Reference and source map

This chapter collects names and limits used earlier. The operating guides contain the full command syntax. The specifications define the contracts; the evidence reports identify which source and binary were checked.

Native commands

CommandPurpose
sqlodin local FILEOpen a standalone SQLite file; bypass replication.
sqlodin connect CLIENT.jsonOpen the interactive or scriptable cluster client.
sqlodin serve NODE.jsonReopen and serve one durable voter.
serve NODE.json --createCreate new state once; refuse an existing store.
request CLIENT.json REQUEST.jsonSend one explicit authenticated protocol request.
backup NODE.json NEW-DIRTake a verified offline application backup.
verify-backup DIRCheck manifest, bytes and application integrity.
restore BACKUP NODE.json --new-clusterRestore into a fenced fresh namespace.
migrate NODE.json NEW-DIRPerform supported offline format-4 migration.
compact NODE.jsonPerform offline certified generation compaction.
version, helpInspect the binary and available syntax.

Interactive client

SQL ends with a semicolon. BEGIN, COMMIT, ROLLBACK and savepoints use the optimistic transaction protocol. Without BEGIN, each write is its own replicated request.

Command familyUse
.helpList the supported dot commands.
.mode, .headers, .nullvalueChoose presentation and null formatting.
.tables, .schema, .indexesInspect the SQL catalog.
.read, .output, .onceRun scripts or direct output.
.timeout, .consistencySet request waiting and explicit read consistency.
.status, .nodesInspect local state and fixed membership.
.pending, .retryInspect or resolve the exact saved uncertain request.
.reconnect CLIENT.jsonChange endpoint within the same cluster and identity.
.session, .retire-sessions E --quiescedInspect session state or explicitly advance its epoch.

The shell stores pending writes durably before sending them. --state PATH selects its private recovery file. Do not share that file between simultaneous shells or delete it to escape an uncertain result. .pending can reveal application values.

Diagnostics name the error and suggest a correction. Data goes to stdout or the selected output; errors go to stderr. Terminal color is disabled for redirected streams, TERM=dumb or NO_COLOR. CSV and JSON preserve values; terminal display escapes control bytes. The CLI guide covers editing keys, scripts and output modes.

Default service bounds

ResourceDefault bound
Write transaction8 statements; 4,096 SQL bytes; 16 parameters.
Text parameter256 UTF-8 bytes.
Vectors384 float32 components per request; at most 384 per vector.
Read result4,096 rows and 256 KiB accounted storage; whole-result failure on overflow.
Read workApproximate one-million SQLite VM instruction budget.
Client request / response64 KiB / 1 MiB wire limit.
Connections32 total; 24 admitted clients; peer capacity reserved.
Queued output256 frames and at most 2 MiB per connection.
Consensus window64 active slots, reused only after safe floor advancement.
Application/journal grouping16 requests per application group; one journal group per service turn, flushed early at 1,024 records or effect capacity.
Sessions65,536 rows in the current epoch; explicit replicated retirement.
MaintenanceOne job; 1 MiB chunks; 32 MiB transfer buffers.
Consensus history8 GiB cap with reserves; separate from application/staging capacity.

Bounds describe the default build and admitted API. They do not bound arbitrary SQL’s wall-clock cost or the operating system’s buffers and cache. Arbitrary BLOB parameters, attached databases, extension loading, dynamic membership and rolling upgrades are outside the supported interface. Vector BLOB results and typed vector inputs are supported.

Terms used in the book

TermMeaning
SlotOne position in the replicated total order.
BallotAn ordered proposal attempt; distinct from a log slot.
ChosenAccepted by a quorum under the protocol.
Applied prefixThe contiguous chosen history reflected in local application state.
AcknowledgedThe service has verified durable choice and application of the expected request.
Read frontierThe largest highest-seen slot of a read quorum, observed after a read’s invocation; the snapshot waits for it.
Read markerA fresh ordered value used by the embedded durable host to authorize a read snapshot.
RevisionAn application-state counter used for optimistic validation.
EpochA replicated fence that prevents reclaimed retry sessions from reviving.
GenerationA recoverable application/consensus pair selected by the root catalog.
CertificateDistinct matching durable snapshot receipts from a quorum.

Find the implementation or argument

ConcernSourceArgument
Consensus adaptersrc/paxos.odin and deps/paxos-odin/Multi-master refinement
SQL and groupingsrc/engine*.odinSQL policy grouping
Reads and transactionssrc/durable/reads.odin, service/read_batch.odinOrdering
Durable lifecyclesrc/durable/, src/snapshot/Publication retirement
Operator recoverycli/backup.odin, cli/restore.odinRecovery procedures
Networking and boundsservice/, transport/mtls/Resource contract
Application clientscli/, languages/python/ORM contract

The SOD index records design decisions. The release record records qualification and known limits. The documentation index separates current guides from historical notes. Use those records to follow a claim to its source rather than treating the book’s prose as a substitute for executable evidence.

Search the documentation