RFC: shared schema gate and the write critical section (#643) - #754
Merged
Merged
Conversation
Base automatically changed from
claude/rfc-0067-detached-table-commits
to
main
September 21, 2026 20:09
azimafroozeh
requested review from
aaltshuler and
azimafroozeh
as code owners
September 21, 2026 20:09
Resolve RFC 0067's open question (#643) as a draft decision: the process-local schema gate becomes shared/exclusive — contract-lifecycle passes (schema apply, system-column upgrade, open/refresh/settle/reload/ sync) exclusive, everything else (writers, merges, maintenance, branch control, read-view captures) shared. The branch gate stays for same-branch writers; per-table gates keep their staging role; promotion moves after guard release as an independently revertible sub-decision. Motivated by the concurrent-writes instrument's sequential cross-engine baselines: 8 writers deliver less than 1 (−9% local, −68% at 30 ms object-store RTT) with p95 exploding to seconds, all writers crossing one exclusive gate regardless of branch, and reads capturing catalogs behind writers' publish windows. The exclusive gate's original rationale — a mutation advancing a Lance HEAD before discovering a schema lock — was abolished by RFC 0067's detached staging, and the classification surface is closed under one auditable rule: readers of the accepted view share, publishers of the accepted view exclude. Cross-process semantics unchanged: the durable sentinel, the mono-branch refusal and the manifest CAS remain the authority; the gate stays an in-process contention structure per the deny-list. Evidence plan maps to existing owners (failpoints branch-gate pins survive; the mid-apply blocking pin re-derives as reader-behind-writer; write_cost counts stay byte-identical) and commissions the missing DST concurrent-universe arm racing writers against a schema apply. Docs only; status draft, implementation not-started. (cherry picked from commit cb6c676)
ragnorc
force-pushed
the
claude/rfc-shared-schema-gate
branch
from
September 25, 2026 08:21
cb6c676 to
1af2323
Compare
azimafroozeh
approved these changes
Sep 25, 2026
This was referenced Sep 28, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What this proposes
A draft RFC (
docs/rfcs/2026-09-18-shared-schema-gate.md) resolving RFC 0067's open question #643 — the second step of its throughput path:("__schema_apply__", None)) becomes shared/exclusive: contract-lifecycle passes (schema apply, system-column upgrade, open/refresh/settle/reload/sync) take it exclusive; ordinary writers, merges, maintenance, branch control and read-view captures take a shared permit. Classification rule, auditable in one sentence: readers of the accepted view share; publishers of the accepted view exclude.Why now
The concurrent-writes instrument (this stack's benchmark) measured the exclusive gate's cost, sequentially, on both engines: 8 writers deliver less than 1 — −9% on local FS, −68% at 30 ms object-store RTT (sidecar-era main: −76%) — with service-time p95 exploding from ~76 ms to seconds and manifest reads/op doubling from gate-serialized revalidation. Reads also capture catalogs behind writers' publish windows today (the architecture guide's contrary claim is corrected by this RFC either way). And step 3 (group commit) is starved without this: under the current gates writers never arrive at the publisher concurrently, so every batch would have size one.
The exclusive gate's founding rationale — a mutation advancing a Lance HEAD before discovering a schema lock — was abolished by RFC 0067's detached staging; a misclassified site can now cost only a stale publish the CAS refuses.
Evidence plan (acceptance bar for the implementation PR)
Before/after
concurrent-writesat--writers 8 --write-branches {1,8}, local + RustFS(+30 ms); success = w8×B8 scales while w8×B1 stays branch-gate-bound. Existing pins mapped (branch-gate cells survive; the mid-apply blocking pin re-derives as reader-behind-writer;write_costcounts byte-identical). Commissions the missing DST concurrent-universe arm racing writers against a schema apply. Doc moves:writes.mdgate order,architecture.mdread-path sentence.Stacking
Rebased onto
mainafter #744 merged (the RFC commit replayed alone; the registry row and the RFC 0067 cross-link re-resolved against main). Docs only: the RFC, its registry row, and the 0067 unresolved-question pointer. The implementation PR follows on acceptance.