Shared reservation arithmetic. Currently the page arena uses this ledger;
it is not a whole-process RSS cap. Constrained stores additionally bound
WAL/record sizes and allocator bookkeeping counts through ResourceLimits.
Exhaustion is fallible, including arithmetic overflow.
Building a large tree by repeated insertion means one descent and one random
write per key. Sorting first and packing bottom-up means one sequential pass.
2i: PostGIS-geography math, ported from e1 (already calibrated equal to
PostGIS to float precision there). Distances = Vincenty’s inverse
formula on the WGS84 ellipsoid, in METRES; areas = spherical excess on
the authalic sphere, in SQUARE METRES; point-in-polygon = planar
even-odd crossing in coordinate space (the named subset deviation:
correct away from poles/antimeridian; geography-PostGIS itself offers
ST_Covers for the sphere-true predicate). Functions take (lat, lon) –
PostGIS textual order; GeoJSON stores [lon, lat] and converters own
the flip. Rings use the internal [[lat, lon], …] layout.
2n: the reader table – how the writer learns the oldest generation any
live snapshot reader still needs, so page recycling never pulls a page
out from under one.
Structural verification. verify_published_tree is public so a live
database’s shape can be proven after a graft; the rest stays internal.
Independent verification for replacement trees.