News: 1585838712

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Boeing 787s must be turned off and on every 51 days to prevent 'misleading data' being shown to pilots

(2020/04/02)


The US Federal Aviation Administration has ordered Boeing 787 operators to switch their aircraft off and on every 51 days to prevent what it called "several potentially catastrophic failure scenarios" – including the crashing of onboard network switches.

The [1]airworthiness directive , due to be enforced from later this month, orders airlines to power-cycle their B787s before the aircraft reaches the specified days of continuous power-on operation.

The power cycling is needed to prevent stale data from populating the aircraft's systems, a problem that has occurred on different 787 systems in the past.

According to the directive itself, if the aircraft is powered on for more than 51 days this can lead to "display of misleading data" to the pilots, with that data including airspeed, attitude, altitude and engine operating indications. On top of all that, the stall warning horn and overspeed horn also stop working.

This alarming-sounding situation comes about because, for reasons the directive did not go into, the 787's common core system (CCS) – a Wind River VxWorks realtime OS product, at heart – stops filtering out stale data from key flight control displays. That stale data-monitoring function going down in turn "could lead to undetected or unannunciated loss of common data network (CDN) message age validation, combined with a CDN switch failure".

Solving the problem is simple: power the aircraft down completely before reaching 51 days. It is usual for commercial airliners to spend weeks or more continuously powered on as crews change at airports, or ground power is plugged in overnight while cleaners and maintainers do their thing.

The CDN is a Boeing avionics term for the 787's internal Ethernet-based network. It is built to a slightly more stringent aviation-specific standard than common-or-garden Ethernet, that standard being called ARINC 664. More about ARINC 664 can be read [2]here .

Airline pilots were sanguine about the implications of the failures when El Reg asked a handful about the directive. One told us: "Loss of airspeed data combined with engine instrument malfunctions isn't unheard of," adding that there wasn't really enough information in the doc to decide whether or not the described failure would be truly catastrophic. Besides, he said, the backup speed and attitude instruments are – for obvious reasons – completely separate from the main displays.

Another mused that loss of engine indications would make it harder to adopt the fallback drill of setting a known pitch and engine power* setting that guarantees safe straight-and-level flight while the pilots consult checklists and manuals to find a fix.

A third commented, tongue firmly in cheek: "Anything like that with the aircraft is unhealthy!"

A previous software bug forced airlines to [3]power down their 787s every 248 days for fear that electrical generators could shut down in flight.

Airbus suffers from similar issues with its A350, with a relatively recent but since-patched bug [4]forcing power cycles every 149 hours .

Staleness persists

Persistent or unfiltered stale data is a known 787 problem. In 2014 a Japan Airlines 787 caught fire because of the (entirely separate, and since fixed) [5]lithium-ion battery problem . Investigators realised the black boxes [6]had been recording false information , hampering their task, because they were falsely accepting stale old data as up-to-the-second real inputs.

Boeing 787 software bug can shut down planes' generators IN FLIGHT [7]READ MORE

More seriously, another 787 stale data problem in years gone by saw superseded backup flight plans persisting in standby navigation computers, and activating occasionally. Activation caused the autopilot to wrongly decide it was halfway through flying a previous journey – and manoeuvre to regain the "correct" flight path. Another symptom was for the flight management system to simply go blank and freeze, triggered by selection of a standard arrival path (STAR) with exactly 14 waypoints – such as the BIMPA 4U approach to Poland's rather busy Warsaw Airport. The Polish air safety regulator [8]published this mildly alarming finding in 2016 [2-page PDF, in Polish].

This was fixed through a software update, [9]as the US Federal Aviation Administration reiterated last year . In addition, Warsaw's BIMPA 4U approach has since been superseded.

The Register asked Boeing to comment. ®

Bootnote

* Pitch and power is a simple concept. If you have the throttles, say, three-quarters open and the nose of the aeroplane is pointing a few degrees above the horizon, chances are you're probably flying straight and level at a safe speed. Training manuals normally contain a number of precise pitch and power settings (they vary between aeroplane types) so if display systems start failing, pilots can fall back to these with confidence.



[1] https://ad.easa.europa.eu/ad/US-2020-06-14

[2] https://www.aim-online.com/products-overview/tutorials/afdx-arinc664p7-tutorial/

[3] https://www.theregister.co.uk/2015/05/01/787_software_bug_can_shut_down_planes_generators/

[4] https://www.theregister.co.uk/2019/07/25/a350_power_cycle_software_bug_149_hours/

[5] https://www.theregister.co.uk/2013/01/17/faa_grounds_boeing_787_batteries/

[6] https://www.flightglobal.com/ntsb-details-issues-with-787-flight-and-data-recorder/115282.article

[7] https://www.theregister.co.uk/2015/05/01/787_software_bug_can_shut_down_planes_generators/

[8] https://regmedia.co.uk/2020/04/02/akt.pdf

[9] https://www.federalregister.gov/documents/2019/02/15/2019-02160/airworthiness-directives-the-boeing-company-airplanes

Millisecond roll-over?

BJC

So, what is the probability that the timing for these events is stored as milliseconds in a 32 bit structure?

Re: Millisecond roll-over?

Yet Another Anonymous coward

Exactly and yet internet experts will start blaming Boeing for improper testing when the real problem is the day being too long.

Re: Millisecond roll-over?

Nigel Sedgwick

My first thought too, but that rolls over after 49.7 days.

Still, they could have it wrong again.

Best regards

Re: Millisecond roll-over?

Simon Harris

The ratio difference between 49.7 and 51 days is suspiciously close to 1.024 though.

Re: Millisecond roll-over?

the spectacularly refined chap

Could well be something like that, the earlier 248 day issue is exactly the same duration that older Unix hands will recognise as the 'lbolt issue': a variable holding the number of clock ticks since boot overflows a signed 32 bit int after 248 days assuming clock ticks are at 100Hz as was usual back then and is still quite common.

See e.g. [1]here. The issue has been known about and the mitigation well documented for at least 30 years. Makes you wonder about the monkeys they have coding this stuff.

[1] http://uw714doc.sco.com/en/HDK_concepts/ddT_lbolt.html

Windows Server 2000

Nunyabiznes

IIRC, we had to restart those at a minimum of every thirty something days or they would lock up. Fortunately, they tended to fall over quite a bit more frequently than that so we seldom ran into that particular bug.

WTH is Boeing doing re-using that particular bit of crusty code?

Re: Windows Server 2000

Yet Another Anonymous coward

It was Windows95/98 and it took years in the wild before anybody noticed for that very reason.

“ - and this is the rock-solid principle on which the whole of the Corporation's Galaxywide success is founded - their fundamental design flaws are completely hidden by their superficial design flaws.”

Re: Windows Server 2000

Nunyabiznes

I could have sworn it was Server 2000 also. There was a lot of shared code there.

Great quote, btw.

Re: Windows Server 2000

Fred Dibnah

And NT4. I worked for a firm that had hundreds of PCs running it, and they were all rebooted every 42 days.

Am I surprised?

Will Godfrey

Sadly no. I get the horrible feeling we are still just seeing the tip of the iceberg. Is there any part of Boeing that can be regarded as up to standard?

Re: Am I surprised?

Flocke Kroes

The boondoggle funding department is world class.

Re: Am I surprised?

Mage

So I for one have cancelled all my orders for Boeings. Actually I don't seem to have any customers either.

If it's Boeing...

Steve K

If it's Boeing...wrong data's showing.

(Yes I know that Airbus have patched somethng similar...)

Turning it off and on

Pascal Monett

So, Boeing is using Windows in its planes now ?

Run for the hills !

Re: Turning it off and on

Nunyabiznes

Um, that's what they are going to run into. I'd run for the flats!

Re: Turning it off and on

ClockworkOwl

Um, are Boeing responsible for any mining equipment software???

NCB donkey jacket>

How long does it take to reboot a 787 ?

alain williams

I imagine that it is longer than the 30 odd seconds it takes to reboot my Linux box.

Re: How long does it take to reboot a 787 ?

Anonymous Coward

And? Your point is what exactly? Genuinely interested.

Anonymous Coward

Ye Gods

Brian Morrison

In the current world situation I imagine it won't be long before a goodly percentage of 787s are simply powered down somewhere out the way and left until there are lemon-soaked paper napkins again.

Of course, it might give RR a chance to catch up with engine rebuilds that have left some aircraft on the ground for a fair while in any case.

If it's Boeing, I'm not going.

Zippy´s Sausage Factory

"If it's Boeing, I'm not going."

I think you found my new philosophy of flying...

Designers needed

Dwarf

Sounds like a number of designers are needed that come from this century and can resolve the endless looking list of shortcuts and issues that seem to be have been designed into this steaming pile of poo.

Why they are not thinking a bit more long-term in either handling the rollover issue better (more bits to make it a far longer duration), or better still design in the fact that things will roll and expecting that in the platform design and software so that it does work properly. .

Alternately, work around with a rolling reboots until better software and firmware can be deployed. The whole idea of "turn it off and on again" is so dated now.

"Sounds like a number of designers are needed ..."

Mike 137

What, they have designers of any kind in their software teams? I thought it was all about coding these days.

Agile, as widely implemented, steps directly from concept to implementation, skipping the design stage entirely.

Simples

Anonymous Coward

Just switch off the airplane for ten minutes for a proper power drain and power it on again. Best practice is to avoid contact with the ground in the meantime.

Just a geek

And every 248 days for this bug -> https://www.slashgear.com/faa-boeing-787s-need-to-be-rebooted-every-248-days-uptime-04381899/

The 787 is mess

Sandtitz

Well, duh, it's mentioned in the article.

HCV

I remember they were very excited to announce that to mitigate problems like this, Windows now included a feature where you could schedule an automatic reboot.

Oh goody! You've invented cron!

Oh, I have slipped the surly bonds of earth,
And danced the skies on laughter silvered wings;
Sunward I've climbed and joined the tumbling mirth
Of sun-split clouds and done a hundred things
You have not dreamed of --
Wheeled and soared and swung
High in the sunlit silence.
Hovering there
I've chased the shouting wind along and flung
My eager craft through footless halls of air.
Up, up along delirious, burning blue
I've topped the wind-swept heights with easy grace,
Where never lark, or even eagle flew;
And, while with silent, lifting mind I've trod
The high untrespassed sanctity of space,
Put out my hand, and touched the face of God.
-- John Gillespie Magee Jr., "High Flight"