7 ms·
A400M Airbus Flier crashed because of software issues
- deleted 11y ago[deleted]
- tntcl 11y agoSo basically the software bug happened, because there are quality problems in the manufacturing street? wtf!?!?
- madez 11y agoThe original speaks of quality problems in the manufacturing plant. This is very general and could include problems in the design phase up to the flashing of the module after assembly of the plane.
- tremon 11y agoI think the OP was reacting to the use of the term "quality problem" to describe a catastrophic failure leading to loss of human life. At least, that was my response when reading that quote.
- VLM 11y agoPerhaps a mental model abstracted from aerospace is you have a somewhat complicated PID controller and it was programmed to tolerate widgets with size of 0.01 to 0.02 because only those can physically fit on the assembly line, and within those limits it is proven and tested to be unconditionally stable and predictable and correct under all operating conditions. Unfortunately manufacturing let a batch of 0.0201 size slip thru inspection, they just barely fit on the assembly line despite being out of spec too large, and the PID controller makes the system go into oscillation and explode because its outside its theoretical limits of whats possible. The most insidious spec violations are "manufactured too well" if for example you rely on frictional damping to eliminate oscillations, then making and shipping better ball bearings than you'd ever shipped before, could ruin an overall system because one component is too good. Possibly the "error" is something is too smooth, too straight, too flat, or too low friction. No one ever expects those to cause a disaster, but it can happen. That would be an example of a disaster involving software, that can be fixed in software, although it wasn't caused by the software, it was caused by bad control system engineering design work. Also this abstract example probably has nothing to do with the real problem, although the "widget" and "size" could very well be something line fuel line tubing inside diameter.
- bhaak 11y agoThere are not many details about why exactly the three engines stopped working and it's not yet officially announced. This article has been written with "information Spiegel Online received". Two translated quotes: "The investigation yield a clear result: Shortly after the lift-off of the test machine, the computers send conflicting commands to the three engines which then powered off." "Soon after the crash, experts of the German Air Force suspected a software issue with the fuel supply unit because such a fatal drop of power so soon after the start could hardly be explained differently." So, not much information why the computers sent conflicting commands and also why the engines power down in such a situation.
- lucaspiller 11y ago> So, not much information why the computers sent conflicting commands and also why the engines power down in such a situation. I think shutting down the engines is probably the safest option when this sort of thing happens. You could argue they should stay in the present setting, but what would happen if one engine were at 0% and another 100%? Most aircraft are pretty good at gliding even without power, and I'd assume a deadstick landing is part of the pilots training. In 2001, TS236 flew unpowered for 19 minutes before making an emergency landing (on a runway) with only minor injuries: http://en.wikipedia.org/wiki/Air_Transat_Flight_236 http://en.wikipedia.org/wiki/Air_Transat_Flight_236
- Piskvorrr 11y agoPretty good at gliding from a high flight level. If you are hitting power poles, you are way too low for gliding an usually-powered aircraft. TS236 and Gimli Glider were exceptionally lucky, IMNSHO.
- VLM 11y ago"but what would happen if one engine were at 0% and another 100%" Part of earning your multi-engine cert is memorizing all manner of different airspeed limits for that kind of situation. If you want to maintain yaw control with one engine feathered (er, shutdown) and the other at full throttle you must be going faster than X knots or whatever. Below that indicated airspeed you pull back on the throttle or you're going into a turn at best or more likely a spin.
- rurounijones 11y agoWatching too many air-crash investigation episodes had lead me to believe 0% of media reported "facts" surrounding plane crashes. I will wait for the official accident investigation report.
- madez 11y agoThis is a very sound decision. The media is infamous for not getting facts straight. They much rather write an opinion based on suspicion. Well, no, thank you. Give me facts, get them straight, then I will make up my opinion.
- rkangel 11y agoThen stick with a news agency rather than journalists. The information from somewhere like Reuters is carefully presented as pure content, no opinion, and probably has a greater chance of being true.
- randomname2 11y agoThis is laughably false. While staying away from outright lying, Reuters very often adds their own spin to their reporting.
- fleitz 11y agoEspecially when it's their own journalists getting taken out in 'classified' videos.
- minwcnt5 11y agoRelated: the Gell-Mann Amnesia effect.
- madez 11y agoThe Gell-Mann Amnesia effect seems to be a specific version of something more general: cognitive dissonance. The fact that the media is not to trust is not forgotten, it is simply not evaluated and acted upon. It sits there in your brain until you sceptically reflect on what you think to know and how you act. Some people do that to some degree, most less so. We have had a long time to recognize that our brains don't work well. It is time to accept the facts.
- userbinator 11y agoI wonder if this is what lead to Airbus making a pretty vague statement compared to Boeing about its software on this other recent related news: http://www.bloomberg.com/news/articles/2015-05-18/hacker-claims-of-plane-takeover-aren-t-credible-official-says http://www.bloomberg.com/news/articles/2015-05-18/hacker-cla...
- tirant 11y agoI am not surprised at all. There are a lot of contractors involved in the development of the software for the A400M, and they are basically competing for price and employing undergraduates making below €18K/year, which they replace every few months due to burnouts and bad working conditions. Projects get continuously delayed, and key people barely stay more than a couple of years.
- hydrogen18 11y agoI thought that 'lowest bidder wins' was an American phenomenon? Certainly, Boeing and others have figured out how to game the system here in the states and abroad.
- VMG 11y ago> I thought that 'lowest bidder wins' was an American phenomenon? Why should it be?
- happyscrappy 11y agoBecause Europe cares about people not money, like in Greece.
- nier 11y agoMy german architect clients say: “Ze lowest bidder wins to start ze project with ze highest bidder’s plans.” Which is funny when you squint enough to ignore the tragedy.
- mhandley 11y agoHere's Airbus's statement on the Alert they sent to operators: Airbus Defence and Space has today (Tuesday 19 May) sent an Alert Operator Transmission (AOT) to all operators of the A400M informing them about specific checks to be performed on the fleet. To avoid potential risks in any future flights, Airbus Defence and Space has informed the operators about necessary actions to take. In addition, these results have immediately been shared with the official investigation team. The AOT requires Operators to perform one-time specific checks of the Electronic Control Units (ECU) on each of the aircraft's engines before next flight and introduces additional detailed checks to be carried out in the event of any subsequent engine or ECU replacement. This AOT results from Airbus Defence and Space's internal analysis and is issued as part of the Continued Airworthiness activities, independently from the on-going Official investigation. They're asking for a one-time check to be performed on the ECU. If it's just a software bug, normally a one-time check wouldn't reveal whether or not that bug could trigger. So, obviously they've found something they're concerned about, but it seems to me to be a bit early to say as Spiegel Online do that software caused the crash. In any event, one of the flight recorders was only just sent off to the manufacturer: http://economictimes.indiatimes.com/news/international/world-news/a400m-black-box-sent-to-us-to-seek-crash-clues-sources/articleshow/47331926.cms http://economictimes.indiatimes.com/news/international/world...
- JshWright 11y agoOr it seems like the problem may have been a known (or suspected) issue with an old firmware, and the check is to make sure the firmware is above a certain version (which would also explain why the check would be necessary on any replacement ECUs).
- deleted 11y ago[deleted]
- mhandley 11y agoThe A400M that crashed was on its first test flight, so unless they've done something very odd with versioning, it's unlikely that all its ECUs had older firmware than planes that already shipped. Besides, with aircraft, all changes are logged with a ton of paperwork, so they shouldn't need to check the aircraft to know what firmware they're running.
- sean-duffy 11y agoWow, this comes as a shock! Last year I saw the A400M appear at the Royal International Air Tattoo and was very impressed, as were many others. Hopefully they'll find the problem and this won't be too much of a blot on the development of this aircraft.
- alandarev 11y agoSoftware contractor for Airbus and Rolls-royce here. All safety critical software (every piece of code ran on-board is safety critical the least) in aerospace needs to pass the DO-178 standard [1]. That is far more serious than standard unit tests you are used to in node.js applications. Generally speaking, to develop a piece of code under that standard it takes 20% of time to write the code, and 80% to testing, and enormous amount of documentation (that is optimistic estimation, usually worse). Quoting speaker from DO-178 training course I attended: People often ask us. "How do we know the standard works?" We give this answer: "We do not know. But there have been zero crashes due to software issues since introduction" If this crash confirms the cause to be a software bug, that is something much bigger than an airplane crash - a huge punch to the whole federal aviation administration. [1] - http://en.wikipedia.org/wiki/DO-178B http://en.wikipedia.org/wiki/DO-178B
- belorn 11y agoHow does liability work, and do Airbus have access to the source code? I assume that if a "bug" was found in the architectural blueprint for a plane it would be the manufacturer who in the end is responsible for not finding it, but they would naturally have full access to the blueprint when making the plane. Is the same true when developing the custom software for the plane?
- luch 11y agoWell it's military airplane so it's a bit special here, usually it's the costumer (i.e. the army) which is liable if the plane has passed the final tests. However it's a complete different matter for civil airplanes : it's the lead dev/project manager which is liable for life for what he has shipped. For example, a retired engineer from Airbus was heard in trial for the Concorde accident in France in 2000.
- agumonkey 11y agoI've seen this first hand, unfortunately this doesn't escape the hiring market reality. Many documents and source files are littered with (very) bad code from an 3 months employee that couldn't do better before leaving considering the extreme size of the project. I wonder if someone can pull an #ElonMusk on the DO-178 to slim things down in order to have better control. ps: planes fly with bugs, see the DreamLiner, Airbus ones aren't free from them either, employees know this. (I guess they travel by train)
- lexy0202 11y agoI have done a quick and rough translation of the German article into English. Hopefully this is better than the Google Translate version: https://gist.github.com/alexcoplan/0018e3320f99a612c737 https://gist.github.com/alexcoplan/0018e3320f99a612c737
- BuildTheRobots 11y agoMuch more readable than the Glenglish version -thank you. I still don't understand "The crash is the worst accident since the development of the A400M", though. To me that implies there was a pretty devastating accident during the development.
- tedunangst 11y agoThat may be reading too much. Another reading is that Prior to development, the plane didn't exist.
- bhaak 11y agoThis is not a translation error. This sentence has the same puzzling meaning in the German version. I think it's sloppy journalist writing for the worst accident that happened with the development of the A400M.
- mrmondo 11y agoI wonder if this is the time to argue that it may be worth open sourcing the controlling software for hackers to start criticising and contributing pull requests to. I'm willing to bet that the competence of the collective community far outweighs that of those specially trained to write the software at present. What is there to lose by opening up the software to criticism other than better aviation safety? We know that obfuscating / hiding source code does not make applications / platforms safer or less at risk to malicious behaviour so I'd like to challenge the manufacturers to do so.
- DougWebb 11y agoWhat is there to lose? 0-Day attacks. Knowledge about bugs in aviation software is potentially more valuable to people who wish to do harm than to the people who would fix the bugs, so there's a concern that someone who finds a bug will sell that info rather than let the maintainers know about it. The other problem is that the maintainers have to be set up to handle a potential avalanche of comments, criticisms, questions, and pull requests, mostly from people who don't know anything about software development processes and standards within the aviation community. If they're already too overloaded to find all of the bugs themselves, they certainly won't be able to effectively manage open-sourcing their code.
- mason240 11y agoRealistically, how could someone exploit a 0-day in a aviation software?
- DougWebb 11y agoI don't know. I wouldn't want to find out. But more realistically, a good bug that's worth a lot of money will be subtle and hard to find, which means it may be around long enough to be exploitable.
- geon 11y agoPercieved commercial advantage and pride.
- tim333 11y agoFrom another report: "Problems in developing the engines, and particularly in certifying the engine control software, contributed to three years of delays and a new cash injection by governments in 2010." Seems like they had some issues. Surprising it's that difficult. http://www.reuters.com/article/2015/05/19/airbus-a400m-idUSL5N0YA28V20150519 http://www.reuters.com/article/2015/05/19/airbus-a400m-idUSL...
- zurn 11y agoAnyone know how much effort Google is putting into improving Translate? It feels like it hasn't gotten much better over the years even with these first-tier language pairs.
- crististm 11y agoEffort has little to do with it. If you don't have an angle of attack, you can't solve the problem. Humans have years of experience to put a text into context and interpret it.
- zurn 11y agoThat would be a bad excuse for not improving even if GT matched the state of the art. But it's doesn't for many/most languages.
- inetsee 11y agoI worked on software for the C-130J military cargo plane. It was before my time, but an earlier model aircraft crashed during a test flight. The crash occurred shortly after take off, and the entire crew was lost. There is a critical time period during a take off when the aircraft is at maximum risk. If an engine fails before rotation (i.e. before the wheels leave the ground) an alert crew can stand on the brakes and use thrust reversers. The aircraft may get dinged up, but there is a reasonable chance the crew (and passengers) will survive. If there is an engine failure after rotation but before the aircraft has gained sufficient altitude, unless there's a big, flat field next to the runway a crash is almost inevitable. When an aircraft turns, it will lose altitude unless the crew compensates by adding power. An aircraft without power and sufficient altitude cannot make the turns necessary to go all the way around to land on the runway they just left.
- sokoloff 11y agoYour post is substantially correct, with a clarification on rotation speed(Vr) vs takeoff decision speed (V1). There are three relevant speeds for large aircraft. (I'm going to generalize very slightly to keep this short and readable.) V1, Vr, V2. V1 is the takeoff decision speed. An engine failure recognized before reaching V1 is handled by aborting the takeoff. An engine failure recognized after reaching V1 is handled by continuing the takeoff. At the V1 callout, the pilot flying removes their hands from the top of the throttles (as a physical reminder that aborting/rejecting the takeoff(RTO) is not happening for a simple engine failure). Vr is the rotation speed, where the nose wheel is lifted from the ground. V2 is the speed at which the airplane will climb safely with one engine INOP. In most cases, V1 is the lowest speed, meaning there are cases (between V1 and Vr) where an engine out with the nosewheel on the ground results in continued acceleration, then rotation, and flight. It's a checkride bust to RTO above V1 for a simple engine failure.
- inetsee 11y agoThank you for clarifying my post. I am not a pilot. I am a software engineer (retired). I worked briefly on the C-130J mission computer operating system, then on the maintenance software the ground crews used to maintain the aircraft. I did not know that there was a situation when a flight crew would continue a take off after an engine failure but before rotation.
- traufetterg 11y agoDear Engup, I have read your thread that is unfortunately deleted. I am the author of the Spiegel-Story on A400M http://www.spiegel.de/politik/ausland/airbus-a400m-militaermaschine-stuerzte-wegen-software-problemen-ab-a-1034421.html http://www.spiegel.de/politik/ausland/airbus-a400m-militaerm... I would like to get into touch with you. gerald_traufetter@spiegel.de Best Gerald
- PhantomGremlin 11y agoAircraft manufacturers and operators go through great amounts of effort to avoid single points of failure. E.g. on a twin they overhaul the two engines at different times. But this is different. I wonder if they need to rethink their approach to software? Four engines, running the same software --> single point of failure.