wireguard-linux-compat icon indicating copy to clipboard operation
wireguard-linux-compat copied to clipboard

allowedips: Increase stack size

Open damianhxy opened this issue 4 years ago • 0 comments

A stack size of 128 is insufficient in the worst-case scenario and leads to a system freeze upon stopping / using syncconf

root_free_rcu / root_remove_peer_lists: We can have up to 128 "0" branches and 1 "1" branch pushed into the stack at once, for a total of 129 elements

walk_remove_by_peer: With 129 possible CIDR values, we can have up to 129 elements in the stack at once

Such configurations are (very) unlikely to occur as it would require rather specific peer allowedips However, it would still be good to guard against such scenarios as they are technically possible (I have managed to trigger said scenarios)

Signed-off-by: Damian Ho [email protected]

damianhxy avatar Apr 12 '21 14:04 damianhxy