The Consensus Problem Lab (Interactive)
Crash nodes, split quorums, and flip async ambiguity to watch safety or liveness give way. Exercise the consensus spec directly: agreement and termination cards flip as you vary cluster size, crash count, partition split, and the FLP-style uncertainty of message timing.
Safety vs Liveness Consensus Bench
Crash nodes, split the cluster, and attempt a decision. Watch the four consensus properties bend — never break safety, sometimes lose liveness.
At most one side can form a majority, so two conflicting decisions are impossible.
A quorum exists on the reachable side; non-faulty nodes eventually decide.
Raft and Paxos make the same bet visible here: they never sacrifice Agreement. When quorum vanishes they simply stop deciding, and they escape permanent FLP stalls by assuming partial synchrony plus randomized election timeouts. Try N=4 with a 2↔2 split — even sizes fail because neither side clears ⌊4/2⌋+1=3.
How It Works Under the Hood
Consensus asks fault-prone processes to irreversibly agree on one value — agreement, integrity, and termination — and the FLP result proves no deterministic asynchronous protocol can guarantee all three if even one process may crash, because waiting forever for a slow message is indistinguishable from a dead one. Practical protocols escape by weakening expectations with timeouts, which convert impossible liveness into eventual liveness. This lab puts numbers to the folklore: quorum ⌊N/2⌋+1, fault tolerance f under N≥2f+1, and a partition slider that shows the exact split where two disjoint majorities become possible.
Core Architectural Principles
- Quorum arithmetic: ⌊N/2⌋+1 votes required, tolerable faults computed from cluster size.
- Safety (agreement) and liveness (termination) evaluated per configuration you build.
- Asynchronous-ambiguity toggle embodies FLP: slow is indistinguishable from crashed.
Interviewers ask “why can’t you have consensus without majority?” — answer with overlapping quorums: any two majorities share a node, so two decisions on different values are impossible. Mention FLP only to show you know timeouts are the engineering escape hatch, not to hand-wave correctness away.
Majority quorums guarantee one truth but freeze progress the moment the majority becomes unreachable.