Shared read performance
mod.rs owns per-process decoded caches, diagnostic counters and a task-local
context for explicit read requests. No cached response, cart, inventory or identity
is stored. Authorization remains in the existing middleware before read admission.
settings.rs/settings.sql: tenant/channel key; one PostgreSQL statement checks base and override UUIDs in one MVCC snapshot. Warm reads return only version metadata. Read-only requests reuse a decoded snapshot; mutations do not enter that scope.languages.rs: versioned global language registry shared within a read request.cache.rs: weighted LRU, bounded entry count and serialized-size-based estimate. Eviction never invalidates an already borrowed immutableArc; I/O is outside locks.pool.rs: validated per-process connection maximum, minimum and queue deadline.- Migration 037 changes identities on every write. UUIDs survive no cache across deletion/recreation. Language triggers also cover registry deletion/truncation.
commerce::scoped_locked remains the authoritative locked checkout/mutation read.
READ_CONTEXT_CACHE=false disables both decoded caches and request memoization.
Only the instance bootstrap credential sees aggregate counters under /api/runtime;
personal merchant accounts cannot inspect other shops' cache activity.
Verification: Rust LRU tests and scripts/read_performance.py exercise two actual
Rust/SQL replicas, committed edits, channel overrides, direct SQL, rollback,
language registry changes, tenant isolation, revocation and cold process restart.
These SQL/async behaviors are tested, not covered by the extracted Lean policies.
Request admission and delivery
access_snapshot.rs/access_snapshot.sql: one fresh, server-owned MVCC read of domain binding, tenant existence, staging parent, live status and selected channel. Middleware reuses it only for the same request and tenant/channel. Personal credentials/grants remain a current SQL lookup; their selected channel joins that lookup. No domain/status/permission TTL cache is introduced.- The hosted proxy uses the original admitted mount; a second lookup cannot retarget an already admitted request. A subsequent request observes a committed pause, deletion, private-channel change or membership revocation.
delivery.rs: only the native public shell and assets skip identity queries. Hosted shop assets, scoped uploads, product HTML and previews still pass admission. Domain resolution runs before compression classification. Gzip/Brotli opt in known secret-free read models; auth, customer, cart/order, payment, MCP/UCP and arbitrary hosted HTML stay uncompressed. Streams/ranges/already encoded bodies retain their delivery contract; all native variants vary byAccept-Encoding.frontend/scripts/precompress.mjsemits deterministic.br/.gzsidecars during the existing frontend build; URLs, original files and MIME types remain unchanged. Precompression requires no running Node or Python service.- Settings hits return
Arc<Settings>instead of deep-copying the object. Consumers clone only when they actually need a mutable method-filtered copy; checkout continues to use the locked authoritative configuration.
The same owner contains decoded caches, delivery and admission; no second read
engine or request-held SQL connection was added. src/studio/overview.sql
consolidates facts while studio.rs admits at most three concurrent read branches.
Inventory statements live in commerce/inventory.rs / inventory_release.sql.
SQL/build inputs are review-hash locked but are unproved adapters. The
native_asset_bypass Boolean policy is extracted to Lean; it does not prove URL
classification, middleware ordering, PostgreSQL or HTTP behavior.
Real regressions: read_performance, channel_management, identity_broker,
tenant_isolation, production_foundations and transaction_pooler; the frontend
precompression test checks round trips, deterministic bytes and stale sidecars.
Measured scope and reproduction.
admission::reserve_ai_attempt is the shared atomic UTC-day attempt owner for
interactive chat/SSE, document extraction (HTTP/MCP/Flow) and background Flow
proposals. Staging uses the live tenant budget. A failed provider attempt is not
refunded; this counts attempts, not tokens or spend. Do not add a process-local
quota counter or a second table to a new AI entry point.