Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

grid-signals: MAX_PROVIDERS global cap can lock out providers (add per-site cap + stale eviction)

Open
#195 0 comments 0 reactions 0 assignees View on GitHub

Maintainers usually reply within 1 day

Nobody has claimed this yet.

Assessment

Difficulty
4/5
Estimated time
3-5 days
Newbie friendliness
48/100
Issue type
Feature
Clarity
Mostly clear
Activity status
Active
Tech stack
rust

Research direction

Start in the grid-signals crate's signals.rs ingest path and review the #160 line-65 comment referenced in the issue. Work out how per-site and global caps, retention-based eviction and idle pruning should interact; done means the cap behavior is bounded and dropped lines are diagnosable, with the memory bound documented and relevant tests passing.

Written by the indexing model from the issue text.

Description

triage/accepted

MAX_PROVIDERS in the grid-signals store is a global, never-evicted cap (currently 4096). Once that many distinct site/provider keys are seen, new legitimate providers are silently rejected until restart. A peer that controls the grid_provider label can consume the slots with distinct values and lock out later providers, and 4096 entries fit within the request limit.

Raised in the #160 review and the pre-merge security review. Not exploitable today because the ingest source is the authenticated operator relay, so this is defense-in-depth / availability hardening, not a merge blocker for #160.

Proposed:

  • Per-site cap so one site cannot exhaust the pool, alongside or instead of the global cap.
  • Evict keys whose newest sample is older than the retention window before rejecting a new one.
  • Prune series idle beyond the window (the idle-pruning half of the #160 line-65 comment).
  • Count or log dropped lines (cap hits, parse failures, future timestamps) so lockouts are diagnosable.
  • Document the resulting worst-case memory bound alongside the count caps.

Scope: the grid-signals crate ingest path (signals.rs).

Dominant language
Rust
Stars
10
Forks
24
Avg merge
1d 8h
Merged PRs (30d)
86

Getting set up

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from praxis-proxy/grid

All issues in praxis-proxy/grid

Similar issues

More Rust issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.