The Boeing 787 is now about nine years old. I wonder how much of this is operator proficiency triggering latent bugs (aka, "pilots got too good at pushing buttons quickly"). The bugs in the Therac 25 were only discovered after the machine had been in production for a while (you had to be typing "too quickly" in order to get the software to trigger the bug with the safety interlock).
Considering the level of fly-by-wire that goes into airframes nowadays, I could certainly see such features added to older airframes through flight-software updates after they are already in service. I have no idea if that's how it's done in the field, though.
Boeing 787 Suffers Rare Dual Engine Failure on Landing
161–170 of 365 posts
Re: Boeing 787 Suffers Rare Dual Engine Failure on Landing
#162Earlier quoted context omitted.
That aircraft was being knowingly flown with [edit: a broken sensor]. It was unsafe on takeoff. The final problem that brought the aircraft down - the trim run-away - happens all the time in airliners you've flown in. When the run-away starts, the pilot is supposed to flip two switches to disable the trim system motors. In the Lion Air crash, it is indeed believed that a software bug from the misbehaving sensors star…
> the trim run-away - happens all the time in airliners you've flown in. It doesn't. A trim run-away is a very very serious incident for any pilot. There are procedures to deal with it, and we check trim override in pre-flight checks, but it's absolutely not an everyday thing. > 737's are even safer here than many airliners, because after you disable the electric trim motors, you have manual wheels in the cockpit tha…
Whereas a 737 has physical cables connected from wheels in the cockpit to the stabilizer jackscrew.
Re: Boeing 787 Suffers Rare Dual Engine Failure on Landing
#163Earlier quoted context omitted.
you would be wrong.
That's not a very useful reply. Can you explain where anonu is wrong? Can you explain why ? Can you give some evidence ? A bare dismissal is like five-year-olds arguing: "Did too!" "Did not!" It's not useful to advance the conversation, and it's not effective at persuading people.
When the software fails (if it did) we assume the software makes it more dangerous because we have a concrete example of what happened but not what could have happened in it's absence.
This is what may eventually stall self driving cars for many years, the first time one does the PR equivalent of smashing through the local orphanage.
We as a society are notoriously poor at assessing systemic risks.
Now to address your point about evidence, I'm curious how you could control for other confounding factors.
Airliners are safer today than ever before (based on passenger miles) but how do you control for better engines, material science, procedures if you compare say 1979 to 2019.
Re: Boeing 787 Suffers Rare Dual Engine Failure on Landing
#164Earlier quoted context omitted.
By self destruct, I meant switching off the engines in flight seems to me to be a terribly dangerous behavior.
Switching off is much safer than a turbine overspeed past certain limits. Because an engine failure (one engine) is a situation all pilots are trained for and it has an almost certain safe outcome. Airplanes fly and land just fine on a single engine. We all train for engine failures all the time. On the other hand, a runaway engine fire or uncontained turbine failure is much much more likely to cause a crash. So almo…
Re: Boeing 787 Suffers Rare Dual Engine Failure on Landing
#165Earlier quoted context omitted.
I always love it when you have worked on something for months and someone new comes by and says "Why don't you just X?".
I found that I now distrust a lot of articles as people tend to get the things in my field blatantly wrong all the time. Things are complicated and rarely as simple as they seem. On the other hand, I've worked on things for hours before for someone to glance at the problem and solve it. Always a humbling experience.
Re: Boeing 787 Suffers Rare Dual Engine Failure on Landing
#166Boeing’s answer seems to say if you accidentally pull the thrust reverser lever before the aircraft is on the ground it just force shuts down the engines. That sounds like an odd safety override. Surely a better solution would be to just not activate reverse thrust. Unlike car engines a jet engine can’t just be quickly restarted if it accidentally shuts down. It typically takes 30-60 seconds to get going. This and ea…
Thrust reversers can never be deployed while airborne. This engine shutdown system is only enable on the ground. It's designed to shutdown an engine if the engine thrust doesn't match the commanded thrust, so an engine malfunction on the ground cannot cause the plane to taxi out of control. But it is still possible for the pilots to deploy reverse thrust too soon, after touchdown but before there there is enough weig…
Re: Boeing 787 Suffers Rare Dual Engine Failure on Landing
#167Earlier quoted context omitted.
> the trim run-away - happens all the time in airliners you've flown in. It doesn't. A trim run-away is a very very serious incident for any pilot. There are procedures to deal with it, and we check trim override in pre-flight checks, but it's absolutely not an everyday thing. > 737's are even safer here than many airliners, because after you disable the electric trim motors, you have manual wheels in the cockpit tha…
Embraer 190? There are no non-electrical trim controls in the cockpit. http://www.smartcockpit.com/docs/Embraer_190-Flight_Controls... Whereas a 737 has physical cables connected from wheels in the cockpit to the stabilizer jackscrew.
Both circuits are electric, but they are separate systems on separate power busses to ensure you always have control.
Re: Boeing 787 Suffers Rare Dual Engine Failure on Landing
#168Earlier quoted context omitted.
After serverless comes codeless.
Airbus has been been doing "codeless" development with Esterel products for quite a while. I put codeless in quotes, because I believe the tools to generate code at the end of the day - but it's not code that is written by humans, and it is generated based on formally verified models. I believe this is what Airbus uses: http://www.esterel-technologies.com/products/scade-suite/
It does not mean that any software done with this tools is thus certified, you need to apply the safety methodology to certify it
Re: Boeing 787 Suffers Rare Dual Engine Failure on Landing
#169Earlier quoted context omitted.
Do you have experience with aircraft engine design, or landing protocols, or insight in to the meetings when the engines were designed? If so, I'll take back my words but considering the manufacturer doesn't know exactly why this happened, and the engineers on the ground said it seems like a "software bug", it seems a bit presumptuous and frankly a bit comical to start saying things like: "Surely a better solution wo…
Reminds me of the quote, "For every complex problem there is an answer that is clear, simple, and wrong." -- H.L. Mencken One of the things I have experienced in my career is the mind boggling complexity of the software in systems that are capable of killing people. The more people it can kill the more complex the software. As a result when I read articles like the one posted I find it tantalizing to speculate about…
Re: Boeing 787 Suffers Rare Dual Engine Failure on Landing
#170Boeing’s answer seems to say if you accidentally pull the thrust reverser lever before the aircraft is on the ground it just force shuts down the engines. That sounds like an odd safety override. Surely a better solution would be to just not activate reverse thrust. Unlike car engines a jet engine can’t just be quickly restarted if it accidentally shuts down. It typically takes 30-60 seconds to get going. This and ea…
This is an issue carmakers have had to deal with, too, since the invention of the automatic transmission: what if you put it in reverse while driving on the highway? There are a number of YouTube videos with people who have tried it. The answer, in a modern car: pretty much nothing. It just stays in Drive. On one car, it turned on the backup camera display!