Boeing looked for flaws in its Dreamliner and couldn’t stop finding them
wsj.com
wsj.com
There was an Al-Jazeera report that was more substantial than any of the other mainstream US media on this, and it was damning and that was done a decade ago. No one has been held to account for the systematic failures that were largely introduced as a result of upper management and propagated due to failures in process with the FAA. I'd like to see a corruption probe, and mandatory cool-off periods for regulators seeking to jump from regulation to working in the industry.
As the name might suggest, Al Jazeera isn't a US media company. And despite being Qatari state owned, has mostly retained its editorial independence. It reminds me of what the BBC used to represent.
https://www.boeing.com/company/general-info/corporate-govern...
This still smells strange, even if the Boeing employees are the most knowledgeable about the planes, having them be under FAA "control" but Boeing pay seems counter-productive.
I wonder if after it's all said and done, whether the splitting up of parts manufacturing will really have saved that much money. I also wonder how much of this is caused by pushing materials as far as they can go to get to the fuel/efficiency targets they want to hit.
Yeah but after I read this:
>The FAA delegated an increasing number of tasks to a group of Boeing employees authorized to work on the agency’s behalf.
I first imagined a typical corporate group which might have turnover and I thought: What if the FAA delegated to individual people, so if Boeing fired someone for raising too much concern the role would fall back to the FAA? But yeah, its still a conflict of interest no matter how you do it.
If the politician themselves make too much, then voters might not like that. If all government jobs pay "too well" then that too would meet opposition. But, as a colorful example: suppose that being a politician was tied to the median wage of the nation, then would anyone object to paying this type of oversight position adequately?
Also, I'm not necessarily convinced a decent enough paycheck is enough to dissuade from corruption. Sure, it helps but it isn't enough on its own. If a person is getting money under the table, then they are making even more money even if they are already making a pretty sum. It's just that the size of the bribe would have to increase proportionally to their salary.
This has had a side-effect of some actually qualified technical people from leaving because of salary.
The FAAs job is to ensure that certification happens and that it is done right; but not necessarily doing it themselves. And effectively they aren't because they let Boeing self certify currently. So, this would be an improvement.
The underpayment is a consistent factor that keeps cropping up wherever you search for the reason why a government project or entire structure failed or went over time/budget.
It does seem, though, like you might want to have something like government pay at 90% of the market rate, so that highly-skilled and in-demand jobs do get pay that is close to the market rate.
So the situation is already what you describe, for the most part.
This is what happens in the US when your company is in a regulated industry and has been found to be so far from best practices that the regulatory body shows up one day, says "We need x number of offices" and then takes over managing your firm until they are satisfied enough Corrective Action have been performed and enough Preventive Actions are in place to right the ship.
Solution: don't get into a regulated industry, and if you must, keep your house in order.
Consider the record of the 737 MAX alone and up to the point where it was grounded worldwide. I bet that's not a great ratio of fight hours to lives lost compared to Boeing pre-merger.
FWIW the only person charged with criminal offenses in the 737 max is the chief test pilot, Mark Forkner[0]. Guess how many business degrees the guy has?
0: https://www.nytimes.com/2021/10/14/business/boeing-737-pilot...
but the reason its so safe is because there are so many redundancies built into so many different layers of the system.
once rot starts to happen, it’ll take the better part of several years or a decade for a wave of elevated fatalities to manifest themselves in these stats.
There’s a similar failure mode in pre-MAX 737s called “runaway trim”. The giant trim wheels on the center pedestal spin in a loud and attention-getting fashion. The fix? Pull the breaker on the overhead panel.
The MAX does not have a stick pusher. MCAS works on the position (trim) of the stabilizer. The elevator feel system (which the NGs have as well) works by creating additional resistance at the yoke (which is hydraulically assisted). Neither are stick pushers.
> There’s a similar failure mode in pre-MAX 737s called “runaway trim”.
That's a thing that can happen on any plane with a similar horizontal stabilizer setup. I'm sure even a plane with a flying stabilizer (e.g. L-1011) has similar failure modes.
> The giant trim wheels on the center pedestal spin in a loud and attention-getting fashion.
The "giant" trim wheels were reduced in size on the NG (and MAX?) reducing their leverage.
> The fix? Pull the breaker on the overhead panel.
There are two switches (whose function was subtly changed with the MAX) that control the trim motors and they're located behind/below the thrust levers.
The design goal for the software was to make it fly like other 737s. The software did not actually do that, but did "something" that inspectors allowed was just enough different from without to certify. And, in case of equipment failure, or various other circumstances, the software failed completely, because it was just really badly designed. If you knew about the system, you could turn it off in case of trouble, and then the plane would fly fine, just not enough like a real 737 that you could completely ignore the difference.
Then they made it hard to know that the system was there. People who knew how to turn it off could prevent disaster.
Thing is though the pilots of the second MAX crash took all the right steps. Just too slow.
There was like 10 seconds to turn off mcas, after that a crash was inevitable.
It wasn't the engine thrust. There were a bunch of subtle design changes because newer, fuel efficient engines are much larger than the style of engine when the 737 was first designed. Unlike the competing A320, the 737 didn't have the necessary clearance under the wing to fit the new engines.
They had to make a bunch of tweaks like moving the engine higher up, further forward, tweak the wings etc. to make it fit with the necessary ground clearance. These subtle differences added up so they added MCAS to make it handle closer to the original design.
But instead they wanted to handle like something it wasn't and then made buggy fix for it to do so.
This had two problems. Firstly, this flight characteristic (more AoA gives less stick pressure) is considered risky, because it can trick pilots into thinking the AoA is decreasing. Secondly, and apparently more importantly to Boeing and American Airlines, this meant that pilots certified to fly the old 737 would need to go through new training. This new training was required because of a significant change in flight characteristics and would be very expensive to airlines.
So Boeing created MCAS, and tried their best to hide the change so no one would question whether new training might be required. If I recall correctly lion air (the airline of the second MAX crash) had actually asked Boeing if they should do some new simulator training for the 737 max in an e-mail and had been ridiculed for even asking that.
If not for a brain dead design decision to not check for bad AOA data, we probably still would never have heard of MCAS.
But ultimately MCAS was a symptom of a failure of process, with people whose entire job was to check and veto designs failing to veto designs, apparently for fear of management pressure. To be clear, the failure was in management. It sucks that people had to die to get us to notice ordinary management failure.
The Lion Air jet had the same MCAS failure on its previous flight. If you dig through ASRS you'll find other reports of uncommanded pitch down events on the MAX. Just because MCAS hadn't yet crashed a plane doesn't mean that nobody noticed its presence.
Do you have examples of incidents that appear otherwise?
This means that there is no (financial) pressure on the passenger to fly on an aircraft they do not trust.
Currently the live-or-die risk devolves to the passenger and they have no direct say in the choice of aircraft: after ticket purchase they are left with a take-it-or-leave-it proposition.
This system might force airlines to think much much harder when making their aircraft purchasing decisions.
Just because the aircraft is certified will no longer amount to adequate commercial due diligence.
An airline which wants to protect its revenue will now need to deep-dive into the manufacturers quality procedures themselves.
Otherwise their customers can vote with their feet, at no financial cost, any time prior to departure.
"How To Avoid Flying The Dreaded Boeing 737-MAX"
https://www.godsavethepoints.com/how-to-avoid-flying-the-dre...
For example, jetBlue only flies Airbus and Embraer. Spirit and Frontier exclusively fly Airbus. Lufthansa's commercial fleet is mostly Airbus and the Boeing aircraft it does operate have good track records.
I've no problem getting in a Boeing airplane. The 737NG, in particular, has one of the best (if not THE best) safety records in history.
As such, the 737NG - which had fatalities - is unlikely to be a contender, considering the much older A340 has had none.
[1] https://turbli.com/blog/the-safest-planes-to-fly-in-by-accid...
Better bring a gas mask[3] though. And bring one for the flight crew too in case they become incapacitated.
[1] https://en.wikipedia.org/wiki/Qantas_Flight_72
[2] https://en.wikipedia.org/wiki/Air_France_Flight_447
[3] https://viewfromthewing.com/is-airbus-doing-enough-to-stop-t...
so i think your point is completely invalid.
There's no such protection on the 737. Nobody's done that because unlike on the Airbus, it's never safe to do so. There are, however, plenty of ways to get caught off guard in a 737 and stall it. Take a look at the UTAir and Thomsonair go arounds that got their planes to about 45° nose up. Or the 737 Air Florida planted right into the Potomac because they didn't have the elevator authority to avoid the stall. Or Fly Dubai…
As for human interactions, the 737 is a series of bad choices (especially the MAX). Take a look at the Helios Air crash, the pilots were confused by an alarm that could mean two different things. Unfortunately hypoxic pilots aren't known for their reasoning ability.
here is what happened in the airbus air france incident:
- one pilot had the sidestick full hard nose up, the other full hard nose down.
- neither pilot realized what the other pilot was doing.
on a boeing airliner:
- the controls for each pilot are physically linked.
- if pilots try to put “their” yolk into an opposing position, they will start having to physically wrestle for control.
- this type of failure mode of the air france crash wouldn’t have happened in a boeing airplane; the pilots would have realized what was going on within seconds.
general note:
- when flying, it is highly unusual for both pilots to be giving input into the controls at the same time. one pilot “has the airplane”, the other is there to assist, help with the radios, planning, etc. the handoff between who “has the airplane” is very deliberate. this was another failure mode of the air france flight.
- but my point still stands, the fact that the controls are linked makes the gp point a bit moot.
Say what? Atlas Air face planted a 767 with pilots doing just that:
> The captain’s and the FO’s opposing elevator control
> forces continued for about 10 seconds, during which the
> airplane’s dive continued to steepen. Thus, the NTSB
> concludes that the captain’s failure to command a positive
> transfer of control of the airplane as soon as he attempted
> to intervene on the controls enabled the FO to continue to
> force the airplane into a steepening dive.
Or the Air France thing that's now on the front page. In a Boeing 777.
Poor training is poor training. Physical feedback is not a safety benefit. It sounds nice in theory but in practice doesn't do much. You can easily say the same thing about A vs B thrust levers, look at that Sriwijaya Air crash. The Boeing design sounds more intuitive until you look at crashes where the feedback didn't do a single thing to help the pilots or avoid a crash.
you cannot ignore a physical link.
you can ignore an alarm.
Both flights gave flight crews unexpected tests on unexpected situations-- something that seemed like runaway trim for the MAX, and simultaneous overspeed (better nose up) and stall (better nose down) indications for AF447.
The problem was that at some point the trim is so much that it becomes nigh impossible to hand crank the trim down, the trim flap applies so much pressure it cannot be overcome by hand. You had to disable mechanized trim because otherwise MCAS would kick in. So you would need to recognize the problem soon enough to prevent MCAS from moving the trim so far that it became unrecoverable.
(Source: Netflix documentary)
10 seconds is a long time of the trim wheel being cranked nose up. The same situation would apply to a stuck trim switch on the yoke. (Indeed, a stuck trim switch is worse in this respect because it cranks constantly and doesn't "yield" to the pilot pushing the switch the other way... of course, the checklist didn't presume a pilot should be diagnosing stuck AOA vs. stuck trim switch and thus recommended immediate use of the trim cutout switches instead of trying to electrically trim the other way).
There's a reason that trim runaway is a "recall" procedure in the QRH that pilots are expected to know-- it gets scary. http://www.b737.org.uk/images/runawaystab2020.jpg But it was the assumption before the MCAS disaster that pilots could deal with trim runaway, given that there was a history of flight crews dealing with trim runaway incidents in flight successfully. But MCAS was worse because:
A) It did it more often, so flight crews were exposed to this dangerous situation more than ever before
B) It did it in a sneakier, strange way (no constant movement of the trim wheel).
Still, some real-world flight crews did overcome MCAS doing the wrong thing without crashing, even if others failed the test.
- It's perhaps understandable why engineering teams-- pushed by management to deliver a 737 that doesn't require retraining-- decided that if flight crews could handle runaway trim, they could handle any errant MCAS activations and that the level of redundancy and fault tolerance necessary in the system would be low.
- On the other hand, real flight crews obviously do not do great when exposed to this test.
- If you give a flight crew a wacky situation with conflicting information (like AF447 or the 737 MAX)-- expect failures, even if the situation is technically 100% recoverable and flyable and some crews exposed to the situation succeed.
It's great that we have humans capable of reason up in the front of the plane, but reason is often faulty and doesn't get you the solution you need on the first try.
And yes, I strongly prefer airlines that do not use "modern" Boeing planes at all (which arguably might be a lot easier here in Europe). If it's Boeing, I'm not going.
What we are seeing is regulatory capture by McDonald-Douglass top level executives and board of the FAA. Standard operating procedure for the capitalists. Everything is permissible as long as it increases their and the shareholders' profiteering.
It's worse than that: They deliberately moved management to Chicago to separate management decisions from engineers. All those pesky pocket-protector-wearing eggheads were considered a nuisance who were apparently hellbent to rain on MBA powerpoint parades.
If someone squinted at Airbus with the same scrutiny, would they find similar problems?
I don't think there is an elephant in the room, but there's potential for an unknown problem, sure.
One way to understand the risk might be to do the differential on each companies commercial and military product, and its failure rate: the mil stuff has different pricing, and might have different 'six sigma' type rules around things because it has to manage being flown in much more variant constraints: bigger envelope, more risk. If they can do it "better" for mil spec, and don't do it better for commercial, then something is bust in the culture.
Also, Europe doesn't have US-style NDAs.
>> One way to understand the risk might be
Don't assume.
Europe certainly does have nda. Not like the US I agree but people are bound by confidentiality agreements enforced in contracts all the time.
Airbus cut 15,000 Jobs internationally in 2020. German unions forced them to halt layoffs in the EU until 2023
https://www.bloomberg.com/news/articles/2019-06-28/boeing-s-... https://www.industryweek.com/supply-chain/article/22027840/b...
Because they don't own anything. They're paid to enrich the requirements into software specifications and nothing else. It gains them absolutely nothing - so why would they ever feel any sense of ownership after the job is delivered and accepted?
The business relationship is predicated on them being disposable contract workers. At a minimum, a sense of ongoing engineering ownership requires an ongoing relationship predicated on trust and support - which requires ongoing financial support after the software project is 'completed' - which Boeing, in hiring contract workers, explicitly did not want to provide.
Given this, how can we seriously expect the engineers of an outsourced development shop, working under a piecework contract, to ever feel any sense of ongoing ownership?
We get really good as gaslighting and hope to find gullible fools
https://en.wikipedia.org/wiki/List_of_accidents_and_incident...
I am looking at these blames on outsourcing from that perspective - that Boeing is trying to blame others to hide their greed.
The Ethiopian pilots did not follow the procedure in the Emergency Airworthiness Directive distributed to all MAX pilots that says:
"Initially, higher control forces may be needed to overcome any stabilizer nose down trim already applied. Electric stabilizer trim can be used to neutralize control column pitch forces before moving the STAB TRIM CUTOUT switches to CUTOUT. Manual stabilizer trim can be used before and after the STAB TRIM CUTOUT switches are moved to CUTOUT."
https://theaircurrent.com/wp-content/uploads/2018/11/B737-MA...
You might want to also read the report:
2018 - 035 - PK-LQP Final Report http://knkt.dephub.go.id/knkt/ntsc_aviation/baru/2018%20-%20...
And note that the first incident of MCAS failure was overcome by the pilots and the airplane landed safely.
The documentary talks about the Ethiopian crash from 32:00 onwards. The below excerpt is from 34:30 onwards. Name of the person talking is in '[]' brackets.
[Pasztor] Soon after the hearings got underway, we managed to get more information about what actually happened in the cockpit of the Ethiopian aircraft. We got the information from the FAA within hours after they received it from the Ethiopian investigators. It was very late at night, and we tried to put together the most comprehensive story we could. When it came out, this was the first story that revealed that the crew, in fact, realized that MCAS had kicked off. And they did what Boeing instructed them to do.
[Tajer] When the MCAS kicks in, it runs for ten seconds and pushes the airplane very powerfully nose-down. Runs for ten, off for five. Runs for ten, off for five.
[Cox] They’ve got this cacophony of stick shaker, master cautions, airspeed disagree, altitude disagree. All of these…these warnings going off. The captain, who’s flying the airplane, is trying to figure out what’s gone wrong.
[Tajer] The first officer called out, “Stab trim cutout switches, Captain.” I think he said it twice. He did what Boeing said. He turned off the MCAS system. I remember reading that, and I said, “Man, the kid got it right. The kid got it right”.
[Cox] The problem now is that the airplane is going too fast. And because of the force on the tail itself, they cannot manually trim the airplane to be able to recover.
"Initially, higher control forces may be needed to overcome any stabilizer nose down trim already applied. Electric stabilizer trim can be used to neutralize control column pitch forces before moving the STAB TRIM CUTOUT switches to CUTOUT. Manual stabilizer trim can be used before and after the STAB TRIM CUTOUT switches are moved to CUTOUT."
https://theaircurrent.com/wp-content/uploads/2018/11/B737-MA...
They didn't follow the first part, which was to restore normal trim with the thumb trim switches, which override MCAS.
Is it? The single path weakness in the MCAS design was not a cost saving measure. I've never seen an explanation for why this mistake was made.
Avoiding this recertification was the only reason MCAS was chosen instead of designing an airframe in such ways the now bigger engines actually have their center of gravity where it is expected to be.
This was ultimately a cost saving measure. Boeing could not be bothered to recertify the airframe purely for comercial reasons, not because it objectively made sense.
I worked on the 757 design, which was designed concurrently with the 767. A lot of effort was made to make them behave in a common manner, even though they were quite different airplanes. This makes perfect sense.
It's the same reason the steering wheel and pedals on your car are laid out the same and do the same things across nearly all very diverse cars. And yes, carmakers adjust the handling characteristics to be predictable and not need the drivers to have additional training.
(With dual path, MCAS would have simply turned itself off if the two inputs disagreed.)
https://m.youtube.com/watch?v=QytfYyHmxtc
Between 35-36m-ish. 35:30 I think.
Boeing was claimed to have "known the FAA would not certify a dual sensor system without Level D simulator training".
This was from an insider at the time, and admittedly, I've not heard of an identity being put to them, but that signal was claimed to have been there.
There is also corroborating evidence that the Chief Technical Pilot actively dissuaded customers who asked for simulator time anyway, characterizing it as unnecessary. I don't have those at my fingertips right now, and unfortunately, my memory is failing me as to whether or not an "oh shit" moment was had at some point as to whether the Chief Technical Pilot had mischaracterized the system to regulators.
I just remember I thought it was awful convenient at the yime that this Chief Technical Pilot had all the hallmarks of a scapegoat for management to start piling blame on, and being glad he got independent counsel instead of relying on Boeing's General Counsel.
I watch every episode of "Aviation Disasters". On more than one, the pilots would get some warning light and would ask each other what it meant. That implies that simulator training is not required for every warning light.
https://www.reuters.com/article/uk-ethiopia-airplane-forkner...
https://www.seattletimes.com/business/boeing-aerospace/why-b...
Texts: https://www.documentcloud.org/documents/6497959-Boeing-Text-...
It seems they never leveraged anything more from this supposed whistleblower, so until more is seen, it's kinda moot. Still thought Forkner was a fall guy for bad management though.
There is a proximate answer that still does not get us to root causes: An MCAS failure was rated as a Major condition as opposed to Hazardous, in which case the regulations allowed (but did not, of course, require) a single source of input.
This rating was arguably justifiable for the 737 MCAS in its original form, but its power had to be increased significantly after flight testing revealed the original version to be inadequate.
As it happens, the 737 MAX airframe was not the first use of MCAS: the KC-46 also has it. Despite the fact that this system is less powerful than that which was fitted to the initial production 737 MAXs, it uses two AofA sensors. There is clearly a strong and obvious engineering case for doing so, so simply observing that Boeing did not have to do so does not exhaust the questions that should be asked.
I have seen it stated in several places that using two AofA sensors would have required a warning in the case of their being in disagreement, which in turn would require it to be mentioned in the AFM, which might have prompted a reevaluation of the no-training decision, either directly or through a reevaluation of the risk classification. Unless a smoking gun has been found, Boeing can stonewall on whether the training concern suppressed a full and objective evaluation of the risks posed by MCAS (especially after its strengthening), and thereby improperly influenced design decisions (among other issues), but the concern is obvious to everyone except those who want to avoid considering it.
Which I raised in the antecedent post.
I did not write that Boeing "did not have to" have dual sensor input. I said if they did have dual sensor input, and had done the other changes to the software, in my not-so-humble opinion additional simulator training would have been entirely unnecessary.
The other question I have is why two sets of pilots did not understand what the STAB TRIM CUTOFF switch was for, despite it being in a very prominent position on the console and is supposed to be a "memory item", meaning the pilot should not have to look it up in an emergency. That indicates inadequate training, whether the airplane had MCAS or not.
Keep in mind that the first MCAS incident, which is never mentioned by the press, landed safely because the crew simply turned off the misbehaving trim system. That crew didn't even seem particularly concerned about it after they landed.
> Which I raised in the antecedent post.
You did, in the sense that you wrote "I've never seen an explanation for why this mistake was made." That does not mean it is somehow wrong for me to also make that point as a prelude to continuing that line of thought.
> I did not write that Boeing "did not have to" have dual sensor input...
And I did not say that you did. I pointed out that this would not be a full answer to the question that both of us raised.
> ...in my not-so-humble opinion additional simulator training would have been entirely unnecessary.
I very much doubt that Boeing was at all concerned about what you or I think. It is rather more plausible that it was concerned about what the FAA might think, especially if the FAA also understood the extent to which MCAS's power had been increased.
And nothing else you have written here has any bearing on the possible motives behind Boeing making a decision that you yourself call a mistake - one which was made before these incidents.
One most of the projects I've worked on they got what they paid for. However, the executives who'd made the money-saving decision had moved on by then.
No, no, no, no! There is no „too much safety“ when we are talking about airplanes.
Feel your mirror sometime when you're driving in traffic at night on the interstate and it's been dimmed because of the vehicle following you for some time...it will be perfectly cold.
The electrochromic material between the panes goes through an oxidation/redox reaction in the presence of a voltage. In circuit, it functions something like a low-storage battery or capacitor. It does not have enough leakage current to cause it to get hot, that's just the effect of the sun on the plane.
The person you are replying to sounds to me like they put their hand on a window and it was hot.
So not for the reasons you rule out, but they have experience, you have theory.
The person that responded to that didn't say it was impossible: they did convey that the reason it was hot was not due to the window itself. The heat could easily be from the light being absorbed by the panel.
> that's just the effect of the sun on the plane.
This would the area where it could just be the effects of the sun.
I feel like the article is really grasping at straws here, and I'd be willing to bet the author doesn't even comprehend how small this is. 0.005" is small. For the hardware-challenged: 0.005" is a typical manufacturing tolerance for a standard-spec PCB. Some of the Chinese board-houses that deal in high volume are higher than that[1]. The fact that they even found a gap this size on something the size of an airplane is amazing to me.
[1] https://www.pcbway.com/pcb_prototype/PCB_Manufacturing_toler...
Also, 0.005 inches = 0.127mm, so we're talking about slightly more tolerance than the thickness of copy paper.
In short, just because 0.005 inch is a small number does not mean the article is grasping at straws. I routinely design mechanical assemblies where the difference between 0.005 inch and 0.010 inch is the difference between a comfortable factor of safety and guaranteed failure under design loads.
Edit: in this case it looks like it was airplane skin panels, some (most?) of which may be stressed members - meaning that it's not a cosmetic piece, it's a load bearing piece. If you have multiple panels with tiny deviations, that changes the loading of the whole structure, potentially leading to warping, flexing, and premature failure.
Why don't they make it one solid piece? You can do that with composite construction. Just overlap layers and glue it all together.
It could have something to do with how the fuselage change shapes and distorts under different conditions. The airplane goes through various different shapes depending on things like pressurization and thermal expansion. The body gets a bit bigger, the wings flap up and down, things get wider and shorter and harder, etc. etc.
With composite construction things are glued into place, but they need to be designed to accommodate this movement. The glues and such things have a particular amount of elasticity and fatigue limits.
Could be that a 0.005 amounts to 10% less gluing surface and thus the projected fatigue life of the glue is now much different because there is much less.
Just speculating.
> Why don't they make it one solid piece? You can do that with composite construction. Just overlap layers and glue it all together.
Are you suggesting they build the entire fuselage as one piece and "glue it all together"? It's an airplane fuselage, not a MacBook chassis.
That's basically how they build ships. The glue is just a little hotter.
It seems doable but QC would probably be a nightmare and it wouldn't be very repairable adding up to it not being an economically sane choice.
Edit: Since apparently this has to be said, they weld ships together creating what is in effect one single piece assembly. The point is that while the techniques for joining fibrous materials are very different, large single piece structures that flex and bow are fairly well understood and there's no reason you couldn't create one out of carbon fiber if doing so penciled out.
Both for pieces abutted against each other and for E.G. rivet holes, mechanical interfaces have extremely precise tolerances to support a range of possible stresses. Too wide a tolerance in one area can allow deformation and wiggle that applies unexpected forces on other areas. You should also remember that many aircraft are pressure vessels, since they operate at altitudes where the density of our atmosphere is substantially different.
Consider a geometrically perfect cylinder resting on a perfect plane. The contact is a line, with zero width. Therefore a contact area of zero. Pressure is force divided by area. So the nonzero weight of the pin, divided by area (zero) is... infinite? You run into the same problem with a pin in a slightly larger hole. How does this seemingly infinite pressure not lead to failures in wheels (think of train wheels on tracks), ball bearings (spherical balls in torroidal raceways with slight clearance), roller bearings, etc? We are surrounded by geometries that have seemingly zero area points of contact, but they support tremendous loads.
Hertz (yeah, the same guy for whom the 1/s unit is named) figured out the math behind these contact stresses. Basically, for round (and round-ish) things in 2d and 3d, the contact stress has a lot to do with the deformation of the materials. To answer the riddle above (of the cylinder on plane infinite contact stress), you have to consider the deformation of the cylinder and the plane. The stiffness of the materials comes into play, as well as the geometry. You can read up on Herz (or Hertzian) contact stresses if you would like to know more. The math is not terribly difficult, especially for 2d geometries. For a 2d case of a pinned joint, you can often find that a change of a couple thousandths of an inch can mean the difference between a comfortable factor of safety and failure.
I have given a hand-waving example of the importance of tight tolerances on clearances for a small class of problems. I hope it is close enough to the subject matter at hand to be of some use. My comment is from memory, so please forgive (and correct!) any mistakes I've made.
edit: I am rereading my comment, and realize that I didn't make explicit the importance of tight fit for Hertzian contact stress. The smaller the gap between a pin and hole, the greater the contact area (with the same amount of deformation). Think of it this way--for a fixed amount of deformation (say strain at failure), you can carry way more load if the contact area is greater. How do you increase this contact area? By a smaller difference in diameters (smaller gap) of pin and hole. So all things equal (material properties, load), a smaller difference between pin and hole diameters will increase load the joint can carry.
Another point: calculating these contact stresses is doable for most metals, but is far more complex for anisotropic materials (mechanical properties vary in different directions) materials like the carbon fiber composites.
I think others might be forgetting (or not know) that the factors of safety* for the parts in airplanes (around 2, or less?) are very different than factors of safety for the structural parts of bridges (around 5?). Compared on those terms, planes are light and fragile, on purpose, so you can't f around with cheating tolerances.
If I design a 10” Diam part to be assembled to another with a .001” gap, then a .010 gap is huge. If it’s a 10’ part that has the same tolerance, a 0.01” gap is still huge.
Tolerances aren’t arbitrary, they are analyzed and the issue is you generally don’t k ow what happens accurately if those tolerance limits are violated.
As for the mechanism, you need to worry not just about a single cycle load to failure, you need to also worry about shortened fatigue life (I,e, failure after many cycles - but many less cycles than predicted). Overall, load transfer is highly complicated in thin skin structures and that the gap is small doesn’t mean that a change in that gap crosses a small change in load
It's a failure of something no matter what, but "it doesn't matter how the gap causes problems" ain't true.
And for newer rules, you need to know why to double check that the rules have been made well.
Edit: Actually there are some highly technical replies and that's awesome! But I still stand by my point - the time to evaluate whether a test is fair or not is generally not when you're failing the test.
...well, this is a technical forum, and mechanical engineers get these types of questions all of the time. "Hey, the machinist accidentally machined this wall 0.010" too thin. Is it OK to use?" Then you run an analysis, and report something like, no, that's too thin, scrap it. Or, yes, because of X, Y, and Z, this one is acceptable. And maybe this means that you can update the drawing to use a looser tolerance. Or maybe it just means that this one time it is OK, because there is another expensive process that you can do to the part to salvage it. Then there is a procedure to track this non-conformance, until it becomes conformant again. And it becomes part of the permanent record. The missing piece of the article's puzzle is whether this was a critical dimension that should have passed some sort of inspection process. Maybe it should have been a critical (inspected) dimension, but wasn't called out as such on the drawing (a documentation error). Or maybe the inspection was called out, but wasn't done. Or the inspection wasn't done correctly (i.e. inspector reported that it met the tolerance). Or the failed inspection reports were ignored. Or the non-conformance was reported, and an analysis was done and was shown to be fine, but that paper-trail has disappeared. Or in fact all the paper-work is in order, but for some reason wasn't available to the person informing the author of the article. Lots of different rabbit holes to go down here, but we don't have much to go off of.
Hahahahahahahahahahahahahahahaha
Source: worked in places that manufactured aerospace stuff.
The .005 is likely the output of some other calculation that got copypasta'd because why not.
Sucks to be Boeing, I want them to be successful. Hell, I even liked that big goofy looking X-32 which was a JSF competitor. People die when their planes fail, it's nothing like a PCB as mentioned by the grandparent. They f-ed around with the 737Max and found out. Honestly though, if your loved ones died on a 737Max and then you found out that they weren't building planes to the specs that they defined, what would you think?
Bob: You've called for a 5mm hole here, but you don't have a precision specified?
Alice: I really only need the sort of hole a 5mm drill bit would produce.
Bob: Do you know what level of precision that is? Have you done any calculations to confirm that's the appropriate level of precision?
Alice: Not really, in my judgement this doesn't rise to the level of needing such calculations.
Bob: Well, our drawing quality standards require a precision to be specified. Would ±0.5mm be OK? If not, how precise does it need to be?
Alice: How precise is the laser cutter we're cutting this out on?
Bob: The spec sheet claims ±0.05mm
Alice: The required precision is ±0.05mm
Not every hole needs a tight tolerance, depending on the loading and assembly methods. And manufacturing prefers a standard tolerance range to be specified to enable consistency in manufacturing operations, rather than some weird lopsided super precise tolerance callout. So you determine the largest tolerances that will meet your design requirements, then select a fit class from the manufacturing standard that meets your tolerance requirement.
Sometimes you just need a specification, because you have to tell your mfgr something[0]. Notably 5 thou is a pretty standard idgaf-tolerance, but in this specific case might be important.
[0] e.g. a spec of 5" is meaningless, 5.00000 +/-.000001 is insane, and 5.000 +/- 0.005" is (generally) readily achievable and good enough.
The way I see it is, if there's a spec. that specifies such a small tolerance (in an airplane of all things), it must be there for good reason.
This below site/article seems to give the most technical description, although I know nothing about aircraft engineering.
And for reference a sheet of bog-standard copy paper is right around 0.004".
If the tolerance was indeed too strict I would expect Boeing to go through a engineering review and seek approval from the FAA.
People who work on assembly lines are really good at keeping the line moving. But I don’t want someone who’s perf bonus relies on pushing out aircraft determining on-the-fly if something that’s outside of the spec is safe or not…
And this isn’t a knock on blue collar labor, almost no one at Boeing has the knowledge to work through all the potential side effects like this.
It's perfectly fine for manufacturing to say, "We can't meet this tolerance, are you sure it has to be this exact?" Then design engineering looks at it, decides it does not need to be that exact, and updates the tolerance.
It's not okay to just ship passenger airplanes that don't meet the build specs.
I have no idea what aircraft manufacturing is like, but the idea that a part might go out the door without matching its drawing is definitely concerning. The drawing and the associated calculations are supposed to be the proof that the matter was considered, and that an informed decision was made.
https://www.nytimes.com/2019/12/09/business/boeing-737-max-w...
https://www.cnbc.com/2021/04/16/more-electrical-problems-fou...
- older, more mature organization
- based near the engineering teams; frequent collaborations
- unionized, highly skilled workforce
The people who took over Boeing and moved the HQ out of SEA intentionally picked SC to union-bust their own workforce.
MBAs just refuse to believe that workplace culture and experience matter — so they treat high skilled workers like dumb, replaceable cogs and then their companies fail a decade later when the senior/principal staff are incompetent or non-existent.
That same mentality is why their new planes have major issues:
They don’t have competent senior/principal engineers because they viewed mid-career engineers as “too expensive” — and so didn’t train any.
FWIW "right to work" is the normal terminology.
It's better to just allow people to name their own movement, otherwise, you end up endlessly fighting about names (i.e. are people 'pro-life' or 'anti-choice' and 'pro-murder'/'anti-life' and 'pro-choice').
Right to work laws do not in any way provide a right to work.
Especially since RTW legislation is not about closed shops (which are illegal at the federal level), so these were jobs you could always get.
The latter is essentially a term of art, the former is not. Using the former is imprecise and confusing.
> Realistically, it's best described as "mutual right to terminate employment without cause" or just "right to terminate".
That is a completely different concept called at-will employment. RTW is about union shops (not to be confused with closed shops, which have been illegal in the US since Taft-Hartley)
What?
Goes to show... something, I guess.
That one factory is the home factory close to where the designs are made and the other is so far away seems like a pretty important thing.
This seems like the kind of argument people who really love unions would make.
When that starts, we may expect they will start by exploding mainly on test stands, instead of vehicles.
My intuition is that the latter would exceed the former, and that test stands aren’t a realistic environment for predicting their likelihood.
It is hard to imagine how you would determine, after the fact, whether a rocket blew up because of material failure or something else, but they seem to do it, anyway during development when they have a zillion sensors attached logging everything in real time: "hmm, a millisecond before the explosion, this reading went out of tolerance, and then this one, then this one, and then the data ends."
When the management pressure is for better quality, the union may interfere. Where management pressure is for lower quality, the union should interfere.
We see the harmful effect of unions where the police are in one.
None of this should have made it out of the factory floor. Every crew that works on a plane has to certify (literally sign off a form) that when they worked on the plane they left it in good shape (no obvious defects, like metal shavings, tools left inside, etc). If the next shift comes in and finds dangerous debris or damage the prior crew should have noted, then the prior crew is required by the FAA to have a formal report written against them, as they have created a dangerous plane.
Management has applied heavy pressure to my friend repeatedly to not report these incidents, despite his legal obligation. Ultimately, he took a $25k hit paying back the Boeing relocation package and left after 10 months to work on repairing trains (which has been a significant improvement).
Yeah, the idea is to have management put pressure on the people who left stuff in bad shape. Shooting the messenger isn't the right answer.
When I was a kid, half the parents I knew worked at Boeing and were proud of the quality engineering or manufacturing they did, but over the past two decades Boeing has had this crew retire and has worked to shift to a blame the messenger culture.
https://en.wikipedia.org/wiki/Downfall:_The_Case_Against_Boe...
Publishing his experience anonymously is likely impossible, but if not, I’d be really keen to read it.
Some reporting suggests several major customers (airlines) were so fed up with this 'foreign object debris' (metal shavings etc) problem that they said they would only accept aircraft from Washington. From your story, I can't help but wonder if Boeing management got around this by flying near-complete aircraft from SC to WA to get around this.
To give you a sense of how bad this debris issue is: the US Air Force refused delivery of new air tankers after finding debris (in fuel tanks if I remember correctly).