From: "Daniel Zahka" <daniel.zahka@gmail.com>
To: "Kuniyuki Iwashima" <kuniyu@google.com>,
"David S . Miller" <davem@davemloft.net>,
"Eric Dumazet" <edumazet@google.com>,
"Jakub Kicinski" <kuba@kernel.org>,
"Paolo Abeni" <pabeni@redhat.com>,
"Neal Cardwell" <ncardwell@google.com>,
"Willem de Bruijn" <willemb@google.com>,
"David Ahern" <dsahern@kernel.org>,
"Ido Schimmel" <idosch@nvidia.com>
Cc: "Simon Horman" <horms@kernel.org>,
"Kuniyuki Iwashima" <kuni1840@gmail.com>,
<netdev@vger.kernel.org>, "Kyle Zeng" <kylebot@openai.com>,
"Michal Luczaj" <mhal@rbox.co>, "Hyunwoo Kim" <imv4bel@gmail.com>
Subject: Re: [PATCH v1 net-next 1/2] tcp: Do not allow buggy transitions between ehash and lhash2.
Date: Thu, 17 Sep 2026 08:49:37 -0400 [thread overview]
Message-ID: <DLHLRA8GVI5B.2Q1IRQG5BVJNZ@gmail.com> (raw)
In-Reply-To: <20260904033543.2635540-2-kuniyu@google.com>
On Thu Sep 3, 2026 at 11:35 PM EDT, Kuniyuki Iwashima wrote:
> The following state transitions have long been a playground for
> syzbot, and recently AI joined in, reporting a lot more bugs.
>
> * listen() + shutdown() + connect()
> * connect() + connect(AF_UNSPEC) + listen()
Hi there. Thanks for closing these. I'm wondering if connect() ->
listen() via timewait is intentionally left open?
0 socket(..., SOCK_STREAM, IPPROTO_TCP) = 3
+.01...0.011 connect(3, ..., ...) = 0
+0 > S 0:0(0) <...>
+0 < S. 0:0(0) ack 1 win 32000 <mss 1460,nop,wscale 7>
+0 > . 1:1(0) ack 1
+0 shutdown(3, SHUT_WR) = 0
+0 > F. 1:1(0) ack 1
+0 < . 1:1(0) ack 2 win 257
+0 < F. 1:1(0) ack 2 win 257
+0 > . 2:2(0) ack 2
+0 connect(3, AF_UNSPEC, ...) = 0
+0 listen(3, 1) = 0
For PSP, this allows us to end up with a listen socket with PSP state,
because we don't clear it out in tcp_disconnect(). I'm planning a series
to remove PSP on listen sockets, and closing this would make that a lot
easier.
next prev parent reply other threads:[~2026-09-17 12:49 UTC|newest]
Thread overview: 16+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-04 3:35 [PATCH v1 net-next 0/2] net: Disallow buggy TCP transitions and IPV6_ADDRFORM Kuniyuki Iwashima
2026-09-04 3:35 ` [PATCH v1 net-next 1/2] tcp: Do not allow buggy transitions between ehash and lhash2 Kuniyuki Iwashima
2026-09-04 11:32 ` Jakub Sitnicki
2026-09-07 4:19 ` netdev-bot+sashiko
2026-09-17 12:49 ` Daniel Zahka [this message]
2026-09-17 18:36 ` Kuniyuki Iwashima
2026-09-04 3:35 ` [PATCH v1 net-next 2/2] ipv6: Remove IPV6_ADDRFORM Kuniyuki Iwashima
2026-09-04 9:10 ` Paolo Abeni
2026-09-07 4:19 ` netdev-bot+sashiko
2026-09-08 9:21 ` David Laight
2026-09-08 1:00 ` [PATCH v1 net-next 0/2] net: Disallow buggy TCP transitions and IPV6_ADDRFORM patchwork-bot+netdevbpf
2026-09-18 22:35 ` Hyunwoo Kim
2026-09-19 21:20 ` Jakub Kicinski
2026-09-20 7:45 ` Greg Kroah-Hartman
2026-09-21 17:23 ` Jakub Kicinski
2026-09-22 0:42 ` Hyunwoo Kim
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=DLHLRA8GVI5B.2Q1IRQG5BVJNZ@gmail.com \
--to=daniel.zahka@gmail.com \
--cc=davem@davemloft.net \
--cc=dsahern@kernel.org \
--cc=edumazet@google.com \
--cc=horms@kernel.org \
--cc=idosch@nvidia.com \
--cc=imv4bel@gmail.com \
--cc=kuba@kernel.org \
--cc=kuni1840@gmail.com \
--cc=kuniyu@google.com \
--cc=kylebot@openai.com \
--cc=mhal@rbox.co \
--cc=ncardwell@google.com \
--cc=netdev@vger.kernel.org \
--cc=pabeni@redhat.com \
--cc=willemb@google.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.