pub struct Config {
pub seed: u64,
pub loss: f64,
pub duplication: f64,
pub reorder: f64,
pub latency_min: Duration,
pub latency_max: Duration,
pub reorder_delay: Duration,
pub synchronous: Option<Duration>,
pub sessions: bool,
pub reconnect_interval: Duration,
pub max_steps: u64,
}Expand description
Network conditions and run limits.
Every knob is consulted through the run’s seeded generator, so a configuration plus a seed determines a run completely.
Fields§
§seed: u64Seed for every random decision in the run — faults, latency, and protocol randomness.
loss: f64Probability in 0.0..=1.0 that a message is dropped rather than delivered.
duplication: f64Probability in 0.0..=1.0 that a message is delivered twice.
reorder: f64Probability in 0.0..=1.0 that a message is delayed far beyond normal latency,
forcing it behind messages sent after it.
latency_min: DurationShortest delivery delay.
latency_max: DurationLongest delivery delay. Jitter between the two produces ordinary reordering.
reorder_delay: DurationExtra delay applied to a message selected for reordering.
synchronous: Option<Duration>When set, the run is synchronous: delivery between connected, uncrashed processes is guaranteed within this bound, and nothing is lost, duplicated or given a reordering spike.
This is what a perfect failure detector needs and what the asynchronous default cannot offer: without a known bound, a live process whose messages are unlucky is indistinguishable from a crashed one. It constrains timing only — crashes and partitions still stop delivery.
sessions: boolWhen true, communication happens within sessions: between each pair of processes there is a session in which delivery is reliable, ordered and free of duplicates — what TCP or QUIC gives. A partition, a crash, or an explicit break ends it, losing an unknown suffix of what was in flight, and a new session begins at a higher epoch.
This is the model a deployed stack would run on. The fair-loss default is what you have if you build reliability yourself, which is the simulator’s own situation and not production’s.
reconnect_interval: DurationHow often a session-based run retries establishing sessions that are not up.
A deployed link keeps trying to reconnect on its own rather than waiting for the layers above to transmit, so the model does too. The value stands in for a retry interval, with or without backoff; no protocol may depend on it.
max_steps: u64Safety valve: a run stops after this many events, whatever the clock says.
Protocols such as the stubborn link retransmit forever by design, so a run is bounded by time or by this, never by quiescence.
Implementations§
Source§impl Config
impl Config
pub fn seed(self, seed: u64) -> Self
Sourcepub fn duplication(self, p: f64) -> Self
pub fn duplication(self, p: f64) -> Self
Deliver messages twice with probability p.
Sourcepub fn reorder(self, p: f64) -> Self
pub fn reorder(self, p: f64) -> Self
Delay messages far beyond normal latency with probability p, forcing reordering.
Sourcepub fn latency(self, min: Duration, max: Duration) -> Self
pub fn latency(self, min: Duration, max: Duration) -> Self
Deliver after a delay drawn uniformly from min..=max.
Jitter here is itself a source of reordering; reorder forces the extreme case.
Sourcepub fn synchronous(self, bound: Duration) -> Self
pub fn synchronous(self, bound: Duration) -> Self
Run synchronously: every message between connected, uncrashed processes is delivered
within bound, and none is lost or duplicated.
The bound is readable afterwards through Config::delivery_bound, so a protocol whose
correctness depends on it can be configured from the same value rather than from a guess.
Setting this overrides the fault knobs, and the override is enforced at delivery time —
calling loss afterwards will not quietly reintroduce loss.
Sourcepub fn delivery_bound(&self) -> Option<Duration>
pub fn delivery_bound(&self) -> Option<Duration>
The upper bound on delivery, when the run is synchronous.
Sourcepub fn is_synchronous(&self) -> bool
pub fn is_synchronous(&self) -> bool
Whether this run makes a timing guarantee.
Sourcepub fn sessions(self) -> Self
pub fn sessions(self) -> Self
Communicate within sessions: reliable, ordered, duplicate-free delivery while a session holds, and an unknown lost suffix when one ends.
Overrides the loss and duplication knobs, enforced at delivery time so builder order cannot reintroduce them. Latency still applies, but a message is never delivered before one sent earlier to the same peer.
Sourcepub fn reconnect_interval(self, d: Duration) -> Self
pub fn reconnect_interval(self, d: Duration) -> Self
How often to retry establishing sessions that are not up.
Sourcepub fn is_session_based(&self) -> bool
pub fn is_session_based(&self) -> bool
Whether this run communicates within sessions.