Hacktoberfest 2026: le issue che i maintainer hanno segnato per ottobre, aperte e adatte ai principianti. Sfoglia le issue Hacktoberfest

Priority: P1 — revenue-leak + metering-loss class: all enforcement state is process-memory.

Aperta
#499 0 commenti 0 reazioni 0 assegnatari Vedi su GitHub

I maintainer di solito rispondono entro 1 giorno

Nessuno ha ancora preso questa issue.

Valutazione

Difficoltà
5/5
Tempo stimato
Più di una settimana
Idoneità per principianti
25/100
Tipo di issue
Funzionalità
Chiarezza
Abbastanza chiara
Stato di attività
Attiva
Stack tecnologico
go
Ambito
backend

Direzione di ricerca

Start by reading src/merchant/merchant.go, src/valve/valve.go, src/valve/customer_data_tracker.go, and startup in main.go or merchant initialization to trace session grants, metering, and deauthentication. Confirm the persistence and metering-reconciliation design with the maintainer before implementing. Done means the required round-trip and reconciliation tests pass, with restart tests demonstrating paid access is restored or safely deauthorized as specified.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Descrizione

Priority: P1 — revenue-leak + metering-loss class: all enforcement state is process-memory.

Problem

customerSessions, gate deauth time.Timers (openGates), and data baselines are in-memory only. After any restart (crash, upgrade, service restart, power cut):

  • time-metered customers keep access forever (the deauth timer died with the process; NDS still holds them authenticated until its own session timeout),
  • bytes-metered customers keep access unmetered (no session → checkDataUsage skips them; baseline gone),
  • remaining paid allotments are forgotten (customers lose paid value on the "remaining" side while the gate stays open — worst of both).

Why it matters

Every restart converts all active paid sessions into free unlimited access (revenue leak) while erasing what customers paid for (value leak). Routers reboot — power cuts, upgrades, OOM — so this is not hypothetical. Lightning quotes are deliberately persisted (quote_store.go) because payment recognition had to survive restarts; sessions need the same treatment.

Current behavior (source refs)

  • src/merchant/merchant.go:73 (customerSessions map), :1112-1173 (access/restore in-memory only).
  • src/valve/valve.go:82-86 (openGates, pendingUntil maps), :222-249 (in-process deauth timer).
  • src/valve/customer_data_tracker.go:20-24 (in-memory baselines).
  • checkDataUsage (merchant.go:249-304) iterates only in-memory sessions.

Desired invariant

Paid access converges to paid state after restart: unexpired paid sessions are re-armed (gate + metering + deauth deadline), expired/unknown clients are deauthorized, and remaining allotment is preserved or explicitly reconciled.

Proposed scope (design-then-implement; pick with maintainer)

  1. Persist sessions on grant (durable before/at gate-open; fsync'd JSONL or bbolt) — remaining allotment, metric, start, expiry, and bytes-baseline snapshot.
  2. Startup reconciliation: load sessions → re-arm timers/baselines → ndsctl deauth for authenticated clients without a valid session (safe direction: close unknowns).
  3. Metering survival: persist used periodically (debounced) — the debatable part; alternative: on restart, re-baseline from NDS counters and subtract persisted used-at-grant (design doc must choose; RAM/flash tradeoffs on 8 MB devices).
  4. Crash-safe writes: tmp+rename, no per-packet fsync.

Areas / files

src/merchant/merchant.go, src/valve/valve.go, src/valve/customer_data_tracker.go, startup in main.go/merchant init.

Acceptance criteria

  • Restart with active time session (T remaining) → client deauthed within bounded grace at T, not before.
  • Restart with active bytes session (B remaining, N used) → client cut off at approximately N+B total (documented tolerance), not at reboot.
  • Restart with expired/NDS-unknown sessions → deauth attempted, no stale access.

Required tests

  • Unit: persistence round-trip; reconciliation decision table.
  • Integration (cloud-lab / PRTA): restart-mid-session lane for both metrics; NDS-unknown-client deauth lane.

Failure-injection tests

  • SIGKILL + restart at: grant, mid-session, after-expiry.
  • Power-cut simulation (PRTA smart-plug lane) with active sessions.
  • Corrupt sessions file → fail safe (deauth all, log loudly) not fail open.

Compatibility

On-disk addition only; NDS behavior unchanged.

Dependencies

None (independent of wallet work).

Out of scope

  • Cross-reboot usage reporting precision beyond documented tolerance.
Lingua principale
Go
Stelle
12
Fork
14
Merge medio
1g 6h
PR unite (30g)
211

Preparare l'ambiente

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Altre issue di OpenTollGate/tollgate-module-basic-go

Tutte le issue di OpenTollGate/tollgate-module-basic-go

Issue simili

Altre issue su Go

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.