distributed-raft-joint-consensus-membership-safety
Done. Delivered two files:
~/raft_joint.py — the working reference implementation + randomized simulator + invariant checker.~/solution.md — the self-contained write-up (title, root-cause analysis, exact fix, verification), with the full code embedded.Raft commits/elects on a majority of the current configuration. If C_old → C_new is applied atomically, quorums can be disjoint (C_old={A,B,C} vs C_new={D,E,F}), so an old-config leader and a new-config leader can each commit independently. A leader knocked into a minority partition mid-transition is the classic trigger: it keeps its old majority while the rest of the cluster moves on.
C_{old,new}; it commits only with a majority of both sets.C_{old,new} is committed does the leader append C_new.C_new steps down.python3 raft_joint.py)[directed] buggy direct switch -> CAUGHT: leader A term 5 cfg=C(['A','B','C'])
quorum ['A','B'] vs leader D term 6 cfg=C(['D','E','F']) quorum ['D','E']
[directed] correct joint consensus, minority leader -> NO violation
[correct joint consensus] seeds=2000 violations=0
[buggy direct switch] seeds=2000 violating-seeds=379
The checker enforces three invariants: at most one leader per term, no two live leaders with disjoint reachable quorums, and state-machine safety (no divergent applied entries/configs). Correct joint consensus passes all 2000 randomized interleavings (random message loss/reordering, partition splits/merges, and forced {A,B,C}/{D,E,F} splits); the buggy direct switch is caught via election-safety, state-machine-safety, and the directed disjoint-leaders check.
# Evidence - Problem class: distributed-raft-joint-consensus-membership-safety - Model: openrouter/deepseek/deepseek-v4.1-flash - Solved: 2026-09-12T04:47:00.173Z - Verification: solution produced by pi in sandbox; see signatures.json
{"description": "Implement Raft membership changes via joint consensus: enter configuration C_{old,new}, require majorities of both old and new sets for commit, then commit C_new once C_{old,new} is committed by both majorities. Your state machine must prove that no two leaders can be elected in disjoint configurations during any interleaving, including a leader that falls into a minority partition mid-transition. Provide a randomized election simulator with a safety-invariant checker that runs thousands of interleavings and reports any violation with the trace.", "environment": "python3", "language": "python", "model": "openrouter/deepseek/deepseek-v4.1-flash", "problem_class": "distributed-raft-joint-consensus-membership-safety", "provider": "openrouter", "solved_at": "2026-09-12T04:47:00.174Z", "version": "3.11"}Done. Delivered two files:
~/raft_joint.py — the working reference implementation + randomized simulator + invariant checker.~/solution.md — the self-contained write-up (title, root-cause analysis, exact fix, verification), with the full code embedded.Raft commits/elects on a majority of the current configuration. If C_old → C_new is applied atomically, quorums can be disjoint (C_old={A,B,C} vs C_new={D,E,F}), so an old-config leader and a new-config leader can each commit independently. A leader knocked into a minority partition mid-transition is the classic trigger: it keeps its old majority while the rest of the cluster moves on.
C_{old,new}; it commits only with a majority of both sets.C_{old,new} is committed does the leader append C_new.C_new steps down.python3 raft_joint.py)[directed] buggy direct switch -> CAUGHT: leader A term 5 cfg=C(['A','B','C'])
quorum ['A','B'] vs leader D term 6 cfg=C(['D','E','F']) quorum ['D','E']
[directed] correct joint consensus, minority leader -> NO violation
[correct joint consensus] seeds=2000 violations=0
[buggy direct switch] seeds=2000 violating-seeds=379
The checker enforces three invariants: at most one leader per term, no two live leaders with disjoint reachable quorums, and state-machine safety (no divergent applied entries/configs). Correct joint consensus passes all 2000 randomized interleavings (random message loss/reordering, partition splits/merges, and forced {A,B,C}/{D,E,F} splits); the buggy direct switch is caught via election-safety, state-machine-safety, and the directed disjoint-leaders check.
# Evidence - Problem class: distributed-raft-joint-consensus-membership-safety - Model: openrouter/deepseek/deepseek-v4.1-flash - Solved: 2026-09-12T04:47:00.173Z - Verification: solution produced by pi in sandbox; see signatures.json
{"description": "Implement Raft membership changes via joint consensus: enter configuration C_{old,new}, require majorities of both old and new sets for commit, then commit C_new once C_{old,new} is committed by both majorities. Your state machine must prove that no two leaders can be elected in disjoint configurations during any interleaving, including a leader that falls into a minority partition mid-transition. Provide a randomized election simulator with a safety-invariant checker that runs thousands of interleavings and reports any violation with the trace.", "environment": "python3", "language": "python", "model": "openrouter/deepseek/deepseek-v4.1-flash", "problem_class": "distributed-raft-joint-consensus-membership-safety", "provider": "openrouter", "solved_at": "2026-09-12T04:47:00.174Z", "version": "3.11"}