Repository navigation
Scale Cell write admission and batch durable root coverage - #59
Merged
Merged
Conversation
forhappy
force-pushed
the
codex/node-write-scaling
branch
from
October 5, 2026 07:52
b96dffd to
02b25a3
Compare
forhappy
marked this pull request as ready for review
October 5, 2026 18:24
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Independent Cells reserved a maximum-sized transaction allowance, which refused otherwise-small concurrent writes. Admit SQLite database, WAL, SHM and temporary-file growth before I/O, and reserve capture/commit credit from the database image bound. Preserve resource causes after proved rollback so the same owner and request identity can retry. Ambiguous commits and capture failures still fence.
Batch exact node-authority coverage across independent and coalesced Cell roots, preserving durability bindings, sparse completion history, cancellation and retirement. Keep a follower-proven owner usable after a later pre-SQL capacity refusal.
Use the installed node lease for quiet Cell liveness, removing periodic per-Cell control writes. Long preparation still checks the shared monotonic lease; exact-root publication, expiry fencing and unleased renewal behavior remain intact.
Share live directory-cache membership and disk reservations across Cell hosts using the same cache scope. Preserve fill synchronization, cancellation ownership and restart reaccounting.
Bound quiet compaction waiters by the existing recovery capacity and queue fairly for shared admission while leaving each Cell and publisher available. Recheck the active generation, lease, queue and compaction eligibility before dispatch. New work, fencing, drain and shutdown cancel only admission; dispatched compaction retains publisher ownership and reservations through publication and cleanup.
Add an offered-load Axum driver and application-owned follower fixture with pinned mTLS and canonical fsynced stores. Audit original identities and scoped receipts after cold restore. Explain rejected follower request validation with bounded phase and envelope timing; retain signed formats and deadlines. Retain bounded native-capture timings and byte/read-strategy counters in the SQL example, including failed attempts. Critical measurements and source/binary provenance live in
crates/cellule-axum/performance; capacity qualification remains open.Validation: isolated LTX tests with and without replica features, all runtime suites, strict LTX/runtime/Axum Clippy and API documentation pass. The independent-writer starvation regression fails repeatedly on the prior nonblocking admission path and passes with fair admission. Existing availability and publisher-exclusion regressions still pass. Blocked admission does not prevent drain or shutdown; cancellation preserves permits and closed-admission source errors. Exact-root restore checks pass. Format, layer/layout, documentation and SQL/peer checks pass. The real-capture/capacity-refusal observer test and strict Axum checks pass. Original multicell provider audits pass on the recorded frozen revisions. The latest admission change’s full provider qualification remains incomplete. Adversarial follower transport tests and strict example Clippy pass with the rejection diagnostics. Broad workspace and process checks run in CI; existing qualification gates remain intact.