pub struct LoggedLink<P: Clone + Ord> { /* private fields */ }Expand description
Perfect-link guarantees over log-delivery, so that they hold across a restart.
Implementations§
Trait Implementations§
Source§impl<P: Clone + Ord> Protocol for LoggedLink<P>
impl<P: Clone + Ord> Protocol for LoggedLink<P>
Source§type Meta = u64
type Meta = u64
The send counter: one small value, rewritten before each send. See the module note.
Source§type Entry = (MsgId, P)
type Entry = (MsgId, P)
One log-delivered message; appended, so the write cost is linear rather than quadratic.
Source§fn on_init(&mut self, cx: &mut ProtoCx<'_, Self>)
fn on_init(&mut self, cx: &mut ProtoCx<'_, Self>)
⟨ lpl, Init ⟩ do delivered := ∅; store(delivered).
The initial write is what makes the branch real: after it, storage holds something, so every later restart takes the recovery path rather than starting afresh. What is written is the send counter at zero — the empty set is the empty sequence of entries, which needs no write of its own.
Source§fn on_recovery(&mut self, cx: &mut ProtoCx<'_, Self>)
fn on_recovery(&mut self, cx: &mut ProtoCx<'_, Self>)
upon event ⟨ lpl, Recovery ⟩ do retrieve(delivered); trigger ⟨ lpl, Deliver | delivered ⟩.
The record is read here rather than handed over, along with the send counter that keys it. Nothing else is dispatched until this returns, which is what makes it safe to have held an empty index a moment ago.
The layer above is told again: the notification sent before the crash may have been lost with the incarnation that sent it.
Source§type Scope = Infallible
type Scope = Infallible
Source§fn on_cmd(&mut self, _: Cmd<P>, cx: &mut ProtoCx<'_, Self>)
fn on_cmd(&mut self, _: Cmd<P>, cx: &mut ProtoCx<'_, Self>)
Source§fn on_msg(&mut self, from: NodeId, msg: Wire<P>, cx: &mut ProtoCx<'_, Self>)
fn on_msg(&mut self, from: NodeId, msg: Wire<P>, cx: &mut ProtoCx<'_, Self>)
from.