Live data from Hacker News

Boeing 737 MAX crash and the rejection of ridiculous data

philip.greenspun.com

91–100 of 194 posts

Re: Boeing 737 MAX crash and the rejection of ridiculous data

#91
post #30

There are several inexcusably egregious errors in the design of the MCAS system, and this "solution" addresses none of them. - Single point of failure: The system makes command decisions based on the readings from a single sensor. The fact that nobody asked (or was bothered by the answer to) the question "what happens when that sensor fails?" is negligence. - No re-training of pilots: Pilots were not aware of new way…

The third factor to add to your list is that the design of MCAS makes the plane unrecoverable in some situations.

On the Ethiopia Air flight, it looks increasingly like the pilots knew what to do, but even after MCAS was disabled it was impossible to recover control because once trim was maxed out, adjusting the physical control trim wheels may have literally taken more brute strength than the pilots had, there was no way to reactivate electric trim control without also reactivating MCAS, and going nose-down to reduce load on the control surfaces to allow manual trim adjustment was infeasible because this all happened at 1000 ft. altitude.

Re: Boeing 737 MAX crash and the rejection of ridiculous data

#92
post #81

Earlier quoted context omitted.

The general consensus on pilot forums is that the side sticks were not a factor. See e.g. here: http://www.airliners.net/forum/viewtopic.php?t=772033&start=... https://aviation.stackexchange.com/questions/14027/sidestick... The thread you link to explains why the sidesticks are a red herring: >Again, the stick inputs from the PF are very easy to see if you just look at them. You would see that immediately if you sat…

I didn't say anything about sidesticks (in a comment below i did). I don't believe myself that the sidesticks were a real factor in themselves - but if the PM had sensed that PF (bonin) was pulling up he would have reacted earlier.

The PNF wouldn't have sensed anything because his hand wouldn't have been on the stick.

The premise of the Popular Mechanics article is that for a significant period, each of the pilots thought that they were the PF and were unaware that the other pilot was making stick inputs at the same time. This is unlikely, because the Airbus has a clear "dual input" warning. If you read the transcript, you can see that there's actually quite a lot of discussion between the pilots about who is in control. It was only the captain who had any clear idea of the correct control inputs to make, and he wasn't seated at the controls at all, so linked sticks wouldn't have made any difference to him.

Re: Boeing 737 MAX crash and the rejection of ridiculous data

#93

It should be noted in the doomed Air France 447 flight, the plane activated the stall warning because of a high angle of attack that was leading to stall. (thanks pdx for the corrected info) At some point the system rejected the data and stopped the stall warning because the angle of attack was so severe that it considered the data erroneous. This is speculated to have caused the co-pilot to keep pulling back on the…

Your basic point is spot on, it isn't simple. The challenge I think is to keep two things separated, one is the flight control laws that the system is implementing to keep the plane in the air (to the best of its ability), and the other is the situational awareness indicators for the pilots so that they can tell what what the plane is "thinking" about how it is flying (or not). The closest analogy I can come up with…

This is not the problem. MCAS in itself sadly is the problem.

They had to solve the issue that the pitch-up moment shouldn't be accelerating on its own just depending on AoA, which was (aerodynamically) inevitable without automated adjustments due to the placement of the engines.

They had to resort to the worst possible cludge, since they weren't even allowed to add new electrical systems (which would have caused a recertification and/or a retraining), so they resorted to an already existing system (assisted trimming by autopilot).

The effect of MCAS is only "fixed" by manually adjusting the trim, which involves moving a jackscrew which holds the last section of the elevator at a fixed angle. Unfortunately the required force of moving this jackscrew increases with the airspeed. There is no easy way out. A bit more background can be found here: https://www.satcom.guru/2018/11/stabilizer-trim.html

Btw, the extra price item was an AoA disagree warning. This is related to MCAS in a way like an odometer failure to traction control. It wouldn't have helped, if pilots stuck to their memory items and checklist (which they have to: they recognize runaway trim and have to react accordingly).

To get a slight feeling what it means to have runaway trim (without assistance which they had to disable in concert with MCAS) please have a look at this video: https://vimeo.com/329558134

Re: Boeing 737 MAX crash and the rejection of ridiculous data

#94

Now, imagine you have 5,000 such checks in millions of lines of flight control system code, many of them interdependent, and you have to fly the ship to test each one. You need to schedule time with the test pilots (who have lives of their own) and get the data dump from IT post-flight. It's aerospace so all this undergoes review, documentation, and signoff, and it all takes time. How do you prevent a single check fr…

I'm sorry i'll have to mention that the software can be thoroughly tested in simulation flights. Funnily enough i was involved with some virtualisation software used to test booking systems for Airports. If you can virtualise a booking systems, trust me you can virtualise the on-board flights systems.

Is this really true though?

From what I have read it sounds like part of the problem is that manually adjusting the trim wheel requires more strength than at least some pilots possess due to the mechanical forces on the plane. I don't think it's reasonable to expect simulators to replicate those types of forces.

Re: Boeing 737 MAX crash and the rejection of ridiculous data

#95
post #66
post #18

Earlier quoted context omitted.

I agree that we frequently see this on HN in regards to aviation. However, I don;t think it applies to Greenspun. He's a knowledgeable and active pilot himself.

Lots of people are, that doesn't mean they aren't armchair quarterbacking. I know how to fly airplanes and helicopters, does that make me an expert on the flight dynamics of 737 MAX?

According to Wikipedia he flew for Delta Airlines/Comair https://en.wikipedia.org/wiki/Philip_Greenspun.

That still doesn't mean he knows anything about writing code for flight control systems in commercial environments. Maybe he's written some toy code in MATLAB demonstrating some things, that's never undergone testing on a real airframe.

Re: Boeing 737 MAX crash and the rejection of ridiculous data

#96
post #40

How does it feel to enter a world where software is killing people ? Driven a new car lately ?

Software CAN be far more safe then humans for tons of reasons. It's a matter of procedure and testing to ensure it's actually safe.

People are going to die, and that sucks. The hope is that we can use software to lower the death rate.

In this case: How did they have a system that can override the pilot without A) Clearly identifying why it's overriding the pilot and B) allowing the pilot to quickly disable it if they wish.

This could have been different, even ignoring how the MCAS didn't detect the strange readings.

* MCAS detects dangerous angles, beeps and has a clear light to alert the pilot to the situation * Pilot understands there is no danger in stalling, disables MCAS * They can now ground the flight or continue to their destination without the plan sending them to the floor.

Although based off what I've read about MCAS it only exists to fix a fundamental design flaw with how the 747 is certified, which is obviously an issue on it's own.

Re: Boeing 737 MAX crash and the rejection of ridiculous data

#97

> Beyond 25 degrees, therefore, it is either sensor error or the plane is stalling/spinning and something more than a slow trim is going to be required. I am not a pilot, and I'm going to take this pilot at his word. But my first question would be, if we add this additional rule into the system (that runaway trim turns off above 25° AOA), will any pilot ever need to know about this rule? If the answer is "absolutely…

Thanks for sharing your perspective.

Re: Boeing 737 MAX crash and the rejection of ridiculous data

#98
post #78

Earlier quoted context omitted.

Have you had to fight your lane assist yet ? I am all for the sensors to give me information but when the systems take over control I am not a fan. Cyclists in the EU have learned that the car sensors will slam on the brakes. Quite irritating when the car slams on the brakes and they are laughing at you.

Ah, see, I'm American. ;) The lane assist can be disabled and a cyclist who hard-brakes in front of me is taking their life in their hands because my Ford only stops if I touch the brake (it just stops as hard as it needs to to minimize risk of impact, regardless of how soft I push the pedal). (Sidebar: I almost feel like that cyclist game is something that should be solved with more sensors. If it's a common issue,…

I am an American too, renting an Audi in Germany has caused me many learning experiences. Like take the 30 minutes to learn the computer system before you take off because attempting to turn things off at speed is interesting when you cant find it.

Audi presense is nice, lane assist is nice, adaptive cruise control is nice etc etc but when its not nice it gives you whiplash or heart attacks

And that ever pervasive feeling that you know somwehere is a bug in that code which could yank your steering wheel sideways or slam on the brakes randomly

Re: Boeing 737 MAX crash and the rejection of ridiculous data

#99
post #78

Earlier quoted context omitted.

Have you had to fight your lane assist yet ? I am all for the sensors to give me information but when the systems take over control I am not a fan. Cyclists in the EU have learned that the car sensors will slam on the brakes. Quite irritating when the car slams on the brakes and they are laughing at you.

Ah, see, I'm American. ;) The lane assist can be disabled and a cyclist who hard-brakes in front of me is taking their life in their hands because my Ford only stops if I touch the brake (it just stops as hard as it needs to to minimize risk of impact, regardless of how soft I push the pedal). (Sidebar: I almost feel like that cyclist game is something that should be solved with more sensors. If it's a common issue,…

The cyclist issue is something I don't consider a fault of software or the car's design. Driving/Cycling/Walking in front of a high speed vehicle who has the right of way to the point that they need to break means you should not have been there to begin with.

The car's only other option is to hit the cyclist, so as far as I'm concerned it's doing it job correctly. Like you mention a dashcam is likely the only remedy here. Thankfully they're cheap and pretty common...

Re: Boeing 737 MAX crash and the rejection of ridiculous data

#100

Earlier quoted context omitted.

AoA is just that: angle of attack ( https://en.wikipedia.org/wiki/Angle_of_attack ) The sensor simply measures the angle of the airflow with respect to the airframe. In fact it is just a free-moving surface attached to the airframe.

I know what AoA is and yes, the calculation of AoA by itself is simple, but the corrective measure is not. Classic 737s climb via trim, not constant stick inputs. This has changed slightly with the MAX but now you have automated AoA correction (involving trim). That's a nasty combination.

That's not nearly the case. MCAS is a stupidly simple system intended to cut in during very unusual phases of flight were a normal commercial flight would not be operating.
Post reply on HN