pub struct FloodingConsensus<P: Clone + Ord, L: VolatileLink<Flood<P>> = PerfectLink<Flood<P>>> { /* private fields */ }Expand description
Regular consensus in the fail-stop model, over best-effort broadcast and a failure detector.
L is the link under the broadcast, and is a parameter rather than a fixed type: what this
stack needs is a link speaking pl::Cmd and pl::Ind, not one particular implementation.
An application with its own driver-backed link runs this consensus over it unedited. It
defaults to PerfectLink, so the ordinary stack is still written FloodingConsensus<P>.
Implementations§
Source§impl<P: Clone + Ord, L: VolatileLink<Flood<P>>> FloodingConsensus<P, L>
impl<P: Clone + Ord, L: VolatileLink<Flood<P>>> FloodingConsensus<P, L>
Sourcepub fn with_link(
me: NodeId,
members: impl IntoIterator<Item = NodeId>,
link: L,
heartbeat: Duration,
detect_after: Duration,
) -> Self
pub fn with_link( me: NodeId, members: impl IntoIterator<Item = NodeId>, link: L, heartbeat: Duration, detect_after: Duration, ) -> Self
Consensus among members, over a link the caller supplies.
The link is anything satisfying crate::link::Link; this layer never names an implementation.
Source§impl<P: Clone + Ord> FloodingConsensus<P, PerfectLink<Flood<P>>>
impl<P: Clone + Ord> FloodingConsensus<P, PerfectLink<Flood<P>>>
Sourcepub fn new(
me: NodeId,
members: impl IntoIterator<Item = NodeId>,
retransmit: Duration,
heartbeat: Duration,
detect_after: Duration,
) -> Self
pub fn new( me: NodeId, members: impl IntoIterator<Item = NodeId>, retransmit: Duration, heartbeat: Duration, detect_after: Duration, ) -> Self
Consensus among members, which must include me.
detect_after must exceed heartbeat plus the network’s delivery bound, or the detector
will accuse correct processes and agreement can break — which is the whole subject of this
module’s documentation.
Sourcepub fn correct(&self) -> impl Iterator<Item = NodeId> + '_
pub fn correct(&self) -> impl Iterator<Item = NodeId> + '_
The processes still believed correct, in a stable order.
Sourcepub fn heard_from(&self, round: u64) -> impl Iterator<Item = NodeId> + '_
pub fn heard_from(&self, round: u64) -> impl Iterator<Item = NodeId> + '_
Who this process heard from in round, for tests watching the guard form.
Sourcepub fn rounds_recorded(&self) -> usize
pub fn rounds_recorded(&self) -> usize
How many rounds hold state. Bounded by the membership; see the space note above.
Sourcepub fn state_entries(&self) -> usize
pub fn state_entries(&self) -> usize
Every entry held across every round — the measure a bounded-space test asserts on.
Trait Implementations§
Source§impl<P: Debug + Clone + Ord, L: Debug + VolatileLink<Flood<P>>> Debug for FloodingConsensus<P, L>
impl<P: Debug + Clone + Ord, L: Debug + VolatileLink<Flood<P>>> Debug for FloodingConsensus<P, L>
Source§impl<P: Clone + Ord, L: VolatileLink<Flood<P>>> Protocol for FloodingConsensus<P, L>
impl<P: Clone + Ord, L: VolatileLink<Flood<P>>> Protocol for FloodingConsensus<P, L>
Source§type Scope = Infallible
type Scope = Infallible
No session beneath, so no scope end can be constructed — as for both children.
Source§type Meta = Infallible
type Meta = Infallible
Keeps nothing durably: a crash loses everything this protocol knows.
Source§fn on_init(&mut self, cx: &mut ProtoCx<'_, Self>)
fn on_init(&mut self, cx: &mut ProtoCx<'_, Self>)
Failure detection begins here, as Module 2.6 has it. It used to need a Start command
because there was no init event to hang the detector’s first timer on.
Source§type Msg = Wire<<L as Protocol>::Msg>
type Msg = Wire<<L as Protocol>::Msg>
Source§type Entry = Infallible
type Entry = Infallible
Source§fn on_cmd(&mut self, cmd: Cmd<P>, cx: &mut ProtoCx<'_, Self>)
fn on_cmd(&mut self, cmd: Cmd<P>, cx: &mut ProtoCx<'_, Self>)
Source§fn on_msg(&mut self, from: NodeId, msg: Self::Msg, cx: &mut ProtoCx<'_, Self>)
fn on_msg(&mut self, from: NodeId, msg: Self::Msg, cx: &mut ProtoCx<'_, Self>)
from.