Skip to content

Ariane 5 Rocket

What happened

On 4 June 1996, the first Ariane 5 launcher (Flight 501) lifted off from Kourou, French Guiana. The flight was normal for about 36 seconds. Then, at H0 + 36.7 s, the backup inertial reference system (SRI) shut itself down, and about 0.05 seconds later the active SRI failed for exactly the same reason. With both units dead, the on-board computer had no valid attitude data. It read a diagnostic bit pattern from the failed SRI as if it were flight data, "commanded the booster nozzles, and somewhat later the main engine nozzle also, to make a large correction for an attitude deviation that had not occurred." The rocket swung to an angle of attack over 20 degrees, aerodynamic loads tore the boosters off the core stage at H0 + 39 s, and the self-destruct system fired at about 4 km altitude. The launcher and its four Cluster science satellites were lost.

The engineering failure

The root cause was a software error in the SRI, whose design was carried over almost unchanged from Ariane 4.

  • An unprotected numeric conversion. A routine converted a 64-bit floating-point value called BH (Horizontal Bias, related to the horizontal velocity sensed by the platform) into a 16-bit signed integer. On Ariane 5 the value was far too large to fit, which raised an Operand Error. Seven such conversions had been reviewed during design; four were given protection and three, including BH, were left unprotected because engineers reasoned the values were "either physically limited or that there was a large margin of safety." That reasoning was correct for Ariane 4 and wrong for Ariane 5.

  • Code that had no job to do. The failing routine was the platform alignment function, which only produces meaningful results before lift-off. On Ariane 4 it was deliberately left running for 50 seconds after flight mode began so that a late countdown hold could be recovered quickly. Ariane 5 had no such requirement, but the behavior was kept "for commonality reasons," so the function was still running about 40 seconds into flight.

  • A different trajectory. Ariane 5 accelerates harder than Ariane 4 and builds horizontal velocity roughly five times faster. Within that 40-second window BH exceeded a limit that Ariane 4 could never have reached. Yet the SRI specification did not include Ariane 5 trajectory data, and no test ever ran the SRI against the Ariane 5 flight profile. The Board noted that a ground test injecting simulated accelerometer signals "would have exposed the failure mechanism."

  • Exception handling designed for hardware faults. The specification said that on any exception the SRI should log the fault and shut its processor down. That policy assumes failures are random hardware faults that a backup can absorb. This was a systematic software fault, and because both SRIs ran identical software, the "backup" failed first. In the Board's words, "this resulted in the switch-off of two still healthy critical units of equipment."

  • Test coverage that stopped short. The full-system simulation facility used software models in place of real SRIs, on the grounds that the SRI was already qualified at equipment level and had flown on Ariane 4. The Board judged those arguments technically valid but concluded that "had the system been included, the failure could have been detected."

The Inquiry Board summarized the cause as "specification and design errors in the software of the inertial reference system," compounded by reviews and tests that "did not include adequate analysis and testing of the inertial reference system or of the complete flight control system."

Lessons

The Board's recommendations read like a checklist for any safety-critical software project: no function should run in flight unless it is needed; sensors should never stop sending best-effort data; every implicit assumption about the range of a variable should be written down and checked against the real operating environment; trajectory (i.e. real-world input) data belong in the specification and the test plan; and software should be "assumed to be faulty until applying the currently accepted best practice methods can demonstrate that it is correct."

Source

Lions, J. L. (Chairman), ARIANE 5 Flight 501 Failure: Report by the Inquiry Board, ESA/CNES, Paris, 19 July 1996. Archived copy at the Internet Archive (retrieved 7 September 2026).