1. The tumble that had to be stopped
Alfonso Cuarón’s Gravity returns as the recalled work because the film is essentially a long lesson in how quickly things go wrong when a spacecraft loses attitude control. The protagonist spends most of the story trying to stop tumbling, find a stable orientation, and reach a vehicle that can take her home. Every failure mode in the ADCS test matrix is a smaller version of that experience: a sensor lies, an actuator saturates, the platform spins, and the mission clock runs out.
This entry defines success and failure for the ADCS payload integration and pointing test.
2. Success criteria
The test passes if the integrated ADCS meets the following criteria:
- Integration: the payload powers up, communicates, and does not interfere with other subsystems beyond predicted levels.
- Sensor accuracy: each sensor meets its specification, and the fused attitude estimate stays within the knowledge budget.
- Actuator authority: wheels and magnetorquers produce at least the torque and dipole required by the pointing budget with margin.
- Detumbling: the platform reduces initial tumble rates to below the safe threshold within the predicted time.
- Pointing hold: steady-state error for nominal targets is within the control budget.
- Tracking: payload tracking error is within the instrument tolerance for the required exposure or dwell time.
- Slew performance: commanded slews are completed within the allowed time and settle without sustained oscillation.
- Disturbance rejection: the platform recovers from calibrated disturbances without exceeding error limits or saturating actuators.
- Momentum management: wheel speeds are kept within safe bounds over a representative orbit profile.
- Safe mode: injected faults trigger a stable safe attitude within a bounded time and without operator intervention.
- Autonomy: the attitude manager resolves conflicts, schedules dumps, and recovers from missed events according to policy.
3. Failure modes and what they mean
The test fails if any of the following occur:
- Sensor fault not detected: the estimator continues to use a bad Sun sensor or magnetometer and produces a drifting attitude. This is a fault-detection failure.
- Wheel saturation not prevented: the autonomy allows a wheel to reach its speed limit and the platform loses control authority. This is a planning failure.
- Control oscillation: the pointing error does not converge but grows or rings. This is usually a tuning or modeling failure.
- Insufficient torque: the actuator set cannot overcome the predicted disturbance plus slew demand. This is a sizing failure.
- Magnetic contamination: the magnetometer is unusable when other subsystems operate. This is an integration failure.
- Safe mode not reached: a critical fault does not trigger the expected safe attitude. This is a survivability failure.
- Autonomy commands impossible attitudes: the scheduler requests a target behind a keep-out cone or beyond rate limits. This is a policy failure.
Each failure mode maps to a design change: better sensor voting, larger wheels, retuned controllers, improved magnetic cleanliness, revised safe-mode logic, or corrected autonomy constraints.
4. What this changes
- The ADCS test has clear pass/fail criteria and a taxonomy of failures.
- A failure in test is information, not a verdict; it tells the team what to fix before launch.
- The next entry will close the ADCS test arc and decide what the results mean for the ledger.