Defining the Fail-Safe State
A trip is only as good as the state it trips to; each machine has an explicitly defined, benign resting state that every failsafe path drives toward.
Safe is a place, not an absence
Cutting power is not automatically safe. A safe state is a specific, defined configuration where stored energy is being removed in a controlled way and no protected limit is being approached. Kronos defines the safe state per machine and per subsystem, and every failsafe path is designed to reach that defined state, not merely to stop.
Breeder safe state
- Plasma terminated by a controlled, mitigated shutdown rather than an uncontrolled disruption.
- Magnet energy extraction initiated into the dump resistors if quench criteria are met.
- Heating and fueling actuators driven to zero; vacuum and cryo interlocks held permissive-off.
- Vessel forces and halo currents kept within the structural envelope during the ramp-down.
Burner safe state
- Plug and throat coil currents ramped to a defined low-stress hold or extracted to dump.
- Neutral beam and fueling to zero; DEC decoupled from the load with controlled ride-down.
- Ambipolar potential allowed to relax along a path that avoids a rapid confinement loss transient.
def safe_state_reached(machine_state, limits):
# all monitored quantities inside their benign holding band
return all(limits[k].lo <= machine_state[k] <= limits[k].hi
for k in limits) and machine_state['stored_energy_falling']
Defining the safe state per subsystem also disciplines recovery. Because the resting configuration is explicit, the path back to operation is a checked sequence from a known state rather than an improvisation from wherever the trip left things. Operators and the supervisory tier both reason against the same defined state, which removes a whole class of restart hazards where a machine is brought up from an ambiguous, partially-tripped configuration whose stored energy and interlock status are not fully known.
For fast-growing faults, reaching the ideal safe state may be impossible in the available time; then the failsafe drives to the least-unsafe reachable state and hands off to mitigation. That trade — ideal versus reachable — is decided in advance per fault, not improvised. See the failure response decision table and this page's companion on magnet energy extraction.