auth: offload IDENTIFY + SASL PLAIN verify off the engine lock
All checks were successful
CI / check (push) Successful in 3m47s
All checks were successful
CI / check (push) Successful in 3m47s
Both ran scram verify_plain (~1s PBKDF2 at 1.2M iters) inline under the engine lock, freezing the whole daemon per login. Add NetAction::DeferAuthenticate + AuthThen continuation + ctx.defer_authenticate, mirroring DeferPassword: the module/SASL path fetches the verifier cheaply and defers; the link layer runs verify_plain on spawn_blocking, then Engine::complete_authenticate finishes the login (IDENTIFY reuses the same ctx helpers, so its login/AJOIN/vhost/memo side-effects are unchanged). Tests resolve the defer inline (cfg(test)). The gRPC web-login path was already fixed; no login path stalls services now. (GHOST/DROP/CERT/GROUP still verify inline but are rare account ops, not logins.)
This commit is contained in:
parent
63fc2fb2c0
commit
2f9790feac
9 changed files with 144 additions and 36 deletions
|
|
@ -56,8 +56,17 @@ impl Engine {
|
|||
self.stash_sasl(client.clone(), SaslSession::Plain { response });
|
||||
return Vec::new(); // more chunks still to come
|
||||
}
|
||||
match login_plain(&response, &self.db) {
|
||||
Some(account) => self.sasl_login(&agent, &client, account),
|
||||
// Decode, then defer the verify off the lock (the login
|
||||
// finish lands in Engine::complete_authenticate).
|
||||
match decode_plain(&response) {
|
||||
Some((authcid, passwd)) => match self.scram_verifier(&authcid) {
|
||||
Some((account, verifier)) => vec![NetAction::DeferAuthenticate {
|
||||
verifier,
|
||||
password: passwd,
|
||||
then: AuthThen::Sasl { agent: agent.clone(), client: client.clone(), account },
|
||||
}],
|
||||
None => mk("D", vec!["F".to_string()]),
|
||||
},
|
||||
None => mk("D", vec!["F".to_string()]),
|
||||
}
|
||||
}
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue