Priority: P1 — revenue-leak + metering-loss class: all enforcement state is process-memory.
Maintainers usually reply within 1 day
Nobody has claimed this yet.
Assessment
- Difficulty
- 5/5
- Estimated time
- Over a week
- Newbie friendliness
- 25/100
Research direction
Start by reading src/merchant/merchant.go, src/valve/valve.go, src/valve/customer_data_tracker.go, and startup in main.go or merchant initialization to trace session grants, metering, and deauthentication. Confirm the persistence and metering-reconciliation design with the maintainer before implementing. Done means the required round-trip and reconciliation tests pass, with restart tests demonstrating paid access is restored or safely deauthorized as specified.
Written by the indexing model from the issue text.
Description
Priority: P1 — revenue-leak + metering-loss class: all enforcement state is process-memory.
Problem
customerSessions, gate deauth time.Timers (openGates), and data baselines are in-memory only. After any restart (crash, upgrade, service restart, power cut):
- time-metered customers keep access forever (the deauth timer died with the process; NDS still holds them authenticated until its own session timeout),
- bytes-metered customers keep access unmetered (no session →
checkDataUsageskips them; baseline gone), - remaining paid allotments are forgotten (customers lose paid value on the "remaining" side while the gate stays open — worst of both).
Why it matters
Every restart converts all active paid sessions into free unlimited access (revenue leak) while erasing what customers paid for (value leak). Routers reboot — power cuts, upgrades, OOM — so this is not hypothetical. Lightning quotes are deliberately persisted (quote_store.go) because payment recognition had to survive restarts; sessions need the same treatment.
Current behavior (source refs)
src/merchant/merchant.go:73(customerSessionsmap),:1112-1173(access/restore in-memory only).src/valve/valve.go:82-86(openGates,pendingUntilmaps),:222-249(in-process deauth timer).src/valve/customer_data_tracker.go:20-24(in-memory baselines).checkDataUsage(merchant.go:249-304) iterates only in-memory sessions.
Desired invariant
Paid access converges to paid state after restart: unexpired paid sessions are re-armed (gate + metering + deauth deadline), expired/unknown clients are deauthorized, and remaining allotment is preserved or explicitly reconciled.
Proposed scope (design-then-implement; pick with maintainer)
- Persist sessions on grant (durable before/at gate-open; fsync'd JSONL or bbolt) — remaining allotment, metric, start, expiry, and bytes-baseline snapshot.
- Startup reconciliation: load sessions → re-arm timers/baselines →
ndsctldeauth for authenticated clients without a valid session (safe direction: close unknowns). - Metering survival: persist
usedperiodically (debounced) — the debatable part; alternative: on restart, re-baseline from NDS counters and subtract persistedused-at-grant(design doc must choose; RAM/flash tradeoffs on 8 MB devices). - Crash-safe writes: tmp+rename, no per-packet fsync.
Areas / files
src/merchant/merchant.go, src/valve/valve.go, src/valve/customer_data_tracker.go, startup in main.go/merchant init.
Acceptance criteria
- Restart with active time session (T remaining) → client deauthed within bounded grace at T, not before.
- Restart with active bytes session (B remaining, N used) → client cut off at approximately N+B total (documented tolerance), not at reboot.
- Restart with expired/NDS-unknown sessions → deauth attempted, no stale access.
Required tests
- Unit: persistence round-trip; reconciliation decision table.
- Integration (cloud-lab / PRTA): restart-mid-session lane for both metrics; NDS-unknown-client deauth lane.
Failure-injection tests
- SIGKILL + restart at: grant, mid-session, after-expiry.
- Power-cut simulation (PRTA smart-plug lane) with active sessions.
- Corrupt sessions file → fail safe (deauth all, log loudly) not fail open.
Compatibility
On-disk addition only; NDS behavior unchanged.
Dependencies
None (independent of wallet work).
Out of scope
- Cross-reboot usage reporting precision beyond documented tolerance.
- Dominant language
- Go
- Stars
- 12
- Forks
- 14
- Avg merge
- 1d 6h
- Merged PRs (30d)
- 211
Getting set up
- No Dockerfile or Docker Compose file
- No pull request template
- Read the contributing guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from OpenTollGate/tollgate-module-basic-go
-
go-battery needs an ndsctl on PATH: TestPurchaseSessionGuardHoldsThroughTheOutcomeUnknownWindow fails on bare hosts (passes with stub)Possibly taken A pull request linked to this issue is open or already merged. Open
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
OpenTollGate/tollgate-module-basic-go#726 ·
Maintainers usually reply within 1 day
-
rebrand-literal-gutter: uhttpd section-vocabulary check trips on a COMMENT (uhttpd.luci in 92-tollgate-admin-setup:178)Possibly taken A pull request linked to this issue is open or already merged. Open
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
OpenTollGate/tollgate-module-basic-go#723 ·
Maintainers usually reply within 1 day
-
Discovery endpoint serves text/plain content-type on / — r2r clients warnPossibly taken A pull request linked to this issue is open or already merged. Open
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
OpenTollGate/tollgate-module-basic-go#628 ·
Maintainers usually reply within 1 day
-
Difficulty 4/5 3-5 days Newbie friendliness 48/100
OpenTollGate/tollgate-module-basic-go#725 ·
Maintainers usually reply within 1 day
-
cloud-lab Dockerfile.client: mid-file ARG invisible to FROM — client and killer images unbuildable on docker/buildkit 29 (golang:-bookworm)Possibly taken @Amperstrand claimed this today. Open
Difficulty 1/5 Under an hour Newbie friendliness 25/100
OpenTollGate/tollgate-module-basic-go#724 ·
Maintainers usually reply within 1 day
All issues in OpenTollGate/tollgate-module-basic-go
Similar issues
-
automation models
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
Maintainers usually reply within 1 day
-
Bug pulumi/pulumi
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
Maintainers usually reply within 1 day
-
bug
Difficulty 1/5 Under an hour Newbie friendliness 74/100
GoogleCloudPlatform/cluster-toolkit#6437 ·
Maintainers usually reply within 2 days
-
Difficulty 2/5 1-3 hours Newbie friendliness 76/100
stripe/stripe-cli#2130 ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
kovidgoyal/kitty#10625 ·
Maintainers usually reply within 1 day