docs: document daemon per-module/per-host caps and shared auth lockout

This commit is contained in:
2026-09-13 10:24:09 +02:00
parent 4c17122b00
commit e1f8f75e7c
3 changed files with 28 additions and 7 deletions
+12
View File
@@ -4,6 +4,18 @@ All notable changes to FastSync are documented here. Versions match
`PROTOCOL_VERSION` (printed by `fastsync --version`); the client and server must
run the same version because the handshake is strict.
## [Unreleased]
### Security
- Enforce the daemon's per-module `max connections` cap and add a global
`max connections per host` cap plus a cross-process `auth lockout`
(`auth lockout threshold` / `auth lockout duration`). Because the listener
forks one child per connection, the counters live in an anonymous shared
mapping created before the accept loop and reclaimed by the parent's
`SIGCHLD` handler, so the per-module, per-source and auth-failure state is
shared across every child (including after `SIGKILL`).
## [2.20.0] - 2026-09-13
### Security