[PR #6865] [CLOSED] [client] Create the WireGuard peer before the peer becomes routable #29154

Open
opened 2026-08-05 08:07:33 -04:00 by saavagebueno · 0 comments
Owner

📋 Pull Request Information

Original PR: https://github.com/netbirdio/netbird/pull/6865
Author: @pappz
Created: 7/22/2026
Status: Closed

Base: fix/lazyconn-idle-keep-wg-peerHead: fix/lazyconn-cold-start-allowed-ips


📝 Commits (1)

  • b8cf088 [client] Create the WireGuard peer before the peer becomes routable

📊 Changes

5 files changed (+104 additions, -34 deletions)

View changed files

📝 client/internal/conn_mgr.go (+24 -16)
📝 client/internal/engine.go (+8 -4)
📝 client/internal/lazyconn/activity/manager.go (+46 -8)
📝 client/internal/lazyconn/activity/manager_test.go (+5 -2)
📝 client/internal/lazyconn/manager/manager.go (+21 -4)

📄 Description

Split peer setup into a prepare and a start phase. AddPeerConn now only registers the conn in the peer store and, in lazy mode, arms the wake endpoint (creating the WireGuard peer) without starting any event source. The peer is then registered in the status recorder, and StartPeerConn starts the activity listener, opens the connection or applies HA activation afterwards.

This closes the cold-start race where the route watcher, reacting to the freshly registered idle peer, pushed routed allowed IPs before the WireGuard peer existed: the update_only add was silently dropped while the allowed-IP refcounter recorded the prefix as installed, so nothing retried and traffic to the routed subnet stayed black-holed until the peer was woken by other means.

Packets arriving on the armed wake endpoint before the listener starts queue in the socket buffer, and no status write can land before the recorder entry exists because no event source runs in between.

Describe your changes

Stack

Checklist

  • Is it a bug fix
  • Is a typo/documentation fix
  • Is a feature enhancement
  • It is a refactor
  • Created tests that fail without the change (if possible)
  • This change does not modify the public API, gRPC protocols, functionality behavior, CLI / service flags, or introduce a new feature — OR I have discussed it with the NetBird team beforehand (link the issue / Slack thread in the description). See CONTRIBUTING.md.

By submitting this pull request, you confirm that you have read and agree to the terms of the Contributor License Agreement.

Documentation

Select exactly one:

  • I added/updated documentation for this change
  • Documentation is not needed for this change (explain why)

Docs PR URL (required if "docs added" is checked)

Paste the PR link from https://github.com/netbirdio/docs here:

https://github.com/netbirdio/docs/pull/__


View with Codesmith Autofix with Codesmith
Need help on this PR? Tag /codesmith with what you need. Autofix is disabled.

Summary by CodeRabbit

  • New Features

    • Improved peer connection startup by separating peer registration from connection activation.
    • Added explicit control over when peer connections and activity monitoring begin.
    • Improved handling of high-availability peer activation.
  • Bug Fixes

    • Improved listener shutdown and cleanup reliability.
    • Prevented duplicate peers from becoming visible before registration succeeds.
    • Deferred permanent connections when lazy connection setup excludes or cannot immediately start a peer.

🔄 This issue represents a GitHub Pull Request. It cannot be merged through Gitea due to API limitations.

## 📋 Pull Request Information **Original PR:** https://github.com/netbirdio/netbird/pull/6865 **Author:** [@pappz](https://github.com/pappz) **Created:** 7/22/2026 **Status:** ❌ Closed **Base:** `fix/lazyconn-idle-keep-wg-peer` ← **Head:** `fix/lazyconn-cold-start-allowed-ips` --- ### 📝 Commits (1) - [`b8cf088`](https://github.com/netbirdio/netbird/commit/b8cf088be313b7072869759e9aa145bc88b334f9) [client] Create the WireGuard peer before the peer becomes routable ### 📊 Changes **5 files changed** (+104 additions, -34 deletions) <details> <summary>View changed files</summary> 📝 `client/internal/conn_mgr.go` (+24 -16) 📝 `client/internal/engine.go` (+8 -4) 📝 `client/internal/lazyconn/activity/manager.go` (+46 -8) 📝 `client/internal/lazyconn/activity/manager_test.go` (+5 -2) 📝 `client/internal/lazyconn/manager/manager.go` (+21 -4) </details> ### 📄 Description Split peer setup into a prepare and a start phase. AddPeerConn now only registers the conn in the peer store and, in lazy mode, arms the wake endpoint (creating the WireGuard peer) without starting any event source. The peer is then registered in the status recorder, and StartPeerConn starts the activity listener, opens the connection or applies HA activation afterwards. This closes the cold-start race where the route watcher, reacting to the freshly registered idle peer, pushed routed allowed IPs before the WireGuard peer existed: the update_only add was silently dropped while the allowed-IP refcounter recorded the prefix as installed, so nothing retried and traffic to the routed subnet stayed black-holed until the peer was woken by other means. Packets arriving on the armed wake endpoint before the listener starts queue in the socket buffer, and no status write can land before the recorder entry exists because no event source runs in between. ## Describe your changes ## Issue ticket number and link ## Stack <!-- branch-stack --> ### Checklist - [x] Is it a bug fix - [ ] Is a typo/documentation fix - [ ] Is a feature enhancement - [ ] It is a refactor - [ ] Created tests that fail without the change (if possible) - [ ] This change does **not** modify the public API, gRPC protocols, functionality behavior, CLI / service flags, or introduce a new feature — **OR** I have discussed it with the NetBird team beforehand (link the issue / Slack thread in the description). See [CONTRIBUTING.md](https://github.com/netbirdio/netbird/blob/main/CONTRIBUTING.md#discuss-changes-with-the-netbird-team-first). > By submitting this pull request, you confirm that you have read and agree to the terms of the [Contributor License Agreement](https://github.com/netbirdio/netbird/blob/main/CONTRIBUTOR_LICENSE_AGREEMENT.md). ## Documentation Select exactly one: - [ ] I added/updated documentation for this change - [x] Documentation is **not needed** for this change (explain why) ### Docs PR URL (required if "docs added" is checked) Paste the PR link from https://github.com/netbirdio/docs here: https://github.com/netbirdio/docs/pull/__ <!-- codesmith:footer --> --- <a href="https://app.blacksmith.sh/netbirdio/codesmith/netbird/pr/6865"><picture><source media="(prefers-color-scheme: dark)" srcset="https://pr-comments-assets.blacksmith.sh/codesmith/view-with-codesmith-dark-v2.svg"><source media="(prefers-color-scheme: light)" srcset="https://pr-comments-assets.blacksmith.sh/codesmith/view-with-codesmith-light-v2.svg"><img alt="View with Codesmith" src="https://pr-comments-assets.blacksmith.sh/codesmith/view-with-codesmith-dark-v2.svg"></picture></a> <a href="https://backend.blacksmith.sh/track/enable-autofix?expires=1787346098&installation_model_id=427504&pr_number=6865&repository=netbirdio%2Fnetbird&return_to=https%3A%2F%2Fgithub.com%2Fnetbirdio%2Fnetbird%2Fpull%2F6865&signature=a2b14f4ab0e7f2fcb4f6dc76b6ecda03f347abe03db20c8c16d3982ace2daaa2"><picture><source media="(prefers-color-scheme: dark)" srcset="https://pr-comments-assets.blacksmith.sh/codesmith/autofix-with-codesmith-dark.svg"><source media="(prefers-color-scheme: light)" srcset="https://pr-comments-assets.blacksmith.sh/codesmith/autofix-with-codesmith-light.svg"><img alt="Autofix with Codesmith" src="https://pr-comments-assets.blacksmith.sh/codesmith/autofix-with-codesmith-dark.svg"></picture></a> <sup>Need help on this PR? Tag <code>/codesmith</code> with what you need. Autofix is disabled.</sup> <!-- codesmith:autofix:disabled --> <!-- /codesmith:footer --> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Improved peer connection startup by separating peer registration from connection activation. * Added explicit control over when peer connections and activity monitoring begin. * Improved handling of high-availability peer activation. * **Bug Fixes** * Improved listener shutdown and cleanup reliability. * Prevented duplicate peers from becoming visible before registration succeeds. * Deferred permanent connections when lazy connection setup excludes or cannot immediately start a peer. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --- <sub>🔄 This issue represents a GitHub Pull Request. It cannot be merged through Gitea due to API limitations.</sub>
saavagebueno added the pull-request label 2026-08-05 08:07:33 -04:00
Sign in to join this conversation.
No Label pull-request
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: DYNR/netbird#29154