4 ms·
What a poor design. Pilots should have a hard "manual control" switch that turns control completely to the pilots. A friend of mine from childhood became a top
by marze 9y ago
What a poor design. Pilots should have a hard "manual control" switch that turns control completely to the pilots.
A friend of mine from childhood became a top expert in formal verification, and got a contract many years back to help Airbus perform formal verification on their control software. I don't know many details, but according to my friend's father, he would never fly on an Airbus jet after this experience.
A pilot friend told a story of some pilot friends of his who were piloting an Airbus in Canada, many years back, who couldn't get the jet to give control back and get out of a holding pattern to land. They had to wake up engineers in France in the middle of the night, who told them to take a hammer to certain fuses or breakers, and let them regain control.
From a UI point of view, the control system and displays in the Airbus are a disaster. For instance, the pilots in the Air France plane that stalled over the pacific couldn't figure out that the plane was stalled for several minutes before it was too late to correct, with all of the displays in front of them.
- hlandau 9y agoAFAIK there is such a switch: there are switches to disconnect the primary computers on the overhead panel. If those are disconnected, presumably the aeroplane reverts to direct law and flight envelope protections become inoperative. I might be mistaken though; I'm no pilot and you seem more knowledgable. The article mentions they were able to regain control of the plane by leaving one of the primary computers disabled. (The end of the article itself has a quote from Airbus suggesting there's always supposed to be a way to get full control; presumably this is what they're referring to.) I was surprised that they left the other computers enabled, especially given that the article suggests they were worried whether it would happen again; to me, the obvious thing would be to do would be to disable all primary computers and use direct law. Malfunction of the flight envelope protections seemed the obvious culprit from the moment it was mentioned the sticks were ignoring commands, short of a mechanical failure in the control surfaces themselves. Certainly AF447 has demonstrated that Airbus aircraft are very poorly designed from a user interface perspective. The anecdotes you have about people working at Airbus sound highly interesting and would be worthy of blog posts in themselves. Would your friend ever consider writing about these concerns (anonymously even)? Also, was an accident report ever filed for that holding pattern incident? Can I read about it?
- hlandau 9y ago...Actually, while I'm criticising Airbus, it would be amiss not to mention the A400M incident [1] [2]. Unfortunately as a military accident the full report was never made available to the public, but based on the available information, failure to load calibration data for the engine computers during manufacturing resulted in the engines shutting down... once they got to the altitude where that calibration data was needed, and found to be absent. The idea that Airbus would design engine computers not to check the validity of vital calibration data until the aeroplane is in the air, and then respond to that contingency when it is identified by shutting down the engines, is so obscene I think I've usually tried to assume that there must be something amiss about the (very limited) reporting as to the details of the issue. But considering your words, and the general lack of consideration that Airbus seems to give to these things the more and more I look at accidents involving Airbus craft, maybe they just really are truly bad at this stuff... it's quite disturbing. [1] https://en.wikipedia.org/wiki/Airbus_A400M#Accidents https://en.wikipedia.org/wiki/Airbus_A400M#Accidents [2] https://arstechnica.com/information-technology/2015/06/report-airbus-transport-crash-caused-by-wipe-of-critical-engine-control-data/ https://arstechnica.com/information-technology/2015/06/repor...
- Avalyst 9y ago> Safety officials are still investigating how safety checks failed to spot that the calibration data had been deleted. So I guess the checks for checking the checks of the data failed? You can never have too much redundancy!
- foldr 9y ago>A friend of mine from childhood became a top expert in formal verification, and got a contract many years back to help Airbus perform formal verification on their control software. I don't know many details, but according to my friend's father, he would never fly on an Airbus jet after this experience. There are safety anecdotes about all of the major airplane manafacturers. If Airbuses were actually unsafe, they would crash more often. >who told them to take a hammer to certain fuses or breakers There would be an incident report about this if it happened. No need to rely on your friend's story.