I don't fly the 737, so I haven't read the aircraft specific books and systems overviews, but I expect this override behavior is very confusing in the MCAS scenario. Because any pilot would counteract a nose-down force by pulling on the yoke. The MCAS would then stop moving the trim, and the pilot would think (as would be true in any other situation) that the override worked. But MCAS didn't stop because of the override, it stops because it always does that after a few seconds and will re-activate 10 seconds later (or 20, didn't read a definitive number on this).
The confusing thing is that 95% of the unwanted trim movements are caused by the autopilot, so at this point the pilot would think the situation is under control and probably disconnect the autopilot if the movement didn't already,
The other 5% (or probably less) of unwanted trim movements are trim runaway, which is either a stuck switch (2 actually, you depress two switches at once to make it move, pressing 1 does nothing) or an electrical problem.
In both cases pulling back works and stops it. If it stays "stopped" you think autopilot and leave it disconnected. If it keeps moving continuously you think trim runaway and flip the trim cutout switches or pull the circuit breaker (this one is usually marked bright orange so you can find it quickly in planes without cutout switches)
But in the MCAS case, and without MCAS knowledge (which apparently nobody had) you would not expect it to start moving again later. You would have concluded "autopilot" of the above two scenarios, and after disconnect would think you're safe. So now when it starts moving again, your first idea is that the autopilot did not disconnect which leads to even more confusion in the cockpit.
The LionAir flight that was saved by the jumpseater got lucky in the sense that this guy was not flying, not debugging the autopilot, and did see the trim move because he has no instruments to scan and the trim is right in front of his face (in the middle between the two pilots). If you conclude that the issue is the trim, then any pilot would decide to go for the cut-out switches. It's just that concluding the trim is the issue, without knowing MCAS, under high pressure and with the wrong (autopilot) conclusion already on your mind is not very likely.
well this other crash was caused by a pilot puling up a plane all the way to its ceiling and stalling it, so there's that, so things can go wrong whether if you do and if you don't allow for easy control overrides.
https://en.wikipedia.org/wiki/Air_France_Flight_447#Third_in...
the trick seems to find the right balance to relinquish control only when appropriate, so it seems that proper documentation, checklists, training and maintenance are crucial.
instead looks like to have had deficiencies in all those elements, one way or another (except the checklist itself which wasn't followed).
AF 447 should never have happened. The copilot crashed the plane, and the pilot and pilot on break had no indication or feedback that he was holding the stick back (crashing the plane by causing a stall). There was no feedback, and the controls deferred to his inputs when the pilot was trying the opposite command (which would have saved the flight). On top of this, the stall warning buzzer was turning off when they were so deep into the stall that the airspeed dropped below a certain threshold, and every time the nose was pitched down and airspeed increased, the buzzer came on again.
Airbus has a controls feedback, stall buzzer parameters, and training problem. 447 should never have gone down.
Well, AF477 shows that sometimes you need it.
Source (in French): https://www.vanityfair.fr/actualites/articles/vol-af-447-rio...
I've never seen a reliable source for the claim that the two pilots at the controls were pushing the stick in opposite directions for any extended period of time. What's the primary source for this info?
AF 447 airspeeds were regularly below 60 kt. That's not a high airspeed stall. The final report is ~223 pages long, it's rather complicated to summarize, BEA blame practically everyone for something including weather, software, simulators, training, and pilots. As a pilot, some of the Airbus system behaviors in this case really piss me off to read, just how aggregiously badly designed it is when it gets confused, papered over by dumping the consequences of failed automation and the ensuing alternate laws onto the pilots. The pilots' job is system admin and troubleshooter. If they fail, they will be partly blaimed no matter what, because that's the job.
From the AF 447 final report: a) Both pilots were shocked by the autopilot disconnect. b) Reconnect of autopilot prior to 30 seconds of stabilized airspeed indication can result in pitch runaway and an unsafe condition. c) stall warning sounded continuously for 54s, neither pilot referenced the warning or stall buffeting. d) absence of any training, at high altitude, in manual aeroplane handling and in the procedure for ”Vol avec IAS douteuse” which you allude to. e) theoretical training for the pilots associated the buffet with stall and overspeed, even though in reality buffet is only encountered with stall. e) when there are no (software) protections left, the aeroplane no longer possesses positive longitudinal static stability even on approach to stall.
It's just crazy, only somehow partly neutralized by the statistical fact air travel is still really safe!
AF 447, last recorded values were a pitch attitude of 16.2 degrees nose-up, roll of 5.3 degrees to the left, a vertical speed of -10,912 ft/min, ground speed of 107 kt, and full power. And for the last 11 seconds "sink rate" and "pull up" warnings sounded. No emergency transmission sent (quite common).
That's only true for Airbus (and probably contributed to the loss of Air France 447, https://en.wikipedia.org/wiki/Air_France_Flight_447). In Boeing airplanes, the movement of the two yokes is synchronized.
So in case of two equally strong and equally determined pilots you still get averaging of opposing control inputs.
The failure mode is two pilots who are UNAWARE they are commanding contradicting inputs.
Airbus negligently averages these inputs. This is legacy tech debt because the physical design didn’t leave room to link the two controls.
Now they are stuck because they feel they can’t change and have some planes that (dangerously) average the inputs, and some that are physically linked.
When controls are physically linked, if one pilot thinks he should nose up, and the other tries to nose down, they can yell “what are you doing” at each other and this create an accurate mental model of what the other is intending.
Think of this every time you fly Airbus.
It’s very similar to debugging a production technology issue. Imagine you decide to restore the database to a snapshot from 1 hour ago, and at the same time someone else tries to restore to an earlier snapshot from 12 hours ago.
Should the system average these inputs and restore from 6.5 hours ago? No, obviously not.
Why? They're not falling out of the sky so the system obviously works. Stop being a fanboy.
This is a really weird way to construe the situation. The accident report doesn't conclude that the handling of dual inputs was a factor, and it's clear from the transcripts that it wasn't. Airbus has no reason to change this.
Merely linking sidesticks would be pointless in any case, since sidesticks don't have an identifiable position (but are used with brief movements away from center). It's hardly any easier for a pilot to passively observe the movements of his own sidestick than it is just to look over at the other pilot's stick.
Is there a case where the averaging of inputs has been proved catastrophic?
On an Airbus, in case of dual input the pilots get a voice alarm and a warning lights up right in front of them.
Also the stick has a switch to take priority, in case the other pilot continues to give dual input.
Source: https://www.vanityfair.fr/actualites/articles/vol-af-447-rio...
I'm not sure what you mean by "throttle up". They were at full TOGA thrust.
Neither Bonin nor Robert, nor the third crew member (Marc
Dubois, the captain) who entered the cockpit 90 seconds
into the episode, recognized that the aircraft had stalled
despite multiple cues. In the confusion, Bonin
misinterpreted the situation as meaning that the plane was
flying too fast and actually reduced the thrust and moved
to apply the speedbrakes – the opposite of what was
required to recover from the stall. Robert overruled him
and attempted to take control, but Bonin continued to try
and fly the plane. He and Robert made simultaneous and
contradictory inputs, without realizing that they were
doing so. By the time the crew worked out what was going
on, there was insufficient altitude left to recover, and
AF447 crashed into the ocean, with the loss of all 228
passengers and crew.
But I've had the stick back the whole time!
At last, Bonin tells the others the crucial fact whose
import he has so grievously failed to understand himself.
https://www.popularmechanics.com/flight/a3115/what-really-ha...Page 28: The right-seat co-pilot Bonin says "j’ai l’impression qu’on a une vitesse de fou non qu’est-ce que vous en pensez ? "(I feel like we're speeding like crazy, what do you think?")
Page 31: Same co-pilot "mais je suis à fond à cabrer depuis tout à l’heure " (But I've pulling back completely for a while), and this while the cockpit is screaming "Dual Input" (so this means that the other pilot was inputting as well, thus "unbeknownst" in my original comment).
Same page, right after, the captain says, "non non non ne remonte plus là" (No, no, no, don't pull back any further".
If you read the entire transcript, it's clear that there was persistent confusion as to who was in control, despite the dual-input warnings. AF447 is widely considered to be a failure in CRM, and a failure to recognize that they were in an aerodynamic stall (again, despite the warnings).
They didn't trust the plane with the information it was providing, which is probably why they ignored these warnings.
Perhaps you didn't notice this, but immediately after the point in the transcript you refer to, there's an exchange between the pilots where they establish who's in control (see "vas-y tu as les commandes" at 2 h 13 min 46,0). There is no way to be sure, but it seems probable that this exchange was prompted by the dual input warnings.
>They didn't trust the plane with the information it was providing, which is probably why they ignored these warnings.
There is no indication that they ignored the dual input warnings.
Linking the control sticks doesn't magically resolve problems caused by a breakdown in cockpit discipline. If both pilots are going for the controls at the same time, you're going to have problems. The warning system seems to have done its job, insofar as it prompted the pilots to figure out who was in control.
As for the dual input thing, there are 6 instances of the the warning. We can't really know what the pilots were thinking, but I believe page 31, from when Bonin says, "je suis à fond à..."... and then Robert à "attends moi j’ai des j’ai des commandes moi hein" a little later, "alors donne moi les commandes à moi les commandes", and 4 warnings Dual Input between them (in the space of about a minute and a half)...
I think it's fair to say that it wasn't super clear who was in control.
I'll make no comments about which system is better since I have no direct experience of flying in such environments (have only piloted small aircraft with mirrored controls, but with clear "Commande à droite/gauche" to establish PF, with my instructor). But à priori, I would imagine both systems work fine if used well.
I'll defer to a pilot to say whether they are mechanically linked -- it sounds like they are on Boeing aircraft but possibly not on Airbus?
Mistakes happen. Part of aviation safety is preventing that from becoming fatal.
That's not what the accident report concludes.
There's a clearly audible "dual input" alarm to prevent dual inputs. Dual control inputs only occurred for brief moments during the AF flight.
> As the plane approaches 10,000 feet, Robert tries to take back the controls, and pushes forward on the stick, but the plane is in "dual input" mode, and so the system averages his inputs with those of Bonin, who continues to pull back. The nose remains high.
02:13:40 (Robert) Remonte... remonte... remonte... remonte...
Climb... climb... climb... climb...
02:13:40 (Bonin) Mais je suis à fond à cabrer depuis tout à l'heure!
But I've had the stick back the whole time!
02:13:42 (Captain) Non, non, non... Ne remonte pas... non, non.
No, no, no... Don't climb... no, no.
02:13:43 (Robert) Alors descends... Alors, donne-moi les commandes... À moi les commandes!
Descend, then... Give me the controls... Give me the controls!
> Bonin yields the controls, and Robert finally puts the nose down. The plane begins to regain speed. But it is still descending at a precipitous angle. As they near 2000 feet, the aircraft's sensors detect the fast-approaching surface and trigger a new alarm. There is no time left to build up speed by pushing the plane's nose forward into a dive. At any rate, without warning his colleagues, Bonin once again takes back the controls and pulls his side stick all the way back.
The crash occurred less than a minute later.
https://www.bea.aero/docspa/2009/f-cp090601.en/pdf/f-cp09060...
https://www.bea.aero/docspa/2009/f-cp090601.en/pdf/annexe.01...
See in particular 2 h 13 min 39,7 and 2 h 13 min 40,6. Both of the pilots at the controls thought that they needed to climb. The captain realizes the mistake, but he's not at the controls, so linked sticks would have made zero difference to his perception of the situation. The accident report concludes that the stall was probably unrecoverable by this point anyway.
The official report does not identify the side sticks as a factor in the accident.
If you think you can do a better job of identifying the cause of the accident than the professionals who investigated it, you should explain clearly why.
With regard to dual input, it's clear from the transcript that the pilots noticed the dual input alarms.