pub struct MultiPaxosSynod<C: Clone, L: VolatileLink<SynodMsg<C>> = SessionLink<SynodMsg<C>>> { /* private fields */ }Expand description
The Synod protocol: acceptor and leader in one process, as §4.4 co-locates them.
L is the link beneath, a parameter rather than a fixed type, and it defaults to
SessionLink rather than to the perfect link. That is deliberate: the real-world set’s first
obligation is running over a session link, and this is the first module here that can meet it
before joining rather than after. A boundary is classified and propagated; this layer bridges
nothing.
Implementations§
Source§impl<C: Clone, L: VolatileLink<SynodMsg<C>>> MultiPaxosSynod<C, L>
impl<C: Clone, L: VolatileLink<SynodMsg<C>>> MultiPaxosSynod<C, L>
Sourcepub fn with_link(
me: NodeId,
acceptors: impl IntoIterator<Item = NodeId>,
timing: Timing,
link: L,
) -> Self
pub fn with_link( me: NodeId, acceptors: impl IntoIterator<Item = NodeId>, timing: Timing, link: L, ) -> Self
The Synod protocol among acceptors, over a link the caller supplies.
Sourcepub fn adopted_ballot(&self) -> Option<Ballot>
pub fn adopted_ballot(&self) -> Option<Ballot>
α.ballot_num — the ballot this process has adopted as an acceptor, or ⊥.
Sourcepub fn leader_ballot(&self) -> Ballot
pub fn leader_ballot(&self) -> Ballot
λ.ballot_num — the ballot this process is leading with.
Sourcepub fn is_active(&self) -> bool
pub fn is_active(&self) -> bool
λ.active — whether phase one has completed for the current ballot.
Sourcepub fn is_trusted(&self) -> bool
pub fn is_trusted(&self) -> bool
Whether Ω currently trusts this process.
Sourcepub fn trusted_leader(&self) -> Option<NodeId>
pub fn trusted_leader(&self) -> Option<NodeId>
Who Ω currently trusts, if it has spoken.
Sourcepub fn decided_count(&self) -> usize
pub fn decided_count(&self) -> usize
The slots this leader has seen decided. Grows with slots decided, exactly as proposals
does; §4.2 collects both.
Sourcepub fn accepted_count(&self) -> usize
pub fn accepted_count(&self) -> usize
How many pvalues this acceptor holds — after §4.1, the number of slots it has accepted
for, not the number of ⟨ballot, slot⟩ pairs. Grows with the slots handled, which is the
measurement docs/bounded-space.md wants for a transcription.
Sourcepub fn commanded_slots(&self) -> impl Iterator<Item = Slot> + '_
pub fn commanded_slots(&self) -> impl Iterator<Item = Slot> + '_
The slots this leader currently has a commander for.
Sourcepub fn accepted_for(&self, slot: Slot) -> Option<(Ballot, &C)>
pub fn accepted_for(&self, slot: Slot) -> Option<(Ballot, &C)>
The pvalue this acceptor holds for slot, if any — after §4.1, at most one, carrying the
highest ballot it has accepted for that slot.
Sourcepub fn collected_below(&self) -> Slot
pub fn collected_below(&self) -> Slot
The slot below which this process has discarded its state — §4.2’s watermark, as it has been acted on. Only ever rises.
Sourcepub fn reports_held(&self) -> usize
pub fn reports_held(&self) -> usize
How many members have said how far they have applied. Bounded by membership; the
measurement docs/bounded-space.md wants beside the two that are now bounded.
Sourcepub fn is_scouting(&self) -> bool
pub fn is_scouting(&self) -> bool
Whether a scout is running phase one.
Source§impl<C: Clone> MultiPaxosSynod<C, SessionLink<SynodMsg<C>>>
impl<C: Clone> MultiPaxosSynod<C, SessionLink<SynodMsg<C>>>
Sourcepub fn new(
me: NodeId,
acceptors: impl IntoIterator<Item = NodeId>,
timing: Timing,
) -> Self
pub fn new( me: NodeId, acceptors: impl IntoIterator<Item = NodeId>, timing: Timing, ) -> Self
The Synod protocol among acceptors, over the session link this module defaults to.
Trait Implementations§
Source§impl<C: Debug + Clone, L: Debug + VolatileLink<SynodMsg<C>>> Debug for MultiPaxosSynod<C, L>
impl<C: Debug + Clone, L: Debug + VolatileLink<SynodMsg<C>>> Debug for MultiPaxosSynod<C, L>
Source§impl<C, L> Protocol for MultiPaxosSynod<C, L>
impl<C, L> Protocol for MultiPaxosSynod<C, L>
Source§type Scope = <L as Protocol>::Scope
type Scope = <L as Protocol>::Scope
Whatever the link’s guarantees are conditional on. This layer adds no condition of its own and bridges none of the link’s.
Source§type Meta = Infallible
type Meta = Infallible
Keeps nothing durably, which is what makes this crash-stop. §4.3 is the change that alters it, and the module documentation says what a durable ballot counter would buy.
Source§fn on_cmd(&mut self, cmd: Cmd<C>, cx: &mut ProtoCx<'_, Self>)
fn on_cmd(&mut self, cmd: Cmd<C>, cx: &mut ProtoCx<'_, Self>)
A request from the layer above carries no sender, which is what distinguishes it from a forwarded one: only a proposal that has not travelled may be forwarded.
Source§fn on_timer(&mut self, id: TimerId, cx: &mut ProtoCx<'_, Self>)
fn on_timer(&mut self, id: TimerId, cx: &mut ProtoCx<'_, Self>)
An expiry is offered to every layer, so both children are given it and this layer acts only on the handle it registered.
Source§fn on_init(&mut self, cx: &mut ProtoCx<'_, Self>)
fn on_init(&mut self, cx: &mut ProtoCx<'_, Self>)
⟨ Init ⟩ — start the detector, whose first Trust may immediately make this process scout,
and arm the sweep.
Source§fn on_scope_event(&mut self, scope: L::Scope, cx: &mut ProtoCx<'_, Self>)
fn on_scope_event(&mut self, scope: L::Scope, cx: &mut ProtoCx<'_, Self>)
Hand the boundary down to the link, which is the layer that knows what it means. Leaving
this to the trait’s default would take a scope event the driver raised and drop it — the
cardinal sin of docs/conditional-guarantees.md.
Source§type Msg = Wire<<L as Protocol>::Msg>
type Msg = Wire<<L as Protocol>::Msg>
Source§type Entry = Infallible
type Entry = Infallible
Source§fn on_msg(&mut self, from: NodeId, msg: Self::Msg, cx: &mut ProtoCx<'_, Self>)
fn on_msg(&mut self, from: NodeId, msg: Self::Msg, cx: &mut ProtoCx<'_, Self>)
from.