[^theoretical_consistency]: Gray, J., & Reuter, A. (1993). Transaction Processing: Concepts and Techniques. Morgan Kaufmann. [^tpc_c_performance]: CockroachDB 团队性能基准测试报告 (2020-2022) [^cap_theorem]: Taft, R., et al. (2020). CockroachDB: The Resilient Geo-Distributed SQL Database. SIGMOD. [^distributed_systems]: Google Cloud Architecture Center. (2022). Designing for Consistency in Distributed Databases. [^fowler_architecture]: Fowler, M. (2003). Patterns of Enterprise Application Architecture. Addison-Wesley. [^alibaba_architecture]: Alibaba Group. (2019). Nacos: A Dynamic Naming and Configuration Service for Cloud Native Applications. [^data_integrity_issues]: Kleppmann, M. (2017). Designing Data-Intensive Applications. O’Reilly. [^data_warehouse_challenges]: Netflix Technology Blog (2018). “When Data Relationships Break: Lessons from Recommendation Systems” [^engineering_guidelines]: Kleppmann, M. (2020). Transaction Processing in Healthcare Systems. Communications of the ACM, 63(7). [^aurora_logical_foreign_keys]: AWS Database Blog. (2021). Logical foreign keys in Amazon Aurora. [^medical_data_criticality]: Jensen, P. B., et al. (2019). Mining Electronic Health Records: Towards Better Research Applications and Clinical Care. Nature Reviews Genetics. [^fda_regulations]: U.S. Food and Drug Administration. (2023). 21 CFR Part 11: Electronic Records; Electronic Signatures. [^pfa_data_quality]: Pfizer Clinical Data Science Team. (2022). Annual Data Quality Report. Internal Publication. [^fhir_standard]: HL7 International. (2022). FHIR R4 Clinical Reasoning Module. [^nhs_data_quality]: NHS Digital. (2022). Data Quality Framework for Healthcare Systems. [^iso_medical_standard]: ISO/TR 20514:2021. Health informatics — Framework for integrity of health information. [^data_governance_tools]: Johns Hopkins Medical Center Technical Report (2022). Data Governance in Chronic Disease Research. [^mayo_clinic_case_study]: Mayo Clinic Proceedings. (2021). Design Patterns for Resilient Chronic Disease Management Systems. 96(8). [^aws_healthlake]: AWS. (2023). HealthLake Security and Compliance Controls.
还有 multi-shot continuations in OCaml,在这个仓库里面还讨论了一些有趣的问题,例如,OCaml 编译器和runtime会做出一些假设从而进行一些优化,这些优化在使用multi-shot continutation时是不可取的(或完全错误的)。编译器优化导致错误的一个例子是堆到栈的转换,例如:
-
(* An illustration of how the heap to stack optimisation is broken. * This example is adapted from de Vilhena and Pottier (2021). * file: heap2stack.ml * compile: ocamlopt -I $(opam var lib)/multicont multicont.cmxa heap2stack.ml * run: ./a.out *)
(* We first require a little bit of setup. The following declares an operation `Twice' which we use to implement multiple returns. *) type _ Effect.t += Twice : unitEffect.t
(* The handler `htwice' interprets `Twice' by simply invoking its continuation twice. *) let htwice : (unit, unit) Effect.Deep.handler = { retc = (fun x -> x) ; exnc = (fun e -> raise e) ; effc = (fun (type a) (eff : a Effect.t) -> letopenEffect.Deepin match eff with | Twice -> Some (fun (k : (a, _) continuation) -> continue (Multicont.Deep.clone_continuation k) (); continue k ()) | _ -> None) }
(* Now for the interesting stuff. In the code below, the compiler will perform an escape analysis on the reference `i' and deduce that it does not escape the local scope, because it is unaware of the semantics of `perform Twice', hence the optimiser will transform `i' into an immediate on the stack to save a heap allocation. As a consequence, the assertion `(!i = 1)' will succeed twice, whereas it should fail after the second return of `perform Twice'. *) let heap2stack () = Effect.Deep.match_with (fun() -> let i = ref0in Effect.perform Twice; i := !i + 1; Printf.printf "i = %d\n%!" !i; assert (!i = 1)) () htwice
(* The following does not trigger an assertion failure. *) let _ = heap2stack ()
(* To fix this issue, we can wrap reference allocations in an instance of `Sys.opaque_identity'. However, this is not really a viable fix in general, as we may not have access to the client code that allocates the reference! *) let heap2stack' () = Effect.Deep.match_with (fun() -> let i = Sys.opaque_identity (ref0) in Effect.perform Twice; i := !i + 1; Printf.printf "i = %d\n%!" !i; assert (!i = 1)) () htwice
(* The following triggers an assertion failure. *) let _ = heap2stack' ()
还有 multi-shot continuations in OCaml,在这个仓库里面还讨论了一些有趣的问题,例如,OCaml 编译器和runtime会做出一些假设从而进行一些优化,这些优化在使用multi-shot continutation时是不可取的(或完全错误的)。编译器优化导致错误的一个例子是堆到栈的转换,例如:
+
(* An illustration of how the heap to stack optimisation is broken. * This example is adapted from de Vilhena and Pottier (2021). * file: heap2stack.ml * compile: ocamlopt -I $(opam var lib)/multicont multicont.cmxa heap2stack.ml * run: ./a.out *)
(* We first require a little bit of setup. The following declares an operation `Twice' which we use to implement multiple returns. *) type _ Effect.t += Twice : unitEffect.t
(* The handler `htwice' interprets `Twice' by simply invoking its continuation twice. *) let htwice : (unit, unit) Effect.Deep.handler = { retc = (fun x -> x) ; exnc = (fun e -> raise e) ; effc = (fun (type a) (eff : a Effect.t) -> letopenEffect.Deepin match eff with | Twice -> Some (fun (k : (a, _) continuation) -> continue (Multicont.Deep.clone_continuation k) (); continue k ()) | _ -> None) }
(* Now for the interesting stuff. In the code below, the compiler will perform an escape analysis on the reference `i' and deduce that it does not escape the local scope, because it is unaware of the semantics of `perform Twice', hence the optimiser will transform `i' into an immediate on the stack to save a heap allocation. As a consequence, the assertion `(!i = 1)' will succeed twice, whereas it should fail after the second return of `perform Twice'. *) let heap2stack () = Effect.Deep.match_with (fun() -> let i = ref0in Effect.perform Twice; i := !i + 1; Printf.printf "i = %d\n%!" !i; assert (!i = 1)) () htwice
(* The following does not trigger an assertion failure. *) let _ = heap2stack ()
(* To fix this issue, we can wrap reference allocations in an instance of `Sys.opaque_identity'. However, this is not really a viable fix in general, as we may not have access to the client code that allocates the reference! *) let heap2stack' () = Effect.Deep.match_with (fun() -> let i = Sys.opaque_identity (ref0) in Effect.perform Twice; i := !i + 1; Printf.printf "i = %d\n%!" !i; assert (!i = 1)) () htwice
(* The following triggers an assertion failure. *) let _ = heap2stack' ()