Priority: P1 — revenue-leak + metering-loss class: all enforcement state is process-memory.
I maintainer di solito rispondono entro 1 giorno
Nessuno ha ancora preso questa issue.
Valutazione
- Difficoltà
- 5/5
- Tempo stimato
- Più di una settimana
- Idoneità per principianti
- 25/100
Direzione di ricerca
Start by reading src/merchant/merchant.go, src/valve/valve.go, src/valve/customer_data_tracker.go, and startup in main.go or merchant initialization to trace session grants, metering, and deauthentication. Confirm the persistence and metering-reconciliation design with the maintainer before implementing. Done means the required round-trip and reconciliation tests pass, with restart tests demonstrating paid access is restored or safely deauthorized as specified.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
Priority: P1 — revenue-leak + metering-loss class: all enforcement state is process-memory.
Problem
customerSessions, gate deauth time.Timers (openGates), and data baselines are in-memory only. After any restart (crash, upgrade, service restart, power cut):
- time-metered customers keep access forever (the deauth timer died with the process; NDS still holds them authenticated until its own session timeout),
- bytes-metered customers keep access unmetered (no session →
checkDataUsageskips them; baseline gone), - remaining paid allotments are forgotten (customers lose paid value on the "remaining" side while the gate stays open — worst of both).
Why it matters
Every restart converts all active paid sessions into free unlimited access (revenue leak) while erasing what customers paid for (value leak). Routers reboot — power cuts, upgrades, OOM — so this is not hypothetical. Lightning quotes are deliberately persisted (quote_store.go) because payment recognition had to survive restarts; sessions need the same treatment.
Current behavior (source refs)
src/merchant/merchant.go:73(customerSessionsmap),:1112-1173(access/restore in-memory only).src/valve/valve.go:82-86(openGates,pendingUntilmaps),:222-249(in-process deauth timer).src/valve/customer_data_tracker.go:20-24(in-memory baselines).checkDataUsage(merchant.go:249-304) iterates only in-memory sessions.
Desired invariant
Paid access converges to paid state after restart: unexpired paid sessions are re-armed (gate + metering + deauth deadline), expired/unknown clients are deauthorized, and remaining allotment is preserved or explicitly reconciled.
Proposed scope (design-then-implement; pick with maintainer)
- Persist sessions on grant (durable before/at gate-open; fsync'd JSONL or bbolt) — remaining allotment, metric, start, expiry, and bytes-baseline snapshot.
- Startup reconciliation: load sessions → re-arm timers/baselines →
ndsctldeauth for authenticated clients without a valid session (safe direction: close unknowns). - Metering survival: persist
usedperiodically (debounced) — the debatable part; alternative: on restart, re-baseline from NDS counters and subtract persistedused-at-grant(design doc must choose; RAM/flash tradeoffs on 8 MB devices). - Crash-safe writes: tmp+rename, no per-packet fsync.
Areas / files
src/merchant/merchant.go, src/valve/valve.go, src/valve/customer_data_tracker.go, startup in main.go/merchant init.
Acceptance criteria
- Restart with active time session (T remaining) → client deauthed within bounded grace at T, not before.
- Restart with active bytes session (B remaining, N used) → client cut off at approximately N+B total (documented tolerance), not at reboot.
- Restart with expired/NDS-unknown sessions → deauth attempted, no stale access.
Required tests
- Unit: persistence round-trip; reconciliation decision table.
- Integration (cloud-lab / PRTA): restart-mid-session lane for both metrics; NDS-unknown-client deauth lane.
Failure-injection tests
- SIGKILL + restart at: grant, mid-session, after-expiry.
- Power-cut simulation (PRTA smart-plug lane) with active sessions.
- Corrupt sessions file → fail safe (deauth all, log loudly) not fail open.
Compatibility
On-disk addition only; NDS behavior unchanged.
Dependencies
None (independent of wallet work).
Out of scope
- Cross-reboot usage reporting precision beyond documented tolerance.
- Lingua principale
- Go
- Stelle
- 12
- Fork
- 14
- Merge medio
- 1g 6h
- PR unite (30g)
- 211
Preparare l'ambiente
- Nessun Dockerfile né file Docker Compose
- Nessun modello di pull request
- Leggi la guida per i contributori
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di OpenTollGate/tollgate-module-basic-go
-
go-battery needs an ndsctl on PATH: TestPurchaseSessionGuardHoldsThroughTheOutcomeUnknownWindow fails on bare hosts (passes with stub)Forse già presa Una pull request collegata a questa issue è aperta o già unita. Aperta
Difficoltà 2/5 1-3 ore Idoneità per principianti 78/100
OpenTollGate/tollgate-module-basic-go#726 ·
I maintainer di solito rispondono entro 1 giorno
-
rebrand-literal-gutter: uhttpd section-vocabulary check trips on a COMMENT (uhttpd.luci in 92-tollgate-admin-setup:178)Forse già presa Una pull request collegata a questa issue è aperta o già unita. Aperta
Difficoltà 2/5 1-3 ore Idoneità per principianti 78/100
OpenTollGate/tollgate-module-basic-go#723 ·
I maintainer di solito rispondono entro 1 giorno
-
Discovery endpoint serves text/plain content-type on / — r2r clients warnForse già presa Una pull request collegata a questa issue è aperta o già unita. Aperta
Difficoltà 2/5 1-3 ore Idoneità per principianti 68/100
OpenTollGate/tollgate-module-basic-go#628 ·
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 4/5 3-5 giorni Idoneità per principianti 48/100
OpenTollGate/tollgate-module-basic-go#725 ·
I maintainer di solito rispondono entro 1 giorno
-
cloud-lab Dockerfile.client: mid-file ARG invisible to FROM — client and killer images unbuildable on docker/buildkit 29 (golang:-bookworm)Forse già presa @Amperstrand l’ha presa oggi. Aperta
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 25/100
OpenTollGate/tollgate-module-basic-go#724 ·
I maintainer di solito rispondono entro 1 giorno
Tutte le issue di OpenTollGate/tollgate-module-basic-go
Issue simili
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 76/100
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 76/100
evilmartians/lefthook#1588 ·
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 85/100
kubernetes-sigs/kubebuilder#6084 ·
I maintainer di solito rispondono entro 3 giorni
-
agent-research-recommend agent-review-finding chore
Difficoltà 2/5 1-3 ore Idoneità per principianti 78/100
jordansmall/spindrift#4821 · 1 commento ·
I maintainer di solito rispondono entro 1 giorno
-
area:web
Difficoltà 2/5 1-3 ore Idoneità per principianti 82/100
praetorianer777/GoTome#178 ·
I maintainer di solito rispondono entro 1 giorno