The first program alarm came at about 33,000 feet, roughly five minutes into the powered descent, and neither man aboard the Lunar Module had seen it in a simulation. The number on the display read 1202. Over the next four minutes there were four more, a 1201 among them, and every one meant the same thing: the Apollo Guidance Computer had been handed more work than it could schedule. It did not crash. It threw out the low-priority jobs, restarted the essential ones from protected checkpoints, and kept the descent engine throttle and the landing radar alive long enough for Neil Armstrong and Buzz Aldrin to reach the Sea of Tranquility.
The reason it did not crash was Margaret Hamilton.
Hamilton led the software effort at MIT’s Instrumentation Laboratory that produced the on-board flight programs for Apollo, and went on to head the lab’s Software Engineering Division. On November 22, 2016, President Barack Obama put the Presidential Medal of Freedom around her neck in the East Room of the White House. The White House citation named the specific things she had built: asynchronous software, priority scheduling, priority displays, and human-in-the-loop decision capability.

Thirty-three thousand feet, five alarms in four minutes
The descent began routinely. Eagle undocked from Columbia, pitched over, and lit the descent engine for the braking phase the computer called P63. Aldrin keyed the DSKY, the display and keyboard unit, to bring up radar data. The machine answered with something else.
“Program alarm,” Armstrong called at 102 hours, 38 minutes, 26 seconds into the mission. Then: “It’s a 1202.” Neither astronaut knew the code by heart. In Mission Control, guidance officer Steve Bales and Jack Garman, working the back room with a handwritten list of alarm codes in front of him, knew what it meant, and Bales gave the call to continue. Capcom Charlie Duke relayed it: go on that alarm.
An MIT Instrumentation Laboratory analysis dated August 4, 1969 timed all five. Four carried the code 1202, one carried 1201. The first pair came during the braking phase; the last three arrived in a burst of roughly forty seconds during the approach phase, as Eagle dropped through 3,000 feet and then 1,000. NASA’s own account of the landing places Armstrong’s takeover of manual attitude control at around 5,000 feet, and his decision to fly past the boulder field near West Crater at around 600 feet, well after the alarms had started.
Each time, the software did the same thing. It discarded the least important work, restarted the essential jobs near where they had been interrupted, and kept the throttle and the radar updating. The crew never lost guidance. Armstrong never lost the display he needed to fly.
Why the alarms fired
The trigger was a hardware fault, not a software bug. The rendezvous radar, the instrument used to find the Command Module for the trip home rather than to land, had been left powered on as an abort precaution. Its angle sensors were driven by one 800 Hz reference while the computer used another. The two were frequency-locked but not phase-locked, so a completely stationary antenna appeared to the computer to be jittering back and forth, and every phantom movement generated a counter update that stole a memory cycle.
Don Eyles, who wrote the lunar landing guidance code at MIT, put the cost precisely. In a 2004 paper hosted by NASA’s Apollo Lunar Surface Journal, he calculated that the uncorrected radar interface consumed roughly 13 percent of the computer’s duty cycle. The descent phase already ran the processor near capacity. Thirteen percent was enough to push the executive scheduler past its limit, which is exactly what a 1202 announces: no free core sets, nowhere to put the next job.
The design decision that saved the landing
What Hamilton’s group had built into the flight software, and what mattered on July 20, 1969, was a priority-driven executive scheduler originating with MIT engineer J. Halcombe “Hal” Laning. Every job carried a priority number. When the scheduler ran out of room it did not lock up. It killed the lowest-priority jobs, freed the space, restarted the highest-priority ones from a saved state, and kept going.
The alarm was not a failure report. It was the software saying: I am overloaded, I am recovering, the work that matters is still running. Engineers who worked on the code have described the behaviour in detail on the Apollo Lunar Surface Journal’s program-alarm page, noting that the restarts deliberately did not reschedule the erroneous radar jobs that had caused the overflow in the first place. Silicon Canals, in a retrospective on the descent, makes the same point about the scheduler shedding load in real time.
Hamilton had pushed for this kind of defensive design against internal resistance. Astronauts, she was told, were trained professionals who would not make mistakes. She wrote the error checking and the asynchronous recovery in anyway. The Boston Globe reported that her team designed the software both to raise an alarm when the processor was overloaded and to keep ranking tasks by importance once that alarm had rung.

Seventy-six kilobytes and no room for waste
The machine this ran on was almost comically small. The Apollo Guidance Computer held 2,048 words of erasable magnetic-core memory and 36,864 words of fixed core rope. At fifteen data bits plus a parity bit per word, that works out to roughly 4 kilobytes of working memory and about 72 kilobytes of program storage, a little over 76 kilobytes in total. It ran at about 43,000 instructions per second and weighed 70 pounds.
Every calculation for orbital insertion, translunar coast, lunar descent, ascent, and rendezvous ran through that machine and its twin in the Command Module. Ars Technica’s technical breakdown of the AGC lays out how tight the margins were. There was nothing to spare.
And yet the computer did something no phone has been asked to do. It flew two people to another world and back, and when it was overwhelmed at the worst possible moment it recovered five times in four minutes without losing the state that kept the spacecraft flying.
Twenty-five seconds, or forty-five
The alarms were not the only drama. At about 600 feet, seeing that the automatic path was carrying Eagle toward a crater strewn with car-sized boulders, Armstrong took over the descent and flew horizontally, hunting for clear regolith. That hunt burned propellant. At around 100 feet the low-level fuel light came on. The BBC’s tally of Apollo-era numbers repeats the figure Mission Control called in real time: roughly 25 seconds of flying left when the engine shut down.
That number deserves an asterisk. Twenty-five seconds was the live estimate from a propellant gauging system that struggled with fuel sloshing in one-sixth gravity. Post-flight reconstruction put the usable remainder closer to 45 seconds. Mission rules called for an abort below 20. Either way the margin was thin enough that the difference is academic to everyone except the people who had to make the call at the time.
Twenty-five seconds. About the time it takes to boil a kettle halfway. Read a paragraph on a phone. Cross a wide city street.
If the guidance computer had gone down cold during those final minutes, Eagle would have lost descent engine throttle, inertial platform alignment, and landing radar altitude updates at once. Armstrong and Aldrin would have fired the ascent engine and left the Moon without setting foot on it.
The woman next to the stack of code
Hamilton joined MIT in 1959 and came to Apollo when the Instrumentation Laboratory won the first contract NASA issued for the programme. She rose to lead the Software Engineering Division. She is credited with coining the term “software engineering” itself, partly to insist that what her group did deserved the same seriousness as the mechanical and electrical work that built the rocket. In interviews across six decades she has returned to one idea: assume the operator will err, assume the hardware will misbehave, assume it happens at the worst possible moment, and write code that survives it.
There is a black-and-white photograph, taken at the Instrumentation Laboratory in 1969 and now held by the MIT Museum, of Hamilton standing beside a stack of program listings that reaches above her head. That stack is the source code that flew the Command Module and the Lunar Module, roughly 145,000 lines of assembly between the two vehicles. She is smiling, one hand on the pile, in a patterned dress and dark-rimmed glasses. She was 32 years old when Eagle landed. MIT’s own account of her Medal of Freedom uses the same photograph.
Every branch, every interrupt handler, every priority tag in that stack was hand-written and hand-checked, then threaded through core rope memory by workers at Raytheon’s plant, many of them women recruited for their experience in the region’s textile industry, who wove copper wire through and around tiny ferrite rings by hand. A one went through the core. A zero went around it. The program was, in a literal sense, sewn.
The rendezvous-radar switch configuration that triggered the alarms is still argued over. Some accounts blame a checklist ambiguity. Eyles concluded it was a hardware design fault already documented during Apollo 5 testing and flown anyway, on the reasoning that a known quirk was safer than an untested replacement. Discover Magazine’s account of the descent walks through how the core sets filled.
What is not argued over is the outcome. Graceful degradation under load, protected restarts, discarding non-essential work to preserve the essential: the pattern became a template. Fly-by-wire aircraft, real-time operating systems, medical device controllers, and autonomous vehicle stacks all inherit from it. Hamilton left MIT in the mid-1970s to found Higher Order Software, and later Hamilton Technologies, still working the same problem.
Fifty-seven years after the landing, Eagle’s descent stage still sits on the Sea of Tranquility, its foil weathered by decades of ultraviolet exposure and micrometeoroid strikes. The ascent stage is a different story. It was jettisoned into lunar orbit and never tracked, and NASA long assumed it had come down somewhere unrecorded on the surface. A 2021 analysis by James Meador, published in Planetary and Space Science, ran the orbital mechanics forward and found the orbit may have been stable enough that Eagle is still up there, circling. Smithsonian magazine covered the finding when it appeared. Nobody has looked hard enough with the right radar to say.
Twenty-five seconds of fuel. Thirteen percent of a duty cycle stolen by a radar nobody needed. One priority scheduler, written by a group that assumed the astronauts would make mistakes and the hardware would misbehave, on the one day it mattered most.