1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
use BTreeSet;
use since;
use crateNodeId;
/// The proposed membership is not one of the transitions a direct membership append supports.
///
/// A direct append writes the caller's exact membership as one log entry, without an intermediate
/// joint membership. It is accepted only when quorum intersection can be proved by a simple rule:
/// two uniform memberships whose voter sets differ by at most one node id, or two memberships that
/// share an exactly equal voter set.
///
/// The rule is conservative, so a rejected transition is **unsupported**, not necessarily unsafe.
/// Some rejected transitions do have intersecting quorums; Openraft does not run a general
/// quorum-intersection solver to find them.
///
/// # Rejected transitions
///
/// Replacing one voter with another in one step:
///
/// ```text
/// [{a,b,c}] -> [{b,c,d}]
/// ```
///
/// The two uniform voter sets differ by two node ids, `a` and `d`. Quorum `{a,b}` of the previous
/// membership and quorum `{c,d}` of the proposed one do not intersect, so the transition is
/// unsafe. Append `[{a,b,c,d}]` first, then `[{b,c,d}]`.
///
/// Adding two voters in one step:
///
/// ```text
/// [{a,b,c}] -> [{a,b,c,x,y}]
/// ```
///
/// Quorum `{a,b}` of the previous membership and quorum `{c,x,y}` of the proposed one do not
/// intersect. Append `x` and `y` one at a time.
///
/// Overlapping, but not exactly equal, voter sets:
///
/// ```text
/// [{a,b,c}, {a,b,d}] -> [{a,b,e}]
/// ```
///
/// No previous voter set equals `{a,b,e}`. Sharing `a` and `b` does not help: quorum `{a,c,d}` of
/// the previous membership and quorum `{b,e}` of the proposed one do not intersect.
///
/// A safe transition this rule still rejects:
///
/// ```text
/// [{a,b,c,d}, {a,b,c,e}] -> [{a,b,d,e}, {a,c,d,e}]
/// ```
///
/// Every voter set holds four of the five node ids `{a,b,c,d,e}`, so every quorum holds at least
/// three of them, and any two such quorums intersect. No voter set is equal across the two
/// memberships, so this rule cannot see that and rejects the transition.