Skip to content

Verify forwarded reads after owner loss - #26

Merged
forhappy merged 1 commit into
mainfrom
codex/owner-route-verification
Sep 30, 2026
Merged

forhappy merged 1 commit into
mainfrom
codex/owner-route-verification

Conversation

@forhappy

@forhappy forhappy commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Follow-up to merged PR #24. Add two regression checks for the metadata-free forwarded route:

  • A forwarding node makes no local metadata reads after the receiver drains, and a peer holding the old handle returns a not-started error instead of a stale read.
  • A query result computed before node-lease fencing cannot be returned after the lease is fenced.

Local verification

  • The complete serialized runtime suite passed, including 379 unit and 161 runtime integration tests. Environment-gated RustFS cases remained ignored.
  • Protocol suite: 18 passed. Peer HTTP suite: 18 passed, one manual benchmark ignored. Serialized ownership suite: 17 passed, two RustFS cases ignored.
  • Runtime Clippy, formatting, boundary and module-layout checks passed.
  • A focused probe reproduced the existing fenced-shutdown assertion's scheduling dependence: if fenced deactivation completes before shutdown starts, its unwaited error is discarded and shutdown returns success. The command still returned OutcomeUnknown(Fenced) and the authority root stayed at sequence zero. This PR does not change that existing contract or assertion.

Temporary benchmarks and raw logs are outside the repository. The initial join_all concurrency comparison was biased because the zero-delay baseline could finish one request before polling the next; its reported 1.1 ms versus 2.8 ms p95 cannot establish a concurrency regression. A corrected release-build harness synchronizes 16 independently scheduled callers to one arrival timestamp.

With a synthetic 2 ms object-read delay, the corrected full signed loopback peer + SQLite path reduced p95 from approximately 39 ms to 9 ms and lane completion time from 443–537 ms to 97–115 ms for 256 queries. Sender metadata body reads fell from three per query to zero. With zero delay, full-path results overlap and vary across pairs on the shared workstation; there is no demonstrated consistent latency or throughput gain in that condition. Production HTTP/provider p95 and sustained fleet throughput remain unmeasured.

@forhappy
forhappy merged commit ce6ae2b into main Sep 30, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant