Core runtime › quorum CLI

The quorum program

Three replica processes, a voter built on the core, fault injection, and enforced resource limits. It reports what it delivered and what that cost.

Synopsis

quorum [--policy shrink|tmr] [--ticks N] [--seed S]
   [--upset-rate R] [--common-mode C] [--kat-period P]
   [--fault kill|corrupt|stuck|hang|sensor:I@T] ... [--faults-file F]
   [--max-memory-mb M] [--max-cpu-seconds S] [--cpu-percent P]
   [--max-seconds S] [--reply-timeout-ms T]
   [--sensor-mb M] [--sensor-every N]
   [--log file.csv] [--progress-every N] [--summary file.txt]

An unknown option prints this list. Every run is reproducible from its seed.

Run settings

OptionDefaultMeaning
--policyshrinkshrink or tmr
--ticks10000Results to compute
--seed1Seed for random upsets and where they land
--upset-rate0Chance per replica per tick of a bit flip in working memory
--common-mode0.05Share of single-replica upsets that hit both self-check runs alike
--kat-period64Ticks between known-answer tests on the last replica

Faults

Schedule a fault as kind:replica@tick. Repeat the option, or read a schedule with --faults-file.

KindWhat happens
killThe replica process dies.
hangThe replica stops answering. The voter drops it after the reply timeout.
stuckThe replica returns the same wrong value from then on.
corruptOne bit flips in the replica's working memory during a computation.
sensorA flip in the radiation-sensor block, to test logging and repair. Needs --sensor-mb. The replica number is ignored.

Limits

Safe on shared hardware. Each process enforces its own memory and CPU-time limits. The voter enforces the CPU share and the run time.

OptionDefaultMeaning
--max-memory-mb128Memory limit per process (Linux only)
--max-cpu-secondsoffCPU-time limit per process
--cpu-percentoffCap on the voter's CPU share
--max-secondsoffMaximum run time
--reply-timeout-ms2000Drop a replica that does not answer in time

Radiation sensor

--sensor-mb M holds M MB of memory in a known pattern and checks it every --sensor-every ticks (default 1000). Every flipped bit is logged with its location, then repaired. On flight hardware, this measures the real upset rate. It must leave at least 32 MB under --max-memory-mb.

Output

--log file.csv writes every event: stuck, hang, lost, retired, cleared, killed, detected, wrong, stopped, halted and sensor flips. --progress-every N adds running totals. --summary file.txt writes the final report for downlink.

quorum --policy shrink ...  useful=14490 detected=10 wrong=0 halted_at=never

On OPS-SAT

opssat/run.sh starts, checks and stops a run with all limits set. Tagged releases ship each static Linux binary (three ARM, one x86_64) with the launcher, a sample fault schedule and the operations note.

Updated 7 Oct 2026 · Source: demo/src/main.rs · Edit on GitHub · Questions? Request information