[PR #6572] [client] Reinject captured first packet on lazy connection activation #28493

Closed
opened 2026-08-05 08:06:27 -04:00 by saavagebueno · 0 comments
Owner

Original Pull Request: https://github.com/netbirdio/netbird/pull/6572

State: closed
Merged: Yes


Describe your changes

When a lazy connection activates, the packet that triggered activation was dropped, so WireGuard had to wait for its handshake retransmit timer (~5s) before the connection became usable. This captures that first packet and replays it through the real transport as soon as ICE or relay comes up, removing the activation stall.

  • Capture the first packet that triggers activation in both the bind (userspace) and UDP (kernel) activity listeners
  • Carry the captured packet through the activity event to the peer connection and reinject it once the real transport is established, via the proxy or directly over the ICE connection
  • Stop removing the peer on activation in the kernel-mode listener, matching the userspace path, so kernel WireGuard's staged queue and the triggering packet are not wiped
  • Widen the UDP listener read buffer to the interface MTU so the triggering packet can be captured
  • Add an InjectPacket method to the proxy implementations to replay a raw packet over the underlying transport

Stack

Checklist

  • Is it a bug fix
  • Is a typo/documentation fix
  • Is a feature enhancement
  • It is a refactor
  • Created tests that fail without the change (if possible)
  • This change does not modify the public API, gRPC protocols, functionality behavior, CLI / service flags, or introduce a new feature — OR I have discussed it with the NetBird team beforehand (link the issue / Slack thread in the description). See CONTRIBUTING.md.

By submitting this pull request, you confirm that you have read and agree to the terms of the Contributor License Agreement.

Documentation

Select exactly one:

  • I added/updated documentation for this change
  • Documentation is not needed for this change (explain why)

Internal client behavior change with no user-facing surface.

Docs PR URL (required if "docs added" is checked)

Paste the PR link from https://github.com/netbirdio/docs here:

https://github.com/netbirdio/docs/pull/__

Summary by CodeRabbit

  • New Features
    • Added capture and replay of the first WireGuard handshake-init packet triggered by peer activity during lazy activation.
    • Activity notifications now include both the peer connection ID and the triggering packet bytes.
    • Added packet-injection capability across proxy implementations to support handshake replay.
  • Bug Fixes
    • Improved handshake reinjection by replaying the captured packet once the transport/proxy path is ready.
    • Updated UDP packet capture to use MTU-sized buffering to better handle larger packets.
  • Tests
    • Refreshed activity and UDP capture tests to assert the new event payload (including packet contents).
**Original Pull Request:** https://github.com/netbirdio/netbird/pull/6572 **State:** closed **Merged:** Yes --- ## Describe your changes When a lazy connection activates, the packet that triggered activation was dropped, so WireGuard had to wait for its handshake retransmit timer (~5s) before the connection became usable. This captures that first packet and replays it through the real transport as soon as ICE or relay comes up, removing the activation stall. - Capture the first packet that triggers activation in both the bind (userspace) and UDP (kernel) activity listeners - Carry the captured packet through the activity event to the peer connection and reinject it once the real transport is established, via the proxy or directly over the ICE connection - Stop removing the peer on activation in the kernel-mode listener, matching the userspace path, so kernel WireGuard's staged queue and the triggering packet are not wiped - Widen the UDP listener read buffer to the interface MTU so the triggering packet can be captured - Add an `InjectPacket` method to the proxy implementations to replay a raw packet over the underlying transport ## Issue ticket number and link ## Stack <!-- branch-stack --> ### Checklist - [ ] Is it a bug fix - [ ] Is a typo/documentation fix - [x] Is a feature enhancement - [ ] It is a refactor - [x] Created tests that fail without the change (if possible) - [ ] This change does **not** modify the public API, gRPC protocols, functionality behavior, CLI / service flags, or introduce a new feature — **OR** I have discussed it with the NetBird team beforehand (link the issue / Slack thread in the description). See [CONTRIBUTING.md](https://github.com/netbirdio/netbird/blob/main/CONTRIBUTING.md#discuss-changes-with-the-netbird-team-first). > By submitting this pull request, you confirm that you have read and agree to the terms of the [Contributor License Agreement](https://github.com/netbirdio/netbird/blob/main/CONTRIBUTOR_LICENSE_AGREEMENT.md). ## Documentation Select exactly one: - [ ] I added/updated documentation for this change - [x] Documentation is **not needed** for this change (explain why) Internal client behavior change with no user-facing surface. ### Docs PR URL (required if "docs added" is checked) Paste the PR link from https://github.com/netbirdio/docs here: https://github.com/netbirdio/docs/pull/__ <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added capture and replay of the first WireGuard handshake-init packet triggered by peer activity during lazy activation. * Activity notifications now include both the peer connection ID and the triggering packet bytes. * Added packet-injection capability across proxy implementations to support handshake replay. * **Bug Fixes** * Improved handshake reinjection by replaying the captured packet once the transport/proxy path is ready. * Updated UDP packet capture to use MTU-sized buffering to better handle larger packets. * **Tests** * Refreshed activity and UDP capture tests to assert the new event payload (including packet contents). <!-- end of auto-generated comment: release notes by coderabbit.ai -->
saavagebueno added the pull-request label 2026-08-05 08:06:27 -04:00
Sign in to join this conversation.
No Label pull-request
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: DYNR/netbird#28493