# Backlog — melinoe
## ATLAS-MELINOE-PARTITION-PANIC-ORACLE-2026-08-20 — Assert recovered panic values [patch, complete]
**Finding:** the panic-recovery regression used `is_err()` for both panic
closures and `is_none()` for the recovered payload mutex. Those checks did not
prove the captured panic values or the empty post-recovery state.
**Outcome:** both `catch_unwind` results now match `Err` and assert their
exact static-string payloads. The recovered empty mutex state is compared as
`Option<()> == None`, preserving the empty-value contract without an
existence-only assertion.
**Evidence (2026-08-20):** clean lane branch
`fix/melinoe-panic-oracle` is based on fetched `origin/main` `689f562`.
All-feature locked all-target check and warning-denied Clippy pass; no-default
locked all-target check and Clippy pass. All-feature Nextest passes `127/127`,
no-default Nextest `52/52`; all-feature doctests pass `31/31`, no-default
doctests `20/20`; Rustdoc is warning-free. The conformance scan reports
`existence_only_assertions: 0` versus `2` on the fetched default, with every
other class unchanged. A temporary `take_panic_payload` mutation to `None`
fails the focused recovery test; the implementation was restored and the
focused test passes.
**Delivery:** commit `67e177d` is published on
`fix/melinoe-panic-oracle`. GitHub compare confirms exact base `689f562` →
head `67e177d` is one commit ahead with four intended files. Draft PR creation
was rejected by the GitHub connector with HTTP 403 `Resource not accessible by
integration`; no hosted gate or merge is claimed. Re-open publication when
repository write authorization is available. The dirty detached primary
checkout remains untouched.
## Atlas in-house replacement roadmap — melinoe slice [minor]
melinoe is the capability/ownership-proof foundation. The Atlas GPU program
(the `hephaestus` device substrate — atlas ADR 0001 — used by coeus/apollo on wgpu +
CUDA, with mnemosyne device pools) wants compile-time proofs for device-buffer ownership:
- [x] [minor] Stage D1 support: a documented device-buffer ownership-transfer pattern —
moving a `SyncRegionToken` transfers write capability across host/device/stream; a
`SharedReadToken` fans out concurrent device reads; `BrandedAtomic` covers fence/
counter values touched on both sides. Add a real contract test over the lowest
available device/stream abstraction; do not substitute a mock buffer.
## Active
- [x] [patch] Verify the declared Rust 1.65 MSRV with a standalone locked
`cargo check --all-targets --all-features` workflow. The current Atlas
overlay is not a valid floor oracle because peer provider manifests can
require newer Cargo. Hosted run `31785253730` passed at PR #16 head
`6e6a181`; the merged default is `6cad6e7`.
- [x] [minor] Add generic branded-vector generation through
`BrandedVec::from_fn` and `collections::with_generated`. The fresh
higher-ranked brand remains inside the callback while its result escapes;
generated cells compose with the existing partition driver, and
`into_boxed_cells` supports Themis's branded placement container. Keep
topology providers above Melinoe: Themis-derived worker counts enter through
`PartitionPlan::parts`, not a reverse dependency. Evidence: all-feature
Nextest 125/125, alloc-only Nextest 79/79, strict Clippy for both feature
surfaces, offline check, documentation and semver gates, Themis branded
placement compile, and CFDrs `cfd-core` Nextest 269/269 through the Atlas
overlay.
- [x] [patch] Consolidate conditional-atomic ordering resolution behind one
generic `OrderingSource` strategy. Runtime `Ordering` and sealed ZST
`AtomicOrder` policies now share the same operation bodies; static policy
monomorphizations retain their associated ordering constants without a
runtime policy branch. No public API or consumer migration is required.
Evidence: ordering-role unit coverage, all-feature Nextest 126/126, strict
Clippy, and offline check.
- [x] [patch] Consolidate fresh higher-ranked brand minting behind the private
GAT-based `TokenFamily` factory. Exclusive, cross-thread region, thread-local,
scoped-worker, and reentrant entry points now share one brand proof boundary
while retaining their distinct token auto-trait postures. Public signatures
and consumer behavior remain unchanged. Evidence: all-feature Nextest
126/126, alloc-only Nextest 80/80, strict Clippy for both feature surfaces,
offline check, 31 doctests, rustdoc, and diff checks.
- [x] [patch] Repair the conditional-atomic README link after the atomic
module hierarchy split; the documented `BrandedAtomic` source now resolves to
`src/atomic/branded.rs`.
- [x] [patch] Split the 513-line `BrandedVec` implementation into named
generation, operation, view, partition, iterator, and manifest modules.
Public exports and signatures remain unchanged; the largest resulting leaf
is 157 lines. Evidence: all-feature Nextest 126/126, alloc-only Nextest
80/80, strict Clippy for both feature surfaces, 31 doctests, rustdoc,
rustfmt, offline check, and diff checks.
- [x] [minor] Move `CellCowExt`'s `Clone` requirement from the public trait
boundary to the four methods that construct `Cow` values. Non-`Clone`
branded cells can now satisfy the capability boundary while clone-dependent
operations retain explicit method bounds. Evidence: all-feature Nextest
127/127, alloc-only Nextest 81/81, strict Clippy for both feature surfaces,
31 doctests, rustdoc, offline check, rustfmt, and diff checks.
- [x] [patch] Consolidate wrapped
`BrandedVecDeque` `Cow` construction through one generic segment helper and
document the transparent-storage safety contracts for deque conversions.
Preserve the existing borrow/retain policy semantics and public methods;
prove contiguous and wrapped value behavior through the existing deque Cow
suite plus focused feature gates. Evidence: focused deque Nextest 22/22,
all-feature Nextest 127/127, alloc-only Nextest 81/81, strict Clippy on both
feature surfaces, 31 doctests, rustdoc, rustfmt, and diff checks.
- [x] [patch] Harden registered partition panic recovery against mutex poisoning.
`sync::scoped::partition::driver_core` now recovers the first captured panic
payload with `PoisonError::into_inner` both when task wrappers report a panic
and when the executor tears down the manually managed result buffer. This
prevents a poisoned payload mutex from masking the original panic; the
existing panic-safety drop-count tests continue to cover initialized-result
cleanup. A focused regression poisons the payload mutex, reports a second
panic, and verifies the first payload remains recoverable. Evidence
(2026-08-06): `cargo check --all-features`, strict
`cargo clippy --all-targets --all-features -- -D warnings`, Nextest **122/122**,
doctests **29/29**, `cargo check --no-default-features`, rustfmt, and diff
checks all pass. Implementation scope is one provider-local source file;
no consumer or peer-owned files changed.
- [x] [patch] Move segmented `Cow` assembly into the existing `cell::cow`
policy owner. `BrandedVecDeque` remains a consumer of the sealed `CowPolicy`
seam; contiguous zero-copy and wrapped owned behavior remain unchanged, with
no public API or peer-owned file changes. Evidence: focused branded-deque
Nextest 22/22, all-feature and alloc-only Nextest, strict Clippy on both
feature surfaces, 31 doctests, rustdoc, rustfmt, and diff checks.
- [x] [patch] Publish future releases through a pinned GitHub Actions workflow
using crates.io OIDC Trusted Publishing and no stored registry credential.
- [x] [patch] Fix executor-state test interference in `tests/partition.rs`.
The executor registry is process-global, so `register_parallel_executor`/
`clear` windows leaked into concurrently running unsynchronized tests: a
non-guard test could observe a registered deterministic executor mid-flight,
overwrite the shared `EXECUTED_TASKS` side-channel, break a guard test's
driver assertions, and the failed guard's unwind then poisoned
`EXECUTOR_TEST_LOCK` and cascaded into the next guard test. Fix: every test
that touches the driver — all partition read/write tests in the module plus
the proptests, not just the registration tests — acquires `ExecutorTestGuard`
(moved to file scope so the proptests can see it), which both serializes
registration windows and guarantees a clean registry baseline; the guard
additionally recovers a poisoned lock (`PoisonError::into_inner`) so one
genuine failure never cascades. Tests still exercise real concurrency inside
their own partition calls. Evidence (2026-08-11): all-feature Nextest
127/127, no-default-features Nextest 52/52, doctests 31/31, strict Clippy on
both feature surfaces, rustfmt, and 8/8 repeated parallel partition-suite
runs. Pre-existing on `origin/main`; unrelated to the book/`mdbook-test`
change.
- No Melinoe-local item remains in progress; the 0.10.0 executor capability is
ready for upstream publication and downstream Moirai lock refresh.
## Next
- <a id="partition-spawn-crossover"></a>[minor] Guard the scoped-thread
partition fallback against shard counts whose work cannot pay for a thread
spawn, **and prefer the pool-backed path**. Measured 2026-09-11 on a 24-core
x86_64 host: the fallback's cost is linear in shard count at **~30 µs/shard**
and essentially independent of work — `cells=8` and `cells=65536` both cost
~250 µs at 8 shards, despite 8192× more elements. `parts=1` costs 40 ns,
`parts=2` costs 93 µs (a 2300× cliff from one spawn). Break-even is **~130 µs
of total work** (≈ `cells × cost ≳ 50,000` element-ops at 4 threads); below
that the parallel path is *slower* than running inline.
`driver_core::drive` spawns `min(parts, n) − 1` OS threads unconditionally, so
every small-region call is pure loss.
Note this is the **fallback**, not the production path: moirai's
`moirai-parallel::melinoe_ext::{par_partition_for_each, par_partition_map}`
already routes partitioning onto the shared work-stealing pool and bypasses
OS-thread spawning entirely, and `CFDrs` uses it
(`crates/cfd-core/src/physics/fluid_dynamics/operations.rs:47`). So the
priority is not to tune the spawn path but to (a) route through the pool, and
(b) document that consumers doing fine-grained work must register an executor.
Any added floor should reuse moirai's own compile-time `ExecutionPolicy`
(`moirai-parallel/src/policy.rs`) rather than introduce a second threshold
concept in melinoe. Blocked on a public-behaviour decision, because
`partition_map`'s `parts` is documented as an exact shard count and a guard
that silently runs inline changes that contract. Evidence:
`benches/access.rs::bench_partition_driver` plus the scaling probe recorded in
the 2026-09-11 workspace log.
- <a id="moirai-melinoe-ext-execution-policy"></a>[minor] (cross-repo, moirai)
`moirai-parallel::melinoe_ext::{par_partition_for_each, par_partition_map}`
dispatch to `global().for_each_indexed(...)` **unconditionally** — no
`ExecutionPolicy` parameter and no size check — so a 4-cell region is
parallelized as eagerly as a million-cell one. This is precisely the failure
mode `Adaptive` exists to prevent, and the policy machinery is already in the
same crate (`moirai-parallel/src/policy.rs`, with the crossover already
tabulated in `ADAPTIVE_PARALLEL_THRESHOLD`'s docs). The module's own tests
call it with 16 and 10 elements. Fix must not break the live `CFDrs` consumer
(`crates/cfd-core/src/physics/fluid_dynamics/operations.rs:47`): either add
`P: ExecutionPolicy` as a type parameter with a `Parallel` default, or add
parallel `*_with_policy` functions and leave the existing signatures as
`Parallel`.
- <a id="moirai-executor-registration-order"></a>[minor] (cross-repo, moirai)
`global_arc()` calls `melinoe::register_parallel_executor` **inside** its
`OnceLock` initializer (`moirai-executor/src/lib.rs:141-154`), so melinoe's
driver routes through the moirai pool only after something has first touched
moirai's `global()`. A consumer calling `melinoe::sync::partition_map` earlier
silently gets the ~54 µs-per-thread spawn fallback. The passing test
`placement.rs:162 test_melinoe_partition_routing` opens with
`let _exec = crate::global();` — that line is load-bearing and the ordering
hazard is undocumented. Either register eagerly from a constructor/`ctor`
path, or document the required ordering at the melinoe registration API.
- <a id="semver-registry"></a>[patch] After registry publication, switch
`cargo-semver-checks` from the `--baseline-rev` git workflow (now established)
to the default crates.io baseline, and re-run once semver-checks supports the
newer rustdoc-JSON format so its lints execute rather than skip.
## Closed
- <a id="parallel-executor-capability"></a>[major] Replaced the
`ParallelExecutorFn` domain alias with an unsafe `ParallelExecutor` trait and
a transparent function-pointer capability. The associated `run_indexed`
entry point stores no fabricated receiver; a non-zero-sized implementation is
covered at the registration boundary. Evidence: compile-time layout assertion,
partition and panic tests, doctests, Clippy/rustdoc, focused Miri executor-path
tests, and major-change semver classification. Decision: ADR 0001.
- <a id="atlas-device-contract"></a>[minor] Added the Atlas device-buffer
ownership-transfer contract crate in commit `375108b`; the workspace now
carries the real Hephaestus-backed contract instead of an uncommitted plan.
- <a id="halo-workspace-crate"></a>[minor] Added `crates/halo` as the
Melinoe-backed protective collection crate. The first migrated vertical slice
is `halo::BrandedVec<'brand, T>`, backed directly by
`Vec<MelinoeCell<'brand, T>>` and Melinoe's permit, zero-copy slice, and
conditional `Cow` traits. Evidence: `cargo check -p halo` plus targeted tests,
docs, and benchmark harness verification in the delivering change.
- <a id="halo-branded-vec-ops"></a>[minor] Extended `halo::BrandedVec` with
owned vector structural operations and `std`-gated partitioned mutation/map
adapters over Melinoe `PartitionPlan` shards. Evidence: default and
`--no-default-features` Halo builds, value-semantic structural/concurrent
tests, workspace nextest/clippy/doc gates, and benchmark harness compilation.
- <a id="halo-read-partitions"></a>[minor] Exposed
`PartitionPlan::chunk_len_for` for downstream chunk planning and added
`halo::BrandedVec` read-side partition map/for-each adapters over
permit-gated shared slices. Evidence: Melinoe plan-resolution tests, Halo
shared-shard tests, workspace gates, and benchmark harness compilation.
- <a id="halo-branded-vecdeque"></a>[minor] Migrated the next lowest-risk
upstream Halo collection as `halo::BrandedVecDeque<'brand, T>`:
`std::collections::VecDeque` maps directly to one owned standard container,
unlike the remaining hash/tree/graph collections with broader invariants.
Storage is `VecDeque<MelinoeCell<'brand, T>>`; element, split-slice, `Cow`,
clone, read-partition, and write-partition access are gated through Melinoe
permits/cells instead of a Halo-local `GhostToken` / `GhostCell` layer.
Evidence: value-semantic deque tests and the `branded_deque` Criterion
harness.
- <a id="halo-branded-deque-ops"></a>[minor] Extended `halo::BrandedVecDeque`
with the same `std`-gated partitioned mutation/map adapters as `BrandedVec`
(`partition_map_with`/`partition_for_each_with` for shared reads,
`partition_for_each_mut_with`/`partition_map_mut_with` for exclusive
mutation), via a `DequeShardPlan` that maps the flat logical index range
onto the deque's front/back ring segments — a shard crossing the wrap
boundary is split into two physical subshards sharing one logical offset.
Evidence: contiguous and wrapped-deque correctness tests, a same-logical-
plan consistency check across both mutation and read paths, workspace
nextest/clippy/fmt gates.
- <a id="halo-upstream-migration"></a>[major] Consolidated `crates/halo` into
the root `melinoe` crate (`2e9bf87`). `halo` workspace member removed;
`BrandedVec`, `BrandedVecDeque`, `BrandedDrain`, `BrandedVecDequeDrain` live
in `melinoe::collections` (re-exported at crate root under `alloc` gate).
Single-crate workspace. 121/121 nextest, clippy/rustdoc clean.
- <a id="region-module-hierarchy"></a>[patch] Region module hierarchy split
delivered in 0.6.0. `src/region/mod.rs` is now the documentation/re-export
root, `src/region/shard.rs` owns `WriterShard`, and
`src/region/chunks.rs` owns `ShardChunks` exact-size iteration. Public exports
are unchanged; evidence: partition integration suite and stable gates.
- <a id="default-provider-feature-policy"></a>[patch] Default `parallel` and
`mnemosyne-memory` feature markers delivered. `mnemosyne-memory` forwards to
`alloc`; no dependency cycle to Mnemosyne is introduced. Evidence: Atlas
feature-policy metadata audit, fmt, and diff checks.
- <a id="apollo-boundary-contract"></a>[patch] Apollo-facing zero-copy scratch
boundary contract tests delivered. `Borrowed` ZST policy returns a
pointer-identical `Cow::Borrowed` with zero element clones; `Retained` ZST
policy returns independent owned storage with exactly one clone per element.
Evidence: value-semantic integration tests in `tests/apollo_boundary.rs`.
- <a id="residuals-0-6-0"></a>[patch] 0.6.0 verification residuals resolved:
(1) `cargo-semver-checks` baseline via `--baseline-rev HEAD` — v0.5.0→v0.6.0
reports no semver update required; (2) Miri clean across all nine test suites
(no UB / no data races), covering the previously-pending partition and
projection paths; (3) nightly `cargo clippy --all-targets --all-features -- -D
warnings` clean (the MSYS2 nightly needs `RUSTC_BOOTSTRAP=1` for the
`doc_cfg` feature gate). Feature matrix verified: default, `alloc`,
`--no-default-features`, and nightly `--all-features` build.
- <a id="shard-chunks-exact-size"></a>[minor] `ShardChunks: ExactSizeIterator`
with exact `size_hint`, delivered in 0.6.0. The partition driver reserves
worker capacity from the iterator's exact size, making it the single source of
truth for the shard count; the duplicated `shard_count` helper and
`ResolvedPartitionPlan` struct are removed. Evidence: exact-size and
empty-region value-semantic tests; `partition_driver/empty_region` benchmark
pins the no-spawn / zero-capacity contract.
- <a id="codegen-example-alloc-gate"></a>[patch] `examples/codegen.rs` gated on
`required-features = ["alloc"]` in 0.6.0; restores a clean
`cargo test --no-default-features` build (the example uses alloc-gated
`borrow_cow`).
- <a id="cell-cow-direct"></a>[minor] Direct conditional-Cow boundary methods
(`borrow_cow` / `retain_cow`) delivered in 0.5.0, covering common static
borrow/retain cases without a generic policy parameter.
- <a id="zst-boundary-policies"></a>[minor] ZST boundary and synchronization
policies delivered in 0.4.0. `CellCowExt` covers conditional borrow-or-retain
at the ownership boundary; `AtomicOrder` covers monomorphized atomic
orderings.
- <a id="partition-plan"></a>[minor] Typed multithreading plan surface delivered
in 0.3.0. `PartitionPlan` supports fixed parts, reported hardware
parallelism, and fixed chunk sizes.
- <a id="partition-driver-memory"></a>[patch] Partition driver memory discipline
delivered in 0.2.1. `partition_map` uses overflow-safe ceiling division and
reserves worker handles to the actual non-empty shard count.
- <a id="guard-projection"></a>[minor] Zero-copy guard projection delivered in
0.2.0 with `MelinoeRef`/`MelinoeMut` `map` and `map_split`.
## Cross-repo filing (2026-06-12 stack audit)
- [x] [minor] (0.7.0) Shared thread-local value-cache utility delivered as
`thread_cached!` (macro: TLS statics are declaration-site constructs no
generic type can capture; same sanctioned route as moirai's
`thread_local_static!`). themis `CACHED_NODE` and mnemosyne `CACHED_CPU_ID`
adopt it in the same coordinated change. moirai's `thread_local_static!`
remains separate by design: it serves no_std targets with a different
fallback shape (evaluated 2026-06-12).