to the 4digit ID
I disagree. A fail safe is much better than a hard crash, particularly if it causes a crash loop. A fail safe can allow for manual recovery and processing while the system is still up and moving flights around, albeit slowly.
If the system had hard crashed the primary and backup, recovery would likely have required dump analysis before the system could have been brought back up to any sort of functional state in production.
I would also argue failing safe is highly preferable to a hard crash that may leave an entire system in an unknown, and potentially dangerous state. Iâ(TM)m pretty sure being unable to communicate is much better than a plane crash.
Failing at all due to failure to sanitize input is always a Bad Thing(TM). However missing a real edge case is almost unavailable. This seems like something that should have been caught though.
**Coming up next on America(single quote)s Home Videos, watch some graybeards get into a good old fashion flame war. :)
âÃ'â&$ just because