Review the prerequisites
Suitable for: Can read SQLite transactions and basic Python.
- Idempotent
- When the same business operation is requested repeatedly, no additional repeated business effects will be generated; the scope of the guarantee depends on the server implementation and validity period.
- operating identity
- A stable identifier representing the same business intent, which is different from the identifier for each network attempt.
- Checkpoint
- The calculation state saved by the caller does not automatically equal the fact that the external service has occurred.
- Unknown result
- The caller does not get a reliable receipt and cannot assert success or failure.
How does the mechanism work?
- persistence intent
Save the stable operation identity and parameters before initiating the action.
- Submitted by service provider
The service party executes and removes duplication with its own contract.
- Caller Check
Response is lost when querying or retrying along the same identity.
- Update task status
Confirm after obtaining a verifiable receipt. If it cannot be verified, the status will remain unknown.
Implementation · Build it
Recover from a successful commit with a lost receipt
Objectives of this level: The same receipt can be replayed with a stable operating identity, and identity and parameter conflicts are rejected.
Keep facts in two databases
provider.db holds effects and receipts; caller.db holds intent and confirmation state. Commit prepared at the caller, then commit at the provider. Deliberately omit the first receipt from caller.db. The caller remains prepared while the provider already has an effect.
Recover using the provider's deduplication contract
Retry publish-1 with report-v1. Within its local transaction, the provider checks operation identity: matching arguments return the original receipt without another effect; different arguments conflict. The caller becomes confirmed only after receiving the receipt. File-backed databases preserve provider facts beyond the first function invocation.
Define the atomic boundary
The provider uses BEGIN IMMEDIATE to put lookup, comparison, and insertion in one SQLite write transaction, preventing the lab's check-then-write race. It covers no real email, payment, or third-party publishing system; those need their own idempotency and status-query contracts. The script simulates receipt loss without killing a process or interrupting a real network.
Run experiments and observe counterexamples
Two local SQLite files simulate independent submission and response loss; there is no real remote end, process termination or network failure, and it does not prove end-to-end exactly-once.
Python 3.10+ · Runs by default using only the standard library · Runs on your computer
- Observe the differences between the caller's prepared and the server's submitted
- Get the original receipt along the same operation identity
- Use the same identity to change content and verify conflicts
python3 idempotency_recovery.pyView the entry-point script
"""Two local SQLite files model independent caller/provider commits.
Not a real remote service, production queue or end-to-end exactly-once proof.
"""
import json
import sqlite3
import tempfile
from pathlib import Path
def provider(path, operation, payload):
with sqlite3.connect(path) as db:
db.execute("CREATE TABLE IF NOT EXISTS effects (operation TEXT PRIMARY KEY, payload TEXT NOT NULL, receipt TEXT NOT NULL)")
# Serializes the read/check/write in this local demonstration.
db.execute("BEGIN IMMEDIATE")
existing = db.execute("SELECT payload,receipt FROM effects WHERE operation=?", (operation,)).fetchone()
if existing:
if existing[0] != payload:
raise ValueError("same operation with different payload")
return existing[1]
receipt = "receipt:" + operation
db.execute("INSERT INTO effects VALUES(?,?,?)", (operation, payload, receipt))
return receipt
def demo():
with tempfile.TemporaryDirectory() as folder:
remote, local = Path(folder) / "provider.db", Path(folder) / "caller.db"
with sqlite3.connect(local) as db:
db.execute("CREATE TABLE intents(operation TEXT PRIMARY KEY, payload TEXT, status TEXT, receipt TEXT)")
db.execute("INSERT INTO intents VALUES('publish-1','report-v1','prepared',NULL)")
first = provider(remote, "publish-1", "report-v1")
# Simulated response loss: provider committed, caller did not get receipt.
with sqlite3.connect(local) as db:
before = db.execute("SELECT status FROM intents").fetchone()[0]
second = provider(remote, "publish-1", "report-v1")
with sqlite3.connect(local) as db:
db.execute("UPDATE intents SET status='confirmed', receipt=?", (second,))
with sqlite3.connect(remote) as db:
effects = db.execute("SELECT COUNT(*) FROM effects").fetchone()[0]
assert before == "prepared" and first == second and effects == 1
return dict(caller_before_recovery=before, same_receipt=first == second,
provider_effects=effects, caller_after_recovery="confirmed")
if __name__ == "__main__":
print(json.dumps(demo(), sort_keys=True))
Expected output when running locally
{"caller_after_recovery": "confirmed", "caller_before_recovery": "prepared", "provider_effects": 1, "same_receipt": true}- There is only one business effect for the server
- Consent diagram retry receipt consistent
- Remote capabilities and deduplication deadlines need to be verified separately
Acceptance task for this level
Run idempotency_recovery.py, and then submit report-v2 for the same identity to observe conflicts.
Check each item after completion
- It is still prepared before the caller resumes
- The two receipts are the same, and the service provider has only one effect.
- Same key but different parameters are rejected
Save your own processes, code and results. Acceptance requirements are provided here, and course mastery status will not be automatically graded or saved at this time.
Hide the answer and check your understanding
Can adding unique constraints to the local database prevent the remote email system from sending messages repeatedly?
Expand reference derivation
Only local constraint ranges can be protected. The side effect of remote mail still requires remote deduplication or queryable receipts, which cannot be automatically guaranteed by local unique keys.
Further explanations and practice
When encountering unfamiliar principles, first read the implementation, continuous questioning and migration cases, and then independently explain the premise and boundaries. Answers and notes are saved to the original account record.
All linked explanations and exercises (5 )
- Idempotency and compensation when outcomes are unknown · answer independently
- Checkpoints, replay, and external side-effect boundaries · answer independently
- Lease takeover and fencing stale workers · answer independently
- One state machine for retries, deadlines, cancellation, and budgets · answer independently
- Approval snapshots, durable waiting, and one logical resumption · answer independently
Sources and verification scope
The principles are based on public information; the numbers, cases and tasks are the teaching design of this website. Offline experiments verify the range noted on this page, and the learning effect still needs to be judged through independent tasks and feedback.