• Alex Tomlins's avatar
    Fix deadlock with iptables with large ruleset · d43db80d
    Alex Tomlins authored
    When running sshuttle with a large list of routes it's failing to clean
    them up at exit. It returns the following:
    
    $ sshuttle -r user@host.example.com -s /tmp/aws-cidrs.txt
    user@host.example.com's password:
    client: Connected.
    ^CAnother app is currently holding the xtables lock; still -9s 0us time ahead to have a chance to grab the lock...
    Another app is currently holding the xtables lock; still -19s 0us time ahead to have a chance to grab the lock...
    Another app is currently holding the xtables lock; still -29s 0us time ahead to have a chance to grab the lock...
    
    This continues indefinitely. Looking in ps reveals that there are 2
    iptables processes running. Killing -9 the first one, allows sshuttle to
    continue and clean up successfully.
    
    The problem lies with the use of Popen here. The function currently
    returns as soon as it finds a match without consuming everything from
    stdout. This means that if there's more output from iptables than will
    fit in the buffer it doesn't exit, and therefore doesn't release the
    kernel xtables lock.
    d43db80d
Name
Last commit
Last update
docs Loading commit data...
sshuttle Loading commit data...
tests Loading commit data...
.gitignore Loading commit data...
.prospector.yml Loading commit data...
.travis.yml Loading commit data...
CHANGES.rst Loading commit data...
LICENSE Loading commit data...
MANIFEST.in Loading commit data...
README.rst Loading commit data...
bandit.yml Loading commit data...
requirements-tests.txt Loading commit data...
requirements.txt Loading commit data...
run Loading commit data...
setup.cfg Loading commit data...
setup.py Loading commit data...
tox.ini Loading commit data...