61508-7 — Iec
I retreated to my office, a tomb of stacked binders and coffee cups. On my screen was the post-mortem: a single, latent software fault. A counter variable in the obstacle-avoidance logic would overflow after 32,767 wheel rotations. Not on day one. Not on day ten. But on day forty-seven—today. The truck thought it had traveled negative distance. It “forgot” the rock pile.
“Eight weeks. No hardware spin. Just a second firmware image and a comparator.” iec 61508-7
No crash. No fire. No $2 million.