Skip to content

Add outcome-aware attempts and durable PostgreSQL GCRA - #9

Merged
featherenvy merged 7 commits into
masterfrom
feat/auth-attempts-gcra
Sep 21, 2026
Merged

featherenvy merged 7 commits into
masterfrom
feat/auth-attempts-gcra

Conversation

@featherenvy

@featherenvy featherenvy commented Sep 21, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • Add opt-in outcome-aware authentication attempts: consecutive failures, capped escalating delay, quiet reset, bounded leases, opaque consuming receipts and separate observations.
  • Add hard-bounded memory/PostgreSQL stores and transaction-scoped claim/finalization so an application can commit retry state and authentication/audit writes together.
  • Add durable PostgreSQL GCRA with shared memory evaluator, atomic multi-key admission, monotonic database-clock watermarks and bounded cleanup.
  • Preserve existing quota workflows, exhaustive enums, no-refund accounting and published migrations. New stores have separate opt-in migrations.

Ownership and compatibility

Runlimit owns storage, algorithms, locks, bounds and maintenance. Consumers own identity normalization, credentials, audit schemas, policy values and transport responses. Batter's companion PR owns the protected authentication sequence. No production rollout or merges are part of this change.

These additions are additive against the base 77890cdb9ce116cf5da9bb42b8737c6d762a17b7. Consumers on older native type APIs must migrate that earlier independent hard cut. Active storage is never evicted to make room; ambiguous database completion never authorizes replay.

Validation

  • Workspace tests, formatting and all-target/all-feature Clippy with warnings denied.
  • PostgreSQL 18.6: 17 attempt, 20 GCRA and 32 existing fixed-window live cases.
  • Packaged external-consumer smoke on Rust 1.94.0, including unchanged quota usage and new API compilation.
  • Native Codex review over the fixed original base through every fix commit. First-round fixes cover cleanup clock monotonicity, lowered-cap occupancy/reclamation and malformed-response classification.

Further fixes invalidate claims after savepoint rollback, give memory completion
an operation-specific error, and reclaim logically expired GCRA counters under
clock regression using a forward-only maintenance index migration.

Final native review reported no findings over
77890cdb9ce116cf5da9bb42b8737c6d762a17b7..bf3c5cd1ba3e96f55ca4c635d79bab9b35e8978d.
All six findings were fixed with regressions; none was rejected or escalated.
The companion adapter is Batter PR #3.
No merge or publication is requested by this delivery.

@featherenvy

Copy link
Copy Markdown
Contributor Author

Reconciled with master 62036e9 via merge commit c335806 (no history rewrite). The eight upstream commits contain dependency/action updates; the merge required no source-conflict resolution. Updated action-version comments to match their pins.

Validation: default/all-feature workspace tests and Clippy, formatting, Rust 1.94 check, packaged consumer smoke, and all 69 PostgreSQL cases under both feature configurations passed. All substantive hosted CI checks are green. Native Codex review over the unchanged original base 77890cd..c335806 reported no actionable findings; builds were validated separately from the read-only review.

GitHub now reports zero commits behind master. No PR merge or release performed.

@featherenvy

Copy link
Copy Markdown
Contributor Author

Addressed the user-reported P2 cleanup access-pattern finding in 904abcf.

The exact production DELETE now uses the same MATERIALIZED authoritative-time CTE plus scalar init-plan cutoff as fixed-window cleanup. It still runs after the shard advisory lock; the later post-row-lock admission/lease clock sample is unchanged. No migration, public API, or limiter-policy change.

Added dense_shard_cleanup_uses_expiry_as_an_index_condition: 65,536 rows in one shard, zero then three expired, EXPLAIN (ANALYZE, BUFFERS), default planner settings, exact production SQL. It fails on the old query: expiry is a Filter removing 65,536 active rows, 1,245 shared-buffer hits. With the fix: expiry is Index Cond, no active-row filter, two shared-buffer hits with zero expired; three-expired case also passes (26 total shared-buffer hits). These are local PostgreSQL 18 fixture measurements, not a production throughput claim.

All 70 PostgreSQL cases pass with default/all features (18 attempts, 20 GCRA, 32 existing fixed-window), as do workspace all-feature tests, Clippy, formatting and the Rust 1.94 packaged-consumer smoke. Native review over the original pinned base and hosted CI are running.

@featherenvy

Copy link
Copy Markdown
Contributor Author

Final check at 904abcf: all five substantive hosted CI jobs are green, including PostgreSQL integration with the dense-shard regression. Native Codex review over 77890cd..904abcf reports no actionable regressions. The user-reported P2 is fixed; no migration, API, or policy change was needed. Branch remains zero commits behind master. Downstream Batter PR #3 now pins this revision.

@featherenvy
featherenvy merged commit 12e035d into master Sep 21, 2026
6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant