The ADR-008 pg-lo admission POC ran in a standalone crate
(/workspace/alkblobs-pglo-poc): PgLoBackend over the ADR-003/008 trait
contract (including size), 10/10 exact-count sweep-outcome contract
tests, clippy/fmt clean; dockerized postgres:16-alpine on :15432,
POC #5 driver stack (tokio-postgres + deadpool) via SQL lo_* functions,
no new dependency.
Gate verdict: passed, with named deltas.
- Performance: durable put 60-65 MB/s at >=1 MiB, within 1.5x of — and
below 1 MiB beating — durable local fs on this fsync-slow disk;
cached gets 70-180 MB/s single-stream, ~0.7 GB/s aggregate over 16
readers (20-50x behind page-cache fs — the honest named delta)
- Contract: companion table is the list()/size()/CAS authority (never
the catalogs); stage-then-commit; GC-participating lo_unlink delete
- Handles: the tx-scoped descriptor is real but pool-compatible via
descriptorless lo_get(oid, off, len) windows — window gets keep
handle-acquire p99 at 1-6 ms under readers <= pool; held descriptor
is the fallback posture
- Vacuum: pg_largeobject pages churn-reused, never returned; tracked
by autovacuum; rel-size monitoring named as an ops requirement
- Crash/orphan: LO creation is transactional — kill/terminate
mid-write-tx leaves zero orphan pages; the only orphan class is a
committed LO bypassing the companion table (planted, reaped by the
~7 ms/oid sweep; committed content survives byte-exact)
- Harness lessons: lo_lseek is int4 — the 64 variants are the
>2 GiB discipline; shared-table parallel tests are unsound (per-test
CREATE DATABASE isolation)
Docs: new poc-pglo-findings.md; poc-pglo-spec.md status passed;
register OQ-BL-06 #7 marked passed; ADR-008 pg-lo bullet updated
(duplicate bullet removed) + backends-and-dispatch/open-questions
cross-references.
Verification: cargo test --release (10 passed), clippy -D warnings,
fmt --check in /workspace/alkblobs-pglo-poc.