Files
lmvpn_client/internal/daemon/daemon.go
T
kevin 3e7df0f4d8
Release / build-macos (push) Canceled after 0s
Release / build-windows (push) Canceled after 0s
Release / release (push) Canceled after 0s
fix: 修复连接状态下切换配置后断开重连导致异常的问题
问题现象:连接中切换配置 -> 断开 -> 连接,会出现连接后瞬间断开、
长时间无法重连。而先断开再切换配置则正常。

根因分析(三个层面的资源泄漏叠加):

1. pumpPackets 死锁 (session.go)
   Disconnect() 只关闭 WebSocket transport,不关闭 TUN 设备。
   TUN->WS goroutine 阻塞在 dev.Read(),pumpPackets 的 wg.Wait()
   永远不返回,cleanup()(关闭 TUN/删路由)无法执行,导致
   TUN 设备和路由泄漏。

2. 僵尸 eventLoop + 僵尸 IPC 连接 (view.go)
   onDisconnect 不清空 ipcClient、不关闭 IPC 连接,旧 eventLoop
   持续运行接收广播事件。eventLoop 正常事件处理无身份校验,
   旧 session 的 disconnected 广播会覆盖新 session 的 connected 状态。

3. stopSession 不等待 goroutine 退出 (daemon.go)
   d.session = nil 在 goroutine 仍在运行时即设置,新旧 session
   并发执行导致 TUN/路由冲突。无 mutex 保护并发访问。

修复内容(10 项,3 个文件):

session.go:
- Disconnect() 新增 dev.Close() 解除 pumpPackets 死锁
- 新增 done channel,Disconnect() 阻塞等待 run goroutine 完全退出
- run() deferred setState 跳过用户主动断开时的冗余广播
- run() 顶部 ctx.Err() 检查后补 cleanup()

daemon.go:
- 新增 sync.Mutex 保护 session/cancel 并发访问
- 拆分 stopSession/stopSessionLocked 避免死锁

view.go:
- onDisconnect 置 ipcClient=nil + client.Close() 终止僵尸 eventLoop
- eventLoop 三个事件分支均加 if current == client 身份校验
- onConnect 覆盖前清理旧 IPC client
- setConnButtons 连接时禁用配置下拉框
2026-07-08 20:57:50 +08:00

195 lines
5.1 KiB
Go

// Package daemon implements the privileged daemon process that owns
// the WebSocket transport, TUN device, and routing. It receives
// commands from the GUI over an IPC unix socket and broadcasts
// state/stats events back.
//
// The daemon is launched (as root) by the GUI via osascript. It holds
// no persistent state — all configuration is provided by the GUI in
// the Start command.
//
// The daemon accepts --user-home, --uid, and --gid flags so it can:
// - Write logs to the user's ~/Library/Logs/ (not /var/root)
// - Chown the IPC socket so the user can connect
// - Chown log files so the user can read them
package daemon
import (
"context"
"fmt"
"net"
"os"
"os/signal"
"sync"
"syscall"
"lmvpn/internal/ipc"
"lmvpn/internal/log"
"lmvpn/internal/model"
"lmvpn/internal/paths"
"lmvpn/internal/stats"
"lmvpn/internal/version"
"lmvpn/internal/vpn"
)
// Run starts the daemon and blocks until Shutdown is received or a
// signal (SIGINT/SIGTERM) is delivered.
//
// userHome, uid, gid are the invoking GUI user's home directory and
// IDs, used to place logs in the user's Library and chown the IPC
// socket so the non-root GUI can connect.
func Run(userHome string, uid, gid int) error {
// Override paths to use the user's home directory (not root's).
paths.SetUserHome(userHome)
if err := paths.EnsureDirs(); err != nil {
// Non-fatal: root can usually create these anyway.
fmt.Fprintf(os.Stderr, "ensure dirs: %v\n", err)
}
log.Init(log.RoleDaemon, paths.DaemonLogFile())
// Chown the daemon log file so the user can read it.
chownToUser(paths.DaemonLogFile(), uid, gid)
log.L().Info("lmvpn daemon starting",
"user_home", userHome, "uid", uid, "gid", gid)
server, err := ipc.NewServer()
if err != nil {
return fmt.Errorf("ipc server: %w", err)
}
defer server.Close()
// Chown the IPC socket so the non-root GUI process can connect.
// This is the critical fix: without it, the socket is owned by
// root:wheel with mode 0660, and the user cannot dial it.
chownToUser(paths.IPCAddress(), uid, gid)
log.L().Info("daemon listening", "socket", paths.IPCAddress())
d := &daemon{server: server}
// Signal handling for clean shutdown.
sigCh := make(chan os.Signal, 1)
signal.Notify(sigCh, syscall.SIGINT, syscall.SIGTERM)
go func() {
<-sigCh
log.L().Info("daemon received signal, shutting down")
d.stopSession()
server.Close()
os.Exit(0)
}()
return server.Accept(d.handle)
}
// chownToUser changes the ownership of a file to the given uid:gid.
// Errors are logged but not fatal (e.g. if uid is -1).
func chownToUser(path string, uid, gid int) {
if uid < 0 {
return
}
if err := os.Chown(path, uid, gid); err != nil {
log.L().Warn("chown failed", "path", path, "error", err)
}
}
type daemon struct {
server *ipc.Server
mu sync.Mutex
session *vpn.SessionManager
cancel context.CancelFunc
}
func (d *daemon) handle(conn net.Conn, req ipc.Request) {
switch req.Cmd {
case ipc.CmdStart:
d.startSession(conn, req)
case ipc.CmdStop:
d.stopSession()
_ = ipc.WriteOK(conn)
case ipc.CmdShutdown:
d.stopSession()
_ = ipc.WriteOK(conn)
d.server.Close()
os.Exit(0)
case ipc.CmdStats:
d.mu.Lock()
sess := d.session
d.mu.Unlock()
if sess != nil {
snap := sess.Stats().Snapshot()
d.server.Broadcast(ipc.Event{Event: ipc.EvStats, Stats: &snap})
}
_ = ipc.WriteOK(conn)
case ipc.CmdVersion:
_ = ipc.WriteVersion(conn, version.Version)
default:
_ = ipc.WriteErr(conn, "unknown command: "+req.Cmd)
}
}
func (d *daemon) startSession(conn net.Conn, req ipc.Request) {
d.mu.Lock()
defer d.mu.Unlock()
if req.Config == nil {
_ = ipc.WriteErr(conn, "missing config")
return
}
if d.session != nil {
d.stopSessionLocked()
}
cfg := vpn.SessionConfig{
ServerURL: req.Config.ServerURL,
SNIHost: req.Config.SNIHost,
ServerIPs: req.Config.ServerIPs,
Username: req.Config.Username,
Password: req.Config.Password,
Token: req.Config.Token,
AuthMode: model.AuthMode(req.Config.AuthMode),
RoutingMode: ipc.RoutingModeFromIPC(req.Config.RoutingMode),
CustomCIDRs: req.Config.CustomCIDRs,
MTUOverride: req.Config.MTUOverride,
TLSCACert: req.Config.TLSCACert,
TLSCAPath: req.Config.TLSCAPath,
TLSInsecure: req.Config.TLSInsecure,
TLSPinnedHash: req.Config.TLSPinnedHash,
}
ctx, cancel := context.WithCancel(context.Background())
d.cancel = cancel
d.session = vpn.New(
func(s stats.State) {
d.server.Broadcast(ipc.Event{Event: ipc.EvState, State: string(s)})
},
func(snap stats.Snapshot) {
s := snap
d.server.Broadcast(ipc.Event{Event: ipc.EvStats, Stats: &s})
},
func(code string, msg string) {
d.server.Broadcast(ipc.Event{Event: ipc.EvError, Code: code, Message: msg})
},
)
if err := d.session.Connect(ctx, cfg); err != nil {
_ = ipc.WriteErr(conn, "connect: "+err.Error())
d.session = nil
return
}
}
func (d *daemon) stopSession() {
d.mu.Lock()
defer d.mu.Unlock()
d.stopSessionLocked()
}
func (d *daemon) stopSessionLocked() {
if d.cancel != nil {
d.cancel()
d.cancel = nil
}
if d.session != nil {
d.session.Disconnect()
d.session = nil
}
}