From b70fdcce1242df149012d6c3e9adcdf555564b4e Mon Sep 17 00:00:00 2001 From: dawn <90008@gaze.systems> Date: Thu, 2 Apr 2026 04:09:57 +0300 Subject: [PATCH] [crawler,firehose] add more tls error variants that will cause a throttle --- src/ingest/firehose.rs | 4 ++-- src/util/mod.rs | 24 +++++++++++++++++++++++- 2 files changed, 25 insertions(+), 3 deletions(-) diff --git a/src/ingest/firehose.rs b/src/ingest/firehose.rs index 6e7c981..ce13691 100644 --- a/src/ingest/firehose.rs +++ b/src/ingest/firehose.rs @@ -3,7 +3,7 @@ use crate::ingest::stream::{FirehoseError, FirehoseStream, SubscribeReposMessage use crate::ingest::{BufferTx, IngestMessage}; use crate::state::AppState; use crate::util::throttle::ThrottleHandle; -use crate::util::{WatchEnabledExt, is_timeout, is_tls_cert_error}; +use crate::util::{WatchEnabledExt, is_timeout, is_tls_cert_error, is_tls_error_our_fault}; use jacquard_common::IntoStatic; use jacquard_common::types::did::Did; use miette::{IntoDiagnostic, Result}; @@ -24,7 +24,7 @@ fn is_throttle_worthy(e: &WsError) -> bool { } match e { - WsError::Rustls(e) if matches!(e, rustls::Error::InvalidCertificate(_)) => return true, + WsError::Rustls(e) if is_tls_error_our_fault(e) => return true, WsError::Io(io_err) if is_tls_cert_error(io_err) => return true, WsError::CannotResolveHost => return true, WsError::Upgrade(tokio_websockets::upgrade::Error::DidNotSwitchProtocols(status)) => { diff --git a/src/util/mod.rs b/src/util/mod.rs index d70e9f6..be6bf9e 100644 --- a/src/util/mod.rs +++ b/src/util/mod.rs @@ -41,7 +41,7 @@ pub fn is_tls_cert_error(io_err: &std::io::Error) -> bool { return false; }; if let Some(rustls_err) = inner.downcast_ref::() { - return matches!(rustls_err, rustls::Error::InvalidCertificate(_)); + return is_tls_error_our_fault(rustls_err); } if let Some(nested_io) = inner.downcast_ref::() { return is_tls_cert_error(nested_io); @@ -49,6 +49,28 @@ pub fn is_tls_cert_error(io_err: &std::io::Error) -> bool { false } +pub fn is_tls_error_our_fault(e: &rustls::Error) -> bool { + use rustls::Error::*; + matches!( + *e, + InvalidCertificate(_) + | PeerMisbehaved(_) + | InconsistentKeys(_) + | InappropriateMessage { .. } + | InappropriateHandshakeMessage { .. } + | InvalidMessage(_) + | NoCertificatesPresented + | UnsupportedNameType + | DecryptError + | PeerIncompatible(_) + | AlertReceived(_) + | InvalidCertRevocationList(_) + | InvalidEncryptedClientHello(_) + | PeerSentOversizedRecord + | NoApplicationProtocol + ) +} + /// outcome of [`RetryWithBackoff::retry`] when the operation does not succeed. pub enum RetryOutcome { /// ratelimited after exhausting all retries -- 2.51.2