mirror of
https://github.com/slackhq/nebula.git
synced 2026-08-15 10:07:01 +02:00
d3779b6a39
The tunnel's real bottleneck queue - the UDP receive buffer feeding the decrypt loop - is invisible to every kernel AQM, so under overload it regulates ECN-capable flows with tail-drop loss like it's 1993. Sample SK_MEMINFO once per recvmmsg batch (tunnels.ecn_mark_threshold, fraction of rcvbuf, 0=off) and treat depth beyond the threshold as an outer CE: the existing RFC 6040 fold then CE-marks ECT inner packets and senders back off without loss.
36 lines
1.1 KiB
Go
36 lines
1.1 KiB
Go
//go:build debug
|
|
|
|
package nebula
|
|
|
|
import (
|
|
"context"
|
|
"errors"
|
|
"log/slog"
|
|
"net/http"
|
|
_ "net/http/pprof" // registers pprof handlers on http.DefaultServeMux
|
|
)
|
|
|
|
// startPprofServer serves net/http/pprof on localhost:6060 for the life of
|
|
// ctx. It is only compiled into debug builds (`-tags debug`, `make debug`),
|
|
// so a debug build announces itself with the Info line below. Loopback only:
|
|
// a wildcard bind would expose profiles (peer addresses, config-derived
|
|
// state) to anything that can reach the host, the overlay included.
|
|
func startPprofServer(ctx context.Context, l *slog.Logger) {
|
|
server := &http.Server{Addr: "localhost:6060", Handler: nil}
|
|
l.Info("Starting pprof debug server (debug build)", "addr", server.Addr)
|
|
|
|
go func() {
|
|
if err := server.ListenAndServe(); err != nil && !errors.Is(err, http.ErrServerClosed) {
|
|
l.Error("pprof debug server stopped", "error", err)
|
|
}
|
|
}()
|
|
|
|
// Shut down the server when the context is cancelled.
|
|
go func() {
|
|
<-ctx.Done()
|
|
if err := server.Shutdown(context.Background()); err != nil {
|
|
l.Debug("Error shutting down pprof debug server", "error", err)
|
|
}
|
|
}()
|
|
}
|