link_payload_scaling_e2e's per-link ceiling grades the TEMP DIRECTORY'S LENGTH — 59 tokens on /tmp, 80 on a long path, 63 on the Windows runner #252
Labels
No labels
code-review
correctness
dos
performance
security
severity/high
severity/low
severity/medium
tech-debt
Kind/Breaking
Kind/Bug
Kind/Documentation
Kind/Enhancement
Kind/Feature
Kind/Security
Kind/Testing
Priority
Critical
Priority
High
Priority
Low
Priority
Medium
Reviewed
Confirmed
Reviewed
Duplicate
Reviewed
Invalid
Reviewed
Won't Fix
Status
Abandoned
Status
Blocked
Status
Need More Info
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
h-dv/code-index#252
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Found by the first real native-Windows verdict since
1d3228e. Run 726 onbd1c4e2failed after 43 minutes with exactly one failing test in the entire suite:
The bound is a function of
$TMPDIRper_linkis(t4 − t1) / 3over serializedproject_overviewbodies. Everyonce-per-response term cancels — but
LinkedProjectSummary::pathis an ABSOLUTE paththat appears once per link, so it does not cancel. The measurement therefore carries
one full temp-directory path per link.
Measured on ONE machine, changing NOTHING but
TMPDIR:TMPDIR/tmp…/AppData/Local/Temp-longer-like-a-windows-runnerLinux passed by 2 tokens and Windows failed by 2. The 4-token gap is the runner's longer
temp root plus JSON escaping every
\as\\.This is the file's own stated error class
The module doc names #160 §0 — "the gate's verdict was decided by which machine ran
it" — as the mistake it exists not to make, and
workspace_with_unavailable_linksfixesthe width of every link NAME and DESCRIPTION for exactly that reason:
pathis the one per-link field that guard does not cover.Fix
Normalise every link's
pathto a fixed-width placeholder before estimating, so theceiling grades which fields the product puts on a link — a product property — and not
how long the deployment's paths are, which is the deployment's.
Plus an anti-vacuity arm that keeps it honest: blanking one field only removes the
environment if that field was the ONLY per-link carrier of the root. The temp directory's
basename is random per run and cannot occur by accident, so the assertion is that no
remaining per-link field contains it.
After the fix the measurement is byte-identical across both environments — 60 per link,
1928/2108, on a 4-characterTMPDIRand an 86-character one alike.Mutations, run
nameinstead ofpath) → RED on the anti-vacuity arm:a per-link field OTHER than 'path' still carries the workspace root (.tmpP0IX1h),printing the offending link.
TMPDIR→ RED at 80/80,reproducing the Windows failure on Linux.
Note on the remaining headroom
At 60 of 80 with a reserve of 19 there is exactly 1 token of true slack. That is the
#235 mechanism working as designed — it will fire before anything breaks — but the next
per-link field will trip it, and the right response then is to attribute and re-record,
not to widen. The ceiling was NOT moved as part of this fix; only the contamination was
removed, which happens to read 60 rather than 59 because the fixed-width placeholder is
slightly longer than a short real path.
Fixed in
5131654, and confirmed on the native runner rather than only locally:43 minutes matches run 726's length, so the suite ran in full rather than short-circuiting — this is a real verdict, not an absent one. It is the first green native-Windows result on master since
1d3228e.The fix normalises each link's
pathto a fixed-width placeholder before the payload is measured, with an anti-vacuity arm asserting no OTHER per-link field carries the workspace root (the temp directory's basename is random per run, so it cannot match by accident). After it the measurement is byte-identical across an 82-characterTMPDIRswing — 60 per link,1928/2108, on both a 4-character and an 86-character temp root, where it previously read 59 and 80.The ceiling itself was not moved; only the contamination was removed. It reads 60 rather than 59 because the fixed-width placeholder is slightly longer than a short real path, which leaves 1 token of true slack above the reserve. The next per-link field will trip #235's reserve, and the right response then is to attribute and re-record rather than widen.
Filed alongside as #253: the same class of "the gate measures the machine" in
claim_domain_scale, where a wall-clock ratio failed at load 37.9 and passes at load 3.0.