Pith. sign in

REVIEW 2 major objections 4 minor 24 references

Passively Safe Convex Guidance for Cislunar Rendezvous and Proximity Operations

T0 review · 2 major / 4 minor · reviewed 2026-08-08 · deepseek-v4-flash

Pith's one-line read Purely convex programs are sufficient for passively safe cislunar rendezvous when relative motion is captured by a first-order flow map.

desk verdict A genuinely convex, fixed-time RPO guidance architecture with a clean MEE reduction and real mission baseline; the 'passively safe' claim is slightly ahead of the verification, which is node-based rather than continuous. read the letter →

arxiv 2608.03060 v1 pith:EQVKZORR submitted 2026-08-04 cs.RO math.OCnlin.CD

classification cs.ROmath.OCnlin.CD MSC 70M2090C25
keywords passivelysaferendezvousconvexoptimizationsecond-orderconeprogrammingcislunarspacenearrectilinearhaloorbitmaneuverexecutionerrorpassivesafetyautonomousguidance
verification ladder T0 review T1 audit T2 compute T3 formal

The pith

A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.

The reading

This paper shows that autonomous rendezvous and proximity operations in cislunar space can be planned onboard using single, purely convex optimization problems, without the iterative loops of successive convexification. The enabling premise is a fixed maneuver timeline and a first-order state transition matrix that maps relative motion from the target's high-fidelity trajectory. Under that premise, approach, arrival, and abort maneuvers are each designed by one second-order cone program that folds in navigation uncertainty and maneuver execution error. The authors validate the approach in high-fidelity closed-loop Monte Carlo simulations at both apolune and perilune of a 9:2 synodic near rectilinear halo orbit and report that these methods form the baseline onboard guidance routines for the CAPSTONE 02 mission.

What carries the argument

The central object is the target's inertial state transition matrix $\Phi(t_f, t_0)$ used as a linear flow map for the chaser's relative motion, which keeps the trajectory optimization convex. Around it, three components carry the argument: a reduced, conservative maneuver execution error model that expresses the post-burn velocity covariance inflation as a quadratic function of the maneuver vector; an ellipsoid-projection technique that turns an instantaneous statistical safety constraint into a second-order cone constraint; and a waterfall update that adds safety constraints at discrete times where a full nonlinear propagation shows a keep-out-sphere violation. The discrete passive-safety evaluation uses a Sundman time regularization so the check nodes are spaced more evenly in path length than in time.

What would settle it

Propagate a designed maneuver with high-fidelity dynamics and the full 99% uncertainty ellipsoid, sampling the minimum statistical distance to the target-centered keep-out sphere on a time grid several times finer than the paper's regularized grid; if that distance ever falls below the keep-out radius between two adjacent regularized check nodes, the approximated passive safety guarantee is violated.

Watch

Extended reading notes

Core claim

The paper's central claim is that purely convex, uncertainty-aware impulsive guidance is a practical and effective solution for autonomous cislunar rendezvous and proximity operations. Under the fixed-time premise, simple convex programs are sufficient for passively safe operations provided the relative motion is accurately captured by a first-order flow map. The authors combine the target's inertial state transition matrix as a linear relative-motion model, a conservative reduction of a four-term maneuver execution error model into second-order cone form, and ellipsoid-projection safety constraints that keep the chaser outside a target-centered keep-out sphere with 99% confidence. The design uses a waterfall strategy: passive safety is checked on a discretized regularized time grid under full nonlinear dynamics, and any violation adds an instantaneous safety constraint at that time and direction before re-solving the same convex program. High-fidelity closed-loop Monte Carlo simulations at apolune and perilune show the chaser reaching the keep-out sphere inside a docking cone under maneuver execution error and navigation uncertainty.

Load-bearing premise

Passive safety is verified only at discrete check times on a regularized grid, and the paper assumes without proof that no safety violation occurs between those nodes.

Editorial extensions

If this is right

  • Onboard maneuver design has bounded, deterministic solve times with no initial guess required, which is decisive for autonomous operations in a delayed-communications environment.
  • The waterfall constraint update folds nonlinear high-fidelity safety information into a convex core, so the approach remains valid in strongly nonlinear regions such as perilune as well as near-straight-line apolune dynamics.
  • The same formulation transfers to any long-period multi-body orbit, provided a first-order flow map of the target's reference trajectory is available and its accuracy is checked.
  • The arrival and abort programs complete the close-operations sequence, so approach, terminal arrival, and active abort are all covered by the same purely convex architecture.
  • Because the convex programs are solved in sub-second times in a Python implementation, they are realistic candidates for flight software with modest onboard computers.

Reading between the lines

Editorial extensions of the paper, not claims the author makes directly.

  • The discrete-grid passive safety check is the load-bearing approximation; if a continuous or adaptively refined verification found an inter-node violation, the designed maneuvers would not be passively safe as claimed, so testing with finer grids is a natural extension of the paper's own verification.
  • The conservative isotropic reduction of the maneuver error model inflates uncertainty in directions perpendicular to the burn; a tighter convex outer approximation of the true error model could reduce the required standoff distance while preserving second-order cone structure.
  • The same convex architecture could be stress-tested in Sun-Earth L2 halo orbits or other three-body regimes, provided the first-order flow map's accuracy is validated with the nonlinear index used here.
Share X Bluesky LinkedIn Reddit HN

Editorial analysis

A structured set of objections, weighed in public.

Desk editor's note, referee report, and a circularity audit.

Referee Report

2 major / 4 minor

Summary. The paper proposes purely convex second-order cone programs for passively safe impulsive rendezvous and proximity operations in cislunar space, developed as the baseline onboard guidance for the planned CAPSTONE 02 mission. Relative motion is mapped through the target's state transition matrix, maneuver execution error is incorporated through a conservative convex reduction of the Gates model, and safety is enforced via ellipsoid-projection constraints, with docking-cone constraints applied at arrival. A 'waterfall' outer loop adds discrete-time safety constraints obtained by nonlinear propagation, and two 100-trial closed-loop Monte Carlo simulations at apolune and perilune are presented to validate the approach, arrival, and abort designs.

Significance. If the passive-safety claim can be made rigorous, this is a valuable and timely engineering contribution: it demonstrates that fixed-time, impulsive cislunar RPO can be handled by a sequence of lightweight SOCPs without the convergence uncertainty of SCP, and the Monte Carlo results show the intended behavior with the planned sensor suite. The paper's strengths include the clean conservative reduction of the Gates MEE model in Eq. (18), the closed-form analytical treatment of the instantaneous safety check in the appendix, and the explicit connection to a real mission, CAPSTONE 02. The principal weakness is that the headline property, passive safety, is verified only at discrete regularized-time nodes, not continuously over the horizon, and the present manuscript does not close that gap. The 'purely convex' characterization also deserves qualification because the design loop includes nonlinear propagation and adaptive parameter updates. With those issues addressed, the paper would be a solid conference contribution; in its current form, the central claim is stronger than the evidence.

major comments (2)
  1. [Passive Safety, Eq. (20)] Passive safety is defined in Eq. (20) as a continuous-time condition over t in [t0, tf], but the verification procedure in the 'Passive Safety' section checks this condition only at N discrete times on a regularized-time grid. The grid is constructed for even path length, not for capturing local minima of ||δr(t)|| - rk, and no inter-sample bound, Lipschitz estimate, or grid-refinement study is provided to show that node satisfaction implies continuous satisfaction. The additional linear close-approach time from Eq. (35) does not close this gap; the paper itself notes that near perilune this time loses physical meaning, and the nonlinear dynamics shown in Fig. 1 can place the true closest approach between nodes. Because the abstract and conclusion state passive safety as a demonstrated property, this is load-bearing. Please either provide a rigorous inter-sample argument (for example, a uniform bound on the time derivative of the distance-to-keep-out-sphere function along the propagated trajectory and covariance) together with a grid-convergence study, or systematically qualify all claims as passive safety at the checked discrete times and revise the abstract and conclusion accordingly.
  2. [Approach, Eqs. (34)-(40)] The overall design process is not purely convex as a whole: after each SOCP solve, the candidate is propagated under full nonlinear dynamics, passive-safety violations are detected at discrete nodes, additional inequality constraints are appended via Eq. (37), and the absolute MEE parameter σa is artificially increased through Eqs. (38)-(40). No termination proof, iteration bound, or convergence analysis is given for this outer loop, so the deterministic guarantees of convex programming apply only to each individual subproblem, not to the complete maneuver design algorithm. The paper's contrast with SCP ('decisive numerical performance guarantees') is therefore stronger than what is demonstrated. Please either state explicitly that the waterfall loop is heuristic with no formal termination guarantee, or provide a bound on the number of iterations and a justification for why the loop is guaranteed to produce a passive-safety-feasible design in the intended operational envelope.
minor comments (4)
  1. [Eq. (37)] The notation δm̂⁻_{r,j} is used as if it were a unit vector, but it is never formally defined; please define it explicitly as the unit vector along the nonlinear relative position at the violation time t_j.
  2. [Closing remark after Fig. (8)] The negative TPM magnitude values in the perilune violin plot are acknowledged in the text as an artifact of the plot construction, but the figure caption itself should state this to prevent misinterpretation by readers who do not read the full paragraph.
  3. [Closed-Loop Simulation Examples] The companion paper [5] is cited for the simulation setup, but some details that are important for reproducibility, such as the exact relative navigation filter model and the 50% duty-cycle modeling of optical and crosslink tracks, are not summarized here; a brief appendix or a more detailed description of these assumptions would make the paper more self-contained.
  4. [Table 1 and Passive Safety section] The number N of discrete nodes used for the regularized-time passive safety grid is never reported; please provide this value, as it directly affects the interpretation of the verification results and the operational margin.

Circularity Check

0 steps flagged · score 1.0 of 10

No significant circularity: the convex guidance derivation is self-contained, with the main caveat being an acknowledged discrete-grid approximation of passive safety rather than a circular step.

full rationale

I find no load-bearing circular step. The maneuver design programs are built directly from the STM flow map (Eqs. 7-11), the conservatively reduced Gates MEE model (Eqs. 14-18), and ellipsoid-projection SOC constraints (Eqs. 33, 62-68); no free constant is fitted to reproduce the reported close-approach distances. The waterfall sigma_a update (Eqs. 38-40) is explicitly a conservative design-closure mechanism - the paper states that artificially inflating the absolute MEE component 'trades close approach distance for conservatism and design closure' - so it is not a fitted input disguised as a prediction. The self-citations to the companion paper [5] supply CAPSTONE 02 simulation setup, navigation-filter description, and MEE parameter values; the mathematical derivation is self-contained, so this is not load-bearing self-citation. One genuine limitation, which is a correctness/verification risk rather than circularity, is that passive safety is defined continuously in Eq. 20 but verified only on a discretized regularized-time grid; the paper itself labels this 'Approximated passive safety' and provides no inter-node bound, so the continuous-time claim is not fully established. Because the central convex-program construction is independent of these caveats, the circularity score is low.

Assumptions & free parameters 1 free parameters · 5 assumptions · 0 invented entities

The central claim rests on the linear STM flow map, the conservative reduction of the Gates MEE model, and the discrete approximation of passive safety. The MEE parameters themselves are external engineering inputs, not fitted to the outcomes. The only adaptive parameter is the artificial sigma_a inflation used in the waterfall closure.

free parameters (1)
  • Artificial MEE inflation delta_sigma_a = Computed per maneuver from worst-case nonlinear safety violation (Eq. 40)
    Introduced ad hoc in the waterfall update to force passive safety closure; varies with each design iteration and effectively tunes the design model until the nonlinear check passes.
assumptions (5)
  • domain assumption The target's inertial state transition matrix linearly maps relative state and covariance over the maneuver horizon (Eq. 7-8).
    Used throughout the design; the paper's own nonlinear index study (Fig. 1c, Eq. 13) identifies strong velocity-dependent nonlinearity near true anomaly 220 degrees, where the STM may be less accurate.
  • domain assumption The passive safety condition (Eq. 20) can be verified at discrete regularized time nodes.
    Section 'Passive Safety' calls this 'Approximated passive safety'; no bound is given for inter-node violations.
  • domain assumption The reduced MEE model (Eq. 18) is conservative relative to the Gates model (Eq. 14-16).
    The max operation in Eq. 17 ensures the absolute error is not underestimated, but the isotropy assumption may mis-model directional dependence and is not validated against the full Gates model.
  • domain assumption The uncertainty in the SLVLH frame transformation is negligible (cm-level).
    Stated in Section 'Convex Guidance for RPO'; preliminary studies are cited but not shown.
  • domain assumption The Gates model accurately characterizes maneuver execution error.
    Standard NASA engineering model [16], treated as ground truth for the error distribution in both design and verification.

how reviews work

0 comments
Cite this review

Pith. "Pith review of Passively Safe Convex Guidance for Cislunar Rendezvous and Proximity Operations." pith.science (2026). https://pith.science/paper/EQVKZORR

@misc{pith2026260803060,
  author       = {Pith},
  title        = {Pith review of: Passively Safe Convex Guidance for Cislunar Rendezvous and Proximity Operations},
  year         = {2026},
  howpublished = {\url{https://pith.science/paper/EQVKZORR}},
  note         = {Machine review of arXiv:2608.03060}
}
read the original abstract

This paper presents purely convex programs for passively safe impulsive rendezvous and proximity operations in cislunar orbits. Approach, arrival, and abort maneuvers are all designed and validated in the context of maneuver execution error and navigation uncertainty, and formulated for efficient onboard execution in the autonomous scenario. The outlined methods form the baseline onboard guidance routines for NASA's CAPSTONE 02 mission planned to demonstrate autonomous rendezvous and proximity operations capabilities in the southern 9:2 synodic near rectilinear halo orbit. High fidelity closed loop Monte Carlo simulations using the planned relative navigation sensor suite and measurement cadence verify the intended maneuver design performance.

Discussion (0). Continue with ORCID to comment.

Reference graph

Works this paper leans on

24 extracted references · 21 canonical work pages

  1. [5]

    End-to-End Closed-Loop Rendezvous and Proximity Operations Performance for the CAPSTONE 02 Mission,

    C. Plaks, I. M. Down, M. Bolliger, N. Bradley, and M. Caudill, “End-to-End Closed-Loop Rendezvous and Proximity Operations Performance for the CAPSTONE 02 Mission,”2026 AAS/AIAA Astrodynam- ics Specialist Conference, 2026, pp. 1–20

  2. [1]

    Cislunar autonomous positioning system technology operations and navigation experi- ment (Capstone),

    B. Cheetham, “Cislunar autonomous positioning system technology operations and navigation experi- ment (Capstone),”ASCEND 2021, p. 4128, 2021

  3. [2]

    Capstone: A cubesat pathfinder for the lunar gateway ecosystem,

    T. Gardner, B. Cheetham, A. Forsman, C. Meek, E. Kayser, J. Parker, M. Thompson, T. Latchu, R. Rogers, B. Bryant,et al., “Capstone: A cubesat pathfinder for the lunar gateway ecosystem,” 2021

  4. [3]

    Successive Convexification for Passively-Safe Spacecraft Rendezvous on Near Rectilinear Halo Orbit

    P. Elango, A. P. Vinod, K. Kitamura, B. Ac ¸ıkmes ¸e, S. Di Cairano, and A. Weiss, “Successive con- vexification for passively-safe spacecraft rendezvous on near rectilinear halo orbit,”arXiv preprint arXiv:2505.17251, 2025

  5. [4]

    Continuous-Time Suc- cessive Convexification for Passively-Safe Spacecraft Rendezvous on a Near Rectilinear Halo Orbit,

    P. Elango, A. P. Vinod, K. Kitamura, B. Acikmese, S. Di Cairano, and A. Weiss, “Continuous-Time Suc- cessive Convexification for Passively-Safe Spacecraft Rendezvous on a Near Rectilinear Halo Orbit,” AIAA SCITECH 2026 F orum, 2026, p. 2446

  6. [6]

    International rendezvous system interop- erability standards (irsis),

    W. H. Gerstenmaier, D. Parker, G. Leclerc, and R. Shirama, “International rendezvous system interop- erability standards (irsis),”Technical Report, Technical report, NASA, 2019

  7. [7]

    Comprehensive survey and assessment of spacecraft rel- ative motion dynamics models,

    J. Sullivan, S. Grimberg, and S. D’Amico, “Comprehensive survey and assessment of spacecraft rel- ative motion dynamics models,”Journal of Guidance, Control, and Dynamics, V ol. 40, No. 8, 2017, pp. 1837–1859

  8. [8]

    Autonomous Satellite Servicing Infrastructure for In-Space Assembly and Manufacturing,

    I. M. Down, D. E. v. Wijk, D. Parikh, and M. Majji, “Autonomous Satellite Servicing Infrastructure for In-Space Assembly and Manufacturing,”Journal of Manufacturing Science and Engineering, V ol. 146, No. 12, 2024, p. 121008

Show all 24 references
  1. [9]

    Relative motion dynamics in the restricted three-body problem,

    G. Franzini and M. Innocenti, “Relative motion dynamics in the restricted three-body problem,”Journal of Spacecraft and Rockets, V ol. 56, No. 5, 2019, pp. 1322–1337

  2. [10]

    Orbital rendezvous and spacecraft loitering in the earth-moon system,

    F. Khoury, “Orbital rendezvous and spacecraft loitering in the earth-moon system,” Master’s thesis, Purdue University, 2020

  3. [11]

    Describing relative motion near periodic orbits via local toroidal coordi- nates,

    I. Elliott and N. Bosanac, “Describing relative motion near periodic orbits via local toroidal coordi- nates,”Celestial Mechanics and Dynamical Astronomy, V ol. 134, No. 2, 2022, p. 19

  4. [12]

    Application of Fundamental Modal Solutions to Relative Dynamics in the Cislunar Environment,

    C. Vela, R. Opromolla, G. Fasano, and H. Schaub, “Application of Fundamental Modal Solutions to Relative Dynamics in the Cislunar Environment,”Journal of Guidance, Control, and Dynamics, V ol. 49, No. 2, 2026, pp. 344–358

  5. [13]

    Safe ren- dezvous trajectory design for the restore-l mission,

    M. A. Vavrina, C. E. Skelton, K. D. DeWeese, B. J. Naasz, D. E. Gaylor, and C. D’souza, “Safe ren- dezvous trajectory design for the restore-l mission,”Advances in the Astronautical Sciences, V ol. 168, No. 3649-3668, 2019, p. 176. 17

  6. [14]

    Applications of induced tensor norms to guid- ance navigation and control,

    J. Kulik, M. Ruth, C. Orton-Urbina, and D. Savransky, “Applications of induced tensor norms to guid- ance navigation and control,”Journal of Guidance, Control, and Dynamics, V ol. 48, No. 10, 2025, pp. 2180–2198

  7. [15]

    Orbit maintenance burn details for spacecraft in a near rectilinear halo orbit,

    D. C. Davis, S. T. Scheuerle, D. A. Williams, F. S. Miguel, E. M. Zimovan-Spreen, and K. C. How- ell, “Orbit maintenance burn details for spacecraft in a near rectilinear halo orbit,”2022 AAS/AIAA Astrodynamics Specialists Conference, No. AAS 22-545, 2022

  8. [16]

    A simplified model of midcourse maneuver execution errors,

    C. R. Gates, “A simplified model of midcourse maneuver execution errors,” tech. rep., NASA, 1963

  9. [17]

    A time regularization scheme for spacecraft trajectories subject to multi-body gravity,

    J. Leith and R. P. Russell, “A time regularization scheme for spacecraft trajectories subject to multi-body gravity,”The Journal of the Astronautical Sciences, V ol. 70, No. 2, 2023, p. 7

  10. [18]

    Boyd and L

    S. Boyd and L. Vandenberghe,Convex optimization. Cambridge university press, 2004

  11. [19]

    ECOS: An SOCP solver for embedded systems,

    A. Domahidi, E. Chu, and S. Boyd, “ECOS: An SOCP solver for embedded systems,”2013 European control conference (ECC), IEEE, 2013, pp. 3071–3076

  12. [20]

    Clarabel: An interior-point solver for conic programs with quadratic objec- tives,

    P. J. Goulart and Y . Chen, “Clarabel: An interior-point solver for conic programs with quadratic objec- tives,”arXiv preprint arXiv:2405.12762, 2024

  13. [21]

    R. T. Rockafellar,Convex analysis, V ol. 28. Princeton university press, 1997

  14. [22]

    Convex optimization for trajectory generation: A tutorial on generating dynamically feasible trajectories reliably and efficiently,

    D. Malyuta, T. P. Reynolds, M. Szmuk, T. Lew, R. Bonalli, M. Pavone, and B. Ac ¸ıkmes ¸e, “Convex optimization for trajectory generation: A tutorial on generating dynamically feasible trajectories reliably and efficiently,”IEEE Control Systems Magazine, V ol. 42, No. 5, 2022, ...

  15. [23]

    Model predictive control of swarms of spacecraft using sequential convex programming,

    D. Morgan, S.-J. Chung, and F. Y . Hadaegh, “Model predictive control of swarms of spacecraft using sequential convex programming,”Journal of Guidance, Control, and Dynamics, V ol. 37, No. 6, 2014, pp. 1725–1740

  16. [24]

    Chance-constrained, drift-safe guidance for space- craft rendezvous,

    A. W. Berning Jr, E. R. Burnett, and S. Bieniawski, “Chance-constrained, drift-safe guidance for space- craft rendezvous,”arXiv preprint arXiv:2401.11077, 2024. APPENDIX: INSTANTANEOUS SAFETY DERIV A TION The zero step for verifying instantaneous safety simply tests the covari...

Pith tools

Reviewed August 8, 2026 · model on record in the stance chip above.