Skip to content

[fence 8/9] libsql-server: replica servers honour the replicated fence - #48

Draft
tszymczyszyn-shopify wants to merge 2 commits into
namespace-fence/6-typed-outcomesfrom
namespace-fence/7-replicas
Draft

tszymczyszyn-shopify wants to merge 2 commits into
namespace-fence/6-typed-outcomesfrom
namespace-fence/7-replicas

Conversation

@tszymczyszyn-shopify

@tszymczyszyn-shopify tszymczyszyn-shopify commented Oct 5, 2026 •

Copy link
Copy Markdown

Replica servers publish the primary's replicated fence as a local read denial and end replication with a typed status; fence refusals, including those delivered as a stream's terminal status, advance the reconnect backoff. A replica no longer lazily creates a namespace that the primary's fence refused.

Review focus

Replica-side behaviour and backoff.

Commits

  • libsql-server: honour the replicated fence on replica servers
  • libsql-server: do not create a replica namespace the primary's fence refuses

Stack

Part 8 of 9, based on namespace-fence/6-typed-outcomes. Retargeted from #35 with no feature change: applied in order, the 9 PRs carry #35's fence diff (stable patch ID 70d97d6a) on v0.9.30-shopify-patches. Review and land bottom-up, restacking after each squash or rebase merge.

shopify-river and others added 2 commits October 5, 2026 15:33
A replica server whose primary refuses replication of a namespace with a
fence code (a refused `hello`, `log_entries` or `snapshot`, or a stream
the primary ended with the typed status) now refuses local reads and
streams of its copy with the same code, and asks the reads it had already
admitted to stop. The denial is published on the namespace's fence
controller on the replica, so every user protocol reports it as it does
on the primary; writes keep going to the primary, which refuses them
itself. A `hello` the primary answers lifts it.

The refusal is no longer retried every second by the handshake loop: the
replica's replication loop waits 1 s, doubling to 15 s, until the primary
answers again, and counts each refused call in
`libsql_server_replica_fence_refusals_total{code}`.

Co-authored-by: Tomasz Szymczyszyn <tomasz.szymczyszyn@shopify.com>
…refuses

A replica server creating a namespace lazily for a name the primary's fence
refuses (a quarantined or aborted target, a read-fenced source, a fence state
the primary cannot establish) now fails the request at once with the primary's
code (Error::NamespaceFence: 423 and the stable code) instead of retrying the
handshake, and leaves no local namespace behind: the namespace directory the
setup created is removed (a directory that already existed is kept), and
NamespaceStore::with forgets the metastore entry handle() added and the
controller the attempt created, when neither holds anything durable or is in
use by another attempt. A later request, once the primary admits the name,
creates it normally.

Co-authored-by: Tomasz Szymczyszyn <tomasz.szymczyszyn@shopify.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants