Deferred from #967 (2026-08-13 scenario review, option B).
The v1 PGO training matrix drives the gateway against a plaintext local mock, so the TLS client paths (handshake, record encrypt/decrypt on every upstream byte) stay untrained and are laid out as cold code. Production upstreams are HTTPS, making this the largest known divergence between the training profile and real traffic.
What v2 needs:
Rejected for v1 because the trainer would lose its zero-dependency property and the benefit cannot be measured on current rigs.
Deferred from #967 (2026-08-13 scenario review, option B).
The v1 PGO training matrix drives the gateway against a plaintext local mock, so the TLS client paths (handshake, record encrypt/decrypt on every upstream byte) stay untrained and are laid out as cold code. Production upstreams are HTTPS, making this the largest known divergence between the training profile and real traffic.
What v2 needs:
Rejected for v1 because the trainer would lose its zero-dependency property and the benefit cannot be measured on current rigs.