The fail-stop processor approach
Fred B. Schneider · 1987
Introduction Programming a computer system that is subject to failures is a difficult task. A malfunctioning processor might perform arbitrary and spontaneous state transformations, instead of the transformations specified by the programs it executes. Thus, even a correct program cannot be counted on to implement a desired input-output relation when executed on a malfunctioning processor. On the other hand, it is impossible to build a computer system that always operates correctly in spite of failures in its components by using (only) a finite amount of hardware . Fortunately, most applications do not require complete fault-tolerance; it is sufficient that the system work correctly provided no more than some predefined number of failures occur within some time interval, or provided certain types of failures do not occur. This more modest goal is attainable. In this chapter we present an approach to designing fault-tolerant computing systems based on the notion of a fail-stop proce