FA-091 / Distributed coordination / Open access
A revoked consumer acknowledges a new assignment's message · case 01
An acknowledgment from a prior assignment is accepted after a rebalance reuses the message identifier.
ROOT CAUSE
Acknowledgment validation omits either the assignment generation or the message identity.
THE FAILURE
Acknowledgment validation omits either the assignment generation or the message identity.
Unsuccessful approach: Validating only the generation accepts acknowledgments for a different message in the same assignment.
Case contract
The active delivery is [assignment generation,message ID]. Acks have the same shape. Return whether any acknowledgment exactly matches both fields. Other deliveries do not share this state.
Why this case matters
Models fencing of consumer acknowledgments across partition ownership changes; unlike checkpoint prefix accounting, the failure concerns ownership of a particular in-flight delivery.
1 / The failure
Exit 1"""Failure Map reference implementation. Python standard library only."""
import json
N = 1
observations = []
def solve(generation, message, acknowledgments):
return any(ack_message == message for ack_generation, ack_message in acknowledgments)
def check(label, actual, expected):
observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
g, message = N+1, 'message-'+str(N)
check('prior owner late ack', solve(g, message, [[g-1, message]]), False)
check('wrong message same assignment', solve(g, message, [[g, 'different']]), False)
check('valid acknowledgment', solve(g, message, [[g, message]]), True)
check('future generation is not this delivery', solve(g, message, [[g+1, message]]), False)
check('valid among delayed noise', solve(g, message, [[g-1, message], [g, 'different'], [g, message]]), True)
check('no acknowledgment yet', solve(g, message, []), False)
check('invalid after valid cannot undo ack', solve(g, message, [[g, message], [g-1, message]]), True)
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
| Boundary fixture | Actual | Expected | Outcome |
|---|---|---|---|
| prior owner late ack | True | False | Failed |
| wrong message same assignment | False | False | Passed |
| valid acknowledgment | True | True | Passed |
| future generation is not this delivery | True | False | Failed |
| valid among delayed noise | True | True | Passed |
| no acknowledgment yet | False | False | Passed |
| invalid after valid cannot undo ack | True | True | Passed |
SHA-256 / bf7b0151932184a1d99329cf8c0becc151bfa0693f531464ed449a3746277f48
2 / The unsuccessful fix
Exit 1"""Failure Map reference implementation. Python standard library only."""
import json
N = 1
observations = []
def solve(generation, message, acknowledgments):
return any(ack_generation == generation for ack_generation, ack_message in acknowledgments)
def check(label, actual, expected):
observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
g, message = N+1, 'message-'+str(N)
check('prior owner late ack', solve(g, message, [[g-1, message]]), False)
check('wrong message same assignment', solve(g, message, [[g, 'different']]), False)
check('valid acknowledgment', solve(g, message, [[g, message]]), True)
check('future generation is not this delivery', solve(g, message, [[g+1, message]]), False)
check('valid among delayed noise', solve(g, message, [[g-1, message], [g, 'different'], [g, message]]), True)
check('no acknowledgment yet', solve(g, message, []), False)
check('invalid after valid cannot undo ack', solve(g, message, [[g, message], [g-1, message]]), True)
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
| Boundary fixture | Actual | Expected | Outcome |
|---|---|---|---|
| prior owner late ack | False | False | Passed |
| wrong message same assignment | True | False | Failed |
| valid acknowledgment | True | True | Passed |
| future generation is not this delivery | False | False | Passed |
| valid among delayed noise | True | True | Passed |
| no acknowledgment yet | False | False | Passed |
| invalid after valid cannot undo ack | True | True | Passed |
SHA-256 / 91a96bff2c4e467511178f12ac25f2e1ccbbc6f38bcf59de422c742e676fe701
HELD IN THE MEMBER ARCHIVE
The verified repair and its recorded checks are member-only.
This mechanism has 7 recorded checks per implementation. The open-access tier publishes the failure and the unsuccessful fix; the repaired source that passes every check, and the observations that prove it, are available to members.
Every case sharing this mechanism uses the same contract and the same repair, so this one record is held back for all of them.
Member access is invitation-based. Sign in with your invited account to inspect the repair.
Sign in to the archive ↗Verification & scope
This reproducer isolates one failure mechanism. Results cover the supplied fixtures. Variants within a family share a test contract and should remain grouped when constructing evaluation splits. Related mechanisms with a shared evaluation_group must also remain together; these controlled models are not independent production incidents.
Observations recorded using Python 3.12.14 at 2026-09-29T14:36:50.439436+00:00.
Case digest / 2398dbbfbf600627f6786f0378f6c1849882c31577c68fabeadfdff67318fd3d