Qantas Airbus A380 engine failure in 2010 (2023)(admiralcloudberg.medium.com) |
Qantas Airbus A380 engine failure in 2010 (2023)(admiralcloudberg.medium.com) |
While I was sitting at the gate, I remembered that line from Rain Main about "Qantas never crashed," and since that flight would be my first time flying on an A380, I wondered if any had crashed or had any other incidents. I looked up "a380 crash" on my phone, and what do you know? The first hit was a Wikipedia article about a Qantas A380 uncontained engine failure, which had occurred four minutes after takeoff... from Changi! Even wilder was the fact that it had happened 9 years earlier. When I looked up the plane's registration number on Flightradar24, I realized that was the same plane I was flying to Melbourne on.
Fan blades and turbine blades can be contained by containment cases if they break off, but turbine disks can't. When a disk breaks, it's an uncontained engine failure. A 20 kg disk fragment flying at Mach 1 goes through everything.
Airframes are have a 30-degree fragment spread cone around every disk stage. Airframes are designed so that no single fragment can destroy all redundant systems at once in this zone (flight controls, fuel lines, and hydraulic systems). Jet fuel cannot be stored in the wings in this zone.
These were pulled and scrapped from the whole A380 fleet.
"Investigators also criticized the culture within the Hucknall facility that manufactured the HP/IP bearing hubs, identifying signs of complacency and widespread procedural non-compliance. A paperwork review showed that the required signatures were missing from 131 out of 138 retrospective concessions issued between 2009 and 2011, and a large number of minor non-conformances had not been properly handled through the normal chain of command."
It was a belt-and-braces fix, because the primary fix was of course to manufacture the engines correctly in the first place.
The "lots of temperature sensors" thing is actually easier said than done; jet engines already have lots of temperature sensors, and they will turn the engine off if a huge overtemperature is detected, but it's not a free win to add more of them. It increases the risk of a faulty sensor shutting down a perfectly good engine in flight, which from a safety-critical perspective is a borderline disaster condition all by itself.
(technically you usually cross-correlate temperature sensor readings with pressure sensor readings to prevent sensor faults turning engines off, but still, extra sensors isn't always a free win.)
> Within the space of four seconds, the energy from the annulus gas flow accelerated the IP turbine past its critical speed, until centrifugal forces exceeded the ultimate strength of the nickel alloy disk. The red-hot, wildly spinning disk instantly fractured into several sections, which rocketed outward in multiple directions at incomprehensible speed.
They got lucky.
TFA describes a fuel leak resulting from a piece of the turbine disk passing through a fuel tank located within the wing:
"When the fragments of the IP turbine disk passed through the wing and belly of the A380, they caused considerable secondary damage along the way, not only to the №2 engine but also to the left wing fuel tank, which sprang a leak"
It also includes a photo of the inside of the damaged wing tank.
Was the requirement you describe added after this incident?
“These [combustion] gases spin the [turbine] disk, which is attached by a drive arm to its associated drive shaft. The shaft then transfers the turbine’s rotational energy forward to the corresponding compressor at the front of the engine.”
I'm probably misunderstanding, but it sounds like the disk is attached to the shaft by a single so-called “drive arm”, which could be imagined to span maybe 10° on the circumference. I would have thought there'd be at least 3 such arms at 120° intervals, if not a continuous full 360° connection, which then I wouldn't call an arm. Could you clarify this point?
> The detailed software allowed them to enter various parameters including the weather, runway condition, and any systems failures, and then calculate whether it was possible to land. But when everything had been entered, the program spit out an unhelpful answer: “no result.”
> When calculating the landing distance, the software applied a generic “operational coefficient” to account conservatively for variations in pilot techniques that could result in less efficient deceleration. The problem, as investigators would later discover, was that the software applied the coefficient again whenever another system failure was added. With so many system failures on the aircraft, the coefficient was applied a total of 9 times, resulting in a calculated landing distance considerably greater than the length of the available runway. However, Check Captain Evans was able to fix the problem by manually entering their actual landing weight, overriding the program’s assumption of a maximum landing weight. By specifying a landing weight in excess of the maximum, the system logic changed to apply the operational coefficient only once — for unrelated and obscure reasons — and lo and behold, when he ran the numbers this time, the computer said they could just barely land on any of the 4,000-meter runways at Singapore Changi Airport, with only 100 meters to spare.
This reeks so much of if-then-else programming as opposed to making a well-typed conceptual model computable.Finally, working from the inside through the inner hub counter bore, the stub pipe counter bore would be drilled to a specified depth to accommodate the filter. (This was the bore that was later found to be offset by half a millimeter.)
Why not machine the stub pipes to their desired dimensions, including the drilling, and then install them? That way, no in-situ drilling, with that accompanying risk of misalignment, would even be necessary. Even if they decided such drilling was unavoidable, a drill with a pilot (no pun intended) would've kept the holes as concentric as needed. (Disclaimer: Not a professional machinist; but have done some lathe and mill work.)
The temperature inside this buffer space was likely between 365 and 375˚C, well above the 280-degree auto-ignition temperature of the engine oil, so the spray immediately ignited.
It's worth noting that due to fire risk, most planes use non-flammable hydraulic fluid, although it's not without its own dangers, so perhaps non-flammable engine oil was considered but ultimately decided against: https://en.wikipedia.org/wiki/Skydrol
If memory serves, they were celebrating some sort of milestone like "60 years without a fatal accident" or similar. Quite an impressive feat!
I'm unclear if it was directly related. But the Qantas inflight entertainment system on our flight from Sydney to Los Angeles meanwhile contained about 12 seasons of the National Geographic series "Air Crash Investigation" (Mayday: Air Disasters for Americans)
I will admit that show made an 18 hour slog of a flight significantly more enjoyable
One of the hosts recently started a new podcast called Runway 23 that's mostly about air crashes, and his cohost is actually a Qantas pilot.
So last few times I opted for "To Catch A Smuggler". Still flight related but hopefully less unsettling.
> According to Check Captain David Evans, the cabin crew were concerned that so many passengers were watching the live feed from the tail camera, but in a collective decision, the pilots elected not to turn it off because, in their view, the feed suddenly cutting out would probably be more alarming than anything that could be seen on it.
I appreciate this part. If I were ever in a similar situation, I'd want to be able to see what's going on. Suddenly cutting the feed would send me straight into a panic.
This flight had a new system to allow passengers to see what the pilots saw. There's a chance that the passengers got to see the panic in the cockpit and watch their fates coming.
I have seen claims that this caused such systems to be avoided for a while.
She recently posted what's basically her magnum opus, on the Potomac river midair collision.[0] It's the length of a short book. I'm working my way through it; I'm taking a flight today, and I'll probably read it on the plane tonight.
This article, on how an A380 with 469 souls aboard almost crashed, but didn't, is one of her best. I like it because it's a happy ending, and a story of the combined effects of good engineering design (the astonishing degree of redundancy built into the A380 proved just enough to prevent catastrophe), and human troubleshooting under pressure in the cockpit by some smart people with vast experience who remained calm throughout. (Another favorite article of her, on the Air France 447 crash, tells the exact opposite story: poor systems design combined with pilots basically losing the most basic ability to aviate in the heat of the moment. That one is a much darker read.[1])
[0] https://admiralcloudberg.medium.com/reaping-the-whirlwind-in... [1] https://admiralcloudberg.medium.com/the-long-way-down-the-cr...
https://admiralcloudberg.medium.com/years-of-salt-and-metal-...
It baffles me that that airlines can run so well on check lists and procedures instead of thinking and understanding. This is a case where just a tiny bit of understanding on the part of the mechanics would have avoided a crash and two deaths.
One of the talks there was from Qantas Senior Check Captain David Evans, "Teamwork Under Duress" there, which was all about that flight and what happened.
It was an amazing talk, and I have a huge amount of respect for the job that airline pilots do.
Because also, from Wikipedia: On 22 June 2011, Qantas announced that it had agreed to a compensation of AUD$95 million (£62 million/US$100 million) from Rolls-Royce. - skipping Airbus entirely.
AIUI when you're buying a plane from Airbus, it's possible/frequent to own the _airframe_; but not the engines — the engines are often _leased_ (sometimes directly from RR/GE); I've even heard of cases where each engine will be owned by a different entity!
https://aviation.stackexchange.com/questions/12528/jet-engin...
[0]https://www.harpercollins.com/products/the-perfectionists-si...
This quote amazes me. My understanding is that Airbus, Qantas, and probably Rolls Royce were willing to spend this much because it meant that the incident was not a "hull loss" and therefore not as bad a hit to reputation and safety statistics. Does anyone know if that's true?
Being able to keep this "never lost a jetliner" / "no accident we couldn't fly away from in 75 years" marketing claim is worth a lot. It's also why Qantas Flight 1 (1999, runway overrun of a 747-400, no significant injuries), despite initially being a write-off, was repaired for over AU$100M and returned to service.
Some discussion:
This person claims that he tells his family to avoid flying on Qantas ( but flies on it himself since he gets free flights)
These days Han airlines ( SIA, Cathay,China Eastern) and Middle Eastern airlines (Emirates,Qatar) are far better than Western Airlines ( American, British, Lufthansa, KLM,Qantas).
https://en.wikipedia.org/wiki/China_Eastern_Airlines_Flight_...
Meanwhile Lufthansa had their last fatal crash in 1993. For British it was in 1976.
great example of why I would avoid any PRC airline if I can help it.
(Presumably one reason they don't want to release the report is because it would lead many others to do the same and they want to protect their airline profits, but of course it ensures that the problem will not be fixed the longer they delay it)
Plane landed without casualties? Check
Plane design so good it helped avoid casualties? Check
Hum... Ah! Not an american Boeing but a french Airbus. Of course.
The article mentions this story should make everyone a little less afraid of flying.
Sure, as long as its not on a Boeing plane.
Any reason for assuming that your preferred solution would have been an available and comfortable option for the Airbus' lead engineers back then?
Nonetheless, the language is not the real impediment, it is the way of approaching a problem. Also, the software we are talking about was a standalone application installed on laptops, they were not part of the airplane's board computer.
inb4 you are racis Im moroccan
I personally know a guy who faked his entire university record (dad is a local politician) and is now working at engine systems at airbus in france
he does have a winning smile though
europe is not ready to deal with third world achievement dynamics
> 5 pilots were in the cockpit of this flight. In addition to the normal crew of pilot-in-command and co-pilot, there was an experienced relief pilot and two additional check captains; one was being trained as a check captain (CC) and the supervising CC, who was training the CC.
Captain Richard Champion de Crespigny had 35 years of flying experience at the time of the incident.
That is an insane amount of flight experience in the cockpit and all of the reports state this was a very significant factor. i.e by allowing distribution of the task load, plenty of time for one of the pilots to compute landing calculations manually etc.
THe A380 is a flying tank no doubt, but it wasn't the sole factor here - I think most people would agree this one was a shared victory.
During the development of the A380, the German and French sides were using different versions of the CATIA PLM software (i.e. CAD), which prevented people from looking at a single unified model of the plane. One concrete problem it caused was major problems with the wiring harnesses, which led to a 2 year delay in the program, and 3 early A380's which couldn't be sold. (Airbus kept one for test, the other two got sent to museums)
That manifested in this accident because the wing wiring was routed through the engine disk burst axes (a hazard which is explicitly accounted for) with insufficient redundancy. That created the dangerous situation where they couldn't turn off the engine after landing.
The guy taking his hat off makes me burst into nervous giggles every time lol.
[0] https://www.reddit.com/r/interestingasfuck/comments/1k80h9j/...
Which is vastly preferable compared to all of the dangerous situations just prior to that landing.
[0] - this one and https://news.ycombinator.com/item?id=49541946
> [something about london taxi drivers, admittedly unrelated]
> I totally get you and in theory you are right. And yet, in the USA you have gerrymandering and apparently _wanted_ Trump. Twice. Something has to be very wrong somewhere.
> I would suggest "lobbying" is not the correct word to describe all the corruption going on in the current USA administration cesspool.
>I recently bought a BambuLab 3D printer. Designed and made in China. Right from the unpacking to first print the experience was top Apple-style quality. Indeed I was agreeably surprised.
> A global non USA success? Plenty. You might want to remove your pink USA glasses and look around. Spotify good enough for you?
> I am Canadian. Never, ever would i knowingly buy any dairy products from the USA , at any price. We have cows too, and farmers.
> Its not that it hates its customers , as much as it it a USA-based company that is run under the rules made by the administration. Not that much different from running Red Star OS from North Korea, actually.
> [Finally something unrelated]
In India, afaik, a well-educated Indian has fairer chances. I don't know how much the current unemployment situation is playing out though.
One of the requirements of FAR/JAR 25 is that the directional control can be maintained when two critical engines (that means under the same wing) fail.
They also required engine software that detected the sudden increase in speed associated with a shaft break and automatically cut fuel.
I'd bet the plane would still be able to take off, if it made it that far. But it never would - with the extra weight guaranteeing that no airline would buy it, Finance would never sign off on funding to even complete the design work.
(Yes, the reality behind my quips about Sales and Finance is more complex:)
A 70kg chunk of nickel alloy is very dense, and at 800m/s , that’s 20 MJ. Thats about the same as 5kg of TNT, but focused on a small area.
For comparison, a modern 120mm artillery shell fired from a tank or similar field artillery has 10-20 MJ of kinetic energy.
A couple thousand kg of armour could likely contain that kind of energy, but it would also translate that energy to the engine mounts, wing, spar, and fuselage if it was not going to become a projectile itself. You could easily stop a fragment and critically damage a spar attachment, rupture a wing fuel tank, or end up with translational shock damage to any number of critical systems and structures. You’d probably have to double or triple your engineering margins of the entire aircraft, probably doubling the weight of the airframe.
So yeah, possible probably. But not on an aircraft designed to carry passengers or freight. It would be the biggest 6 seat aircraft ever built lol.
Interestingly, if you work backwards from that cargo capacity, you can arrive at a much smaller aircraft that could possibly feature full containment, because engine diameter and energy goes way down and containment starts to look much more practical. I would not be surprised if containment could be achieved in the small biz jet scale, with just significant sacrifices in cargo or range.
OTOH even the A10 warthog does not have full disk containment, and it’s probably the strongest candidate ever fielded for such a project… so, ymmv.
> For comparison, a modern 120mm artillery shell fired from a tank or similar ...
Yes. But when the goal is kinetic penetration of modern armour, they don't use artillery shells. Instead -
https://en.wikipedia.org/wiki/Armour-piercing_fin-stabilized...
- which bear no resemblance to a failed turbine disk. And have about twice the muzzle velocity, which makes huge difference in penetrating a modern armour systems. Ditto their far greater density, vs. nickel alloy.
OTOH, your "A couple thousand kg of armour could likely contain..." seems too charitable. High-bypass jet engines are big. Beyond that, I'm more optimistic about mitigating shocks and such.
A critical parameter here - https://en.wikipedia.org/wiki/A380#A380F The freight variant was to have a 6,400 mile range carrying 150t of payload. So we could squander 25t per engine on disk containment and shock mitigation, and still have a 50t payload. Or a 3-digit passenger headcount.
Bottom line, there is no real-world difference between your "nearly useless" and my "disastrously uneconomical". Neither one will be designed, let alone built.
For the A10, I'd say military priorities would always block full disk containment - because every pound used for that is a pound they don't have for more weapons or munitions or range or armour or fuel or runway length or electronics or whatever. And over most of the 360 which disk fragments could exit a warhog's engines, there's nothing critical which they could hit.
Now we can go to the running of the bulls with our respective napkin backs, and see who attracts the bull!
100t actually - 25t per engine, of which there are four. And the plane could still carry 50 tonnes of cargo/people.