Keyboard shortcuts

Press ← or → to navigate between chapters

Press S or / to search in the book

Press ? to show this help

Press Esc to hide this help

Credential projection evidence (GL-108)

Measured on 2026-09-09 on mistral, Apple M1 Pro, Darwin 25.6.0, Rust 1.97.1. Crates use the ordinary Criterion release profile; loopback load uses production (fat LTO, panic abort). These measurements accompany the owning invariants and tests; they do not prove cryptography, scheduler behavior or SQL-to-Rust refinement.

Request and session cost

./scripts/check_perf_thresholds.sh passed all 46 benchmark rows. The new same-run ratios passed: cached managed/direct 0.992, uncached managed/direct 1.011, each bounded at 1.25. Historical baseline enforcement was not enabled (active_host unset); the existing gate reported some unstable unrelated rows as inconclusive. No existing threshold was relaxed. New baseline rows record this run on the same host as the baseline header.

Managed credential operationMean
Warm finite cached proof36.98 ns
Direct verifier, same finite cached proof37.26 ns
Uncached managed verification802.43 ns
Uncached direct verification793.49 ns
Cold session authentication1,022.32 ns
Expired proof renewed from a fresh table1,088.38 ns
Expired session refused988.27 ns

The existing indefinite-cache fixture measured 16.50 ns. Finite proof expiry activates the existing timestamp comparison, so its cost must be stated rather than claiming that every warm credential remains at the indefinite-cache cost. A cold managed verification adds one projection load; warm hits do not consult the registry. Expired proofs are checked using caller-supplied time.

./scripts/check_allocations.sh passed, including required report scopes auth/projected_cache_hit and auth/projected_expiry: both allocate zero. Renewal creates new cached evidence and is measured separately from warm hits.

The production loopback load gate passed:

Paired workloadAdmission/baseline p50Required maximum
Sequential1.0221.150
Ten connections, same account1.0291.200
Ten distinct accounts1.006Informational

Admitted throughput was 29,344 requests/s sequentially and 104,924 requests/s with ten connections. The example imports its documented demo-key-N tokens into durable MemoryStore records, then authenticates through KeyManager. Its API test additionally retires a stored key, refreshes, and checks that new verification refuses it with no extra usage charge. Account snapshot checks continue on every request, independently of cached credential identity.

Page and publication scaling

Reproduce with:

cargo bench -p tollgate-client --bench key_projection_scaling -- \
  --warm-up-time 1 --measurement-time 2 --sample-size 30

The page fixture holds 256 active keys and returns 64 per read. Retired history is deliberately before the cursor's first active key.

Retired keys retained in memoryPage mean
04.310 µs
1,0004.312 µs
100,0004.354 µs
Active keysInitial complete manager pass, including startup/shutdown
25667.03 µs
4,096871.28 µs
16,3843.860 ms

The ordered unrevoked-key index removes retired-history scans. Expired but unrevoked rows remain candidates, and the whole installed table still costs O(active keys) memory. The per-pass deadline and total page-call budget include revision-conflict restarts and candidate construction.

PostgreSQL 16 EXPLAIN (ANALYZE, BUFFERS, FORMAT JSON) used 100,000 retired rows and 256 active rows, with LIMIT 65 (64 records plus lookahead). Both the first page and a cursor in the live set used tollgate_credential_keys_projection: 65 rows, zero rows removed by the expiry filter, four shared blocks, no sort. Execution times were 0.038 ms and 0.027 ms. The fixture was inserted in a transaction and rolled back; plans are in the generated reports/credential_pg_plans.json artifact. Reproduce against the local fixture:

docker compose exec -T postgres psql -U tollgate -d tollgate \
  -v ON_ERROR_STOP=1 -f - < testing/credential_projection_plans.sql

These are query-plan observations, not a latency promise for arbitrary expiry distributions or remote databases.

Those PostgreSQL observations used the pre-0018 expiry schema. The runnable fixture now uses exact timestamp pairs; GL-118 does not claim a fresh timing measurement or reuse these historical query timings as validation of that schema. Its correctness evidence covers both page predicates and the complete HTTP/session boundary without changing the measured request-path code.

Reproducible assurance

The invariant witnesses live in INVARIANTS.md 27 and 34. Core commands:

cargo fmt --check
cargo clippy --workspace --all-targets --all-features -- -D warnings
TOLLGATE_REQUIRE_PG=1 TOLLGATE_PG_URL=<local-fixture-url> \
  cargo test --workspace --all-features
./scripts/check_formal.sh
TOLLGATE_PG_URL=<local-fixture-url> ./scripts/check_mutations.sh --diff main
./scripts/check_allocations.sh
./scripts/check_perf_thresholds.sh
./scripts/check_load_thresholds.sh
./scripts/check_advisories.sh
./scripts/check_ci_rules.sh

The Lean model proves exact fixed-catalogue drains, no omissions or duplicates, whole replacement, failed/mixed-revision preservation and finite expiry bounds. Backend tests cover revisions from the same committed read, legacy writes, rollback, no-op idempotency and overflow. HTTP tests cover the role boundary, server-selected time, strict query and digest decoding, complete response semantics, and exact body bounds with and without Content-Length.