|
| 1 | +namespace KeyLoad.Core; |
| 2 | + |
| 3 | +public sealed class CommandAdmissionGovernor |
| 4 | +{ |
| 5 | + private readonly object gate = new(); |
| 6 | + private readonly Dictionary<(bool Control, string Id), int> tenants = []; |
| 7 | + private readonly Dictionary<(bool Control, string Id), int> principals = []; |
| 8 | + private int commands, controlCommands; |
| 9 | + private long retainedBytes, controlRetainedBytes; |
| 10 | + public CommandAdmissionLimits Limits { get; } |
| 11 | + public CommandAdmissionGovernor(CommandAdmissionLimits? limits = null) |
| 12 | + { |
| 13 | + Limits = limits ?? new(); Limits.Validate(); |
| 14 | + } |
| 15 | + public static bool IsControl(OperationKind kind) |
| 16 | + => kind is OperationKind.Delivery or OperationKind.SubscriptionDelivery or OperationKind.Membership or OperationKind.SetDispatch; |
| 17 | + public Lease Reserve(OperationKind kind, PrincipalRecord principal, int payloadBytes, int payloadCharacters, |
| 18 | + CancellationToken cancellationToken = default) |
| 19 | + { |
| 20 | + cancellationToken.ThrowIfCancellationRequested(); |
| 21 | + if (payloadBytes < 0 || payloadCharacters < 0) |
| 22 | + throw new ArgumentOutOfRangeException(nameof(payloadBytes)); |
| 23 | + // JSON embedded in the Raft envelope escapes quotes/backslashes again; reserve two UTF-8 copies. |
| 24 | + var bytes = checked(payloadCharacters * 2L + payloadBytes * 2L + 4_096); |
| 25 | + var control = IsControl(kind); |
| 26 | + if (control && payloadBytes > Limits.MaxControlPayloadBytes) |
| 27 | + throw Errors.Fail(ErrorCode.ResourceExhausted, "The control command exceeds its reserved byte budget."); |
| 28 | + var tenantKey = (control, principal.TenantId); var principalKey = (control, principal.Id); |
| 29 | + lock (gate) |
| 30 | + { |
| 31 | + cancellationToken.ThrowIfCancellationRequested(); |
| 32 | + var count = control ? controlCommands : commands; |
| 33 | + var used = control ? controlRetainedBytes : retainedBytes; |
| 34 | + var maxCount = control ? Limits.ReservedControlCommands : Limits.MaxCommands; |
| 35 | + var maxBytes = control ? Limits.ReservedControlBytes : Limits.MaxRetainedBytes; |
| 36 | + var maxTenant = control ? Limits.MaxTenantControlCommands : Limits.MaxTenantCommands; |
| 37 | + var maxPrincipal = control ? Limits.MaxPrincipalControlCommands : Limits.MaxPrincipalCommands; |
| 38 | + var tenantCount = tenants.GetValueOrDefault(tenantKey); var principalCount = principals.GetValueOrDefault(principalKey); |
| 39 | + if (count >= maxCount || bytes > maxBytes - used || tenantCount >= maxTenant || principalCount >= maxPrincipal) |
| 40 | + throw Errors.Fail(ErrorCode.ResourceExhausted, "The node, tenant or principal command admission budget is exhausted."); |
| 41 | + if (control) { controlCommands++; controlRetainedBytes += bytes; } |
| 42 | + else { commands++; retainedBytes += bytes; } |
| 43 | + tenants[tenantKey] = tenantCount + 1; principals[principalKey] = principalCount + 1; |
| 44 | + return new(this, control, principal.TenantId, principal.Id, bytes); |
| 45 | + } |
| 46 | + } |
| 47 | + public CommandAdmissionSnapshot Snapshot() |
| 48 | + { |
| 49 | + lock (gate) return new(commands, retainedBytes, controlCommands, controlRetainedBytes, tenants.Count, principals.Count); |
| 50 | + } |
| 51 | + private void Release(Lease lease) |
| 52 | + { |
| 53 | + lock (gate) |
| 54 | + { |
| 55 | + if (lease.Released) return; |
| 56 | + lease.Released = true; |
| 57 | + if (lease.Control) { controlCommands--; controlRetainedBytes -= lease.Bytes; } |
| 58 | + else { commands--; retainedBytes -= lease.Bytes; } |
| 59 | + Decrement(tenants, (lease.Control, lease.Tenant)); Decrement(principals, (lease.Control, lease.Principal)); |
| 60 | + } |
| 61 | + } |
| 62 | + private static void Decrement(Dictionary<(bool Control, string Id), int> scopes, (bool Control, string Id) key) |
| 63 | + { |
| 64 | + if (scopes[key] == 1) scopes.Remove(key); else scopes[key]--; |
| 65 | + } |
| 66 | + public sealed class Lease : IDisposable |
| 67 | + { |
| 68 | + private readonly CommandAdmissionGovernor owner; |
| 69 | + internal bool Control { get; } |
| 70 | + internal string Tenant { get; } |
| 71 | + internal string Principal { get; } |
| 72 | + internal long Bytes { get; } |
| 73 | + internal bool Released { get; set; } |
| 74 | + internal Lease(CommandAdmissionGovernor owner, bool control, string tenant, string principal, long bytes) |
| 75 | + { this.owner = owner; Control = control; Tenant = tenant; Principal = principal; Bytes = bytes; } |
| 76 | + public void Dispose() => owner.Release(this); |
| 77 | + } |
| 78 | +} |
0 commit comments