[Bug] Document concurrent update causes race condition and data inconsistency #21616

Open
opened 2026-02-21 20:13:31 -05:00 by yindo · 1 comment
Owner

Originally created by @FallingSnowFlake on GitHub (Jan 13, 2026).

Self Checks

  • I have read the Contributing Guide and Language Policy.
  • This is only for bug report, if you would like to ask a question, please head to Discussions.
  • I have searched for existing issues search for existing issues, including closed ones.
  • I confirm that I am using English to submit this report, otherwise it will be closed.
  • 【中文用户 & Non English User】请使用英语提交,否则会被关闭 :)
  • Please do not modify this template :) and fill in all the required fields.

Dify version

1.11.3

Cloud or Self Hosted

Self Hosted (Docker), Self Hosted (Source)

Steps to reproduce

The DatasetService.update_document_with_dataset_id() method (dataset_service.py:2174-2315) lacks Redis distributed lock protection during document updates, which can lead to race conditions and data inconsistency when multiple concurrent requests try to update the same document.

  1. Set up a document in a dataset with display_status="available"
  2. Send more concurrent POST requests to /console/api/datasets/{dataset_id}/documents with the same original_document_id
  3. Observe that multiple requests succeed simultaneously

✔️ Expected Behavior

Only one update request should succeed at a time. Other concurrent requests should either:

  • Wait for the lock to be released and then proceed
  • Fail with "Document is not available" error

Actual Behavior

Multiple concurrent requests successfully update the same document, causing:

  • Document being processed multiple times unnecessarily
Originally created by @FallingSnowFlake on GitHub (Jan 13, 2026). ### Self Checks - [x] I have read the [Contributing Guide](https://github.com/langgenius/dify/blob/main/CONTRIBUTING.md) and [Language Policy](https://github.com/langgenius/dify/issues/1542). - [x] This is only for bug report, if you would like to ask a question, please head to [Discussions](https://github.com/langgenius/dify/discussions/categories/general). - [x] I have searched for existing issues [search for existing issues](https://github.com/langgenius/dify/issues), including closed ones. - [x] I confirm that I am using English to submit this report, otherwise it will be closed. - [x] 【中文用户 & Non English User】请使用英语提交,否则会被关闭 :) - [x] Please do not modify this template :) and fill in all the required fields. ### Dify version 1.11.3 ### Cloud or Self Hosted Self Hosted (Docker), Self Hosted (Source) ### Steps to reproduce The `DatasetService.update_document_with_dataset_id()` method (dataset_service.py:2174-2315) lacks Redis distributed lock protection during document updates, which can lead to race conditions and data inconsistency when multiple concurrent requests try to update the same document. 1. Set up a document in a dataset with `display_status="available"` 2. Send more concurrent POST requests to `/console/api/datasets/{dataset_id}/documents` with the same `original_document_id` 3. Observe that multiple requests succeed simultaneously ### ✔️ Expected Behavior Only one update request should succeed at a time. Other concurrent requests should either: - Wait for the lock to be released and then proceed - Fail with "Document is not available" error ### ❌ Actual Behavior Multiple concurrent requests successfully update the same document, causing: - Document being processed multiple times unnecessarily
yindo added the 🐞 bugstale labels 2026-02-21 20:13:31 -05:00
Author
Owner

@dosubot[bot] commented on GitHub (Feb 13, 2026):

Hi, @FallingSnowFlake. I'm Dosu, and I'm helping the Dify team manage their backlog and am marking this issue as stale.

Issue Summary:

  • You reported a race condition in DatasetService.update_document_with_dataset_id() due to missing Redis distributed lock protection.
  • This causes multiple concurrent updates to the same document, resulting in data inconsistency and redundant processing.
  • The issue calls for synchronization to ensure only one update happens at a time.
  • No further comments or activity have been recorded since your report.

Next Steps:

  • Please let me know if this issue is still relevant with the latest version of Dify by commenting here.
  • Otherwise, this issue will be automatically closed in 15 days.

Thank you for your understanding and contribution!

@dosubot[bot] commented on GitHub (Feb 13, 2026): Hi, @FallingSnowFlake. I'm [Dosu](https://dosu.dev), and I'm helping the Dify team manage their backlog and am marking this issue as stale. **Issue Summary:** - You reported a race condition in `DatasetService.update_document_with_dataset_id()` due to missing Redis distributed lock protection. - This causes multiple concurrent updates to the same document, resulting in data inconsistency and redundant processing. - The issue calls for synchronization to ensure only one update happens at a time. - No further comments or activity have been recorded since your report. **Next Steps:** - Please let me know if this issue is still relevant with the latest version of Dify by commenting here. - Otherwise, this issue will be automatically closed in 15 days. Thank you for your understanding and contribution!
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: langgenius/dify#21616