auth: offload IDENTIFY + SASL PLAIN verify off the engine lock
All checks were successful
CI / check (push) Successful in 3m47s
All checks were successful
CI / check (push) Successful in 3m47s
Both ran scram verify_plain (~1s PBKDF2 at 1.2M iters) inline under the engine lock, freezing the whole daemon per login. Add NetAction::DeferAuthenticate + AuthThen continuation + ctx.defer_authenticate, mirroring DeferPassword: the module/SASL path fetches the verifier cheaply and defers; the link layer runs verify_plain on spawn_blocking, then Engine::complete_authenticate finishes the login (IDENTIFY reuses the same ctx helpers, so its login/AJOIN/vhost/memo side-effects are unchanged). Tests resolve the defer inline (cfg(test)). The gRPC web-login path was already fixed; no login path stalls services now. (GHOST/DROP/CERT/GROUP still verify inline but are rare account ops, not logins.)
This commit is contained in:
parent
63fc2fb2c0
commit
2f9790feac
9 changed files with 144 additions and 36 deletions
|
|
@ -1,4 +1,4 @@
|
|||
// The normalized protocol vocabulary lives in the echo-api SDK crate;
|
||||
// re-exported so the engine keeps referring to it as `crate::proto::*`. The
|
||||
// concrete ircd link (InspIRCd) is an external module crate, not part of core.
|
||||
pub use echo_api::{NetAction, NetEvent, Protocol, RegReply};
|
||||
pub use echo_api::{AuthThen, NetAction, NetEvent, Protocol, RegReply};
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue