arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

OneBarrier:网络必须为透明容错提供什么以实现无开销的容错

OneBarrier: What a Network Must Provide for Transparent Fault Tolerance to Be Free

Bojie Li

arXiv 2608.14601首次发表:更新:

AI 中文总结

OneBarrier提出四项条件,通过网络全局顺序架构1Pipe和用户空间垫片,实现无开销的透明容错,经15种应用测试验证,核心协议已机器检查。

AI 中文摘要

透明容错——让未修改的服务器二进制文件在崩溃后仍能正常运行——已被追求了四十年,但始终未达到生产可用状态。所有尝试都在关键路径上付出了三项成本:记录消息到达顺序以用于重放、协调一致的快照,以及持有每个回复直到生成该回复的状态被持久化。本文认为这些成本并非本质性的,它们是网络既不保证顺序也不保证交付所付出的代价。我们提出了四项条件,在这些条件下这三项成本全部消失。其中三项与网络相关:顺序(消息以单一全局顺序交付)、屏障(交付由提交屏障确认)和持久化(每条消息在其屏障完成前被复制到备份节点);第四项确定性则由主机端实现:用户空间垫片为未修改的二进制文件实现确定性,开销为2%-10%,采用虚拟时间、虚拟化随机性和无共享分片替代线程调度。OneBarrier通过微秒级往返的网络全局顺序架构(1Pipe)实现了这四项条件。十五个未修改的应用程序——包括Redis、Memcached、Nginx、该HTTP服务以及多进程PostgreSQL——以字节一致的方式恢复,注入崩溃测试确认了线性化、恰好一次的历史记录;核心协议已在TLA+中进行了机器检查。放置在屏障内的持久写操作会为请求增加4.6微秒的延迟,而放置在屏障后的相同写操作则会增加3毫秒的延迟。在满足这些条件的网络上,容错是一种属性,而非一种负担。

英文摘要

Transparent fault tolerance -- making an unmodified server binary survive crashes -- has been pursued for four decades without reaching production. Every attempt paid three costs on the critical path: recording message arrival order for replay, coordinating a consistent snapshot, and holding each reply until the state that produced it was durable. This paper argues the costs are not intrinsic: they are the price of a network that guarantees neither order nor delivery. We state four conditions under which all three vanish. Three concern the network: Order (messages are delivered in one global sequence), Barrier (delivery is confirmed by a commit barrier), and Durability (each message is replicated to backups before its barrier completes). The fourth, Determinism, falls to the host: a user-space shim closes it for unmodified binaries at 2-10% overhead -- virtual time, virtualized randomness, and share-nothing sharding in place of thread scheduling. OneBarrier realizes all four conditions over an in-network total-order fabric (1Pipe) with microsecond round trips. Fifteen unmodified applications -- including Redis, Memcached, Nginx, Node.js, and a multi-process PostgreSQL -- recover byte-identically, and crash injection confirms linearizable, exactly-once histories; the core protocols are machine-checked in TLA+. A durable write placed inside the barrier adds 4.6 microseconds to a request; the same write placed after it adds three milliseconds. On a network that meets the conditions, fault tolerance is a property, not a tax.

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑