
Liveness asks not whether a system has done something wrong, but whether the good thing that ought to happen will eventually happen. Imagine four drivers at an intersection, each carefully yielding to the others. No collision occurs, yet nobody moves. The arrangement satisfies safety while failing liveness.
Liveness does not promise that every request will finish immediately. Under stated assumptions about scheduling and fairness, it promises that waiting will not continue forever. It also differs from performance: a task that eventually completes very slowly may still satisfy liveness, though its performance is poor. If one participant never gets a turn, the system can remain busy overall while failing liveness for that participant.
The distinction matters because “nothing bad happened” is easily mistaken for “the system works”. Reliable co-operation must preserve boundaries while also checking that work keeps moving towards completion. Safety constrains what must never happen; liveness states what must eventually happen. A complete promise needs both.
https://lamport.azurewebsites.net/tla/book.html
https://doi.org/10.1007/BF01782772
Discover more from Geoffrey Chen
Subscribe to get the latest posts sent to your email.