Measure the borrow, rather than asserting it bounds the disk

The claim that hydration-as-a-borrow makes peak disk the working set
rather than the library was so far an argument. `--example vfs_cycle`
runs it: 100 photographs of 25 MB, 90 dehydrated, a pass over all of
them through the real engine.

Peak 275 MB — the resting set plus one photograph — against 2,500 MB
had the pass simply fetched everything. Back to 250 MB afterwards, and
all ten files the user already kept still there, which is the half of
the contract that matters more.

Recorded in docs/storage.md §6.3 and ARCH §9.0a, because a bound argued
from a number nobody measured is one that gets quietly lost.
This commit is contained in:
2026-08-29 09:57:53 +02:00
parent 5768100816
commit 702d83c218
4 changed files with 161 additions and 2 deletions
+3 -1
View File
@@ -892,7 +892,9 @@ unamended for the direct connector, which must still never hydrate to browse.
1. **Hydration is a borrow, not an acquisition.** A file is returned to the state it was found in —
what the pass downloaded is released, what the user already had is left alone. Peak disk is the
working set, not the library.
working set, not the library. **Measured 2026-08-29** over 100 photographs of 25 MB, 90 of them
dehydrated: peak 275 MB against 2,500 MB unborrowed, back to 250 MB afterwards, and all ten the
user already held still there.
2. **It is paid once.** Thumbnails are kept, and `derived_sync` pushes the shards to the server, so
a second device downloads 200 MB of shards instead of hydrating 340 GB of RAWs.
3. **It is quoted and consented to.** Never automatic, never on the browsing path, always