5 ms·
Its funny, back when I want to college I had a CS professor who referred to himself as "an otherwise reputable computer scientist who sometimes gets on Airbus a
by lastofthemojito 3y ago
Its funny, back when I want to college I had a CS professor who referred to himself as "an otherwise reputable computer scientist who sometimes gets on Airbus airplanes".
That was in reference to the difference in philosophy between Boeing and Airbus about whether the pilot or the plane's computer should get the final say in emergency situations, with Boeing letting the pilot override the plane and Airbus having some protections that won't allow the pilot to do something dangerous (I'm sure I'm oversimplifying or misconstruing details, I'm not a pilot or aviation engineer and it's been a couple of decades since I heard this particular rant).
With the last few years of Boeing's misadventures I wonder what he'd call himself today, "an otherwise reputable computer scientist who sometimes gets on modern jetliners"?
- tibbydudeza 3y agoAirbus has 3 flight computers (1 PRIM and two SECs) for fly by wire - they run same software with voting deciding outcomes of commands that comes from the pilot to the flight surfaces. The unit not matching the others are marked as suspect and removed from flight operations-the switch out is not done by software but hard cutover system using relays. Good design.
- SteveNuts 3y agoI think they’re talking about the pilot being able to apply inputs that might otherwise be considered dangerous by the flight control computers. So in an emergency a Boeing may allow the pilots to make an input that may overstress the airframe but save the lives of the passengers. Whereas the Airbus computer would override the pilot’s decision and not allow it. IANAP so I have no idea if that’s true or not.
- 7thaccount 3y agoIsn't the MCAS situation the exact opposite? Boeing pilots tried hard to override it, but it wouldn't let them.
- SteveNuts 3y agoYes but MCAS is relatively recent, the controversy in GP happened when fly by wire was a new concept.
- rootusrootus 3y agoYes, it's one of the most notable aspects of MCAS, that it departs from previous Boeing design philosophy.
- kotaKat 3y agoYou can dump an A3xx to "direct law" if you turn off the right switches and get direct controls. ECAM memo: "DIRECT LAW (PROT LOST)" https://apstraining.com/wp-content/uploads/FCS-Airbus-Quick-Reference.pdf https://apstraining.com/wp-content/uploads/FCS-Airbus-Quick-...
- deleted 3y ago[deleted]
- theolivenbaum 3y agoMore or less that - the rationale being that pilots could overreact in stressful emergency situations and thus the flight control system would prevent unintentional damage that would only make the situation worse.
- tivert 3y ago> Airbus has 3 flight computers (1 PRIM and two SECs) for fly by wire - they run same software with voting deciding outcomes of commands that comes from the pilot to the flight surfaces. So a software bug could doom the plane? IIRC, some other flight-control voting system have 3 computers, but one runs software developed independently from the others.
- Gare 3y agoBoeing 787 is also fly-by-wire. Yes, software is life-critical. Therefore it is developed to a very high standard. Ada is often used.
- 7thaccount 3y agoI heard the military relaxed restrictions that required Ada. So the F-22 Raptor was mostly Ada, but the newer JSF is mostly C++. No idea if true, but that is what I remember.
- tivert 3y ago> I heard the military relaxed restrictions that required Ada. So the F-22 Raptor was mostly Ada, but the newer JSF is mostly C++. No idea if true, but that is what I remember. I think that's correct. IIRC, the JSF C++ coding standard document is floating around.
- chasil 3y agoI would certainly hope that it's the MISRA variant. https://en.wikipedia.org/wiki/MISRA_C https://en.wikipedia.org/wiki/MISRA_C
- tivert 3y ago> I would certainly hope that it's the MISRA variant. I think this is it: https://www.stroustrup.com/JSF-AV-rules.pdf https://www.stroustrup.com/JSF-AV-rules.pdf, and it appears you're right: > The MISRA Guidelines were written specifically for use in systems that contain a safety aspect to them. The guidelines address potentially unsafe C language features, and provide programming rules to avoid those pitfalls. The Vehicle Systems Safety Critical Coding Standards for C, which are based on the MISRA C subset, provide a more comprehensive set of language restrictions that are applied uniformly across Vehicle Systems safety critical applications. The AV Coding Standards build on the relevant portions of the previous two documents with an additional set of rules specific to the appropriate use C++ language features (e.g. inheritance, templates, namespaces, etc.) in safety-critical environments.
- m463 3y ago> Boeing letting the pilot override the plane and Airbus ... won't allow I still think it is basically true (MCAS notwithstanding). For Boeing: The design philosophy is: "to inform the pilot that the command being given would put the aircraft outside of its normal operating envelope, but the ability to do so is not precluded." https://en.wikipedia.org/wiki/Flight_control_modes https://en.wikipedia.org/wiki/Flight_control_modes I thought there was some situation where an airbus plane though it was landing and cut back on the throttle causing a crash. Can't find it now.
- t0mas88 3y agoWhat you have in mind for the Airbus crash is what the captain claimed, but it was not true. The engines responded normally and started to spool up to maximum power, but that takes time for older jet engines coming from idle. The crew then pulled as far back as the stick would go, and the computer put the aircraft at it's maximum possible pitch-up. Unfortunately that wasn't enough to clear the trees they were flying into. More details here: https://en.wikipedia.org/wiki/Air_France_Flight_296Q https://en.wikipedia.org/wiki/Air_France_Flight_296Q A 737 in the same situation would have similar engine challenges. But the crew would have stalled it instead of the Airbus computer avoiding the stall. That would have most likely been a more severe crash than what happened here.
- larusso 3y agoThis article shows how pilots could also get confused by the 3 tier autopilot system. https://admiralcloudberg.medium.com/the-long-way-down-the-crash-of-air-france-flight-447-8a7678c37982 https://admiralcloudberg.medium.com/the-long-way-down-the-cr...
- maurits 3y agoI had a prof too (formal methods?) who opened with "Ladies and gentlemen, if you follow my lecture series, you will never fly model x of brand y aircraft again.
- deleted 3y ago[deleted]
- t0mas88 3y agoThe way it works for the Airbus is that the pilot controls the plane, but there are safety parameters that determine what the controls do. Consider it like a modern car with engine management software. If you floor the accelerator all at once from a low rpm in a very old car, the engine will stumble, if you do it in a modern car the engine management software will inject the maximum amount of fuel that can be burned and not too much, getting you maximum acceleration. The same applies for the way Airbus controls work. Let's say you want the maximum climb (for example due to wind shear on landing), in the Airbus you push the throttles all the way forward, and pull the stick all the way back. The computer will figure out not to pitch you up further than the plan can handle. The same manoeuvre in a Boeing means you press the TO/GA switch twice for maximum power (because the engines are computer controlled here as well) but then you pull back on the yoke up to stick shaker activation (stall warning) and manually try to pitch just below the maximum. There is no safeguard stopping you from pulling too far and stalling the airplane. Every pilot can do that, small training aircraft that everyone learns this in don't have any protections either. But the accuracy won't be as good as what the Airbus computers can do and it requires paying more attention. Now in an emergency, systems failures, the Airbus will downgrade to how the Boeing works. Full back stick will be an unlimited pitch-up and the pilots need to manually figure out what the maximum is.
- Night_Thastus 3y ago>Now in an emergency, systems failures, the Airbus will downgrade to how the Boeing works. Full back stick will be an unlimited pitch-up and the pilots need to manually figure out what the maximum is. You're referring to Alternate Law and the more extreme version, Direct Law. One note is that it's not always an emergency that can cause this. If important sensors like AOA or airspeed disagree (for example, due to a temporarily-frozen pitot tube), that will also reduce to alternate or direct depending on the situation. Unfortunately this can bite pilots badly if they either don't notice or don't understand the new situation quickly enough. There have been one or two crashes attributed to this over the years. [See Air France 447]
- V__ 3y agoI went down a youtube rabbit hole about aircraft investigations once. One think I am still surprised by is the (in my opinion) bad UX of some errors. For example: It can be really easy to not notice a change from normal to alternate or direct law, if there are multiple problems going on at once.
- rcxdude 3y agoThere's a bigger difference, as I understand it, which is where airbus generally considers the pilot as managing a complex machine with a lot of automation (even without autopilots), and the inputs and controls reflect that, being a bit more abstract. Boeing basically tries to make every plane they make fly like a cessna, using the same basic controls but always adapting the interface to the same thing, even if that abstraction is leaky. There's upsides and downsides to it, but MCAS is one example of boeing's philosophy going wrong (in part exacerbated by trying to conserve the type rating and avoiding pilot retraining).
- abadpoli 3y agoThe very first A320 demonstration flight _and_ one of the first A330 flights both crashed and killed multiple people due to issues with the autopilot programming. The whole “if it’s not Boeing, I’m not going” thing was because of distrust around the fly-by-wire system that Airbus used. I guess all big companies eventually succumb to this fate. It sucks.
- SoftTalker 3y agoYeah older pilots distrusted the Airbus design and joystick controls. They preferred Boeing's direct cable-and-pully design. But many of them are retired now, younger pilots probably don't have such strong opinions. They also like airplanes where the doors don't blow out in flight.
- cccbbbaaa 3y agoAF296 crashed because the pilot selected TOGA too late for the engines to spool up in time, and was completely unprepared. There was no issue with the FCS, nor the autopilot which was disengaged. For Airbus Industrie 129, it seems that the FCS was not the root cause of the issue, but I don't know a lot about this flight.
- abadpoli 3y agoThe pilot of AF296 claims the crash happened because the fly-by-wire system preventing him from being able to select TOGA and from pulling up. The official investigation still found the pilot at fault, but there were also claims and later investigation that Airbus interfered with the official investigation, leading to general distrust of Airbus and the fly-by-wire system.
- cccbbbaaa 3y agoAsseline can claim what he wants, but, unfortunately for him, the FDR and reconstitutions (performed in a simulator and in a real plane) do not back him up. And the only “proof” of FDR tampering comes from someone who did not understand what he was looking at. Now, I don't want to be too harsh on him. AF set him up to fail (acknowledged by the BEA report), then threw him under the bus. I can understand why he chose the support of the SNPL, even if it meant going at war against the plane.
- phkahler 3y agoWell they switched that philosophy with the MAX and look what happened...