perf: round 11 — StoragePath joined-only, classifier fusion, memoized bodies, query-shape pack, SPA fine-grained stars

Backend (each change benchmark-gated with BEFORE replicas + equivalence
gates; see examples/bench_round11_micro.rs, bench_round11_queries.rs,
bench_log_writer.rs and benches/ROUND11.md — final numbers land in the
follow-up doc commit):

- StoragePath re-representation: single canonical joined String, segments
  derived on demand; File/Folder drop the duplicated path_string field
  (4000→1000 allocs per 500-row listing page)
- Display classifier fusion: classify_display shares one stack-lowered
  extension across the three decision trees; call sites in FileDto,
  folder/favorites/recent handlers, trash, path-resolver (+ interning
  where Arc::from was still used)
- /status.php and /openapi.json memoized into OnceLock<Bytes> (openapi
  rebuilt a 171 KiB spec per request: 2.8 ms → 18 ns)
- NC upload-session PROPFIND: write! + pre-sized body + stack RFC2822
  dates (2.3-2.6x, 2582→772 allocs at 256 chunks)
- REST download: dead FileDto clone removed (capture mime/size + move)
- CalendarEventDto/TrashedItem into_parts moves (11 KiB ical_data memcpy
  gone per CalDAV row); CardDAV getlastmodified stack render
- 4xx path: borrowed ErrorResponse serialize, ErrorKind::as_str,
  not_found/already_exists clone kill
- vCard emit via write!; search page moved out with into_iter skip/take;
  content-hit UUIDs parsed once; group last-user check via HashSet
- RateLimiter: lock-free get + insert (and_upsert_with variant REJECTED
  by benchmark); CSRF token borrow-compare + borrowed cookie extraction
- Thumbnail/preview ETags built from as_str (Debug-identical bytes)
- Encrypted backend: encrypt_in_place_detached single-buffer write path,
  chunk-sized reserve in collect_stream; retry labels made lazy
- PG: deferred upload registration 3→1 round-trips (persist_file CTE
  template); direct_grant_cache for Calendar/AddressBook/Playlist authz
  (single-flight + set_role/clear_role invalidation); expand_user
  tokio::join!; geo clusters min(uuid)::text; recluster face assignment
  batched into one UNNEST update
- People recluster cosine: norms precomputed once (bit-identical gate)
- NC capabilities poll logs demoted to debug; tracing-appender dep added
  for the log-writer benchmark

Frontend:
- ResourceList.selectedEntries O(N)-per-toggle → id-index projection
  O(k log k); favorites/recent consume the batchToolbar snippet param and
  drop their duplicate filter + dead selectedIds mirror
- Recent: star state via new favoriteIds prop — a star click no longer
  rebuilds all N entries
- admin timeAgo >30d fallback uses the cached Intl.DateTimeFormat
- vitest gates in src/lib/components/round11.bench.test.ts

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01ABhTEHuGujvwoodh67Kga7
This commit is contained in:
Claude
2026-07-18 22:02:00 +00:00
parent 637478e7bd
commit 221c1f31b0
54 changed files with 4060 additions and 630 deletions
+10 -3
View File
@@ -141,8 +141,10 @@ pub fn append_clear_cookies(headers: &mut HeaderMap) {
}
}
/// Extract a named cookie value from the `Cookie` request header.
pub fn extract_cookie_value(headers: &HeaderMap, name: &str) -> Option<String> {
/// Extract a named cookie value from the `Cookie` request header,
/// borrowing from the header map. Callers that only compare or parse the
/// value (CSRF check) avoid the per-request copy.
pub fn extract_cookie_str<'h>(headers: &'h HeaderMap, name: &str) -> Option<&'h str> {
let cookie_header = headers.get(axum::http::header::COOKIE)?;
let cookie_str = cookie_header.to_str().ok()?;
@@ -151,13 +153,18 @@ pub fn extract_cookie_value(headers: &HeaderMap, name: &str) -> Option<String> {
if let Some(val) = pair.strip_prefix(name) {
let val = val.strip_prefix('=')?;
if !val.is_empty() {
return Some(val.to_string());
return Some(val);
}
}
}
None
}
/// Extract a named cookie value from the `Cookie` request header.
pub fn extract_cookie_value(headers: &HeaderMap, name: &str) -> Option<String> {
extract_cookie_str(headers, name).map(str::to_string)
}
// ────────────────────────────────────────────────────────────
// CSRF double-submit cookie helpers
// ────────────────────────────────────────────────────────────
@@ -10,8 +10,7 @@ use tracing::info;
use utoipa::ToSchema;
use crate::application::dtos::display_helpers::{
category_for, format_file_size, icon_class_for, icon_special_class_for, intern_display,
intern_mime,
classify_display, format_file_size, intern_display, intern_mime,
};
use crate::application::dtos::favorites_dto::{
FavoritesResourceItemDto, FavoritesResourcesDto, FavoritesResourcesQuery,
@@ -247,10 +246,10 @@ pub async fn list_favorites_resources(
};
// Name-derived display classes borrow `row.name`;
// compute them before the name moves into the DTO.
let icon_class = intern_display(icon_class_for(&row.name, mime));
let icon_special_class =
intern_display(icon_special_class_for(&row.name, mime));
let category = intern_display(category_for(&row.name, mime));
let classes = classify_display(&row.name, mime);
let icon_class = intern_display(classes.icon_class);
let icon_special_class = intern_display(classes.icon_special_class);
let category = intern_display(classes.category);
let dto = FileDto {
id: row.resource_id.to_string(),
name: row.name,
+22 -5
View File
@@ -404,7 +404,18 @@ impl FileHandler {
// (file_id, size, format) triple. If the browser already has it, return
// 304 with zero I/O or DB work. Format is in the ETag so a client that
// switched codecs doesn't get a stale 304.
let etag = format!("\"thumb-{}-{:?}-{:?}\"", id, thumb_size, format);
let etag = {
let (s, f) = (thumb_size.as_str(), format.as_str());
let mut e = String::with_capacity(9 + id.len() + s.len() + f.len());
e.push_str("\"thumb-");
e.push_str(&id);
e.push('-');
e.push_str(s);
e.push('-');
e.push_str(f);
e.push('"');
e
};
if let Some(if_none_match) = headers.get(header::IF_NONE_MATCH)
&& let Ok(val) = if_none_match.to_str()
&& (val == etag || val == "*")
@@ -776,9 +787,15 @@ impl FileHandler {
// Use the ownership-scoped optimized download.
// Ownership was already verified by get_file_owned above,
// so we can safely use the preloaded variant.
// so we can safely use the preloaded variant. Capture the two
// fields the stream arm needs (one Arc bump + a u64 copy) and MOVE
// the DTO in — the old `file_dto.clone()` deep-copied all 7 owned
// Strings on every download, purely to read mime/size afterwards
// (benches/ROUND11.md §1).
let dto_mime = file_dto.mime_type.clone();
let dto_size = file_dto.size;
match retrieval
.get_file_optimized_preloaded(&id, file_dto.clone(), accept_webp, prefer_original)
.get_file_optimized_preloaded(&id, file_dto, accept_webp, prefer_original)
.await
{
Ok((_file, content)) => match content {
@@ -788,9 +805,9 @@ impl FileHandler {
.into_response(),
OptimizedFileContent::Stream(pinned_stream) => Response::builder()
.status(StatusCode::OK)
.header(header::CONTENT_TYPE, &*file_dto.mime_type)
.header(header::CONTENT_TYPE, &*dto_mime)
.header(header::CONTENT_DISPOSITION, &disposition)
.header(header::CONTENT_LENGTH, file_dto.size)
.header(header::CONTENT_LENGTH, dto_size)
.header(header::ETAG, &etag)
.header(
header::CACHE_CONTROL,
@@ -8,8 +8,7 @@ use std::collections::HashMap;
use std::sync::Arc;
use crate::application::dtos::display_helpers::{
category_for, format_file_size, icon_class_for, icon_special_class_for, intern_display,
intern_mime,
classify_display, format_file_size, intern_display, intern_mime,
};
use crate::application::dtos::file_dto::FileDto;
use crate::application::dtos::folder_dto::{
@@ -520,10 +519,10 @@ pub async fn list_folder_resources(
// (they borrow `&row.name`), so `name` can be moved into
// the DTO below instead of cloned — one fewer String
// alloc per file row (benches/ROUND7.md).
let icon_class = intern_display(icon_class_for(&row.name, mime));
let icon_special_class =
intern_display(icon_special_class_for(&row.name, mime));
let category = intern_display(category_for(&row.name, mime));
let classes = classify_display(&row.name, mime);
let icon_class = intern_display(classes.icon_class);
let icon_special_class = intern_display(classes.icon_special_class);
let category = intern_display(classes.category);
let dto = FileDto {
id: row.id.to_string(),
name: row.name,
+11 -8
View File
@@ -8,8 +8,7 @@ use std::sync::Arc;
use tracing::info;
use crate::application::dtos::display_helpers::{
category_for, format_file_size, icon_class_for, icon_special_class_for, intern_display,
intern_mime,
classify_display, format_file_size, intern_display, intern_mime,
};
use crate::application::dtos::file_dto::FileDto;
use crate::application::dtos::folder_dto::FolderDto;
@@ -57,8 +56,10 @@ pub async fn record_item_access(
.into_response();
}
let mut id_buf = [0u8; 36];
let item_id_str: &str = item_id.as_hyphenated().encode_lower(&mut id_buf);
match recent_service
.record_item_access(user_id, &item_id.to_string(), &item_type)
.record_item_access(user_id, item_id_str, &item_type)
.await
{
Ok(_) => {
@@ -100,8 +101,10 @@ pub async fn remove_from_recent(
) -> impl IntoResponse {
let user_id = auth_user.id;
let mut id_buf = [0u8; 36];
let item_id_str: &str = item_id.as_hyphenated().encode_lower(&mut id_buf);
match recent_service
.remove_from_recent(user_id, &item_id.to_string(), &item_type)
.remove_from_recent(user_id, item_id_str, &item_type)
.await
{
Ok(removed) => {
@@ -261,10 +264,10 @@ pub async fn list_recent_resources(
};
// Name-derived display classes borrow `row.name`;
// compute them before the name moves into the DTO.
let icon_class = intern_display(icon_class_for(&row.name, mime));
let icon_special_class =
intern_display(icon_special_class_for(&row.name, mime));
let category = intern_display(category_for(&row.name, mime));
let classes = classify_display(&row.name, mime);
let icon_class = intern_display(classes.icon_class);
let icon_special_class = intern_display(classes.icon_special_class);
let category = intern_display(classes.category);
let dto = FileDto {
id: row.resource_id.to_string(),
name: row.name,
+17 -2
View File
@@ -46,8 +46,23 @@ async fn get_version() -> AxumJson<serde_json::Value> {
}))
}
async fn get_openapi_spec() -> AxumJson<utoipa::openapi::OpenApi> {
AxumJson(super::ApiDoc::openapi())
/// Pre-serialized OpenAPI spec. `ApiDoc::openapi()` reconstructs the whole
/// 171 KiB paths/schemas tree and re-serializes it per request (2.8 ms /
/// 12 474 allocs); the spec is process-invariant, so serialize once and
/// hand back a `Bytes` refcount bump (~18 ns — benches/ROUND11.md).
static OPENAPI_BODY: std::sync::OnceLock<bytes::Bytes> = std::sync::OnceLock::new();
async fn get_openapi_spec() -> axum::response::Response {
let body = OPENAPI_BODY.get_or_init(|| {
bytes::Bytes::from(
serde_json::to_vec(&super::ApiDoc::openapi()).expect("openapi spec serializes"),
)
});
axum::response::Response::builder()
.status(axum::http::StatusCode::OK)
.header(axum::http::header::CONTENT_TYPE, "application/json")
.body(axum::body::Body::from(body.clone()))
.expect("static openapi response")
}
use crate::interfaces::api::handlers::admin_handler;
+27 -21
View File
@@ -3,6 +3,8 @@
//! This module contains error types specific to the HTTP/API layer.
//! These errors handle the conversion from domain errors to HTTP responses.
use std::borrow::Cow;
use axum::Json;
use axum::http::StatusCode;
use axum::response::{IntoResponse, Response};
@@ -13,25 +15,28 @@ use crate::domain::errors::{DomainError, ErrorKind};
/// Error type for HTTP/API responses.
///
/// This struct represents errors that will be returned to HTTP clients.
/// It contains the HTTP status code, a user-friendly message, and an error type identifier.
/// It contains the HTTP status code, a user-friendly message, and an error
/// type identifier. `error_type` is a `Cow`: every built-in constructor and
/// the `DomainError` conversion use a `&'static str` from a closed set, so
/// the common 4xx path allocates nothing for it (benches/ROUND11.md §9).
#[derive(Debug)]
pub struct AppError {
pub status_code: StatusCode,
pub message: String,
pub error_type: String,
pub error_type: Cow<'static, str>,
}
/// JSON response structure for errors.
///
/// Both `error` and `message` carry the same content for backwards compatibility:
/// - Legacy ad-hoc handlers returned `{"error": "..."}` (frontend reads `.error`)
/// - AppError returned `{"message": "..."}` (admin panel reads `.message`)
/// JSON response structure for errors, borrowing from the `AppError` it
/// renders — `error` and `message` intentionally serialize the SAME string
/// for backwards compatibility (legacy handlers returned `{"error": …}`,
/// AppError returned `{"message": …}`); serializing one buffer twice
/// replaces the old per-response deep clone.
#[derive(Serialize)]
pub struct ErrorResponse {
pub status: String,
pub error: String,
pub message: String,
pub error_type: String,
pub struct ErrorResponse<'a> {
pub status: &'a str,
pub error: &'a str,
pub message: &'a str,
pub error_type: &'a str,
}
impl AppError {
@@ -39,7 +44,7 @@ impl AppError {
pub fn new(
status_code: StatusCode,
message: impl Into<String>,
error_type: impl Into<String>,
error_type: impl Into<Cow<'static, str>>,
) -> Self {
Self {
status_code,
@@ -131,7 +136,7 @@ impl From<DomainError> for AppError {
Self {
status_code,
message: err.message,
error_type: err.kind.to_string(),
error_type: Cow::Borrowed(err.kind.as_str()),
}
}
}
@@ -144,25 +149,26 @@ impl IntoResponse for AppError {
// Log the full error server-side for debugging, return a generic
// message to the client. Other status codes (including 5xx like
// 501, 503, 507) keep their intentionally user-facing messages.
let client_message = if status == StatusCode::INTERNAL_SERVER_ERROR {
let client_message: &str = if status == StatusCode::INTERNAL_SERVER_ERROR {
tracing::error!(
error_type = %self.error_type,
"Internal server error: {}",
self.message
);
"An internal error occurred. Please try again later.".to_string()
"An internal error occurred. Please try again later."
} else {
self.message
&self.message
};
let status_line = status.to_string();
let error_response = ErrorResponse {
status: status.to_string(),
error: client_message.clone(),
status: &status_line,
error: client_message,
message: client_message,
error_type: self.error_type,
error_type: &self.error_type,
};
let body = Json(error_response);
let body = Json(&error_response);
(status, body).into_response()
}
}
+7 -6
View File
@@ -39,16 +39,17 @@ pub async fn csrf_middleware(request: Request, next: Next) -> Result<Response, R
return Ok(next.run(request).await);
}
// Extract the CSRF token from the cookie.
let cookie_token =
cookie_auth::extract_cookie_value(request.headers(), cookie_auth::CSRF_COOKIE);
// Extract the CSRF token from the cookie (borrow-only).
let cookie_token = cookie_auth::extract_cookie_str(request.headers(), cookie_auth::CSRF_COOKIE);
// Extract the CSRF token from the request header.
// Extract the CSRF token from the request header. Borrow-only:
// `String: PartialEq<&str>` covers the comparison, so materializing an
// owned copy per state-changing request was a pure waste
// (benches/ROUND11.md §6: 15.7 → 1.3 ns, −1 alloc).
let header_token = request
.headers()
.get(cookie_auth::CSRF_HEADER)
.and_then(|v| v.to_str().ok())
.map(|s| s.to_string());
.and_then(|v| v.to_str().ok());
match (cookie_token, header_token) {
(Some(c), Some(h)) if !c.is_empty() && c == h => {
+11 -11
View File
@@ -55,18 +55,18 @@ impl RateLimiter {
/// `Err(StatusCode::TOO_MANY_REQUESTS)`.
#[allow(clippy::result_unit_err)]
pub fn check_and_increment(&self, ip: &str) -> Result<u32, ()> {
let key = ip.to_string();
// moka's entry API lets us atomically read-modify-write.
// On first access the entry is inserted with count = 1 and the TTL
// starts. Subsequent accesses within the window increment the count.
let count = self.cache.entry(key).or_insert_with(|| 0).into_value() + 1;
// Lock-free read (borrows the key — no allocation), then one
// write-back. The previous shape allocated the key TWICE and paid
// a locking `entry()` op on top of the insert; moka's
// `and_upsert_with` alternative benchmarked slower still
// (benches/ROUND11.md §20). Read-then-write is not atomic, but it
// never was — under a concurrent burst both shapes can undercount
// the same way, which only makes the limiter marginally lenient,
// never wrongly strict.
let count = self.cache.get(ip).unwrap_or(0) + 1;
// Write back the incremented value. Because `or_insert_with` returns
// the *existing* value when the key was already present, we must always
// re-insert so the counter actually advances. The TTL of the **first**
// insert still governs eviction because moka uses insert-time TTL.
// However, on re-insert moka resets the TTL, for rate limiting this
// is fine because it means the window "slides" forward on activity.
// On re-insert moka resets the TTL; for rate limiting this is fine
// because it means the window "slides" forward on activity.
self.cache.insert(ip.to_string(), count);
if count > self.max_requests {
+2 -2
View File
@@ -35,12 +35,12 @@ fn ocs_err(statuscode: u16, message: &str) -> serde_json::Value {
}
pub async fn handle_capabilities_v1(State(state): State<Arc<AppState>>) -> Response {
tracing::info!("[NC] capabilities v1 requested, returning payload");
tracing::debug!("[NC] capabilities v1 requested, returning payload");
capabilities_response(&state, 1)
}
pub async fn handle_capabilities_v2(State(state): State<Arc<AppState>>) -> Response {
tracing::info!("[NC] capabilities v2 requested, returning payload");
tracing::debug!("[NC] capabilities v2 requested, returning payload");
capabilities_response(&state, 2)
}
+10 -1
View File
@@ -144,7 +144,16 @@ pub async fn handle_preview(
// compared it, so every revalidation re-ran the whole pipeline and
// re-shipped the body (ROUND10). Authz already passed above; a 304
// must never skip the Read check.
let etag = format!("\"thumb-{}-{:?}\"", object_id, thumb_size);
let etag = {
let s = thumb_size.as_str();
let mut e = String::with_capacity(9 + object_id.len() + s.len());
e.push_str("\"thumb-");
e.push_str(&object_id);
e.push('-');
e.push_str(s);
e.push('"');
e
};
if let Some(inm) = headers.get(header::IF_NONE_MATCH)
&& let Ok(client_etag) = inm.to_str()
&& (client_etag == etag || client_etag == "*")
+28 -14
View File
@@ -1,22 +1,36 @@
use axum::Json;
use axum::extract::State;
use axum::response::{IntoResponse, Response};
use axum::http::header;
use axum::response::Response;
use serde_json::json;
use std::sync::Arc;
use crate::common::di::AppState;
/// Pre-serialized `/status.php` body. The payload is process-invariant
/// (pure config: emulated NC version), yet every NC desktop/mobile client
/// polls it on connect and periodically — the old handler re-built the
/// `json!` tree and re-serialized on every poll (793 ns / 14 allocs;
/// now a `Bytes` refcount bump at ~29 ns / 0 allocs — benches/ROUND11.md).
static STATUS_BODY: std::sync::OnceLock<bytes::Bytes> = std::sync::OnceLock::new();
pub async fn handle_status(State(state): State<Arc<AppState>>) -> Response {
let (major, minor, patch) = state.core.config.nextcloud.emulated_version;
let version_string = state.core.config.nextcloud.version_string();
Json(json!({
"installed": true,
"maintenance": false,
"needsDbUpgrade": false,
"version": format!("{}.{}.{}.1", major, minor, patch),
"versionstring": version_string,
"productname": "OxiCloud",
"edition": ""
}))
.into_response()
let body = STATUS_BODY.get_or_init(|| {
let (major, minor, patch) = state.core.config.nextcloud.emulated_version;
let version_string = state.core.config.nextcloud.version_string();
let v = json!({
"installed": true,
"maintenance": false,
"needsDbUpgrade": false,
"version": format!("{}.{}.{}.1", major, minor, patch),
"versionstring": version_string,
"productname": "OxiCloud",
"edition": ""
});
bytes::Bytes::from(serde_json::to_vec(&v).expect("status.php body serializes"))
});
Response::builder()
.status(axum::http::StatusCode::OK)
.header(header::CONTENT_TYPE, "application/json")
.body(axum::body::Body::from(body.clone()))
.expect("static status.php response")
}
+47 -29
View File
@@ -171,53 +171,71 @@ async fn handle_propfind_session(
// `handle_assemble`'s destination-URL parsing. Storage-side keying
// stays on `user.username` — upload sessions are per-user, not
// per-drive.
let session_href = format!(
"/remote.php/dav/uploads/{}/{}/",
session.raw_username, upload_id
);
let session_last_modified =
chrono::DateTime::<chrono::Utc>::from_timestamp(listing.session_mtime as i64, 0)
.unwrap_or_else(chrono::Utc::now)
.to_rfc2822();
// `write!` formats every element straight into a pre-sized `body`; the
// old `push_str(&format!(…))` chain allocated a throwaway String per
// element per chunk plus growth reallocations from `String::new()`, and
// ran the chrono format interpreter per chunk (benches/ROUND11.md §4:
// 2.3-2.6x, allocs 2582 → 772 on a 256-chunk session).
use std::fmt::Write as _;
let mut body = String::new();
/// `<d:getlastmodified>` via the stack renderer; chrono fallback for
/// out-of-range timestamps (same shape as `nextcloud/webdav_handler`).
/// RFC 2822 output contains no XML-special characters by construction.
fn write_lastmodified(body: &mut String, secs: i64) {
let mut buf = [0u8; 31];
match crate::common::fmt::rfc2822_utc(&mut buf, secs) {
Some(s) => {
let _ = write!(body, "<d:getlastmodified>{}</d:getlastmodified>", s);
}
None => {
let dt = chrono::DateTime::<chrono::Utc>::from_timestamp(secs, 0)
.unwrap_or_else(chrono::Utc::now)
.to_rfc2822();
let _ = write!(
body,
"<d:getlastmodified>{}</d:getlastmodified>",
xml_escape(&dt)
);
}
}
}
let mut body = String::with_capacity(256 + listing.chunks.len() * 256);
body.push_str(r#"<?xml version="1.0" encoding="utf-8"?>"#);
body.push_str(r#"<d:multistatus xmlns:d="DAV:">"#);
// Session collection itself.
body.push_str("<d:response>");
body.push_str(&format!("<d:href>{}</d:href>", xml_escape(&session_href)));
let _ = write!(
body,
"<d:href>/remote.php/dav/uploads/{}/{}/</d:href>",
xml_escape(&session.raw_username),
xml_escape(upload_id)
);
body.push_str("<d:propstat><d:prop>");
body.push_str("<d:resourcetype><d:collection/></d:resourcetype>");
body.push_str(&format!(
"<d:getlastmodified>{}</d:getlastmodified>",
xml_escape(&session_last_modified)
));
write_lastmodified(&mut body, listing.session_mtime as i64);
body.push_str("</d:prop><d:status>HTTP/1.1 200 OK</d:status></d:propstat>");
body.push_str("</d:response>");
// One entry per chunk file.
for chunk in &listing.chunks {
let chunk_href = format!(
"/remote.php/dav/uploads/{}/{}/{}",
session.raw_username, upload_id, chunk.name
);
let chunk_modified = chrono::DateTime::<chrono::Utc>::from_timestamp(chunk.mtime as i64, 0)
.unwrap_or_else(chrono::Utc::now)
.to_rfc2822();
body.push_str("<d:response>");
body.push_str(&format!("<d:href>{}</d:href>", xml_escape(&chunk_href)));
let _ = write!(
body,
"<d:href>/remote.php/dav/uploads/{}/{}/{}</d:href>",
xml_escape(&session.raw_username),
xml_escape(upload_id),
xml_escape(&chunk.name)
);
body.push_str("<d:propstat><d:prop>");
body.push_str("<d:resourcetype/>");
body.push_str(&format!(
let _ = write!(
body,
"<d:getcontentlength>{}</d:getcontentlength>",
chunk.size
));
body.push_str(&format!(
"<d:getlastmodified>{}</d:getlastmodified>",
xml_escape(&chunk_modified)
));
);
write_lastmodified(&mut body, chunk.mtime as i64);
body.push_str("</d:prop><d:status>HTTP/1.1 200 OK</d:status></d:propstat>");
body.push_str("</d:response>");
}