learning_tla/lamport_video/docs/lecture06.md
2025-02-08 18:44:33 +01:00

2.6 KiB

Two-phase commit

Records

  • r == [prof |-> "Fred", num |-> 42] defines
    • r as a record with two fields prof and num
    • The vales of the fields can be written r.prof = "Fred", r.num = 42
  • Corresponds roughly to a C struct, but with the field order being irrelevant, like in a map.
  • [prof: {"Fred", "Ted", "Ned"}, num: 0..99]
    • is the set of all records of the form [prof |-> ..., num |-> ...]
    • with the value of prof being in {"Fred", "Ted", "Ned"}
    • and the value of num being in 0..99
    • one value would be [prof: "Fred", num: 42]
    • That value is actually a function f
      • Its domain is the set {"prof", "num"}
      • Such that f["prof"] = "Fred" /\ f["num"] = 42
  • f.prof is an abbreviation for f["prof"]
  • [f EXCEPT !["prof"] = "Red"] has shortcut
    [f EXCEPT !.prof = "Red"]

An action formula is one that contains primed variables.

In a formula, conditions without a prime are on the first state of a step, and are called "enabling conditions". They should almost always go at the beginning of an action formula, for readability.

In 2-phase commit, all RMs are interchangeable.

Suppose RM = {"r1", "r2", "r3" }

Swapping "r1" with "r3" in one possible state also yields a possible state. This means

  • rmState["r1"] <-> rmState["r3"]
  • [type |-> "Prepared", rm |-> "r1"] \in msgs
    <->
    [type |-> "Prepared", rm |-> "r3"] \in msgs
  • etc

If we interchange them in ALL states of a behavior b allowed by the TwoPhase spec, we get another behavior also allowed by that spec. TLC does not habve to check it if it has already checked b : RM is a symmetry set of TwoPhase

Being a symmetry set for a specification means all members of a set can be interchanged with no effect.

TLC will check fewer state if the model sets a symmetry set to a set of model values. In the model, replace the model, which was {"r1", "r2", "r3"} as an ordinary assignment, with a set of model values with symmetry set checked, and value {r1, r2, r3} (no quotes).

The model still has the same 288 reachable states as before. But not TLC only has to check 80.

WARNING: TLC may miss errors if we claim a set is a symmetry set when it is not.

"For now", we can declare a set to be a symmetry set if its model values are not used elsewhere.

Correctness of two-phase commit

In module TwoPhase, the statement INSTANCE TCommit imports the definitions from TCommit into module TwoPhase.

This allows adding the TCConsistent invariant from TCommit to the model for TwoPhase.

Two-phase commit doesn't just maintain the invariance of TCConsistent: it implements the specification of transaction commit.