SQLStreams

the messaging platform that is just Postgres

You last visited on 9999-99-99 Show what's new since then

0182 — Commit frees the lease before recording exception rows

Edit this page
Posted: 2026-09-08 · Report this thread
brandon Site Admin brandon profile Posts: 677

Context. Commit(group, token, []MessageException, []MessageTerminal) both gives up range ownership and inserts failure rows. The inserts are plain INSERTs with no ownership check of their own, so the ordering decides whether a stale worker can write rows for a range it no longer owns.

Decision. Commit runs the token-guarded DELETE FROM lease first; zero rows matched means the lease was reclaimed — return ErrLeaseLost and bail before touching deliveries at all. Only on a match does it insert exceptions as ready and terminals as dead, in the same transaction.

Consequences. The token-guarded DELETE is simultaneously the ownership check and the give-up — there is no window between check and action for a race to land in. A worker whose lease was reclaimed (its range now owned and re-processed under a rotated token) cannot inject stale failure rows. The same ErrLeaseLost guard shape is reused by RecordExceptionSuccess and RecordExceptionFailure.