Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
aphyr
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
9 ms
·
61.
▲
by
aphyr
2y ago
I'm not sure. I've worked on a few projects now which employed simulation testing and passed, only to discover serious bugs using Jepsen. State space exploration and oracle design are hard problems, and I'm not convinced ther
62.
▲
by
aphyr
2y ago
You'll find lots about the Jepsen analysis process here: https://jepsen.io/services/analysis
63.
▲
by
aphyr
2y ago
I have not yet, though you're not the first to ask. Some folks have suggested it might be... how do you say... fun? :-)
64.
▲
by
aphyr
2y ago
I would love to do a Kafka analysis. :-)
65.
▲
by
aphyr
2y ago
Here's a good article from New Relic on the problem, if you'd like more detail: https://newrelic.com/blog/best-practices/kafka-consumer-conf... Or here, you can reproduce it yourself using the Bufstream
66.
▲
by
aphyr
2y ago
Ack, pardon me. That should be fixed now!
67.
▲
by
aphyr
2y ago
It is a little surprising, and I agree, the docs here are not doing a particularly good job of explaining it. It might help to ask: if you don't explicitly commit, how does Kafka know when you've processed the messages it gave you
68.
▲
Jepsen: Bufstream 0.1
(jepsen.io)
224 points
by
aphyr
2y ago
|
85 comments
69.
▲
by
aphyr
2y ago
For this test, you can do it on pretty much any reasonable Linux machine. Longer histories can churn through more CPU and RAM--some of the more aggressive tests I ran for this work involved 20 GB heaps and 50 cores--but you can tune all tha
70.
▲
by
aphyr
2y ago
Yeah, that's a good way of phrasing it! :-)
71.
▲
by
aphyr
2y ago
> strict serializability doesn't imply idempotency I think we're probably getting at the same thing, but I do want to clarify a bit. A Strict Serializable history, like a Serializable one, requires equivalence to a total order
72.
▲
Jepsen: Jetcd 0.8.2
(jepsen.io)
134 points
by
aphyr
2y ago
|
18 comments
73.
▲
by
aphyr
2y ago
This is also good to hear! I'm not sure whether I'd call it a "footgun" per se--that's really an empirical question about how Datomic's users understand its model. I can say that as someone with some database e
74.
▲
by
aphyr
2y ago
This is good to hear! Nubank has also argued that in their extensive use of Datomic, this kind of issue doesn't really show up. They suggest custom transaction functions are infrequently written, not often composed, and don't usua
75.
▲
by
aphyr
2y ago
Yeah, I think this is next to Zookeeper as one of the most positive Jepsen reports. :-)
76.
▲
by
aphyr
2y ago
Thank you!
77.
▲
by
aphyr
2y ago
To build on this, Datomic includes a pre-commit conflict check that would prevent this particular example from committing at all: it detects that there are two incompatible assertions for the same entity/attribute pair, and rejects the
78.
▲
by
aphyr
2y ago
Yeah, this basically boils down to "a potential pitfall, but consistent with documentation, and working as designed". Whether this actually matters depends on whether users are writing transaction functions which are intended to
79.
▲
Jepsen: Datomic Pro 1.0.7075
(jepsen.io)
401 points
by
aphyr
2y ago
|
98 comments
80.
▲
by
aphyr
3y ago
Yeah, of course :-)
81.
▲
by
aphyr
3y ago
You'll find many of those additional variants (e.g. strong session SI) in the linked papers, and they're cited extensively in the Jepsen reports as well. I just haven't had time to write up every single model--tried to stick
82.
▲
by
aphyr
3y ago
Same. Hi, Apple! :D I'd love to do more work with predicates in general. That's an open research problem I've been noodling on for years. Pretty much any SQL DB would be a good candidate for that work! I'm gonna be a wei
83.
▲
by
aphyr
3y ago
It's not a huge market. I usually have a queue of clients, but both deal flow and actual scheduling are wildly variable--sometimes I'll go without income for six months or more. I've considered hiring one or two people, but I
84.
▲
by
aphyr
3y ago
Even an unpaid report like this involves weeks of work: reading docs, designing tests, executing and refining them, filing issues, writing the report, and editing it. Each report costs thousands of dollars in hardware and and editing. I
85.
▲
RavenDB 6.0.2 (A Jepsen Report)
(jepsen.io)
195 points
by
aphyr
3y ago
|
69 comments
86.
▲
by
aphyr
3y ago
The point of isolation levels is that the database manages those locks (or other concurrency control mechanisms) for you.
87.
▲
by
aphyr
3y ago
This depends on what you mean by "atomic". Prior to 5.0, MongoDB's defaults were to use a sub-majority write concern. This allowed all kinds of interesting atomicity violations, even on single documents. For instance, you cou
88.
▲
by
aphyr
3y ago
The FUSE stuff actually isn't too bad--Jepsen goes to a lot of trouble to make all this stuff automatic. The test harness pulls dependencies, compiles LazyFS, and mounts the filesystem for you. Just pass `--lazyfs` at the CLI. :-)
89.
▲
by
aphyr
3y ago
Basically all of it. MariaDB exhibits every class of anomaly we found in MySQL, all in single-node deployments.
90.
▲
by
aphyr
3y ago
I, uh, do want to point out that the alternative here is not "everything is OK". If you don't abort when, say, two users update the same row concurrently, then you might cause (e.g.) silent data loss for one of them. Or you
More ›