feat(protocol): publish Git and Xet state through capsules - #208
Conversation
1962719 to
9850e91
Compare
|
Follow-up qualification and hardening (commit 9393caf):
The Kubernetes 5,000-commit stress artifact remains explicitly negative at the 500-commit fetch/repack boundary because the interrupted pre-fix repository state still requires a large historical pack; it is not being reported as parity proof. Hosted-provider, multipart, replica/tiering, mount/browser, S3 gateway, migration/recovery, and backup/restore rows remain release gates. |
|
Parity follow-up (commit d6431f8): removed the stale client rejection for protected pushes carrying a v2 mirror-plan ID. The plan ID is already authenticated in |
|
Added |
|
Documentation follow-up (commit 0233c25): the main capsule publication design now records the authenticated external thin-base rule and protected mirror-plan receipt path alongside the parity inventory and RustFS evidence. |
0233c25 to
6ad3b0b
Compare
V1 parity passImplemented and pushed in
Proof after rebase:
Remaining release blockers are intentionally explicit: hosted-provider checksum/multipart and 5,000-commit current-format replay; managed replica failover/repair; tier/archive restore; mount range/cancellation/unmount; browser/HTTP load and fault matrix; S3 gateway operation/concurrency/restart matrix; lifecycle/workflow/admin inventory; backup/restore export inventory; and migration fault/resume/provider plus older-Git/interrupted/adversarial qualification. Full v1 production parity is not claimed until those Level-3 gates pass. |
|
Parity closure update (c2d87d8):
Local proof after this change:
This closes the local wiring gap, but is not a claim of complete v1 production parity. Release gates remain: live S3/GCS/Azure lifecycle and restore behavior; replica readiness/failover/repair; restored-content verification; the full FUSE/NFS range/cache/cancellation matrix; browser and smart-HTTP load/fault coverage; S3 gateway restart/concurrency/request-count coverage; and migration, backup inventory, and delete/restore qualification on populated v1/v2 repositories. |
|
Follow-up test hardening: the focused mount module now passes 122/122. I also serialized the unmount test's HOME override through the existing test guard; this removes a process-global HOME race that could make |
|
Final local rerun after the test-only race fix: |
4b94ade to
cc8700f
Compare
|
Layered-pack qualification update (commit 1640af9):
The 5,000-commit replay with 500-commit fetch/repack checkpoints and hosted-provider matrix remain explicit release gates; v1 is not being retired until those pass. |
|
Follow-up pushed in The first fresh PR-208 5,000-commit run found a correctness blocker before replay could continue: an append-only in-memory visibility dictionary could be non-canonical when serialized into the layered capsule ( Proof for the fix:
I am rebuilding the exact release binary from this commit and rerunning the fresh local-RustFS qualification. The earlier run remains recorded as a failed negative qualification at seed + replay 1; no 5,000-commit success is claimed until all replay, checkpoint fetch/repack, clone, and fsck gates pass. |
|
Layered-pack follow-up pushed in
The PR is updated with the fixes and evidence, but v1 is not retired and the 5,000-commit/multi-pack cold-clone gates remain open until the authenticated multi-member install or equivalent whole-member union path is implemented and requalified. |
|
Post-push test completion for
The branch remains clean apart from the pre-existing untracked local |
|
Updated in commit 1cfdd63 (perf(fetch): preload layered locators for cold clones).\n\nWhat changed:\n- Complete layered views now coalesce and authenticate index, reverse-index, and kind-bearing locator sidecars, then expose inline locators to the planner.\n- Ordinary incremental haves stay on the footer/tip-bound path; cold, filtered, shallow, and tag requests promote only when complete visibility is required.\n- Multi-member cold clones no longer fall back to per-object visibility reads; direct one-pack installation remains fail-closed.\n- Design history and qualification evidence are recorded in crab/docs/design/capsule-layered-packs.md.\n\nVerification:\n- crab-read: 200 passed.\n- remote-helper: 139 passed.\n- upload-pack wire: 39 passed.\n- Local RustFS, Kubernetes-derived fixture: blob:none clone 14.50 s with 173 ms planning; cache-miss shallow blob:none clone 6.12 s with 1,095 planning reads and 372 terminal response-pack reads; unfiltered multi-member clone 85.94 s, exact source tip, native git fsck --full clean.\n- Full, filtered, and shallow clone tips all match the source.\n\nThe fresh 5,000-push/fetch/repack matrix, hosted-provider latency, and v1-retirement gates remain open; this update does not claim those are complete. |
|
CI follow-up: GitHub did not emit a synchronize run for the new head, so I manually dispatched the current commit (1cfdd63) against the repository workflows:\n- CI: https://github.com/crabbuild/crab/actions/runs/35675208869\n- Git protocol v2 partial-clone qualification: https://github.com/crabbuild/crab/actions/runs/35675210814\n- Large repository RustFS qualification: https://github.com/crabbuild/crab/actions/runs/35675212409\n\nAt this update they are queued, not yet green; the prior completed run was for an older head. |
|
Pushed dba2cb4 (fix(protocol-v2): retain negotiated fetch haves). What changed:
Proof:
Qualification status remains honest: the replay later reached an existing 503,980,520-byte Crab/Xet pointer commit and stopped with CRAB-E0086 because the replay harness had not staged its local chunks. The 5,000-push/xorb qualification gate is still open; this is a staging-contract failure, not evidence that the haves fix is incorrect. |
|
Pushed follow-up commit 1696f53 to PR 208. The fresh full-history GitHub-origin Kubernetes RustFS qualification (pr208-v2-fresh-github-smoke2-20260921, binary dba2cb4) passed seed publication, protocol-v2 incremental fetches at pushes 1/5/10, exact tip checks, cold and warm full clones, and native fsck. Measured incremental fetches were 33.457s / 15,494 storage range reads / 50.1MB response at push 1 and 24.227s / 16,999 reads / 55.5MB response at push 5. Cold full clone was 217.5s with 10 store requests; warm clone was 99.8s with zero store requests. The run stopped only at the blobless-clone qualification assertion blob-none-ordinal-metadata-lookup: the exact ordinal-metadata lookup branch emitted no locator_lookup_mode event, so the harness observed zero metadata events even though the request completed through the catalog-filter plan. The new commit adds that trace at the crab-metadata reader boundary; no data-path or authorization behavior changes. Focused crab-metadata tests pass (212/212). Fresh workflows have been dispatched at this new head:
I am not marking the PR green until those runs complete. |
|
Pushed This fixes the v2 incremental-fetch regression caused by generation-owner checkpoint compaction: the control-only reader previously saw no live capsule transitions after compaction and fell back to a visibility traversal. Layered checkpoints now carry a bounded, authenticated recent per-ref transition suffix in the footer. Control-only fetches consume that suffix; older/incomplete have chains still fail closed to the existing catalog/traversal planner. The complete ordinal visibility body remains authoritative for cold/strict paths. Proof:
Fresh manual workflows for this commit:
|
|
Qualification update for
|
|
Update: pushed
Known local gate: workspace |
|
Qualification update from the exact |
|
Focused regression gate from |
|
Qualification update: the 1,500-boundary checkpoint completed with 1,501/1,501 pushes successful. Owner maintenance was 511.8 s (peak child RSS ~1.69 GiB, two active packs). The incremental fetch then completed in 15.4 s with 146 storage requests and 17,445 logical objects; visibility planning was 1 ms. This reinforces the outstanding protocol-v2 response-pack scaling gap; correctness remains intact and the 5,000 replay is continuing. |
|
Qualification update: the 2,000-boundary checkpoint completed with 2,001/2,001 pushes successful. Owner maintenance was 659.3 s (peak child RSS ~0.79 GiB, two active packs). Incremental fetch completed in 5.88 s with 126 storage requests and 20,279 logical objects; visibility planning was 3 ms. Fetch wall time varied versus the 1,500 sample, but the request count remains dominated by protocol-v2 response-pack reads. The 5,000 replay continues with no correctness failure. |
Interim 100 GiB Xet qualification (not closeout)Fresh local RustFS 1.0.0 GA run against PR head
These seed timings are not evidence of acceptable performance or a matched v1 comparison. The current-head CI Compose/Cellule qualification failure and remaining provider/product parity gates are still open. Fetch request count is diagnostic only per acceptance; it is not a gate. Keep v1 supported until all correctness, parity, and matched-performance gates pass. |
Qualification progress: v1 incremental updateThe full-run report now includes v1 on the 100 GiB fixture. This was a broad history commit (50 model files and 500 source files changed), not a simple one-file push:
This is not a matched v1 performance comparison and does not pass the sub-second/simple-push or <10-request push gates. The full run remains in progress; v1 stays supported. |
v2 update push: repeated measurementThe third history version completed on the same 100 GiB fixture. The v1 and v2 updates each changed 50 model files plus 500 source files and had nearly flat push results:
Each update added 50 xorbs and one shard; push request bodies were about 80 MB. These are broad content updates, not the simple-push benchmark, and they do not pass the sub-second goal. Each push has one aggregated 4xx response with no path trace; proxy transport exceptions are zero, but the 4xx still needs classification. The report currently has 178 checks and no failures. Consumer cross-repository reuse, cold clone/hydrate, retained-history restore, and full-run completion remain pending. |
Fresh cold cross-repository reuse resultThe current-head 100 GiB run has now passed This supersedes the earlier failed cold-cache fixtures for this tested overlap shape. It does not yet establish arbitrary partial-overlap discovery, all-provider behavior, or full v1 parity. The request meter does not isolate request counts for this individual consumer push. At the last report snapshot, all 234 checks passed and transport-proxy exceptions remained zero. |
Clone and hydration progressThe independent 537,919,488-byte consumer hydrate completed in 14,279 ms with exact byte identity. The full 100 GiB repository clone completed in 839 ms; this is pointer/Git metadata clone latency, not full content materialization. Full-corpus cold hydration is still in progress. At the latest sample it had materialized 8 of 50 model files (16 GiB logical output) after 12m39s; RustFS transfer/block counters continued increasing, with no observed transport exceptions. All 238 checks remain passing. This phase must finish exact byte verification, a rehydrate cycle, and retained-history restore before the run can pass. |
Cold-hydrate midpointThe exact-head 100 GiB cold hydrate has reached 25/50 model files (50 GiB logical output) at 24m39s. RustFS network counters have stayed flat since the shared Xet chunks were fetched; current progress is local reconstruction and file writes. Workspace free space is ~245 GiB, and the report remains at 238 passing checks with no failures. The clone command itself was 839 ms; this slower phase is full Xet content materialization, not Git/capsule clone metadata. Final byte verification, the rehydrate cycle, and history restore are still pending. |
|
Qualification update for PR #208 at 03b3185. The 500-commit incremental fetch passed correctness in 5.55 s and installed one pack. Its 27 object-store requests are diagnostic only, not an acceptance gate; fetch correctness and latency remain gated. The fresh RustFS 1.0.0 GA 100 GiB run has 238 checks with no reported failures so far, including the large seed/repack, v1/v2 updates, Xet cross-repository chunk reuse, and byte-identical consumer hydration. Full cold hydrate is still running at about 30 minutes, actively writing large temporary outputs; workspace free space is about 231 GiB. The report has not advanced past the hydrate-capacity check. Transport totals are 1,197 requests with no proxy exceptions; 16 4xx responses still need path-level classification, so this is not a zero-error result. This does not close v2 qualification. Remaining gates include completing and verifying cold hydrate plus dehydrate/rehydrate and historical restore, classifying the 4xx responses, current-head large replay and matched v1 performance, provider/product parity, and resolving the current-head CI failure in Build and inspect image (fallback-candidate/Cellule rotation assertion). Azure, GCS, NFS, and Kubernetes qualification jobs are skipped in the current workflow. V1 retirement remains deferred until correctness, parity, and matched performance are demonstrated. |
|
Qualification update for current PR head Fetch decision: the 27 requests observed for a 500-commit incremental fetch are accepted as diagnostic, not a release gate. Keep the correctness/latency contract: exact tip, one installed pack, no fetch-triggered repack or stable-body reread, and p95 at or below 10 seconds. The completed October 3 replay meets that fetch contract at 8.581 s p95; request count is not a blocker. The latest pushed change fixes the Compose qualification fixture while preserving the genuine non-member recovery assertion. Its current CI job is still in progress, so this does not yet count as a pass. Current PR checks: 5 passed, 10 running, 6 queued, and 2 skipped. The fresh RustFS GA 100-GiB run is still active. Its report has 839 checks and zero reported failures; cold hydrate and dehydrate passed, and rehydrated hydrate is in progress after passing capacity admission (315,642,658,816 available bytes vs. 128,849,018,880 required). The transport artifact currently records 1,197 requests: no proxy exceptions, but 16 HTTP 4xx responses remain unclassified, so this is not yet a zero-error result. Closeout remains blocked by push tails (five of ten 500-push windows miss the 1-second p95 target), clone throughput and missing matched-v1 comparison, completion of the 100-GiB Xet/history run, v2 add-time cross-repository chunk discovery parity, live crash/GC and eventual historical-restore qualification, hosted provider/platform and shipped-product parity, and green final-head CI. The request-count change closes none of those gates. Keep v1 supported; do not mark the capsule design or implementation complete yet. Design/gate inventory: layered-pack closeout and Xorb/shard parity. |
Current-head update: guarded push visibility reuseCurrent PR head: This commit narrows one incremental-push path: for a verified, non-force, single-ref fast-forward whose incoming pack proves the new tip and excludes only the old tip, visibility uses the exact verified pack-member set instead of repeating a graph walk. Force pushes, multiple ref edits, uncertain ancestry, excluded/sibling refs, and oversized visibility sets retain the existing graph-walk path. The focused capsule-push suite passed (14 tests); Current-head CI run The retained 100-GiB RustFS run is not current-head proof: its frozen Crab source revision is Closeout decisionThe capsule design and implementation are not complete or ready to retire v1. The prior 5,000-push replay passed content correctness, but five of ten windows missed the sub-second push-p95 gate; this new optimization has only focused-test proof and needs a current-head replay plus a matched v1 comparison. The 500-commit fetch result remains accepted: 8.581-second p95 and 27 requests, with request count diagnostic rather than a gate. Still open are a successful current-head 100-GiB Xet/history run with classified transport responses, general add-time partial-overlap dedup parity, the live crash/concurrency/GC and eventual-restore matrix, and complete provider/platform/product parity. The design inventories in |
|
Exact-head qualification closeout update (behavior HEAD
Do not conclude the design or retire v1: the push window, instrumentation gap, final integrity checks, few-second clone goal, 100 GiB Xet, matched v1, provider/product parity, and recovery/concurrency/GC qualification remain open. |
Closeout decision: still not completeAgreed: the 27 object-store requests on the 500-commit fetch are acceptable and diagnostic only. Fetch remains within the correctness/latency contract; request count is not a blocker. The capsule design/implementation still has material open gates on the current behavior head. The exact-head 5,000-commit run completed all pushes and exact-tip fetch checkpoints, but one 500-push window missed the 1 s p95 target (1.144 s; maximum push 9.731 s), and per-push request telemetry was not measured. Full clones took 19.3/15.7 s and strict Git fsck took about 2 minutes. The blobless clone command exited successfully, but the harness stopped on a telemetry-only assertion before proving omitted-blob/lazy-hydration behavior and before final source/sample and Crab fsck checks. This is incomplete qualification, not a correctness pass. CI for documentation head The design doc records the evidence and acceptance inventory: capsule layered-pack status. Keep v1 supported; do not mark v2 release-qualified or retire v1 yet. |
Summary
Qualification status
This PR is not release-qualified. Provider/product parity, full crash/recovery and maintenance coverage, the zero-error 100 GiB Xet run, push-tail and clone targets, and matched v1 performance remain open. Keep v1 supported until correctness, parity, and matched-or-better performance are demonstrated.
Evidence: