nerd post ahead...
strfry spawns a noteguard read-policy process for each read thread, so a naive per-IP rate limit actually enforces NΓ the budget. each process has its own counter.
claude came up with a pretty cool fix:
put the token buckets in a shared mmap'd file on /dev/shm.
- open-addressing hash table
- one tiny spinlock per slot (atomic compare-exchange)
- fixed FNV-1a hash so every process maps an IP to the same slot
now N processes share ONE authoritative bucket per IP.
lock-free IPC, no daemon, no redis. just a file and some atomics.
pretty neat!
View quoted note β