Skip to content

Tensions in Practice: Uniform observation strength in tension with operation-specific cost

Inventory record · advisory display and binding reservation

A service displays an inventory count and also accepts reservations. Once the last unit is reserved, a fully ordered later display must show zero. A permitted stale replica may still show one, but the reservation operation can independently recheck and decrement at its authority, so the next attempt fails. Both policies protect the binding reservation; they differ in what the advisory display promises.

Give a current ordered display

Keep a later display consistent with already completed reservations.

Avoid unnecessary read coordination

Serve advisory information through a cheaper path when temporary lag is acceptable.

Why these aims pull against each other

Different operations on the same record can need different observation contracts. Relaxing the display must not silently relax the atomic reservation or turn the stale display into a promise of availability.

Compare the arrangements

Order every operation

After the successful last-unit reservation completes, route the later display through the ordered authority as well.

Every operation uses the ordered authority.
Observed resultEnforced path
Reserve last unitSuccess; 0 leftAtomic authority
Later display0 remainingOrdered read
Next reservationRejected; 0 leftAtomic authority
What it protects
The displayed count reflects that completed reservation in this history.
What it costs
Advisory reads also pay the authority’s coordination, latency and possible blocking costs.
When it fits
Fits a display whose currentness is important enough to justify that cost.

Illustration note: The history orders the display after the reservation’s completion. A new concurrent change could still occur after the display; viewing availability does not itself reserve it.

Relax only the display

Permit replica reads for the advisory display, while all reservations retain the same atomic authority. The table shows one allowed stale display of one remaining unit.

The display may lag; reservations still serialize.
Observed resultEnforced path
Reserve last unitSuccess; 0 leftAtomic authority
Later displayMay show 1Chosen stale observationReplica view
Next reservationRejected; 0 leftAtomic authority
What it protects
The display can be served without coordinating every read with the latest reservation.
What it costs
A user can see apparent availability and then receive a failed reservation; the interface must communicate this advisory status.
When it fits
Fits tolerable display lag and a reliably enforced separation between advisory viewing and binding reservation.

Illustration note: One is a permitted stale observation, not a promise that every replica returns one. No maximum lag is assumed.

What this illustration does—and does not—establish

Consistency Model: System-Wide versus Per-Operation Guarantee (scopal) supplies the per-operation scope. The fixed operation history makes the changed legal observation visible while holding the binding reservation behavior constant.

  • Atomic reservation and authoritative state maintenance are assumed; merely naming a strong model does not implement them.
  • This is a single-record finite example, not a multi-item transaction or oversell prevention theorem for an entire service.

Source entries

Consistency Model

Prime · Source of the tension

Consistency Model: System-Wide versus Per-Operation Guarantee (scopal) supplies the conflict examined here.

System-Wide versus Per-Operation Guarantee (scopal)

The right unit of analysis is the operation, not the system; the same shared object can legitimately carry different models per operation.

Read the source section

Strength versus Coordination Cost (the core trade)

The defining axis: stronger models forbid more interleavings and demand more coordination (latency, bandwidth, blocking); weaker ones permit divergence cheaply.

Read the source section