Just like when we test software, they want to have everything as close to what they would expect on launch day as possible (2 days from now). All the stresses, the structure, etc. That means putting stage 2 and the payload on top of the main rocket before the test starts. They probably did a lot of tests before the payload was on board as well, and those didn't reveal whatever flaw has caused this issue.
Yes, it sucks that the payload was lost but there will have been insurance to cover the loss. No human lives lost, no cruise missile scenario, no out of control fire... this is the best case scenario for a rocket failure.
A rocket straying off course could either smash into city under full power (thus being a cruise missile) or have its propulsion cut off remotely beforehand (thus being a ballistic missile), depending on a scenario. What kind of a correction were you making?
In that case the rocket has a flight-termination system, though, which should activate as soon as it veers too far outside the planned/expected parameters of the flight.
The cruise missile scenario is highly unlikely as the rocket itself would be destroyed soon after leaving its intended trajectory.
https://en.wikipedia.org/wiki/Intelsat_708
(China, CZ-3B, Intelsat 708 payload, the launcher flew off-course and crashed on a village in 1996: by some estimates 200-500 civilians were killed.)
> Like Russian vehicles, there is no flight termination system that receives ground commands onboard Chinese launch vehicles. Only US and ESA launch sites have such a system. Correction, Falcon 1 did not have such a system for launching on Kwaj.
The launch pad at the Kennedy Space Center/CC is effectively about 50 mile from downtown Orlando, Baikonur is in the middle of nowhere.
An unpredictable, malfunctioning rocket could still million-to-one itself onto a school bus filled with children, halfway across a continent.
The text I quoted implies there is an onboard flight termination system, even if there is no Range Safety Officer who can send external commands.
FWIW, a part from an exploded rocket, like the engine, could still destroy a school bus filled with children. The odds are very hard to estimate, and made more complicated in that there are few failure modes where a rocket failure halfway across a continent, at supersonic speeds, would reach the ground without breaking long before.
There will still be debris, of course, but I guess the reasoning is that it's preferable to have relatively small debris, than one large piece of exploding debris.
Two important roles of flight termination are: 1. Cause the rocket to stop thrusting (and thus prevent it from thrusting out of range safety exclusion zone). 2. Cause the propellant tanks to be destroyed. This prevents the propellants from causing a large explosion on the ground (when the tanks hit the ground) in preference to a conflagration in the air.
But of all systems I never want to have to test in production, the flight-termination system is at the top of my list.
http://www.esa.int/esapub/bulletin/bullet87/cavall87.htm
But yes, Cluster was run on the cheap, hence the use of the Ariane 5 test flight, and didn't have insurance.
The board argues that there was a bias towards believing the software does not have an error. Thus, any out-of-range value is interpreted as a hardware error, which means the CPU should shut down.
There was a decision to not include Ariane 5 trajectory data in the SRI requirements and specification. Thus, while tests were rigorous at the equipment ("unit") level, and there were system tests, they didn't test that case. This is test design failure.
In addition, the board says "the review process was a contributory factor in the failure."
I can see how those can be aspects of "over-reliance on unit testing", but it doesn't explain, for example, how some of the variables from Ariane 4 were protected from overflow exceptions but others were not.
Lots of things had to go wrong to cause the Ariane 5 failure - including bad handling of overflow, as you mention. But to my mind, the universal last line of defence against any kind of mistake is an integration test: put all of the parts of the system together, feed them real input, and verify that you get correct output. Arianespace did not do that.
Well, until they actually launched it. It was a test flight, right? It proved to be an essential and very effective test.
Everything is incredibly obvious in hindsight, of course, but making things obvious is largely what hindsight is for.
And once you've finished reading that, go look up the Therac-25...
This is a big plot point in the "Twin Spica" series.
There's a lot of testing, both in isolation and in integration with other components. The risk of the rocket exploding should actually reduce with each test. Note also that in this case the malfunction was most likely with the pad equipment, not the rocket, so not doing static fires would in this case probably just have meant that you'd have an explosion at launch time one day.
EDIT: The static fire is more of a test for launch procedures, apparently:
“The goal of the static fire is to provide a dress rehearsal for the launch team, culminating in a three second firing of all nine of the first stage Merlin 1D engines to validate the health of the rocket.” (https://www.nasaspaceflight.com/2016/09/falcon-9-explodes-am...)
Makes sense in that the rocket itself is tested quite a bit beforehand already.
Facilities and other things on the pad may not like it, though.
They already said that their Horizontal Integration Facility (where the rocket is put together prior to erection) is intact, as are the tanks on site. But the strongback looks mangled and may well be destroyed. It's also right beside the rocket, so the most likely casualty in such an explosion. Other pads and facilities are most likely far enough away that the only concern is debris from the explosion landing there.
The energy released in the first few seconds of a controlled launch is not remotely comparable to the energy released by an entire rocket blowing up simultaneously. Also, with an explosion, the entire rocket, along with parts of the strongback and other structures it's attached to, become shrapnel. Superheated water exhaust is a lot easier to protect against.
The tower features - the hold-down arms, etc - are painted with a sacrificial paint. The idea is that it's the paint that chars and burns, rather than the tower features.
Then there's the water deluge system.
In the video, the rocket and exhaust is clear of the tower, and the fires are out, within 30 seconds. Neither the sacrificial paint nor the water deluge are designed to handle long-duration fires from a RUD.
After a 2014 Antares rocket failure, the launchpad at Wallops Flight Facility took 1 year and $15 million to repair [1].
[1] http://www.space.com/31412-virginia-launchpad-private-rocket...
https://spaceflightnow.com/2015/10/06/workers-complete-15-mi...
If you get interest in this stuff, the HBO miniseries "From the Earth to the Moon" has an episode about Apollo1 (and the series as a whole, though slightly dated on the FX side, is amazing).
[1] http://money.cnn.com/2016/08/30/technology/spacex-rocket-reu...
Of course normally a failure during a test would be something like minor thrust fluctuations - not a complete loss of vehicle and payload!