Science

When the Apollo 11 guidance software developed under Margaret Hamilton’s leadership began flashing a sequence of 1201 and 1202 alarms more than seven minutes before Eagle touched down in the Sea of Tranquility, it was doing what MIT engineers had designed it to do years earlier: restarting and protecting higher-priority tasks so critical landing computations could continue, a design choice that helped save the landing with about 45 seconds of fuel remaining


At 102:38:26 mission elapsed time, the Apollo 11 lunar module was still more than seven minutes from touchdown when Neil Armstrong announced a program alarm. The code was 1202. Eagle was roughly 33,500 feet, or 10 kilometers, above the Moon, and neither Armstrong nor Buzz Aldrin knew whether the alarm required an abort.

The Apollo 11 Lunar Surface Journal records Houston clearing the crew to continue 27 seconds after Armstrong’s first alarm call. The immediate judgment came from 26-year-old guidance officer Steve Bales, working with computer specialist Jack Garman and the rest of the flight-control team.

Four more overload alarms followed. Yet the computer did not lose its navigation state, stop controlling Eagle, or force an abort. Its recovery software repeatedly discarded unfinished work, restarted the essential programs, and continued the descent.

When the alarms actually happened

A technical memorandum prepared by the MIT Instrumentation Laboratory on August 4, 1969, provides the clearest sequence. According to the contemporaneous alarm analysis, the first 1202 occurred 316 seconds after powered descent initiation. Another followed 40 seconds later, while the final three alarms arrived during the last three and a half minutes before touchdown.

The complete sequence consisted of four 1202 alarms and one 1201 alarm. This is why later accounts sometimes describe the crisis as beginning three minutes before landing: the final cluster did, but the first alarm came more than seven minutes before contact.

What 1201 and 1202 meant

The two codes identified slightly different shortages inside the Executive, the Apollo Guidance Computer’s job-control system. A 1201 alarm meant no vector-accumulator memory areas, known as VAC areas, were available. A 1202 meant the computer had exhausted its smaller core sets.

In either case, the response was a controlled software restart. A NASA-hosted explanation by Apollo programmer Peter Adler describes how the computer reinitialized itself and resumed selected programs near the points where they had been interrupted. It restarted essential functions such as engine steering and the cockpit display while leaving dispensable work behind.

This was more precise than simply “dropping low-priority tasks.” The restart cleared the Executive and Waitlist queues, then used phase tables prepared by the programmers to restore the jobs that had to survive. Navigation, guidance, and digital-autopilot work continued; crew-requested displays could be requested again later.

Why Eagle’s computer became overloaded

The rendezvous radar switch was in AUTO TRACK, the position specified by the crew checklist. Because of an electrical phase mismatch in the radar interface, the system produced a rapid stream of counter-increment requests. Those requests consumed about 15 percent of the computer’s available processing time.

The landing programs were already using most of the machine’s capacity. Some recurring guidance jobs therefore had not finished when the Executive was asked to schedule their next cycle. The backlog consumed the available core sets and VAC areas until the computer invoked its recovery routine.

Aldrin noticed that one of the 1202 alarms appeared while Verb 16 Noun 68 was running. That display showed information including velocity and range to the landing site. The request was not the underlying fault, but its additional workload could push an already overloaded computer across the limit, so Houston monitored some of the information instead.

Hamilton’s role and Laning’s role

Margaret Hamilton was 32 and directed the Software Engineering Division at MIT’s Instrumentation Laboratory. She led the group responsible for the onboard flight software used by the Apollo command and lunar modules. Her documented contributions included asynchronous software, error detection and recovery, and priority displays that could interrupt the crew’s normal readouts during an emergency.

The Executive operating system itself, however, should be credited more specifically. MIT’s history of the Apollo computer says J. Halcombe “Hal” Laning devised the Executive and its priority-based method of handling multiple programs. That operating system became crucial during Apollo 11 because it protected the work needed to keep Eagle flying.

Hamilton did encounter resistance at MIT and NASA, but the documented episodes involved different issues. In a 2019 Guardian interview, she recalled that managers initially rejected a safeguard against an astronaut selecting a prelaunch program during flight. She also said one supervisor worried that male employees might rebel when she became their boss.

Those stories demonstrate the resistance Hamilton sometimes faced, but they do not establish that she personally forced Laning’s priority scheduler through MIT objections. Apollo’s recovery system was a collective engineering achievement, with Hamilton’s leadership and Laning’s operating-system design both essential to an accurate account.

The decision in Mission Control

The software could recover from the overload, but people still had to decide whether its behavior was safe. Bales consulted Garman and advised the flight director that Eagle could continue as long as the alarms were intermittent and the computer’s critical outputs remained stable.

Bales was later selected to accept a NASA Group Achievement Award on behalf of the mission-operations team. The Iowa State University biographical record confirms that distinction. The Presidential Medal of Freedom presented at the same 1969 ceremony went to the Apollo 11 astronauts, not Bales.

Hamilton received the Presidential Medal of Freedom from Barack Obama in 2016 for her contributions to Apollo flight software. The two honors recognized different parts of the same outcome: a computer built to recover, and controllers prepared to recognize that it had recovered.

How much fuel remained

The program alarms and the low-fuel warnings were separate problems. Armstrong flew beyond the computer’s original target because the approach was carrying Eagle toward the boulder field around West Crater. The extra maneuvering extended the powered descent.

At the time, Mission Control believed the lunar module was much closer to exhausting its propellant than it actually was. The low-level sensor had been uncovered early by fuel sloshing. The post-flight reconstruction found about 770 pounds of propellant remained, of which roughly 670 pounds was usable. That represented about 45 seconds of engine time, including approximately 20 seconds reserved for an abort.

Aldrin later recalled a smaller margin. In a 2019 interview, he estimated that about 15 seconds remained. His recollection is worth preserving as the crew’s impression, but the post-flight engineering analysis supports the larger figure.

A small computer doing sophisticated work

The Apollo Guidance Computer was constrained but not primitive. An MIT AeroAstro account gives its weight as 70 pounds, or about 32 kilograms, with a power draw of 55 watts and a volume of less than one cubic foot. It carried approximately 36,000 words of fixed memory and 2,000 words of erasable memory, with a memory cycle of about 12 microseconds.

Most of its programs were physically encoded in core rope memory. MIT describes the manufacturing process as weaving wires through or around tiny magnetic cores, with much of the work performed by women at Raytheon in the Boston suburbs. Passing through a core represented one binary value; passing around it represented the other.

At 20:17:40 UTC, a probe beneath one of Eagle’s footpads touched the lunar surface. Armstrong shut down the descent engine seconds later and reported that Eagle had landed. The computer beneath him had survived five overload alarms because its designers had planned for work to arrive faster than the machine could safely complete it.

The lasting lesson is not that one person wrote a miraculous piece of code. It is that Laning’s priority-driven Executive, Hamilton’s software leadership and recovery work, the wider MIT team’s testing, and Mission Control’s preparation all met in the same few minutes. The landing continued because the system knew which work could wait and which work could not.



Source link