Skip to content

Make failed statements atomic and harden recovery boundaries - #248

Merged
zvndev merged 3 commits into
mainfrom
codex/powdb-integrity-milestone
Oct 8, 2026
Merged

zvndev merged 3 commits into
mainfrom
codex/powdb-integrity-milestone

Conversation

@zvndev

@zvndev zvndev commented Sep 26, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

Make failed data mutations atomic across text, SQL, parameterized, prepared, and native/client entry points. Explicit transactions abort on statement errors; uncertain commits and poisoned handles return safe recovery guidance. Also harden view failure handling, correlated field binding, TLS dependencies, and benchmark/test reliability.

Type of change

  • Bug fix
  • Documentation
  • CI / tooling
  • Performance improvement

Behavior change

  • Breaking: after an explicit-transaction error, applications must ROLLBACK before further work or COMMIT.
  • Breaking: new Rust QueryError variants affect exhaustive matches.
  • Ambiguous correlated bare fields are rejected; explicit outer aliases are supported. SQL subquery support is not expanded.
  • Commit uncertainty never implies rollback or invites automatic retry. Poisoned engine locks use Internal wire errors with fixed safe guidance.
  • Implicit transactions carry buffered BEGIN markers so pre-commit crashes cannot be mistaken for legacy boundary-free logs. No extra per-point fsync is introduced.
  • Existing disk formats and numeric wire classes are unchanged. DDL is not newly transactional.

Test plan

  • Final frozen Linux arm64 workspace with powdb-query/testing: 2,682 passed, zero failed, 202 targets. Four pre-existing ignored tests plus one ignored child fixture explicitly invoked by its parent crash test.
  • Default-feature workspace run: all runtime suites passed except two stale oracle source anchors; anchors corrected and oracle passed in final workspace run.
  • Strict all-target Clippy, rustfmt, warnings-as-errors rustdoc, missing-docs ratchet, version/CI-needs/testing-feature guards.
  • Process-kill recovery before/after commit in Full and Normal; all-mode live rollback; fsync failure/uncertain-commit tests; view refusal and registry publication-failure tests.
  • Fresh TS client suites and all 60 fresh Node-addon tests; packed npm import and Rust package-manifest smoke.
  • Refreshed root/fuzz audits: zero vulnerabilities; seven existing root advisory warnings. cargo-deny and redacted gitleaks passed.
  • All 23 Criterion workloads pass execution smoke; corrected wide comparison and durable-write/fsync smoke executed.
  • Documentation and CHANGELOG updated.
  • GitHub two-OS/sanitizer/Miri/compatibility release gates: pending CI.
  • Authoritative Depot performance comparison: not completed locally; comparator correctly refuses ARM laptop vs x86 baseline.

Performance disposition and limits

This is a correctness/security update, not a speedup claim. Local same-harness control/candidate/control diagnostics show materially slower WAL-Off writes with rollback protection; reads are broadly comparable. Runs overlapped other verification and are not publication-quality timing evidence. The bounded safety tradeoff was independently reviewed and is documented in CHANGELOG; no thresholds or baselines were changed. Full remains default and point-write fsync counts remain unchanged.

Process-kill tests do not model power loss. View protections do not claim a complete cross-file DDL crash journal. No automatic data repair, version bump, merge, or release publication is included.


View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.

Unify mutation completion and aborted-transaction handling across engine and
client entry points. Preserve rollback in every WAL mode and distinguish
uncertain commits from ordinary statement failures. Add crash and fsync proofs,
explicit correlated bindings, view failure guards, and patched TLS dependencies.

Constraint: Preserve existing disk formats and numeric wire error classes.
Rejected: Treat a missing COMMIT reply as rollback | the durable outcome can be unknown.
Confidence: high
Scope-risk: broad
Directive: Keep internal BEGIN markers even without a separate fsync; legacy replay accepts boundary-free logs.
Tested: Linux instrumented workspace 2682 passed, strict Clippy/rustdoc, TS and Node suites, package smoke, audit/deny/gitleaks, Criterion execution smoke.
Not-tested: Actual power loss, full cross-file DDL fault matrix, authoritative Depot performance gate; WAL-Off write overhead is explicitly accepted and documented.
Preserve the reviewed correctness fixes while carrying forward current
compiler/Miri compatibility and the published-site analytics integration.

Constraint: Strict branch protection requires the candidate to include current main
Confidence: high
Scope-risk: moderate
Tested: Previously green independent branches; fresh combined CI follows this merge
Not-tested: Fresh merged CI until pushed
…ffer

Relieve prior committed dirty pages before the next implicit rollback pin.
Settle WAL generations before writing heap/header/index state, retain the WAL
history, and leave explicit transaction admission unchanged.

Constraint: Preserve statement rollback, retained history and deferred durability
Rejected: Raise the budget or cap the benchmark fixture | That would hide a real long-lived autocommit failure
Confidence: high
Scope-risk: moderate
Tested: Six query regressions after three failing-first cases; all WAL modes; prior-row preservation; deferred claims and retained history; 16 atomicity/durability tests; 257 storage unit tests; independent code review; fmt/diff checks
Not-tested: Fresh authoritative Depot rerun and combined CI pending
@zvndev
zvndev merged commit b6ba286 into main Oct 8, 2026
43 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant