Skip to content

test(benchmarks): canonical baseline and CI bench gate#206

Merged
NathanFlurry merged 1 commit into
mainfrom
stack/test-benchmarks-canonical-baseline-and-ci-bench-gate-yxkpzryl
Jul 2, 2026
Merged

test(benchmarks): canonical baseline and CI bench gate#206
NathanFlurry merged 1 commit into
mainfrom
stack/test-benchmarks-canonical-baseline-and-ci-bench-gate-yxkpzryl

Conversation

@NathanFlurry

Copy link
Copy Markdown
Member

Wins must not silently regress:

  • Canonical baseline (results/baseline-local.json, committed): full 70-row
    matrix from a RELEASE sidecar with hardware, binary provenance, and engine
    defaults embedded; regeneration procedure documented.
  • bench:gate: 12 deterministic rows across fs/net/modules/wasm/command tiers,
    relative threshold (fail > 2.0x) with a sub-ms noise floor (baseline <0.3ms
    ignored until current >= 1ms); REFUSES debug binaries (exit 2). Verified to
    bite: a deliberate slowdown in fs_write_big failed at 3.57x and passed after
    revert.
  • .github/workflows/bench.yml: PR quick-gate using the filtered install
    (pnpm --filter '@secure-exec/benchmarks...' works without the gitignored
    website vendor dir, so the gate is independent of the broken root install)
    • release builds; nightly full matrix uploading results. CI baselines
      bootstrap per-environment: nightly produces a baseline-ci.json candidate, a
      human commits it, then PRs are gated on runner-native numbers.

Wins must not silently regress:

- Canonical baseline (results/baseline-local.json, committed): full 70-row
  matrix from a RELEASE sidecar with hardware, binary provenance, and engine
  defaults embedded; regeneration procedure documented.
- bench:gate: 12 deterministic rows across fs/net/modules/wasm/command tiers,
  relative threshold (fail > 2.0x) with a sub-ms noise floor (baseline <0.3ms
  ignored until current >= 1ms); REFUSES debug binaries (exit 2). Verified to
  bite: a deliberate slowdown in fs_write_big failed at 3.57x and passed after
  revert.
- .github/workflows/bench.yml: PR quick-gate using the filtered install
  (pnpm --filter '@secure-exec/benchmarks...' works without the gitignored
  website vendor dir, so the gate is independent of the broken root install)
  + release builds; nightly full matrix uploading results. CI baselines
  bootstrap per-environment: nightly produces a baseline-ci.json candidate, a
  human commits it, then PRs are gated on runner-native numbers.
@NathanFlurry

Copy link
Copy Markdown
Member Author

Stack for rivet-dev/secure-exec

Get stack: forklift get 206
Push local edits: forklift submit
Merge when ready: forklift merge 206

@railway-app
railway-app Bot temporarily deployed to secure-exec / secure-exec-pr-206 July 2, 2026 13:58 Destroyed
@NathanFlurry
NathanFlurry merged commit e56b2d8 into main Jul 2, 2026
0 of 3 checks passed
@NathanFlurry
NathanFlurry deleted the stack/test-benchmarks-canonical-baseline-and-ci-bench-gate-yxkpzryl branch July 2, 2026 13:58
@railway-app
railway-app Bot temporarily deployed to secure-exec / preview July 2, 2026 13:58 Inactive
@railway-app
railway-app Bot temporarily deployed to secure-exec / production July 2, 2026 13:58 Inactive
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant