caddy/modules/caddyhttp/reverseproxy
TowyTowy b2be548275
reverseproxy: fix broken reservoir sampling in random_choose policy (#7873)
The random_choose selection policy is meant to implement
power-of-d-choices: sample d available upstreams uniformly, then pick
the least-loaded of that sample. The sampling loop, however, was not a
correct reservoir sample (Algorithm R): it never filled the first k
reservoir slots unconditionally, instead writing every candidate to a
random slot j = rand(i+1), which can evict an earlier candidate while
leaving another slot nil. It also derived j from the upstream's index
in the pool rather than from the number of available upstreams seen,
skewing the sample whenever unavailable upstreams precede available
ones.

As a result the reservoir frequently held fewer than min(k, available)
upstreams, so the least-load comparison often never happened. Most
notably, with two upstreams and 'random_choose 2' (the canonical
power-of-two-choices setup), half of all requests were routed to the
more-loaded upstream even when it was saturated and the other idle --
identical behavior to plain 'random'. The nil slots this leaves behind
were also the cause of the panic reported in #3810, which was patched
by skipping nils in leastRequests rather than by fixing the sampling.

Replace the loop with a standard Algorithm R reservoir sample over the
available upstreams: fill the first k slots, then replace a random slot
with probability k/n. Every available upstream is now sampled uniformly
and the reservoir always holds min(k, available) candidates.

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
2026-07-12 09:25:31 +10:00
..
fastcgi Merge commit from fork 2026-05-29 11:37:17 -06:00
forwardauth forwardauth: error on duplicate uri subdirective (#7814) 2026-06-10 23:31:04 -04:00
addresses.go core: Implement socket activation listeners (#6573) 2024-09-30 10:55:03 -06:00
addresses_test.go
admin.go reverseproxy: Track dynamic upstreams, enable passive healthchecking (#7539) 2026-03-04 15:05:26 -05:00
admin_test.go reverseproxy: Track dynamic upstreams, enable passive healthchecking (#7539) 2026-03-04 15:05:26 -05:00
ascii.go
ascii_test.go filesystem: Globally declared filesystems, fs directive (#5833) 2024-01-13 20:12:43 +00:00
buffering_test.go reverseproxy: more comments about buffering and add new tests (#6778) 2025-03-07 11:22:43 -07:00
caddyfile.go reverseproxy: fix misleading handle_response error for extra matcher args (#7869) 2026-07-10 05:40:23 +00:00
client_disconnect_test.go reverseproxy: log status 499 instead of 0 when client disconnects (#7827) 2026-06-18 13:31:02 +10:00
command.go cmd: prevent commas in header values from being split (#7268) 2025-09-22 21:12:06 -06:00
copyresponse.go
dynamic_upstreams_test.go reverseproxy: Track dynamic upstreams, enable passive healthchecking (#7539) 2026-03-04 15:05:26 -05:00
headers_test.go chore: replace interface{} with any for modernization (#7571) 2026-04-11 19:53:12 +03:00
healthchecks.go reverseproxy: save dial info in a context key instead of a variable key to avoid race conditions when forward_auth is used (#7859) 2026-07-10 09:37:07 -06:00
hopheaders_test.go Merge commit from fork 2026-06-12 12:39:01 -06:00
hosts.go reverseproxy: save dial info in a context key instead of a variable key to avoid race conditions when forward_auth is used (#7859) 2026-07-10 09:37:07 -06:00
httptransport.go reverseproxy: replace placeholders specified for sni while using http3 (#7737) 2026-06-02 21:49:00 -06:00
httptransport_test.go reverseproxy: save dial info in a context key instead of a variable key to avoid race conditions when forward_auth is used (#7859) 2026-07-10 09:37:07 -06:00
metrics.go reverseproxy: ignore duplicate collector registration error (#6820) 2025-02-04 10:55:30 +03:00
passive_health_test.go reverseproxy: Track dynamic upstreams, enable passive healthchecking (#7539) 2026-03-04 15:05:26 -05:00
retries_test.go reverseproxy: further prevent body closes from dial errors (#7715) 2026-05-12 12:05:50 -06:00
reverseproxy.go reverseproxy: save dial info in a context key instead of a variable key to avoid race conditions when forward_auth is used (#7859) 2026-07-10 09:37:07 -06:00
selectionpolicies.go reverseproxy: fix broken reservoir sampling in random_choose policy (#7873) 2026-07-12 09:25:31 +10:00
selectionpolicies_test.go reverseproxy: fix broken reservoir sampling in random_choose policy (#7873) 2026-07-12 09:25:31 +10:00
streaming.go reverseproxy: make stream copy buffer size configurable (#7627) 2026-04-10 14:49:32 -06:00
streaming_test.go reverseproxy: make stream copy buffer size configurable (#7627) 2026-04-10 14:49:32 -06:00
upstreams.go reverseproxy: Add ability to clear dynamic upstreams cache during retries (#7662) 2026-04-28 09:16:18 -06:00
upstreams_test.go chore: upgrade .golangci.yml and workflow to v2 (#6924) 2025-06-03 02:24:32 +03:00