One Sensor, No Second Opinion — JavaScript Bug Hunt

Modelled on the Boeing 737 MAX MCAS design: the system trimmed the aircraft nose-down based on a single angle-of-attack sensor, even though two were fitted.

  • Language: JavaScript
  • Layer: Backend
  • Difficulty: Medium
  • Concepts: Redundancy, Sensor Fusion
  • Modelled on: Boeing 737 MAX · MCAS
  • Visible tests: agreeing sensors below the threshold command no trim; a single stuck sensor disengages the system; agreeing sensors above the threshold do trim
  • Reward: 50 XP for a complete fix

Briefing

Modelled on the Boeing 737 MAX MCAS design: the system trimmed the aircraft nose-down based on a single angle-of-attack sensor, even though two were fitted. A single failed vane commanded repeated nose-down trim, and two crashes followed.

mcas.js reads one sensor and acts on it.

Fix computeTrim so it cross-checks both sensors and disengages when they disagree.

Bug report

BUG-MCAS · Priority: Critical (safety) · Reported by: flight controls

computeTrim(left, right, threshold, disagreeLimit) must:

  • disengage (return 0) when |left - right| exceeds disagreeLimit — the sensors disagree and neither can be trusted
  • otherwise use the AVERAGE of the two; trim nose-down by -1 when the average exceeds threshold, and 0 otherwise

Observed: only the left sensor is read. A stuck vane at 74.5 degrees commands continuous nose-down trim while the right sensor reads a healthy 5 degrees.

Logs

[mcas] trim=-1 aoaLeft=74.5 aoaRight=5.0
[mcas] trim command repeated 21 times

The code as shipped

src/flight/mcas.js (editable)

// Decides whether to command nose-down trim.
exports.computeTrim = function (left, right, threshold, disagreeLimit) {
  if (left > threshold) return -1;
  return 0;
};

Read-only context: src/flight/DESIGN.js.

Open the hunt to edit the files, run the visible tests and submit against the hidden ones. More JavaScript bug hunts.