8.5 Variable Recovery Point Creation
The principle of recovery point (RP) tuning [54] might be best explained with an
example. Imagine a program Q with execution time T q in which during compile and
link time n recovery points are inserted. Please note that recovery points are only
placed in specific locations, for example, procedure entrance.
In loops such as while, repeat until and for, no recovery points are placed, as it is
in general not statically known how many times such a loop will be executed.
Therefore, a consistent numbering of the recovery points as it is required as shown
later is difficult.
Creating recovery points is expensive; we propose therefore to dynamically
adjust the frequency of the recovery point creation. The basic principle is simple.
The normal malfunction rate Δk est (faults/time) of the system can be calculated or
estimated in advance as well as the maximum tolerable malfunction rate Δk max .
If the current malfunction rate c is higher than the maximum rate, the system is
considered as faulty. We now split the possible malfunction intensities into n equal
intervals (Eq. 8.1).
Dk ¼
Dk max À Dk est
n
ð8:1Þ
The theoretical minimum of Δk est is of course 0. Whenever a request for an RP
creation is sent to the operating system, it can decide whether a real recovery point
(RP) is created or just a fake one (FRP).
In case of a fake (not-created) recovery point, the call is simply returned to the
application that results in a minimal performance impact. To implement this feature,
the runtime keeps a table containing a mapping between the reliability modes and
the indexes of the recovery points that should start a real recovery point creation.
In other words, if the index i of the current recovery point does match the rule
given by the current reliability mode introduced by runtime system, the recovery
point is created; otherwise, a fake recovery point is created.
Figure 8.4 shows an example of such a rule, where the recovery point is only
created if i mod n = 0, i.e., every nth recovery point. This rule can of course be
adapted to the needs of the system and application.
The reliability mode is changed dynamically by the runtime system if a change
in the current fault rate is detected or if an additional safety-critical application is
started. The simplest scheme to adjust the current reliability index is by changing it
linearly depending on the current malfunction rate of the system.
Every fault is logged by the runtime and can therefore be used for fine-tuning. It
is assumed that the fault rate does not change in extremely short time, and that the
index is only changed after program termination, which eases recovery.
The current index is therefore calculated as follows:
8.5 Variable Recovery Point Creation
125
The principle of recovery point (RP) tuning [54] might be best explained with an
example. Imagine a program Q with execution time T q in which during compile and
link time n recovery points are inserted. Please note that recovery points are only
placed in specific locations, for example, procedure entrance.
In loops such as while, repeat until and for, no recovery points are placed, as it is
in general not statically known how many times such a loop will be executed.
Therefore, a consistent numbering of the recovery points as it is required as shown
later is difficult.
Creating recovery points is expensive; we propose therefore to dynamically
adjust the frequency of the recovery point creation. The basic principle is simple.
The normal malfunction rate Δk est (faults/time) of the system can be calculated or
estimated in advance as well as the maximum tolerable malfunction rate Δk max .
If the current malfunction rate c is higher than the maximum rate, the system is
considered as faulty. We now split the possible malfunction intensities into n equal
intervals (Eq. 8.1).
Dk ¼
Dk max À Dk est
n
ð8:1Þ
The theoretical minimum of Δk est is of course 0. Whenever a request for an RP
creation is sent to the operating system, it can decide whether a real recovery point
(RP) is created or just a fake one (FRP).
In case of a fake (not-created) recovery point, the call is simply returned to the
application that results in a minimal performance impact. To implement this feature,
the runtime keeps a table containing a mapping between the reliability modes and
the indexes of the recovery points that should start a real recovery point creation.
In other words, if the index i of the current recovery point does match the rule
given by the current reliability mode introduced by runtime system, the recovery
point is created; otherwise, a fake recovery point is created.
Figure 8.4 shows an example of such a rule, where the recovery point is only
created if i mod n = 0, i.e., every nth recovery point. This rule can of course be
adapted to the needs of the system and application.
The reliability mode is changed dynamically by the runtime system if a change
in the current fault rate is detected or if an additional safety-critical application is
started. The simplest scheme to adjust the current reliability index is by changing it
linearly depending on the current malfunction rate of the system.
Every fault is logged by the runtime and can therefore be used for fine-tuning. It
is assumed that the fault rate does not change in extremely short time, and that the
index is only changed after program termination, which eases recovery.
The current index is therefore calculated as follows:
8.5 Variable Recovery Point Creation
125
