perf: round 10 — auth alloc purge, parent-herd batching, query-shape pack, NC 304s

Benchmark-gated (benches/ROUND10.md; every change carries a BEFORE/AFTER
harness with equivalence/safety gates — two designs were rejected or
rewritten by their own benches before adoption):

- Auth hot path: TokenClaims/CurrentUser display fields to Arc<str>, role
  to inline SmolStr end-to-end (Bearer, cookie, Basic-auth cache) — 4→1
  allocs per authenticated request, 3→0 per warm DAV request; JWT
  Encoding/Decoding/Validation built once.
- Cold shared-album herd: leader-inline parent batching in PgAclEngine
  (+ cascade try_get_with single-flight) — 100→2 parent queries per
  100-thumb cold herd, herd wall 1.9x, sequential + warm paths unchanged,
  all ROUND8/9 safety gates plus new herd-equivalence gates.
- Query-shape pack: share download double-fetch 2→1 (2.18x), contact-group
  COUNT(*) 14.9x, save_faces UNNEST 3.9x, playlist reorder UNNEST 63.7x
  (now atomic), search files∥folders join! 1.45x, move drive-lookup join!
  2.14x, trash partial (drive_id, trashed_at) indexes, CalDAV event-gate
  narrow read, favorites/recents binary-decode port, dead count_files
  removed.
- NC surface: preview + avatar honour If-None-Match (e2e: 5 KB and 197 KB
  → 0 bytes per revalidation), avatar WebP→PNG transcode memoised,
  PROPFIND/trashbin integer+date emits on stack formatters, folder-header
  enrichment join!, chunk-PUT retry stat folded into create_new open.
- common::fmt integer rendering rewritten on the std 2-digit LUT after the
  round's own bench caught the div-loop losing to to_string (16.1 ns vs
  22.5; speeds every prior-round call site).
- Micro-pack: WebDAV scope probe borrow-only, ShareService base_url
  snapshot, cookie_secure OnceLock, Arc'd AES-GCM cipher, stack request-id,
  tantivy analyzer clone dropped.
- SPA: search stale-guard + AbortController (10→1 completed round-trips,
  stale-clobber gone), getFolder in-flight dedup, gridColumns matchMedia
  hoist (10k→0 style reads).

Backend: cargo fmt + clippy -D warnings clean, 524 tests green.
Frontend: npm run check clean, 301 vitest green.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018DdM7V7M3QPW7HEHg3gLov
This commit is contained in:
Claude
2026-07-18 20:33:50 +00:00
parent 4fe429a109
commit c51af68432
64 changed files with 3452 additions and 442 deletions
+10
View File
@@ -44,7 +44,17 @@ pub fn is_cookie_secure() -> bool {
cookie_secure()
}
/// Memoised [`resolve_cookie_secure`]. The flag is a pure function of two
/// process-invariant env vars, yet a single login used to re-resolve it
/// ~4× (two auth cookies + the CSRF cookie + the handler's own probe) —
/// each call paying the env-lock syscalls and re-emitting the same
/// "⚠️ SECURITY" log line. Resolve once, log once.
fn cookie_secure() -> bool {
static COOKIE_SECURE: std::sync::OnceLock<bool> = std::sync::OnceLock::new();
*COOKIE_SECURE.get_or_init(resolve_cookie_secure)
}
fn resolve_cookie_secure() -> bool {
if let Ok(v) = std::env::var("OXICLOUD_COOKIE_SECURE") {
let secure = v == "true" || v == "1";
if !secure {
+9 -2
View File
@@ -489,7 +489,14 @@ async fn serve_share_file(
}
}
match retrieval.get_file_optimized(file_id, false, true).await {
// The metadata was already fetched at the top of this fn — hand the DTO
// to the `_preloaded` variant (as the authenticated download path does)
// instead of letting `get_file_optimized` re-run the same metadata query.
let file_size = file_dto.size;
match retrieval
.get_file_optimized_preloaded(file_id, file_dto, false, true)
.await
{
Ok((_, content)) => match content {
OptimizedFileContent::Bytes { data, .. } => Response::builder()
.status(StatusCode::OK)
@@ -510,7 +517,7 @@ async fn serve_share_file(
.status(StatusCode::OK)
.header(header::CONTENT_TYPE, &*mime)
.header(header::CONTENT_DISPOSITION, &disposition)
.header(header::CONTENT_LENGTH, file_dto.size)
.header(header::CONTENT_LENGTH, file_size)
.header(header::ACCEPT_RANGES, "bytes")
.header(header::ETAG, &etag)
.header(
@@ -259,6 +259,13 @@ struct DriveScope {
db_path: String,
}
/// Borrow-only `s.strip_prefix(&format!("{prefix}/"))` — the prefix tests
/// below run on EVERY native WebDAV verb, so they must not allocate a
/// throwaway `{prefix}/` String per request.
fn strip_prefix_slash<'a>(s: &'a str, prefix: &str) -> Option<&'a str> {
s.strip_prefix(prefix)?.strip_prefix('/')
}
async fn resolve_webdav_scope(
state: &Arc<AppState>,
user_id: Uuid,
@@ -292,8 +299,7 @@ async fn resolve_webdav_scope(
if normalized == listing_marker {
return Ok(WebdavTarget::ListDrives);
}
let with_slash = format!("{}/", listing_marker);
if let Some(after_prefix) = normalized.strip_prefix(&with_slash) {
if let Some(after_prefix) = strip_prefix_slash(normalized, listing_marker) {
if after_prefix.is_empty() {
return Ok(WebdavTarget::ListDrives);
}
@@ -316,7 +322,7 @@ async fn resolve_webdav_scope(
let root_name = default.root_folder_name.as_str();
let db_path = if normalized.is_empty() {
root_name.to_string()
} else if normalized == root_name || normalized.starts_with(&format!("{}/", root_name)) {
} else if normalized == root_name || strip_prefix_slash(normalized, root_name).is_some() {
// Pre-refactor bookmark already carried the drive-root prefix.
normalized.to_string()
} else {