mirror of
https://github.com/jmcorgan/fips.git
synced 2026-10-05 11:08:25 +00:00
The Tor accept loop spawned the per-connection receive task, then inserted the pool entry, then bumped the inbound counter. A remote that reset immediately let the receive task reach its cleanup first: the removal found nothing, the conditional teardown that decrements never fired, and the increment landed afterwards with nothing left to undo it. Enough of those and the max_inbound gate rejects every further onion connection while the pool is visibly empty. Restore the readiness barrier the TCP accept loop already uses. The shared proxied receive loop takes an optional oneshot receiver and waits on it before its read loop; a dropped sender means the accept loop went away, so it falls through to the cleanup rather than returning and stranding the entry it was meant to release. The tor accept loop signals after both the insert and the counter bump. Outbound tor connections and nym pass None: neither holds a counted inbound slot, and nym binds no listener at all. The same accept path now also releases the slot of an entry it evicts. A reused ephemeral forward port can collide with an entry whose receive task has not finished cleaning up; left alone that task later removes the entry the new connection just inserted, leaking one slot and orphaning a live connection.