Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Would you being willing to elaborate on what makes it special to you? I'd love to know more!

Years ago I worked at Ames on the ACES system (minor but fixes and a Greenfield projects involving data/flight path visualization), but I felt the airplanes themeselves were these magical black boxes. I'd would appreciate having a deeper understanding about how they differentiate from one another in a non-superfical sense.



Simply, what makes it special is I had a hand in it. Every time you fly on one, you're betting your life on my parts. I know how it works, and I know why it's safe.

I worked specifically on the stabilizer trim system (like the one in the news on the 737MAX), and did some work on the elevator system. In particular on the latter, I did many calculations to prove it would not flutter (dynamic instability).

My very first assignment was to size the stabilizer trim jackscrew. I panicked and told my lead I had no idea how to do that. He laughed and said of course you do, it's a simple column buckling problem. Which of course it was, and I sized it.

A couple years later, and the first jackscrew gearbox assembly came off the line, and was doomed to be subjected to the ultimate load test. Any buckling, cracks, deformation, etc., would be a failure. The test guys told me they were gonna bust my jackscrew.

They hooked it up to this big ugly iron I-beam with a hydraulic ram to compress my green BMS10-11 painted gearbox and shiny chrome steel jackscrew (made by Saginaw Gear, who made the best kick-ass forgings).

They started cranking up the pressure, while I stood around anxiously watching it. Slowly, the I-beam bent into a nice curve. We didn't have to make any changes to any of the stab trim system due to test failures. Whaddya know, the math works! So I am not a bit afraid to fly on a 757. The seating can be cramped, but that's the way it goes these days.

As far as know, there have been no in-service failures of that system. The 757 itself has a fantastic safety record, of which I am proud to have contributed to. The last D conference I flew to on a 757 operated by Iceland Air, yay!

At the time I bought a bunch of Boeing stock as a result of my confidence in Boeing, and it has paid off handsomely.


And here is the kind of catastrophe, that was prevented by Walter's calculations:

https://en.wikipedia.org/wiki/Aeroflot_Flight_8641


The 757 jackscrew gearbox is a scaled down version of the 747 one. There was one failure of the 747 jackscrew:

https://en.wikipedia.org/wiki/National_Airlines_Flight_102

A loose armored vehicle crashed into the jackscrew snapping it. There is no possible recovery from that. I cringe every time I see the video of that one. Horrible.


I thought the main cause of the crash was the cargo weight, didn't know it had also damaged the control hydraulics. Wonder if it could have been recovered if they'd had those controls.


Going down the wikipedia rabbit hole, the Aeroflot page refers to https://en.wikipedia.org/wiki/Alaska_Airlines_Flight_261

A few days ago I'd asked how the NTSB gets good co-operation from the airlines in these cases (thanks for the answers at the time!)

The interesting point to me was the contrast between the 2 cases.

In the Aeroflot case:

> Three engineers who signed the jackscrew drawings were convicted.

In the Alaska Airlines case:

> The investigation then proceeded to examine why scheduled maintenance had failed to adequately lubricate the jackscrew assembly. In interviews with the Alaska Airlines mechanic at San Francisco International Airport (SFO) who last performed the lubrication it was revealed that the task took about one hour, whereas the aircraft manufacturer estimated the task should take four hours. This and other evidence suggested to the NTSB that "the SFO mechanic who was responsible for lubricating the jackscrew assembly in September 1999 did not adequately perform the task". Laboratory tests indicated that the excessive wear of jackscrew assembly could not have accumulated in just the four-month period between the September 1999 maintenance and the accident flight. Therefore, the NTSB concluded that "more than just the last lubrication was missed or inadequately performed".

I couldn't find any mention of personal sanction.

Just surprised by the difference in treatment between the 2 cases...


If you read further, there is an even more interesting bit -

> In 1998, an Alaska Airlines mechanic named John Liotine, who worked in the Alaska Airlines maintenance center in Oakland, California, told the Federal Aviation Administration that supervisors were approving records of maintenance that they were not allowed to approve or that indicated work had been completed when, in fact, it had not. Liotine began working with federal investigators by secretly audio recording his supervisors. On December 22, 1998, federal authorities raided an Alaska Airlines property and seized maintenance records. In August 1999 Alaska Airlines put Liotine on paid leave, and in 2000 Liotine filed a libel suit against the airline. The crash of AS261 became a part of the federal investigation against Alaska Airlines because in 1997, Liotine had recommended that the jackscrew and gimbal nut of the accident aircraft be replaced, but had been overruled by another supervisor.In December 2001 federal prosecutors stated that they were not going to file criminal charges against Alaska Airlines. Around that time Alaska Airlines agreed to settle the libel suit by paying about $500,000; as part of the settlement, Liotine resigned.

The deficiencies of the FAA regulator regime should be obvious from this case, but it seems that no-one was held accountable for Alaska Airline's lack of safety culture in its maintenance operation.


Not to nitpick, but the failure mechanism in the crash and what Walter was testing are slightly different.

Fatigue failures like the one in the crash are from multiple sub-maximal loads (look up "S-N" curves for more info). In other words, fatigue comes from cycling lower loads many times on a part. Buckling calculations look for maximal load failures on a column (i.e. a single larger load event that can make it fail).

The link is a great example of a real world case study (and thank you for finding it!), and no doubt somebody was doing fatigue calculations on the jackscrew at Boeing as well. I just wanted to add a bit of nuance


> no doubt somebody was doing fatigue calculations on the jackscrew at Boeing as well.

Yes, they were (the stress group). The airframe was designed for 62,000 hours of operation, then scrapped due to fatigue considerations. Fatigue was a bit of a black art at the time, with rules based on extensive testing and experience. It's much better understood today.

Take a paper clip and bend it back and forth. Eventually, it will break. That's fatigue.


> It's much better understood today.

When I studied this it seemed to just be empirical, as in you calibrate some law to some measurements and use that to tell you when it is likely to fail. Has this changed?


I simply heard it had gotten much better. I don't know the details, as I pivoted to programming.


>no doubt somebody was doing fatigue calculations

I'm always surprised by the general publics' lack of awareness and understanding of fatigue. And then seeing the figurative lightbulb illuminate after asking them how they would break a metal clotheshanger, without any tools.

Anyway, it may not have been his personal responsibility, but certainly fatigue must have been a significant consideration during design, since (afaik) it's most often the controlling factor in lifetime estimates for structural components in airframes.

I would strongly assume the same would apply to a component who's expected failure mode might be buckling.


True, the design is one important part, but the design can be 100% on, but the manufacturing and the operational inspections are important to present failures too. Variance from controlled manufacturing conditions can result in parts that basically look and perform ok at first, but are at risk of failing early, that's why aircraft have inspection schedules - that are sometimes increased due to increased cycles on some routes/airports.

(and of course there is the case of the part being damaged somehow, where some of the other comments have linked cases where this happened catasropically).


Hmmm...

I'm not real familiar with that mass production qaqc.

Is there a term that describes a minimum design spec (or similar aspect), that takes into account the actual manufacturing (and other) variances?

I'm thinking that in construction, a rough equivalent would be a designs constructability / bidability review.


The design may call out a specific material and how to manufacture it, say make this part out of 6061 Aluminum, and. mill it in this way. You can look up the standard properties of that material. But depending on how that material is worked, cut, bent etc, you would expect in come cases some changes in the material properties or just sensitivities to fatigue. E.g. if you cut a sharp corner into that metal, fatigue will increase in that corner over the life of the part, so maybe you specify rounded corner - but how much it makes a difference you won't do necessarily a whole specific detailed study on it unless its a critical part or corner. If it's milled, if the machine that day has a duller bit, maybe it heats up the part more, and the material properties shift a bit more due to the heating. All these and are controlled in the process, but are still little things lead to variation, and maybe the controls fail one day and some slightly different aluminum makes in into the process.

For critical parts on the aircraft, there is the backup of inspecting for aspects like accelerated fatigue just for variation of manufacturing, of environmental contributors, etc. It's a lot like security defense in depth - many layers of protection for lives (and aircraft industry trustability linked to profitability too) at stake.


I'm not sure what you're asking but there is term in manufacturing called DFM or design for manufacturability. Otherwise, design drawings are loaded with specs that call out design tolerances etc. QA and process control are used ensure these tolerances are met


Maybe a dumb question, but wouldn’t you have expected it to break at the target max load? I would have thought it being stronger than required would mean it was heavier than necessary?


That is a fun question. Boeing had two groups - the design group, and the stress group. The design group does the design, the stress group checks it. I was in the former.

One day, I got called into the stress group, where they told me they were unhappy with my parts. I asked why, they said there just barely strong enough for the ultimate load, only about 1% over. They said they'd feel more comfortable with 10% extra strength.

I said this was no coincidence, I used math to size the part to the load, rather than guessing at a size and checking to see if it was strong enough. The requirement was the ultimate load, which is 150% of the maximum load that could ever be expected.

I asserted that I designed to the design requirement, and an extra 10% would make it overweight. Brat that I was, I said if you guys were unhappy with the design requirement, increase it. They grudgingly signed off on it.

The reason it didn't break on the test stand is because all parts vary in size due to manufacturing tolerances. It was sized to pass the ultimate load test under the most adverse size allowed under the tolerances. Odds are, it'll be a little stronger.

For comparison, spacecraft have (I think) an ultimate load of 110% of the max load. The margins are awfully thin, but they have little choice. If you really want a math heavy engineering job, design spacecraft.

BTW, the stress group signed off on the jackscrew size. If it had failed the ultimate load test, both them and I would have had a black eye. As it turned out, the test guys were embarrassed by their bent rig :-) and fortunately that wasn't really a problem.


>They said they'd feel more comfortable with 10% extra strength.

Did they want the extra 10% buffer for any particular reason?

Reason I ask, I always agreed with your take on not over-designing, philosophically. I had a couple of professors who made a big deal about being conservative/ round-up on calculating design elements, but once you tally up the different loading cases, you shouldn't ever bump the total required strength (again) beyond whatever the required multiplier is.

However, when faced with real life projects, I learned fairly early to ignore that advise, mostly because of the risk of having to redesign due to a changed design requirement. Of course I've also never worked for a company as structured as one like Boeing, and I've also encountered LRFD 99% of the time over ASD.

It's one of those life lessons that's never really sat right with me, but I still consider to be the rational choice.


> Did they want the extra 10% buffer for any particular reason?

They said they just were more comfortable with more margin. The stress group was an independent organization to avoid conflicts of interest with the design group. Our job was to design, their job was to verify. If parts broke, they got the black eye. If the airplane was overweight, design got the black eye. We both had to agree, and it was a system that worked well.

Most design engineers didn't work out the stresses themselves, they just hoped to pass the stress group. It was pass/fail for them. In my not so humble opinion, they were making overweight parts. I was interested in using math to sculpt perfect parts :-)

For example, the inside diameter of the jackscrew was specified to the ten-thousandth of an inch, something like 2.1834..2.2096. So I'd get the "why not make it a nice round 2.19..2.20?" I'd reply because if it came in at 2.205, it would get rejected, even though it was perfectly usable. And I got my way, because the jackscrew forging was a very, very expensive part and rejecting a usable part did not make anyone happy.

(Rejected expensive parts often got bounced back to engineering to find a way to salvage them. I just was doing the math in advance so they wouldn't have to.)


That specification is to 2.5 micron accuracy. Surely the forging can't be made to that precision?


> Surely the forging can't be made to that precision?

It's forged slightly oversized, then machined down to spec.

Forgings are about 3x stronger than a casting, and are of a more consistent quality, which is why when I increased the HP for my Dodge, I spent the extra bucks to get forged spinning parts (usually they are cast).


The range is much larger: OP was just being very precise in expressing the range so the manufacturing process had some extra leeway.


I wonder what was measuring to that precision with such accuracy! It’s when I think about tolerances on the equipment that’s checking tolerances that I start getting dizzy and retreat to software for a bit.


2.5 micron is basically the metric value for a 'tenth', i.e. one ten-thousandths of an inch. A typical machine shop will usually work in tolerances of a 'thou' or two, but most are equipped to measure to tenths without too much fuss. Standard micrometers have a vernier that reads tenths, and tenths indicators aren't uncommon.

Going beyond that, to tens of millionths or sub-micron, is where things get nutty with special climate controlled rooms. Digital indicators can easily read with such precision, but controlling for factors like radiated body heat become important.

Reference measurement is usually done with gauge blocks and pins. The development and popularization of these sets is basically how mechanical parts became standardized.

If you're interested in that sort of thing - bootstrapping precision and the like - check out "The Foundations of Mechanical Accuracy".


The precision (ability) of the machine rarely matches the precision of the measuring apparatus, if it's even part of the same equipment. And that's usually ok, even preferred, and cheaper.

If it's a rabbit hole you're interested in, then check out the history of geodesy / geodetic surveying & the design of mechanical / optical surveying equipment- especially theodolites & auto-levels (and even chronometers and astronomic observatories, if you want to go 4-dimensional).

It was the "industry" that had a large hand in innovating this technology, which led to the smaller versions used in manufacturing (made even more interesting due to the fact it was all funded to better artillery, and ultimately ballistic missle targeting, sans-GPS.)

I'd be happy to steer you in the right direction, if interested. It's a personal favorite.


Possibly a coordinate measuring machine (CMM) in an environmentally controlled environment, but even then it's coming awfully close to the capability limits


The spec is almost certainly for the machining after it's been forged.


I would have loved to take a field trip to Saginaw Gear and see all the various steps in its manufacture.


Like this but bigger.

https://www.youtube.com/watch?v=dzIsR4Mg158

"ball screw" and "lead screw" are your search terms. For aerospace it's gonna also be center drilled to save weight as well.


The forged parts are likely machined (for better finish and tolerance).


I wonder if you guys all went on a field trip to watch The Wind Rises haha


Sometimes these factors of safety are matters of convention (like the discretion of a company of certifying engineer) and sometimes they are grounded in some safety standard.

For example, if you're testing the integrity of a pressure vessel, the standard is to test it to 110% the rated maximum allowable working pressure if the medium is a compressible fluid (like air) or 150% if it's a 'non-compressible' fluid (like water, although everything is compressible to a certain extent). This is because the compression of a fluid stores a lot more internal energy if suddenly released. (Don't quote me exactly on these numbers because it's been a looooong time since I've had my nose in ASME standards)


I get factor of safety- (and phi etc for LRFD) what we're talking about is beyond the required factor of safety. OP designed the part using required multipliers, but the department checking the design wanted an extra 10% strength.


The point I was trying to get at is that in many cases (e.g., those not covered by an industry standard) there is no explicit “required” factor of safety. It’s left up to the discretion of the authority having jurisdiction. So while the design engineer may feel like a factor of safety of 2.0 is sufficient, the AHJ may “require” a 2.2 FOS to sign off


Thank you for sharing these stories, they’re amazing.


I'll add my thanks to the others - you must have (had?) a very interesting career.


Working on D is fun, too!


Thanks for the in-depth response! I think your response about increasing the design requirement was spot on. Maybe I'm a brat too. :P


Thanks for sharing! This was super interesting :-)




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: