perf(runtime): reduce forwarding admission and compaction publication latency - #39
Merged
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Continue the forwarding latency follow-up deferred from #33 with two measured changes:
Owner hints remain destination hints. Unleased requests retain one fresh authority read; zero-read admission remains restricted to a live node lease. Ambiguous commands reconcile rather than replay.
Diagnostic evidence
All three repeats of each frozen diagnostic binary recover exactly 768 acknowledged commands. Diagnostics use one actor, signed/authorized mTLS, real RustFS and balanced route ordering; they do not replace original qualification.
Correctness verification
Qualification status
Updated to
origin/mainat0dc04a658bd99668936f7ec58032d054f6fbc141(#40). Itstry_updatereplacements and website compiler fix are adopted unchanged; the earlier overlapping compatibility annotations and compiler changes are absent from the PR diff. Current head:33a34f4d50d9ffef8cc428251bd4db3fe0246cf6; CI merge snapshot:292e4f0e08c9a5c5b3ead5532d2560b41465787b. Format, all 12 Python qualification unit tests, and isolated Rust 1.99 Clippy across the workspace/all targets/all features pass on this merged head.The complete routing comparison on the prior candidate passes both modes and the required aggregate check. An independent raw-data audit confirms all four pairs per mode, 484,384 latency samples, 65,536 publication records, and 98,304 exactly recovered commands, with no performance-gate failures. Its frozen source is
e44758e862d0851c15945bdf60dc5faf6d159931(the merge snapshot for head9ac9f8c), against baselinec51dd12.That candidate also passes six capacity profiles with 37,598 acknowledged writes, and audited fleet scaling with 80 entity Cells, 11,866 entity writes, 267,624 successful reads and 1,500 mixed writes. Qualification contract, fuzz, MSRV and website checks pass. Its Rust run passed tests and documentation but failed the Rust 1.99 deprecation lint, now addressed by main's atomic rename.
The merged head passes Rust/MSRV, contract, fuzz, website, fleet smoke and both capacity modes. Focused publication tests also pass on the isolated merged source. Independently audited capacity evidence recovers 40,992 acknowledged writes across six runs. Fleet evidence verifies 80 entity Cells, 12,454 entity writes, 305,986 successful reads and 1,500 mixed writes, including constrained resource and exit proofs.
Current merge blocker: the complete routing comparison fails
forwarded_command/c16in both modes. The independent raw-data audit confirms all four pairs per mode, original workloads/nonoverlap, 484,384 latencies, 65,536 publication records and 98,304 exactly recovered commands. Leased candidate p95/p99 ratios are 1.140/1.244 (p99 472.275 → 587.597 ms); unleased ratios are 1.213/1.465 (p99 342.547 → 501.899 ms). Both exceed the unchanged 1.10 latency limit; throughput ratios 0.950/0.987 pass. The required aggregate routing check fails by design when either mode fails. These failures are not waived.The raw phases show preparation and authority publication pauses in both versions, with approximately 79 fewer puts per 1,024 commands for the candidate. These observations do not establish a code-versus-environment cause. An identical frozen candidate binary control completed with the same original profiles, pairs and thresholds. Independent raw audit proves exactly equal source and executable hashes. It reports apparent leased
forwarded_command/c1p99 regression of 42.4% andlocal_command/c16p99 regression of 83.9%, while object-only control passes. This establishes measurement/environment variability sufficient to trip the gate; it does not clear the failed PR comparison.CPU separation is insufficient: the first identical control, second independent control, and matched candidate-versus-main all completed with performance gate failures. Independent audits verify every original profile, all four pairs, exact recovery, source/executable provenance, benchmark/provider CPU placement and real durable volumes without CPU quotas. The second identical control reports six apparent regressions across both modes despite exactly equal executables. The matched CPU trial fails leased paced local query p99 (1.345) and unleased serial forwarded command p99 (1.121). This diagnostic-only workflow is not integrated as a fix.
Two diagnostic experiments retain all original workloads and gates: background work tracing correlates wall-clock compaction/publication/request intervals with serialized windows, and independent paired provider control gives each fixture its own pinned RustFS process and durable volume. Provider assignments are balanced across AB/BA order. These experiments are underway; no causal conclusion or performance clearance is claimed. Merge readiness remains blocked.
Retained earlier evidence
The first candidate (empty-ingress shortcut alone) passes six capacity profiles (37,320 acknowledged writes) and constrained fleet scaling (80 entity Cells, 11,992 entity writes, 277,958 successful reads and 1,500 mixed writes), with independently audited raw evidence and resource/exit/recovery proofs. Its original routing comparison hit the 90-minute CI limit. All four leased pairs completed, but the full two-mode comparison did not. The completed leased partition reports
local_command/c16andlocal_query_expired_bursts/c16failures; these are retained and are not waived. Fresh final-source qualification runs both complete modes in separate jobs.The first Rust run passed workspace tests but exposed the website compiler issue now repaired in main (#40). The first qualification-contract run timed out in the existing reader-hint notification test; a focused local run and an unchanged-source CI rerun pass. The 2-second timeout and assertions remain unchanged. Final-source CI must pass again; the initial failure is retained.
Original thresholds, workloads, metadata-read counts, hop counts and exact-recovery requirements remain unchanged. Plans and raw evidence remain outside the repository. No diagnostic instrumentation or diagnostic-only workflow is included in this PR. Evidence is recovered under
$HOME/.codex/evidence/cellule-serial-p99-20261001-5ca5after the build-target evidence directory was removed externally.