Fix #338: land the sim tier #350

Merged
crueber merged 2 commits from fix/issue-338-sim into main 2026-09-11 22:43:24 +00:00
Owner

Lands the sim tier specified in docs/go/15_testing.md §4 (child of #331): new internal/sim package (Cluster harness + 11 of 12 TestSim_ scenarios against FaultStore op counts, budgets asserted per §4.1/§4.8 with the law-6 reconciliation written down), real make sim + contract-fs recipes, sim joins ci, D3 corrected to the actual .PHONY set.

Proving safety exposed three real wal liveness bugs, fixed minimally in the same change (each regression-pinned, doc 05 amended): orphan sweep deleting concurrently-committed segments; unbounded orphan-backlog growth on failed batches (failure-path sweep); wiped version token never healing on guard-reject (token adopt into empty slot).

Gaps stated, not dropped: G1 base-rebuild kill hook (needs maintain machinery), G2 same-head checkpoint retry 412 (pinned), G3 SIGTERM delivery (e2e).

Verification: make sim green (~12s); safety 3x3 Chaos(0.05) + seeds green incl. 8/8 parallel runs; -race clean (sim + wal); covergate >=95% (sim 96.5%, wal 95.4%); gofmt/vet clean. Store surface untouched (no contract run needed).

Note: branch is fix/issue-338-sim (fix/issue-338 is held by a parallel active worktree at /tmp/opencode/walhub-338 — may be a duplicate effort worth coordinating).

Lands the sim tier specified in docs/go/15_testing.md §4 (child of #331): new internal/sim package (Cluster harness + 11 of 12 TestSim_ scenarios against FaultStore op counts, budgets asserted per §4.1/§4.8 with the law-6 reconciliation written down), real make sim + contract-fs recipes, sim joins ci, D3 corrected to the actual .PHONY set. Proving safety exposed three real wal liveness bugs, fixed minimally in the same change (each regression-pinned, doc 05 amended): orphan sweep deleting concurrently-committed segments; unbounded orphan-backlog growth on failed batches (failure-path sweep); wiped version token never healing on guard-reject (token adopt into empty slot). Gaps stated, not dropped: G1 base-rebuild kill hook (needs maintain machinery), G2 same-head checkpoint retry 412 (pinned), G3 SIGTERM delivery (e2e). Verification: make sim green (~12s); safety 3x3 Chaos(0.05) + seeds green incl. 8/8 parallel runs; -race clean (sim + wal); covergate >=95% (sim 96.5%, wal 95.4%); gofmt/vet clean. Store surface untouched (no contract run needed). Note: branch is fix/issue-338-sim (fix/issue-338 is held by a parallel active worktree at /tmp/opencode/walhub-338 — may be a duplicate effort worth coordinating).
15_testing.md §4 specified sim scenarios against FaultStore op counts but
internal/sim did not exist and 'make sim' was a no-op PHONY. This lands it:
Cluster harness (one truth store, one FaultStore link per instance,
crash-boundary wrappers, retrying pusher, truth oracle) + 11 of 12 TestSim_
scenarios with the §4.8 budgets asserted via link Stats.Ops (doc §4.1:
push 6/5 = Rust 5/4 + parallel sidecar PUT, depth unchanged — reconciles
law 6 explicitly). Gaps G1/G2/G3 stated in package doc + D8, not dropped.

Proving safety turned up three real wal liveness bugs (each minimal,
regression-pinned, doc 05 amended):
- sweepBurned deleted concurrently-committed segments (listed-but-absent;
  now rechecks latest manifest, sweeps only unlisted)
- failed batches never swept their burns (orphan-backlog death spiral to
  the ErrCorrupt cap; now swept on failure under the same guard)
- wiped version token never healed on guard-reject (CAS ladder spun to
  exhaustion deterministically; freshen now adopts into an empty slot)

Makefile: real sim + contract-fs recipes; sim joins ci; D3 corrected to
the actual .PHONY set (test-slow/dev dropped — no recipe exists).
Sign in to join this conversation.
No description provided.