Skip to content

perf(runtime): reduce forwarding admission and compaction publication latency - #39

Merged
forhappy merged 8 commits into
mainfrom
codex/serial-forwarding-p99
Oct 2, 2026
Merged

forhappy merged 8 commits into
mainfrom
codex/serial-forwarding-p99

Conversation

@forhappy

@forhappy forhappy commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Continue the forwarding latency follow-up deferred from #33 with two measured changes:

  • An empty ingress runtime uses its existing active/activating Cell ledger to avoid a negative dispatcher lookup. Nonempty runtimes retain actor admission. Activation reserves its charge before enqueueing and holds it through teardown; the shortcut preserves lease, shutdown and closed-dispatcher checks.
  • Foreground compaction can keep its representation-only root private and prepare the successor append against it. The final append publishes with one fenced CAS against the original authority root. Cascades that remain above the existing segment bound and full-image fallback retain their existing publication path. Immutable dependencies still upload and verify before acknowledgement; schema migrations use the same combined preparation path.
  • Partition the unchanged routing qualification into leased/object-only CI jobs. Each runs all four pairs against its isolated provider; the final routing check requires both jobs. The 90-minute limit, workloads and performance thresholds remain unchanged.
  • Preserve completed frozen comparisons when a new commit is pushed by queuing the next reference run.

Owner hints remain destination hints. Unleased requests retain one fresh authority read; zero-read admission remains restricted to a live node lease. Ambiguous commands reconcile rather than replay.

Diagnostic evidence

All three repeats of each frozen diagnostic binary recover exactly 768 acknowledged commands. Diagnostics use one actor, signed/authorized mTLS, real RustFS and balanced route ordering; they do not replace original qualification.

  • An ingress control isolates approximately 28 microseconds of extra serial query median latency from the negative dispatcher lookup. After the shortcut, the same-actor runtime-versus-bare-peer difference is approximately 2–4 microseconds.
  • Explicit compaction telemetry identifies 37 foreground compactions per 768 commands. The private-compaction trial retains that schedule. Median preparation time excluding compaction is approximately 6.1 ms, compared with 10.7–11.8 ms in the earlier diagnostic. Forwarded command p99 is 40.4/41.4/42.1 ms versus approximately 51 ms previously. These separate diagnostic runs support qualification; they are not a paired regression verdict.
  • Runs: ingress control, post-shortcut/compaction telemetry, private-compaction trial.

Correctness verification

  • Deterministic empty-ingress scheduling test observed failing before and passing afterward. Seven actor tests and 27 enabled client protocol/routing tests pass; two existing ignored tests remain unchanged.
  • Four publication tests pass, including schema migration under compaction pressure. Fresh authority remains unchanged during preparation and after a rejected successor; final publication advances the authority revision once.
  • Public LTX integration test passes: invalid proposals are refused, original predecessor is retained, the combined append produces the same immutable root as the existing two-step path, and exact SQLite recovery succeeds.
  • All 12 authored website guides compile. Format, crate boundaries, module layout, document links, Rust fences and SQL/peer contract validation pass.

Qualification status

Updated to origin/main at 0dc04a658bd99668936f7ec58032d054f6fbc141 (#40). Its try_update replacements and website compiler fix are adopted unchanged; the earlier overlapping compatibility annotations and compiler changes are absent from the PR diff. Current head: 33a34f4d50d9ffef8cc428251bd4db3fe0246cf6; CI merge snapshot: 292e4f0e08c9a5c5b3ead5532d2560b41465787b. Format, all 12 Python qualification unit tests, and isolated Rust 1.99 Clippy across the workspace/all targets/all features pass on this merged head.

The complete routing comparison on the prior candidate passes both modes and the required aggregate check. An independent raw-data audit confirms all four pairs per mode, 484,384 latency samples, 65,536 publication records, and 98,304 exactly recovered commands, with no performance-gate failures. Its frozen source is e44758e862d0851c15945bdf60dc5faf6d159931 (the merge snapshot for head 9ac9f8c), against baseline c51dd12.

That candidate also passes six capacity profiles with 37,598 acknowledged writes, and audited fleet scaling with 80 entity Cells, 11,866 entity writes, 267,624 successful reads and 1,500 mixed writes. Qualification contract, fuzz, MSRV and website checks pass. Its Rust run passed tests and documentation but failed the Rust 1.99 deprecation lint, now addressed by main's atomic rename.

The merged head passes Rust/MSRV, contract, fuzz, website, fleet smoke and both capacity modes. Focused publication tests also pass on the isolated merged source. Independently audited capacity evidence recovers 40,992 acknowledged writes across six runs. Fleet evidence verifies 80 entity Cells, 12,454 entity writes, 305,986 successful reads and 1,500 mixed writes, including constrained resource and exit proofs.

Current merge blocker: the complete routing comparison fails forwarded_command/c16 in both modes. The independent raw-data audit confirms all four pairs per mode, original workloads/nonoverlap, 484,384 latencies, 65,536 publication records and 98,304 exactly recovered commands. Leased candidate p95/p99 ratios are 1.140/1.244 (p99 472.275 → 587.597 ms); unleased ratios are 1.213/1.465 (p99 342.547 → 501.899 ms). Both exceed the unchanged 1.10 latency limit; throughput ratios 0.950/0.987 pass. The required aggregate routing check fails by design when either mode fails. These failures are not waived.

The raw phases show preparation and authority publication pauses in both versions, with approximately 79 fewer puts per 1,024 commands for the candidate. These observations do not establish a code-versus-environment cause. An identical frozen candidate binary control completed with the same original profiles, pairs and thresholds. Independent raw audit proves exactly equal source and executable hashes. It reports apparent leased forwarded_command/c1 p99 regression of 42.4% and local_command/c16 p99 regression of 83.9%, while object-only control passes. This establishes measurement/environment variability sufficient to trip the gate; it does not clear the failed PR comparison.

CPU separation is insufficient: the first identical control, second independent control, and matched candidate-versus-main all completed with performance gate failures. Independent audits verify every original profile, all four pairs, exact recovery, source/executable provenance, benchmark/provider CPU placement and real durable volumes without CPU quotas. The second identical control reports six apparent regressions across both modes despite exactly equal executables. The matched CPU trial fails leased paced local query p99 (1.345) and unleased serial forwarded command p99 (1.121). This diagnostic-only workflow is not integrated as a fix.

Two diagnostic experiments retain all original workloads and gates: background work tracing correlates wall-clock compaction/publication/request intervals with serialized windows, and independent paired provider control gives each fixture its own pinned RustFS process and durable volume. Provider assignments are balanced across AB/BA order. These experiments are underway; no causal conclusion or performance clearance is claimed. Merge readiness remains blocked.

Retained earlier evidence

The first candidate (empty-ingress shortcut alone) passes six capacity profiles (37,320 acknowledged writes) and constrained fleet scaling (80 entity Cells, 11,992 entity writes, 277,958 successful reads and 1,500 mixed writes), with independently audited raw evidence and resource/exit/recovery proofs. Its original routing comparison hit the 90-minute CI limit. All four leased pairs completed, but the full two-mode comparison did not. The completed leased partition reports local_command/c16 and local_query_expired_bursts/c16 failures; these are retained and are not waived. Fresh final-source qualification runs both complete modes in separate jobs.

The first Rust run passed workspace tests but exposed the website compiler issue now repaired in main (#40). The first qualification-contract run timed out in the existing reader-hint notification test; a focused local run and an unchanged-source CI rerun pass. The 2-second timeout and assertions remain unchanged. Final-source CI must pass again; the initial failure is retained.

Original thresholds, workloads, metadata-read counts, hop counts and exact-recovery requirements remain unchanged. Plans and raw evidence remain outside the repository. No diagnostic instrumentation or diagnostic-only workflow is included in this PR. Evidence is recovered under $HOME/.codex/evidence/cellule-serial-p99-20261001-5ca5 after the build-target evidence directory was removed externally.

@forhappy forhappy changed the title perf(runtime): avoid empty-ingress dispatcher hops before forwarding perf(runtime): reduce forwarding admission and compaction publication latency Oct 1, 2026
@forhappy
forhappy marked this pull request as ready for review October 1, 2026 18:05
@forhappy
forhappy merged commit fbfd84f into main Oct 2, 2026
10 of 15 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant