grid-signals: MAX_PROVIDERS global cap can lock out providers (add per-site cap + stale eviction)
Maintainers usually reply within 1 day
Nobody has claimed this yet.
Assessment
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Newbie friendliness
- 48/100
- Issue type
- Feature
- Clarity
- Mostly clear
- Activity status
- Active
- Tech stack
- rust
- Domain
- distributed-systems
Research direction
Start in the grid-signals crate's signals.rs ingest path and review the #160 line-65 comment referenced in the issue. Work out how per-site and global caps, retention-based eviction and idle pruning should interact; done means the cap behavior is bounded and dropped lines are diagnosable, with the memory bound documented and relevant tests passing.
Written by the indexing model from the issue text.
Description
MAX_PROVIDERS in the grid-signals store is a global, never-evicted cap (currently 4096). Once that many distinct site/provider keys are seen, new legitimate providers are silently rejected until restart. A peer that controls the grid_provider label can consume the slots with distinct values and lock out later providers, and 4096 entries fit within the request limit.
Raised in the #160 review and the pre-merge security review. Not exploitable today because the ingest source is the authenticated operator relay, so this is defense-in-depth / availability hardening, not a merge blocker for #160.
Proposed:
- Per-site cap so one site cannot exhaust the pool, alongside or instead of the global cap.
- Evict keys whose newest sample is older than the retention window before rejecting a new one.
- Prune series idle beyond the window (the idle-pruning half of the #160 line-65 comment).
- Count or log dropped lines (cap hits, parse failures, future timestamps) so lockouts are diagnosable.
- Document the resulting worst-case memory bound alongside the count caps.
Scope: the grid-signals crate ingest path (signals.rs).
- Dominant language
- Rust
- Stars
- 10
- Forks
- 24
- Avg merge
- 1d 8h
- Merged PRs (30d)
- 86
Getting set up
- No Dockerfile or Docker Compose file
- No pull request template
- Read the contributing guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from praxis-proxy/grid
-
triage/accepted
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
praxis-proxy/grid#200 ·
Maintainers usually reply within 1 day
-
Clock steps shift relayed signal ages silently; surface them as a GridNetwork conditionPossibly taken @shaneutt claimed this today. Opentriage/accepted
praxis-proxy/grid#337 · 1 assignee ·
Maintainers usually reply within 1 day
-
Audit and remove unintended Unicode characters in repository textPossibly taken @shaneutt claimed this today. Opentriage/accepted
praxis-proxy/grid#333 · 1 assignee ·
Maintainers usually reply within 1 day
-
Narrow Deployment RBAC for delegated gateway mount reconciliationPossibly taken @shaneutt claimed this today. Openarea/security priority/high triage/accepted
Difficulty 5/5 Over a week Newbie friendliness 35/100
praxis-proxy/grid#321 · 1 assignee ·
Maintainers usually reply within 1 day
-
triage/needs-triage
Difficulty 4/5 3-5 days Newbie friendliness 42/100
praxis-proxy/grid#320 ·
Maintainers usually reply within 1 day
All issues in praxis-proxy/grid
Similar issues
-
area:docs documentation good first issue priority:low
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
Maintainers usually reply within 1 day
-
triage:accepted
Difficulty 2/5 1-3 hours Newbie friendliness 65/100
open-telemetry/otel-arrow#4343 ·
Maintainers usually reply within 2 days
-
bug
Difficulty 2/5 1-3 hours Newbie friendliness 75/100
mishraprafful/multihull#150 ·
Maintainers usually reply within 1 day
-
bug
Difficulty 2/5 1-3 hours Newbie friendliness 70/100
voidzero-dev/vite-plus#2970 ·
Maintainers usually reply within 1 day
-
ai_p2 comp-parquet-reader-v3
Difficulty 2/5 Half a day Newbie friendliness 66/100
ClickHouse/ClickHouse#124986 ·
Maintainers usually reply within 1 day