writeonce/docs/examples/porch/middleware
shoney.arickathil 659ea26582 fix(porch-store): delete the ephemeral nonce row after one read
- The nonce naming an ephemeral (4xx/5xx) row is handed to exactly one
  call() reply and nowhere else -- no other message can ever construct
  that key, so idempotent.wo deleting it right after building the Resp
  is safe by construction (unlike the earlier shared bare-key row,
  which a second message COULD reach and made deleting it racy)
- Closes the leak AND a real correctness edge: the nonce is
  time.ticks() % 1_000_000_000, wrapping every ~1000s -- with rows kept
  forever, a later failed attempt on the same key could land on the
  same nonce and either collide with the unguarded insert or resurface
  a stale replay, exactly what rounds 1/2 removed
- Gate leg 18f: N ephemeral attempts against the same key must return
  IdempotencyKey's row count to baseline, not grow it by N -- confirmed
  failing (baseline+N) against the pre-fix code, passing after
- N picked at 3: the pre-existing runtime hang/segfault (out of scope,
  being tracked separately) reproduces more often at higher sequential
  insert+delete volume against the same key; 3 stayed clean across
  many runs while still proving the property precisely

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
(cherry picked from commit 9ad594748e01a665ccaf29733a48c2b83a2749da)
2026-09-15 01:15:30 +02:00
..
idempotent.wo fix(porch-store): delete the ephemeral nonce row after one read 2026-09-15 01:15:30 +02:00
keypool.wo fix(porch-store): delete the ephemeral nonce row after one read 2026-09-15 01:15:30 +02:00
limiter.wo fix(porch-store): trust_proxy falls back to net.peer on an absent XFF 2026-09-15 01:15:30 +02:00
store.wo feat(porch-store): add digest column to IdempotencyKey table 2026-09-15 01:15:30 +02:00