Commit graph

403 commits

Author SHA1 Message Date
bf343045ab feat(porch-store): Idempotent middleware (Phase C, in progress)
- replays a stored response for a repeated Idempotency-Key: before()
  checks the key, after() stores status/body/content-type on a 2xx/3xx
- key is "idem:<header>:<value>", optionally plus a sha256 digest of
  method|path|body when include_body is set
- 409 while a key is in flight (stored within the last 10s), lazy TTL
  expiry on access, default 24h
- replay allowlists content-type only — never Set-Cookie or Date
- backed by IdempotencyKey from Phase A (519d411)

Written by a parallel session and committed here as-is because its
branch was consolidated away. NOT verified: it calls json.decode and
json.encode without a `use json` import, which every other example that
uses json has. Left unedited rather than fixed blind.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
(cherry picked from commit aee79264095eea3b2c38c92789c44b31f1c9ef8a)
2026-09-15 01:15:30 +02:00
b21cfde1bf docs(commit-history): record the branch consolidation
- porch-store and query-corpus prefixes registered; both replayed onto
  dev, so dev is a superset of porch-store-middleware
- three branches could not be replayed and are preserved as annotated
  tags rather than merged or discarded:
  - cleanup/pre-existing-changes carries crates/ + Cargo.toml, the Rust
    runtime master deleted; replaying it would resurrect it
  - ipc-attach refactors wo_row_insert/wo_row_update_field into
    encoded cores, which db2-keys rewrote for keys-residency — two
    overlapping refactors of one function
  - keypair-auth builds on ipc-attach, blocked by the same overlap
- names the specific hazard: 9c transfers ownership of vals on failure,
  dev's keys-resident arm returns early without freeing, so a merge
  that compiles and passes could still leak or double-free

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
(cherry picked from commit bc8fec01d565d0ad54696fb3d2f85a9d1e0531a1)
2026-09-15 01:15:30 +02:00
5941a092f7 feat(query-corpus): iteration 9g corpus #1 — skillhost needs no new query grammar
- resolved 9g's forks EMPIRICALLY against the running compiler:
  - count(<query>) and len(<query>) already work (fork 2 collapses to
    zero code)
  - skillhost's correlated NOT EXISTS is a backlink emptiness in
    writeonce (`where len(x.children) == 0`), using only 9b machinery
    (fork 1) — verified on a self-referential ?ref/backlink table
  => corpus #1 forces NO new grammar; per the method ("add only what a
     corpus uses"), exists/not-exists was NOT built
- docs/examples/skill-catalog: mirrors skillhost's `skills` table
  (name @unique, description/location/root, parent ?ref Skill, children
  backlink) and translates all five of its SQL statements 1:1
  (insert+dup-trap, get-by-name, list, roots via backlink-emptiness,
  count); scripts/skill-catalog-accept.sh 7/0, WAL-durable, dup trap
  persists across restart
- fixture run/db-query-corpus (count(query) + backlink NOT EXISTS);
  just skill-catalog module; target/ gitignored
- general exists/not-exists left unbuilt and recorded as "enters when a
  corpus forces a non-relation correlation"
- gates: oop-e2e 80/0, woc-test 566/0, skill-catalog 7/0; story + board
  record the finding

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
(cherry picked from commit 4c82461634d45f11eca1a252702031c03d999c7f)
2026-09-15 01:15:30 +02:00
e159b5a754 feat(porch-store): Limiter middleware (Phase B)
(cherry picked from commit 5b1e82ab4bf3bad39bb6762a52b2dfaafd18a110)
2026-09-15 01:15:30 +02:00
192d451f5e feat(porch-store): store tables for rate limit + idempotency (Phase A)
(cherry picked from commit 519d4117fd0d6d0bd7d51f80bcb20de4d6294503)
2026-09-15 01:15:30 +02:00
4f6dc2dcfc docs(commit-history): record the lang42 cherry-pick
- registry: lang42 on master 2026-09-01
- pick row: 8 commits mapped dev -> master, zero conflicts
- verified on master after full rebuild: 38 runtime suites 0 fail both
  flavors (test_proc 128/0, test_wal 5966/0), woc-test 557/0 forced,
  subprocess-accept 12/0, site-accept 23/0

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-09-01 22:27:02 +02:00
b17b848403 docs(lang42): close out iteration 42
- story frontmatter status: done, Progress section records what landed
  vs the spec (everything, same day as the brainstorm)
- board: NEXT PLAN entry with the six standup answers (deadlock proven
  real: 5 s hang, 8192-byte truncation; 15 ms after; ping 2 ms during a
  parked child; 1000 spawns fd-flat; SIGTERM leaves no child); pending
  row flipped to DONE
- graph: node 42 class done, same change as the board row
- runtime/src/CODE-LOGIC.md: the bounded-subprocess section (bundle
  park, slot registry, ownership sweeps, raw pidfd syscalls)
- full belt at close: 19 runtime suites 0 fail (test_proc 128/0),
  woc-test 557/0, subprocess-accept 12/0, site-accept 23/0

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-09-01 22:19:25 +02:00
c91027bcc6 feat(lang42): subprocess example + gate
- docs/examples/subprocess: line-oriented TCP service, one Handler actor
  per request — ping/run/slow/deadline/cap/long exercise the whole
  bounded surface from .wo, traps caught with try/catch in the language
- scripts/subprocess-accept.sh + `just subprocess`: 12 checks, 0 failures
  first run — deadline and cap messages verbatim, ping answered in 2 ms
  while a sleep-2 child was parked, SIGTERM exit 0 with the sleep-30
  child verifiably gone (pid checked from outside)
- service logs to /tmp/subprocess.log, banner-separated per run

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-09-01 22:19:25 +02:00
baede5c373 feat(lang42): proc.run_dl — deadline and caps at the call site
- one stdlib_members row (arity 5, id 96, nullable Proc return, Proc
  record class appended) — the net _dl precedent verified: those rows
  needed no emit.ml change and neither does this one
- woc-test: 557 checks, 0 failures

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-09-01 22:19:25 +02:00
4180ee09d4 feat(lang42): ceiling, churn, unwind and stop legs
- ceiling: 32 fibers hold live sleepers; the 33rd spawn traps WO_T_IO
  naming the ceiling; destroy sweeps all 32 (waitpid -1 = ECHILD after)
- unwind: a fiber parked on a live child is reaped at main's return and
  the child dies with it (nchildren 0 straight after the call)
- churn: one thousand sequential `true` runs through a bytecode loop —
  fd count flat, every slot released
- stop: SIGTERM from a helper 200 ms into a sleep-10 child answers rc 1
  (STOPPED) with no surviving child
- test_proc 128 pass 0 fail in 2.6 s, suite ASan clean

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-09-01 22:19:25 +02:00
5d1c82bbd6 feat(lang42): deadline and output caps refuse by name, shard keeps scheduling
- proc.run_dl reachable: dispatch range extended to id 96 (builtin.c) and
  the loader arity table gains [WO_B_PROC_RUN_DL] = 6 — without both, the
  builtin answered "unknown stdlib builtin" (WO_T_EXPLICIT)
- deadline leg: sleep 10 vs 100 ms deadline traps WO_T_IO naming the
  deadline in ~120 ms; the pid is gone (waitpid -1 = ECHILD) and the fd
  count is flat; a worker fiber completes WHILE main is parked — the
  shard was never blocked
- cap legs: stdout and stderr caps trap naming "cap 1000", child dead
- argv multi carries a drop entry at the run pc: a trapping run frees it
  (LeakSanitizer caught the miss)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-09-01 22:19:25 +02:00
258222c3a1 feat(lang42): proc.run parks — pidfd + epoll bundle + child registry
- deadlock proven first: chatty child (200 KB stdout, stderr held open)
  hung the old sequential drain 5.0 s into the alarm, code -1, stdout
  truncated at 8192; the leg demands completion under 4 s
- rework: nonblocking pipe read ends + pidfd_open behind one epoll fd the
  fiber parks on (the _dl retry mould); both pipes drain on readiness, so
  the deadlock is gone structurally — leg passes in 15 ms
- wo_child slot table in wo_vm (32/shard) carries cross-park state; caps
  refuse by name (kill + WO_T_IO), deadline armed via dl_active/dl_at,
  defaults 30 s / 1 MiB / 64 KiB
- WO_B_PROC_RUN_DL = 96 shares the case (per-call deadline_ms/out_cap/
  err_cap; compiler row lands in a later task)
- fib_reap kills a reaped fiber's child; wo_vm_destroy sweeps the table
- raw syscalls for pidfd_open/pidfd_send_signal: glibc 2.35 build floor
  has no wrappers
- all 19 suites green under ASan+UBSan

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-09-01 22:19:25 +02:00
b8d9f9f594 feat(lang42): pin proc.run's current contract in test_proc
- new suite runtime/test/test_proc.c (auto-globbed by the Makefile)
- three legs against today's behavior: echo exits 0 with exact stdout,
  false exits 1, a missing command answers 127 (the execvp convention)
- record fields copied out before the vm dies; ASan clean

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-09-01 22:19:25 +02:00
8bcd24969e docs(lang42): story, spec and plan for bounded subprocess
- claim the lang42 prefix; iteration 42 story (readiness: ready), approved
  spec, and the 11-task implementation plan
- board: pending row for 42; graph: node 42 with green edges (11, 24)
- graph: porch track section added (same sweep)
- parity studies that motivated 42: alacritty, tmux, zen-browser under
  docs/plan/exploration/ — staged path, gap lists, refused routes

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-09-01 22:19:25 +02:00
bed1167ca9 docs(commit-history): record the iteration-12 cherry-pick
- seven commits dev to master, zero conflicts: the six db2-migrate
  commits plus site-deploy, which the close-out edits and which had
  been dev-only
- verified on master after the pick: 36 suites 0 fail (test_wal
  5966/0), woc-test clean, residency-accept 14/0, site-accept 23/0

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-31 22:02:18 +02:00
4ad24d6381 docs(db2-migrate): close out iteration 12
- crash-before-rename test: a COMPLETE valid migrated temp beside the
  untouched original is discarded and the boot re-migrates — the
  sharpest point on the crash timeline, deterministic, no fault
  injection needed
- story: all six tasks done with commit hashes, all eight criteria met
  with the test that proves each, plus the three deviations from the
  plan and why (transcode over replay, lazy head, poison forces
  transcode)
- CODE-LOGIC: migration section; also corrected limitation 3, which
  still claimed unbounded hot-row chains — iteration 11 closed that
- status board row 12; deploy guide's rollback section gets its real
  answer (rolling back across a migration is a migration backwards:
  expect the refusal, restore the .bak)
- test_wal 5966 pass, 0 fail

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
(cherry picked from commit 4bb6ece2531e2123eb958c91d9bef4a6528eab3b)
2026-08-31 21:54:27 +02:00
27aecd3dc1 feat(db2-migrate): boot performs the migration, and refuses by name
- main.c builds the compiled schema (names out of the constant pool,
  which the database layer never sees), peeks the log head before
  replay, and diffs: match replays as-is, add/delete migrates through
  the transcode, poisons refuse naming class, field and what to do
- fixed en route: a poisoned class SKIPPED the identity check, so no
  transcode ran and replay greeted the shape mismatch with the generic
  "corruption" — the exact message this iteration exists to replace.
  A poison now forces the transcode, where it either bites with its
  text or passes harmlessly when the class has no records
- the schema head is written LAZILY, ahead of the first real record:
  an eager head broke the documented "durable: false writes ZERO
  bytes" contract by 75 bytes and the residency gate caught it
- end-to-end at the language level: fresh boot seeds, identity
  replays, +field migrates with "migrating `Note`: +flag" and reads 0,
  retype refuses naming `val`, and the refused log still boots the
  previous binary untouched
- gates: wovm-test all green (test_wal 5951/0), woc-test clean,
  residency-accept 14/0, site-accept 23/0

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
(cherry picked from commit b21943aa91152ebdcfc72bd4c9fba38730ab1c2f)
2026-08-31 21:54:27 +02:00
c6e158c6a1 feat(db2-migrate): the transcode — old log to new shape, record by record
- wo_wal_migrate rewrites the log without touching db state: no id
  maps, no indexes, no keys-resident logic — the new log replays
  through the machinery that already exists and is already tested
- cids remap by name, INCLUDING the ones embedded inside stored owned
  values (an owned value carries a cid on the wire); the embed closure
  guarantees every nested class is shape-unchanged, so only numbers
  move
- surviving fields go to their new slot, deleted fields' values are
  freed, added fields take the kind's zero value straight from
  enc_val(0)
- a delta on a deleted field is SPLICED out: an offset map (old record
  start -> new) rewrites every back pointer, and the dropped delta maps
  to its own target so later deltas step over it
- temp + fsync + rename, compaction's own crash discipline; a stale
  temp is discarded at start; a torn tail bounds the intact prefix
  exactly as replay does
- fixed en route: early `goto corrupt` jumped over initializers, so the
  handler freed uninitialized memory — declarations hoisted above the
  first jump
- six end-to-end tests: add, delete (ASan watches the freed Text),
  reorder with owned fixup, delta splice on a keys-resident chain,
  poison-bites-only-with-records, corrupt input
- test_wal 5951 pass, 0 fail

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
(cherry picked from commit b69092a99206e1dcdf6f2dcdb02146939b0564c6)
2026-08-31 21:54:27 +02:00
df09158b7f feat(db2-migrate): the boot diff — name-keyed, poisons instead of errors
- wo_schema_diff matches classes and fields by NAME, so declaration
  reordering is identity apart from the cid map — the silent
  cid-renumbering hole closes as a side effect
- owned-field references (fclass) compare by the NAME the number
  resolves to, never the number: a raw compare would false-poison
  retype on every pure reorder
- refusals are per-class POISONS carried in the plan, not diff errors:
  a poison bites only when a record of the class is met, so a retyped
  class with no stored rows never blocks a boot
- poison set: retype, same-shape delete+add (a disguised rename, one
  reading destroys a column), vanished class, storage-flag change, and
  the embed closure — any class whose old records carry values of a
  class whose shape changed, iterated to a fixpoint
- identity plans skip the rewrite entirely; a NEW class in the binary
  does not break identity (no records; the head refreshes at the next
  compaction)
- ten verdict tests; test_wal 5778 pass, 0 fail

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
(cherry picked from commit 63a063b822af381a10c2e599c58cf3455d9c5bf7)
2026-08-31 21:54:27 +02:00
f07295b3c0 feat(db2-migrate): WO_WAL_SCHEMA — the log states the shape that wrote it
- new record kind 5: class and field NAMES, kinds and the two
  encoding-relevant metadata words (field_class, field_elem), CRC-framed
  like every record. Index layout deliberately absent: indexes rebuild
  from rows at boot and never touch record bytes
- names are byte pointers, not constant-pool indices — the database
  layer never sees the module's consts, so the runtime resolves them
  once; a decoded schema owns a private copy of its bytes
- wo_wal_set_schema adopts the compiled schema; wo_wal_ensure_schema
  writes it as a fresh log's first record; compaction writes it at the
  head of every replacement, which is how a legacy log becomes
  self-describing without a migration step of its own
- apply_record skips it BEFORE reading cid/id (its class count would be
  misread as a cid and bounds-refused); replay does not count it
- schema unset = byte-for-byte today's behaviour: all 5700 prior
  assertions pass untouched; four new tests cover roundtrip, fresh-log
  head, legacy adoption via compaction, and absent/empty files
- test_wal 5743 pass, 0 fail

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
(cherry picked from commit ba8519fa5e39c6ed6a3504d39e5a372f8decd045)
2026-08-31 21:54:27 +02:00
1b6d633ed1 docs(db2-migrate): spec + story for schema migrations v1
- brainstorm settled: declarative and automatic at boot; v1 verbs are
  add and delete only; data/seed migrations deferred to v2
- added fields zero-fill by kind: the grammar has no field-default
  syntax and v1 refuses to grow compiler surface for it
- same-kind delete+add refuses as a disguised rename; retype and
  vanished classes refuse by name
- schema lives in the log itself: WO_WAL_SCHEMA head record, written by
  fresh-log open and compaction; name-keyed diff also closes the
  silent cid-renumbering hole
- story is iteration 12, board row added, db2-migrate prefix claimed

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
(cherry picked from commit 072e007b144ff6689b6ff920ea10665900c1a2ef)
2026-08-31 21:54:27 +02:00
552c129ce3 docs(site-deploy): redeploy runbook for writeonce.de
- new docs/guides/deploying-site.md: build, content refresh, systemd
  unit, post-deploy verification, rollback, and the gaps behind each
  workaround
- leads with the trap that costs the most: shipping a binary does NOT
  update chapters. seed_if_empty only fills an EMPTY table and
  AdminEdit answers not_found for an unknown slug, so a host with an
  existing WO_DATA shows the old chapter list with no error anywhere
- that claim is measured, not argued: a 9-chapter build seeded a data
  dir, then the 10-chapter binary against it still 404'd /ch/storage
  and rendered 9 nav entries; wiping WO_DATA gave 200 and 10
- records two more blockers found while writing it: both site deps
  (porch, writeonce-view) 404 on GitHub and wo.lock is untracked, so
  the site submodule cannot build standalone; and the embedded wovm
  sets the glibc floor (this machine: 2.38, above Ubuntu 22.04's 2.35)
- build recipe run verbatim before publishing; releasing.md points here

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
(cherry picked from commit 930a715c4a3d847529e3e341edc71c65a7e11d1c)
2026-08-31 21:54:27 +02:00
e31a037533 docs(commit-history): record the site-submodule cherry-pick
- 4b56348 -> 7d9d526, 4eead89 -> 653a91c
- the registry rows for lang41, porch-store and query-corpus came with
  the pick and are kept: the registry is a global claim ledger, so a
  copy that silently omits three claimed prefixes is worse than one
  that names them and says they are dev-only
- site-submodule row corrected on the way in — it said "Not picked to
  master", which this pick is precisely what falsifies
- verified on master after the pick: site-accept 23 checks, 0 failures

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-30 22:03:43 +02:00
653a91c702 docs(commit-history): register the site-submodule prefix
- records that docs/examples/site is now a submodule on dev only
- states the consequence plainly: master still carries the site inline,
  so the branches differ structurally at that path until this is
  cherry-picked

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
(cherry picked from commit 4eead8938c7292a130723aeabe7b74bdd1ba60f6)
2026-08-30 22:03:18 +02:00
7d9d526bb6 refactor(site-submodule): docs/examples/site becomes a submodule
- extracted to github.com/shoneyJ/writeonce-site with `git subtree
  split`, so the site keeps its own 9 commits of history rather than
  landing there as a flattened snapshot
- .gitmodules gains the third entry, alongside reference/writeonce-app
  and reference/writeonce-api; path is unchanged, so every doc and
  script that names docs/examples/site still resolves
- site-accept.sh fails early and says `git submodule update --init`
  when the directory is empty. Without it a clone lacking submodules
  copies an empty app and fails later as a build error naming nothing
- releasing.md: the steps that edit install/view.wo now say that edit
  is a commit in the site repo plus a pointer bump here — editing and
  committing only in this repo would record nothing
- gate re-run against the submodule: site-accept 23 checks, 0 failures

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
(cherry picked from commit 4b5634801d5379890bad24c8129cfb23ab6b98df)
2026-08-30 22:02:55 +02:00
e93284befb docs(commit-history): record the databasev2 residency cherry-pick
- first cherry-pick under this convention: 37 commits, dev to master,
  mapped one-to-one with titles
- iteration 11 could not travel alone — its commits touch
  wo_wal_fold_row_at, keys_fold_into and row_apply_field_keys, none of
  which existed on master, so the whole db2-keys/db2-delta stack came
- porch-store (26 commits) deliberately left on dev: porch 1 was
  re-scoped mid-flight, which is what "ready, not merely green" is for
- records the three docs conflicts and how each was resolved, including
  keeping only the databasev2 half of a status entry that would
  otherwise have had master claiming porch 1 was done
- records what is still outstanding: task 6's byte-budget refusal, a
  missing guard rather than an unhonoured annotation

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-30 20:45:39 +02:00
92d2600ae7 docs(commit-history): feature-to-cherry-pick reference
- records the workflow: develop on dev, feature prefix as the
  conventional-commit scope, cherry-pick onto master when ready
- prefix registry so two features cannot claim the same prefix; the
  prefix is claimed before the feature's first commit
- cherry-pick log maps dev hashes to the master hashes they produced —
  they differ, and that mapping is what makes a feature traceable or
  revertible as a unit after dev moves on
- notes the db2-keys seam: written pre-convention on
  porch-store-middleware, replayed onto dev, replay verified identical
- work before 2026-08-29 landed by merge; git log --merges covers it

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
(cherry picked from commit 41923eb1f9510ab53804ca8dc6fe30a9a7eac849)
2026-08-30 20:44:14 +02:00
aee78c2296 feat(site): tutorial chapter for durable and resident storage modes
- new chapter 7, "Storage modes: durable and resident", covering what
  master gains with the databasev2 cherry-pick: durable: false for a
  RAM-only table, resident: keys for a table that outgrows RAM
- states the parts a reader would otherwise hit as surprises: a
  keys-resident table is REFUSED at startup without WO_DATA, an update
  appends a delta rather than rewriting the row, and the chain is
  bounded at 16 links so a hot row does not degrade reads or replay
- quotes the measured 2.55x smaller resident set, not an estimate
- actors/deps/serving shift to ord 8/9/10; seeding is ord-driven so an
  existing WO_DATA keeps its rows and only a fresh boot reseeds
- home card says a table can be RAM-only or outgrow RAM
- two gate legs pin the new chapter; site-accept 23 checks, 0 failures

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
(cherry picked from commit 3b503c0db50aa737dd06ef6d17151c654a42c59b)
2026-08-30 20:38:03 +02:00
710325b94a docs(db2-chain): close out iteration 11 on the board
- status: done in the story frontmatter (was the non-conventional
  "complete"; the board's axis uses done/in-progress/pending/hold)
- board row 11: what landed, the WO_WAL_UPDATE correction, the ceiling
  removed as unreachable, and the one criterion still weaker than
  written (expected value, not a resident: all oracle)

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
(cherry picked from commit de39a88e81e97bf6f8b75e9f15331aae20f7ab29)
2026-08-30 20:38:03 +02:00
68dd3d88b8 test(db2-chain): cover flattening, and drop a ceiling no input could reach
- flattened row image is WO_WAL_UPDATE, not WO_WAL_INSERT: the row's
  original INSERT is already in a live log, so a second one for the same
  id is a duplicate replay refuses as corruption. INSERT is right only
  for compaction, which builds a fresh log
- remove WO_CKPT_MAX_GARBAGE: with the absolute term at 64 MiB, garbage
  large enough to reach a 256 MiB ceiling has already tripped it, so the
  branch was unreachable. Postgres needs both constants because it
  thresholds on tuples with its pair at opposite ends; this thresholds
  on bytes, where one constant does both jobs
- test_delta_chain_flattens_at_k: chain depth stays <= WO_DELTA_MAX_HOPS
  across 2K+2 updates, and a reset is observed
- test_delta_chain_flatten_replays: a flattened chain replays correctly
- test_keys_resident_indexed_across_flatten: a delta on an indexed
  column composes with flattening, checked at every step across the
  bound and after restart. Found no product defect
- test_should_compact_absolute_and_ceiling: pins the absolute term, the
  boundary just under it, and the small-log case the ratio still governs
- test_wal 5700 pass / 0 fail; wovm-test and woc-test green

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
(cherry picked from commit f93b5d9db753305c297e868d977670e6d703684c)
2026-08-30 20:38:03 +02:00
2cad84b7c6 feat(db2-chains): bound a keys-resident row's delta chain
TESTS DELIBERATELY HELD at the developer's instruction — logic only.
The existing suite passes (36 suites, 0 fail) but exercises NEITHER new
behaviour: nothing builds a 16-deep chain, and no checkpoint test uses a
log near 64 MiB. Green here means "did not break what existed".

- tier 1: wo_wal_fold_row_at gains hops_out. The walk already visits
  every hop, so the depth is free — this is the design's pd_prune_xid,
  a cheap "is work worth doing" hint taken from work already happening
- the update path branches on it: past WO_DELTA_MAX_HOPS (16) it writes
  a full-row image instead of a delta, terminating the chain. `r`
  already holds the complete post-update row because index maintenance
  required folding it, so flattening costs bytes, not an extra read
- wo_wal_append_row_image encodes from a caller-held row, as
  WO_WAL_INSERT: a chain's base must replay into a database where
  nothing precedes it, so replay/compaction/fold need no change
- tier 2: should_compact gains a TRIGGERING absolute term and a ceiling.
  Our `floor` SUPPRESSES on a small log — the opposite of postgres's
  vac_base_thresh, which triggers on a small absolute problem the
  proportion hides. We had the proportion and the suppressor and
  neither real guard
- verified by construction, not test: both update entry points converge
  on row_apply_field_keys; db.c captures next_offset BEFORE calling in,
  so the re-point is transparent to which record type was written

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
(cherry picked from commit 1b808abd5942de81c3a6416714d1302384103040)
2026-08-30 20:38:03 +02:00
841f6c8f3f feat(db2-keys): gate the residency measurement, close out task 7
- new `residency` leg in db-bench.py driving docs/examples/residency-bench:
  two tables identical except the annotation, control cap + binding cap
- ITS OWN PROGRAM, not a db-bench mode: declaring a resident: keys table
  is a WHOLE-PROGRAM constraint, so the no-WO_DATA refusal fires for
  every mode in the module. Putting those classes in db-bench's shared
  types made growth/ceiling/randread — which run without WO_DATA —
  refuse to start. Caught by running the leg, not by reading it
- gates the RATIOS, waives the absolutes: ops/sec under a cap is swap
  and disk I/O and belongs to the box. Same split randread makes
- rss_ratio 2.55 floor 2.0 tol 10% (structural, like bytes_per_row);
  overcap_vs_swap_x 1.53 floor 1.0; in_ram_cost_x 4.23 ceiling 8.0;
  all_collapse_x 105.4 floor 2.0
- all_collapse_x exists because the leg's FIRST run silently measured
  nothing: at QUICK's 40k rows a 48 MiB cap binds neither mode, so the
  "over-cap" half was not over cap. The cap now scales with N and the
  leg asserts it binds
- verified the gate bites: rss_ratio 1.4, overcap_vs_swap_x 0.6 and
  in_ram_cost_x 12.0 are all rejected
- task 7 closed: both criteria moved to Met with how each was verified

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
(cherry picked from commit a310496664982c372f51b43113465eb8ad9e9fb5)
2026-08-30 20:38:03 +02:00
6fc5b4b7d4 feat(db2-keys): GB-scale bench modes, unmeasured
- hreadall/hreadkeys: the same resident A/B as wread_*, but ~2 KB per
  row so a GB of data is reachable in a few hundred thousand inserts
- the insert path is fsync-bound at roughly 2 000 rows/s, so row COUNT
  is the expensive axis and row SIZE is nearly free — 20k rows already
  produce 38 MB
- NOT RUN: the GB-scale measurement was called off. These modes are
  committed working and typechecking so the leg can be run later
  without rebuilding it, not because a result exists

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
(cherry picked from commit abc276ac39dd45a1052b6ae24d25aedb9eea3e1e)
2026-08-30 20:38:03 +02:00
882c1f7d24 feat(db2-keys): task 7 — measure resident: keys against swapping
- two tables identical except the annotation, 200k rows, 40k reads in
  one key order, WAL on ext4 (not /tmp, which is tmpfs here and would
  have put the log in RAM), rootless cgroup v2 cap
- WIDE shape, 2.55x smaller resident set: 34.4 MB vs 87.5 MB. That is
  the real win and the thing the mode was built for
- under a 48 MB cap (between the two resident sets): keys 19635 ops/s
  vs all 12854 — only 1.53x faster than letting the kernel swap
- degradation is far gentler though: all collapses 105x from its own
  uncapped throughput, keys 16x
- costs 4.2x read throughput when memory is not tight, and writes are
  markedly slower — the keys fill did not finish in 2 min where the
  resident fill plus 40k reads did. No design doc had costed writes
- THE UNANTICIPATED FINDING: cgroup limits charge the PAGE CACHE, so
  moving rows to a file does not escape a container memory limit. WAL
  37 MB + RSS 34 MB cannot both live under a 48 MB cap, so every pread
  reaches disk. The premise "the page cache will hold the hot rows"
  fails in exactly the deployment this targets
- first attempt used Int-only rows and showed parity; recorded, because
  drop_payload frees a field's VALUE and an Int's value is its inline
  slot word, so that shape cannot benefit and would have condemned the
  feature for the wrong reason
- verdict: keep it, to fit ~2.5x more data in given RAM — not to make
  an over-capacity table fast

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
(cherry picked from commit 7cba9b1174b0bf581314b3147e25cc49e6f49464)
2026-08-30 20:38:03 +02:00
cfd660a5e6 docs(db2-chains): spec + story for bounding a row's delta chain
- fixes a limitation iteration 2 shipped: compaction was supposed to
  bound chain length, but wo_wal_should_compact triggers on a whole-log
  byte ratio and cannot see one hot row's chain
- tier 1, flatten on update: the update path ALREADY folds the row for
  index maintenance and the fold already walks hop by hop, so it reports
  depth for free. Past a fixed K it writes a full row instead of a
  delta. Read <= K+1 reads, replay O(K^2) per row. No format change, no
  per-row RAM, no new trigger
- tier 2: our compaction policy has a proportional term and a
  SUPPRESSOR misleadingly called a floor; postgres's floor TRIGGERS on
  small absolute garbage. Add that term and a ceiling
- design read from .dev/reference/postgresql, not recalled:
  heap_page_prune_opt gates on an O(1) on-page hint then page fullness
  against Max(fillfactor, BLCKSZ/10); autovacuum uses base + scale *
  reltuples clamped by a max (50, 0.2, 1e8). Neither thresholds on
  new-bytes-versus-old-bytes
- K deliberately does NOT scale with table size: postgres scales a
  table-level aggregate with proportional harm, ours is per-row with
  additive cost, so scaling up would make big databases boot worst
- the story says plainly it should NOT be next: task 7 has still never
  measured whether resident: keys beats the kernel's own paging

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
(cherry picked from commit f667cad2cfbe187b5973440ab1af015b2df288f8)
2026-08-30 20:38:03 +02:00
b058feb517 docs(db2-delta): guide to log-structured rows for a new reader
- explains replay, the row chain, how a checkpoint flattens it, and why
  replay of a long chain is quadratic
- worked SKU example with the actual record layout and back-pointers,
  and a trace of the fold showing first-seen-wins
- states plainly why the checkpoint does not bound the hot-row case:
  both triggers are ratios over the whole log and nothing counts
  per-row chain length
- records the bounded-memory vs linear-time conflict behind the O(N^2)
  replay rather than presenting it as an oversight
- closes with the reviewing lesson, since this shape survived several
  rounds: complexity bugs hide in the caller's loop, not in the linear
  helper being read

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
(cherry picked from commit e6434403d566b5d72a24e9c0dcad1f25a2c16320)
2026-08-30 20:38:03 +02:00
64035bf177 docs(db2-delta): resident:keys has storage; move done criteria to Met
- "no storage behind it" / "nothing yet stores a table that way" was
  false — CRUD, checkpoint survival and updates all landed; replaced
  with an accurate summary naming task 6/7 as what remains
- the three checked delete/delete-replay/update criteria sat in
  Outstanding despite being done; moved to Met, leaving Outstanding
  holding only genuine task 6/7 work

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
(cherry picked from commit b575678ee95fa3125fa4e8145320a9cdca10ba38)
2026-08-30 20:38:03 +02:00
061942c9a6 fix(db2-delta): pend_repoint failure fatal; delta fold no longer trusts a live WAL
- wo_wal_pend_repoint's failure was silently discarded (db.c); its
  own doc claimed replay reconciles a stale map — false, a second
  same-drain update chains past the lost one, permanently. Now
  fatal, like wo_wal_stage_fatal; comment corrected
- apply_delta dereferenced db->rt->wal unguarded — NULL rt + any
  DELTA record was a crash. Now refuses cleanly (-1)
- wo_wal_replay_ex lent its throwaway view only when rt->wal was
  unset, so a live wal's non-empty staging buffer could be folded
  against during replay. Now installs unconditionally whenever rt
  exists, saving/restoring whatever was there

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
(cherry picked from commit fed9fe8b5fe022f0b22a4170c7fd68008700939f)
2026-08-30 20:38:03 +02:00
e37a10b70d fix(db2-delta): borrow the pending re-point, not the stale durable offset
- wo_row_borrow's keys arm folded at hget()'s DURABLE offset even
  when an earlier update in the same drain had only a PENDING
  re-point
- idx_remove_row then hashed the pre-first-update value, found no
  matching bucket entry (already moved by the earlier update), and
  idx_add_row added a second one — N same-drain updates leaked N-1
  entries, unbounded, nothing reclaims them but a restart
- now prefers wo_wal_repoint_offset1() over the durable offset, same
  as back_off already does, closing it for every borrow
- new test: 5 updates to one row in one drain, assert exactly one
  index entry — fails (5) before the fix, passes (1) after

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
(cherry picked from commit d4b12d1908e574419c7af2411e52d02623f7e5b7)
2026-08-30 20:38:03 +02:00
49a0a9d047 fix(db2-delta): refuse resident:keys with no WO_DATA at runtime
- loader stopped refusing durable:true+resident:keys once UPDATE
  landed; nothing replaced it at runtime
- rows for such a table live only in the WAL, so every read failed
  with a misleading "no such row" instead of naming the problem
- main.c now refuses at startup, names the class, exit(2)
- residency-accept.sh gains a leg: refuses without WO_DATA, still
  runs with it — verified failing before the fix, passing after

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
(cherry picked from commit 3ea6d6452f260d45f92045c0f300fa49faa1d810)
2026-08-30 20:38:03 +02:00
e08c26309a feat(db2-delta): lift the resident:keys refusal, prove it end to end
- loader.c: delete the INCOMPLETE-update BAIL; durable:false +
  resident:keys stays refused (nowhere to read from)
- table.c: root-cause fix for the Text-index gap — a keys-resident
  borrow now holds ENGINE values, matching wo_row_ptr's contract
  (table.h's "no VM pointer" doctrine), not a VM-decoded row. Fixes
  idx_hash/idx_cols_equal/wo_idx_probe AND db.c's GET_FIELD/PROBE
  arms with one change; reproduced pre-fix as an ASan
  heap-buffer-overflow
- docs/examples/residency: Product is genuinely resident:keys;
  residency-accept.sh's refusal leg replaced by proving the program
  runs and stock survives a restart (11/0)
- test_wal.c: oracle test drives resident:all and resident:keys
  through the same update sequence and asserts identical rows;
  Text-indexed-update test catches the representation bug; five
  pre-existing tests corrected to the fixed contract (4746/0)
- story, README, status board, CODE-LOGIC.md updated; three known
  limitations documented: mid-drain stale reads, O(N^2) replay in
  chain length, compaction blind to per-row chain length

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
(cherry picked from commit b87c68f950f01aa5e572fbb86a0f374adc83d813)
2026-08-30 20:37:49 +02:00
f138ac0abe feat(db2-delta): replay and compaction fold delta chains
- apply_delta: DELTA replay arm — fold pre-delta state via back_off,
  overlay the field, remove-then-recreate so indexes stay correct
- apply_record/replay loop: dispatch DELTA to apply_delta, drop its
  payload back to the log same as INSERT/UPDATE
- stage_flattened_row: compaction's delta-chain path — fold + re-encode
  as one fresh INSERT instead of copying the chain
- wo_wal_compact: peek the row's current record kind, flatten deltas,
  keep the byte-for-byte copy for chains already at length zero
- test_wal: three new tests — chain-of-three replay incl. secondary
  index, compaction flattens to chain length zero (asserts the record
  is a full row, not a delta), and the commit-before-repoint crash
  window replays the update without ever re-pointing the map

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
(cherry picked from commit 7e4ae70d7beb2a2e396a002184bc06f41253decb)
2026-08-30 20:37:27 +02:00
1f402ae4bb fix(db2-delta): close the unique-shadow-check's same-drain blind spot
- table.c: unique shadow-check's candidate lookup now checks
  wo_wal_repoint_offset1 before the durable wo_row_offset1, same as
  back_off — a candidate updated earlier in the SAME uncommitted drain
  was folded from its stale pre-update offset, letting a real @unique
  clash through and committing a duplicate
- the offset-only substitution alone was NOT enough (verified): the
  candidate must be FOLDED to compare values, and folding a pending
  offset via pread saw "no record" (bytes still only in the staging
  buffer), so the clash was still missed, just for a different reason
- wal.c: wo_wal_fold_row_at now reads a hop inside the currently-staged
  region from `w->buf` (new scan_record_staged, scan_record's framing
  over memory) instead of pread; every durable hop, and every existing
  caller, is unchanged
- test_wal.c: two updates in one drain where the second collides with
  the first's new unique value; must be refused. Verified failing
  against the prior commit, and still failing with only the offset
  substitution, before the fold fix; passing with both in place

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
(cherry picked from commit c049ab92570cfba4d12a018884a20b25a8916727)
2026-08-30 20:37:27 +02:00
3525435eb5 feat(db2-delta): wire the request path, defer re-point to the barrier
- db.c: guard both WO_B_DB_UPDATE_FIELD arms on keys-resident tables —
  wo_wal_append_update read a NULL wo_row_ptr there; a live crash, fixed
- ruling override on Task 3: row_apply_field_keys no longer commits or
  moves the id map — stages the delta, does the index swap (RAM apply,
  unconditional past the shadow-check; a stage failure past that point
  is now fatal, like insert). Commit/re-point move to the caller,
  mirroring insert. table.c's WAL commit removal is this ruling, not a
  regression
- offset passed back via caller-side wo_wal_next_offset(), insert's
  koff pattern
- inline arm commits then re-points; request arm records
  wo_wal_pend_repoint (own list/name — a drop and a re-point differ),
  flushed by wo_db_flush_drops after the barrier
- back_off checks the pending re-point before the durable offset, else
  a second update in one drain skips the first delta; verified failing
  this way, passing after
- wal.c: fixed a stale comment — keys-resident updates CAN reach
  wo_wal_append_update's caller now, they just never call it
- test_wal.c: 2 tests updated for the new contract; new test drives 2
  same-row updates via wo_row_update_field_slot in one uncommitted
  "drain", checks the value and delta 2's on-disk back-pointer

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
(cherry picked from commit 4d13bcebfe51936ba8c608dd9e791c784e5b8983)
2026-08-30 20:37:27 +02:00
d492d1fefb fix(db2-delta): unique shadow-check gets its own buffer, not r's
- row_apply_field_keys's shadow-check borrowed candidates via
  wo_row_borrow, which shares ONE per-table scratch with the row already
  borrowed for the update — every candidate borrow returned NULL, clash
  was always false, `@unique` silently accepted duplicates on update
- idx_add_row's own internal check has the identical defect at the same
  call site; discarding its result is now actually safe, since the fixed
  shadow-check clears uniqueness before it ever runs
- fix: extracted keys_fold_into (fold+decode) out of wo_row_borrow so it
  can target a throwaway per-call buffer instead of t->scratch; the
  shadow-check probes candidates into that buffer — r is never
  released-and-reborrowed (r IS t->scratch; that would overwrite it)
- wo_row_borrow itself is behavior-preserving: same checks, same order,
  same messages, just factored
- test_wal.c: new test — genuine @unique index, update collides with an
  existing row, asserts refusal (DB_ERR_UNIQUE) and both rows untouched;
  verified failing (update wrongly succeeded) pre-fix, passing after

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
(cherry picked from commit 409186da51fec0042d8d1e3dcf9f69f704937823)
2026-08-30 20:37:27 +02:00
7cb4bcf0c3 feat(db2-delta): keys-resident updates append, indexes follow
- table.c: wo_row_update_field/_slot no longer refuse `resident: keys`,
  both converge on one new static row_apply_field_keys
- borrows (folds), shadow-checks uniqueness, appends the delta with the
  row's current offset as back-pointer, commits, THEN idx_remove_row +
  idx_add_row + wo_row_set_offset — failure through commit leaves the
  row's offset and index untouched
- nv decoded to a VM value before touching the materialised copy, since
  wo_row_release drops every slot through the runtime, not db_val_free
- borrow released on every exit, including every failure arm
- resident: all path (row_apply_field_slot) byte-for-byte unchanged;
  wal.c untouched — Tasks 1/2 already expose everything needed
- test_wal.c: plain field update read back, and an indexed scalar
  column updated then found via wo_idx_probe by its new value, gone
  from its old — both verified failing pre-implementation, passing after
- concern: idx_hash/idx_cols_equal/wo_idx_probe cast Text slots to
  db_text* unconditionally; a keys-resident borrow decodes Text to a VM
  wo_str* (different layout) — pre-existing, left untouched; tests use
  a scalar index to sidestep it

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
(cherry picked from commit 89c56a13ed9f4abd082bfcabb46f46bb53d39faa)
2026-08-30 20:37:27 +02:00
b758f2978d fix(db2-delta): fold's cycle guard checks direction, not step count
- wal.c: wo_wal_fold_row_at now refuses any delta back-pointer that
  does not point strictly earlier than the record naming it
  (back_off >= cur), instead of capping total hops at off/13+1
- this is the real invariant, not a proxy for it: a step-count bound
  lets a forward-pointing back-pointer through in one hop whenever it
  happens to land on a genuine record, returning a plausible-but-wrong
  row instead of refusing it
- removes the 13-byte-record magic number entirely; no arithmetic
  tied to record framing remains in the guard
- wal.h: docblock updated to describe the direction invariant
- test_wal.c: two new tests — self-pointing back-pointer (boundary
  case, back_off == cur) and forward-pointing back-pointer to a real
  future record for the same row (the actual gap: verified failing
  against the old step-count guard, passing after the fix)

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
(cherry picked from commit 173dbf28a42d45a8c7f9fe430355f61f70c81935)
2026-08-30 20:37:27 +02:00
4f3f71e003 feat(db2-delta): fold a delta chain, route reads through it
- wal.h/wal.c: wo_wal_fold_row_at — THE fold. Walks BACKWARD from an
  offset through WO_WAL_DELTA records, remembering the first value
  seen per field index (newest wins, since newest is seen first),
  stops at the first INSERT/UPDATE, decodes it, overlays resolved
  fields. Returns ENGINE-owned values so reads, replay, and
  compaction (Tasks 3/5) can all build on the same output.
- Cycle guard: caps the walk at what the log up to the starting
  offset could possibly hold (13 = scan_record's own record-size
  floor), so a corrupt or malicious back-pointer fails loudly
  instead of spinning.
- table.c: wo_row_borrow's keys arm now calls the fold instead of
  wo_wal_read_row_at directly, then VM-decodes the result — same
  two-stage pattern wo_wal_read_row_at used internally. Per-table
  scratch, scratch_busy nested-borrow refusal, and the cid/id
  identity check all preserved unchanged.
- resident: all path (wo_row_ptr) untouched.
- test_wal.c: two new tests — deltas on two different fields (changed
  fields take the new value, the untouched field keeps its original)
  and two deltas on the SAME field (the newer wins, pinning direction
  — a reversed fold would pass with the older value instead).
  Verified failing pre-implementation (wo_row_borrow returned NULL
  since a delta record isn't INSERT/UPDATE) and passing after.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
(cherry picked from commit a60231cde1d49d74743cedbd134d2da11158b70b)
2026-08-30 20:37:27 +02:00
b860823dad fix(db2-delta): make delta test detect a field_idx/back_off transposition
- review finding: field_idx=0 and back_off=0 (fresh WAL, offset 0) meant
  a u32/u64 swap of these two values wrote identical zero bytes either
  way — undetectable by the prior assertions
- test_delta_record: new dedicated 3-scalar-field class (not shared
  KEYS_CLASSES) so field_idx can be a nonzero, fixed-8-byte value without
  a Text field's variable-length encoding complicating the fixed body
  size assertion
- stage+commit a filler row first so the target row's insert record (the
  delta's back-pointer) lands at a nonzero offset, not the WAL's initial 0
- delta now targets field_idx=2 with back_off=base_off, both nonzero and
  distinct from each other and from class_id=0
- class_id stays 0: this fixture registers exactly one class, so there is
  no other value to give it without an unused second class purely to
  shift an index
- verified live: temporarily swapped the field_idx/back_off wput calls in
  wal.c, confirmed test_wal now fails (fidx==49 want 2, back==2 want 49),
  then reverted — wal.c diff is a no-op, only the test changed

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
(cherry picked from commit 20ba0965e15e200641b8b63893a2f238a0279fba)
2026-08-30 20:37:27 +02:00
f1cf2d2f85 feat(db2-delta): WAL delta record kind and encoder
- enum: add WO_WAL_DELTA = 4, existing 1/2/3 untouched (on-disk logs)
- wal.h: document kind 4's payload shape in the format docblock
- wal.h: declare wo_wal_append_delta(w, db, class_id, id, field_idx,
  back_off, value) — back-pointer taken as a parameter, not looked up,
  keeping the encoder ignorant of table/map state
- wal.c: implement it, modeled on wo_wal_append_insert's shape —
  wput_u8/u32/u64 the header fields, enc_val the one field, stage()
- test_wal.c: new test_delta_record — stages a delta after an insert,
  commits, then preads the raw record and asserts kind/class/id/
  field_idx/back-pointer/value all round-trip; registered in main()
- nothing reads deltas back yet — decode/apply is a later task

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
(cherry picked from commit 9c6f832c0534a59e644c53b7cd2850581da12159)
2026-08-30 20:37:27 +02:00