Skip to content
GitHubRSS

Optimization catalog

Every performance decision that shipped, in one place: what it is, where it lives, why it’s safe, and the invariant that keeps it valid. If you change code near one of these, the invariant column is the contract you must re-verify. Measured numbers come from benchmarks.md; the decision history is in git (the log was retired 2026-09-02).

The headline numbers live in benchmarks.md and move with each measurement; this catalog carries the decisions and the invariants, not the figures.

#WhatWhereWhy / effectInvariant to preserve
1xxHash3 for every cache-key site (was SHA-256)util/hash.ts, cache/key-fold.ts, orchestrator/task-hash.ts, workspace/fingerprint.ts, workspace/project-loader.ts~5× faster derivation on the warm path; 16-hex keys match Turbo’s xxh64 widthNot cryptographic — fine for content addressing, never use for auth/integrity vs. an adversary
2Seed-chained key folding (xxh3(part, prevDigest)) instead of a streaming hashercache/key-fold.tsBun has no streaming xxh3; chaining avoids concatenating a big key bufferEvery variable-length part must be length-prefixed or \0-delimited so part boundaries stay unambiguous
3Workspace fingerprint computed once per run, folded into every task keyworkspace/fingerprint.tsOne lockfile read/hash instead of NMust cover every supported lockfile + pnpm-workspace.yaml; fixed file order
4Config module-cache busting by content hash, not mtimeworkspace/project-loader.tsSame content → Bun module-cache hit; changed content → fresh eval. Hashing a <10 KB config is ~50 µsThe hash must cover the full file bytes; mtime is not reliable (Bun mtimeNs undefined; ms granularity misses rapid edits)
5Per-run hashCache for repeated file/config hashesorchestrator/prepare.ts → orchestrator/task-hash.tsShared files (presets) hash once per runCache is per-run only; nothing may persist across runs without entering the key itself
#WhatWhereWhy / effectInvariant to preserve
6git ls-files -s -v + git status --porcelain -uall instead of an FS walk + ignore parsing (ls-files --others --exclude-standard only in the per-project fallback, runGitLsFiles)cache/git-inputs.tsTurbo/Nx parity; git’s C-speed ignore handling; correct nested-.gitignore anchoring (fixed a real v13 bug); -s also harvests index OIDs (row 31)vx hard-requires git — no fallback walker. Absent git → UserError, never silent degradation
7One workspace-root git snapshot per run, partitioned per project (gitFilesCache, applyGitEnumeration)cache/git-inputs.ts, invalidated in orchestrator/miss-save.ts and orchestrator/hit-restore.tsOne snapshot’s spawns instead of P; zero re-spawns in src→dist layoutsStaleness rule: after a SAVE and after a RESTORE the exact changed (declared-output) paths are recorded via GitFilesCache.markOutputsChanged; downstream tasks re-spawn git only when their input globs can match a changed path. (The save-path used to DROP the whole entry — replaced 2026-06, −28% cold; a CACHED task writing UNDECLARED files a same-project downstream reads is undeclared behavior — declare your outputs; a task with NO cache block cannot declare any, so its project’s entry, OIDs and package.json digest are dropped once its command exits, item 743)
8O(P log P) nested-project-boundary computation (sort + contiguous prefix scan; was O(P²))workspace/nested-dirs.tsNegligible at 10 projects, real at 1000Prefix match must include the trailing path.sep so pkg/a is not treated as parent of pkg/ab
34Per-run memo of inputs.files resolution, keyed by project + declaration (projectFilesCache)cache/inputs.ts, held in orchestrator/task-hash.ts’s HashCacheTasks of one project declaring the same inputs and outputs walk the git snapshot once, not once each: this repo’s twelve shard tasks took task hash from 50.6-54.9 ms to 37.1-40.5 ms over 44 tasks (2026-09-20)Reuse is gated on the snapshot being the SAME ARRAY the entry walked, so a mid-run re-enumeration misses; the key must carry every exclude (own outputs, negations, project boundaries)
35key() checks input order instead of copying and sorting every callcache/key-fold.tsresolveFiles already returns sorted paths, so the common case is one comparison per file instead of n log n: 7.4 ms of a 44-task run over ~3,000 files each (2026-09-20)An unsorted list must still be sorted — the fold order is what makes a key stable across runs
36The per-file digests are gathered synchronously when the caller’s OID map covers themcache/key-fold.tsA warm task builds no promises for values already in hand: 8.4 ms of that same runThe first gap falls back to the awaited form for the WHOLE list, so a partial map keys exactly as before
37relPosix memoized per Cache while the workspace root holdscache/cache.ts:relForThe same files are re-relativized for every task of a project — 132,000 calls for 3,000 answers on this repo’s gateThe memo clears when a caller arrives with a different root, or one workspace’s names would fold under another’s
#WhatWhereWhy / effectInvariant to preserve
9O(N + E) scheduler tick: per-node dep counters + ready priority queue (was O(N²) rescan per completion)graph/scheduler.tsTick cost independent of graph size: O(E) counter decrements over the run, one O(log N) heap op per enqueue and per dispatchPriority contract: higher transitive-reverse-dep count first; ties break in graph-insertion order (the ready heap orders by priority DESC, enqueue-seq ASC)
9bBitset transitive-dependent closure in reverse-topo order (was memoized DFS over string Sets)graph/priorities.ts:computeReverseDepCountSet closures were O(N²) entries: 8.5 s of a 10 s warm run on a 1090-package / 100-layer repo; bitsets = O(E·N/32), single-digit msCounts must stay EXACT (popcount of the closure), not a summed approximation — diamonds double-count under naive summing. With a restore tier, exec-tier counts are exact over the exec tier and a restore’s rank is a sum (item 754)
10Iterative cycle detection with Uint8Array color array (was recursion + Map)graph/task-graph.ts:detectCycleNo V8 stack ceiling on deep dependsOn chains; no per-node Map costMust still report the cycle path in the error
11Group tasks execute with zero I/O — hash rolled up from upstream outcomesorchestrator/task-hash.ts:computeGroupHashUmbrella tasks (install, ci) cost microsecondsGroup hash must fold every upstream id:hash pair, sorted, so it stays order-independent
#WhatWhereWhy / effectInvariant to preserve
12In-process tar pack/read/extract (Bun.Archive in v27, vx’s own streaming tar code since 2026-09-03), + a .vx-meta.json mode/mtime sidecarcache/archive.tsReplaced the hand-rolled reader AND the tar subprocess (v27). Pack no longer stages a copy of every output: measured on Cache.save, min-of-5, interleaved against a git worktree of the previous commit — 1 file 6.15 → 0.32 ms, 20 files 11.9 → 0.65 ms, 300 files / 12 MB 158 → 11 ms. Restore is a wash (0.27 / 2.16 ms unchanged). Corrects the earlier entry here claiming Bun.Archive was 15–400× slower for this shape: not true on Bun 1.4Entry-name validation and destination containment stay vx’s (absolute, .., backslash/drive, symlinked-ancestor walk, symlink-unlink before write); non-regular entries are never surfaced by the reader, so they cannot be materialised at all
13Restore skip via output_files rows + stat check (isOutputsCurrent)cache/output-index.ts, orchestrator/hit-restore.tsWarm-warm hit = N stats, zero writes, zero decompressStored size/mode/mtime fingerprint must match what the restore produces (both come from the .vx-meta.json sidecar, at millisecond precision), and the inode + ctime stamp recorded after each save and restore must match — a row with no stamp is never current
14SQLite metadata index, WAL, busy_timeout = 5000, one handle per runcache/cache.tsIndexed lookups; concurrent vx run invocations don’t crashEntry metadata lives in SQL only (artifacts carry just stdout, outputs/<rel>, workspace-outputs/<rel> and the .vx-meta.json mode/mtime sidecar) — never move entry metadata into the artifact, where it can drift from the rows
15Atomic artifact publish: unique tmp name → rename (no pre-rm)cache/cache.ts:writeArtifactAndIndexConcurrent saves of the same hash are either-or; readers never see partial bytesPOSIX rename replaces atomically; the pre-rm variant reintroduces a delete-after-rename race
16Single-transaction batch writes: recordRuns, prune deletes (+ parallel artifact rm)cache/run-history.ts, cache/cache.tsOne fsync instead of NPrune’s IN-list binding must stay under SQLite’s 999-placeholder limit per statement
17Artifact = stdout + outputs/<rel> + workspace-outputs/<rel> + .vx-meta.json sidecar; identical bytes local and remotecache/cache.ts, cache/layered-cache.tsNo stage-dir repack for upload — save re-reads the just-written artifact and PUTs it verbatim; remote hit writes the body straight to diskLocal and remote layers must keep transporting the same byte format; metadata travels out-of-band (SQL row / HTTP headers)
17bAsync remote prefetch: derive stable keys up front, fire remote GETs in the background, overlapping network with executionorchestrator/remote-prefetch.ts, cache/layered-cache.ts (prefetch + inflight map)A remote-served warm run no longer pays remote-GET latency on each task’s critical path; the GETs race alongside execution and land in local before execute-task needs themRemote-only (gated on a remote layer, prepared.hasRemoteLayer; a local-only run takes 17d’s batched local probe instead, never this remote path). Stable-key-only (a task whose inputs could match an upstream output is skipped → lazy read-through; gate shared with 17d via orchestrator/stable-keys.ts). At-most-once per key (prefetch + get share the inflight map; a settled-false miss blocks a second probe). Provenance stays remote (outcome cache-hit-remote) ONLY for genuinely remote-pulled hashes — local-first: a hash local already holds is skipped before the GET (no redundant download on a warm-local run) and stays local. Caller awaits the prefetch pool before cache.close() so no ingest hits a closed DB
17cBackground remote uploads: LayeredCache.save PUTs in the background; run() drains before cache.close()cache/layered-cache.tsA task’s outcome (and its dependents) never wait on upload latency; uploads race alongside the rest of the runEvery upload must be drained before the process exits (a short run still ships all artifacts); failures log via onRemoteError, never propagate; the uploaded bytes stay the verbatim local artifact (no repack)
17dLocal short-circuit + two-tier restore-ahead scheduler: up-front stable-key classify + ONE batched local probe (getMany); confirmed hits become a restore tier the scheduler runs ahead of their deps as LOW-priority worker backfillorchestrator/local-shortcircuit.ts, orchestrator/stable-keys.ts, graph/scheduler.ts−6.6% on a mixed slow-upstream/warm-downstream workload; parity on all-hit warm runs (probe reuse means zero double work)Local-only (never with a remote layer, cache.hasRemote — prefetch owns those; an awaited up-front remote GET would sit on the critical path). Probe reuse — execute-task consumes preProbed, exactly one probe per stable task (per-task cache.get only when the layer has no getMany). Misses own the worker pool (execReady drains first). A task whose project dir (or workspace inputs) an outputs.workspaceFiles glob’s static prefix reaches stays out of the restore tier, with every transitive dependant; a glob with no literal prefix reaches every task. Never throws — degrades to the plain schedule
17e--dry / --graph remote prediction via HEAD existence probeorchestrator/plan.ts, cache/layered-cache.tsPlanning a remote-warm graph costs headers, not artifact downloads + local ingestPlanning stays side-effect-free on artifact storage: no download, no ingest; a predicted hit-remote = the artifact exists remotely
17fPure-SQL cache.get: stdout in the entries row; artifact untouched on probe; accessed_at bumps batch at flushcache/cache.tsHit cost no longer scales with artifact size (118 ms → 5 ms for four ~70 MB binaries); one batched UPDATE instead of per-hit writesThe entries-row stdout and the artifact’s stdout entry must stay identical (the artifact copy is what remote round-trips)
#WhatWhereWhy / effectInvariant to preserve
18Logger buffers chunks as string[], joins on flush (was += accumulation)orchestrator/logger.ts+= was O(N²) over total bytes for chatty tasksPer-task ordering within a stream must be append-only
19Memoized Bun.color ANSI lookupsorchestrator/colors.tsCalled thousands of times with a handful of hex stringsCache key is the color string; gating (NO_COLOR etc.) happens before lookup
20Bun.Glob for filter matching + recursive listing (was hand-rolled regex / readdir recursion)workspace/filter.ts, cache/inputs.tsNative glob engineGlob semantics are now Bun’s — brace/bracket behavior changes with Bun upgrades
21Concurrent project discovery (Promise.all over package globs)workspace/workspace.tsWas serializedDedupe pass after must keep deterministic order
22AbortSignal.timeout for remote-cache fetchesturboCache(), nxCache() in @vzn/vx-migrate (the wires left core)Drops the manual controller + setTimeout ceremonyCatch both AbortError and TimeoutError
23toPosix fast path when path.sep === '/'util/paths.tsSkips split/join on the dominant platformWindows is unsupported anyway; revisit if that changes
24Hoisted dynamic imports out of per-task pathsorchestrator/execute-task.ts, cache/layered-cache.tsawait import() per task was measurable—
25Bun.spawn everywhere (with resourceUsage())exec/runner.tsNative spawn + free cpu_ms / peak-RSS capture per child—
25bStatus-region force-floor coalescing (forced redraws within 30 ms collapse into one trailing draw)orchestrator/status-line.ts6,540 forced redraws ≈ 6.7 MB of ANSI on a 3,270-task warm run → ~20 KBThe FINAL state must always land (the trailing draw); the first draw after idle stays immediate

June 2026 scaling pass (1090-package stress repo: 10.2 s → 0.62 s)

Section titled “June 2026 scaling pass (1090-package stress repo: 10.2 s → 0.62 s)”
#WhatWhereWhy / effectInvariant to preserve
26Bitset transitive-dependent closure for scheduler priority (was Set-DFS)graph/priorities.ts:computeReverseDepCount8.5 s → ms on dense 100-layer graphs; O(E·N/32)Counts stay EXACT (popcount); own Kahn pass — never trust Map insertion order
27Bitset package-graph closures, sorted-name indexing (sort-free materialization)workspace/package-graph.ts68 ms → ~ms at 1090 projectsCyclic dep graphs fall back wholesale to legacy DFS
28Binary-search git-file partitioning (was O(P·F) startsWith)cache/git-inputs.ts:applyGitEnumeration54 ms → ~5 ms at 1090×9kPrefix ranges need the array sorted with the SAME comparator as the search
29Parallel project discovery; config lookup is one readdir per project on Linux, in-order stats of the candidate names on macOSworkspace/workspace.ts:listProjectsserial I/O → concurrentDuplicate-name check stays a deterministic sequential pass
30Frontier ^task expansion (nearest holder per path, sparse bridging kept) — v19graph/task-graph.ts8.5× fewer edges on dense graphs; shrinks group-hash sorts, dep sorts, closures, upstream folds at onceHolder’s own dependsOn owns deeper ordering (Turbo parity, documented stop)
31Git blob OIDs as input-file hashes; dirty files get in-process blob OIDs; three git spawns concurrent (ls-files -s -v, status, var -l), rev-parse memoized, check-attr only where a filter could convert bytes — v20cache/git-inputs.ts, cache/file-hashes.ts:hashFileClean-tree hashing: zero reads/stats/SQLite. 3.2× warm run-phase at 15k files (245→76 ms)A file’s key contribution must never flip across dirty↔clean (uniform blob-OID domain); symlinks/conflict stages never trusted
32Early cutoff: downstream keys fold upstream OUTPUT content identity — v21 REVERTED in v22orchestrator/upstream.ts (now folds the upstream INPUT key)Removed: pure-input transitive hashing replaced it (owner: “rely only on task input hashes”). Identical-output rebuilds re-run dependents again — rare in practice; see caching.md.n/a — no output content participates in any cache key in v22
33Scoped config loading: only in-scope projects + their transitive dep closure evaluateorchestrator/prepare.ts1090 config evals (~200 ms) → only the run’s closure; single-task wall 0.32 s → ~0.19 s on the 1090-package repoBoundary geometry still considers EVERY config-bearing project (loaded or not); a broken out-of-scope config surfacing only when it enters scope is the documented Turbo-like semantic

Known headroom (deliberately not taken yet)

Section titled “Known headroom (deliberately not taken yet)”

From benchmarks.md and the perf-pass backlog — candidates with a measured or suspected win, parked until profiled:

  • Group-task reverse-index for ^build fan-out re-resolution.
  • relPosix fast path for ASCII workspace-root prefixes in the enumeration loop.

Two earlier entries here shipped: the batched cache-entry lookup for the all-hits path (#17d, one probe per task from the stable-key classify, 2026-09-02) and the per-run memo of taskConfigHash (#5).

For the record: restores are tar extracts with a stat-check fast path (see #12/#13) — there is no hardlink-based restore, and tar hardlink entries are rejected as a security measure.