Boeing Starliner updates: Spacecraft flies into wrong orbit, jeopardizing test
cnbc.com
cnbc.com
It's been a very tough year for Boeing, and SpaceX makes it all seem so easy that you tend to forget this stuff is very hard and that success is not at all guaranteed.
To be fair, their version of this capsule blew up rather dramatically.
https://www.youtube.com/watch?v=xe4ee56aHSg
After that exact capsule had visited the ISS, incidentally, which must've caused a little butt-clenching at NASA.
Is this a covertly taken video? Why so low quality?
https://www.space.com/spacex-crew-dragon-explosion-nasa-memo...
To be fair they have not stated why it exploded. If it was damage during landing or retrieval then oh well. It could be a design flaw.
Edit: It turns out they did explain and I missed that news.
Yes, they have.
https://www.cbsnews.com/news/spacex-explosion-destroyed-crew...
They redesigned the capsule to not need the valve.
They actually did explain:
https://www.businessinsider.com/spacex-crew-dragon-explosion...
> "We believe that we had a liquid slug of the (NTO) in the pressurization system," Koenigsmann said. "When we opened the valves and pressurized the propellant system, we think that this slug was driven back into the check valve. ... That basically destroyed the check valve and caused an explosion."
Hence the redesign.
There's also been discussion of reusing Crew Dragon on unmanned CRS missions. https://www.teslarati.com/spacex-no-crew-dragon-spaceship-re...
> Although the OIG report in question never specifically states it, some of the language used to describe Dragon 2’s cargo configuration does seem to imply that Cargo Dragon 2s will predominately (if not exclusively) be derived as slightly-modified Crew Dragon capsules, seemingly indicating that SpaceX’s CRS-2 missions may only ever launch flight-proven Crew Dragon capsules.
I do not understand the effort being put into arguing that this failure was largely inconsequential because it was a test. Clearly - and rightly - neither SpaceX nor NASA took it that way.
That's not what I'm attempting to argue... and why my post starts with a disclaimer that I'm not trying to argue that.
I just think it's important to keep the facts straight.
Note the issue that unites these two statements - it is relevance. A test does not have to be a simulation of actual use to be relevant.
That doesn't make it necessarily relevant to the original point of whether or not it was an issue that needed to be taken seriously, but that's why I explicitly started my post by stating so.
I honestly can't believe that you're defending a serious misstatement of the conditions of the test on the internet by saying "well it doesn't matter that the premise of my post was wrong". Of course it matters, even if I agree with your conclusion anyways.
The capsule blew up. True.
The capsule blew up after already having visited the ISS. Also true.
Wasn't much more to my post.
> the failure of a test conducted within operational parameters should be treated as seriously as a failure in actual use.
Everything before the "should be".
Until the failure had been diagnosed, it would have been correct to consider whether the problem was entirely the consequence of the capsule's previous history, but by now, we are all - even you - agreed that the test did reveal a potentially serious problem that could be fixed. It turns out, fortunately, that tests do not have to be equivalent to live operations to be useful, because relevance does not depend on them being so (as this case demonstrates.)
The premise, that the test was conducted within operational parameters, is not true.
This test was part of the process of identifying and eliminating those risks.
There is no difference between a failure during a test and a failure during operation, in terms of identifying needed changes in space craft design.
There is a difference when it comes to evaluating the design and testing process of the company. SpaceX seems to be very good at balancing moving quickly with design, then testing safely, using those test to find weaknesses and learning from their failures to iterate rapidly.
Despite some early failures, it seems SpaceX is rapidly on its way to having the best launch safety record in the industry.
I agree that SpaceX is looking very competent.
It seems like there is a balance between the level of confidence you achieve prior to a flight test, the costs of a failed test, and the speed at which you can implement and iterate designs.
> A failure at that point should lead to a serious reevaluation of that confidence,
If, as in this case, the failure is due to non-considered risk, you certainly want to make changes to the assumptions you make during the design process in the future (in additional to the changes you make in your current design.)
I don't think you need to generally question your confidence in your components that have not only passed all their operational tests, but have been used successfully to complete operational missions.
So I don't think that's at all a fair comparison.
That they wound up redesigned indicates NASA and SpaceX agree.
To be clear, it blew up when pressurizing those motors' systems, not during firing. As you note, that makes it unlikely to have happened in orbit, but it's still a major concern for future crew - it's a step that'd happen in every launch. Hence the redesign.
This was a serious flaw in a critical system, and the redesign was very important. It also advances the state of the art in engineering in these sorts of systems... the failure that took place was something that no one considered possible (specifically the Ti/NTO reaction).
I was just responding to the fact that you mentioned the capsule had visited the ISS, which is totally irrelevant to the failure.
See PDF pg. 66 (not report pagination) https://ntrs.nasa.gov/archive/nasa/casi.ntrs.nasa.gov/197200...
See PDF pg.11 https://apps.dtic.mil/dtic/tr/fulltext/u2/866010.pdf
On December 29, 1953, a technician at Edwards Air Force Base was examining a set of titanium samples immersed in RFNA, when, absolutely without warning, one or more of them detonated, smashing him up, spraying him with acid and flying glass, and filling the room with NO2. The technician, probably fortunately for him, died of asphyxiation without regaining consciousness.
There was a terrific brouhaha, as might be expected, and JPL undertook to find out what had happened. J. B. Rittenhouse and his associates tracked the facts down, and by 1956 they were fairly clear. Initial intergranular corrosion produced a fine black powder of (mainly) metallic titanium. And this, when wet with nitric acid, was as sensitive as nitroglycerine or mercury fulminate. (The driving reaction, of course, was the formation of TiO2.) Not all titanium alloys behaved this way, but enough did to keep the metal in the doghouse for years, as far as the propellant people were concerned.
Different oxidizer from SpaceX, but still useful as a data point.
But a big difference is Boeing tests on the ground and SpaceX tests in flight.
Notably, ULA has a nearly perfect record (they've never lost a vehicle, only one or two payloads didn't reach the correct orbit) and ULA has launched nearly twice as many times compared to SpaceX. While the SpaceX's record is very bad by modern standards.
https://en.wikipedia.org/wiki/SpaceX_CRS-1#Secondary_payload
> Both SpaceX and Orbcomm were aware, prior to the mission, of the high risk that the secondary payload satellite could remain at the lower altitude of the Dragon insertion orbit, and that was a risk that Orbcomm agreed to take given the dramatically lower cost of launch for a secondary payload.
As for this...
> CRS-7's launch vehicle catastrophically failed, the cargo capsule ejected, but its parachutes didn't deploy (had it been a crewed mission, the astronauts would have died)
Had it been a crewed mission, the parachutes would've been active. It's not standard practice to have a escape rockets or armed parachutes on ascent for cargo flights, SpaceX or otherwise. Standards are different for crewed flights.
For CRS-7 Wikipedia says "SpaceX officials stated that it could have been recovered if the parachutes had deployed, but the software in the capsule did not include any provisions for parachute deployment in this situation."
No, that was the outcome. The lower orbit has much more atmospheric drag, resulting in deorbit within a few days. SpaceX and Orbcomm both knew this was a possibility. From Wikipedia: "Both SpaceX and Orbcomm were aware, prior to the mission, of the high risk that the secondary payload satellite could remain at the lower altitude of the Dragon insertion orbit, and that was a risk that Orbcomm agreed to take given the dramatically lower cost of launch for a secondary payload."
FTFY
Astonishing to me they make it sound like it runs like an independent stopwatch and not kept in sync with the actual IRL mission parameters in a more direct/continuous way. They're talking about the automation handover between the launch vehicle to the spacecraft, and on Starliner "clearly the time got messed up" ... "the spacecraft was not on the timer we expected it to be on"
Also, if I have understood things correctly, the lunar lander used a timer based approach to keep the rotation of the vehicle aligned with the surface of the moon as it orbited.
Since the orbital dynamics are very well understood and there really isn't anything that can affect the motion of the spacecraft other than engine burns, there doesn't seem to be any good reason to make it more complicated.
But many things can go slightly wrong when firing all engines fighting your way up the atmosphere.
This is like saying that because the airplane crashed because the wing was incorrectly designed and popped off, everyone should fly biplanes...
We do that. Not with the wings, but with the engines. When jetliner engines were less reliable, we required 3 or more engines on flights that included long sections without passing near an airport (mostly transoceanic flights). Now that some engines are more reliable, we have ETOPS certifications for jetliners using two high-reliablility engines. And yes, there still are two, because no matter how reliable the engines may be, one _may_ fail.
What is backing up that CST-100 timer?
It would seem we have an existence proof now saying that the above statement is incorrect.
The wording “it would seem” should have tipped you off that no assumptions are being made, but I guess it didn’t work.
And even if we were to make a comparison as you suggest and derive some ratio, that’s not super useful without comparing it to the ratio for some alternative approach that does not use timers.
This is wrong.
1) Atmospheric drag (unless you're in really high orbits)
2) Wind
3) Uneven gravitational field. Our planet is not a perfect sphere. The moon is even less so.
4) Solar pressure (though very minor and kinda evens out in orbit).
Space is empty enough and engines imprecise enough that for orbital stuff you have enough margins to correctly predict and plan a trajectory ahead of time, and just do correction burns later if necessary.
On the Moon the gravitational field is indeed uneven enough to matter, but exactly one orbiter really cares about it (LRO iirc has a specific orbit where the unevenness mostly cancels out), most simply rely on occasional station keeping burns.
Interesting, this might explain the failure to land the rover (vikram) on the dark side of the moon by India's recent moon mission.
For example, what if the altitude assumed by the timer is off by a few kilometers, and it starts operating in a manner which is for landing within few meters.
I imagine the reason timers are used is this right here. We don't have complete coverage of the earth for satellite control, so there needs to be a timer running for when it can't phone home to stay synchronized.
Think about this - if you're one of those software engineers and you read some random person on forums criticizing your work without context or thorough understanding, how would you feel?
I love HN for insight and intellectual debate, this kind of analysis does not add any insight - it is flat out dismissing and condescending.
Edit: Also, this behavior against Boeing is unwarranted because it has bias of 737 MAX issues. Completely different team, completely different problem.
This leads to a phenomenon where software engineers tend to come up with "one weird trick to solve the space shuttle, NASA hates him". And it's always specifically software engineers.
Generally, most people are just as competent at their job as you are at yours. If the obvious solution is not being used, there is usually a very good reason why. A lot of fields have problems that are hard for reasons of physics or other things that are not trivially gone around, and the solution is not one software engineer swooping in with a great idea that totally revolutionizes avionics.
(sometimes of course it is social factors, same as software engineering. The best way is too expensive, or management is making bad decisions, etc)
I wouldn't doubt most programmers could do an failure mode effects analysis on the software and figure out they need to mitigate an event where the timer fails to sync. But how many would also capture how to mitigate that sync failure at the precise time the system lost satellite comm? Probably a heck of a lot less.
Now multiply that by the total number of software failure modes (including those latent ones we just get lucky with) and see how many get captured. There's a reason why software in these types of systems is incredibly hard to test.
Who gives a shit how he feels? He works at a company that builds death traps, and someone at that company has built one himself. People like this should feel overpowering shame and contemplate the poor life choices that brought them to this terrible place.
Boeing is a great argument for the corporate death penalty. Its stock price should go to zero, and its assets divided between its creditors and the military pieces nationalized.
Wrong. Do you somehow thing there's a different management team running these parts of the company? There's only one CEO at Boeing, it's only one company. And culture starts at the top.
Questioning Boeing's competence here is entirely warranted when the company has already PROVEN that it is happy to put profits ahead of safety.
That's internet in a nutshell, and HN is not that different despite pretensions to the contrary. What partly redeems it is the better than even chance that in posts with technical subjects, someone informed and/or competent will appear and write something worthy. You learn to filter out the rest.
It...seems sort of similar to me, based on the article I read. It's not similar at all in the consequences, because of the context of the flight. But in the way things went wrong.
A question that I have unanswered is, Boeing was reported as saying that if there were astronauts they would be "safe"...but would it be possible to retrieve them?
SHIT happens in space flight all the time. The rate at which shit happens in space is on a few orders of magnitude different than shit that happens in commercial aerospace. Ask how many times SpaceX failed to do what they do today and it will fail more times in future, no doubt.
I also understand the company culture point - yea, company culture probably isnt the best at Boeing but they've done many many things right in past decades. They're a huge company with a lot of talented engineers (and a lot of bozos). Their CEO is a complete asshat and I am sure people inside Boeing talk about it.
I just think that there is unnecessary scrunity without data to say definitively what happened.
Update: #Starliner had a Mission Elapsed Time (MET) anomaly causing the spacecraft to believe that it was in an orbital insertion burn, when it was not. More information at 9am ET:
Because #Starliner believed it was in an orbital insertion burn (or that the burn was complete), the dead bands were reduced and the spacecraft burned more fuel than anticipated to maintain precise control. This precluded @Space_Station rendezvous.
We are getting good burns and are elevating the orbit of the spacecraft.
There will be a press conference on NASA TV[0] at 9:30am ET (29 minutes from now)
Also some speculation from Scott Manley[2][3] that the spacecraft may have fired it's engines 90 degrees from prograde during orbital insertion, based on mission control displays seen during the launch livestream
[0] https://www.nasa.gov/live/ [1] https://twitter.com/JimBridenstine/status/120802259102746215... [2] https://twitter.com/DJSnM [3] https://twitter.com/DJSnM/status/1208006636746330120
Edit: looks like Tory Bruno (ULA CEO) has confirmed that Atlas and Centaur performed well [0]
[0] https://twitter.com/planet4589/status/1208035453850587136
http://www-users.math.umn.edu/~arnold//disasters/patriot.htm...
https://arstechnica.com/science/2019/11/nasa-report-finds-bo...
This sort of issue would have shown up on the first Dragon 1 flight if SpaceX had it.
I wonder how much further along SpaceX might be if they were able to ripoff NASA and the federal government the same way Boeing is able to.
In the pad abort test a parachute failed, this wouldn't have been a deadly failure since the remaining parachutes are sufficient, but it is pretty damn concerning.
Now this test suffered a major failure too.
This does not bode well for the reliability of this vehicle.
It is not entirely clear to me whether this would have been the chosen course of action had it been manned, or whether it is merely being presented in support of the statement that it would not have created a dangerous situation.
It also singlehandedly makes up about a half a percent of GDP. https://www.cnbc.com/2019/03/21/boeings-737-max-could-hit-us...
I don't think it's likely, but it doesn't seem impossible.
The price being high on the market means that none of these issues are a real threat to the company.
Furthermore, the military has not demonstrated much ability to constrain the excesses of the military-industrial complex in any matter.
I doubt that's true.
https://en.wikipedia.org/wiki/Patrick_M._Shanahan
> He previously spent 30 years at Boeing in a variety of roles.
There are plenty of examples of this sort of revolving door between contractors like Boeing and the US government.
The military could very cleanly nationalise the Defense division and leave Boeing Commercial to flap in the wind.
The only complications would be the P-8 and KC-46 which use Boeing civil airframes.
I've little doubt we'd get a Troubled Boeing Relief Program if a Boeing bankruptcy was looming.
I suspect the same would be true with a Boeing bailout, especially if you count the continued employment of the staff at their 8,000+ suppliers.
Am I looking at the wrong stock or something?
Its really unfortunate to hear this news as its not easy to gt these things off the ground. (pun very much intended) Hopefully it doesn't take too long for another attempt if any.
It'll be good for space travel and the space economy.
I am not American, so: not my money, not my country. I have no say in it... But I wonder if I am the only one to think like that.
No way. NASA is subject to the political whims of two branches of government. The executive branch is looking for short term wins and the legislative branch is looking for jobs in their districts.
The private market has introduced great innovations that are significantly driving down the cost of going to space.
The only difference is that public money now is financing private companies...
SpaceX is landing and reusing rockets every month, resulting in much lower launch costs, and you're saying the only difference is where the money is going? Get out of here.
I believe NASA has never produced everything in-house. They don't build (or even design, as far as I can tell) launch vehicles, spacecraft, EVA suits, computers etc. They come up with requirements and contract private companies to build hardware (and software, for that matter) meeting those requirements. For an example, see how the Apollo Lunar Module came to be [1].
[1] https://en.wikipedia.org/wiki/Apollo_Lunar_Module#Contract_l...
NASA doesn't run a rocket factory. It used to be that NASA specified and ordered hardware from contractors then integrated and operated it in house. The space shuttle orbiter was built by Rockwell (now ~Boeing), the external tank by Martin Marietta (now Lockheed Martin), the SRBs by Morton Thiokol (now ATK).
Commercial cargo and commercial crew change this model to NASA specifying and ordering missions or mission capabilities. This affords the vendor more autonomy in how they choose to solve problems, and NASA's still in the loop to sign off on their solutions. In principle, this approach contains cost overruns, since NASA pays only for the deliverable. What it doesn't contain are schedule overruns…
Others have commented on how NASA has never built very much in-house.
But I'll go broader. American technological leadership, in space and other fields, goes back to its private contracting heritage. Contractors competed to develop tech. They then had an incentive to find other uses for that tech, thereby proliferating its benefits into the broader economy.
It's not a coincidence that while most countries have a tepid public space program, America has multiple launch vehicles under development for a diversity of purposes.
NASA & ESA are not the same as Boeing & Airbus
Launch vehicles are not the same field as "space travel"
Spinning up entities like JPL is a non trivial matter in either civilian or commercial domains.
Spreading the engineering challenges across a wider array of organisations would not expedite their solution imho. Just thin out the available resources.
https://spacenews.com/missing-pin-blamed-for-boeing-pad-abor...
I'd love to chat about the idea in more depth with you, it's defiantly plausible and with the increased rate of launch it could be a great business.
Still, even if it borked this is still a fairly monumental step in the development. Getting stuff into space isn't all that easy and there's a lot that can go wrong even if you successfully launch something, I'm sure they'll gather a ton of actionable data and fix it in the next attempt.
https://blogs.nasa.gov/commercialcrew/2019/12/20/meet-rosie-...
https://en.wikipedia.org/wiki/Rosie_the_Riveter#/media/File:...
I think they are colorized. Here one comparison of the original [0] (taken in the 30s/40s!) in comparison to the image on Wikipedia [1]
[0] http://loc.gov/pictures/resource/fsac.1a34931/
[1] https://en.wikipedia.org/wiki/Rosie_the_Riveter#/media/File:...
https://twitter.com/BoeingSpace/status/1207977494277738496?r...
It wasn’t the engines (Boeing doesn’t make engines). It was MCAS.
Now, to be fair, going faster DOES create apparent wind coming from the front, so it decreases your angle of attack, but that's it.
(the sensor that failed on the 737s was the angle of attack indicator, trying to estimate if the wing was going to stall).
Could this be a relic of the era when we needed people in the spacecraft? As far as I'm aware, SpaceX has never had manned flights - a catastrophic explosion is momentary bad press, but they can continue on. Every time someone died in NASA it was a real tragedy. Plus every NASA launchpad explosion is more obviously "wasted" tax payer money.
I think everyone would agree that manned flights should be as thoroughly tested as possible. Although SpaceX has never had manned flights, they do dock with the ISS, a failure of which could have very real consequences including possible loss of life.
The belief that an iterative, agile approach is too "fast and loose" for complex engineering projects has been throughly debunked, but for some reason continues to pervade.
"The quality control mechanisms supported by current agile processes (e.g., informal reviews, pair-programming) have not been proven to be adequate to assure users that the product is safe. In fact there is some doubt these techniques alone will be sufficient. Formal specification, rigorous test coverage, and other formal analysis and evaluation techniques included in software engineering approaches provide better, but also more expensive, mechanisms to tackle the development of safety- or business- critical software" [1]
SpaceX has shown quality control issues on their hardware processes in the past, which, from the outside looking in seems like they should have been caught.[2] I wonder if the fact that they are a relatively young organization is why these processes were lacking to begin with. It seems to be the nature of the learning process that as the 'unknown unknowns' are uncovered, processes will become more robust (and possibly cumbersome) by extension. The real question is whether they should have been unknown to begin with. I also wonder if they will start to look less like the agile upstart as they create more mature processes.
[1] https://arxiv.org/ftp/arxiv/papers/1409/1409.6600.pdf
[2] https://www.wsj.com/articles/structural-failure-likely-cause...
Reference 2 is non sequitur; nobody is suggesting that there are zero errors/failures in agile, simply that Boeing may benefit from taking a more agile approach.
Here's how iteration works: https://www.youtube.com/watch?v=bvim4rsNHkQ
Sorry if I wasn't clear enough on the point of Ref. 2. The reason that was brought up was the issue found was related to supplier quality. The fact that these checks were not in place is a bit surprising from a quality perspective and SpaceX indicated they will include additional quality oversight in the future.[1] I.e., through failures, they are adding additional processes that move them away from being an agile organization and closer towards the bureaucratic processes they are often contrasted against.
"SpaceX will implement additional hardware quality audits throughout the vehicle to further ensure all parts received perform as expected per their certification documentation."[1]
[1]https://www.spacex.com/news/2015/07/20/crs-7-investigation-u...
What I am hoping to find is more concrete examples of successful application of agile processes to safety-critical software. For example, how can user stories be used in lieu of a traditional software requirements specification and still effectively capture all the necessary safety requirements (including those the customer may be unaware of).
As for SpaceX's cadence, one of those NASA-mandated tests, which was thought to be low-risk beforehand, did blow up the capsule. That sort of thing makes it a little awkward to be critical of the test requirements afterward. And while I am also very much a fan of the "cheap iterations" approach up to a point, it's less appropriate once people are on the craft and their lives are at stake.
They've just gotten comfortable indoors, growing fat, lazy, and old in the decades since then.
I've heard people say SpaceX looks very much like NASA during the Apollo days, including the average age being in the mid-20s in the control rooms. Contrast that with today where NASA's average age is north of 50. What I think will be interesting is if SpaceX maintains this over the coming decades or if they will become more bureaucratic as the organization ages.
If that's why they fail, do they regularly succeed in spite of it or also because of it?