|
ProtoCore v1.0.16
Deterministic, zero-heap network stack for embedded targets
|
Layer: L4 Transport ยท Build flags: PROTOCORE_ENABLE_ACCEPT_THROTTLE
This is a build-time defense, not an API. When enabled, the accept callback rejects new connections once more than PROTOCORE_ACCEPT_THROTTLE_MAX have been accepted within PROTOCORE_ACCEPT_THROTTLE_WINDOW_MS - a global fixed window using two counters, no per-IP table. It bounds connection churn (reconnect/brute-force floods) on top of the already-bounded connection pool. The sketch's only job is to show that enabling the flag is all it takes.
Zero runtime surface. There is nothing to call - the throttle lives in the accept path. The handler is a plain route; the defense is active simply because the flag was compiled in:
Tuning. Set the two knobs as build flags alongside the enable flag - for example a window of 1000 ms and a cap of 20 accepts/window:
For a per-source-IP throttle (so one noisy host cannot starve everyone), see PerIpThrottle.
Hammer it with many rapid connections (e.g. ab -n 500 -c 50 http://<ip>/) and watch excess connections get refused at accept time.
The complete sketch (AcceptThrottle.ino), reproduced verbatim with added explanatory comments: