fix(security): cluster auth tracker saturation DoS (#185) - #186
Draft
cursor[bot] wants to merge 4 commits into
Draft
fix(security): cluster auth tracker saturation DoS (#185)#186cursor[bot] wants to merge 4 commits into
cursor[bot] wants to merge 4 commits into
Conversation
The per-IP cluster auth lockout added in #182 rejected every new source IP once the 10k-entry failure map filled, even for peers presenting a valid CLUSTER_SECRET. Mirror the HTTP rate limiter: LRU-evict only non-throttled buckets and fail closed solely when every entry is actively throttled. Fixes #185. Co-authored-by: Alexander Wagner <info@alexanderwagnerdev.com>
* fix(ci): apply rustfmt to cluster auth throttle helper Co-authored-by: Alexander Wagner <info@alexanderwagnerdev.com> * Update Cargo.lock --------- Co-authored-by: Cursor Agent <cursoragent@cursor.com> Co-authored-by: Alexander Wagner <info@alexanderwagnerdev.com> Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Security fix — Medium
Issue: #185
Location:
src/cluster/security.rsImpact: An unauthenticated attacker who fills the 10k-entry cluster auth failure map (one failed handshake per source IP) could block all new peer IPs from completing control/media auth—even with a valid
CLUSTER_SECRET—until entries aged out.Fix: Mirror the HTTP rate limiter eviction strategy from #36:
Tests: Added unit coverage for eligible-bucket eviction and fail-closed when every bucket is throttled.
Closes #185.