## Code Analysis ### Session lock acquisition delegates to the shared lock subsystem `server/functions/advisory_locks.go:129-150` ```go func acquireSessionAdvisoryLock(ctx *sql.Context, lockName string, try bool) (bool, error) { lockSubsystem := getLockSubsystem() if lockSubsystem == nil { return false, errors.Errorf("lock subsystem not available") } acquired := true var err error if try { acquired, err = lockSubsystem.TryLock(ctx, lockName) } else { err = lockSubsystem.Lock(ctx, lockName, time.Millisecond*-1) } if err != nil || !acquired { return acquired, err } if err = core.AddSessionAdvisoryLock(ctx, lockName); err != nil { _ = lockSubsystem.Unlock(ctx, lockName) return false, err } return true, nil } ``` The session-scoped functions call this path. The shared subsystem decides whether the key is available; the session bookkeeping is updated only after acquisition succeeds. ### Session bookkeeping is local metadata `core/context.go:92-130` ```go func AddSessionAdvisoryLock(ctx *sql.Context, lockName string) error { cv, err := getContextValues(ctx) if err != nil { return err } if cv.sessionAdvisoryLockCounts == nil { cv.sessionAdvisoryLockCounts = make(map[string]int) } cv.sessionAdvisoryLockCounts[lockName]++ return nil } func HasSessionAdvisoryLock(ctx *sql.Context, lockName string) (bool, error) { cv, err := getContextValues(ctx) if err != nil { return false, err } return cv.sessionAdvisoryLockCounts[lockName] > 0, nil } ``` This map records whether the current SQL session has acquired a key. It does not itself make the shared lock subsystem distinguish session A from session B, so it cannot provide cross-session exclusion without ownership-aware acquisition underneath. ### Repository test defines the required peer-session result `testing/go/lock_test.go:155-165` ```go // A session acquisition can be released while a transaction acquisition // of the same key remains held until commit. {Query: `/* client A */ SELECT pg_advisory_lock(43)`, Expected: []sql.Row{{"t"}}}, {Query: `/* client A */ BEGIN`, ExpectedTag: "BEGIN"}, {Query: `/* client A */ SELECT pg_advisory_xact_lock(43)`, Expected: []sql.Row{{nil}}}, {Query: `/* client A */ SELECT pg_advisory_unlock(43)`, Expected: []sql.Row{{"t"}}}, {Query: `/* client A */ SELECT pg_advisory_unlock(43)`, Expected: []sql.Row{{"f"}}}, {Query: `/* client B */ SELECT pg_try_advisory_lock(43)`, Expected: []sql.Row{{"f"}}}, {Query: `/* client A */ COMMIT`, ExpectedTag: "COMMIT"}, {Query: `/* client B */ SELECT pg_try_advisory_lock(43)`, Expected: []sql.Row{{"t"}}}, ``` The test requires client B to receive `false` while client A's session-scoped reference remains held, and `true` only after client A commits/releases the remaining transaction state. ### Observed execution #### two-session SQL probe ```sql SELECT pg_advisory_lock(9223372034774770001); SELECT pg_try_advisory_lock(9223372034774770001); ``` Session A held the session advisory lock. The captured session output recorded `t` for A and the first B result as `t`; the evidence pack identifies that first B result as `pg_try_advisory_lock(9223372034774770001)`. Thus session B acquired the same key before session A explicitly unlocked it. #### additional lock probe ```sql SELECT proname, proargtypes::regtype[] FROM pg_proc WHERE proname LIKE 'pg_advisory%'; SELECT pg_advisory_lock(123456789); SELECT locktype, mode, granted, objid, classid FROM pg_locks WHERE locktype = 'advisory'; ``` The captured output included `t` for the lock call and no returned `pg_proc` or `pg_locks` rows from the local server. The SQL endpoint was exercised with `psql`; browser navigation to port 5432 was not evidence because that port speaks PostgreSQL wire protocol rather than HTTP. ### Result The two independent SQL sessions observed session B acquiring the key while session A still held it, violating the repository's required session-lock retention behavior. The source path confirms that the session functions delegate to the shared lock subsystem while the added session map only records per-session state. ### Test context No stubs, mocks, or bypasses were applied. Transaction-scoped probes released correctly after commit and rollback; this attachment concerns the separate session-scoped cross-session result.