1. When the station must survive its own engines
Stanisław Lem’s Solaris returns as the recalled work because the station must keep its position and core functions even when the ocean below disrupts every assumption about how its systems behave. The desktop’s propulsion must do the same: keep the platform safe even when thrusters misfire, valves stick, or a planned burn becomes the wrong burn.
This entry defines success and failure for the propulsion fault recovery and maneuver verification test.
2. Minimum success
The test passes if:
- Single thruster faults are detected and the burn is terminated or reconfigured without loss of attitude control.
- A stuck-on thruster is isolated by a valve or power cutoff before propellant is exhausted or attitude is lost.
- Degraded thrust is detected and the platform reconciles actual impulse with the orbit estimate.
- Valve and pressure faults are detected before they cause an uncommanded burn or propellant loss.
- Pre-burn verification rejects a maneuver when attitude, power, or propellant checks fail.
- A mid-burn abort stops thrust cleanly and leaves the platform in a recoverable state.
- Propellant isolation protects the deorbit reserve and prevents a leak from draining the whole system.
- Ground receives a coherent event report after each injected fault.
This minimum says the desktop’s propulsion can absorb common propulsion faults.
3. Full success
A stronger result would add:
- Multiple simultaneous propulsion faults are handled without ground intervention.
- The platform autonomously re-plans a recovery maneuver from the actual post-fault state.
- Fault injection results match predictions from propulsion and orbit analysis.
- No single propulsion fault requires a platform reboot to recover.
- Recovery maneuvers respect customer payload windows and ground-notification policy.
- Propellant margins are updated in real time after a fault or partial burn.
This stronger result supports a claim that the desktop’s propulsion is robust enough for extended autonomous operation.
4. Failure modes
The test fails if any of the following occur:
- A single thruster fault causes loss of attitude control or an unsafe orbit.
- A stuck-on thruster is not isolated before propellant is exhausted.
- Degraded thrust goes undetected and the orbit diverges from the planned state.
- A valve or pressure fault causes an uncommanded burn or uncontrolled vent.
- Pre-burn verification passes when attitude, power, or propellant conditions are actually inadequate.
- A mid-burn abort leaves the platform tumbling or on a collision course.
- A leak is not isolated and threatens the deorbit reserve.
- Recovery actions are not logged or are incomprehensible to ground.
Each failure mode points to a fix in thruster selection, valve design, fault detection, maneuver verification, or recovery planning.
5. What this changes
- The propulsion fault recovery and maneuver verification test has clear pass and fail criteria.
- The criteria separate safe termination from successful reconfiguration and from graceful recovery.
- The next entry will close the test arc.