fix(daemon): exempt trusted loopback peers from per-host limits

Every client on loopback shares the 127.0.0.1 identity, so counting them
against 'max connections per host' or the default-on auth lockout lets one
local client deny service to all the others (and makes a shared-NAT/proxy
address a natural DoS vector for remote clients).  Use
utils_fd_peer_is_local (fail-closed) in the daemon gate to exempt a
provably local peer from the per-source cap and the auth lockout while
keeping the per-module and global caps.  Remote peers are unchanged.

Document the shared-NAT/proxy identity limitation and the loopback
exemption in README/RSYNC_COMPAT/CHANGELOG, update the integration test to
assert the exemption, and fix the README 'auth failure delay' cap (5000,
not 60000).
This commit is contained in:
2026-09-13 10:50:58 +02:00
parent bd43448af2
commit 25909110ac
5 changed files with 69 additions and 21 deletions
+8 -1
View File
@@ -14,7 +14,14 @@ run the same version because the handshake is strict.
forks one child per connection, the counters live in an anonymous shared
mapping created before the accept loop and reclaimed by the parent's
`SIGCHLD` handler, so the per-module, per-source and auth-failure state is
shared across every child (including after `SIGKILL`).
shared across every child (including after `SIGKILL`). The per-source table
now has a bounded lifetime (expired-lockout/idle entries are reclaimed, with a
rate-limited warning when it is genuinely full), and the occupancy counters are
re-derived from the shared slot table on every child exit so a child killed
mid-registration cannot leak a count. Trusted loopback peers are exempt from the
per-host cap and the auth lockout (they share one address); clients behind a
shared NAT/proxy still share a single per-host budget and lockout, which is
documented.
## [2.20.0] - 2026-09-13