The quorum program
Three replica processes, a voter built on the core, fault injection, and enforced resource limits. It reports what it delivered and what that cost.
Synopsis
quorum [--policy shrink|tmr] [--ticks N] [--seed S] [--upset-rate R] [--common-mode C] [--kat-period P] [--fault kill|corrupt|stuck|hang|sensor:I@T] ... [--faults-file F] [--max-memory-mb M] [--max-cpu-seconds S] [--cpu-percent P] [--max-seconds S] [--reply-timeout-ms T] [--sensor-mb M] [--sensor-every N] [--log file.csv] [--progress-every N] [--summary file.txt]
An unknown option prints this list. Every run is reproducible from its seed.
Run settings
| Option | Default | Meaning |
|---|---|---|
| --policy | shrink | shrink or tmr |
| --ticks | 10000 | Results to compute |
| --seed | 1 | Seed for random upsets and where they land |
| --upset-rate | 0 | Chance per replica per tick of a bit flip in working memory |
| --common-mode | 0.05 | Share of single-replica upsets that hit both self-check runs alike |
| --kat-period | 64 | Ticks between known-answer tests on the last replica |
Faults
Schedule a fault as kind:replica@tick. Repeat the option, or read a schedule with --faults-file.
| Kind | What happens |
|---|---|
| kill | The replica process dies. |
| hang | The replica stops answering. The voter drops it after the reply timeout. |
| stuck | The replica returns the same wrong value from then on. |
| corrupt | One bit flips in the replica's working memory during a computation. |
| sensor | A flip in the radiation-sensor block, to test logging and repair. Needs --sensor-mb. The replica number is ignored. |
Limits
Safe on shared hardware. Each process enforces its own memory and CPU-time limits. The voter enforces the CPU share and the run time.
| Option | Default | Meaning |
|---|---|---|
| --max-memory-mb | 128 | Memory limit per process (Linux only) |
| --max-cpu-seconds | off | CPU-time limit per process |
| --cpu-percent | off | Cap on the voter's CPU share |
| --max-seconds | off | Maximum run time |
| --reply-timeout-ms | 2000 | Drop a replica that does not answer in time |
Radiation sensor
--sensor-mb M holds M MB of memory in a known pattern and checks it every --sensor-every ticks (default 1000). Every flipped bit is logged with its location, then repaired. On flight hardware, this measures the real upset rate. It must leave at least 32 MB under --max-memory-mb.
Output
--log file.csv writes every event: stuck, hang, lost, retired, cleared, killed, detected, wrong, stopped, halted and sensor flips. --progress-every N adds running totals. --summary file.txt writes the final report for downlink.
quorum --policy shrink ... useful=14490 detected=10 wrong=0 halted_at=neverOn OPS-SAT
opssat/run.sh starts, checks and stops a run with all limits set. Tagged releases ship each static Linux binary (three ARM, one x86_64) with the launcher, a sample fault schedule and the operations note.
Updated 7 Oct 2026 · Source: demo/src/main.rs · Edit on GitHub · Questions? Request information