跳到主要內容

18 March 2019 TWL MTR crash report, from MTR

Background

The new signalling system of TWL developed by the contractor is divided into two control zones. In each control zone, it comprises three signalling zone controller computers, namely the Primary("A), Hot-standby("B"), and Warm-standby("C") computers.

Computers A, B and C are of the same hardware and loaded with common software.

They are configured to perform functions of Computer A, B and C through a hardware identity plug, which allows the common software to process dynamic data among the three computers correspondingly.

Computer C only receives selected dynamic data from Computers A/B so as to avoid common mode failure.

This configuration aims to improve system availability and service recovery through high resilience

Computer C is housed at a different station which enhances system security through access control and diverse power supply.


The Panel agrees the warm-standby arrangement is novel in contractor's signalling system application for reducing the recovery time during signalling failure incidents.


Cause 
 
The Panel found that the contractor made three software implementation errors when performing a software change in 2017, to achieve the design intention of avoiding common mode failure in Computer C, should there be a problem in computers A and B.

To do that, the contractor needs to exclude selected data to be transferred from computer A/B to computer C, and the excluded data should be re-created by computer C, so as to avoid common mode failure.

three implementation errors: 
1.  internal software development documents of the contractor's software team did not denote clearly the exclusion of "Conflict Zone Data" from being transferred to computer C. This led to no subsequent specific test, risk assessment or safety analysis, including laboratory verification simulation and on-site testing, being done to verify the "Conflict Zone Data" when computer C took over the control of the signalling system.

2. the contractor made a software implementation error which resulted in computer C not re-creating the "Conflict Zone Data"properly

3. while the "Conflict Zone Protection" was absent in computer C, the software logic developed by the contractor did not stop the computer from taking over the control of the system. The absence of the conflict zone protection resulted in the incident.

The Panel also concluded that the software implementation errors reflected inadequacies in ATDJV's software development process with respect to

software quality assurance,
risk assessment and
the extent of simulation

on this software ( "Conflict Zone Data" re-creation") change.


Recommendations
to prevent recurrence
(a) replace software design and development team
(b) confirm after the software fix
(c) traceable in the changes
(d) external independent software assessor (ISA) for Quality Assurance and Audit

To assist ATDJV

(a) expand scope of ISA
(b) upgrade training simulator

contractor :  Alstom-Thales DUAT Joint Venture


 btw, where is the KISS principle applied? Is MTR relying too much on the contractor's deliverables to carry out the drills? Does MTR understand and, before the  March 18 drill, cross check the "Conflict Zone protection" is properly working?





press release

wiki 

facebook

留言

這個網誌中的熱門文章

越南香草

Ngo ~ "N-gaw" Mui ~ "Moo-ee" Ngo ~ "N-gaw" Mui ~ "Moo-ee" Ngo ~ "N-gaw" Mui ~ "Moo-ee" Ngo (N-gaw) ,  Mui  (Moo-ee )  Cilantro Ngo Gai (N-gaw guy), Mui Tau (Moo-ee Tao), Ngo Tau (N-gaw Tao)   Mexican Coriander,  Sawtooth Coriander, Culantro    娥女帝(拼音), 刺芹   特徵:娥女帝是短株形的植物,氣味清淡,葉邊呈鋸齒形,十分容易辨認。來源地:越南。 功效:和白夏差不多,娥女帝亦有祛濕、解毒及驅風的療效。建議食法: Pho,  (Bánh Xeò) 越南煎餅, 炒菜,湯,咖哩 Ngo Gai ~ "N-gaw guy" Mui Tau ~ "Moo-ee Tao" Ngo Tau ~ "N-gaw Tao" - See more at: http://vietworldkitchen.typepad.com/blog/vietnamese-herb-primer.html#sthash.I9rzkzwI.dpuf Rau Ram (Rau Rahm) Vietnam Coriander, Laksa Leaf, "Vietnamese mint(actually not a mint)" Peppery, quite spicy. In salad Hung (Hoong), , Hung Lang (Hoong Lang) Spearmint.  Vietnamese coriander Hung Lui (Hoong Lou-ee), Hung Diu(Hoong Zee-ew) round mint used in salad Hung Cay (Hoong Kay) Mint Rau Que, Hung Que (H...

沖田博文 Hirofumi Okita 60cm F3.25 dobsonian telescope

  the making mirror from Mike Lockwood webpage   youtube uwakina bokura other ATMers in Japan blueforest anettai  

劣質洗衣機入水喉

上面白色是最易找到,$2x. 但漏水. 灰色, $4x, 是假冒 "MADE IN ITALY"  假冒 "MADE IN ITALY"  的標緻  左面是白色膠喉的喉頭, 右面是灰色膠喉的喉頭, 上圖左面是真正 好貨 ( MADE IN ITALY )灰色膠蓋.右面是冒牌 白色膠蓋. 膠蓋在安裝扭緊時爆開  上圖左面是真正 好貨 , 標了其他規格.右面是冒牌, 單單印了 MADE IN ITALY  好貨的膠蓋是可以下移, 露出喉頭及黑色軟膠墊 黑色軟膠墊是有坑紋. 質感較柔軟. 緊後可以"迫實"水龍頭 及喉蓋, 沒有滲漏 正板 MADE IN ITALY 賣 $4x, 價錢絕對合理. 冒牌貨在旺角新填地街買的, 也是$4x. 真是要小心!!! NB: MADE IN ITALY 是否真正 意大利制造實在無從考 証