A flood of wrong passwords stalls every other request #137
Reference in New Issue
Block a user
Delete Branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Found by the load tests (#133) on 2026-10-05. Forty clients sending wrong passwords to /api/login, 54 attempts a second, which needs no account, made everyone else's requests take 4s (median 3.96s for /api/feeds, normally about 20ms), and
ipx status, the healthcheck, took up to 1.3s.login checks the password with Argon2id (19 MiB, two passes: tens of milliseconds of CPU) inside the async handler, on one of the runtime's worker threads, so a handful of attempts at once holds every worker the rest of the server answers on. The LAN port is open to anyone on the network; Cloudflare Access fronts only the tunnel.
Fixed in
f1d3604: auth::check_password runs Argon2 on the blocking pool, at most half the cores at once. Under the load test's flood (40 clients of wrong passwords) everyone else's p95 went from 4.29s to 57ms and the slowest ipx status from 1.3s to 90ms. Deployed 2026-10-05 (0.10.1-dev).