The Challenge of Flying Below Sea Level
avgeekery.com
avgeekery.com
There's a phenomenon called mountain wave where strong winds at altitude get angled upward. When it's working right, a glider can point into the wind and ride it up like an elevator.
Some GPS units save you from running down the battery if you forget to turn them off by noticing you haven't moved in a while and shutting off automatically.
So you get into wave, point into the wind, ride the elevator up while motionless over the ground... and then, boop, your GPS shuts off because it thinks you're parked.
I suppose it's possible that the unit doesn't include an altimeter or doesn't account for altitude, but that seems odd.
Now, I know that this is impossible (no way the stall speed, even with full flaps, sensible AoA and near empty plane is lower than the wind speed at which the airport closes!) - but it definitely felt and looked as we simply gently dropped out of the sky, helicopter style.
The pilot suggested this was not uncommon practice when I asked him after we'd parked on the apron - fast, steady wind was what they encountered every day landing on these northern Norwegian islands.
GPS units that you actually rely on are built to a totally different standard (and price).
https://en.wikipedia.org/wiki/List_of_places_on_land_with_el...
Another thing to consider with modern avionics is this isn't a hand held Garmin or an iphone. There are two interesting military, and increasingly civilian, avionics features, GCAS ground collision avoidance system and TAWS terrain avoidance and warning system. GCAS theoretically engages the autopilot and pulls up if the plane is about to hit what it thinks is the ground. GCAS has already saved at least one F16 pilot's life, probably more by now. TAWS is about the same concept but rather than "don't hit the ground" its "don't hit the radio tower in front of you" which is somewhat more complicated to calculate both the danger and how to safely avoid it. Either GCAS or TAWS might have freaked out and "fail safe" design means you're better off shutting off or dumping into a reboot loop than letting something detected to be freaked out take over the plane. I specifically listed "or" because nothing fires off a fail safe quite like having GCAS report all is chill and calm while TCAS vehemently disagrees (or vice versa). I am a little unclear in avionics in general what happens when a GCAS and TCAS disagree. I guess TCAS only avoids obstacles by turning or climbing whereas GCAS only avoids obstacles by climbing (obviously?) so as long as they both implement that protocol they should never disagree. Unless there's a bug in only one of them below 400 feet.
Finally the verbal description of the problem indicates the nav gear failed after reboot but operated fine until reboot. My guess is the GPS firmware itself might have an "issue" in its acquisition firmware where obviously all positions below sea level are categorically unable to be accurate during acquisition mode so you can toss out any interim solution and keep acquiring if you find an altitude below -400 feet (see first paragraph). Or the GCAS or TAWS do the finite low pass input filter thing over multiple location data points where the last 60 seconds of flight data show a smooth descent to -1400 feet or whatever so thats perfectly fine because the boot up self test is not running while the system is booted, but on boot up during self test the input data filter having an output of -1400 is "obviously" a software bug so keep on rebooting until the input data filter has a reasonable value.
In the source of the Apple-published program, there's a comment that it was based on an earlier program from MECC* (you might remember them as the creators of Oregon Trail). That program goes back to 1973.
Perhaps that version didn't check the input.
* https://web.archive.org/web/20130226024448/http://theodor.la...
It's all too easy for designers to consider input constraints that (a) don't actually improve the user experience, and (b) don't actually make the downstream part of the system more robust.
If the user's signature is a chicken scratch and the GPS is reporting a trusted, verified altitude of -750 feet, who cares?
Ah, altitude. I'll use an unsigned long.
"GPS operates in a well-de - fined set of coordinate systems, and all performance standard definitions assume their usage. The satellite position and geometric range computations must be accomplished in the World Geo - detic Survey 1984 (WGS-84) Earth-Centered, Earth-Fixed (ECEF) coordinate system."
Later tables say that the ephemeris (not the user position) is broadcast in units of 2^-29 radians. Other bits of the table use "2^-31 semi-circles" - effectively a custom coordinate system that spreads the 2^32 bits evenly around a circle.
I hope that's actually down to :)
I don't know why it might handle some negative numbers but not others. Maybe there's an overflow somewhere?
Orders a beer. Orders 0 beers. Orders 999999999 beers. Orders a lizard. Orders -1 beers. Orders a sfdeljknesv.
Hug your QA engineers, they save you from eternal embarrassment.
If you are attacking with the intent of stealing information it would likely better to use the database injection as the foundation for multiple pivots into other systems that would presumably have more valuable stuff than a list of people who bought a beer and or their credit card numbers.
The bar gets flooded by the contents of hundreds of broken bottles.
Beer delivered, but at the center of the bar, not to the customer.
> Orders 0 beers.
> Orders 999999999 beers.
Bar room fills up with beer, drowning everyone.
> Orders a lizard.
Bartender yells gibberish at customer.
> Orders -1 beers.
Keg explodes in taproom.
> Orders a sfdeljknesv.
Bartender complements customer on their fine taste in Hungarian beer.
From what I've read: if this happened at all, it was in the simulator.
They ended up visually following their tankers back to Hawaii.