Failure Lab · offline editionOne file · no network · nothing saved or sent

1996

Flight software

Ariane 5 Flight 501

You are on the inertial-reference software team with an 80% processor budget. Seven conversions could overflow. Ariane 4 flight evidence says which ones matter. Choose what to protect, and whether proven behaviour keeps running after lift-off.

Prepared with AI assistance. Published by CyberNative AI LLC. Corrections: hello@cybernative.ai.

Quickstart for a 25-minute team session

  1. Before
    Put the browser in full screen (F11, or Ctrl+Cmd+F on a Mac). Choose Run with a group, pick a timer length, then Start.
  2. 0–3 min
    Read the briefing aloud: role, constraints, evidence.
  3. 3–13
    For each decision: read the prompt, discuss, take an optional show of hands, record the group's choice. ← Back reopens the previous decision.
  4. 13–15
    Run the model on the group's choices.
  5. 15–23
    Compare with the record and work through the discussion questions. Each one cites a numbered source.
  6. 23–25
    Open the one-page summary, write the team's actions on it, then print it or save it as a PDF.
Decisions
A protection budget and one heritage setting
Record
ESA/CNES Inquiry Board report, 19 July 1996

Sources

Source registerESA/CNES Inquiry Board report, 19 July 1996 · tags S1–S6

Primary document: ESA/CNES Inquiry Board, Ariane 501 Inquiry Board report, 19 July 1996.

Both were opened through native web search on 2026-10-03. Page references below use the PDF's physical pages, counting its first page as 1.

Passage register

S1 — §2.1, PDF p5: BH is an alignment result related to horizontal velocity, rather than velocity itself. Its 64-bit float to 16-bit signed-integer conversion overflowed. This section also states that alignment served no purpose after lift-off.

S2 — §2.2, PDF p6: the workload target was 80%; seven variables were at risk. Four received protection; three remained unprotected, including BH. The report does not supply per-variable costs or six other names.

S3 — §2.2, PDF p6; §3.1(o), PDF p13: safety reasoning was faulty for BH. No evidence established use of trajectory data in that analysis. Ariane 4's early trajectory kept this variable within its limit.

S4 — §3.1(e–j), PDF pp11–12: backup failed at H0+36.7s; active failed approximately 0.05s later. Diagnostic information became flight input; nozzle commands caused disintegration at H0+39s and automatic destruction. §2.1, PDF p5, also places the backup failure in the preceding 72ms data cycle. Do not equate the two timing descriptions.

S5 — §4 R1, PDF p14: the Board recommended switching off the alignment function immediately after lift-off.

S6 — §2.2, PDF p7; §3.1(m), PDF p12: continued alignment supported late-hold restart on Ariane 4; Ariane 5 retained it for commonality. Verified in the public PDF on 2026-10-03.

Implementation limits

Label costs, selectable anonymous variables, curves, magnitudes, playback scale, and counterfactual outcomes illustrative. Counterfactual outcomes must say only that this modelled failure is avoided, without promising a full mission outcome. Use H0 labels for sourced event times.

The HTML quotes 21 source words total: the two short S2 excerpts (8 words) and the S5 recommendation (13 words). Keep source locators linked to the report and use concise paraphrases elsewhere.

Model-only choices

The HTML uses anonymous variables A–F plus BH, a 62% illustrative base load, illustrative protection costs, and illustrative Ariane 4/Ariane 5 peaks. These values do not come from the report. The requested “protect BH instead of E” pass case conflicts with the original illustrative E peaks of 110%/115% and the rule that any unprotected peak above 100% fails. To keep that specified test coherent, the final model uses 96%/98% for E. This is an explicit model adjustment, not a historical claim.

The report places the backup failure at H0 + 36.7 s, the active-unit failure about 0.05 s later, and also says the backup had failed during the preceding 72 ms data cycle. The UI preserves these as separate report statements; it does not equate the two intervals.

The initial state is undecided (no protections, alignment on); the as-flown mapping is available through its explicit load button and revealed after flight. Source S6 supplies the alignment trade rationale.

Licence

MIT licence and noticeCovers the original Failure Lab software and documentation only. Third-party excerpts and linked records are excluded.

The MIT licence applies only to the original software and documentation created for Failure Lab by CyberNative AI LLC. Third-party material, including attributed excerpts reproduced in these files and linked inquiry, regulatory and postmortem records, is excluded from that grant and remains subject to its respective rights. The source registers identify the publishers and cited passages. No source PDF or complete third-party record is bundled.

MIT License

Copyright (c) 2026 CyberNative AI LLC

Permission is hereby granted, free of charge, to any person obtaining a copy
of this software and associated documentation files (the "Software"), to deal
in the Software without restriction, including without limitation the rights
to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
copies of the Software, and to permit persons to whom the Software is
furnished to do so, subject to the following conditions:

The above copyright notice and this permission notice shall be included in all
copies or substantial portions of the Software.

THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
SOFTWARE.