One bit of inspiration is Galileo mission running 13 years using its 6 1802's with redundant boards. That ended prematurely due to mission saturating it with radiation & slamming it into a planet. A similar setup fabbed on older nodes for their extra reliability might be able to last decades.
https://en.wikipedia.org/wiki/Galileo_(spacecraft)#Command_a...
https://en.wikipedia.org/wiki/RCA_1802
Of course, this link is talking about supporting the software and such. The hardware itself might not need to last several decades. It might be enough to simply design the HW architecture to be portable to whatever process node, link into a cluster, and take over for faulty hardware. In other words, standardize the interface on the HW and then the software. The hardware developers could then keep making the replacements on cheapest processes. However, I'd still recommend older, mature, simple nodes if it's safety-critical because the extra safety can only help & they can often forgo 1+GHz processors anyway.
Btw, what you think of a micro version of NonStop's HW/SW on inexpensive, embedded boards?
'Course, they're not running Linux.
However these spare parts usually don't come with updated or even maintained software. The lifecycle for SW currently is: Car is developed (3-4 years), then car enters the market and some minor updates/bugfixes are added (probably also for 3 years) and then nobody touches anything anymore. That worked out reasonably well for the last gen. However things will get very interesting for the current and next generation of vehicles with lots of connected features - and also driver assistance features which rely on connectivity. If the same model is applied here unlucky customers could be unable to use lots of features after only a fraction of the cars total lifetime. And of course they could be driving around with security holes.
The design spec was final well before 1985. 1985 would have been considered "support and maintenance". Cars started getting EEC-IV in '81 IIRC and the form factor was revised soon after.
The system would have continued to have been used on new vehicles well past 1996 but it didn't have enough I/O pins to deal with all the things required for OBD2 compliance, thanks Commiefornia.
The latter is much more interesting to me.
With a definition of machine that's slightly more broad than "single desktop box or server" then I think 60yr is a pretty reasonable uptime goal. Something with redundancy and hot swap capabilities should have no problem getting several decade uptime. These are embedded devices, it's not like a nuclear reactor needs to reboot frequently.
A nuclear reactor has regulatory oversight and a risk management plan. It must survive the failure of any single component, no matter its reliability target.
Over 60 years, those 'highly unlikely' threats -- earthquake, terrorist attack, military action -- they become 'kinda probable'. No single component can survive these, and you'd be foolish to try.
http://www.theregister.co.uk/2013/06/19/nuke_plants_to_keep_...