⏱️ Reading time: 12 min
Margaret Hamilton died on September 30, 2026, at age 90, but the code she wrote for the Apollo Guidance Computer is still published on GitHub, line by line, exactly as it flew in 1969. That computer decided, in seconds, not to abort the Apollo 11 moon landing when two unknown alarms started sounding during the final minutes of the descent.
📑 En este artículo
- TL;DR
- What is the Apollo Guidance Computer?
- Why it matters
- How the AGC’s priority system worked
- Practical examples: the real AGC code
- Getting started: exploring the Apollo 11 code
- From the Moon to Mars: the same lesson 28 years later
- Common mistakes and lessons from Apollo 11
- Comparison: priority scheduling, from 1969 to today
- Going deeper: fixed-point arithmetic and core rope memory
- Frequently Asked Questions
- What exactly is the Apollo Guidance Computer?
- Why did the AGC trigger alarms 1202 and 1201 during Apollo 11?
- What role did Margaret Hamilton play in the AGC’s software?
- Where can I see the real AGC code?
- Did the AGC have an operating system like today’s computers?
- Why did Apollo 11 help create the term software engineering?
- References
TL;DR
- The AGC’s priority system discarded low-priority tasks and prevented the 1969 moon landing from being aborted.
- Alarms 1202 and 1201 were executive overflows, not hardware failures.
- GitHub hosts the real source code of Luminary099, the software that guided the lunar module.
- Margaret Hamilton coined the term software engineering to legitimize the discipline in the 1960s.
- Cloning chrislgarry/Apollo-11 and running grep reveals the actual routines that flew in 1969.
What is the Apollo Guidance Computer?
The Apollo Guidance Computer is the guidance computer designed by MIT’s Instrumentation Laboratory for the Apollo spacecraft, built by Raytheon and based on hand-woven core rope memory. It ran navigation, attitude control, and the lunar descent sequences with just a few thousand words of available memory.
Why it matters
In the 1960s, programming wasn’t considered real engineering: it was a manual, almost clerical task, subordinate to hardware. Hamilton led the software division of the MIT Instrumentation Lab, overseeing more than 400 people, and began calling her work software engineering so it would carry the same weight as building a rocket.
The label stuck. In 1968 NATO convened the first formal software engineering conference in Garmisch, Germany, acknowledging that writing code for critical systems required processes and specifications, not just individual talent. Hamilton spent two decades at that intersection of mathematics, meteorology (she had earlier worked with Edward Lorenz, the chaos theory pioneer), and critical systems programming.
Recognition came late, but it came: in 2016 President Barack Obama awarded her the Presidential Medal of Freedom, citing how her software architecture led to giant leaps for mankind. She died at 90, the author of more than 130 technical publications.
How the AGC’s priority system worked
The AGC ran the DSKY (Display and Keyboard) console on a simple principle: any low-level task had to be able to yield immediately if the astronaut pressed a key. That priority of human over software ran in parallel to the mechanism that, hours later, saved the moon landing.
The Executive: the first priority scheduling
The Apollo Guidance Computer ran its own operating system, called Executive, which allocated the processor among different tasks using priority numbers: the lower the number, the more urgent the task. Each task needed a block of memory called a core set to store its temporary variables, and the AGC only had a few of these blocks available at any one time.
If all the core sets were occupied and a higher-priority task came in, the Executive didn’t wait: it canceled the lower-priority task that was running, took its core set away, and started the new one. That design decision, discard rather than collapse, is the basis of what we now call priority scheduling in a real-time system.
flowchart TD
A["New task in queue"] --> B{"Core set available"}
B -- "Yes" --> C["Run the task"]
B -- "No" --> D{"Priority higher than active task"}
D -- "Yes" --> E["Discard the lower-priority task"]
E --> C
D -- "No" --> F["Trigger alarm 1202 and restart the Executive"]
F --> G["Restore only guidance and navigation"]
Alarm 1202: when the radar lied
The real cause wasn’t a programming error: it was a switch. The crew left the rendezvous radar, meant for the return phase, turned on during the entire descent. That radar kept sending the AGC extra electrical pulses, requesting compute cycles that weren’t planned in any registered task.
The Executive tried to make room for those requests and ran out of free core sets for the real tasks. That’s when alarms 1202 and then 1201 appeared, meaning executive overflow with no cores available. The system didn’t freeze: it discarded lower-priority tasks, like the display update, and kept guidance, navigation, and control, the three it actually needed to avoid crashing.
At Mission Control, guidance officer Steve Bales and engineer Jack Garman recognized the alarm within seconds thanks to a list that Hamilton’s own team had prepared after reproducing similar failures in earlier simulations. They gave a GO, and Neil Armstrong and Buzz Aldrin continued the descent.
sequenceDiagram
participant R as Rendezvous radar
participant E as AGC Executive
participant G as Guidance task
R->>E: Unplanned interrupts
E->>E: Task queue saturates
E-->>G: Alarm 1202, partial restart
Note over E,G: Only the highest-priority tasks survive
Practical examples: the real AGC code
The code was never lost. Today anyone can clone it and read exactly what Apollo 11 executed.
The original assembler was called YUL, and today a reimplementation called yaYUL exists, part of the Virtual AGC project, which recompiles that same source code and produces binaries equivalent to the ones that flew in 1969. That verification is the proof that the text on GitHub isn’t an approximate reconstruction.
Most of the code uses instructions like TC (transfer control), CCS (count, compare and skip), and DXCH (double exchange). A fuel check looked something like this, in a simplified version inspired by the real structure of the Executive:
CCS FUEL_LOW_FLAG # Compares the flag and decides the branch
TC ALARM_JOB # If negative, trigger the alarm
TC RETURN_TO_WAITLIST
ALARM_JOB TC PRIORITY_INSERT
CA LOW_PRIORITY
TC EXECUTIVE
This snippet doesn’t run on its own, it needs the rest of the program and the emulator, but it represents the real pattern: compare, decide, and hand the decision to the Executive instead of to an isolated if.
The file that actually ignites the lunar ascent engine is literally called BURN_BABY_BURN--MASTER_IGNITION_ROUTINE.agc, and the routine that handles the control panel’s buttons and lights is called PINBALL_GAME_BUTTONS_AND_LIGHTS. Hamilton’s programmers named their routines with that informal tone even in code that literally sent three people to the Moon.
Getting started: exploring the Apollo 11 code
Cloning the repository only requires having git installed. On Linux or macOS, run these commands in a terminal:
git clone https://github.com/chrislgarry/Apollo-11.git
cd Apollo-11
grep -rln "BURN_BABY_BURN" .
The expected output is a single line with the path to the actual file:
./Luminary099/BURN_BABY_BURN--MASTER_IGNITION_ROUTINE.agc
On Windows, the same commands work the same way inside Git Bash or WSL. To locate the routines behind the moon landing alarm, run:
grep -rln "1202" . | head -5
This returns the lunar module files that mention the alarm, including the Executive’s own routines that trigger it.
💡 Tip: if grep finds nothing, make sure you’re standing inside the cloned Apollo-11 folder; the repository organizes the code by mission.
From the Moon to Mars: the same lesson 28 years later
The logic of discarding rather than collapsing was put to the test again in 1997, when the Mars Pathfinder rover started rebooting on its own on the Martian surface. The cause was almost the opposite of a priority overflow: a low-priority task held onto a shared resource and blocked a high-priority one, a problem called priority inversion.
NASA’s team, using VxWorks, fixed the behavior remotely by enabling priority inheritance, a technique that already existed in theory but that Pathfinder made famous in practice. The parallel with Apollo 11 is direct: both missions survived because someone, before launch, had already designed a mechanism for the priority system to correct itself.
Today that philosophy shows up in aerospace software standards like DO-178C, which requires classifying each function by how much damage its failure would cause, and in any real-time operating system. The AGC didn’t invent the idea of priorities, but it was the first mission-critical human system to prove, with three astronauts on board, that the idea worked.
Common mistakes and lessons from Apollo 11
- Confusing an alarm with a failure: 1202 and 1201 were overflows of a task counter, not physical damage to the computer.
- Blaming only the software: the root cause was a human procedure, the rendezvous radar switch, not a bug in the guidance code.
- Assuming Hamilton worked alone: she led two teams with more than 400 people combined across the lunar module and command module.
- Thinking more memory solves overload: the AGC had only 2,048 words of erasable memory and solved the saturation with a discard policy, not more hardware.
Comparison: priority scheduling, from 1969 to today
The Executive’s fixed-priority scheme is still alive, with variations, in today’s real-time operating systems.
| System | Scheduling type | What happens when it saturates |
|---|---|---|
| AGC Executive (1969) | Cooperative fixed priority | Discards lower-priority tasks and restarts |
| VxWorks | Preemptive fixed priority, 256 levels | The highest-priority task always preempts the current one |
| FreeRTOS | Preemptive fixed priority | Same as VxWorks, designed for microcontrollers |
| Linux (CFS) | Fair virtual time, no fixed priorities | Distributes CPU proportionally among processes |
Going deeper: fixed-point arithmetic and core rope memory
The AGC had no floating-point hardware: every physical value (speed, altitude, angle) was represented as an integer scaled to a fixed range, and the programmer decided the scale factor by hand so it wouldn’t overflow or lose precision. That fixed-point discipline forced engineers to reason through the physics of the flight before writing a single instruction.
A subtraction of orbital positions, for example, was written by reserving in advance how many bits represented the integer part and how many the fraction, something like this:
# Scale: 1 unit = 2^(-7) nautical miles
DAS CURRENT_POSITION # Double-precision subtraction
DXCH TARGET_POSITION # Swap the result
The output wasn’t a floating-point number like 1500.75: it was a scaled integer that the programmer had to interpret manually against the program’s scale factor table, documented on paper alongside the code.
The final program didn’t live on a disk: it was woven. The fixed 36,864-word memory was manufactured as a core rope memory, a set of magnetic cores threaded by hand with copper wires following the program’s exact binary code. Changing an instruction after the memory was woven meant starting a new rope, a process that took weeks, so every software version went through months of review before reaching the Raytheon factory.
Hamilton defended something unpopular at the time: specifying interfaces with the same formal rigor as the code, so that one astronaut’s error couldn’t corrupt another program’s data mid-flight. Years before the moon landing, she had already asked for that kind of error to be shielded against after watching her own daughter accidentally run a prelaunch program during a simulation; NASA responded that trained astronauts don’t make mistakes. The proposal didn’t make it in time, and a similar failure contributed to the overload that triggered the Apollo 11 alarms.
Your next step: clone chrislgarry/Apollo-11 and run grep -rn "P01" to find the prelaunch routine that nearly repeated the error Hamilton had warned about before the flight.
Frequently Asked Questions
What exactly is the Apollo Guidance Computer?
It’s the digital computer that guided both the command module and the lunar module of the Apollo program, designed by MIT between 1961 and 1969 and built by Raytheon using integrated circuits, cutting-edge for the time.
Why did the AGC trigger alarms 1202 and 1201 during Apollo 11?
Because the rendezvous radar, mistakenly left on during the descent, saturated the Executive with unplanned compute requests until it ran out of memory for new tasks. The system responded by discarding the least critical tasks, not by shutting down.
What role did Margaret Hamilton play in the AGC’s software?
She directed the software engineering division of the MIT Instrumentation Lab, with more than 400 people working on the guidance, navigation, and control code for the lunar module and command module.
Where can I see the real AGC code?
In the public repository chrislgarry/Apollo-11 on GitHub, which gathers the scanned listings of Luminary099 and Comanche055 exactly as they were printed in 1969.
Did the AGC have an operating system like today’s computers?
It had its own, called Executive, with a priority scheduler and a deferred task list, but no virtual memory, no disk, and only about two kilowords of working memory.
Why did Apollo 11 help create the term software engineering?
Because Hamilton needed her discipline to be taken as seriously as the rocket’s mechanical or electrical engineering, and the AGC’s success during the moon landing emergency publicly proved that software could be a matter of life and death.
References
- MIT News: official obituary of Margaret Hamilton published by MIT.
- GitHub: chrislgarry/Apollo-11: scanned source code of Luminary099 and Colossus237.
- Wikipedia: technical specifications of the AGC, the Apollo guidance computer.
- Wikipedia: biography and career of Margaret Hamilton.
📱 Like this content? Follow @programacion on Telegram for daily tech content in Spanish: quick summaries, fresh content every day. @programacion
Featured image: Foto de Trnava University en Unsplash
Did it work for you? Got a different error? Say so below: questions get answered and help the next reader.
Leave a comment
0 Comments