This is an invited paper for next year's Safety-Critical Systems Symposium. The full reference is:

