docs(audit): fifth-batch ledger — quota atomic gate closed (audit #4)

The deferred-seams entry that waited for a real-Postgres harness is struck:
ClaimServer owns the gate now, proven red-then-green by the pgint concurrency
test (two claims, one win, one 403), and the storage-cache zeroing found in the
same pass is recorded with its hermetic test. auditfix19 is live on the VM.
This commit is contained in:
Lemon-miaow committed 2026-09-23 03:39:25 +08:00
1 parent bb68fefe04
commit 1d0ec61c9d
2 files changed
+7 -2

No files matched your search

+5 -2
View File
@@ -83,8 +83,11 @@ or a real upstream account to run it against — not an implementation.
These are decisions, not backlog. Each names the condition under which it would be
worth revisiting.
- `internal/api/pgrepo.go:281` — the quota check and `ClaimServer` are two statements
(audit #4 TOCTOU). Closeable only against a real Postgres.
- ~~`internal/api/pgrepo.go:281` — the quota check and `ClaimServer` are two statements
(audit #4 TOCTOU). Closeable only against a real Postgres.~~ **Closed** — the gate
moved inside `ClaimServer` (advisory lock + re-check + UPDATE in one transaction),
red-then-green in the pgint suite, which is exactly the real-Postgres harness this
line was waiting for.
- `internal/api/api.go:671` — `cooldownLimiter` is process-local, so across N api
replicas a caller could draw up to N OTP codes per window. The intra-replica burst
is closed; cross-replica bounding needs a shared store, out of scope for a