HydraIssues

Pairing cert rotation risk: always pair before stream start, never mid-stream
done unclassified Project: hydrahead Reporter: anonymous 20 May 2026 07:58

Description

Sunshine rotates its TLS cert on restart. If a head has a cached pairing state pointing to a body that has since restarted Sunshine, the next stream attempt uses a stale cert and fails silently. v2.0.63 fixed this by always re-pairing on every tick, but that caused a regression: pairWithSunshine calls stopMoonlightStream at the end, so an active stream was killed every 30 seconds. v2.0.67 reverted to cached pairingState, which avoids the kill regression but re-exposes cert staleness. The correct fix: always pair, but only when no stream is currently active. hydraheadipad already does this correctly via its state machine.