mirror of
https://github.com/jmcorgan/fips.git
synced 2026-10-06 11:38:24 +00:00
The discovery dedup cache is also the reverse-path table for responses in flight, and at its 4096-entry bound it dropped the arriving request. That drop sat ahead of both the check for whether the request names this node and the forwarding path, so one link peer emitting fresh request_ids could stop the node answering lookups for itself and stop it carrying anyone else's, for as long as it kept the cache full. Make room instead of refusing. An arrival-order index partitioned by the link peer the request came from says who pays: a peer over its own share loses its oldest entry, and at global capacity the peer holding the most entries loses its oldest. A light peer's reverse path is therefore never taken to admit a heavy one, and extra identities buy a flooder proportionally less. A share is the cache divided by the current link-peer count with a floor of 64, so it tracks the peer count rather than being pinned to a number a many-peer node outgrows. The loosening this accepts is that an evicted request_id arriving again inside the window is forwarded a second time rather than recognised as a duplicate; the per-target forward limiter and TTL already bound that. Meter answering lookups for ourselves per link peer, in the same change, because the cache filling up was the only thing bounding it. The response proof is signed over the requester's request_id, so every request addressed to this node costs a fresh Schnorr signature that cannot be cached or served twice. A token bucket of 256 signatures refilling at 32 per second per link peer absorbs the legitimate burst that follows a topology change, when many correspondents re-look-up at once through the few links that lead here, while capping what one neighbour can make the node sign. A refused request keeps its dedup entry, and retries carry fresh request_ids, so a refusal cannot suppress the retry. Evictions count as req_dedup_evicted and signing refusals as req_sign_rate_limited, both in show routing, show metrics and the fipstop routing pane. The old req_dedup_cache_full counter stays in place, frozen at zero, so a dashboard carried across versions does not lose the series.