PERF: separate Mail IDLE waits from the three sync worker slots (#663) #763

Closed
opened 2026-10-02 13:09:54 +00:00 by kayg · 3 comments
Owner

Parent audit: #663. Baseline: c4a61e8cf0; unchanged in round 7a.

C1: Three Mail sync slots include five-minute idle waits

Status: source-confirmed performance finding. No crash or security exploit was reproduced.

Evidence: crates/plugins/mail/src/sync.rs:60 sets IDLE and polling waits to
300 s. mail.sync allows three concurrent jobs per Instance (:131), including
backfill, provider commands, IDLE and retries. Completed backfill waits for
a hint before return (:358). A provider without IDLE sleeps inside the job
(:1206). The next poll is also scheduled 300 s later (:237).
The durable lease heartbeat stays active during the wait.
These limits and waits remain in round 7a.

Impact estimate: with 1,000 enabled accounts and no provider hints, three
slots supply at most 36 five-minute waits per hour. One rotation needs at
least ceil(1000/3) * 300 = 100,200 s (27.8 h), excluding provider work and
schedule delays. This is not a measured delay; ordering affects which
account waits. Even a fourth account can wait five minutes behind three
quiet accounts. The §53 five-second arrival budget is not a general guarantee.

Fix: separate bounded provider work from wait subscriptions. A non-IDLE
account must end its job after scheduling its next check. IDLE must hold an
independently bounded subscription that queues a short delta job. Use
fairness per User and account. Do not raise the cap without a socket and
memory budget.

Test: deterministic fake provider with at least four quiet accounts. A delta
for the fourth must run while the first three wait. Check lease renewal,
reconnect, cancellation, backfill and per-User fairness.

Duplicate search: all-state IDLE, IMAP and unbounded. #613 covers first sync
visibility; #486 covers the future Mail proxy. This finding concerns shared
scheduler capacity.

Parent audit: #663. Baseline: c4a61e8cf090170f35b1bed3350d9de20c83ecd5; unchanged in round 7a. C1: Three Mail sync slots include five-minute idle waits Status: source-confirmed performance finding. No crash or security exploit was reproduced. Evidence: crates/plugins/mail/src/sync.rs:60 sets IDLE and polling waits to 300 s. mail.sync allows three concurrent jobs per Instance (:131), including backfill, provider commands, IDLE and retries. Completed backfill waits for a hint before return (:358). A provider without IDLE sleeps inside the job (:1206). The next poll is also scheduled 300 s later (:237). The durable lease heartbeat stays active during the wait. These limits and waits remain in round 7a. Impact estimate: with 1,000 enabled accounts and no provider hints, three slots supply at most 36 five-minute waits per hour. One rotation needs at least ceil(1000/3) * 300 = 100,200 s (27.8 h), excluding provider work and schedule delays. This is not a measured delay; ordering affects which account waits. Even a fourth account can wait five minutes behind three quiet accounts. The §53 five-second arrival budget is not a general guarantee. Fix: separate bounded provider work from wait subscriptions. A non-IDLE account must end its job after scheduling its next check. IDLE must hold an independently bounded subscription that queues a short delta job. Use fairness per User and account. Do not raise the cap without a socket and memory budget. Test: deterministic fake provider with at least four quiet accounts. A delta for the fourth must run while the first three wait. Check lease renewal, reconnect, cancellation, backfill and per-User fairness. Duplicate search: all-state IDLE, IMAP and unbounded. #613 covers first sync visibility; #486 covers the future Mail proxy. This finding concerns shared scheduler capacity.
Author
Owner

Concurrent sync audit finding: #753 was filed first for the same three-slot IDLE lifecycle; #763 appeared during this audit. Please keep one implementation owner for both. #753 also records the 300 s enqueue_poll gap after a single IDLE hint/delta, so new arrivals have no continuous listener. Scope this fix to both scheduler fairness and continuous IDLE; do not implement two listener managers. Source confirmed on round-7a 2f4482ded, sync.rs:131, :183, :237, :358 and :1213. No runtime latency measurement in this audit.

Concurrent sync audit finding: #753 was filed first for the same three-slot IDLE lifecycle; #763 appeared during this audit. Please keep one implementation owner for both. #753 also records the 300 s enqueue_poll gap after a single IDLE hint/delta, so new arrivals have no continuous listener. Scope this fix to both scheduler fairness and continuous IDLE; do not implement two listener managers. Source confirmed on round-7a 2f4482ded, sync.rs:131, :183, :237, :358 and :1213. No runtime latency measurement in this audit.
Author
Owner

Starting implementation on job/mailperf, based on job/merge-round-7a at 2f4482ded066d9c5d9c59130377907f7fd2916c9. The target areas are IDLE scheduling, bounded delta/expunge work, and unread-count invalidation. I will merge origin/dev and job/merge-round-7a before the final gates.

Starting implementation on `job/mailperf`, based on `job/merge-round-7a` at `2f4482ded066d9c5d9c59130377907f7fd2916c9`. The target areas are IDLE scheduling, bounded delta/expunge work, and unread-count invalidation. I will merge `origin/dev` and `job/merge-round-7a` before the final gates.
Author
Owner

Duplicate of #753; the implementation and final report are tracked on #753.

Duplicate of #753; the implementation and final report are tracked on #753.
kayg closed this issue 2026-10-02 18:07:22 +00:00
Sign in to join this conversation.
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
kayg/calternal#763
No description provided.