Skip to content

Split 2084/4 o1 eviction - #2448

Draft
Effi-S wants to merge 1 commit into
split-2084/3-activationfrom
split-2084/4-o1-eviction
Draft

Effi-S wants to merge 1 commit into
split-2084/3-activationfrom
split-2084/4-o1-eviction

Conversation

@Effi-S

@Effi-S Effi-S commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

The signature-throttle policy (#2440) evicts per-principal/per-bucket state with an O(MaxPrincipals) linear scan on the signature path under a global mutex; once the cap is reached every unseen principal pays two full scans, serialized process-wide — a hard throughput ceiling under the exact pseudonym-flood threat the policy targets. Separately, the gate keys on Identity.UniqueID() with no principal-key resolver installed, so a party rotating pseudonyms is a fresh full quota every request and walks around the per-principal limit.

@Effi-S Effi-S self-assigned this Oct 8, 2026
@Effi-S Effi-S added the security label Oct 8, 2026
@Effi-S
Effi-S marked this pull request as draft October 8, 2026 12:41
@Effi-S
Effi-S changed the base branch from main to split-2084/3-activation October 8, 2026 12:41
@Effi-S
Effi-S added this pull request to stack #2442 October 8, 2026 12:43
Signed-off-by: Effi-S <effi.szt@gmail.com>
@Effi-S
Effi-S force-pushed the split-2084/4-o1-eviction branch from ec016ad to 84dbe99 Compare October 8, 2026 12:46

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant