mirror of
https://github.com/Buriburizaem0n/nezha_domains.git
synced 2026-09-21 02:30:14 +00:00
fix(rpc): cap concurrent IO streams per user and per server
GHSA-jg62-j5h6-8mpq: the terminal and file-manager endpoints created unbounded IO streams; an authenticated member could open thousands, each spawning goroutines, a 1MiB buffer and an agent-side PTY, exhausting dashboard and agent resources. CreateStream now enforces a per-user (20) and per-server (40) cap in the existing ioStreamMutex critical section, using the stream map as the single source of truth. Dashboard-internal streams (uid==0: NAT, server transfer, MCP transfer) skip the per-user cap but still count per-server. Adds caps, exemption, slot-release and no-leak regression tests.
This commit is contained in:
@@ -49,7 +49,9 @@ func createFM(c *gin.Context) (*model.CreateFMResponse, error) {
|
||||
return nil, err
|
||||
}
|
||||
|
||||
rpc.NezhaHandlerSingleton.CreateStream(streamId, getUid(c), server.ID)
|
||||
if err := rpc.NezhaHandlerSingleton.CreateStream(streamId, getUid(c), server.ID); err != nil {
|
||||
return nil, err
|
||||
}
|
||||
|
||||
fmData, _ := json.Marshal(&model.TaskFM{
|
||||
StreamID: streamId,
|
||||
|
||||
Reference in New Issue
Block a user