quorum-lease-fencing-under-clock-drift
Done. I diagnosed the problem, built a working Go reference implementation, verified it under the race detector, and wrote the full solution to ~/SOLUTION.md.
Root cause — stale writes come from four independent defects: (R1) treating the lease as the mutual-exclusion primitive, (R2) non-monotonic/unpersisted fencing tokens, (R3) the resource not enforcing the token, and (R4) vote/term state not fsynced before voting. A paused leader's local clock is meaningless, so any safety proof containing "the clocks agree" is wrong.
The fix — split responsibilities:
- Safety (clock-free): strict-majority quorum + persisted one-vote-per-term + strictly increasing term used as a fencing token + a monotonic high-water mark enforced at the resource. A resumed old leader is rejected regardless of its clock.
- Clock drift (liveness only): replica promise P = T·(1+ρ)/(1−ρ) + ε, derived from the worst adversarial case (leader clock slow, replica clock fast). New leaders cannot be elected until promises expire.
- Recovery: available ≥ Q → elect term+1, commit a barrier, bump the fence; available < Q → refuse leadership, never shrink quorum; disk-loss majority → out-of-band epoch bump.
Verification — 7 tests pass with go test -race, including a direct stale-leader-resume regression test, a negative control showing an unprotected store does get clobbered, the drift-boundary inequality, quorum loss at 3/5 vs 2/5, and crash/restart term persistence.
The document contains the complete source, the drift derivation, the recovery runbook, and the captured test output — self-contained and directly runnable.
# Evidence - Problem class: quorum-lease-fencing-under-clock-drift - Model: openrouter/deepseek/deepseek-v4.1-flash - Solved: 2026-10-06T04:09:12.912Z - Verification: solution produced by pi in sandbox; see signatures.json
{"description": "Design a crash-recoverable lease protocol for a replicated service where clocks have bounded but nonzero drift, messages can be delayed or reordered, and a former leader may resume after a long pause. Derive the fencing-token and quorum rules that prevent stale writes without requiring synchronized clocks, and explain recovery after partial quorum loss.", "environment": "go1.26", "language": "go", "model": "openrouter/deepseek/deepseek-v4.1-flash", "problem_class": "quorum-lease-fencing-under-clock-drift", "provider": "openrouter", "solved_at": "2026-10-06T04:09:12.912Z", "version": "1.26"}