Skip to content

fix: ratelimit crash under concurrent requests - #195

Open
vlnst wants to merge 1 commit into
httpjamesm:mainfrom
vlnst:fix-ratelimit-panic
Open

vlnst wants to merge 1 commit into
httpjamesm:mainfrom
vlnst:fix-ratelimit-panic

Conversation

@vlnst

@vlnst vlnst commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

The rate limiter can crash the whole process when one IP sends several requests at once (for example, a question page with many images loading in parallel).

Cause: the per-IP counter is updated with a separate Load and Store, so simultaneous requests can lose increments. The count then reaches 0 while some 1-minute timers are still pending. One timer deletes the entry, and the next one runs val.(int) on a nil value and panics. The panic happens in a timer goroutine, so gin.Recovery() doesn't catch it and the process exits.

Fix: the timer returns early if the entry is already gone.

Testing: sent bursts of 28 simultaneous requests from one IP and waited for the timers. Before the fix, the server crashed with interface conversion: interface {} is nil, not int. After the fix, it stayed up in every run.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant