mirror of
https://github.com/stablyai/orca.git
synced 2026-09-22 16:02:32 +00:00
* perf(git): pack the loose refs Orca's own fetches leave behind Orca strips git's auto-maintenance off every fetch it issues (GIT_FETCH_SKIP_AUTO_MAINTENANCE_CONFIG_ARGS) and never compensated, so nothing in an Orca-driven checkout ever packs refs. One real machine reached 36,574 loose refs, where `git show-ref -- main` costs 5.2s and every worktree create pays for it. Add an idle-time, per-repo `git pack-refs --all --prune`, armed by the fetches that create the debt. It runs only after ten minutes of quiet on that repo, only above 1000 loose refs (probed with a walk bounded by that threshold, not by the backlog), one at a time across the whole app, at the background admission tier, and never while an agent is working, a create is prepared or in flight, a worktree removal is deleting refs, the app is quitting, or the machine is on battery. A user who set `maintenance.auto=false` or `gc.auto=0` has opted out. Measured on a 36,001-loose-ref fixture (macOS/APFS, git 2.44): `show-ref` 5.5-12.2s -> 30-49ms, `for-each-ref` 4.0-10.8s -> 43-48ms. Also fixes a pre-existing bug the split exposed: `--path-format=absolute` is ignored before git 2.31, and taking rev-parse's stdout raw collapsed every repo on such a host onto one fetch-serialization key. Refs #17828 * perf(git): make idle ref maintenance preemptible and cheaper to probe The idle veto was one-directional: it stopped a pack from starting during a create, removal, or agent work, but nothing stopped those from starting during a pack. A user-clicked Fetch, a branch delete, or a worktree removal that needed `packed-refs.lock` mid-rewrite could fail with `unable to create packed-refs.lock` -- a git error with no visible cause. Make the pack cancellable end to end. An AbortSignal now reaches the `pack-refs` child and both pre-pack probes, and `pause()` aborts what is running, waits for it to actually stop, and holds a suspension count so nothing new starts until the caller releases. Every entry point that deletes a ref takes that pause: gitFetch, gitPull, gitFastForward, removeWorktree, forceDeleteLocalBranch, prepareWorktreeCreateCheckout, addWorktree. Five more triggers close the rest of the window: battery drop, window focus, quit, the attempt deadline, and any other git command queueing for an admission slot. Judge a pack by re-probing the backlog rather than by the child's exit code. Measured in the field: another Orca session moved a branch mid-pack, git reported `cannot lock ref`, skipped that ref and packed the rest -- 36,688 loose refs down to 3. On a machine running several sessions that is the normal case, and retrying it would be wrong. Probe with one batched `readdir` per directory instead of streaming `opendir`, which issues a thread-pool round trip every 32 entries: 177ms -> 23ms on a real 36,600-ref repository, with half the event-loop lag. The walk stays strictly sequential so it can never occupy more than one of libuv's four filesystem threads. `PackRefsLockOwnership` makes a lock left by SIGKILL attributable, and only reclaims one when a marker exists, the lock is older than any pack-refs could run for, and the recorded process is gone. Refs #17828 * fix(git): wait out the packed-refs lock instead of killing the pack Measured on Git 2.55/APFS with 37k loose refs: a full `pack-refs --all --prune` takes 23-32s but holds `packed-refs.lock` for only 0.03-1.37s of it. The other ~95% is the prune phase, during which a concurrent `fetch --prune`, `branch -D` or `update-ref` succeeds every time -- per-ref locks last microseconds and git retries for `core.filesRefLockTimeout`. So the abort-on-everything design was strictly harmful. SIGTERM into the prune loop strands an empty `refs/**/*.lock` about one time in five (9/30, 5/40, 6/30 kills): `tempfile.c` opens the lock O_EXCL before `activate_tempfile()` links it into the list the signal handler walks, and a pack does ~36k lock cycles. Afterwards `update-ref -d` on that ref fails with `cannot lock ref ... File exists`, permanently. On Windows `taskkill /f` never runs git's handlers at all, so an abort inside the rewrite strands `packed-refs.lock` every time. Never signal the child. `packRefs` no longer takes an abort signal; it polls `packed-refs.lock` and reports the window through a `PackedRefsLockReporter`. `pause()` resolves when the lock is released -- bounded, and free during the prune -- while the suspension counter still blocks new attempts. Battery and window-focus become do-not-start rather than stop-what-is-running, and quit waits for the lock and lets the child finish orphaned. For strands that already exist, `PackRefsLockOwnership` now also reclaims `refs/**/*.lock` under the same three conditions plus a 0-byte check, and a lock carrying our own not-yet-reclaimable marker records `locked` with a 30min retry instead of the 6h failure cooldown -- so a Windows strand self-heals in half an hour rather than six. Reverts the git admission-scheduler event bus, which existed only to drive the abort this removes. Refs #17828 * test(git): make the ref-maintenance waits survive a loaded runner CI shard 4/8 failed on `restarts every armed countdown when the user does ref work themselves`, which passes locally. The `until()` helper spun a fixed 200 event-loop turns and then returned silently, so on a contended runner the filesystem probe had not finished and the assertion that followed failed with an unrelated message. Bound the wait by wall clock instead and throw a named error, which immediately exposed a second latent bug: the single-flight test's second wait could never succeed, because the deferred repo's retry is on a faked `setTimeout` that spinning the real loop never advances. It had been passing only because the old helper gave up quietly. Add a timer-aware variant for those, and have the countdown test await a signal the fake pack resolves rather than polling at all. Verified stable across five sequential runs and once under load average 32 with six concurrent suites. Refs #17828
120 lines
3.9 KiB
TypeScript
120 lines
3.9 KiB
TypeScript
import { mkdir, mkdtemp, rm, symlink, writeFile } from 'node:fs/promises'
|
|
import { tmpdir } from 'node:os'
|
|
import { join } from 'node:path'
|
|
import { afterEach, describe, expect, it, vi } from 'vitest'
|
|
|
|
// Wraps the real `readdir` so the walk's concurrency is observable without
|
|
// changing what it reads.
|
|
const readdirCalls = vi.hoisted(() => ({ outstanding: 0, peak: 0, count: 0 }))
|
|
|
|
vi.mock('node:fs/promises', async (importOriginal) => {
|
|
const actual = await importOriginal<Record<string, unknown>>()
|
|
const realReaddir = actual.readdir as (...args: unknown[]) => Promise<never>
|
|
return {
|
|
...actual,
|
|
readdir: async (...args: unknown[]) => {
|
|
readdirCalls.outstanding += 1
|
|
readdirCalls.count += 1
|
|
readdirCalls.peak = Math.max(readdirCalls.peak, readdirCalls.outstanding)
|
|
try {
|
|
return await realReaddir(...args)
|
|
} finally {
|
|
readdirCalls.outstanding -= 1
|
|
}
|
|
}
|
|
}
|
|
})
|
|
|
|
import { countLooseRefs } from './loose-ref-count'
|
|
|
|
const roots: string[] = []
|
|
|
|
async function makeRefsTree(counts: Record<string, number>): Promise<string> {
|
|
const root = await mkdtemp(join(tmpdir(), 'orca-loose-refs-'))
|
|
roots.push(root)
|
|
const refs = join(root, 'refs')
|
|
for (const [namespace, count] of Object.entries(counts)) {
|
|
const directory = join(refs, namespace)
|
|
await mkdir(directory, { recursive: true })
|
|
for (let index = 0; index < count; index += 1) {
|
|
await writeFile(join(directory, `ref-${index}`), 'a'.repeat(40))
|
|
}
|
|
}
|
|
await mkdir(refs, { recursive: true })
|
|
return refs
|
|
}
|
|
|
|
afterEach(async () => {
|
|
vi.restoreAllMocks()
|
|
await Promise.all(roots.splice(0).map((root) => rm(root, { recursive: true, force: true })))
|
|
})
|
|
|
|
describe('countLooseRefs', () => {
|
|
it('counts files across nested namespaces', async () => {
|
|
const refs = await makeRefsTree({ heads: 3, 'remotes/origin': 4, 'remotes/fork/deep': 2 })
|
|
|
|
await expect(countLooseRefs(refs, 100)).resolves.toEqual({ count: 9, saturated: false })
|
|
})
|
|
|
|
it('stops at the budget instead of walking the whole backlog', async () => {
|
|
const refs = await makeRefsTree({ 'remotes/origin': 500 })
|
|
|
|
const result = await countLooseRefs(refs, 10)
|
|
|
|
expect(result).toEqual({ count: 10, saturated: true })
|
|
})
|
|
|
|
it('reports zero for a repository with no refs directory', async () => {
|
|
const root = await mkdtemp(join(tmpdir(), 'orca-loose-refs-missing-'))
|
|
roots.push(root)
|
|
|
|
await expect(countLooseRefs(join(root, 'refs'), 100)).resolves.toEqual({
|
|
count: 0,
|
|
saturated: false
|
|
})
|
|
})
|
|
|
|
it('never has more than one directory read outstanding', async () => {
|
|
// libuv's filesystem thread pool has four slots shared with the whole main
|
|
// process. A probe that fanned out would stall unrelated fs work, so this
|
|
// pins the walk as strictly sequential rather than merely bounded.
|
|
const refs = await makeRefsTree({
|
|
'remotes/a': 3,
|
|
'remotes/b': 3,
|
|
'remotes/c': 3,
|
|
'remotes/d': 3,
|
|
'remotes/e/deep': 3
|
|
})
|
|
readdirCalls.peak = 0
|
|
readdirCalls.count = 0
|
|
|
|
await countLooseRefs(refs, 1000)
|
|
|
|
expect(readdirCalls.count).toBeGreaterThan(1)
|
|
expect(readdirCalls.peak).toBe(1)
|
|
})
|
|
|
|
it('reads each directory once rather than streaming it in batches', async () => {
|
|
// One thread-pool round trip per directory is what makes the probe ~8x
|
|
// cheaper than the streaming form on a real degraded repository.
|
|
const refs = await makeRefsTree({ 'remotes/origin': 400 })
|
|
readdirCalls.count = 0
|
|
|
|
await countLooseRefs(refs, 1000)
|
|
|
|
// refs/ plus refs/remotes plus refs/remotes/origin.
|
|
expect(readdirCalls.count).toBe(3)
|
|
})
|
|
|
|
it('does not follow directory symlinks into a loop', async () => {
|
|
const refs = await makeRefsTree({ heads: 2 })
|
|
await symlink(refs, join(refs, 'loop'), 'dir')
|
|
|
|
const result = await countLooseRefs(refs, 100)
|
|
|
|
expect(result.saturated).toBe(false)
|
|
// The symlink is one dirent, never a second traversal of the tree.
|
|
expect(result.count).toBe(3)
|
|
})
|
|
})
|