perf: overhaul session loading, caching, and runtime isolation (#2360)

Improve OpenChamber responsiveness under large session workloads while fixing
cache, synchronization, and persistence correctness across runtimes, projects,
directories, and worktrees.

- prioritize selected and visible sessions during bootstrap and defer
  non-critical enrichment work
- reduce redundant message loading, event processing, store publication, and
  hidden sidebar work
- prevent stale session and message requests from overwriting newer
  authoritative state
- preserve existing data when authoritative fetches fail instead of treating
  failures as successful empty responses
- scope session materialization, messages, drafts, queues, todos, pins,
  permissions, folders, tabs, Git state, and pull request data by runtime and
  directory identity
- harden runtime switching, reconnect, cleanup, mutation reconciliation, and
  persisted-state ordering
- preserve live subagent Task linkage when metadata arrives after an older
  message request or while streaming parts are suspended
- coalesce overlapping tail refreshes without losing newer refresh demand
- improve cold-session loading by moving deferrable work out of the critical
  bootstrap path
- isolate URL authentication, mobile credentials, native secrets, and other
  runtime-owned state across endpoint changes
- bound long-lived caches and remove avoidable allocations from event and
  rendering hot paths
- limit virtualization to archive collections where it improves rendering
  without disrupting active sidebar layout
- stabilize session folders, pin ordering, expanded state, and persisted
  sidebar behavior
- open skill files through the same secure editor and outside-workspace grant
  flow used by file navigation, including worktree sessions
- expand regression coverage for stale completions, runtime collisions,
  reconnect behavior, persistence races, authoritative empty results, and
  subagent refresh ordering
- document the updated synchronization, cache ownership, performance, and
  runtime-isolation invariants
This commit is contained in:
Bohdan Triapitsyn
2026-07-21 20:52:20 +03:00
committed by GitHub
parent 485efc7117
commit 85400459e9
197 changed files with 10835 additions and 3400 deletions
+51
View File
@@ -5,6 +5,8 @@ import {
clearRuntimeUrlAuthToken,
getRuntimeBearerTokenSync,
refreshRuntimeUrlAuthToken,
refreshLocalRuntimeUrlAuthToken,
getLocalRuntimeUrlAuthTokenSync,
setRuntimeAuthCredentialProvider,
setRuntimeBearerToken,
setRuntimeExtraHeaders,
@@ -145,4 +147,53 @@ describe('runtime auth headers', () => {
clearRuntimeAuthCredentialProvider();
}
});
test('never reuses a local URL token for another origin', async () => {
const previousFetch = globalThis.fetch;
let fetchCount = 0;
try {
clearRuntimeUrlAuthToken();
globalThis.fetch = (async (input: RequestInfo | URL) => {
fetchCount += 1;
const origin = new URL(String(input)).origin;
return Response.json({ token: `${origin}-token`, expiresAt: Date.now() + 60_000 });
}) as typeof fetch;
const a = await refreshLocalRuntimeUrlAuthToken('http://127.0.0.1:3001');
const b = await refreshLocalRuntimeUrlAuthToken('http://127.0.0.1:3002');
expect(a).toBe('http://127.0.0.1:3001-token');
expect(b).toBe('http://127.0.0.1:3002-token');
expect(getLocalRuntimeUrlAuthTokenSync('http://127.0.0.1:3001')).toBe('');
expect(getLocalRuntimeUrlAuthTokenSync('http://127.0.0.1:3002')).toBe(b);
expect(fetchCount).toBe(2);
} finally {
globalThis.fetch = previousFetch;
clearRuntimeUrlAuthToken();
}
});
test('rejects a local mint that completes after switching origins', async () => {
const previousFetch = globalThis.fetch;
let resolveA!: (response: Response) => void;
try {
clearRuntimeUrlAuthToken();
globalThis.fetch = ((input: RequestInfo | URL) => {
const origin = new URL(String(input)).origin;
if (origin.endsWith(':3001')) return new Promise<Response>((resolve) => { resolveA = resolve; });
return Promise.resolve(Response.json({ token: 'token-b', expiresAt: Date.now() + 60_000 }));
}) as typeof fetch;
const requestA = refreshLocalRuntimeUrlAuthToken('http://127.0.0.1:3001');
const tokenB = await refreshLocalRuntimeUrlAuthToken('http://127.0.0.1:3002');
resolveA(Response.json({ token: 'token-a', expiresAt: Date.now() + 60_000 }));
expect(tokenB).toBe('token-b');
await expect(requestA).rejects.toThrow('stale');
expect(getLocalRuntimeUrlAuthTokenSync('http://127.0.0.1:3002')).toBe('token-b');
} finally {
globalThis.fetch = previousFetch;
clearRuntimeUrlAuthToken();
}
});
});