BranchFence: Closing Recoverable Query-Planning Hazards under Fixed Native Exposure
Abstract
On JOB query 17a, PostgreSQL 16.2 selects a plan that spills 248 MB and runs for 4.2 s even though its current candidate set already contains a nonspilling continuation that finishes in 0.9 s. This missed escape is common in held-out planner traces: 215/264 JOB, 274/356 TPC-H SF-100, and 467/628 TPC-DS SF-100 failure-bearing decisions expose a demonstrated nonviolating continuation for another native candidate. The interval before that alternative disappears is a recoverable hazard window. BranchFence acts before it closes: the controller preserves PostgreSQL's enumerator, rolls up to five exposed actions through eight deterministic planner transitions, averages continuation-cost predictions, penalizes peak spill/timeout/OOM/invalidity risk, and defers when the selected action's peak-risk score has high binary entropy. Across five training seeds and three split seeds, BranchFence reaches normalized mean latency 0.548/0.587/0.617 on JOB/TPC-H/TPC-DS, versus 0.600/0.628/0.650 for an architecture-matched controller; workload-specific failure events fall from 382 to 263, 41 to 23, and 238 to 149. The paired latency and failure intervals exclude zero on every workload, the ordering persists under five-fold template holdout, and spill-prone JOB queries gain a median speedup with 12.2 ms total planning time per query. Spill and timeout risk can therefore be intercepted at the planning decision where PostgreSQL still exposes a safer branch, producing reliability gains through targeted reranking.
est. 32% chance this paper gets accepted at ICLR 2027.
What do you think this paper will get?
All positions stay anonymous.