Offline First · Open source · This offline-first-opensource bug hid for three years before anyone reported it

350
OFr/offline-first-opensource·posted by huang_ke·6 hours agoTooling

This offline-first-opensource bug hid for three years before anyone reported it

It took me two weeks of on-and-off digging and plenty of wrong turns. Writing the process down as it happened so the next person spends less time.

The first thing was to collapse the variables. We were changing config and upgrading the version at the same time, and afterwards nobody could say which change caused what. We rolled back to moving one variable at a time, re-ran three times, and only then did the curve settle. Tedious, but not skippable.

Keep it and wait for an official fix44%
Switch to a third-party option now28%
Fork and maintain it ourselves17%
Write an adapter layer and wait11%

595 votes total

195 comments

195 comments

· first 120 loaded
M
Wwinter·2 days ago

One counter-example: below offline-first-opensource 7.4 the semantics of that code are different, so do not copy it verbatim. We got burned in staging and rolled back once.

501
RraseOP·2 days ago

Agreeing with the above. One addition: with this option enabled the GC count in your metrics doubles, so adjust the alert threshold at the same time or it will keep firing.

430
Mmike_xuMod·2 days ago

Sharing our numbers, 8 cores 16GB, same scenario:

| Concurrency | P50 | P99 |
|---|---|---|
| 200 | 12ms | 88ms |
| 500 | 31ms | 340ms |

P99 clearly collapses at 500 concurrency, which lines up with your knee point.

486
Sswoole_lee·2 days ago

Saved. I am reworking this area this week — this saves a lot of wrong turns.

476
Kkite·2 days agoedited

We have run this in production for two years without hitting it. That said, we never reached this scale, so our experience is not really evidence here.

466
Mmike_xu·2 days ago

This is not a offline-first-opensource problem, it is a usage problem. The docs say this API is not thread-safe and you must lock around it yourself.

423
Sslow_queryOP·yesterday

Can you give a minimal reproduction? I ran it locally for ten minutes and could not reproduce on macOS with the latest version.

326
Ddev_zhou·12 minutes ago

Worth learning from this debugging approach. We went straight at the logs and took a much longer route.

185
Hhuang_ke·5 hours agoedited

One counter-example: below offline-first-opensource 7.4 the semantics of that code are different, so do not copy it verbatim. We got burned in staging and rolled back once.

385
Hhuang_ke·2 days ago

This matches what we see in production. We only hit it past 3k QPS; the earlier load tests showed nothing — the test traffic was too clean, with no long-tail requests.

359
Hhuang_ke·2 days ago

Has anyone run a controlled experiment? I did, reducing it to a single variable, and the difference was 4% — within noise. So I suspect the main cause is something else.

356
Kkernel_panic·2 days ago

Saved. I am reworking this area this week — this saves a lot of wrong turns.

338
Lli_ming·2 days ago

This matches what we see in production. We only hit it past 3k QPS; the earlier load tests showed nothing — the test traffic was too clean, with no long-tail requests.

300
Mmike_xu·3 minutes ago

Can you give a minimal reproduction? I ran it locally for ten minutes and could not reproduce on macOS with the latest version.

250
Ddev_zhou·2 hours ago

A question: what changes in a container with a 512Mi memory limit? That is how we run it in production.

447
Aalice_dev·2 hours ago

This matches what we see in production. We only hit it past 3k QPS; the earlier load tests showed nothing — the test traffic was too clean, with no long-tail requests.

378
Zzhou_yiOP·1 hour ago

Worth learning from this debugging approach. We went straight at the logs and took a much longer route.

435
Wwinter·2 days ago

Can you give a minimal reproduction? I ran it locally for ten minutes and could not reproduce on macOS with the latest version.

176
Ttang_hao·1 hour ago

Saved. I am reworking this area this week — this saves a lot of wrong turns.

151
Aalice_dev·2 days ago

A question: what changes in a container with a 512Mi memory limit? That is how we run it in production.

378
Aalice_devOP·2 days agoLevel 6

Can you give a minimal reproduction? I ran it locally for ten minutes and could not reproduce on macOS with the latest version.

348
Aalice_dev·2 days agoLevel 6

There is actually a simpler fix that needs no architecture change: move this check up to the gateway and the problem disappears. The cost is one extra lookup at the gateway.

2
Ttang_hao·2 days ago

This matches what we see in production. We only hit it past 3k QPS; the earlier load tests showed nothing — the test traffic was too clean, with no long-tail requests.

61
Zzhu_zong·2 days agoLevel 6

Worth learning from this debugging approach. We went straight at the logs and took a much longer route.

461
Kkite·2 days agoLevel 6

Agreeing with the above. One addition: with this option enabled the GC count in your metrics doubles, so adjust the alert threshold at the same time or it will keep firing.

74
Zzhou_yi·12 minutes ago

We have run this in production for two years without hitting it. That said, we never reached this scale, so our experience is not really evidence here.

274
Oops_wangOP·2 hours ago

One counter-example: below offline-first-opensource 7.4 the semantics of that code are different, so do not copy it verbatim. We got burned in staging and rolled back once.

497
Ddev_zhou·2 days ago

There is actually a simpler fix that needs no architecture change: move this check up to the gateway and the problem disappears. The cost is one extra lookup at the gateway.

6
Hhuang_ke·2 days agoLevel 6

We have run this in production for two years without hitting it. That said, we never reached this scale, so our experience is not really evidence here.

158
Lli_mingMod·2 days ago

Worth learning from this debugging approach. We went straight at the logs and took a much longer route.

95
Hhuang_ke·2 days ago

We have run this in production for two years without hitting it. That said, we never reached this scale, so our experience is not really evidence here.

67
Rrase·2 hours ago

This is not a offline-first-opensource problem, it is a usage problem. The docs say this API is not thread-safe and you must lock around it yourself.

86
Oops_wang·2 days ago

We have run this in production for two years without hitting it. That said, we never reached this scale, so our experience is not really evidence here.

300
Zzhou_yi·2 hours ago

I just read the offline-first-opensource source — the author actually explains the reasoning in a comment, roughly "so that it degrades into predictable behaviour in extreme cases".

96
Aalice_dev·2 days ago

Thanks for sharing real numbers — far more useful than the articles that only cover concepts.

1
Ttang_hao·2 days ago

I see point 3 differently. The trade-off depends on your read/write ratio: read-heavy with little writing means caching actually widens the inconsistency window.

1
Bbob_chen·28 minutes ago

I see point 3 differently. The trade-off depends on your read/write ratio: read-heavy with little writing means caching actually widens the inconsistency window.

65
Cchen_dev·28 minutes agoedited

This is not a offline-first-opensource problem, it is a usage problem. The docs say this API is not thread-safe and you must lock around it yourself.

103
Hhuang_ke·3 minutes ago

One counter-example: below offline-first-opensource 7.4 the semantics of that code are different, so do not copy it verbatim. We got burned in staging and rolled back once.

246
Sslow_query·12 minutes ago

Agreeing with the above. One addition: with this option enabled the GC count in your metrics doubles, so adjust the alert threshold at the same time or it will keep firing.

85
Mmike_xu·2 hours agoedited

Has anyone run a controlled experiment? I did, reducing it to a single variable, and the difference was 4% — within noise. So I suspect the main cause is something else.

250
Ttang_hao·2 days agoedited

We have run this in production for two years without hitting it. That said, we never reached this scale, so our experience is not really evidence here.

86
Llinlin·2 days ago

Agreeing with the above. One addition: with this option enabled the GC count in your metrics doubles, so adjust the alert threshold at the same time or it will keep firing.

196
Rran_bo·3 minutes ago

Has anyone run a controlled experiment? I did, reducing it to a single variable, and the difference was 4% — within noise. So I suspect the main cause is something else.

38
Bbob_chen·1 hour ago

Can you give a minimal reproduction? I ran it locally for ten minutes and could not reproduce on macOS with the latest version.

5
Wwinter·2 days agoLevel 6

Can you give a minimal reproduction? I ran it locally for ten minutes and could not reproduce on macOS with the latest version.

113
Kkite·2 days agoLevel 6

This matches what we see in production. We only hit it past 3k QPS; the earlier load tests showed nothing — the test traffic was too clean, with no long-tail requests.

26
Cchen_dev·2 days agoedited

I see point 3 differently. The trade-off depends on your read/write ratio: read-heavy with little writing means caching actually widens the inconsistency window.

2
Rrase·3 minutes agoLevel 6

Thanks for sharing real numbers — far more useful than the articles that only cover concepts.

342
Cchen_dev·5 hours agoedited

Saved. I am reworking this area this week — this saves a lot of wrong turns.

64
Oops_wang·2 days agoedited

Can you give a minimal reproduction? I ran it locally for ten minutes and could not reproduce on macOS with the latest version.

203
Zzhou_yiOP·3 minutes ago

Has anyone run a controlled experiment? I did, reducing it to a single variable, and the difference was 4% — within noise. So I suspect the main cause is something else.

187
Lli_ming·2 days ago

There is actually a simpler fix that needs no architecture change: move this check up to the gateway and the problem disappears. The cost is one extra lookup at the gateway.

114
Nnikic·2 days ago

Has anyone run a controlled experiment? I did, reducing it to a single variable, and the difference was 4% — within noise. So I suspect the main cause is something else.

57
Mmike_xuOPMod·3 minutes ago

This matches what we see in production. We only hit it past 3k QPS; the earlier load tests showed nothing — the test traffic was too clean, with no long-tail requests.

48
Wwinter·2 days ago

Sharing our numbers, 8 cores 16GB, same scenario:

| Concurrency | P50 | P99 |
|---|---|---|
| 200 | 12ms | 88ms |
| 500 | 31ms | 340ms |

P99 clearly collapses at 500 concurrency, which lines up with your knee point.

1
Wwinter·2 days agoLevel 6

I just read the offline-first-opensource source — the author actually explains the reasoning in a comment, roughly "so that it degrades into predictable behaviour in extreme cases".

225
Hhuang_keOP·2 days agoLevel 6

A question: what changes in a container with a 512Mi memory limit? That is how we run it in production.

53
Cchen_devMod·2 days ago

Worth learning from this debugging approach. We went straight at the logs and took a much longer route.

174
Kkite·2 days agoedited

Sharing our numbers, 8 cores 16GB, same scenario:

| Concurrency | P50 | P99 |
|---|---|---|
| 200 | 12ms | 88ms |
| 500 | 31ms | 340ms |

P99 clearly collapses at 500 concurrency, which lines up with your knee point.

102
Kkernel_panic·2 days ago

Sharing our numbers, 8 cores 16GB, same scenario:

| Concurrency | P50 | P99 |
|---|---|---|
| 200 | 12ms | 88ms |
| 500 | 31ms | 340ms |

P99 clearly collapses at 500 concurrency, which lines up with your knee point.

11
Cchen_dev·2 days ago

One counter-example: below offline-first-opensource 7.4 the semantics of that code are different, so do not copy it verbatim. We got burned in staging and rolled back once.

239
Wwinter·2 days agoedited

One counter-example: below offline-first-opensource 7.4 the semantics of that code are different, so do not copy it verbatim. We got burned in staging and rolled back once.

234
Sslow_query·2 days ago

Has anyone run a controlled experiment? I did, reducing it to a single variable, and the difference was 4% — within noise. So I suspect the main cause is something else.

201
Aalice_dev·2 days ago

Can you give a minimal reproduction? I ran it locally for ten minutes and could not reproduce on macOS with the latest version.

457
Nnikic·2 days ago

Agreeing with the above. One addition: with this option enabled the GC count in your metrics doubles, so adjust the alert threshold at the same time or it will keep firing.

125
Ddev_zhou·2 days ago

Agreeing with the above. One addition: with this option enabled the GC count in your metrics doubles, so adjust the alert threshold at the same time or it will keep firing.

13
RraseMod·5 hours ago

Agreeing with the above. One addition: with this option enabled the GC count in your metrics doubles, so adjust the alert threshold at the same time or it will keep firing.

193
Rrase·2 days ago

Saved. I am reworking this area this week — this saves a lot of wrong turns.

388
Hhuang_ke·1 hour ago

We have run this in production for two years without hitting it. That said, we never reached this scale, so our experience is not really evidence here.

160
Zzhou_yi·2 days ago

I just read the offline-first-opensource source — the author actually explains the reasoning in a comment, roughly "so that it degrades into predictable behaviour in extreme cases".

121
Nnikic·2 days ago

This is not a offline-first-opensource problem, it is a usage problem. The docs say this API is not thread-safe and you must lock around it yourself.

119
Hhuang_ke·2 days agoedited

This is not a offline-first-opensource problem, it is a usage problem. The docs say this API is not thread-safe and you must lock around it yourself.

118
Zzhu_zong·2 days ago

Sharing our numbers, 8 cores 16GB, same scenario:

| Concurrency | P50 | P99 |
|---|---|---|
| 200 | 12ms | 88ms |
| 500 | 31ms | 340ms |

P99 clearly collapses at 500 concurrency, which lines up with your knee point.

110
Sswoole_leeOP·2 days ago

A question: what changes in a container with a 512Mi memory limit? That is how we run it in production.

41
Cchen_dev·2 days ago

A question: what changes in a container with a 512Mi memory limit? That is how we run it in production.

98
Oops_wang·just now

Thanks for sharing real numbers — far more useful than the articles that only cover concepts.

89
Kkernel_panic·5 hours ago

There is actually a simpler fix that needs no architecture change: move this check up to the gateway and the problem disappears. The cost is one extra lookup at the gateway.

508
Llinlin·1 hour ago

There is actually a simpler fix that needs no architecture change: move this check up to the gateway and the problem disappears. The cost is one extra lookup at the gateway.

147
Zzhou_yi·yesterday

This is not a offline-first-opensource problem, it is a usage problem. The docs say this API is not thread-safe and you must lock around it yourself.

422
Ddev_zhou·2 days ago

One counter-example: below offline-first-opensource 7.4 the semantics of that code are different, so do not copy it verbatim. We got burned in staging and rolled back once.

61
Sslow_query·2 days ago

Worth learning from this debugging approach. We went straight at the logs and took a much longer route.

140
Bbob_chenMod·5 hours ago

I just read the offline-first-opensource source — the author actually explains the reasoning in a comment, roughly "so that it degrades into predictable behaviour in extreme cases".

17
Zzhou_yi·2 days ago

A question: what changes in a container with a 512Mi memory limit? That is how we run it in production.

73
Hhuang_ke·yesterday

Worth learning from this debugging approach. We went straight at the logs and took a much longer route.

14
Wwinter·2 days ago

Thanks for sharing real numbers — far more useful than the articles that only cover concepts.

2
Ddev_zhou·2 days ago

This is not a offline-first-opensource problem, it is a usage problem. The docs say this API is not thread-safe and you must lock around it yourself.

290
Zzhou_yi·2 days agoedited

Has anyone run a controlled experiment? I did, reducing it to a single variable, and the difference was 4% — within noise. So I suspect the main cause is something else.

83
Mmike_xu·12 minutes ago

There is actually a simpler fix that needs no architecture change: move this check up to the gateway and the problem disappears. The cost is one extra lookup at the gateway.

82
Oops_wang·1 hour ago

Thanks for sharing real numbers — far more useful than the articles that only cover concepts.

77
Rrase·2 days ago

Worth learning from this debugging approach. We went straight at the logs and took a much longer route.

74
RraseOP·2 days ago

One counter-example: below offline-first-opensource 7.4 the semantics of that code are different, so do not copy it verbatim. We got burned in staging and rolled back once.

318
Mmike_xuOP·1 hour ago

Sharing our numbers, 8 cores 16GB, same scenario:

| Concurrency | P50 | P99 |
|---|---|---|
| 200 | 12ms | 88ms |
| 500 | 31ms | 340ms |

P99 clearly collapses at 500 concurrency, which lines up with your knee point.

11
RraseOP·2 days ago

I just read the offline-first-opensource source — the author actually explains the reasoning in a comment, roughly "so that it degrades into predictable behaviour in extreme cases".

9
Rran_boOP·just now

I see point 3 differently. The trade-off depends on your read/write ratio: read-heavy with little writing means caching actually widens the inconsistency window.

6
Lli_ming·12 minutes ago

I just read the offline-first-opensource source — the author actually explains the reasoning in a comment, roughly "so that it degrades into predictable behaviour in extreme cases".

227
Sswoole_lee·2 days ago

There is actually a simpler fix that needs no architecture change: move this check up to the gateway and the problem disappears. The cost is one extra lookup at the gateway.

11
Mmike_xu·5 hours ago

I just read the offline-first-opensource source — the author actually explains the reasoning in a comment, roughly "so that it degrades into predictable behaviour in extreme cases".

63
Zzhu_zong·2 days ago

I see point 3 differently. The trade-off depends on your read/write ratio: read-heavy with little writing means caching actually widens the inconsistency window.

48
Ttang_hao·2 days agoedited

Thanks for sharing real numbers — far more useful than the articles that only cover concepts.

40
Ttang_hao·2 days agoedited

Sharing our numbers, 8 cores 16GB, same scenario:

| Concurrency | P50 | P99 |
|---|---|---|
| 200 | 12ms | 88ms |
| 500 | 31ms | 340ms |

P99 clearly collapses at 500 concurrency, which lines up with your knee point.

37
Wwinter·2 days ago

I see point 3 differently. The trade-off depends on your read/write ratio: read-heavy with little writing means caching actually widens the inconsistency window.

31
Llinlin·2 days ago

This matches what we see in production. We only hit it past 3k QPS; the earlier load tests showed nothing — the test traffic was too clean, with no long-tail requests.

25
Lli_ming·2 days ago

I see point 3 differently. The trade-off depends on your read/write ratio: read-heavy with little writing means caching actually widens the inconsistency window.

21
Aalice_dev·2 days agoedited

Saved. I am reworking this area this week — this saves a lot of wrong turns.

36
Bbob_chen·3 minutes ago

Saved. I am reworking this area this week — this saves a lot of wrong turns.

18
Bbob_chen·1 hour agoedited

There is actually a simpler fix that needs no architecture change: move this check up to the gateway and the problem disappears. The cost is one extra lookup at the gateway.

11
Cchen_dev·12 minutes ago

I see point 3 differently. The trade-off depends on your read/write ratio: read-heavy with little writing means caching actually widens the inconsistency window.

183
Aalice_dev·2 days ago

This matches what we see in production. We only hit it past 3k QPS; the earlier load tests showed nothing — the test traffic was too clean, with no long-tail requests.

3
Hhuang_ke·2 days ago

We have run this in production for two years without hitting it. That said, we never reached this scale, so our experience is not really evidence here.

2
Wwinter·2 days ago

Agreeing with the above. One addition: with this option enabled the GC count in your metrics doubles, so adjust the alert threshold at the same time or it will keep firing.

169
Rran_bo·2 days ago

Thanks for sharing real numbers — far more useful than the articles that only cover concepts.

97
Oops_wang·2 days ago

Has anyone run a controlled experiment? I did, reducing it to a single variable, and the difference was 4% — within noise. So I suspect the main cause is something else.

11
Hhuang_ke·2 days ago

Saved. I am reworking this area this week — this saves a lot of wrong turns.

5
Zzhou_yi·just now

A question: what changes in a container with a 512Mi memory limit? That is how we run it in production.

1
Kkite·2 days ago

A question: what changes in a container with a 512Mi memory limit? That is how we run it in production.

1
Wwinter·2 days ago

Sharing our numbers, 8 cores 16GB, same scenario:

| Concurrency | P50 | P99 |
|---|---|---|
| 200 | 12ms | 88ms |
| 500 | 31ms | 340ms |

P99 clearly collapses at 500 concurrency, which lines up with your knee point.

1
Hhuang_ke·2 days ago

This is not a offline-first-opensource problem, it is a usage problem. The docs say this API is not thread-safe and you must lock around it yourself.

1
Kkite·2 days ago

I just read the offline-first-opensource source — the author actually explains the reasoning in a comment, roughly "so that it degrades into predictable behaviour in extreme cases".

1
Bbob_chen·2 days ago

This is not a offline-first-opensource problem, it is a usage problem. The docs say this API is not thread-safe and you must lock around it yourself.

1

This is the post detail page /en/c/offline-first-opensource/post/p9. Posts and comments are generated deterministically from a seeded PRNG, so the same post always renders the same content and the link can be shared, reloaded and indexed. In production this page reads MySQL for the post, Redis for hot-post caching, and fetches the whole comment tree in a single query on the path column.

See the database schema →