[SystemSafety] Overflow triggering AC power cut-off in Boeing 787

> http://rgl.faa.gov/Regulatory_and_Guidance_Library/rgad.nsf/0/584c7ee3b270fa3086257e38004d0f3e/$FILE/2015-09-07.pdf

For those that don't want to read the FAA advisory, a signer integer overflow can trigger a cut-off of all AC power in Boeing 787 planes after 248 days (~8 months). It never occurred on real planes but in simulation.

Other source:

This would not happen if absence of overflow was automatically checked (by using tools like Frama-C, Astrée or Polyspace). Or more probably this overflow was identified but judged as "could never happen". Would a reader of this list have some insight about what really happened?

