arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

分布式系统中的重试放大:重试策略及其在级联故障中的作用的系统分析

Retry Amplification in Distributed Systems: A Systematic Analysis of Retry Policies and Their Role in Cascading Failures

Rishabh Mehan, Jasmit Kaur Saluja

arXiv 2608.25403首次发表:更新:

AI 中文总结

本文针对分布式系统的重试策略,引入重试放大因子(RAF),发现其存在放大请求量的问题,梳理出五种反模式,提出自适应重试预算(ARB)方法,验证其可维持高成功率,主张重试行为应系统设计而非本地配置。

AI 中文摘要

重试机制是弹性分布式系统的标准组成部分,但调用路径中的每一层并发重试时的集体行为,相较于指导客户端层面重试的规则,人们对其了解较少。本文引入重试放大因子(RAF)这一指标,用于量化部分故障期间重试策略产生的额外请求量。在对200个开源Python微服务项目的研究中,检测到11.5%的项目存在显式重试逻辑,结合对自身漏检情况的核查,真实普及率接近41%;在检测到的项目中,60.9%的项目至少存在一个无退避的配置,经人工验证,113个生产配置中仅有1个对延迟进行了随机化处理。随后,本文在模拟环境中(每种策略各进行100次试验)评估这些策略:在相关故障下,与完全不进行重试相比,朴素的标准重试策略将成功率从55.4%降至41.5%。本文梳理出五种常见反模式,提出自适应重试预算(ARB)方法,并证明受预算约束的重试策略能将成功率维持在接近无重试的基准水平,同时仍可从瞬态故障中恢复。这些结果表明,重试行为应被设计为系统层面的属性,而非在每个调用站点单独配置。

英文摘要

Retry mechanisms are a standard component of resilient distributed systems, but their collective behavior, when every tier in a call path retries concurrently, is less well understood than the per-client guidance that produced them. This paper introduces the retry amplification factor (RAF), a metric quantifying the additional request volume that retry policies generate during partial failures. In a study of 200 open-source Python microservice projects, explicit retry logic is detected in 11.5%, and an audit of our own false negatives places true prevalence near 41%. Among the projects detected, 60.9% contain at least one configuration without backoff, and after manual verification exactly one of 113 production configurations randomizes its delay. We then evaluate these policies in simulation (n = 100 trials per strategy). Under correlated failures, a naive standard retry policy reduces the success rate from 55.4% to 41.5% relative to performing no retries at all. We catalog five recurring anti-patterns, propose Adaptive Retry Budgeting (ARB), and show that budget-constrained retries maintain success rates close to the no-retry baseline while still recovering from transient faults. These results indicate that retry behavior should be designed as a system-level property rather than configured locally at each call site.

DOI:10.2139/ssrn.6313332

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑