panel,mail: fail closed on the rate-limit race, session create and app delete
test / test (push) Has been cancelled
test / test (push) Has been cancelled
The level-2 limiter counted stored plus in-flight messages and reserved its own slot in two critical sections, so SMTP sessions that overlapped could each take the last free slot; tryAdmit now does both under one lock. A session that cannot be written no longer yields a cookie the browser would carry while every request bounced to /login. Deleting an application clears its SASL account before its registry row, matching domain delete, so a saslpasswd2 failure leaves a retryable application rather than an account that still authenticates. Co-authored-by: Claude Opus 5 <noreply@anthropic.com> Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
@@ -54,22 +54,23 @@ func (s *session) overLimit() bool {
|
||||
}
|
||||
|
||||
// enforceLimit counts recent messages for scope/ref and refuses when at or
|
||||
// above the ceiling. On admit it reserves an in-flight slot on the session.
|
||||
// above the ceiling. The stored count and the in-flight slots are weighed and
|
||||
// the admitted message's own slot is taken in one atomic step (tryAdmit), so
|
||||
// two sessions racing at MAIL FROM cannot both claim the last free slot.
|
||||
func (s *session) enforceLimit(scope, ref string, rl store.RateLimit) bool {
|
||||
since := time.Now().Add(-time.Duration(rl.WindowSeconds) * time.Second)
|
||||
n, err := s.rec.CountMessages(scope, ref, since)
|
||||
stored, err := s.rec.CountMessages(scope, ref, since)
|
||||
if err != nil {
|
||||
log.Printf("journal-milter: rate-limit count %s %q: %v (fail-open)", scope, ref, err)
|
||||
return false
|
||||
}
|
||||
key := scope + "|" + ref
|
||||
n += s.flight.count(key, since)
|
||||
if n >= int64(rl.MaxMessages) {
|
||||
r, n, ok := s.flight.tryAdmit(scope+"|"+ref, since, stored, int64(rl.MaxMessages))
|
||||
if !ok {
|
||||
log.Printf("journal-milter: %s %q over limit: %d/%d in %ds from %s — refusing 4xx",
|
||||
scope, ref, n, rl.MaxMessages, rl.WindowSeconds, s.clientIP)
|
||||
return true
|
||||
}
|
||||
s.reserved = append(s.reserved, s.flight.reserve(key))
|
||||
s.reserved = append(s.reserved, r)
|
||||
return false
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user