Skip to content

feat(egress): track bounded request snapshot lifecycles - #2091

Merged
Pangjiping merged 1 commit into
opensandbox-group:mainfrom
hpliStartAgain:codex/osep0023-request-lifecycle
Sep 30, 2026
Merged

Pangjiping merged 1 commit into
opensandbox-group:mainfrom
hpliStartAgain:codex/osep0023-request-lifecycle

Conversation

@hpliStartAgain

Copy link
Copy Markdown
Contributor

Summary

Related to #1713. Follows #2088.

  • Register an immutable RequestHandle for every successful internal request admission. The result and handle share the same pinned Snapshot, and registration stays under the Registry lock through capacity checking, Receiver acquisition, and index publication.
  • Add a separate, bounded global request budget. The compatibility default is connection capacity; explicit values must be positive integers. Exhaustion denies without waiting or evicting active requests, while invalid-token and fence reasons keep priority.
  • Add exact-identity, idempotent request completion and terminal connection cleanup. Terminal release removes only that connection's requests and now rejects copied or malformed connection tokens. Host removal, Registry deactivation, and Receiver close retain admitted requests until completion or terminal cleanup.
  • Add bounded serial-ordered metadata queries, with connection/revision filters and cursors. Queries return no Snapshot or finish handle, and each page is consistent without promising a frozen cross-page view.
  • Roll back partial registration on ordinary insertion errors, remove empty indexes, and cover the capacity, ownership, lifecycle, rollback, privacy, and concurrency contracts. Update OSEP-0023 progress.

These remain unused internal primitives. A future adapter must finish every request on completion, cancellation, and error, and call connection release only after confirmed transport termination. Bookkeeping counts and empty query pages do not prove network drain or credential zeroization. This change adds no live hooks, joint publication, mutation ACK, drain timer, socket closure, or HTTP/2 GOAWAY. #1759's destination-identity hardening remains a prerequisite for live activation.

Testing

Validation environment: Python 3.12.14.

  • Registry suite: 51 tests passed, including 18 new tests.
  • Receiver suite: 18 tests passed.
  • Registry/classifier suites in both import orders: 63 tests passed in each order.
  • 800 concurrency test executions across 100 iterations, including last-slot races, duplicate finish, finish/release ordering, capacity reuse, and lock-protected registration.
  • RED regressions exposed the missing request budget and the previous copied-token release behavior before implementation.
  • python3 -m compileall -q mitmscripts/tls_registry.py, git diff --check, and ./scripts/verify-license.sh ..
  • Separate read-only review found no blocking issue. Verified the live addon has no import or call of the new primitives.
  • Full Python egress suite is not a complete pass: 214 tests discovered, 190 passed, 16 skipped because mitmdump is absent, and 8 Unix-socket-dependent tests errored because this environment prohibits Unix socket creation (EPERM). The clean base has the identical 16 skips and 8 error cases among its 196 tests.
  • Live mitmproxy/e2e, Go suites, drain, and GOAWAY verification were not run for this isolated Python foundation.

Breaking Changes

No public API or live-traffic change. The internal connection release contract is tightened to exact token identity, and each successful internal request admission now consumes a bounded record until request completion or terminal connection release.

Checklist

  • Linked Issue and clearly described motivation
  • Updated OSEP implementation progress
  • Added regression and concurrency tests
  • Security impact considered
  • Backward compatibility considered

@github-actions github-actions Bot added component/egress documentation Improvements or additions to documentation size/L Denotes a PR that changes 100-499 lines, ignoring generated files. labels Sep 30, 2026

@Pangjiping Pangjiping left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@Pangjiping
Pangjiping merged commit 2d23940 into opensandbox-group:main Sep 30, 2026
55 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

component/egress documentation Improvements or additions to documentation size/L Denotes a PR that changes 100-499 lines, ignoring generated files.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants