Prior art and related work
The shrinking quorum builds on decades of work in fault-tolerant computing. Stepping down from three replicas to two to one is not new. This page lists the work Mru draws on and how Mru relates to each.
TMR and its origins
von Neumann, 1956. Shows that reliable computation can be built from unreliable components through redundancy. Mru: the shrinking quorum is one use of that idea, with the redundancy shrinking as parts fail.
J. von Neumann, "Probabilistic Logics and the Synthesis of Reliable Organisms from Unreliable Components," in C. E. Shannon and J. McCarthy (eds.), Automata Studies, Princeton University Press, 1956, pp. 43-98.
Lyons and Vanderkulk, 1962. Triple modular redundancy with a majority vote, applied to reliability. Mru: fixed TMR in this form is the baseline on these pages. With three replicas, the shrinking quorum votes the same way.
R. E. Lyons and W. Vanderkulk, "The Use of Triple-Modular Redundancy to Improve Computer Reliability," IBM Journal of Research and Development, 6(2):200-209, 1962. doi:10.1147/rd.62.0200
Degradable systems and performability
Meyer, 1980. Defines performability, a measure that combines performance and reliability for systems that degrade. Mru: Dusk's figure of merit, useful work summed over the whole decline, is a measure of this kind. The whitepaper cites Meyer for it.
J. F. Meyer, "On Evaluating the Performability of Degradable Computing Systems," IEEE Transactions on Computers, C-29(8):720-731, 1980. doi:10.1109/TC.1980.1675654
Byzantine agreement
Lamport, Shostak and Pease, 1982. Sets the limits of agreement when faulty components can give conflicting information to different parts of a system. Mru: the shrinking quorum assumes replicas that are damaged, not malicious. It does not solve input agreement: all replicas must already have the same input. See Open questions.
L. Lamport, R. Shostak and M. Pease, "The Byzantine Generals Problem," ACM Transactions on Programming Languages and Systems, 4(3):382-401, 1982. doi:10.1145/357172.357176
Redundancy management on the Space Shuttle
Sklaroff, 1976. The Shuttle's general-purpose computers ran as a redundant set. Voting detected and identified two failures. The remaining two used comparison and self-test to tolerate a third. Mru: degradation from voting to comparison to self-test is not new. Mru does it with no ground team.
J. R. Sklaroff, "Redundancy Management Technique for Space Shuttle Computers," IBM Journal of Research and Development, 20(1):20-28, 1976. doi:10.1147/rd.201.0020
Spector and Gifford, 1984. A case study of the Shuttle's primary computer system. Mru: a reference for how a flown redundant system was designed and managed.
A. Spector and D. Gifford, "The Space Shuttle Primary Computer System," Communications of the ACM, 27(9):872-900, 1984. doi:10.1145/358234.358246
Autonomous fault protection on deep-space missions
Avizienis et al., 1971 (STAR). JPL's self-testing and repairing computer, designed for outer-planet spacecraft. Standby spares replaced failed units by automatic recovery. Mru: autonomous recovery in deep space is decades old. The shrinking quorum steps down instead of relying on spares. The F´
RedundancyManagercan admit a spare after a known-answer test.A. Avizienis, G. C. Gilley, F. P. Mathur, D. A. Rennels, J. A. Rohr and D. K. Rubin, "The STAR (Self-Testing And Repairing) Computer: An Investigation of the Theory and Practice of Fault-Tolerant Computer Design," IEEE Transactions on Computers, C-20(11):1312-1321, 1971. doi:10.1109/T-C.1971.223133
Rasmussen, 2008. Fundamentals of fault-tolerant design for spacecraft guidance, navigation and control, from JPL. Mru: the shrinking quorum is one autonomous response to processor loss. It is not a full fault-protection system and does not replace one.
R. D. Rasmussen, "GN&C Fault Protection Fundamentals," 31st Annual AAS Guidance and Control Conference, Breckenridge, CO, 2008. Jet Propulsion Laboratory. Companion presentation: NASA NTRS 20100020171.
What Mru adds
- Autonomy with no ground team. The step-down from three replicas to one runs on board, with no command from the ground.
- A small decision core with proofs. The quorum crate is
no_stdwith no allocation. Kani proves four properties ofdecide()for every set of three replies. See Kani proofs for the scope of each. - Published trade data. Dusk and the bench publish what the step-down buys in useful work and what it costs in wrong results, with the code to reproduce them.
Updated 11 Oct 2026 · Edit on GitHub · Questions? Get in touch

