Learn Labs
9. The Trouble with Distributed Systems

9.12 Self-test

Self-test37 questions

—/37
  1. Why do computers deliberately crash rather than return wrong results? What does that design choice hide?

  2. Define partial failure. Why is nondeterminism the thing that makes it hard?

  3. List the six things that may have happened when a request times out. Which of them mean the operation already took effect?

  4. Give four reasons TCP's "reliability" doesn't give you application-level reliability. What do you actually need?

  5. Why doesn't redundant network hardware reduce faults as much as expected?

  6. Give two examples of asymmetric or partial network faults from the chapter.

  7. Enumerate the four points at which a packet can be queued, and say which one is invisible to both endpoints.

  8. Why does a system near capacity have far worse delay variance than one with spare capacity?

  9. Why is there no "correct" timeout value? What should you do instead of a constant?

  10. Explain the cascading-failure loop caused by a timeout that's too short.

  11. Contrast a telephone circuit with a TCP connection. Why did the internet choose packet switching?

  12. "Variable delays are not a law of nature." Explain the cost/benefit trade-off in one sentence.

  13. Give three properties of monotonic clocks and three of time-of-day clocks. Which is safe for measuring a timeout, and why?

  14. Why do bad clocks cause silent data loss rather than visible crashes?

  15. Walk through the LWW example where a causally later write gets an earlier timestamp. Name three separate problems with client-clock LWW.

  16. Why can NTP never be accurate enough to guarantee correct event ordering?

  17. What is a clock confidence interval? Why do most APIs not expose one, and what do TrueTime and ClockBound do differently?

  18. Explain Spanner's commit-wait. Why are atomic clocks helpful but not strictly necessary?

  19. Find both bugs in the lease-renewal loop. Which one survives switching to a monotonic clock?

  20. List six causes of a multi-second process pause. Which two can occur without any code of yours running?

  21. Why don't mutexes and semaphores translate to distributed systems?

  22. What does "hard real-time" require at each layer, and why is real-time not the same as high-performance?

  23. Describe the technique of treating a GC pause as a planned outage.

  24. Tell the three "majority rules" parables. What is the moral, in one sentence?

  25. Why can there only ever be one majority? What does that buy you?

  26. Draw both distributed-lock failure modes. Which one involves no pause at all?

  27. Why is STONITH insufficient? Give three reasons.

  28. Explain fencing tokens. What must the storage side do, and what must a newly-elected leaseholder do immediately?

  29. How do you fence a leaderless replicated store with LWW?

  30. Define a Byzantine fault. Give two contexts where BFT is warranted and two things it cannot protect against.

  31. Name three cheap defences against "weak lying."

  32. Define the three timing models and the four node-failure models. Which combination is most useful, and which failure mode does it fail to capture?

  33. Distinguish safety from liveness precisely (not "bad" vs "good"). Which one may be conditioned on caveats, and what caveats are standard?

  34. Why does node amnesia break quorum correctness? What does that tell you about system models?

  35. Compare model checking, fault injection, and DST on what each finds and misses. Why is DST's replayability so valuable?

  36. List six places determinism has appeared in this book so far. Name two residual sources of nondeterminism even after mocking I/O and clocks.

  37. Design question

    you operate a sharded database with single-leader replication per shard, leases held via etcd, storage in S3, running on VMs in three availability zones. Enumerate every failure mode from this chapter that could produce two nodes writing as leader for the same shard, and specify the mechanism you'd use to make each one harmless. State explicitly which of your defences are safety properties and which are liveness properties.