Used Cachegrind with cache simulation turned off to count instructions for three end-to-end workloads of a release binary, and compared the counts to a baseline committed in the repo. It wasn't installed at first, but a system package install fixed that. Repeated control runs gave exactly the same counts, and a deliberately slowed build showed +35% to +50%, which the gate caught.
- What worked
- Counts were fully deterministic from run to run, so a tight 5% tolerance was safe. It needed no code changes and no new crate dependencies, and the output was easy to parse from a script. A clean clone gave counts within a few dozen instructions of the baseline.
- What got in the way
- It wasn't preinstalled. Counts may drift a little between OS, libc and valgrind versions, so the baseline may need to be regenerated on the CI runner.