Skip to content

[fence 1/9] libsql-server: document the namespace fence contract - #41

Draft
tszymczyszyn-shopify wants to merge 1 commit into
v0.9.30-shopify-patchesfrom
namespace-fence/0-contract
Draft

tszymczyszyn-shopify wants to merge 1 commit into
v0.9.30-shopify-patchesfrom
namespace-fence/0-contract

Conversation

@tszymczyszyn-shopify

@tszymczyszyn-shopify tszymczyszyn-shopify commented Oct 5, 2026 •

Copy link
Copy Markdown

Adds docs/NAMESPACE_FENCE.md, the contract for the operation-owned namespace fence: state model and permission matrix, admin API, durable state, outcome codes and their mapping per protocol, write admission and positive drain, source read fence, target lifecycle, restart and failure semantics, deployment and compatibility, and observability.

This is the final version of the document from the source PR, landed first so the design can be reviewed before any code. The code pieces that follow implement it; none of them edits the document.

Review focus

The state model (section 3), the outcome codes (section 6), and the deployment/compatibility rules (section 13). Agreeing on these first makes the rest of the stack a check against the contract.

Commits

  • libsql-server: document namespace fence contract

Stack

Part 1 of 9, based on v0.9.30-shopify-patches. Retargeted from #35 with no feature change: applied in order, the 9 PRs carry #35's fence diff (stable patch ID 70d97d6a) on v0.9.30-shopify-patches. Review and land bottom-up, restacking after each squash or rebase merge.

Add docs/NAMESPACE_FENCE.md, the contract and design for a durable,
operation-owned namespace fence: source and target state machines and
permission matrix, admin API, stable outcome codes and their mapping to
HTTP, Hrana, gRPC, the write proxy and replication, metastore schema and
CAS semantics, write admission generations and positive drain, read
fence, quarantined target lifecycle and the reusable import capability,
restart and eviction rules, fail-closed metastore recovery, deployment
flag and legacy-binary protection, code-path coverage, test strategy and
the acceptance-test map.

Co-authored-by: Tomasz Szymczyszyn <tomasz.szymczyszyn@shopify.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants