Network policy: throttle on terminal 429 and make the sync loop / send queue defer to §5 after retry exhaustion (CR-4) #134
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Review finding 2026-08-27 (A1).
NetworkPolicy.kt:113-117throwsRateLimited(serverDelay)aftermaxAttemptswithout callingthrottle();SyncLoop.kt:109-113then sleeps a fixedbackoffOnError(5 s) andSendQueue.kt:54a fixedretryDelay(3 s), ignoring the surfacedretryAfter. ARetry-Afterlonger than the fixed delay is violated on the next request. The CR-4 storm test drivespolicy.executedirectly, andFleetFairnessGateTest/EncryptedPuppetingGateTestassertpolitenessViolations.isEmpty()without ever enablingstrictRateLimit(vacuous).Acceptance (§5, §10.3.4, §10.5.2, CR-4, NFR-6):
RateLimited.retryAfter(server delay always beats the fixed/computed delay) and otherwise use the §5 per-class backoff, not private timers;SessionCrypto.kt:201-215own attempt counter reviewed against the same rule;KatrixSession(sync + send + media +/keys/query//keys/claim) and through anAppserviceFleetwithstrictRateLimitenabled, asserting zero politeness violations;cr4_serverDelayBindsSyncLoopexercises the realSyncLoop.