docs(changelog): scheduler/messages IO fixes and hono bump (#203)
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
@@ -0,0 +1,3 @@
|
||||
# Dependencies: hono ≥ 4.12.34 (CORS preflight ReDoS)
|
||||
|
||||
Resolves the repository's one open Dependabot alert: GHSA-8j4g-w8fx-2239 / CVE-2026-69207, a moderate ReDoS in Hono's `hono/cors` middleware — quadratic regex backtracking on an attacker-controlled `Access-Control-Request-Headers` preflight header when `allowHeaders` is unconfigured. The server package's direct `hono` range moves from `^4.8.0` to `^4.12.34` (the first patched version, same major); the lockfile change is confined to the hono chain, and `pnpm audit` reports no known vulnerabilities after the bump.
|
||||
@@ -0,0 +1,11 @@
|
||||
# Server: the last two IO hotspots — scheduler ticks and chat-history loads
|
||||
|
||||
The disk-IO audit that produced the trace index left two hotspots standing; both are closed.
|
||||
|
||||
## Scheduler ticks and project-config reads
|
||||
|
||||
The 30-second scheduler tick used to re-read every schedule file of every agent and re-parse the same `.project_config.toml` once per schedule file, forever, with no change detection — the only unconditional recurring disk load in the process. Schedule scanning is now cached per agent, keyed on the schedule directory's mtime plus a per-file mtime/size check (the per-file stat closes the POSIX blind spot where an in-place edit never touches the directory mtime, so hand-edited files are still picked up on the next tick); the agents-dir enumeration itself is gated the same way, and the "fresh mtime is never cached as clean" sentinel moved to a shared `internal/mtime-gate.ts` that the trace index now imports too — the contract lives in one place. `.project_config.toml` gains a parsed-table cache inside `ProjectConfigService`, stat-checked before reuse and invalidated synchronously by every service write path, so scheduler validation, the schedules routes and usage pricing all share one parse per on-disk version while hand edits still land. Steady state per tick: a handful of stats, zero file reads; scheduling behavior, listing order and validation semantics are byte-identical, and tests pin the zero-read steady state with fs probes.
|
||||
|
||||
## Chat-history pagination
|
||||
|
||||
`GET /api/sessions/:id/messages` rebuilt a session's entire transcript per request — every shard read whole, subagent sessions recursively included, all of it re-done on every SSE resync. The endpoint now takes additive cursor params: `tailLimit` returns the newest window (with the running session's live attachment, same capture semantics), `before=<shard>:<ordinal>` pages older history; without params the response stays byte-identical to before, pinned by a raw-byte test. Windows cut on Task boundaries only — tool-call pairings, compaction spans and grouped sends are never split — and only the shards overlapping the window are read, with shard inventory from the trace index and older shards' turn counts and token totals served from a per-shard `page_stats` prefix cache (a derived, versioned column added idempotently to existing databases; no user action). The web loads the tail first (200 units) and backfills 100 at a time on scroll-up with anchored prepends; a resync splices onto the retained prefix only when epoch and cursor continuity are provable, anything doubtful falling back to the legacy full refetch. The conversation outline keeps globally correct turn numbering over partial history via a server-supplied earlier-turn count, and the header token/elapsed figures stay truthful through seeded prefix stats.
|
||||
@@ -1,5 +1,9 @@
|
||||
# Unreleased
|
||||
|
||||
- [2026-08-04] Server: the last two IO hotspots closed — the 30-second scheduler tick and the schedules routes now serve from mtime-gated caches (zero steady-state file reads, hand edits still picked up; `.project_config.toml` parsed once per on-disk version across scheduler, routes and usage pricing), and `GET /messages` gains cursor pagination with tail-first web loading, Task-boundary windows, provable-continuity resync splicing and globally correct outline numbering — the no-params response stays byte-identical. ([details](2026-08-04-io-hotspots-scheduler-messages.md))
|
||||
|
||||
- [2026-08-04] Dependencies: `hono` bumped to ≥ 4.12.34, resolving the open Dependabot alert (GHSA-8j4g-w8fx-2239, CORS preflight ReDoS); lockfile change confined to the hono chain. ([details](2026-08-04-deps-hono-redos.md))
|
||||
|
||||
- [2026-08-04] Desktop app: new `packages/desktop` — an Electron shell that runs the existing server as a utilityProcess on the shared data root and its window on `http://localhost` with token-based no-login sign-in, graceful shutdown, and crash restart; desktop mode on the server (one-shot login, shutdown endpoint, unprinted random seed, `desktopMode`/`sessionVia` on /api/me), a new per-root `server.lock` single-instance guard the CLI and shell both honor, desktop-aware Web App chrome, and three-platform packaging (electron-builder over a pnpm-deploy staging tree, built by a reusable CI matrix ahead of Release creation; unsigned until the signing milestone). ([details](2026-08-04-desktop-app.md))
|
||||
|
||||
- [2026-08-04] Web App: the public fixed admin password `penguin-2026` is replaced by a random `penguin-<4 digits>` seed printed once at first start (`PENGUIN_SEED_ADMIN_PASSWORD` pins it for tests, policy-checked), and the login endpoint gains per-username exponential throttling (5 free failures, 1s doubling to 60s, `429 too_many_attempts`, reset on success, identical for unknown usernames) so the 4-digit space cannot be enumerated. ([details](2026-08-04-web-app.md))
|
||||
|
||||
Reference in New Issue
Block a user