Arxiv:2012.03692V1 [Cs.DC] 7 Dec 2020
Total Page:16
File Type:pdf, Size:1020Kb
Separation and Equivalence results for the Crash-stop and Crash-recovery Shared Memory Models Ohad Ben-Baruch Srivatsan Ravi Ben-Gurion University, Israel University of Southern California, USA [email protected] [email protected] December 8, 2020 Abstract Linearizability, the traditional correctness condition for concurrent data structures is considered insufficient for the non-volatile shared memory model where processes recover following a crash. For this crash-recovery shared memory model, strict-linearizability is considered appropriate since, unlike linearizability, it ensures operations that crash take effect prior to the crash or not at all. This work formalizes and answers the question of whether an implementation of a data type derived for the crash-stop shared memory model is also strict-linearizable in the crash-recovery model. This work presents a rigorous study to prove how helping mechanisms, typically employed by non-blocking implementations, is the algorithmic abstraction that delineates linearizabil- ity from strict-linearizability. Our first contribution formalizes the crash-recovery model and how explicit process crashes and recovery introduces further dimensionalities over the stan- dard crash-stop shared memory model. We make the following technical contributions that answer the question of whether a help-free linearizable implementation is strict-linearizable in the crash-recovery model: (i) we prove surprisingly that there exist linearizable imple- mentations of object types that are help-free, yet not strict-linearizable; (ii) we then present a natural definition of help-freedom to prove that any obstruction-free, linearizable and help-free implementation of a total object type is also strict-linearizable. The next technical contribution addresses the question of whether a strict-linearizable implementation in the crash-recovery model is also help-free linearizable in the crash-stop model. To that end, we prove that for a large class of object types, a non-blocking strict-linearizable implementation cannot have helping. Viewed holistically, this work provides the first precise characterization of the intricacies in applying a concurrent implementation designed for the crash-stop (and resp. crash-recovery) model to the crash-recovery (and resp. crash-stop) model. arXiv:2012.03692v1 [cs.DC] 7 Dec 2020 1 Contents 1 Introduction 2 1.1 Contributions . .3 1.2 Related work . .3 2 Crash-stop Model 4 3 Characterization of the Crash-recovery Model 5 4 Process Helping 7 5 Strict-linearizability vs. Linearization-helping 9 6 Help-freedom vs. Strict-linearizability 12 6.1 Sticky-Bit Object . 13 6.2 An Equivalence between Linearizability and Strict-linearizability . 15 7 Strict-Linearizability vs. Universal-helping 18 7.1 Equivalence between Strict-linearizability and Universal-help Freedom . 18 8 Strict-Linearizability vs. Valency-helping 21 9 Discussion 23 1 Introduction Concurrent data structures for the standard volatile shared memory model typically adopt lin- earizability as the traditional safety property [15]. However, in the non-volatile shared memory model where processes recover following a crash, linearizability is considered insufficient since it allows object operations that crash to take effect anytime in the future. In the crash-recovery model [8], linearizability is strengthened to force crashed operations to take effect before the crash or not take effect at all, so-called strict-linearizability [2]. While there exists a well-studied body of linearizable data structure implementations in the crash-stop model [17], concurrent implementations in the crash-recovery model are comparatively nascent. Consequently, it is natural to ask: under what conditions is a linearizable implementation in the crash-stop also strict-linearizable in the crash-recovery model? Non-blocking implementations in the crash-stop model employ helping: i.e., apart from completing their own operation, processes perform additional work to help linearize concurrent operations and make progress. This helping mechanism enables an operation invoked by a process pi to be linearized by the event performed of another process pj, but possibly after the crash of pi. However, strict-linearizability stipulates that the operation invoked by pi be linearized before the crash event. Intuitively, this suggests that linearizable implementations that are help-free must be strict-linearizable (also conjectured in [8]). This work formalizes and answers this precise question: whether a help-free implementation of a data type derived for the crash-stop model can be used as it is in the crash-recovery model. Precisely answering this question necessitates the formalization of the crash-recovery shared memory model. Explicit process crashes introduces further dimensionalities to the set of ex- ecutions admissible in the crash-recovery model over the well formalized crash-stop shared memory [6]. Processes may crash on an individual basis, i.e., an event in the execution corre- sponds to the crash of a single process (we refer to this as the individual crash-recovery model). An event may also correspond to m (1 < m ≤ n), process crashes where n is total number of processes participating in the concurrent implementation (when m = n it is the full-system 2 crash-recovery model). Following a crash event in this model, the local state of the process is reset to its initial state when it recovers and restarts an operation assuming the old iden- tifiers crash-recovery model (and resp. new identifiers crash-recovery model) with the original process identifier (and resp. new process identifier). Our contributions establish equivalence and separation results for crash-stop and the identified crash-recovery models, thus providing a precise characterization of the intricacies in applying a concurrent implementation designed for thecrash-stop model to the crash-recovery model, and vice-versa. 1.1 Contributions First, we define the crash-recovery model and its characteristics. We show that there exist sequential implementations of object types in the crash-stop model that as is have inconsistent sequential specifications in the old identifiers crash-recovery model. We then consider how data structures use helping in the crash-stop model by adopting the definitions of linearization-helping [9] and universal-helping [5]. When considering an execution with two concurrent operations, the linearization of these operations dictates which operation take effect first. The definition of linearization-helping considers a specific event e, in which it is decided which operation is linearized first. In an implementation that does not have linearization-helping, e is an event by the process whose operation is decided to be the one that comes first. Universal-helping requires that the progress of some processes eventually ensures that all pending invocations are linearized, thus forcing a process to ensure concurrent operations of other processes are eventually linearized. The first technical contribution of this paper is proving that some pairs of conditions are incomparable. That is, an implementation can satisfy exactly one of them, both, or none. • linearization-helping vs. universal-helping • strict-linearizability vs. linearization-helping • strict-linearizability vs. universal-helping The second technical contribution is to show that under certain restrictions there is a cor- relation between some of the above pairs. • Restricting the definition of linearization-helping to be prefix-respecting, we prove that linearization-help free implies strict-linearizability. More specifically, any obstruction-free implementation of a total object type that is linearizable and has no linearization-helping in the crash-stop model is also strict-linearizable in the new identifiers individual crash- recovery model (Lemma §1). • We prove that any non-blocking implementation of an order-dependent type that is strict- linearizable in the crash-recovery model has no universal-helping in the crash-stop model (Lemma §7). Roadmap. The contributions in this paper are structured as follows: §2 introduces the crash- stop shared memory model and other preliminaries. §3 presents our characterization of the dimensionalities of the crash-recovery shared memory model. §4 recalls universal-helping, linearization-helping, valency-helping and presents new results on implementations satisfying these definitions. §5 discuss the correlation between strict-linearizable implementations and linearization-helping. §6 proves that help-freedom does not implies strict-linearizability in gen- eral, but under a natural definition of help-freedom it does follows. §7 proves that strict- linearizability and universal-helping are independent. However, for a large class of objects, strict-linearizability implies universal-help freedom. Finally, §8 discuss the relation between strict-linearizability and valency-helping. The paper is concluded with a short discussion in §9. 1.2 Related work Strict-linearizability was proposed by Aguilera et al. [2] who show that it precludes wait-free implementations of multi-reader single-writer registers from single-reader single-writer registers. 3 [8] showed that this is in fact possible with linearizability thus yielding a separation between the crash-stop and crash-recovery models. That helping mechanisms, typically employed by non-blocking implementations, is the algorithmic abstraction that may delineate linearizability from strict-linearizability was also conjectured in [8]. This is the first work to conclusively