pub struct PerfectFailureDetector { /* private fields */ }Expand description
Detects crashes by heartbeat timeout.
Implementations§
Source§impl PerfectFailureDetector
impl PerfectFailureDetector
Sourcepub fn new(
me: NodeId,
peers: impl IntoIterator<Item = NodeId>,
period: Duration,
timeout: Duration,
) -> Self
pub fn new( me: NodeId, peers: impl IntoIterator<Item = NodeId>, period: Duration, timeout: Duration, ) -> Self
Detect among peers, announcing this process every period and declaring a peer crashed
after timeout of silence.
For strong accuracy, timeout must exceed period plus the network’s delivery bound —
otherwise a live process’s heartbeat can arrive after it has already been accused.
Configure the bound from the simulator’s own Sim::delivery_bound rather than guessing
it. Named rather than linked: recon-sim is a dev-dependency of this crate, so the path
does not exist for a reader of these docs — and it is the right way round, since a protocol
that depended on the simulator would be the thing constraint 2 forbids.
Sourcepub fn detected(&self) -> impl Iterator<Item = NodeId> + '_
pub fn detected(&self) -> impl Iterator<Item = NodeId> + '_
The processes currently believed crashed.
Sourcepub fn has_detected(&self, node: NodeId) -> bool
pub fn has_detected(&self, node: NodeId) -> bool
Whether node has been detected as crashed.
Trait Implementations§
Source§impl Debug for PerfectFailureDetector
impl Debug for PerfectFailureDetector
Source§impl Detector for PerfectFailureDetector
P satisfies the detector port, and never withdraws a suspicion.
impl Detector for PerfectFailureDetector
P satisfies the detector port, and never withdraws a suspicion.
PFD2 is strong accuracy — a detected process has crashed — so there is nothing to take back.
The port’s second arm is unreachable over this detector rather than merely unused, which
tests/detector_port.rs pins.
Source§impl Protocol for PerfectFailureDetector
impl Protocol for PerfectFailureDetector
Source§type Scope = Infallible
type Scope = Infallible
No scope conditions: this protocol’s guarantees do not lapse.
Source§type Meta = Infallible
type Meta = Infallible
Keeps nothing durably: a crash loses everything this protocol knows.
Source§fn on_init(&mut self, cx: &mut ProtoCx<'_, Self>)
fn on_init(&mut self, cx: &mut ProtoCx<'_, Self>)
⟨ P, Init ⟩ do alive := Π; detected := ∅; starttimer(Δ).
The book’s own trigger, now that there is one. It used to be a Start command because
there was no init event to hang the first timer on; there is, so there is no command.
Source§type Cmd = Infallible
type Cmd = Infallible
Source§type Entry = Infallible
type Entry = Infallible
Source§fn on_cmd(&mut self, cmd: Cmd, _cx: &mut ProtoCx<'_, Self>)
fn on_cmd(&mut self, cmd: Cmd, _cx: &mut ProtoCx<'_, Self>)
Source§fn on_msg(
&mut self,
from: NodeId,
Heartbeat: Heartbeat,
cx: &mut ProtoCx<'_, Self>,
)
fn on_msg( &mut self, from: NodeId, Heartbeat: Heartbeat, cx: &mut ProtoCx<'_, Self>, )
from.