Skip to content

feat(chunk-store): ADR 0072 phase 1 — write-through floor (#548) - #586

Merged
nikhilunni merged 1 commit into
mainfrom
epic/548-gcs-free-resume
Jul 7, 2026
Merged

nikhilunni merged 1 commit into
mainfrom
epic/548-gcs-free-resume

Conversation

@nikhilunni

Copy link
Copy Markdown
Contributor

Phase 1 of epic #548 (GCS-free resume). ADR 0072 (Proposed). Branches off main (has the #528/#529 deps).

The mechanical write-through floor — moves 4+5 of the ADR. Backend-agnostic, no wire change.

Changes

  • Move 4 — close the exists() write-through hole (engram-chunk-store/src/store.rs): put_chunk's idempotency short-circuit now runs the local write-through (warm_local) before returning. A chunk that is remotely present but locally evicted is re-warmed by a put, so the producing host stops re-fetching its own uploads from GCS on the next resume. (Closes the 583+55 write_local failed / write-through … failed re-miss class for the exists-arm.)
  • Move 5 — drop the per-dirty-chunk GCS HEAD on flush (store.rs + both flush call sites): new put_chunk_unchecked(body) — unconditional PUT + unconditional local warm, no exists(). The NBD disk flush (disk_daemon/backend.rs) and teleport memory catch-up (pooled_backend.rs) switch to it: their input is freshly re-chunked, new by construction, so the per-chunk HEAD was O(dirty) round-trips/flush that always missed. put_chunk keeps its dedup HEAD for capture/enable-scale uploads (there it saves re-uploading tens of GiB on a re-bake) — the fix is a second entry point, not a behavior change.
  • Metric engram_chunk_put_total{mode=checked|unchecked, outcome}. The divergence_source{tier} counter lands in phase 3, where local|peer|gcs are all real (emitted at the resume miss-chain) — not redundantly bolted onto the generic cache hit/miss path now.

Tests

Counting-mock BlobStorage asserts: exists()-arm warms a locally-evicted chunk (move 4); put_chunk_unchecked issues zero HEADs + uploads + warms (move 5, acceptance #2); a 16-chunk flush issues zero HEADs; put_chunk still dedups on a second identical put (capture-path regression guard). All green; cargo check -p engram-host-agent clean; clippy + fmt clean.

Notes

🤖 Generated with Claude Code

@nikhilunni
nikhilunni force-pushed the epic/548-gcs-free-resume branch from be8f416 to 5b310e8 Compare July 6, 2026 13:30
@nikhilunni
nikhilunni changed the base branch from main to epic/544-transactional-snapshots July 6, 2026 13:30
@github-actions

github-actions Bot commented Jul 6, 2026

Copy link
Copy Markdown

The latest Buf updates on your PR. Results from workflow CI / buf (pull_request).

BuildFormatLintBreakingUpdated (UTC)
✅ passed⏩ skipped⏩ skipped❌ failed (5)Jul 6, 2026, 1:31 PM

@nikhilunni
nikhilunni force-pushed the epic/544-transactional-snapshots branch 2 times, most recently from 630cf00 to 3ee7c6e Compare July 7, 2026 04:33
Base automatically changed from epic/544-transactional-snapshots to main July 7, 2026 05:11
@nikhilunni
nikhilunni force-pushed the epic/548-gcs-free-resume branch from 5b310e8 to c0d684e Compare July 7, 2026 05:30
@nikhilunni
nikhilunni marked this pull request as ready for review July 7, 2026 05:30
@nikhilunni
nikhilunni force-pushed the epic/548-gcs-free-resume branch from c0d684e to 8bd5563 Compare July 7, 2026 06:12
GCS-free resume moves 4+5, rebased onto main past #583/#584/#597. Close
the put_chunk exists()-arm write-through hole + add put_chunk_unchecked
to drop the per-dirty-chunk GCS HEAD on flush paths. ADR renumbered
0075 -> 0078 at land (main's 0075 = substrate-single-writer, #583).

The flush path keeps its explicit cache.put alongside the store-internal
write-through: cache and store travel separately into the disk backend,
so the store carrying a cache is prod wiring, not a structural
guarantee — collapsing to one cache identity is ADR 0076 (substrated)
territory. (A review pass tried cutting it; reverted — the CI-proven
shape stands. Note: eviction_finalize_redrive fails on the DEV-VM for
main and this branch alike — environmental, tracked in the dev-vm
pitfalls; CI is the arbiter for that suite.)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_014jJi2vqAaxt3Q5UKxbe4Gx
@nikhilunni
nikhilunni force-pushed the epic/548-gcs-free-resume branch from 8bd5563 to b26914c Compare July 7, 2026 06:45
@nikhilunni
nikhilunni merged commit b3e458c into main Jul 7, 2026
18 checks passed
@nikhilunni
nikhilunni deleted the epic/548-gcs-free-resume branch July 7, 2026 07:02
nikhilunni added a commit that referenced this pull request Jul 7, 2026
…ocal_snapshots (#548)

Rebased onto main past #586/#598. Renumbered at land: migration
0090_drop_hosts_local_snapshots -> 0091 (main took 0090); ADR refs
0075 -> 0078. WIRE_VERSION 10 -> 11 (lockstep coord+host roll; v10
hosts drain from scheduling until the fleet rolls).

Review fixes folded in:
- the TS tier now follows the retirement: buf-generated fleet_pb.ts
  regenerated (web + orchestrator) and the four web consumers of the
  always-zero localSnapshots field removed (the un-regenerated codegen
  would have failed CI's drift check; the Fleet page rendered a dead
  '0 snapshots' datum).
- snapshot_host_veto's cap arm now emits the promised `cap:<name>`
  label (bare "cap" made fc_snapshot_version-vs-bundle-stamp spikes
  undiagnosable from the metric).
- pick_from's tier doc no longer claims capacity-BLIND affinity (tier-0
  is capacity-checked by construction).
- HostUtilization's rustdoc un-interleaved from the disk-floor consts;
  migration comment corrected (said WIRE 9->10; actual 10->11) before
  checksum-freeze; README/DESIGN heartbeat field lists updated; ADR
  gains the possession-freshness divergence note.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_014jJi2vqAaxt3Q5UKxbe4Gx
nikhilunni added a commit that referenced this pull request Jul 7, 2026
…ocal_snapshots (#548) (#587)

Rebased onto main past #586/#598. Renumbered at land: migration
0090_drop_hosts_local_snapshots -> 0091 (main took 0090); ADR refs
0075 -> 0078. WIRE_VERSION 10 -> 11 (lockstep coord+host roll; v10
hosts drain from scheduling until the fleet rolls).

Review fixes folded in:
- the TS tier now follows the retirement: buf-generated fleet_pb.ts
  regenerated (web + orchestrator) and the four web consumers of the
  always-zero localSnapshots field removed (the un-regenerated codegen
  would have failed CI's drift check; the Fleet page rendered a dead
  '0 snapshots' datum).
- snapshot_host_veto's cap arm now emits the promised `cap:<name>`
  label (bare "cap" made fc_snapshot_version-vs-bundle-stamp spikes
  undiagnosable from the metric).
- pick_from's tier doc no longer claims capacity-BLIND affinity (tier-0
  is capacity-checked by construction).
- HostUtilization's rustdoc un-interleaved from the disk-floor consts;
  migration comment corrected (said WIRE 9->10; actual 10->11) before
  checksum-freeze; README/DESIGN heartbeat field lists updated; ADR
  gains the possession-freshness divergence note.


Claude-Session: https://claude.ai/code/session_014jJi2vqAaxt3Q5UKxbe4Gx

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant