perf: round 4 — one-pass row paths, drive-selector cache, CalDAV single-parse, streamed Azure, batched hydration
Nine benchmark-gated changes (benches/ROUND4.md; every one ships with a BEFORE/AFTER bench + equivalence gate, rollback rule as ROUND2/3): - Row→entity path build: one-pass StoragePath::from_folder_and_name / from_joined + normalize_storage_name_owned + alloc-free Display — 743→417 ns/file-row (1.78x), −5 allocs/row on every listing surface. - WebDAV drive-selector: per-user readable_cache (single-flight, 30 s TTL, explicit invalidation incl. membership + group changes) replaces the grants join per request — 441 µs → 0.8 µs (~550x), 0 queries warm. - CalDAV from_ical/update_ical_data: 8 full IcalParser runs per VEVENT → 1 (7.1x per PUT, 4.4x on 50-event imports); alloc-free split_vevents, chunk scan without the whole-body uppercase copy (1.4x), borrowed-key UID grouping (1.3x), REPORT props no longer cloned. - PROPFIND emit: partition Vecs dropped (single-pass 404 list) + stack rendered RFC 3339/2822 dates, sizes, quoted etags (common::fmt, chrono-byte-identical, sweep-tested) on both DAV surfaces — 1.22x per page, 17.9→12.0 allocs/row. - Grant-listing hydration: calendars/address books/playlists batch hydrate via = ANY($1) — 15 serial queries → 1 (~13x per sync poll). - user-flags cache: get→insert → try_get_with single-flight (32→1 queries per cold herd). - Azure downloads: whole-blob Vec buffering → streamed SDK pages — TTFB 349→4 ms (87x), peak heap 480→1.9 MiB (254x) on 256 MiB blobs; new OXICLOUD_AZURE_ENDPOINT_URL override (Azurite/bench hook). - Face indexing: unbounded per-image tokio::spawn → core-count semaphore, permit before blob read — peak heap 1175→176 MiB (6.7x). Checks: cargo fmt, clippy --all-features --all-targets -D warnings, cargo test --workspace (523 passed) + --features test_utils. hurl API suite and dockerized integration DB not runnable in this environment — left to CI. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017aJu9ghvuT8WqC31ZEGTBA
This commit is contained in:
@@ -56,14 +56,32 @@ fn parse_caldav_datetime(value: &str) -> Option<DateTime<Utc>> {
|
||||
/// `None` if either tag is missing (malformed body) so callers
|
||||
/// can fall back safely.
|
||||
pub(crate) fn extract_vevent_chunk(ical_data: &str) -> Option<&str> {
|
||||
let upper = ical_data.to_ascii_uppercase();
|
||||
let begin = upper.find("BEGIN:VEVENT")?;
|
||||
// End marker: the line-start of END:VEVENT after `begin`, plus
|
||||
// the length of "END:VEVENT" itself, then find the next CRLF/LF
|
||||
// to include the terminator line.
|
||||
let after_begin = &upper[begin..];
|
||||
let rel_end = after_begin.find("END:VEVENT")?;
|
||||
let end_tag_end = begin + rel_end + "END:VEVENT".len();
|
||||
// Byte index of the first ASCII-case-insensitive occurrence of
|
||||
// `needle` in `hay` at or after `from`. Every stored body OxiCloud
|
||||
// itself writes carries uppercase tags, so try the memchr-backed
|
||||
// exact `find` first; only genuinely mixed-case foreign bodies pay
|
||||
// the manual scan. Either way this replaces the old
|
||||
// `to_ascii_uppercase()` of the ENTIRE body — one full-copy String
|
||||
// allocation per event per REPORT/GET, done purely to locate two
|
||||
// tags.
|
||||
fn find_ci(hay: &str, needle: &str, from: usize) -> Option<usize> {
|
||||
if let Some(i) = hay[from..].find(needle) {
|
||||
return Some(from + i);
|
||||
}
|
||||
let h = hay.as_bytes();
|
||||
let n = needle.as_bytes();
|
||||
if h.len() < n.len() {
|
||||
return None;
|
||||
}
|
||||
(from..=h.len() - n.len()).find(|&i| h[i..i + n.len()].eq_ignore_ascii_case(n))
|
||||
}
|
||||
|
||||
let begin = find_ci(ical_data, "BEGIN:VEVENT", 0)?;
|
||||
// End marker: the first END:VEVENT after `begin`, plus the length
|
||||
// of "END:VEVENT" itself, then any immediate CRLF/LF to include
|
||||
// the terminator line.
|
||||
let rel_end = find_ci(ical_data, "END:VEVENT", begin)?;
|
||||
let end_tag_end = rel_end + "END:VEVENT".len();
|
||||
// Include any immediate line terminator so the chunk stays a
|
||||
// well-formed line even when the caller concatenates.
|
||||
let mut end = end_tag_end;
|
||||
@@ -88,21 +106,27 @@ pub(crate) fn extract_vevent_chunk(ical_data: &str) -> Option<&str> {
|
||||
pub(crate) fn group_events_by_uid<'a>(
|
||||
events: &'a [CalendarEventDto],
|
||||
) -> Vec<Vec<&'a CalendarEventDto>> {
|
||||
let mut order: Vec<String> = Vec::new();
|
||||
let mut buckets: std::collections::HashMap<String, Vec<&'a CalendarEventDto>> =
|
||||
// Keys borrow from the DTO slice (which outlives every local) — the
|
||||
// old String-keyed map cloned every event's UID (twice for first
|
||||
// appearances) on every REPORT / collection PROPFIND / GET.
|
||||
let mut order: Vec<&'a str> = Vec::new();
|
||||
let mut buckets: std::collections::HashMap<&'a str, Vec<&'a CalendarEventDto>> =
|
||||
std::collections::HashMap::new();
|
||||
|
||||
for event in events {
|
||||
let key = event.ical_uid.clone();
|
||||
if !buckets.contains_key(&key) {
|
||||
order.push(key.clone());
|
||||
let key = event.ical_uid.as_str();
|
||||
match buckets.entry(key) {
|
||||
std::collections::hash_map::Entry::Vacant(slot) => {
|
||||
order.push(key);
|
||||
slot.insert(vec![event]);
|
||||
}
|
||||
std::collections::hash_map::Entry::Occupied(mut slot) => slot.get_mut().push(event),
|
||||
}
|
||||
buckets.entry(key).or_default().push(event);
|
||||
}
|
||||
|
||||
let mut out = Vec::with_capacity(order.len());
|
||||
for uid in order {
|
||||
let mut bucket = buckets.remove(&uid).unwrap_or_default();
|
||||
let mut bucket = buckets.remove(uid).unwrap_or_default();
|
||||
// Master first (recurrence_id None), exceptions in insertion order.
|
||||
bucket.sort_by_key(|e| e.recurrence_id.is_some());
|
||||
out.push(bucket);
|
||||
@@ -1123,11 +1147,13 @@ impl CalDavAdapter {
|
||||
]),
|
||||
))?;
|
||||
|
||||
// Determine which properties to include based on request type
|
||||
// Determine which properties to include based on request type —
|
||||
// borrowed straight out of the request (the old `clone()` copied
|
||||
// the whole Vec of owned QualifiedName strings per REPORT).
|
||||
let props = match request {
|
||||
CalDavReportType::CalendarQuery { props, .. } => props.clone(),
|
||||
CalDavReportType::CalendarMultiget { props, .. } => props.clone(),
|
||||
CalDavReportType::SyncCollection { props, .. } => props.clone(),
|
||||
CalDavReportType::CalendarQuery { props, .. } => props,
|
||||
CalDavReportType::CalendarMultiget { props, .. } => props,
|
||||
CalDavReportType::SyncCollection { props, .. } => props,
|
||||
};
|
||||
|
||||
// Add responses for events — folded per UID so a
|
||||
@@ -1143,7 +1169,7 @@ impl CalDavAdapter {
|
||||
None => continue,
|
||||
};
|
||||
let href = format!("{}{}.ics", base_href, anchor.ical_uid);
|
||||
Self::write_event_response(&mut xml_writer, &bundle, &props, &href)?;
|
||||
Self::write_event_response(&mut xml_writer, &bundle, props, &href)?;
|
||||
}
|
||||
|
||||
// End multistatus
|
||||
@@ -1418,6 +1444,26 @@ impl CalDavAdapter {
|
||||
}
|
||||
}
|
||||
|
||||
// ─────────────────────────────────────────────────────────────
|
||||
// Bench support
|
||||
// ─────────────────────────────────────────────────────────────
|
||||
|
||||
/// Thin public wrappers over the `pub(crate)` read-side helpers so
|
||||
/// `examples/bench_caldav_parse.rs` can measure them. Gated behind the
|
||||
/// `bench` feature — adds nothing to prod builds.
|
||||
#[cfg(feature = "bench")]
|
||||
pub mod bench {
|
||||
use super::*;
|
||||
|
||||
pub fn extract_vevent_chunk(ical_data: &str) -> Option<&str> {
|
||||
super::extract_vevent_chunk(ical_data)
|
||||
}
|
||||
|
||||
pub fn group_events_by_uid(events: &[CalendarEventDto]) -> Vec<Vec<&CalendarEventDto>> {
|
||||
super::group_events_by_uid(events)
|
||||
}
|
||||
}
|
||||
|
||||
// ─────────────────────────────────────────────────────────────
|
||||
// Tests
|
||||
// ─────────────────────────────────────────────────────────────
|
||||
|
||||
@@ -627,17 +627,19 @@ impl WebDavAdapter {
|
||||
// RFC 4918 §9.2: known props → 200 propstat; unknown → 404 propstat.
|
||||
// Props found in the dead store are returned in the dead 200 propstat,
|
||||
// so exclude them from the 404 propstat to avoid duplicate reporting.
|
||||
let (known, unknown): (Vec<_>, Vec<_>) = props
|
||||
// Single pass: the requested-props writer skips unknown
|
||||
// names itself (its match arms mirror
|
||||
// `folder_prop_is_known` exactly), so only the usually
|
||||
// empty 404 list needs materialising — the old
|
||||
// `partition` built two throwaway Vecs per row.
|
||||
let truly_unknown: Vec<_> = props
|
||||
.iter()
|
||||
.partition(|p| Self::folder_prop_is_known(p, quota));
|
||||
let truly_unknown: Vec<_> = unknown
|
||||
.into_iter()
|
||||
.filter(|p| !dead_name_set.contains(*p))
|
||||
.filter(|p| !Self::folder_prop_is_known(p, quota) && !dead_name_set.contains(p))
|
||||
.collect();
|
||||
|
||||
xml_writer.write_event(Event::Start(BytesStart::new("D:propstat")))?;
|
||||
xml_writer.write_event(Event::Start(BytesStart::new("D:prop")))?;
|
||||
Self::write_folder_requested_props(xml_writer, folder, &known, quota)?;
|
||||
Self::write_folder_requested_props(xml_writer, folder, props, quota)?;
|
||||
xml_writer.write_event(Event::End(BytesEnd::new("D:prop")))?;
|
||||
xml_writer.write_event(Event::Start(BytesStart::new("D:status")))?;
|
||||
xml_writer.write_event(Event::Text(BytesText::new("HTTP/1.1 200 OK")))?;
|
||||
@@ -714,16 +716,19 @@ impl WebDavAdapter {
|
||||
// RFC 4918 §9.2: known props → 200 propstat; unknown → 404 propstat.
|
||||
// Props found in the dead store are returned in the dead 200 propstat,
|
||||
// so exclude them from the 404 propstat to avoid duplicate reporting.
|
||||
let (known, unknown): (Vec<_>, Vec<_>) =
|
||||
props.iter().partition(|p| Self::file_prop_is_known(p));
|
||||
let truly_unknown: Vec<_> = unknown
|
||||
.into_iter()
|
||||
.filter(|p| !dead_name_set.contains(*p))
|
||||
// Single pass: the requested-props writer skips unknown
|
||||
// names itself (its match arms mirror `file_prop_is_known`
|
||||
// exactly), so only the usually empty 404 list needs
|
||||
// materialising — the old `partition` built two throwaway
|
||||
// Vecs per row.
|
||||
let truly_unknown: Vec<_> = props
|
||||
.iter()
|
||||
.filter(|p| !Self::file_prop_is_known(p) && !dead_name_set.contains(p))
|
||||
.collect();
|
||||
|
||||
xml_writer.write_event(Event::Start(BytesStart::new("D:propstat")))?;
|
||||
xml_writer.write_event(Event::Start(BytesStart::new("D:prop")))?;
|
||||
Self::write_file_requested_props(xml_writer, file, &known)?;
|
||||
Self::write_file_requested_props(xml_writer, file, props)?;
|
||||
xml_writer.write_event(Event::End(BytesEnd::new("D:prop")))?;
|
||||
xml_writer.write_event(Event::Start(BytesStart::new("D:status")))?;
|
||||
xml_writer.write_event(Event::Text(BytesText::new("HTTP/1.1 200 OK")))?;
|
||||
@@ -759,6 +764,71 @@ impl WebDavAdapter {
|
||||
Ok(())
|
||||
}
|
||||
|
||||
// ── Per-row formatted-value writers (stack-rendered) ─────────────
|
||||
//
|
||||
// PROPFIND emits two formatted dates, a size and a quoted etag for
|
||||
// EVERY row of every listing. `to_rfc3339()`/`to_rfc2822()` ran
|
||||
// chrono's format-spec interpreter and allocated a String each;
|
||||
// `to_string()`/`format!` added two more. These render the same
|
||||
// bytes from stack buffers (`common::fmt`); out-of-range timestamps
|
||||
// keep the old chrono path as a byte-identical fallback.
|
||||
|
||||
fn write_creationdate<W: Write>(xml_writer: &mut Writer<W>, secs: u64) -> Result<()> {
|
||||
xml_writer.write_event(Event::Start(BytesStart::new("D:creationdate")))?;
|
||||
let secs = secs as i64;
|
||||
let mut buf = [0u8; 25];
|
||||
match crate::common::fmt::rfc3339_utc(&mut buf, secs) {
|
||||
Some(s) => xml_writer.write_event(Event::Text(BytesText::new(s)))?,
|
||||
None => {
|
||||
let s = chrono::DateTime::<Utc>::from_timestamp(secs, 0)
|
||||
.unwrap_or_else(Utc::now)
|
||||
.to_rfc3339();
|
||||
xml_writer.write_event(Event::Text(BytesText::new(&s)))?;
|
||||
}
|
||||
}
|
||||
xml_writer.write_event(Event::End(BytesEnd::new("D:creationdate")))?;
|
||||
Ok(())
|
||||
}
|
||||
|
||||
fn write_lastmodified<W: Write>(xml_writer: &mut Writer<W>, secs: u64) -> Result<()> {
|
||||
xml_writer.write_event(Event::Start(BytesStart::new("D:getlastmodified")))?;
|
||||
let secs = secs as i64;
|
||||
let mut buf = [0u8; 31];
|
||||
match crate::common::fmt::rfc2822_utc(&mut buf, secs) {
|
||||
Some(s) => xml_writer.write_event(Event::Text(BytesText::new(s)))?,
|
||||
None => {
|
||||
let s = chrono::DateTime::<Utc>::from_timestamp(secs, 0)
|
||||
.unwrap_or_else(Utc::now)
|
||||
.to_rfc2822();
|
||||
xml_writer.write_event(Event::Text(BytesText::new(&s)))?;
|
||||
}
|
||||
}
|
||||
xml_writer.write_event(Event::End(BytesEnd::new("D:getlastmodified")))?;
|
||||
Ok(())
|
||||
}
|
||||
|
||||
fn write_etag_quoted<W: Write>(xml_writer: &mut Writer<W>, etag: &str) -> Result<()> {
|
||||
xml_writer.write_event(Event::Start(BytesStart::new("D:getetag")))?;
|
||||
// One exactly-sized allocation instead of format!'s grow-from-empty.
|
||||
let mut quoted = String::with_capacity(etag.len() + 2);
|
||||
quoted.push('"');
|
||||
quoted.push_str(etag);
|
||||
quoted.push('"');
|
||||
xml_writer.write_event(Event::Text(BytesText::new("ed)))?;
|
||||
xml_writer.write_event(Event::End(BytesEnd::new("D:getetag")))?;
|
||||
Ok(())
|
||||
}
|
||||
|
||||
fn write_contentlength<W: Write>(xml_writer: &mut Writer<W>, size: u64) -> Result<()> {
|
||||
xml_writer.write_event(Event::Start(BytesStart::new("D:getcontentlength")))?;
|
||||
let mut buf = [0u8; 20];
|
||||
xml_writer.write_event(Event::Text(BytesText::new(crate::common::fmt::u64_str(
|
||||
&mut buf, size,
|
||||
))))?;
|
||||
xml_writer.write_event(Event::End(BytesEnd::new("D:getcontentlength")))?;
|
||||
Ok(())
|
||||
}
|
||||
|
||||
/// Write standard folder properties
|
||||
fn write_folder_standard_props<W: Write>(
|
||||
xml_writer: &mut Writer<W>,
|
||||
@@ -776,31 +846,15 @@ impl WebDavAdapter {
|
||||
xml_writer.write_event(Event::End(BytesEnd::new("D:displayname")))?;
|
||||
|
||||
// Creation date
|
||||
xml_writer.write_event(Event::Start(BytesStart::new("D:creationdate")))?;
|
||||
|
||||
// Convert u64 timestamp to DateTime
|
||||
let created_at = chrono::DateTime::<Utc>::from_timestamp(folder.created_at as i64, 0)
|
||||
.unwrap_or_else(Utc::now);
|
||||
|
||||
xml_writer.write_event(Event::Text(BytesText::new(&created_at.to_rfc3339())))?;
|
||||
xml_writer.write_event(Event::End(BytesEnd::new("D:creationdate")))?;
|
||||
Self::write_creationdate(xml_writer, folder.created_at)?;
|
||||
|
||||
// Last modified
|
||||
xml_writer.write_event(Event::Start(BytesStart::new("D:getlastmodified")))?;
|
||||
|
||||
// Convert u64 timestamp to DateTime
|
||||
let modified_at = chrono::DateTime::<Utc>::from_timestamp(folder.modified_at as i64, 0)
|
||||
.unwrap_or_else(Utc::now);
|
||||
|
||||
xml_writer.write_event(Event::Text(BytesText::new(&modified_at.to_rfc2822())))?;
|
||||
xml_writer.write_event(Event::End(BytesEnd::new("D:getlastmodified")))?;
|
||||
Self::write_lastmodified(xml_writer, folder.modified_at)?;
|
||||
|
||||
// ETag — routes through `FolderDto::etag` (= `Folder::etag()`)
|
||||
// so every WebDAV emitter and HEAD response agree on a single
|
||||
// value for the same folder.
|
||||
xml_writer.write_event(Event::Start(BytesStart::new("D:getetag")))?;
|
||||
xml_writer.write_event(Event::Text(BytesText::new(&format!("\"{}\"", folder.etag))))?;
|
||||
xml_writer.write_event(Event::End(BytesEnd::new("D:getetag")))?;
|
||||
Self::write_etag_quoted(xml_writer, &folder.etag)?;
|
||||
|
||||
// Content length (0 for directories)
|
||||
xml_writer.write_event(Event::Start(BytesStart::new("D:getcontentlength")))?;
|
||||
@@ -829,13 +883,19 @@ impl WebDavAdapter {
|
||||
used_bytes: i64,
|
||||
available_bytes: Option<i64>,
|
||||
) -> Result<()> {
|
||||
let mut buf = [0u8; 21];
|
||||
xml_writer.write_event(Event::Start(BytesStart::new("D:quota-used-bytes")))?;
|
||||
xml_writer.write_event(Event::Text(BytesText::new(&used_bytes.to_string())))?;
|
||||
xml_writer.write_event(Event::Text(BytesText::new(crate::common::fmt::i64_str(
|
||||
&mut buf, used_bytes,
|
||||
))))?;
|
||||
xml_writer.write_event(Event::End(BytesEnd::new("D:quota-used-bytes")))?;
|
||||
|
||||
if let Some(available_bytes) = available_bytes {
|
||||
xml_writer.write_event(Event::Start(BytesStart::new("D:quota-available-bytes")))?;
|
||||
xml_writer.write_event(Event::Text(BytesText::new(&available_bytes.to_string())))?;
|
||||
xml_writer.write_event(Event::Text(BytesText::new(crate::common::fmt::i64_str(
|
||||
&mut buf,
|
||||
available_bytes,
|
||||
))))?;
|
||||
xml_writer.write_event(Event::End(BytesEnd::new("D:quota-available-bytes")))?;
|
||||
}
|
||||
|
||||
@@ -861,36 +921,18 @@ impl WebDavAdapter {
|
||||
xml_writer.write_event(Event::End(BytesEnd::new("D:getcontenttype")))?;
|
||||
|
||||
// Content length
|
||||
xml_writer.write_event(Event::Start(BytesStart::new("D:getcontentlength")))?;
|
||||
xml_writer.write_event(Event::Text(BytesText::new(&file.size.to_string())))?;
|
||||
xml_writer.write_event(Event::End(BytesEnd::new("D:getcontentlength")))?;
|
||||
Self::write_contentlength(xml_writer, file.size)?;
|
||||
|
||||
// Creation date
|
||||
xml_writer.write_event(Event::Start(BytesStart::new("D:creationdate")))?;
|
||||
|
||||
// Convert u64 timestamp to DateTime
|
||||
let created_at = chrono::DateTime::<Utc>::from_timestamp(file.created_at as i64, 0)
|
||||
.unwrap_or_else(Utc::now);
|
||||
|
||||
xml_writer.write_event(Event::Text(BytesText::new(&created_at.to_rfc3339())))?;
|
||||
xml_writer.write_event(Event::End(BytesEnd::new("D:creationdate")))?;
|
||||
Self::write_creationdate(xml_writer, file.created_at)?;
|
||||
|
||||
// Last modified
|
||||
xml_writer.write_event(Event::Start(BytesStart::new("D:getlastmodified")))?;
|
||||
|
||||
// Convert u64 timestamp to DateTime
|
||||
let modified_at = chrono::DateTime::<Utc>::from_timestamp(file.modified_at as i64, 0)
|
||||
.unwrap_or_else(Utc::now);
|
||||
|
||||
xml_writer.write_event(Event::Text(BytesText::new(&modified_at.to_rfc2822())))?;
|
||||
xml_writer.write_event(Event::End(BytesEnd::new("D:getlastmodified")))?;
|
||||
Self::write_lastmodified(xml_writer, file.modified_at)?;
|
||||
|
||||
// ETag — routes through `FileDto::etag` (= `File::etag()`) so
|
||||
// PROPFIND, GET, HEAD, PUT-response, and MOVE all emit
|
||||
// byte-identical values for the same file.
|
||||
xml_writer.write_event(Event::Start(BytesStart::new("D:getetag")))?;
|
||||
xml_writer.write_event(Event::Text(BytesText::new(&format!("\"{}\"", file.etag))))?;
|
||||
xml_writer.write_event(Event::End(BytesEnd::new("D:getetag")))?;
|
||||
Self::write_etag_quoted(xml_writer, &file.etag)?;
|
||||
|
||||
Ok(())
|
||||
}
|
||||
@@ -936,7 +978,7 @@ impl WebDavAdapter {
|
||||
fn write_folder_requested_props<W: Write>(
|
||||
xml_writer: &mut Writer<W>,
|
||||
folder: &FolderDto,
|
||||
props: &[&QualifiedName],
|
||||
props: &[QualifiedName],
|
||||
quota: Option<(i64, Option<i64>)>,
|
||||
) -> Result<()> {
|
||||
for prop in props {
|
||||
@@ -953,37 +995,13 @@ impl WebDavAdapter {
|
||||
xml_writer.write_event(Event::End(BytesEnd::new("D:displayname")))?;
|
||||
}
|
||||
"creationdate" => {
|
||||
xml_writer.write_event(Event::Start(BytesStart::new("D:creationdate")))?;
|
||||
|
||||
// Convert u64 timestamp to DateTime
|
||||
let created_at =
|
||||
chrono::DateTime::<Utc>::from_timestamp(folder.created_at as i64, 0)
|
||||
.unwrap_or_else(Utc::now);
|
||||
|
||||
xml_writer
|
||||
.write_event(Event::Text(BytesText::new(&created_at.to_rfc3339())))?;
|
||||
xml_writer.write_event(Event::End(BytesEnd::new("D:creationdate")))?;
|
||||
Self::write_creationdate(xml_writer, folder.created_at)?;
|
||||
}
|
||||
"getlastmodified" => {
|
||||
xml_writer
|
||||
.write_event(Event::Start(BytesStart::new("D:getlastmodified")))?;
|
||||
|
||||
// Convert u64 timestamp to DateTime
|
||||
let modified_at =
|
||||
chrono::DateTime::<Utc>::from_timestamp(folder.modified_at as i64, 0)
|
||||
.unwrap_or_else(Utc::now);
|
||||
|
||||
xml_writer
|
||||
.write_event(Event::Text(BytesText::new(&modified_at.to_rfc2822())))?;
|
||||
xml_writer.write_event(Event::End(BytesEnd::new("D:getlastmodified")))?;
|
||||
Self::write_lastmodified(xml_writer, folder.modified_at)?;
|
||||
}
|
||||
"getetag" => {
|
||||
xml_writer.write_event(Event::Start(BytesStart::new("D:getetag")))?;
|
||||
xml_writer.write_event(Event::Text(BytesText::new(&format!(
|
||||
"\"{}\"",
|
||||
folder.etag
|
||||
))))?;
|
||||
xml_writer.write_event(Event::End(BytesEnd::new("D:getetag")))?;
|
||||
Self::write_etag_quoted(xml_writer, &folder.etag)?;
|
||||
}
|
||||
"getcontentlength" => {
|
||||
xml_writer
|
||||
@@ -1000,21 +1018,25 @@ impl WebDavAdapter {
|
||||
}
|
||||
"quota-used-bytes" => {
|
||||
if let Some((used, _)) = quota {
|
||||
let mut buf = [0u8; 21];
|
||||
xml_writer
|
||||
.write_event(Event::Start(BytesStart::new("D:quota-used-bytes")))?;
|
||||
xml_writer
|
||||
.write_event(Event::Text(BytesText::new(&used.to_string())))?;
|
||||
xml_writer.write_event(Event::Text(BytesText::new(
|
||||
crate::common::fmt::i64_str(&mut buf, used),
|
||||
)))?;
|
||||
xml_writer
|
||||
.write_event(Event::End(BytesEnd::new("D:quota-used-bytes")))?;
|
||||
}
|
||||
}
|
||||
"quota-available-bytes" => {
|
||||
if let Some((_, Some(available))) = quota {
|
||||
let mut buf = [0u8; 21];
|
||||
xml_writer.write_event(Event::Start(BytesStart::new(
|
||||
"D:quota-available-bytes",
|
||||
)))?;
|
||||
xml_writer
|
||||
.write_event(Event::Text(BytesText::new(&available.to_string())))?;
|
||||
xml_writer.write_event(Event::Text(BytesText::new(
|
||||
crate::common::fmt::i64_str(&mut buf, available),
|
||||
)))?;
|
||||
xml_writer.write_event(Event::End(BytesEnd::new(
|
||||
"D:quota-available-bytes",
|
||||
)))?;
|
||||
@@ -1035,7 +1057,7 @@ impl WebDavAdapter {
|
||||
fn write_file_requested_props<W: Write>(
|
||||
xml_writer: &mut Writer<W>,
|
||||
file: &FileDto,
|
||||
props: &[&QualifiedName],
|
||||
props: &[QualifiedName],
|
||||
) -> Result<()> {
|
||||
for prop in props {
|
||||
if prop.namespace == "DAV:" {
|
||||
@@ -1055,44 +1077,16 @@ impl WebDavAdapter {
|
||||
xml_writer.write_event(Event::End(BytesEnd::new("D:getcontenttype")))?;
|
||||
}
|
||||
"getcontentlength" => {
|
||||
xml_writer
|
||||
.write_event(Event::Start(BytesStart::new("D:getcontentlength")))?;
|
||||
xml_writer
|
||||
.write_event(Event::Text(BytesText::new(&file.size.to_string())))?;
|
||||
xml_writer.write_event(Event::End(BytesEnd::new("D:getcontentlength")))?;
|
||||
Self::write_contentlength(xml_writer, file.size)?;
|
||||
}
|
||||
"creationdate" => {
|
||||
xml_writer.write_event(Event::Start(BytesStart::new("D:creationdate")))?;
|
||||
|
||||
// Convert u64 timestamp to DateTime
|
||||
let created_at =
|
||||
chrono::DateTime::<Utc>::from_timestamp(file.created_at as i64, 0)
|
||||
.unwrap_or_else(Utc::now);
|
||||
|
||||
xml_writer
|
||||
.write_event(Event::Text(BytesText::new(&created_at.to_rfc3339())))?;
|
||||
xml_writer.write_event(Event::End(BytesEnd::new("D:creationdate")))?;
|
||||
Self::write_creationdate(xml_writer, file.created_at)?;
|
||||
}
|
||||
"getlastmodified" => {
|
||||
xml_writer
|
||||
.write_event(Event::Start(BytesStart::new("D:getlastmodified")))?;
|
||||
|
||||
// Convert u64 timestamp to DateTime
|
||||
let modified_at =
|
||||
chrono::DateTime::<Utc>::from_timestamp(file.modified_at as i64, 0)
|
||||
.unwrap_or_else(Utc::now);
|
||||
|
||||
xml_writer
|
||||
.write_event(Event::Text(BytesText::new(&modified_at.to_rfc2822())))?;
|
||||
xml_writer.write_event(Event::End(BytesEnd::new("D:getlastmodified")))?;
|
||||
Self::write_lastmodified(xml_writer, file.modified_at)?;
|
||||
}
|
||||
"getetag" => {
|
||||
xml_writer.write_event(Event::Start(BytesStart::new("D:getetag")))?;
|
||||
xml_writer.write_event(Event::Text(BytesText::new(&format!(
|
||||
"\"{}\"",
|
||||
file.etag
|
||||
))))?;
|
||||
xml_writer.write_event(Event::End(BytesEnd::new("D:getetag")))?;
|
||||
Self::write_etag_quoted(xml_writer, &file.etag)?;
|
||||
}
|
||||
_ => {
|
||||
// Unknown prop — skipped here; caller writes 404 propstat.
|
||||
@@ -1586,3 +1580,36 @@ impl WebDavAdapter {
|
||||
Self::write_file_response_with_dead_props(writer, file, request, href, dead_props)
|
||||
}
|
||||
}
|
||||
|
||||
/// Thin public wrappers over the private per-row PROPFIND writers so
|
||||
/// `examples/bench_propfind_xml.rs` can measure them. Gated behind the
|
||||
/// `bench` feature — adds nothing to prod builds.
|
||||
#[cfg(feature = "bench")]
|
||||
pub mod bench {
|
||||
use super::*;
|
||||
|
||||
pub fn write_file_propfind_row<W: Write>(
|
||||
xml_writer: &mut Writer<W>,
|
||||
file: &FileDto,
|
||||
request: &PropFindRequest,
|
||||
href: &str,
|
||||
dead_props: &[(QualifiedName, Option<String>)],
|
||||
) -> Result<()> {
|
||||
WebDavAdapter::write_file_response_with_dead_props(
|
||||
xml_writer, file, request, href, dead_props,
|
||||
)
|
||||
}
|
||||
|
||||
pub fn write_folder_propfind_row<W: Write>(
|
||||
xml_writer: &mut Writer<W>,
|
||||
folder: &FolderDto,
|
||||
request: &PropFindRequest,
|
||||
href: &str,
|
||||
dead_props: &[(QualifiedName, Option<String>)],
|
||||
quota: Option<(i64, Option<i64>)>,
|
||||
) -> Result<()> {
|
||||
WebDavAdapter::write_folder_response_with_dead_props(
|
||||
xml_writer, folder, request, href, dead_props, quota,
|
||||
)
|
||||
}
|
||||
}
|
||||
|
||||
@@ -34,6 +34,12 @@ pub trait CalendarStoragePort: Send + Sync + 'static {
|
||||
) -> Result<CalendarDto, DomainError>;
|
||||
async fn delete_calendar(&self, calendar_id: &str) -> Result<(), DomainError>;
|
||||
async fn get_calendar(&self, calendar_id: &str) -> Result<CalendarDto, DomainError>;
|
||||
|
||||
/// Batch sibling of [`Self::get_calendar`]: hydrate a page of
|
||||
/// grant-derived calendar ids in ONE storage round-trip. Missing
|
||||
/// rows (deleted/trashed race) drop out silently; ordering is not
|
||||
/// guaranteed.
|
||||
async fn get_calendars_by_ids(&self, ids: &[Uuid]) -> Result<Vec<CalendarDto>, DomainError>;
|
||||
async fn list_calendars_by_owner(
|
||||
&self,
|
||||
owner_id: Uuid,
|
||||
|
||||
@@ -37,6 +37,12 @@ pub trait ContactStoragePort: Send + Sync + 'static {
|
||||
) -> Result<AddressBook, DomainError>;
|
||||
async fn delete_address_book(&self, id: &Uuid) -> Result<(), DomainError>;
|
||||
async fn get_address_book_by_id(&self, id: &Uuid) -> Result<Option<AddressBook>, DomainError>;
|
||||
|
||||
/// Batch sibling of [`Self::get_address_book_by_id`]: hydrate a page
|
||||
/// of grant-derived ids in ONE storage round-trip. Missing rows drop
|
||||
/// out silently; ordering is not guaranteed.
|
||||
async fn get_address_books_by_ids(&self, ids: &[Uuid])
|
||||
-> Result<Vec<AddressBook>, DomainError>;
|
||||
async fn get_public_address_books(&self) -> Result<Vec<AddressBook>, DomainError>;
|
||||
|
||||
// ── Contacts ─────────────────────────────────────────────────
|
||||
|
||||
@@ -104,6 +104,11 @@ pub trait MusicStoragePort: Send + Sync {
|
||||
|
||||
async fn get_playlist(&self, playlist_id: &str) -> Result<Option<PlaylistDto>, DomainError>;
|
||||
|
||||
/// Batch sibling of [`Self::get_playlist`]: hydrate a page of
|
||||
/// grant-derived ids in ONE storage round-trip. Missing rows drop
|
||||
/// out silently; ordering is not guaranteed.
|
||||
async fn get_playlists_by_ids(&self, ids: &[Uuid]) -> Result<Vec<PlaylistDto>, DomainError>;
|
||||
|
||||
async fn list_playlists_by_owner(
|
||||
&self,
|
||||
owner_id: Uuid,
|
||||
|
||||
@@ -147,8 +147,12 @@ pub struct AuthApplicationService {
|
||||
/// request. The short TTL keeps the "role changes apply without token
|
||||
/// rotation" property within seconds while removing one DB round-trip
|
||||
/// per request; the known mutation paths (`change_user_role`,
|
||||
/// `set_user_active`) also invalidate eagerly.
|
||||
user_flags_cache: Cache<Uuid, UserFlags>,
|
||||
/// `set_user_active`) also invalidate eagerly. `moka::future` so
|
||||
/// concurrent misses for one user coalesce into a single DB lookup
|
||||
/// (`try_get_with` single-flight) — every authenticated request
|
||||
/// calls this, so each 30 s TTL expiry used to fan out one SELECT
|
||||
/// per in-flight request of that user.
|
||||
user_flags_cache: moka::future::Cache<Uuid, UserFlags>,
|
||||
/// Self-service auth-method allowlist (mirrors
|
||||
/// `AuthConfig::allowed_auth_methods`). Empty = both methods
|
||||
/// allowed. Consulted by login / register / magic-link handlers via
|
||||
@@ -198,7 +202,7 @@ impl AuthApplicationService {
|
||||
.time_to_live(Duration::from_secs(120))
|
||||
.build(),
|
||||
magic_link_repo: None,
|
||||
user_flags_cache: Cache::builder()
|
||||
user_flags_cache: moka::future::Cache::builder()
|
||||
.max_capacity(10_000)
|
||||
.time_to_live(USER_FLAGS_CACHE_TTL)
|
||||
.build(),
|
||||
@@ -1363,7 +1367,7 @@ impl AuthApplicationService {
|
||||
// Invalidate the flags cache so subsequent per-request guards
|
||||
// observe the new `is_external=false` without waiting for the
|
||||
// 30-second TTL. Same pattern as `change_user_role`.
|
||||
self.user_flags_cache.invalidate(&caller_id);
|
||||
self.user_flags_cache.invalidate(&caller_id).await;
|
||||
|
||||
// Dispatch — home-drive provisioning happens here. Log-and-
|
||||
// continue: a provisioning failure leaves the row updated and
|
||||
@@ -1508,12 +1512,20 @@ impl AuthApplicationService {
|
||||
/// Staleness is bounded by [`USER_FLAGS_CACHE_TTL`]; role and active
|
||||
/// changes made through this service invalidate the entry eagerly.
|
||||
pub async fn get_user_flags(&self, user_id: Uuid) -> Result<UserFlags, DomainError> {
|
||||
if let Some(flags) = self.user_flags_cache.get(&user_id) {
|
||||
return Ok(flags);
|
||||
}
|
||||
let flags = self.user_storage.get_user_flags(user_id).await?;
|
||||
self.user_flags_cache.insert(user_id, flags);
|
||||
Ok(flags)
|
||||
// Single-flight: concurrent misses for the same user coalesce
|
||||
// into ONE storage lookup; errors are never cached (same herd
|
||||
// shape ROUND3 fixed for basic-auth, minus the Argon2 cost).
|
||||
self.user_flags_cache
|
||||
.try_get_with(user_id, async {
|
||||
Ok::<_, DomainError>(self.user_storage.get_user_flags(user_id).await?)
|
||||
})
|
||||
.await
|
||||
// try_get_with hands back `Arc<DomainError>` shared by all
|
||||
// waiters; DomainError isn't Clone, so rebuild a fresh one
|
||||
// preserving the kind / entity / message.
|
||||
.map_err(|shared: std::sync::Arc<DomainError>| {
|
||||
DomainError::new(shared.kind, shared.entity_type, shared.message.clone())
|
||||
})
|
||||
}
|
||||
|
||||
/// Apply a profile update on behalf of the calling user (PR 24).
|
||||
@@ -2226,7 +2238,7 @@ impl AuthApplicationService {
|
||||
self.user_storage
|
||||
.set_user_active_status(user_id, active)
|
||||
.await?;
|
||||
self.user_flags_cache.invalidate(&user_id);
|
||||
self.user_flags_cache.invalidate(&user_id).await;
|
||||
Ok(())
|
||||
}
|
||||
|
||||
@@ -2240,7 +2252,7 @@ impl AuthApplicationService {
|
||||
));
|
||||
}
|
||||
self.user_storage.change_role(user_id, role).await?;
|
||||
self.user_flags_cache.invalidate(&user_id);
|
||||
self.user_flags_cache.invalidate(&user_id).await;
|
||||
Ok(())
|
||||
}
|
||||
|
||||
|
||||
@@ -189,17 +189,13 @@ impl CalendarUseCase for CalendarService {
|
||||
})
|
||||
.collect();
|
||||
|
||||
// Hydrate DTOs. `get_calendar` misses on trashed / deleted
|
||||
// calendars — those are dropped from the listing rather than
|
||||
// erroring, so a lifecycle-race doesn't turn a PROPFIND into
|
||||
// a 5xx.
|
||||
let mut out = Vec::with_capacity(calendar_ids.len());
|
||||
for id in calendar_ids {
|
||||
if let Ok(dto) = self.calendar_storage.get_calendar(&id.to_string()).await {
|
||||
out.push(dto);
|
||||
}
|
||||
}
|
||||
Ok(out)
|
||||
// Hydrate DTOs in ONE `= ANY` round-trip (was one point SELECT
|
||||
// per accessible calendar — K serial round-trips on every
|
||||
// CalDAV discovery poll). Missing rows (deleted/trashed race)
|
||||
// drop out of the result set instead of erroring, so a
|
||||
// lifecycle-race still doesn't turn a PROPFIND into a 5xx.
|
||||
let ids: Vec<Uuid> = calendar_ids.into_iter().collect();
|
||||
self.calendar_storage.get_calendars_by_ids(&ids).await
|
||||
}
|
||||
|
||||
async fn list_public_calendars(
|
||||
|
||||
@@ -494,12 +494,14 @@ impl AddressBookUseCase for ContactService {
|
||||
|
||||
let mut address_book_map = std::collections::HashMap::new();
|
||||
|
||||
for id in book_ids {
|
||||
// Missing rows (deleted / trashed race) drop out silently
|
||||
// — matches the calendar-listing carve-out.
|
||||
if let Ok(Some(book)) = self.contact_storage.get_address_book_by_id(&id).await {
|
||||
address_book_map.insert(*book.id(), book);
|
||||
}
|
||||
// Hydrate in ONE `= ANY` round-trip (was one point SELECT per
|
||||
// accessible book — K serial round-trips on every CardDAV
|
||||
// discovery poll). Missing rows (deleted / trashed race) drop
|
||||
// out of the result set — matches the calendar-listing
|
||||
// carve-out.
|
||||
let ids: Vec<Uuid> = book_ids.into_iter().collect();
|
||||
for book in self.contact_storage.get_address_books_by_ids(&ids).await? {
|
||||
address_book_map.insert(*book.id(), book);
|
||||
}
|
||||
|
||||
// Public address books surface for every authenticated caller
|
||||
|
||||
@@ -263,6 +263,12 @@ impl DriveManagementService {
|
||||
self.authz
|
||||
.invalidate_drive_role_cache_for_drive(drive_id)
|
||||
.await;
|
||||
// Same freshness contract for the repo's readable-drives cache:
|
||||
// the subject's drive list changed with this grant.
|
||||
match subject {
|
||||
Subject::User(uid) => self.drive_repo.invalidate_readable_for_user(uid).await,
|
||||
_ => self.drive_repo.invalidate_readable_all(),
|
||||
}
|
||||
|
||||
// D6 §11: canonical `drive.member_added` audit event covers
|
||||
// every successful membership write (add + role-refresh, since
|
||||
@@ -335,6 +341,12 @@ impl DriveManagementService {
|
||||
self.authz
|
||||
.invalidate_drive_role_cache_for_drive(drive_id)
|
||||
.await;
|
||||
// And the repo's readable-drives cache: the drive must vanish
|
||||
// from the removed subject's list immediately.
|
||||
match subject {
|
||||
Subject::User(uid) => self.drive_repo.invalidate_readable_for_user(uid).await,
|
||||
_ => self.drive_repo.invalidate_readable_all(),
|
||||
}
|
||||
|
||||
// D6 §11: canonical `drive.member_removed` audit event covers
|
||||
// every successful removal (owner-driven or admin bypass).
|
||||
|
||||
@@ -196,15 +196,18 @@ impl MusicUseCase for MusicService {
|
||||
// only. Owner is a grant like any other in `role_grants`, so we
|
||||
// filter the aggregated set against the owner_id stamped on
|
||||
// each row after hydration — cheaper than a second SQL round-trip.
|
||||
let mut playlists: Vec<PlaylistDto> = Vec::with_capacity(playlist_ids.len());
|
||||
// Hydrate in ONE `= ANY` round-trip (was one point SELECT per
|
||||
// accessible playlist). Missing rows (deleted race) drop out of
|
||||
// the result set silently, as before.
|
||||
let user_str = user_id.to_string();
|
||||
for id in playlist_ids.drain() {
|
||||
if let Ok(Some(p)) = self.storage.get_playlist(&id.to_string()).await
|
||||
&& (include_shared || p.owner_id == user_str)
|
||||
{
|
||||
playlists.push(p);
|
||||
}
|
||||
}
|
||||
let ids: Vec<Uuid> = playlist_ids.drain().collect();
|
||||
let mut playlists: Vec<PlaylistDto> = self
|
||||
.storage
|
||||
.get_playlists_by_ids(&ids)
|
||||
.await?
|
||||
.into_iter()
|
||||
.filter(|p| include_shared || p.owner_id == user_str)
|
||||
.collect();
|
||||
|
||||
if include_public {
|
||||
let public = self.storage.list_public_playlists(limit, offset).await?;
|
||||
|
||||
@@ -44,6 +44,11 @@ pub struct SubjectGroupService {
|
||||
/// 30 s TTL. Without this, fresh group-mediated drive grants
|
||||
/// don't appear in `/api/drives` for up to 30 s after `add_member`.
|
||||
engine: Arc<crate::infrastructure::services::pg_acl_engine::PgAclEngine>,
|
||||
/// Same freshness contract for the drive repository's per-user
|
||||
/// readable-drives cache: a membership change on a group that holds
|
||||
/// drive grants changes every affected user's visible drive list,
|
||||
/// so the cached lists drop alongside `user_groups_cache`.
|
||||
drive_repo: Arc<crate::infrastructure::repositories::pg::DrivePgRepository>,
|
||||
}
|
||||
|
||||
impl SubjectGroupService {
|
||||
@@ -52,12 +57,14 @@ impl SubjectGroupService {
|
||||
pool: Arc<PgPool>,
|
||||
user_storage: Arc<UserPgRepository>,
|
||||
engine: Arc<crate::infrastructure::services::pg_acl_engine::PgAclEngine>,
|
||||
drive_repo: Arc<crate::infrastructure::repositories::pg::DrivePgRepository>,
|
||||
) -> Self {
|
||||
Self {
|
||||
repo,
|
||||
pool,
|
||||
user_storage,
|
||||
engine,
|
||||
drive_repo,
|
||||
}
|
||||
}
|
||||
|
||||
@@ -426,6 +433,7 @@ impl SubjectGroupService {
|
||||
// call for up to 30 s.
|
||||
for uid in self.invalidation_targets(member).await? {
|
||||
self.engine.invalidate_user_groups_cache(uid).await;
|
||||
self.drive_repo.invalidate_readable_for_user(uid).await;
|
||||
}
|
||||
|
||||
tracing::info!(
|
||||
@@ -525,6 +533,7 @@ impl SubjectGroupService {
|
||||
// for up to 30 s, surfacing grants they no longer have.
|
||||
for uid in self.invalidation_targets(member).await? {
|
||||
self.engine.invalidate_user_groups_cache(uid).await;
|
||||
self.drive_repo.invalidate_readable_for_user(uid).await;
|
||||
}
|
||||
|
||||
tracing::info!(
|
||||
@@ -634,7 +643,9 @@ mod integration_tests {
|
||||
// future test starts exercising real authz lookups.
|
||||
let engine =
|
||||
Arc::new(crate::infrastructure::services::pg_acl_engine::PgAclEngine::new_stub());
|
||||
SubjectGroupService::new(repo, pool, user_storage, engine)
|
||||
let drive_repo =
|
||||
Arc::new(crate::infrastructure::repositories::pg::DrivePgRepository::new(pool.clone()));
|
||||
SubjectGroupService::new(repo, pool, user_storage, engine, drive_repo)
|
||||
}
|
||||
|
||||
async fn first_admin(pool: &sqlx::PgPool) -> Uuid {
|
||||
|
||||
Reference in New Issue
Block a user