№ 004 · Release
Mru Flight: a first prototype
Onboard software that keeps a spacecraft doing useful work as its computers fail. A small, verified Rust core, and a demo on real processes with faults injected.
What it is
Dusk showed what a shrinking quorum is worth in simulation. This is where the policy becomes flight software. It has two parts.
The decision core is a Rust crate that decides, each tick, whether to vote, compare or self-check, and keeps the health record of each replica. It has no dependencies and allocates nothing, so the same code can run on flight hardware and be checked by a model checker.
The demo runs three real replica processes and a voter built on the core. It injects faults: kill, hang, stuck, and bit flips in working memory, the way radiation would.
What the core guarantees
- Never less than fixed TMR. While TMR can still run, both policies decide the same.
- It stops only with nothing left. Fixed TMR stops below two replicas.
- Only agreed results go out. Two votes, or a clean self-check on the last replica.
Unit tests check every combination of a small value domain. Kani checks every possible input, in CI, on every change.
One run, two designs
Fixed TMR masks the stuck replica while it has three. Once another replica dies, it is left comparing a good replica with a stuck one, and every result is rejected. The shrinking quorum retired the stuck replica two ticks after it failed, then carried on with self-check on the last good one.
| Scenario, 20,000 ticks | Fixed TMR | Shrinking quorum |
|---|---|---|
| Random upsets only | 20,000 | 20,000 |
| Replicas die at 5,000 and 10,000 | 9,990, halts | 14,989 |
| One dies, one stuck | 9,990, stuck | 14,988 |
The honest cost
On one replica, a stuck fault is caught only by the periodic known-answer test, every 64 ticks. In one run, the demo delivered 24 wrong results before the test caught the fault and the system stopped. Fixed TMR would have stopped long before and delivered none.
A shorter test period trades throughput for a smaller window. That is the trade the whitepaper and Dusk put numbers on.
Small enough to fly
| Platform | Voter | Each replica | Binary |
|---|---|---|---|
| Linux ARM64 | ~1.5 MB | ~1.5 MB | ~0.5 MB |
| Linux x86_64 | ~2.0 MB | ~2.0 MB | ~0.5 MB |
| macOS, Apple silicon | ~1.5 MB | ~1.4 MB | ~0.5 MB |
What comes next
F´ components around the Rust core: RedundancyManager, HealthRegistry, ReplicaHost.
Measurements on representative processors.
A hardware-in-the-loop bench with real boards and injected faults.
In orbit: a flight experiment on a real satellite.
On Earth: the same software on an unattended ocean node. Mru Field
Cite this
W. Binns, Mru Flight, version 0.1.0, 2026. github.com/mruspace/flight. See CITATION.cff.