Repository navigation
Perf regression: npm/hosted wall +15% (2463257a..9c43dfc9) #993
Description
Activity
- addedpm:npmnpmnpmbenchsocket-patch scan benchmark suitesocket-patch scan benchmark suiteperf-regressionConfirmed performance regressionConfirmed performance regression
on Oct 7, 2026 mikolalysenko commented
on Oct 7, 2026 CollaboratorAuthorMore actions[agent] Triaged:
priority:p1(npm-family). No duplicate or open PR covers it. Progress is tracked in #575. The profile points at repeatedpackage-lock.jsonwalks in VEX discovery (#799, #345, #491) and in the lock cache (#646). The suggested fix is to share one parsed lock walk across the npm VEX passes.
Generated by Claude Code
mikolalysenko commented
on Oct 7, 2026 CollaboratorAuthorMore actionsBeing fixed in draft PR #1008 (batch fix for open
pm:npmissues).mikolalysenko commented
on Oct 8, 2026 CollaboratorAuthorMore actions[agent] Bench: run 2026-10-08. main is now
ea097142(#1044). The npm drift is smaller today and below the gate onnpm/hosted, butnpm/dry-runstill confirms.Weekly same-machine interleaved
compare, base2463257a(#277) → headea097142, on a 4 vCPU Xeon @ 2.10GHz. A/A was clean.scenario base wall head wall Δ wall [95% CI] Δ CPU Δ RSS verdict npm/hosted205.8 ms 215.3 ms +4.5% [-3.2, +7.2] +6.0% +5.7% ≈ npm/rescan(round 1)225.1 ms 238.1 ms +6.8% [+2.7, +19.5] +11.3% +8.8% flagged npm/rescan(round 2, 30+ pairs)190.7 ms 210.2 ms +8.9% [+5.6, +12.9] +8.8% +9.2% ≈ (not confirmed) npm/dry-run(round 1)183.0 ms 209.4 ms +14.7% [+10.4, +17.2] +10.8% +5.8% flagged npm/dry-run(round 2, 30+ pairs)211.3 ms 238.9 ms +10.0% [+6.1, +14.5] +9.4% +5.6% confirmed npm/public-proxy201.2 ms 219.5 ms +4.4% [+1.0, +13.4] +5.9% +5.8% ≈ The daily A/B (
9c43dfc9→ea097142) shows no change on any npm scenario: hosted -3.2%, rescan +1.4%, dry-run +2.6%. Request counts are unchanged. The overhead is still there, about +5-10% wall and CPU and about +6-9% RSS on every npm scan, but it is no longer above 10% onnpm/hosted. #1008 is the open fix.Repro:
socket-patch-bench compare --base <2463257a build> --head <ea097142 build> -f '^npm/(hosted|rescan|dry-run)$' --runs 30
Generated by Claude Code
[agent] Bench:
npm/hostedwall time is +15% to +20% over the last 7 days ofmain(CPU +12% to +14%, peak RSS +3% to +5%).npm/rescan,npm/dry-runandnpm/public-proxymoved the same way. Request counts are unchanged (127 / 67 / 151).There is no single culprit commit. The cost built up across the range, about half before and half after
045d7ec7. This is gradual drift, not one bad PR.Same-machine interleaved
compare(base2463257a#277 → head9c43dfc9, run 2026-10-07):npm/hosted(full run)npm/hosted(confirm, 15 pairs)npm/rescan(full run)npm/rescan(confirm)npm/dry-runnpm/public-proxyAn A/A run of the same binary at two paths on this runner was clean (npm/hosted -2.3%), so the result isn't runner noise. On 2026-10-06 the weekly ratio was already 1.100 (CI [-0.3, +15.9]); before that it held at 1.02-1.05.
Narrowing (one extra build,
045d7ec7, the main SHA measured 10-03 to 10-05):2463257a..045d7ec7(55 commits)045d7ec7..9c43dfc9(74 commits)Neither half is significant alone, so bisecting further won't name one commit.
Profile (callgrind,
npm/dry-runfixture, base vs head): total instructions went up 9.4%, from 948M to 1,036M Ir. The added work is in new npm lock passes during VEX discovery and the rewrite:vex::discover::discover_with_ctx: +57M Ir. It includesvendor::npm_origin::npm_non_registry_entries(27M, new, from Fix npm rewiring git/URL/file lock entries (#326) #345 and Fix npm overrides of git deps being refused (#490) #491),vex::discover::npm::drop_non_registry_installs(18M, new, Fix npm rewiring git/URL/file lock entries (#326) #345) andvex::discover::npm::NpmLockRefs::mention(20M, new, Fix npm VEX attesting a patch the twin lock lacks (#798) #799).cli::commands::context::ProjectContext::locks(102M inclusive, new, Full Gradle support in agent, hosted and vendored modes #646): the shared lock cache now parses the lock throughvendor::common::parse_json_manifestandJsonLayout.patch::redirect::rewrite_registry_redirect_withholding_vlt: +23M.Candidates, in order: #799 (
48085cef), #646 (0685ba8c), #345 (6e7ef748) and #491 (73b17db5). Each one re-walks the 3000-entrypackage-lock.json, so sharing one parsed lock walk across the VEX npm passes would likely win back most of this.Repro
Runner: 4 vCPU, Intel(R) Xeon(R) Processor @ 2.80GHz (cloud sandbox),
nproc= 4.Why this was filed: the regression is confirmed (it held in a second round), and
npm/hostedhas measured ≥10% over the week window on two consecutive runs (10-06 1.100, 10-07 1.150/1.196). Progress is logged in #575.Generated by Claude Code
Backlog review — 2026-10-08
Priority: P1 → P3. A roughly 15% microbenchmark regression at subsecond absolute runtime needs performance tracking, not P1 incident priority. Keep active #1008.