Engine
Engine memory management
Kaveon reserves retained execution state against explicit query budgets and fails closed when a bounded operator cannot continue safely.
Alpha boundary: coordinator and worker execution propagate query budgets into retained operator state. Logical reservations are not a universal process RSS ceiling: decoders, runtime overhead, and retained caller buffers require separate limits and measurement.
Budget hierarchy
- The admission controller reserves a complete query budget before execution.
- The query pool atomically enforces one hard limit across its operators.
- Named operator accounts expose current and peak reserved bytes.
- RAII reservations return capacity on success, error, cancellation, or destruction.
Operator behavior
| Operator | Current bounded behavior |
|---|---|
| Sort / TopN | Opt-in reservations, bounded Arrow IPC spill runs, and fixed-fan-in merge. |
| Hash aggregate | Accounts typed group/distinct state; opt-in partitioned Single/Partial/Final spill. Unsplittable skew fails closed. |
| Hash join | Accounts retained inputs, build index, match bitmap, and output growth; opt-in partitioned spill. |
| Window / set operations | Accounts buffered state and expression workspaces; cancellation checks interrupt long loops. |
| Exchange | Bounded disk-backed coordinator exchange storage, query quotas, download leases, and cleanup accounting. |
What remains
Pressure and worker-loss fixtures provide local evidence, including fail-closed skew and disk-quota cases. High-cardinality distributed aggregation, full pipeline backpressure, sustained soak tests, and cloud fault testing remain qualification gates. Do not equate a configured query budget with a hard process RSS limit.