Refresh Cellule and add table Cell placement and admission batching - #15
Merged
Merged
Conversation
Enable the existing opt-in 500 ms owner handle cache on the private receiver when server caches are enabled. Keep peer authorization fresh and invocation-only routing unable to acquire ownership. Signed SQL regression proves warm authority I/O is removed, expiry reloads, and drained owners reject reads. Ownership races, placement, and actual process-kill durability verification pass.
Use bounded compact images for internal read results so legal binary and escaped-string aggregates avoid durable coordinator and participant publication. Preserve raw item values, canonical collection ordering, nesting limits, and a saved-image fallback beyond the compact envelope. Bump both query codec versions without changing stored item or command formats. Signed remote SDK reads leave the participant root unchanged; release-style process coverage verifies the large read after a hard owner restart.
forhappy
marked this pull request as ready for review
October 2, 2026 22:19
forhappy
force-pushed
the
codex/cellule-main-refresh-20260930
branch
from
October 2, 2026 22:25
78c8bc3 to
1581d33
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Current changes
Head
906c8567740eaf1262f411b1b8c8baa8265223e5pins the user-approved Cellule EOF fix at1d0648b3b5ae0cca040c614b505b4d72bb769ab1(Cellule PR 46). Only seven Cellule Git source entries change in Cargo.lock; registry packages and dependency edges are unchanged. ExtendDB remains pinned to7eaa89b437feed0af0f05883d3f1493f86c6fc6d.Verification
Current pin: formatting, locked strict all-target Clippy, 30 library tests, credential recovery with caches off/on, two live-owner/Idle recovery cases, and the original follower process-kill test pass. The original process test keeps its assertions and deadlines, with withheld object publication, durable follower acknowledgment, owner kill, recovery, and graceful shutdown. The full local process suite is terminal 6/8: follower durability, large reads, local-index pagination, metadata caching, signed stream restart, and capacity reporting pass. Two coordinator-churn cases fail when the serving node lease fences:
directory-refreshwaits 7.2 seconds in the bootstrap case; the coordinator-history case logs almost 50 seconds inheartbeat-timer. This is separate from the EOF panic. Broad recovery qualification remains failed. The unchanged suite completes in 1,586.38 seconds on this workstation.Cellule: both new EOF regressions reproduce the original panic before the production fix. With the fix, 167 store unit tests and two integration tests pass, including cancellation/error accounting. LTX replica tests, workspace/all-target/all-feature check and strict Clippy, API docs, boundary/layout checks, Rust fences, links and runtime contracts pass. All ten upstream Cellule CI checks pass.
Before the EOF-only dependency change, this BeyondDB recovery code also passes the original complete two-owner scenario (587.17 seconds), 45 library/focused peer tests, and the full native suite (49/49). Ten focused repeats and the native suite do not reproduce the latest CI retirement failure; no retirement fix is claimed.
Preceding
ce4e7b7CI is terminal: Rust passes; SDK fails, with native 48/49, peers 85/85, and processes 7/8. Failures are table-retirement owner resolution and follower shutdown's EOF panic. The new head's Rust CI passes. Its full SDK CI passes: native 49/49 (253.23 seconds), peers 88/88 (1,740.27 seconds), and processes 8/8 (373.81 seconds). Both checks qualify this exact head. The separate local lease-fencing failures remain unresolved.Latest release/performance refresh
The fresh locked release build at
906c856passes in 365.726 seconds, binary SHA256c80badeb0f0dc56c43065e47e51e042b971be26b3338911d6fec04d2a3bcfcf2. All 72 unique signed SDK cases run once with retries disabled: 12 APIs, one/eight clients, 1 KiB items, single/four-partition BeyondDB fixtures and pinned ExtendDB SQLite. Single Cell completes 18,934 requests/zero errors, four partitions 25,645/zero, SQLite 96,666/zero.Transaction-write p95 is 2,021.21/2,701.45/15.70 ms, from 30/24/4,826 successful samples (single/four/SQLite). Four-partition transaction-read p95 is 2,547.86 ms from 29 successes. These short samples do not establish production tails. Batch/transaction calls contain two items; their item rates are twice their request rates. Every BeyondDB throughput case remains below SQLite; all-API parity is unmet. Zero errors in this short harness do not close the separate process recovery failures.
SQL command primitives average 1.761/0.564 ms while follower-backed responses average 70.715/91.753 ms and publication 108.213/181.767 ms (single/four). These scopes overlap and have different foreground/background populations; they are not additive request costs. Four-partition logs retain three deferred-resolution warnings; no maintenance-convergence claim is made.
The 12-CPU SDK-window load is single 20.29→18.88, four partitions 17.69→22.60, SQLite 21.99→15.79, with about 34.5–36 GiB of swap. No task-local builds, tests or provider probes overlap measurement. Changing contention, sequential order, and different SQLite open authorization/WAL NORMAL versus follower/object durability prevent causal or fleet-capacity claims. All seven owned performance processes and two containers are independently absent without forced server cleanup; object volumes are retained. Source, binary and lock stay unchanged.
Raw controls/logs, all rates/latencies/counts/errors, counter summaries, source attestation, cleanup evidence and a 63-file SHA256 manifest remain local and excluded from Git. The unchanged controls differ only in output directory and dependency-revision metadata after AST normalization.
Repository scope and remaining work
Benchmark files are excluded from the latest commit and the entire PR diff; raw logs, controls, and reports remain local. The user's separate dirty checkout is untouched.
Local lease stability under coordinator churn, the intermittent native retirement failure, sustained fleet recovery/load, older-root upgrades, and SQLite performance parity remain qualifications to complete. The README continues to document unimplemented DynamoDB features explicitly.