I'd like to hope that this wasn't caused by ground crew error, i.e. an improperly secured cowling or access hatch, which snowballed into major component failure...
I'd like to hope that this wasn't caused by ground crew error, i.e. an improperly secured cowling or access hatch, which snowballed into major component failure...
Source: http://www.roger-wilco.net/wp-content/uploads/2010/11/Untitl...
Which is of course what happened in that linked incident below:
https://en.wikipedia.org/wiki/United_Airlines_Flight_232
The three hydraulic systems were separate, so that failure of any one of them would leave the crew with full control, but lines for all three systems shared the same narrow passage through the tail where the engine debris had penetrated, and thus control surfaces were inoperative.
A quick search for "A 380 hydraulic fuses" finds sources like http://www.airliners.net/forum/viewtopic.php?t=765509 :
> If one or both hydraulic systems fail, the following hydro-electrical backups remain available: For flight controls: The Electrical-Hydrostatic Actuators (EHAs) and the Electrical Backup Hydraulic Actuators (EBHAs) For braking and steering: The Local Electro-Hydraulic Generation System (LEHGS)"
That's depicted in the image bad_alloc showed.
And, "hopelessly intertwined"? Is that your viewpoint as a software developer, or are you an aircraft designer? Because I'm sure that an outsider would see my code as "hopelessly intertwined" even when it isn't.
Even with modern aircraft, even with the A380, when a fan lets go or the engine grenades bad things happen.
Qantas Flight 32, an A380, suffered a UCE and everyone was very lucky that there were additional, experienced pilots on board. Take a look at the ATSB report. Pretty much everything that could fail, did. Engine control for the #1 (IIRC) engine had been destroyed and it took the firefighters three hours to pump enough water to shut down the engine. Without the extra crew things could have gone very differently.
British Airways 2276, a 777 -- a plane that has an excellent safety record, suffered a UCE and the plane caught fire. Luckily the pilots were able to abort the takeoff, but fire on a plane is about the worst possible failure mode.
AA #383, a 767, also suffered a UCE on takeoff that resulted in a massive fire.
Cameroon Airlines Flight 786, same deal. UCE, punctured fuel tank, fire.
So, yes, things have almost certainly gotten better but given how much energy is released when a high bypass turbofan lets go, it's pretty damn hard to design something that's completely failsafe.
I'd hope so, given that all the redundancy didn't prevent an engine control failure on the A380.
As for Qantas Flight 32, which I believe is the engine control failure you are referring to, my reading of http://www.atsb.gov.au/media/4173625/ao-2010-089_final.pdf says that only one hydraulic system, Green, was damaged. The redundancy worked.
> Damage to the wiring also resulted in the loss of monitoring capability of the Yellow hydraulic system engine-driven pumps on the No. 4 engine and the crew disconnected both pumps as per the ECAM procedure. The Yellow hydraulic system was powered by the No. 3 engine for the remainder of the flight. The Yellow hydraulic system maintained 5,000 psi for the remainder of the flight and subsequent examination found no fluid loss.
The inability to shut down engine #1 was due to "[d]amage to wiring looms located in the left wing and the fuselage belly fairing."
Again I ask why "hopelessly intertwined" is a meaningful description for the A380 hydraulic control systems.
It isn't luck. It is the result of millions of engineering hours spent on the development of highly reliable and resilient passenger aircraft, an emphasis on public identification and dissemination of design weaknesses, errors, and failures, and an unwavering focus by industry regulators on safety.
This is a particularly egregious failure mode and very hard to contain, but also one which a lot of design hours have been spent mitigating. They were very lucky to have suffered (apparently, as far as has been reported) no significant damage of any kind, but even an extremely egregious uncontained engine failure is frequently flyable because of the emphasis on redundancy in modern plane designs.