mirror of
https://github.com/tailscale/tailscale.git
synced 2026-10-09 11:52:00 -04:00
derp/derpserver: bound dup client sendHistory growth
When two connections share a node key, they form a dup client set and noteClientActivity records each sending connection in the set's sendHistory. It appended on every frame whenever the sender was not the immediately previous one, and nothing trimmed the slice while both connections stayed alive. Two connections taking turns sending therefore grew sendHistory by one *sclient per frame without bound. Under the default lastWriterIsActive policy nothing ever stops that growth, so a malicious client (which controls its own node key) or a buggy one that keeps two connections alive and both sending could leak server memory, roughly 8 bytes per frame, for the life of the connection pair. Record the sender by moving it to the end of sendHistory and dropping any earlier occurrence, so each connection appears at most once and the slice stays bounded by the number of connections in the set. This preserves the existing behavior: the fighting check under disableFighters still runs before the move and still disables everyone on the first repeat, and removeClient still promotes the previous speaker from the slice tail. Fixes tailscale/corp#48884 Change-Id: I06198178e6ab0d7e2f04c1dc4c09eafcb16ace46 Signed-off-by: Brad Fitzpatrick <bradfitz@tailscale.com>
This commit is contained in:
500 Internal Server Error
Gitea Version: 1.28.0+dev-477-g8b6ad49a5f