Hacktoberfest 2026: những issue maintainer đã đánh dấu cho tháng Mười, đang mở và phù hợp người mới. Xem issue Hacktoberfest

Priority: P1 — revenue-leak + metering-loss class: all enforcement state is process-memory.

Đang mở
#499 0 bình luận 0 reaction 0 người được giao Xem trên GitHub

Maintainer thường phản hồi trong vòng 1 ngày

Chưa có ai nhận issue này.

Đánh giá

Độ khó
5/5
Thời gian dự kiến
Hơn một tuần
Mức phù hợp với người mới
25/100
Loại issue
Tính năng
Độ rõ ràng
Khá rõ ràng
Mức độ hoạt động
Sôi nổi
Công nghệ
go
Lĩnh vực
backend

Hướng nghiên cứu

Start by reading src/merchant/merchant.go, src/valve/valve.go, src/valve/customer_data_tracker.go, and startup in main.go or merchant initialization to trace session grants, metering, and deauthentication. Confirm the persistence and metering-reconciliation design with the maintainer before implementing. Done means the required round-trip and reconciliation tests pass, with restart tests demonstrating paid access is restored or safely deauthorized as specified.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Mô tả

Priority: P1 — revenue-leak + metering-loss class: all enforcement state is process-memory.

Problem

customerSessions, gate deauth time.Timers (openGates), and data baselines are in-memory only. After any restart (crash, upgrade, service restart, power cut):

  • time-metered customers keep access forever (the deauth timer died with the process; NDS still holds them authenticated until its own session timeout),
  • bytes-metered customers keep access unmetered (no session → checkDataUsage skips them; baseline gone),
  • remaining paid allotments are forgotten (customers lose paid value on the "remaining" side while the gate stays open — worst of both).

Why it matters

Every restart converts all active paid sessions into free unlimited access (revenue leak) while erasing what customers paid for (value leak). Routers reboot — power cuts, upgrades, OOM — so this is not hypothetical. Lightning quotes are deliberately persisted (quote_store.go) because payment recognition had to survive restarts; sessions need the same treatment.

Current behavior (source refs)

  • src/merchant/merchant.go:73 (customerSessions map), :1112-1173 (access/restore in-memory only).
  • src/valve/valve.go:82-86 (openGates, pendingUntil maps), :222-249 (in-process deauth timer).
  • src/valve/customer_data_tracker.go:20-24 (in-memory baselines).
  • checkDataUsage (merchant.go:249-304) iterates only in-memory sessions.

Desired invariant

Paid access converges to paid state after restart: unexpired paid sessions are re-armed (gate + metering + deauth deadline), expired/unknown clients are deauthorized, and remaining allotment is preserved or explicitly reconciled.

Proposed scope (design-then-implement; pick with maintainer)

  1. Persist sessions on grant (durable before/at gate-open; fsync'd JSONL or bbolt) — remaining allotment, metric, start, expiry, and bytes-baseline snapshot.
  2. Startup reconciliation: load sessions → re-arm timers/baselines → ndsctl deauth for authenticated clients without a valid session (safe direction: close unknowns).
  3. Metering survival: persist used periodically (debounced) — the debatable part; alternative: on restart, re-baseline from NDS counters and subtract persisted used-at-grant (design doc must choose; RAM/flash tradeoffs on 8 MB devices).
  4. Crash-safe writes: tmp+rename, no per-packet fsync.

Areas / files

src/merchant/merchant.go, src/valve/valve.go, src/valve/customer_data_tracker.go, startup in main.go/merchant init.

Acceptance criteria

  • Restart with active time session (T remaining) → client deauthed within bounded grace at T, not before.
  • Restart with active bytes session (B remaining, N used) → client cut off at approximately N+B total (documented tolerance), not at reboot.
  • Restart with expired/NDS-unknown sessions → deauth attempted, no stale access.

Required tests

  • Unit: persistence round-trip; reconciliation decision table.
  • Integration (cloud-lab / PRTA): restart-mid-session lane for both metrics; NDS-unknown-client deauth lane.

Failure-injection tests

  • SIGKILL + restart at: grant, mid-session, after-expiry.
  • Power-cut simulation (PRTA smart-plug lane) with active sessions.
  • Corrupt sessions file → fail safe (deauth all, log loudly) not fail open.

Compatibility

On-disk addition only; NDS behavior unchanged.

Dependencies

None (independent of wallet work).

Out of scope

  • Cross-reboot usage reporting precision beyond documented tolerance.
Ngôn ngữ chính
Go
Star
12
Fork
14
Merge trung bình
1 ngày 5 giờ
Pull request đã merge (30 ngày)
220

Chuẩn bị môi trường

Bắt đầu từ đâu

  1. Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
  2. Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
  3. Fork repository và làm thay đổi trên một nhánh.
  4. Mở pull request có tham chiếu số hiệu của issue.

Issue khác của OpenTollGate/tollgate-module-basic-go

Tất cả issue của OpenTollGate/tollgate-module-basic-go

Issue tương tự

Thêm issue về Go

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.