PERF: release inactive User writer-lock entries in Notes and saved searches (#663) #809

Open
opened 2026-10-02 13:12:49 +00:00 by kayg · 3 comments
Owner

Parent audit #663. Baseline c4a61e8cf0; checked against round 7a.

M5: Notes and saved-search lock maps retain inactive User IDs

Status: source-confirmed; audit finding. Low priority.

Evidence: crates/plugins/notes/src/lib.rs:1987 and :2001 keep strong Arc
mutexes in a static User map, with no remove or retain step.
crates/calternal-search/src/saved.rs:191 does the same. Round 7a keeps both.
Unlike stream counters and weak filesystem settings locks, rows survive the
last operation and User deletion. Cost follows all Users seen since startup.

Impact estimate: 0.2–0.4 MiB per 1,000 historical Users across the two maps,
assuming 100–200 bytes per entry/map (UUID string, Arc mutex, map capacity
and allocation overhead). This is small for a normal Instance, but it is
monotonic during User churn. There are no file bodies in these maps.

Fix: use a shared weak-lock registry pattern; prune dead entries on lookup.
An active OwnedMutexGuard must keep the same mutex alive, so a concurrent
operation cannot create a second writer lock. Reuse Root::lock_user_settings
or Mail's account_lock approach instead of adding another registry helper.

Test: many distinct valid User IDs, followed by pruning; map size must follow
active operations. Concurrent operations for one User must serialize while
pruning runs. Include User deletion and a still-active operation.

Duplicate search: all-state memory/unbounded/cache, plus User locks; no
matching lifetime issue. This is not a merge blocker.

Parent audit #663. Baseline c4a61e8cf090170f35b1bed3350d9de20c83ecd5; checked against round 7a. M5: Notes and saved-search lock maps retain inactive User IDs Status: source-confirmed; audit finding. Low priority. Evidence: crates/plugins/notes/src/lib.rs:1987 and :2001 keep strong Arc mutexes in a static User map, with no remove or retain step. crates/calternal-search/src/saved.rs:191 does the same. Round 7a keeps both. Unlike stream counters and weak filesystem settings locks, rows survive the last operation and User deletion. Cost follows all Users seen since startup. Impact estimate: 0.2–0.4 MiB per 1,000 historical Users across the two maps, assuming 100–200 bytes per entry/map (UUID string, Arc mutex, map capacity and allocation overhead). This is small for a normal Instance, but it is monotonic during User churn. There are no file bodies in these maps. Fix: use a shared weak-lock registry pattern; prune dead entries on lookup. An active OwnedMutexGuard must keep the same mutex alive, so a concurrent operation cannot create a second writer lock. Reuse Root::lock_user_settings or Mail's account_lock approach instead of adding another registry helper. Test: many distinct valid User IDs, followed by pruning; map size must follow active operations. Concurrent operations for one User must serialize while pruning runs. Include User deletion and a still-active operation. Duplicate search: all-state memory/unbounded/cache, plus User locks; no matching lifetime issue. This is not a merge blocker.
Author
Owner

Starting work on job/notesperf, based on job/merge-round-7a at 2f4482ded066d9c5d9c59130377907f7fd2916c9. I will address the issue with focused changes and regression coverage, then report the final head SHA and verbatim gate output here.

Starting work on `job/notesperf`, based on `job/merge-round-7a` at `2f4482ded066d9c5d9c59130377907f7fd2916c9`. I will address the issue with focused changes and regression coverage, then report the final head SHA and verbatim gate output here.
Author
Owner

The Notes writer-lock registry now stores weak entries and prunes expired Users at lookup. The regression test creates 512 released User locks, checks the registry stays bounded, and verifies a held guard still serializes its User. Evidence: cargo test -p calternal-plugin-notes inactive_user_writer_locks_are_pruned_without_splitting_active_locks passed (1 passed). Commit: eb8a5d100. The issue also has the Search half in db48e08cc.

The Notes writer-lock registry now stores weak entries and prunes expired Users at lookup. The regression test creates 512 released User locks, checks the registry stays bounded, and verifies a held guard still serializes its User. Evidence: `cargo test -p calternal-plugin-notes inactive_user_writer_locks_are_pruned_without_splitting_active_locks` passed (1 passed). Commit: eb8a5d100. The issue also has the Search half in db48e08cc.
Author
Owner

Implemented in db48e08cc and eb8a5d100: inactive saved-search and Notes User lock entries no longer retain strong mutex ownership. Targeted regression tests passed (Search and Notes); full crate gates were blocked by shared-host I/O/load.

Implemented in db48e08cc and eb8a5d100: inactive saved-search and Notes User lock entries no longer retain strong mutex ownership. Targeted regression tests passed (Search and Notes); full crate gates were blocked by shared-host I/O/load.
Sign in to join this conversation.
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
kayg/calternal#809
No description provided.