Repository navigation
Make failed statements atomic and harden recovery boundaries - #248
Merged
Merged
Conversation
Unify mutation completion and aborted-transaction handling across engine and client entry points. Preserve rollback in every WAL mode and distinguish uncertain commits from ordinary statement failures. Add crash and fsync proofs, explicit correlated bindings, view failure guards, and patched TLS dependencies. Constraint: Preserve existing disk formats and numeric wire error classes. Rejected: Treat a missing COMMIT reply as rollback | the durable outcome can be unknown. Confidence: high Scope-risk: broad Directive: Keep internal BEGIN markers even without a separate fsync; legacy replay accepts boundary-free logs. Tested: Linux instrumented workspace 2682 passed, strict Clippy/rustdoc, TS and Node suites, package smoke, audit/deny/gitleaks, Criterion execution smoke. Not-tested: Actual power loss, full cross-file DDL fault matrix, authoritative Depot performance gate; WAL-Off write overhead is explicitly accepted and documented.
This was referenced Sep 26, 2026
Preserve the reviewed correctness fixes while carrying forward current compiler/Miri compatibility and the published-site analytics integration. Constraint: Strict branch protection requires the candidate to include current main Confidence: high Scope-risk: moderate Tested: Previously green independent branches; fresh combined CI follows this merge Not-tested: Fresh merged CI until pushed
…ffer Relieve prior committed dirty pages before the next implicit rollback pin. Settle WAL generations before writing heap/header/index state, retain the WAL history, and leave explicit transaction admission unchanged. Constraint: Preserve statement rollback, retained history and deferred durability Rejected: Raise the budget or cap the benchmark fixture | That would hide a real long-lived autocommit failure Confidence: high Scope-risk: moderate Tested: Six query regressions after three failing-first cases; all WAL modes; prior-row preservation; deferred claims and retained history; 16 atomicity/durability tests; 257 storage unit tests; independent code review; fmt/diff checks Not-tested: Fresh authoritative Depot rerun and combined CI pending
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Make failed data mutations atomic across text, SQL, parameterized, prepared, and native/client entry points. Explicit transactions abort on statement errors; uncertain commits and poisoned handles return safe recovery guidance. Also harden view failure handling, correlated field binding, TLS dependencies, and benchmark/test reliability.
Type of change
Behavior change
QueryErrorvariants affect exhaustive matches.Test plan
powdb-query/testing: 2,682 passed, zero failed, 202 targets. Four pre-existing ignored tests plus one ignored child fixture explicitly invoked by its parent crash test.Performance disposition and limits
This is a correctness/security update, not a speedup claim. Local same-harness control/candidate/control diagnostics show materially slower WAL-Off writes with rollback protection; reads are broadly comparable. Runs overlapped other verification and are not publication-quality timing evidence. The bounded safety tradeoff was independently reviewed and is documented in CHANGELOG; no thresholds or baselines were changed. Full remains default and point-write fsync counts remain unchanged.
Process-kill tests do not model power loss. View protections do not claim a complete cross-file DDL crash journal. No automatic data repair, version bump, merge, or release publication is included.
Need help on this PR? Tag
@codesmith-botwith what you need. Autofix is disabled.