My cynical view is that little will change in this era.
My cynical view is that little will change in this era.
As far as we know the MCAS behaved exactly according to specifications. All of its flaws seem to be intentional (e.g. only using one AoA sensor, not being easy for the pilots to disable, not being explained to the pilots).
The MBA piece of it is why I'm cynical. "Ho-ho-hold on one second. This installation has a substantial dollar value attached to it." --- C.J. Burke "Aliens"
The context is airbus has an advanced and fuel-economic model that was eating Boeing market share. Boeing decided to produce one more version of the 737 model - it fit the category and as a fuel-efficinet "drop-in replacement", it was very competitive but was rather aerodynamically unstable. So Boeing added a software system to compensate but didn't tell anyone, didn't make it dependent on redundant sensors and basically produced a plane where, once the facts were all out, it became obvious it could never fly again - not because it could never be made safe but because making safe would involve admitting how flagrantly you initially skirted safety. No one flies on the "once this was utterly unsafe but now we've fixed it" plane if they really have fixed it.
Everything about the plane was super advanced but cheap-as-could-be, including the software. But by that token, none of this seems the fault of "software culture", indeed, there's been no implication that the software was at fault in the crashes, just the total shitshow design package, which was indeed the fault of finance and management pushing this approach through.
It had two pitch sensors but each is paired with a single computer. There was an optional add on to use both sensors in some way but this is unreliable as well since you don’t know which is right. It was when the plane was flying with the failed sensor (every other time since only one sensor failed) that they ran into the problem.
At least from my readings of how you are supposed to build robust systems from unreliable parts, this is a terrible way to design a system.
See https://www.seattletimes.com/business/boeing-aerospace/faa-c... for info on the sensors.
Search for Jim Gray and fault tolerance on how to build reliable systems from unreliable parts. You need redundant parts with voting (which implies more than 2 sensors and more than 2 computers), error detection, etc... Supposedly the Space Shuttle computer systems were designed right although much of the rest of the Shuttle wasn’t designed right.
The Boeing way relied on the pilots to compensate for mechanical or software failure. Unfortunately, they seemed to willingly choose to not inform pilots of MCAS and there seemed to be failure scenarios where recovery is difficult.
Lastly, I think it is part of the job of a software engineer to push back on requirements and designs that don't work even if it is a failure in the system. Falling back to built as spec'd isn't worth of being called engineering.