Skip to content

W4 (part one): keep file verdicts outside F5, one publisher memory per pass - #27

Merged
donislawdev merged 1 commit into
mainfrom
perf/w4-signatures
Sep 28, 2026
Merged

donislawdev merged 1 commit into
mainfrom
perf/w4-signatures

Conversation

@donislawdev

Copy link
Copy Markdown
Owner

First part of W4 of the performance series: the owner's S-1 decision and backlog 468. The AUTO_CACHE prototype is left for the next chat.

Keep what the window knows about files (S-1)

A full reading after a plan, after something is installed or removed, and when a column or a query needs a family the window has not read keeps the signature, version and hash of every file the window already asked about. Only F5 and the first look verify everything again. This follows the owner's decision recorded in ADR-13 and its addendum of 2026-09-29, and the price was accepted there: a file replaced by someone else between F5 and a plan keeps its old verdict until the next F5.

  • SecondPass.Keep(fresh, earlier) carries answers by file path. A new service on an already verified host has its answer. An entry whose path changed is a different key and gets verified. "Not read" (a skipped network file) is not kept.
  • SecondPass.Fill asks only about files no entry has an answer for. Every existing caller (the command line, F5, the details panel) hands it a fresh listing, so nothing changes for them.
  • The window has Relisting.Afresh and Relisting.Keeping, and takes the answers from the rows before replacing them, so the column does not flicker. MainViewModel.LoadKeepingAsync runs after a plan.

From the measurement in the analysis (P3), the full second phase costs about 12 s of processor over 797 entries, and 4.3-5.0 s of clock on two processors. After a plan it now verifies nothing unless a path is new. This is an inference, not a measurement after the change. A plan needs elevation, which this session does not have.

One publisher memory per pass (backlog 468)

The Windows inspector remembers the publisher of every catalogue it opens, and the window held one inspector for its whole life, which is longer than any F5. IBinaryInspector.ForOnePass (by default the inspector itself) makes the Windows inspector hand out a fresh one for each pass.

Not done

  • The split of the signature family was rejected by the owner (it would change the JSON).
  • The AUTO_CACHE prototype goes to the next chat.

Guards and runs

  • KeptFileAnswersTests in the window: after a plan zero files are verified again, F5 verifies all of them, after an install only the new file, and a new column verifies no signature.
  • SecondPassKeepTests in the core: five cases.
  • Mutation entries: 9 new, 2 re-anchored, 11 of 11 caught.
  • Narrow runs:
    • core SecondPass* and *BinaryInspector*: 18/18
    • integration runs=anywhere: 24/24
    • SignatureContractTests (verdicts against Get-AuthenticodeSignature): 5/5
    • architecture: 182/182
    • window: 49/52. The three failures are the known unelevated ones, and each fails on the sentence "Running without administrator rights".

🤖 Generated with Claude Code

The owner's S-1 decision (ADR-13): a full reading after a plan, after a
change to what is installed, and when a question needs a family the window
has not read, keeps the signature, version and hash of every file the
window already asked about. Only F5 and the first look verify everything
again. Keyed by the file path, so a new service on an already verified host
has its answer and an entry whose path changed is verified afresh. "Not
read" is not kept.

SecondPass.Keep carries the answers onto a fresh listing, and SecondPass.Fill
asks only about files no entry has an answer for, which changes nothing for
callers that hand it a fresh listing (the command line, F5, the details
panel). The window distinguishes Relisting.Afresh from Relisting.Keeping and
takes the answers from the rows before they are replaced, so the column does
not flicker. MainViewModel.LoadKeepingAsync is what runs after a plan.

Backlog 468: the publisher memory of the Windows inspector lived as long as
the window, longer than any F5. IBinaryInspector.ForOnePass hands every pass
a fresh inspector, so F5 really does read everything again.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@coderabbitai

coderabbitai Bot commented Sep 28, 2026

Copy link
Copy Markdown

Important

  • 🔍 Trigger review

This repository does not receive automatic reviews because it has fewer than 10 stars.

⚙️ Run configuration

Configuration used: Repository UI (base), Organization UI (inherited)

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 923c59b7-59a4-4363-a153-c156f9526b42


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@donislawdev
donislawdev merged commit be66326 into main Sep 28, 2026
8 checks passed
@donislawdev
donislawdev deleted the perf/w4-signatures branch September 28, 2026 23:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant