Skip to main content

Module pool

Module pool 

Source
Expand description

Credential identity and pool lifecycle (Phase 2 of the hardening plan).

Pool identity is never a raw or unkeyed password hash: it is a process-keyed HMAC digest over the credential, held in a redacted type whose Debug/Display emit only a fixed placeholder. Pools enter the shared cache only after a successful handshake plus health query; concurrent first users coalesce on one initialization; superseded or failed pools are closed and evicted; the cache is bounded.

Structs§

CredentialGeneration
Redacted credential identity. The inner bytes are a process-keyed HMAC-SHA-256 digest of the secret — useless outside this process, never an offline verifier — and can never be printed, logged, or serialized.
PoolManager
Shared pool cache with verified publication. A pool becomes visible only after Pool::get_conn() + a SELECT 1 health query succeed on it.

Enums§

PoolManagerError

Constants§

MAX_POOLS
Maximum distinct pools kept in the shared cache.

Functions§

evict_by_generation
Close and remove every pool riding the given tunnel generation (tunnel retirement). Returns how many pools were evicted.