Zombie connection after lightningd ignores `connectd_peer_spoke`
I maintainer di solito rispondono entro 2 giorni
Valutazione
- Difficoltà
- 4/5
- Tempo stimato
- 3-5 giorni
- Idoneità per principianti
- 55/100
- Tipo di issue
- Bug
- Chiarezza
- Specificata chiaramente
- Stato di attività
- Tranquilla
- Stack tecnologico
- c
- Ambito
- networking
Direzione di ricerca
Inizia dalla gestione collegata in connectd/multiplex.c e lightningd/peer_control.c, in particolare dai sei percorsi in cui handle_peer_spoke non risponde. Segui il messaggio connectd_peer_no_subd proposto attraverso entrambi i componenti; il lavoro è completo quando l'avvio o la ricerca falliti del subdaemon liberano il subd corrispondente e connectd riprende a leggere i messaggi del peer.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
When connectd reads a peer message whose channel_id has no attached subd, it creates a subd with conn == NULL and sends connectd_peer_spoke to lightningd, asking it to start up a subdaemon and respond with connectd_peer_connect_subd and the file descriptor that should be assigned to conn.
While connectd is waiting for lightningd's response, it stops reading all messages from the peer:
The io_wait at the end is only released when either lightningd responds, or when CLN needs to send a message to that peer (e.g., gossip flush). If neither happens, the connection becomes a zombie and all peer messages are ignored until eventually the ping timeout expires and the connection is dropped.
There are currently six situations where lightningd's handle_peer_spoke never responds:
-
The peer sends an
errorfor its first message (e.g., data loss recovery).
https://github.com/ElementsProject/lightning/blob/ae53e8775e57ddf8debfd6fc7b8e3cb5e2c93dc6/lightningd/peer_control.c#L2067-L2072 -
channeld dies from a bug or protocol violation, and the peer sends another message for that channel before lightningd recognizes the channeld died. An alternative (benign) way to trigger this is when
lightningdhas already created the requested subdaemon butconnectdhasn't processed it yet.
https://github.com/ElementsProject/lightning/blob/ae53e8775e57ddf8debfd6fc7b8e3cb5e2c93dc6/lightningd/peer_control.c#L2074-L2081 -
The peer attempts a
channel_reestablishwhile the node is shutting down.
https://github.com/ElementsProject/lightning/blob/ae53e8775e57ddf8debfd6fc7b8e3cb5e2c93dc6/lightningd/peer_control.c#L2083-L2097 -
The peer sends a message after channeld was killed without a status message (e.g., OOM).
https://github.com/ElementsProject/lightning/blob/ae53e8775e57ddf8debfd6fc7b8e3cb5e2c93dc6/lightningd/peer_control.c#L2100-L2109 -
openingd fails to spawn (e.g., fd limit reached).
https://github.com/ElementsProject/lightning/blob/ae53e8775e57ddf8debfd6fc7b8e3cb5e2c93dc6/lightningd/peer_control.c#L2143-L2145 -
dualopend fails to spawn (e.g., fd limit reached).
https://github.com/ElementsProject/lightning/blob/ae53e8775e57ddf8debfd6fc7b8e3cb5e2c93dc6/lightningd/peer_control.c#L2163-L2165
Suggested fix
Add a new message connectd_peer_no_subd that lightningd can respond with when handle_peer_spoke fails in the above situations. Then connectd knows to free the matching subd and continue reading from the connection.
Discovery
This bug was discovered while fuzzing CLN with smite. Smite would send a channel_ready message with an incorrect channel_id, causing channeld to exit. Then smite would send another channel message, which would trigger the Situation 2 race condition and zombify the connection.
- Lingua principale
- C
- Stelle
- 3.1k
- Fork
- 1k
- Merge medio
- 4g 2h
- PR unite (30g)
- 45
Preparare l'ambiente
- Include un Dockerfile o un file Docker Compose
- Ha un modello di pull request
- Nessuna guida per i contributori
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di ElementsProject/lightning
-
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 90/100
ElementsProject/lightning#9593 ·
I maintainer di solito rispondono entro 2 giorni
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 68/100
ElementsProject/lightning#9322 ·
I maintainer di solito rispondono entro 2 giorni
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 68/100
ElementsProject/lightning#9206 ·
I maintainer di solito rispondono entro 2 giorni
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 68/100
ElementsProject/lightning#9187 · 1 commento · 1 reazione ·
I maintainer di solito rispondono entro 2 giorni
-
QA
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 88/100
ElementsProject/lightning#9117 · 2 commenti ·
I maintainer di solito rispondono entro 2 giorni
Tutte le issue di ElementsProject/lightning
Issue simili
-
[sqlcipher] update to 4.19.0Apertacategory:port-update
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
I maintainer di solito rispondono entro 2 giorni
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 75/100
mypaint/libmypaint#209 ·
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 78/100
I maintainer di solito rispondono entro 1 giorno
-
[LOGO] Keenetic OSForse già presa @Ivan-Alone l’ha presa oggi. Apertalogo request
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
fastfetch-cli/fastfetch#2646 ·
I maintainer di solito rispondono entro 1 giorno
-
rc_runtime_activate_richpresence leaves a half-initialised entry when the buffer allocation failsAperta
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 88/100
RetroAchievements/rcheevos#558 ·