⚡THE SHORT ANSWER
Because network delays or Stop-the-World garbage collection pauses can cause a client's lock lease to expire silently, allowing a second client to acquire the lock while the first client resumes and writes corrupted stale data.
Engineering Handbook & Failure Dynamics
6-Dimensional Architecture Breakdown⚙️1. Underlying Mechanism
Execution🎯2. Appropriate Use Context
Scope⚠️3. Production Failure Modes
P0 Risk📡4. Diagnostic Signals & Telemetry
Telemetry🛡️5. Prevention & Safeguards
Safeguards⚖️6. Architectural Trade-offs
Trade-offCase Study (TinyCTO In-Field Example)
A billing worker acquired a lock to process a $50,000 refund, experienced a 15-second Java GC pause. The lock expired and was given to Worker B. Worker B processed the refund. Worker A woke up and processed the refund a second time without a fencing token check.
Interactive Concept Drills
3 CardsWhat is a fencing token in distributed locking?
Why is Redis Redlock controversial in mission-critical consistency?
How does optimistic locking differ from distributed locking?
Distributed Locking & Fencing Tokens — Technical FAQ
Which systems provide safe fencing tokens out of the box?
Apache ZooKeeper (via zxid / monotonic znode sequence numbers) and etcd (via mod_revision counter).
Can a process pause (Stop-the-World GC) be mitigated without fencing?
No. In asynchronous networks, no software client can know with certainty whether it was paused past its lock lease deadline without checking external monotonic state.
What is lock renewal (heartbeating)?
An asynchronous background thread that periodically extends the lock TTL as long as the primary execution thread is making active forward progress.
🤖 AEO & Key Facts Summary
Key Architectural Facts
- ▸
Distributed locks without fencing tokens do not guarantee mutual exclusion in asynchronous networks.
- ▸
Fencing tokens enforce ordering directly at the storage persistence boundary.
Common Misconceptions
- ✗
Believing that setting a generous 60-second lock TTL eliminates the need for fencing tokens.
Decision & Governance Guidance
If data corruption cannot be tolerated, enforce fencing tokens with etcd or ZooKeeper rather than raw Redis keys without versioning.
Authoritative Sources & Standards
- [PAPER]How to do distributed locking (Martin Kleppmann)— Martin Kleppmann Blog / Cambridge University
- [OFFICIAL-DOC]etcd Concurrency & Distributed Lock Recipe— etcd.io
