fix(runner): avoid data race by retaining rate limiter pointer (#2653) - #2656
TassioSales wants to merge 1 commit into
Conversation
…ctdiscovery#2653) - Store ratelimiter as *ratelimit.Limiter pointer in Runner struct instead of copying the struct value - Retain constructor pointer directly in New() without dereferencing, avoiding concurrent race with the limiter's atomic replenishment goroutine - Add nil-safe check in Close() and add unit test TestRunner_RateLimiterInitialization covering all rate limit modes
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (2)
Included review availability: This review used your included allowance. Your plan provides up to 10 included reviews per hour; 9 remain after this review. WalkthroughThe runner now stores the rate-limiter pointer returned by its constructor. Shutdown stops the limiter only when the pointer is non-nil. Tests cover default, per-second, and per-minute configurations. ChangesRunner rate-limiter handling
Priority: ⬇️ Low Estimated code review effort: 2 (Simple) | ~10 minutes Change: Bug fix Suggested reviewers: Merge Risk: ⚪ Minimal · up to The runner retains its initialized rate limiter and stops it during shutdown. No merge-blocking behavior is established by the supplied review context. Security Architecture ReviewSecurity architecture risk: ⚪ Minimal · up to The change preserves the rate limiter’s identity instead of copying its mutable state. Existing rate settings, request throttling, public interfaces, and endpoint exposure remain unchanged. No material security risk introduced or worsened by this PR was identified. Retained concerns Security review detailsSecurity Blast Radius
Trust Boundaries and Controls
Resilience and Maintainability Implications
Hardening Proposals
🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
A rabbit checks the limiter’s pace, Comment |
Proposed changes
Closes #2653
Fixes a data race during runner initialization where
runner.Newwas dereferencing and copying theratelimit.Limiterreturned by its constructor into a value field onRunner. Because the limiter's constructor starts a background goroutine (run()) that concurrently writes to atomic token counters, copying the struct by value races with that goroutine.Changes
Runner.ratelimiterfield fromratelimit.Limiterto*ratelimit.Limiter.runner.New()across all rate limit branches (RateLimitMinute,RateLimit,NewUnlimited) without dereferencing.Close()before callingr.ratelimiter.Stop().TestRunner_RateLimiterInitializationcovering all rate limit modes.Proof
Checklist
Summary by CodeRabbit