fix(daemon): exempt trusted loopback peers from per-host limits
Every client on loopback shares the 127.0.0.1 identity, so counting them against 'max connections per host' or the default-on auth lockout lets one local client deny service to all the others (and makes a shared-NAT/proxy address a natural DoS vector for remote clients). Use utils_fd_peer_is_local (fail-closed) in the daemon gate to exempt a provably local peer from the per-source cap and the auth lockout while keeping the per-module and global caps. Remote peers are unchanged. Document the shared-NAT/proxy identity limitation and the loopback exemption in README/RSYNC_COMPAT/CHANGELOG, update the integration test to assert the exemption, and fix the README 'auth failure delay' cap (5000, not 60000).
This commit is contained in:
+8
-1
@@ -14,7 +14,14 @@ run the same version because the handshake is strict.
|
||||
forks one child per connection, the counters live in an anonymous shared
|
||||
mapping created before the accept loop and reclaimed by the parent's
|
||||
`SIGCHLD` handler, so the per-module, per-source and auth-failure state is
|
||||
shared across every child (including after `SIGKILL`).
|
||||
shared across every child (including after `SIGKILL`). The per-source table
|
||||
now has a bounded lifetime (expired-lockout/idle entries are reclaimed, with a
|
||||
rate-limited warning when it is genuinely full), and the occupancy counters are
|
||||
re-derived from the shared slot table on every child exit so a child killed
|
||||
mid-registration cannot leak a count. Trusted loopback peers are exempt from the
|
||||
per-host cap and the auth lockout (they share one address); clients behind a
|
||||
shared NAT/proxy still share a single per-host budget and lockout, which is
|
||||
documented.
|
||||
|
||||
## [2.20.0] - 2026-09-13
|
||||
|
||||
|
||||
Reference in New Issue
Block a user