pub struct PoolConfig {
pub path: Option<PathBuf>,
pub max_readers: usize,
pub wal_mode: bool,
pub busy_timeout: Duration,
pub checkout_timeout: Duration,
pub journal_size_limit_bytes: i64,
pub read_only: bool,
pub write_queue_enabled: Option<bool>,
pub write_queue_capacity: usize,
pub write_routing_strict: bool,
pub write_admission_deadline_ms: u64,
pub read_tx_max_age: Duration,
}Expand description
Configuration for the connection pool.
Fields§
§path: Option<PathBuf>Database path. None = in-memory (pool degrades to single connection).
max_readers: usizeNumber of reader connections (default: min(num_cpus, 8)).
wal_mode: boolWAL mode (must be true for pooling to work; default: true).
busy_timeout: DurationBusy timeout per connection (default: 30s).
Overridable via KHIVE_BUSY_TIMEOUT_SECS.
checkout_timeout: DurationTime to wait for a reader connection before returning an error (default: 5s).
Overridable via KHIVE_CHECKOUT_TIMEOUT_SECS.
journal_size_limit_bytes: i64Maximum WAL journal size in bytes before SQLite resets the WAL.
Maps to PRAGMA journal_size_limit. Default: 64 MiB.
Overridable via KHIVE_JOURNAL_SIZE_LIMIT_BYTES.
read_only: boolOpen the database read-only (default: false).
When true, the pool’s writer connection is opened with
SQLITE_OPEN_READ_ONLY (no SQLITE_OPEN_CREATE, so a missing path is
rejected instead of created) and PRAGMA query_only = ON is set on
every connection that can execute SQL. Reader connections are already
opened read-only regardless of this flag.
write_queue_enabled: Option<bool>Route migrated store write paths through the single-writer
WriterTask channel (ADR-067 Component A) instead of the legacy
per-call pool-mutex/standalone-connection path. Enabled by default
for file-backed pools when unset; explicit override always wins.
That default is a compatibility-routing posture subordinate to
ADR-135 Amendment 1 and ADR-136 D1/D2 — the strict-routing default
flip has NOT happened.
The store layer resolves all of its routed write paths at write time;
the classification table in writer_task.rs remains the authoritative
inventory. This tranche does not claim the repository-wide
single-writer guarantee, and the strict default is still evidence-gated.
None means the caller expressed no preference: ConnectionPool::new
resolves it once path is known, defaulting to true for file-backed
pools and false for in-memory ones. Some(_) is an explicit
preference and always wins, in both directions, over that default.
An explicit Some(true) on an in-memory pool is accepted DELIBERATELY
and emits a warning before degrading to the legacy path — an in-memory
pool cannot host a writer task (writer_task::spawn’s
standalone-connection open fails); see
ConnectionPool::writer_task_handle and the
explicit_true_stays_on_for_memory_backed_pool test.
Overridable via KHIVE_WRITE_QUEUE ("1" or "true",
case-insensitive, sets Some(true); any other value sets Some(false);
unset leaves it None).
write_queue_capacity: usizeBounded channel capacity for the WriterTask write queue.
Overridable via KHIVE_WRITE_QUEUE_CAPACITY. Default: 256 pending
operations (ADR-067 Component A recommended default).
write_routing_strict: boolADR-136 D1: when true, every covered store write path that would
otherwise silently degrade to the legacy pool-mutex/standalone-
connection path on a missing or failed WriterTask handle instead
returns an error.
Exercises the store-layer routing tranche toward ADR-135 F2’s
strict-routing precondition without changing behavior for callers that
never set the env var.
Overridable via KHIVE_WRITE_ROUTING (value "strict",
case-insensitive; anything else, or unset, leaves this false).
write_admission_deadline_ms: u64Dedicated admission deadline (ADR-131 Decision 2) bounding ONLY the
wait for capacity on the WriterTask write queue —
WriterTaskHandle::send_bounded/send_top_level_bounded’s default
timeout. Distinct from checkout_timeout, which bounds reader/pool
checkout instead; the two authorities used to be conflated (#1382,
#1643) before this field existed.
Default: 2000 ms. Validated at ConnectionPool::new to fall in
[100, 10000] ms; a value outside that range is a configuration
error (SqliteError::InvalidConfig), never silently clamped into
range.
Overridable via KHIVE_WRITE_ADMISSION_DEADLINE_MS.
read_tx_max_age: DurationMaximum age an explicit cached-reader read transaction
(sql_bridge’s BEGIN-then-reuse path) may reach before its next use
is refused and it is rolled back instead of extending its WAL
snapshot further (#1846). Shares KHIVE_TX_MAX_AGE_SECS with the
ADR-091 Plank 1 visibility sweep in checkpoint.rs so one knob
governs both when an operator is warned about a stale reader and when
that reader’s snapshot is actually released.
Overridable via KHIVE_TX_MAX_AGE_SECS. Default: 120 seconds.
Trait Implementations§
Source§impl Clone for PoolConfig
impl Clone for PoolConfig
Source§impl Debug for PoolConfig
impl Debug for PoolConfig
Auto Trait Implementations§
impl Freeze for PoolConfig
impl RefUnwindSafe for PoolConfig
impl Send for PoolConfig
impl Sync for PoolConfig
impl Unpin for PoolConfig
impl UnsafeUnpin for PoolConfig
impl UnwindSafe for PoolConfig
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
Source§impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> CloneToUninit for Twhere
T: Clone,
Source§impl<T> Instrument for T
impl<T> Instrument for T
Source§fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
Source§fn in_current_span(self) -> Instrumented<Self> ⓘ
fn in_current_span(self) -> Instrumented<Self> ⓘ
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read more