▶ Cinematic fable · Watch on YouTube ▶ 影片版寓言 · 在 YouTube 观看
太行深处的洗墨峰顶,有一座孤悬绝壁之上的“灵台同律斋”。
斋中常年设五席,由五位饱读天文律历的钦天监掌案共守。天下州郡的岁差、星躔与潮候,皆由这五人每日各自测算推演,并互通手札,订成一部万民奉行的《大明统历》。
山峰高插云霄,石斋四周罡风怒号。五位掌案虽同处一斋,但按太祖定下的戒律,为防互相偏私,五人各居东西南北中五座石室,彼此不得当面开口交谈。五室之间,仅以悬于半空的五色彩绳相连。
每当一人推算出一条新的日月盈亏度数,便抄录在素绢之上,系于彩绳滑轮,向其余四位同僚同时滑送。
然而绝壁风烈,滑轮时常在暴风中卡滞,飞索更偶有冻裂。
某一日,东室推得“岁差增二分”,西室推得“火星犯南斗”,北室推得“望日月食入既”。三道绢帛同时在风雪中穿梭滑行。由于风向变幻,南室先收到了东室的素绢,中室却先收到了北室的绢帛。更棘手的是,正当西室滑送的绢帛行至半途,一道惊雷劈中北室的廊柱,北室的石窗轰然坍塌,北室掌案当场咯血昏厥,桌上油灯尽灭!
石斋刹那间陷入大乱。
南室已将北室送来的星占度数抄录进历书,西室却尚未来得及收到北室的消息;如今北室掌案人事不知,他究竟算到了哪一步?西室滑送给北室的火星度数,北室昏迷前到底看没看到?倘若有人算进去了、有人没算进去,待到明日黎明各自呈交中枢,天下历法岂非彼此背离、天命崩解?
正当局势摇摇欲坠之际,首席大掌案推开中室石门,步入斋心祭坛,抬起重达百斤的紫铜巨槌,狠狠砸向悬于中庭的“定风铜磬”。
“铛——!”
清越沉雄的铜音穿透狂风暴雪,回荡于五方石壁之间。
这是同律斋立斋百年的第一条祖训:“凡有同僚缺席、暴风断绳、或斋中席位更迭,必鸣落铜之磬。磬声一响,天地定界,名为‘换籍’。”
铜磬长鸣,其余三位尚能动弹的掌案闻声,立即遵循古礼,将悬于半空的毛笔霍然收住,不再书写任何新的日月星度。所有人停下手头政务,转向中庭。
大掌案站在青铜祭坛之上,高声宣唱祖训的第二条铁律:“磬响之后、新籍未立之前,清点旧界内之一切流转!”
掌案们不再对外收发新测算,而是迅速将彩绳上尚在半空滑行、或自己已收到但尚未确认同僚是否收到的旧绢帛,全数取下,互相大声对质清点:
“北室昏迷前发出的‘望日月食’,西室可曾收到?” “未曾收到!” “老夫手中有抄本,立刻转抄与你!” “西室发出的‘火星犯南斗’,东室与南室皆已收到,惟北室未能阅览!” “北室既已覆灭,不复计入!但尚存之东、西、南、中四席,必须人人尽数抄录!”
在彻骨的寒风中,四位掌案在青铜磬声的庇护下,奔走于残存的绳索之间。他们并不急着恢复日常观星,而是耐着性子,将上一任五人同在时的每一道悬空手札,彻底在彼此案头上补齐。凡有一人未收到的,其余人必代为转抄补齐;凡是全斋尚未达成共识的,一律在磬声平息前彻底结清。
半个时辰过去。四人案头的旧账丝毫不差,每一道在暴风中漂浮的手札均已落定成墨。
此时,大掌案取出一枚滚烫的朱砂火印,在案头的羊皮名册上,将北室掌案的名字划上一道朱线,重新题写下今日的新席位:“洗墨峰同律第四代第三籍,存东、西、南、中四席。”
火印落下,大掌案收起铜槌,对着四方石室朗声长喝:“旧籍已清,新籍既立!自此刻起,天下唯以此四席为准,开案续算!”
铜磬止息,风雪中重新传出四方掌案落笔沙沙之声。
翌日清晨,钦天监正使登上峰顶收缴历草。当他展开四卷崭新的长绢并列勘验时,不由倒吸一口凉气:
历草之上,从第一行“岁差增二分”到最后一行“月食入既”,四卷长绢上的每一个干支、每一颗星位、每一道朱批,竟然排列得严丝合缝、完全同序!哪怕北室在狂暴的山洪与落雷中溘然陨落,整座石斋留下的天算图谱,却像从未经历过任何狂澜风暴一般,纯净而不可动摇。
使者惊叹拜伏:“暴风裂索,席位更迭,何以四卷历草丝毫不乱?”
大掌案抚须淡笑:“山风无常,信使或迟或疾,我等肉眼凡胎,本就无法让天地间的每一次传书都瞬间齐至。但我斋有铜磬之法——席位变幻之际,先鸣磬划界;在旧界落幕与新界启幕之间,宁止前路,务使残存同僚所见尽同。如此,虽风狂雨骤、席位消长,而同席之人所见之景,宛如与天地齐步同拍。”
—看到这里,你或许已经认出来了:这座在风暴与减员面前,以鸣磬划界、在席位更迭点补齐消息、确保所有人眼中的事件历史分毫不差的石斋,正是分布式系统通信理论中最经典、也最优雅的一块基石——由图灵奖得主 Kenneth P. Birman 于 1980 年代在康奈尔大学 Isis Toolkit 中提出的 虚拟同步(Virtual Synchrony) 架构。
这是什么
在分布式系统与群组通信(Group Communication Systems, GCS)中,多个节点常常需要协同维护相同的应用状态(如高可用集群的内存状态复制、分布式锁服务、金融交易撮合引擎)。
现实网络是不可预测的异步网络(Asynchronous Network):网络丢包、延迟乱序随时发生,节点随时可能崩溃(Fail-Stop),新的节点也随时可能加入。
如果直接使用普通的多播(Multicast),就会出现极具破坏性的视图裂痕:
- 节点 $A$ 发送的消息 $M$,在网络中传递给 $B$ 和 $C$;
- $B$ 收到并处理了 $M$,但随后节点 $A$ 突然掉电宕机,导致消息 $M$ 永远无法到达 $C$;
- 此时 $B$ 和 $C$ 的内存状态彻底分叉,系统陷入不可逆的逻辑混乱。
为了解决这个根本难题,Ken Birman 提出了虚拟同步(Virtual Synchrony)。它的核心定义非常精妙:
“将系统的执行历史划分为一系列离散的视图(Views)。如果一条消息在视图 $V_k$ 中被某个正确的节点交付(Deliver),那么在视图切换到 $V_{k+1}$ 之前,该消息必然且必须被视图 $V_k$ 中所有存活且进入下一视图的节点全部交付。”
虚拟同步的核心协议由四个阶段紧密咬合:
- 成员视图(Membership View): 群组在任意时刻都有一个明确的节点成员列表,称为视图 $V_k$(如故事中同律斋的五人名册)。所有应用消息都在特定的视图上下文中发送与交付。
- 视图变更触发(View Change Detection): 当故障检测器(Heartbeat / Failure Detector)发现有节点宕机、脱网,或有新节点加入时,系统暂停向上层应用交付常规业务消息,启动视图变更协议(故事中鸣响定风铜磬)。
- 清洗与栅障同步(Flush & Barrier Protocol):
在真正安装新视图 $V_{k+1}$ 之前,存活的节点之间必须执行一轮清洗(Flush)协议:
- 节点互相交换“我在视图 $V_k$ 期间到底收到了哪些消息”的确认清单;
- 若节点 $B$ 发现节点 $C$ 遗漏了某条消息,存活节点会主动代为重传(Gossip / Retransmission);
- 确保在跨过视图变更门槛之前,所有未能被全员收到的游离消息要么在存活集合内全员补齐,要么被全体丢弃。
- 视图更迭与状态转移(View Installation & State Transfer): 一旦清洗完成,所有存活节点同时安装新视图 $V_{k+1}$。若有新节点加入,在此刻执行状态快照转移(State Transfer)。随后,系统恢复正常的业务多播。
对于上层应用程序而言,虽然底层网络是异步、丢包、充满故障的,但虚拟同步给应用程序提供了一种“就好像整个集群在一个完全同步、完全没有节点故障的理想世界中运行一样”的执行幻觉(这也是它名字中“虚拟(Virtual)”二字的真意)。
为什么重要
虚拟同步是分布式计算从“理论象牙塔”走向“工业高可用”的里程碑:
- 状态机复制(SMR)的实用化先驱: 在 Raft 和 Paxos 成为主流工业共识协议之前,整个 1990 年代至 2000 年代初期的高可用容灾系统,几乎全由虚拟同步架构统治。它将极其复杂的网络故障恢复逻辑从业务代码中剥离,沉淀为通信中间件底座。
- 支撑现代基础设施的工业级血脉:
- Corosync & Pacemaker:Linux 高可用高可靠集群的核心通信层(Red Hat Enterprise Linux HA、SUSE HA),底层使用的正是 Totem 单环冗余协议,完美实现了虚拟同步语义;
- JGroups:Java 生态中最著名的高性能群组通信工具包,被广泛应用于 Infinispan(分布式内存网格)、JBoss / WildFly 集群会话复制以及 Keycloak 的高可用多节点同步中;
- Spread Toolkit:金融与高频交易系统中经久不衰的可靠组播中间件;
- Galera Cluster (MySQL / MariaDB):多主同步复制数据库集群,其底层的写集复制协议(Write-Set Replication, wsrep)直接继承了虚拟同步的思想。
- 因果与全序多播的自然载体: 在虚拟同步构建的清晰视图边界之内,系统可以非常廉价、高效地叠加 FIFO、因果序(Causal Multicast / CBCAST) 或 全序原子广播(Total Order / ABCAST),而无需为跨故障时期的消息悬空问题付出灾难性的全网回滚代价。
隐喻对应表
- 洗墨峰顶的灵台同律斋与五位掌案 → 分布式系统集群与节点群组(Node Group / Cluster Membership)
- 记载日月盈亏、互相滑送的素绢手札 → 集群节点间广播的多播消息(Multicast Messages)
- 绝壁罡风导致滑轮卡滞与飞索受损 → 异步网络中的延迟、乱序与丢包(Asynchronous Network Delays & Packet Loss)
- 惊雷击塌北室、掌案昏厥覆灭 → 节点无预警崩溃停机(Fail-Stop Crash Failure)
- 首席大掌案撞击中庭定风铜磬,宣布“换籍” → 故障检测触发视图变更协议(View Change Trigger)
- 铜磬长鸣期间,众人提笔停算、暂停日常星占 → 视图切换期间暂停接收新业务消息的栅障(View Change Barrier)
- 存活掌案互相核对残存绢帛、代为转抄补齐 → 视图变更时的消息清洗与重传协议(Message Flush & Retransmission)
- 在羊皮名册上划去北室、加盖朱砂火印确立第三籍 → 存活节点共同提交并安装新视图(New View Installation, $V_{k+1}$)
- 铜磬止息后四人重新开案测算 → 新视图生效并恢复常规消息多播(Resume Message Multicast)
- 四卷崭新长绢上的星历干支分毫不差、完全一致 → 虚拟同步保证在同一视图下所有存活节点交付完全相同的消息历史(Virtual Synchrony Invariant)
High atop Mount Ximo in the deep Taihang range stood an isolated pavilion clinging to the sheer precipice: the Hall of Unbroken Harmony.
Inside the hall five desks were kept in perpetuity, manned by five senior astronomers from the Imperial Observatory. The precession of the equinoxes, the paths of the planets, and the rise and fall of the tides across every province in the empire were calculated independently by these five scholars each day, cross-checked by hand, and compiled into the authoritative Grand Ming Calendar.
The peak pierced the clouds, and howling gales battered the stone pavilion day and night. Though housed under a single roof, ancestral statutes enacted by the dynastic founder forbade them from ever speaking face to face, lest affection or rivalry cloud their mathematical objectivity. Each scholar occupied an isolated stone chamber facing east, west, south, north, and center. Between their rooms stretched five slender colored silk cords strung upon aerial brass pulleys.
Whenever an astronomer derived a new astronomical degree, he inked it upon plain white silk, hitched it to a pulley, and let it glide across the open air to all four colleagues at once.
Yet mountain winds were fickle. Pulleys seized in sudden squalls, and frozen cords snapped beneath winter frost.
One fateful afternoon, the Eastern Chamber calculated a precession increment of two minutes; the Western Chamber charted Mars encroaching upon the Southern Dipper; and the Northern Chamber recorded the total immersion of an approaching lunar eclipse. Three rolls of silk drifted into the howling storm simultaneously. Because the winds shifted erratically, the Southern Chamber received the eastern scroll first, whereas the Central Chamber snatched the northern dispatch first. Worse still, while the Western Chamber’s silk was halfway across the chasm, a blinding lightning bolt shattered the pillar of the Northern Chamber. The stone casement collapsed inward, leaving the northern astronomer unconscious amidst blood and debris, his oil lantern snuffed out.
Pandemonium struck the hall.
The Southern Chamber had already copied the northern astronomical degree into its official ledger; the Western Chamber had not yet laid eyes upon it. Now that the northern astronomer lay insensate, how far had his calculations advanced? Had he even glimpsed the Mars observations gliding toward him before the rafters fell? If some scholars incorporated a calculation while others missed it, when the scrolls were presented to the throne at dawn, the imperial calendar would tear itself apart, and the mandate of heaven would fracture into irreconcilable contradictions.
Just as the institution stood upon the brink of ruin, the Senior Astronomer pushed open the door of the Central Chamber, stepped onto the terrace, and seized a hundred-pound bronze hammer. With both arms, he struck the massive Bronze Gong of Stillness suspended in the courtyard.
CLANG——!
The deep, penetrating chime cut through the blizzard, reverberating across the stone facades.
This was the paramount decree carved into the hall’s foundation a century prior: “Whenever a comrade falls silent, a cord snaps, or the roster of seats changes, the Tolling Gong must sound. The instant it rings, the boundary of heaven and earth is fixed; this is called the Renewal of Views.”
As the chime rolled through the storm, the three remaining conscious astronomers adhered strictly to ancient protocol. They arrested their hair-tip brushes mid-stroke, refusing to write down a single new coordinate. Halting all outward affairs, they turned their undivided attention to the courtyard.
Standing upon the bronze altar, the Senior Astronomer recited the second ironclad clause: “Once the gong tolls and before the new roster is sealed, clear all floating dispatches within the old horizon!”
The scholars ceased all new observations. Instead, they hauled down every dispatch lingering upon the cords, comparing their tallies across the courtyard at the top of their lungs:
“The lunar eclipse dispatch sent by the North before he fell—did the West receive it?” “Never arrived!” “I hold the true copy here; I shall transcribe and bridge it across to you at once!” “The Mars observation sent from the West reached the East and South, but the North collapsed before reading it!” “The North is severed and counts no longer! But among the surviving four seats—East, West, South, and Center—every man must possess the full, identical text!”
Amidst the biting gale and beneath the sheltering resonance of the bronze gong, the four scholars scurried back and forth across the intact lines. They did not rush to resume stargazing; instead, with painstaking discipline, they reconciled every floating record that originated during the five-man era. If a single surviving scholar lacked a dispatch, his peers bridged the gap with verified transcripts; if an entry could not achieve universal consensus, it was systematically cleared before the gong fell silent.
Half an hour passed. The books across all four desks aligned to the stroke; every scroll that had danced in the gale was firmly bound in ink.
At that moment, the Senior Astronomer retrieved a glowing cinnabar brand. Upon the sheepskin registry, he drew a single crimson line through the name of the Northern Chamber and penned the new roster for the day: “Fourth Generation, Third Registry of the Hall of Harmony: Comprising the East, West, South, and Central Seats.”
The hot brand bit into the leather. Setting aside his hammer, the Senior Astronomer shouted into the wind: “The old view is purged; the new view is enthroned! From this breath forward, let all astronomical decrees proceed under these four seats alone!”
The vibrations of the gong subsided, and the whispering scratch of four synchronized brushes resumed.
At dawn, the Imperial Envoy climbed the peak to collect the astronomical proofs. When he unrolled the four long scrolls side by side along the terrace, his breath caught in his throat:
From the very first line recording the precession increment to the final annotation regarding the lunar eclipse, every stroke, astronomical degree, and cinnabar seal across all four scrolls was aligned in exact, identical sequence. Even though the Northern Chamber had collapsed amidst thunder and mountain torrents, the celestial records left behind by the surviving four appeared as though no tempest had ever disturbed their peace.
The envoy bowed in reverence: “Gales severed the cords, and a master fell from his chair. How can four scrolls remain in such immaculate harmony?”
The Senior Astronomer stroked his beard with a faint smile: “Mountain winds are wild, and messengers travel at unequal speeds. We mortals cannot force every letter in the world to arrive in the same instant. But our hall possesses the law of the Tolling Gong: whenever seats change, strike the bell to fix the boundary. Between the dusk of the old order and the dawn of the new, halt all forward motion until every surviving brother shares the identical horizon. Thus, though storms rage and seats rise and fall, all who sit at the table behold the exact same world, stepping in unbroken harmony with the heavens.”
—By now you have probably recognized it: this tale of an isolated observatory that sounds a gong upon failure, reconciles pending messages across a barrier, and guarantees that all surviving members share an identical history across membership boundaries is the foundational breakthrough of distributed group communication systems: Virtual Synchrony, conceived by Turing Award laureate Kenneth P. Birman at Cornell University in the 1980s as the core architecture of the Isis Toolkit.
What it is
In distributed systems and Group Communication Systems (GCS), clusters of nodes must frequently maintain identical application states (such as replicated in-memory state machines, distributed lock managers, and financial matching engines).
The underlying physical network is inevitably an asynchronous network: packets are delayed, reordered, or lost, nodes crash abruptly (Fail-Stop), and new nodes join at arbitrary moments.
If applications communicate using raw point-to-point IP multicast or uncoordinated sockets, devastating view anomalies occur:
- Node $A$ multicasts message $M$ to nodes $B$ and $C$;
- $B$ receives and executes $M$, but node $A$ crashes immediately afterward, preventing $M$ from ever reaching node $C$;
- As a consequence, the internal states of $B$ and $C$ diverge irreversibly, corrupting cluster consensus.
To eliminate this fundamental flaw, Ken Birman formulated Virtual Synchrony. Its mathematical invariant is defined with elegant precision:
“System execution is partitioned into a succession of discrete Views ($V_0, V_1, \dots$). If a message $M$ is delivered to any non-faulty process in view $V_k$, then that message must be delivered to all non-faulty processes that survive and transition from view $V_k$ into view $V_{k+1}$.”
Virtual Synchrony achieves this guarantee through four interlocking phases:
- Membership Views: At any point in logical time, the group operates under an explicit roster of participating nodes known as a View $V_k$ (analogous to the five-man registry of the hall). Application messages are strictly transmitted and delivered within the scope of a specific view.
- View Change Detection: When a failure detector (heartbeat monitor) discovers that a node has crashed, disconnected, or that a new node wishes to join, normal application multicasts are suspended. The system initiates the view change protocol (the striking of the Bronze Gong of Stillness).
- Flush and Barrier Protocol:
Before the new view $V_{k+1}$ can be installed, surviving nodes execute a Flush Protocol:
- Nodes exchange receipt vectors detailing which messages were received during view $V_k$;
- If node $B$ possesses a message that node $C$ missed, surviving peers actively retransmit (bridge) that message to $C$;
- All in-flight messages sent during $V_k$ are either delivered to every surviving member entering $V_{k+1}$ or entirely discarded before the view barrier closes.
- View Installation and State Transfer: Once the flush barrier clears, all surviving nodes install view $V_{k+1}$ in lockstep. If a new node joins the cluster, an authoritative state snapshot is transferred at this precise barrier. Regular application multicasts then resume.
To application developers, although the underlying network is asynchronous, lossy, and failure-prone, Virtual Synchrony presents the clean execution abstraction of an idealized, fully synchronized system where membership changes happen instantaneously between message deliveries—the very definition of “Virtual” synchrony.
Why it matters
Virtual Synchrony served as the essential bridge transitioning distributed computing from academic theory to enterprise-grade high availability:
- The Practical Precursor to State Machine Replication (SMR): Long before Paxos and Raft became dominant in production systems, high-availability clustering throughout the 1990s and early 2000s relied on Virtual Synchrony. It decoupled Byzantine-like network failure handling from business logic, embedding fault recovery directly into the communication fabric.
- The Backbone of Enterprise Infrastructure:
- Corosync & Pacemaker: The gold-standard clustering engine in Linux enterprise distributions (Red Hat Enterprise Linux High Availability, SUSE Linux Enterprise Server), utilizing the Totem Single-Ring Redundant Protocol to enforce Virtual Synchrony semantics across bare-metal nodes;
- JGroups: The venerable Java group communication toolkit powering Infinispan distributed in-memory caches, WildFly / JBoss HTTP session replication, and Keycloak high-availability identity clusters;
- Spread Toolkit: Ultra-reliable multicast middleware powering financial trading exchanges, SCADA telemetry, and mission-critical control rooms;
- Galera Cluster (MySQL & MariaDB): The synchronous multi-master database replication engine whose Write-Set Replication (
wsrep) provider is built directly on Virtual Synchrony concepts.
- The Natural Foundation for Causal and Total Order Multicast: Within the pristine view boundaries established by Virtual Synchrony, clusters can implement FIFO, Causal Multicast (CBCAST), or Total Order Atomic Broadcast (ABCAST) with extraordinary efficiency, eliminating the need for expensive distributed rollbacks when nodes crash mid-transaction.
Metaphor mapping
- The Hall of Unbroken Harmony on Mount Ximo and its five scholars → A distributed cluster and its constituent node membership (Node Group / Cluster Membership)
- The silk scrolls bearing astronomical calculations slid across cords → Application messages broadcast across the network (Multicast Messages)
- The erratic mountain gales causing pulley friction and broken cords → Network latency, out-of-order delivery, and packet drops in an asynchronous network (Asynchronous Network Anomalies)
- The lightning bolt felling the Northern Chamber and knocking the scholar unconscious → An abrupt node crash without prior warning (Fail-Stop Crash Failure)
- The Senior Astronomer striking the Bronze Gong of Stillness to declare a “Renewal of Views” → A failure detector initiating the view change protocol (View Change Trigger)
- Halting all brushwork and suspending new calculations while the gong tolls → The view change barrier suspending incoming application multicasts (View Change Barrier)
- Surviving scholars cross-checking pending dispatches and retranscribing missing items → The message flush and retransmission protocol (Message Flush & Retransmission)
- Crossing out the Northern Chamber with a cinnabar brand and sealing the Third Registry → Surviving nodes committing and installing a new view (New View Installation, $V_{k+1}$)
- Resuming astronomical calculations once the gong falls silent → Restoring normal application multicast in the new view (Resuming Application Multicast)
- The four dawn scrolls matching character for character without discrepancy → The Virtual Synchrony invariant guaranteeing that all surviving nodes deliver an identical message history (Virtual Synchrony Invariant)