perf: round 10 — auth alloc purge, parent-herd batching, query-shape pack, NC 304s

Benchmark-gated (benches/ROUND10.md; every change carries a BEFORE/AFTER
harness with equivalence/safety gates — two designs were rejected or
rewritten by their own benches before adoption):

- Auth hot path: TokenClaims/CurrentUser display fields to Arc<str>, role
  to inline SmolStr end-to-end (Bearer, cookie, Basic-auth cache) — 4→1
  allocs per authenticated request, 3→0 per warm DAV request; JWT
  Encoding/Decoding/Validation built once.
- Cold shared-album herd: leader-inline parent batching in PgAclEngine
  (+ cascade try_get_with single-flight) — 100→2 parent queries per
  100-thumb cold herd, herd wall 1.9x, sequential + warm paths unchanged,
  all ROUND8/9 safety gates plus new herd-equivalence gates.
- Query-shape pack: share download double-fetch 2→1 (2.18x), contact-group
  COUNT(*) 14.9x, save_faces UNNEST 3.9x, playlist reorder UNNEST 63.7x
  (now atomic), search files∥folders join! 1.45x, move drive-lookup join!
  2.14x, trash partial (drive_id, trashed_at) indexes, CalDAV event-gate
  narrow read, favorites/recents binary-decode port, dead count_files
  removed.
- NC surface: preview + avatar honour If-None-Match (e2e: 5 KB and 197 KB
  → 0 bytes per revalidation), avatar WebP→PNG transcode memoised,
  PROPFIND/trashbin integer+date emits on stack formatters, folder-header
  enrichment join!, chunk-PUT retry stat folded into create_new open.
- common::fmt integer rendering rewritten on the std 2-digit LUT after the
  round's own bench caught the div-loop losing to to_string (16.1 ns vs
  22.5; speeds every prior-round call site).
- Micro-pack: WebDAV scope probe borrow-only, ShareService base_url
  snapshot, cookie_secure OnceLock, Arc'd AES-GCM cipher, stack request-id,
  tantivy analyzer clone dropped.
- SPA: search stale-guard + AbortController (10→1 completed round-trips,
  stale-clobber gone), getFolder in-flight dedup, gridColumns matchMedia
  hoist (10k→0 style reads).

Backend: cargo fmt + clippy -D warnings clean, 524 tests green.
Frontend: npm run check clean, 301 vitest green.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018DdM7V7M3QPW7HEHg3gLov
This commit is contained in:
Claude
2026-07-18 20:33:50 +00:00
parent 4fe429a109
commit c51af68432
64 changed files with 3452 additions and 442 deletions
@@ -15,6 +15,7 @@ use crate::infrastructure::services::password_hasher::Argon2PasswordHasher;
use chrono::{Duration, Utc};
use moka::future::Cache;
use rand_core::RngCore;
use smol_str::SmolStr;
use std::sync::Arc;
use std::time::Duration as StdDuration;
use uuid::Uuid;
@@ -56,12 +57,17 @@ const BASIC_AUTH_CACHE_TTL_SECS: u64 = 300;
const BASIC_AUTH_CACHE_MAX_ENTRIES: u64 = 10_000;
/// Cached identity returned after a successful Basic Auth verification.
///
/// `Arc<str>` / inline `SmolStr` fields: moka's `get` clones the value, so
/// with owned `String`s every warm Basic-auth request (all DAV traffic)
/// paid 3 string copies just to read the cached identity. Now a hit is
/// refcount bumps + a 24-byte memcpy.
#[derive(Clone)]
struct CachedBasicAuthResult {
user_id: Uuid,
username: String,
email: String,
role: String,
username: Arc<str>,
email: Arc<str>,
role: SmolStr,
}
pub struct AppPasswordService {
@@ -299,7 +305,7 @@ impl AppPasswordService {
&self,
username: &str,
password: &str,
) -> Result<(Uuid, String, String, String), DomainError> {
) -> Result<(Uuid, Arc<str>, Arc<str>, SmolStr), DomainError> {
// ── 1. Compute cache key = blake3("username:password") ────────
let cache_key: [u8; 32] =
blake3::hash(format!("{}:{}", username, password).as_bytes()).into();
@@ -400,9 +406,9 @@ impl AppPasswordService {
// stores this value under the blake3 key on return.
return Ok(CachedBasicAuthResult {
user_id: user.id(),
username: user.username().unwrap_or("").to_string(),
email: user.email().to_string(),
role: user.role().to_string(),
username: Arc::from(user.username().unwrap_or("")),
email: Arc::from(user.email()),
role: SmolStr::new_static(user.role().as_str()),
});
}
}
@@ -1102,9 +1102,9 @@ impl AuthApplicationService {
Ok(crate::application::dtos::user_dto::CurrentUser {
id: user.id(),
username: user.username().unwrap_or("").to_string(),
email: user.email().to_string(),
role: user.role().to_string(),
username: std::sync::Arc::from(user.username().unwrap_or("")),
email: std::sync::Arc::from(user.email()),
role: smol_str::SmolStr::new_static(user.role().as_str()),
})
}
+12 -4
View File
@@ -253,15 +253,23 @@ impl CalendarUseCase for CalendarService {
update: UpdateEventDto,
user_id: Uuid,
) -> Result<CalendarEventDto, DomainError> {
let event = self.calendar_storage.get_event(event_id).await?;
self.require_calendar_perm(&event.calendar_id, user_id, Permission::Update)
// Only the owning calendar id is needed for the gate — skip the
// full event hydration (`ical_data` can run to tens of KB).
let calendar_id = self
.calendar_storage
.calendar_id_for_event(event_id)
.await?;
self.require_calendar_perm(&calendar_id, user_id, Permission::Update)
.await?;
self.calendar_storage.update_event(event_id, update).await
}
async fn delete_event(&self, event_id: &str, user_id: Uuid) -> Result<(), DomainError> {
let event = self.calendar_storage.get_event(event_id).await?;
self.require_calendar_perm(&event.calendar_id, user_id, Permission::Delete)
let calendar_id = self
.calendar_storage
.calendar_id_for_event(event_id)
.await?;
self.require_calendar_perm(&calendar_id, user_id, Permission::Delete)
.await?;
self.calendar_storage.delete_event(event_id).await
}
+4 -3
View File
@@ -1005,11 +1005,12 @@ impl ContactUseCase for ContactService {
self.require_address_book_read_or_public(group.address_book_id(), &user_id)
.await?;
// Get the number of contacts in the group
let contacts = self.contact_storage.get_contacts_in_group(&id).await?;
// Count-only read: the summary DTO never looks at the contacts, so
// don't hydrate N full rows (vCard TEXT + 3 JSONB parses each).
let members = self.contact_storage.count_contacts_in_group(&id).await?;
let mut dto = ContactGroupDto::from(group);
dto.members_count = Some(contacts.len() as i32);
dto.members_count = Some(members as i32);
Ok(dto)
}
@@ -336,18 +336,18 @@ impl FileManagementUseCase for FileManagementService {
Uuid::parse_str(file_id).map_err(|_| DomainError::not_found("File", file_id))?;
let dst_folder_uuid = Uuid::parse_str(target_folder_id)
.map_err(|_| DomainError::not_found("Folder", target_folder_id))?;
let (src_drive_id, src_policies) = drive_repo
.get_drive_id_and_policies_for_file(file_uuid)
.await
.map_err(|e| {
DomainError::internal_error("Drive", format!("source drive lookup: {e:?}"))
})?;
let dst_drive_id = drive_repo
.drive_id_for_folder(dst_folder_uuid)
.await
.map_err(|e| {
DomainError::internal_error("Drive", format!("destination drive lookup: {e:?}"))
})?;
// Independent point reads — overlapped so the pre-move drive
// resolution pays one round-trip, not two (ROUND10).
let (src_res, dst_res) = tokio::join!(
drive_repo.get_drive_id_and_policies_for_file(file_uuid),
drive_repo.drive_id_for_folder(dst_folder_uuid),
);
let (src_drive_id, src_policies) = src_res.map_err(|e| {
DomainError::internal_error("Drive", format!("source drive lookup: {e:?}"))
})?;
let dst_drive_id = dst_res.map_err(|e| {
DomainError::internal_error("Drive", format!("destination drive lookup: {e:?}"))
})?;
if src_drive_id != dst_drive_id {
src_policies.refuse_cross_drive_move(
crate::domain::entities::drive::CrossDriveMoveGateContext {
+13 -12
View File
@@ -665,18 +665,19 @@ impl FolderUseCase for FolderService {
Uuid::parse_str(id).map_err(|_| DomainError::not_found("Folder", id))?;
let dst_folder_uuid = Uuid::parse_str(parent_id)
.map_err(|_| DomainError::not_found("Folder", parent_id.as_str()))?;
let (src_drive_id, src_policies) = drive_repo
.get_drive_id_and_policies_for_folder(src_folder_uuid)
.await
.map_err(|e| {
DomainError::internal_error("Drive", format!("source drive lookup: {e:?}"))
})?;
let dst_drive_id = drive_repo
.drive_id_for_folder(dst_folder_uuid)
.await
.map_err(|e| {
DomainError::internal_error("Drive", format!("destination drive lookup: {e:?}"))
})?;
// Independent point reads — overlapped so the pre-move drive
// resolution pays one round-trip, not two (ROUND10, same shape
// as `move_file_with_perms`).
let (src_res, dst_res) = tokio::join!(
drive_repo.get_drive_id_and_policies_for_folder(src_folder_uuid),
drive_repo.drive_id_for_folder(dst_folder_uuid),
);
let (src_drive_id, src_policies) = src_res.map_err(|e| {
DomainError::internal_error("Drive", format!("source drive lookup: {e:?}"))
})?;
let dst_drive_id = dst_res.map_err(|e| {
DomainError::internal_error("Drive", format!("destination drive lookup: {e:?}"))
})?;
if src_drive_id != dst_drive_id {
src_policies.refuse_cross_drive_move(
crate::domain::entities::drive::CrossDriveMoveGateContext {
+36 -32
View File
@@ -620,18 +620,30 @@ impl SearchUseCase for SearchService {
// Pre-compute once — avoids N heap allocations inside enrich_file/enrich_folder.
let query_lower = query.to_lowercase();
// Content-index candidates (first page only). Feature-off or an
// index failure yields an empty set — the search stays name-only.
let content_hits = self.lookup_content_hits(&criteria, user_id).await;
// For non-recursive searches, use efficient database-level pagination
// This avoids loading all files into memory
if !criteria.recursive {
// Use database-level pagination
let (files, total_file_count) = self
.file_repository
.search_files_paginated(criteria.folder_id.as_deref(), &criteria, user_id)
.await?;
// The content-index lookup (drive resolve + Tantivy +
// ReBAC batch), the file page and the folder query are
// mutually independent — overlap them so the search pays
// ~max() instead of the serial sum (`suggest_with_perms`
// already used this shape; ROUND10 brought it here).
let (content_hits, files_page, folders_res) = tokio::join!(
self.lookup_content_hits(&criteria, user_id),
self.file_repository.search_files_paginated(
criteria.folder_id.as_deref(),
&criteria,
user_id,
),
self.folder_repository.search_folders(
criteria.folder_id.as_deref(),
criteria.name_contains.as_deref(),
user_id,
false,
),
);
let (files, total_file_count) = files_page?;
let folders = folders_res?;
// Convert to DTOs and enrich with metadata — one fused
// pass, no intermediate Vec<FileDto> materialization.
@@ -640,17 +652,6 @@ impl SearchUseCase for SearchService {
.map(|f| Self::enrich_file(FileDto::from(f), &query_lower))
.collect();
// Get folders for this folder (non-recursive, filtered in SQL)
let folders = self
.folder_repository
.search_folders(
criteria.folder_id.as_deref(),
criteria.name_contains.as_deref(),
user_id,
false,
)
.await?;
// For folders, apply sorting and pagination in memory (usually fewer folders)
let mut enriched_folders: Vec<SearchFolderResultDto> = folders
.into_iter()
@@ -717,22 +718,25 @@ impl SearchUseCase for SearchService {
// ── Recursive search via ltree (single SQL query per entity type) ──
// Uses PostgreSQL ltree GiST index to find all files and folders
// in the subtree in O(1) queries, replacing the O(N) spawn-per-folder
// approach that could saturate the connection pool.
let (found_files, total_file_count) = self
.file_repository
.search_files_in_subtree(criteria.folder_id.as_deref(), &criteria, user_id)
.await?;
// Get folders (SQL-filtered, user-scoped, recursive when applicable)
let found_folders: Vec<Folder> = self
.folder_repository
.search_folders(
// approach that could saturate the connection pool. The content
// lookup, subtree file query and folder query overlap (`join!`),
// same as the non-recursive branch.
let (content_hits, files_page, folders_res) = tokio::join!(
self.lookup_content_hits(&criteria, user_id),
self.file_repository.search_files_in_subtree(
criteria.folder_id.as_deref(),
&criteria,
user_id,
),
self.folder_repository.search_folders(
criteria.folder_id.as_deref(),
criteria.name_contains.as_deref(),
user_id,
true,
)
.await?;
),
);
let (found_files, total_file_count) = files_page?;
let found_folders: Vec<Folder> = folders_res?;
// ── Convert to DTOs and enrich with server-computed metadata ──
// Fused single pass: no intermediate DTO Vec materialization.
+24 -24
View File
@@ -79,6 +79,11 @@ const MAX_CONCURRENT_HASHES: usize = 2;
pub struct ShareService {
config: Arc<AppConfig>,
/// `AppConfig::base_url()` snapshot, taken once at construction —
/// the method re-reads `OXICLOUD_BASE_URL` from the environment (a
/// global env-lock + String build) and was being called per DTO row
/// in the share listings. Process-invariant, so snapshot it.
base_url: String,
share_repository: Arc<SharePgRepository>,
file_repository: Arc<FileBlobReadRepository>,
folder_repository: Arc<FolderDbRepository>,
@@ -107,6 +112,7 @@ impl ShareService {
authorization: Arc<PgAclEngine>,
) -> Self {
Self {
base_url: config.base_url(),
config,
share_repository,
file_repository,
@@ -204,7 +210,7 @@ impl ShareService {
));
}
Ok(ShareDto::from_entity(&share, &self.config.base_url()))
Ok(ShareDto::from_entity(&share, &self.base_url))
}
pub fn issue_unlock_jwt(&self, share_token: &str) -> Result<String, DomainError> {
@@ -338,7 +344,7 @@ impl ShareUseCase for ShareService {
// Return DTO with the requested expires_at (grant subquery on the share
// row would return NULL at this point since INSERT ran before the grant).
let mut response = ShareDto::from_entity(&saved_share, &self.config.base_url());
let mut response = ShareDto::from_entity(&saved_share, &self.base_url);
response.expires_at = dto.expires_at;
Ok(response)
}
@@ -354,7 +360,7 @@ impl ShareUseCase for ShareService {
}
// Convert the entity to DTO for the response
Ok(ShareDto::from_entity(&share, &self.config.base_url()))
Ok(ShareDto::from_entity(&share, &self.base_url))
}
async fn get_shared_link_by_token(&self, token: &str) -> Result<ShareDto, DomainError> {
@@ -380,7 +386,7 @@ impl ShareUseCase for ShareService {
// Convert the entities to DTOs for the response
let share_dtos = active_shares
.iter()
.map(|s| ShareDto::from_entity(s, &self.config.base_url()))
.map(|s| ShareDto::from_entity(s, &self.base_url))
.collect();
Ok(share_dtos)
@@ -427,7 +433,7 @@ impl ShareUseCase for ShareService {
// Use the requested expires_at for the response (subquery in update_share
// runs before set_expiry_for_subject committed, so entity may lag).
let mut response = ShareDto::from_entity(&updated_share, &self.config.base_url());
let mut response = ShareDto::from_entity(&updated_share, &self.base_url);
if dto.expires_at.is_some() {
response.expires_at = dto.expires_at;
}
@@ -462,7 +468,7 @@ impl ShareUseCase for ShareService {
// Convert the entities to DTOs
let share_dtos: Vec<ShareDto> = shares
.iter()
.map(|s| ShareDto::from_entity(s, &self.config.base_url()))
.map(|s| ShareDto::from_entity(s, &self.base_url))
.collect();
// Create the paginated result
@@ -506,7 +512,7 @@ impl ShareUseCase for ShareService {
}
// Password verified (or not required) — return full share metadata
Ok(ShareDto::from_entity(&share, &self.config.base_url()))
Ok(ShareDto::from_entity(&share, &self.base_url))
}
async fn register_shared_link_access(&self, token: &str) -> Result<(), DomainError> {
@@ -540,7 +546,9 @@ mod tests {
/// Test-only service that mirrors `ShareService` logic but accepts generic repos.
struct ShareServiceForTest<SR, FR, FoR, PH> {
#[allow(dead_code)]
config: Arc<AppConfig>,
base_url: String,
share_repository: Arc<SR>,
file_repository: Arc<FR>,
folder_repository: Arc<FoR>,
@@ -563,6 +571,7 @@ mod tests {
password_hasher: Arc<PH>,
) -> Self {
Self {
base_url: config.base_url(),
config,
share_repository,
file_repository,
@@ -641,7 +650,7 @@ mod tests {
.save_share(&share)
.await
.map_err(|e| ShareServiceError::Repository(e.to_string()))?;
Ok(ShareDto::from_entity(&saved_share, &self.config.base_url()))
Ok(ShareDto::from_entity(&saved_share, &self.base_url))
}
async fn get_shared_link(
@@ -659,7 +668,7 @@ mod tests {
if share.is_expired() {
return Err(ShareServiceError::Expired.into());
}
Ok(ShareDto::from_entity(&share, &self.config.base_url()))
Ok(ShareDto::from_entity(&share, &self.base_url))
}
async fn get_shared_link_by_token(&self, token: &str) -> Result<ShareDto, DomainError> {
@@ -673,7 +682,7 @@ mod tests {
if share.is_expired() {
return Err(ShareServiceError::Expired.into());
}
Ok(ShareDto::from_entity(&share, &self.config.base_url()))
Ok(ShareDto::from_entity(&share, &self.base_url))
}
async fn get_shared_links_for_item(
@@ -690,7 +699,7 @@ mod tests {
Ok(shares
.into_iter()
.filter(|s| !s.is_expired())
.map(|s| ShareDto::from_entity(&s, &self.config.base_url()))
.map(|s| ShareDto::from_entity(&s, &self.base_url))
.collect())
}
@@ -720,7 +729,7 @@ mod tests {
.update_share(&share)
.await
.map_err(|e| ShareServiceError::Repository(e.to_string()))?;
Ok(ShareDto::from_entity(&updated, &self.config.base_url()))
Ok(ShareDto::from_entity(&updated, &self.base_url))
}
async fn delete_shared_link(
@@ -749,7 +758,7 @@ mod tests {
.map_err(|e| ShareServiceError::Repository(e.to_string()))?;
let dtos = shares
.iter()
.map(|s| ShareDto::from_entity(s, &self.config.base_url()))
.map(|s| ShareDto::from_entity(s, &self.base_url))
.collect();
Ok(PaginatedResponseDto::new(dtos, page, per_page, total))
}
@@ -779,9 +788,9 @@ mod tests {
"Invalid share password",
));
}
Ok(ShareDto::from_entity(&share, &self.config.base_url()))
Ok(ShareDto::from_entity(&share, &self.base_url))
}
None => Ok(ShareDto::from_entity(&share, &self.config.base_url())),
None => Ok(ShareDto::from_entity(&share, &self.base_url)),
}
}
@@ -915,15 +924,6 @@ mod tests {
Ok((Vec::new(), 0))
}
async fn count_files(
&self,
_folder_id: Option<&str>,
_criteria: &crate::application::dtos::search_dto::SearchCriteriaDto,
_user_id: Uuid,
) -> Result<usize, DomainError> {
Ok(0)
}
async fn stream_files_in_subtree(
&self,
_folder_id: &str,
@@ -536,15 +536,6 @@ impl FileReadPort for MockFileRepository {
Ok((Vec::new(), 0))
}
async fn count_files(
&self,
_folder_id: Option<&str>,
_criteria: &crate::application::dtos::search_dto::SearchCriteriaDto,
_user_id: Uuid,
) -> std::result::Result<usize, DomainError> {
Ok(0)
}
async fn stream_files_in_subtree(
&self,
_folder_id: &str,