1. The question left open

Entry 873 said a shared power bus is honest for an abort-sized SEP backup, but only if the design includes fault isolation and load shedding. This entry asks the next question: which loads are so essential that they must stay powered through a PPU transient or bus sag, and how long must the batteries cover them?

The answer is not a single number. It is a priority list, with the sail’s attitude-control system at the top.

2. What the sail cannot lose

A solar sail is a structure under tension, driven by continuous solar pressure. If the attitude-control system stops commanding the actuators, the sail does not coast like a rocket; it starts to drift under photon pressure, thermal snap, and structural relaxation. Within minutes the thrust vector can wander far enough to make the planned trajectory meaningless.

The essential loads for sail control are therefore:

  • Attitude-determination sensors: star trackers, Sun sensors, and an inertial measurement unit. Without them the tug does not know where the sail is pointing.
  • ADCS computer and software: the processor that turns sensor data into actuator commands. Solar Cruiser’s ADCS is built around this closed loop for thrust-vector control.
  • Sail actuators: tip vanes, reflectivity-control devices, boom-mounted gimbals, or whatever physically steers the membrane. Duan’s fault-tolerant sail work treats actuator failure as a direct threat to orbit and attitude control.
  • Communications receiver: the tug must be able to hear an abort or safe-mode command from the ground. A transmitter is nice; a receiver is mandatory.
  • Thermal survival heaters and battery management: electronics and batteries have temperature limits. The power subsystem itself must stay within its operating envelope.

If any of these drops out, the sail is no longer a controlled engine. It becomes a very large, very thin kite in a steady wind.

3. What can be shed

The point of load shedding is to protect the essential loads by cutting everything else. On a hybrid tug, the sheddable list includes:

  • The SEP PPU itself. This is the irony: the device most likely to cause the bus sag is also the first thing that should be disconnected. The ECSS high-voltage handbook notes that switching a thruster off during a transient interrupts thrusting but is acceptable if the alternative is bus collapse.
  • High-rate transmitters. A deep-space radio can draw hundreds of watts. It is not needed during a power emergency.
  • Science instruments and health-monitoring cameras. Valuable for diagnostics, but not for survival.
  • Non-essential compute. The payload processors can reboot; the ADCS processor cannot.
  • Thermal heaters for non-critical areas. Survival heaters stay on; comfort heaters do not.

The Cassini under-voltage response is the heritage template: sense the power drop, shed non-essential loads, isolate the defective device, and re-establish essential hardware. The goal is to keep critical memories and control loops alive long enough to recover.

4. Ride-through mechanisms

Load shedding is fast, but not instantaneous. Between the fault and the disconnect, the bus voltage sags. Something has to carry the essential loads across that gap.

Batteries are the primary ride-through source. A battery sized for eclipse operations already stores energy; the question is whether it can also cover a SEP-induced transient. For a 1 kW essential load, a 100 Wh battery provides roughly six minutes of ride-through. That is enough time for software to detect, isolate, and reconfigure.

Hold-up capacitors in the power supplies of the ADCS computer and sensors cover the first milliseconds to seconds. They are not a long-term solution, but they prevent the processor from rebooting during a brief glitch. The SSL PPU experience Corey describes — a noise transient from the thruster latching off the PPU auxiliary supply — is exactly the kind of event that can be ridden out if the control electronics have enough local capacitance.

Power switches with current limiting and isolation, such as the radiation-validated FDIR switches TI describes, make the shedding decision hardware-fast. A software loop that polls the bus every hundred milliseconds is too slow for a PPU fault; the switch should trip in microseconds and notify the computer afterwards.

5. The safe-mode attitude problem

Most spacecraft safe modes point the solar arrays at the Sun and wait for instructions. A sailcraft safe mode is harder because the sail itself is the solar collector and the thruster. Sun-pointing may be the right answer, or it may produce thrust in exactly the wrong direction.

The safe-mode design therefore depends on the trajectory geometry at the moment of the fault. Sometimes the right answer is “edge-on to the Sun” to kill thrust and drift. Sometimes it is “face-on with a fixed cone angle” to maintain a known, gentle acceleration. Sometimes it is “run from a pre-stored attitude timeline” because the computer cannot compute a new one under reduced power.

This is not a generic setting. It is a mission-specific table, computed on the ground and triggered by the fault type.

6. The Hoyle echo

Fred Hoyle’s The Black Cloud imagines a sentient interstellar cloud that parks itself between Earth and the Sun. Agriculture collapses, the climate shifts, and human civilization has to decide which systems keep running when the solar flux drops. The scientists in the novel argue about whether the cloud is alive; the rest of the species argues about calories and watts.

The hybrid tug has the same problem at a smaller scale. Sunlight is both the energy source and the propulsive force. A PPU fault is a local, artificial eclipse. The design question is not whether the lights go out, but which lights must stay on long enough to survive the cloud.

7. The Popperian note

The conjecture is that a battery plus fast load shedding can keep the sail controllable through a SEP PPU fault. The refutations would be:

  • A fault whose transient is faster than the power switches can isolate, or
  • A safe-mode attitude that, because of geometry, pushes the tug onto a worse trajectory than an uncontrolled sail would take, or
  • An essential-load power requirement that exceeds the battery’s eclipse margin, forcing a larger battery and changing the mass budget.

If any of those is true, the shared-bus architecture from Entry 873 needs to be reconsidered.

8. What this changes

Entry 873 shared the bus. Entry 874 says the bus must come with a rigid priority table and a ride-through budget. The essential loads are the ADCS sensors, computer, actuators, comm receiver, and power-subsystem survival. Everything else, including the SEP PPU, is sheddable.

For the keeper arc, this means the power subsystem design is not complete when the array area is known. It is complete when the fault-response timeline is known: how fast the switches trip, how long the battery carries the essential load, and what attitude the sail adopts while the bus recovers.

9. Next curiosity

If the SEP PPU is the most likely source of a bus sag, should the tug command the PPU to throttle down or shut off before large sail actuator moves? And if so, does that mean the sail and the SEP are never allowed to operate at full power simultaneously?