@@ -28,13 +28,15 @@ import {AuthorityJournalScan} from "./authority_journal_scan.ts";
2828
2929const STORE_IDENTITY_PATTERN = / ^ f i l e : [ 0 - 9 a - f ] { 32 } $ / ;
3030// File retains a checkpoint/delta journal in one durable envelope. A managed Effect server
31- // opens a new store handle for each request. Keep one verified read view across
32- // handles, keyed by exact bytes and store identity. Large journals retain only
31+ // opens a new store handle for each request. Retain a bounded working set across
32+ // handles so alternating Goals do not evict each other on every observation.
33+ // Every lookup still reads and hashes the full file and checks store identity. Large journals retain only
3334// the head and receipt index in memory; commits and scans still load and verify
3435// the complete history. This is a bounded read optimization, not a new source
3536// of authority or a substitute for the SQLite long-goal profile.
3637const MAX_CACHED_DOCUMENT_BYTES = 128 * 1024 * 1024 ;
3738const MAX_CACHED_READ_VIEW_BYTES = 16 * 1024 * 1024 ;
39+ const MAX_CACHED_STORES = 4 ;
3840interface VerifiedDocument {
3941 path : string ;
4042 identity : string ;
@@ -49,7 +51,7 @@ interface VerifiedDocument {
4951 } > ;
5052 document ?: FileAuthorityJournal ;
5153}
52- let verifiedDocument : VerifiedDocument | null = null ;
54+ const verifiedDocuments = new Map < string , { view : VerifiedDocument ; bytes : number } > ( ) ;
5355// Only identical immutable input bytes share in-flight verification. Failed
5456// proofs are removed too; neither a path nor a pending promise grants authority.
5557const pendingVerification = new Map < string , Promise < FileAuthorityJournal > > ( ) ;
@@ -76,10 +78,22 @@ function rememberVerifiedDocument(path: string, identity: string, raw: Uint8Arra
7678 const view : VerifiedDocument = { path, identity, digest, head : document . head ,
7779 providerRevision : document . provider_revision , cursor : document . cursor ,
7880 receipts, document} ;
79- verifiedDocument = raw . byteLength <= maxDocumentBytes ? view
80- : viewBytes <= MAX_CACHED_READ_VIEW_BYTES
81- ? { ...view , document : undefined }
82- : null ;
81+ // Account for serialized history and the separate head/receipt index. This
82+ // is a retained-byte bound, not a claim about the JS heap or process RSS.
83+ const fullBytes = raw . byteLength + viewBytes ;
84+ const retainHistory = raw . byteLength <= maxDocumentBytes && fullBytes <= MAX_CACHED_DOCUMENT_BYTES ;
85+ const retained = retainHistory ? view : { ...view , document : undefined } ;
86+ const bytes = retainHistory ? fullBytes : viewBytes ;
87+ verifiedDocuments . delete ( path ) ;
88+ if ( retainHistory || viewBytes <= MAX_CACHED_READ_VIEW_BYTES ) {
89+ verifiedDocuments . set ( path , { view : retained , bytes} ) ;
90+ let total = [ ...verifiedDocuments . values ( ) ] . reduce ( ( sum , entry ) => sum + entry . bytes , 0 ) ;
91+ while ( verifiedDocuments . size > MAX_CACHED_STORES || total > MAX_CACHED_DOCUMENT_BYTES ) {
92+ const oldest = verifiedDocuments . keys ( ) . next ( ) . value ! ;
93+ total -= verifiedDocuments . get ( oldest ) ! . bytes ;
94+ verifiedDocuments . delete ( oldest ) ;
95+ }
96+ }
8397 return view ;
8498}
8599
@@ -274,10 +288,12 @@ export class FileAuthorityStore implements AuthorityStore {
274288 const identity = knownIdentity ?? await this . readStoreIdentity ( ) ;
275289 try {
276290 const digest = documentDigest ( raw ) ;
277- if ( verifiedDocument ?. path === this . path &&
278- verifiedDocument . identity === identity && verifiedDocument . digest === digest &&
279- ( ! requireHistory || verifiedDocument . document !== undefined ) ) {
280- return verifiedDocument ;
291+ const cached = verifiedDocuments . get ( this . path ) ;
292+ if ( cached ?. view . identity === identity && cached . view . digest === digest &&
293+ ( ! requireHistory || cached . view . document !== undefined ) ) {
294+ verifiedDocuments . delete ( this . path ) ;
295+ verifiedDocuments . set ( this . path , cached ) ;
296+ return cached . view ;
281297 }
282298 const key = JSON . stringify ( [ this . path , identity , digest ] ) ;
283299 let proof = pendingVerification . get ( key ) ;
@@ -420,7 +436,7 @@ export class FileAuthorityStore implements AuthorityStore {
420436 // A failure after rename may already have published the new bytes.
421437 // The next read must prove the actual file rather than reuse either
422438 // the previous or attempted document.
423- verifiedDocument = null ;
439+ verifiedDocuments . delete ( this . path ) ;
424440 return {
425441 status : "ambiguous" ,
426442 reason_code : "commit_outcome_unknown" ,
0 commit comments