Lineside signals aren't made to be "free or error or failure" as that is impossible to guarantee. After all, they are positioned outside and thus are susceptible to external influences.
The systems
are designed in such a way that if a failure
does happen, the system will choose a safe mode of failure: signals will turn red, level crossing will remain closed, traffic lights will go into hazard mode (flashing yellow aspects).
Wrong-side failures are incredibly rare, and are nearly always caused by external factors which prohibit the normal systems operation. Three incidents spring to mind:
- The 1988 Clapham Junction crash, in which stray wires caused false information to be fed into the signalling system
- The 2011 Zevenaar ICE crash: thieves had cut away a lot of copper around the Zevenaar junction, and had done so in such a way that the signalling system was not aware of it.
- The 2014 TER-TGV crash: rodents had eaten through signalling cables on a rural line in France, which caused the train occupation detection system to fail in an unsafe way.
Those are not safety critical systems.
Yes, and this is an issue which is being investigated (see the post mentioned earlier).
Isn't that basically their job?
On the current Thameslink route, drivers
are responsible. What I understood from Geoff Marshall's video is that -upon entering the TL Core- the train is offered to run under ATO. The driver explicitly has to accept this, and has to indicate that he wishes to continue ATO running after every station stop in the Core. Upon leaving the tunnels, the driver then regains control as the ATO section ends.