damacus
The TUI retains visited inspector text without a cache limit, eagerly loads the entire document library in pages of 25, and starts new inspector threads during navigation. Refresh starts another document loader without cancelling the old generation. This is a source-backed scalability risk, not a measured whole-process memory baseline. Sources: src/tui.rs inspector_cache, request_documents_reload and spawn_*_loader functions. ## Scope Measure prolonged browsing first. Bound inspector cache bytes and in-flight inspector work. Track/cancel document-load generations so stale results cannot repopulate a refreshed list. Consider on-demand document pages only if measurements justify that additional change; preserve end-of-list navigation semantics. ## Passing bar - At most two inspector requests in flight and one active document-load generation. - No results from an old generation appended after refresh. - During repeated navigation through 1,000 documents with 100 KiB inspector text each, retained text plateaus at <=16 MiB and RSS grows by <=32 MiB after warm-up. - Preserve correct selection when responses arrive out of order; verify repeated refresh and back navigation. - Record baseline RSS and request counts before choosing an implementation. Avoid a new cache dependency. ## Evidence and acceptance Baseline: commit ffd29e3, macOS arm64, release build, Rust 1.97.1, assessed 5 September 2026. These are local measurements, not production guarantees. Compare before/after with locked dependencies on the same machine in at least three interleaved batches. Keep timing checks out of shared-runner CI; test deterministic behaviour there. Preserve JSON, terminal output meaning and errors. Avoid new runtime dependencies. Reject unexplained CPU/RSS growth over 5% or executable growth over 1%.