FAILURE MAP
← Case archive

FA-616 / Replication / Open access

Persist a replication resume checkpoint: A resume point splits a source transaction · case 01

The replication checkpoint operation is admitted even though a resume point splits a source transaction.

Verified by executionVariant 1 · 9 checks per implementationDownload source bundle ↓JSON ↗

ROOT CAUSE

The admission path omits the transaction boundary invariant while validating the other operation preconditions.

VERIFIED REPAIR

Require r['transaction_boundary'][0] in r['transaction_boundary'][1] together with every other stated precondition before accepting the operation.

Unsuccessful approach: Adding the transaction boundary check repairs the reported defect, but replacing the adjacent checkpoint monotonic check loses that independent invariant.

Case contract

Return a Boolean admission decision for persist a replication resume checkpoint. The record r must satisfy all of: all(x in r['contiguous_applied'][1] for x in range(r['contiguous_applied'][0]+1)); r['source_incarnation'][0] == r['source_incarnation'][1]; r['durable_destination'][0] <= r['durable_destination'][1]; r['transaction_boundary'][0] in r['transaction_boundary'][1]; r['checkpoint_monotonic'][0] >= r['checkpoint_monotonic'][1]. Extra tracing fields are ignored; validation does not mutate the record.

Why this case matters

A deterministic local contract for replication. Each negative fixture violates exactly one invariant. No transport timing, persistence, cryptographic verification, or full protocol implementation is claimed.

1 / The failure

Exit 1
"""Failure Map reference implementation. Python standard library only."""
import json

N = 1
observations = []
def solve(r):
    return (all(x in r['contiguous_applied'][1] for x in range(r['contiguous_applied'][0]+1))) and (r['source_incarnation'][0] == r['source_incarnation'][1]) and (r['durable_destination'][0] <= r['durable_destination'][1]) and (r['checkpoint_monotonic'][0] >= r['checkpoint_monotonic'][1])
def check(label, actual, expected):
    observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
r = {'contiguous_applied': [3, [0, 1, 2, 3]], 'source_incarnation': ['g2', 'g2'], 'durable_destination': [7, 7], 'transaction_boundary': [8, [4, 8, 12]], 'checkpoint_monotonic': [9, 8]}
check('valid operation', solve(r), True)
check('The resume point crosses an unapplied sequence gap', solve(dict(r, **{'contiguous_applied': [3, [0, 1, 3]]})), False)
check('A checkpoint is reused after the source log is recreated', solve(dict(r, **{'source_incarnation': ['g1', 'g2']})), False)
check('The checkpoint exceeds durable destination progress', solve(dict(r, **{'durable_destination': [8, 7]})), False)
check('A resume point splits a source transaction', solve(dict(r, **{'transaction_boundary': [7, [4, 8, 12]]})), False)
check('A delayed checkpoint regresses persisted progress', solve(dict(r, **{'checkpoint_monotonic': [7, 8]})), False)
check('unrelated tracing metadata', solve(dict(r, trace='run-'+str(N))), True)
check('repeat validation is pure', solve(r), True)
invalid = {'contiguous_applied': [3, [0, 1, 3]], 'source_incarnation': ['g1', 'g2'], 'durable_destination': [8, 7], 'transaction_boundary': [7, [4, 8, 12]], 'checkpoint_monotonic': [7, 8]}
keys = list(invalid)
pair = {keys[N % len(keys)]: invalid[keys[N % len(keys)]], keys[(N+1) % len(keys)]: invalid[keys[(N+1) % len(keys)]]}
check('two independent violations in variant', solve(dict(r, **pair)), False)
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
Boundary fixtureActualExpectedOutcome
valid operationTrueTruePassed
The resume point crosses an unapplied sequence gapFalseFalsePassed
A checkpoint is reused after the source log is recreatedFalseFalsePassed
The checkpoint exceeds durable destination progressFalseFalsePassed
A resume point splits a source transactionTrueFalseFailed
A delayed checkpoint regresses persisted progressFalseFalsePassed
unrelated tracing metadataTrueTruePassed
repeat validation is pureTrueTruePassed
two independent violations in variantFalseFalsePassed

SHA-256 / 95b9178c3341a2d0c629bfc14b08a4b8d0dfbe3b0bd99d5f873f6c93544f18a8

2 / The unsuccessful fix

Exit 1
"""Failure Map reference implementation. Python standard library only."""
import json

N = 1
observations = []
def solve(r):
    return (all(x in r['contiguous_applied'][1] for x in range(r['contiguous_applied'][0]+1))) and (r['source_incarnation'][0] == r['source_incarnation'][1]) and (r['durable_destination'][0] <= r['durable_destination'][1]) and (r['transaction_boundary'][0] in r['transaction_boundary'][1])
def check(label, actual, expected):
    observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
r = {'contiguous_applied': [3, [0, 1, 2, 3]], 'source_incarnation': ['g2', 'g2'], 'durable_destination': [7, 7], 'transaction_boundary': [8, [4, 8, 12]], 'checkpoint_monotonic': [9, 8]}
check('valid operation', solve(r), True)
check('The resume point crosses an unapplied sequence gap', solve(dict(r, **{'contiguous_applied': [3, [0, 1, 3]]})), False)
check('A checkpoint is reused after the source log is recreated', solve(dict(r, **{'source_incarnation': ['g1', 'g2']})), False)
check('The checkpoint exceeds durable destination progress', solve(dict(r, **{'durable_destination': [8, 7]})), False)
check('A resume point splits a source transaction', solve(dict(r, **{'transaction_boundary': [7, [4, 8, 12]]})), False)
check('A delayed checkpoint regresses persisted progress', solve(dict(r, **{'checkpoint_monotonic': [7, 8]})), False)
check('unrelated tracing metadata', solve(dict(r, trace='run-'+str(N))), True)
check('repeat validation is pure', solve(r), True)
invalid = {'contiguous_applied': [3, [0, 1, 3]], 'source_incarnation': ['g1', 'g2'], 'durable_destination': [8, 7], 'transaction_boundary': [7, [4, 8, 12]], 'checkpoint_monotonic': [7, 8]}
keys = list(invalid)
pair = {keys[N % len(keys)]: invalid[keys[N % len(keys)]], keys[(N+1) % len(keys)]: invalid[keys[(N+1) % len(keys)]]}
check('two independent violations in variant', solve(dict(r, **pair)), False)
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
Boundary fixtureActualExpectedOutcome
valid operationTrueTruePassed
The resume point crosses an unapplied sequence gapFalseFalsePassed
A checkpoint is reused after the source log is recreatedFalseFalsePassed
The checkpoint exceeds durable destination progressFalseFalsePassed
A resume point splits a source transactionFalseFalsePassed
A delayed checkpoint regresses persisted progressTrueFalseFailed
unrelated tracing metadataTrueTruePassed
repeat validation is pureTrueTruePassed
two independent violations in variantFalseFalsePassed

SHA-256 / 0a0c975296cd05871dccbc2243be093479eb3a14cea4a20eda79e47fb7eb1d37

3 / The verified repair

Exit 0
"""Failure Map reference implementation. Python standard library only."""
import json

N = 1
observations = []
def solve(r):
    return (all(x in r['contiguous_applied'][1] for x in range(r['contiguous_applied'][0]+1))) and (r['source_incarnation'][0] == r['source_incarnation'][1]) and (r['durable_destination'][0] <= r['durable_destination'][1]) and (r['transaction_boundary'][0] in r['transaction_boundary'][1]) and (r['checkpoint_monotonic'][0] >= r['checkpoint_monotonic'][1])
def check(label, actual, expected):
    observations.append({"check": label, "actual": actual, "expected": expected, "passed": actual == expected})
r = {'contiguous_applied': [3, [0, 1, 2, 3]], 'source_incarnation': ['g2', 'g2'], 'durable_destination': [7, 7], 'transaction_boundary': [8, [4, 8, 12]], 'checkpoint_monotonic': [9, 8]}
check('valid operation', solve(r), True)
check('The resume point crosses an unapplied sequence gap', solve(dict(r, **{'contiguous_applied': [3, [0, 1, 3]]})), False)
check('A checkpoint is reused after the source log is recreated', solve(dict(r, **{'source_incarnation': ['g1', 'g2']})), False)
check('The checkpoint exceeds durable destination progress', solve(dict(r, **{'durable_destination': [8, 7]})), False)
check('A resume point splits a source transaction', solve(dict(r, **{'transaction_boundary': [7, [4, 8, 12]]})), False)
check('A delayed checkpoint regresses persisted progress', solve(dict(r, **{'checkpoint_monotonic': [7, 8]})), False)
check('unrelated tracing metadata', solve(dict(r, trace='run-'+str(N))), True)
check('repeat validation is pure', solve(r), True)
invalid = {'contiguous_applied': [3, [0, 1, 3]], 'source_incarnation': ['g1', 'g2'], 'durable_destination': [8, 7], 'transaction_boundary': [7, [4, 8, 12]], 'checkpoint_monotonic': [7, 8]}
keys = list(invalid)
pair = {keys[N % len(keys)]: invalid[keys[N % len(keys)]], keys[(N+1) % len(keys)]: invalid[keys[(N+1) % len(keys)]]}
check('two independent violations in variant', solve(dict(r, **pair)), False)
print(json.dumps({"observations": observations, "passed": all(x["passed"] for x in observations)}, ensure_ascii=False))
raise SystemExit(0 if all(x["passed"] for x in observations) else 1)
Boundary fixtureActualExpectedOutcome
valid operationTrueTruePassed
The resume point crosses an unapplied sequence gapFalseFalsePassed
A checkpoint is reused after the source log is recreatedFalseFalsePassed
The checkpoint exceeds durable destination progressFalseFalsePassed
A resume point splits a source transactionFalseFalsePassed
A delayed checkpoint regresses persisted progressFalseFalsePassed
unrelated tracing metadataTrueTruePassed
repeat validation is pureTrueTruePassed
two independent violations in variantFalseFalsePassed

SHA-256 / 4587535ff7d136d91d32baecb3f787994644e06afeb88ee13ab465fdf281e443

Verification & scope

This reproducer isolates one failure mechanism. Results cover the supplied fixtures. Variants within a family share a test contract and should remain grouped when constructing evaluation splits. Related mechanisms with a shared evaluation_group must also remain together; these controlled models are not independent production incidents.

Observations recorded using Python 3.12.14 at 2026-09-29T14:36:54.304281+00:00.

Case digest / 7ef2f521bc894c192357d677914f6a123388a17ad146455ae62aad1273c6fbd7