Priority: P1 — revenue-leak + metering-loss class: all enforcement state is process-memory.
Maintainer thường phản hồi trong vòng 1 ngày
Chưa có ai nhận issue này.
Đánh giá
- Độ khó
- 5/5
- Thời gian dự kiến
- Hơn một tuần
- Mức phù hợp với người mới
- 25/100
Hướng nghiên cứu
Start by reading src/merchant/merchant.go, src/valve/valve.go, src/valve/customer_data_tracker.go, and startup in main.go or merchant initialization to trace session grants, metering, and deauthentication. Confirm the persistence and metering-reconciliation design with the maintainer before implementing. Done means the required round-trip and reconciliation tests pass, with restart tests demonstrating paid access is restored or safely deauthorized as specified.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
Priority: P1 — revenue-leak + metering-loss class: all enforcement state is process-memory.
Problem
customerSessions, gate deauth time.Timers (openGates), and data baselines are in-memory only. After any restart (crash, upgrade, service restart, power cut):
- time-metered customers keep access forever (the deauth timer died with the process; NDS still holds them authenticated until its own session timeout),
- bytes-metered customers keep access unmetered (no session →
checkDataUsageskips them; baseline gone), - remaining paid allotments are forgotten (customers lose paid value on the "remaining" side while the gate stays open — worst of both).
Why it matters
Every restart converts all active paid sessions into free unlimited access (revenue leak) while erasing what customers paid for (value leak). Routers reboot — power cuts, upgrades, OOM — so this is not hypothetical. Lightning quotes are deliberately persisted (quote_store.go) because payment recognition had to survive restarts; sessions need the same treatment.
Current behavior (source refs)
src/merchant/merchant.go:73(customerSessionsmap),:1112-1173(access/restore in-memory only).src/valve/valve.go:82-86(openGates,pendingUntilmaps),:222-249(in-process deauth timer).src/valve/customer_data_tracker.go:20-24(in-memory baselines).checkDataUsage(merchant.go:249-304) iterates only in-memory sessions.
Desired invariant
Paid access converges to paid state after restart: unexpired paid sessions are re-armed (gate + metering + deauth deadline), expired/unknown clients are deauthorized, and remaining allotment is preserved or explicitly reconciled.
Proposed scope (design-then-implement; pick with maintainer)
- Persist sessions on grant (durable before/at gate-open; fsync'd JSONL or bbolt) — remaining allotment, metric, start, expiry, and bytes-baseline snapshot.
- Startup reconciliation: load sessions → re-arm timers/baselines →
ndsctldeauth for authenticated clients without a valid session (safe direction: close unknowns). - Metering survival: persist
usedperiodically (debounced) — the debatable part; alternative: on restart, re-baseline from NDS counters and subtract persistedused-at-grant(design doc must choose; RAM/flash tradeoffs on 8 MB devices). - Crash-safe writes: tmp+rename, no per-packet fsync.
Areas / files
src/merchant/merchant.go, src/valve/valve.go, src/valve/customer_data_tracker.go, startup in main.go/merchant init.
Acceptance criteria
- Restart with active time session (T remaining) → client deauthed within bounded grace at T, not before.
- Restart with active bytes session (B remaining, N used) → client cut off at approximately N+B total (documented tolerance), not at reboot.
- Restart with expired/NDS-unknown sessions → deauth attempted, no stale access.
Required tests
- Unit: persistence round-trip; reconciliation decision table.
- Integration (cloud-lab / PRTA): restart-mid-session lane for both metrics; NDS-unknown-client deauth lane.
Failure-injection tests
- SIGKILL + restart at: grant, mid-session, after-expiry.
- Power-cut simulation (PRTA smart-plug lane) with active sessions.
- Corrupt sessions file → fail safe (deauth all, log loudly) not fail open.
Compatibility
On-disk addition only; NDS behavior unchanged.
Dependencies
None (independent of wallet work).
Out of scope
- Cross-reboot usage reporting precision beyond documented tolerance.
- Ngôn ngữ chính
- Go
- Star
- 12
- Fork
- 14
- Merge trung bình
- 1 ngày 5 giờ
- Pull request đã merge (30 ngày)
- 220
Chuẩn bị môi trường
- Không có Dockerfile hay tệp Docker Compose
- Không có mẫu pull request
- Đọc hướng dẫn đóng góp
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của OpenTollGate/tollgate-module-basic-go
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 68/100
OpenTollGate/tollgate-module-basic-go#833 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
merchant: TestPurchaseSessionGuardHoldsThroughTheOutcomeUnknownWindow fails deterministically without ndsctl on PATH — harness installs no fake (needs installRenewalNdsctl)Có thể đã có người làm Có pull request liên kết đang mở hoặc đã được merge. Đang mở
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 72/100
OpenTollGate/tollgate-module-basic-go#822 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 65/100
OpenTollGate/tollgate-module-basic-go#813 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 70/100
OpenTollGate/tollgate-module-basic-go#804 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
go-battery needs an ndsctl on PATH: TestPurchaseSessionGuardHoldsThroughTheOutcomeUnknownWindow fails on bare hosts (passes with stub)Có thể đã có người làm @Amperstrand đã nhận 2 ngày trước. Đang mở
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 78/100
OpenTollGate/tollgate-module-basic-go#726 · 2 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
Tất cả issue của OpenTollGate/tollgate-module-basic-go
Issue tương tự
-
raised-by:worker
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 68/100
medici-finance/assay#2486 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 78/100
openimsdk/openim-sdk-core#1127 ·
-
github_actions
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 65/100
Hochfrequenz/aibap.mcp#578 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 85/100
mvanhorn/cli-printing-press#4980 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 62/100
lenaxia/LLMSafeSpaces#1644 · 3 bình luận · 1 reaction ·
Maintainer thường phản hồi trong vòng 1 ngày