From: Hannes Frederic Sowa <hannes@stressinduktion.org>
To: David Miller <davem@davemloft.net>
Cc: netdev@vger.kernel.org, fw@strlen.de
Subject: Re: [PATCH net] tcp: don't allow syn packets without timestamps to pass tcp_tw_recycle logic
Date: Thu, 14 Aug 2014 11:37:45 +0200 [thread overview]
Message-ID: <1408009065.2751.6.camel@localhost> (raw)
In-Reply-To: <1407830922.3313272.151751729.150ABE1E@webmail.messagingengine.com>
Hi David,
On Di, 2014-08-12 at 10:08 +0200, Hannes Frederic Sowa wrote:
>
> On Tue, Aug 12, 2014, at 05:08, David Miller wrote:
> > From: Hannes Frederic Sowa <hannes@stressinduktion.org>
> > Date: Tue, 12 Aug 2014 02:21:36 +0200
> >
> > > Thus this broken situation could easily arise by a Linux and Windows
> > > box sharing one IP address and talking to a tcp_tw_recycle enabled
> > > server.
> >
> > As Eric Dumazet mentioned, timewait recycling does not work if any
> > traffic goes through a NAT box.
> >
> > So this situation of two boxes "sharing one IP address" fundamentally
> > makes timewait recycling unusable.
>
> Exactly, I'll just throw away the SYN packet instead of opening a
> connection where we couldn't very if the preconditions for timewait
> recycling did not hold.
did you have a chance to look at this patch again?
I found this during code review. Non time stamped SYN packets could
eventually trigger the completion of a 3WHS even though we had
tw_recycle enabled and the SYN arrived in a TCP_PAWS_MSL of this host
period.
I don't want to make this feature more general usable (without time
stamps), they are absolutely required. It just adds protection against
accidental 3WHS completion of 3WHS if a packet without time stamps
arrived.
I don't have a strong opinion on that but it just seems to be natural,
as we also conditional schedule the timeout for the tw buckets depending
on if we saw time stamps on the prior connection.
Thanks,
Hannes
next prev parent reply other threads:[~2014-08-14 9:37 UTC|newest]
Thread overview: 8+ messages / expand[flat|nested] mbox.gz Atom feed top
2014-08-12 0:21 [PATCH net] tcp: don't allow syn packets without timestamps to pass tcp_tw_recycle logic Hannes Frederic Sowa
2014-08-12 1:32 ` Eric Dumazet
2014-08-12 8:03 ` Hannes Frederic Sowa
2014-08-12 3:08 ` David Miller
2014-08-12 8:08 ` Hannes Frederic Sowa
2014-08-14 9:37 ` Hannes Frederic Sowa [this message]
2014-08-14 15:38 ` Eric Dumazet
2014-08-14 18:39 ` Hannes Frederic Sowa
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=1408009065.2751.6.camel@localhost \
--to=hannes@stressinduktion.org \
--cc=davem@davemloft.net \
--cc=fw@strlen.de \
--cc=netdev@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).