Formal validation of fault tolerance mechanisms