Skip to content

Slow scan: cargo hosted 3.8x median ms/pkg (per-patch Cargo.lock re-parse) #761

Description

[agent] Bench: cargo has been flagged slow in 3 consecutive benchmark runs (2026-10-02, 10-03, 10-04). Its hosted scan costs about 3.8x the median ms per package across all package managers.

run cargo/hosted median ms/pkg x median ms/pkg cargo/rescan median
2026-10-02 228.4 ms 0.381 3.0x 229.5 ms
2026-10-03 262.5 ms 0.438 3.4x 251.4 ms
2026-10-04 258.5 ms 0.431 3.8x 213.9 ms

Fixture: 600 crates, 15 patched, Cargo.lock v4.

Hot spot (callgrind, cargo/hosted, 2026-10-04)

  • patch::redirect::rewrite_cargo: 87% of all instructions, of which formats::cargo::CargoLock::parse is 79%.
  • rewrite_cargo (crates/socket-patch-core/src/patch/redirect/mod.rs) parses the full (and progressively rewritten) Cargo.lock again for every patched crate. It does this in cargo_unpinnable_dependents (CargoLock::parse(lock), ~L1700) and again in the lock plan (CargoLock::parse(lock_text)…plan_hosted, ~L1463), plus the helpers near L2496/L2505. That's several full parses per dep, so O(patches × lock size).
  • Possible fix: parse once up front. Dependents don't change when a package's source and checksum are repointed, so answer them from the single parse, and apply the per-package edits to the text (or to one structure) without re-parsing per dep.
  • Secondary: formats::cargo::read_packages (12.4%), the inventory's own parse.

Runner

4 vCPU, Intel(R) Xeon(R) Processor @ 2.10GHz (cloud sandbox), main 045d7ec7. Absolute timings vary from runner to runner; the ratio to the cross-PM median is the signal.

Repro

CARGO_PROFILE_PERF_INHERITS=release CARGO_PROFILE_PERF_LTO=thin CARGO_PROFILE_PERF_STRIP=none \
  cargo build --locked --profile perf -p socket-patch-cli -p socket-patch-bench
target/perf/socket-patch-bench run --bin target/perf/socket-patch -f '^cargo/' -v
# profile: serve the fixture, then prefix the printed command's binary with
#   valgrind --tool=callgrind
target/perf/socket-patch-bench serve cargo/hosted --bin target/perf/socket-patch

Tracked in the ledger of #575 (standing slow-systems list). This is a standing slowness report, not a regression: the cost has been flat since the suite started.


Generated by Claude Code

Activity

  1. mikolalysenko commented on Oct 9, 2026

    @mikolalysenko
    CollaboratorAuthor

    v5 triage: P3, not a release blocker. The reported hosted scan is about 0.26 seconds for 600 crates. Keep the optimization, but P3 after functional release work.

    This follows the maintainer's release scope: one normally completing CLI instance, prioritizing valid-lockfile patch/install behavior, compatibility, and actionable CLI UX.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions