You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Plan of record and close gate for the ingest-throughput workstream. #1387 owns the floor; #1456 owned the construction foundation beneath it. This issue closes only after #1387's acceptance outcomes are met. #735 remains M5's canonical closing tracker; this plan does not close the milestone.
History. Revisions 10–14 (measured rung tables, the rev 12–14 corrections, research routing, evidence index) are archived verbatim in docs/development/evidence/ingest-floor-plan-1478-rev14.md. GitHub keeps this body's edit history. Nothing in the archive is maintained; the decisions and cautions below are what carried forward.
How this plan stays current
This body owns the strategy, decisions and ordering rationale. GitHub owns execution state: the task list below renders each issue's live open/closed state, and each issue's native sub-issue and Blocked by / Blocking panels carry the prerequisites. Do not mirror status, counts, current main or queue contents here. Edit this body only when the order of operations changes or a finding changes a decision, budget, contract or closure criterion; record the change as a dated line under Revision log.
The floor
#1387: 1,000,000 edges per second, sustained at every supported scale, maintainer-confirmed 2026-09-18. It is one falsifiable number: any eligible complete ingest below it fails. The tested deadline is
T_complete_ingest(E) <= E / 1,000,000
which allows 4.19 s at S18 and 67.1 s at S22. Complete ingest includes registration, normalization, validation, identity resolution, construction, authentication, publication and acknowledgement; moving work between stages or behind verify does not change the boundary. S26 admission is a release claim about a billion-edge round trip and does not close the epic.
Decisions in force
#
Decision (maintainer, 2026-09-19 unless noted)
What it forbids
D1
The direct floor is the acceptance gate. Resource figures (≤1.6 KB device I/O per edge, ingest-scoped; S18 begin + resume + publish ≤0.84 s; wall exponent ≤1.02) are policy allocations and diagnostics, judged by matched-boundary measurement W/E = (C/E)/(C/W).
Any CPU-per-edge ceiling derived from an N-process probe (the ≤3.54 µs derivation is withdrawn); treating effective cores below one as a measured serial fraction; achieved rates as capacities; logical bytes as device bytes.
D2
Bytes and work removal run ahead of and alongside structural experiments; overlap is tried before decomposition.
Building a pipeline to hide measured preparation work (F5 no-go: ≤1.06× bound).
D3
The encode seam was viable and a performance no-go (#1496).
Inferring engine migration or a shaping experiment from the seam result.
D4
Reusable phase/region attribution in stock release output (#1477, landed).
Test-only scopes as the measurement instrument.
D5
Regression ratchets coexist with the unmet 1M gate (#1476).
Retiring the requirement by rewording; ratchets that stop tracking as performance improves.
R14
Continuation rule (2026-09-21). After each landed repair, recompute the remaining gap from a complete-ingest measurement on the integrated tree before starting or continuing structural work. Structural A/Bs run against a frozen baseline SHA under the owning issue's predeclared gate. Shaping alone is bounded below 1.92× (48% of validate).
Scoping #1448 as a floor-closing change; adopting the explicit-exchange, owned-artifact pipeline (a #1509 hypothesis row) as a second roadmap.
R14
Retention rule (2026-09-21). Ladder evidence is archived under #1530 before it is reported; issue text carries every number a decision rests on.
Citing scratch paths as evidence (the ladder root was deleted on 2026-09-21; the only S24 rung is gone).
Baseline of record
Retained evidence (#1530 / PR #1534). The archive index distinguishes complete rung evidence from surviving controller summaries. The b6ffb088 baseline retains S18–S22 rung/result JSON, receipts, plan, projection and controller summary; its MANIFEST.sha256 digest is 807609f97477e91c3cb5321261a4e9274f51573c150da88b320baf3b55c8342d. These links pin the merged archive commit from #1534. Historical raw evidence for 93c041df, f80f69fe (including S24), 1955f17d, ab1a713e, 4fbfe84c and 403fc02a was lost on 2026-09-21. Retained controller summaries support only their reported values; other historical numbers rest on the copied issue tables and comments, not missing per-operation receipts or publication-region data. The archived rev14 §12 is historical; this retained index is the current evidence location.
The integrated baseline is b6ffb088 (2026-09-21, quiet host, stock release, one S18–S22 ladder on a tree containing #1452, #1519 and the #1526 fix). S18 32.3 s / 129,975 edges/s; S19 63.1 s / 132,986; S20 128.8 s / 130,240; S22 532.2 s / 126,099 edges/s, 0.87 authority cores. The floor gap at S22 is 7.93×. Per-operation cpu_ns and publication regions were archived before this number was reported. The prior ab1a713e summary (S22 432.7 s, 155,093 edges/s, 0.99 cores) has no receipts. Historical rows (93c041df S22 593.1 s; f80f69fe S24 2,754.0 s) stay in the archive.
Work order
Each item is a native issue reference; GitHub shows its state. Prerequisites are the issues' own Blocked by panels. Ordering rationale is in the right column and changes only by editing this body.
perf(storage): make one complete ingest scale with available cores #1448 — shaping over partitions: one hypothesis, frozen baseline SHA, ≥10% whole-ingest median at S18 and S20 with identical digests, no verification or contract changes. The largest lever that is not byte removal; cannot meet the floor alone.
Hardware last — one run on a defined reference host only after the per-resource budgets pass on OVHC-AGENCY. A 32-core box changes neither bytes per edge nor the S24 drift.
Conditional: any need for a process-wide admission manager, a manifest format or a publication-protocol change stops the experiment that found it and routes to #1509 for a separate decision. Reopen #1448's adoption before production if incremental import would need full adjacency reconstruction, a query-admission contract change (ADR 0026), or substantial discarded preparation after publication conflicts.
Cautions that must survive into any design
Worker count, execution partitions and durable partition layout are three different numbers; hash or round-robin repartitioning does not replace recorded UUID splitters.
Streaming does not eliminate blocking stages; sorts accumulate or spill.
Keep a separate total-memory admission budget; a framework pool accounts for registered consumers, not every flowing batch or writer buffer.
CPU work in async needs explicit admission and cooperative cancellation.
Retain GraphForge's filesystem authority; tokio::fs removes no fsync cost.
No two schedulers may each claim all cores; cap build jobs the same way.
Delivered speedup at N workers is not a pool size; size pools by measuring the stage.
Do not move work across the ingest boundary to move the metric; the lifecycle budget beside the rate prevents it.
N independent processes are not one parallel ingest.
Achieved rates are not capacities, and logical bytes are not device bytes; state demand and capacity in the same units or it is not an argument.
Do not take ratios from a small fixture; use rung-scale attribution.
Standards that do not move
TCK green (cargo test -p graphforge-api --test bdd) · G500 S26 admits and completes · GDC suites green · every feature retained · fail-closed publication · no silently accepted corruption · the open-time content sweep is not tradeable. Spendable: recoverability-without-restart, eager verification whose refusal is duplicated at a consuming boundary, in-memory representations and buffer sizes, process boundaries and phase counts, constants priced for other hardware, wire formats with a version bump and the determinism suite green, byte-identical intermediates (ADR 0038).
Reversibility
Byte cuts, resource-policy unpinning, the encode seam and the contention characterization are two-way doors. Replacing sort/spill/memory accounting with DataFusion in shaping is one-way in practice and carries the heaviest gate (#1509).
rev 15, 2026-09-21 — focused rewrite; revisions 10–14 archived to the repo; work order converted to native issue references; R14 continuation and retention rules carried forward. No D1–D5 change.
Ingest floor plan — the #1387 floor, per resource
Plan of record and close gate for the ingest-throughput workstream. #1387 owns the floor; #1456 owned the construction foundation beneath it. This issue closes only after #1387's acceptance outcomes are met. #735 remains M5's canonical closing tracker; this plan does not close the milestone.
History. Revisions 10–14 (measured rung tables, the rev 12–14 corrections, research routing, evidence index) are archived verbatim in
docs/development/evidence/ingest-floor-plan-1478-rev14.md. GitHub keeps this body's edit history. Nothing in the archive is maintained; the decisions and cautions below are what carried forward.How this plan stays current
This body owns the strategy, decisions and ordering rationale. GitHub owns execution state: the task list below renders each issue's live open/closed state, and each issue's native sub-issue and Blocked by / Blocking panels carry the prerequisites. Do not mirror status, counts, current
mainor queue contents here. Edit this body only when the order of operations changes or a finding changes a decision, budget, contract or closure criterion; record the change as a dated line under Revision log.The floor
#1387: 1,000,000 edges per second, sustained at every supported scale, maintainer-confirmed 2026-09-18. It is one falsifiable number: any eligible complete ingest below it fails. The tested deadline is
which allows 4.19 s at S18 and 67.1 s at S22. Complete ingest includes registration, normalization, validation, identity resolution, construction, authentication, publication and acknowledgement; moving work between stages or behind
verifydoes not change the boundary. S26 admission is a release claim about a billion-edge round trip and does not close the epic.Decisions in force
W/E = (C/E)/(C/W).Baseline of record
Retained evidence (#1530 / PR #1534). The archive index distinguishes complete rung evidence from surviving controller summaries. The b6ffb088 baseline retains S18–S22 rung/result JSON, receipts, plan, projection and controller summary; its
MANIFEST.sha256digest is807609f97477e91c3cb5321261a4e9274f51573c150da88b320baf3b55c8342d. These links pin the merged archive commit from #1534. Historical raw evidence for93c041df,f80f69fe(including S24),1955f17d,ab1a713e,4fbfe84cand403fc02awas lost on 2026-09-21. Retained controller summaries support only their reported values; other historical numbers rest on the copied issue tables and comments, not missing per-operation receipts or publication-region data. The archived rev14 §12 is historical; this retained index is the current evidence location.The integrated baseline is
b6ffb088(2026-09-21, quiet host, stock release, one S18–S22 ladder on a tree containing #1452, #1519 and the #1526 fix). S18 32.3 s / 129,975 edges/s; S19 63.1 s / 132,986; S20 128.8 s / 130,240; S22 532.2 s / 126,099 edges/s, 0.87 authority cores. The floor gap at S22 is 7.93×. Per-operationcpu_nsand publication regions were archived before this number was reported. The priorab1a713esummary (S22 432.7 s, 155,093 edges/s, 0.99 cores) has no receipts. Historical rows (93c041dfS22 593.1 s;f80f69feS24 2,754.0 s) stay in the archive.Work order
Each item is a native issue reference; GitHub shows its state. Prerequisites are the issues' own Blocked by panels. Ordering rationale is in the right column and changes only by editing this body.
mainSHA containing perf(storage): sealing one spill costs eight durability barriers, serialised on the directory inode #1452, perf(storage): retire staged input at shaping boundaries with crash-safe resume (#1418) #1519 and the fix(storage): S22 construction fails "control record exceeds bound" because the shape-end checkpoint ledger holds one entry per sealed segment (#1519) #1526 fix, stock release, per-operationcpu_nsand observe(storage): decompose publication into named regions in stock receipts (#1481) #1512 publication regions, ingest-scoped device bytes and sync counts where the instruments exist. Archived before it is reported. Every later step scopes from this, not from the archive.Conditional: any need for a process-wide admission manager, a manifest format or a publication-protocol change stops the experiment that found it and routes to #1509 for a separate decision. Reopen #1448's adoption before production if incremental import would need full adjacency reconstruction, a query-admission contract change (ADR 0026), or substantial discarded preparation after publication conflicts.
Cautions that must survive into any design
tokio::fsremoves no fsync cost.Standards that do not move
TCK green (
cargo test -p graphforge-api --test bdd) · G500 S26 admits and completes · GDC suites green · every feature retained · fail-closed publication · no silently accepted corruption · the open-time content sweep is not tradeable. Spendable: recoverability-without-restart, eager verification whose refusal is duplicated at a consuming boundary, in-memory representations and buffer sizes, process boundaries and phase counts, constants priced for other hardware, wire formats with a version bump and the determinism suite green, byte-identical intermediates (ADR 0038).Reversibility
Byte cuts, resource-policy unpinning, the encode seam and the contention characterization are two-way doors. Replacing sort/spill/memory accounting with DataFusion in shaping is one-way in practice and carries the heaviest gate (#1509).
Live views
#1387 floor · #1456 foundation · #1194 storage bytes · #1504 reuse evaluation · #1388 query workstream · #735 M5 · open PRs
Revision log
docs/development/evidence/ladder/instead of the deleted ladder root. No D1–D5 change.b6ffb088S18–S22 ladder (S22 126,099 edges/s, 7.93× gap). perf(bench): make the ingest gates two-sided so improvements ratchet automatically (#1387 D1/D5) #1476 checked on close. No D1–D5 change.perf statrefuted rev 11's byte and scaling premises; D1–D5 ruled.