Skip to content

smp-server: limit concurrent name resolutions - #1908

Open
shumvgolove wants to merge 3 commits into
masterfrom
sh/fix-rslv-fanout
Open

shumvgolove wants to merge 3 commits into
masterfrom
sh/fix-rslv-fanout

Conversation

@shumvgolove

@shumvgolove shumvgolove commented Sep 30, 2026 •

Copy link
Copy Markdown
Collaborator

RSLV is unauthenticated, and each RSLV runs an outbound HTTP/TLS request to the resolver. Nothing actually bounded these requests:

  • forkCmd released its concurrency slot when the thread was forked, not when the command finished, so serverResolverConcurrency (and serverClientConcurrency for PFWD) limited nothing.
  • There was no global limit: managerConnCount only sizes the idle pool, so excess requests opened new connections.
  • Error responses were returned without reading the body, so http-client closed the connection and every 5xx cost a new TCP/TLS handshake.

Changes:

  • forkCmd holds the slot until the command completes; the slot is also released if the fork fails.
  • A global limit on concurrent resolver requests (new INI [NAMES] resolver_global_concurrency, default 32, 1-1000), counted within the resolver timeout; the connection pool is sized to it.
  • Error response bodies are read (up to the response size limit), so the connection is reused.
Test Before After
16 RSLVs, per-connection limit 4 16 at the resolver 4
64 RSLVs, global limit 8 64 at the resolver 8
5 lookups answered with 502 5 connections 1

With the limit enforced, a connection that reaches it blocks its own command loop until a slot frees.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant