№ 004 · Release

Mru Flight: a first prototype

Onboard software that keeps a spacecraft doing useful work as its computers fail. A small, verified Rust core, and a demo on real processes with faults injected.

What it is

Dusk showed what a shrinking quorum is worth in simulation. This is where the policy becomes flight software. It has two parts.

The decision core is a Rust crate that decides, each tick, whether to vote, compare or self-check, and keeps the health record of each replica. It has no dependencies and allocates nothing, so the same code can run on flight hardware and be checked by a model checker.

The demo runs three real replica processes and a voter built on the core. It injects faults: kill, hang, stuck, and bit flips in working memory, the way radiation would.

What the core guarantees

  • Never less than fixed TMR. While TMR can still run, both policies decide the same.
  • It stops only with nothing left. Fixed TMR stops below two replicas.
  • Only agreed results go out. Two votes, or a clean self-check on the last replica.

Unit tests check every combination of a small value domain. Kani checks every possible input, in CI, on every change.

Correct results over 20,000 ticks. Both lines match until tick 9,000. Then fixed TMR stops at 8,993 correct results. The shrinking quorum reaches 14,490.
Fig. 1 · Same seed, same faults: random upsets, replica 1 stuck from tick 4,000, replica 0 dead at tick 9,000.

One run, two designs

Fixed TMR masks the stuck replica while it has three. Once another replica dies, it is left comparing a good replica with a stuck one, and every result is rejected. The shrinking quorum retired the stuck replica two ticks after it failed, then carried on with self-check on the last good one.

Scenario, 20,000 ticksFixed TMRShrinking quorum
Random upsets only20,00020,000
Replicas die at 5,000 and 10,0009,990, halts14,989
One dies, one stuck9,990, stuck14,988

The honest cost

On one replica, a stuck fault is caught only by the periodic known-answer test, every 64 ticks. In one run, the demo delivered 24 wrong results before the test caught the fault and the system stopped. Fixed TMR would have stopped long before and delivered none.

A shorter test period trades throughput for a smaller window. That is the trade the whitepaper and Dusk put numbers on.

Small enough to fly

PlatformVoterEach replicaBinary
Linux ARM64~1.5 MB~1.5 MB~0.5 MB
Linux x86_64~2.0 MB~2.0 MB~0.5 MB
macOS, Apple silicon~1.5 MB~1.4 MB~0.5 MB

What comes next

1

F´ components around the Rust core: RedundancyManager, HealthRegistry, ReplicaHost.

2

Measurements on representative processors.

3

A hardware-in-the-loop bench with real boards and injected faults.

4

In orbit: a flight experiment on a real satellite.

5

On Earth: the same software on an unattended ocean node. Mru Field

Cite this

W. Binns, Mru Flight, version 0.1.0, 2026. github.com/mruspace/flight. See CITATION.cff.

→ Request information

Questions about this release?

A few lines are enough: the hardware, where it is, and how long it must run without a visit. We will tell you plainly whether Mru fits, including when it does not.

  • Requests go to the founder, not a sales team.
  • We reply by email. If a call helps, we suggest one.
  • Technical questions are welcome. The docs and code are public.

Or write to contact@mru.space

About: № 004 · Mru Flight prototype

Interested in

We use these details only to reply. No mailing list.