Preliminary conclusion MCAS misfired in Ethiopian's 737 max crash
cnbc.com
cnbc.com
Think of an analogy: when the autopilot commands a nose-down elevator input, and the pilot pulls back on the control column, that's enough to disengage the autopilot.
Or think of cruise control in a car: if the computer commands acceleration, and the driver steps on the brake, cruise control disengages.
The necessity of MCAS is to meet regulatory requirements for similarity in handling characteristics to achieve a common type rating. It's not strictly an engineering requirement, nor is it a safety-assisting technology. It's an attempt to mask the actual aerodynamic characteristics of the aircraft being flown. That is a conflicting mission if you will.
It does. It's just that MCAS tries again in 5 seconds. That's why the experienced pilots in both the Lion Air and Ethiopian crashes kept the MCAS in check - trimming to neutral column force is second nature to them - and it only crashed when the first officers took over, who allowed it to get to full nose down trim.
A constantly incorrectly trimming system is supposed to trigger the runaway stabilizer trim checklist, so Boeing thought a failure in this system was covered by existing training. Unfortunately, a periodic every-5-seconds trim wasn't recognized as such. I'm not a 737 pilot, so I don't know what runaway stab trim normally looks like; maybe it's usually constant?
Yes, exactly.
The problem (well, one of the problems) is that during normal operations the trim wheels are constantly moving intermittently, so additional intermittent motion isn't immediately seen as unusual.
(Disclaimer: I am not a 737 pilot either, but I am a pilot, I fly a plane with an electric trim (Cirrus SR22) and the info above came from a very experienced 737 pilot named Juan Browne who hosts an excellent channel on YouTube called Blancolirio.)
1. MCAS failure produces an intermittent stab trim movement.
2. Boeing claimed that the stab trim runaway checklist should have been run and would have let the crew recover.
3. Boeing's checklist only calls for action on "continuous" uncommanded stab trim movement https://www.satcom.guru/2019/03/taking-next-steps-while-awai... (second image)
4. Intermittent uncommanded stab trim movement is normal. The Speed Trim System and Elevator Feel Shift system regularly adjust trim, so merely seeing the wheels move by themselves is not cause for alarm.
5. MCAS is not documented at all in the flight manual, and the stab trim runaway checklist was not updated to address how MCAS might cause a failure necessitating its use, presumably to avoid the need for additional transition training.
6. MCAS is unreliable due to its reliance on a single AoA sensor.
From what I understand it did but it would reengage again. It's the reason why the Lion Air flight lasted longer in the air than Ethiopian, because the pilots in that case kept hitting the trim and buying themselves 40-60 seconds each time
Pilots use the term "ahead of the plane" to describe being in a state where they understand exactly how a plane and its systems will respond to inputs (including theirs). MCAS (and lack of training) resulted in pilots being "behind the plane", which meant they could not regain control over the plane and ultimately crashed.
Here’s some discussion about this from 2009: https://www.airliners.net/forum/viewtopic.php?t=761011
Even if the cause is an MCAS failure, the way that failure presents in the cockpit follows the same procedures as runaway trim: which means to me that the Ethiopian and Lion Air pilots were simply under-trained. The 200 total hours of the Ethiopian first officer supports that assertion. In the US, a first officer has a 1500 hour requirement: having a 200 hour pilot in the cockpit can’t be ignored as a contributing cause especially since following the standard checklists would have saved the plane— if the first officer would have known to consult those checklists. In the US, you can’t even fly Cessnas commercially with 200 hours and this first officer was copiloting a modern 737.
I thought the problem here was that it doesn't appear the same.
To be fair, it's not clear that the time someone would spend flying a Cessna between their 200-1500 hours in the US is actually helping them become a better 737 first officer..
Ah yes implying those weird "African" airlines cannot compare to the supreme training of the US ones. You closet racism is pretty self evident.
When driver steps on the brakes -- the system disengages and car slows down.
When pilot disables MCAS -- the system disengages and the plane is more likely to enter aerodynamic stall and crash.
So with cruise control there is no potential for catastrophic positive feedback loop when the system disengages, whereas MCAS needs to be pretty aggressive in what it does.
The problem with articles thus far: there's a lot of confusion whether MCAS exists to meet a FAR 25 requirement (aircraft airworthiness for transport category aircraft)[1], or FAR 61 requirement (pilot certification and ratings)[2].
I still don't know the answer to that, but either way it seems problematic to have an ostensibly required function that can be disabled and either have an instantly decertified (not airworthy) airplane, or an instantly decertified (not type rated) pilot, or both.
[1] There's are many behavioral requirements in FAR 25, I'm cherry picking two:
§ 25.203 Stall characteristics. (my emphasis on paragraph a.)
https://www.law.cornell.edu/cfr/text/14/25.203
§ 25.173 Static longitudinal stability. (my emphasis on paragraph c. and d.)
https://www.law.cornell.edu/cfr/text/14/25.173
[2] The pilot must have a type rating, 61.31 a(3) for aircraft the FAA says must have a type certificate
https://www.law.cornell.edu/cfr/text/14/61.31
which then points to this section which has all kinds of ins and outs
Why wouldn't you design it that way from the beginning? This isn't Boeing's first plane.
Outstanding Max order backlog is $600 billion at list price. That is what matters.
> Outstanding Max order backlog is $600 billion at list price. That is what matters.
So at 600 billion in orders they got greedy and didn't want to spend 1M extra per plane to make it safe.
But I guess Ethiopian/Indonesian cries for some sort of compensation/justice would have to go very viral in western media to force a corporation like Boeing into anything (since it is also a clear admission its purely their fault, which it seems to be).
With lots of of passengers on both flights being from lots of different countries, what they're getting instead is lots and lots and lots of individual lawsuits all being filed in different jurisdictions.
Which is, I'm guessing, likely to be more damaging to them in the long run.
MH370 was a multi-national class-action lawsuit filed in SC that was only dismissed because the circumstances of the disappearance were not clear and nothing to do with it being multi-national
https://www.documentcloud.org/documents/3512628-16319045179....
With the Lion Air crash the settlements the Indonesian government had passengers sign included waiving any right to sue Boeing in the USA
https://www.nytimes.com/2019/03/21/world/asia/lion-air-crash...
The fault being with Boeing in this case seems a lot more clear-cut
There is a tendency to fixate on the bug that caused a crash to the extent that you introduce new more new bugs than you had before.
These things are essentially just wind vanes that read the direction that the air is moving past them.
Short of the plane flying obliquely into a tornado, I can't think of any atmospheric effect that could lead to a disagreement.
You'd need an atmospheric effect that causes a significant difference in wind direction between two points that are maybe 3 m apart and the difference that atmospheric effect is trying to cause would have to be noticeable when superimposed on the wind vector due to the plane's velocity.
Exactly this. It can't be both required for safe flight and disabled at a moments notice during the most dangerous portion of a flight (takeoff).
Plenty of normal flights fly manually for a significant portion of the climb-out after takeoff, which is exactly the portion of the flight when MCAS issues happened for the Lion Air and Ethiopian Air flights.
Also, you will have higher AoA in a bank, which can be encountered in manual flight on normal flights.
Nobody said there was anything abnormal about the two flights that crashed. It really doesn't matter since the root problem is the plane doing things without telling anyone and then doing it wrongly. Without MCAS these accidents would not have happened.
Without MCAS, wouldn't there be accidents caused by the nonlinear pitch though?
Not sure this is right. General aviation pilots often think of wing stalls as a consequence of low speed (their planes don't have AoA indicators!) but they can happen at any airspeed: they simply happen whenever the critical AoA is reached.
I think the idea is that the extra lift generated by the nacelles due to the engine position causes the plane to reach high AoA at e.g. full engine power, not just when flying slowly.
I think it's also the case that the plane does not actually become aerodynamically unstable, it just starts to handle differently (yoke pressure-wise) in a way that fails airworthiness requirements.
So it would only cause a stall if the pilots continued to pull back on the yoke into the stall while it's not fighting them as much as they're expecting it to.
What is your source? This is not what I have been reading. What I have been reading is that the MAX has a bigger engine and this engine has been positioned forward on the wing in order to preserve ground clearance. As a result of this unusual engine position, the MAX has a tendency to pitch up during acceleration. Nowhere did I read that this doesn't happen during normal flights.
Yes, but not what you may be thinking. The AoA is the angle of the wing vs relative wind (the angle the wing is attacking the air). You can have high relative pitch (attitude) to the horizon but a low AoA, such as during climb. That same attitude is a full stall at slower speeds/power.
The wing doesn't care where the nose points. All it cares about is its relative angle to the wind. Once it diverges past a critical angle the wing stalls.
What appears to have happened with these MCAS issues is that the MCAS senses that the AoA is too high when it's completely normal and safe, so it auto-trims down.
The nose can be pointed up with a low angle of attack (e.g. a climb during cruise) and conversely the aircraft can be pitched down with a high angle of attack (e.g. descent approach with flaps extended)
This is true for climb and cruise, but not necessarily true for a bank.
MCAS compensates this by trimming elevators. Without MCAS, it is up to the pilot to handle the unstable system.
It’s obvious that the code was executed during the regular flight conditions which means it has to be applied even then.
The motors simply push the plane nose up too much compared to the previous models, threating the plane to enter the stall. Once in the stall the plane is just not controllable. MCAS was there to hide that.
And now that the problem is known to the world either will Boeing provide the proper solution, no matter the cost, or there will be a third crash and that will be too much. Boring still tries to present all that as “business as usual.” It’s wrong.
I am not saying that Boeing did not try to cut corners (I just do not know), but the current media circus painting Boeing as a bunch of [idiot engineers | greedy execs | lazy testers] is likely far from reality or at least a major oversimplification. Boeing planes (including 737 max) are still very safe (compare to cars). Mistakes should be calmly assessed and fixed and making a public circus of this simply pushes engineers to avoid everything but uber-conservative, uber-safe solutions, which has major costs in itself. My 2c.
Instead they wasted time and resources to smear the airline and the pilots.
And that's inexcusable.
At least until the cause is known.
Edit : Some clarification
When MCAS was established to be a likely factor in the first crash, Boeing issued an emergency airworthiness directive to all operators of the 737 Max, alerting pilots to the possibility of undesired nose down trim, and reminding them that the runaway trim procedure would disable it.
When it comes to mass transport, safety should definitely have higher priority than pushing some potentially new cool tech ASAP (which is debatable, making plane unstable ain't cool by any measure)
No simulator time required, no sire!
This is significantly different to the Lion air incident where you can easily give the pilots the benefit of the doubt because the failure mode hadn't been previously identified. The details of MCAS and the procedure to handle it was communicated to all operators months before this accident.
All of those are “above the line, memory items” which the crew must be able to recall and execute prior to referencing the checklists in the QRH.
Boeing has some significant fault here, but I’d expect a full performance crew to handle this emergency and suspect the CVR and FDR data will show them in a less than fully flattering light, especially after Lion Air, the emergency AD, safety memos, and general publicity surrounding the previous crash.
Has the information disclosed to pilots after the LyonAir incident been made public?
What I have gathered from reading other forums about this, many pilots say they would interpret any significant undesired trim as a runaway condition, regardless of whether it was happening in intervals or it was literally continuous.
Others say that depending on training, and the policies of the operator, a much more literal reading of procedures is enforced.
I don't fly, but apparently trim is a very fundamental control for a pilot. It's easy to recognize when the aircraft is out of trim, and reacting to it is about as natural as it is for a driver of a car to use the steering wheel to keep the car centered in a lane.
So my assumption is, that with the AoA disagreement, and resulting multiple alerts and chaos in the cockpit, the pilots lost awareness of what the trim was doing.
I'm wondering if there's not a deeper problem within the air data systems. Why are the AoA sensors on new aircraft failing? They are just simple vanes, normally very reliable. The same ones are used on many different aircraft. So I don't think the actual sensor is a problem. But maybe there's something different downstream of the sensor itself. I would think if there were persistent problems with bad AoA data in 737s generally, it would have been addressed. Because the stick shakers, unreliable air speed, and everything else would still be happening regardless of MCAS.
This is a very good point. If the AoA sensor failed say climbing through cloud at 5000ft on auto-pilot, dropping control of the aircraft to a pilot who's busy thinking about what he's going to have for lunch, with half a dozen alerts going off, an AF447 type incident could easily happen MCAS or no MCAS.
If I've read correctly, the former only temporarily disengages MCAS. The pilots may have repeatedly hit the button on the stick, but then 20s later, MCAS re-engages and sends the plane nose down again.
I agree that the procedure calls for flipping the switch on the panel. But, not sure that's actually what the pilots were doing.
In the image below, you can see the electric trim control on the stick in the left portion, and the manual trim cut-out switch on the panel in the top right.
https://theaircurrent.com/wp-content/uploads/2018/11/737-max...
When this situation happens, five things happen at once. MASTER CAUTION (whoop, whoop noises and a big red light!), ALT DISAGREE alert on the MFD, Incorrect Airspeed on the MFD, the stick shaker goes off, and by the way, if you take the time to look down at the throttle section of the dashboard with all those other alerts going off, you'd see that there is suddenly a lot of trim on the APL trim indicator but the trim wheel doesn't actually move (which would provide an audible 'click click click' that would probably trigger that there was a problem with trim.
Each of those things has a separate memory checklist that you have to run down, and subtract ten seconds to register them, prioritize, communicate with the other pilot, and start executing them.
The worst part here is that they've added another alert and then changed how the airplane will fly in the middle of an emergency. While the extra alert narrows down the number of branches from the "prioritization" part of the checklist, I'm not sure that's "fixing" the problem.
I appreciate your point about all of the alerts going off however the pilot is manually flying the aircraft at this point, they should feel that something is going on through the controls and react to that firstly. Imagine having a blow-out in a fancy car with pressure sensors, sure lots of alerts are going off but you have probably not registered that because keeping the car going in a straight line is taking 100% of your attention.
Otherwise, yes I agree. A lot of stuff probably went crazy in a short time for them.
In all those cases, your reaction is the same and instinctive regardless of whether or not you know the root cause.
Flying an airplane manually on instruments, the pilot sees the airplane undershooting the pitch target and pulls back on the control column every bit as naturally as the car driver above. When the pitch target is correct and the control force high, use the stab trim to take the force away. This is every bit as much a continual process as the driver lane keeping.
If MCAS is trimming against you every time you let go of the trim, you get feedback that this is likely a trim issue. Keep flying the airplane and trimming as needed.
This is not a case where the airplane automation fails and an airplane suddenly gets “dumped” onto a pilot who has to regain control and figure things out.
It’s obvious that the time and space available was not enough for that Lion Air or that Ethiopian Air flight, so you have real world evidence to support your point. I acknowledge that fact, of course.
http://www.b737.org.uk/images/throttlequadrant.jpg
See the scale with "APL NOSE UP" and "APL NOSE DOWN" next to the trim wheels.
Whether the pilots noticed it (or the attitude indicator pointing nose-down, or the rapidly decreasing altimeter...) is the question.
https://www.flightradar24.com/blog/wp-content/uploads/2018/1...
I've put the relevant figure showing the trim adjustments here:
Think professional developers (granted the bar is infinitely lower). You would assume no one would introduce a SQL injection vulnerability in new code given all we know and all that happened. Well...
Also some commercial pilot on HN provided another element of answer. When you are in an emergency situation, you don't have the time to sit back and think, you revert to experience, muscle memory and training. Even if it may have crossed these guys mind that it was the same problem than Lion air, they may not necessarily know the procedure to fix it while trying to keep the plane from crashing at the same time.
Just speculating.
- unreliable airspeed warning
- stick shaker (=stall is imminent)
So you don't know your airspeed (otherwise you can conclude you're safe for your current pitch and vertical speed) and a stall warning. The last thing you do is to look for horizontal trim.
You can see them in the Lion Air preliminary report linked above.
Pilots are trained to deal with partial panel situations. The mantra is pitch + power = performance. In VMC this should be well within the capibilities of a normal pilot, put the nose on the horizon and set something like 65% power.
Not true. From what I have read, MCAS runs in 10 second intervals, with the amount of trim added increasing with each successive run. Once the trim has reached a certain point, it over-powers the amount of control the pilot has by putting pressure on the yoke (this controls elevators, which have less overall influence on the aircraft than the trim at full bore).
We know that the pilots on the previous flight with the 3rd deadheading pilot were attempting to right the plane using yoke pressure, and at one point the first officer mentioned that the yoke was "too heavy to hold back". That indicates that MCAS had pushed the trim past the point at which the pilots could physically overcome it's influence using the elevators. (source here: https://www.reuters.com/article/us-ethiopia-airplane-regulat...)
For some reason before the crash the pattern of repeatedly correcting changes, possibly because he handed control to the first officer.
It specifically noted that at speeds greater than 230 knots (265mph, 425kph) with flaps retracted, pilots might have to use the wheel in the cockpit’s center console rather than an electric thumb switch on the control yoke. "
So, yes and no. It gives SOME control over the trim, but if the trim keeps getting bumpped progressively higher by the MCAS, it will eventually outstrip the yoke control.
My guess is that that change you mentioned is the threshold at which their yoke trim control became insufficient.
They are saying there that near Vmo (maximum operating speed) with an aft centre of gravity (the aircraft loaded in a specific way) there might not be enough nose down trim authority available within the limits of the electric trim to completely trim the aircraft (allow the pilot to relax the forward pressure on the yoke).
In the crashes there was too much nose down trim and MCAS kept adding it more. They are trying to move it in the other direction.
Pants reporting but nothing to see here.
> there might not be enough nose down trim
After reading it, I'm not sure how you are gathering that it's only nose down trim. It only mentions an inability to completely set the trim longitudinally. Longitudinal doesn't mean in one direction. It only indicates which plane we are talking about, which in this case is pitch.
> Vmo (maximum operating speed) with an aft centre of gravity (the aircraft loaded in a specific way)
"The aisle stand trim switches can be used to trim the airplane throughout the flight envelope and fully complies with the reference regulation Simulation has demonstrated that the thumb switch trim does not have enough authority to completely trim the aircraft longitudinally in certain corners of the flight envelope, e.g. gear up/flaps up, aft center of gravity, near Vmo/Mmo corner, and gear down/flaps up, at speeds above 230 kts"
The issue mentions that there are certain corners, and lists what you posted after e.g. That isn't the only corner case in which the yoke trim control becomes insufficient.
Further, the section on EUSA's position clarifies that they wanted to improve the margin of safety on an out of trim dive, this is where 3 seconds of nose down trim (incidentally, that's how long they expect it to take for a mediocre pilot to identify a trim runaway) are applied without pilot intervention and the pilot has to demonstrate controllability.
But that point is pretty moot because the electronic trim cannot drive the jackscrew to the extremes that the manual trim wheel can, but it can return from the extremes to the centre. MCAS is driving trim to the nose-down extreme and the pilot is trying to return it to neutral.
Introducing a new condition of "We think MCAS is on, but we're not quite sure / it's cutting in and out due to censor disagreements" is preposterous.
Modern aircraft have many automatic systems that are there to make the pilot's job easier. That doesn't mean they are unsafe to fly if those systems malfunction and have to be disabled.
It's definitely a safety feature that's required and not an assistive device. It was required for certification, and in fact as originally specified was unsuitable to prevent stalls, so Boeing had to increase the authority of the system to make it functional.
The necessity of MCAS means the airframe has fatal flaws.
I would avoid 737 Max by all means, no matter whatever software revisions Boeing releases.
Previous discussions:
they'll eventually get this right - they just need to step back and recognise that the MAX is a completely new type of aircraft and stop taking shortcuts on certification and training
what saves them is that Airbus is at production capacity on the neo
The main reason they are unstable is to increase agility. Is this necessary or even wanted in passenger aviation? I don't know but I'd guess not. Probably safety, comfort and fuel economy are far more important and can (should?) be achieved with a stable airframe.
fuel efficiency in these modern aircraft has been gained with swept back wings, larger intake engines etc. which with direct control and no software would be almost impossible to keep flying
discarding all of these systems because of a problem with one would set airline safety and efficiency back decades
The fly-by-wire system has multiple redundancies and layered protection, including direct law (at least for Airbus). Fly by wire is, like you say, of course a great innovation for improved control and safety, but it's nice when the plane continues flying even during a failure, however unlikely.
I guess in the case of MCAS the software was activity working against the pilots so maybe it's more of a problem with the design of this particular system and training.
A well designed aircraft should not have a single point of failure, including the software.
There's no benefit in developing and certifying software that just passes raw pilot commands to actuators.
Boeing made a plane that conformed to all rules and regulations. As part of the design process, they made many, many tradeoff's. What kind of fastener goes on this panel? How often does this data go across the data bus? What material is used for this cable? Literally thousands of them. Not every one , by itself is safety critical; but many of them can turn out to be.
The MCAS design was not some engineer skirting the law, or wanting to kill people, or even disinterested in safety. It was a compromise design of cost vs safety; in hindsight it looks like the compromise was done poorly.
A 100% safe airplane weighs too much to fly and costs too much to build. This means every design decision has to take into account other things than just 'raw safety'.
They made a mistake. Even when you are not "moving fast and breaking things", people make mistakes. process adherence misses the mistake.
And in this case people die. Unfortunately, that is how we improve aviation safety. With the blood of passengers and crew. Not on purpose, not because boeing is greedy, but because people make mistakes, systems fail, airplanes crash. This was not a single failure of the aviation safety system. N things had to happen for these crashes. And the system is going to fix each one of them, and do a humans best effort to change the process so it does not happen again.
i would fly a Boeing aircraft tomorrow (yes, a 737 MAX 8). Or an Airbus. They are both built and overseen by the best our world has to offer.
This is not the first design failure that has been the cause of an incident (or even a series of incidents) and it will not be the last.
Boeing deserves to go out of business for this.
Similarly, I'd like any plane I'm flying in to have a fully qualified pilot AND copilot, and I don't consider 200 hours of total flight experience to be 'fully qualified'.
Joke aside, let's be fair, Boeing did not sell air. Their greed got the better of them, and the institutions set to prevent that did not do their job. They should take responsibility for the things they did (or in this case, did not). There is no penalty high enough to bring back lives.
Perhaps my sense of humor is broken but I find the fact that jest was even made quite alarming. I'm used to playing word games, and taking refuge in audacity...but damn.
So you want to turn the company over to the same governmental body that lets companies get off by firing a few middle managers? The same body that possibly allowed this lapse in safety to get through regulations in the first place?
https://www.google.com/search?q=Investigators+Believe+Boeing...