mirror of
https://github.com/coder/coder.git
synced 2026-09-24 15:04:27 +08:00
fix: never send local endpoints if disabled (#12138)
This commit is contained in:
@@ -168,6 +168,7 @@ func NewConn(options *Options) (conn *Conn, err error) {
|
||||
|
||||
magicConn := sys.MagicSock.Get()
|
||||
magicConn.SetDERPForceWebsockets(options.DERPForceWebSockets)
|
||||
magicConn.SetBlockEndpoints(options.BlockEndpoints)
|
||||
if options.DERPHeader != nil {
|
||||
magicConn.SetDERPHeader(options.DERPHeader.Clone())
|
||||
}
|
||||
@@ -345,6 +346,7 @@ func (c *Conn) SetDERPForceWebSockets(v bool) {
|
||||
func (c *Conn) SetBlockEndpoints(blockEndpoints bool) {
|
||||
c.configMaps.setBlockEndpoints(blockEndpoints)
|
||||
c.nodeUpdater.setBlockEndpoints(blockEndpoints)
|
||||
c.magicConn.SetBlockEndpoints(blockEndpoints)
|
||||
}
|
||||
|
||||
// SetDERPRegionDialer updates the dialer to use for connecting to DERP regions.
|
||||
|
||||
@@ -4,6 +4,7 @@ import (
|
||||
"context"
|
||||
"net/netip"
|
||||
"testing"
|
||||
"time"
|
||||
|
||||
"github.com/google/uuid"
|
||||
"github.com/stretchr/testify/assert"
|
||||
@@ -412,6 +413,63 @@ parentLoop:
|
||||
require.True(t, client2.AwaitReachable(awaitReachableCtx4, ip))
|
||||
}
|
||||
|
||||
func TestConn_BlockEndpoints(t *testing.T) {
|
||||
t.Parallel()
|
||||
logger := slogtest.Make(t, nil).Leveled(slog.LevelDebug)
|
||||
|
||||
derpMap, _ := tailnettest.RunDERPAndSTUN(t)
|
||||
|
||||
// Setup conn 1.
|
||||
ip1 := tailnet.IP()
|
||||
conn1, err := tailnet.NewConn(&tailnet.Options{
|
||||
Addresses: []netip.Prefix{netip.PrefixFrom(ip1, 128)},
|
||||
Logger: logger.Named("w1"),
|
||||
DERPMap: derpMap,
|
||||
BlockEndpoints: true,
|
||||
})
|
||||
require.NoError(t, err)
|
||||
defer func() {
|
||||
err := conn1.Close()
|
||||
assert.NoError(t, err)
|
||||
}()
|
||||
|
||||
// Setup conn 2.
|
||||
ip2 := tailnet.IP()
|
||||
conn2, err := tailnet.NewConn(&tailnet.Options{
|
||||
Addresses: []netip.Prefix{netip.PrefixFrom(ip2, 128)},
|
||||
Logger: logger.Named("w2"),
|
||||
DERPMap: derpMap,
|
||||
BlockEndpoints: true,
|
||||
})
|
||||
require.NoError(t, err)
|
||||
defer func() {
|
||||
err := conn2.Close()
|
||||
assert.NoError(t, err)
|
||||
}()
|
||||
|
||||
// Connect them together and wait for them to be reachable.
|
||||
stitch(t, conn2, conn1)
|
||||
stitch(t, conn1, conn2)
|
||||
awaitReachableCtx, awaitReachableCancel := context.WithTimeout(context.Background(), testutil.WaitShort)
|
||||
defer awaitReachableCancel()
|
||||
require.True(t, conn1.AwaitReachable(awaitReachableCtx, ip2))
|
||||
|
||||
// Wait 10s for endpoints to potentially be sent over Disco. There's no way
|
||||
// to force Disco to send endpoints immediately.
|
||||
time.Sleep(10 * time.Second)
|
||||
|
||||
// Double check that both peers don't have endpoints for the other peer
|
||||
// according to magicsock.
|
||||
conn1Status, ok := conn1.Status().Peer[conn2.Node().Key]
|
||||
require.True(t, ok)
|
||||
require.Empty(t, conn1Status.Addrs)
|
||||
require.Empty(t, conn1Status.CurAddr)
|
||||
conn2Status, ok := conn2.Status().Peer[conn1.Node().Key]
|
||||
require.True(t, ok)
|
||||
require.Empty(t, conn2Status.Addrs)
|
||||
require.Empty(t, conn2Status.CurAddr)
|
||||
}
|
||||
|
||||
// stitch sends node updates from src Conn as peer updates to dst Conn. Sort of
|
||||
// like the Coordinator would, but without actually needing a Coordinator.
|
||||
func stitch(t *testing.T, dst, src *tailnet.Conn) {
|
||||
|
||||
Reference in New Issue
Block a user