pub struct Budget { /* private fields */ }Expand description
One connection’s send and receive allowance, refilling each window.
A RATE, not a lifetime total. The thing worth bounding is a peer flooding the kernel — how fast bytes arrive, and how fast the kernel is asked to produce them. A running total bounds that, but it bounds every legitimate use with it: a subscription is meant to run for days and a blob read moves as many bytes as the blob holds, so under a total both die at a threshold that says nothing about whether they misbehaved.
Exceeding the allowance therefore WAITS rather than failing. “Too fast” is answered by going slower; a connection is only killed when it has done something a slower version of would still be wrong. The one exception is a frame larger than a whole window’s allowance, which no amount of waiting would ever admit — that is a misconfiguration, and it fails loudly instead of hanging forever.
Both directions are charged the FULL frame — prefix, kind byte, and body — because that is what the connection actually costs to move. Charging only the body would let a peer spend the allowance on a million one-byte frames and be told it had used a megabyte.
ponytail: a fixed window, so a peer can spend a full allowance at the end of one and again at the start of the next — a 2x burst across the boundary. For a flood guard that is immaterial; a token bucket if smoothing ever matters.
Implementations§
Trait Implementations§
Auto Trait Implementations§
impl Freeze for Budget
impl RefUnwindSafe for Budget
impl Send for Budget
impl Sync for Budget
impl Unpin for Budget
impl UnsafeUnpin for Budget
impl UnwindSafe for Budget
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
Source§impl<T> Instrument for T
impl<T> Instrument for T
Source§fn instrument(self, span: Span) -> Instrumented<Self>
fn instrument(self, span: Span) -> Instrumented<Self>
Source§fn in_current_span(self) -> Instrumented<Self>
fn in_current_span(self) -> Instrumented<Self>
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self>
fn into_either(self, into_left: bool) -> Either<Self, Self>
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read more