How the Boeing 737 Max disaster looks to a software developer (2019)
spectrum.ieee.org
spectrum.ieee.org
http://www.gregorytravis.com/WhyDoesNotPresent/
First off, as an engineer who often has to find and fix electrical short circuits, they'd be easy to find if they were continuous. They're frustratingly intermittent.
Secondly, I worked on the design of the 757 stab trim system. Runaway trim is the trim system coming on and trying to crash the airplane - it being intermittent is NOT part of the diagnosis. That intermittent vs continuous NEVER was part of the discussions about runaway trim. I don't know where that notion comes from. It doesn't make any sense.
Anyhow, the author certainly knows a lot about Cessnas. He stretches this into knowing about 737 systems, a much more complex airplane in its systems and aerodynamics, and he stretches it past the breaking point.
#1 turned off the trim system and continued the flight without incident. (This flight is almost never mentioned, as it doesn't fit the narrative.)
#2 never turned off the trim system and crashed.
At this point, an Emergency Airworthiness Directive was distributed to all MAX pilots instructing them to restore trim with the electric trim switches and then turn it off.
#3 turned off the trim system when it was severely nose down, and crashed.
It was mentioned repeatedly Walter; if not in the articles, then in the comments. The fact remains that afterward, when regulators put more pilots (two military and one civilian trained) pilots into single-event upset simulations, 1 of the three failed to recover the plane in time.
If you acknowledge the training was faulty, then just let it be. Trim runaway presenting continuously vs. intermittently may not seem that important from a clean room engineer's perspective, but when viewed by a pilot through the lens of instruments, blaring alarms, and whatever else is going on in the cockpit, my engineer's optimism favors not relying on the human being perfect, or the defect only happening at a non-terminal part of the flight regime.
It sucks that it played out the way it did. Maybe if someone would have spent as much time on MCAS and the pilot training as you did the 757 auto-trim, it wouldn't have been an issue.
But they didn't. And innocents paid for it.
Without more information on what the background and training of those pilots, and why the one failed, I'm afraid it's just an anecdote.
In both crashes, the trim came on repeatedly and the crews repeatedly brought it back to normal with the electric trim switches. 25 times in the case of the LA crash. They obviously knew that the trim was the problem, because they took this corrective action. The trim running is obvious by the large black&white spinning wheels in the cockpit, and the deliberately loud clacking sound the running trim makes.
All they had to do was then turn it off.
> But they didn't. And innocents paid for it.
That's right, and that's the tragedy.
As to why they didn't, who knows. The stab trim cutoff switch is right there in a priority position on the console, because it's a damned important switch. Dealing with runaway trim is supposed to be a memory item, i.e. memorized.
It does suggest a training problem.
Nobody is blaming the engineers for this. But it is, by design, a bad system, that can by attrition defeat human decisions.
http://airsoc.com/articles/view/id/5d5143c7c4263ce96fd616b6/...
Differen source.
https://aviationweek.com/air-transport/software-fix-will-add...
The civillian trained test pilot lost it. The two military pilots did not.
"In one scenario, the bits chosen first told the computer that MCAS was engaged when it wasn’t. This had the effect of disabling the cut-off switches inside the pilot-control column, which normally stop any uncommanded movement of the horizontal tail if the pilot pulls in the opposite direction."
The cutoff switches cannot be disabled on the airplane.
"They flew the same fault scenario again, this time deliberately allowing the fault to run for some time before responding. This time, one of the three pilots didn’t manage to recover and lost the aircraft."
That's kinda vague.
There it is! Knew it was in SeattleTimes somewhere!
And lookout for the part about disabling cutoff switches, I think Dominic might have written that better, because I think he's talking about a safety function that was removed specifically for the MAX where hauling back hard on the yoke would stop trim commands in progress on NG airframes? MCAS required that that functionality not be ported forward to the MAX.
This isn't disabling those cutouts though. Those are literally, like you said, a hard switch.
>According to a second FAA source, it was the AEG pilot, representing a typical U.S. airline captain, who failed to recover the jet.
There's the bit about the civilian test pilot.
It's a hard switch for good reason. I hate "soft" switches that supposedly disable microphones. Phooey on that.
BTW, on my hotrod I installed a hard switch to shut off the fuel pump, as well as an oil pressure switch that would shut it off. I have a g-switch to cut it off, too, but haven't gotten around to installing it.
So the procedure for runaway trim (turn off electric trim, use hand wheels) doesn't work. You have to instead use electric trim first to get back into normal trim, then turn off the electric trim, and never turn it back on for that flight.
I feel like this isn't talked about enough. I had no idea how bad it can actually get: https://youtu.be/aoNOVlxJmow?t=806
There is some discussion amongst pilots at https://www.pprune.org/tech-log/619326-boeing-advice-aerodyn... which further explains how difficult it can be to manually reduce load on the stabilizer and manually trim the nose up.
With the gear ratios we're talking with by hand actuation, I would not want to have to be one of those pilots.
Aviation rules are written in blood. Training is being updated and fixed. But regardless, MCAS itself is controversial and fallible - it’s crucially important that Boeing make it better.
I.e. they piloted the plane without the MCAS, which they were not trained to do. The whole reason of the existence of the MCAS is to avoid training the pilots to fly the planes without it.
This kind of hand wringing shares a non-negligible part of the blame for why hundreds of people are dead.
If Boeing had been allowed to say "of course our new engines are gonna pull the nose up a little harder, throttle back and climb slower if you don't like it" the MCAS system would never have been built to be the safety critical boondoggle it became. The plane itself handled just fine but the problem that they tried to solve with MCAS is that it wasn't identical to the prior 737. Even the most incompetent professional 737 pilot can fly a 737 that wants to <insert control input here> slightly when <insert other control input here> so long as they're expecting it (remember, they train for this stuff in simulator and most of these pilots are certified for multiple different aircraft) but just letting the pilots deal with it wasn't an option because the regulations disallowed that due in large part to decades of "people are just dumb cogs" type thinking.
And once the airplanes started falling out of the sky nobody could say "just turn of MCAS, it won't handle the same but close enough" because Boeing, the airlines and the FAA were all so balls deep in the lie they'd look like idiots if they changed their opinions and thanks to the society we've cultivated nobody is willing to be the first to break formation because that's who gets targeted by the bulk of the fallout.
> MCAS is a longitudinal stability enhancement. It is not for stall prevention (although indirectly it helps) or to make the MAX handle like the NG (although it does); it was introduced to counteract the non-linear lift generated by the LEAP-1B engine nacelles at high AoA and give a steady increase in stick force as the stall is approached as required by regulation. > The LEAP engine nacelles are larger and had to be mounted slightly higher and further forward from the previous NG CFM56-7 engines to give the necessary ground clearance. This new location and larger size of nacelle cause the vortex flow off the nacelle body to produce lift at high AoA. As the nacelle is ahead of the C of G, this lift causes a slight pitch-up effect (ie a reducing stick force) which could lead the pilot to inadvertently pull the yoke further aft than intended bringing the aircraft closer towards the stall. This abnormal nose-up pitching is not allowable under 14CFR §25.203(a) "Stall characteristics". Several aerodynamic solutions were introduced such as revising the leading edge stall strip and modifying the leading edge vortilons but they were insufficient to pass regulation. MCAS was therefore introduced to give an automatic nose down stabilizer input during elevated AoA when flaps are up.
http://www.b737.org.uk/mcas.htm#background
[0]: https://www.airbus.com/en/products-services/commercial-aircr...
That summarizes why the plane did not go through a new type certification process - avoid costs of pilot training. Boeing instead painted over the differences (larger fans mounted forward) with software to make it feel the same.
The 737 Max was sold on not having to do certain kinds of retraining. "Something wrong with the training" is a divide by zero error here. There was no training. If memory serves this was also tied up in how much and what kind of recertification the FAA would require for a 'new' plane versus a refit of an existing one. Training means newness, and newness means retesting. The lies snowballed into dead passengers.
This seems a bit of a non sequitur from your first comment, but you did reply (here). I'm still not sure what your point is, though. What "narrative" are you referring to?
That's not the only problem with TFA. I worked on the Hercules, not any of the Boeing airliners, but this "30-year pilot" has some pretty fundamental misunderstandings of how MCAS works, what the effects of moving the engines are, and what actually went wrong with the 737 Max. Color me surprised.
Regurgitating the same "MCAS prevents the aircraft from stalling because it's unstable" shlock betrays the author's surface level (at best) understanding of the issue.
No, it's not unstable. The 737 Max exhibits stable pitch behavior along the entire envelope. A lot of people think "unstable" means "it crashes" but these terms have precise meanings.
The 737 Max is a stable airplane. One of the problems it exhibits is that with increasing angle of attack, the stick force does not increase (linearly is the requirement, I think, I'm writing from memory here).
The way you know this is because MCAS moves the horizontal stabilizer directly, and not the control column that the pilot is holding. An anti-stall device like a stick pusher or a stick shaker provides tactile feedback to the pilot via the control column. Moving the horizontal stab directly is (basically) altering the trim of the aircraft. Thus it is a handling-qualities system.
This is part of why the MCAS could not be decoupled from the flight computer as I recall. If you turned off MCAS, you'd be non-compliant in the wind-up turn flight regime, and when coming in on final if I recall correctly.
So in aerodynamic parlance it is stable, but with disqualifying flying characteristics that had to be mitigated via a gadget whose nature, failure modes, and existence was largely hidden from the pilot, and downplayed in the FMEA/FMECA. (Failure Mode, Effects, and Criticality Analysis)
This downplaying was specifically intended to keep regulators from stipulating enhanced training for pilots. Thereby saving money.
It's not just a cost saving measure.
MCAS was a sound concept. It's implementation, however, was not sound at all.
As far as MCAS goes, in my opinion Airbus got it right already in the 80's in their A320 with their flight envelope protection.
Yes, it would likely have been safer if the 737 Max worked as expected by the pilots flying it.
That only works if retraining is not actually needed. Boeing's own test program gave adequate (but undisclosed, at the time) information for an independent observer to conclude that this was not the case here.
I've never understood why the fix wasn't implemented in the elevator feel computer. Except perhaps that it doesn't have AoA inputs and it's an old hydroelectrical system for which there may be a lack detailed knowledge.
It comes from Boeing's checklists: https://i.stack.imgur.com/cRG4J.jpg
It makes perfect sense, because continuous operation identifies a fault condition. Under normal conditions, automatic systems may intermittently move the stabilizer, but never continuously. It may be faulty when moving on its own, but if it moves continuously without input, it's definitely faulty. That's where the name cames from: runs away into physical stops.
Nope, this is 100% false. The purpose of MCAS is to give the MAX the same aircraft handling characteristics so that it retains the original 737's type rating. Thus 737 type rated pilots can fly the MAX under their 737 type rating. A big part of selling the MAX is type rating commonality with the airlines existing 737-train pilots. Juan Browne, a real 777 airline pilot, mentions this in one of his excellent YouTube videos (https://www.youtube.com/user/blancolirio).
> I have been a pilot for 30 years
I suspect this person is a private pilot with no actual airline aviation experience.
Edit: This is the same guy that boosted his aviation credentials by citing that he's flown a 757 simulator (https://www.eetimes.com/software-wont-fix-boeings-faulty-air...). So yes, he's a GA pilot that has flow in some aircraft simulators.
> Among Boeing’s critics is Gregory Travis, a veteran software engineer and experienced, instrument-rated pilot who has flown aircraft simulators as large as the Boeing 757.
The article mentions that prominently in a few paragraphs, this is the first one:
“That's because the major selling point of the 737 Max is that it is just a 737, and any pilot who has flown other 737s can fly a 737 Max without expensive training, without recertification, without another type of rating.”
It also correctly points out that "with the 737 Max, Boeing has changed philosophies about human/machine interaction" - they didn't just hide a system in the plane that changed the planes behavior without telling the pilot, they fundamentally changed the basic assumptions pilots make, and still called it the same plane that doesn't require separate training. I'd consider that an even bigger crime than the other recklessness that ultimately led to the crashes.
- design certification treated as "just another 737" which ignored fundamental deviations in hardware and software, complicated by safety certification by manufacturer instead of public employee
- hardware design including a "dynamic instability" in which airplane approaching an aerodynamic stall had a tendency to go further into the stall due to lift produced by the oversized engines at high angles of attack, which was intended to be mitigated with software
- omission of using multiple inputs, including the opposite angle-of-attack sensor, in the computer's determination of an impending stall
- a changed philosophy about human/machine interaction from humans winning a battle of the wills every time to computers winning a battle of wills in cases of envelope protection
The final item is perhaps the one most fundamental to other cases of safety critical human machine interaction designs. If we are signing over agency to machines for envelope protection, that means we need in advance to understand every potential edge case scenario where that envelope may be mis-framed. Such comprehensive foresight in some environments may be intractable. For the 737 this was exasperated by the presence of an inherent source of instability originating from hardware design.
> The people who wrote the code for the original MCAS system were obviously terribly far out of their league and did not know it.
Hmmm... having met a few embedded aerospace software engineers, I'm not sure I would be pointing the finger in their direction, although I would love an insider account. All public information seems to indicate these were decisions made at the executive level.
They could have blown the whistle anonymously then.
Do we know what is next for Boeing in that same segment? Are they planning to come up with another 737 variant after the MAX, or starting from a completely different platform[1]? Did they disclose anything?
[1](I mean from a technical standpoint - not marketing/naming)
Because that would force retraining? “Sometimes the MCAS system will disagree, if that happens it will disengage and you are no longer flying a 737, good luck!”
I still don't get how this design was ever allowed to happen or continue to happen. Passenger jetliners shouldn't be dynamically unstable.
The Max could fly without MCAS just fine, but pilots would have to be re-trained. Airlines didn't want to foot the bill for such an expense so Boeing applied the Maneuvering Characteristics Augmentation System (MCAS) to literally augment the maneuvering characteristics of the Max to match the 737-NG, which pilots are already familiar with.
Bugs in the system then led to runaway trim which caused a stall and crashes.
But it isn't just an issue of retraining. To prevent inadvertent stalls, FAA regulations require increasing control stick force feedback - a requirement which the Boeing 737 Max did not meet without MCAS.
I wish we had a good source, the best I've found is the 737 technical site, I wish it was available in an official report.
https://www.faa.gov/foia/electronic_reading_room/boeing_read...
Page 10:
>The 737 MAX was designed to handle and feel the same to the pilot as the 737 NG. Without the MCAS function, in some small areas of the flight envelope — such as approaching a stall and during higher g-force maneuvering — the new engines contribute to the control column feeling lighter in the 737 MAX than the regulations allow. These are not areas of the flight envelope in which the airplane normally operates. However, FAA regulations - specifically 14 CFR 25.143, 25.201, 25.203, 25.251, and 25.255 - still require the control column to have a higher pull-force feel in these flight regimes than would exist on the 737 MAX without the added stability from the STS and MCAS function.
> The LEAP engine nacelles are larger and had to be mounted slightly higher and further forward from the previous NG CFM56-7 engines to give the necessary ground clearance. This new location and larger size of nacelle cause the vortex flow off the nacelle body to produce lift at high AoA. As the nacelle is ahead of the C of G, this lift causes a slight pitch-up effect (ie a reducing stick force) which could lead the pilot to inadvertently pull the yoke further aft than intended bringing the aircraft closer towards the stall. This abnormal nose-up pitching is not allowable under 14CFR §25.203(a) "Stall characteristics". Several aerodynamic solutions were introduced such as revising the leading edge stall strip and modifying the leading edge vortilons but they were insufficient to pass regulation. MCAS was therefore introduced to give an automatic nose down stabilizer input during elevated AoA when flaps are up.
http://www.b737.org.uk/mcas.htm#background
The following debacle of only relying on one input, trying (and still trying) to blame the pilots, a 1960's designed system, not declaring it as a safety critical piece to reduce review and so on is well documented.
And most of all, and the truly inexcusable part, zero redundancy.
There are plenty of aircraft with common type ratings which are more different than the Max and the NG. As an example the 757 and the 767 share a common type rating.
So it might not exactly be a fighter jet but its outside of the bounds of passenger airlines.
(Or if they'd just correctly classified MCAS as a safety critical feature and made it have redundant inputs).
Well, they are. The active yaw damper is required by the FAA.
The cited article doesn't even seem to support the line in the wiki. I don't see the word "unsafe" anywhere in the cited source and the only "requirement" is the descent to FL260 in case of a failure.
You might also be interested in fatal crashes resulting from yaw damper failures:
That is incredibly tragic.
The EA flight received an Emergency Airworthiness Directive instructing them to (1) restore normal trim with the electric trim switches and then (2) turning off the trim system with the cutoff switch. They did not follow those directions.
Runaway stabilizer trim is the trim motors coming on and driving the stabilizer in an adverse direction. This is exactly how the MCAS failure presented itself. The author tries to claim it isn't really runaway trim, an argument which doesn't make sense.
It looks like you are pushing a certain agenda.
Anyway, just because the pilots "could have" recovered the plane(s) they were flying, does not make the design of MCAS sound. By all accounts the MCAS design was botched (single source of inputs, no sanity check on the inputs, etc.). This does not seem to be a point of controversy. Plus, as others will point out, two hull losses are a grim testament to this.
Other times this has come up, I faulted Boeing for making several design errors in the MCAS.
But the pilots bear some responsibility, too, because they did not follow runaway trim emergency procedures. In order to make flying safe, all causes of an accident (and there are usually many for each accident) must be addressed.
Your agenda is throwing "shade" at Pilots and insinuating that their responsibility is much larger than it actually is.
I am not sure why you keep pushing this given that you yourself are not a Pilot. Yes, you have listed your credentials but they are not a substitute for the actual job of "Piloting".
As a layperson starting with the collection of data from https://en.wikipedia.org/wiki/Boeing_737_MAX_groundings (which also contains a link to this article) it is very clear that Boeing is fully to blame for NOT disclosing the changes done to the 737 MAX system and how different it was from what the Pilots were used to. The Pilots were shown and assured a facade (i.e. everything works the same as what you know and trained on!) but when things went wrong they had no training to handle the new components behind the facade (they were not even told about these!).
It is inexcusable and Boeing bears full liability.
So you're saying that out of 3 flights with this issue occurring: 2 have crashed and 1 has been recovered by the crew. And this supposed to be a supporting point? So 66% failure ratio due to whatever circumstances?
Everywhere in this thread you are saying that MCAS was a good concept, the execution wasn't. As a software person, albeit not in aviation but worked with piston aviation engines engineers (so I kinda understand the whole concept of airworthiness and what goes into the certification process), I have to say that there are many ideas one comes across as sound on paper but should never be done just because they can be done.
The other thing which really raises my eyebrows is the claim, and I'm sorry if I'm misinterpreting what you are saying, that the EA and LA crews were able to apply the correct procedure multiple times yet the aircraft still crashed?
> But the pilots bear some responsibility, too, because they did not follow runaway trim emergency procedures.
So here's a question: would that single procedure justify the need to retrain pilots? Why would pilots fail to execute this emergency procedure if the aircraft was flying like the original 737 or NG? Would the crew be required to execute the same procedure on earlier 737's in a similar scenario?
That's the best read of what's going on with the 737 Max system and the MCAS software that helps to drive it.
Totally understandable now.
http://www.gregorytravis.com/About/
He also writes about runaway trim: http://www.gregorytravis.com/WhyDoesNotPresent/ and assumes that Cessna training on stab trim is the same as for a jet airliner.
It isn't.
He also seems quite unaware that the flight previous to the LA flight that crashed also had MCAS activation, recognized it as runaway trim, and recovered by simply turning off the stab trim.
Jet pilots require substantially different flight training.
While this is true, for air-breathing propulsion engines there's another factor: It is more efficient to accelerate a lot of air a bit, than a bit of air a lot. That's why the jet engine was replaced by the turbo fan with increasingly higher bypass ratio: they have a jet engine in the middle, but the fan also pushes through a lot of additional air that passes around the turbine itself entirely.
In particular, the propulsive efficiency under some simplifying conditions is 2/(1+v_ex/v_in): the higher the exhaust velocity the worse the efficiency.
https://en.wikipedia.org/wiki/Turbofan
https://en.wikipedia.org/wiki/Propulsive_efficiency#Jet_engi...
Origins of the D Programming Language https://dl.acm.org/doi/pdf/10.1145/3386323
Software development can learn a lot from aviation designs.
I will not question this.
They fixed that and moved to semver, and the FAA should put limits on what can be "technically the same version" too.
It seems we're learning the same lessons over and over again about the nature of failure in complex systems. It seems reasonable to me that we'll observe more of these failures as our world becomes increasingly complicated, particularly in social and economic systems.
Perhaps we should be teaching the fundamentals of complex systems in high-school just as we teach basic science? It seems to me there is a distinct lack of appreciation of the nature of complex systems in our culture at a general level.
Just as some people think it would be better to learn statistics than calculus in high school - I wonder if it would be equally important to learn about complex systems?
I'm interested to hear what others think.
1. Use the Wikipedia Page https://en.wikipedia.org/wiki/Boeing_737_MAX_groundings as your starting point for understanding the details. This article and more and better ones are all listed here.
2. This article from The Verge is the best for the layperson to get the overall picture of all the issues involved: https://www.theverge.com/2019/5/2/18518176/boeing-737-max-cr... Note that "Human Error" mentioned here refers to everything from Boeing Management, Marketing, Sales and Training.
3. Article on Department of Transportation Inspector General's scathing report on how Boeing misled FAA and everybody else : https://www.flightglobal.com/airframers/inspector-general-sl...
4. Remarks from "Allied Pilots Association" : https://www.businessinsider.com/boeing-737-max-apa-head-ques...
Boeing's previous suggestion that pilot error may have caused the crashes "offended" members of the APA, Carey said, as he criticized suggestions from some in the media that training standards may have been lower in the countries where the crashes occurred.
"To make the claim that these accidents would not happen to US-trained pilots is presumptuous and not supported by fact. Vilifying non-US pilots is disrespectful and not solution-based, nor is it in line with a sorely needed global safety culture that delivers one standard of safety and training."
He also said that Ethiopian Airlines has a simulator for the 737 Max, while no US airlines do.
5. Blaming Dead Pilots by Boeing and its lobby in Washington : https://www.corporatecrimereporter.com/news/200/blaming-dead...
https://www.amazon.com/Flying-Blind-Tragedy-Fall-Boeing/dp/0...
It talks about GE a lot as well, as both companies were destroyed by the Jack Welch "school of managers".
The one that was followed by the Ethiopian pilots and the plane still crashed, resulting in the grounding of the 737 Max by all aviation authorities bar the FAA?
For reference:
Boeing Emergency Airworthiness Directive
"Initially, higher control forces may be needed to overcome any stabilizer nose down trim already applied. Electric stabilizer trim can be used to neutralize control column pitch forces before moving the STAB TRIM CUTOUT switches to CUTOUT. Manual stabilizer trim can be used before and after the STAB TRIM CUTOUT switches are moved to CUTOUT."
https://theaircurrent.com/wp-content/uploads/2018/11/B737-MA...
I highlighted the omitted action.
This was also not pointed out in any type of pilot accessible documentation either; nor did it apparently make it's way to the FAA; as I recall them mentioning it was supposed to at max apply .6 degrees trim at once, but was later changed to ramp up to 2.5 degrees trim repeatedly, without an updated safety analysis.
Paperwork update failure:
https://www.avweb.com/recent-updates/business-military/mcas-...
Electric stab trim switch reset of MCAS activation timer was mentioned in the final report.
https://www.faa.gov/foia/electronic_reading_room/boeing_read...
You can also turn off the trim system while using the trim switches giving a 0 second delay. The reason is the circuit turning on the trim is a wire with the trim switch and the cutoff switch in series. Both have to be on for current to flow. Think of it like a light switch in a room and the corresponding breaker in the breaker box. Both have to be "on" for the light to come on.
The evidence that this is quite possible is the first LA crew experiencing MCAS malfunction trimmed back to normal, turned it off, and landed safely.
https://www.seattletimes.com/business/boeing-aerospace/boein...
In their eagerness to match the procedure, they actually lost a level of granularity in system isolation. The infamous "electrical short" misunderstanding, I think, may have risen from system description that supported the change. The idea being a short in the yoke switches could cause a runaway, which is what the left switch in the NG is for isolating, and the right switch was for isolating the Autopilot.
In MAX, this distinction was lost. Either switch completely isolated both Autopilot and yoke switches.
Assumedly, if one was very studious and aware of the switches purpose in the NG, one could get taken by surprise flying the MAX if they expected them to work the same way.
This is why I tend to beat into my devs the importance of "if you change the interface, you explain the change, or you offer the ability to fall back to older behavior.
I realize that's not practical in aerospace's regulatory environment, but it is nevertheless a helpful guide.
If they did not understand the EAD, all of it, it was their job to get clarification.
P.S. At least you read it. That's nice to see, and rare.
Besides, consider that overhead is a matrix of circuit breakers. Their purpose is so the pilot can individually shut down each system. They work just like the breakers in your house.
The stab trim, however, is so important the switch is right there on the console within quick & easy reach. It's still a breaker, though. It works by cutting off all power to the trim motors.
It's really not rocket science. It's a freakin' switch.
The author's name is Gregory Travis, and this abridged paragraph stands out to me:
> Another difference is between the autopilots in my system and that in the 737 Max...
> ...the system simply goes off-line and alerts the pilot that she is now flying manually.
Why would the author refer the themself in the female? Is Gregory a female name too, or is this some literary device that I don't understand?It's a thing that has become more popular to get away from assumptions that one sex or another is predominantly associated with some manner of activity. I've noticed it in several different authors writings. Or it could be that that by 'she', the author is referring to their aircraft, which I believe traditionally is considered a "she" just as a ship or boat is.