Skip to content

fix(authority): skip members with incomplete data instead of panicking - #251

Open
eejd wants to merge 1 commit into
zerotier:mainfrom
eejd:fix/skip-incomplete-members
Open

fix(authority): skip members with incomplete data instead of panicking#251
eejd wants to merge 1 commit into
zerotier:mainfrom
eejd:fix/skip-incomplete-members

Conversation

@eejd

@eejd eejd commented Jun 6, 2026

Copy link
Copy Markdown

Problem

ZTRecord::new() panics via .expect() in three places when a network member has incomplete data:

  • node_id missing → expect("Node ID for member does not exist")
  • config missing → expect("Member config does not exist")
  • an ip_assignment that doesn't parse → IpAddr::from_str(s).expect("Could not parse IP address")

A single such member is enough to abort the whole configure_members() pass. The most common trigger in practice is an authorized member with no IPv4 assignment (e.g. an iOS/cellular client that has joined but not been assigned a managed IP). Because find_members() runs on a refresh loop and the process is normally run under a supervisor that restarts it on exit (launchd KeepAlive, systemd Restart=, Docker restart:), the panic becomes a crash loop that takes DNS down for the entire network until the offending member is given an IP or deauthorized.

Fix

Make ZTRecord::new() total:

  • return an Err (the caller logs a warning and continues to the next member) when node_id is missing;
  • treat a missing config as "no IP assignments";
  • filter_map IP parsing so an unparseable address is dropped instead of fatal.

This mirrors the defensive filter_map already used a few lines up in configure_members() for the reverse-PTR path, so the two code paths now handle malformed member data consistently. A member with no usable IPs simply gets a hostname record with no A/AAAA (which match_or_insert already handles), instead of crashing the server.

No behavior change for well-formed members.

ZTRecord::new() panics via .expect() when a network member lacks a node_id
or config, or has an unparseable ip_assignment. A single such member (e.g. an
authorized iOS/cellular client with no IPv4 assignment) brings down the whole
server; under a process supervisor with restart-on-exit this becomes a crash
loop that takes DNS down for the entire network.

Make ZTRecord::new total: return an error (caller logs and skips the member)
when node_id is missing, treat a missing config as no IP assignments, and
filter_map IP parsing so an unparseable address is dropped rather than fatal.
This mirrors the defensive filter_map already used in configure_members().
@CLAassistant

Copy link
Copy Markdown

CLA assistant check
Thank you for your submission! We really appreciate it. Like many open source projects, we ask that you sign our Contributor License Agreement before we can accept your contribution.


Eric DeWitt seems not to be a GitHub user. You need a GitHub account to be able to sign the CLA. If you have already a GitHub account, please add the email address used for this commit to your account.
You have signed the CLA already but the status is still pending? Let us recheck it.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants