The 3 GiB page cache and temp_store=MEMORY were set once in Initialize, so
only one pooled connection carried them and the other nine got no busy_timeout,
which drove many "database is locked" errors. None of that memory was visible
to the Go runtime.
Move the per-connection settings into the DSN so every pooled connection gets a
64 MiB cache (640 MiB worst case over ten connections), synchronous OFF, a
5 s busy_timeout and WAL. Drop cache_size, temp_store, synchronous and
busy_timeout from the Initialize pragmas; DISTINCT temp B-trees now spill to
disk. Add process-wide soft (1 GiB) and hard (1.5 GiB) heap limits; at the hard
limit a statement returns SQLITE_NOMEM and the existing batch paths already log
and drop, so nothing panics or exits.
Model: opus-4-8