Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
2238 commits
Select commit Hold shift + click to select a range
ed4bc95
cas: 10-backups.md — consolidation identity is plain re-hashing; skip…
filimonov Jul 14, 2026
82d3f80
cas: opt spec — reject dedup-validate-on-hit as unsafe (not equivalen…
filimonov Jul 14, 2026
2871886
cas: opt §5 BLOCKED — spare-clear reopens 2026-07-11 deposed-leader d…
filimonov Jul 14, 2026
02fd9f0
cas: opt §6 — content_addressed_log emit-path move + reason LowCardin…
filimonov Jul 14, 2026
e4c0d2d
cas: opt §5 marked ABANDONED (user decision); §6 done — round wrap docs
filimonov Jul 14, 2026
64c7999
cas: investigation — adoptEvidence source-dropped-mid-relink lifecycl…
filimonov Jul 14, 2026
994507d
cas: spec — all-tree part files (mutable set = ∅) + committed-part re…
filimonov Jul 14, 2026
c254cf2
cas: fold fetch-relink commit-before-release fix into the read-replic…
filimonov Jul 14, 2026
cb01c55
cas: implementation plan — all-tree part files (12 tasks, phase 0 = W…
filimonov Jul 14, 2026
03b3b95
cas: `Store::openForDecommission` — admin claim gate for pool-member …
filimonov Jul 14, 2026
e0e83e8
cas: `decommissionPoolMember` core — namespace erasure with report + …
filimonov Jul 14, 2026
1b5a7f5
cas: fix decommission precommit undercount, add member_decommission e…
filimonov Jul 14, 2026
9300b29
cas: reject B1 (manifest_hash on Keeper znode) — replication stays di…
filimonov Jul 14, 2026
a6ea558
cas: extract fetch-handoff retention pin into its own spec (orthogona…
filimonov Jul 14, 2026
eb8f78a
cas: decommission drain phases — manifest debris, staging, roots sweeps
filimonov Jul 14, 2026
5780b6e
cas: fault-injection test for the decommission drain fail-close nuance
filimonov Jul 14, 2026
6ae2bb6
cas: codecs v3 design — everything-text formats, Core/Formats/ placem…
filimonov Jul 14, 2026
3d64199
cas: decommission manifest-debris drain honors the tolerate-and-conti…
filimonov Jul 15, 2026
bbee623
cas: codecs v3 — phase 1 implementation plan (Formats/ bootstrap)
filimonov Jul 15, 2026
6c86dee
cas: decommission slot retirement — farewell + control-object deletio…
filimonov Jul 15, 2026
a9fd849
cas: codecs v3 — compressed objects get a .zst key suffix; policy per…
filimonov Jul 15, 2026
70599d3
cas: `SYSTEM CONTENT ADDRESSED DROP POOL MEMBER` — grammar, privilege…
filimonov Jul 15, 2026
0def36c
cas: prove the decommission mid-retirement crash-recovery fallback
filimonov Jul 15, 2026
e375faf
cas: \`clickhouse-disks ca-drop-member\` -- disks facade for pool-mem…
filimonov Jul 15, 2026
51ff687
cas: fix ON CLUSTER round-trip order, consolidate parser coverage int…
filimonov Jul 15, 2026
c3acd4c
cas: docs — pool-member decommission landed (B200 without roster)
filimonov Jul 15, 2026
68a7ace
cas: integration test — kill a replica, `SYSTEM CONTENT ADDRESSED DRO…
filimonov Jul 15, 2026
23f251d
cas: fix illegal double-hyphen inside XML comments in the decommissio…
filimonov Jul 15, 2026
8628f57
cas: decommission integration test — aggregate the per-disk mount rows
filimonov Jul 15, 2026
d26c095
cas: decommission integration test — SYSTEM queries take no FORMAT cl…
filimonov Jul 15, 2026
2a52774
cas: decommission integration test — drain-to-baseline needs t1 dropp…
filimonov Jul 15, 2026
83a8d9f
cas: rev.6 fix-round commit 1 — F1 empty-dead-region detector carve-o…
filimonov Jul 15, 2026
7669414
cas: rev.6 fix-round commit 2 — F4-F10 polish (threshold dedup, obser…
filimonov Jul 15, 2026
6432794
cas: rev.6 fix-round commit 1a — F3 unlock-throw SCOPE_EXIT race (com…
filimonov Jul 15, 2026
a4fdb2f
cas: rev.6 fix-round commit 1a follow-up — pin the F3-1a side-finding…
filimonov Jul 15, 2026
681997a
cas: all-tree phase 0 — WRepoint TLA gate re-confirmed green
filimonov Jul 15, 2026
45e43b3
mergetree: supportsAtomicFileWrites capability; single-write txn_vers…
filimonov Jul 15, 2026
3c7c047
cas: Build::promote allow_repoint mode (same-key committed transition…
filimonov Jul 15, 2026
21bf462
cas: repointRef primitive — audited committed-ref manifest republish,…
filimonov Jul 15, 2026
c08d89f
cas: publishStaging — carry-forward repoint for standalone writes on …
filimonov Jul 15, 2026
430216a
cas: route uuid/metadata_version/txn_version through the content path…
filimonov Jul 15, 2026
1dd17ed
cas: correct the all-tree Phase-0 verification claim — the repoint tr…
filimonov Jul 15, 2026
d570a7d
cas: complete the truncated message of the Phase-0 correction commit
filimonov Jul 15, 2026
439dc76
cas: attribution record for the all-tree T3/T4/T6 commits
filimonov Jul 15, 2026
578a96c
cas: relink is manifest-self-contained — drop metadata_version wire f…
filimonov Jul 15, 2026
3b4d0f2
cas: committed-file unlink stages removal marks — repoint-remove unle…
filimonov Jul 15, 2026
c98c41e
cas: drop freeze metadata_version special case — byte-equal repoint n…
filimonov Jul 15, 2026
35c739a
cas: reword the stale freeze-skip sentence after all-tree Task 10
filimonov Jul 15, 2026
74f0604
cas: formats v3 phase 1 — move CasFormat into Core/Formats/, add refs…
filimonov Jul 15, 2026
50bbdd1
cas: formats v3 phase 1 — CasTextFormat: JSON vocabulary, header/trai…
filimonov Jul 15, 2026
065f6e9
cas: formats v3 phase 1 — shared format test battery, Formats/README.…
filimonov Jul 15, 2026
82cab8c
cas: fetch-handoff pin cleanup rides the existing min_active heartbea…
filimonov Jul 15, 2026
6e02e1f
cas: docs — all-tree part files model (mutable set = ∅), repoint sema…
filimonov Jul 15, 2026
f81ae8e
cas: codecs v3 phase 2 plan — control-plane text cutover + phases 3-8…
filimonov Jul 15, 2026
75c864d
cas: docs — T11 review follow-up: correct §9.1 read-your-writes mecha…
filimonov Jul 15, 2026
8f74b72
cas: delete the mutable-file concept — schema, codec, staging, view, …
filimonov Jul 15, 2026
16caf40
cas: codecs v3 phase 2 plan — fix imprecise outcomes replay wording
filimonov Jul 15, 2026
4ed45f3
cas: fix CaWiringOps.MoveDirectoryOntoExistingDestinationBuildSurvive…
filimonov Jul 15, 2026
bb1da9d
cas: codecs v3 phase 4 plan — cas_blob_meta text cutover
filimonov Jul 15, 2026
3bd454b
cas: migrate test_cas_replicated_relink from MinIO to RustFS
filimonov Jul 15, 2026
6fb325d
cas: downgrade repointRef's routine repoint log from WARNING to DEBUG
filimonov Jul 15, 2026
5c932d3
cas: codecs v3 phase 7 plan — cas_blob 256-byte JSON envelope header
filimonov Jul 15, 2026
1be66ae
cas: codecs v3 phase 5 plan — runs (record stream) text cutover
filimonov Jul 15, 2026
47ce91e
cas: codecs proposal v3 — fix example header stamps to v=3 (G_BUILD)
filimonov Jul 15, 2026
cabe38e
cas: soak asserts zero repoints on the non-transactional profile
filimonov Jul 15, 2026
6470649
cas: worklog — all-tree Tasks 7-12 landed + T12 validation-gate evidence
filimonov Jul 15, 2026
db28579
cas: backlog — four measured findings from the all-tree milestone soak
filimonov Jul 15, 2026
dce4f45
cas: worklog — all-tree milestone 20-min soak GREEN
filimonov Jul 15, 2026
22a4f73
cas: worklogs + ledger — reboot checkpoint (all-tree closed, #49 to r…
filimonov Jul 15, 2026
0abd300
cas: worklog — final quiescence watchdog line before reboot
filimonov Jul 15, 2026
4b90320
cas: cold-start resume instructions for the campaign (2026-07-15 reboot)
filimonov Jul 15, 2026
416c982
cas: source-layout refactoring design spec (layered tree, merges, Sto…
filimonov Jul 15, 2026
de8a38b
cas: dispatch part-file unlinks eagerly in DiskObjectStorageTransacti…
filimonov Jul 15, 2026
725dbc7
cas: gate eager unlink dispatch on the router's predicate, not the pa…
filimonov Jul 15, 2026
5a2b0ad
cas: backlog — [TXN-ONE-PIPELINE] one-pipeline CA disk transaction (o…
filimonov Jul 15, 2026
fa4c0b1
cas: backlog — [TXN-ONE-PIPELINE] refined to a two-phase disk-transac…
filimonov Jul 15, 2026
23e7c0d
cas: backlog — [TXN-ONE-PIPELINE] precommit/commit contract decisions
filimonov Jul 15, 2026
95f1c1d
cas: backlog — [TXN-ONE-PIPELINE] scope addition: de-patch upstream w…
filimonov Jul 15, 2026
359027a
cas: upstream patch inventory (A/B/C classification for TXN-ONE-PIPEL…
filimonov Jul 15, 2026
eddc074
cas: backlog — [GATE-DEBRIS] repo-root junk poisons clickhouse-local …
filimonov Jul 15, 2026
f1b5502
cas: formats v3 phase 2 — pin CAS JSON write settings (Phase-1 review…
filimonov Jul 15, 2026
31fcd69
cas: formats v3 phase 2 — shared wire-value vocabulary (Token/BlobRef…
filimonov Jul 15, 2026
e2bd18f
cas: formats v3 phase 2 — cas_pool_meta text cutover
filimonov Jul 15, 2026
eac9fe1
cas: formats v3 phase 2 — cas_owner/cas_epoch/cas_mount_lease text cu…
filimonov Jul 15, 2026
8f69599
cas: formats v3 phase 2 — cas_gc_state + cas_gc_hb text cutover (last…
filimonov Jul 15, 2026
ec709f9
cas: formats v3 phase 2 — cas_gc_outcomes text cutover (.zst key suffix)
filimonov Jul 15, 2026
582334a
cas: formats v3 phase 2 — cas_fold_seal text cutover (deterministic r…
filimonov Jul 15, 2026
45c53fa
cas: formats v3 phase 2 — remove the protobuf graveyard
filimonov Jul 15, 2026
adcd600
cas: formats v3 phase 2 — review nits (fail-close absent gcs, doc ref…
filimonov Jul 15, 2026
71b4ecc
cas: formats v3 phase 4 — cas_blob_meta text codec
filimonov Jul 15, 2026
893c472
cas: formats v3 phase 4 — split Core/CasBlobMeta; keep the etag-gated…
filimonov Jul 15, 2026
6c227fa
cas: codecs v3 — phase-5 plan upgraded to full task level (JIT vs lan…
filimonov Jul 15, 2026
bffaee8
cas: formats v3 phase 7 — cas_blob 256-byte JSON envelope header
filimonov Jul 15, 2026
938797a
cas: formats v3 phase 7 — rewire writer/inspect to the JSON envelope;…
filimonov Jul 15, 2026
5101a50
cas: [TXN-ONE-PIPELINE] one-pipeline disk transaction design spec
filimonov Jul 15, 2026
dc2c00c
cas: [TXN-ONE-PIPELINE] spec self-review fix — seal breadth deferred-…
filimonov Jul 15, 2026
889195b
cas: formats v3 phase 7 — review nits (raise blob_header_len floor to…
filimonov Jul 15, 2026
de23673
cas: codecs v3 — phase-3 plan (refsnaplog) at full task level
filimonov Jul 15, 2026
311bf8e
cas: formats v3 phase 5 — CasRecordStreamFormat (cas_run sorted-NDJSO…
filimonov Jul 15, 2026
652d344
cas: formats v3 phase 5 — flip the cas_run registry row (+ reconcile …
filimonov Jul 15, 2026
84066e3
cas: attribution note — de23673c1b9 carries the phase-5 code, not pha…
filimonov Jul 15, 2026
ac50a59
cas: formats v3 phase 5 — per-consumer seal-checksum RED tests + fsck…
filimonov Jul 15, 2026
13823e3
cas: worklog — gate-49 + codecs waves checkpoint (2026-07-15 evening)
filimonov Jul 15, 2026
b44b795
cas: formats v3 phase 3 — refsnaplog (cas_ref_log, cas_ref_snap) text…
filimonov Jul 15, 2026
b6a7806
cas: codecs v3 — phase-6 plan (embedded manifest stream) at full task…
filimonov Jul 15, 2026
3cae132
cas: formats v3 phase 6 — CasPartManifestFormat skeleton (descriptor …
filimonov Jul 15, 2026
11f69aa
cas: formats v3 phase 6 — part manifest encode/decode + banner payloa…
filimonov Jul 15, 2026
a4d7cf5
cas: formats v3 phase 6 — part manifest .proto→.zst key + persist wra…
filimonov Jul 16, 2026
aa381a6
cas: formats v3 phase 6 — delete CasRunFile + gtest_cas_run_file; mig…
filimonov Jul 16, 2026
08fcead
cas: codecs v3 phase 6 — record the corrected Task-4 deviation in-line
filimonov Jul 16, 2026
0001385
cas: formats v3 phase 8 — fix stale CasManifestCodec comment
filimonov Jul 16, 2026
8e43f4c
cas: formats v3 phase 8 — remove dead magicFor + CARS FormatId (+ the…
filimonov Jul 16, 2026
b2e2a60
cas: [TXN-ONE-PIPELINE] implementation plan (5 phases + audits + desi…
filimonov Jul 16, 2026
39cf327
cas txn-one-pipeline: moveDirectory tmp->final is a pure re-key; publ…
filimonov Jul 16, 2026
3a32e02
cas txn-one-pipeline: B183 migration-gate test — staged finalize drop…
filimonov Jul 16, 2026
6577004
cas txn-one-pipeline: read-your-writes test after tmp->final re-key
filimonov Jul 16, 2026
6ceb8d9
cas txn-one-pipeline: overlay program-order test (create/delete/create)
filimonov Jul 16, 2026
1ad70f2
cas: fix stale manifest-body failpoint predicate (.proto->.zst) — re-…
filimonov Jul 16, 2026
d201e2e
cas txn-one-pipeline: remove B151 early-publication machinery (rename…
filimonov Jul 16, 2026
35a3335
cas txn-one-pipeline: commit-rollback spares pre-existing ref (Audit …
filimonov Jul 16, 2026
4c709db
cas txn-one-pipeline: fault-injection regression — post-multi termina…
filimonov Jul 16, 2026
3549020
cas txn-one-pipeline: add transactionIsStagingOverlay capability + di…
filimonov Jul 16, 2026
c4897cd
cas txn-one-pipeline: route removeFile family through dispatch; drop …
filimonov Jul 16, 2026
41a7035
cas txn-one-pipeline: generic tryCreateWriteBuffer hook; move CA writ…
filimonov Jul 16, 2026
1697d4f
cas txn-one-pipeline: route moveDirectory/createHardLink/copyFile thr…
filimonov Jul 16, 2026
0676a95
cas txn-one-pipeline: release-build assertion that eager transactions…
filimonov Jul 16, 2026
b08c562
cas: fix in-flight size of a carried-forward inline entry (blob_size …
filimonov Jul 16, 2026
0c2f386
cas txn-one-pipeline: phase 4 tail de-patch — remove redundant checkA…
filimonov Jul 16, 2026
edf0234
cas: encapsulate ManifestEntry logical size (size() accessor) — inlin…
filimonov Jul 16, 2026
f2e9bea
cas: implementation plan for source-layout refactoring (scripted merg…
filimonov Jul 16, 2026
067f99b
cas: reconcile source-layout plan to post-v3 tree
filimonov Jul 16, 2026
b64fccb
cas(refactor): merge CasBackendListing into CasBackend (files, not cl…
filimonov Jul 16, 2026
8008b31
cas(refactor): merge CasGcCursorKey into CasGcShardPlan
filimonov Jul 16, 2026
dfc61a5
cas(refactor): merge CasGcRoundLogRecord into CasGcScheduler
filimonov Jul 16, 2026
2423992
cas(refactor): merge identity micro-headers into CasTypes
filimonov Jul 16, 2026
4d6560e
cas(refactor): merge ContentAddressedWriteBuffers into ContentAddress…
filimonov Jul 16, 2026
915a314
cas(refactor): merge SingleWriterSlot + StagingSweeper into CasServer…
filimonov Jul 16, 2026
9f9250b
cas(refactor): merge PartRefKey + PartFolderView + CachedPartFolderAc…
filimonov Jul 16, 2026
629f43e
cas(refactor): merge CasRefStateMachine + CasRefIntake into CasRefPro…
filimonov Jul 16, 2026
592b9b8
cas(refactor): move Core/ into layered tree (git mv only, no content …
filimonov Jul 16, 2026
0af2b31
cas(refactor): fix include paths + CMake for the layered tree
filimonov Jul 16, 2026
6c98cf6
cas(refactor): move toEventKind into Formats so CasEvent is dependenc…
filimonov Jul 16, 2026
0c80edd
cas(refactor): add ContentAddressed/README.md layer map + doc path sweep
filimonov Jul 16, 2026
afe0689
cas(refactor): extract CasPlainObjects from CasStore (stateless move)
filimonov Jul 16, 2026
905f495
cas(refactor): extract CasManifestReader (read path + decode cache) f…
filimonov Jul 16, 2026
9d714dd
cas(refactor): slice PoolConfig into RefLedgerConfig + MountConfig (p…
filimonov Jul 16, 2026
6c3180f
cas(refactor): commit stranded external-consumer include fixes from t…
filimonov Jul 16, 2026
636d044
cas(refactor): extract CasRefLedger (ref-log/ref-table subsystem) fro…
filimonov Jul 16, 2026
b4a24d5
cas(refactor): extract CasMountRuntime (mount/fence/watermark/self-re…
filimonov Jul 16, 2026
4278e99
cas(refactor): 3.5 member-order — keep ref_ledger before mount_runtim…
filimonov Jul 16, 2026
b79fbd8
cas(refactor): rename Store -> Pool (identifiers + files; no persiste…
filimonov Jul 16, 2026
e3a165d
cas(refactor): rename Build -> PartWriteTxn (class only; protocol bui…
filimonov Jul 16, 2026
b2f09bc
ca-soak: fix multidisk cluster bring-up (ch1 exit 233, disks/ parent …
filimonov Jul 16, 2026
03f6da7
docs(cas): backlog — S36-found MOVE-to-CA product bug (root-caused) +…
filimonov Jul 16, 2026
c14a860
ca-soak: land S36/S37 scenario cards (MOVE PART/PARTITION + multi-dis…
filimonov Jul 16, 2026
3af7fa4
docs(cas): backlog — S37 run confirms + refines the MOVE-to-CA bug fi…
filimonov Jul 16, 2026
fd93aa5
cas: design spec for #37 merge upload-failure resilience (fence-loss …
filimonov Jul 16, 2026
6526d1e
cas: design spec for MOVE PART/PARTITION to a content-addressed disk …
filimonov Jul 16, 2026
d292b7b
cas: implementation plan for #37 merge upload-retry fix (fence-loss +…
filimonov Jul 16, 2026
b55e75b
cas: design spec for ref-table committed-map O(touched) copy via a CO…
filimonov Jul 16, 2026
ea2a789
cas: implementation plan for #36 MOVE PART/PARTITION to a CA disk
filimonov Jul 16, 2026
8df8090
cas: implementation plan for ref-table COW map (spec 2026-07-17)
filimonov Jul 16, 2026
2c3adbe
cas: add RefCowMap -- copy-on-write ordered map for the ref-table (Ph…
filimonov Jul 16, 2026
f327210
cas: RefCowMap property/fuzz test + materialize + O(1)-copy proof (Ph…
filimonov Jul 16, 2026
2657ba3
cas: RefTableState::committed -> RefCowMap (Phase 2 Task 3)
filimonov Jul 16, 2026
e16fb7b
cas: materialize the ref-table COW map once per flush (Phase 3 Task 5)
filimonov Jul 16, 2026
2f2a3b0
cas: MOVE-to-CA fix L1 part 1 -- route() folds `moving` onto the fina…
filimonov Jul 17, 2026
81eab8b
cas: MOVE-to-CA fix L1 part 2 -- findPartDirComponent anchors `moving…
filimonov Jul 17, 2026
10c98bc
cas: MOVE-to-CA spec L1 correction -- moving/ prefix ref (crash-atomi…
filimonov Jul 17, 2026
4d73e19
cas: MOVE-to-CA fix L1 part 1 (corrected) -- route() folds `moving` o…
filimonov Jul 17, 2026
4229a14
cas: MOVE-to-CA fix L2 -- clonePart routes CA destinations through on…
filimonov Jul 17, 2026
e114f8c
cas: S36 -- add the dedup-on-TO-CA assertion (byte-identical content …
filimonov Jul 17, 2026
26590e4
cas: S36 -- calibrate two assertions surfaced by the first real MOVE-…
filimonov Jul 17, 2026
93bb65e
cas: S37 -- neutralize the permanently-expired TTL rule after the rou…
filimonov Jul 17, 2026
a2c420d
cas: S37 -- fix the TTL-neutralization (node1-only, before the move-b…
filimonov Jul 17, 2026
b8fdfda
cas: backlog — killed mid-MOVE PARTITION leaves a persistent duplicat…
filimonov Jul 17, 2026
82af4cf
cas: fix #37 over-fencing — retry transient renew failures while the …
filimonov Jul 17, 2026
6733358
cas: wire the renew-retry fence-safety-margin into CasMountRuntime
filimonov Jul 17, 2026
6dd0e62
cas: add throwCasWriteRetryLater/makeCasWriteRetryLaterExceptionPtr (…
filimonov Jul 17, 2026
49ae9fc
cas: reroute CasRefLedger.cpp retry-later throws through throwCasWrit…
filimonov Jul 17, 2026
49f490e
cas: fix gtest_cas_ref_writer.cpp tests broken by the CasRefLedger.cp…
filimonov Jul 17, 2026
e774790
cas: reroute 9 of CasPartWriteTxn.cpp's retry-later throws through th…
filimonov Jul 17, 2026
0be59e8
cas: fix remaining ABORTED->NETWORK_ERROR test fallout from the #37 r…
filimonov Jul 17, 2026
ae01417
cas: rate-limited Warning log for the retry-later helper (fix #37 pha…
filimonov Jul 17, 2026
e93c28a
cas: S39 scenario card -- mount-lease resilience under a degraded-but…
filimonov Jul 17, 2026
9da0c2a
cas: reroute precommitAdd's cleanup-marker-pending throw (fix #37 pha…
filimonov Jul 17, 2026
da137f5
cas: backlog — gtest gate-filter gap (Cas*:CA* excludes ~60 RefWriter…
filimonov Jul 17, 2026
58b4d1b
cas: register the S39 scenario card in cards/__init__.py
filimonov Jul 17, 2026
f47ff08
cas: S39 leg A -- decouple the fault window from the best-effort writ…
filimonov Jul 17, 2026
3104f16
cas: fix stale ABORTED-only relink catch after #37 NETWORK_ERROR reroute
filimonov Jul 17, 2026
82bec8e
cas: S39 -- poll the post-recovery write instead of a single bare INSERT
filimonov Jul 17, 2026
8e39ea2
cas: S39 -- create the table on both replicas + sync before the agree…
filimonov Jul 17, 2026
cdac5ce
cas: backlog CRITICAL — acked-then-lost INSERT data-loss on cross-req…
filimonov Jul 17, 2026
314489f
cas: backlog UPDATE — dedupTrace refutes the orphan-token mechanism; …
filimonov Jul 17, 2026
ef8eda5
cas: data-loss REPRODUCED + TRACED — phantom part-znode via cross-rep…
filimonov Jul 17, 2026
a132e6f
cas: data-loss deeper trace — part_log (RemovePart, no NewPart) + blo…
filimonov Jul 17, 2026
9467f23
cas: backlog UPDATE-2 — data-loss reproduced+traced (block_id znode v…
filimonov Jul 17, 2026
700d28b
cas: data-loss DECISIVE — block_id znode written AFTER durable (order…
filimonov Jul 17, 2026
7d438d7
cas: data-loss WHY-REMOVED — split commit (ZK block_id/part-znode com…
filimonov Jul 17, 2026
f7d337b
cas: data-loss re-trace CORRECTION — CA publish is at commit(:990) AF…
filimonov Jul 17, 2026
e7de5d4
cas: watchdog — rotate round-2 worklog (>40KB) + BACKLOG UPDATE-3 (co…
filimonov Jul 17, 2026
a0a67d5
cas: data-loss ORIGIN (39cf3279652 Task 1.1 regression, B151 was the …
filimonov Jul 17, 2026
95cc316
cas: data-loss AUDIT — upstream plain-S3 violates part-durable-before…
filimonov Jul 17, 2026
5545ca8
cas: data-loss AUDIT-2 — rename_in_transaction semantics (lock-scope,…
filimonov Jul 17, 2026
11077ee
cas: spec — part durability before Keeper commit (close disk txn in r…
filimonov Jul 17, 2026
a000658
cas: watchdog tick — spec committed, awaiting user review
filimonov Jul 17, 2026
f865af0
cas: implementation plan — part durability before Keeper commit (rena…
filimonov Jul 17, 2026
7eb291b
cas: watchdog tick — plan committed, awaiting execution-mode choice
filimonov Jul 17, 2026
f04ce13
cas: proposal — concurrency checks improvements (lock-hold blindspot …
filimonov Jul 17, 2026
a40ab5f
cas: plan+spec review fixes — S40 anti-vacuity gates (docker check=Tr…
filimonov Jul 17, 2026
eb03392
cas: watchdog tick — review fixes landed, awaiting execution go
filimonov Jul 17, 2026
c741465
cas: plan/spec amendment — targeted part_storage_fail_commit_transact…
filimonov Jul 17, 2026
2c1b15e
cas: failing regression test — INSERT dedup vs disk-commit failure (a…
filimonov Jul 17, 2026
82f2620
cas: watchdog tick — T1 complete, T2 in flight
filimonov Jul 17, 2026
28de6d7
cas: watchdog — implT2 stalled post-build, resumed with foreground steps
filimonov Jul 17, 2026
30b22f5
cas: BACKLOG B199 — pre-existing RefWriterRecoverySeal seal-conflict …
filimonov Jul 17, 2026
7748419
cas: close part disk-storage transactions in renameParts — part durab…
filimonov Jul 17, 2026
82d0dc7
cas: watchdog tick — T2 complete (fix landed), S40 mid-run
filimonov Jul 17, 2026
525650f
cas: watchdog tick — S40 PASS 10/10, implT3 wake ping
filimonov Jul 17, 2026
e302c36
cas: S40 scenario — acked-then-lost INSERT gate (S3 outage + replica …
filimonov Jul 17, 2026
8839235
cas: BACKLOG B200 — CA startup mount-probe aborts server on transient…
filimonov Jul 17, 2026
355cd67
cas: B200 amend — S40 gives no recovery signal for the startup-probe …
filimonov Jul 17, 2026
01b5ec7
cas: track the acked-then-lost reproducer (dl_probe) in utils/ca-soak…
filimonov Jul 17, 2026
e08fb29
cas: watchdog tick — dl_probe LOST=0 on fixed binary, S39 in flight
filimonov Jul 17, 2026
dc32ded
cas: BACKLOG — sharpen S37 chaos-leg oracle bug (rows 100 vs 200); mi…
filimonov Jul 17, 2026
4567206
cas: watchdog tick — T4 gates 3.5/4 green, soak mid-run
filimonov Jul 17, 2026
54f47fa
cas: HARD RULE — no known reds, all green (user directive); GREEN-DEB…
filimonov Jul 17, 2026
76fdea4
cas: watchdog tick — all T4 gates green (soak PHASE3 OK), implT4 fini…
filimonov Jul 17, 2026
f938bfe
cas: validation gates for the renameParts durability fix (dl_probe=0 …
filimonov Jul 17, 2026
e398768
cas: BACKLOG GREEN-DEBT — S39 ci-scale param bug (latent since card c…
filimonov Jul 17, 2026
b89e8ed
cas: DL-fix T5 bookkeeping — FIX LANDED (backlog+report), upstream is…
filimonov Jul 17, 2026
70b3604
cas: final-review minors — B208 renumber (B200 collision), stale move…
filimonov Jul 17, 2026
9926f38
cas: watchdog tick — GREEN-DEBT cards in progress
filimonov Jul 17, 2026
9b48a53
cas: commit the long-uncommitted TXN-ONE-PIPELINE spec revision (eage…
filimonov Jul 17, 2026
a1e2717
cas: GREEN-DEBT in progress (paused) — S37 oracle self-grounding + MO…
filimonov Jul 17, 2026
75dfccc
cas: campaign tails swept at session pause — s15 gc_shards8 variant (…
filimonov Jul 17, 2026
fd446a4
cas: session pause — full resume state recorded (DL-fix landed+gated;…
filimonov Jul 17, 2026
15754de
cas: sweep last stray tail — uncommitted 2026-07-13 worklog edit
filimonov Jul 17, 2026
6d509b6
Merge remote-tracking branch 'altinity/antalya-26.6' into cas-gc-rebuild
filimonov Jul 17, 2026
d8b401f
cas: comment denoise sweep — self-contained rationale, no internal do…
filimonov Jul 17, 2026
f89d515
cas: rewrite directory READMEs as a maintainer's guide
filimonov Jul 17, 2026
d072f9e
cas: remove confirmed-dead code
filimonov Jul 17, 2026
bdf803a
cas: remove the vestigial CoordinatorPlan policy object
filimonov Jul 17, 2026
a6a0069
cas: fold CasSourceEdgeMarkers.h into CasRecordStreamFormat.h
filimonov Jul 17, 2026
b75cae7
cas: untangle namespace and include debris left by file concatenation
filimonov Jul 17, 2026
f094ee6
cas: merge DB::ContentAddressed into DB::Cas
filimonov Jul 17, 2026
a474556
cas: remove the dead ShardIncarnation type
filimonov Jul 17, 2026
f6bdfde
cas: reshape the blob-hash/digest file family around honest names
filimonov Jul 17, 2026
7eb246d
cas: remove RoundReport::meta_write_anomalies — a counter with no con…
filimonov Jul 17, 2026
927ea14
cas: fix false GC-lease steal — heartbeat seq compared across differe…
filimonov Jul 17, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
3 changes: 3 additions & 0 deletions .gitignore
Original file line number Diff line number Diff line change
Expand Up @@ -198,3 +198,6 @@ tests/casa_del_dolor/_instances*
ci/praktika/json_test.html
ci/praktika/json_test.html.gz
ci/praktika/json.html.gz

# SDD scratch (briefs, reports, review diffs, progress ledger) — never committed
.superpowers/
16 changes: 16 additions & 0 deletions ci/defs/job_configs.py
Original file line number Diff line number Diff line change
Expand Up @@ -777,6 +777,22 @@ class JobConfigs:
runs_on=RunnerLabels.ARM_SMALL,
requires=[ArtifactNames.CH_ARM_BINARY_GH],
),
# Content-addressed disk as the default MergeTree storage (CAS M6 drop-in). Mirrors the
# "s3 storage" variant but installs only content_addressed_storage_policy_for_merge_tree_by_default.xml.
Job.ParamSet(
parameter="arm_binary, content_addressed storage, parallel",
runs_on=RunnerLabels.ARM_MEDIUM_CPU,
requires=[ArtifactNames.CH_ARM_BINARY],
),
# Content-addressed disk over S3 (minio) as the default MergeTree storage — the real-S3
# (north star) counterpart of the local-object-storage variant above. minio is started
# by the stateless job itself; installs only
# content_addressed_s3_storage_policy_for_merge_tree_by_default.xml.
Job.ParamSet(
parameter="arm_binary, content_addressed s3 storage, parallel",
runs_on=RunnerLabels.ARM_MEDIUM_CPU,
requires=[ArtifactNames.CH_ARM_BINARY],
),
)
functional_tests_jobs_coverage = common_ft_job_config.parametrize(
*[
Expand Down
20 changes: 19 additions & 1 deletion ci/jobs/functional_tests.py
Original file line number Diff line number Diff line change
Expand Up @@ -142,6 +142,8 @@ def run_tests(
"old analyzer": "--analyzer",
"WasmEdge": "--wasm-engine wasmedge",
"s3 storage": "--s3-storage",
"content_addressed storage": "--content-addressed-storage",
"content_addressed s3 storage": "--content-addressed-s3-storage",
"DatabaseReplicated": "--db-replicated",
"DatabaseOrdinary": "--db-ordinary",
"wide parts enabled": "--wide-parts",
Expand All @@ -155,6 +157,8 @@ def run_tests(

OPTIONS_TO_TEST_RUNNER_ARGUMENTS = {
"s3 storage": "--s3-storage --no-stateful",
"content_addressed storage": "--content-addressed-storage",
"content_addressed s3 storage": "--content-addressed-s3-storage",
"ParallelReplicas": "--no-zookeeper --no-shard --no-parallel-replicas",
"AsyncInsert": " --no-async-insert",
"DatabaseReplicated": " --no-stateful --replicated-database",
Expand Down Expand Up @@ -241,6 +245,7 @@ def main():
is_targeted_check = False
is_bugfix_validation = False
is_s3_storage = False
is_content_addressed_s3 = False
is_azure_storage = False
is_database_replicated = False
is_shared_catalog = False
Expand Down Expand Up @@ -294,8 +299,13 @@ def main():
is_excluded_from_llvm = True
if "per_test_coverage" in to:
is_per_test_coverage = True
if "s3 storage" in to:
if "s3 storage" in to and "content_addressed" not in to:
# The content-addressed-over-s3 variant ("content_addressed s3 storage") installs
# only its own default policy and must not pull in the s3 stateful-data / encrypted
# storage machinery, so it is deliberately excluded from is_s3_storage.
is_s3_storage = True
if "content_addressed s3 storage" in to:
is_content_addressed_s3 = True
if "azure" in to:
is_azure_storage = True
if "DatabaseReplicated" in to:
Expand Down Expand Up @@ -636,6 +646,14 @@ def main():

def start():
res = CH.start_minio(test_type="stateless") and CH.start_azurite()
if res and is_content_addressed_s3:
# The CA-over-S3 pool lives on RustFS (M-W D-W8): the incarnation pool
# needs ENFORCED conditional deletes, which MinIO OSS lacks (the
# fail-closed capability probe rejects it). start_rustfs wipes its data
# dir per run, so no pool state bleeds between runs (the local-CA
# analogue is the per-run server-store wipe). MinIO keeps the non-CA
# s3 disks.
res = CH.start_rustfs()
res = res and CH.start()
res = res and CH.wait_ready()
if res:
Expand Down
11 changes: 11 additions & 0 deletions ci/jobs/scripts/check_style/check_cpp.sh
Original file line number Diff line number Diff line change
Expand Up @@ -462,6 +462,17 @@ xargs < "$STYLE_TMPDIR/all_excluded" rg -n '\bassert[[:space:]]*\(' |
echo "Use chassert instead of assert"
} > "$O.18" 2>&1 &

# 19: CAS wiring must not mutate committed refs through raw Cas::Store / Cas::Build (spec
# docs/superpowers/specs/2026-07-08-cas-part-folder-cache-design.md): committed part-ref mutations
# go through CachedPartFolderAccess (dot-syntax on the partAccess() reference). Best-effort textual
# guard: Core/ (the protocol implementation) and the facade itself are exempt.
{
find $ROOT_PATH/src/Disks/DiskObjectStorage/MetadataStorages/ContentAddressed -maxdepth 1 \( -name '*.h' -or -name '*.cpp' \) 2>/dev/null |
grep -v 'CachedPartFolderAccess' |
xargs -r rg -n -e '->(dropRef|updateRefPayload|dropNamespace|promote)\(' &&
echo "Committed part-ref mutations in CAS wiring must go through CachedPartFolderAccess (docs/superpowers/specs/2026-07-08-cas-part-folder-cache-design.md)"
} > "$O.19" 2>&1 &

# Wait for all parallel checks to complete, then output results in order
wait
cat "$O".* 2>/dev/null
Expand Down
50 changes: 50 additions & 0 deletions ci/jobs/scripts/clickhouse_proc.py
Original file line number Diff line number Diff line change
Expand Up @@ -163,6 +163,56 @@ def start_minio(self, test_type):
print("Failed to start minio")
return False

def start_rustfs(self):
# RustFS backs the content-addressed-over-S3 pool (M-W D-W8): the incarnation pool needs
# ENFORCED conditional operations (a wrong-token DELETE must fail with 412), which MinIO
# OSS lacks - the CA disk's fail-closed capability probe rejects it. The static binary
# lives at ci/tmp/rustfs (extracted from rustfs/rustfs:1.0.0-beta.8); the data dir is
# wiped per run so no pool state bleeds between runs. MinIO keeps serving the non-CA s3
# disks on its own port.
rustfs_bin = f"{temp_dir}/rustfs"
if not Path(rustfs_bin).is_file():
print(f"rustfs binary not found at {rustfs_bin}")
return False
data_dir = f"{temp_dir}/rustfs_data"
Shell.check(f"rm -rf {data_dir} && mkdir -p {data_dir}", verbose=True)
# Disable the background data-scanner and auto-heal manager (B93). On a single-disk
# ephemeral test pool they do no useful work (no parity to heal from; data-usage/bitrot
# accounting on throwaway data is pointless) but their cost is NOT free: the scanner walks
# the whole object tree (CPU grows with object count - observed ~120% sustained after the
# pool reached ~177k objects in a full lane) and the heal manager's 10s auto-disk-scan
# takes namespace locks, producing periodic multi-minute bursts of 503 ServiceUnavailable
# (NamespaceLockQuorumUnavailable) that stalled client I/O and caused ~50 test timeouts.
# Client GET/PUT/LIST/DELETE do not depend on either service, so disabling them is safe.
# Env names: RUSTFS_SCANNER_ENABLED/RUSTFS_HEAL_ENABLED (the RUSTFS_ENABLE_* forms are
# deprecated in 1.0.0-beta.8).
command = (
f"RUSTFS_SCANNER_ENABLED=false RUSTFS_HEAL_ENABLED=false "
f"{rustfs_bin} server --address 0.0.0.0:11121 "
f"--access-key clickhouse --secret-key clickhouse {data_dir}"
)
with open(f"{temp_dir}/rustfs.log", "w") as log_file:
self.rustfs_proc = subprocess.Popen(
command, stdout=log_file, stderr=subprocess.STDOUT, shell=True
)
print(f"Started rustfs asynchronously with PID {self.rustfs_proc.pid}")

if not Shell.check(
"curl -s -o /dev/null -w '%{http_code}' http://127.0.0.1:11121/ | grep -qE '403|200'",
verbose=False,
retries=6,
):
print("Failed to start rustfs")
return False
# The `test` bucket the storage policy expects.
res = Shell.check(
"/mc alias set carustfs http://localhost:11121 clickhouse clickhouse && /mc mb --ignore-existing carustfs/test",
verbose=True,
)
if not res:
print("Failed to create rustfs test bucket")
return res

def start_azurite(self):
# Raise the open files limit before launching azurite-rs.
# Each concurrent test query opens a TCP connection plus an in-memory
Expand Down
5 changes: 4 additions & 1 deletion contrib/CMakeLists.txt
Original file line number Diff line number Diff line change
Expand Up @@ -236,6 +236,10 @@ add_contrib(simdcomp-cmake simdcomp)

add_contrib (numactl-cmake numactl)

# CRC32C: a tiny, dependency-free checksum library. Built unconditionally because the content-addressed
# storage core (CasRunFile) uses it for per-block integrity; google-cloud-cpp also depends on it.
add_contrib (crc32c-cmake crc32c)

# Google Cloud Cpp
if(ENABLE_LIBRARIES AND (OS_LINUX OR OS_DARWIN OR OS_FREEBSD) AND (ARCH_AMD64 OR (ARCH_AARCH64 AND NOT NO_ARMV81_OR_HIGHER)))
set(ENABLE_GOOGLE_CLOUD_CPP_DEFAULT ON)
Expand All @@ -245,7 +249,6 @@ endif()
option(ENABLE_GOOGLE_CLOUD_CPP "Enable Google Cloud Cpp" ${ENABLE_GOOGLE_CLOUD_CPP_DEFAULT})
if(ENABLE_GOOGLE_CLOUD_CPP)
add_contrib (nlohmann-json-cmake nlohmann-json)
add_contrib (crc32c-cmake crc32c)
add_contrib (google-cloud-cpp-cmake google-cloud-cpp) # requires grpc, protobuf, absl, nlohmann's json, crc32c
else()
message(STATUS "Not using Google Cloud Cpp")
Expand Down
Original file line number Diff line number Diff line change
@@ -0,0 +1,67 @@
---
description: 'System table containing per-round records of the content-addressed (CA) MergeTree garbage collector.'
sidebar_label: 'content_addressed_garbage_collection_log'
sidebar_position: 30
slug: /operations/system-tables/content_addressed_garbage_collection_log
title: 'system.content_addressed_garbage_collection_log'
doc_type: 'reference'
---

## Description {#description}

The `system.content_addressed_garbage_collection_log` table contains per-round records of the
content-addressed (CA) MergeTree garbage collector. For every garbage-collection round it stores a
`Start` row and a `Finish` row (like `system.part_log` stores events per data part), with the counts
of objects marked and deleted, the round duration, the outcome, and a per-round `ProfileEvents`
delta.

Rounds are emitted both by the background GC scheduler (`trigger = 'Scheduled'`) and by the
synchronous [`SYSTEM CONTENT ADDRESSED GARBAGE COLLECTION`](/sql-reference/statements/system#content-addressed-garbage-collection)
command (`trigger = 'Manual'`).

The table is created only if the `content_addressed_garbage_collection_log` server setting is
specified (it is enabled by default in the shipped `config.xml`).

## Columns {#columns}

- `hostname` ([LowCardinality(String)](/sql-reference/data-types/lowcardinality)) — Host name of the server executing the round.
- `event_date` ([Date](/sql-reference/data-types/date)) — Event date.
- `event_time` ([DateTime](/sql-reference/data-types/datetime)) — Event time.
- `event_time_microseconds` ([DateTime64(6)](/sql-reference/data-types/datetime64)) — Event time with microseconds precision.
- `event_type` ([Enum8](/sql-reference/data-types/enum)) — `Start` or `Finish` of a GC round.
- `disk_name` ([LowCardinality(String)](/sql-reference/data-types/lowcardinality)) — The content-addressed disk (pool) the round ran on.
- `gc_id` ([String](/sql-reference/data-types/string)) — The GC scheduler instance id (which mounter ran the round).
- `trigger` ([Enum8](/sql-reference/data-types/enum)) — `Scheduled` (background tick) or `Manual` (`SYSTEM` command).
- `round` ([UInt64](/sql-reference/data-types/int-uint)) — The GC round number (`0` on a `Start` row).
- `outcome` ([Enum8](/sql-reference/data-types/enum)) — `Success`, `NotALeader`, or `Error` (meaningful on a `Finish` row). `NotALeader` means another mounter held the GC lease; `Error` means the round threw.
- `candidates_marked` ([UInt64](/sql-reference/data-types/int-uint)) — Objects retired (marked) this round.
- `objects_deleted` ([UInt64](/sql-reference/data-types/int-uint)) — Objects physically deleted this round.
- `objects_absent` ([UInt64](/sql-reference/data-types/int-uint)) — Retire candidates found already absent.
- `objects_replaced` ([UInt64](/sql-reference/data-types/int-uint)) — `412`-saves: a resurrection won the race against the delete (a health metric).
- `objects_spared` ([UInt64](/sql-reference/data-types/int-uint)) — Candidates spared because their in-degree was greater than zero at recheck.
- `children_cascaded` ([UInt64](/sql-reference/data-types/int-uint)) — Child edges freed by the cascade this round.
- `duration_ms` ([UInt64](/sql-reference/data-types/int-uint)) — The round wall-clock duration (on a `Finish` row).
- `error` ([String](/sql-reference/data-types/string)) — The exception text when `outcome = 'Error'`.
- `ProfileEvents` ([Map(LowCardinality(String), UInt64)](/sql-reference/data-types/map)) — The per-round `ProfileEvents` delta (the `Cas*` counters and S3/disk events for this round).

## Example {#example}

```sql
SELECT
event_type,
disk_name,
trigger,
outcome,
candidates_marked,
objects_deleted,
duration_ms
FROM system.content_addressed_garbage_collection_log
ORDER BY event_time_microseconds DESC
LIMIT 2
FORMAT Vertical;
```

## See Also {#see-also}

- [`SYSTEM CONTENT ADDRESSED GARBAGE COLLECTION`](/sql-reference/statements/system#content-addressed-garbage-collection) — run one GC round synchronously.
- [`system.part_log`](/operations/system-tables/part_log) — the analogous per-part event log.
12 changes: 12 additions & 0 deletions docs/en/sql-reference/statements/system.md
Original file line number Diff line number Diff line change
Expand Up @@ -457,6 +457,18 @@ Wait until all asynchronously loading data parts of a table (outdated data parts
SYSTEM WAIT LOADING PARTS [ON CLUSTER cluster_name] [db.]merge_tree_family_table_name
```

### SYSTEM CONTENT ADDRESSED GARBAGE COLLECTION {#content-addressed-garbage-collection}

Runs one garbage-collection round of the content-addressed (CA) MergeTree garbage collector synchronously and node-local: it reclaims content-addressed objects that are no longer referenced by any part. This is the on-demand counterpart of the background GC scheduler; it is useful for tests and diagnostics.

```sql
SYSTEM CONTENT ADDRESSED GARBAGE COLLECTION [ON CLUSTER cluster_name] [disk_name]
```

When `disk_name` is given, the round runs on that content-addressed disk only; targeting a non-content-addressed disk raises an exception. When `disk_name` is omitted, one round runs on every content-addressed disk configured on the node; if none are configured, the command raises an exception.

Each round is recorded in [`system.content_addressed_garbage_collection_log`](/operations/system-tables/content_addressed_garbage_collection_log) as a `Start` and a `Finish` row (with `trigger = 'Manual'`).

## Managing ReplicatedMergeTree Tables {#managing-replicatedmergetree-tables}

ClickHouse can manage background replication related processes in [ReplicatedMergeTree](/engines/table-engines/mergetree-family/replication) tables.
Expand Down
Loading
Loading