{"record":{"id":"9aa9f7f1ff5d68d5","repo":"influxdata/influxdb","slug":"token-to-be-updated","errorCode":null,"errorMessage":"token to be updated","messagePattern":"token to be updated","errorType":"panic","errorClass":null,"httpStatus":null,"severity":"critical","filePath":"influxdb3_catalog/src/catalog/versions/v2.rs","lineNumber":1890,"sourceCode":"\n                            // Capture the database name with deletion metadata\n                            if let Some(ref mut resource_names) = permission.resource_names {\n                                resource_names.entry(db_id.to_string()).or_insert_with(|| {\n                                    influxdb3_authz::ResourceMetadata {\n                                        name: db_name.to_string(),\n                                        deleted: true,\n                                    }\n                                });\n                                needs_update = true;\n                            }\n                        }\n                    }\n\n                    if needs_update {\n                        // Update the token in the repository\n                        self.tokens\n                            .update_token(token_id, (*updated_token).clone())\n                            .expect(\"token to be updated\");\n                    }\n                }\n            }\n        }\n\n        // Now proceed with the normal database batch processing\n        if let Some(db) = self.databases.get_by_id(&database_batch.database_id) {\n            let Some(new_db) = DatabaseSchema::new_if_updated_from_batch(&db, database_batch)?\n            else {\n                return Ok(false);\n            };\n            self.databases\n                .update(db.id, new_db)\n                .expect(\"existing database should be updated\");\n        } else {\n            let new_db = DatabaseSchema::new_from_batch(database_batch)?;\n            self.databases\n                .insert(new_db.id, new_db)","sourceCodeStart":1872,"sourceCodeEnd":1908,"githubUrl":"https://github.com/influxdata/influxdb/blob/06200ef96ba82c5f6727e5038a83af8e722c6875/influxdb3_catalog/src/catalog/versions/v2.rs#L1872-L1908","documentation":"A panic from `.expect()` in the token-update path of catalog batch replay. After deciding `needs_update` (an existing token must be refreshed), `update_token()` failed to find the token, meaning the token disappeared from `self.tokens` between the existence check and the update. The catalog treats this as an integrity violation and aborts the process.","triggerScenarios":"Replaying a batch that mutates an existing token where the token_id present in the earlier scan is missing from the tokens repository at update time; concurrent token deletion during replay.","commonSituations":"Racing token revocation and token-update operations, duplicated/overlapping batch replay, or catalog snapshot/WAL inconsistency hiding the token.","solutions":["Serialize catalog writes so token scans and updates are atomic with respect to each other.","Check for a concurrent DeleteToken/rotate path removing the token mid-batch.","Re-derive catalog state from a consistent snapshot if the token set is corrupted.","Convert the expect into a warn-and-skip (or re-insert) if the race is expected to be benign."],"exampleFix":"// before\nself.tokens\n    .update_token(token_id, (*updated_token).clone())\n    .expect(\"token to be updated\");\n// after\nif self.tokens.update_token(token_id, (*updated_token).clone()).is_none() {\n    warn!(?token_id, \"token missing at update time; re-inserting\");\n    self.tokens.insert_token((*updated_token).clone());\n}","handlingStrategy":"validation","validationCode":"// confirm the token still exists before update\nif tokens.get(token_id).is_none() { /* re-insert, skip, or error out gracefully */ }","typeGuard":"fn token_exists(tokens: &Tokens, id: TokenId) -> bool { tokens.get(id).is_some() }","tryCatchPattern":null,"preventionTips":["Avoid concurrent token deletion while mutation batches replay","Serialize token scans and updates under one writer","Restore from a consistent snapshot if the token set diverges","Add tests mixing token update and delete operations in one batch"],"tags":["panic","catalog","token","replay"],"backgroundTag":"internal-invariant-violation","analyzedSha":"06200ef96ba82c5f6727e5038a83af8e722c6875","analyzedAt":"2026-09-19T12:55:30.003Z","contentChangedAt":"2026-09-19T12:55:30.003Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}