fix(pit): stop /pit rendering the entire namespace at once - #167
Merged
Conversation
The page locks browsers up and there is no script on it to blame. It drew every ending the account holds, and under each one a form per name — CSRF field, two inputs, two buttons — with no limit on either end. This registry already holds 200 endings under one account. Measured at 50 endings x 100 names: 3.1 MiB of HTML and 36,082 elements. Nothing has to be slow for that to jam; it is the DOM, and the sticky blurred app bar repaints over all of it on every scroll frame. Same data now renders 173 KiB and 1,926 elements — 20 endings a page, 10 names each, with the totals stated so a window is never mistaken for the whole. `?tld=` opens one ending in full, which is where the "show all N" links go, and where TronBrowser's mosh.<tld> console link already pointed at a page that ignored the parameter and drew everything anyway. Paging orders by `created_at DESC, tld` rather than `created_at` alone. A bulk claim writes one timestamp across every ending in it, so the old sort was not a total order: a page boundary inside a tie would repeat one ending and lose another. Covered by a test that ties every timestamp on purpose. Only the endings on screen are queried now — this used to run one listNames per ending held, regardless of what it was about to render. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
vu1nz Security Review0 finding(s) in PR #? No security issues found. |
ralyodio
marked this pull request as ready for review
August 1, 2026 02:32
Merged
ralyodio
added a commit
that referenced
this pull request
Aug 1, 2026
install.sh resolves releases/latest, so the sixteen commits merged since v0.13.3 have been sitting on main unreachable — including a fix for a page that locks browsers up. The headline is the pit. /pit rendered every ending an account held and a form per name under each, with no bound on either: at 50 endings x 100 names that was 3.1 MiB of HTML and 36,082 DOM elements, and it managed to jam a browser with no script on the page at all (#167). It now draws a window and says what it is not drawing — 173 KiB, 1,926 elements — with a filter box over the top that takes `eggs` as a substring and `def*` as a glob, debounced against the API (#168). The namespace also stopped being the one part of the product a script could not touch: /api/moshpit/* now accepts the same API key /api/me and /api/sessions already did (#169), and /pit/dns finally documents the TronBrowser route for machines whose DNS is not theirs to change (#165). moshcode: foreign keys are enforced, and the licence package.json claims actually ships (#154) cli: help aliases exit 0 (#157), invalid integration commands fail (#160), `--` is honoured (#159), a BOM before a shebang no longer breaks (#158) skills: engines with no skills primitive are reported, not dropped (#166); `--name` requires a value (#156) mcp: an unsupported flag is rejected rather than registered as the server name (#164) pit: the namespace rules are vendored again with a drift test holding them to the published package (#161, #162, #163) Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
/pitlags and locks up the browser. There is no JavaScript on the page to blame — the only script it ships is the service-worker registration. It's the DOM.What was happening
The page rendered every ending the account holds, and under each one a
<form>per name (CSRF field, two inputs, two buttons), with no limit at either end. This registry already holds 200 endings under a single account.Measured against a seeded 50 endings × 100 names:
<form>Nothing has to be slow for that to jam — and the sticky
backdrop-filter: blur(10px)app bar repaints over the whole thing on every scroll frame, which is the part that feels like a lockup.What changed
10 of 100 shown,page 1 of 3 · 50 endings) so a window is never mistaken for the whole list. Silent truncation reads as data loss.?tld=opens one ending in full — where the "show all N" links go, and where TronBrowser'smosh.<tld>console link already pointed, at a page that ignored the parameter and drew everything anyway. Guarded so it can't focus an ending another account holds.listNamesper ending held, whatever it was about to render.ORDER BY created_at DESC, tldinstead ofcreated_atalone: a bulk claim writes one timestamp across every ending in it, so the old sort wasn't a total order and a page boundary inside a tie would repeat one ending and drop another.Testing
apps/pwa/test/moshpit-pit-page.test.mjs— 6 tests: page stays bounded at 5,000 names, totals are stated, paging covers every ending exactly once with every timestamp deliberately tied,?tld=focus works and can't be used to read someone else's ending, and an unreadable?page=lands on page 1.apps/pwa: 307 pass, 0 fail. Repo root: 714 pass, 0 fail, 2 skipped.🤖 Generated with Claude Code