github / github/copilot-sdk

Rust bundled runtime installation retains large native-image buffers on cold and warm startup

Open
#2,675 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
Java
Stars
10.5k
Forks
1.5k
Avg merge
1d 11h
Merged PRs (30d)
127

Description

## Description

The Rust SDK's `install_bundled_runtime()` path allocates complete runtime archive entries and reads installed files into full-size buffers. `install_hostless_assets` handles `runtime.node`, then `install_runtime_pair` extracts and compares it again. On macOS, those allocations can leave substantial physical memory retained by the allocator even after the installer returns, including when every installed file is already valid.

This is an installer-only reproduction, not evidence of a live-object leak or a measurement of a client/model session. No authentication, CLI subprocess or service request is needed.

## Reproduction

At SDK revision `a675b55531a9dfc647ee015e32d74279568550f3`, build a release Rust executable with default `bundled-cli` features which calls `github_copilot_sdk::install_bundled_runtime()` once and stays alive for one second afterward. Run the executable with a fresh isolated `HOME`. For the warm case, first seed that same home's SDK cache using a separate process, then run the measured executable in a new process. Do not reuse the same process, because its `OnceLock` bypasses installation.

Measure process-lifetime peak RSS/physical footprint with macOS `/usr/bin/time -l`, and current RSS/physical footprint using `proc_pid_rusage(RUSAGE_INFO_V0)` after the one-second idle period. Keep allocation-stack logging disabled in these measurements.

## Observed SDK-only baseline

Apple M4 Pro, 48 GiB RAM, macOS 26.6.2 (25G83), arm64; rustc 1.94.0; release optimization level 3, debug level 1. Public bundled runtime `1.0.84-8`. Five independent processes per cohort; medians (minimum-maximum):

| Cohort | Retained physical footprint, MiB | Installer seconds |
| --- | --- | --- |
| Cold installation | 155.438 (154.563-156.047) | 0.880 (0.863-1.037) |
| Valid warm installation | 174.360 (172.735-174.907) | 1.031 (0.997-1.092) |

The installed `runtime.node` is 71,166,736 bytes, SHA-256 `839cd681c72cb92f27697d5e3e3ee96d7bb8df4234ffb5f7b442956828ec173a`. Filtered embedded runtime archive SHA-256: `6c43b789080fc06b25d406af8fae709daa99f0724c4d290cc8a31160c5a3ad64`.

A separate instrumented warm process recorded two page-rounded 71,172,096-byte VM allocations through the SDK runtime installer, one also through `std::fs::read`; after installation, `vmmap` reported 165.7 MiB in `MALLOC_LARGE (empty)` regions. Instrumented values are excluded from the comparison above.

## Expected behavior

Runtime extraction and existing-file verification should use bounded buffers, preserve exact output bytes/modes, permit valid read-only warm caches, and repair corrupt files with staged atomic replacement. The full CLI installer is a separate path and outside the memory optimization scope.

A focused fix with runnable reproduction and cold/warm/corrupt/truncated measurements is prepared.

Contributor guide

Open the contributing guide

Research direction

Start at the Rust SDK entry point install_bundled_runtime(), then trace install_hostless_assets and install_runtime_pair handling runtime.node. Run the isolated cold and seeded warm reproductions described in the issue, including corrupt and truncated files. Done means bounded extraction and verification preserve bytes and modes, valid read-only caches remain usable, corrupt files are atomically repaired, and measurements cover cold, warm, and repair cases.

Written by the indexing model from the issue text.

Assessment

Tech stack
node.js, rust
Domain
performance, tooling
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Active
Clarity
Mostly clear
Newbie friendliness
55/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.