Skip to content

docs: fold production review into the scheduler design - #337

Merged
beinan merged 1 commit into
lance-format:mainfrom
beinan:docs/scheduler-design-review-fixes
Oct 8, 2026
Merged

beinan merged 1 commit into
lance-format:mainfrom
beinan:docs/scheduler-design-review-fixes

Conversation

@beinan

@beinan beinan commented Oct 8, 2026

Copy link
Copy Markdown
Collaborator

Part of #333. Addresses the review comments on #334/#335.

Changes to the design

Review point Change
One assignment per table re-serialises merge and compaction Invariant 1 is now one write-turn holder per table; preparation units run concurrently with the turn holder and each other (§4.3, §4.5, §7). Explicit: never re-serialise merge behind preparation (#308, #327).
Strict class order + in-class aging still starves commit-ready compaction under a hot merger Two hard bounds in §4.2: max_consecutive_turns[kind] (applies across classes, incl. class 1) and max_turn_wait_secs[kind] promoting to class 1. Invariant 5 rewritten.
Delta demand events race and get overwritten; stale snapshots can hide progress Per-shard watermarks (sealed_through_seq), max-merge per shard, sum across shards; snapshot lowers a watermark only with a newer observed revision; new invariant 5a (idempotent folding).
bytes_free heartbeat is a sample, not a reservation Assignments carry reserved_bytes; headroom = bytes_total − Σ reserved over live assignments, rebuilt from etcd on failover; executor still enforces local budget (§4.4).
Shadow phase would leave a scheduling gap P1 keeps all loops running; scanner additionally writes demand; per-table switch only after the fleet is homogeneous (§8, backlog P1/P2 and mixed-version rules).
Isolating legacy RPCs is not recovery Stated explicitly in §4.4 and backlog C3: isolation bounds blast radius; stall detection stays on the execution's actual read/encode/commit progress.

Factual corrections

  • generate_id() is UUIDv7 (core/src/id.rs:28): the queue is approximately enqueue-time ordered; what it lacks is priority. Backlog §0 and C6 corrected.
  • failure.rs:74-79 parses line/column as u32, so renumbering is safe. What breaks it is a path move, crate rename, or a change in how Lance wraps InvalidInput. C1 corrected.

Docs only; typos clean.

🤖 Generated with Claude Code

Corrections from review of lance-format#333/lance-format#334/lance-format#335:

- One write-turn holder per table, not one assignment per table.
  Preparation units run concurrently with the turn holder and with each
  other; the scheduler must never re-serialise merge behind compaction
  or index preparation (lance-format#308, lance-format#327).
- Class ordering plus in-class aging still starves commit-ready
  compaction under a hot merger. Add hard bounds: max_consecutive_turns
  per kind (applies across classes) and max_turn_wait_secs promoting to
  class 1.
- Demand events become per-shard watermarks (sealed_through_seq), which
  are idempotent under loss and duplication; stats snapshots may lower a
  watermark only with a newer observed revision.
- Heartbeat bytes_free is a sample. Assignments carry reserved_bytes;
  the planner computes executor headroom from live assignments, rebuilt
  on failover; executors still enforce the local memory budget.
- Shadow phase keeps every existing loop running; per-table switch to
  the planner happens only on a homogeneous fleet.
- Isolating legacy RPCs bounds blast radius only; stall detection stays
  on the execution's actual read/encode/commit progress.

Factual fixes: generate_id() is UUIDv7 (time-ordered, not random) so
the queue is approximately FIFO without priority; failure.rs accepts
any line/column digits, so renumbering is safe while path or wrapper
changes are not.

Refs lance-format#333.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@beinan
beinan merged commit 1e73692 into lance-format:main Oct 8, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant