Live data from Hacker News

The Coming Boeing Bailout?

mattstoller.substack.com

181–189 of 189 posts

Re: The Coming Boeing Bailout?

#181
post #125
post #120

Earlier quoted context omitted.

That is true. But please keep in mind that the whole MCAS fiasco was precipitated by a dubious cost-cutting initiative related to an engine placed more in front than would be aerodynamically stable. The game was lost in the first quarter. The whole point is that civilian aircraft, unlike fighter jets, have to be aerodynamically stable without the need for such software, whether developed by holistic engineers, or com…

The 737 MAX is aerodynamically stable. MCAS isn't even active while any flap is extended. MCAS should be active only at angle of attacks, which wouldn't be reached at extreme angle of attacks. The sole purpose of MCAS is to emulate the exact reactions of the older 737 machines in this domain, as this was required for maintaining the same type rating. That is also the reason, the pilots are supposed to deactivate MCAS…

Incorrect. The aircraft is not aerodynamically stable in pitch unaided by software, thereby failing the demonstration of positive pitch stability as written in FAR 25.173. The non-compliance is of the form of a slackening of control stick response force at high AoA due to extra lift generation ahead of the center of gravity caused by the forward mounted engine nacelles.

In regulatory parlance, this specifically means the airframe (the specific physical assembly of parts that collectively determine the flight characteristics of the object in question) possesses an "instability" that disqualifies it from being certified airworthy as a Civil Transport Aircraft unless the FAA amends or reinterprets the requirement.

The penultimate Lion Air flight only recovered thanks to The intervention of a third pilot; a luxury not universal to every cockpit.

>MCAS should be active only at angle of attacks, which wouldn't be reached at extreme angle of attacks.

The potential for MCAS subroutine activation is active during all phases of manually controlled (Autopilot off), flaps up flight,and is gated only by readings from an AoA sensor; which can fail in flight to catastrophic effect.

>The sole purpose of MCAS is to emulate the exact reactions of the older 737 machines in this domain, as this was required for maintaining the same type rating.

Incorrect. The sole purpose of MCAS is to induce an intentional "mistrim" during certain points of the flight envelope to counter the extra lift generated by the repositioned engines, with the end goal of smoothing out the non-compliant stick force response curve. Note, jury is still out whether this should even be allowed. I've gotten wildly different responses based on who I've talked to. Pilots seem to express horror or extreme discomfort. Aerodynamicsts are disconcertingly quiet, but tend toward hard reconfiguration to obviate the need for a software based solution.

Also, MCAS specifically deviates from oldaircraft behavior in that it removes an override of auto-trim commands activated by heavy back pressure on the yoke. There were also specific reconfiguration of the stabilizer trim cutout switches that removed any capability of locking out the MCAS system's ability to actuate the trim motor, while leaving pilot's thrim switches active.

https://www.seattletimes.com/seattle-news/times-watchdog/the...

https://www.seattletimes.com/business/boeing-aerospace/boein...

Make no mistake: Boeing screwed the pooch. Big Time.

Re: The Coming Boeing Bailout?

#182

Earlier quoted context omitted.

No sensor failure should cause the plan to go into swan dive to destruction mode. The software that carries your tweets has to deal with exceptional situations including hardware failure so to must software that runs life critical hardware. Seems to me that if the proper response to faulty sensors was to disable MCAS perhaps it should have just done that for the pilot. Even without a second AoA sensors perhaps someth…

> Even without a second AoA sensors perhaps something could have been derived from the fact that the pilot was furiously pulling up while the aircraft was losing altitude? People keep saying this. But AF 447 was caused by this. Pilot furiously pulling up, plane rapidly approaching the ground... And the steps to fix it would have been to push down . None of this is as simple as you seem to think.

AF 447 was caused by not being "ahead of the plane", or not being "10% smarter than the piece of equipment you're operating".

Pilots speak of being ahead of the plane as the mental state of understanding the current condition of the aircraft, and being able to correctly forecast the end result of any control action on the current state.

This is like driving a well maintained car. You know the car will "follow" your directions.

Reasoning "behind the plane" is a state where the plane has started to do something, and you have to figure out what changed; I.e. the actual plane is no longer equivalent to your mental model of the plane. You can no longer with any certainty forecast the end behavior of the plane on your understanding alone. You're essentially in a reactive state. You have to rebuild your model.

AF447 suffered a major automation casualty. The pilot's didn't realize this, and attempted to fly off their flawed mental models of the plane's behavior. For instance, the Stall alert becoming active when the pilot tried pitching the aircraft down being unsilenced due to the automation coming back within non-extreme input regimes. The pilot attempted to avoid the alert by returning to the extremis instead of pitching down through the alert to recoverable flight.

Did the pilot's know that the alert would silence beyond an extreme value? No, but instinct told them if they did something that caused a stall response, reverse it to get away. Without the extra intelligence around how the automation worked, heuristic reasoning led to a valid, but ultimately lethally unsound course of action.

Re: The Coming Boeing Bailout?

#183

Earlier quoted context omitted.

It's not just the checklist: the experience of MCAS-induced trim runaway is significantly different from that which NG pilots are trained for, to the point where additional training seems necessary. Boeing set up the conditions for an accident by first hiding, and then downplaying, those differences, apparently to avoid additional training being required. I have seen some suggestions that this was also the reason for…

I agree with you, hence the "arguably, this may be a problem" parenthetical. Nevertheless, the provided checklist did work as evidenced by Lion Air 043.

Note: the penultimate flight had the luxury of a third pilot in the cockpit with nothing else to do than to pay attention to anything the other two pilots couldn't.

Also, that "checklist", and he existence of MCAS, was not even commonly known until after Lion Air went down.

The secrecy behind this is largely attributed to Boeing trying to keep MCAS from intense scrutiny by the FAA, based on whistleblower testimony reported in the 60 Minutes Expose.

https://m.youtube.com/watch%3Fv%3DaO7_indbfME&ved=2ahUKEwiPp...

Re: The Coming Boeing Bailout?

#184
post #171

Earlier quoted context omitted.

No; the third crew member on prior Lion Air flight (043) is the one who diagnosed the issue as runaway trim and cued the flight crew to execute that checklist. I've read nothing to suggest that they participated physically in the response (despite having read quite a bit on the topic). The excessive force on the trim required in the Ethiopian Air case was a consequence of the crew leaving the engines at high power, t…

One should however mention that the failing sensor gave an "unreliable airspeed" warning. The checklist for that requires a designated power setting as well as a designated pitch for which the airspeed is known for the altitude. Afaik the pilots executed that checklist at least for the power setting part before moving to the stab trim runaway memory item. The failing AoA sensor triggered several checklists to work on…

This would have been complicating in Boeing's attempt to get the plane certified without simulator training, as it would have raised inconvenient questions as to why a previously non-safety-critical sensor suddenly needed a checklist, which would have kicked off a chain of very difficult and expensive to remediate questions upon a more in-depth, impartial design review.

Re: The Coming Boeing Bailout?

#185

Earlier quoted context omitted.

> Even without a second AoA sensors perhaps something could have been derived from the fact that the pilot was furiously pulling up while the aircraft was losing altitude? People keep saying this. But AF 447 was caused by this. Pilot furiously pulling up, plane rapidly approaching the ground... And the steps to fix it would have been to push down . None of this is as simple as you seem to think.

AF 447 was caused by not being "ahead of the plane", or not being "10% smarter than the piece of equipment you're operating". Pilots speak of being ahead of the plane as the mental state of understanding the current condition of the aircraft, and being able to correctly forecast the end result of any control action on the current state. This is like driving a well maintained car. You know the car will "follow" your d…

No disagreement at all from me. I just wanted to point out that the suggested 'should I cancel MCAS' heuristic was not nearly sophisticated enough.

Re: The Coming Boeing Bailout?

#186

Earlier quoted context omitted.

Companies can come back after the HBS MBAs/bizdevs take over, they must return to product/engineering/creative focused though and it is tough, usually it takes a near failure for the problem to be recognized. Apple survived when Jobs came back and focused on products/engineering/creativity. Microsoft survived post-Ballmer after returning to product/engineering led decision making and power structures. Amazon is top o…

>> Companies can come back after the HBS MBAs/bizdevs take over, they must return to product/engineering/creative focused though and it is tough, usually it takes a near failure for the problem to be recognized. I'd also point to AMD. After AMD64 came out, Ruiz focused on marketing and cut back in engineering. He also bought ATI, which was a good long term but cost a lot of money at the time. They only turned around…

He also sold their mobile graphics technology, Adreno, only about 2 years before the smartphone revolution began.

Re: The Coming Boeing Bailout?

#187
post #91

Earlier quoted context omitted.

kind of depends on how you name it. my understanding is the code 'worked per requirements', meaning it did everything that it was supposed to, as defined by the requirements allocated to it. for things like this, there is a layer of 'systems engineering', that decides (hopefully using an engineering process) how the airplane will work. this is codified into a 'specification', that is then handed over to software to i…

The MCAS is a good example, why certain software must not be outsourced. Implementing the software correctly to spec isn't enough, you need enough understanding of the application to question the spec itself.

That assertion in the article seems to be incorrect according to the linked Bloomberg article, which states that the MCAS software was not outsourced: https://www.bloomberg.com/news/articles/2019-06-28/boeing-s-.... Given that apparent factual error, I’m suspicious of the other claims, which are highly rhetorical and mostly asserted without evidence.

Re: The Coming Boeing Bailout?

#188

Earlier quoted context omitted.

It has been mentioned in the article that MCAS was never outsourced. Also it’s unfair to blame the software engineers who are building it to specification. It would be fantastical to assume that Boeing management( the same one ploughing through engineering with bean counting) would give a rats crap about a low level engineer raising a concern.

Not sure why this comment is being downvoted. First, none of the software in question was outsourced to the company. Second, the Bloomberg article does not describe the problems Boeing had with the software engineers from HCL, beyond a cryptic, "it took many rounds going back and forth because the code was not done correctly." Was it a genuine misunderstanding of ambiguous language? Was it because the programmers did…

MSFT had a similar experience with HCL (I think it was them, one of the large Indian outsourcing firms in any case) when I was working on Vista. All fixes for bugs identified by static analyzers (PREfix/PREfast) were outsourced to contract programmers who had zero familiarity with the Windows source code. The “fixes” they sent back almost invariably introduced new bugs, and the whole back-and-forth process took much more time and effort (and presumably money) than just having the code owners fix the bugs in the first place.
Post reply on HN