10 ms·
We found an undocumented bug in the Apollo 11 guidance computer code
- josephg 6mo agoSuper interesting. I wish this article wasn’t written by an LLM though. It feels soulless and plastic.
- retard2 6mo ago[flagged]
- vrighter 6mo agoit's actually the second one I read that fit that description.
- ModernMech 6mo agoI'm starting to develop a physiological response when I recognize AI prose. Just like an overwhelming frustration, as if I'm hearing nails on chalkboard silently inside of my head.
- voodooEntity 6mo agoI feel ya.... and i have to admit in the past i tried it for one article in my own blog thinking it might help me to express... tho when i read that post now i dont even like it myself its just not my tone. therefor decided not gonne use any llm for blogging again and even tho it takes alot more time without (im not a very motivated writer) i prefer to release something that i did rather some llm stuff that i wouldnt read myself.
- retard3 6mo ago[flagged]
- embedding-shape 6mo agoAny specific sections that stick out? Juxt in the past had really great articles, even before LLMs, and know for a fact they don't lack the expertise or knowledge to write for themselves if they wanted and while I haven't completely read this article yet, I'd surprise me if they just let LLMs write articles for them today.
- croemer 6mo agoHere's one tell-tale of many: "No alarm, no program light." Another one: "Two instructions are missing: [...] Four bytes." One more: "The defensive coding hid the problem, but it didn’t eliminate it."
- monooso 6mo agoThat's just writing. I frequently write like that. This insistence that certain stylistics patterns are "tell-tale" signs that an article was written by AI makes no sense, particularly when you consider that whatever stylistic ticks an LLM may possess are a result of it being trained on human writing.
- gcr 6mo agoSee also: “I'm Kenyan. I Don't Write Like ChatGPT. ChatGPT Writes Like Me” by Marcus Olang', https://marcusolang.substack.com/p/im-kenyan-i-dont-write-like-chatgpt?triedRedirect=true https://marcusolang.substack.com/p/im-kenyan-i-dont-write-li... For what it’s worth, Pangram reports that Marcus’ article is 100% LLM-written: https://www.pangram.com/history/640288b9-e16b-4f76-a730-800080cb35f4 https://www.pangram.com/history/640288b9-e16b-4f76-a730-8000...
- croemer 6mo agoIn theory, wouldn't be too hard be to settle the question if whether he used ChatGPT to write it: get Olang to write a few paragraphs by hand, then have people judge (blindly) if it's the same style as the article. Which one sounds more like ChatGPT.
- gcr 6mo agoFor what it’s worth, Pangram thinks this article is fully human-written: https://www.pangram.com/history/f5f68ce9-70ac-4c2b-b0c3-0ca8827580ec https://www.pangram.com/history/f5f68ce9-70ac-4c2b-b0c3-0ca8...
- xmcqdpt2 6mo agoThen pangram isn't very good, because that article is full of Claude-isms.
- DiffTheEnder 6mo agoIs it possible for a tool to know if something is AI written with high confidence at all? LLMs can be tuned/instructed to write in an infinite number of styles. Don't understand how these tools exist.
- gcr 6mo agoThe WikiEDU project has some thoughts on this. They found Pangram good enough to detect LLM usage while teaching editors to make their first Wikipedia edits, at least enough to intervene and nudge the student. They didn’t use it punatively or expect authoritative results however. https://wikiedu.org/blog/2026/01/29/generative-ai-and-wikipedia-editing-what-we-learned-in-2025/ https://wikiedu.org/blog/2026/01/29/generative-ai-and-wikipe... They found that Pangram suffers from false positives in non-prose contexts like bibliographies, outlines, formatting, etc. The article does not touch on Pangram’s false negatives. I personally think it’s an intractable problem, but I do feel pangram gives some useful signal, albeit not reliably.
- cameronh90 6mo agoIt has Claude-isms, but it doesn't feel very Claude-written to me, at least not entirely. What's making it even more difficult to tell now is people who use AI a lot seem to be actively picking up some of its vocab and writing style quirks.
- embedding-shape 6mo ago
- ChrisRR 6mo agoIt's not setting off any LLM alarm bells to me. It just reads like any other scientific article, which is very often soulless
- bbstats 6mo agothe subheadings are extremely AI IMHO
- fragmede 6mo agoIsn't that just a normal way to organize a large document?
- Jolter 6mo agoIt repeats a few points too many times for a professional writer to not catch it. I don’t mind that they let an LLM write the text, but they should at least have edited it.
- monooso 6mo agoYou have no evidence that it was.
- NiloCK 6mo agoThis is the top reply on a substantial percentage of HN posts now and we should discourage it. It is: - sneering - a shallow dismissal (please address the content) - curmudgeonly - a tangential annoyance All things explicitly discouraged in the site guidelines. [1] Downvoting is the tool for items that you think don't belong on the front page. We don't need the same comment on every single article. [1] - https://news.ycombinator.com/newsguidelines.html https://news.ycombinator.com/newsguidelines.html
- monooso 6mo agoNo idea why you're being downvoted. I've done my bit to redress the balance, I hope others do the same.
- masklinn 6mo ago> Downvoting is the tool for items that you think don't belong on the front page. You can’t downvote submissions. That’s literally not a feature of the site. You can only flag submissions, if you have more that 31 karma.
- timdiggerm 6mo agoIt's not a shallow dismissal; it's a dismissal for good reason. It's tangential to the topic, but not to HN overall. It's only curmudgeonly if you assume AI-written posts are the inevitable and good future (aka begging the question). I really don't know how it's "sneering", so I won't address that.
- TruffleLabs 6mo ago"Written by an LLM" based on what data or symptom?
- mpalmer 6mo agoI've seen way, way worse. Either someone LLM-polished something they already wrote, or they did their own manual editing pass. The short sentence construction is the most suspicious, but I actually don't see anything glaring. It normally jumps out and hits me in the face.
- bookofjoe 6mo ago>Hemingway's 4 Fast Rules For Effective Writing 1. Use Short Sentences https://www.wordsthatsing.com.au/post/hemingway-rules https://www.wordsthatsing.com.au/post/hemingway-rules
- mpalmer 6mo agoI didn't say they're dispositive. I said they're suspicious. Most people don't write effectively.
- NetMageSCW 6mo agoSo LLMs write effectively and when people do you accuse them of using an LLM?
- mpalmer 6mo agoNo, they don't. They use short sentences in weird, stilted ways.
- rudhdb773b 6mo agoNot to single out your comment, but it feels like it's gotten to the point where HN could use a rule against complaining about AI generated content. It seems like almost every discussion has at least someone complaining about "AI slop" in either the original post or the comments.
- Gigachad 6mo agoHN has gotten to the point where it’s not even worth clicking the link because of course it’s ai slop. There is some real content in the haystack, but we almost need some kind of curator to find and display it rather than a vote system where most people vote on the title alone.
- brookst 6mo agoIf you’re looking for a place that surfaces only human-written content regardless of whether it’s interesting, rather than interesting content regardless of how it was written, HN is not the place. There might be a market for your alternative though. Should be easy enough to build with Claude Code.
- bakugo 6mo agoIf the content was interesting, the author would've written about it himself. By asking AI to write the article for you, you're asserting that the subject matter is not interesting enough to be worth your time to write, so why would it be worth my time to read?
- Gigachad 6mo agoYou just need AI to read it for you and summarise back in to the original prompt.
- malcolmjuxt 6mo agoI know the author personally. He's hardly the type of person to publish AI slop. Read his other articles and watch his talks, this is very much Henry's literary style.
- croemer 6mo agoAnd it turns out at least the part about Rust and locks is plain wrong. What a surprise: https://news.ycombinator.com/reply?id=47676938&goto=item%3Fid%3D47673005%2347676938 https://news.ycombinator.com/reply?id=47676938&goto=item%3Fi...
- jandrese 6mo agoAI tends to write like it is getting paid by the word. This article wasn't too egregious but an editor could have improved it.
- iJohnDoe 6mo agoI did not get any “written by LLM vibes”. I enjoyed it and it pulled me in to keep reading. Who gives a crap if it was written by an LLM. Read it or don’t read it. Your choice. If it conveys the idea and your learn something new, then it’s mission accomplished.
- croemer 6mo agoIncidental finding: another blog posts was written by Claude and they admit it openly in the last paragraph (not earlier): A Note on the Process To be clear about what happened here: Claude wrote this article. https://www.juxt.pro/blog/what-we-learned-from-34-clojure-interviews/ https://www.juxt.pro/blog/what-we-learned-from-34-clojure-in...
- yodon 6mo agoThis is so insightfully and powerfully written I had literal chills running down my spine by the end. What a horrible world we live in where the author of great writing like this has to sit and be accused of "being AI slop" simply because they use grammar and rhetoric well.
- dotancohen 6mo agoI was completely riveted the whole read. The description of Collins' dilemma is the first time I've seen an actual real world scenario described that might cause him to return to Earth alone. If an LLM wrote that, then I no longer oppose LLM art.
- breakingcups 6mo agoI thought that was the least likeable part of the article. They speculated wildly, somehow making the leap that a trained astronaut would not resort to a computer reset if the problems persisted to weave the narrative that this bug was super-duper-serious indeed. They didn't need that and it weakened the presentation.
- jwpapi 6mo agoHas someone verified this was an actual bug? One of AI’s strengths is definitely exploration, f.e. in finding bugs, but it still has a high false positive rate. Depending on context that matters or it wont. Also one has to be aware that there are a lot of bugs that AI won’t find but humans would I don’t have the expertise to verify this bug actually happened, but I’m curious.
- throwaway27448 6mo agoIt's not even clear if AI was used to find the bug: they mention modeling the software with an "ai native" language, whatever that means. What is not clear is how they found themselves modeling the gyros software of the apollo code to begin with. But, I do think their explanation of the lock acquisition and the failure scenario is quite clear and compelling.
- Aurornis 6mo ago> It's not even clear if AI was used to find the bug The intro says “We used Claude and Allium”. Allium looks like a tool they’ve built for Claude. So the article is about how they used their AI tooling and workflow to find the bug.
- throwaway27448 6mo agoThe article does not explain anything about how they used AI—it just has some relation with the behavioral model a human seems to have written (and an AI does not seem necessary to use!)
- MBCook 6mo agoSure it does. They used their AI tool to extract the rules for the Apollo guidance system based on the source code. Then they used Claude to check if all paths followed those rules.
- zeristor 6mo ago[dead]
- wg0 6mo agoSomeone please amend the title and add "using claude code" because that's customary nowadays.
- riverforest 6mo agoSoftware that ran on 4KB of memory and got humans to the moon still has undiscovered bugs in it. That says something about the complexity hiding in even the smallest codebases.
- whiplash451 6mo agoMy guess is that in such low memory regimes, program length is very loosely correlated with bug rate. If anything, if you try to cram a ton of complexity into a few kb of memory, the likelihood of introducing bugs becomes very high.
- pooloo 6mo agoYet here we are compounding the issues by adding more and more layers to these systems... The higher the level it becomes the more security risks we take.
- SoftTalker 6mo agoWell you don't have room for a lot of "defensive" code. You write the program to function on expected inputs, and hope that all the "shouldn't happen" scenarios actually don't happen.
- airstrike 6mo ago^ This is slop. Typical platitude that really means nothing.
- pvdebbe 6mo agoAlso contrast with the busy beaver problem and how much can be done with a small handful of instructions.
- MeteorMarc 6mo agoAre there any consequences for the Artemis 2 mission (ironic)?
- ChicagoBoy11 6mo agoFor anyone who liked this, I highly suggest you take a look at the CuriousMarc youtube channel, where he chronicles lots of efforts to preserve and understand several parts of the Apollo AGC, with a team of really technically competent and passionate collaborators. One of the more interesting things they have been working on, is a potential re-interpretation of the infamous 1202 alarm. It is, as of current writing, popularly described as something related to nonsensical readings of a sensor which could (and were) safely ignored in the actual moon landing. However, if I remember correctly, some of their investigation revealed that actually there were many conditions which would cause that error to have been extremely critical and would've likely doomed the astronauts. It is super fascinating.
- deepsun 6mo agoAnd that's why it's harder (or easier?) to make the same landing again -- we taking way less chances. Today we know of way more failure modes than back then.
- wat10000 6mo agoIt's a miracle nobody died in flight during the program. Exploding oxygen tank, rockets shaking themselves to pieces during launch, getting hit by lightning on top of a flying skyscraper full of kerosene and liquid oxygen....
- thinkingtoilet 6mo agoStarting from the first test pilots, a lot of people died for us to get to the point to launch that flight. So while no one died on the flight, lots of people died just getting us there. If I recall, in The Right Stuff, it's mentioned that those early test pilots had something like a 25% mortality rate.
- wat10000 6mo agoThe early jet age was pretty nuts. Check the Wikipedia page for a random fighter from the era and you'll see figures like, 1,300 built, 50 lost in combat, 1,100 lost in accidents. And that's operational aircraft. Test pilots were in even more danger.
- chrisjj 6mo ago> The specs were derived from the code itself Oh dear. I strongly suggest this author look specification up in a dictionary.
- perching_aix 6mo agoIt's (what they're describing is) just reverse engineering. That's what reverse engineering is.
- chrisjj 6mo agoFortunately reverse engineering too is in the dictionary - to help anyone mistaking it for spec generation.
- deleted 6mo ago[deleted]
- deleted 6mo ago[deleted]
- perching_aix 6mo agoImplying that I did make such mistake, which I did not, unless you're willfully taking me overly literal. Nor did they make any mistakes when they described how they produced a specification, (and indeed, that it is a specification) despite your insinuation otherwise, for a similar reason. Maybe instead of pointing towards dictionaries, stop pretending that you lack reading comprehension, and get off of your high horse please.
- buredoranna 6mo agoStill my all time favorite snippet of code. TC BANKCALL # TEMPORARY, I HOPE HOPE HOPE CADR STOPRATE # TEMPORARY, I HOPE HOPE HOPE TC DOWNFLAG # PERMIT X-AXIS OVERRIDE https://github.com/chrislgarry/Apollo-11/blob/master/Luminary099/LUNAR_LANDING_GUIDANCE_EQUATIONS.agc https://github.com/chrislgarry/Apollo-11/blob/master/Luminar...
- donkeyboy 6mo agoCan you explain this to me?
- buredoranna 6mo agoWish I could... but I know of it from a previous HN post, where there is some discussion on its purpose. https://news.ycombinator.com/item?id=22367416 https://news.ycombinator.com/item?id=22367416
- dylan604 6mo agoI think the point was the comments more than any of the code requiring explanation. There's nothing more permanent than a temporary solution
- f1shy 6mo agoCadr here has no relation with lisp cadr, right?
- jacquesm 6mo agohttps://news.ycombinator.com/item?id=16008239 https://news.ycombinator.com/item?id=16008239
- jasomill 6mo agoCorrect. CADR is an AGC assembly directive defining a "complete address" including a memory bank, in this case a subroutine to be called by the preceding BANKCALL (TC = transfer control, i.e., store return address and jump to subroutine), which switches to the memory bank specified in the CADR before jumping to the address specified in the CADR. For a brief explanation of AGC subroutine calls, see [1]. CAR and CDR in Lisp come from the original implementation on the IBM 704, where pointers to the two components of a cons cell were stored as the (C)ontents of the (A)ddress and (D)ecrement fields of a (R)egister (memory word). (CADR x) is just shorthand for (CAR (CDR x)), i.e., a function that returns the second element of a list (assuming x is a well-formed list). [1] https://epizodsspace.airbase.ru/bibl/inostr-yazyki/American_Scientist/2019/3/Hayes_Moonshot_Computing_American_Scientist_107_no_03_(2019).pdf#page=4 https://epizodsspace.airbase.ru/bibl/inostr-yazyki/American_...
- iJohnDoe 6mo agoFascinating read. Well done. Everyone involved in the Apollo program was amazing and had many unsung heroes.
- _2fnr 6mo ago[flagged]
- msgilligan 6mo agoBut this seems like a reasonable approach for reverse-engineering, and it seems the bug they found is real.
- nraynaud 6mo agoI took it as the extracted spec was weird and they looked into it.
- jcalvinowens 6mo agoThe code was inconsistent with itself: that's not circular. Every path dropped the lock except one.
- esafak 6mo agoAn application of their specification language, https://juxt.github.io/allium/ https://juxt.github.io/allium/ It seems the difference between this and conventional specification languages is that Allium's specs are in natural language, and enforcement is by LLM. This places it in a middle ground between unstructured plan files, and formal specification languages. I can see this as a low friction way to improve code quality.
- kmeisthax 6mo ago> Rust’s ownership system makes lock leaks a compile-time error. Rust specifically does not forbid deadlocks, including deadlocks caused by resource leaks. There are many ways in safe Rust to deliberately leak memory - either by creating reference count cycles, or the explicit .leak() methods on various memory-allocating structures in std. It's also not entirely useless to do this - if you want an &'static from heap memory, Box.leak() does exactly that. Now, that being said, actually writing code to hold a LockGuard forever is difficult, but that's mainly because the Rust type system is incomplete in ways that primarily inconvenience programmers but don't compromise the safety or meaning of programs. The borrow checker runs separately from type checking, so there's no way to represent a type that both owns and holds a lock at the same time. Only stacks and async types, both generated by compiler magic, can own a LockGuard. You would have to spawn a thread and have it hold the lock and loop indefinitely[0]. [0] Panicking in the thread does not deadlock the lock. Rust's std locks are designed to mark themselves as poisoned if a LockGuard is unwound by a panic, and any attempt to lock them will yield an error instead of deadlocking. You can, of course, clear the poison condition in safe Rust if you are willing to recover from potentially inconsistent data half-written by a panicked thread. Most people just unwrap the lock error, though.
- totalmarkdown 6mo ago[flagged]
- dmoy 6mo agoI don't think apollo 11's toilet malfunctioned, it was just not very good. Everything smelled like poop mixed with chemicals, and that was by design.
- croemer 6mo agoI've had a look at the (vibe coded) repro linked in the article to see if it holds up: https://github.com/juxt/agc-lgyro-lock-leak-bug/blob/c3784385bd71c66b0c3723b64d57624a84175a99/reproduce_lgyro_bug.py#L234-L261 https://github.com/juxt/agc-lgyro-lock-leak-bug/blob/c378438... The repro runs on my computer, that's positive. However, Phase 5 (deadlock demonstration) is entirely faked. The script just prints what it _thinks_ would happen. It doesn't actually use the emulator to prove that its thinking is right. Classic Claude being lazy (and the vibe coder not verifying). I've vibe coded a fix so that the demonstration is actually done properly on the emulator. And also added verification that the 2 line patch actually fixes the bug: https://github.com/juxt/agc-lgyro-lock-leak-bug/pull/1 https://github.com/juxt/agc-lgyro-lock-leak-bug/pull/1
- ErroneousBosh 6mo ago> However, Phase 5 (deadlock demonstration) is entirely faked. The script just prints what it _thinks_ would happen. I see this a lot in AI slop, which I mostly get exposed to in the form of shitty pull requests. You know when you're trying to explain Test-Driven Development to people and you want to explain how you write the simplest thing that passes the test and then improve the test, right? So you say "I want a routine that adds VAT onto a price, so I write a test that says £20+VAT is £24, and the simplest thing that can pass that test is just returning 24". Now you know and I know that the routine and its test will break if you feed it any value except £20, but we've proved we can write a routine and its test, and now we can make it more general. Or maybe we don't care and we slap a big TODO: make this actually work on there because we don't need it to work properly now, we've got other things to do first, and every price coming up as £20+VAT is a useful indicator that we still have to make other bits work. It doesn't matter. The problem is that AI slop code "generators" will just stop at that point and go "THERE LOOK IT'S DONE AND IT'S PERFECT!" and the people who believe in the usefulness of AI will just ship it.
- djmips 6mo agoI think it's interesting that they found what seems to be a real bug (should be independantly verified by experts). However I find their story mode, dramatization of how it could have happened to be poorly researched and fully in the realm of fiction. An elbow bumping a switch, the command module astronaut unable to handle the issue with only a faux nod to the fact that a reset would have cleared up the problem and it was part of their training. So it's really just building tension and storytelling to make the whole post more edgy. And yes, this is 100% AI written prose which makes it even more distasteful to me.
- retard4 6mo ago[flagged]
- jcalvinowens 6mo ago> An elbow bumping a switch [..] really just building tension and storytelling to make the whole post more edgy. A guarded switch, no less. But personally I'm trying to be more generous about this sort of thing: it is very very difficult to explain subtle bugs like this to non-technical people. If you don't give them a story for how it can actually happen, they tend to just assume it's not real. But then when you tell a nice story, all us dry aged curmudgeons tut tut about how irreverent and over the top it is :) Finding the middle ground between a dry technical analysis and dramatization can be really hard when your audience is the entire internet.
- parliament32 6mo agoBoth the article and repo[1] are slop. [1] In the repo, the "reproduce" is just a bunch of print statements about what would happen, the bug isn't actually triggered: https://github.com/juxt/agc-lgyro-lock-leak-bug/blob/c3784385bd71c66b0c3723b64d57624a84175a99/reproduce_lgyro_bug.py#L258 https://github.com/juxt/agc-lgyro-lock-leak-bug/blob/c378438...
- bsoles 6mo agoAnother CTO "published" an AI slop to get attention to their vibe-coded company that will disappear in two years. Tell me something new...
- callamdelaney 6mo agoMore likely the llm misinterpreted something and hallucinated an error. Just yesterday Claude code hallucinated itself an infinite loop.
- garaetjjte 6mo agoThis article is garbage. >The Apollo Guidance Computer (AGC) is one of the most scrutinised codebases in history. What? AGC programs were developed by relatively small team and pretty much left alone since then. Architecture is rather quirky when viewed with modern sensibilities. There's not much people that are familiar with it. Compare it to widely used software like libcurl or sqlite. Or perhaps to Super Mario Bros, which was extensively analyzed for competitive speedruns reasons. Surely that dwarfs amount of knowledge about Apollo code. >2K of erasable RAM and a 1MHz clock. The AGC’s programs were stored in 74KB of core rope How about picking a unit and staying with it? AGC has 2K words of RAM, where each word has 15 bits of usable data (physically it's 16 bits, but one bit is used for parity). Maximum amount of ROM that could be installed is 36K words. (but they switch to KB, which is not only inconsistent with previous sentence but the number is also wrong! It's 72 KiB, 73.728 KB or 67.5 KiB, 69.12 KB depending whether you include parity or not) (maximum of 64K ROM words could be addressed by architecture design, but isn't available in any real hardware) And yes, there is 1.024 MHz clock in the system, which is revelant for peripherals, but you probably want to know how fast it executed instructions. One memory cycle takes 11.71875 μs (85 1/3 kHz), and most instructions take 2 such cycles (one for operation, second for fetching next instruction) (each memory cycle is long enough for read from ROM, or read and write to RAM. ROM speed was the limiting factor, by standard of core memories it wasn't particularly fast. AGS backup computer used core for both RAM and ROM and had memory cycle time of 5 μs) (in case you are confused, "core memory" and "core rope memory" refers to quite different things!). If you think I'm nitpicking, try writing an emulator and wondering why you have to sift through all that slop. You could give the correct numbers, you know? >“My secret terror for the last six months has been leaving them on the Moon and returning to Earth alone”, Collins later wrote of the rendezvous. A dead gyro system behind the Moon, with Armstrong and Aldrin on the surface waiting for a rendezvous burn that depends on a platform he can no longer align, is exactly that scenario. A hard reset would have cleared it. But the 1202 alarms during the lunar descent had been stressful enough with Mission Control on the line and Steve Bales making a snap abort-or-continue call. Behind the Moon, alone, with a computer that was accepting commands and doing nothing, Collins would have had to make that call by himself. You know what an orbit is? That it goes around? That you could just wait for a while and speak with Mission Control? What even is this scenario? That your guidance system failed, and you for some inexplicable reason are considiering immediately leaving back for Earth right now leaving your pals behind? (with a manual burn, I guess, since guidance is dead?) You just wait for contact with Houston and tell them what happened. They pore over the program listings and find the bug. They radio you back appropiate VERB and NOUN commands for poking right values into memory. The End. And besides, spacecraft can be tracked and orbit determined from Earth, so even if the PGNCS did fail completely LM would just get necessary orbit information from Mission Control. (also in case guidance fails in either LM or CM, either one can have active role during rendezvous. And LM have extra backup system, the previously mentioned AGS) The whole thing of "we found a minor deadlock bug in AGC program, what a shock!" is bizzare. It's not a small program. If you have any experience with software, of course you know it has bugs! They iterated on the software, releasing new software for most missions, adding new features, and, fixing bugs they found. What a concept!
- merlin1de 6mo ago[flagged]
- thewonderidiot 6mo agoMike Stewart here! I led the restoration of the AGC documented on CuriousMarc's channel and co-administrate VirtualAGC. There is a lot to unpack here. First: this is indeed a real bug in the AGC software. However, it did not go unnoticed for the whole program. It was discovered during level 3 testing of SATANCHE, and late development branch of the Command Module software COMANCHE. It was assigned anomaly number L-1D-02, and was fixed between Apollo 14 and 15. There are two known surviving copies of the L-1D-02 anomaly report: * https://www.ibiblio.org/apollo/Documents/contents_of_luminary_1d.pdf#page=51 https://www.ibiblio.org/apollo/Documents/contents_of_luminar... * https://www.ibiblio.org/apollo/Documents/contents_of_luminary_1e.pdf#page=316 https://www.ibiblio.org/apollo/Documents/contents_of_luminar... The fix described in the article is partially complete, but as noted in the anomaly report there's a little bit more to it. Rather than just adding the two instructions to zero LGYRO, they restructured the code a bit and also cause it to wake up pending jobs. You can compare the relevant sections of the Apollo 14 and Apollo 15 LM software here: * Apollo 14: https://github.com/virtualagc/virtualagc/blob/master/Luminary178/IMU_MODE_SWITCHING_ROUTINES.agc#L703 https://github.com/virtualagc/virtualagc/blob/master/Luminar... * Apollo 15: https://github.com/virtualagc/virtualagc/blob/master/Luminary210/IMU_MODE_SWITCHING_ROUTINES.agc#L702 https://github.com/virtualagc/virtualagc/blob/master/Luminar... The bug would not manifest silently in the way described in the article. For starters, LGYRO is also zeroed in STARTSB2, which is executed via GOPROG2 on any major program change: https://github.com/virtualagc/virtualagc/blob/master/Luminary099/FRESH_START_AND_RESTART.agc#L570 https://github.com/virtualagc/virtualagc/blob/master/Luminar... This means that changing from any program to any other program would immediately resolve the issue. This is almost certainly a large part of why it took them so long to notice. Hitting BADEND while actively pulse-torquing is quite rare, and avoided by normal procedure. The scenario presented in the article can't happen since the act of starting P52 will zero LGYRO. Moreover, in the very specific scenarios in which the bug can be triggered and remain, it results in multiple jobs stacking up attempting to torque the gyros. Eventually the computer runs out of space for new jobs -- similar to what happened on 11 -- and a 31202 (the Apollo 12+ equivalent of 1202) is triggered. Since the issue was found before the flight of Apollo 14, a further description of how it might occur and what the recovery procedure should be was added to the Apollo 14 Program Notes: https://www.ibiblio.org/apollo/Documents/LUM159_text.pdf#page=3 https://www.ibiblio.org/apollo/Documents/LUM159_text.pdf#pag... Some other notes: > Ken Shirriff has analysed it down to individual gates I've done the bulk of the gate-level analysis. :) > the Virtual AGC project runs the software in emulation, having confirmed the recovered source byte-for-byte against the original core rope dumps. We've only been able to do that in very specific circumstances and only for subsections of assorted programs, but never for a full program. Most AGC software either comes from a program listing, from a core rope dump, or from reconstruction using changelogs and known memory bank checksums. We've disassembled all of the rope dumps into source files that assemble back into the same binary, but the comments and labels will be different from what was in the original listing. And to be extra clear: I've never had the opportunity to dump a module containing Apollo 11 software for either vehicle. Our sole source for both programs is a pair of printouts in the MIT Museum's collection. > Margaret Hamilton (as “rope mother” for LUMINARY) approved the final flight programs before they were woven into core rope memory. Jim Kernan was the rope mother for Luminary at least up through Apollo 11. Margaret was the rope mother for Comanche, the CM software, and was later promoted to lead the software division. Their positions at the time of 11 can be seen on this org chart: https://www.ibiblio.org/apollo/Documents/ApolloOrg-1969-02.pdf#page=3 https://www.ibiblio.org/apollo/Documents/ApolloOrg-1969-02.p... > Their priority scheduling saved the Apollo 11 landing when the 1202 alarms fired during descent, shedding low-priority tasks under load exactly as designed. This is a huge topic on its own, but the AGC software was not designed to shed low-priority jobs. Ironically, the lowest priority job during the landing was the landing guidance itself, with high-priority jobs being reserved for things that needed quick response like antenna movements or display updates. If the computer were to shed the lowest-priority jobs, it would shed the landing guidance. This memo contains a list of all jobs active during the landing and their priorities: https://www.ibiblio.org/apollo/Documents/CherryApollo11Exegesis.pdf https://www.ibiblio.org/apollo/Documents/CherryApollo11Exege... > For example, the ICD for the rendezvous radar specified that two 800 Hz power supplies would be frequency-locked but said nothing about phase synchronisation. The resulting phase drift made the antenna appear to dither, generating roughly 6,400 spurious interrupts per second per angle and consuming roughly 13% of the computer’s capacity during Apollo 11’s descent. This was the underlying cause of the 1202 alarms. The frequency-lock prevents phase drift, so the phase is essentially fixed once the power supplies are up. Ironically, however, the bigger issue is that one reference was 28V while the other was 15V. Initial testing on actual Apollo hardware suggests that at least for Apollo 11, this voltage difference was the key contributor rather than the phase difference: https://www.youtube.com/watch?v=dT33c70EIYk https://www.youtube.com/watch?v=dT33c70EIYk
- devnotes77 6mo ago[dead]
- thiht 6mo ago> We used Claude […] Ughhhh… I know this is probably legit here, but reading these words make me lose interest sooo fast these days…