feat: log-tailer offset persistence + in-flight L2 rate-limit accounting (code-review.md § Phase 3)
- logtail: persist the read position (offset + fingerprint of the log's first 512 bytes) in a new logtail_state table (migration 0003) and resume from it on start, so delivery lines written while the panel was down are parsed instead of skipped and their send-log rows no longer stay "queued" forever. Fingerprint mismatch (rotated/recreated while down) reads the file from the start — re-parsing is idempotent; a first-ever start with nothing stored still begins at end-of-file. Writes are throttled to one per 5s, forced on rotation and shutdown. - milter: count messages that passed the level-2 check but have not reached the send log yet (internal/milter/inflight.go), so concurrent SMTP sessions cannot each spend the same last slot. A literal count+insert transaction, as the review suggested, is not possible: the count happens at MAIL FROM and the insert at end-of-message. Reservations are released after the insert, on ABORT, and after a 10-minute TTL — a client that drops mid-transaction must not be able to hold a slot, since the limiter is fail-open by design. Docs: architecture.md (log tailer, persistence, L2 counting), security.md and roadmap.md (restart gap closed, container recreate remains), CHANGELOG, progress.md, code-review.md. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
@@ -17,6 +17,10 @@ import (
|
||||
// can never block mail — Postfix's level-1 anvil limit (spec 5) remains the
|
||||
// backstop, and it does not depend on this milter at all. Only a clean count at
|
||||
// or above a configured ceiling returns true.
|
||||
//
|
||||
// A message that passes reserves a slot per applicable limit, released once it
|
||||
// reaches the send log (or is abandoned) — see inflight for why the stored
|
||||
// count alone is not enough.
|
||||
func (s *session) overLimit() bool {
|
||||
if s.clientIP == "" {
|
||||
return false // no client IP to key on; level-2 does not apply
|
||||
@@ -25,6 +29,7 @@ func (s *session) overLimit() bool {
|
||||
{store.RateLimitScopeDomain, domainOf(s.from)},
|
||||
{store.RateLimitScopeApp, s.login},
|
||||
}
|
||||
var taken []*reservation
|
||||
for _, c := range checks {
|
||||
if c.ref == "" {
|
||||
continue
|
||||
@@ -45,15 +50,34 @@ func (s *session) overLimit() bool {
|
||||
log.Printf("journal-milter: rate-limit count %s %q: %v (fail-open)", c.scope, c.ref, err)
|
||||
continue
|
||||
}
|
||||
key := c.scope + "|" + c.ref
|
||||
n += s.flight.count(key, since)
|
||||
if n >= int64(rl.MaxMessages) {
|
||||
log.Printf("journal-milter: %s %q over limit: %d/%d in %ds from %s — refusing 4xx",
|
||||
c.scope, c.ref, n, rl.MaxMessages, rl.WindowSeconds, s.clientIP)
|
||||
// The message is refused, so the slots claimed for the limits
|
||||
// checked before this one must not stay claimed.
|
||||
for _, r := range taken {
|
||||
s.flight.release(r)
|
||||
}
|
||||
return true
|
||||
}
|
||||
taken = append(taken, s.flight.reserve(key))
|
||||
}
|
||||
s.reserved = append(s.reserved, taken...)
|
||||
return false
|
||||
}
|
||||
|
||||
// releaseReservations gives back every slot this message holds. It runs once
|
||||
// the message is in the send log (where the stored count sees it), and whenever
|
||||
// the transaction ends without getting there.
|
||||
func (s *session) releaseReservations() {
|
||||
for _, r := range s.reserved {
|
||||
s.flight.release(r)
|
||||
}
|
||||
s.reserved = nil
|
||||
}
|
||||
|
||||
// recordRejected writes a send-log row for a message refused by a level-2 limit
|
||||
// (spec 7.4, "опционально фиксирует ... для видимости в UI"), so the rejection
|
||||
// shows up in the monitoring screen. Only MAIL-stage fields are known; the write
|
||||
|
||||
Reference in New Issue
Block a user