Oh man. That sounds like a mess.
Oh man. That sounds like a mess.
Always thought they would spec a substantially more processing capability than required. I understand economics are a factor but surely it’s not through necessity to save power?
https://www.nytimes.com/2019/06/26/business/boeing-737-max-f... (somewhere in the middle: "The issue discovered last week is linked to the data-processing speed of a specific flight control computer chip, according to the two people with knowledge of the matter. In the test, the F.A.A. pilot encountered delays in executing a crucial step required to stabilize an aircraft." )
Of course, the faster one can do more stuff in less time, but for flying an airplane (or going to the moon) the amount of computing power needed is much less than people imagine.
The issue here is adding more computing into an aging platform. But there's nothing inherently wrong into using an older platform into the flight computer.
Now I'm not sure if for certification purposes they would be allowed to replace it with modern hardware but just keeping the functionality the same, I believe the answer would be yes, that they are allowed (but they probably didn't want to rewrite the sw and recertify the hw)
For example, the regulator doesn't care (much) how you built your wing, but it does care that's able to withstand 150% of the maximum expected forces.
You can have parts done by different manufacturers (but to the same spec) and this is sometimes done on purpose in redundancy settings so that unknown bugs in one model are less likely to show up in a different model.
This is unbelievably fucked
What seems to have dubious benefits for safety is lying to the regulators and shoehorning new processes into old technology. Because hundreds of people have died from that exact thing, just on this one airplane.
Is it fair to say the hardware is fulfilling the requirements though?
https://www.moonofalabama.org/2019/06/boeings-software-fix-f...
Although still slower than an Arduino :)
Then taking umbrage here that they were too conservative and possibly froze the hardware spec.
"American also intends to order 100 of Boeing's expected new evolution of the 737NG, with a new engine that would offer even more significant fuel-efficiency gains over today's models. American is pleased to be the first airline to commit to Boeing's new 737 family offering, which is expected to provide a new level of economic efficiency and operational performance, pending final confirmation of the program by Boeing. This airplane would be powered by CFM International's LEAP-X engine."
When a customer demands...
The lesson is real engineers do not need row hammer afflicted processing power, they are not running crappy JavaScript. They built something that works and over engineered the hell out it.
Ford in Detroit once lost a mainframe. For 20 years
As I have mentioned here before: The angle of attack sensor was never intended for the purpose it is now used for - military aircraft may do such things but not as an afterthought and not connected with a control surface which has a lot of delay (trim wheel winding. Delay is a major factor in destabilizing control loops). Equivalent sensors are the airspeed pitot tubes but they are a much more robust concept. Even they have brought down airplanes. We lack sufficient real world (heat, humidity, snow) information about the quality of the sensor data even before it may get distorted by transmission and processing on its way to the control law. Cleaning and validating sensor data is tricky under the best of circumstances. It does not sound like they have a handle on it.
Hi Boeing, what real world data from mounted angle of attack sensors have you analyzed? Why do you believe this data sufficiently represents climate zones and flight conditions (take-off, landing, turbulence, malfunction modes)? How do you clean and validate the sensor data? Please explain, because otherwise I won't step into one of these machines.
Despite everything, I still don't think the solution to the 737 MAX problem is to start over. The base problem that Boeing has its actually their terrible engineering culture, the one that values shortcuts and profit over thoroughness and safety.
Even if they started from a blank piece of paper, they'd have that engineering culture problem (and to be fair, it is far more likely an engineering management culture problem), and they'd still turn out a design that kills people.
So it's not if they should "start from clean" but just accept the need for the new certification and then do the changes that are really needed. It will be less profitable for Boeing but it righly should be this time! They are killing people otherwise.
In other words, even in financial terms, it cost more than damages. It may have cost the entire company. They “DeHavailland”’ed their company. Ever heard of DeHavailland? No? That’s probably to do with their 4 successive deintegrating planes that “CEOs have complete trust in.” It just died, as a name. The risk is high.
Yet, fumbled the ball.
They also had a space program, closed it down after their first satellite, which was a success.
Concorde! (With France.)
It goes on an on, I'm sure you have favourite examples.
It's heart wrenching.
Its happening right now too with electric cars and solar electricity - solar has generally been seen as a success with a lot of installations taking us to 3rd place in Europe for solar megawatts despite there being essentially no sun (1), and EV cars are starting to become something actually viable for most people's lives. The government has just announced that the UK is now legally bound to be carbon neutral by 2050... yet the government chose also to revoke funding and support for both solar and EVs and so subsequently update has plummeted (2, 3) right at this vital point.
1 - https://en.wikipedia.org/wiki/Solar_energy_in_the_European_U... 2 - https://www.theguardian.com/environment/2016/apr/08/solar-in... 3 - https://www.autocar.co.uk/car-news/industry/new-car-sales-fa...
Marshall plan replaced and thankfully rejected the previous Morgenthau plan - which would have explicitly ruled out any aid to Germany, and actually further destroyed the country.
In a fine bit of statesmanship Marshall plan aid was offered to the Soviets, who rejected it. It was offered in fairness, but in the certain knowledge Stalin would refuse. It would never have got through Congress anyway. :)
The Raspberry Pi is a spiritual successor which I am generally pleased to see. The RPi was I think partly responsible for a real Computer Science curriculum getting back into schools ... I hate to say it but I think it was Michael Gove that made this happen!
This is pretty typical of the UK government's approach to the computer hardware/software industry. Had the first business computer industry in Europe (anyone else remember the LEO line of mainframes?) and a promising software biz, of which only bits remain. (The gaming industry is thriving, but the rest mostly ended up being absorbed by US multinationals. I could speculate that having a common language, in combination with a series of governments who believed in leaving things to the Invisible Hand, and a business culture dominated by accountants, were at the root of the problem ...)
Which kind of speaks to the prevalence of luck over design in favorable outcomes at any macro level. Too many small, randomly whirling bits, and they all need to line up just so.
Royal Aircraft Establishment - merged and amalgamated a dozen times to become DERA - privatised. Now QinetiQ.
Most of the decent research sites are gone now.
GEC/Plessey
I'm going to stop now, it'll get depressing.
The alternative is to ignore the problem.
Sensors go bad. Actuators go bad. Voting hardware goes bad. Message routing goes bad. Even the RAM sometimes goes bad.
When the hardware is failing ("specific streams of erroneous flight data") there isn't going to be a reliable solution. You can't even fully enumerate all the possible failures. How could you possibly guess that a message routing chip now flips bit 7 in every angle-of-attack measurement?
Boeing's answer is standard: when the values look crazy, stop doing stuff that might make the situation worse.
Because most of the time you can't. There is no reliable way of knowing when the sensor is lying to you.
You might try to reduce the probability of it happening and try to make it warn you (for example, redundancy, etc), but in aviation, even things that have a probability of failure of 10e-6 or even lower must be considered. 0% chance of reading an erroneous value doesn't exist.
The computer can deal with suspected erroneous input: it can ignore it. There. That's the standard way.
This might just be a bad case of people talking past one another.
If this is what we can expect going forward, the Jet Age isn't going to last another 50 years. This kind of software ought to be developed using a tool like TLA+.
But don't worry, when it is found out that it is a mess, we have a plan.
We can add a software patch to correct the bad software output. Not fix the bad software. But add some more to correct the output.
Genius!