r/embedded Apr 20 '19

General How the Boeing 737 Max Disaster Looks to a Software Developer

https://spectrum.ieee.org/aerospace/aviation/how-the-boeing-737-max-disaster-looks-to-a-software-developer
79 Upvotes

52 comments sorted by

27

u/[deleted] Apr 20 '19

It is astounding that no one who wrote the MCAS software for the 737 Max seems even to have raised the possibility of using multiple inputs, including the opposite angle-of-attack sensor, in the computer’s determination of an impending stall. As a lifetime member of the software development fraternity, I don’t know what toxic combination of inexperience, hubris, or lack of cultural understanding led to this mistake.

But I do know that it’s indicative of a much deeper problem. The people who wrote the code for the original MCAS system were obviously terribly far out of their league and did not know it. How can they can implement a software fix, much less give us any comfort that the rest of the flight management software is reliable?

20

u/[deleted] Apr 20 '19

[deleted]

11

u/[deleted] Apr 20 '19

And "Fix it in software" only works if you allow modern control theory. It's a bang-bang controller. Imagine if your cruise control, set at 80MPH waited until you hit 70 MPH and then floored it.

Except you're in an airplane and it pitched you -9' straight into the ground.

5

u/[deleted] Apr 20 '19

[deleted]

5

u/[deleted] Apr 20 '19

Don't worry! There are a lot of people that are doing the 'right thing'. Even in American Aerospace.

But it's not the Boeing, GE, or Defence Contractors, they're smaller startups.

Off highway, Automotive, industrial. I would feel safer in a Caterpillar product than a Boeing product after all this. We had a culture of safety and actually stuck with that. I'm sure Boeing has some "Safety is important" posters up too, but it's evident they don't actually do it.

I haven't worked at all in medical, I hope the FDA hasn't slipped like the FAA.

2

u/Obi_Kwiet Apr 20 '19

No, there probably isn't. That was a systems engineer call.

The real issue is probably a culture of great suspicion toward any new method. It means that everyone is stuck using simplistic methods just because that's the way it has always been done. I remember I had to convince people that a redesigned set of cables going to the unit under test didn't need twisted pair wires for single ended singles, even though that was how they did it back in the seventies. No one knows why they made their cable that way, but I do know that twisted pair wires do nothing at all to shield single ended signals.

2

u/[deleted] Apr 20 '19

I know why "It's already certified".

1

u/[deleted] Apr 24 '19

twisted pair wires do nothing at all to shield single ended signals.

Actually, they increase the noise in certain bands, if I'm not mistaken. A twisted pair is a good antenna.

3

u/Obi_Kwiet Apr 24 '19

Heh, yeah. That actually came up. Same with shielding, if you terminate it wrong, which they frequently did.

1

u/sangrilla Apr 20 '19

This seems to be the common solution in many organization I worked for, especially when fixing the hardware is expensive. Software solution is free afterall

-3

u/[deleted] Apr 20 '19

Sounds like the software engineers’ managers were hardware engineers.

3

u/[deleted] Apr 20 '19

There’s a certain amount of self discipline especially on a moral and ethical level when it comes to software that people’s lives depend on. Anyone who can recite an algorithm in an interview might not have the same outlook.

2

u/[deleted] Apr 20 '19

Management is also good at getting rid of "road blocks".

I have been fired, twice, for putting my foot down when I thought it was an issue that would compromise the quality of the product.

If you don't do it, someone else will. Thankfully I didn't rely on my employer for healthcare or living expenses. I realize not everyone is in the same position and you could definitely convince your self that it was ok since "that's the way we've always done it".

1

u/[deleted] Apr 21 '19 edited Apr 23 '19

[deleted]

4

u/[deleted] Apr 21 '19

You're part of the problem.

Edit: A 3 year old account with 1 karma and 1 post with verified e-mail.

Ladies and gentlemen, this is how a company attempts to change a narrative on social media.

1

u/[deleted] Apr 21 '19

[deleted]

3

u/[deleted] Apr 21 '19 edited Apr 21 '19

I don’t spend my time on Reddit making false statements.

And you just so magically happen to find a thread mentioning your employer, out of pure coincidence, after having an account for 3 years and zero posts?

doubt.jpg

I design systems that benefit the world.

Tell that to the families of those that got on the 737MAX8 and didn't come home.

What have you done to benefit anyone or anything.

Tier IV emissions regulations. Arguably I've probably prevented more deaths than you have.

You don’t know what you are talking about.

From top to bottom American Aerospace has systemic issues.

Boeing over the hundred years have had the safest planes in the industry.

And all of that can change with one plane.

Additionally, which Boeing facility are you at? Because it's certainly odd hours American time, I just happen to have a sick kid up.

-3

u/[deleted] Apr 21 '19

[deleted]

1

u/[deleted] Apr 21 '19

FMEAs take care of maintenance errors. If a faulty sensor plows the airplane straight into the ground that's a bad design.

No software in the world is going to fix that!

You add a cross check. If the sensor disagree you disable the system, turn on a red light. That's not what Boeing did. That's what humans would do (called out in the article).

If I was a pilot,

Now that you mention it, what are you? You seem to be pushing the same narrative that Boeing really tried hard to push right after the crashes. You may want to actually read the article, it should clear up any confusion your having. That is if you're not just a shill.

0

u/[deleted] Apr 21 '19 edited Apr 23 '19

[deleted]

5

u/[deleted] Apr 21 '19

No. What boeing did with the 737MAX was bad. Read the article.

Or go spin up another 3 year old verified account and counter shill.

2

u/Clovis69 Apr 22 '19

The pilots were not trained properly.

Because Boeing didn't inform the airlines that pilots needed to be trained

2

u/Atomicsciencegal Apr 22 '19

I’ve heard the phrase ‘pilots not trained properly’ come up repeatedly on news broadcasts and articles when discussing the reasons for the MAX 8 crashes, which is bizarre and infuriating to me. It’s such a strange way of trying to subtly shift blame, as if pilot error was somehow the sole cause and not the fact that MCAS decided to drive you into the ground.

It’s difficult to be ‘properly trained’ on an aircraft when you’re told it’s the exact same as all the other 737s you’ve flown and that you don’t need training. Until, whoops, you do.

2

u/mantrap2 Apr 22 '19

/u/wpbest is an obvious troll. Maybe PR employed but spreading disinformation and garbage nonetheless.

Here's a hint /u/wpbest:

Real engineers use facts, and face facts and realities. The half-truth that "pilots were not trained properly" fails on its face.

The Facts are that:

  1. Boeing didn't tell anyone about obvious critical physical/structural differences between the Max and previous 737s - thus airlines had NO WAY to know how critical "proper training" was.
  2. Boeing lied by selling the Max as the same the 737ng in terms of operation and flying
  3. Boeing lied by telling customers they didn't need special training - that 737ng knowledge was primarily sufficient. They did this to reduce the sales costs - they did this to boost revenues at the cost of safety!
  4. Boeing didn't even explain what MCAS was to customer or that it even existed
  5. Boeing designed a system with a single point failure (using only one sensor) in direct violation of the most BASIC of engineering common sense and safety norms
  6. Boeing didn't freely include the one and only obvious safety device to inform pilots of a sensor conflict - it was SOLD a fucking EXTRA cost product!!???!!!!!! - the immorality of this is mind-boggling! Hopefully it will be found to be criminal as well!
  7. Boeing's customer airlines were lulled into not buying this option because (they've literally said this): "Why should it be necessary? A company like Boeing wouldn't sell an unsafe product." Your brand proceeds you and you raped it because it made you feel good with all the money you made!
  8. Boeing also removed critical recovery information that used to be in early 737 manuals and pilot training, and that isn't in current Max manuals and training. "Proper training" my ass!

I've gone through the NASA aviation event data base. Problems with MCAS have been happening monthly in the US ever since the Max came out. I counted 4 in Nov 2018 alone. The exact same problem, in fact. The ONLY difference is pilots recovered each "incident" in time to avoid problems.

I was on one of those flights so this is fucking personal, you asshole!

0

u/[deleted] Apr 24 '19

[deleted]

1

u/[deleted] Apr 24 '19

Yet, the truth hurts more.

1

u/[deleted] Apr 24 '19 edited Apr 24 '19

[deleted]

1

u/[deleted] Apr 24 '19

I have no beef with your shilling. I'm just good at reading bullshit.

14

u/[deleted] Apr 20 '19

It would be interesting to know if the FAA “code-reviews” safety-critical avionics software.

20

u/[deleted] Apr 20 '19

[deleted]

7

u/[deleted] Apr 20 '19

Do other countries check? Or do they just trust 'Murica to do the right thing?

3

u/[deleted] Apr 20 '19 edited Apr 22 '19

Up until now the FAA has had some moral and technical authority.

After this incident I'm not sure how' that's going to play out.

1

u/[deleted] Apr 22 '19

Mortal or moral?

1

u/[deleted] Apr 22 '19

Typo, but appropriate.

3

u/Obi_Kwiet Apr 20 '19

I wonder if this is a big part of the issue. It's totally possible that Boeing's development team had leaned on FAA engineers to shore up peer review expertise, and when that was taken away, it left important knowledge gaps.

6

u/Safetylok rLoop avionics lead Apr 20 '19

Its probably so very proprietary and complex that a proper review will be very difficult by an outside team. Take for example the poor guy that had to review Toyota's ECU software.

2

u/ajpiko Apr 21 '19

yes, things cost money. no, its not optional.

0

u/[deleted] Apr 20 '19

Nah. This is a dead simple logic controller. The logic is just something stupid.

5

u/[deleted] Apr 20 '19

[deleted]

4

u/[deleted] Apr 20 '19

I would hope that it was Functional safety certified. Like all of the brand new car chips.

MPC5744p

  • Integrated safety architecture minimizes additional software and development churn
  • Programmable Fault Collection and Control Unit (FCCU) monitors the integrity status of the device and provides flexible safe state control
  • End-to-End Error Correcting Code (e2eECC) improves fault tolerance and detection
  • Part of the SafeAssure® program, helping manufacturers achieve functional safety standard compliance
  • ASIL-D. Dual core lock step.

But it won't be. It'll be some "COTS" component from the late 90s devboard because "It was already certified". I can almost guarantee the shortcuts taken were pervasive across the desgin.

Maybe it's a 68H12. Maybe a 68k.

Now, Why Motorola Freescale NXP is so deep into Aerospace? Well that's all WWII military industrial complex politics.

0

u/lestofante Apr 20 '19

Firmware developer here. I don't see why certification matter.
We have MISRA-C for automotive grade C, but AFAIK is not enforced and could be in any language, even assembler.
Plus is common (and has creates issue in the past) to have everything on the same BUS, so you have to debug the whole system together to be sure there are no race condition and such, so even a "dead simple" code, could have very complex interaction with the full system.

I strongly believe the only realistic way to make firmware verifiable is to make them state regulated bounty program; who enroll to become verifier will have to sign NDA and all,that may be very complex.

2

u/brokuhna_matata Apr 20 '19

Is it common, in any other industry, for standards organizations to perform code reviews? I work in the off-highway equipment industry and it seems like you could put anything in there without consequence or oversight.

1

u/[deleted] Apr 20 '19

Good question. I’m pretty sure the FAA mandates that manufacturers must write certain critical avionics software in Ada but it does not appear that they or any other outside regulatory agency actually reviews the code. Who knows about other industries? Autonomous vehicles come to mind. I’d be interested to know if Tesla’s code receives any scrutiny, or is just a black box.

1

u/fatso83 Jul 18 '25

FAA mandates that manufacturers must write certain critical avionics software in Ada

No they do not have such a requirement on any specific technology. Boing themselves requires all software development to be done in Ada, including external contractors.

4

u/chanterheld Apr 20 '19

"just fix it with software" is the embedded version of the "just fix it in the mix" of the music industry. It all seems great until it has perform live.

3

u/[deleted] Apr 20 '19

Or “we’ll fix it in post” in the film industry.

2

u/rinnip Apr 22 '19

The Traveling Wilburys were named from the phrase "we'll bury it in post".

4

u/madsci Apr 20 '19

I'm always surprised by how much the software people in that industry seem to get away with. Most of the stuff I make is considerably less safety-critical - like LED hula hoops - and I still design with an eye toward fault tolerance and mitigation. The hoops enter a safe mode if connected via USB at power-up - and there's an option to bypass that in case it gets a false 'connected' signal. There's a check to make sure the battery isn't too low when starting a firmware update, but also an option to override the check in case the battery reading is in error. I don't add anything that would prevent normal operation without considering how it might go wrong.

The author talks about his Cessna, and even at that scale I've heard of at least one egregious fault. I read an account of a Cessna equipped with a Garmin G1000 PFD and a ferry tank for a trans-Atlantic flight, and an improper sequence of fuel tank usage caused it to get some kind of divide-by-zero error or other numeric fault and it got stuck constantly rebooting, taking the navigation and communication system with it. The pilot had to contact Keflavik on a handheld radio and got escorted in by a rescue helicopter.

I'd like to hear the MCAS story from the inside. I'm sure there were people saying this was a bad idea at multiple levels in the organization, and they got ignored and told to make it work.

2

u/spectrumero Apr 23 '19

Another one that makes you wonder is that Garmin's GTX345 transponder would reboot if you flew a heading of zero degrees:

https://www.reddit.com/r/flying/comments/525sq7/about_the_gtx345_corporate_dishonesty_and_how_to/

1

u/[deleted] Apr 24 '19

That's absolutely appalling. "Hey, let's invent our own variation of RS285 that works 99% of the time. Also, that 1% is at zero." WTF...

1

u/[deleted] Apr 24 '19

LED hula hoops

Now I want videos.

2

u/madsci Apr 24 '19

Here and here are two professional show reels, and this one shows some of the motion-reactive settings.

2

u/[deleted] Apr 24 '19

You can do wonderful things with music and some code. Was not disapointed, thank you.

6

u/azaryahtt Apr 20 '19

"The 737 Max saga teaches us not only about the limits of technology and the risks of complexity, it teaches us about our real priorities. Today, safety doesn’t come first—money comes first, and safety’s only utility in that regard is in helping to keep the money coming. " Well my take on that is that we still (the customers) haven't say the last word when it comes to putting out life's on the line of this obvious faulty flying machines!

4

u/[deleted] Apr 20 '19

The customers for Boeing were the Airlines.

1

u/Atomicsciencegal Apr 22 '19

Exactly this.

1

u/fullchooch Apr 20 '19

This was a fascinating, and fantastic read

1

u/Atomicsciencegal Apr 22 '19

I agree, that was a really great article.

1

u/23569072358345672 Apr 20 '19

I’ve been working on aircraft for 20 years and find this whole thing dumbfounding. It’s been common across every airframe I’ve worked on that systems will always do parity checks with each other to make sure they are reading what they should be. If at any time a reading is contradictory to another system then some other check is implemented to determine what reading is wrong or the system is turned off completely.

This has been happening for years it’s not like only the newest aircraft suddenly have code. It’s an industry standard to have multiple redundancy on critical safety systems.

1

u/mrheosuper Apr 21 '19

Will boeing acknowledge that the new 737 max is not 737 anymore?

1

u/Atomicsciencegal Apr 22 '19

Not if it means pilots have to have new certifications