fix(gateway): memoize only resolved profile homes, never the miss
Review feedback on the memo introduced with _profile_home_for_key. The problem is sharper than "no invalidation on profile deletion": caching the miss pinned a profile that appears AFTER the gateway started to the ambient store for the life of the process, which is the exact failure this helper exists to prevent. That is not hypothetical — an enrollment bridge can provision profiles/<name>/ at runtime, so a key is legitimately seen before its directory exists. Memoize hits only. A miss costs one profile_exists() stat and recurs only for profiles that genuinely do not exist, so the hot path for real profiles is still a dict hit. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
+8
-1
@@ -1425,7 +1425,14 @@ class SessionStore:
|
||||
"Could not resolve profile home for %r: %s", session_key, exc
|
||||
)
|
||||
home = None
|
||||
cache[profile] = home
|
||||
# Only a hit is memoized. A profile directory can appear *after* the
|
||||
# gateway started — the enrollment bridge provisions profiles/<name>/
|
||||
# at runtime — and caching the miss would pin that profile's rows to
|
||||
# the ambient store for the life of the process, which is the bug
|
||||
# this helper exists to prevent. A miss costs one profile_exists()
|
||||
# stat and only recurs for profiles that genuinely do not exist.
|
||||
if home is not None:
|
||||
cache[profile] = home
|
||||
return home
|
||||
|
||||
def _db_for_key(self, session_key: Optional[str]):
|
||||
|
||||
@@ -606,3 +606,22 @@ def test_pinned_handle_still_wins_over_key_resolution(multiplex_homes):
|
||||
store._db = sentinel
|
||||
assert store._db_for_key("agent:fitness:telegram:dm:1") is sentinel
|
||||
assert store._db_for_session_id("whatever") is sentinel
|
||||
|
||||
|
||||
def test_profile_home_is_not_memoized_before_the_profile_exists(multiplex_homes):
|
||||
"""A profile provisioned after startup must not stay pinned to the root store.
|
||||
|
||||
The enrollment bridge creates ``profiles/<name>/`` at runtime, so a key can
|
||||
be seen before its directory exists. Memoizing that miss would pin the
|
||||
profile to the ambient store for the life of the process — the exact bug
|
||||
this helper exists to prevent.
|
||||
"""
|
||||
root, _profile = multiplex_homes
|
||||
store = _multiplex_store(root)
|
||||
key = "agent:latecomer:telegram:dm:9"
|
||||
|
||||
assert store._profile_home_for_key(key) is None
|
||||
|
||||
(root / "profiles" / "latecomer").mkdir(parents=True)
|
||||
|
||||
assert store._profile_home_for_key(key) == root / "profiles" / "latecomer"
|
||||
|
||||
Reference in New Issue
Block a user