doublehop: switching from an active connection races the old tunnel's teardown #202
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Seen live 2026-08-29 while validating #201: with a single-hop connection up, launching a doublehop attempt fails after ~60s with no-push-reply, while the same pair connects reliably from a fresh disconnect.
The race: establish_connection kills the current main tunnel and immediately launches the hop leg, whose pin via the physical link only lands at --up. Its handshake traffic therefore rides the dying tunnel's def1 routes; when they vanish mid-handshake, the PUSH reply is lost. OpenVPN would retry — but both clients kill the attempt on the first conn_attempt_failed_hop (the gui always has; the cli since #201), so the attempt dies. A single-hop switch survives the same race because nothing kills it before the retry succeeds.
Fix shapes, in rough preference order:
Probably best absorbed into #176 rather than fixed standalone.