Skip to content

perf(history): defer artifact probes until after semantic retention - #5240

Merged
huangruiteng merged 2 commits into
mainfrom
codex/history-artifact-observation
Sep 28, 2026
Merged

huangruiteng merged 2 commits into
mainfrom
codex/history-artifact-observation

Conversation

@huangruiteng

Copy link
Copy Markdown
Collaborator

Goal And Delivered Outcome

history --limit 3 previously checked both artifact paths for every indexed Run before choosing the returned rows. On a captured 27,659-Run workload this meant 55,318 filesystem existence checks for one observation.

History now decodes, hashes and deduplicates the complete index and computes quota/semantic history first, then observes artifacts for the returned recent, latest-status, lane and semantic-evidence rows. The same workload needs 86 checks and returns identical JSON values. Older vision, owner correction and active retry evidence remain available even with --limit 0.

Related to #4574 and the shared-authority read-cost/deletion checkpoint. Base: main; independent of #5237's canonical contract-health fix.

Scope And Continuation

  • Shared caller I/O, not a provider cache: fresh observations on each request, including unchanged-index file creation/deletion. Full load_index/load_index_snapshot callers keep complete artifact observation by default.
  • Python remains the existing filesystem adapter. No new capability, TS/Python semantic owner, authority provider, persistence format or decision-history limit. Semantic traversal stays beside its existing schema fields.
  • Reuses one artifact observer for full/selected reads and removes the eager per-row probing closure. Selection, ordering, quota and retention rules are unchanged.
  • This closes redundant filesystem checks in history collection. Full index parsing, startup, other status work and public payload size remain. It does not qualify the default provider, sustained operation, or legacy-writer deletion.

Validation

  • Tested revision: 739381d7ef2ba891dc1217e00f446ea394011c9d
  • Run state: finished
  • Input classes: public_fixture, synthetic, authorized_private_read_only
Check kind Result Public-safe evidence / limitation
unit / regression_parity passed 61 tests covering history chronology, index writer serialization, feedback lookup, readiness, semantic retention, replan transport/provider policy and status-history reuse. New 1,000-Run fixture independently checks digest/count/duplicate semantics, lane/status windows, retained vision/correction/retry and unchanged-index file changes. Probe-bound assertions fail on baseline.
real_entrypoint / real_backend passed Public history and status commands with isolated real File and SQLite canonical stores. Full readers retain fresh flags, including broken symlinks. Only disposable state/processes used.
regression_parity passed Captured ~50 MB index copied into an isolated runtime with existence-only artifact replicas; all 27,659 Runs retained. Baseline/head collector and actual CLI responses have identical JSON values and 597,304-byte CLI output. JSON member order is not the comparison oracle. Raw private data is excluded.
manual passed Alternating base/head/head/base collector runs: warm collection 0.63–0.65 s → 0.27–0.29 s; probes 55,318 → 86. These are collector measurements, not total-command qualification.
manual not_run No whole-CLI latency acceptance is claimed: observed process-level pairs varied, including an unfavorable 1.55 s baseline → 1.84 s head sample. Worktree/release startup, concurrency and other costs remain separate. No OS-cache-cold, sustained or cross-platform claim.
integration passed Standard premerge: 19 selected checks, no failures. Final census-only update has six passing architecture checks; initially four moved locations were stale and have been refreshed.
static passed Changed Python Ruff; configured mypy (19 files); whitespace and five-file public-boundary checks.

No PostgreSQL store, mutation, migration or transport changes; this is shared local artifact observation. Production-size evidence is a read-only copy, not active Goal migration or complete artifact-content recovery.

Frontend / Visual Evidence

UI impact: none. The status schema and artifact flags consumed by existing UI/Lark/CLI remain intact; there is no editor or layout change. The public CLI is validated; the candidate is not installed.

Shared-authority RFC fixture impact

No fixture schema or canonical-store contract changes. Public fixtures add selection-vs-observation, retained old evidence and artifact freshness coverage; File/SQLite entrypoint arms pass. Provider defaults and PostgreSQL qualification remain unchanged.

Boundary Checklist

  • No private state, raw logs, credentials, internal URLs or local paths in the diff/body.
  • No duplicated benchmark work, generated evidence or speculative cache framework.
  • Changes are confined to the shared history reader and its contract/tests.
  • DCO signed; exact source reviewed locally; left for maintainer review/merge.

Signed-off-by: huangruiteng <14976749+huangruiteng@users.noreply.github.com>
Signed-off-by: huangruiteng <14976749+huangruiteng@users.noreply.github.com>

@huangruiteng huangruiteng left a comment

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approval conclusion (author-owned PR; GitHub blocks formal self-approval)

结论:APPROVE,没有发现阻塞项。审查与验证针对 739381d7ef2ba891dc1217e00f446ea394011c9d,不是仅接受作者的性能数字。

动机

这项改动解决的是共享 history 读取中的重复文件系统工作:先前对完整索引中的每条 Run 都检查两种 artifact,再挑选真正需要返回的记录。历史积累会持续增加这种调用开销。目标是减少被丢弃记录的探测,同时保留完整索引、额度账本、排序、旧控制证据与每次读取的真实文件状态。它不等于整条 CLI 的延迟或 shared-authority 持续运行验收;作者已经明确保留这些边界。

改动思路

collect_history 仍解码、去重并归约完整历史,只把文件存在性检查推迟到选择完成之后。_observe_run_artifacts 统一服务完整读取与选中读取,请求结束就丢弃缓存;不是持久化缓存、provider 切换或新的决策源。iter_goal_semantic_history_runs 放在已有语义字段列表旁,避免 filesystem adapter 再复制一套 retention 规则。

具体改动

五个文件的 +258/-21 各有对应作用:history adapter 去除 eager probing,retention 模块只增加已保留引用的遍历,registry I/O manifest 更新移动后的源码位置,双语 status 数据合同解释实时 artifact flags,179 行回归测试覆盖保留证据、lane/status 窗口、文件增删及真实 File/SQLite CLI。底层 load_index/load_index_snapshot 默认仍逐条观测;全局 runs 复用已观测的 per-Goal 引用,未改变输出 schema 或 UI/Lark 的既有输入。

正向路径是完整索引 → quota/semantic reduction → recent/status/lane/semantic 引用 → filesystem observation → 返回。反向检查是 limit=0、很旧的愿景/纠偏/重试、错误的 persisted flags、破损 symlink 和索引不变时的文件变化:不能因为没有出现在近期窗口就丢失证据,也不能信任索引里的旧布尔值。

对主干的风险

独立构造两个 Goal、2,400 条唯一 Run,覆盖 limit 0/1/3/7 与安静 lane、七类 agent 语义引用、owner correction、有效 blocked retry、重复/坏索引记录、全局窗口及完整 reader。11 组 base/head 的完整 JSON 值相同;八个 collection 对照的探测集合精确等于返回记录的路径,4,800 次降至 28–56 次。文件实时变化与索引只读校验通过,未使用作者的私有历史拷贝。

原生 head 52 项、base 44 项,以及 retention/retry/census 在每侧各 19 项通过;新增真实 File/SQLite history/status 子进程覆盖生产入口。source worktree 的 standard premerge 19 selected + 5 direct 通过,Ruff、配置中的 19 文件 mypy、public-boundary 检查通过;精确质量回执有效。没有查询或等待 GitHub CI,也没有通过调整预算抹除失败。

尚未证明的是完整 CLI 启动、冷缓存、长期/跨平台 latency 及其它 status 成本;本 PR 没有宣称完成这些目标。文件观测本来也不是原子跨文件快照。没有改变 PostgreSQL、Todo authority 或迁移行为,不把本地 fixture 当成活跃 Goal 升级证据。

我的整体评价

这是一个完整而可回退的 caller-I/O 优化,保留原有决策语义,收益与承诺范围匹配。future-facing pass 已体现在共享 observer 和 shape-owned traversal;无需增加持久化缓存或泛化 provider 框架。没有新的 frontend 编辑器、配置或视觉内容要交付,已有状态输出合同保持一致。支持该 exact head;按 repository policy 留给 maintainer 合并,不自行合并或安装。

English verdict: APPROVE - 739381d; full retained-history observations match the immutable base, bounded artifact probes are independently demonstrated, and native/source-worktree validation passes. Whole-CLI latency and broader shared-authority acceptance remain out of scope.

@huangruiteng

Copy link
Copy Markdown
Collaborator Author

Frame alignment — exact head 739381d7ef2ba891dc1217e00f446ea394011c9d

APPROVE the bounded shared-history artifact-observation repair. This serves the redundant caller-I/O part of #4574/shared-authority read-cost acceptance: decode and reduce the complete history first, then observe only retained references. It does not close whole-CLI cold/sustained latency, full parsing/startup cost, provider selection, migration, or broader shared-authority acceptance.

Independent base/head qualification: 11 complete observation graphs match, old semantic evidence and fresh flags survive, and eight probe sets shrink from 4,800 to exactly 28–56 returned paths. Native history/real File+SQLite CLI: head52/base44; retention/retry/census:19 each; source standard premerge19 selected+5 direct passes with an exact valid quality receipt. No GitHub CI consultation, install, live Goal rewrite, or merge.

Bounded future-facing pass: shared request-local observer plus reference traversal beside the existing semantic schema, without another retention owner or persistent cache. The wider read-cost frontier remains separate; author performance claims were not substituted for these checks.

@huangruiteng
huangruiteng merged commit 056390f into main Sep 28, 2026
34 checks passed
@huangruiteng
huangruiteng deleted the codex/history-artifact-observation branch September 28, 2026 12:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant