Problem
The legacy-migration "done" seal (mark_legacy_migration_done / is_legacy_migration_done) is a localStorage flag. In production the app runs in the gateway's sandboxed iframe, where localStorage is unavailable (SecurityError), so the seal is never written.
Accounts with rooms are unaffected: their current delegate lists room: keys, and that load path never probes legacy. But an account with no rooms takes the ProbeLegacy path on every page load. Each load then fires, to every one of the 29 registered legacy delegates:
GetRequest for rooms_data;
GetRequest for outbound_dms;
- a
ListRequest.
The freenet-migrate walk runs on top of that. Every brand-new visitor on a hosted node pays this cost on each load, which is the class of per-load overhead #757 is about.
Why it was not fixed in #758
Moving the seal into the delegate store would turn a never-active "never probe legacy again" decision on in production. The seal is requested by any definitive answer, including the "delegate not found" door, and it lands at quiescence, which can also be reached when some generations were merely silent. Activating that needs its own review of when "done" is safe to make permanent, so a silent generation's rooms are not skipped for good.
Possible direction
Store the seal in the current delegate, as #758 does for the in-progress marker. Gate it on every probed generation having answered definitively, with no silence or timeouts.
[AI-assisted - Claude]
Problem
The legacy-migration "done" seal (
mark_legacy_migration_done/is_legacy_migration_done) is alocalStorageflag. In production the app runs in the gateway's sandboxed iframe, wherelocalStorageis unavailable (SecurityError), so the seal is never written.Accounts with rooms are unaffected: their current delegate lists
room:keys, and that load path never probes legacy. But an account with no rooms takes theProbeLegacypath on every page load. Each load then fires, to every one of the 29 registered legacy delegates:GetRequestforrooms_data;GetRequestforoutbound_dms;ListRequest.The freenet-migrate walk runs on top of that. Every brand-new visitor on a hosted node pays this cost on each load, which is the class of per-load overhead #757 is about.
Why it was not fixed in #758
Moving the seal into the delegate store would turn a never-active "never probe legacy again" decision on in production. The seal is requested by any definitive answer, including the "delegate not found" door, and it lands at quiescence, which can also be reached when some generations were merely silent. Activating that needs its own review of when "done" is safe to make permanent, so a silent generation's rooms are not skipped for good.
Possible direction
Store the seal in the current delegate, as #758 does for the in-progress marker. Gate it on every probed generation having answered definitively, with no silence or timeouts.
[AI-assisted - Claude]