{"abstract":"An event escapes before its associated business state commits, or committed events disappear before dispatch.","category":"Distributed coordination","checks":7,"contract":"Actions are ['stage',ID,value], ['commit'], ['rollback'], or ['dispatch']. Stage replaces an uncommitted pending write; commit atomically stores its value and appends its event; rollback discards pending work. Dispatch publishes each locally pending committed event once. IDs are unique per committed transaction. Return [business value,published event IDs]. No transport crash or exactly-once external-delivery guarantee is modeled.","evaluation_group":"model-0edc58bb69e6ebb2","failed_approach":"Waiting until dispatch but retaining only the latest transaction's event loses earlier committed work.","family":"dist-transactional-outbox","id":"FA-101","implementations":{"attempt":{"sha256":"13b47db6a04e5f5fe92b0aafd2ee16bf958f52ceccdf4c688bb8ace86d5f6463","source":"\"\"\"Failure Map reference implementation. Python standard library only.\"\"\"\nimport json\n\nN = 1\nobservations = []\ndef solve(actions):\n    pending, business, latest, published = None, None, None, []\n    for action in actions:\n        if action[0] == 'stage':\n            pending = action[1:]\n        elif action[0] == 'commit' and pending is not None:\n            business, latest = pending[1], pending[0]\n            pending = None\n        elif action[0] == 'rollback':\n            pending = None\n        elif action[0] == 'dispatch' and latest is not None:\n            published.append(latest)\n            latest = None\n    return [business, published]\ndef check(label, actual, expected):\n    observations.append({\"check\": label, \"actual\": actual, \"expected\": expected, \"passed\": actual == expected})\ncheck('rollback cannot publish', solve([['stage', 'a', N], ['rollback'], ['dispatch']]), [None, []])\ncheck('commit before publication', solve([['stage', 'a', N], ['dispatch']]), [None, []])\ncheck('all committed events survive delay', solve([['stage', 'a', N], ['commit'], ['stage', 'b', N+1], ['commit'], ['dispatch']]), [N+1, ['a', 'b']])\ncheck('single committed event', solve([['stage', 'a', N], ['commit'], ['dispatch']]), [N, ['a']])\ncheck('repeat dispatch does not resend', solve([['stage', 'a', N], ['commit'], ['dispatch'], ['dispatch']]), [N, ['a']])\ncheck('rollback preserves prior outbox', solve([['stage', 'a', N], ['commit'], ['stage', 'b', N+1], ['rollback'], ['dispatch']]), [N, ['a']])\ncheck('empty transaction stream', solve([]), [None, []])\nprint(json.dumps({\"observations\": observations, \"passed\": all(x[\"passed\"] for x in observations)}, ensure_ascii=False))\nraise SystemExit(0 if all(x[\"passed\"] for x in observations) else 1)\n"},"broken":{"sha256":"e2eaf6cfb4857b60478876ef9e05381055cefa3ea899779364b94cf3707c019b","source":"\"\"\"Failure Map reference implementation. Python standard library only.\"\"\"\nimport json\n\nN = 1\nobservations = []\ndef solve(actions):\n    pending, business, published = None, None, []\n    for action in actions:\n        if action[0] == 'stage':\n            pending = action[1:]\n            published.append(pending[0])\n        elif action[0] == 'commit' and pending is not None:\n            business = pending[1]\n            pending = None\n        elif action[0] == 'rollback':\n            pending = None\n    return [business, published]\ndef check(label, actual, expected):\n    observations.append({\"check\": label, \"actual\": actual, \"expected\": expected, \"passed\": actual == expected})\ncheck('rollback cannot publish', solve([['stage', 'a', N], ['rollback'], ['dispatch']]), [None, []])\ncheck('commit before publication', solve([['stage', 'a', N], ['dispatch']]), [None, []])\ncheck('all committed events survive delay', solve([['stage', 'a', N], ['commit'], ['stage', 'b', N+1], ['commit'], ['dispatch']]), [N+1, ['a', 'b']])\ncheck('single committed event', solve([['stage', 'a', N], ['commit'], ['dispatch']]), [N, ['a']])\ncheck('repeat dispatch does not resend', solve([['stage', 'a', N], ['commit'], ['dispatch'], ['dispatch']]), [N, ['a']])\ncheck('rollback preserves prior outbox', solve([['stage', 'a', N], ['commit'], ['stage', 'b', N+1], ['rollback'], ['dispatch']]), [N, ['a']])\ncheck('empty transaction stream', solve([]), [None, []])\nprint(json.dumps({\"observations\": observations, \"passed\": all(x[\"passed\"] for x in observations)}, ensure_ascii=False))\nraise SystemExit(0 if all(x[\"passed\"] for x in observations) else 1)\n"},"fixed":{"sha256":"7ecc29ca30dfff0bd15f1b6bdb77bc49947185d74efe7e7c2eba96a98398a088","source":"\"\"\"Failure Map reference implementation. Python standard library only.\"\"\"\nimport json\n\nN = 1\nobservations = []\ndef solve(actions):\n    pending, business, outbox, published = None, None, [], []\n    for action in actions:\n        if action[0] == 'stage':\n            pending = action[1:]\n        elif action[0] == 'commit' and pending is not None:\n            business = pending[1]\n            outbox.append(pending[0])\n            pending = None\n        elif action[0] == 'rollback':\n            pending = None\n        elif action[0] == 'dispatch':\n            published.extend(outbox)\n            outbox = []\n    return [business, published]\ndef check(label, actual, expected):\n    observations.append({\"check\": label, \"actual\": actual, \"expected\": expected, \"passed\": actual == expected})\ncheck('rollback cannot publish', solve([['stage', 'a', N], ['rollback'], ['dispatch']]), [None, []])\ncheck('commit before publication', solve([['stage', 'a', N], ['dispatch']]), [None, []])\ncheck('all committed events survive delay', solve([['stage', 'a', N], ['commit'], ['stage', 'b', N+1], ['commit'], ['dispatch']]), [N+1, ['a', 'b']])\ncheck('single committed event', solve([['stage', 'a', N], ['commit'], ['dispatch']]), [N, ['a']])\ncheck('repeat dispatch does not resend', solve([['stage', 'a', N], ['commit'], ['dispatch'], ['dispatch']]), [N, ['a']])\ncheck('rollback preserves prior outbox', solve([['stage', 'a', N], ['commit'], ['stage', 'b', N+1], ['rollback'], ['dispatch']]), [N, ['a']])\ncheck('empty transaction stream', solve([]), [None, []])\nprint(json.dumps({\"observations\": observations, \"passed\": all(x[\"passed\"] for x in observations)}, ensure_ascii=False))\nraise SystemExit(0 if all(x[\"passed\"] for x in observations) else 1)\n"}},"limitations":" This reproducer isolates one failure mechanism. Results cover the supplied fixtures. Variants within a family share a test contract and should remain grouped when constructing evaluation splits. Related mechanisms with a shared evaluation_group must also remain together; these controlled models are not independent production incidents.","method":"Deterministic executable model with adversarial boundary fixtures.","provenance":{"created_by":"Failure Map","dependencies":"Python standard library","family":"dist-transactional-outbox","generated_at":"2026-09-29T14:36:50.453163+00:00","license":"CC0-1.0","python":"3.12.14","seed":1,"split":"open-access"},"relevance":"Models the database-to-message-broker boundary and why a relay needs a committed durable outbox, while explicitly excluding the separate problem of duplicate deliveries after relay crashes.","repair":"Commit the staged state and event together, then dispatch undelivered committed outbox entries.","root_cause":"Publication is coupled to in-progress transaction state rather than a durable committed outbox.","sha256":"e23424818803346e4159b7f3441d8e195651337bf05dcd679eec84b82e066437","title":"An aborted transaction publishes an external event · case 01","variant":1,"variant_policy":"Five numbered records share a model and may reuse boundary fixtures.","verification":{"attempt":{"elapsed_ms":35.001,"exit_code":1,"observations":[{"actual":[null,[]],"check":"rollback cannot publish","expected":[null,[]],"passed":true},{"actual":[null,[]],"check":"commit before publication","expected":[null,[]],"passed":true},{"actual":[2,["b"]],"check":"all committed events survive delay","expected":[2,["a","b"]],"passed":false},{"actual":[1,["a"]],"check":"single committed event","expected":[1,["a"]],"passed":true},{"actual":[1,["a"]],"check":"repeat dispatch does not resend","expected":[1,["a"]],"passed":true},{"actual":[1,["a"]],"check":"rollback preserves prior outbox","expected":[1,["a"]],"passed":true},{"actual":[null,[]],"check":"empty transaction stream","expected":[null,[]],"passed":true}],"passed":false,"stderr":"","stdout":"{\"observations\": [{\"check\": \"rollback cannot publish\", \"actual\": [null, []], \"expected\": [null, []], \"passed\": true}, {\"check\": \"commit before publication\", \"actual\": [null, []], \"expected\": [null, []], \"passed\": true}, {\"check\": \"all committed events survive delay\", \"actual\": [2, [\"b\"]], \"expected\": [2, [\"a\", \"b\"]], \"passed\": false}, {\"check\": \"single committed event\", \"actual\": [1, [\"a\"]], \"expected\": [1, [\"a\"]], \"passed\": true}, {\"check\": \"repeat dispatch does not resend\", \"actual\": [1, [\"a\"]], \"expected\": [1, [\"a\"]], \"passed\": true}, {\"check\": \"rollback preserves prior outbox\", \"actual\": [1, [\"a\"]], \"expected\": [1, [\"a\"]], \"passed\": true}, {\"check\": \"empty transaction stream\", \"actual\": [null, []], \"expected\": [null, []], \"passed\": true}], \"passed\": false}\n"},"broken":{"elapsed_ms":35.239,"exit_code":1,"observations":[{"actual":[null,["a"]],"check":"rollback cannot publish","expected":[null,[]],"passed":false},{"actual":[null,["a"]],"check":"commit before publication","expected":[null,[]],"passed":false},{"actual":[2,["a","b"]],"check":"all committed events survive delay","expected":[2,["a","b"]],"passed":true},{"actual":[1,["a"]],"check":"single committed event","expected":[1,["a"]],"passed":true},{"actual":[1,["a"]],"check":"repeat dispatch does not resend","expected":[1,["a"]],"passed":true},{"actual":[1,["a","b"]],"check":"rollback preserves prior outbox","expected":[1,["a"]],"passed":false},{"actual":[null,[]],"check":"empty transaction stream","expected":[null,[]],"passed":true}],"passed":false,"stderr":"","stdout":"{\"observations\": [{\"check\": \"rollback cannot publish\", \"actual\": [null, [\"a\"]], \"expected\": [null, []], \"passed\": false}, {\"check\": \"commit before publication\", \"actual\": [null, [\"a\"]], \"expected\": [null, []], \"passed\": false}, {\"check\": \"all committed events survive delay\", \"actual\": [2, [\"a\", \"b\"]], \"expected\": [2, [\"a\", \"b\"]], \"passed\": true}, {\"check\": \"single committed event\", \"actual\": [1, [\"a\"]], \"expected\": [1, [\"a\"]], \"passed\": true}, {\"check\": \"repeat dispatch does not resend\", \"actual\": [1, [\"a\"]], \"expected\": [1, [\"a\"]], \"passed\": true}, {\"check\": \"rollback preserves prior outbox\", \"actual\": [1, [\"a\", \"b\"]], \"expected\": [1, [\"a\"]], \"passed\": false}, {\"check\": \"empty transaction stream\", \"actual\": [null, []], \"expected\": [null, []], \"passed\": true}], \"passed\": false}\n"},"fixed":{"elapsed_ms":42.336,"exit_code":0,"observations":[{"actual":[null,[]],"check":"rollback cannot publish","expected":[null,[]],"passed":true},{"actual":[null,[]],"check":"commit before publication","expected":[null,[]],"passed":true},{"actual":[2,["a","b"]],"check":"all committed events survive delay","expected":[2,["a","b"]],"passed":true},{"actual":[1,["a"]],"check":"single committed event","expected":[1,["a"]],"passed":true},{"actual":[1,["a"]],"check":"repeat dispatch does not resend","expected":[1,["a"]],"passed":true},{"actual":[1,["a"]],"check":"rollback preserves prior outbox","expected":[1,["a"]],"passed":true},{"actual":[null,[]],"check":"empty transaction stream","expected":[null,[]],"passed":true}],"passed":true,"stderr":"","stdout":"{\"observations\": [{\"check\": \"rollback cannot publish\", \"actual\": [null, []], \"expected\": [null, []], \"passed\": true}, {\"check\": \"commit before publication\", \"actual\": [null, []], \"expected\": [null, []], \"passed\": true}, {\"check\": \"all committed events survive delay\", \"actual\": [2, [\"a\", \"b\"]], \"expected\": [2, [\"a\", \"b\"]], \"passed\": true}, {\"check\": \"single committed event\", \"actual\": [1, [\"a\"]], \"expected\": [1, [\"a\"]], \"passed\": true}, {\"check\": \"repeat dispatch does not resend\", \"actual\": [1, [\"a\"]], \"expected\": [1, [\"a\"]], \"passed\": true}, {\"check\": \"rollback preserves prior outbox\", \"actual\": [1, [\"a\"]], \"expected\": [1, [\"a\"]], \"passed\": true}, {\"check\": \"empty transaction stream\", \"actual\": [null, []], \"expected\": [null, []], \"passed\": true}], \"passed\": true}\n"}},"verified":true,"visibility":"public"}