---
title: "The quorum program"
url: https://docs.mru.space/core/quorum-cli/
description: "Options for the quorum demo: policy, fault injection (kill, hang, stuck, bit flips), resource limits, radiation sensor and logging."
---

[Docs](https://docs.mru.space/) / [Core runtime](https://docs.mru.space/core/quorum-crate/) / quorum CLI

# The `quorum` program

Three replica processes, a voter built on the core, fault injection, and enforced resource limits. It reports what it delivered and what that cost.

## Synopsis

```
quorum [--policy shrink|tmr] [--ticks N] [--seed S]
   [--upset-rate R] [--common-mode C] [--kat-period P]
   [--fault kill|corrupt|stuck|hang|sensor:I@T] ... [--faults-file F]
   [--max-memory-mb M] [--max-cpu-seconds S] [--cpu-percent P]
   [--max-seconds S] [--reply-timeout-ms T]
   [--sensor-mb M] [--sensor-every N]
   [--log file.csv] [--progress-every N] [--summary file.txt]
```

An unknown option prints this list. Every run is reproducible from its seed.

## Run settings

| Option | Default | Meaning |
| --- | --- | --- |
| \--policy | shrink | `shrink` or `tmr` |
| \--ticks | 10000 | Results to compute |
| \--seed | 1 | Seed for random upsets and where they land |
| \--upset-rate | 0 | Chance per replica per tick of a bit flip in working memory |
| \--common-mode | 0.05 | Share of single-replica upsets that hit both self-check runs alike |
| \--kat-period | 64 | Ticks between known-answer tests on the last replica |

## Faults

Schedule a fault as `kind:replica@tick`. Repeat the option, or read a schedule with `--faults-file`.

| Kind | What happens |
| --- | --- |
| kill | The replica process dies. |
| hang | The replica stops answering. The voter drops it after the reply timeout. |
| stuck | The replica returns the same wrong value from then on. |
| corrupt | One bit flips in the replica's working memory during a computation. |
| sensor | A flip in the radiation-sensor block, to test logging and repair. Needs `--sensor-mb`. The replica number is ignored. |

## Limits

Safe on shared hardware. Each process enforces its own memory and CPU-time limits. The voter enforces the CPU share and the run time.

| Option | Default | Meaning |
| --- | --- | --- |
| \--max-memory-mb | 128 | Memory limit per process (Linux only) |
| \--max-cpu-seconds | off | CPU-time limit per process |
| \--cpu-percent | off | Cap on the voter's CPU share |
| \--max-seconds | off | Maximum run time |
| \--reply-timeout-ms | 2000 | Drop a replica that does not answer in time |

## Radiation sensor

`--sensor-mb M` holds M MB of memory in a known pattern and checks it every `--sensor-every` ticks (default 1000). Every flipped bit is logged with its location, then repaired. On flight hardware, this measures the real upset rate. It must leave at least 32 MB under `--max-memory-mb`.

## Output

`--log file.csv` writes every event: stuck, hang, lost, retired, cleared, killed, detected, wrong, stopped, halted and sensor flips. `--progress-every N` adds running totals. `--summary file.txt` writes the final report for downlink.

```
quorum --policy shrink ...  useful=14490 detected=10 wrong=0 halted_at=never
```

## On OPS-SAT

`opssat/run.sh` starts, checks and stops a run with all limits set. Tagged releases ship each static Linux binary (three ARM, one x86\_64) with the launcher, a sample fault schedule and the operations note.

Updated 7 Oct 2026 · Source: demo/src/main.rs · [Edit on GitHub](https://github.com/mruspace/docs/edit/main/src/pages/core/quorum-cli.astro) · [Questions? Request information](https://mru.space/contact/)
