Expand description
Concurrent-subscriber caps (§F4, §12).
Two bounded counts:
- Global: total live subscribers across all clients.
- Per-IP: live subscribers per client IP, a defense against a single misbehaving peer exhausting the global budget.
A single std::sync::Mutex is fine — acquisition happens once per
connection (a rare event compared to per-message work) and holds for a
few tens of nanoseconds. Avoids pulling dashmap for the single map we
need, and keeps the whole module auditable at a glance.
A permit is returned as an RAII guard; dropping it (on connection end or on rejection) releases the slots. If both global and per-IP slots are available, the acquisition is atomic — never leave the counters in a state where one was incremented but the other was rejected.