Story of QF72: What happens when 'psycho' automation leaves pilots powerless?
smh.com.au
smh.com.au
Either the article is wrong on some crucial facts about the event, or the Airbus spokesman's statement quoted above is a complacent, self-serving and presumably deliberate misrepresentation of what happened. If the article is to be believed, the rogue system prevented the pilots from making command inputs, and only stopped doing so because it crashed before the airplane did.
While Airbus design philosophy is that pilots should be able to take over at all times may be true, pilots should be able to take over at all times was not true in that particular design/implementation.
The report also reveals that a "design limitation" in the flight control primary computer's algorithm failed to handle multiple spikes in the angle-of-attack data.'
A design limitation implemented in a software algorithm, didn't that used to be known as a software bug?
"Although there were many injuries on the 7 October 2008 flight, it is very unlikely that the FCPC design limitation could have been associated with a more adverse outcome. Accordingly, the occurrence fitted the classification of a ‘hazardous’ effect rather than a ‘catastrophic’ effect as described by the relevant certification requirements.
Really? The pilots were certainly worried about a "more adverse outcome" if it recurred near the ground.
This statement is followed by an apparent justification:
"As the occurrence was the only known case of the design limitation affecting an aircraft’s flightpath in over 28 million flight hours on A330/A340 aircraft, the limitation was within the acceptable probability range defined in the certification requirements for a hazardous effect.
This non-sequitur seems to say that because such faults don't happen very often, such events are merely hazardous (unless they mean even the occasional total loss of an airplane and all aboard does not count as catastrophic.) This is followed by an enumeration of quality-assurance practices, as if they argued for this event not having happened.
I guess I will have to read the whole report to find out why this failure in a triply-redundant system does not raise deep concerns about its architecture.
The report says "Flight simulations also showed that an undesired pitch-down just above 500 ft would be easily recoverable by a flight crew." It does not say if that was two events in close succession, or whether the crew were primed for the test.