yuqi1129 opened a new issue, #13593: URL: https://github.com/apache/gravitino/issues/13593
## What would you like to be improved? On main `8e9ca0009d68dbf9edb5e313d3d51688b9c4cff1`, listTables over 1,000 managed MySQL tables with a role allowed to see only eight tables plateaus around 16–18 successful requests/s. Raising concurrency from 8 to 32 increases p99 to approximately 2.1–2.2 seconds, without improving throughput. The result cardinality is correct and requests succeed; this is a performance improvement, not a permission bypass or an asserted contractual SLO failure. In the final 32-client measured window (16.73 seconds), 236/242 Java execution samples include authorization; recorded filter-future joins total 478 thread-seconds and stacks containing `ognl.internal.ClassCacheHandler.getHandler` total 134 thread-seconds. Sampled allocation weight is 36.7 GiB, with HashMap nodes/arrays, byte arrays, strings and Aviator environments prominent. There are 130 GCs with about 1.02 seconds of total pauses. These are overlapping recorded waits and allocation estimates, not additive request latency or exact allocation accounting. Metadata/catalog MySQL CPU is low during this workload. A separate fully visible reader control uses the same fully managed 1,000-table dataset, authorizer, JVM size and catalog settings. Its three-run medians are 372.1 requests/s at 8 clients and 262.2 requests/s at 32 clients, with p99 54.4/312.4 ms, despite returning more identifiers. The restricted medians are 17.0/16.4 requests/s, with p99 699.3/2176.1 ms. ## How should we improve? Profile `MetadataAuthzHelper.doFilter` and the OGNL/Jcasbin permission-evaluation chain. Reduce repeated per-object environment/allocation work and contention; consider bulk permission evaluation and reusable immutable evaluation structures while preserving ownership, deny rules, inherited grants and active-role semantics. Increasing the filtering thread pool alone is not supported by the observed flat throughput. Reproduce with simple test identities, default Jcasbin authorization, 1,000 managed empty eight-column tables, ordinary USE_CATALOG/USE_SCHEMA grants and SELECT_TABLE on eight individual tables. Warm the endpoint, run three repeats at 8 and 32 clients, and retain per-request data, exact-window CPU/wait JFR summaries and independent database metrics. No external IdP or application-table row scan is involved. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
