---
title: "Architecture status"
url: https://docs.mru.space/concepts/architecture/
description: "Where each part of Mru's six-layer design stands: what is built, where the code is, and the evidence. Only Layer 1 has code today."
---

[Docs](https://docs.mru.space/) / [Concepts](https://docs.mru.space/concepts/shrinking-quorum/) / Architecture status

# Architecture status

The whitepaper describes six layers and the parts they share. This page shows where each part stands today: what is built, where the code is, and what evidence supports it.

For the design itself, read the [architecture overview](https://mru.space/architecture/) or the [whitepaper](https://mru.space/mru-whitepaper.pdf). Section numbers on this page refer to the whitepaper.

## Status levels

Each part has one of five levels. A part moves up only with the evidence the level names.

| Level | Meaning |
| --- | --- |
| Paper | Described in the whitepaper. No code. |
| Spec | A written specification: interfaces, data formats and the properties to prove. No code. |
| Prototype | Code with tests or proofs, run on general-purpose processors. Not measured on target hardware. |
| Bench-tested | Measured on target-class processors with injected faults. Results published. |
| Deployed | Ran in orbit or at a field site. Logs published. |

## Layers 0 to 5

Only Layer 1 has code today. Layers 0 and 2 to 5 exist only in the whitepaper.

| Layer | Whitepaper | Code | Status | Evidence |
| --- | --- | --- | --- | --- |
| 0 · Survival kernel | §7 | None | Paper | None |
| 1 · Hardware consensus and health | §8 | [`quorum` crate](https://docs.mru.space/core/quorum-crate/), [demo](https://docs.mru.space/core/quorum-cli/), [F´ components](https://github.com/mruspace/flight/tree/main/fprime) | Prototype | Nine Kani proofs, 21 scenario checks and 37 F´ unit tests in CI, an F´ system test against the demo, [bench](https://docs.mru.space/core/bench/) on general-purpose processors, Dusk |
| 2 · Navigation and orientation | §9 | None | Paper | None |
| 3 · Science and knowledge triage | §10 | None | Paper | None |
| 4 · Communication | §11 | None | Paper | None |
| 5 · Bounded self-modification | §12 | None | Paper | None |

## Layer 1, part by part

Section 8 gives Layer 1 five parts. The shrinking quorum is built. The health registry is partly built. The other three are not started.

| Part | Status | What exists |
| --- | --- | --- |
| Shrinking quorum | Prototype | `quorum::mode` and `quorum::decide`: vote on three, compare on two, self-check on one. `no_std`, no allocation, builds for ARM Cortex-M. The F´ component `RedundancyManager` runs it through a C interface that Kani proves equal to the core. |
| Node health registry | Prototype, partial | `quorum::Health` counts strikes per replica. Three strikes within 200 ticks start a known-answer test, which retires or clears the replica. The F´ component `HealthRegistry` holds the record. The whitepaper's score of error rate, response time and gate use is not built. |
| Memory scrubbing | Paper | Listed as the F´ `ScrubScheduler`, not started. The demo's radiation sensor checks a memory block for bit flips. It counts upsets. It does not scrub. |
| Hardware inventory and cannibalization | Paper | Not started. `RedundancyManager` can admit a spare into a replica slot after a known-answer test; choosing when is the inventory's job. Dusk models salvaged spares in simulation only. |
| Power accountant | Paper | Listed as the F´ `PowerAccountant`, not started. `RedundancyManager` can put a replica on standby, the hook it will use. |

F´ component status from [docs/fprime-design.md](https://github.com/mruspace/flight/blob/main/docs/fprime-design.md) in mruspace/flight.

## Shared parts

These parts serve every layer.

| Part | Whitepaper | Status | What exists |
| --- | --- | --- | --- |
| Duty-cycle scheduler | §4.5 | Paper | None. The whitepaper does not yet assign it to a layer. |
| Memory tiers | §4.3 | Paper | None. |
| Degradation model and mission phases | §13 | Paper | None. Dusk models processor loss, not the power phases. |
| Simulation framework | §14 | Prototype, partial | [Dusk](https://docs.mru.space/simulation/dusk/) models processor failures, correlated failures, salvaged spares and upsets. It does not model power decay, thermal limits, memory decay or science targets. |

Section 14 names six metrics. Dusk reports useful work, wrong results and the day output ends, which is survival duration. The other five need power and science models that Dusk does not have yet. Dusk's parameters are illustrative, not calibrated. The [bench](https://docs.mru.space/core/bench/) measures useful work, survival and the Graceful Degradation Index on real processes.

## Products and research

-   **Mru Flight** runs Layer 1 on spacecraft. The F´ components `RedundancyManager`, `HealthRegistry` and `ReplicaHost` are built and tested: 37 unit tests, and a system test that gives the demo's counts on the bench schedules. They have not run on flight hardware. A launcher for [ESA's OPS-SAT](https://docs.mru.space/core/quorum-cli/#opssat) is in the repository.
-   **Mru Field** runs the same Layer 1 core on systems on Earth that are hard to reach. See [Mru Field](https://mru.space/field/).
-   **Dusk** is the first part of the §14 simulation framework.
-   **Mru 2049** is not part of the layers. It is a [browser flight simulator](https://docs.mru.space/lab/2049/) on real astronomical data.

## What comes next

In order:

-   **Measure Layer 1 on target-class processors.** The [bench](https://docs.mru.space/core/bench/) runs today on general-purpose processors. The same bench on flight-class boards moves Layer 1 to Bench-tested.
-   **Calibrate Dusk** with radiation or flight data. Its policy model is already [checked against the bench](https://docs.mru.space/core/bench/#model).
-   **Specify Layer 0.** The instruction set, the format of behavior programs, the integrity check against Tier 0, and the properties to prove. Code starts after the specification.

## Related

-   [Architecture overview](https://mru.space/architecture/): the six layers and the descent, on mru.space
-   [Shrinking quorum](https://docs.mru.space/concepts/shrinking-quorum/): the Layer 1 rule and its guarantees
-   [Dusk](https://docs.mru.space/simulation/dusk/): 10,000 missions, 1.34× the useful work of fixed TMR

Updated 11 Oct 2026 · [Edit on GitHub](https://github.com/mruspace/docs/edit/main/src/pages/concepts/architecture.astro) · [Questions? Get in touch](https://mru.space/contact/)
