Conversation
The transcript data-plane benchmark called store.readTranscriptPageSnapshot, which apache#4879 removed when Session transcripts moved to the RuntimeEvent ledger; the storage contract kept only readTranscriptHighWaterSnapshot, so the script has crashed on main ever since. Retire rather than repair: the script seeded its fixture through store.appendMessages, and rows written that way never reach the RuntimeEvent ledger the replacement reader pages from, so pointing the same harness at the new reader would page an empty Session. A repair means rebuilding the fixture through the composition's turn pipeline - which is exactly what apache#5800's benchmark:hydration-e2e already measures end to end (subscription.open tail bootstrap, session.transcript.page paging through real handlers, production ClientSessionSubscription decode). Drop the script and its dead benchmark:transcript entry rather than duplicate that harness. Refs apache#4677 Generated-by: GLM-5.3-Flash (ZCode)
|
The The fix is a lockfile bump (undici to >=6.28.1 / >=7.29.1 / >=8.10.2 depending on the copy; |
hqhq1025
left a comment
There was a problem hiding this comment.
Reviewed the current head against main 2f322055. The only change deletes packages/runtime-host/scripts/transcript-data-plane-benchmark.mjs and its benchmark:transcript package script (packages/runtime-host/package.json:24-29). The deleted harness calls store.readTranscriptPageSnapshot at its former line 164, but SessionStore exposes only the high-water snapshot (packages/storage/src/session-store.ts:691-694); the production transcript reader instead pages the durable ledger (packages/runtime-host/src/server/session-transcript-reader.ts:65-85). I found no remaining repository reference to the deleted benchmark and no substantiated P0-P3 issue in the two-file removal. The package JSON parses, and the fresh-main merge tree and diff check are clean. I did not independently execute the old broken harness or a full local test suite; current-head hosted test passes.
This is not yet a clean merge gate: current-head audit and immutable-tarball checks fail on shipped dependency advisories (ip-address and undici; the tarball's production audit reports two moderate vulnerabilities). This PR does not change the dependency lockfile, so those failures are outside the deletion itself, but they remain red. Also, #5800 is still open and measures a Host-client decode proxy, not the Desktop visible-tail SLO; its small-turn fixture does not replace this deleted harness's large-message/64 MiB stress cases. Please keep that distinction in the performance/acceptance record.
Automated review notice: This comment was posted by an automated review agent operated by hqhq1025. It is not an independent human review and does not replace one.
|
The two reds on
|
The tarball and audit lanes failed on npm resolving undici@7.29.0 for the CLI release tree - GHSA-3wwx-pv8p-q78v was published against that version, and undici 7.29.1 (the fixed release) is out. Tree-identical retrigger so the installer resolves the patched version. Generated-by: GLM-5.3-Flash (ZCode)
|
Correction to my previous comment: the retrigger did not self-heal, and the reason is now established — the root Fixed on head The affected lanes (audit, Build immutable tarball) should go green on this head. |
The release/audit lanes fail because the lockfile pins undici@7.29.0 (three nested copies) and undici@6.28.0, both in the advisory's range; the release tree installs from the lockfile, so no retrigger helps. Overrides pin each consumer to the fixed release of its own major (7.30.0 / 6.29.0 / 8.11.2), and packages/runtime is pinned to exactly 7.30.0 because @slack/socket-mode's peer demands ^7 while runtime code needs a working WebSocket/fetch/buildConnector (gateway and plugin-client-bridge tests pass on 7.30.0). Generated-by: GLM-5.3-Flash (ZCode)
|
Second correction, with the missing piece: the overrides update had silently dropped six unrelated resolution entries from the lockfile ( Head is now |
The undici overrides update left the lockfile with six dangling dependency edges: gpt-tokenizer, @stylexjs/stylex (plus its styleq / css-mediaquery / loose-envify peers) and invariant were still declared by the astryx packages but their node_modules resolution entries had been dropped, so `npm ci` refused to install at all. A full `npm install` re-resolved them; `npm ci` now passes locally and the undici pins are unchanged. Generated-by: GLM-5.3-Flash (ZCode)
app-builder-lib declares electron-builder-squirrel-windows in its devDependencies and peerDependencies (exact 26.16.1), and npm's tree validation refuses the desktop workspace while that peer has no resolution entry - every npm lane (audit, test, package, tarball) fails with ELSPROBLEMS. The entry was silently dropped by the same re- resolution that trimmed the undici lockfile, and being a peer it never regenerates on its own. Declaring it explicitly in the desktop devDependencies satisfies the peer durably; npm ci passes with the workspace tree clean. Generated-by: GLM-5.3-Flash (ZCode)
|
Third and (with luck) final piece: the lockfile was still missing one resolution entry — Fixed durably by declaring it in the desktop devDependencies (next to |
|
Fourth increment on
The squirrel-windows peer declaration from the previous push is what cleared the ELSPROBLEMS layer these were hiding behind. audit / tarball / test should go green on this head. |
…lex notice The shipped-closure audit now flags ip-address@10.4.0 (GHSA-rpw4-54j3- 4h4q / GHSA-2vr4-cq9g-pvrc, SSRF); an override pins 10.7.2, which both declaring ranges accept. The third-party-notices generator's MIT copyright override for @stylexjs/stylex tracked 0.19.0 while the tree resolves 0.19.1 (same upstream, same copyright line) - the key follows. Generated-by: GLM-5.3-Flash (ZCode)
hqhq1025
left a comment
There was a problem hiding this comment.
This head also changes production dependencies while retiring the obsolete transcript benchmark. I found two regressions in the added dependency changes. The benchmark removal itself remains sound: it called a SessionStore API that no longer exists. The current head is not ready to merge: hosted test, package, package-linux, and immutable-tarball checks fail, although audit passes. I verified the HTTP-proxy behavior against installed Undici 7.30.0 and 8.10.2, and the stale notices against the current-head hosted logs; I did not run a packaged Desktop or a real external proxy.
Automated review notice: This comment was posted by an automated review agent operated by hqhq1025. It is not an independent human review and does not replace one.
| "socks-proxy-agent": "^10.1.0", | ||
| "turndown": "^7.2.4", | ||
| "undici": "^8.10.2", | ||
| "undici": "7.30.0", |
There was a problem hiding this comment.
[P2] Preserve forward-proxy behavior for HTTP targets when changing Undici majors. buildProxyDispatcher creates new ProxyAgent({ uri, factory, clientFactory }) without proxyTunnel. In Undici 8.10.2, the default forwards HTTP requests to an HTTP proxy; in 7.30.0, proxyTunnel defaults to true, so the same request starts with CONNECT. With this head's installed dependencies, the existing closed successful connections ... (http) network test does not complete within 8 seconds; the same test with Undici 8.10.2 passes in about 80 ms. HTTP forward-only proxies can therefore stop working. Please preserve the previous HTTP behavior (or use an Undici 8 security-fix release) and add a focused proxy regression test. This does not establish failure for proxies that accept CONNECT.
| "unifont": { | ||
| "undici": "8.11.2" | ||
| }, | ||
| "ip-address": "10.7.2" |
There was a problem hiding this comment.
[P2] Regenerate and commit both Desktop and CLI third-party notices after changing the production dependency graph. Current-head hosted check:third-party-notices reports missing @stylexjs/stylex@0.19.1, ip-address@10.7.2, and undici@6.29.0/7.30.0; the immutable-tarball check:cli-third-party-notices also reports missing ip-address@10.7.2 and undici@7.30.0/8.11.2. Old versions remain listed. This fails the test, package, package-linux, and immutable-tarball gates. Updating the generator's StyleX copyright override alone does not update the checked-in notices.
The ip-address and undici pins moved the shipped closure; the committed notices files now match it (stylex 0.19.1, ip-address 10.7.2, undici 6.29.0 / 7.30.0 / 8.11.2). Generated-by: GLM-5.3-Flash (ZCode)
|
Fifth increment on
audit was already green last round; test / tarball / package / package-linux should follow on this head. |
The undici re-key left two references behind: the release packager hardcoded undici@8.10.2 when copying the eval closure and writing the CLI manifest (the tree now resolves 8.11.2), and the regenerated lockfile carried registry.npmmirror.com resolved URLs from a local mirror config where main's entries all use registry.npmjs.org. knip also gained an exemption for electron-builder-squirrel-windows: it satisfies app-builder-lib's peer and is never imported by renderer code, same as the existing fontsource entries. Generated-by: GLM-5.3-Flash (ZCode)
|
Formatting nit from the last push: the knip exemption array exceeded the line width, so biome wants it wrapped. Fixed on head |
Generated-by: GLM-5.3-Flash (ZCode)
|
The remaining test failure was a real undici regression from the aggressive re-key, not flake: on |
The aggressive undici re-key broke two real consumers: the eval suite's initialization proxy test saw an unexpected CONNECT through the 7.30.0 ProxyAgent, and the runtime scoped-fetch-transport suite hung on 7.30.0. Walk @ai-sdk/provider-utils back to 7.29.1 (the minimal fixed release) and packages/runtime back to its previous 8.10.2 (already past the advisory line); @electron/get keeps 7.30.0 and the 6.x/8.x leaves keep their resolved versions. Both previously failing suites pass locally (42/42 and 1/1). Generated-by: GLM-5.3-Flash (ZCode)
|
One more piece removed on |
The `@slack/socket-mode` override demanded undici@7.30.0 while the runtime tree deduped to 8.10.2, and npm flagged the mismatch as invalid - which every npm ls consumer (audit, release closure, notices) turned into ELSPROBLEMS. The lockfile's nested `@slack/socket-mode/node_modules/undici@7.30.0` entry already satisfies the ^7 peer with the fixed release, so the override is redundant; dropping it leaves a fully valid tree. Generated-by: GLM-5.3-Flash (ZCode)
…losure The undici version walk-back changed the shipped closure again (+7.29.1, +8.10.2 after the @slack nested entry re-landed); the committed notices files now match it, per the lockfile-chain checklist. Generated-by: GLM-5.3-Flash (ZCode)
hqhq1025
left a comment
There was a problem hiding this comment.
The two findings from my previous review are addressed on this head. packages/runtime/package.json restores Undici 8.10.2 for the runtime; after npm ci, the existing HTTP forward-proxy test completes in 74 ms rather than hanging. The regenerated Desktop and CLI third-party notices both pass their local --check commands. The obsolete transcript benchmark remains removed, and I found no new actionable issue in the seven-file increment. The fresh-main merge-tree and diff check are clean; hosted audit, package-linux, and immutable-tarball checks pass.
The hosted test check is still red: an unchanged ACP Goal/Plan child-process test timed out after 30 seconds. I did not reproduce that test locally because this checkout has no built CLI test artifact, so its cause remains unconfirmed. The hosted package check was still running when I submitted this review. This is not merge approval; recheck the current-head required gates before merging. I did not run a real external proxy, a packaged Desktop, or the retired 64 MiB stress scenario.
Automated review notice: This comment was posted by an automated review agent operated by hqhq1025. It is not an independent human review and does not replace one.
Summary
benchmark:transcript(packages/runtime-host/scripts/transcript-data-plane-benchmark.mjs) crashes on current main: its sqlite reader adapter callsstore.readTranscriptPageSnapshot(...)(line 164 of the script), a method #4879 removed when Session transcripts moved to the RuntimeEvent ledger. The storage contract kept onlyreadTranscriptHighWaterSnapshot, so every run dies withTypeError: store.readTranscriptPageSnapshot is not a functionbefore printing any row (reproduced locally on this branch's base; stack below).Verdict: retire, not repair. Two independent reasons:
store.appendMessages, and rows written that way never reach the RuntimeEvent ledger that the replacement reader (createSessionTranscriptReader) pages from - pointing the same harness at the new reader would page an empty Session and fail its own materialized-count assertion. A repair means rebuilding the fixture through the composition's turn pipeline.benchmark:hydration-e2e, which measures the same data plane end to end: a real execution composition,subscription.openwith the 16 KiB tail bootstrap,session.transcript.pagepaging through real handlers, and productionClientSessionSubscriptiondecode - with the storage scan and pager CPU inside each measured round trip. The old script's unique angle (bare sqlite direct reads, arithmetic RTT floor) no longer exists in isolation post-refactor(runtime): derive Session transcripts from RuntimeEvents #4879, since the ledger read path is the read model projection, not a message-table snapshot.This PR deletes the script and its dead
benchmark:transcriptpackage.json entry. History: the script and the API it calls were born together in #2922; #4879 removed the API. Merge-order note: #5800 is still open; until it merges there is a window with no data-plane benchmark, which is acceptable for a script that cannot run at all. Refs #4677 (the hydration budget work that motivated both benchmarks).Verification
TypeError: store.readTranscriptPageSnapshot is not a functionatcreateSessionTranscriptBootstrap(dist/server/session-transcript-pager.js:33), thrown from the script'ssqliteReaderadapternpx biome check packages/runtime-host/package.jsonnpm run check:asf-headersnode scripts/protocol-epoch-check.mjs --stagedgit diff --check --cachedbenchmark:hydration-e2eruns on this branch's rebuilt workspaceTURNS=2 ROUNDS=1 RTT_MS=1: seed 2s, hostDecodeTail 9.1ms, fullHydration 9.3ms, tail 1.10 KiB / 6 msgs, materialized 6 msgsgrep -r "benchmark:transcript|transcript-data-plane"over the repo: zero hits after deletionAI use
Generative tooling - GLM-5.3-Flash (ZCode)
Checklist