---
title: "Same hardware, 1.34× the useful work"
url: https://mru.space/research/dusk-results/
description: "10,000 simulated missions on processors that are never repaired. A shrinking quorum delivers 1.34× the useful work of fixed TMR, never less on any mission."
---

[Research](https://mru.space/research/) / [Results](https://mru.space/research/?kind=results) / № 002

№ 002 · Results

# Same hardware, 1.34× the useful work

Dusk simulates 10,000 missions on processors that fail and are never repaired. A shrinking quorum delivered a third more useful work than fixed triple redundancy, and never less on any single mission.

By **Will Binns** Published **29 Sep 2026** Updated **7 Oct 2026** 12 min read Code [**mruspace/dusk**](https://github.com/mruspace/dusk) Interactive [**dusk.mru.space**](https://dusk.mru.space/)

## The question

Classic triple modular redundancy has a fixed threshold. Three processors vote. Two can still detect a disagreement. One cannot outvote anything, so the system stops.

On a mission with no repairs and no ground team in reach, that throws away the last processor's whole remaining life. The whitepaper proposes a shrinking quorum instead: vote while three are alive, compare while two are, self-check on one. Falling back from TMR to simplex is not new. The question is what it is worth when no ground team can command it.

Note 1:TMR is triple modular redundancy. Lyons and Vanderkulk described it in 1962, building on von Neumann (1956).

## The model

Each mission is a day-by-day fault-injection run. Processors die on a Weibull lifetime. Deaths can be correlated, as a shared thermal or power fault would be. Upsets corrupt a day's result at the rate that gets past EDAC and scrubbing.

Every policy runs against the same fault history and the same upsets. Any difference between policies is the policy.

Note 2:Shape 1.5 and a 125-year scale give a median processor life of about 98 years. The parameters are illustrative, not calibrated.

## The result

Mean useful years per mission, over 10,000 missions:

Fixed TMR 99.0

One computer, spares 83.1

Mru shrinking quorum 132.6

That is 1.34× the useful work of fixed TMR (95% CI 1.33× to 1.35×). It is never less on any single mission, because the two policies are identical until TMR stops.

Note 3:Intervals are from a paired bootstrap: 2,000 resamples of whole missions.

![Useful output over the mission. The shrinking quorum stays above fixed TMR after year 50 and keeps working long after TMR has stopped.](https://mru.space/charts/dusk-output-light.svg)

Fig. 1 · Useful output over the mission, mean of 10,000 missions. The shaded area is total useful work. Drawn by `dusk --bin charts`; nothing by hand.

## The cost

A lone self-checking processor misses a few of its upsets. Those become wrong results that nobody knew were bad. Fixed TMR never produces them, because it never lives long enough.

So the honest comparison is a price. Fixed TMR comes out ahead only if one wrong result costs more than **136 years** of useful work (95% CI 131 to 142). Against one computer with spares, the shrinking quorum gives 1.6× the useful work and 59% fewer wrong results.

Note 4:The 59% compares against standby simplex, one computer that swaps in spares. Against TMR, the quorum has more wrong results, late in life.

## When the ground can help

Real spacecraft do not run TMR alone. When a string fails, a ground team commands a fallback by hand. Dusk adds that team as a baseline, for as long as support lasts.

| Ground support ends | Gain over TMR |
| --- | --- |
| At launch | 1.34× |
| After 25 years | 1.31× |
| After 50 years | 1.25× |
| After 100 years | 1.11× |
| Never | 1.00× |

Answer time barely matters. A fallback a day or six months late gives the same result to two decimals. What matters is whether anyone is still there.

Note 5:Voyager has had 49 years of support so far. Its power falls about 4 watts a year.

## How sure are we

The sweep varies every parameter the model cannot pin down. Across every row, the shrinking quorum returned **1.11× to 1.68×** the useful work of fixed TMR. The gain is largest with early, random failures and smallest with sharp wear-out, where all three processors die close together.

Note 6:Run it yourself: `cargo run --release -- --sweep`, about 30 seconds on a laptop.

![Sensitivity of the gain over fixed TMR to each uncertain parameter. Every row stays above 1.1 times.](https://mru.space/charts/dusk-sensitivity-light.svg)

Fig. 2 · Sensitivity. 10,000 missions per row, seed 1.

## What this does not claim

The parameters are plausible orders of magnitude, not values fitted to flight data. The claim is the shape of the trade, and the sweep shows where it holds. Power, thermal limits and duty cycling are not modelled. The ground team in the baseline is perfect, which flatters the ground.

Cite this

```
@software{binns2026dusk,
  author = {Binns, Will},
  title  = {dusk: A Monte Carlo of Redundancy Policies
            on Hardware That Only Ever Decays},
  year   = {2026},
  url    = {https://github.com/mruspace/dusk}
}
```

Sources

1.  R. E. Lyons and W. Vanderkulk, “The Use of Triple-Modular Redundancy to Improve Computer Reliability,” IBM J. Res. Dev., 1962.
2.  W. Binns, “Mru: A Fault-Tolerant Operating System for Thousand-Year Autonomous Operation,” 2026. doi:10.5281/zenodo.20579438
3.  J. F. Meyer, “On Evaluating the Performability of Degradable Computing Systems,” IEEE Trans. Computers, 1980.
4.  B. Efron, “Bootstrap Methods: Another Look at the Jackknife,” Annals of Statistics, 1979.

[Previous · № 001 The whitepaper](https://zenodo.org/records/20579438) [Next · № 003 Mru 2049: the sense of scale](https://docs.mru.space/lab/2049/)
