Skip to content

fix(opds): cap Argon2 concurrency and bound request pressure - #144

Closed
phildenhoff wants to merge 6 commits into
stack-3-genresfrom
stack-4-packaging
Closed

phildenhoff wants to merge 6 commits into
stack-3-genresfrom
stack-4-packaging

Conversation

@phildenhoff

@phildenhoff phildenhoff commented Sep 17, 2026 •

Copy link
Copy Markdown
Member

Pre-merge review distilled the v1 blockers down to "cap the expensive path, cap the inputs, don't leak the secret." This does that:

  • Argon2 concurrency cap — password verification runs under a 3-permit semaphore; excess requests get 503 + Retry-After without hashing anything, so N parallel wrong passwords can't monopolize the CPU
  • Request bounds — 30s timeout on catalog feeds (asset downloads deliberately untimed — they legitimately run long), 16 KiB request-body limit, and a shared 64-request permit pool answering 503 when saturated
  • No link-local anywhere — the headless server config rejects link-local listener addresses outright, and a test pins advertised URLs to IPv4-first with no fe80:: entries
  • Sharing pane — generated passwords now say they're shown once and travel unencrypted

(One known gap, deliberately deferred: the request guard only engages after headers arrive, so slowloris-style connections aren't bounded yet. Follow-up material.)

Validation

62 crate tests, including new ones for the busy-verifier 503 path, guard exhaustion, feed-timeout vs. untimed assets, format traversal attempts (..%2f etc. → 400), and link-local config rejection. cargo check -p citadel-rs and the frontend suite (216 tests) stay green.

Also lands the packaged-side validation evidence: the signed/notarized nightly smoke test and Linux package checks recorded in docs/opds-validation.md.

@phildenhoff
phildenhoff added this pull request to stack #145 September 17, 2026 18:59
@phildenhoff phildenhoff changed the title stack 4 packaging fix(opds): cap Argon2 concurrency and bound request pressure Sep 17, 2026
@github-actions

Copy link
Copy Markdown

libcalibre Test Coverage Report

Overall coverage: 83.86%

📊 Download HTML Report

Coverage breakdown available in the artifacts.

@github-actions

Copy link
Copy Markdown

libcalibre Test Coverage Report

Overall coverage: 83.86%

📊 Download HTML Report

Coverage breakdown available in the artifacts.

@github-actions

Copy link
Copy Markdown

libcalibre Test Coverage Report

Overall coverage: 83.86%

📊 Download HTML Report

Coverage breakdown available in the artifacts.

@github-actions

Copy link
Copy Markdown

libcalibre Test Coverage Report

Overall coverage: 83.86%

📊 Download HTML Report

Coverage breakdown available in the artifacts.

@github-actions

Copy link
Copy Markdown

libcalibre Test Coverage Report

Overall coverage: 83.86%

📊 Download HTML Report

Coverage breakdown available in the artifacts.

@github-actions

Copy link
Copy Markdown

libcalibre Test Coverage Report

Overall coverage: 83.86%

📊 Download HTML Report

Coverage breakdown available in the artifacts.

@github-actions

Copy link
Copy Markdown

libcalibre Test Coverage Report

Overall coverage: 83.86%

📊 Download HTML Report

Coverage breakdown available in the artifacts.

@github-actions

Copy link
Copy Markdown

libcalibre Test Coverage Report

Overall coverage: 83.86%

📊 Download HTML Report

Coverage breakdown available in the artifacts.

phildenhoff and others added 6 commits September 17, 2026 15:50
Merge-blocking hardening from the v1 review:
- Limit concurrent password verifications to 3 permits; excess requests
  get 503 with Retry-After without hashing or caching the header
- Bound catalog feeds with a 30s timeout, 16KiB request-body limit, and a
  shared 64-request permit pool; asset downloads stay untimed
- Reject link-local explicit listener addresses in the headless server and
  assert advertised URLs are IPv4-first without link-local entries
- Note in the Sharing pane that generated passwords are shown once and
  travel unencrypted
@github-actions

Copy link
Copy Markdown

libcalibre Test Coverage Report

Overall coverage: 83.86%

📊 Download HTML Report

Coverage breakdown available in the artifacts.

@github-actions

Copy link
Copy Markdown

libcalibre Test Coverage Report

Overall coverage: 83.86%

📊 Download HTML Report

Coverage breakdown available in the artifacts.

@phildenhoff

Copy link
Copy Markdown
Member Author

Superseded: the OPDS v1 stack was restructured for reviewability - see stack #156 (#146 → #155). This layer's content is absorbed into the new stack.

@phildenhoff
phildenhoff deleted the stack-4-packaging branch September 23, 2026 16:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant