AtrekesLibHFTDocumentationHigh availability

Reliability

One store. One primary.

LibHFT’s documented HA model is active/passive continuity around an arbitrated durable store. Promotion restores sequence state before the new owner reconnects.

Writer-lock arbitrationStandby backoffSequence continuity

HA model

Arbitrate ownership before accepting traffic.

  1. The primary acquires the durable store’s writer lock.
  2. A second instance cannot map or mutate that store as another writer.
  3. The losing instance stays passive and retries with bounded backoff.
  4. When ownership is released or lost, the standby attempts promotion.
  5. The promoted owner restores persisted sequence state before reconnecting.

A process that cannot prove ownership must not accept a session as primary. That rule is more important than the speed of promotion.

Tracked capability

The generated matrix records HA on all six flavors.

CapabilityC++Java PureJava/JNI.NET Pure.NET NativeRust Pure
Writer-lock arbitrationYesYesYesYesYesYes
Standby retryYesYesYesYesYesYes
PromotionYesYesYesYesYesYes
Sequence restoreYesYesYesYesYesYes

The generated capability matrix records source evidence across six flavors. Scenario and cross-host proof depth must still be assessed for the chosen provider and filesystem.

Deployment boundary

The filesystem participates in correctness.

The two instances must see the same durable state and a lock implementation with the semantics the arbitration model expects. Local tests do not automatically establish correctness on NFS, container bind mounts, clustered filesystems or cloud volumes.

Validate the actual mount.

Cross-host acceptance needs a deployment-specific drill: prove one writer, prove a blocked standby, terminate the primary, promote the standby, restore sequences and complete a counterparty exchange without split ownership.

Explicit non-claims

What active/passive does not mean.

  • No second state copy is continuously replicated by this mechanism.
  • No hot standby serves the same order session concurrently.
  • No cross-datacentre latency or quorum claim follows from a file lock.
  • No network filesystem is considered safe without tested lock and durability semantics.
  • No promotion should be called successful until sequence continuity and the peer exchange are proven.

Acceptance drill

The counterparty should observe continuity.

A useful HA test sends and stores application traffic, kills or isolates the current owner, promotes the standby and then exercises Logon, expected sequence, resend and new application flow. It records store ownership and Workbench state throughout the transition.

Promotion that resets sequence numbers is recovery work, but it is not transparent failover.