Showing posts with label forensics. Show all posts
Showing posts with label forensics. Show all posts

Saturday, September 12, 2026

Starship/Superheavy Hot Staging

This is not insider knowledge.  It is based only upon what SpaceX has publicly released. 

There is some kind of geometrically-shaped shield plate that protects the front end of the Superheavy booster where the forward dome of the forward propellant tank is otherwise exposed.  This shield was shed after hot staging with Version 2,  but is now integral to the booster stage in Version 3.  It deflects the plumes of the Starship upper stage engines,  from striking and damaging or destroying that forward tank end,  during hot staging.

This shield structure is coupled with an interstage ring between the stages,  part of the Superheavy,  that is “porous”,  in the sense that there are openings through which the deflected engine plumes can exit laterally,  in a more-or-less radial direction,  during the transient hot-staging event.  The force to turn a plume gets exerted upon that shield.

The Superheavy booster had four grid fins spaced 90 degrees apart,  in Version 2.  Plume blast damage had been noted to the grid fin rotated into the way of plumes,  during the booster flip maneuver,  in Version 2.  In Version 3,  there are only 3 grid fins,  still spaced 90 degrees  apart,  but somewhat larger than the Version 2 grid fins.  That leaves a space where there is no grid fin,  which is clocked to align with the dorsal side of the upper stage Starship,  as shown in Figure 1. 

Figure 1 – Version 3 Starship/Superheavy Arrangement and Intended Booster Flip Direction

The design direction of the booster flip is a plane aligned with the dorsal-ventral plane of Starship,  and the front of the booster is supposed to flip in the direction where it moves “down” as shown in the figure.  Thus,  no grid fin is exposed to plume blast damage anymore,  in Version 3.  The side of the booster is less vulnerable to plume blast damage,  being cooled by the cryogenic propellant vapors inside.  

In Version 2,  the torque to flip the booster came from a strong gimbal angle of the 3 booster engines firing during the staging event to keep the booster propellants settled into the aft ends of their tanks,  where the suction-feeds to the engines are located.   This is still the case in Version 3,  with some control of the deflected plume force directions added,  by one or both of two means:   (1) the geometric shaping of the shield and of the “porosity” of the interstage ring,  can favor a plume deflection force component in the intended flip direction,  and (2)  the startup sequencing of the Starship engines can also produce a temporary plume deflection force component favoring the intended flip direction. 

There are two separate effects going on during the hot-staging event,  which must both be successful,  but which are also linked to each other in ways that make the successful “solution space” rather small!  These are indicated in Figure 2 below,  which depicts the conditions as the hot staging begins,  but before the flip starts.  (Drag was ignored.)

First,  the acceleration of the upper stage Starship has to be larger than the acceleration of the Superheavy booster (before the flip starts),  in order not to risk a collision. 

Second,  the axial acceleration of the Superheavy booster must be a positive number large enough to keep the propellants settled,  all during the staging event,  and all during the flip maneuver. 

That last is also complicated by the flip motion possibly flinging the propellants forward,  in only the forward tank,  if the flip is too fast!

The variables available for controlling this event are the thrust levels used in the booster and upper stage engines,  the shaping of the shield and interstage ring porosity geometries,  and the sequence of ignition of the upper stage engines. 

To simplify this first look,  the author chose only a full thrust setting in the 3 booster engines,  and lighting all 6 upper stage engines at once,   but a some reduced thrust.  Guesses were made for plume deflection force component angles and booster engine gimbal angles.   All of this is indicated in the figure.

The author has no actual data for the engine thrust levels at the staging altitude,  or for the actual masses of either stage at the time of staging.  He made reasonable guesses for these,  as well,  as indicated in the figure.  So the results are inherently approximate!

Figure 2 – Finding A Thrust Setting For Starship That Keeps Superheavy Accelerating

It would not be possible to get full thrust in an engine at the moment of ignition!  It is more practical to ignite at a partial-thrust setting propellant flow rate,  stabilize after a split second,  and then throttle up quickly a split second after that,  as desired. 

The author chose to look at full and half thrust initially,  and then added a 40% thrust setting,  after getting negative booster acceleration at full upper stage thrust,  and zero booster acceleration at half thrust.  The 0.1 gee booster axial at 40% Starship thrust is in the rough ballpark of other ullage thrust applications.  The 40% thrust setting is within the capability of the Raptor-3 engine design,  so this point really is a feasible thing to do!

As the figure indicates,  the Starship upper stage has the acceleration to leave the booster behind,  at 40% thrust on 6 engines.  It cannot throttle up until the flip has proceeded enough to direct the front end of Superheavy out of the way of the Starship engine plumes.

Also indicated in the figure,  the Superheavy axial acceleration is zero at half Starship thrust,  and only 0.10 gees at 40% Starship thrust.  Starship cannot throttle down much more than that,  and still leave the vicinity at about 0.4 gees!  Which is exactly why this author says the solution space here is quite narrow!  Screw this up,  and the propellants will unsettle,  the booster engines will suck vapor,  and their turbopumps will explode!

The next step was to look at starting the booster flip.  This is illustrated in Figure 3,  which presumes the 40% thrust solution just obtained above.  Two cases were examined:  a booster engine gimbal angle of 10 degrees,  and a comparable lateral deflection force generated by shield geometry and/or interstage porosity distribution.  The booster mass moment of inertia was approximated by the solid bar formula for rotation about its center of gravity (cg).  That cg was simply presumed to be halfway along the booster.  

Figure 3 – Starting the Booster Flip Maneuver During Hot Staging

The results for time-to-clear shown lower right of figure are amazingly close to what is in the publicly-released videos of these flight tests (about a second or two to clear)!  Considering how crude all the assumed data is,  that outcome is quite remarkable!  Letting deflected upper stage plumes help the gimballed booster engines to start the flip maneuver is definitely beneficial,  but it is not an overwhelming effect.  That would seem to be the lesson to be learned here.

That brings up the “spin gravity” effect of the flipping booster upon the settling of propellants in its forward tanks by engine-induced acceleration.  As depicted in Figure 4,  this depends upon which side of the booster cg falls the free surface in the forward tank.  One must take into account relative tank sizes,  and how full those tanks are.  A very crude estimate is shown in the figure,  indicating that spin will help settle the propellants.


Figure 4 – Evaluating Whether Spin of Flip Affects Propellant Settling

Note that had the LOX tank been forward in the design instead of aft,  this outcome would not be true!

The magnitude of the “spin gravity” effect depends upon the rotation rate ω at the time the booster clears the plumes,  which is crudely angular acceleration times the clearance time,  for the two cases shown in Figure 3 above. Those would be 0.139 rad/s for the gimbal only case,  and 0.186 rad/s for both effects together. 

The acceleration in gees at the free surface would be L ω2,  where L is the distance between the cg and the free surface.  As measured from the left as shown in Figure 4,  as long as the free surface is left of the cg,  the spin gravity gees adds to the axial thrust gees.  If the free surface falls to right of the cg as shown in the figure,  then the spin gees would subtract from the axial gees!  There is a coupling between stage layout and “spin gravity” risks.

For the dimensions indicated in Figure 4,  the LCH4 free surface is 10 m left of the cg. So,  if only gimballing,  one would add about 0.020 gees to the axial 0.1 gees.  If faster for both effects together,  one would add about 0.035 gees.  The additions would be a bit over 3 times larger for the LOX tank,  as the L to its free surface is larger at something like 33.7 m.

Much more accurate dimensions masses,  and propellant-remaining percentages would be needed to get reliable results!  But these results obtained here do seem to crudely indicate what is going on during Starship/Superheavy hot staging.

-----   

search code DDMMYYYY format      12092026

search keywords:  forensics, launch, space program

-----   



Tuesday, June 9, 2026

Close Call at Newark

On May 3, 2026,  United Airlines Flight UA169,  a Boeing 767,  very nearly hit the I-95 roadway while completing its approach to runway 29 at the Newark airport.  It did hit a light pole,  which subsequently hit a truck on the bridge,  and its landing gear may,  or may not,  have brushed against that truck.  The airliner suffered enough damage to be grounded for significant repairs.  The truck was nearly destroyed,  and its driver was injured.

Only about 6 or 7 feet lower,  and the airliner would have struck the concrete rail!  Hitting a solid structure like that is a death sentence for the aircraft,  and likely everyone aboard it!  The NTSB is investigating this,  but even this early on,  it is clear from the images made public so far,  that this airliner was below its approach glide path,  by too far.  There is no judgement,  as of yet,   as to why that happened.

I see two serious questions here:  (1) Why was the airliner too low on approach?  (2) Why is such a tall concrete obstruction as I-95,  so close to the end of that runway?  The first one is a matter for the NTSB and FAA to sort out.  The second one is a zoning-related matter for the FAA to sort out with local leaders in Newark.  It may require closing runway 29-11.

With an approach speed of about 160 mph,  by the time this photo was taken,  the airliner was already below the rail,  while still very close to the highway,  which is somewhat elevated,  like all interstates. 

You can see the close proximity of the I-95 elevated highway to the end of runway 29-11 in this image.  Such a proximity should never have been allowed to happen in the first place,  in this observer’s opinion.  

-----  

Search code DDMMYYYY format:     09062026

Search keywords:  current events, forensics

-----   



Wednesday, December 1, 2021

The Seal Failure in the SRB that Doomed Challenger

Update 7-15-2024:  This article suddenly saw a brief spike of enormous readership in July of 2024!  It became the all-time most-viewed-ever article here on this site,  in only a few days!  I saw no comments during that spike of readership,  so I do not know who or why.  But I hope those readers found it useful.  THAT is why I post these things!

----------   

Update 4-8-2024:  Should any readers want to learn how to do what I do (estimating performance of launch rockets or other space vehicles),   be aware that I have created a series of short courses in how to go about these analyses,  complete with effective tools for actually carrying it out.  These course materials are available for free from a drop box that can be accessed from the Mars Society’s “New Mars” forums,  located at http://newmars.com/forums/,  in the “Acheron labs” section,  “interplanetary transportation” topic,  and conversation thread titled “orbital mechanics class traditional”.  You may have scroll down past all the “sticky notes”. 

The first posting in that thread has a list of the classes available,  and these go far beyond just the two-body elementary orbital mechanics of ellipses.  There are the empirical corrections for losses to be covered,  approaches to use for estimating entry descent and landing on bodies with atmospheres,  and spreadsheet-based tools for estimating the performance of rocket engines and rocket vehicles.  The same thread has links to all the materials in the drop box. 

The New Mars forums would also welcome your participation.  Send an email to newmarsmember@gmail.com to find out how to join up.

A lot of the same information from those short courses is available scattered among the postings here.  There is a sort of “technical catalog” article that I try to main current.  It is titled “Lists of Some Articles by Topic Area”,  posted 21 October 2021.  There are categories for ramjet and closely-related,  aerothermodynamics and heat transfer,  rocket ballistics and rocket vehicle performance articles (of specific interest here),  asteroid defense articles,  space suits and atmospheres articles,  radiation hazard articles,  pulsejet articles,  articles about ethanol and ethanol blends in vehicles,  automotive care articles,  articles related to cactus eradication,  and articles related to towed decoys.  All of these are things that I really did. 

To access quickly any article on this site,  use the blog archive tool on the left.  All you need is the posting date and the title.  Click on the year,  then click on the month,  then click on the title if need be (such as if multiple articles were posted that month).  Visit the catalog article and just jot down those you want to go see.

Within any article,  you can see the figures enlarged,  by the expedient of just clicking on a figure.  You can scroll through all the figures at greatest resolution in an article that way,  although the figure numbers and titles are lacking.  There is an “X-out” top right that takes you right back to the article itself. 

----------     

Update 10-29-2023:  recently,  I have received "comments" on this article that are nothing but ad solicitations from the makers of O-ring products,  usually from overseas.  They picked this article precisely because it mentions O-rings,  which tells me this was the result of a keyword search of published articles on the internet.  My blog site is not a monetized,  commercial site.  I do not accept any advertising from anyone.  When I find them,  I delete them.

-------

I have real difficulty with the fact that,  even after all these years,  it is still necessary to explain to people what really destroyed Space Shuttle Challenger and killed her crew,  back in January 1986.  It was really two very seriously-bad upper management decisions at NASA,  one long before the launch: 

(1) to insist on poorly-designing the O-ring seal joints with 3 interacting serious errors,  and

(2) to fly soaked-out colder than had ever been tested,  when everybody’s engineers did not want to.

Background

First,  you have to understand what really happens in federal government contracting.  There is only one customer,  and he thinks he is always right about every decision that he makes.  If you do not do it exactly the way he wants,  no matter how wrong he might be,  then you lose the contract and you don’t get paid.  And,  the government is quite often wrong about how best to do things!  That’s not to say the contractors are always right,  but they are wrong a lot less often than the government.

You also have to understand that NASA never did know,  and still does not know,  the art of building reliable solid propellant rockets.  Essentially,  no one at NASA ever did that kind of work.  They buy these things from contractors who (by definition) know much more of the science,  and especially the art,  than anyone at NASA knows.  The “science” is that knowledge which was written down.  The “art” is the knowledge that was not written down,  usually because no one wanted to pay for the writing.

I can tell you from experience as an insider within the business,  that “rocket science” isn’t really “science”!  It is only about 40% science,  about 50% art,  and about 10% blind dumb luck.  And that’s in production work!  In new product development work,  the art and luck percentages are even higher. 

Further,  this same sentiment applies to pretty much any type of engineering effort,  not just rocket work.  That explains a lot,  about a lot of things,  doesn’t it?

Poorly-Designed O-Ring Seal Joints

What I show in Figure 1 is how such joints should be designed and built.  This is the design that most solid rocket motors use,  very successfully,  whether large or small.  In most rocket motors,  you need only join the aft and forward closures to the case cylinder.  Only in some of the really large motors,  the case cylinder itself is divided into segments that must be joined,  usually to limit the size of the case-bonded propellant masses that must be cast and cured within them.

The sketch in the figure is what mechanical engineers call a “radial static seal”.  It is “radial” because the O-ring lies between an inner and an outer surface,  that must include a gap of tightly-controlled size between the two parts,  for assembly.  One part stabs into/inside the other,  in order to join them,  in this case by a row of pins.  It is “static”,  because the parts,  once joined,  do not move anymore.  There are strict but well-published guidelines and procedures for sizing the O-ring groove dimensions,  the gap for assembly,  and the size of the O-ring,  as well as its material composition and its hardness.  These guidelines and procedures are used precisely because they work so very well.   Examples:  Refs. 1 and 2.

Something also shown in the figure is peculiar to solid rocket motors,  especially those that are segmented-case designs.  There is a joint in the insulation (and thus also the propellant) that leads to the sealing surface gap,  that in turn leads directly to the O-ring in its groove.  You DO NOT obstruct this path with sealants,  putties,  greases,  or anything else!  But there does need to be a right-angle bend,  to stop radiant heat transfer from the flame in the motor from heating the O-ring directly.

The air in this path is what gets suddenly compressed upon motor pressurization,  and which in turn forces the O-ring to the far side of its groove,  where it gets squeezed against that surface to seal.  This is called “seating the O-ring”,  and until it is properly seated,  it CANNOT seal,  and so it briefly leaks!

Figure 1 – A Properly Designed O-Ring Seal Joint

It is the air in the path that gets compressed against the O-ring,  with hot booster gases and hot solids filling most of the path volume that the air formerly occupied.  But the air cools by convection to the steel much more effectively and faster than to the O-ring itself.  THAT is how the O-ring is not damaged by the hot air,  or the hot gases!  The hot solids are stopped by the right-angle bend.  This is a rapid transient on a time scale equal to,  or shorter than,  the motor pressurization event. 

What you DO NOT want is contact of the hot gases (and especially the hot solids) upon the O-ring!  The “hot sandblast” effect of that outcome would cut through the O-ring almost instantaneously.

Note that these two design requirements of (1) one O-ring and (2) an unobstructed pressurization path,  will interact very strongly with how one verifies proper assembly of the motor!  You must do a pressure leak check of the motor to verify sealing,  but you must do it by pressurizing the entire motor!  However,  you NEED NOT pressurize the motor to its full operating pressure to do this verification! 

You only need an atmosphere or so of pressure difference to seat any O-ring and then verify its sealing.  If it holds at that low pressure,  and you followed the design guidelines correctly,  it will hold at full motor operating pressure!  THAT is what you verify when you do motor case hydroburst testing,  long before you ever cast propellant to make a live motor!  That’s the way the real solid rocket motor manufacturers prefer to do it.  And it works to very high reliability levels,  as indicated in the figure.

However,  that is NOT what NASA insisted upon doing!  In the mistaken belief that a second back-up O-ring increases sealing reliability,  they insisted upon the two O-ring design indicated in Figure 2.  Thiokol complied,  lest they lose the contract.  In the mistaken belief that they had to pressure leak check at full motor operating pressure,  NASA did not want to risk fully pressurizing a live loaded motor (and rightly so).  And so NASA insisted on a way to apply air pressure at full motor operating pressure,  between each pair of O-rings at every joint,  instead of any motor pressurization.   This is shown in the figure.

What this does is drive the downstream (backup) O-ring to the correct side of the groove,  thus seating it for motor operation.  But,  it also drives the upstream (primary) O-ring to the wrong side of its groove,  from which motor pressurization upon ignition must unseat it,  drive it across its groove,  and re-seat it on the correct side!  Until and unless it re-seats on that correct side,  the upstream (primary) seal ALWAYS leaks!  Period!  There is NO WAY AROUND that outcome!  And THAT lets hot gases and solids reach the primary O-ring,  simply because the re-seating process takes a longer time than pressurization!

Figure 2 – The Improperly-Designed 2 O-ring Joint That Flew,  Up Through Challenger

NASA made a third mistake:  in the mistaken belief that it would prevent hot gases and hot solids from reaching the O-ring,  they insisted on obstructing the pressurization path by filling the insulation joint with “heat protective” putty (zinc chromate putty actually).  This is also shown in the figure.

This last mistake makes a bad risk even far worse,  because high pressure gases always (ALWAYS!!!) “wormhole-through” a not-solid material (like putty or grease) at a single point!  THIS effect is also shown in the figure.  That re-distributes the “push” of the gas from a broad front all around the O-ring,  to a single point upon the O-ring,  as indicated in the figure.  The delay unseating the ring,  pushing it to the other side of the groove,  and reseating it,  almost guarantees that the compressed air leaks past it,  so that booster hot gases and solids can reach the O-ring.  And those will cut a hole right through it.

“Half-moon slices” right through the primary upstream O-ring were seen,  upon SRB motor disassembly,  in a rather significant percentage of the SRB’s recovered and refurbished.  That verifies what I just said about the upstream O-ring being cut!  There is no surprise there,  once you understand the process!

The difference between this point load problem,  and what NASA analyzed in its structural calculations for the O-ring seal is quite stark!  The structural analysts were assuming pressurization on a broad front.  They did not model the point load effect of the hot gases and solids wormholing-through the putty obstructing the pressurization path.  Quite simply,  what was built was NOT what was analyzed!

Unnecessary Risk to Fly Too Cold

If the motor is sufficiently cold-soaked,  the primary upstream O-ring loses its flexibility and resilience (as do all of them).  Pushing the entire embrittled O-ring across its groove all at once is risky enough,  but if you concentrate the “push” at one single location by the wormhole effect,  you essentially guarantee snapping the O-ring apart at that point!  This cold brittleness effect was amply demonstrated by Dr. Feynman at the Rogers Commission hearings (assisted by Gen. Kutyna),  when he stirred his sample of the O-ring material in his glass of ice water,  and then demonstrated its non-resilience.

Any failure of the primary upstream O-ring,  whether by hot sandblast cutting,  or by cold brittle fracture from the point jet force load,  then puts a single-point hot sandblast jet impacting onto the downstream O-ring,  simply because it is nearby!  Thus,  a sort of “cascade failure” is a very high risk indeed!

The post-Challenger “fix” was a third O-ring in every joint.  This just set up the cascade failure as a longer chain,  as indicated in Figure 3.  The only reason the Challenger disaster did not repeat is that they never flew that cold again.  But the 1/51 failure rate demonstrated by loss of Challenger speaks for itself!

Figure 3 – The Cascade Failure Risk Was Compounded By the Redesigned Joint

Fatal Consequences We All Saw

The photography obtained during the launch and loss of Challenger confirms everything claimed here.  The seal failed upon motor ignition and pressurization,  as shown quite clearly in Figure 4.  The dark grey plume is carbon soot-bearing hot gases spewing through the two failed O-rings at the aft segment joint. 

Figure 4 – Seal Leak Upon Ignition Seen In Photography

This leak miraculously “cured” itself by plugging-up with aluminum oxide-carbon slag from the metallized propellant.  This slag-plugging just happened to hold pressure like that,  until the Challenger encountered a wind shear while at “max-Q”,  where it was also most highly stressed by aerodynamic forces.  The slag plug failed,  letting the hot motor gases and solids rush through the hole again.  This is shown quite clearly as the anomalous bright-but-small extra plume in Figure 5 below.

This jet of leaking hot gases and solids finally got so big that it cut through one of the aft struts holding the SRB to the center tank.  There is always hydrogen leaking from the center tank’s hydrogen tank,  and in this case the leaked plume probably burned a hole in that hydrogen tank.  With the strut cut,  the bottom of the SRB moved outboard.  That pushed the nose of the SRB inboard,  such that the nose of the SRB poked a hole in the side of the center tank’s oxygen tank. 

Suddenly dumping oxygen into a base-burning hydrogen-air fire caused an explosion in the wake behind the center tank that both overheated and structurally overloaded it.  The tank collapsed,  letting both SRB’s and the orbiter fly free.   The released propellants burned explosively as this happened.  All this happened in an instant,  so it looks like just the one sudden explosion.

Figure 5 – Leakage Resumed After Being Shaken By Wind Shear at Max Q

The released SRB’s continued to “fly” out-of-control under their own thrusts,  as we all saw.  This is shown in Figure 6.  The orbiter’s engines were pointed through a center of gravity that suddenly no longer existed,  so they forced the orbiter to pitch-up violently,  before starving for lack of propellant from the suddenly-missing center tank.  The pitched-up orbiter went broadside to the supersonic wind,  which tore it to pieces.  This is how those pieces,  that we all saw fall into the sea,  came to be.  

Figure 6 – The SRB Did Not Explode,  But It Punched a Hole In the Center Tank

Final Remarks

The two O-ring joint was a NASA-mandated design mistake,  compounded by mandating putty obstructing the O-ring pressurization paths.  The “customer is always right” in government contracting,  except that he was lethally and fatally wrong about this one!  See also Ref. 3.

The decision to fly cold-soaked colder than the SRB’s had ever been tested,  was also a NASA management decision.  Both NASA and Thiokol engineers objected,  but were over-ruled.  Thiokol upper management also over-ruled their own engineers,  and told NASA to go ahead and launch.  Thus emboldened by Thiokol management,  NASA launched the thing,  thus killing its crew.

The stand-down to “correct” this problem was nearly 2 years long and horribly expensive.  Which just goes to prove what I like to say to anyone who will listen:  “there is nothing as expensive as a dead crew,  especially one dead from a bad management decision”. 

The only problem with that return-to-flight effort is that they did not correct the real problems upon return-to-flight,  they actually made them worse with a 3-O-ring joint,  and by keeping the putty obstructions.  The ONLY thing they did “right” was never to fly that cold again!  Which is very likely the ONLY reason that the Challenger disaster did not repeat itself before the Shuttle got retired,  since there were more than 51 more flights after the Challenger disaster!

By the way,  the crew did not die in the tank explosion and subsequent ripping-apart of the orbiter by air loads.  The telemetry showed no high-gee accelerations at all!  The crew was still alive in the orbiter cabin until it finally hit the sea,  which is about a 200-gee stop,  since it hit dead broadside.  See Figure 7.

Figure 7 – The Crew Was Still Alive In This Cabin Section (Arrow) That Is Falling Back

I say what I said about the crew because the flight deck back-seaters leaned forward and flipped on the breathing-air packs for the front-seater pilots.  They would not have done that unless they knew the cabin had depressurized,  and that would have been significantly AFTER the explosion and ripping-apart of the orbiter.  They were tumbling clear of the explosion cloud by that time,  as illustrated in the figure. 

Those two flight deck pilots had breathed-up all the oxygen in their breathing packs by the time they hit the sea,  something confirmed by the empty breathing packs that were recovered.  Which means they were alive when they hit the sea!  By extension,  so were the back-seaters,  plus the three down on the mid-deck.

They did not have pressure suits,  parachutes,  breathing bottles,  and a hatch they could blow open (basic bail-out gear).  More importantly,  there was no way to take the spin off the tumbling cabin.  Spinning like that,  there was no way to reach and exit the hatch,  even if they had the other basic bailout gear!  But a small drogue parachute from the nose of the cabin section would have taken off the spin!  That plus the basic bail-out gear just listed could have saved that crew!  It took almost 5 minutes to hit the sea.  They had the time to bail out.

I submitted that means for bail-out to NASA,  but I was ignored.  Coming from an outsider,  my idea was “not invented here”,  as far as NASA was concerned.  Yet,  something rather like it might even have worked for Columbia some years later:  the 3 mid-deck occupants were still alive inside a tumbling cabin section as it approached impact near Tyler,  Texas,  well after the breakup during re-entry.   Time was short for a bail-out,  but without the de-spin drogue,  they could not reach the hatch at all. 

References

#1. Parker O-ring Handbook ORD 5700,  copyright 2021,  original release 1957,  Parker O-Ring and Engineered Seals Division,  Lexington,  KY, available from parkerorings.com 

#2. Seal Design Guide,  Apple Rubber Products,  Lancaster NY,  available from AppleRubber.com

#3. Wikipedia article “Rogers Commission Report”,  in this case accessed 11-26-2021

Final Notes

There are different design rules for static radial and static face seals,  and different rules yet for dynamic radial seals (as on a piston moving inside a cylinder,  like a syringe or a hydraulic cylinder).  The Shuttle SRB joints fall into the static radial classification. 

The appropriate set of rules specifies O-ring sizes and hardness,  groove dimensions,  and when to use back-up rings.  You just follow the design rules,  and make sure that only compressed air reaches the O-ring (and on a broad front),  upon solid propellant motor ignition.  

You accomplish that broad-front pressurization with the 90-degree bend geometry to stop the hot solids and radiant heat transfer,  and by NEVER obstructing the O-ring pressurization path with anything!  Even too close a fit between the hard parts,  can cause problems with the transient pressurizing flow.

You verify your seal design,  your case structural design,  and your leak check procedure,  during case hydroburst testing,  long before you ever cast a live motor!  You NEVER delete the hydroburst testing step in your development effort.  Never!  Not for any reason at all! 

Then you test live motors at every environmental extreme condition in which you think you might possibly operate.  If any redesigns (of anything) are needed,  you go back and verify them in all the tests,  from hydroburst all the way forward.  No motor goes to production,  until its exact design configuration has been verified in every test at every test condition!

Once your design has passed all those tests,  you stick with your verified leak check procedure as if it were a religious mandate!  You add rigorous quality control (of the “total quality management” type),  for production.  That includes X-raying every single item,  to verify that there are no casting voids in the propellant,  no unbonds between propellant and case liner,  and no other propellant grain cracks or other problems.  And then you NEVER operate a motor outside the conditions for which it was tested! 

THAT is the way to achieve no-more-than-1-in-a-million failure rates,  with solid propellant rocket motors!

The “bean counters” and “management professionals” will absolutely hate that prescription as “too expensive”,  but killing a crew with a bad design just costs a whole lot more,  than the cost of following that prescription.  We’ve already seen that with Apollo-1,  Challenger,  and Columbia.

Simple as that. 

And just as hard to sell to the “bean counters” and “management professionals”,  as you might fear.  


Thursday, December 10, 2020

Spacex Test Flight Results in Explosion

 So,  Spacex’s SN-8 “Starship” prototype exploded at landing.  The news reports seem to be focusing on that explosion,  which was not at all unexpected,  even by Spacex,  based on their remarks before this test.  I suggest that we look instead at what they accomplished on this test,  before we render any judgement.

The flight was supposed to demonstrate controlled 3 engine-or-fewer flight to an altitude.  Few outfits have ever actually done that.  Intentionally or not,  Spacex’s SN-8 did that rather well,  shutting down to 2,  then 1,  engines on the way up!  See Figure 1 for the launch,  and Figure 2 for the ascent.  All figures are at the end of this article. 

Note that all three engines are required for launch,  and only a fraction of the intended full propellant load (some 1200 metric tons) can be loaded.  Each sea level Raptor engine is rated for a max thrust force of 2 MN,  meaning total liftoff thrust is 6 MN.  Assuming an unloaded dry-tanks mass is 120 metric tons,  there is zero payload,  and we have some 412 tons of propellant,  the total liftoff mass is some 532 metric tons,  for a weight force of about 5.2 MN.  That puts the liftoff thrust/weight at 1.15,  which is about the minimum for decent ascent kinematics.  At only 492 tons of propellant,  the vehicle just sits on the launch pad,  unable to rise at all,  because weight is greater than thrust.

If all 6 installed Raptors in the final flight design were sea level Raptors,  so that 6 engines could be run for liftoff,  then the max liftoff thrust would be 12 MN.    120 tons inert plus 100 tons payload plus 1200 tons propellant is 1420 metric tons liftoff mass,  for a weight of 13.9 MN.  It cannot liftoff because weight exceeds thrust.  At zero payload and full propellant,  the weight is still 12.9 MN,  exceeding thrust.  If you start off-loading propellant in order to take off,  then you won't have enough propellant to reach orbit.  Some commentators have referred to the possible use of Starship as a single stage to orbit vehicle,  but this is simply infeasible.  

SN-8 did not have all the propellant tankage installed,  nor did it have anything to represent the cargo hold or manned spaces.  The fuel header tank was located in the nose of the empty shell to make the weight and balance work out.  But SN-8 was equipped with the right external shape and wings and canards.  That was a large part of the point of this flight test. 

This SN-8 test flight was supposed to demonstrate aerodynamic control into a stable "belly-flop" descent with the tail wings and the canard fins.  It did exactly that!  No other outfit has ever done that!  None at all!  Did you notice the variable rake angle of the canards and wings during the descent?  That reflects active control,  real-time.  It was very successful. See Figure 3.

The flight was supposed to demonstrate engine relight and thrust vector control to achieve tail-first vertical attitude for landing.  It looks to me like they did it,  or at least mostly.  No other outfit has ever done that,  either!  I was a tad concerned by the off-vertical attitude angle in the terminal descent toward touchdown.  But all-in-all,  it looked like this goal was achieved.  See Figure 4. 

The flight was supposed to demonstrate touchdown at essentially zero speed in a vertical attitude,  so that the landing legs would only be stressed within limits,  and that stress would be fairly evenly distributed among the legs.  This is where the test failed:  SN-8 was still moving on the order of 80 mph downward at impact,  and it was around 5-10 degrees off vertical.

Touchdown weight should have been under 130-140 metric tons,  so that 1 engine could balance vehicle weight at 60-65% thrust,  and two should handle it at 30-33% thrust,  they being advertised as throttleable between 20 and 100% of rated thrust.  Double those figures for a net one-gee deceleration to touchdown,  triple them for net two gees.  But,  they didn't get it slowed! 

There is the Musk tweet saying the header tank pressure was low upon touchdown.  A loss of propellant tank pressure might explain low engine thrust capability,  in turn failing to control descent speed.  There is also the odd green flame color and smoky plume right before touchdown.  There is even perhaps a hint of excess plume smoke during the thrust vector out of the belly-flop.  Clearly something went wrong.

I'm not at all sure where the off-angle attitude at touchdown derives from.  But that off-angle attitude literally crumples the landing leg that strikes first.  That is the risk,  and it is very serious!

All-in-all,  I think the attitude angle error would have toppled and destroyed this particular test vehicle,  regardless of whether the velocity error was zero or not.  But the big nonzero velocity error simply guaranteed an explosion.

Of the two,  the attitude may actually be the more serious problem to resolve.  Although,  the early Falcon booster recovery failures were remarkable more for velocity error than attitude angle error.  Either way,  Spacex has a lot of work to do to resolve this.

Net score:  3 of 4 overall goals demonstrated successfully in the very first test of this type!  That is a 75% success!  I'd say that's really,  really good!  So,  I agree with Elon Musk congratulating his team,  despite the explosion on landing.

Remember,  this is very early in a test effort that is going to require lots of flights,  and which will likely produce some more spectacular explosions. 

Such is the nature of rocket vehicle test flight work.  Take it from me,  I know.  Long ago,  I used to do this same sort of thing.


Figure 1 – Launch of SN-8


Figure 2 – Ascent


Figure 3 – “Belly-Flop”


Figure 4 – Vectoring to Tail-First


Figure 5 – Odd Flame and Plume Just Prior to Touchdown


Figure 6 – Explosion at Touchdown



Tuesday, September 1, 2020

On the Beirut Explosion

The devastation in Beirut was caused by an ammonium nitrate explosion,  similar to that which devastated West,  but very much larger.  This is a material that is both dangerous,  and very necessary.  So,  it is important to understand it well.

 Ammonium nitrate as small particles is something you have all seen as 100-0-0 fertilizer.  The other fertilizers will not explode,  but this one can.  Surprisingly,  it is hard to get the explosion,  except under a physical confining pressure,  although it is shock-sensitive.  Otherwise it decomposes "peacefully" during a fire event,  just making the fire much hotter and more vigorous,  because it is an oxidizer.

There was enough ammonium nitrate in the warehouse in West to have utterly destroyed the entire city.  Most of it burned "peacefully" away during the fire,  until the building collapsed onto the decomposing fertilizer.  The weight of the building debris provided the confinement necessary for the explosion to happen.  And it did,  almost instantaneously.

There were only about 20 to 30 tons of un-decomposed fertilizer that exploded in West,  out of the possible 200-something tons that the site was permitted for.  It could have been a lot worse!  See Figure 1 for an aerial view of the site taken shortly after the fires were put out. 


Figure 1 – Aerial View of West Explosion Site,  Annotated for Scale

At the old Rocketdyne plant in McGregor,  waste ammonium nitrate from propellant-making, was disposed-of by burning.  It was bulldozed out on the burn pad not to exceed 4 feet in depth,  and topped with a thin layer of scrap wood as fuel for the fire.  No explosions ever happened,  because the weight of the wood,  and the shallow depth of ammonium nitrate,  prevented the bottom layers of the fertilizer from ever feeling enough confining weight to explode.

The fire codes require that bagged ammonium nitrate fertilizer not be stacked any higher than 6 feet.  That is to prevent the bottom of the pile from feeling enough confinement to explode,  in a fire event. According to the fire codes,  you are supposed to fire-sprinkle facilities like that,  to prevent the building from collapsing as it burns,  by stopping the fire in its tracks long enough for the fire department to put it out safely.

The building in West was not fire-sprinkled,  with the catastrophic results that we all saw.  Those fire codes have to be mandated by local or state authorities before they can be enforced.  That was (and still is) just not the case in Texas,  McLennan county,  or many Texas cities,  despite the recommendations to do so by the State Fire Marshal.  Remember that when you vote!

In Beirut,  back in 2013,  a Russian ship entered the harbor,  and its cargo of ammonium nitrate was confiscated and stored in a harbor warehouse.  The tonnages carried by ships are large,  and this particular cargo of ammonium nitrate is widely said to have been 2750 tons.  I don't know whether that is US tons or metric tons,  but it really doesn't matter;  the two are only about 10% different.  The point here is "thousands of tons".

Nobody has said anything yet about how those tons of ammonium nitrate were stored in that Beirut harbor warehouse.  It was just "forgotten-to-death" there,  since 2013. But the smart money is on the notion that it was stacked up many times higher than the 6 feet maximum specified by our US fire codes.  What that means is that an awful lot of those thousands of tons,  probably much more than half of them,  felt the weight of the overlying material as a confining pressure sufficient to risk explosion!

Then there was a fire and explosion in an adjacent warehouse,  setting off some fireworks.  We have all seen the video footage.  That fire spread to the building where the ammonium nitrate was piled up,  starting its decomposition,  seen as the column of reddish smoke (see Figure 2).


Figure 2 – Reddish Decomposition Plume Gets Overtaken By Explosion Shock

Once that reaction reached the lower levels of the pile,  where the confining pressure was high,  the whole bottom of the thousands-of-tons-pile exploded all at once,  with a white condensation cloud demarking where the shock wave has passed,  with the blast effects we have seen on TV.  See Figure 3 for an aerial view of the devastation in Beirut.  Bear in mind the devastated area extends more than a mile from the crater.

 

Figure 3 – Aerial View of Beirut Before and After

1000-2000 tons of ammonium nitrate exploding all at once has the blast effect of a fractional-kiloton nuclear weapon.  This scale of destruction we have seen before,  in Texas City 1947,  when two 10,000 ton shiploads detonated only hours apart.  The destruction was comparable to about-a-5-kiloton nuclear weapon.  See Figure 4.  Here the destruction radius is multiple miles.


Figure 4 – Texas City 1947

Now this stuff is a very necessary material.  It is the feedstock for the other fertilizer grades,  among other things.  It also makes a very safe-to-handle blasting agent for quarries and mines.  It just has two vulnerabilities in agricultural warehouse facilities that we have failed to address:  avoid the confinement,  and stop the fire to stop the building collapse.  Such buildings really do need to be fire-sprinkled,  and periodically inspected for compliance. 

This isn't about politics,  it's just plain old common sense.  So get on with it,  state politicians!  And if they won’t (and they haven’t so far),  then you need to use your vote to correct their misdeeds.


Friday, May 4, 2018

Some Thoughts on the Anniversary of the West Explosion

I wrote this article on 23 April,  2018.  A slightly-edited form of it appeared in the Waco "Tribune-Herald" on 26 April,  2018.  By way of disclosure,  I am on the board of contributors for that newspaper.  And a few years ago,  I worked in fire protection engineering,  which gave me much more than just a nodding familiarity with the various fire codes.

For those from out-of-state,  the "Trib" is the Waco,  Texas,  USA,  newspaper.  The agricultural plant in nearby West,  Texas,  caught fire and suffered an ammonium nitrate fertilizer explosion,  some 5 years ago.  Recovery from that devastation is now complete. And devastation it was.

---------------------------------------------------------


The 5 year anniversary of the West fertilizer plant explosion recently passed,  with excellent coverage on TV and in the newspaper regarding recovery since.  That recovery is now said to be complete,  and is a testimony to the people of West,  and to all who helped them.

Many things in life are a sort of “double-edged sword” that can either help you or hurt you.  Ammonium nitrate is one of those things.  It makes a wonderful fertilizer as a source of fixed nitrogen.  It is also a mass-detonable explosive in its pure form,  which is type 100-0-0 fertilizer,  something well-known from a long history of such explosions.

When combined with other fertilizer compounds as something other than 100-0-0 fertilizer,  the explosive risk goes away.  But there is still an enhanced fire danger,  as the ammonium nitrate decomposes when exposed to fire,  releasing oxygen into the fire.  That makes the fire very intense.

Now,  neat 100-0-0 ammonium nitrate fertilizer is hard to detonate,  requiring either the same sort of detonator as dynamite (just larger),  or confinement when decomposing in a fire.  Without confinement,  decomposing the material in a deliberate fire is actually the best way to dispose of mass quantities. 

The confinement comes from anything heavy resting on top of the fertilizer (including large amounts of the fertilizer itself,  as at Texas City),  or containing the fertilizer within some physical structure as it decomposes from the heat of a fire.  The fertilizer itself doesn’t burn,  it decomposes. It also melts and runs as a liquid down into any holes or spaces,  even floor drains.

In a building fire such as happened at the West fertilizer plant,  the confinement is generated by either (1) the burning building collapses down upon the decomposing fertilizer,  or (2) the melted fertilizer flows down a floor drain into a pipe.  Either will start the tremendous explosion. 

At the West fertilizer plant,  it was the building collapse that prompted the explosion.  This event actually happened after the majority of the stored fertilizer had already decomposed in the building fire.  Had it happened sooner,  much more of (perhaps all) the town of West would have been obliterated,  and the death toll would have been much,  much higher.

The way to positively prevent ammonium nitrate explosions is to positively prevent the building fire from collapsing the building in the first place.  Wooden structures,  feed,  and grain,  plus other building interior furnishings,  are all flammable:  fuel for the fire. 

In a new facility,  you simply eliminate all those materials from where ammonium nitrate is processed and stored.  But because the fertilizer is stored in paper bags,  there is still fuel next to the fertilizer that enhances the fire. 

So,  you fire-sprinkle the building according to the specific standards for fertilizer storage (and these already exist,  courtesy of the National Fire Protection Association).  There is no other way to be certain.

In an existing facility,  there are likely to be wooden floors,  wooden building structure,  wooden storage racks or pallets,  and perhaps even wooden handling and process equipment.  These are all flammable,  fuel for the fire.  That makes the fire-sprinkling of the building even more crucial,  plus it is prudent to seriously over-design the sprinkler system.

Most of these facilities now lie within the city limits of small towns all over Texas.  Many of them were outside the city limits when originally built,  putting them under county (or state) jurisdiction.  If there is no authorization for a county to impose the fire code standards upon these facilities,  then it is the Legislature’s job to authorize them to do so,  or else to make it a statewide mandate. 

And,  believe me,  they should do so!  There have been many of these explosions over the past century.  There is no excuse to let money trump public safety.  Official both in public service and in private organizations should be judged by how they prioritize public safety versus profit.

There is also the problem of urban sprawl.  As already mentioned,  towns grow toward and engulf these facilities.  Without thinking about the threat,  residences,  businesses,  and schools get built right next to facilities handling what amounts to a high explosive,  if mishandled. 

What that really means is that local officials need to understand the true nature of the threat from ammonium nitrate.  They need to zone around these facilities as their locations are annexed into the city,  to restrict development to a safe distance.  This has not been happening,  but ignorance should not be an excuse!

As for anhydrous ammonia,  it poses much less of an explosion hazard,  but something of a toxic gas release hazard,  even in a plant fire.  However,  there are standards for these,  too.  If applied,  the risks are reduced quite effectively.  Again,  this starts as a county or state requirement for rural construction,  and those same requirements should be applied by the cities as they engulf these facilities,  as well as proper zoning.

Citizens,  you render your judgements at the polls!

Saturday, November 1, 2014

Two Commercial Spaceflight Disasters in One Week

Two commercial launch failures within days is a lot for a fledgling industry to take.  Especially with political critics that are quite undeserved.  One of these failures relates to commercial manned flights,  that being Virgin Galactic's SpaceShip Two.  The other relates to unmanned cargo and satellite launch,  that being Orbital Sciences' Antares rocket and Cygnus cargo spacecraft.  

Update 11-3-14:  with a rocket-powered vehicle,  the first suspect is always the engine when there is a problem.  That appears to be the case with the Orbital Sciences launch failure.  

But with the Virgin Atlantic spaceplane,  preliminary NTSB comments reported this morning indicate there was a problem with the re-entry feathering system,  not the engine.  This one is going to be very interesting when the report is done.  

In any event,  enjoy the rocket technology discussions that follow.

Update 11-5-14:  Published news releases as of today indicate that Orbital thinks their launch disaster was caused by a turbopump failure.  They also no longer intend to use those engines.  The best new information about the Spaceship Two disaster suggests that the two pilots were literally ejected into the air as the cabin broke up around them,  at about Mach 1,  near 50,000 feet.  These reports indicate they were so ejected without pressure suits or supplemental oxygen.  One managed to deploy his parachute and lived,  the other didn't and died.  

Update 4-15-15:  There is no news yet from the NTSB regarding Spaceship Two that has made public release.  However,  regarding the Antares explosion,  it does appear that the turbopump bearings were essentially destroyed in one of the refurbished Russian engines,  probably from foreign object damage.  

Orbital (builder of the vehicle) and Aerojet Rocketdyne (refurbisher of the engines) are at odds over this.  similar to Ford and Firestone Tires a few years ago.  At issue is where the foreign objects that got into the turbopump came from.  Whose fault was it that such debris got in there?  

If it were in the engine to begin with,  how did it escape quality control at Aerojet Rocketdyne?  If it came from the vehicle tanks or piping,  was there not an inlet screen in Orbital's design to catch such stuff?  Both possibilities are rather hard to believe.  

We may or may not ever hear in public which is true.  But there's not a lot of other possibilities for that kind of failure.  

Hybrid vs Solid Rocket Technology

Hybrid rockets “done right” have safety advantages over solid propellant rockets,  if the fuel is just that:  fuel,  without any oxidizer in its formulation.  That can be a rubber,  a plastic,  or even a wax,  and it can have solid powders dispersed in it,  just not oxidizer powders. 

That kind of hybrid ceases combustion when you stop the liquid oxidizer flow.  That makes the vehicle abortable,  since you can shut off the engine,  as with liquid rockets.  Solids burn like dynamite sticks:  once lit,  they burn to completion,  no choice.

Solid propellants are typically a rubber or rubber-like binder loaded with particulate solids,  solids that include the solid oxidizer as powder.  Solid oxidizers are typically ammonium perchlorate or ammonium nitrate these days.  There are some others. 

Solid propellants,  even those that are seriously fuel-rich,  all burn with two physical effects controlling their burn rate.  The prime factor is an inherent burn rate of exposed surface that depends upon chamber pressure per a power function with an exponent under 1,  usually well under 1.  The secondary factor is often called “erosive burning”,  and shows up as a burn rate enhancement (added term) in the presence of hot gas scrubbing along the exposed surface at high speed. 

All exposed solid surface quickly produces massflow,  because there is very rapid surface flame spread from lit areas to unlit areas.  The most common problem encountered with solid rockets is the presence of cracks or voids in the propellant charge,  because these very quickly (in milliseconds) add large quantities of burning surface,  producing massive increases in motor massflow.

This very quickly drives the chamber pressure too high,  overpressuring the case,  and causing a violent explosion.  It typically happens without warning symptoms,  and very quickly (on a few milliseconds time scale).  This is due to the very nonlinear mathematics of what determines the chamber pressure,  which is a balance between pressure-driven surface massflow generation,  and pressure-driven nozzle massflow capability.

The second most common failure in solid motors is a case insulation failure,  leading to a burn-through,  followed quickly (usually just under a second) by the case exploding.  The third most common failure is a type of combustion instability wherein the oscillations cause higher average pressures from an enhanced burn rate,  due to the erosive-burning effect.  These can lead to over-pressurization explosions on a time scale of a few seconds,  but not always.

That kind of combustion instability has an unstable positive feedback of combustion energy released from tiny combustion eddies directly into the oscillations.  It occurs when some natural gas vibration mode in the geometry is close to the small-scale combustion eddy frequencies.

A very distant fourth most common failure is a piece of propellant or other debris coming loose inside the motor,  and getting blown into the nozzle,  where it obstructs the throat,  causing the motor to virtually-instantaneously explode like a pipe bomb. 

The most common problem in the hybrids is a kind of combustion instability that causes very rough operation and vibrations,  but usually without the unstable feedback of the solid.  This is inherent due to the gross unmixedness resulting from generating the fuel from only the erosive-burning effect of the hot port flow (oxidizer plus fuel from upstream plus still-combusting fuel and oxidizer). 

There are localized fuel-rich and fuel-lean pockets of gas.  As fuel and oxidizer suddenly combine in the very turbulent mixing,  these pockets explode.  The bigger the “exploding vortices”,  the stronger the thrust and pressure oscillations.  But because there is no feedback into a chamber-pressure burn rate effect,  the instability doesn’t grow catastrophically out-of-control within seconds,  the way it does in solids. 

The other two fatal hybrid failure modes are the same as solids:  case insulation failure leading to burn-through,  and debris blocking the throat.  Update 11-3-14:  hybrids with no oxidizer in their fuel grains are pretty much immune to the effects of grain cracks or voids.  There is no pressure effect burn rate in these freshly-exposed spaces,  and the massflow scrubbing effect just doesn't reach there hardly at all.  Fuel burnout "tailoff" characteristics can be affected somewhat,  though.  

Historically,  hybrids have suffered design impracticality from very low effective burn rates (more properly,  “regression rates”).  The historical “fixes” for this are (1) multiport grain designs that reduce the effective thickness to be burned,  and (2) adding low amounts of oxidizer powder to the fuel grain formulation. 

In recent years,  a third option has become available:  fuel formulations that liquefy (literally melt) before they pyrolyze into combustion.  That third option is the best.  The multiport option leads to low volumetric efficiency.  Adding solid oxidizer is absolutely the worst,  by far.

Adding oxidizer,  even in amounts too low to sustain combustion with the liquid oxidizer shut off,  converts the hybrid “fuel” into a fuel-rich conventional solid propellant.  That negates the very most important safety advantage of being a hybrid.  Now there is fast surface flamespread,  drive by the inherent burn rate vs pressure effect of a solid,  into cracks and voids.  This restores the same vulnerability to motor explosion as any other solid.  

If you add too much solid oxidizer,  you cannot stop the motor by cutting off the liquid oxidizer.  This negates the other advantage of a hybrid,  abortability. 

A Word About Liquid Rockets

Liquids have three of the very same failure modes that afflict solids and hybrids:  burn-through,  debris blocking nozzle throats,  and combustion instability.  The failure of regenerative cooling (not insulation) is what causes the burn-through.   Combustion instability in liquids takes many forms,  all being related to ignition of mixing eddies that are rich or lean in fuel. 

The unique problem with liquids is turbopump failures,  since nearly all liquid systems have them. (Update 11-3-14:  some hybrids can also have pumped liquid oxidizers,  others are pressure-fed.)  These components are very highly stressed,  and exposed to very extreme conditions of heat and cold simultaneously.  It is not surprising that they fail.  When they do,  there is almost always some kind of explosion. 

Another failure mode known since the V-2 missile of World War 2 is starting at too high a propellant flow rate.  This will literally blow the engine apart,  virtually instantaneously.  It does take a very finite time to spool turbomachinery up from low thrust settings to high thrust settings.  Further,  there are serious limitations on just what the minimum thrust of any particular engine design can be. 

SpaceShip Two’s Loss 10-31-14:

The available data-to-date are spotty at best.  We will have to wait for the NTSB investigation to complete,  before the truth and all the facts come out.  That can take over a year. 

The news photos I have seen indicates that SpaceShip Two dropped from White Knight Two successfully,  and then successfully ignited its rocket engine.  Then there was an explosion. Update 11-3-14:  not an explosion,  a mid-air breakup,  according to very preliminary comments made by the NTSB.  

Photos of the wreckage tell me that the engine compartment was violently destroyed,  also blowing away the tail booms of Spaceship Two.  Without the tails,  the fuselage and its stub wings just become a tumbling ballistic projectile to the desert floor. 

The tail booms,  and that which is recognizable as fuselage wreckage,  appear to have crashed in different places on the desert.  I did recognize the fuselage aft pressure bulkhead in some photos of the wreckage.  There was nothing left aft of it.  Update 11-3-14:  more published photos from more view angles show that there was nothing left on either side of this bulkhead.  

Some accounts I have seen claim CNN as a source for the assertion that the engine shut down,  and then exploded upon a restart attempt.  I do not know anything about that,  myself. 

Nothing I have found among open sources on the internet would indicate that solid oxidizer was a part of the original HTPB fuel grain formulation,  or the new plastic grain formulation on the lost flight.  That’s not to say there wasn’t any,  but nothing released publicly indicates it. 

Everything I saw says fuel-only grain plus liquid nitrous oxide (N2O).  The only change seemed to be the switch from HTPB rubber to a plastic for the binder.  That occurred when Virgin took the motor design in-house,  away from Sierra Nevada,  who had done the HTPB version.

That leaves motor case burn-throughs or debris plugging the nozzle,  from the failure modes listed above.  There is also the possibility that the restart attempt was transiently just too violent an event,  and simply split the motor case open. 

Whatever happened,  the event was violent enough to suddenly “disperse” the entire engine compartment from the aft fuselage,  since the fuselage debris in the desert terminates at the aft pressure bulkhead.  Update 11-3-14:  with a midair breakup,  it was broadside air pressures that broke up and dispersed everything.  It doesn't take an internal explosion to do that,  just a loss of attitude control.  

This same violent event was enough to separate both articulated tail booms from the aircraft.  They can be quite clearly seen about a vehicle length away on each side in the news still photo that was taken a split second after the explosion. 

Pieces of the motor case are going to be hard to find in all of that desert.  It may be impossible to find enough to reassemble it,  to determine if there was a burn-through. 

If there was some kind of mixing baffle inside the motor to help with the low-grade instability of hybrids due to poor mixing,  then it might have come loose and blocked the nozzle.  It might be vulnerable during an ignition transient.  If it can be found,  extreme distortion of the part might suggest this possibility.

Finding out whether restart attempts might be too violent will require motor restart testing on the ground.  Virgin and Scaled Composites certainly have a lot to investigate.  I would suggest doing any such restart tests in a revetment of some kind,  as a ground crew safety measure. 

Update 11-3-14:  With the NTSB focusing up the the feathering system causing a mid-air breakup,  the engine issue revises to confirming that it was operating correctly.  

Orbital Sciences Antares/Cygnus Loss

I have seen news video footage of this loss enough times to know that something was wrong from liftoff.   The engine plumes of kerosene-liquid oxygen engines are very brilliant,  enough to cause camera “image bloom” all the time.  Yet in this launch,  that “apparent fireball” was just too bright. 

A few vehicle lengths off the launch pad I saw the vehicle slowing to a stop,  followed by the first explosion.  That first explosion would have been the range safety self-destruct charge ripping apart the first stage.  The rest of it blew up as multiple explosions upon impact very near the launch pad.

I do not know,  but I suspect either a turbopump or chamber failure leading to a loss of incandescent gas around the engine at vehicle rear.  After a few seconds overheating,  the engine blew apart,  killing thrust,  and precipitating self-destruct.  These are refurbished 40+ year-old Russian-made engines! 

Orbital Sciences is using these Russian-made engines as the only thing available to them in the right size range.  These were originally built in Russia over 4 decades ago,  and were stored most of those years in a barn of some kind in Siberia.  Aerojet Rocketdyne refurbished these for Orbital Sciences.

This says more about corporate (and government) policies regarding offshoring overseas critical US capabilities,  than it does anything about the engines themselves.  If “we” had not frittered-away this country’s rocket engine manufacturing capabilities,  Orbital would not have been forced to use refurbished 40+ year old foreign made units.  Period.  Somebody needs their butt thoroughly kicked over this issue!

From what I can find on the internet,  one of these same engines blew up in a ground test a while back.  I could not locate anything explaining that test failure,  but then,  I am no internet expert.  However,  that’s enough to cast some doubt on this engine.

Conclusions:

Orbital has to get to the bottom of this.  They will need Aerojet’s help.  The rest of us need to give them the “wiggle room” to get that job done.  Critics stirring up trouble in the halls of congress are not needed,  and can go stuff their unhelpful “suggestions” where the sun doesn’t shine!

Same goes for Virgin’s fatal problem with SpaceShip Two:  they need “wiggle room” and time to get to the bottom of what happened. 

I can only wish both outfits well,  and may God speed their investigations.  I would gladly help either or both of them.


GW