Skip to content

fix(runtime): consolidate patch correctness and retire unsafe shortcuts - #218

Open
f0rr0 wants to merge 4 commits into
mainfrom
f0rr0/patch-correctness-refresh
Open

f0rr0 wants to merge 4 commits into
mainfrom
f0rr0/patch-correctness-refresh

Conversation

@f0rr0

@f0rr0 f0rr0 commented Sep 27, 2026 •

Copy link
Copy Markdown
Owner

September 29 follow-up: measured fixes

Current head: 8d57e35902367efc8a51b5f16dfd4cc9a55f5a87. This adds one focused commit on top of the September 29 rebase onto main 32ce7b29510b74333e799601b69a71fd28122e80.

Fixed and verified

  • Remove the introduced 64 MiB SQL-response quota. Ordinary buffered results grow on demand up to the actual signed-i32 bridge range or available memory. The independent collected-tool-output cap stays unchanged.
  • Repair terminal Rust cleanup: direct is_closed() reflects unusable state, subsequent SQL reports a lifecycle error, and close releases storage for reopen without re-entering the failed guest. Async/TS closed flags retain their settled-shutdown meaning. Interrupted writes still must not be blindly retried.
  • Remove misleading browser output-limit annotations from unrelated errors and duplicate Rust error causes.
  • Keep the existing collected-result API and document retained guest-buffer capacity, streaming trade-offs, login-role behavior and native queue semantics. No new dependencies, public options, environment flags or production benchmark framework.
  • Verify the PR's existing startup-role fix against actual main: main opens username=app with session_user=postgres, and RESET ROLE restores the bootstrap superuser. The PR preserves app, applies role defaults, denies unauthorized elevation and rejects NOLOGIN. The embedding host still authenticates/selects the caller.

Performance: attribution, not a speedup claim

All measurements use retained release executables, balanced serial process runs and validated results on a shared Linux host.

Comparison Result
Main vs original PR: 176 validated runs across 11 workloads, memory and directory RTT about 6.9 → 7.7 µs (+12%); several INSERT/read/mixed workloads also regress. No general query speedup.
Exact main guest/host, changing only compiler memory policy: 80-run four-variant memory experiment Strict Wasmer memory semantics account for roughly 9–15% on the tested memory workloads; this is compiler semantics, not storage durability.
Original PR vs these fixes: initial directory watchout, then 32-run confirmation Suspected 5–6% penalty did not reproduce: logged INSERT −0.6%, mixed transactions −0.4%. Practically neutral in this test, not a claimed win or universal non-regression proof.
Native default autocommit, four variants × four repeats About 9.4× slower when the default changes from fsync-off to on; matched fsync-on main nearly matches the PR. Preserve the durability contract.
Automatic streaming followed by collecting the complete result Rejected: +8.8% RTT, +4.3% at 32 MiB, +6.5% at 80 MiB. No adaptive transport switch added.

The Rust LLVM/AOT memory-policy percentages do not apply to browser V8. Remaining native PostgreSQL 18.4 INSERT/mixed-workload gaps are not closed. PGlite 0.5.8 remains slower on several tested workloads, but its PG 18.3 and fsync-off policy prevent an engine-only/equivalent-durability comparison.

Local verification of this follow-up

  • Combined source/package checks: 32 tasks passed, 23 valid cached results, including Rust/TS formatting, lint, types, source packages, C bridge/generator tests and browser-example checks (161 Rust unit tests, eight public API tests, Rust doctests, 357 TS tests).
  • Actual fixed Rust host + guest: 21 runtime integration tests passed, including 80 MiB memory/directory responses and direct/async terminal close/reopen. The direct test verifies that a committed row survives and an uncommitted row does not.
  • Final Chromium 148: validated 80 MiB in direct memory, direct IndexedDB and worker IndexedDB; previous-response ownership and ordinary SQL-error recovery pass. Both persistent placements close/reopen after terminal failure and retain committed data. Custom-role direct → worker → direct reopen, role resets, login triggers and NOLOGIN rejection pass.
  • Changed browser-host patch series applies with zero fuzz and its canonical host was rebuilt. The changed guest bridge was rebuilt/relinked from unchanged retained PostgreSQL objects, and the matching strict core AOT was reserialized; compatible unchanged support/initdb outputs were reused.
  • git diff --check passes. Local artifacts/manifests are explicitly diagnostic-only, not publishable release evidence. Benchmark machinery and binaries are not staged.

Browser fixture caveat: the diagnostic carrier omits the normal cluster seed, so the worker database was initialized through the direct host; this does not qualify fresh seeded worker provisioning. Browser terminal diagnostics still duplicate a bounded historical stderr tail, although the real terminal cause remains present.

Remaining blockers and scope

Keep this PR draft. Windows recovery remains a merge blocker (#208). The PR removes main's incomplete host-exit workaround and exposes the known MSVC Sys exception-recovery failure; it is not claimed to behave identically to main. Upstream's move to V8 requires an actual Windows WASIX/dynamic-linking/cache and SQL-recovery evaluation, not merely a dependency-version bump.

No exact-SHA hosted/release qualification is claimed. Windows/macOS, complete extension lifecycles, fresh concurrent Postmaster qualification, and Node/Bun/Deno N-API end-to-end performance remain outside this local checkpoint. Production stack-exhaustion protection, CPU-bound WASIX cancellation and Postmaster signal semantics remain separate unfinished runtime work.

Keep real ABI and AOT-policy identity checks: changed interfaces must agree, and Wasmer 7.2.1 does not include every codegen flag in its artifact identity. These are publisher/install/open responsibilities, not per-query guards or consumer tuning choices. Matching artifacts does not require rebuilding compatible unchanged outputs.

Earlier rebase, scope and historical evidence

September 29 rebase

Rebased onto remote main 32ce7b29510b74333e799601b69a71fd28122e80. Current head: 5b1d7b7b.

Preserves main's ABI 12, release versions, bounded streaming queue, streaming archives and COPY callback-abort handling alongside the PR's deadline checks. Both sets of owner tests remain enabled. The standalone queue fixture supplies the new timeout hook and fails if it is unexpectedly invoked. Resource notes were updated for main's queue/archive behavior.

Validation: moon run liboliphaunt-native:test release-tools:metadata passed (15 tasks, 10 cached); git diff --check passed. Earlier runtime/build evidence below is historical, not qualification of this rebased SHA. Windows recovery blocker remains; this PR stays draft. Pre-rebase head ef4821f5 remains on the closed #202 branch and local backup f0rr0/backup-pr218-20260929.

September 27 scope and evidence (before rebase)

Replacement for #202

Reopened on a new branch against current main so GitHub computes the correct comparison. Exact same head commit ef4821f50a05db7ecfa2782e2accea5a8c544f5b; no source or scope changes. Historical discussion and evidence remain in #202.

Expected diff against main df2b112e866f8ea76d320d7b3e172cf7be764177: 248 files, +59,360 / -43,720 lines. Most line churn is splitting existing Postmaster patch files, not new engine implementation.

Windows clarification: main already has the engine limitation, but its host-exit workaround avoids that path. This change removes that semantically incomplete workaround and exposes the demonstrated Windows crash. It is a compatibility blocker introduced by this recovery transition, not a reproduced identical crash on main. Track the replacement in #208.

September 27 refresh onto current main

The earlier correctness work has been selectively ported onto main df2b112e866f8ea76d320d7b3e172cf7be764177, preserving its current source/build graph, resources/extensions, seedless browser startup, and extracted Postmaster executor. Existing PR history is preserved; no force push.

Not yet merge/release-ready: Windows/MSVC Sys exception recovery remains a blocker for the complete supported matrix. A production early stack guard is not enabled. Fresh Postmaster concurrent runtime and full supported-platform/extension qualification remain outstanding.

Implemented

  • Retire the 13 rejected embedded WASIX patches, with reasons retained in the patch ledger; port guest recovery and Rust/browser host ABI changes together.
  • Port native startup cleanup, process/session boundaries, trusted identity, checked entropy and bounded output. Stop disabling native fsync by default.
  • Use strict-memory AOT and reject stale artifact profiles instead of relabelling binaries.
  • Split Postmaster Wasmer/libc patches into ordered series while preserving main's first-party executor; strict patch replay and preparation receipts replace unsafe application assumptions.
  • Reuse existing owner tests/contracts instead of restoring obsolete policy machinery. No new public environment flags.
  • Fix two newly exposed integration gaps: omitted broker application_name overriding role defaults, and a file-wide feature gate silently skipping core Rust runtime tests.

Fresh local evidence

  • Native Linux core build, C ABI/process-boundary smoke, broker identity/wire integrations, 108 SDK and 3 broker unit tests.
  • Fresh WASIX core/initdb and production browser host; Chromium memory, IndexedDB and OPFS startup, error recovery, COPY callback failure/reuse, identity and persistent close/reopen.
  • Fresh strict AOT; seven PostgreSQL regressions, 17 existing runtime cases, plus actual 10,000-row COPY OUT/recovery in both memory and directory modes.
  • Strict source replay: 22 native PG, 31 embedded WASIX PG, 27 browser-host, nine Postmaster Wasmer and eight libc patches. Postmaster owner tests/lint pass; full new Postmaster producer/runtime not yet qualified.
  • First hosted run 36310352902 exposed the release metadata requirement for a single-parent tip; documentation follow-up ef4821f now follows the history-preserving merge. The full local release-tools:metadata check passes on this tip; policy was not weakened. Hosted CI must still qualify the new SHA.

These are correctness checks, not a comparative performance or release qualification claim. Native fsync-on can cost write latency intentionally.

New dependencies: experiments, not production upgrades

  • Wasmer 7.4.2 / WASIX 0.704.2 passed isolated Linux LLVM/AOT, exception recovery, memory-growth and real host-module probes. Worth a separate full SDK compatibility and matched-workload evaluation; no Windows or stack-exhaustion fix established.
  • @wasmer/sdk 0.18 ran SQL and large local browser transfers. It exposes a command-oriented API, not our embedded exports; the tested PostgreSQL data did not survive command restart in the same Sandbox. A supported JavaScript PGDATA mount/persistence contract is still needed. Its tested PostgreSQL package is Oliphaunt-derived, not ElectricSQL PGlite.
  • Production Wasmer/browser-host pins remain unchanged.

Current implementation, evidence, retained assets and next steps.
Follow-up tracking: #201.

@vercel

vercel Bot commented Sep 27, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
oliphaunt-docs Ready Ready Preview Sep 29, 2026 9:28pm UTC

@f0rr0
f0rr0 marked this pull request as ready for review September 30, 2026 23:14

This branch was successfully deployed

1 active deployment
Preview — 8d57e359 Deployed Sep 29, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant