Jepsen: Distributed Systems Safety Analysis
jepsen.io
jepsen.io
EDIT: don't mean to speak for him though; I hope this is ok.
> Get the latest Flash player to view this content
No, I won't. This scares me too much: https://www.cvedetails.com/vulnerability-list/vendor_id-53/p...
Not sure why anyone would want to play video (I guess it's a video? I don't do Flash either) through Flash nowadays... Isn't it easier and better to just use HTML video tag?
You can also use JS detection. For instance, Youtube uses Flash unless you allow google.com & googlevideo.com, then it uses HTML video tag. It's not like it costs you anything to add HTML video tag.
>> Can you test X next?
> Tests take about a month. I do take suggestions into consideration, but I can't promise you anything. Backlog is a few years long at this point.
(from https://aphyr.com/about)
> For folks who would like to pay for a Jepsen analysis, email aphyr+jepsen@aphyr.com. I've got one client lined up but I'll keep in touch. :)
A negative report could generate the opposite though. Are they ready to bet the new $12M+ on that?
Then also if they compensate him, not sure how unbiased others will think (and we are talking about perception here) the study will be.
Slava at RethinkDB here. Yes, we are.
I disagree; it all depends on how they act upon it.
So worst case scenario he finds something deeply flawed. What does RethinkDB do? Work to fix it while communicating and being responsive to the development community. Show developers that you're humble and, more importantly, you listen and fix things. That would generate a good amount of good will, in my opinion.
Everyone makes mistakes - what matters is what you do to discover and fix them.
Right now I'd trust Aphyr more than any other analyst, consultant, or full-time employee (with employment to lose) to give truly impartial judgement.
It's even harder to square with the appearance of impartial judgment. What if a product is honestly great? If we decide that he's being fair because he says both positive and negative things, he has an incentive to create the appearance of fairness rather than actual fairness.
There's a reason that systems where truth is important (e.g., legal proceedings, medicine, science) have complicated rules around conflicts of interest. I hope he finds a way to find funding that doesn't put either his judgment or his reputation at risk. Consider, e.g., Consumer Reports: they get money from their subscribers, not advertisers or manufacturers. Maybe he could let database users fund all his public Jepsen work.
huh, you mean Factual
I would love to see the multixact data corruption problems introduced in 9.3 analyzed, and see if he can verify them to be solved in the latest version.
As an example: This means that idempotency is really important if you're doing any kind of retries on commit failure.
EDIT: Another example: If you're doing application-level optimistic concurrency control (using e.g. an incrementing version number) you can end up in a situation where an update appears to conflict with itself. Usually, though, this isn't a big concern since client<->server paritions are usually catastrophic anyway.
(Off the top of my head that's what I can recall -- there may be other things to be gleaned from the original article.)
[1] At least for all practical purposes.
This is true for almost every database. Otherwise they would require a distributed transaction between the client and server.
You are of course technically right... which is the best kind of right! :)
Apples and Oranges.
(The problem, then, is that data structures with all these properties are hard to find.)
So to answer the question, no Jepsen was not "developed at stripe" though part of its development probably happened there.
[0] https://twitter.com/avibryant/status/561315494204952579
[1] https://aphyr.com/posts/281-call-me-maybe-carly-rae-jepsen-a...
TL;DR - Aphyr thinks Damien Katz never read this: https://en.wikipedia.org/wiki/Consensus_%28computer_science%...
this is why so many of the new DB offerings have docs that are either misleading or wrong -- often the doc writers or even the devs themselves don't know what invariants their system can guarantee and assume several that it can't.
I think it's smart to know a little about the literature; enough to know what battle you don't want to fight. It is not smart to try to develop an engine on the basis that it will need to beat the law of thermodynamic to be possible.
But also, “They did not know it was impossible so they did it”, Mark Twain
+1 For Jepson on Couchbase