perf: reduce durable transaction round trips - #14
Merged
Merged
Conversation
forhappy
force-pushed
the
codex/release-perf-diagnostics
branch
from
September 29, 2026 16:24
a1fc2c9 to
41cf917
Compare
Open a bounded opt-in follower store on the private mTLS listener and enforce directory authority before append, retire, seal, or tail operations. Keep admission held through detached durable work after HTTP timeout. Record a fresh signed release fixture showing the historical peak rates remain unreproduced.
Implement bounded mTLS append, seal, retire, and tail transport for Cellule node logs with a short live-advertisement cache. Add a host durability provider adapter, but leave it disconnected from serving until successor recovery is proven. Exercise a real two-identity append and persisted follower reopen.
Allow a claimant to seal and page its own persistent follower lane only after directory recovery authorization and a live lease check. Exercise an expired-leader claim through Cellule bounded witness gathering, while keeping serving follower proofs disabled.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
This PR reduces round trips in BeyondDB's signed DynamoDB path, adds bounded background index projection, and advances Cellule follower-log recovery wiring. The latest commit also retries transient startup recovery after a fenced takeover. It keeps ExtendDB responsible for HTTP, SigV4, IAM, and DynamoDB semantics and Cellule responsible for durable Cell execution.
Follower-backed commit proof is not enabled in the serving binary. Writes still wait for object-store publication. The all-API goal of exceeding pinned ExtendDB SQLite remains open.
Cellule
origin/mainrefresh and full release rerunCellule is pinned to
9e17746a633ca1046bd93866866074226091f81ain the manifest and lockfile. The release binary built; formatting, strict all-target Clippy, and all 17 library tests passed. A signed boto3 PutItem of a 1 KiB item survived an unclean serving-process restart on the new release fixture.The latest complete 24-case report and raw JSON compare the new release with pinned ExtendDB SQLite. Both finished all cases with zero foreground request errors. At eight clients, BeyondDB/SQLite measured 235/507 GetItem, 78/55 PutItem, 4.18/473 TransactGetItems, and 1.50/131 TransactWriteItems requests/s. BeyondDB also logged deferred capacity sweeps and participant resolution. Host load changed from 47.5 to 30.3 during BeyondDB and ended at 37.3 after SQLite on 12 logical CPUs; these rates do not establish a controlled speed ratio. The all-API performance objective is not met.
An earlier attempt with the same pin stopped at eight-client TransactGetItems after a throttling cancellation under heavier load. A local larger signed SDK restart attempt failed with HTTP 503 during GSI setup when host load approached 100. GitHub Actions then passed all seven
server_binarytests on the new Cellule pin, including unclean restart and 70-shard process-loss coverage. Thepeer_networktarget passed 46 of 48 tests; two failures remain under investigation:sdk_creation_recovery_tolerates_concurrent_delete(placement capacity) andsigned_sdk_request_routes_across_two_owners_and_survives_restart(large transaction read received HTTP 503). Test-only peer-route diagnostics are now on this branch for the next CI run.Earlier full release comparison
The pre-Cellule-update full 24-case report and raw JSON compare a release BeyondDB binary from the pre-retry working tree with pinned ExtendDB SQLite
7eaa89b. Both used signed boto3, 1 KiB items, five-second cases, one and eight clients, and zero foreground SDK errors. At eight clients:The host had one-minute load of roughly 22–27 on 12 logical CPUs. These sequential short runs are diagnostic and do not establish a stable speed ratio or production capacity. BeyondDB logged one deferred transaction recovery pass. The index batching change targets background GSI maintenance; the benchmark workload did not create or query a GSI. The earlier recovery-wiring rerun is also included. Historical peak rates in this PR were not reproduced by current release fixtures.
Verification
cargo fmt --all -- --check, strict locked all-target Clippy, and all 17 library tests passed on the pushed source tree.server_binarytests, including signed SDK 70-shard process-loss and unclean restart coverage.elastic_cellspassed 46 tests.peer_networkpassed 46 of 48; the two named failures above remain open.peer_networktests and full green GitHub Actions qualification are remaining PR gates.Remaining work
Durable writes and cross-Cell transactions are still much slower than local SQLite. Enabling follower acknowledgments requires a proven multi-node crash-after-acknowledged-SDK-write path and safe successor replay. Do not infer fleet-scale capacity from these local fixtures. More detailed benchmarks, bottleneck analysis, and qualification limits are in performance documentation and follower durability design.