Files
fips/src
Johnathan Corgan 65321617ae Evict from the lookup dedup cache instead of refusing the request
The discovery dedup cache is also the reverse-path table for responses in
flight, and at its 4096-entry bound it dropped the arriving request. That
drop sat ahead of both the check for whether the request names this node
and the forwarding path, so one link peer emitting fresh request_ids could
stop the node answering lookups for itself and stop it carrying anyone
else's, for as long as it kept the cache full.

Make room instead of refusing. An arrival-order index partitioned by the
link peer the request came from says who pays: a peer over its own share
loses its oldest entry, and at global capacity the peer holding the most
entries loses its oldest. A light peer's reverse path is therefore never
taken to admit a heavy one, and extra identities buy a flooder
proportionally less. A share is the cache divided by the current link-peer
count with a floor of 64, so it tracks the peer count rather than being
pinned to a number a many-peer node outgrows. The loosening this accepts
is that an evicted request_id arriving again inside the window is
forwarded a second time rather than recognised as a duplicate; the
per-target forward limiter and TTL already bound that.

Meter answering lookups for ourselves per link peer, in the same change,
because the cache filling up was the only thing bounding it. The response
proof is signed over the requester's request_id, so every request
addressed to this node costs a fresh Schnorr signature that cannot be
cached or served twice. A token bucket of 256 signatures refilling at 32
per second per link peer absorbs the legitimate burst that follows a
topology change, when many correspondents re-look-up at once through the
few links that lead here, while capping what one neighbour can make the
node sign. A refused request keeps its dedup entry, and retries carry
fresh request_ids, so a refusal cannot suppress the retry.

Evictions count as req_dedup_evicted and signing refusals as
req_sign_rate_limited, both in show routing, show metrics and the fipstop
routing pane. The old req_dedup_cache_full counter stays in place, frozen
at zero, so a dashboard carried across versions does not lose the series.
2026-08-23 11:46:53 +01:00
..