1. The weight that could not be argued with
Tom Godwin’s “The Cold Equations” returns one last time for this arc because the story’s lesson is not that the universe is cruel; it is that the margin was already spent. The desktop’s power autonomy test exists to make sure the margin is not already spent when the first eclipse arrives. This entry defines what success and failure look like for the test matrix defined in Entry 750.
2. Success criteria
The test as a whole passes if the autonomous power manager demonstrates:
- Estimation credibility: state-of-charge, temperature, and degradation estimates remain within specified tolerances across all test conditions.
- Forecast reliability: eclipse entry and exit, array output, and load profiles are predicted accurately enough to schedule operations without surprise.
- Correct shedding: when generation is insufficient, non-critical loads are dropped before critical loads, and the order matches the value model.
- Timely protection: undervoltage, overvoltage, overcurrent, and thermal faults are detected and contained within design limits.
- Graceful degradation: the system enters defined survival modes, preserves commandability, and avoids uncontrolled shutdown.
- Clean recovery: when the fault clears or the Sun returns, loads are reconnected in priority order only after stable margin is confirmed.
- Subsystem coordination: conflicts with ADCS, thermal, communications, and payload operations are resolved according to a documented policy.
A single row may be waived only if the failure is traced to a test artifact, not to flight software or hardware, and the waiver is documented.
3. Failure modes that stop the arc
The test arc fails, and the design must be fixed before flight, if any of the following occur:
- Critical load loss: a survival-critical load loses power during a recoverable fault or eclipse.
- Bus collapse: the common bus drops below minimum operating voltage due to a single injected fault.
- False confidence: the autonomy reports healthy margins while the hardware is actually in a dangerous state.
- Cascade failure: one fault leads to a second, unrelated fault because the recovery sequence was wrong.
- Silent failure: a fault is not detected, not reported, or not logged.
- Uncommanded mode: the autonomy enters a safe mode that ground cannot exit or diagnose.
- Requirement mismatch: the autonomy behaves in a way that contradicts the documented load-shedding or fault-protection policy.
4. Partial success and the gray zone
Some results are not clean pass or fail. Examples include:
- The autonomy survives the fault but sheds more load than necessary, leaving science data on the table.
- The state estimate converges slowly, causing a brief but recoverable conservatism in scheduling.
- A non-critical load is dropped out of order because its priority was misclassified.
These are yellow flags. They do not stop the arc, but they require a documented mitigation: a software update, a procedure change, or an operational constraint. The arc cannot be closed until every yellow flag has an owner and a plan.
5. What this changes
- Success is defined as trustworthy autonomy across estimation, scheduling, protection, recovery, and coordination.
- Failure is defined as any loss of critical capability, bus collapse, false confidence, cascade, silence, or uncommanded mode.
- Partial results are allowed but must be tracked to closure.
- The next entry will close the power test arc.