Skip to documentation
Documentation
AlphaVerified September 4, 2026
Engine

Engine memory management

Kaveon reserves retained execution state against explicit query budgets and fails closed when a bounded operator cannot continue safely.

Alpha boundary: coordinator and worker execution propagate query budgets into retained operator state. Logical reservations are not a universal process RSS ceiling: decoders, runtime overhead, and retained caller buffers require separate limits and measurement.

Budget hierarchy

  1. The admission controller reserves a complete query budget before execution.
  2. The query pool atomically enforces one hard limit across its operators.
  3. Named operator accounts expose current and peak reserved bytes.
  4. RAII reservations return capacity on success, error, cancellation, or destruction.

Operator behavior

OperatorCurrent bounded behavior
Sort / TopNOpt-in reservations, bounded Arrow IPC spill runs, and fixed-fan-in merge.
Hash aggregateAccounts typed group/distinct state; opt-in partitioned Single/Partial/Final spill. Unsplittable skew fails closed.
Hash joinAccounts retained inputs, build index, match bitmap, and output growth; opt-in partitioned spill.
Window / set operationsAccounts buffered state and expression workspaces; cancellation checks interrupt long loops.
ExchangeBounded disk-backed coordinator exchange storage, query quotas, download leases, and cleanup accounting.

What remains

Pressure and worker-loss fixtures provide local evidence, including fail-closed skew and disk-quota cases. High-cardinality distributed aggregation, full pipeline backpressure, sustained soak tests, and cloud fault testing remain qualification gates. Do not equate a configured query budget with a hard process RSS limit.