A Review of Software Upgrade Techniques for Distributed Systems

Sameer Ajmani · 2007

This document reviews work on software upgrades in distributed systems. The main text describes the work in various sub-areas, and the bibliography provides annotations on these and several other related papers. 1 Reconfigurable Distributed Systems The earliest work on upgrades in distributed systems appears to be Bloom’s work on reconfiguration in Argus [25,26]. Argus is a strongly-typed distributed system in which modules called “guardians” implement interfaces composed of sets of “handlers ” (i.e., RPCs). Argus guarantees that stable state survives crashes and that actions are atomic. Bloom’s work addresses the problem of replacing implementations in this environment. The unit of replacement may be a single guardian (which resides at a single physical node) or a set of multiple guardians, called a subsystem (which may span nodes). Bloom defines a formal model to determine which replacements are legal; these are those replacements that preserve or invisibly extend the replaced subsystem’s continuation abstraction. Bloom presents several examples of replacements that seem intuitively legal but that actually violate this condition. The actual mechanisms used to replace subsystems allow a user to manually locate,

Read the paper · More papers on PaperTik