Latest 737 Max Fault That Alarmed Test Pilots Rooted in Software
bloomberg.com
bloomberg.com
Oh man. That sounds like a mess.
If this is what we can expect going forward, the Jet Age isn't going to last another 50 years. This kind of software ought to be developed using a tool like TLA+.
The alternative is to ignore the problem.
Sensors go bad. Actuators go bad. Voting hardware goes bad. Message routing goes bad. Even the RAM sometimes goes bad.
When the hardware is failing ("specific streams of erroneous flight data") there isn't going to be a reliable solution. You can't even fully enumerate all the possible failures. How could you possibly guess that a message routing chip now flips bit 7 in every angle-of-attack measurement?
Boeing's answer is standard: when the values look crazy, stop doing stuff that might make the situation worse.
This might just be a bad case of people talking past one another.
Because most of the time you can't. There is no reliable way of knowing when the sensor is lying to you.
You might try to reduce the probability of it happening and try to make it warn you (for example, redundancy, etc), but in aviation, even things that have a probability of failure of 10e-6 or even lower must be considered. 0% chance of reading an erroneous value doesn't exist.
The computer can deal with suspected erroneous input: it can ignore it. There. That's the standard way.
Always thought they would spec a substantially more processing capability than required. I understand economics are a factor but surely it’s not through necessity to save power?
https://www.moonofalabama.org/2019/06/boeings-software-fix-f...
Although still slower than an Arduino :)
Then taking umbrage here that they were too conservative and possibly froze the hardware spec.
"American also intends to order 100 of Boeing's expected new evolution of the 737NG, with a new engine that would offer even more significant fuel-efficiency gains over today's models. American is pleased to be the first airline to commit to Boeing's new 737 family offering, which is expected to provide a new level of economic efficiency and operational performance, pending final confirmation of the program by Boeing. This airplane would be powered by CFM International's LEAP-X engine."
When a customer demands...
https://www.nytimes.com/2019/06/26/business/boeing-737-max-f... (somewhere in the middle: "The issue discovered last week is linked to the data-processing speed of a specific flight control computer chip, according to the two people with knowledge of the matter. In the test, the F.A.A. pilot encountered delays in executing a crucial step required to stabilize an aircraft." )
Of course, the faster one can do more stuff in less time, but for flying an airplane (or going to the moon) the amount of computing power needed is much less than people imagine.
The issue here is adding more computing into an aging platform. But there's nothing inherently wrong into using an older platform into the flight computer.
Now I'm not sure if for certification purposes they would be allowed to replace it with modern hardware but just keeping the functionality the same, I believe the answer would be yes, that they are allowed (but they probably didn't want to rewrite the sw and recertify the hw)
For example, the regulator doesn't care (much) how you built your wing, but it does care that's able to withstand 150% of the maximum expected forces.
You can have parts done by different manufacturers (but to the same spec) and this is sometimes done on purpose in redundancy settings so that unknown bugs in one model are less likely to show up in a different model.
This is unbelievably fucked
Is it fair to say the hardware is fulfilling the requirements though?
What seems to have dubious benefits for safety is lying to the regulators and shoehorning new processes into old technology. Because hundreds of people have died from that exact thing, just on this one airplane.
The lesson is real engineers do not need row hammer afflicted processing power, they are not running crappy JavaScript. They built something that works and over engineered the hell out it.
Ford in Detroit once lost a mainframe. For 20 years
In other words, even in financial terms, it cost more than damages. It may have cost the entire company. They “DeHavailland”’ed their company. Ever heard of DeHavailland? No? That’s probably to do with their 4 successive deintegrating planes that “CEOs have complete trust in.” It just died, as a name. The risk is high.
Yet, fumbled the ball.
They also had a space program, closed it down after their first satellite, which was a success.
Concorde! (With France.)
It goes on an on, I'm sure you have favourite examples.
It's heart wrenching.
The Raspberry Pi is a spiritual successor which I am generally pleased to see. The RPi was I think partly responsible for a real Computer Science curriculum getting back into schools ... I hate to say it but I think it was Michael Gove that made this happen!
This is pretty typical of the UK government's approach to the computer hardware/software industry. Had the first business computer industry in Europe (anyone else remember the LEO line of mainframes?) and a promising software biz, of which only bits remain. (The gaming industry is thriving, but the rest mostly ended up being absorbed by US multinationals. I could speculate that having a common language, in combination with a series of governments who believed in leaving things to the Invisible Hand, and a business culture dominated by accountants, were at the root of the problem ...)
Which kind of speaks to the prevalence of luck over design in favorable outcomes at any macro level. Too many small, randomly whirling bits, and they all need to line up just so.
Its happening right now too with electric cars and solar electricity - solar has generally been seen as a success with a lot of installations taking us to 3rd place in Europe for solar megawatts despite there being essentially no sun (1), and EV cars are starting to become something actually viable for most people's lives. The government has just announced that the UK is now legally bound to be carbon neutral by 2050... yet the government chose also to revoke funding and support for both solar and EVs and so subsequently update has plummeted (2, 3) right at this vital point.
1 - https://en.wikipedia.org/wiki/Solar_energy_in_the_European_U... 2 - https://www.theguardian.com/environment/2016/apr/08/solar-in... 3 - https://www.autocar.co.uk/car-news/industry/new-car-sales-fa...
Marshall plan replaced and thankfully rejected the previous Morgenthau plan - which would have explicitly ruled out any aid to Germany, and actually further destroyed the country.
In a fine bit of statesmanship Marshall plan aid was offered to the Soviets, who rejected it. It was offered in fairness, but in the certain knowledge Stalin would refuse. It would never have got through Congress anyway. :)
Royal Aircraft Establishment - merged and amalgamated a dozen times to become DERA - privatised. Now QinetiQ.
Most of the decent research sites are gone now.
GEC/Plessey
I'm going to stop now, it'll get depressing.
Despite everything, I still don't think the solution to the 737 MAX problem is to start over. The base problem that Boeing has its actually their terrible engineering culture, the one that values shortcuts and profit over thoroughness and safety.
Even if they started from a blank piece of paper, they'd have that engineering culture problem (and to be fair, it is far more likely an engineering management culture problem), and they'd still turn out a design that kills people.
So it's not if they should "start from clean" but just accept the need for the new certification and then do the changes that are really needed. It will be less profitable for Boeing but it righly should be this time! They are killing people otherwise.
As I have mentioned here before: The angle of attack sensor was never intended for the purpose it is now used for - military aircraft may do such things but not as an afterthought and not connected with a control surface which has a lot of delay (trim wheel winding. Delay is a major factor in destabilizing control loops). Equivalent sensors are the airspeed pitot tubes but they are a much more robust concept. Even they have brought down airplanes. We lack sufficient real world (heat, humidity, snow) information about the quality of the sensor data even before it may get distorted by transmission and processing on its way to the control law. Cleaning and validating sensor data is tricky under the best of circumstances. It does not sound like they have a handle on it.
Hi Boeing, what real world data from mounted angle of attack sensors have you analyzed? Why do you believe this data sufficiently represents climate zones and flight conditions (take-off, landing, turbulence, malfunction modes)? How do you clean and validate the sensor data? Please explain, because otherwise I won't step into one of these machines.
But don't worry, when it is found out that it is a mess, we have a plan.
We can add a software patch to correct the bad software output. Not fix the bad software. But add some more to correct the output.
Genius!
> The failure scenario was known previously and had been assessed in a safety analysis when the plane was certified before entering service in 2017. At that time, Boeing concluded that pilots could overcome the nose-down movement by performing a procedure to shut off the motor driving the stabilizer movement.
This isn't a new fault. Boeing certified this as safe along with MCAS back when the aircraft first flew in 2017, using the same justifications ("pilots can overcome it").
They weren't going to fix it this time either, except test pilots ran across it in late-stage simulations monitored by the FAA and found it wasn't as easy to overcome as Boeing had been asserting in their cost-safety analysis (just like MCAS) and now the FAA are requiring a fix.
Has Boeing learned anything from MCAS? The company has cultural problems vis-à-vis safety. I'm just glad the FAA are doing their job this time around.
Has Boeing learned anything? Of course not. There are no executives facing jail time, or even fines! They're shameless frauds that outsourced their critical systems to the lowest bidder with predictable results.
I wonder if it might be a consequence of being a late adopter, and rushing the development of systems they never had before.
They used a one sensor input to MCAS because the FAA wouldn't certify a two sensor input without requiring a level D certification which meant sim training for pilots.
This latest revelation in the article only strengthens my belief it was rushed and possibly to the point that it was irresponsible.
I hope all the other agencies worldwide will double check all the prior certifications issued by the FAA, because all their credibility is gone. Especially considering the US was the one the last countries to ground the 737 MAX.
I wonder what happened there. Bribes? Favors? Lobbying and ties? All of the above?
I can't imagine what it must be like to be one of the first pilots to fly the MAX once the grounding is lifted. Can pilots refuse to fly a specific plane "for a few months, 'cause I have kids waiting for me home"?
The probability of a total loss of an aircraft is basically proportional to either its flight hours or number of takeoffs and landings (which are (handwave) correlated (unless you are Aloha Airlines)). A fleet of thousands of planes (especially a 'mature' design), flying thousands of hours per year, in service for decades should have very few losses due to fundamental design issues. It would be nice to say it should be <1, but the reality is the stars sometimes align and several weaknesses conspire to make a fatal event. With MCAS, the 737 Max 8 was already at a rate of 2 events in less than a year with a fleet that was a tiny fraction (<6%) of its ultimate fleet size.
Assuming nothing else changed, at full fleet size, that would be over 30 losses a year, or well over 1000 losses over the fleet's lifetime. They misengineered the system by at least 3 orders of magnitude. This is, at the very least, profound professional and managerial negligence. I'm not not yet convinced it's not also criminal. At the very least, all management who touched this subsystem or were part of the no-new-training-at-any-cost push should have already been shown the door up to and including the CEO.
And yes, things _are_ being done and they are adding 'nines' to the reliability as quickly as they can, but again, they are starting from a subsystem that kills everybody on board every 800,000 flight hours or so.
They appear to be dishonest with the public (and perhaps themselves) about how much risk is eliminated with each change and, similarly, appear to not be factoring in that some of these changes introduce other risks and failure modes.
What we have here is a giant fucking mess and a management organization that fosters no confidence in its ability to navigate itself out of it. In the end, I do expect Boeing to somehow glue-gun 3 more 9's of reliability onto this airframe and stop bleeding valuation, but it won't be pretty and it probably won't be fast.
If they are doing 96% of the safety validation work — then they should bear 96% of the responsibility for safety process failures ... in this case, given the break down of safety validation capacity and what I’m increasingly viewing as essentially a coverup after the first and second crashes — 96% of the responsibility is and probably should be - enough to bring Boeing down ...
I’m beginning to think that might be the only way to ensure responsibility for this failure gets allocated in a sufficiently accurate way to ensure this scenario isn’t likely to happen again ... allowing the faa to have the responsibility to bear the weight of this process breakdown would basically just allow Boeing to shift responsibility for this outcome off themselves and onto an organization which it seems has been deliberately engineered (by Boeing) to not have the capacity to perform effective oversight ...
This is world the 737MAX software people are living in, for this alone, they have my utmost respect.
Who wouldn’t pay attention to the little mention in Google Flights with the brand of the plane?
In my experience this is pretty normal for specialized stuff like this, it has nothing to do with corruption.
The 737 Max name is now being replaced with the 737-8200 term (1). I assume they are hoping that 737-8200 is not tarnished like 737 Max is.
1 - https://www.independent.co.uk/travel/news-and-advice/ryanair...
If another 737 Max crashed then that would be the end of the Max, IMO, but I doubt older 737s would be dropped and Boeing would still be around easily enough.
- Boeing is certainly well financially engineered in many financial vehicles,
- It’s alone the #1 net exporter of USA,
- USA needs Boeing, whether it exports or not. Boeing also funds candidates, just mentioning.
- Existing conpanies need to maintain their existing planes, and they need Boeing’s consultancy for that,
- I’d say even Airbus needs their competitor, or they would fall in a dangerous monopolistic position.
As much as one would enjoy the spectacle of a corrupted eating the dust, it is probably too stable to happen. But ever heard of De Havailland? That’s probably to do with their 4 crashes in a row, due to its airframe shredding of metal fatigue and material constraints being concentrated on the edges of their square windows. Ever flew in a DC-10 or MD-11? That’s probably to do with their 4 crashes in a raw, for a bad doorlock. Just saying.
Boeing developers have been put in an untenable position and should consider walking out until management does the right thing and kills the plane.
The only flaw the plane had was being treated as 'just another 737'
It’s fundamental because the whole fundament this rests one isn’t stable and all the adding instability add-ons do not make sense.
the 737MAX could have been certified as a new airplane, with a new type certificate, and a new pilot type rating to go with it - but that would have removed much (or all) of its economic justification to exist.
Any new airplane would be a bit higher, it brings some downsides (ground operations people really like the easy access), but having bigger engines under the wings is such an advantage that it overrides all other considerations.
I bet if you offered Delta some brand new MD-95's they'd take up on them, as they have basically every MD-95 produced.
> The only flaw the plane had was being treated as 'just another 737'
Passing as "just another 737" was the whole point of this plane. Which is why it should be scrapped. Boeing and its customers will scream? Tough - next time, build a plane in the proper way, so you don't kill people. If that means making a bit less money, well, money comes and goes.
But where would we be without corruption...
Have you heard of the site called github?
So unless you’ve found an economical way to develop an open source jetliner... honestly, what would be the point of open sourcing safety critical systems to the general public?
I’m not at all saying it should be closed off from external safety inspectors or regulators or anything like that, but I’m not really seeing the value of opening the software up to the general public.
And I also challenge you on "it doesn't hurt". Consider military adversaries developing targeted attacks against critical infrastructure because it's open sourced.
This just isn’t a good idea. Full stop.
I assume that currently there's several gatekeepers involved who can shut most independent investigators out.
Simply reading the code isn’t going to help you find critical safety flaws.
Would be very happy to be corrected here.
I work in automation an I guess most of our plc code is much smaller and simpler than just one website.
Software devs still live in this "you can use this software as-is" world. This thinking is just not compatible with, we use software for everything.
Even I liked PLC programming as a younger guy and a kind of I still like to do it .. you can do cool things on the machines .. the way it goes at moment does worry me quiet a bit.
And if you would work in a different job, for ex. design a building or bridges, since ever was this "if you fail, you are in the news".
So please you just software guys, grow up.
This would raise the whole aircraft off the ground. Surely that wouldn't effect aerodynamics too much as the wheels are up most of the time.
They actually cleverly modified the landing gear to gain a bit of heigth, but it was not enough: https://youtu.be/F4IGl4OizM4
An angle of attack sensor measures something a gyroscope cannot measure: the angle of the plane relative to the wind. The amount of lift produced by the wings depends on this angle.
Also too big to fail (fall) doesn't apply here.