pub struct EpochConsensus<V: Clone> { /* private fields */ }Expand description
Abortable consensus within one epoch.
Implementations§
Source§impl<V: Clone> EpochConsensus<V>
impl<V: Clone> EpochConsensus<V>
Sourcepub fn new(
me: NodeId,
peers: impl IntoIterator<Item = NodeId>,
ets: u64,
leader: NodeId,
state: State<V>,
retransmit: Duration,
) -> Self
pub fn new( me: NodeId, peers: impl IntoIterator<Item = NodeId>, ets: u64, leader: NodeId, state: State<V>, retransmit: Duration, ) -> Self
⟨ ep, Init | state ⟩ — an instance for epoch ets led by leader, beginning from state.
Sourcepub fn is_aborted(&self) -> bool
pub fn is_aborted(&self) -> bool
Whether this instance has been abandoned and is therefore silent.
Trait Implementations§
Source§impl<V: Clone> Protocol for EpochConsensus<V>
impl<V: Clone> Protocol for EpochConsensus<V>
Source§type Meta = Infallible
type Meta = Infallible
Keeps nothing durably. logged_epoch_consensus is the variant that does.
Source§fn on_msg(&mut self, from: NodeId, msg: BebMsg<V>, cx: &mut ProtoCx<'_, Self>)
fn on_msg(&mut self, from: NodeId, msg: BebMsg<V>, cx: &mut ProtoCx<'_, Self>)
such that ts = ets, applied at the door rather than after the link beneath.
The guard has to be here, not only where the delivery is handled, and the reason is the
perfect link’s duplicate-detection set. Each epoch gets a new instance, so each epoch gets a
new link, and a new link restarts its sequence numbers at one — while the receiver’s set is
cleared at a different moment, when its own epoch changes. Hand a foreign-epoch message to
the link and it records (src, 1) as delivered; the real epoch-ets message with sequence
one is then discarded as a duplicate, silently, and that process never answers the leader
again. Three of five processes stalled this way before the guard moved up here.
This is CLAUDE.md’s “identity is as durable as the state it keys” seen from the other side:
the identifier’s scope is one epoch, so nothing outside that epoch may enter the set that
keys on it.