I would really hope that airplanes are a place where "dirty hacks" are unacceptable.
This doesn't mean they are 100% flawless, but any known potential problem areas should be well-documented and accounted for.
I would really hope that airplanes are a place where "dirty hacks" are unacceptable.
This doesn't mean they are 100% flawless, but any known potential problem areas should be well-documented and accounted for.
The device has been performing admirably (as far as I know) for over 12 years in the field with no issues due to those few lines of code.
Hacks are everywhere in engineering. As long as the analysis behind it is rigorous and the hack is provably correct, I'm OK with it.
You understood exactly what was going on and were wholly confident it would be reliable. And more to the point, you wouldn't have counted it as a mark against the product's reliability.
A hack could be completely reliable (for the same hardware, library versions, and compiler), but still be a "dirty hack". And whether a hack is "dirty" is very subjective and, IMO, based more on how obvious the fix is (e.g. radians -> degrees -> function -> back to radians because the library documentation is wrong is less bad than a non-obvious hack like multiplying by 1 or something to avoid a compiler codegen bug because of a hardware bug).
I think this horse has been thoroughly beaten, so I'll leave it here.
https://www.latimes.com/local/california/la-fi-boeing-max-de...
The airframe should be retired and they should make a new one. To push this, the FAA and other certifying bodies should treat the plane as an all-new plane with no commonality with previous 737 planes, requiring all new training for pilots and a complete, new certification process for the plane, just as if it had been a clean-sheet new design.
Airbus pilots can't safely fly their jets at cruising speed without software (envelope protection, etc) assisting them. Air France 447 crashed, killing 228 people, when that software became disabled due to bad values from frozen sensors. The pilot flying thought the software would save him from stalling but that protection was disabled, so he crashed into the ocean.
So does that mean it's a bad idea to make flight software safety critical? Probably not.
It probably just means that safety critical software must be extremely good. MCAS v1 was not good software but if MCAS v2 is good software then it could might function safely for decades. And, if MCAS v1 had been good, it would have been lauded as a great solution.
Engineering is about trade offs and maybe Boeing made the wrong trade off here. Ideally, you would have as little safety critical software as possible. But the fundamental concept of software correcting for flight characteristics seems entirely sound.
Second System Syndrome is a well known engineering pitfall. If the only thing wrong with the 737 MAX is that the MCAS v1 software is bad, and the MCAS v2 software is good, then the 737 MAX should fly perfectly well for decades.
Boeing historically built planes flown by pilots. Every aspect of the planes behavior had a way for the pilot to control it. A Boeing plane would follow a pilot right out of the flight envelope, at least maintaining a 1:1 binding of pilot intent to plane output behavior.
Airbus makes planes flown by automation, directed by pilots, that should that automation fail, requires a significant investment of skill maintenance to know what not to do at that time. This makes common UI for the pilot easier to implement, but comes with discipline degradation through having a computer that will largely ignore your daft commands until it suddenly has no way to measure your daftness, leaving you with a plane with a hodgepodge of reliable automation to reason through about whether or not the plane will do something daft if you order it to.
History may show who won that argument, (Airbus does exist), but the fact does remain today that aircraft that one wants to certify as flying just like another aircraft (MAX flying like a 737) should actually do so. The MAX doesn't; the technological fix intended to make it so was not developed to a sufficient standard of rigor, or communicated to pilot clearly enough, to transparently account for that aerodynamic divergence.
The problem is multi-faceted, yes; but the statement that the MAX suffered from a fundamental design flaw is absolutely accurate.
The flaw exists aerodynamically, and in the fundamental engineering process through which it was certified.
[1]https://www.aerosociety.com/news/audio-the-d-p-davies-interv...
But my understanding is that other jets have a similar pitch up characteristics and no one considers them to be fundamentally flawed. That the 737 MAX design creates a new problem vs the 737-NG does not necessarily mean it's fundamentally flawed.
I'd only consider it a fundamental flaw if MCAS can't actually be designed to compensate for the problem. An unsolvable problem due to bad design = fundamental flaw.
Otherwise having to stick a windshield on the front of an airplane could be considered a fundamental flaw. But it's not considered one because of very strong laminated materials compensating for the the problem. And yet it's still a huge potential risk. Windshields have cracked, broken, clouded up, etc.
MAX, however, has additional problems where its flyability is adversely impacted when flying at high Angles of Attack when the engine nacelles (positioned higher and in front of the wing) creates extra lift in front of the center of mass of the aircraft. This creates divergences from the normal "control feel" of the older aircraft.
When at low power, and high AoA, (such as might be experienced on descent), sudden applications of power can cause pitch up, which can put the plane at an AoA that experiences this handling divergence. MCAS, in it's second form, was intended to induce a controlled mistrim to compensate for both it's original purpose (high speed, high AoA divergence from 737 NG handling), and a low speed, high AoA handling divergence.
It was being modified to handle the low speed case that removed an extra G-Load based cross check, and greatly increased the authority the MCAS system commanded, due to the larger deflections required to induce attitude changes in the low speed portions of the flight envelope.
The fundamental flaw I mention, is several fold.
Requirementswise:
A)The MAX had to be developed yesterday to allow Boeing to maintain dominance/market share in narrow body civil transport against the A320neo. (They needed it fast)
B) It had to be cheap. They needed minimum overhead cost to appease airlines, and comparable fuel efficiency to the A320neo. This meant no blank slate redesign. This locked them into the 737 type cert.
This meant (to an engineer):
C) It had to fly exactly like a 737... Without being one (They need it to be right).
In engineering, there is a common saying:
You can get it done cheap You can get it done fast. You can get [everything you want] done right).
Pick two.
For success, they needed all three, and delivering the third was not allowed the flexibility to intrude on either of the other points of the triad areas of process.
The only way this project could have ended was with a breakdown somewhere in the process. That breakdown was in communication and propagation of the significance of the aerodynamics change. That failure in communication was bundled in the "fast and cheap" directive. The "right" directive required the aerodynamics divergence, and the software control system reconfiguration to compensate for it. The cheap and fast also required that the software solution not be driven by a dual sensor system, as that wouldn't have been allowed through without simulator training by the FAA, as testified to by a whistleblower as reported in the Australian 60 minutes expose.
The whole thing is just a Greek tragedy in an engineering project's clothing. Hubris, greed, equivocation, catastrophe... It's all there.
I'm still not yet aware of any reason that they won't be able to eventually make the MAX design safe and functional.
It's a very interesting example of engineering/business dynamics. I'll be happy whether the MAX flies successfully or gets totally scrapped, as long as no one else dies in a MAX from negligence.
And before anyone says "hurr durr it pitches up" (or something like that) the amount it pitches up when wide open at low speed is perfectly fine from a performance standpoint but it is not similar enough to the old plane to get away without retraining pilots, hence the software.