Skip to main content

PerfectFailureDetector

Struct PerfectFailureDetector 

Source
pub struct PerfectFailureDetector { /* private fields */ }
Expand description

Detects crashes by heartbeat timeout.

Implementations§

Source§

impl PerfectFailureDetector

Source

pub fn new( me: NodeId, peers: impl IntoIterator<Item = NodeId>, period: Duration, timeout: Duration, ) -> Self

Detect among peers, announcing this process every period and declaring a peer crashed after timeout of silence.

For strong accuracy, timeout must exceed period plus the network’s delivery bound — otherwise a live process’s heartbeat can arrive after it has already been accused. Configure the bound from the simulator’s own Sim::delivery_bound rather than guessing it. Named rather than linked: recon-sim is a dev-dependency of this crate, so the path does not exist for a reader of these docs — and it is the right way round, since a protocol that depended on the simulator would be the thing constraint 2 forbids.

Source

pub fn period(&self) -> Duration

How often this process announces itself.

Source

pub fn detected(&self) -> impl Iterator<Item = NodeId> + '_

The processes currently believed crashed.

Source

pub fn has_detected(&self, node: NodeId) -> bool

Whether node has been detected as crashed.

Source

pub fn correct(&self) -> impl Iterator<Item = NodeId> + '_

The processes not yet detected as crashed, this one included.

Source

pub fn timeout(&self) -> Duration

The silence a process is allowed before being declared crashed.

Trait Implementations§

Source§

impl Debug for PerfectFailureDetector

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
Source§

impl Detector for PerfectFailureDetector

P satisfies the detector port, and never withdraws a suspicion.

PFD2 is strong accuracy — a detected process has crashed — so there is nothing to take back. The port’s second arm is unreachable over this detector rather than merely unused, which tests/detector_port.rs pins.

Source§

fn classify(_: Ind) -> DetectorInd

Read one of this detector’s indications in the port’s terms. Read more
Source§

impl Protocol for PerfectFailureDetector

Source§

type Scope = Infallible

No scope conditions: this protocol’s guarantees do not lapse.

Source§

type Meta = Infallible

Keeps nothing durably: a crash loses everything this protocol knows.

Source§

fn on_init(&mut self, cx: &mut ProtoCx<'_, Self>)

⟨ P, Init ⟩ do alive := Π; detected := ∅; starttimer(Δ).

The book’s own trigger, now that there is one. It used to be a Start command because there was no init event to hang the first timer on; there is, so there is no command.

Source§

type Cmd = Infallible

Requests from the layer above.
Source§

type Ind = Ind

Indications to the layer above — this protocol delivering on its guarantee.
Source§

type Msg = Heartbeat

What crosses the wire to a peer running the same protocol.
Source§

type Note = Note

The vocabulary in which this protocol narrates its decisions. Read more
Source§

type Entry = Infallible

The durable entries this protocol appends: what accumulates.
Source§

fn on_cmd(&mut self, cmd: Cmd, _cx: &mut ProtoCx<'_, Self>)

Handle a request from the layer above.
Source§

fn on_msg( &mut self, from: NodeId, Heartbeat: Heartbeat, cx: &mut ProtoCx<'_, Self>, )

Handle a message received from from.
Source§

fn on_timer(&mut self, id: TimerId, cx: &mut ProtoCx<'_, Self>)

Handle a timer that fired somewhere in this protocol or in what it composes. Read more
§

fn on_recovery( &mut self, _cx: &mut Cx<'_, Self::Msg, Self::Ind, Self::Note, Self::Meta, Self::Entry>, )

Resume after a crash, reading what survived. Read more
§

fn on_scope_event( &mut self, _scope: Self::Scope, _cx: &mut Cx<'_, Self::Msg, Self::Ind, Self::Note, Self::Meta, Self::Entry>, )

Handle a boundary of a scope this protocol’s guarantees depend on — its end, or the beginning of the one that succeeds it. Read more

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
§

impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
where ST: ?Sized, DT: ?Sized,

§

impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

§

impl<T> Read<Exclusive, BecauseExclusive> for T
where T: ?Sized,

Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = Infallible

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, <T as TryFrom<U>>::Error>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
§

impl<V, T> VZip<V> for T
where V: MultiLane<T>,

§

fn vzip(self) -> V

Source§

impl<D> VolatileDetector for D
where D: Detector<Meta = Infallible, Entry = Infallible>,