{
  "status": "shipping",
  "advantages": [],
  "limitations": [],
  "supersedes": [],
  "supersededBy": [],
  "firstSeen": null,
  "lastSeen": null,
  "updated": "2026-10-11",
  "slug": "fencing-token",
  "term": "Fencing token",
  "aliases": [],
  "definition": "A fencing token identifies an ownership generation that a receiving service checks to reject operations from an obsolete owner.",
  "note": "Chubby's sequencer includes the lock name, acquisition mode and generation. The receiving service must validate it; merely issuing or attaching a token does not enforce exclusion. This is distinct from a SCSI registration key. Correct recovery of the recipient's validation state is part of the protection, not a property supplied by an arbitrary counter.",
  "related": [
    "io-fencing",
    "scsi-persistent-reservations"
  ],
  "citations": [
    {
      "id": "chubby",
      "title": "Mike Burrows. The Chubby lock service for loosely-coupled distributed systems. OSDI 2006, sections 2.1 and 2.4.",
      "url": "https://www.usenix.org/legacy/event/osdi06/tech/full_papers/burrows/burrows.pdf",
      "accessed": "2026-10-11"
    },
    {
      "id": "hesela-fencing",
      "title": "Storage fencing: why a lost heartbeat does not stop writes",
      "url": "https://hesela.com/analyses/storage-fencing-stale-writes/",
      "accessed": "2026-10-11"
    }
  ]
}
