Skip to content

Refresh Cellule and add table Cell placement and admission batching - #15

Merged
forhappy merged 74 commits into
mainfrom
codex/cellule-main-refresh-20260930
Oct 3, 2026
Merged

forhappy merged 74 commits into
mainfrom
codex/cellule-main-refresh-20260930

Conversation

@forhappy

@forhappy forhappy commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Current changes

Head 906c8567740eaf1262f411b1b8c8baa8265223e5 pins the user-approved Cellule EOF fix at 1d0648b3b5ae0cca040c614b505b4d72bb769ab1 (Cellule PR 46). Only seven Cellule Git source entries change in Cargo.lock; registry packages and dependency edges are unchanged. ExtendDB remains pinned to 7eaa89b437feed0af0f05883d3f1493f86c6fc6d.

  • Table placement can select a single Cell or partitioned Cells through the documented creation tag.
  • Read routing resolves active sparse/hydrating owners without repeated authority reads. Cached handles validate the complete owner fence, code and schema. A held-hydration regression reduces five receiver authority GETs to zero while preserving signed SDK reads; this is metadata-work evidence, not a TPS claim.
  • Write and transaction paths bound prepare, saved-image, and reply admission; preserve durable decisions, immutable results, restart recovery, and cleanup ordering.
  • Node heartbeat observations progress independently of serialized follower-log transitions. Private follower authorization uses the separately approved Cellule enrollment API.
  • Authentication now recovers an existing published credential shard after its owner's lease expires. It preserves live owners and creates no catalog/control state for unknown access keys.
  • Recovery assertions check retained identity, code/schema, owner epoch and committed progress. A focused serving-worker test preserves the exact live coordinator fence, then completes both participant resolutions after expiry. A separate test establishes legitimate Idle reacquisition while the former node remains alive.
  • Fused object-store observation streams remain finished after EOF, avoiding the repeated-poll panic during follower recovery shutdown.

Verification

Current pin: formatting, locked strict all-target Clippy, 30 library tests, credential recovery with caches off/on, two live-owner/Idle recovery cases, and the original follower process-kill test pass. The original process test keeps its assertions and deadlines, with withheld object publication, durable follower acknowledgment, owner kill, recovery, and graceful shutdown. The full local process suite is terminal 6/8: follower durability, large reads, local-index pagination, metadata caching, signed stream restart, and capacity reporting pass. Two coordinator-churn cases fail when the serving node lease fences: directory-refresh waits 7.2 seconds in the bootstrap case; the coordinator-history case logs almost 50 seconds in heartbeat-timer. This is separate from the EOF panic. Broad recovery qualification remains failed. The unchanged suite completes in 1,586.38 seconds on this workstation.

Cellule: both new EOF regressions reproduce the original panic before the production fix. With the fix, 167 store unit tests and two integration tests pass, including cancellation/error accounting. LTX replica tests, workspace/all-target/all-feature check and strict Clippy, API docs, boundary/layout checks, Rust fences, links and runtime contracts pass. All ten upstream Cellule CI checks pass.

Before the EOF-only dependency change, this BeyondDB recovery code also passes the original complete two-owner scenario (587.17 seconds), 45 library/focused peer tests, and the full native suite (49/49). Ten focused repeats and the native suite do not reproduce the latest CI retirement failure; no retirement fix is claimed.

Preceding ce4e7b7 CI is terminal: Rust passes; SDK fails, with native 48/49, peers 85/85, and processes 7/8. Failures are table-retirement owner resolution and follower shutdown's EOF panic. The new head's Rust CI passes. Its full SDK CI passes: native 49/49 (253.23 seconds), peers 88/88 (1,740.27 seconds), and processes 8/8 (373.81 seconds). Both checks qualify this exact head. The separate local lease-fencing failures remain unresolved.

Latest release/performance refresh

The fresh locked release build at 906c856 passes in 365.726 seconds, binary SHA256 c80badeb0f0dc56c43065e47e51e042b971be26b3338911d6fec04d2a3bcfcf2. All 72 unique signed SDK cases run once with retries disabled: 12 APIs, one/eight clients, 1 KiB items, single/four-partition BeyondDB fixtures and pinned ExtendDB SQLite. Single Cell completes 18,934 requests/zero errors, four partitions 25,645/zero, SQLite 96,666/zero.

Eight clients Single req/s Four partitions req/s SQLite req/s
GetItem 220.89 591.30 804.92
PutItem 47.99 29.09 1,220.83
TransactGetItems 200.85 4.08 1,275.97
TransactWriteItems 5.02 3.86 964.48

Transaction-write p95 is 2,021.21/2,701.45/15.70 ms, from 30/24/4,826 successful samples (single/four/SQLite). Four-partition transaction-read p95 is 2,547.86 ms from 29 successes. These short samples do not establish production tails. Batch/transaction calls contain two items; their item rates are twice their request rates. Every BeyondDB throughput case remains below SQLite; all-API parity is unmet. Zero errors in this short harness do not close the separate process recovery failures.

SQL command primitives average 1.761/0.564 ms while follower-backed responses average 70.715/91.753 ms and publication 108.213/181.767 ms (single/four). These scopes overlap and have different foreground/background populations; they are not additive request costs. Four-partition logs retain three deferred-resolution warnings; no maintenance-convergence claim is made.

The 12-CPU SDK-window load is single 20.29→18.88, four partitions 17.69→22.60, SQLite 21.99→15.79, with about 34.5–36 GiB of swap. No task-local builds, tests or provider probes overlap measurement. Changing contention, sequential order, and different SQLite open authorization/WAL NORMAL versus follower/object durability prevent causal or fleet-capacity claims. All seven owned performance processes and two containers are independently absent without forced server cleanup; object volumes are retained. Source, binary and lock stay unchanged.

Raw controls/logs, all rates/latencies/counts/errors, counter summaries, source attestation, cleanup evidence and a 63-file SHA256 manifest remain local and excluded from Git. The unchanged controls differ only in output directory and dependency-revision metadata after AST normalization.

Repository scope and remaining work

Benchmark files are excluded from the latest commit and the entire PR diff; raw logs, controls, and reports remain local. The user's separate dirty checkout is untouched.

Local lease stability under coordinator churn, the intermittent native retirement failure, sustained fleet recovery/load, older-root upgrades, and SQLite performance parity remain qualifications to complete. The README continues to document unimplemented DynamoDB features explicitly.

Enable the existing opt-in 500 ms owner handle cache on the private receiver when server caches are enabled. Keep peer authorization fresh and invocation-only routing unable to acquire ownership. Signed SQL regression proves warm authority I/O is removed, expiry reloads, and drained owners reject reads. Ownership races, placement, and actual process-kill durability verification pass.
Use bounded compact images for internal read results so legal binary and escaped-string aggregates avoid durable coordinator and participant publication. Preserve raw item values, canonical collection ordering, nesting limits, and a saved-image fallback beyond the compact envelope. Bump both query codec versions without changing stored item or command formats. Signed remote SDK reads leave the participant root unchanged; release-style process coverage verifies the large read after a hard owner restart.
@forhappy forhappy changed the title Refresh Cellule main pin and rerun signed qualification Upgrade Cellule routing and publication performance and verify release behavior Sep 30, 2026
@forhappy
forhappy marked this pull request as ready for review October 2, 2026 22:19
@forhappy
forhappy force-pushed the codex/cellule-main-refresh-20260930 branch from 78c8bc3 to 1581d33 Compare October 2, 2026 22:25
@forhappy
forhappy merged commit c05cae8 into main Oct 3, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant