FA-73713 / Rate limiter algorithms / Member archive
Distributed limiter with leased quota chunks: exhausted lease never refetched · case 03
A node that used up its first chunk denies everything for the rest of the window although quota remains.
Case contract
Input {quota, window_s, chunk, events [[t, node, "req"|"return"]]} with nondecreasing t. Each epoch window starts with the full global quota and voids all node leases. A node with an empty lease fetches min(chunk, remaining) from the coordinator; each request spends one leased unit or is denied when none is available. "return" credits the node's unused lease back and reports the new remaining. Return [results, remaining, sorted [node, lease]].
Why this case matters
Large-scale limiters hand out quota in chunks to avoid a coordinator round trip per request; lease accounting errors oversubscribe the global limit or strand quota.
One recorded failure
Sample boundary fixtureThis sample comes from the broken implementation of a controlled reproducer.
| Boundary fixture | Actual | Expected | Outcome |
|---|---|---|---|
| partial last chunk | [["allow", "allow", "allow", "deny", "allow", "allow", "allow", "deny", "allow"], 0, [["a", 0], ["b", 0], ["c", 0]]] | [["allow", "allow", "allow", "allow", "allow", "deny", "deny", "deny", "deny"], 0, [["a", 2], ["b", 0], ["c", 0]]] | Failed |
MEMBER ARCHIVE
The complete case is available to members.
This record includes three runnable implementations, regression fixtures, execution results, and source hashes.
Member access is invitation-based. Sign in with your invited account to inspect the sources.
Sign in to the archive ↗