mirror of
https://github.com/tailscale/tailscale.git
synced 2026-10-09 11:52:00 -04:00
net/{pktinfo,stunserver}: reply from the address the request was sent to
If people ran derper on a multi-NIC or multi-address host, STUN replies could go out from the wrong address. The wildcard UDP socket let the kernel pick the reply's source address by routing to the client, which means the default route's address rather than the one the request came in on. With connmark-based policy routing (e.g. DNAT through a tunnel), the reply then doesn't match the inbound conntrack entry, goes out the wrong interface, and the client never sees it. DERP over TCP was fine, since accepted sockets are pinned to the local address. Add net/pktinfo, a small Linux-only package that uses IP_PKTINFO and IPV6_RECVPKTINFO to learn each datagram's destination address and to reply from it, and use it in the STUN server. Only the source address is pinned; routing still picks the interface. Other platforms are unchanged. Fixes #21404 Signed-off-by: Brad Fitzpatrick <bradfitz@tailscale.com> Change-Id: I7b3e9c2d41a8f60e5d9c1b2a3f4e5d6c7b8a9f01
This commit is contained in:
500 Internal Server Error
Gitea Version: 1.28.0+dev-477-g8b6ad49a5f