Flying the Unflyable Plane: The near crash of Air Astana flight 1388
admiralcloudberg.medium.com
admiralcloudberg.medium.com
It's truly remarkable that they managed to land that plane, against all odds.
In this case, though, better design, better tooling, and better training are probably the best fix; there are too many variations in stick-to-aileron connection for a single standard to be accepted.
Hats off to the Air Astana guys. That's some solid debugging work and very impressive ability to keep calm and focused under pressure.
My guess is that in this scenario, small angles of yoke deflection would have little effect, and the pilot's almost instinctual response would be to increase that deflection, quickly reaching the point where the spoilers would kick in, giving the sort of roll response the pilot was seeking (together with some unexpected yaw that I suspect also happened in the actual case). It would be a problem, but not quite so counterintuitive and baffling.
In short, the mental model required to understand the plane and its indicia of state was way too complex. These guys literally had to read technical manuals and follow (run-book) procedures step-by-step while the plane was cavorting.
Dynamic stability is the tendency of a system to restore stability, given external forces. There should be a term for dynamic-breaking stability, the ability to restore stability when broken, while also maintaining dynamic and static stability.
This is probably the only real benefit of devops: designing systems on the assumption people will need to intervene to fix them during moments of highest demand.
I remember one accident where part of the cause was that both pilots were trying to yank the plane in different direction, and the system just averaged out both inputs and as it was fly by wire and there was no feedback and "too much to do", pilots didn't notice. That's the reason why many planes have pilot's controls connected with eachother - so one can feel what the other one is trying to do.
> This is probably the only real benefit of devops: designing systems on the assumption people will need to intervene to fix them during moments of highest demand.
I have noticed the interesting trend when it comes to automating and "cattlefication" of everything - the less something breaks the less everyone involved understands it. Because it's automated and because nobody needs to even read anything to deploy it (just add a line in Puppet manifest and you're done) when it does break not even the author has a clue why. Documentation helps a little bit but there is a gulf between "describing what it is and how to use it" and "knowing enough to find where the problem is.
That is one of my pet peeves with modern development. A lot of things are way too easy to get started with, while very few people understands what is going on. And then when things doesn't work so well, there are even more tools and frameworks that can be deployed without understanding, but that in some ways mitigate the problems. But now it's even more complex, and suddenly there's a team of 20 people maintaining an application that doesn't do much more than moving some files between servers, reading them and saving records in a database. Sorry, not a database, five different types of databases that no one in any of the teams have any deeper understanding of.
I bet designers of software were like "there is no need to check whether moving it in direction actually moves it in that direction, we have thousand procedures to make sure hardware is done right". Defense in depth really is the best approach, not just strictly for security
The Proton crash involved angular velocity sensors -- rotational accelerometers -- installed upside down. It's not that it wanted to fly into the ground, it was that it couldn't fly straight because (from the guidance computer's perspective) it was responding backwards to the behavior commanded by the guidance system. And rockets just don't fly sideways very well.
Watch the direction of thrust from the engines (the Proton, like most rockets, steers by thrust vectoring) in this slowed-down video of the incident:
The ones I find most interesting are those where I remember the media coverage at the time. So often, the post has fascinating details which emerged later. For example:
https://admiralcloudberg.medium.com/days-of-our-discontent-t...
I remember this crash of a Jamaica-bound plane after 9/11, and I remember the press reporting initially that the tail had been repaired at the factory, and then a few months later that the NTSB had issued a directive that pilots shouldn't respond to wake turbulence too aggressively.
However, the cloudberg post has fascinating details about how the particular characteristics of a training scenario for the A300 had led many pilots to conclude that the proper response to wake turbulence was massive inputs to the controls. It would have been easy to conclude the pilot who made them was just incompetent. But in fact, evidence was he was very competent, and that he had learned what the training taught him quite well. The trainers did not understand what the implementation of their simulation was teaching until after the accident was investigated.
Also, the industry did not fully understand what tests for structural integrity of the tail really said about its capacity to withstand inputs at lower speeds until after this crash. The details are just fascinating.
Or this one:
https://admiralcloudberg.medium.com/lost-souls-of-grammatiko...
About a plane where everyone is unconscious and it circles until it runs out of gas. I remember the coverage at the time, which presented it as a mystery. It turns out it wasn't such a mystery, the compression system on the plane was left in an incorrect state by maintenance, and the pilots repeatedly failed to recognize it. The details behind those short statements are fascinating.
Anyway, thanks for posting this.
whew : ) but yeah, a pretty epic save
> and how this wasn't an issue in manufacturing?
Manufacturing does same exact thing every single time in order and then someone checks it.
But this was something staff don't do often.
Are there any home-computer flight simulators (or their controllers) that can be hacked to simulate reversed ailerons?
Yes, it took me ten crashes before checking that the control surfaces move the right way before flight. Now I run a battery of tests, each one inspired by multiple crashes.
I wonder if you could do it by dicking around with the joystick inputs, giving "reversed" controls over the first little bit, then a dead spot, then correct inputs once you've moved more than a certain amount?
I'm going to go with "pretty much no". I'm prepared to bet that you in your house with no pressure could probably more-or-less do it, because you know already what's going on and you're not going to die and you're not in a real plane with your primary instrument - the Mk1 Human Backside - being tossed around enough to knock it out of calibration.
Have you seen the film "Sully"? If not I won't spoil it for you, but it raises a similar issue.
I have seen "Sully", but I don't recall where the issue of inverted controls came up, either in the movie or the actual incident.
Part of me wonders if also as long as you see the ailerons _move_ you assume they've moved in the right direction. There have been similarly tragic rigging accidents in GA aircraft as well – and 38 incidences of aileron mis-connection in gliders between 1974 and 2014 reported in the UK. [1]
[1] https://members.gliding.co.uk/wp-content/uploads/sites/3/201...
The instances in the past probably caused the newer ones to make that impossible
Works fine for cars though. Drive through lube shops and states with safety inspections will perform indicator checks this way. If you push the left blinker and the right light starts flashing you've got a problem...
Hopefully by now the cockpit has access to external cameras to visualize what's happening behind them in real time
Pointless. Reversing of controls is not possible between flights.
After service it should've been on checklist to validate everything (really, if plane's computer have feedback on position it should immediately alert), but, well, I'd imagine after this it will be mandatory anyway