No, it most certainly was not a seal that failed. It was an organization that failed. Unfortunately, it's harder to fix an organization than it is to design an O-ring that won't become brittle from sitting out a few hours on a cold night.
No, it most certainly was not a seal that failed. It was an organization that failed. Unfortunately, it's harder to fix an organization than it is to design an O-ring that won't become brittle from sitting out a few hours on a cold night.
The seal performed exactly as it was specified to. The spec was that below certain temperatures it wasn't guaranteed to perform as a seal, and that's exactly how it performed.
The issue was that some level of management was alerted that they were operating outside of the spec, and they gambled that it didn't matter.
Of course, the Thiokol engineers weren't sure that 40 was sufficient (they were worried about anything below 52 degrees), but in defense of the people that chose the o-ring material, Challenger launched outside of the design spec for the Space Shuttle.
The seal leaked during initial static pressure testing, it leaked during test-firings, etc. Engineers and management at both Thiokol and NASA knew about this. NASA engineers repeatedly objected to the Thiokol design (both original and modified) for different reasons, talked to the o-ring supplier who stated that the design was using o-rings in a way never used before, etc.
The author of the blog post is wildly wrong, but so are a lot of comments.
Everyone, PLEASE read the Rogers Commission report. It spells out the extensive problems with the design/manufacture, and at both Thiokol and NASA.
https://www.nasa.gov/history/rogersrep/v1ch6.htm
Edit: I can't post a response because my account has a posting limit, but "the o-rings were not defective" is...misleading.
The o-rings were constructed as an assembly that used multiple lengths of o-ring material glued together, instead of the entire o-ring being molded at once, which is what had been done on prior rockets. Up to five joints were allowed. No inspection of the glued joints was performed other than a surface inspection.
Second edit: no, the problem is not that the "selection team did not account for atmospheric pressure." The joints between sections mechanically did not hold together correctly. NASA engineers predicted this when examining the revised design during the earliest phases, although the assembly was found to act in a way different than how they had predicted, but still caused the seals to leak. Everyone knew the seals leaked, before the first shuttle headed to the launch pad.
Third edit: the blog is "wildly wrong" because it claims NASA supplied or modified the revised seal design and outright declares them incompetent government bureaucrats who didn't know how solid rocket motors worked. In fact, both designs came from Thiokol in entirety - and NASA engineers basically said in reports something to the effect of "the government (ie NASA and the military) has never seen a solid rocket motor sealed like this".
When NASA engineers approached the o-ring manufacturing company, the company said they'd never seen a design like it and felt that it was 'not being used like an o-ring' or something to that effect.
From the very beginning NASA engineers were screaming their heads off that the design was shit. Testing validated their concerns. Upper management at both Thiokol and NASA didn't care.
There was no defect in the o-ring. The design of the entire joint it was sealing was suspect, and was known to perform in a way that was not satisfactory. It did perform just as it was expected to (they expected a failure under the conditions) by the people that had the technical details.
According to what I recall of Allan McDonald's version of things, they had a good amount of data that colder temperatures meant worse sealing performance from the o-rings (soot making its way past the first o-ring and in some cases damaging the second, basically). Like you said, it was a well-known issue in some circles. They also knew the Challenger launch the next morning would be very cold indeed, something wild like at or just above freezing, I think.
The engineers at Thiokol raised their concerns and were asked what a safe temperature to launch is and said something like 53F, basing this on the fact that a previous launch at that temp was successful. NASA (and Thiokol) management balked at this because the booster's certified minimum launch temp was something lower like 30 or 40F. Then they basically asked them to prove it would catastrophically fail at the temperatures expected the next morning, which they couldn't conclusively do since they didn't have the data to back it up. Management reversed the no-go recommendation based on this.
So yes, the o-rings performed as expected insofar as colder = worse, but it was a matter of how much worse at temperatures lower than any successful previous launch.
Turns out they _did_ conclusively prove that, just not within the time or budget (or casualty) constraints demanded by management at the time.
:sigh:
Yeah, no.
The seal never performed the way it was designed to.[1] It was faulty by design. The seal always leaked, but that didn't always lead to an explosion.
There were multiple times where the erosion/blow-by problem was observed; in fact, the O-ring was (unsuccessfully) redesigned by Morton Thiokol to address the issue.[2]
The problem was that nobody really understood what was going on, and waved their hands about it.
Quote[3]:
“NASA had developed a peculiar kind of attitude: if one of the seals leaks a little and the flight is successful, the problem isn’t so serious. Try playing Russian roulette that way: you pull the trigger and the gun doesn’t go off, so it must be safe to pull the trigger again.”
Please do some due diligence before simply saying things that feel right for the sake of making a point.
Your point still stands (it was an organizational failure), but premising it on a false statement (that the O-ring performed to spec) isn't a way to make it.
[1] https://www.latimes.com/archives/la-xpm-1986-11-19-mn-4295-s...
[2] https://www.nasa.gov/history/rogersrep/v1ch6.htm
[3] https://lithub.com/how-legendary-physicist-richard-feynman-h...
this quote is also feels pertinent to the Starliner decision to launch. They knew there was helium, but they just decided there was more helium for the mission than was leaking. so the acceptable risk bar seems to be pretty low.
Complicated systems are always having some issues that aren't to spec. The difficulty is assigning an appropriate risk to them.
I've heard people who design 5+ sigma aircraft who refuse to fly on it because they know of some system that isn't up to spec in their eyes; in that case, the opposite is true: they're assigning a risk that is probably too large given the data.
The gist of it is that the failure was expected by everyone with technical knowledge of the seal.
>The gist of it is that the failure was expected by everyone with technical knowledge of the seal.
Nobody is denying that.
What you wrote was, quote: "The seal performed exactly as it was specified to."
That statement is false. It was not performing as specified at warmer temperatures either.
The seal absolutely failed, in the way that any reasonable person would interpret that phrase. A seal prevents things from getting past it, and it did not do that.
Some alternate phrasings that I believe make the (valid) point without this semantic flaw:
- The Challenger did not explode because of a simple or unexpected seal failure.
- The seal failure was merely a symptom of a larger, harder to fix, much more troubling failure.
- The seal failed, but that was not the failure that mattered.
Small nit, but from a reliability perspective you can almost never guarantee something will work. It's a probability distribution but, to your point, you need decent data to estimate that probability.
The other issue is a psychological one. Humans aren't generally wired to think about probabilities well, especially low-probability events. There's a fairly decent chance you can roll the dice over and over on these types of decisions and not have anything bad happen, leading you to think you're good when in reality you're just lucky.
Anything as complex as the shuttle is going to have any number of groups raising any number of warnings about any number of components. If you heeded all of them, you'd spend eternity investigating everything and nothing would ever fly (welcome to the SLS.) How many other warnings of similar perceived severity were ever raised but flew anyway and never resulted in anything catastrophic? Probably a lot. "Go fever" is a problem, but so is its opposite in warning fatigue.
It's easy to condemn the organization, but that has to also come with some sense that the organization had a million problems to deal with, and we only knew to pick out this one after it happened.
IOW almost completely unfavorable, but not quite as bad as it was earlier.
The media revealed some skepticism that a launch would be advisable that day, but once a lift-off time was set, then it became all systems go as usual.
If there's a freezing day on that part of the Florida coast, that's an unusual year. You question everything that hasn't previously survived that kind of year in the past.
I didn't feel optimistic for those reasons alone.
>The “science” is that knowledge which was written down. The “art” is the knowledge that was not written down, usually because no one wanted to pay for the writing.
That's so true why so much documentation is never made, you have to make the most of what you have and fill in the rest through experimentation.
But O-rings are so boring, seems like nobody wants to take the time to even read the "free" literature. It's not any more complex than an average engineering semester.
Now it would take more than a semester to get really deep into polymer properties that can be involved under different conditions, but engineers themselves are never expected to get very far in that direction if they're not even experts in the mechanical engineering of the o-ring dimensional enclosures.
Once it was revealed that the Challenger was doomed by inadequate o-ring engineering, it reminded me of the day one blew out when I had my first gas lab, at over 10,000 psi the explosive force was easily noticeable. From quite a few doors down.
The engineer who designed the cylinders had "copied them from XXXX lab" and we were using them no differently than they were doing, but it was always an accident waiting to happen because the tolerances and material selection were not given but a fraction of the attention necessary to avoid a mission-critical failure, much less a potentially hazardous aftermath. Quintessential technical debt.
Anyway I had to redesign the cylinders and deal with the machinists and suppliers myself. I guess maybe it was a bit like artistic background that was helpful since I had already worked in one of the highest-precision machine shops during summer, and then after university full-time (12-hour days) at a polymer plant laboratory. What it brought to the table was greater than the available documentation which was essential too. Before it was over I had then spent time with a life-long o-ring expert who had built a company based on o-rings for severe service. There is no substitute for a large warehouse filled with nothing but millions of o-rings, and browsing around with the pro who has helpful advice at every turn and truly wants you to never have a blowout as if your life depended on it.
So the o-ring blowout had been my initiation into a commercial laboratory startup back in 1980, building custom engineering laboratories to handle contract research projects.
Definitely a single point of failure which is worse than others because it is so boring, it is much more likely to be overlooked.
Things I won't work with: engineers that are not so great but think they are.
Much better off handling things like benzene, methanol, or sulfuric acid in shorts and flip-flops which people know not to try this at home.
SpaceX generally does the opposite of this for example. Their testing is very hardware rich. Then they'll have dozens of automated flights on very similar hardware. Then after the hardware has been used in a wide range of conditions we see it migrate to human ratings.
NASA picked something too complicated, was warned it was too complicated, then lost human lives when it was too complicated.