SYSE.40:4.4 - Bound retry and dependency failure
For each retrying layer, know the operation’s replay behavior, deadline and attempt identity. Reconcile uncertain effects before repeating a state-changing operation. SYSE.34 and SYSE.41 supply the relevant data and runtime boundaries.
Bound the aggregate retry amplification across layers, not only each local loop. Delays and jitter can spread attempts but do not make an unbounded retry policy finite. Stop work that can no longer produce its permitted result rather than spending resources until an outer timeout hides it.
Protect both the component receiving pressure and the dependency receiving calls. A local resource monitor, a dependency concurrency limit and a fallback can address different failure mechanisms. Do not treat one control’s existence as proof that the whole path is protected.