PostgreSQL 18.6
listen_addresses=''
Unix socket mode 0700
port 55444 only names the private socket
max_connections=24
superuser_reserved_connections=3
max_replication_slots=4
checksums=on
not a Patroni/DCS/HAProxy/PgBouncer member
30 non-superuser psql clients
same advisory lock
one holder sleeps for 20 seconds
other admitted clients wait on Lock
excess clients hit the connection boundary
RETENTION:
one exact inactive physical replication slot
immediately reserved restart_lsn
bounded WAL generation
stop after retained >= 32 MiB
hard cap 128 MiB
FLOW =
observed_sessions >= 18
AND connection_rejections >= 1
AND lock_waiters >= 1
AND inactive_physical_slots = 0
RETENTION =
inactive_physical_slots = 1
AND retained_wal_bytes >= 33554432
AND connection_rejections = 0
both or neither =
STOP_AND_INVESTIGATE
classifier 不读取 hidden-answers.json。validator 会比较 case identity set、字段完整性、
classifier provenance 与 hidden answer;blind packet 若带 truth 或 expected_route
字段反而判失败。
production/managed mutation guard opened
scenario or classifier contract weakened
blind packet leaks truth or misses fields
classification duplicated/unsupported/wrong
flow evidence below threshold or broad cancel
retention slot/bytes/active state falsified
manual WAL deletion or leftover slot claimed
cleanup root left behind
production gate falsely approved
production max_connections should be 24
every inactive slot may be dropped after 32 MiB
42 MB WAL implies a disk incident
exact cancel always has zero fallback
managed Pigsty can tolerate the same storm