perf(storage): retire staged input at shaping boundaries with crash-safe resume (#1418) - #1519
Conversation
…afe resume (#1418) Sealing cadence: the shape routing loop seals every open partition spill into a boundary-named segment set once the group's routed input crosses open_spills x 255 KiB (the #1442 fsync budget), installs a chained shape-progress control, and only then unlinks that group's staged inputs. Staged residency falls from the whole run to one boundary group. The boundary control is installed before any unlink and proven against the chunk receipts' identity-record count, so an interrupted retirement can neither strand routed data behind missing inputs nor lie forward. Resume: an interrupted shape rebuilds its partitioners from the claimed sealed segments and the chain's exact routing balance, replays the recorded splitters, and continues routing at the boundary. Claimed segments are authenticated at the resume boundary and retained until supersession; unclaimed segments are authenticated and discarded. Boundary-less shapes keep the single-pass finish-unlink behavior.
Peak-probe receipts and README for S17/S18 before/after on the same host, inputs and #1393 instrumentation: staged chunks at the peak instant fall 186.38 -> 0.00 B/edge at both scales; the rung peak shifts to the later per-edge-constant encode/publish phases (total peak -0.8..-1.2% at these scales); live staged ceiling saturates at ~4.3 GB for S22+.
|
Important Review skippedAuto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: Repository: CurateLabs/graphforge/.coderabbit.yaml Review profile: CHILL Plan: Advanced Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Warning Billing warning: we have not been able to collect payment for this subscription for more than 72 hours. Please update the payment method or pay any pending invoices in Billing to avoid service interruption. Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Closes #1418 · part of #1387 · blocks toward #1194 / #900 / #745
What
Shaping held every staged chunk on disk until the whole shape completed, even though nothing reads a chunk again once its records are routed — 186.38 B/edge, 34% of the S22 transient peak, resident for 94% of the run (#1393). The routing loop now works in sealing boundaries:
open_spills × 255 KiB(the perf(storage): one fsync per 255 KB written, because the cache-release window is divided by stream count #1442 bytes-per-fsync budget — one fsync per open spill per seal), every open partition spill seals into a boundary-named segment set (part-<family>-g<boundary>-p<NNNNN>.run/.arrow);shape-progress-<boundary>.jsoncontrol is installed — chained by body digest, append-only per boundary;retire_payloadledger accounting.Staged residency falls from the whole run to at most one boundary group (saturating at ~4.3 GB for S22+, per the cadence arithmetic).
Crash safety (the acceptance that matters)
retired_through.Measured (same host/inputs/probe as #1393, before =
main@ab1a713e):The rung peak now sets in the later encode/publish phases (per-edge-constant); the admission-relevant staged ceiling saturates at ~4.3 GB for S22+ (projection in the evidence README; S22/S26 confirmation stays with #900/#745). Receipts:
docs/development/evidence/staged-retirement-1418/.Tests
shape.after_group_sealandshape.after_group_retire: reopen → resume → complete → publish; ledger (storage_current) equals a clean run;current_merge_temporaryreturns to 0; progress controls are cleaned at supersession.cargo test --workspace4,942 passed / 0 failed (durable tests under TMPDIR on ext4), Bazel//:ci_rust_tests108/108 locally,cargo clippy --workspace -- -D warningsclean,cargo fmtclean,make pre-push-fastgreen.Non-goals respected
No S24/S25/S26 execution, no new certification workflow, backward compatibility untouched (pre-v1.0.0 maintainer scope), and no change to the segment spill grammar's classification (
Unclassifiedstays 0 — asserted by the transient-composition test).Need help on this PR? Tag
@codesmith-botwith what you need. Autofix is disabled.