traverse-server: the pkarr rate limiters read an injected clock - #509
Merged
Merged
Conversation
manifest_and_pkarr_store_over_http asserts the fourth GET and the fourth PUT are refused, with buckets of three tokens refilled at one per second against the wall clock. A PUT commits a redb transaction with fsync; on a slow Windows runner the sequence took over a second, a token refilled and the request passed with 200. The test failed twice today on unrelated branches. RateLimiter now takes a Clock (Instant::now in production) and Server::spawn_with_clock threads it through. The integration test freezes the clock, so its bursts are consumed by request count alone. The unit test keeps driving allow_at with explicit instants.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
manifest_and_pkarr_store_over_httpmeasured a 1 token/s token bucket against the wall clock. A PUT commits a redb transaction (fsync), so on a slow Windows runner more than a second passed between GETs, a token refilled, and the expected 429 came back 200. It failed twice today on unrelated branches (ui: walk back into a landed history page inside the render, not between frames #507 and orchestrate/sol-executor).RateLimiternow reads an injectedClock(Instant::nowin production);Server::spawn_with_clockthreads it through. The integration test freezes the clock so bursts are consumed by request count alone.Test plan
cargo test -p tcode-traverse-server: all pass. Clippy clean, fmt applied.