perf(quartz): skip the resolver's second pass when it cannot change anything

The two-pass ban-aware fold doubles resolve(), which runs once per held epoch in
controlFloorsLocked plus once in fold, on a client that re-folds the whole buffer
from scratch on every Control Plane change. So the second pass is now skipped
unless a banned member actually authored a Control edition — not merely when the
banlist is empty. Bans overwhelmingly land on plain members who hold no role and
write nothing, and for those pass B is provably identical to pass A. Armada's
fold checks the same condition.

Measured over ConcordCommunityState.fold (throwaway benchmark, not committed;
226 and 2059 editions, 200 reps after warmup). Pass A is byte-for-byte the old
algorithm, so the single-pass rows are the before-numbers:

  226 eds, no bans                          1457 us
  226 eds, 20 bans, none authored            994 us
  226 eds, 20 bans, one authored -> pass B  1881 us
  2059 eds, no bans                         2194 us
  2059 eds, 50 bans, none authored          2001 us
  2059 eds, 50 bans, one authored -> pass B 5697 us
  2059 eds, with floors (B1's arm)          2015 us

So the common case is free, and B1's chain-first compaction arm is not
measurable — the floored fold matches the unfloored one. A banned staffer costs
~2-3x, which is the price of the fix and is paid only under the attack.

The audit records this, plus the standing opportunity it surfaced: we have no
fold memoization where Armada does, which predates this work and would absorb
the pass-B cost too. Not done here — that is a change to make on its own merits.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DrJhpFhhLjuDJQNkGvYMGj
This commit is contained in:
Claude
2026-08-09 16:09:53 +00:00
parent 6147f72c81
commit 54d3bfc84a
2 changed files with 45 additions and 0 deletions
+40
View File
@@ -502,6 +502,46 @@ bans they drop. Worth a spec question about which is normative.
could not locate the recipient-set construction itself with confidence, so treat this as unchecked
rather than as a finding either way.
---
## Performance of the fixes
Measured on the JVM with a synthetic Control Plane (throwaway benchmark, not committed —
`ConcordCommunityState.fold` over 226 and 2059 editions, 200 reps after warmup). Pass A of the
two-pass resolver is byte-for-byte the old algorithm, so the single-pass rows below *are* the
before-numbers.
| Case | µs / fold |
|---|---|
| 226 editions, no bans | 1457 |
| 226 editions, 20 bans, none of them authors | 994 |
| 226 editions, 20 bans, one an author → pass B runs | 1881 |
| 2059 editions, no bans | 2194 |
| 2059 editions, 50 bans, none of them authors | 2001 |
| 2059 editions, 50 bans, one an author → pass B runs | 5697 |
| 2059 editions, with floors (B1's compaction arm) | 2015 |
Two things to take from it.
**B1 costs nothing measurable.** Trying the floor-anchored chain before the raw-version bootstrap
adds a per-entity version index on the compaction arm, but an entity carries a handful of editions,
and the floored fold measures the same as the unfloored one.
**B2 costs a second fold, but only when it can change the answer.** `resolve` skips pass B when
nobody is banned *or* when nobody banned ever authored a Control edition — the overwhelmingly common
shape, since bans land on plain members who hold no role and write nothing. Those rows show no
regression. When a banned member *did* author editions — a banned staffer, exactly the case B2 exists
for — the fold costs ~2–3× more. That is the price of the fix and it is paid only by communities
under the attack.
**Worth knowing, unrelated to this work:** Amethyst re-folds the whole buffer from scratch on every
Control Plane change, and `resolve` runs once per held epoch inside `controlFloorsLocked` plus once
in `fold`, so a refresh is already several folds. Armada memoizes the fold by
`(community, owner, floors, snapshot, edition ids)`; we do not. That is the real optimization here,
it predates these fixes, and it would also absorb the pass-B cost. Left alone deliberately — it is a
change to make on its own merits, with its own measurements.
---
## What was NOT examined
@@ -170,7 +170,12 @@ data class AuthorityResolver private constructor(
ownerPubKey: String,
): AuthorityResolver {
val passA = resolveOnce(editions, ownerPubKey, bannedAuthors = emptySet())
// Pass B costs a whole second fold, so skip it unless it could change something. Nobody
// banned, or nobody banned who ever wrote to the Control Plane — the overwhelmingly common
// shape, since most bans land on plain members who hold no role and author no editions —
// and pass B is provably identical to pass A. This is also what Armada's fold checks.
if (passA.banned.isEmpty()) return passA
if (editions.none { it.author.lowercase() in passA.banned }) return passA
return resolveOnce(editions, ownerPubKey, bannedAuthors = passA.banned)
}