Flight 501 · decision simulation
Choose what to protect
You are on the 1990s inertial-reference software team. Keep processor load under 80% (S2), using Ariane 4 flight evidence to decide which conversions need protection.
One protection budget. One separate choice about what keeps running after lift-off.
01 · choose
Spend the workload budget
Select the conversions to protect. All variable labels, costs and peak magnitudes are illustrative unless a source is linked.
02 · fly
Run the profiles in order
Ariane 4 flights using this type of inertial-reference system did not have the BH limit failure; the report links this to their early trajectory (S3). Profile peaks shown here are illustrative.
Choose your protections, then fly.
Run Ariane 4 first. Ariane 5 unlocks after its result.
Illustrative playback window · 4×
White dots mark reported Ariane 501 events (S4); *the endpoint and playback scale are illustrative.
Sequence text is revealed in source order; the display pacing is illustrative.
03 · reveal
What the report found
These findings describe the historical flight; the choices above are a simplified counterfactual model.
- The report says protection was added to “four of the variables,” while “three of the variables” remained unprotected, BH among them (S2). It found no evidence trajectory data were used to analyze the unprotected variables (S3). In this model the as-flown choice is A, B, C and E; A–F are anonymous labels, so that mapping is illustrative.
- The backup unit's failure was followed about 0.05 seconds later by the active unit's same failure, despite identical hardware and software (S4).
- The alignment function had no purpose after lift-off on Ariane 5 (S1), and the Board's first recommendation was: “Switch off the alignment function of the inertial reference system immediately after lift-off.” (S5)
Source passages
S1–S6 refer to the ESA/CNES Inquiry Board report, 19 July 1996. Section and physical PDF page locators are included for direct checking.
- S1 · §2.1, PDF p. 5. BH was an alignment result related to horizontal velocity; its conversion from 64-bit floating point to signed 16-bit integer caused an Operand Error. The alignment function served no purpose after lift-off. Report textPDF p. 5
- S2 · §2.2, PDF p. 6. The workload target was 80%; seven variables were considered at risk; protection covered four and three, including BH, remained unprotected. Costs and anonymous A–F labels are not from the report. Report textPDF p. 6
- S3 · §2.2, PDF p. 6; §3.1(o), PDF p. 13. The report found faulty reasoning about BH and no evidence Ariane 5 trajectory data were used; Ariane 4's early trajectory kept BH within its limit. Report textPDF p. 13
- S4 · §3.1(e–j), PDF pp. 11–12; §2.1, PDF p. 5. The backup failed at H0 + 36.7 s; the active unit failed approximately 0.05 s later; diagnostic data was treated as flight data; disintegration occurred at H0 + 39 s, followed by automatic destruction. The separate 72 ms data-cycle wording is in §2.1. Report textPDF p. 11
- S5 · §4, Recommendation 1, PDF p. 14. The Board recommended turning the alignment function off immediately after lift-off. Report textPDF p. 14
- S6 · §2.2, PDF p. 7; §3.1(m), PDF p. 12. Continued alignment supported late-hold restart on Ariane 4; the requirement was retained for commonality. Report textPDF p. 7PDF p. 12
Ariane 4/Ariane 5 model peaks, costs, load points, timeline scale and counterfactual outcomes are illustrative. The report describes the historical failure, not these modeled outcomes.