From: Adriano Cordova <adrianox@gmail.com>
To: Simon Horman <horms@verge.net.au>, Julian Anastasov <ja@ssi.bg>,
Pablo Neira Ayuso <pablo@netfilter.org>
Cc: Florian Westphal <fw@strlen.de>,
netfilter-devel@vger.kernel.org, lvs-devel@vger.kernel.org,
netdev@vger.kernel.org, linux-kernel@vger.kernel.org
Subject: [PATCH v6 nf-next 0/3] ipvs: add per-service secure_tcp
Date: Mon, 5 Oct 2026 20:08:05 -0300 [thread overview]
Message-ID: <20261005230808.148478-1-adrianox@gmail.com> (raw)
IPVS currently exposes secure_tcp as a per-netns sysctl. It switches the
TCP state machine to the hardened tcp_states_dos table.
These patches make it per-service: a virtual service can set
IP_VS_SVC_F_SECURE_TCP which is passed into IP_VS_CONN_F_SECURE_TCP at
connection creation. set_tcp_state() then selects tcp_states_dos for those
connections with IP_VS_CONN_F_SECURE_TCP set and keeps pd->tcp_state_table
(the netns default, including the nomem floor) otherwise.
1. uapi: define the per-service secure_tcp flags and stamp the flag in
ip_vs_bind_dest() (cache-bypass has no dest)
2. honor it in the TCP state machine, resolving the stale FIXME, and
document the new default/opt-in split
3. kselftest contrasting a secure vs. a plain service
Changes in v2:
- Let IP_VS_SVC_F_SECURE_TCP be 0x0100, leaving 0x0040/0x0080 for the
scheduler flags. Let IP_VS_CONN_F_SECURE_TCP be (1 << 17) and no longer
in IP_VS_CONN_F_BACKUP_MASK.
- Set flag in ip_vs_bind_dest() instead of at every ip_vs_conn_new()
call site.
- selftest: send probes with TTL=1 instead of an nft drop, and fix
Sashiko comments.
Changes in v3:
- Merge patch 1/4 and 2/4
- Re-send patches (v2 dropped patches 3/4 and 4/4)
Changes in v4:
- selftest: check the return values of setsockopt(IP_HDRINCL), sendto()
and mnl_socket_bind(), and fail do_add() when IPVS does not reply.
- selftest: fix the remaining Sashiko comments: check inet_pton(),
initialize fam and the parsed addresses, and verify the flags attribute
length before copying it.
Changes in v5:
- Document secure_tcp as the netns-wide default and the new per-service
IP_VS_SVC_F_SECURE_TCP opt-in.
- selftest: reword the changelog to "a bare SYN followed by a bare ACK".
- selftest: skip when the ip_vs or ip_vs_rr module is unavailable.
- selftest: check the probe exit status so that a probe which dies after
the SYN cannot leave the secure-side SYN_RECV assertion passing.
Changes in v6:
- Rebase onto nf-next.
Adriano Cordova (3):
ipvs: add flags for per-service secure TCP state table
ipvs: tcp: enable per-connection secure_tcp in state machine
selftests: netfilter: ipvs: add per-service secure_tcp test
Documentation/networking/ipvs-sysctl.rst | 4 +
include/uapi/linux/ip_vs.h | 2 +
net/netfilter/ipvs/ip_vs_conn.c | 4 +
net/netfilter/ipvs/ip_vs_core.c | 3 +
net/netfilter/ipvs/ip_vs_proto_tcp.c | 16 +-
.../testing/selftests/net/netfilter/Makefile | 6 +
.../selftests/net/netfilter/gen_tcp_probe.c | 158 ++++++++
.../net/netfilter/ipvs_secure_tcp.sh | 169 +++++++++
.../net/netfilter/ipvs_secure_tcp_mln.c | 337 ++++++++++++++++++
9 files changed, 692 insertions(+), 7 deletions(-)
create mode 100644 tools/testing/selftests/net/netfilter/gen_tcp_probe.c
create mode 100755 tools/testing/selftests/net/netfilter/ipvs_secure_tcp.sh
create mode 100644 tools/testing/selftests/net/netfilter/ipvs_secure_tcp_mln.c
base-commit: 8b4e7209c842d8cb9516f1f5ef0a88aa2d8831a6
--
2.51.0
next reply other threads:[~2026-10-05 23:08 UTC|newest]
Thread overview: 5+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-05 23:08 Adriano Cordova [this message]
2026-10-05 23:08 ` [PATCH v6 nf-next 1/3] ipvs: add flags for per-service secure TCP state table Adriano Cordova
2026-10-05 23:08 ` [PATCH v6 nf-next 2/3] ipvs: tcp: enable per-connection secure_tcp in state machine Adriano Cordova
2026-10-05 23:08 ` [PATCH v6 nf-next 3/3] selftests: netfilter: ipvs: add per-service secure_tcp test Adriano Cordova
2026-10-07 3:52 ` [PATCH v6 nf-next 0/3] ipvs: add per-service secure_tcp Julian Anastasov
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20261005230808.148478-1-adrianox@gmail.com \
--to=adrianox@gmail.com \
--cc=fw@strlen.de \
--cc=horms@verge.net.au \
--cc=ja@ssi.bg \
--cc=linux-kernel@vger.kernel.org \
--cc=lvs-devel@vger.kernel.org \
--cc=netdev@vger.kernel.org \
--cc=netfilter-devel@vger.kernel.org \
--cc=pablo@netfilter.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.