[v0.20.x-branch] Backport #11132: peer: answer every valid ping - #11217
Conversation
|
Please cherry-pick the changes locally and resolve any conflicts. git fetch origin backport-11132-to-v0.20.x-branch
git worktree add --checkout .worktree/backport-11132-to-v0.20.x-branch backport-11132-to-v0.20.x-branch
cd .worktree/backport-11132-to-v0.20.x-branch
git reset --hard HEAD^
git cherry-pick -x 458fc48ef9a8b5b011e68f9f2fd03da2b7ee0a1d 0e9b7f241826b4cd3af7bb35e509a776ddb9a4af 4d7805c8282bb2ec03d7b477a5dc80d4f728bb95 bef201833cb6fa1c88270cd7ee218bd6c43b1177
git push --force-with-lease |
b152346 to
ce9ae06
Compare
🔴 PR Severity: CRITICAL
🔴 Critical (2 files)
🟢 Low (2 files)
AnalysisThis PR modifies To override, add a |
3fc6e63 to
6cb71cd
Compare
Remove the separate Pong reply check so every accepted Ping below the BOLT 1 size ceiling receives its mandated response. Keep the request flood limiter as the abuse boundary and verify full-burst replies continue through the high-priority queue. (cherry picked from commit 458fc48)
Delete the unused reply limiter after valid Pongs stop consulting it. Store the remaining request flood limiter directly on the peer and retain its existing rate, burst, and teardown behavior. (cherry picked from commit 0e9b7f2)
Document the Ping reply correction in the 0.20.5 and 0.21.4 release notes and credit the contributor in both versions. (cherry picked from commit 4d7805c)
Charge the existing inbound Ping budget based on requested Pong bytes. Keep normal and oversized no-reply Pings at one token while maximum replies cost ten. Disconnect when the weighted budget is exhausted so admitted valid Pings still receive BOLT-required responses without restoring a separate limiter. (cherry picked from commit bef2018)
6cb71cd to
33b710b
Compare
Divergence from the parent PRDerived by diffing this branch's net patch against #11132's net patch, so Parent commits, cherry-picked with Root cause
Every difference below follows from that. Backporting #10674 was considered Differences
All five conflict regions from the Looks like a difference, but is pre-existing base stateBoth verified as context lines on both sides of the patch comparison — the
Consequently Verification
Rebased onto The companion v0.21.x backport is #11218, which is a clean parent adoption. |
Backport of #11132
Summary
Restore BOLT 1 compliance by answering every valid Ping admitted by the peer flood policy while retaining the former worst-case Pong bandwidth bound.
Closes #11129.
Change Description
Remove the separate Pong reply limiter and retain one per-peer token bucket at 10 tokens per second with a burst of 200. Valid requests cost
max(1, ceil(num_pong_bytes / 6554))tokens, so normal lnd requests up to 4,096 bytes cost one token while a maximum 65,531-byte Pong costs ten.Every admitted valid Ping receives its required Pong through the existing high-priority outgoing queue. Exhausting the weighted budget disconnects the peer instead of silently suppressing a required response. Requests for 65,532 or more Pong bytes remain ignored under BOLT 1 and cost one token so they cannot bypass inbound flood protection.