737 Max

Mar 12, 2019 456 Replies

"My" incident wasn't a parking lot. It was a normal surburban road with a 30mph limit (until a politically inspired decision to impose a 20mph limit over a 5*7 mile area of the city).

More importantly, that was merely one incident of many. It happens regularly here, usually because someone is looking at their phone while walking. I know people that have been injured on busses when people stepped out in front of them.

A local "shared space" (where the distinction between roadway and footway is obscured by design) gained a bad reputation because peds didn't spot they were walking in front of vehicles.

Also true in a glider, but s/engine/airbrkes/

For an excellent description, see the classic textbook "Stick and Rudder: An Explanation of the Art of Flying" by Wolfgang Langewiesche

Yes and yes.

Plus soaring is fun: you can and do expect to have some good surprises, which is "impossible" in a powered aircraft.

A 20:1 glide angle is a good rule of thumb, in the absence of more specific information.

I'm not interested in the "no single point of failure" theory. It is great for the contingencies you can imagine, but fails when you don't consider r eal life issues. Case in point that actually was an issue for me personall y. During the east coast earthquake a few years ago the North Anna power p lant went offline and the backup generators had to kick in to provide cooli ng power.

One of the generators failed and another unit had to substitute for it. Th e NRC required an investigation and the bungling of the local crew almost m ade it impossible to determine the root cause of the generator failure. Cl early they were not motivated to find out why it failed, just to get it bac k online.

Subsequently it was found the head gasket failed due to improper installati on because... the installation procedure was faulty... a single point of fa ilure for each and every one of the generators! Why was it never considere d that the generators all suffer from the same maintenance, repair and oper ating procedures. A flaw in any one and they can all fail when you need th em. Not to mention the possibility of a bad shipment of parts, lubes, fuel , etc. I now have little confidence they have actually covered the potenti al contingencies and this or any other nuclear reactor is meltdown proof.

This was a failure in design just like the metal fatigue issue was a failur e in design in the Reindeer... opps, I mean the de Havilland Comet.

While humans can be amazingly adaptive, they are really good at making mist akes... much better than automated control systems. With every crash and r esulting failure analysis, automated systems improve. Humans are pretty mu ch static and rely on better training to improve, but there is only so much that can be done.

Just look at the causes of many of the accidents. Something in the plane s crews up and pilots forget their training and fail to fly the plane correct ly in spite of the fact that the failure was not necessarily fatal.

Wings seldom fall off anymore and cabins seldom explode, but pilots still m anage to crash airplanes.

Rick C.

The organisational failure wasn't in the head gasket installation (that was the technical failure), but in failing to regularly perform end-to-end tests (fire up the generator and use it for a while!) that would find errors like that and others.

Simple rule of thumb: if it's not tested, it won't work.

Clifford Heath.

e

reat for the contingencies you can imagine, but fails when you don't consid er real life issues. Case in point that actually was an issue for me perso nally. During the east coast earthquake a few years ago the North Anna pow er plant went offline and the backup generators had to kick in to provide c ooling power.

The NRC required an investigation and the bungling of the local crew almo st made it impossible to determine the root cause of the generator failure. Clearly they were not motivated to find out why it failed, just to get it back online.

lation because... the installation procedure was faulty... a single point o f failure for each and every one of the generators! Why was it never consi dered that the generators all suffer from the same maintenance, repair and operating procedures. A flaw in any one and they can all fail when you nee d them. Not to mention the possibility of a bad shipment of parts, lubes, fuel, etc. I now have little confidence they have actually covered the pot ential contingencies and this or any other nuclear reactor is meltdown proo f.

What makes you think they didn't? Testing can confirm something is wrong, but can't confirm something is correct. Testing won't always catch potenti al failures. A thing works perfectly right up until the moment it doesn't.

Yes, the organizational failure was in the installation procedure and think ing there were no single points of failure. It may not have been likely th at enough units would fail when needed to prevent a catastrophe, it wasn't so unlikely as to be dismissed. They fixed the defective procedure. Now, how many other procedures are flawed and yet to be discovered?

Rick C.

You were worried about *all* (or many) the generators failing for the same reason. But if they *all* got started occasionally and *none* ever failed, you'd have to be terribly unlucky for *all* or most of them to fail when actually needed.

One can never know. But regular testing can dramatically reduce the odds. It's amazing how many people manage their computer backup schedule rigorously, only to find out that *none* of the backups are recoverable, or ever would have been.

As I said: if you don't test it, it won't work.

If you do, it might still fail, but there's much less chance of that.

Clifford Heath

:

ake

nd

great for the contingencies you can imagine, but fails when you don't cons ider real life issues. Case in point that actually was an issue for me per sonally. During the east coast earthquake a few years ago the North Anna p ower plant went offline and the backup generators had to kick in to provide cooling power.

t. The NRC required an investigation and the bungling of the local crew al most made it impossible to determine the root cause of the generator failur e. Clearly they were not motivated to find out why it failed, just to get it back online.

allation because... the installation procedure was faulty... a single point of failure for each and every one of the generators! Why was it never con sidered that the generators all suffer from the same maintenance, repair an d operating procedures. A flaw in any one and they can all fail when you n eed them. Not to mention the possibility of a bad shipment of parts, lubes , fuel, etc. I now have little confidence they have actually covered the p otential contingencies and this or any other nuclear reactor is meltdown pr oof.

t

ng, but can't confirm something is correct. Testing won't always catch pot ential failures. A thing works perfectly right up until the moment it does n't.

I own a half million dollar house 3 miles from the reactors. There are man y billions of dollars of property close enough to be impacted if there were a meltdown. What you seem to be ignorant of is the degree of "inconvenien ce" a meltdown would cause. When the results of an error are catastrophic it warrants an equivalent degree of caution.

hinking there were no single points of failure. It may not have been likel y that enough units would fail when needed to prevent a catastrophe, it was n't so unlikely as to be dismissed. They fixed the defective procedure. N ow, how many other procedures are flawed and yet to be discovered?

As I said, testing doesn't indicate it will work when you need it as was cl early demonstrated by the results.

Not less chance in a hugely significant way. Do you really think they didn 't regularly test the damn generators for a nuclear power station???!!!

Someone - possibly in another group who works in the field of this sort of high reliability design if not in nuclear itself - told me all about how th ey test the generators on a regular basis and how problem would be spotted and taken care of. Yet, in the only case of an emergency scram at this rea ctor that I am aware of, one of the generators failed. I know enough about statistics to know that this indicates it is entirely within a unacceptabl e probability that multiple failures could have occurred due to this single point of failure (the incorrect installation procedure) that would have pr ovided insufficient cooling. The generators would have been repaired using the exact same procedure and much like the pilots who ignored two working air speed indicators and paid attention to the non-working indicator the pa nic of the situation could easily have resulted in doing exactly the wrong thing and a meltdown.

Or perhaps your view is that the one generator failed as an exception to th e rule and was an exceedingly unlikely event that happened on the ONLY time it was put to the REAL test.

My point is not specifically about this one failure. My point is that ther e are numerous single points of failure no matter what anyone tells you. T his is a perfect example of one whether you accept it or not.

"A man who is not afraid of the sea will soon be drowned, he said, for he w ill be going out on a day he shouldn't. But we do be afraid of the sea, and we do only be drownded now and again."

If you understand this quote, you should understand my argument.

Rick C.

That is entirely reasonable behaviour on their part - getting the plant cooling back running should always be their first priority.

So why were the generators never actually tested? We had nothing like the level of power continuity requirement that a nuclear power plant has but our emergency backup generators were routinely tested every 6 months. In the ten years I worked there I can only recall one time where they didn't start properly and mains power was restored immediately.

You always test everything if your life depends on it (or even if serious financial losses will result from major system failure). Even so you cannot guard against some moron pressing the wrong switch or putting an axe or JCB through some critical cable beyond your control.

formatting link

If it hasn't been tested then it may not work when you really need it.

Software MFUs happen with monotonous regularity. Facebook is today's hot topic for software meltdown.

No! It wasn't like the Comet. Metal fatigue and stress concentration in pressure vessels was very poorly understood when they made mistakes in the original Comet design. They were pushing into very new territory.

Stall warnings have been routine for a long time.

Bodging an oversize engine onto an existing airframe and then bodging the software to stop it tipping its nose too high from the resulting torque is neither rocket science nor is it good engineering practice.

Good to see that the FAA have finally made an independent decision.

US pilots have also complained about the unable to climb after takeoff issue but were sufficiently well trained to disable the MCAS junk code.

Automatic control systems can do wonderful things when things are normal but when the unexpected happens a human is usually a lot more adaptable. I don't see that changing very much in the foreseeable future.

Most times the captain is extremely professional, calm and cool about the situation and deals with whatever emergency has occurred. I was on a plane with a landing gear fault once it wasn't really all that exciting. Bad enough we had fire engines waiting but no emergency evacuation.

Or in this case a trivial sensor fault made the plane unflyable. There is no way that should have been allowed to happen in the first place.

Per passenger mile flying is by far the safest mode of transport.

Regards, Martin Brown

Twin engine ETOPS planes have different maintenance crews for each engine.

And then there's the Brown's Ferry nuke incident involving a candle and, more relevantly multiple backup control systems sharing the same conduit. And coming from the same control room, of course.

One classic example was traced to the tape head - which was hanging off and not in contact with the tape :)

Wrong. The plant was being cooled by the backup with more in reserve. Jus t like the airline pilot who trusted the wrong gauge this was a mistake. W ell, maybe I don't know much about it, but that's what the NRC said.

You keep making false statements. Of course the generators were tested. T he failure happened 20 minutes into the scram. They don't run them all the time as hot spares.

Every 6 months is much longer than in the nuke plant. You can't seem to gr asp that testing DOES NOT PROVE SOMETHING IS WORKING CORRECTLY. It just sh ows the absence of failure at that time under those conditions. Why can't you grasp that???

This is getting tedious. You continue to ask why they didn't test the gene rators when I keep telling you they did. You continue to believe the gener ators would have worked -had they only tested them-. I give up on this poi nt. You clearly can't accept as fallacies the two points you continue to p resent.

You don't actually understand what happened. You focus on the airplane des ign when the failure was with the pilots not flying the plane correctly, at least in the examples where they have found the reason for the crash. We still don't know what happened in the 737 MAX 8 crashes.

Yes, when something goes wrong with any part of the aircraft the pilot has to know instinctively how to handle that situation. It doesn't matter whic h part. You want to place blame unreasonably and without justification.

Yes, that is what I said. They are adaptable and can override faulty syste ms. But they actually fail more often than the systems do.

Which case was that exactly? Are you talking about one of the cases where they know what happened or the 737 MAX 8 case where the cause has not been determined?

In any event, you certainly don't know the plane was unflyable.

I'm calling code on our conversation. You seem to thing saying the same th ing over and over makes it true. You don't dispute my claims you just igno re them. No point in continuing. Enjoy.

Rick C.

Yeah, what was the reason for the candle exactly? They hadn't heard of flash lights or there was some reason for not using electricity?

Rick C.

How does flashlights detect draft ?

The candle is very sensitive to detect minor air flow. Apparently they were checking cable feed trough tightness.

Candles are better at detecting air leaks than light bulbs.

formatting link

On Thursday, March 14, 2019 at 1:38:44 PM UTC-4, snipped-for-privacy@downunder.com wro te:

flash lights or there was some reason for not using electricity?

They have aerosol cans of smoke which are just as sensitive. They don't bu rn through cabling.

If they were going to use a candle, it should have been in an enclosure to prevent the flame from being able to damage anything. A wire cage large en ough and with a grid fine enough would allow the flame to feel the draft bu t prevent the heat from harming anything.

Whatever the need... a candle was not the appropriate tool in a wire chase.

Rick C.

These reports are enlightening: The original engineering problem:

formatting link

-max-8-a-1257608.html Trying to mount an engine that is too big.

The makeshift solution:

formatting link

-flight-control-system/

Add a control system that fights another control system and operates with a non-redundant AOA sensor whose data has been shown to be unreliable. The quick fix: a software patch to ?make a safe aircraft safer? ??. Big mistake.

Age old question on dual redundant sensors: Which one is right? Solved man y years ago, both mathematically and practically: Triple Mode Redundant Redundancy in this space has it own own issues: truth basis, voting scheme, hw vs software tradeoffs, and many more. Other issue is doing safety anal ysis of a system versus subsystems. Look at STPA for approach to system sa fety. Another issue is failure modes and detection. Failure modes are different for hw and sw. I work in this area...still amazes me that ppl do no unders tand sw failure mechanisms. Point of all this, it is *very* difficult to make things safe. Things beco me 'obvious' when the failure mode is known but they are not always enumera ted or understood. Also, I've seen sw systems where the 'safety software' is between 40-50% of the total lines of code. A bit scary when you conside r a 787 has about 7M LOC. Software performs 80-90% of the functionality. Some research I am involved with indicates that next gen aircraft will be ' too complex to test' with today's testing + evaluation approaches. (Concer ns of two aircraft companies) Not an easy problem....

I think your link shows the opposite, a candle is the worst possible tool for detecting air leaks in highly flammable material.

Duh!

Rick C.

37-max-8-a-1257608.html

This says they mounted the engines on shorter mounts under the wing. Would n't that lower the tendency to tip the nose up? Shorter lever arm has less torque.

a non-redundant AOA sensor whose data has been shown to be unreliable.

What is the second control system?

??. Big mistake.

any years ago, both mathematically and practically: Triple Mode Redundant

e, hw vs software tradeoffs, and many more. Other issue is doing safety an alysis of a system versus subsystems. Look at STPA for approach to system safety.

t for hw and sw. I work in this area...still amazes me that ppl do no unde rstand sw failure mechanisms.

come 'obvious' when the failure mode is known but they are not always enume rated or understood. Also, I've seen sw systems where the 'safety software ' is between 40-50% of the total lines of code. A bit scary when you consi der a 787 has about 7M LOC. Software performs 80-90% of the functionality.

'too complex to test' with today's testing + evaluation approaches. (Conc erns of two aircraft companies)

The bottom line is the pilots did not recognize the failure and so the Lion Air flight crashed. This was not a fatal failure in the airplane if the p ilots had been trained in this procedure.

'If the pilots had known the MCAS was at fault, they could have shut down t he plane?s ability to automatically adjust its trim (which determin es its position in the air) so they could manually do it themselves. But th ey ended up ?behind the airplane,? confused and trying to f igure out what the computer was up to. ?When you?re behind the airplane, you?re almost dead,? Aimer says.'

formatting link
x-lion-air/

Rick C.

Join the Discussion

Have something to add? Share your thoughts — no account required.

Didn't find your answer?

Ask the community — no account required