Skip to content

Newsletter · Issue #058

One Row Cannot Prove One Sender

After this issue, the reader can decide whether a status record, a green test suite, or a gapless archive is evidence that a job ran exactly once, and name the surface that would settle it.

Published
Format
Toolkit
Reader job
Help Decide
Length
2 min read
Written by
Victor Solano

This newsletter's sender keeps one Postgres row per issue, and each deploy asks that row whether the latest issue already went out. Until yesterday the guard read the row and then wrote 'sending' as two separate statements. A regression test firing two simultaneous requests proved both cleared the read before either wrote, and both went on to load the subscriber list. The row is unique by slug and the finish step overwrites it, so one row reading 'sent' is equally consistent with one sender and with two.

The tail of one INSERT. A row already 'sending' or 'sent' fails the WHERE clause, RETURNING hands back nothing, and that caller stops before reading a subscriber.
ON CONFLICT (slug) DO UPDATE
  SET status = 'sending', attempted = 0, sent = 0, failed = 0, started_at = NOW()
  WHERE newsletter_issue_email_sends.status = 'failed'
RETURNING status

The losing request is skipped with the reason sendInProgress and attempted 0. Keeping 'failed' in that WHERE clause is deliberate: a bare insert-if-missing would leave a partially failed send unretryable, trading a duplicate for a silent gap.

Read the middle column before citing the signal on the left.
Clean signalIt cannot proveWhat settles it
Status row reads 'sent'that exactly one sender ranthe statement granting the row: can two callers both win it?
Test suite is greenthat an unwritten case is saferun the new test against the old code and watch it go red
No duplicate complaintsthat no duplicate arrivedthe provider's per-recipient log for that issue
Archive has no gapsthat each issue shipped on the date it showseach issue's date against the commit that added it

The rule

A record written by the process you are auditing reports only what it chose to store. Verify at the surface that would have to contradict itself to hide the failure.

A check that states its own limits

App Store Submission Checker

Free, in the browser. It counts listing characters and UTF-8 bytes, and reads screenshot type and dimensions from a bounded file header without uploading your images. Each Apple-dependent check links the rule it used with that rule's verification date, and the page states what it cannot decide: App Review acceptance, legal compliance, ranking, or any subjective guideline call.

Open the checker

Ask what the record had no way to record.