diff --git a/bin/cdp-relay-watchdog.sh b/bin/cdp-relay-watchdog.sh index 948312a..e8b2dd3 100755 --- a/bin/cdp-relay-watchdog.sh +++ b/bin/cdp-relay-watchdog.sh @@ -84,7 +84,10 @@ restart_relay() { port="${target##*:}" netns="warp-$node" # Kill any existing relay for this node's port (correct or not) - pkill -f "netvm-cdp-relay.py .* $port 127.0.0.1 $port" 2>/dev/null || true + # Relays are root-owned (started via sudo ip netns exec); the timer runs as + # super, so the kill needs sudo too. Without it pkill fails EPERM silently + # and the "restart" false-positives via SO_REUSEADDR double-bind. + sudo -n pkill -f "netvm-cdp-relay.py .* $port 127.0.0.1 $port" 2>/dev/null || true sleep 2 # Launch inside the netns, listening on the veth IP (host-reachable) sudo -n ip netns exec "$netns" setsid nohup python3 \