- Today : Date.Object; Note also that negative numbers of days vide support for inheritance. Tagged types ... are not allowed, as that would not be con- provide support for dynamic dispatching. Date.Advance (Today, 100); sidered advancing a date.

Volume 25, Number 2, June 2004 Ada User Journal Ada in Context 69

Ada has no built-in concept of "Class" in From: Ludovic Brenta at the end of it, I will put off compiling the usual sense. If you consider that a until the next day. Otherwise, I hand all class is an encapsulation with dynamic Date: 07 Feb 2004 14:00:35 +0100 the code to the compiler, and I am not binding, then a class in Ada is a design Subject: Re: No call for Ada surprised to be handed back dozens of pattern where you just declare one tagged Newsgroups: comp.lang.ada, comp.lang.c, error messages. Fix the syntax bugs, and type inside a package. *For this design comp.lang.c++, comp.lang.java now I get twices as many semantic errors. pattern*, it makes a lot of sense to declare [In response to various articles for a Kill all those and I am surprised if the test the package with the class name. A full specific poster:] I was thinking along the programs--often written between the discussion of this has been published in same lines last evening, and I came up package interface and the package bodies- Ada Letters (Vol. XV, n°2): "A naming with a small theory that explains why so -don't run correctly. convention for classes in Ada 9X". The few pople can be bothered to learn Ada. For example, I recently finished writing a paper can be downloaded from It goes like this: There are 3 types of library of matrix operations which works http://www.adalog.fr/publica2.htm. Note languages. with "views" that may be a submatrix of that this convention works very well with The first type of language says "we're an existing matrix, and supports opera- "facets" generics, i.e. generics used to add tions like Add(A,B) where the result is properties to tagged types. going to make programming easy". Of course, this is a lie, because programming written in A. That's a bit tricky, but the Now, this is not the only possible design is inherently difficult and no language can real complex one is Mult(A,B) where the pattern. For example, you can have the make it easy. These languages fake it by amount of temporary storage space for equivalent of "friends" in C++ by declar- being simplistic. Java is the most promi- two N by N matricies is N. (A buffer that ing two tagged types in the same package. nent member of this family of languages; stores one row.) The previous notation is no more applica- most scripting languages also fall in this Why am I mentioning this? After all the ble to this pattern. category. Beginners tend to flock to these coding I had a bug in the Mult routine that For more sophisticated use of building "easy" languages and never learn proper the compiler didn't catch. A wrong sub- blocks/design pattern approach, look at programming skills (like e.g. memory script inside a loop. (Why am I doing "Ada, Interfaces and the Listener Para- management. If some Java "guru" reads this? To submit as a new benchmark for digm", a paper presented at Ada-Europe this, ask yourself this one question: how SPECfp. All that stuff is just scaffolding 2002 which is available from the same many threads does your program have, for implementing Strassen's algorithm web page. and please justify the existence of each efficiently.) ). Since I don't take what the compiler tells Ada Popularity The second type says "we will let you do me personally, I love the ratio of a hun- anything, absolutely anything you want, dred to one or so between compile errors From: Carroll-Tech Programmers". Languages in this cate- look at a list of compiler error messages Date: Sat, 7 Feb 2004 01:50:28 -0700 gory include, among others, C and C++. as if each one was a major failing on their Subject: No call for it Many people take a foolish pride in being part. Me? I could proofread the code Newsgroups: comp.lang.ada called a True Programmer, and therefore carefully, but it is easier to let the com- > I've seen some fair sized 'C' and C++ like these languages. I myself once was piler find out where I typed a comma for a projects. They are readable to 'C'/C++ in this category: I would show off my period, and so on. And IMHO it would be programmers. skills by writing a single-line program nice if the compiler found all the typos, I'd have loved to have used Ada, but that nobody else could read. But humans not just most of them. ;-) there never was much call for it. write bugs, and these languages don't lend Could I write the same code in C, C++, or I've been reading posts to this newsgroup a hand finding these. Hence the famous Java? Sure. It is just much easier to let for some time now, as well as reading buffer overflows. the Ada compiler do the heavy lifting part other information and I don't get the The third type is what I would call the of the debugging, so I would still write in "never was much call for it" ideal about "zen master" type of languages. They Ada, then modify the code to match the C, Ada. I'm not saying that anyone is wrong treat you like an apprentice, slapping you C++, or Java syntax. So to me, all that or right for saying or feeling that there on the hand each time you make a small frequent hand-slapping is a major benefit. "never was much call for it"; maybe there mistake, and they scorn at you for choos- From: Ludovic Brenta wasn't. I'm leaning more toward saying ing the quick and easy path -- which leads "it's a conscious choice". to the Dark Side. If you accept their Date: 08 Feb 2004 02:00:01 +0100 I tell the students that I tutor that learning teachings, you quickly become a Master Subject: Re: No call for Ada some Pascal or Ada would help them and yourself. If you rebel against them, you Newsgroups: comp.lang.ada they get scared. I mention doing a project will never achieve and will > > Of course, this is a lie, because pro- in Ada and everyone looks at me like I'm always produce bugs. The "zen master" gramming is inherently difficult and no out to punish myself. To me it isn't any languages are Pascal, Modula, Oberon, language can make it easy. easier to use C/C++, Java, Perl, Lisp or and, master of masters, Ada. The beauty Prolog than it is to use Ada. How is it of these languages is that, once you are > That's exactly what the assembly lan- that Ada has this "super powerful", "super Enlightened, you can apply your wisdom guage programmers said about the first difficult", "there's not much call for it be- to other languages as well -- but often FORTRAN compiler, and it's equally cause it's too advanced and powerful" air would prefer not to. wrong now. Sure, there are cases where about it when it's just another language? From: Robert I. Eachus you need to run DSP code and coordi- It's like saying that the machine code spit nate with the home base thirty million out of an Ada compiler has some mysti- Date: Sat, 07 Feb 2004 10:03:20 -0500 miles away using one space-hardened cal, magical properties that makes the Subject: Re: No call for Ada 386, and that's hard. Then there's the Ada language more difficult to use. Newsgroups: comp.lang.ada, comp.lang.c, cases where you need two lines of to simplify moving files around, and To me, with Ada0Y coming out, the "not comp.lang.c++, comp.lang.java that's something assembly or Fortran or much call for it" attitude is the cliché to I think you are on the right track. When I Ada or Java would make much more dismiss. Or at least one of the things to am programming in Ada, I often spend complex then it is. overcome. most of a day coding. If I am exhausted

Ada User Journal Volume 25, Number 2, June 2004 Ada in Context 71

If you call this programming, then you're 3. not very performance demanding can be evaluated. Surely, one of these right. Scripting languages do have a place (don't know about other compilers, but implementations will turn out to be the and purpose. I was more concerned with they say GNAT produces slow execu- best tool for the job. But, this requires large-scale, real-world programming, tables) effort to evaluate the compilers and li- where Ada shines but is being ignored by However, it does not look like it's a braries. In my experience, very few peo- too many people. I was only trying to ex- good match for me, since my needs are ple actually make that effort. Do you plain to myself why. I stand by my claim the exact opposite: think they evaluate the Java compiler and that no language can make programming 1. no real time library? If they did, they wouldn't use easy. But a language help you find, or 2. bugs welcome (but not wrong re- them. avoid, bugs. sults) - lusers will not come near my > The best tool for the job is the tool that > > (like e.g. memory management. If programs lets me do the job while optimizing some Java "guru" reads this, ask your- 3. performance is highly important cost, schedule and quality. We tend to self this one question: how many I find your list of needs interesting. be convinced that Ada offers superior threads does your program have, and How do you distinguish between bugs and quality when one considers only the please justify the existence of each wrong results? My experience is that bugs language proper. That may even be true thread). are detected because they produce incor- in most cases, but it often ignores cost > In the Jargon file, there's a story of a rect results. If nothing goes wrong we do and schedule in evaluating "The Best man who bummed every cycle out of a not declare the presence of a bug. Tool For The Job". "Quality" can poker program, even the initialization I think you will find, if you look into hard I differ in this respect. I find that I am code, who spurned assembly language real-time systems, that performance is much more productive with Ada than with because it was too inefficient. How critical. While it is true that GNAT has Java, C++, C or Pascal. With Ada, I would you explain your choice of pro- produced relatively slow executables in spend more time developing and less time gramming language to him? the past, those same executables are often debugging. I would ask him, "would you trust your 3 to 5 times faster than early Java pro- > be a relative thing - do I really need own life to your program"? grams. I know that current JVMs have -plated screws when I'm building a > Who cares if there's a couple extra improved performance significantly. I birdhouse? Even if Java as a language threads running? You make a big deal speak of JVMs from around the year doesn't detect as many bugs as does about languages that protect you 2000. Other Ada compilers produce faster Ada, the presence of a well worn li- against buffer overflows, why not use a code than GNAT. Sometimes you get brary means I'm not generating new language that protects you against what you pay for. (GNAT is a free com- and potentially buggy code to do the memory leaks? piler in the GNU compiler chain). same thing. Might that not result in a higher quality end product - while re- Because I want to control exactly how What kind of performance measures do you use in your problem domain? C pro- ducing my costs and improving my much memory my program uses, and I schedule? want to know exactly how many "a cou- grammers are fond of fast code execution ple" means, and why these "couple" and fast compilation. C++ programmers Ada has all the libraries needed to get that threads are necessary. You referred to have similar performance priorities, but kind of leverage. The only problem is embedded software for space-bound de- are willing to sacrifice some compiler that these libraries don't come with the vices, this is one area where these ques- speed for the flexibility of templates. Java compiler, so you have to look for them. tions are really important. I am willing to programmers frequently prize speed of Or use Debian :) accept run-time inefficiency and "a couple coding, with the clever use of the large set > People don't select Java because they extra threads" if justified. There are some of API libraries available to them. Ada are fools. They often select Java over languages that force these upon you and programmers are fond of fast code and Ada for all sorts of legitimate and im- won't justify this cost. early detection of coding defects. portant reasons. If we want to get them > > The "zen master" languages are Pas- From: Ludovic Brenta selecting Ada over Java, we have to cal, Modula, Oberon, and, master of understand those reasons and come to masters, Ada. Date: 03 Apr 2004 21:46:14 +0200 the table being a better satisfier of those Subject: Re: No call for Ada needs. > Pascal is hardly usable, unless you use Newsgroups: comp.lang.ada one of a dozen proprietary extensions. No, they are not fools. Their legitimate That's hardly "zen master". Marin David Condic wrote: reason for choosing Java is that "every- body uses it", so it is easy for them to find That is true, but I meant "master" in the > Standards are a wonderful thing. Every- one should have one of their own. :-) disposable, cheap beginner programmers. sense of "teacher". Pascal was quite good They instruct these programmers to de- at teaching, and as a "master" it had quite That's a nice way of describing Sun's liver buggy code quickly. These begin- a lot of apprentices. policy :) I'm not as diplomatic as you are ners are all too happy to use an "easy" and From: James Rogers :) "fashionable" language, which their > I'd differ in this respect: What makes teachers at school taught them because Date: Tue, 10 Feb 2004 02:45:27 something "The Best Tool For The "the industry demands it" (see the self- Subject: Re: No call for Ada Job"? Ada is superior in some technical fulfilling prophecy there?). Then, when Newsgroups: comp.lang.ada, comp.lang.c, aspects to other languages such as Java customers complain about the bugs, they comp.lang.c++, comp.lang.java when considering the language defini- blame the developers and fire them. Now > Thanks very much to everyone for the tion alone. But if Ada doesn't provide is an "urgent" problem, so they quickly interesting info. It made me look more as much stuff in its toolbox, isn't that in hire new apprentices and use them to closely at Ada. It looks like it is indeed some respect making it a less satisfac- churn out a new, buggy release that one of the safest languages among the tory tool? Or if the implementation un- "fixes" the worst bugs while at the same ones that aren't garbage collected, der consideration isn't very good, does time bringing new ones. which probably makes it suitable for it still qualify as the best tool just be- In short, their legitimate and important programming things like airplanes, etc.: cause in theory it could be better? reasons are "job security for managers" 1. hard real-time One of the nice things with Ada is that and "repeat customers". 2. bug-averse several implementations are available and

Ada User Journal Volume 25, Number 2, June 2004 72 Ada in Context

Development managers want a high This project clearly need managerial and * Charles or AI302 for data structures price/quality ratio, i.e. a high development commercial skills as well as technical, and algorithms price and low quality. Why? Because, by and as I said, money investment (e.g. for In terms of development tools, I keep be- spending lots of money on development, the meetings), and thus a business plan, ing impressed with ASIS and the potential they are important. And by delivering and thus a market research. We have it has. At work I use an ASIS-based tool low quality, they can say "See? My some market indicators from the people that generates code coverage information; budget was too low!", and they can also on this list, but perhaps not enough. […] I am learning how invaluable that tool is. charge big bucks to customers. From: Jeffrey Carter I know of no other language that provides In corporations, customers want a high Date: Sun, 11 Apr 2004 01:01:17 this, especially not in a _standard_ way. price, because spending lots of money Subject: Call for Ada You also say that students and hobbyists makes them important. But they also Newsgroups: comp.lang.ada are not a good market to target. I disagree want high quality. Once they've paid the Wes Groleau wrote: with this. Ada ia already entrenched in a big bucks for the expensive software > Scenario: Two 100,000 SLOC collec- very high-profile market - avionics, train they've selected, they are reluctant to ad- control systems, nuclear industry - which mit that it's buggy or inadequate. There- tions. One in Ada, with (hope, hope) 1 error is small, but sustains several healthy fore, they pay even more for fixes and companies that provide development upgrades, and eveyone is happy. per 100 SLOC One in C, with 10 per 100 SLOC tools. In fact this small market is big Except for software developers and end enough to sustain comptetition between users. The former work under pressure At least 2 studies indicate that Ada re- these vendors. duces errors by a factor of 4. and get all the blame, while the latter have The problem is that the companies that so totally lost confidence in the software > Assume an Ada programmer can find make up this high-profile market are quite that they blame it for everything. and fix a bug in a day, while the C guy secretive, and do not normally advertise From: Marius Amado Alves takes two. that they use Ada; they just do it with the The same studies indicate that Ada re- understanding that Ada is a competitive Date: Thu, 8 Apr 2004 13:46:14 -0700 duces the time/cost to fix an error by a weapon in their arsenal. This backlashes Subject: Re: No call for Ada factor of 10. on them, as they now find it difficult to Newsgroups: comp.lang.ada hire Ada programmers, or people willing > There are a hundred C hackers and 5 to learn. Here's a idea to ease the adoption of Ada, Ada hackers. and thus expand it, and thus augment the The only thing that Ada needs is visibility percentage of reliable software in the There are 100s of 1000s of C hackers. to the masses. So, if you really mean to world, and throw some business our way There are many Ada software engineers, help Ada rather than complain about the along with it. but I'll accept 5 as the the number of Ada situation, I suggest you go out and write hackers :) The main result is a CD+book that con- free software in Ada. You may join one stitutes the big package everyone seems to So, if Ada actually has 1 error per 100 of the existing projects, e.g. the Unified be expecting, containing every re- LOC, then real numbers indicate 1000 Ada Library being discussed in another source/library required to learn Ada and errors in the Ada and 4000 in the C. If it thread; or you may use the libraries I build a vast class of applications, and easy actually takes 1 day to correct an error in mentioned for maximum leverage in an to install and use. the Ada, then real numbers indicate that it application for end users. If you feel that takes 10 days to correct an error in the C. integration is poor between these libraries, *The economical feasability of this pro- So we get 1000 person-days/5 people = then go out and fix that. If you think that ject assumes that such a package does not 200 days for Ada, and 40000 person- they are not portable enough, then port exist already. Is GNAT Pro it? Is ACE? days/100 people = 400 days for C. Ada them. Basically, whenever you say "Ada Another? If yes then stop reading here.* still wins. should", replace it with "I will". The realisation of this project requires I haven't seen any data to support it, but I And all the while, put a sticker on your money investment and/or resources, be- suspect that C introduces more new errors software saying "Engineered to perfection cause I see no other way to do it than set- for every error fixed than Ada, giving Ada with help from Ada", and let the world be ting up a team of Ada library mantainers, an even greater edge, for the same reasons in awe of you. application developers, authors, and per- that C creates more errors in the 1st place. haps trainers, holding at least one initial From: Richard Riehle physical meeting in a laboratory some- From: Ludovic Brenta where. 10 or 20 people. Date: Sat, 17 Apr 2004 00:12:37 Date: 16 Apr 2004 13:00:13 Subject: Re: No call for Ada This requires coordination, leading to the Subject: Re: No call for it Newsgroups: comp.lang.ada selection of participants and identification Newsgroups: comp.lang.ada of leaders. CEO+CTO is a likely struc- Georg Bauhaus wrote: ture. The very initial brainstorming could You keep complaining that Ada lacks lev- > What are the requirements in the minds be done right here on CLA, but to ad- erage, and you keep saying that Ada of CS teachers? vance it should rapidly shift to a dedicated should this and Ada should that. - A university job is not enough grati- structure. A virtual organization. I think Ada does already provide a lot of fying per se, so they need to feel close The first gathering would take a week or leverage. From your posts, it looks like to the software industry? two and result in: you are not aware of the existence of: For the past several years, I have been - the first prototype of the product * AWS for web-based applications and teaching in a university where Ada was web services originally a required subject. When I - a planned structure to produce and dis- first began teaching at this institution, my tribute copies of it * GNADE for database apps (includes an Embedded-SQL preprocessor) classes were well-attended and students - coordination and maintainance struc- were enjoying the opportunity to learn tures strengthened. * GtkAda for portable GUI's, CLAWS Ada. The requirement for Ada was and GWindows for Win32 GUI's eliminated a couple of years ago and at- The launch would of coincide with Ada tendance in the Ada classes plummeted. 2005 :-) * XML/Ada for XML processing * OpenToken for lexical analysis

Volume 25, Number 2, June 2004 Ada User Journal Ada in Context 73

Many of the other faculty members have Maybe things are slightly different in > C++ provides the necessary structures expressed a distaste for Ada, some sug- Europe? A few hints make me think that to built very reliable, efficient and mis- gesting that the sooner it disappears for- use of Ada in universities is at least a sion critical systems. In the above I de- ever, the better. When I recommend that a "moving distribution". fine what exceptions are expected from student use Ada for a thesis project, From: Warren W. Gay VE3WWG each member function, and we can also unless I am the thesis advisor, the student use the Resoorurce Aquisition is Ini- is told that Ada is not appropriate for seri- Date: Fri, 16 Apr 2004 15:45:32 -0400 tializatization technique which the ous thesis work. "Use Java or C++, but Subject: Re: No call for it standard library itself also uses. not Ada." Newsgroups: comp.lang.ada The problem with safety critical pro- My school is not unique. Throughout aca- Ludovic Brenta wrote: gramming in C or C++ is not what is al- demia, Ada is falling victim to a lowed or possible but what should not be widespead misunderstanding of its value > The problem is that the companies that allowed and should be impossible. And and capabilities. One might think that make up this high-profile market are for that I just need two line: well-educated faculty members would quite secretive, and do not normally char X[10]; know better, but that seems not to be the advertise that they use Ada; they just do X[10]='A'; case. it with the understanding that Ada is a competitive weapon in their arsenal. ... From: Michiel Salters As long as industry is not using Ada, it is difficult to persuade academics to pro- Maybe we just need to get someone to fund some prime time TV advertisments Date: 26 Apr 2004 04:06:08 -0700 mote it. As long as academia fails to in- Subject: Re: "Ravenscar-like" profile for clude Ada in the curriculum, it is difficult along the lines of (perhaps in a Russian accent): C/C++ to persuade industry of its viability. We Newsgroups: have something of a stand-off between "PSSST! Do you want to know a secret? comp.lang.c++,comp.lang.ada industy and academia. It does not help It's a pretty good secret.. that some of our graduate students are Did you know that XYZZY Corp. uses What's the problem with that code, from a bragging about how they are "ripping out Ada? safety perspective? Certainly a C com- all that old Ada code" in this or that You can too. piler which is supposed to be suited for system and replacing it with C++. Stay tuned to find out why and how... " safety-critical programs will diagnose this. The base C and C++ languages have Some of the largest military contractors Ravenscar Profile for quite a number of "undefined behavior - have decided to abandon Ada even as no diagnostic required" cases, but a simi- they commend its value over competing C/C++? lar profile may very well tighten that to technologies. "We just cannot hire ex- "undefined behavior - must be rejected at perienced Ada programmers, and the uni- From: Marc Le Roy compile time". versities don't teach it anymore." In their view it is cheaper and easier to find Date: Sun, 25 Apr 2004 15:23:32 +0200 The base philosophy in C and C++ is that C++ programmers. While this is a short- Subject: "Ravenscar-like" profile for C/C++ flexibility can be traded for safety, but not sigthed, perhaps even irresponsible man- Newsgroups: comp.lang.c, vice versa. Certainly, in C++ it is easy to agement decision, for weapon systems comp.lang.c++,comp.lang.ada create a verifiable subset. For instance, it development, the fact that the Pentagon is possible to define a range template and Ada Ravenscar is a restricted subset of the with it a type. The toolset has abandoned all support for Ada gives Ada language that has been defined for those contractors good reason to go a dif- would be hard pressed to prove that the real-time software development in safety range template is correct and overflow- ferent direction. From their view, the critical applications. Completed with ad- DoD is actually opposed to the use of free. However, this could be proven by ditional restrictions like the ones defined humans. The tool chain instead only has Ada. It is a wrong point-of-view, but it is in the SPARK profile, it allow to build widespread. to check that all possible overflows are very deterministic applications that sup- located in this checked range< > code. We need a statement from someone of port automatic static code analysis and Together, this would prove that a body of influence in the U.S. DoD establishment schedulability analysis. code is overflow-free. that affirms the value of Ada. Unfortu- "Guide for the use of the Ada Ravenscar From: Michiel Salters nately, no one will do this. It is not politi- Profile in high integrity systems" cally expedient. Furthermore, there may http://polaris.dit.upm.es/~str/proyectos/or Date: 5 May 2004 02:40:39 -0700 not be anyone left in the Pentagon that k/documents/RP_ug.pdf actually understands the importance of Subject: Re: "Ravenscar-like" profile for this issue. As a consequence, we are I would like to know if there is a similar C/C++ likely to see, over the next decade, a se- standard for C / C++. I found only Newsgroups: comp.lang.c++, ries of software systems, written in C++ MISRA-C and EC++, but they are rather comp.lang.ada that are expensive to create, difficult to permissive with respect to the Ravenscar Vinzent 'Gadget' Hoefler wrote: maintain, and highly profitable for mili- Ada profile. Moreover, because the Ada tary contractors. It is an example, in the standard covers concepts that are out of > Michiel Salters wrote: case of the U.S. DoD, of "grabbing defeat the scope of the C/C++ standards, I sup- > > Certainly, in C++ it is easy to create a from the jaws of victory." Ada could pose that an equivalent of the Ravenscar verifiable subset. have been a powerful force for software profile in C/C++ should make reference to an RTOS. > Not quite true. Or maybe the FIASCO superiority. Instead, they are allowing project just did not find it yet? URL: contractors to choose whatever technol- From: Martin Krischik http://os.inf.tu-dresden.de/vfiasco/ ogy is expedient, and, I fear, at the ex- pense of long-term software quality. Date: Mon, 26 Apr 2004 07:48:38 +0200 Quite true. For instance, if I restrict C++ to the subset which allows only From: Georg Bauhaus Subject: Re: "Ravenscar-like" profile for int main() { } Date: Sat, 17 Apr 2004 10:29:50 +0000 C/C++ I know that that subset is perfectly verifi- Subject: Re: No call for Ada Newsgroups: able. For instance, Newsgroups: comp.lang.ada comp.lang.c++,comp.lang.ada int main() { int i; } Ioannis Vranos wrote:

Ada User Journal Volume 25, Number 2, June 2004 74 Ada in Context is not in the subset. This shows the main How about SPARK-classes for C++? I The developers did NOT do everything problem: Safe and verifiable subsets are mean regular C++ classes, but with attrib- they could. They could have used the more easiliy created by building from the ute SPARK (in GCC you can relatively Ravenscar profile in Ada; they could bottom, not stripping from the top. Yet easily define such additional attributes for use RavenSPARK; they could have powerful subsets are created by removal classes, it will look something like done some model checking of the con- of a few features from the full language. __SPARK__), which tells that the class current parts of the program. They did However, it doesn't have a lot to do with conforms with SPARK-imposed restric- NOT test exhaustively because it is im- the FIASCO project. The goal there was tions. In other words, SPARK in C++ can possible (/exhaustingly/ I am willing to to deal with a lof of known unsafe fea- be applied for individual classes, which believe). And software doesn't HAVE tures. Some were even unsafe by design can be mixed in a program (and even in to be cr*p! (e.g. reinterpret_cast<>). This is not an an individual source file) with other (non- sigh issue when creating safe subsets; reinter- SPARK) classes. It is unbelievable how often I have heard pret_cast<> is the first feature to go. Perhaps many C++ programmers will find the third statement quoted above. When I FIASCO is also hindered by a lack of un- this approach acceptable, they may per- try to argue that constructing a software derstanding of C++: ceive it as reasonable and useful compro- system is just as much an engineering task mise. (And there will be nothing heretic in as constructing a bridge (although much [quote] One of the few things that are that - even in SPARK applications for less mature), I am met with disbelief and required is that all built-in integer types Ada it may happen that some packages "hackish" counter-arguments. are at least 7 bits wide. [/quote] are for SPARK examination, while others These arguments always turn on single Now, as range errors in vaiables are a bypass SPARK for some reasons). point - that programming is an art or common cause of errors, this is a rather From: Martin Krischik maybe even something resembling a painful lack of understanding. magic craft, which can only be learned From: Martin Dowie Date: Mon, 26 Apr 2004 07:40:28 +0200 through years of hacking. And most cer- Organization: AdaCL tainly you can't use any theoretical Date: Wed, 5 May 2004 17:44:39 +0000 Subject: Re: "Ravenscar-like" profile for knowledge when constructing "real" sys- Subject: Re: "Ravenscar-like" profile for C/C++ tems (as opposed to the fancy useless uni- C/C++ Newsgroups: comp.lang.c, comp.lang.c++, versity exercises). Newsgroups: comp.lang.ada comp.lang.ada Funny enough, the discussion is always Vinzent 'Gadget' Hoefler wrote: Finallylein wrote: about programming and not construction. For some reason, the programming task is > Well, I'd say that SPARK as an verifi- > This discussion, as I already pointed out, belongs in groups like regarded as something special and holy - able Ada-subset is quite successful in probably the reason why programming that regard. I doubt that an equally veri- news:comp.programming and news:comp.software-eng. Language language discussions always turn into fiable subset of C++ can ever be im- holy wars. plemented. But perhaps that's just me. subsetting, for whatever purpose, is not defined by the ISO standard for either No, it's not just you - I have asked a sen- C or C++, and is not topical here. Nor About Ada Tutorials ior Praxis person before if they had plans is safety critical programming. for a C++ version and they told they had From: Georg Bauhaus could achieve something worthwhile for fesses that safety critical programming is Date: Sat, 20 Mar 2004 00:30:07 C++ and similar to SPARK but they just in deed off topic in C and C++. Subject: Ada Tutorials couldn't think of anything! Newsgroups: comp.lang.ada The Nature of Software Doesn't prove that such a thing could be Randy Brukardt wrote: done, of course, but they are the people in From: Mark Lorenzen > Another tool that provides the same the best position to attempt such a thing! functionality, but a different interface, That was also ~2001 - things may have Date: Sat, 10 Apr 2004 14:32:20 +0200 is a lot harder to use -- and for a novice, changed! Subject: Re: "Tracking the Blackout bug" might be impossible. Newsgroups: comp.lang.ada From: Peter Amey Peter Amey writes: Ada tutorials. Date: Thu, 06 May 2004 18:22:06 +0100 > > Article at "The Register" about the The same tool with a different interface is Subject: Re: "Ravenscar-like" profile for electricity blackout in the Northeast a lot harder to use not because it is more C/C++ (USA) last year. No directly relevent to difficult to use, but because Newsgroups: comp.lang.ada c.l.a but interesting since it talks of race (a) it requires learning Your memory serves you well! I don't conditions etc. which are issues of Ada. think things have changed that much. My http://www.theregister.co.uk/2004/04/0 (b) it requires that you forget the old personal view is that any such subset, if it 8/blackout_bug_report/ ways. did exist, would be so restrictive and un- > Interesting read. What I do find irritat- If the interfaces are similar enough, they natural to typical C++ users that they ing are quotes such as will introduce another level of complex- would find it unacceptable. Persuading a "The company did everything it ity, because you will have to switch be- potential Ada user of the merits of could..." tween old memories and fresh memories. SPARK is a much easier proposition be- "We test exhaustively..." Short Ada tutorials are (freely) available cause they have already taken several "Unfortunately, that's kind of the nature for different audiences. I guess some if steps down the early error detection route. of software..." not all of them are made for programmers From: Alexander Kopilovitch All these statements are untrue and they with some experience. Is there one that is also reflect a kind of defeatism that I both short and suitable for studying by Date: 14 May 2004 19:27:53 -0700 wholly reject (imagine Boeing saying people with less experience? Subject: Re: "Ravenscar-like" profile for "OK, the wings did fall off, but we When I had an opportunity to introduce C/C++ tested it a lot and anyway that is just the people to computers, or to specific com- Newsgroups: comp.lang.ada nature of aeroplanes").

Volume 25, Number 2, June 2004 Ada User Journal Ada in Context 75 puter programs like text processing pro- I see that Ada ImgSvr 0.4 made the list of 2) Redundant parameter lists grams, it was always refreshing to see vulnerabilities in this week's at Risk Q. I am used to languages that don't en- that: newsletter. (# 04.14b.8) force a strict separation of package speci- (a) people like to learn how things work One problem with the Ada software out fications and bodies. So it seems redun- (e.g. context menues, para styles) there is that it doesn't have enough bugs. dant and potentially error prone to have to (b) people are capable of using operating :-) Thus it never appears on those weekly repeat the parameters for subprograms. system techniques (e.g. folder vulnerability bug lists, so no one even Help! integration) knows that Ada is being used in many A. It is acceptable to use pragma er- projects. (I learn a lot about software that But it is somewhat saddening to see that rors(off) when a subprogram has more I never even thought of from those lists.) I than 10 parameters. (a) and (b) don't become lasting skills don't know of any security bugs found in when there are only the equivalent of any of the RRS products in the last num- package pak2 is "left-mouse-button peers", and when they ber of years -- I half think I need to intro- generic procedure p2 are reluctant to RTFM because it duce some, because we need the expo- (i,j,k,l,m,n: integer; q,,s,x,y,z: float); *appears* bulky. Absurd as it may be, sure... when there is a tutorial part in the FM, the end pak2; package body pak2 is thickness of FMs can hide the good short April's Fool Day pragma Warnings (Off); tutorial part. It is a BIG mistake from both pragma Errors (Off); a pedagogical and economic point of view From: [email protected] (Dan Eilers) procedure p2 is separate; not to draw attention to these tutorials be- Newsgroups: comp.lang.ada pragma Errors (On); cause a good tutorial is what gets you Subject: Hacker's Ada FAQ end pak2; going. It prevents frustration, it might Date: 1 Apr 2004 10:42:52 -0800 lead to adoption. (For example, people get Hacker's Ada FAQ 3) Internal representation of enumerations regularly excited when they learn that there is a mechanism in just about any 1 April 2004 Q. I need to get at the internal representa- tion of object of an enumeration type. text processing program that allows for Disclaimer: boxes of text being placed somewhere on Pascal offers "union" types, but Ada the page without having to play tricks The editor of this FAQ accepts absolutely doesn't seem to allow that. Do I have to using tables, or worse spaces and tabs... no responsibility whatsoever for the "ad- resort to unchecked_conversion or non- The tutorials introduce this on one or two vise" given herein. The solutions have standard attributes? pages, conceptually, without listing all the not been rigorously tested, and do not A. Try wrapping the union type in a re- steps you need not understand in order to even pretend to comport with accepted cord. Occasionally this will work. see and try out what a frame is.) software engineering principles. What happens to work on one compiler is al- function char_to_int Is there a good short hands-on Ada begin- most certain not to work on another com- (ch : character) ners tutorial that does not talk about Ada's piler, or even on a different release of the return integer is history, safety, the new features, and this same compiler. You have been warned. pragma Warnings (Off); and that, but starts in medias res of pro- type union (b: boolean := false) gramming, just makes you want to write 1) Ada as a PDL. is record programs using the nice-simple-powerful case b is Q. I want to use Ada as a PDL (Program- when false => i: integer; facilities of the language that you have ming Design Language) but the compiler when true => c: character; just seen? complains about missing details that I end case; So far I have only found Ada presentation wish to leave TBD for now, such as the end record; slides by R. Dewar (C) 2004 available initializers for constants. Even worse, this type wrapper is record from the NYU as "course ware", but I happens in my lowest level packages, u : union; preventing me from using the compiler to end record; guess they lack spoken words and exer- type wrapper_ptr is cises. at least check the syntax of all my pack- ages. Help! access wrapper; x : wrapper_ptr := new wrapper; The Importance of Bugs A. AI-00078 confirms that RM 10.1.4(6) pragma Errors (Off); allows an implementation to add illegal j : integer renames x.u.i; From: Randy Brukardt compilation units to the Ada environment. pragma Errors (On); But since you might forget which con- begin Date: Mon, 12 Apr 2004 17:56:35 -0500 stants you have left TBD, it is best to x.u := (b => true, c => ch); Subject: Re: AdaImgSvr version 0.5 return j; mark them using pragma errors(off). end char_to_int; released. Since this pragma is non-standard, it is Newsgroups: comp.lang.ada with text_io; use text_io; best to also use pragma warnings(off). with char_to_int; Patrice Freydiere wrote: package pak1 is procedure main is begin pragma Warnings (Off); > We are proud to annonce the version put_line private 0.5 of AdaImgSvr this new release im- (integer'image plements: pragma Errors (Off); (char_to_int ('A'))); - MySQL database support max_speed: constant float := … end; - Win32 service integration upper_bound: constant integer - Linux deamon utilities := … […] - Security fixes switch: constant boolean := … http://adaimgsvr.sourceforge.net pragma Errors (On); Enjoy, and feel free for feedbacks end pak1;

Ada User Journal Volume 25, Number 2, June 2004 Conference Calendar 77 Conference Calendar This is a list of European and large, worldwide events that may be of interest to the Ada community. Further information on items marked ♦ is available in the Forthcoming Events section of the Journal. Items in larger font denote events with specific Ada focus. Items marked with ☺denote events with close relation to Ada. The information in this section is extracted from the on-line Conference announcements for the international Ada community at: http://www.cs.kuleuven.ac.be/~dirk/ada-belgium/events/list.html on the Ada-Belgium Web site. These pages contain full announcements, calls for papers, calls for participation, programmes, URLs, etc. and are updated regularly.

2004

☺ June 30 – July 02 16th Euromicro Conference on Real-Time Systems (ECRTS'04), Catania, Italy. Topics include: embedded real-time systems; real-time control applications; frameworks and tools for development and analysis; software architectures and languages; design, scheduling, timing and execution-time analysis; validation; etc. July 05-09 8th International Conference on Software Reuse (ICSR-8), Madrid, Spain. Theme: "Software Variability Management for Reusable Software". Topics include: Software generators and domain- specific languages; Quality aspects of reuse, e.g. security and reliability; Success and failure stories of reuse approaches from industrial context; etc. ☺ July 07-09 10th International Conference on Parallel and Distributed Systems (ICPADS'2004), Newport Beach, California. Topics include: Parallel and Distributed Systems, Parallel and Distributed Applications and Algorithms, Distributed Operating Systems, Security and Privacy, Dependable Computing and Systems, Real-Time Systems, etc. July 12-13 Foundations of Computer Security (FCS'2004), Turku, Finland. Affiliated with LICS'2004 and ICALP'2004. Topics include: Formal specification, Language-based security, Static analysis, etc.

☺ July 12-15 OMG Annual Workshop on Real-Time and Embedded Distributed Object Computing, Washington, DC, USA. Topics include: Applying CORBA in any real-time or embedded system; High-confidence, high-availability or safety-critical CORBA applications; Security considerations in real-time or embedded CORBA deployments; Real-Time & Embedded Specifications and Standards; Real-Time & Embedded Product Issues; Real-Time and Embedded Advanced R&D Topics, such as advanced scheduling techniques and high-level real-time programming models; etc. July 12-16 10th International Conference on Algebraic Methodology And Software Technology (AMAST'2004), Stirling, Scotland, UK ☺ July 25-28 23rd Annual ACM SIGACT-SIGOPS Symposium on Principles of Distributed Computing (PODC'2004), St. John's, Newfoundland, Canada. Topics include: all areas of distributed systems; any aspect of distributed computing, including systems, design, verification, implementation, application, ...; implementation, analysis, evaluation, and deployment of real systems; intersection of security and distributed computing; etc. August 17-19 11th Nordic Workshop on Programming and Software Development Tools and Techniques (NWPER'2004), Turku, Finland. Topics include: tools, methods and languages for programming and software development, etc. August 19-20 3rd International ACM-IEEE Symposium on Empirical Software Engineering (ISESE'2004), Redondo Beach, CA, USA. Topics include: strengths and weaknesses of software engineering technologies; empirical studies of software processes and products; evaluation and comparison of techniques and models (cost estimation, analysis and design methods, testing); reports on benefits derived from using certain technologies; experience management; etc. August 19-20 9th Australian Workshop on Safety Related Programmable Systems, Brisbane, Australia. Theme: "Transport - Can we trust programmable technology?"

Ada User Journal Volume 25, Number 2, June 2004 78 Conference Calendar

August 22-27 18th IFIP World Computer Congress (WCC'2004), Toulouse, France. Includes a.o. the following events: August 22-27 IFIP 13.5 Working Conference on Human Error, Safety and Systems Development (HESSD'2004). Topics include: Aviation, Training, System design maintenance, Design, Methodologies, Formal methods, etc. August 26-27 2nd International Workshop on Formal Aspects in Security & Trust (FAST'2004). Topics include: Language-based security, Case studies, etc. August 27 Workshop on Architecture Description Languages (WADL'2004). Topics include: Components, Connectors, Composition; Semantics, Formalization; Verification, Simulation, Test; Tools and Development Environments; Standardization; Industrial Projects. ☺ August 25-27 Real-Time and Embedded Computing Systems and Applications Conference (RTCSA'2004), Gothenburg, Sweden. Topics include: quality of service and scheduling; software engineering; fault-tolerance and distributed systems; programming languages and run-time systems; formal methods, and design and analysis tools; case studies; etc. August 26-28 11th International Static Analysis Symposium (SAS'2004), Verona, Italy. Co-located with LOPSTR'04, PEPM'04, and PPDP'04 August 30 – Sep. 04 15th International Conference on Concurrency Theory (CONCUR'2004), London, UK. Includes a.o. the following events: ☺ August 30 Workshop on Object-Oriented Developments (WOOD'2004). Topics include: language semantics, type systems, program analysis and verification, design of new calculi and languages, etc. September 04 4th International Workshop on Automated Verification of Critical Systems (AVoCS'2004)

☺ August 31 – Sep 03 10th International Conference on Parallel and Distributed Computing (Euro-Par'2004), Pisa, Italy. Topics include: Support tools and environments; Compilers for high performance; Distributed systems and algorithms; Parallel programming models, methods and languages; etc. August 31 – Sept 03 30th EUROMICRO Conference (EUROMICRO'2004), Rennes, France

September 06-10 12th IEEE International Requirements Engineering Conference (RE'2004), Kyoto, Japan. Includes a.o. the following event: September 06-07 International Workshop on Principles of Software Evolution (IWPSE'2004). Topics include: theory of software evolution; evolution of requirements and environments; architecture for evolution, evolution of architecture; methodology for evolutionary design and development; validation and verification of evolution; environment for evolutionary design; experience reports and lessons learned from evolutionary software systems; etc. September 08-10 4th International Conference on Quality Software (QSIC'2004), Braunschweig, Germany. Topics include: economics of software quality, review, inspection and walkthrough, reliability, safety and security, quality tools, formal methods, static and dynamic analysis, validation and verification, distributed systems, embedded systems, enterprise applications, etc. September 11-12 1st International Workshop on Views on Designing Complex Architectures (VODCA'2004), Bertinoro, Italy. Topics include: Information Security (language-based security, availability, ...); Information Management (component-based software engineering, software reuse, trust management, distributed systems, ...) September 11-17 20th IEEE International Conference on Software Maintenance (ICSM'2004), Chicago, IL, USA. September 14-16 10th International Software Metrics Symposium (Metrics'2004), Chicago, IL, USA. Co-located with ICSM'2004. Topics include: Use and reuse of open source software in industry, Empirical

Volume 25, Number 2, June 2004 Ada User Journal Conference Calendar 79

studies of open source software development practices, Studies of evolving software systems, Software changeability, Empirical studies evaluating new technologies, etc. ☺ September 15-17 17th International Conference on Parallel and Distributed Computing Systems (PDCS'2004), San Francisco, California, USA. Topics include: Reliable Distributed Computing; Languages, Compilers, and Operating Systems; Libraries and Programming Environments; Software Development, Services, Support, Tools; Middleware for Parallel and Distributed Computing; Embedded Systems; Parallel and Distributed Applications; etc. ☺ September 19-22 5th Austrian-Hungarian Workshop on Distributed and Parallel Systems (DAPSYS'2004), Budapest, Hungary. Topics include: Distributed and Grid middleware; Parallel and distributed programming languages and methodologies; Software engineering and development tools, environments for parallel systems; etc. September 20-21 9th International Workshop on Formal Methods for Industrial Critical Systems (FMICS'2004), Linz, Austria. Co-located with ASE'2004. Topics include: Verification and validation of complex, distributed, real-time systems and embedded systems; Verification and validation methods that aim at circumventing shortcomings of existing methods in respect to their industrial applicability; Case studies and project reports on formal methods related projects with industrial participation (e.g. safety critical systems, mobile systems, object-based distributed systems); etc. September 20-22 5th Argentine Symposium in Software Engineering (ASSE'2004), Córdoba, Argentina. Topics include: Software Quality; Object Oriented Technology and Theory; Design Patterns; Reuse; Software Understanding; Maintenance and Reverse Engineering; Reliability, Safety and Security; Formal methods; Tools and Development Environments; Education in software engineering; Software Engineering Techniques for Challenging Application Areas such as Distributed Systems, Real-Time Systems, etc. September 20-24 8th International IEEE Enterprise Distributed Object Computing Conference (EDOC'2004), Monterey, California, USA. Topics include: Use and enhancement of middleware platforms; Practical experiences with enterprise distributed object computing; etc.

September 20-25 19th IEEE International Conference Automated Software Engineering (ASE'2004), Linz, Austria. Includes a.o. the following event: September 20-21 Software Engineering and Middleware Workshop (SEM'2004). Topics include: Impact of middleware on software architecture design; Software architecture and architectural styles for middleware-based distributed systems; Selection of middleware; Performance, reliability, security, heterogeneity, scalability issues of middleware; etc. ☺ September 21-24 23rd International Conference on Computer Safety, Reliability and Security (Safecomp'2004), Potsdam, Germany. Topics include: Safety Foundations (Fault Tolerance; Distributed and Real-time Systems; Maintenance; Reliability; Formal Methods; Risk Analysis; Open Source Software and Safety; Standards, Guidelines and Certification; Commercial-Off-The- Shelf; Verification, Validation and Testing; ...); Safety Applications (Aerospace and Avionics; Automotive; Medical Systems; Power Plants; Railways; Robotics; Chemical Industry; Process Industry; Programmable Electronic Systems; Accident Reports and Management); Security in Safety-Critical Systems; etc. ☺ September 22-24 GI-Jahrestagung Informatik 2004 - Workshop "Automotive Software Engineering & Concepts", Ulm, Germany September 22-24 8th Conference on Formal Techniques in Real-Time and Fault Tolerant Systems (FTRTFT'2004), Grenoble, France September 26-30 2nd IEEE International Conference on Software Engineering and Formal Methods (SEFM'2004), Beijing, China. Topics include: software specification, validation and verification; software design and refinement; integration of formal and informal methods; fault-tolerant, real- time and hybrid systems; analysis of safety-critical systems; light-weight formal methods; CASE tools and tool integration; application to industrial cases; etc.

Ada User Journal Volume 25, Number 2, June 2004 Conference Calendar 81

September 27-30 24th IFIP WG 6.1 International Conference on Formal Techniques for Networked and Distributed Systems (FORTE'2004), Madrid, Spain September 28-30 28th IEEE Annual International Computer Software and Applications Conference (COMPSAC'2004), Hong Kong, China. Theme: "Developing Trustworthy Software Systems" Topics include: Software safety; Trustworthy software; Software fault tolerance; High performance software; Component-based software development; Design patterns; Software certification; Software standards; Software engineering education; Distributed systems; Embedded systems; Enterprise systems; High dependable systems; etc. ☺ October 04-08 18th International Symposium on DIStributed Computing (DISC'2004), Amsterdam, the Netherlands. Topics include: distributed programming languages; distributed applications; specification, semantics, and verification of distributed systems; fault-tolerance of distributed systems; cryptographic and security protocols for distributed systems; etc. ♦ October 07-08 Ada-Deutschland Tagung 2004, Stuttgart, Germany. Co-located with the Automotive - Safety and Security 2004 Workshop, October 6-7, 2004. Topics include (in German): Methoden und Werkzeuge für zuverlässige Softwaresysteme; Beherrschung der Komplexität in SW-Projekten; UML Profile für zuverlässige Software; Vorgehensmodelle und Lifecycle Management von Systemen; Echtzeitsysteme mit Ada; Sichere Software mit Ada; Ravenscar und weitere Sprachprofile; Erfahrungsberichte über Produktivität, Performance und Kosten in Ada-Projekten; Interoperabilität von Ada und anderen Programmiersprachen; Ada in der Ausbildung; etc. October 11-15 7th International Conference on the Unified Modeling Language (UML'2004), Lisbon, Portugal. Deadline for submissions: July 2, 2004 (tool exhibits), July 19, 2004 (workshop papers), August 30, 2004 (posters and demos) October 18-20 5th Conference for Quality in Information and Communications Technology (QUATIC'2004), Porto, Portugal. Theme: "Quality: a bridge to the future in ICT". Topics include: Economics of quality: costs and savings; Critical success factors in quality improvement; Quality and legal issues; Reliability, safety and security issues; System extensibility: accommodating evolving requirements; Integrating new and legacy systems; Improving the quality of legacy systems; Product reengineering for quality improvement; Forecasting quality characteristics; Quality perception by customers; ICT teaching quality; etc.

October 18-22 ACM/IFIP/USENIX International Middleware Conference (Middleware'2004), Toronto, Ontario, Canada. Topics include: Distributed real-time and embedded middleware platforms; Reliable and fault-tolerant middleware platforms; Applications of middleware technologies, including telematics, command and control, avionics, and e-commerce; Novel paradigms, APIs, and languages for distributed systems; Impact of emerging Internet technologies and standards on middleware platforms; etc. Deadline for submissions: July 10, 2004 (posters) October 18-22 18th Brazilian Symposium on Software Engineering (SBES'2004), Brasília, Federal District, Brazil. Topics include: Component-Based Software Engineering; Design Patterns and Frameworks; Software Engineering Industrial Applications; Software Engineering Tools and Environments; Software Maintenance and Reverse engineering; Software Quality; Software Reengineering; Software Reuse; Software Verification, Validation and Testing; etc. ☺ October 24-28 19th Annual ACM SIGPLAN Conference on Object-Oriented Programming, Systems, Languages, and Applications (OOPSLA'2004), Vancouver, Canada. Topics include: object technology and its offshoots. Deadline for submissions: July 2, 2004 (posters, demonstration proposals, and Doctorial Symposium and Student Volunteers submissions) October 24-28 3rd International Conference on Generative Programming and Component Engineering (GPCE'2004), Vancouver, Canada. Topics include: Generative techniques for Product lines and architectures, Embedded systems, etc.; Component-based software engineering (Reuse, distributed platforms, distributed systems, evolution, analysis and design patterns, development methods, formal methods); Integration of generative and component-based approaches; Industrial applications; etc. Deadline for submissions: July 2, 2004 (demonstrations)

Ada User Journal Volume 25, Number 2, June 2004 82 Conference Calendar

☺ October 25-29 6th International Symposium on Distributed Objects and Applications (DOA'2004), Larnaca, Cyprus. Topics include: Enabling Technologies, Middleware, Distributed Objects and Applications, etc. October 25-29 International Conference on Practical Software Quality Techniques & Testing Techniques (PSQT/PSTT'2004 North), Minneapolis, Minnesota, USA. Conference dates changed from August 23-27, 2004. Deadline for submissions: July 9, 2004 (papers, presentations) October 31 – Nov. 06 ACM SIGSOFT 2004 12th International Symposium on the Foundations of Software Engineering (FSE-12), Newport Beach, California, USA. Topics include: Component-Based Software Engineering; Empirical Studies of Software Tools and Methods; Generic Programming and Software Reuse; Software Engineering and Security; Software Engineering Tools and Environments; Software Metrics; Software Reliability Engineering; Software Safety; Specification and Verification; etc. November 02-05 3rd International Symposium on Formal Methods for Components and Objects (FMCO'2004), Leiden, the Netherlands November 02-05 15th IEEE International Symposium on Software Reliability Engineering (ISSRE'2004), Saint-Malo, Bretagne, France. Theme: "Achieving Software Dependability through Model-Driven Engineering". Deadline for submissions: July 1, 2004 (industry practice), July 10, 2004 (student papers, fast abstracts) November 04-06 2nd Asian Symposium on Programming Languages and Systems (APLAS'2004), Taipei, Taiwan. Topics include: semantics and theoretical foundations; type systems and language design; language interpreters and compilers; program analysis, optimization and transformation; models and tools for parallel and distributed systems; language support for security and safety; domain- specific languages and systems; storage management techniques; software development methods and systems; techniques for embedded and mobile code; process algebra and concurrency; etc.

November 09-12 11th Working Conference on Reverse Engineering (WCRE'2004), Delft, the Netherlands. Topics include: Program analysis and slicing; Program transformation and refactoring; Legacy systems; Transitioning to software product lines; Documentation generation; Pre-processing, parsing and fact extraction; Reengineering patterns; Traceability recovery; Reverse engineering economics; UML and roundtrip engineering; Program comprehension; Reverse engineering tool support; etc. Deadline for submissions: July 7, 2004 (workshops), October 13, 2004 (tool descriptions) November 10-12 European Software Process Improvement Conference (EuroSPI'2004), Trondheim, Norway ♦ November 14-18 2004 ACM SIGAda Annual International Conference (SIGAda'2004), Atlanta, Georgia, USA. Topics include: safety and high integrity issues, real-time and embedded applications, Ada & software engineering education, Ada in other environments such as XML and .NET, Ada and other languages, metrics, standards, analysis, testing, validation, and quality assurance, etc. November 18-19 CoLogNet / Formal Methods Europe Symposium on Teaching Formal Methods 2004, Gent, Belgium. Topics include: experiences of teaching Formal Methods, both successful and unsuccessful; educational resources including the use of books, case studies and the internet; the integration, or otherwise, of FMs into the curriculum; the advantages of FM trained graduates in the workplace; changing attitudes towards FMs in students, academic staff and practitioners; etc. November 22-26 John Robinson & Associates - Public Ada Programming Course, Cheltenham, UK. A practical course with two streams covering Ada 83 and Ada 95. November 30 – Dec. 12 11th Asia-Pacific Software Engineering Conference (APSEC'2004), Busan, Korea. Topics include: Software Design Methods, Software Testing, Verification and Validation, Program Analysis, Software Maintenance, Software Development Methodology, Metrics and Measurement, Software Quality Assurance, Object-Oriented Technology and Design Patterns, Components Based Software Engineering, Product Line Engineering, Distributed and Parallel Software Engineering, Embedded & Real-Time Software Systems, Standards and Legal Issues, Software Engineering Education, etc.

Volume 25, Number 2, June 2004 Ada User Journal Conference Calendar 83

☺ December 05-08 25th IEEE Real-Time Systems Symposium (RTSS'2004), Lisbon, Portugal. Topics include: QoS support; Real-time systems middleware; Security and survivability; Real-time and dependability; Compiler support; Embedded operating systems; Software engineering; RT programming languages; Scheduling; Formal methods; Case-studies; etc. December 10 Birthday of Lady Ada Lovelace, born in 1815. Happy Programmers' Day! ☺ December 13-15 2nd International Symposium on Parallel and Distributed Processing and Applications (ISPA'2004), Hong Kong, China. Topics include: Parallel/distributed system architectures; Parallel/distributed algorithms; Reliability, fault-tolerance, and security; Performance evaluation and measurements; Tools and environments for software development; Distributed systems and applications; High-performance scientific and engineering computing; etc. Deadline for submissions: July 1, 2004 (papers) ☺ December 15-17 8th International Conference on Principles of Distributed Systems (OPODIS'2004), Grenoble, France. Topics: theory, specifications, design and implementation of distributed systems, including: real-time and embedded systems; distributed and multiprocessor algorithms; communication and synchronization protocols; self-stabilization, reliability and fault-tolerance; specification verification of distributed systems; security issues in distributed computing and systems; etc. Deadline for submissions: July 31, 2004 2005

January 03-06 Software Technology Track of the 38th Hawaii International Conference on System Sciences (HICSS-38), Big Island of Hawaii, USA. Includes mini-tracks on: Strategic Software Engineering; Adaptive and Evolvable Software Systems: Techniques, Tools, and Applications; etc. February 07-11 4th International Conference on COTS-Based Software Systems (ICCBSS'2005), Bilbao, Spain. Deadline for submissions: July 16, 2004

April 02-10 European Joint Conferences on Theory and Practice of Software (ETAPS'2005), Edinburgh, Scotland, United Kingdom. Event includes: conferences from 4-8 April, 2005, satellite events on 2-3 and 9-10 April, 2005 ☺ April 05-08 2nd Jahrestagung Fachbereich "Sicherheit - Schutz und Zuverlässigkeit", Regensburg, Germany. Event includes: special session "Informationssicherheit im Automobil", workshop "Privacy Respecting Incident Management", etc. Topics include (in German): Vertrauenswürdige Softwarekomponenten; Zuverlässigkeit und Fehlertoleranz in Hardware- und Softwaresystemen; Formale Techniken, Modellierung, Spezifikation und Verifikation; Betriebssicherheit unter extremen Bedingungen; Standards und Normung; Sicherheitsevaluation und -zertifizierung; Kosten von Sicherheit; etc. Deadline for submissions: October 15, 2004 ☺ May 15-21 27th International Conference on Software Engineering (ICSE'2005), St Louis, Missouri, USA. Topics include: Software architectures and design; Software components and reuse; Software security; Software safety and reliability; Reverse engineering and software maintenance; Software economics; Empirical software engineering and metrics; Distribution and parallelism; Software tools and development environments; Programming languages; Object-oriented techniques; Embedded and real-time software; etc. Deadline for submissions: September 1, 2004 (papers), October 47, 2004 (tutorial and workshop proposals), December 6, 2004 (doctoral symposium, research demonstrations) ♦ June 20-24 10th International Conference on Reliable Software Technologies - Ada- Europe'2005, York, UK. Sponsored by Ada-Europe, in cooperation with ACM SIGAda (approval pending). July 18-22 13th International Symposium of Formal Methods Europe (FM'2005), Newcastle upon Tyne, UK. Topics include: introducing formal methods in industrial practice (technical, organizational, social, psychological aspects); reports on practical use and case studies (reporting positive or negative experiences); tool support and software engineering; environments for formal methods; etc.

Ada User Journal Volume 25, Number 2, June 2004 91 Standardizing the Next Version of Ada James W Moore Convener, ISO/IEC JTC 1/SC 22/WG 9 The MITRE Corporation, 7515 Colshire Drive, H505, McLean, VA 22102, USA; Tel:+1.703.883.7396; email: [email protected] (The author's affiliation with The MITRE Corporation is provided for identification purposes only, and is not intended to convey or imply MITRE's concurrence with, or support for, the positions, opinions or viewpoints expressed by the author.) Abstract The situation in the US is more complicated because the US doesn't have a governmentally designated standards Ada is a mature language but not a perfect language. organization. Even the American National Standards As time passes, we discover portions of the language Institute (ANSI), which serves as the US national body, is specification that need clarification or, occasionally, only an umbrella for several hundred organizations who contain errors. We also discover better ways in which agree to follow ANSI's rules in producing their own the language can support programming in both old standards, which are then endorsed by ANSI. and new application areas. A major revision of the Fundamentally, though, any organization in the US can original Ada language standard was completed in create a "standard" if it follows a few rules regarding 1995. A corrigendum to the standard was published in openness, due process, and consensus to prevent running 2001. Currently, work is underway to produce an afoul of laws regarding antitrust. In the US, we can regard amendment to the standard. That amendment will standards produced by members of ANSI as de jure probably be completed during 2005. This article standards, while those produced by others as de facto provides an overview of the international standards standards. process and how the amendment to the Ada language standard will be accomplished. International standards development Background As I mentioned before, there are two international standards organizations. The International Electrotechnical When discussing standards, it is important to realize that (in Commission (IEC) produces standards for electrical and English, at least) the word "standard" can have multiple electronic equipment. The International Organization for meanings. The word can apply to a range of concepts from Standardization (ISO) produces standards for everything proprietary products that have achieved widespread market else. Each subdivides its scope hierarchically via Technical share, e.g. the "standard", to Committees and Subcommittees. When the first Ada specifications developed through a consensus process specification was completed, the hierarchical committee intended for widespread implementation in the products of structures of ISO and IEC were completely disjoint. many companies, e.g. the Ada language standard. Furthermore, one should realize that even consensus Circa 1986, ISO discovered that IEC was creating standards are produced in a variety of ways by a variety of standards for computers and IEC discovered that ISO was organizations, ranging from professional societies (like the creating standards for computing. To avoid conflict, they Institute of Electrical and Electronics Engineers) to created their first and only Joint Technical Committee corporate consortia (like the Object Management Group) to (JTC1) and gave it the scope of "information technology". organizations established by treaties among nations (like JTC1 created a number of subcommittees, including SC22 the International Telecommunications Union or NATO). which is responsible for programming languages. Standardization of a number of existing languages was A suitable classification for this article is the distinction assigned to various Working Groups of SC22. A new between de facto and de jure standards. De facto standards working group, WG9, was created to process the are simply specification or products that have achieved international standardization of the ANSI Ada standard. widespread acceptance in the marketplace. De jure standards are specifications produced by organizations that Despite the tidy hierarchical subdivision of scope, it is clear are legally chartered to create standards. Most countries that information technology standards must relate to other have a single governmental organization that produces standards committees outside the scope of JTC1. For standards. The international standards organizations—the example, the famous ISO 9000 standards for quality International Organization for Standardization (ISO) and management are produced in an ISO Technical Committee, the International Electrotechnical Commission (IEC)— TC176. Treatment of dependability and safety is performed were created by an agreement among these "national by two IEC committees, TC56 and SC65A, respectively. bodies".

Ada User Journal Volume 25, Number 2, June 2004 92 Standardizing the Next Version of Ada

At all levels of ISO and IEC, the participants are "national According to the Directives, a JTC1 standard must be bodies" rather than individuals. The individuals who attend reconsidered every five years for confirmation, revision, meetings are required to represent national positions that withdrawal or stabilization (retention without are developed by a variety of mechanisms in the different maintenance). Besides revision, though, there are two other nations. ways to update a standard. A Corrigendum (COR) permits the correction of defects in the wording of a standard and is ISO and IEC once had distinct procedures—"directives"— approved by an abbreviated process that delegates final for processing standards work. JTC1 wrote a set of authority to the Subcommittee. The Amendment process directives that were intended to be a compromise between allows more extensive technical changes to be made the two. Although the directives differ in detail, they all without reopening the entire standard for revision. describe a similar process. In short, standards are drafted in Amendments are approved by a process similar to the working groups, receive technical approval by a approval of a standard. Following a Working Draft, the subcommittee, and receive management approval by a stages of approval are called Preliminary Draft Amendment technical committee. For Ada standardization, the jargon is (PDAM), Final Preliminary Draft Amendment (FPDAM), that: and Final Draft Amendment (FDAM), resulting in an • A Working Draft (WD) is developed by WG9. Amendment (AMD). Corrigenda or Amendments may be When consensus is reached, the document is … published as distinct documents or may be combined with the base standard. • Registered as a Committee Draft (CD) at the SC22 level. Committee Drafts undergo successive Ada standardization balloting periods that are 3 months in duration. Technical comments are accepted from national The original Ada standard was published in 1983. It was bodies and the document is modified until created through a consensus process facilitated by contracts consensus is reached. The Final Committee Draft from the US Department of Defense (DoD) and approved (FCD) ballot is an extra month in length allowing as an ANSI standard via the "canvass" process that national bodies to perform more extensive essentially allows anyone who claims an interest to vote inquiries regarding the acceptability of the yes or no. In 1987, after the creation of JTC1, the standard. When the FCD is approved by 75% of specification and its French translation were adopted as the national bodies, the document is forwarded for ISO/IEC 8652 and assigned to a new SC22 working group, … WG9. A revision of the language commenced shortly thereafter, again facilitated by contracts from the US DOD, • Balloting as a Final Draft International Standard resulting in publication of the revised standard in 1995. (FDIS) at the JTC1 level. This ballot is only two months in duration and provides management From the beginning, the Ada language has always had a approval. No technical comments are accepted. An process for dealing with perceived or actual flaws in the approved document is … specification of the language. Even the initial version of the specification provided directions for submitting Ada • Published as an International Standard (IS). comments. These comments were handled by a designated Working Groups can also develop documents that are not group of reviewers. Selected comments resulted in the standards and are called Technical Reports. Their approval drafting of Ada Issues. Some Ada Issues were politely follows a process that is similar but has different names for rejected, some resulted in explanations, some resulted in the stages. clarifications, and some resulted in implicit changes to the specification. The implicit changes to the specification Although the process appears complicated, it is actually were handled via notification to compiler suppliers and possible to progress a standard rapidly—once consensus modifications to the compiler "validation" suite of test has been reached. The "speed of light" for the voting cases intended to check conformance to the standard. process is about one year.1 To progress rapidly, a working group must ensure that technical consensus is reached In the years following the ISO adoption of the Ada within the working group before the document is standard, ISO developed procedures for dealing with progressed to the subcommittee level. Of course, it also perceived "defects" in standards. National bodies were helps if the delegates to the working group are careful to permitted to write "defect reports" which were given to a advise their national bodies of the existence of consensus. designated "editorial team". If the editorial team If this is done carefully, then the voting above the working determined that the standard was, in fact, flawed, then a group level can be considered as merely an administrative Corrigendum to the standard would be written. exercise to confirm the existence of consensus. After the completion of the 1995 standard, and the subsequent end of US DOD subsidies, the ISO working group for Ada became the focal point for continued 1 This rapid speed is not merely theoretical. The Ada committee, ISO/IEC improvement of the language. WG9 wrote a standard JTC1/SC22/WG9, actually processed ISO/IEC 18009, Conformity regarding compiler conformance assessment—ISO/IEC Assessment of Ada Language Processors, in 13 months—after reaching consensus on its contents. 18009. The traditional Ada defect correction process was

Volume 25, Number 2, June 2004 Ada User Journal J W Moore 93 formalized to comply with the rules of the JTC1 defect the exploration of speculative changes to the language. The correction process.2 phrase "usage or adoption" is intended to suggest appeal to both current and new users within identified application The Ada standards committee took advantage of the new areas—"high-reliability, long-lived, real-time, and/or formal correction process to produce a corrigendum to the embedded applications and very large complex systems". Ada standard in 2001. The mechanism was suitable for the The final sentence steers a middle course between addition of clarifying text and the correction of wording sanctioning extensive change and prohibiting it. errors in the standard. However, the mechanism was not suitable for making substantive changes to the language to WG9 agreed that two changes should be made to the address changing user requirements. language: Six years of experience since the 1995 revision, though, • inclusion of the Ravenscar profile, had indicated the need for a technical refresh. Revision of • inclusion of a solution to the problem of mutually the language standard was considered but rejected for dependent types across packages. concern that it might signal dissatisfaction with the language. Instead, WG9 decided to prepare an amendment Beyond those two, WG9 chose to state its desires more to the language standard. WG9 customarily delegates generically. document preparation to subgroups (called "Rapporteur WG9 designated two categories of improvement: Groups" in the jargon). The responsibility to draft the amendment was delegated to the Ada Rapporteur Group (A) Improvements that will maintain or improve Ada's (ARG), the same group that had developed the advantages, especially in those user domains Corrigendum. The ARG is currently chaired by Pascal where safety and criticality are prime concerns; Leroy and the amendment editor is Randy Brukardt. The (B) Improvements that will remedy shortcomings in ARG's members are language experts nominated by the Ada. national bodies and by the two professional societies that are liaisons to WG9—SIGAda and Ada-Europe. In item (B), the phrase "with respect to other languages" was considered, but rejected, suggesting that the ARG From the beginning, it was recognized that the Ada user should not offer a feature-by-feature competition with other community should not be destabilized by a concern that the languages. Of course, item (A) calls particular attention to language definition would be subject to widespread change. Ada's existing advantages for applications involving safety It was decided that the extent of language change should be and other critical properties, and suggests building on the strictly bounded by providing a set of "instructions" to the language's strengths in those areas. ARG regarding the preparation of the amendment. The next part of the instructions elaborates further on these The instructions to the ARG categories: In October 2002, WG9 agreed on the wording of a set of Improvements in the real-time features are an instructions (WG9 N412) [1] to the ARG regarding their example of (A) and should be considered a high preparation of a draft amendment to the Ada language priority. Improvements in the high-integrity standard. Despite spirited discussion, broad agreement was features are an example of (A) and should be achieved and the instructions were approved by all six of considered a high priority. Features that increase the national bodies which cast a ballot. This section static error detection are an example of (A) and discusses those instructions and offers my interpretation of 3 should be considered a priority, but less important the significance of those instructions. than the two listed above. Improvements in the WG9 specified that the facilities for interfacing to other languages are an example of (A) and should be considered. purpose of the Amendment is to address identified Improvements in the object-oriented features— problems in Ada that are interfering with Ada's specifically, adding a Java-like interfaces feature usage or adoption, especially in its major and improved interfacing to other OO applications areas (such as high-reliability, long- languages—are an example of (B) and should be lived real-time and/or embedded applications and considered. very large complex systems). The resulting language changes may range from relatively I interpret this language as providing three levels of minor, to more substantial. priority: In restricting the amendment to "identified problems", • "High Priority" WG9 rejected an overall refresh of the language design or o Real-time features o High-integrity features 2 This was easy because the ISO process was derived in part from the Ada process. • "A Priority, but less Important"

3 Parts of this section are based on [2]. o Increased static error detection

Ada User Journal Volume 25, Number 2, June 2004 94 Standardizing the Next Version of Ada

• "Should be Considered" • Interoperability. Does the proposed feature ease problems of interfacing with other languages and o Interfacing to other languages systems? o Object-oriented features—specifically, • Language consistency: Is the provision of the adding a Java-like interfaces feature and feature syntactically and semantically consistent providing improved methods for with the language's current structure and design interfacing to other OO languages philosophy? The list is notable, not only for the prioritization, but also As before, items missing from the list can be as informative for what is missing. WG9 considered but rejected adding as items present in the list. WG9 considered adding the "design by contract features" to the list. No other categories criterion of "uniqueness and innovation" to the list, but of features were offered during the discussion of the rejected it—another indication that WG9 was interested in instructions. addressing identified problems rather than expanding the The prioritization advises the ARG of the nature of desired language into new areas. improvements, but does not restrict them in the choice of Of course, it is now well known that additions or changes technical solutions for improvement. It is assumed that the to languages cannot be made without some impact on users. specific proposals come from the "Ada Issues", including For example, words that were once legitimate identifiers those submitted from outside WG9 and those written by the might be pre-empted as keywords for new language ARG itself. features. The Ada 95 revision was extremely conservative In looking for good solutions, a period of time was in dealing with backward incompatibility.4 WG9 wanted to provided for outside submissions. The instructions included provide a little more freedom to the ARG in preparing this an appropriate schedule, beginning with the approval of the amendment, but it is difficult to write that without instructions in October 2002 and continuing with: providing license. The following wording was used in the instructions: • December 2002: Presentation at SIGAda, providing for discussion groups and feedback. In order to produce a technically superior result, it is permitted to compromise backwards • June 2003: Similar presentation at Ada-Europe compatibility when the impact on users is judged • September 2003: Receipt of the final AIs from to be acceptable. groups other than WG9 or delegated bodies It should be noted that this wording was approved by a very • September 2003: Presentation at the International narrow margin in WG9, suggesting that proposed Ada Real-time Workshop (IRTAW) incompatibilities may be judged skeptically. • Autumn 2003: Presentation at SIGAda In the 1995 language revisions, some subjects were relegated to "secondary standards" rather than being • December 2003: Receipt of the final AIs from incorporated into the annexes of the Ada language WG9 or delegated bodies standard.5 Since then, a consensus has emerged that placing Nearly a year was provided for outside submissions. Three a subject in a secondary standard, in effect, dooms it to additional months were provided for groups specifically obscurity. WG9 decided that the mistake should not be delegated to write proposals or improve existing proposals, repeated and offered instructions on that subject: for example, the IRTAW. The use of secondary standards should be Of course, it is the task of the ARG to select among the minimized; secondary standards should be proposals for language improvement. In the instructions, proposed only when they would include material WG9 provided some criteria for making that selection: so important as to require standardization but so voluminous as to preclude inclusion in the Ada • Implementability (vendors' concerns). Can the language standard. In particular, material similar proposed feature be implemented at reasonable to the current ISO/IEC 13813, Generic Packages cost? of Real and Complex Vector and Matrix Type • Need (users' concerns). Does the proposed feature Declarations and Basic Operations for Ada, fulfil an actual user need? should be incorporated into the language standard. • Language stability (users' concerns). Would the proposed feature appear disturbing to current users? 4 • Competition and popularity. Does the proposed For the 1995 revision, WG9 attempted to catalogue every possible incompatibility, assess its impact on users, and reduce the impact to feature help improve the perception of Ada, and insignificance. make it more competitive with other languages? 5 The term “secondary standard” is not used by the JTC1 directives. I think it is peculiar to the Ada community.

Volume 25, Number 2, June 2004 Ada User Journal J W Moore 95

The ARG instructions also provided a schedule for the At that point, the process becomes more formal and approval of the amendment: proceeds to voting by SC22 and then JTC1. We hope to process the standard through balloting by the parent bodies • June 2004: WG9 approval of the scope of at the ISO "speed of light" that was described previously. amendment (perhaps by approving AIs, perhaps So it is important that all technical issues are resolved by reviewing draft amendment) within the ARG and confirmed by WG9 prior to • Informal circulation of draft, receipt of comments progressing the amendment to the subcommittee level. In and preparation of final text the past, WG9 has been very successful in anticipating the concerns of SC22 and JTC1 and communicating our • Spring 2005: Completion of proposed text of technical judgment to them via the national bodies amendment to be contributed to WG9 represented in WG9. It is reasonable to hope that the • Mid 2005: WG9 email ballot amendment can be approved without further changes and published early in 2006. • Third Quarter 2005: SC22 FPDAM ballot • Late 2005: JTC1 FDAM ballot Summary As of the writing of this article (May 2004), the preparation An amendment to the Ada language standard is being of the amendment is on schedule. The ARG Chair, Pascal prepared for publication early in 2006. It will address many Leroy, has prepared a document [3] describing the scope of of the issues of usage that have arisen since the language's the amendment and has tabled it for the June 2004 meeting revision in 1995 but which could not be addressed by the of WG9. The document uses AIs to define the scope of the 2001 corrigendum. The emphasis of the amendment is to amendment. This is not intended to suggest that the AIs are address identified problems rather than provide a broad yet approved, but only to indicate that a solution to the update of the language. Perhaps the most notable result of problem described by the AI is within the scope of the the amendment will be repeated emphasis on safety and amendment. The AIs are grouped and aligned with the criticality as Ada's most important areas of application. instructions, providing assurance that the ARG is carrying References out WG9's intent. [1] ISO/IEC JTC 1/SC 22/WG 9, Instructions to the ARG It is important to remember that the "scope" of a standard for Preparation of the Amendment to ISO/IEC 8652, or an amendment is a boundary. The document should not WG9 document N412, 10 October 2002. venture outside the scope but is not required to explore all http://www.open-std.org/jtc1/sc22/wg9/n412.pdf. of the available space within the scope. So the listing of an Republished in Ada User, 25:1, March 2004, page 27. AI in this scope document does not presume that the AI as currently written will be included in the amendment. [2] James W. Moore, Convener's Comments on Furthermore, it doesn't even guarantee that the problem Instructions to the Ada Rapporteur Group from described in the AI will be addressed in the amendment. SC22/WG9 for Preparation of the Amendment to All of that is determined later in the process. ISO/IEC 8652, December 2002 SIGAda conference, WG9 document N423, 20 December 2002. We can anticipate that WG9 will approve this scope http://www.open-std.org/jtc1/sc22/wg9/n423.pdf. document—perhaps with some changes—during its June Republished in Ada User, 25:1, March 2004, pages 28- meeting 2004, or shortly thereafter via an email ballot. 29. During the succeeding months, the ARG will continue to work on the AIs and begin drafting the text of the [3] Pascal Leroy, Proposal for Defining Scope of amendment. The next milestone is spring of 2005 when the Amendment to ISO/IEC 8652:1995, WG9 document ARG is requested to submit the draft text of the N437, March 2004. amendment. It will be circulated to WG9 for comment and http://www.open-std.org/jtc1/sc22/wg9/n437.pdf. consideration by the national bodies. Approval of text Republished in Ada User, 15:1, March 2004, pages 30- would be done by an email ballot during mid-2005. 31.

Ada User Journal Volume 25, Number 2, June 2004 97 Ada Academic Initiative in Paris Louise Arkwright Academic Program Manager, ACT Europe, 8 rue de Milan, 75009 Paris. [email protected]

On 13th February 2004, a group of Ada Academic experts material, which will be made freely available as part of the met at the AdaCore European Headquarters in Paris to GNAT package to be accessed via the AdaCore website, is review the current uses of Ada for educational purposes in currently underway. It is planned to launch the special European universities, and to explore ways in which integrated academic package for the start of the 2004/2005 academics and AdaCore can team up to promote and academic year. extend the use of Ada.

The main objectives of this initiative are to: - Encourage and extend the use of Ada in Academia by providing a quality assured software packages, among other material, to facilitate Ada programming for students. - Create a collaborative platform for the Ada academic community enabling it to access support across several fields (technology, advocacy, teaching materials, etc) as well as facilitating contribution of ideas. - Generate stronger links between academia and the professional Ada community.

There is a clear need for grouped resources for academic support materials via the provision of website hosting for The team at work material and Ada libraries. Such a shared site will focus the energies of the Academic community and lead to the Much of this material has already been prepared and development of software for pedagogical and industrial AdaCore will be holding a follow-up session at Ada Europe uses. 2004 on 16th June for review. All interested academics are welcome to join this meeting which will continue in the path of a worthwhile collaboration set to grow to include more teachers in the future.

The Ada Academic Working Group

To this end, and as a result of the workshop, several proposals are currently being acted upon. Notably, AdaCore is preparing an academic offer to include an integrated binary distribution for Windows, Solaris and Gnu/Linux, as well as source releases for various packages. Also being compiled by the members of the Working Group are materials such as source packages for additional tools, teaching materials (slides, articles, books), laboratory case studies and technical papers. A call for educational

Ada User Journal Volume 25, Number 2, June 2003 98 Practical Experiences of Safety- and Security-Critical Technologies Peter Amey and Adrian J Hilton Praxis Critical Systems Ltd., 20 Manvers Street, Bath BA1 1PX; Tel: +44 1225 823761; email: {peter.amey/adrian.hilton}@praxis-cs.co.uk Abstract 2 Methods of Verification In this article we identify the special properties of We define the following terms: systems intended for use in ultra-reliable domains and • verification as “the process of determining that a the qualitative shift in development methods needed to system (or its component) meets its specification”; achieve those properties. The advantages (and disadvantages) of Ada are introduced in the contexts • validation as “the process of determining that a of the ISO HRG report on High-Integrity Ada and of system is appropriate for its purpose”; and the SPARK sub-language. The demands of common, • certification as “persuading an external regulatory important development standards are described body that a set of specific requirements have been together with appropriate and cost-effective met and/or processes followed”. techniques for meeting them. Finally project experience illustrating successes in meeting the main Techniques of verification include: standards is discussed. • inspections / reviews, e.g. requirements or code; Keywords: high integrity, safety, security, case study, • testing, e.g. requirements tests or unit tests; and SPARK, Ada. • analysis e.g. flow analysis, model-checking or 1 Introduction partial program proof. Safety- and security-critical systems have a fundamental Inspections are uniquely flexible, since the primary tool is common property, that they are not just correct and reliable the engineer, and can be done early on. However they are but that they can be shown to be correct and reliable. Most inherently informal and fallible, and what inspection is modern critical systems contains software, and often feasible is limited by the semantic precision of the object (though not always) the system relies on the operation of being inspected and the semantic gap between the objects the software to achieve safety or security. In this case the being compared. software is designated safety-critical or security critical, and is often termed generically high-integrity software. (Dynamic) testing spans the entire development testing and can potentially identify errors in requirements, High-integrity software is code where reliability is more specifications, code, the compiler and the hardware. important than efficiency, cost, time-to-market or However, exhaustive testing is rarely feasible or even functionality. Examples are security systems, financial possible, and for high-integrity systems the high levels of systems where down-time incurs a large cost, and cases assurance required the testing time becomes impractical. where a costly one-off mission capability may be lost such Littlewood [4] and Butler [5] note the limitations of as a Mars Lander. Bayesian testing and the implications for reliability of any The unique characteristic of high-integrity software is the failures during a very long testing process. need to be able to show, before there is any service There are also the practical problems arising from the need experience, that a system will meet its requirements. It is a for a complete or mostly complete system before testing problem qualitatively different from normal software, since can begin. The testing phase of a system development is the standards involved may be very high (e.g. requiring the frequently a bottleneck for the entire development, and equivalent of no more than 1 failure every 114,000 years of over-running testing is an expensive risk for most projects. operation). It is not enough to be just “more careful” in development! Analysis, by contrast, can be conducted early on in the development process and can establish properties that In this article we consider how such assurance may be cannot be shown statistically, such as the proof of absence obtained for the software component of a system, in of run-time errors or freedom from timing deadlocks. particular for software components written in Ada. We However it can only compare objects (e.g. the code against draw on our experiences with illustrative case studies in the specification), and what can be achieved is limited by developing and verifying safety-critical and security- the precision of the descriptions and notations used. critical systems.

Volume 25, Number 2, June 2004 Ada User Journal P N Amey and A J Hilton 99

Showing “correctness” is therefore harder than building First, the compiler’s behaviour must be known; it must also correct systems; the key is to use a range of verification be consistent. If it changes with new releases, or between techniques. Since bug detection and correction is the host and the target, then the dialect may be invalid. expensive, the focus should be on: Developers must also know when it matters; we must recognise that implementation-dependent behaviour is • preventing bugs from occurring; present and know what the compiler’s behaviour is in this • using techniques to find bugs early on; and case. • using final testing as a demonstration of correct You cannot expect to avoid all anomalous behaviour by behaviour rather than as a method of finding bugs. this method, but it may be valuable in special cases e.g. small, specialised processors where only one company 3 Reliable programming provides support, or for an established compiler where a The language in which we choose to program will affect small number of problems are known but service the way we think about the program. A developer is less experience provides confidence in the rest of its behaviour. likely to think about abstractions if programming in 3.3 Subsets machine code or assembler; she will think more in terms of the target machine if programming in C. For larger The need for subsetting was described by Wichmann [6]: systems, language support for abstraction and “No currently standardised language could be encapsulation is vital if the program is to remain recommended without reservation for the most critical manageable and verifiable. applications without subsetting”. To be useful, however, language subsets need to be: 3.1 Formality and uncertainty • simple; Machine code is formal, in that the target machine provides an operational semantics for it. However we cannot • application oriented; normally reason about the code, we can only observe its • predictable; behaviour. Early reasoning about program correctness saves money and reduces risk, but is hampered by the lack • formally verifiable; and of formality of most programming languages. • be supported by sound tools. Typical causes of uncertainty in programming languages A subset comprises a base language, a set of troublesome include deficiencies in the language definition (e.g., the language features which are removed, a set of limitations semantics of integer division in C) and deliberate on the way that remaining features may be used, and implementation freedoms (e.g. order of evaluation of optionally the introduction of annotations to provide extra expression components and parameter passing information. We can construct subsets that vary on four mechanisms). This leads to either: axes: precision (security and lack of ambiguity), expressive • ambiguity, where program behaviour cannot be power, depth of analysis possible and the efficiency of the predicted from the source code; or analysis process. There are complex trade-offs in this model. • insecurity, where violations of a language rule cannot be detected. The fundamental trade-off is between the discipline which programmers accept in order to reduce bug insertion, and Ambiguities are resolved by compiler authors. Insecurities the effort which they are prepared to make in bug detection. are left for the user to discover. Neither of these situations For example, unrestricted C provides little or no protection are attractive, but there are possible solutions: from bug insertion, whereas Ada requires extra discipline • invent new languages without these problems; (e.g. strong typing) which reduces the bug insertion rate. • work with dialects associated with compilers; or A qualitative shift in what is possible will only occur when the precision of the subset becomes exact. • use logically coherent language subsets to overcome ambiguities and insecurities. 3.4 MISRA C When inventing new languages the very small user base MISRA-C is a C subset defined by the UK motor industry leads to poor or non-existent tools, staff shortage and a lack research association (MIRA) and its associated software of training support; this approach is impractical for most reliability association (MISRA). It comprises 127 “rules” projects. presented in the form of a coding standard, and its designers regard it as suitable for “SIL 3” systems; they 3.2 Dialects recommend Ada or Modula-2 if available. When using a dialect, the first step is to find out what your The base language of MISRA C is ISO/IEC 9899:1990 + compiler does. Its behaviour can then be documented and the 1995 technical corrigendum. It removes troublesome C included in coding standards and review checklists. This features such as pointer arithmetic, and imposes limitations can be an effective solution, but there are problems. such as all switch statements having to have a final default. It does not use extra annotations.

Ada User Journal Volume 25, Number 2, June 2003 100 Practical Experiences of Safety- and Security-Critical Technologies

There was no attempt to make the MISRA C subset language features, such as Systeam “Safe Ada”, and subsets logically coherent and free from ambiguity and insecurity, generated by compiler back-end and run-time library and its machine checkability is well short of 100%. Some considerations. The latter are exemplified by GNAT Pro rules cannot be machine-checked at all, e.g. Rule 4: High Integrity Edition, C-Smart and Raven. “Provision should be made for appropriate run-time checking” and the exact meanings of some other rules are 4 An overview of standards unclear and much debated. Nevertheless, following the There are many standards relating to software development subset rules should prevent many common C errors. for safety-related or security-related systems. Each domain 3.5 The Ada HRG (e.g. rail, aerospace, automotive) has its own standards. They vary in their power to mandate or recommend The Ada HRG is an ISO committee under WG9 to particular practices. In this section we discuss some investigate high-integrity Ada issues, responsible for representative standards and their implications for software interpreting and developing Annex H of the LRM and development practice. focused on developing Ada in the high-integrity field. Its members include tool vendors, users, Government (e.g. the 4.1 Software development techniques UK Ministry of Defence) and academics. Common aspects of standards’ recommended or mandated HRG report ISO/IEC JTC1/SC22/WG9 “Programming techniques for software development include: Languages – Guide for the Use of the Ada Programming • hazard or risk analysis; Language in High Integrity Systems” [7] does not define a subset but identifies the basis on which a subset might be • defining safety integrity levels; selected. The general approach is to identify verification • defining the system lifecycle; techniques, then compare each technique with Ada language features and assess the level of compatibility. • formal methods for requirements and design;

Particular points of interest are exceptions and tasking. • modelling various system properties; Exceptions are essential for high-integrity applications but • choice of language, RTOS etc.; must be avoided because of the difficulties they cause for flow and symbolic analysis. HRG had to reconcile these • validation, verification and testing (VVT); and views; propagation of exceptions is clearly a key issue. • accumulation of evidence in a safety case. For tasking they chose to define the “Ravenscar Profile”, of which more later. We now examine selected techniques in more detail. 3.6 SPARK and other Ada subsets 4.2 Hazard analysis SPARK [8] is a sub-language of Ada with particular Hazard analysis is the process of identifying hazards and properties that suit it to the most critical applications: their causes. A hazard is defined by Leveson [9] as “a certain state of a system that, combined with other • completely unambiguous; conditions in the environment, will lead inevitably to an accident or loss”. An example of a hazard for a car is “the • free from implementation dependencies; wheels fall off while the car is travelling at speed”. Each • all rule violations are detectable; hazard in a system has an estimated probability of occurrence and an associated severity. • formally defined and tool supported. The base languages are ANSI/MIL-STD-1815A-1983 Associated terms are risk and safety. Risk is a combination (SPARK 83) and ISO-8652;1995 (SPARK 95). SPARK of probability and severity: the above hazard is severe, but removes the troublesome language features (e.g. tasking, (hopefully) very unlikely in most modern cars, so does not access types), limits the way remaining features may be carry great risk. There are three main “risk regions”: broadly acceptable, As Low As Reasonably Practical used (e.g. limitations on the placement of exit and return) and introduces annotations to provide extra information. (known as ALARP, of which more later) and intolerable. Safety is freedom from unacceptable risk. SPARK annotations describe program design information. They are related to executable code by static-semantic Various formalised hazard analysis techniques exist, such rules, which are checked mechanically by the SPARK as Hazard and Operability (HAZOP), Failure Modes and Examiner tool. This tool also checks language subset Effects Analysis (FMEA) and Fault Tree Analysis. Their compliance, does system-wide data flow and information common theme is the creation and maintenance of a hazard flow analysis, formal verification including proof of safety log, detailing the identified hazards and stating what steps and security properties, and can demonstrate prior to have been taken to mitigate them. execution that a program is “exception free”. SPARK is 4.3 Risk and ALARP compatible with both HRG guidance and compiler-defined Risk itself is regulated (in the UK) on the basis of being high-integrity subsets. reduced As Low As Reasonably Practical (ALARP). This Other Ada subsets tend to fall into two groups: informal stems from a UK Court of Appeal decision on the 1949 coding standards involving fairly arbitrary exclusion of

Volume 25, Number 2, June 2004 Ada User Journal P N Amey and A J Hilton 101 case Edwards vs. The National Coal Board where Judge to A (catastrophic) in a similar approach to SILs. Only Asquith noted: levels A and B are regarded as safety-critical. “...a computation must be made by the owner in which the 5.1 Qualification and verification quantum of risk is placed on one scale and the sacrifice For the output of each development step, the standard involved in the measures necessary for averting the risk requires that either the tool that produced that output (e.g. (whether in money, time or trouble) is placed in the other, the compiler) be qualified, or the output itself (e.g. object and that, if it be shown that there is a gross disproportion code) be verified. Since most tools in the object generation between them - the risk being insignificant in relation to the path are not qualified, the object code itself must be sacrifice - the defendants discharge the onus on them.” [10] verified. This is achieved by specified test coverage 4.4 Safety integrity levels criteria according to the criticality level. The coverage can be of the source code rather than the object code if source- It is common when developing against a safety standard for to-object traceability can be achieved. the system to be assigned a safety integrity level (SIL), typically in the range 1 (low) to 4 (high). The techniques 5.2 Coverage (and costs) for system validation will be defined by the In modified decision/condition branch coverage (MC/DC) standard for each SIL. testing, each value independently affecting a decision must A SIL is a general indicator of the quality required for be executed. In all cases the guidelines require coverage design / build processes. It is applicable to both software analysis to show that the coverage required has been and hardware, and indicates the probability that the system attained. At Level A, the coverage must take place on the meets its requirements and avoids systematic failure. object code if the object code is not directly traceable from However, it is often misunderstood and misused. the source code – if Ada run-time checks are turned on in the compiler, for instance, then it is unlikely that such It is important to note that if software is developed to e.g. traceability exists. SIL 4 for a particular system then it is not automatically SIL 4 for a different system. The hazards against which the Note that it is often possible to “cheat” on coverage. One software was originally may not include all the hazards of way of reducing the number of tests required in Ada is to the new system, so although the software might be high translate an if-else if – else block into a single lookup into a quality it has not been shown to be safe or secure in the constant array, reducing many tests (one for each branch, new environment. for instance) to a single test – there is no concept of “covering” the data in such an array. For this reason, and 4.5 The safety case others, coverage should not be regarded as a gold standard. A safety case is a collection of evidence for safety of a 5.3 DO-178B Critique system in the form of an argument for overall safety. It will relate various verification and analysis activities to DO-178B is a software correctness standard, not a system avoidance or mitigation of the system hazards. Typically a safety standard; there is no relation of the software to the safety case may contain or reference: system hazards, the developer can only state “the whole box has been tested to level A”. • the configuration management plan There is undue emphasis on testing activities in the • the software verification plan document. This may reflect its age (released in 1992) but • the software quality assurance plan means that there is little or no credit for analysis and review which are both worthwhile activities. It can create an • standards for design and coding environment where getting to the testing phase quickly is • specifications for requirements, design and tests seen as the prime aim, and where MC/DC is widely misinterpreted as “exhaustive” testing when we have seen • the results of software verification how it can be circumvented to some extent. • a software configuration index; and The role of the Designated Engineering Representative • a traceability matrix. (DER) is a specialist designated by the FAA is to establish compliance with the DO-178B process, not system safety. 5 DO-178B In this respect DO-178B is very different from more RTCA DO-178B “Software Considerations in Airborne modern safety-related standards. Systems and Equipment Certification” [11] is a set of 5.4 Economic arguments guidelines produced by the civil avionics industry for good The cost of testing to DO-178B rises as the criticality level practice in producing avionics software. It is neither a rises. Most testing work needs a test rig, the development process document nor a standard, but in practice it has been of which is a back-end high-risk process. MC/DC requires endorsed by the FAA and JAA and is regarded as the many more tests than statement coverage; one estimate is “Bible” for civil avionics software. that it multiplies the cost of testing by 5. DO-178B defines five levels of criticality for software As noted, the required testing for level A is likely to be based on consequence of failure, from E (no effect) through harder in Ada than in C. Is the best solution therefore to

Ada User Journal Volume 25, Number 2, June 2003 102 Practical Experiences of Safety- and Security-Critical Technologies

“hack in C”? No – this is because it is much cheaper to • SPARK code had only 10% of the residual errors adopt a process that reduces errors before going into formal of full Ada, and Ada only 10% of the residual test. This was the approach taken when developing errors of C; and software for the C-130J Hercules II aircraft. • there was no statistically significant difference in 5.5 C-130J development residual error rate between DO-178B Level A, The C-130J was a project by Lockheed Martin which Level B and Level C code. aimed to produce a much-improved version of the The results of the C-130J development are detailed by venerable C-130 Hercules transport aircraft. It included a Sutton and Croxford [12] and Amey [13] and compared by new propulsion system with 29% more thrust and 15% German [14] to the results of other development methods. better fuel efficiency, advanced avionics and control systems, two mission computers and two backup bus 6 UK Defence Standards interface units to give dual redundancy to the aircraft The UK Ministry of Defence uses Defence Standard 00-56 systems. Issue 2 [15] as its primary safety standard. This references The development process emphasised “Correctness by Defence Standard 00-55 for specific requirements and Construction” (CbC), focused on “doing it right first time”. guidance on developing safety-related software. 00-56 is a The requirements of DO-178B were kept in mind but not system-wide standard and defines the safety analysis allowed to dominate the development. Development was process to be used to determine safety requirements, driven by verification, aiming to verify objects as soon as including SILs. It promotes an active, managed approach they were created. to safety and risk management. Formality was introduced early, in the specification phase 6.1 Defence Standard 00-55 (using the CoRE requirements engineering process and 00-55 Issue 2 is applied to software components of various Parnas table to specify in/out mappings) and in the SILs. It defines the process and techniques to be followed programming language (Ada 83 and SPARK). There was a to achieve a level of rigour appropriate to the SIL. It close map from the requirements to the code: “one requires the production of a software safety case to: procedure per table”. Static analysis (with the SPARK

Examiner) was part of the development process • justify the suitability of the development process, tools and methods; and 5.6 C-130J results • present a justification based on objective evidence There was an unexpected benefit of using SPARK; the that the software satisfies the safety aspects of the language requires all data interactions to be described in software requirement. annotations, but some interactions were not clearly specified in the CoRE tables (e.g. validity flags). The Compared to DO-178B, 00-55 puts a heavy emphasis on coders could not ignore the problem, and so the the use of formal methods and proof. It still requires requirements/specification document became a dynamic stringent testing. It uses integrity levels S1 to S4 rather document as ambiguities were resolved during coding. than criticality levels E to A, but the main difference is that 00-55 focuses on software safety whereas DO-178B Early static analysis picked up a number of errors which focuses on software correctness. would have been unlikely to surface during testing. The testing required by DO-178B was greatly simplified as a 6.2 SHOLIS – a 00-55 project result. Very few errors were found during testing, which The Ship Helicopter Operating Limits Instrumentation was done for less than 20% of the normal industry cost, and System (SHOLIS) is a system for assessing and advising on the overall cost of the level A system was half that of the safety of helicopter flying operations on board Royal typical non-critical system development cost. Navy and Royal Fleet Auxiliary vessels. Power Magnetics 5.7 C-130J UK verification and Electronic Systems Ltd. was the prime contractor. Praxis Critical Systems developed all the operational The UK Ministry of Defence commissioned Aerosystems software to Interim Defence Standard 00-55 (1991). International to perform retrospective static analysis of all the C-130J critical software, using a variety of tools e.g. the SHOLIS is a dual redundant system, implementing fault SPARK Examiner and SPADE toolset for proving SPARK tolerance by hot-standby. The two data processing units code against CoRE, and MALPAS for Ada. All anomalies (DPUs) are located at opposite ends of the ship to increase were investigated and “sentenced” by system safety tolerance of battle damage, and are not synchronised in any experts. The results were instructive: way. It was the first system with software developed to Interim 00-55 at S4. • significant safety-critical errors were found by static analysis in code developed to DO-178B The final requirements numbered 4000 statements, with Level A; 300 pages of Z, English and mathematics. The code was 27,000 lines of non-blank non-comment Ada plus 54,000 • proof of SPARK code was shown to be cheaper lines of SPARK flow annotations and 20,000 lines of than other forms of static analysis performed; SPARK proof annotations.

Volume 25, Number 2, June 2004 Ada User Journal P N Amey and A J Hilton 103

6.3 SHOLIS verification ALARP. The developer must define the safety standards The major verification activities were: that they will meet, and then demonstrate compliance. • review and Z proof of the System Requirements The Code of Practice in 00-56 refers to the software as a and System Design; Safety Related Programmable System (SRPS). It requires validated safety arguments or claims for the SRPS, • SPARK static analysis and proof of the code; supported by: • worst-case timing, stack-use and I/O estimates; • direct evidence from deductive analysis, • module, integration and system validation tests demonstration and review; based on Z specifications and requirements; • process evidence from following good practice; • testing to cover 100% statement and MC/DC; and • acceptance, endurance and performance testing; • qualitative evidence from good design. and Tools and processes which might undermine the SRPS • review of everything with a documentation trail. integrity (e.g. compilers or analysis tools) must be qualified in some way. The standard also explicitly requires As of January 2001 the system had passed all system consideration of counter-evidence i.e. testing and in-service validation, endurance and performance tests. The failures. acceptance test for the customer was completed with no problems, and following sea trials some cosmetic changes 7. The Common Criteria were requested but no faults, crashes or unexpected Security-critical applications are as important as safety- behaviour were reported. critical applications. We now consider the international 6.4 SHOLIS conclusions Common Criteria security evaluation guidelines, and see Z proof and system validation tests were the most cost- how a security application (the Mondex Certification effective phases at finding faults. Traditional module Authority) was developed and verified. testing was arduous and found few faults, except in fixed- 7.1 Common Criteria concepts point numerical code. The strong static analysis removed The Common Criteria for IT Security Evaluation [17] aims many common faults before they could be tested. to set a “level playing field” for all developers in the Software integration work was trivial. More detailed participating states, and aims for international mutual conclusions and fault metrics are given by King et al. [16]. recognition of evaluated products. It combines and The proof work demonstrated proof of exception freedom replaces the US “Orange Book” and the UK ITSEC on the whole system, which was a significant win. In the scheme. proof work, the major lesson at the time (1998) was that a The Common Criteria (CC) defines two types of IT big computer is far cheaper than the time of the engineers security requirement: using it. Moving on to today, the proof simplification work would be better done distributed on personal workstations, • functional (defining the behaviour of a system or reducing the original simplification time by 1-2 orders of product); and magnitude. • assurance (for establishing confidence in the The conclusion of the SHOLIS development work is that implemented security functions – is the product the use of formal techniques such as proof and static built well and does it meet its requirements?) analysis not only satisfies the stringent requirements of UK The CC defines seven Evaluation Assurance Levels – EAL defence standards, but provides a real payback in terms of 1 (lowest) through EAL 7 (highest). An EAL defines a set reduced testing time and increased system assurance. of functional and assurance components from the CC 6.5 00-56 revision documents which must be met. EAL 7 roughly Defence Standard 00-56 is being revised, and the second corresponds to ITSEC E6 and Orange Book A1. public draft for comments was released in January 2004. 7.2 The MULTOS CA The new version incorporates Defence Standards 00-55 and MULTOS is a multi-application operating system for smart 00-54 (safety-related electronic hardware) merged under cards. It allows applications to be loaded and deleted the title “Programmable Systems”. We will briefly dynamically when the card is “in the field”. To prevent examine the new approach in this draft standard, mindful forging or the use of invalid applications, applications and that it may change before release as Issue 3. card-enabling data are signed by the MULTOS The approach in the new 00-56 is to require the developer Certification Authority (CA). At the heart of the CA is a to provide evidence that the system is safe for its intended high-security computer system that issues these certificates. purpose throughout its life. This will include a safety case, The CA has some unusual requirements: an auditable safety management system, risk assessment, hazard analysis, and a demonstration that risk is tolerable or • a target of 6 months between reboots and warm stand-by fault tolerance;

Ada User Journal Volume 25, Number 2, June 2003 104 Practical Experiences of Safety- and Security-Critical Technologies

• a lifetime of decades, and must be supported for • available and competent support; that long; • runtime support for high-integrity systems; and • to be tamper-proof and subject to the most • support for object code verification. stringent physical and procedural security; and The HRG report [7] recommends validation of appropriate • meet the requirements of UK ITSEC E6. annexes – almost certainly A, B, C, D and H. Annex G All the requirements, design, implementation and on-going (Numerics) may also be applicable for some systems. It support for the CA were done by Praxis Critical Systems. does not recommend use of a subset compiler, although it recognises that a compiler may have a mode in which a 7.3 MULTOS CA development process particular subset is enforced. The main compiler The overall development process conformed to ITSEC E6, algorithms should be unchanged in such a mode. minimising the reliance on COTS by assuming arbitrary but non-Byzantine behaviour. The COTS components (e.g. 8.2 Compiler features Windows NT, Backup tool and SQL Server) were not Annex H support and available pragmas will vary among certified. compilers. One of the most important considerations is whether the compiler vendor has documented The security policy and top-level specification was implementation decisions – demand this information from formalised in Z, although no formal proof was carried out. the vendor, and if they cannot or will not supply such The system was implemented in a mix of SPARK Ada, full information then find out why not! Ada 95, Visual C++ and SQL, and tested top-down with coverage measurement. The mixed-language approach was “Qualification” of a full compiler as per the DO-178B (or due to selecting “the right tools for the right job” – similar) definition is beyond our reach at the moment. The implementing a GUI in SPARK Ada was clearly as wrong pragmatic alternative is to combine: as implementing security-critical functions in C++. • avoidance of “difficult to compile” language The use of SPARK in particular was because it is almost features in the high-integrity subset used; certainly the only industrial-strength language that meets • in-service history of the compiler; the requirements of ITSEC E6. Full Ada 95 was used where the necessary constructs (e.g. tasking) were not in • choosing the “most commonly used” compiler the SPARK language at the time; even then, the use of Ada options; was “Ravenscar-like” in using simple, static allocation of • a study of the compiler faults history and database; memory and tasks. • verification and validation of the system; and 7.4 MULTOS CA results The use of Z for the formal security policy and system • object code verification as a last resort. specification helped to produce an indisputable 8.3 Runtime systems specification of functionality, and using Z, CSP and In delivering a high-integrity system, a run-time library SPARK “extended” the formality into the design and (RTL) must be verified to the same level of assurance as implementation. The top-down incremental approach to the rest of the application. Most Ada compiler vendors integration and test was effective and economic. High- have responded to this need with products for Ada 83 and security systems incorporating COTS are possible, and Ada 95. There are three main approaches to certifiable indeed probably necessary. runtime systems: “small and certifiable”, Ravenscar or no Note that the CA was not formally evaluated against runtime. ITSEC E6; nevertheless, there was a clear benefit in The “small and certifiable” approach is largely aimed at security and reliability from developing to this standard. meeting the requirements of DO-178B up to and including 8 Compilers and runtime level A systems. The technical goal is to eliminate language features with an unacceptably large runtime Having established and demonstrated approaches to impact, e.g. tasking, heap allocation, exceptions, predefined developing high-integrity systems for the safety and I/O. Examples are Aonix C-SMART and Rational security domains we now examine how developers should VADSsc for Ada 83. select a compiler and run-time for such a high-integrity system. Ravenscar is a “profile” of tasking and other features in Ada 95 which is appropriate for high-integrity and hard 8.1 High-integrity compilers real-time systems. It is designed to be a particularly A high-integrity Ada compiler should have: efficient, simple runtime system implementation on a single • Annex H support; processor target, amenable to static timing and schedulability analysis. An example implementation is • evidence of qualification against the Ada standard; Aonix Object Ada Real-Time/Raven. The SPARK subset • optimisation and other switches; now includes Ravenscar.

Volume 25, Number 2, June 2004 Ada User Journal P N Amey and A J Hilton 105

The idea of “no runtime” is to eliminate all language development processes can pay off in reduced development features which require any runtime library support. The time and increased system reliability. advantage is that there is no COTS component to certify. References 8.4 Runtime options and development [4] B. Littlewood and L. Strigini (1993), Validation of For all runtime options, the Board Support Package is Ultrahigh Dependability for Software-based Systems, necessary. This provides support for download and start Communications of the ACM, November 1993. up, cold boot (i.e. from ROM), hardware-specific initialisation, debugging, coverage analysis and some [5] R. W. Butler and G. B. Finelli (1993), The Infeasibility predefined simple I/O. of Qualifying the Reliability of Life-critical Real-time Software, IEEE Transactions on Software Engineering, The BSP must be tested, but traditional testing techniques vol. 19 no. 1, January 1993, pp. 3—12. such as unit test and coverage analysis may not work on the BSP. In some projects we have fielded two BSPs: a [6] B. A. Wichmann (1992), Requirements for “debug” version supporting all the above functionality for Programming Languages, Computer Standards and any application, and a “strip” version supporting only the Interfaces, National Physical Laboratory. functionality required for delivery of a specific application. [7] ISO/IEC JTC1/SC22/WG9, Programming Languages This makes (manual) coverage analysis and testing easier, – Guide for the Use of the Ada Programming with no “dead” code. Language in High Integrity Systems, 8.5 Object code verification http://www.dkuug.dk/jtc1/sc22/wg9/n359.pdf If a compiler cannot be trusted sufficiently, manual [8] J. Barnes (2003) High Integrity Ada – the SPARK verification of the object code may be required (OCV). Approach to Safety and Security, Addison Wesley, This should be avoided if at all possible as it requires ISBN 0-321-13616-0 detailed knowledge of the language, compiler and target processor, and is hard and lengthy work. [9] N. G. Leveson (1995) Safeware: System Safety and Computers, Addison-Wesley, ISBN 0-201-11972-2 The 1-step approach to OCV is to compare source code with disassembled object code directly. However the [10]Judge Asquith (1949) Edwards v. National Coal “semantic gap” between the two is very wide, especially for Board, All England Law Report Vol. 1, p. 747 a rich language like Ada, and this therefore requires [11] RTCA (1992) Software Considerations in Airborne detailed knowledge of Ada compilation, code generation, Systems and Equipment Certification, DO-178B language issues etc. [12] J. Sutton and M. Croxford (1996) Breaking Through The 2-step approach is to review the Ada source against the the V&V Bottleneck, Lecture Notes in Computer compiler-generated intermediate language (IL), then review Science vol. 1031, Springer-Verlag the IL against the disassembled object code. This means that the semantic gaps are narrower and splits the reviewing [13]P. Amey (2002) Correctness by Construction: Better skills required, but not many compilers allow users access Can Also Be Cheaper, CrossTalk journal, March 2002 to IL. [14] A. German (2003) Software Static Code Analysis From experience on the SHOLIS project, where a compiler Lessons Learned, CrossTalk journal, November 2003 feature caused large aggregates to be allocated on the heap [15] UK Ministry of Defence (1996) Safety Management although no heap was used in the runtime, we recommend Requirements for Defence Systems, Defence Standard always having someone on a project team who is capable of 00-56, Issue 2 reading and reviewing the object code. [16] S. King, R. Chapman, J. Hammond and A. Pryor 9 Conclusions (2000) Is Proof More Cost-Effective Than Testing? IEEE Transactions on Software Engineering, vol. 26 In this article we have examined the challenge of no. 8, August 2000 implementing high-integrity systems in the context of our experience with them. We have shown what the current [17] National Institute of Standards and Technology (1999) safety and security standards demand, described three real- Common Criteria for Information Technology Security world commercial projects developed under these Evaluation, CCIMB-99-031, version 2.1, August 1999 standards, and shown how the selection of tools and

Ada User Journal Volume 25, Number 2, June 2003 107 No Pointers, Great Programs Mário Amado Alves University of Porto, Rua do Campo Alegre 823, 4150-180 Porto, Portugal; email: [email protected]

function "+" (S : String) return String_Ptr is Abstract begin return new String'(S); This article summarizes the half day tutorial given at end; RST 2004, fully entitled “No Pointers, Great Last_Names : array (Positive range <>) of String_Ptr := Programs. How to stay on the value semantics side of (+"Eachus", the Ada way with a little help from containers.” +"Leif", +"Kasakov"); 1 The Ada ways with the new, pointerless way, using the Unbounded_String In this half day tutorial at RST 2004 [1], we explore the container: value semantics side of the Ada way. The tutorial is function "+" (S : String) return Unbounded_String targeted mainly at beginners and newcomers to Ada, so we renames To_Unbounded_String; review the Ada foundations for value semantics, including Last_Names : array (Positive range <>) of Unbounded_String := unconstrained types, parameter modes, and class-wide … types. Other types, namely records, and other The Ada way is contrasted with the ways of C-like containers, are also studied. languages, and the ‘new’ value semantics way is contrasted with the ‘traditional’ Ada way regarding certain 3 Cells constructions e.g. heterogeneous arrays and ragged arrays. The cell abstraction is introduced as an alternative to Whereas the traditional way uses pointers (access types and pointers. A cell encapsulates a possibly indefinite type values), the new way uses containers. inside a definite one, the cell container. 2 The inescapable string examples generic To contrast with the C way, the paradigmatic example of type Element_Type (<>) is private; passing a string is used: package Cells is do_something (char * s); type Cell_Type is private; Do_Something (S : String); -- no pointers! function Put (Item : Element_Type) return Cell_Type; Strings continue to be used to introduce the container function Get (Cell : Cell_Type) return Element_Type; concept, namely with Unbounded_String. The memory An abstraction of simple arithmetic expressions is given as magic of Unbounded_String is focused upon: an example of a fitting use of Cells, together with class- No storage associated with an Unbounded_String wide programming. An expression is a recursive structure: object shall be lost upon assignment or scope exit. expression ::= integer | operation (expression, expression) §A.4.5 (88) operation ::= add | multiply (The notation § is used to refer to parts of the Reference The traditional way must use pointers: Manual [2].) type Expression is abstract tagged null record; As an example of a fitting use of Unbounded_String, a function Value (X : Expression) return Integer is abstract; function Escape is specified that prefixes a backslash to any type Expression_Class_Ptr is access all Expression'Class; special character in a string: type Operation is abstract new Expression with function Escape (Source : String) return String is record U : Unbounded_String; Left_Operand : Expression_Class_Ptr; begin Right_Operand : Expression_Class_Ptr; for I in Source'Range loop end record; if Is_Special (Source (I)) then Append (U, '\'); end if; … Append (U, Source (I)); end loop; The pointerless way uses containers: return To_String (U); package Expression_Cells is new Cells (Expression'Class); end; use Expression_Cells; Ragged string arrays, i.e. one-dimensional arrays whose type Operation is abstract new Expression with components are strings of possibly different sizes, are used record to contrast the traditional way, using pointers: Left_Operand : Cell_Type; Right_Operand : Cell_Type; type String_Ptr is access String; end record;

Ada User Journal Volume 25, Number 2, June 2003 108 M Amado Alves

The tutorial notes include the full source code of all Tutorial data sheet at the RST 2004 website: examples. http://dmi.uib.es/~AE2004/documents/tutorials/tutorial04.pdf 4 Ada.Containers About the presenter The forthcoming standard container library for Ada 2005 is M. A. Alves is currently with the University of Porto, doing overviewed: PhD research on adaptive hypertext. He has degrees in Linguistics and Informatics Engineering, and has taught Definite element type Indefinite element type Ada, Software Engineering and other courses at several Vectors Indefinite_Vectors universities and institutions. He has been a software Doubly_Linked_Lists Indefinite_Doubly_Linked_Lists developer since the mid 1980’s and an Adaist since the mid Hashed_Maps Indefinite_Hashed_Maps 1990’s. He has been in the Ada Standard Container Library Ordered_Sets Indefinite_Ordered_Sets Working Group since its inception in the RST 2002 An already existing reference implementation is identified workshop. Lately he has contributed to Ada Issue 302 for and used: AI302, mantained by Matthew Heaney at the creation of such a library for Ada 2005, where he has Tigris.org. focused on indefinite elements and persistence. His latest persistent container experiments include Mneson, a Several examples of use are presented, including an developing 100% Ada database system, available from his implementation of Cells based on Indefinite_Vectors. homepage at http://www.liacc.up.pt/~maa 5 Conclusions A practical application, XML_Translator, is presented as an example of building complex data structures the pointerless way. A drawback of this way is noted: for complex, and particularly cyclic, structures, strict value semantics force the copy of the entire structure upon each update of an element, which hinders efficiency for large structures. Finally, the following conclusions are drawn: Value semantics approach: no pointers. Mandatory for small values. Excellent for inspection of structures of any size and complexity. References Good for change of simple structures of any size (because of by reference passing). [18] A. Llamosi and A. Strohmeier (eds) (2004), Reliable Software Technologies Ada-Europe 2004, Problems with many changes to large complex structures. LNCS 3063, Springer-Verlag. When pointers necessary: [19] T. S. Taft et al. (eds) (2001), Consolidated Ada Use smart, or safe, pointers (another tutorial). Reference Manual, LNCS 2219, Springer-Verlag In any case: use Ada! (online at www.adaic.org) 100% Ada, 0% bugs. 6 Miscellaneous information Tutorial notes website (most up-to-date): http://www.liacc.up.pt/~maa/no_pointers

Volume 25, Number 2, June 2004 Ada User Journal 110 Ada-Europe 2004 Sponsors

ACT Europe 8 Rue de Milan, F-75009 Paris, France Contact: Zépur Blot Tel: +33-1-49-70-67-16 Fax: +33-1-49-70-05-52 Email: [email protected] URL: www.act-europe.fr

Aonix 66/68, Avenue Pierre Brossolette, 92247 Malakoff, France Contact: Anne Chapey Tel: +33-1-41-48-10-10 Fax: +33-1-41-48-10-20 Email : [email protected] URL : www.aonix.fr

Artisan Software Tools Ltd Suite 701, Eagle Tower, Montpellier Drive, Cheltenham, GL50 1TA, UK Contact: Emma Allen Tel: +44-1242-229300 Fax: +44-1242-229301 Email : [email protected] URL : www.artisansw.com

Green Hills Software Ltd House, St Peter Street, Winchester, Hampshire, SO23 8BW, UK Contact: Christopher Smith Tel: +44-1962-829820 Fax: +44-1962-890300 Email : [email protected] URL : www.ghs.com

I-Logix 1 Cornbrash Park, Bumpers Way, Chippenham, Wiltshire, SN14 6RA, UK Contact: Martin Stacey Tel: +44-1249-467-600 Fax: +44-1249-467-610 Email : [email protected] URL : www.ilogix.com

LDRA Ltd 24 Newtown Road, Newbury, Berkshire, RG14 7BN, UK Contact: Jim Kelly Tel: +44-1635-528-828 Fax: +44-1635-528-657 Email: [email protected] URL: www.ldra.com

Praxis Critical Systems Ltd 20 Manvers Street, Bath, BA1 1PX, UK Contact: Rod Chapman Tel: +44-1225-823763 Fax: +44-1225-469006 Email : [email protected] URL : www.sparkada.com

Scientific Toolworks Inc 321 N. Mall Drive Suite I-201, St. George, UT 84790, USA Contact: Matthew Bergeson Tel: +1-435-627-2529 Fax: +1-877-512-0765 Email: [email protected] URL: www.scitools.com

TNI Europe Limited Triad House, Mountbatten Court, Worrall Street, Congleton, Cheshire CW12 1DT, UK Contact: Pam Flood Tel: +44-1260-29-14-49 Fax: +44-1260-29-14-49 Email: [email protected] URL: www.tni-europe.com

Volume 25, Number 2, June 2004 Ada User Journal