Personal systems projectPart 3 of 3Drawing 15.3 of 37
Runtime and safety
How the nine processes share data, with one writer for each piece of it. It also covers the twenty four calibrations and the safety document, which overrides every other tradeoff.
- StatusIn development, 2026
- WrittenAbout 129,000 lines of hand-written C++17 across 15 subsystems
- Desktop tests105 run, 105 pass, on a laptop with no sensor attached
- Not run on hardwareZero lines. Every performance figure below is a budget
- OwnedThe helmet display. Everything else is still unbought
- TargetJetson Orin Nano 8GB worn on the body, Raspberry Pi 5 on the robot
Sheet 02 of 04/Plumbing
Nine processes and a supervisor
Argus runs as nine separate processes instead of threads, plus a supervisor that restarts them. That way a crash in one subsystem shouldn't be able to take the render loop down with it. The processes share data through two primitives, and each piece of shared data has exactly one writer. Only descriptors get passed between them, and the frame pixels never cross a process boundary.
Sheet 03 of 04/Safety
The safety document
One rule overrides every other tradeoff on this project. If the software fails, the helmet has to fail safe. That starts with a physical bypass that sends a direct camera feed to the display with the compute completely out of the circuit. It also never freezes a frame, because a frozen HUD that still looks alive is more dangerous than a black one.
Sheet 04 of 04/Calibration
Twenty four calibrations
I've specified 24 calibration procedures, in order, and what each looks like when it's wrong. I haven't done any of them yet, because there's no camera to calibrate.