mirror of
https://github.com/netbirdio/netbird.git
synced 2026-09-28 17:49:08 +02:00
[client] make AllowedIPs swap self-healing on WireGuard errors
Address CodeRabbit review on #6799. Decrement now decides whether to reprogram based on whether the currently installed peer still holds references (e.peers[e.active] > 0) instead of whether the released peer was the active one. If a prior swap's remove/add failed, e.active was left pointing at a peer with zero references and every later Decrement returned early, permanently stranding the prefix and leaking the entry. The active peer is now detached only when e.active != "", and a failed hand-off is retried on the next Decrement/Increment. Also clear currentPeerKey unconditionally in the static handler's RemoveAllowedIPs (matching dynamic/dnsinterceptor) and assert Increment errors in the tests. Added self-heal tests for the failed remove/add paths.
This commit is contained in:
@@ -62,9 +62,10 @@ func (r *Route) AddAllowedIPs(peerKey string) error {
|
||||
}
|
||||
|
||||
func (r *Route) RemoveAllowedIPs() error {
|
||||
if _, err := r.allowedIPsRefcounter.Decrement(r.route.Network, r.currentPeerKey); err != nil {
|
||||
return err
|
||||
var err error
|
||||
if _, decErr := r.allowedIPsRefcounter.Decrement(r.route.Network, r.currentPeerKey); decErr != nil {
|
||||
err = fmt.Errorf("remove allowed IP %s: %w", r.route.Network, decErr)
|
||||
}
|
||||
r.currentPeerKey = ""
|
||||
return nil
|
||||
return err
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user