Summary
The Pure-Go SQLite CI job can fail when docbank email-documents release starts a transaction while a temporary SQLite writer lock is still held.
The failure observed on PR #440 was:
cmd/docbank/email_documents_test.go:72
error executing request: daemon error (500 internal): beginning transaction:
database is locked (5) (SQLITE_BUSY)
The request waits for the driver's five-second busy timeout, then returns HTTP 500. The failing operation is Store.RemoveEmailDocumentPublication, which starts an immediate transaction through the ordinary transaction helper. A transient writer lock can outlive the helper's busy timeout, even though the operation is safe to retry before the transaction begins.
PR #458 contains a scoped fix that retries transaction acquisition for this release path and adds contention coverage in both SQLite modes. This issue records the failure mode and the required behavior so the fix remains tracked if that PR changes or is superseded.
Expected behavior
A temporary writer lock should be retried until it is released or the request context expires. The transaction callback must run at most once, and unrelated storage mutations should keep their existing busy behavior.
How to observe
Run the focused test with the Pure-Go driver:
set CGO_ENABLED=0
go test -timeout 20m -tags fts5 ./cmd/docbank -run ^TestEmailDocumentsCLIReleasesTrashBlocker$ -count=1
The failure is timing-sensitive and appears in CI when the release request overlaps a temporary writer lock.
Summary
The Pure-Go SQLite CI job can fail when
docbank email-documents releasestarts a transaction while a temporary SQLite writer lock is still held.The failure observed on PR #440 was:
The request waits for the driver's five-second busy timeout, then returns HTTP 500. The failing operation is
Store.RemoveEmailDocumentPublication, which starts an immediate transaction through the ordinary transaction helper. A transient writer lock can outlive the helper's busy timeout, even though the operation is safe to retry before the transaction begins.PR #458 contains a scoped fix that retries transaction acquisition for this release path and adds contention coverage in both SQLite modes. This issue records the failure mode and the required behavior so the fix remains tracked if that PR changes or is superseded.
Expected behavior
A temporary writer lock should be retried until it is released or the request context expires. The transaction callback must run at most once, and unrelated storage mutations should keep their existing busy behavior.
How to observe
Run the focused test with the Pure-Go driver:
The failure is timing-sensitive and appears in CI when the release request overlaps a temporary writer lock.