mirror of
https://github.com/netbirdio/netbird.git
synced 2026-10-09 06:59:08 +02:00
OnNewPSKReady could be applied out of order: two exchanges for a peer can derive concurrently (one over signal, one over the data path), and the callbacks run outside the manager lock, so an older exchange's apply could land after a newer one and restore a stale WireGuard PSK, splitting the tunnel. Give each exchange a per-peer monotonic generation, assigned under the lock at creation so a later exchange always carries a higher one, and pass it to OnNewPSKReady. The host adapter records the newest generation applied per peer and drops any callback that is not newer, with the check-and-record atomic so the slow SetPresharedKey call stays off that lock. Found in cubic review on #7098 (client/internal/pqkem/callbacks.go:12).