PERF: narrow durable Index writes without weakening Security state (#824) #853

Open
opened 2026-10-02 14:43:49 +00:00 by kayg · 1 comment
Owner

Follow-up from #824/#823. The shared Index now uses FULL so acknowledged Security state survives power loss. Keep that guarantee. Do not revert the writer to NORMAL without a complete authority durability boundary.

Evidence: release binaries built on the build host; SQLite 3.51.3; perf VM under /root/perf.lock for each complete run; ext4 direct-I/O HDD emulation with 8 ms read/write delay and 200 IOPS. 100k synthetic 1 KiB rows in 100-row transactions, 1,000 changed authority-row mutations, then a 32-request burst. Before uses the audited c4a61e8cf opener (NORMAL/default checkpoints); after uses 819457f0b (FULL/background PASSIVE). Integration at 466d3baa8 changed no database source.

Metric Before After
Authority p50 ms 0.179 54.897
Authority p95 ms 0.363 103.992
Authority max ms 391.877 578.404
Ingest p95 ms 0.870 110.972
Ingest max ms 1077.680 636.519
Burst p95 ms 4.151 1894.848
Probe seconds 20.178 141.508
CPU user + system seconds 0.88 1.62
Peak RSS KiB 8132 8700

Load at start: before 0.08/0.73/0.66; after 0.00/0.03/0.24. All sampled mutations succeeded. Before is not power-loss durable; the fast number is not a correct Security state target. docs/perf/baseline.json has no matching SQLite profile. The same-profile latency increases exceed the project's 10% latency comparison threshold. Peak RSS is about +7%, below the 15% threshold. No financial data or User data was used.

The shared writer also commits Derived data. That data does not need the same power-loss guarantee, but the exposed pool cannot temporarily downgrade safely without auditing every authority write and cancellation path. The narrowest safe change in #824 was therefore FULL for this shared Index.

Next: establish a cancellation-safe boundary that keeps every authority commit durable while allowing bounded Derived data batches to retain speed. Include accounts, credentials, sessions, Roles, Shares, permissions, Plugin enablement and queued authority receipts; Auth-only coverage is insufficient. A separate Security state Index or a typed sole-writer lease is a design choice, not assumed here. Re-run bench/sqlite-wal.sh and the sync-image negative/positive/failure controls. Keep background checkpoints off the interactive commit path. Active-WAL limits remain on #823.

Performance is not a merge gate. No weakening of Security state durability is authorized by this finding.

Follow-up from #824/#823. The shared Index now uses FULL so acknowledged Security state survives power loss. Keep that guarantee. Do not revert the writer to NORMAL without a complete authority durability boundary. Evidence: release binaries built on the build host; SQLite 3.51.3; perf VM under `/root/perf.lock` for each complete run; ext4 direct-I/O HDD emulation with 8 ms read/write delay and 200 IOPS. 100k synthetic 1 KiB rows in 100-row transactions, 1,000 changed authority-row mutations, then a 32-request burst. Before uses the audited c4a61e8cf opener (NORMAL/default checkpoints); after uses 819457f0b (FULL/background PASSIVE). Integration at 466d3baa8 changed no database source. | Metric | Before | After | | --- | ---: | ---: | | Authority p50 ms | 0.179 | 54.897 | | Authority p95 ms | 0.363 | 103.992 | | Authority max ms | 391.877 | 578.404 | | Ingest p95 ms | 0.870 | 110.972 | | Ingest max ms | 1077.680 | 636.519 | | Burst p95 ms | 4.151 | 1894.848 | | Probe seconds | 20.178 | 141.508 | | CPU user + system seconds | 0.88 | 1.62 | | Peak RSS KiB | 8132 | 8700 | Load at start: before 0.08/0.73/0.66; after 0.00/0.03/0.24. All sampled mutations succeeded. Before is not power-loss durable; the fast number is not a correct Security state target. docs/perf/baseline.json has no matching SQLite profile. The same-profile latency increases exceed the project's 10% latency comparison threshold. Peak RSS is about +7%, below the 15% threshold. No financial data or User data was used. The shared writer also commits Derived data. That data does not need the same power-loss guarantee, but the exposed pool cannot temporarily downgrade safely without auditing every authority write and cancellation path. The narrowest safe change in #824 was therefore FULL for this shared Index. Next: establish a cancellation-safe boundary that keeps every authority commit durable while allowing bounded Derived data batches to retain speed. Include accounts, credentials, sessions, Roles, Shares, permissions, Plugin enablement and queued authority receipts; Auth-only coverage is insufficient. A separate Security state Index or a typed sole-writer lease is a design choice, not assumed here. Re-run bench/sqlite-wal.sh and the sync-image negative/positive/failure controls. Keep background checkpoints off the interactive commit path. Active-WAL limits remain on #823. Performance is not a merge gate. No weakening of Security state durability is authorized by this finding.
Author
Owner

Round 2 status: partial at the four-hour job limit. Head 1b6c287040ada1741c867cf008905f5b8efdeb1f; full report and exact gate output on #824.

Ordinary HDD mutation p95 is 0.401852 ms, versus round 1 FULL 103.992 ms. Separate FULL authority p95 is 117.234803 ms. The real Auth fault checks passed again after the telemetry change. #855 records the +10.70% comparison with the older NORMAL sample and the load/workload differences.

This issue stays open: the Files, AI and production server authority adapters remain uncommitted. Files has its existing storm deadline failure, AI tests were not completed, and server gates did not run. The committed NORMAL opener must not be used without the pending authority wiring. No merge or push was performed by this job.

Round 2 status: partial at the four-hour job limit. Head `1b6c287040ada1741c867cf008905f5b8efdeb1f`; full report and exact gate output on #824. Ordinary HDD mutation p95 is 0.401852 ms, versus round 1 FULL 103.992 ms. Separate FULL authority p95 is 117.234803 ms. The real Auth fault checks passed again after the telemetry change. #855 records the +10.70% comparison with the older NORMAL sample and the load/workload differences. This issue stays open: the Files, AI and production server authority adapters remain uncommitted. Files has its existing storm deadline failure, AI tests were not completed, and server gates did not run. The committed NORMAL opener must not be used without the pending authority wiring. No merge or push was performed by this job.
Sign in to join this conversation.
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
kayg/calternal#853
No description provided.