23f7624596
ADR-166 MCP Bridge Security Lock / Static-source security lock (push) Failing after 0s
ADR-166 MCP Bridge Security Lock / Compose default binds loopback + Mongo has auth (push) Failing after 2s
CodeQL Advanced / Analyze (rust) (push) Failing after 0s
ADR-166 MCP Bridge Security Lock / plugin-agent-federation bindHost default (push) Failing after 1s
ADR-166 MCP Bridge Security Lock / Runtime behavior — 401 + terminal gate + fail-closed (push) Failing after 4s
business-pods-smoke / smoke (push) Failing after 1s
all-plugins-smoke / smoke-all (push) Failing after 2s
CI/CD Pipeline / Security & Code Quality (push) Failing after 1s
CI/CD Pipeline / Test Suite (ubuntu-latest) (push) Failing after 1s
CI/CD Pipeline / Build & Package (macos-latest) (push) Has been skipped
CI/CD Pipeline / Build & Package (ubuntu-latest) (push) Has been skipped
CI/CD Pipeline / Build & Package (windows-latest) (push) Has been skipped
CI/CD Pipeline / Documentation & Examples (push) Failing after 1s
Clone Tracker (14-day rolling) / Snapshot clones for ruflo ecosystem (push) Failing after 1s
CodeQL Advanced / Analyze (actions) (push) Failing after 1s
CodeQL Advanced / Analyze (javascript-typescript) (push) Failing after 1s
federation-peer-rust / stable-noop (push) Failing after 1s
metaharness-ci / score (push) Failing after 1s
metaharness-ci / router-compat (push) Failing after 0s
metaharness-ci / similarity-tests (push) Failing after 0s
no-agentbbs-smoke / smoke-without-agentbbs (push) Failing after 1s
V3 CI/CD Pipeline / Build V3 (windows-latest) (push) Has been skipped
codex-integration-audit / Codex integration audit (push) Failing after 1s
helpers-manifest-guard / guard (push) Failing after 1s
🔗 Cross-Agent Integration Tests / 🤝 Agent Coordination Tests (push) Has been skipped
🔗 Cross-Agent Integration Tests / 🧠 Memory Sharing Integration (push) Has been skipped
🔗 Cross-Agent Integration Tests / 🛡️ Fault Tolerance Tests (push) Has been skipped
🔗 Cross-Agent Integration Tests / ⚡ Performance Integration Tests (push) Has been skipped
metaharness-ci / mcp-scan (push) Failing after 1s
metaharness-ci / eject-dryrun (push) Failing after 1s
metaharness-ci / metaharness-real-data (push) Failing after 0s
no-cli-optdep-bloat-2561 / guard (push) Failing after 1s
no-metaharness-smoke / smoke-without-metaharness (push) Failing after 1s
no-phantom-agentic-flow-subpath / guard (push) Failing after 1s
🔄 Automated Rollback Manager / 🚨 Failure Detection (push) Failing after 1s
V3 CI/CD Pipeline / Plugin hooks smoke / ubuntu-latest / Node 22 (push) Failing after 1s
V3 CI/CD Pipeline / ruflo-graph-intelligence build + test smoke (#2044, ADR-123) (push) Failing after 1s
CVE Audit Gate / Audit root (critical-blocking) (push) Failing after 2s
cost-tracker-smoke / smoke (push) Failing after 3s
oia-audit-weekly / audit (push) Failing after 2s
ruflo-agent-smoke / ruflo-agent structural smoke (push) Failing after 1s
📊 Status Badges Update / 📊 Update Status Badges (push) Failing after 1s
V3 CI/CD Pipeline / Static regression guards (#2267 YAML + (push) Failing after 1s
V3 CI/CD Pipeline / Test V3 Packages (push) Failing after 0s
V3 CI/CD Pipeline / agent_execute provider routing smoke (#2042) (push) Failing after 0s
CVE Audit Gate / Audit v3 (critical-blocking) (push) Failing after 1s
federation-peer-rust / stable-native (push) Failing after 2s
🔗 Cross-Agent Integration Tests / 🚀 Integration Test Setup (push) Failing after 2s
neural-trader-smoke / runtime-smoke (push) Failing after 1s
V3 CI/CD Pipeline / Build V3 (macos-latest) (push) Has been skipped
V3 CI/CD Pipeline / Build V3 (ubuntu-latest) (push) Has been skipped
V3 CI/CD Pipeline / Type Check V3 (push) Failing after 1s
V3 CI/CD Pipeline / Smoke (no better-sqlite3) / ubuntu-latest / Node 24 (push) Failing after 1s
V3 CI/CD Pipeline / Smoke (no better-sqlite3) / ubuntu-latest / Node 22 (push) Failing after 2s
V3 CI/CD Pipeline / browser rvf create flag smoke (#2015) (push) Failing after 0s
V3 CI/CD Pipeline / Dependency review (#2046) (push) Has been skipped
V3 CI/CD Pipeline / Supply-chain audit (#2046) (push) Failing after 0s
V3 CI/CD Pipeline / witness marker drift smoke (#2021) (push) Failing after 1s
V3 CI/CD Pipeline / neural-trader portfolio CG smoke (#2068, ADR-126 Phase 3) (push) Failing after 1s
V3 CI/CD Pipeline / neural-trader backtest signing smoke (#2068, ADR-126 Phase 4) (push) Failing after 1s
V3 CI/CD Pipeline / kg-extract type-import classification smoke (#2049) (push) Failing after 0s
V3 CI/CD Pipeline / witness verify precondition smoke (#1880) (push) Failing after 2s
V3 CI/CD Pipeline / neural-trader pipeline risk-gate smoke (#2068, ADR-126 Phase 5) (push) Failing after 0s
V3 CI/CD Pipeline / neural-trader feature attribution smoke (#2068, ADR-126 Phase 6) (push) Failing after 0s
V3 CI/CD Pipeline / plugin-registry signature verification smoke (#1922, CWE-347) (push) Failing after 4s
V3 CI/CD Pipeline / memory stats legacy-DB smoke (#2120) (push) Failing after 4s
V3 CI/CD Pipeline / github deprecated actions smoke (#2089, ADR-127 Phase 3) (push) Failing after 1s
V3 CI/CD Pipeline / graph query + pathfinder smoke (ADR-130 P2+P5) (push) Has been skipped
V3 CI/CD Pipeline / graph trajectory hooks smoke (ADR-130 P3) (push) Has been skipped
V3 CI/CD Pipeline / graph plugin adapter smoke (ADR-130 P4) (push) Has been skipped
V3 CI/CD Pipeline / graph benchmark (ADR-130 P6) (push) Has been skipped
V3 CI/CD Pipeline / statusline generator delegation smoke (#2195) (push) Failing after 1s
V3 CI/CD Pipeline / wizard init regression guard (#2206 (push) Failing after 1s
V3 CI/CD Pipeline / memory no-stray-db smoke (ADR-125 P7) (push) Failing after 1s
V3 CI/CD Pipeline / github-safe injection smoke (#2089, ADR-127 Phase 1) (push) Failing after 1s
V3 CI/CD Pipeline / github actions pin smoke (#2089, ADR-127 Phase 1) (push) Failing after 1s
V3 CI/CD Pipeline / github attribution opt-in smoke (#2089, ADR-127 Phase 4) (push) Failing after 1s
V3 CI/CD Pipeline / pre-bash hook safety smoke (#2017) (push) Failing after 1s
V3 CI/CD Pipeline / Memory import smoke / ubuntu-latest (push) Failing after 0s
V3 CI/CD Pipeline / MCP protocol smoke / ubuntu-latest (push) Failing after 2s
V3 CI/CD Pipeline / ruvllm WASM auto-init smoke (#2086) (push) Failing after 4s
V3 CI/CD Pipeline / MCP paired-tool round-trip smoke (#1889) (push) Failing after 1s
V3 CI/CD Pipeline / Plugin package install-safety (#1902/#1903/#1904) (push) Failing after 1s
V3 CI/CD Pipeline / Tool description discoverability (ADR-112) (push) Failing after 3s
V3 CI/CD Pipeline / CLI npx-install smoke (#1147 / (22) (push) Failing after 1s
V3 CI/CD Pipeline / CLI npx-install smoke (#1147 / (24) (push) Failing after 1s
V3 CI/CD Pipeline / Windows hook shim smoke (#2132) / ubuntu-latest (push) Failing after 2s
V3 CI/CD Pipeline / Windows hook execution smoke (#2132) / ubuntu-latest (push) Failing after 1s
V3 CI/CD Pipeline / Windows init hooks smoke (#2132) / ubuntu-latest (push) Failing after 1s
V3 CI/CD Pipeline / Vector-index dimension audit (#1947) (push) Failing after 0s
V3 CI/CD Pipeline / Hook-command install safety (#1921) (push) Failing after 1s
V3 CI/CD Pipeline / ToolOutputGuardrail smoke (ADR-131, (push) Failing after 1s
V3 CI/CD Pipeline / init-bundle invariants smoke (#2095, ADR-128 Phase 5) (push) Failing after 1s
V3 CI/CD Pipeline / wasm provider bridge smoke (ADR-129 P1) (push) Failing after 2s
V3 CI/CD Pipeline / wasm gallery CRUD smoke (ADR-129 P3) (push) Failing after 1s
V3 CI/CD Pipeline / wasm plugin bridge smoke (ADR-129 P4) (push) Failing after 0s
V3 CI/CD Pipeline / wasm compose smoke (ADR-129 P2) (push) Failing after 4s
V3 CI/CD Pipeline / graph schema smoke (ADR-130 P1) (push) Failing after 0s
Validate Marketplace / validate (push) Failing after 1s
🔍 Verification Pipeline / 🚀 Setup Verification (push) Failing after 1s
🔍 Verification Pipeline / 🛡️ Security Verification (push) Has been skipped
🔍 Verification Pipeline / 📝 Code Quality (push) Has been skipped
🔍 Verification Pipeline / 🧪 Test Verification (${{ matrix.os }}, Node ${{ matrix.node }}) (push) Has been skipped
🔍 Verification Pipeline / 🏗️ Build Verification (push) Has been skipped
🔍 Verification Pipeline / 📚 Documentation Verification (push) Has been skipped
CVE Audit Gate / High-severity report (warn only) (push) Has been cancelled
🔄 Automated Rollback Manager / 🔄 Execute Rollback (push) Has been cancelled
🔄 Automated Rollback Manager / ✅ Post-Rollback Verification (push) Has been cancelled
🔄 Automated Rollback Manager / 📊 Rollback Monitoring (push) Has been cancelled
V3 CI/CD Pipeline / Windows init hooks smoke (#2132) / windows-latest (push) Has been cancelled
V3 CI/CD Pipeline / Windows hook execution smoke (#2132) / macos-latest (push) Has been cancelled
V3 CI/CD Pipeline / Windows hook execution smoke (#2132) / windows-latest (push) Has been cancelled
🔄 Automated Rollback Manager / ⏳ Manual Rollback Approval (push) Has been cancelled
V3 CI/CD Pipeline / MCP protocol smoke / macos-latest (push) Has been cancelled
V3 CI/CD Pipeline / Memory import smoke / macos-latest (push) Has been cancelled
V3 CI/CD Pipeline / Windows hook shim smoke (#2132) / macos-latest (push) Has been cancelled
V3 CI/CD Pipeline / Windows hook shim smoke (#2132) / windows-latest (push) Has been cancelled
V3 CI/CD Pipeline / Windows init hooks smoke (#2132) / macos-latest (push) Has been cancelled
V3 CI/CD Pipeline / Witness verify (signed manifest) / macos-latest (push) Has been cancelled
V3 CI/CD Pipeline / Witness verify (signed manifest) / ubuntu-latest (push) Has been cancelled
V3 CI/CD Pipeline / Witness verify (signed manifest) / windows-latest (push) Has been cancelled
V3 CI/CD Pipeline / Publish to npm (alpha) (push) Has been cancelled
V3 CI/CD Pipeline / Smoke (no better-sqlite3) / macos-latest / Node 22 (push) Has been cancelled
V3 CI/CD Pipeline / Plugin hooks smoke / macos-latest / Node 22 (push) Has been cancelled
CI/CD Pipeline / Deploy & Release (push) Has been cancelled
CI/CD Pipeline / CI Status (push) Has been cancelled
🔗 Cross-Agent Integration Tests / 📊 Integration Test Report (push) Has been cancelled
🔄 Automated Rollback Manager / 🔍 Pre-Rollback Validation (push) Has been cancelled
🔍 Verification Pipeline / ⚡ Performance Verification (push) Has been cancelled
🔍 Verification Pipeline / 📊 Verification Report (push) Has been cancelled
205 lines
8.7 KiB
JavaScript
205 lines
8.7 KiB
JavaScript
#!/usr/bin/env node
|
||
/**
|
||
* Performance verification — benchmark key user-visible capabilities and
|
||
* append per-OS measurements to verification/<os>/performance.jsonl.
|
||
*
|
||
* Each entry is one capability×measurement at a single git commit. The
|
||
* file is JSONL so a regression in install-time or CLI-startup gets
|
||
* caught the same way `verify.mjs` catches a marker disappearing — by
|
||
* comparing to the running baseline (median of last N) and flagging
|
||
* deltas that exceed a threshold.
|
||
*
|
||
* Capabilities tracked
|
||
* ────────────────────
|
||
* install_pack how long `pnpm pack @claude-flow/memory` takes
|
||
* install_no_optional how long `npm install <tarball> --omit=optional` takes
|
||
* memory_load how long `import('@claude-flow/memory')` takes
|
||
* memory_round_trip store + get on the auto-selected backend
|
||
* witness_verify how long `verify.mjs --manifest` takes
|
||
*
|
||
* Each measurement records:
|
||
* { v, commit, issuedAt, os, capability, durationMs, metadata }
|
||
*
|
||
* Usage:
|
||
* node plugins/ruflo-core/scripts/witness/perf.mjs \
|
||
* --output verification/<os>/performance.jsonl
|
||
*
|
||
* --capabilities install_pack,memory_load # subset
|
||
* --baseline # compare against last 5 entries
|
||
* --json # machine-readable output
|
||
*/
|
||
|
||
import { writeFileSync, appendFileSync, readFileSync, existsSync, mkdtempSync, rmSync } from 'node:fs';
|
||
import { join, resolve, dirname } from 'node:path';
|
||
import { tmpdir } from 'node:os';
|
||
import { execFileSync, spawnSync } from 'node:child_process';
|
||
import { fileURLToPath } from 'node:url';
|
||
import { osDir } from './lib.mjs';
|
||
|
||
const __dirname = dirname(fileURLToPath(import.meta.url));
|
||
|
||
const args = parseArgs(process.argv.slice(2));
|
||
if (args.help) {
|
||
console.log(readFileSync(new URL(import.meta.url), 'utf8').split('\n').filter(l => l.startsWith(' *')).map(l => l.slice(3)).join('\n'));
|
||
process.exit(0);
|
||
}
|
||
|
||
const REPO_ROOT = resolve(args.root ?? process.cwd());
|
||
const OUTPUT = args.output ? resolve(args.output) : join(REPO_ROOT, 'verification', osDir(), 'performance.jsonl');
|
||
const ASJSON = !!args.json;
|
||
const COMPARE_BASELINE = !!args.baseline;
|
||
const ENABLED = (args.capabilities ?? 'install_pack,install_no_optional,memory_load,memory_round_trip,witness_verify').split(',').map(s => s.trim()).filter(Boolean);
|
||
|
||
const gitCommit = execFileSync('git', ['rev-parse', 'HEAD'], { cwd: REPO_ROOT }).toString().trim();
|
||
const issuedAt = new Date().toISOString();
|
||
const os = osDir();
|
||
|
||
// ─── benchmark runners ─────────────────────────────────────────
|
||
const runners = {
|
||
install_pack: () => bench(() => {
|
||
// execFileSync with array args prevents shell injection (CWE-78).
|
||
execFileSync('pnpm', ['pack', '--pack-destination', tmpdir()], {
|
||
cwd: join(REPO_ROOT, 'v3/@claude-flow/memory'),
|
||
stdio: 'pipe',
|
||
});
|
||
}),
|
||
|
||
install_no_optional: () => {
|
||
const dir = mkdtempSync(join(tmpdir(), 'perf-install-'));
|
||
const tarball = execFileSync('pnpm', ['pack', '--pack-destination', dir], {
|
||
cwd: join(REPO_ROOT, 'v3/@claude-flow/memory'),
|
||
stdio: 'pipe',
|
||
}).toString().trim().split('\n').filter(l => l.endsWith('.tgz')).pop();
|
||
if (!tarball) throw new Error('pnpm pack produced no tarball');
|
||
execFileSync('npm', ['init', '-y'], { cwd: dir, stdio: 'pipe' });
|
||
execFileSync('npm', ['pkg', 'set', 'type=module'], { cwd: dir, stdio: 'pipe' });
|
||
const ms = bench(() => {
|
||
// Pass tarball path as a discrete argument — no shell quoting needed.
|
||
execFileSync('npm', ['install', tarball, '--omit=optional', '--no-audit', '--no-fund'], { cwd: dir, stdio: 'pipe' });
|
||
});
|
||
rmSync(dir, { recursive: true, force: true });
|
||
return ms;
|
||
},
|
||
|
||
memory_load: () => {
|
||
return bench(() => {
|
||
// Spawn a fresh node process so import is truly cold.
|
||
spawnSync(process.execPath, ['-e', "import('@claude-flow/memory').then(()=>{}).catch(e=>{process.exit(1)})"], {
|
||
cwd: REPO_ROOT,
|
||
stdio: 'pipe',
|
||
});
|
||
});
|
||
},
|
||
|
||
memory_round_trip: () => {
|
||
const dbPath = join(tmpdir(), `perf-mem-${Date.now()}.db`);
|
||
const ms = bench(() => {
|
||
const r = spawnSync(process.execPath, ['-e', `
|
||
const m = await import('@claude-flow/memory');
|
||
const db = await m.createDatabase('${dbPath}', { provider: 'auto' });
|
||
await db.initialize();
|
||
const ts = Date.now();
|
||
await db.store({ id: 'p1', key: 'k', content: 'v', type: 'episodic', namespace: 'd',
|
||
tags: [], metadata: {}, accessLevel: 'private',
|
||
createdAt: ts, updatedAt: ts, version: 1, references: [], accessCount: 0, lastAccessedAt: ts });
|
||
await db.get('p1');
|
||
await db.shutdown?.();
|
||
`], { cwd: REPO_ROOT, stdio: 'pipe' });
|
||
if (r.status !== 0) throw new Error('memory_round_trip failed: ' + r.stderr?.toString());
|
||
});
|
||
try { rmSync(dbPath, { force: true }); } catch { /* */ }
|
||
return ms;
|
||
},
|
||
|
||
witness_verify: () => {
|
||
const manifest = join(REPO_ROOT, 'verification', os, 'manifest.md.json');
|
||
if (!existsSync(manifest)) return null;
|
||
return bench(() => {
|
||
// Use execFileSync so paths with spaces or special chars are safe (CWE-78).
|
||
execFileSync(process.execPath, [join(__dirname, 'verify.mjs'), '--manifest', manifest, '--json'], {
|
||
cwd: REPO_ROOT, stdio: 'pipe',
|
||
});
|
||
});
|
||
},
|
||
};
|
||
|
||
// ─── bench helper ───────────────────────────────────────────────
|
||
function bench(fn) {
|
||
const start = process.hrtime.bigint();
|
||
try { fn(); } catch (e) {
|
||
return { error: e.message ?? String(e), durationMs: null };
|
||
}
|
||
const ms = Number((process.hrtime.bigint() - start) / 1_000_000n);
|
||
return { durationMs: ms };
|
||
}
|
||
|
||
// ─── baseline comparison ────────────────────────────────────────
|
||
function loadBaseline(capability) {
|
||
if (!existsSync(OUTPUT)) return null;
|
||
const lines = readFileSync(OUTPUT, 'utf8').split('\n').filter(Boolean);
|
||
const recent = lines.map(l => JSON.parse(l)).filter(e => e.capability === capability && e.durationMs != null).slice(-5);
|
||
if (recent.length < 3) return null;
|
||
const sorted = [...recent].sort((a, b) => a.durationMs - b.durationMs);
|
||
return sorted[Math.floor(sorted.length / 2)].durationMs; // median
|
||
}
|
||
|
||
// ─── run ─────────────────────────────────────────────────────────
|
||
const results = [];
|
||
for (const cap of ENABLED) {
|
||
if (!runners[cap]) {
|
||
if (!ASJSON) console.error(`unknown capability: ${cap}`);
|
||
continue;
|
||
}
|
||
if (!ASJSON) console.error(`benchmarking: ${cap}`);
|
||
const r = runners[cap]();
|
||
if (r === null) continue; // skipped
|
||
const baseline = COMPARE_BASELINE ? loadBaseline(cap) : null;
|
||
const entry = {
|
||
v: 1,
|
||
commit: gitCommit,
|
||
issuedAt,
|
||
os,
|
||
capability: cap,
|
||
...r,
|
||
...(baseline != null && r.durationMs != null
|
||
? { baselineMs: baseline, deltaPct: Math.round(((r.durationMs - baseline) / baseline) * 100) }
|
||
: {}),
|
||
};
|
||
results.push(entry);
|
||
appendFileSync(OUTPUT, JSON.stringify(entry) + '\n');
|
||
}
|
||
|
||
// ─── report ─────────────────────────────────────────────────────
|
||
if (ASJSON) {
|
||
console.log(JSON.stringify({ commit: gitCommit, os, results }, null, 2));
|
||
} else {
|
||
console.log(`\nperf summary (commit=${gitCommit.slice(0, 12)}, os=${os})`);
|
||
console.log('─'.repeat(60));
|
||
for (const r of results) {
|
||
const dur = r.durationMs != null ? `${r.durationMs}ms`.padStart(10) : 'error'.padStart(10);
|
||
const delta = r.deltaPct != null ? ` (${r.deltaPct >= 0 ? '+' : ''}${r.deltaPct}% vs baseline)` : '';
|
||
const err = r.error ? ` ERROR: ${r.error}` : '';
|
||
console.log(` ${r.capability.padEnd(22)} ${dur}${delta}${err}`);
|
||
}
|
||
console.log(`\nappended: ${OUTPUT}`);
|
||
}
|
||
|
||
const failed = results.filter(r => r.error);
|
||
process.exit(failed.length > 0 ? 1 : 0);
|
||
|
||
// ─── arg parser ─────────────────────────────────────────────────
|
||
function parseArgs(argv) {
|
||
const out = {};
|
||
for (let i = 0; i < argv.length; i++) {
|
||
const a = argv[i];
|
||
if (a === '--baseline' || a === '--json' || a === '--help') { out[a.slice(2)] = true; continue; }
|
||
if (a.startsWith('--')) {
|
||
const key = a.slice(2);
|
||
const next = argv[i + 1];
|
||
if (next && !next.startsWith('--')) { out[key] = next; i++; }
|
||
else { out[key] = true; }
|
||
}
|
||
}
|
||
return out;
|
||
}
|