Netdev List
 help / color / mirror / Atom feed
From: Lilly Aronleigh <lilly@aronleigh.au>
To: steffen.klassert@secunet.com, herbert@gondor.apana.org.au
Cc: Lilly Aronleigh <lilly@aronleigh.au>,
	"David S. Miller" <davem@davemloft.net>,
	Eric Dumazet <edumazet@google.com>,
	Jakub Kicinski <kuba@kernel.org>, Paolo Abeni <pabeni@redhat.com>,
	Simon Horman <horms@kernel.org>,
	Christian Hopps <chopps@labn.net>,
	netdev@vger.kernel.org (open list:NETWORKING [IPSEC]),
	linux-kernel@vger.kernel.org (open list)
Subject: [PATCH net v3] xfrm: iptfs: avoid canceling reorder-window drop timer
Date: Mon, 24 Aug 2026 17:28:52 +1000	[thread overview]
Message-ID: <20260824072851.301644-3-lilly@aronleigh.au> (raw)

IP-TFS uses xtfs->drop_timer for both partial inner-packet
reassembly and the reorder-window drop timeout. Reassembly completion
currently cancels the timer unconditionally.

That is only correct when the reorder window is empty. If the reorder
window already contains saved packets, the same timer belongs to the
reorder-window state and must remain armed so the missing sequence can
be considered lost and the window can advance.

Only cancel drop_timer from __iptfs_reassem_done() when the reorder
window has no saved packets. The existing drop_lock serializes this
with the reorder-window paths, and a failed cancel remains harmless.

Tested with a reproducer that completes reassembly while the reorder
window contains saved packets.

With this change, the reorder-window timeout remains active and the
window can advance correctly when the missing sequence is not received.

Fixes: 0756947654468 ("xfrm: iptfs: handle received fragmented inner packets")
Assisted-by: ChatGPT:5.5-extrahigh
Assisted-by: Claude:4.6-opus
Signed-off-by: Lilly Aronleigh <lilly@aronleigh.au>

---
v3:
 - Resubmission via git send-email to fix formatting

v2:
 - Rebased onto current net tree
 - No functional changes

Link: https://lore.kernel.org/netdev/CAFrrV-O1fesaza+5_WqH8OciXRu9KKE4UsB6RcMamDu0j2-nBA@mail.gmail.com/T/#u
---
 net/xfrm/xfrm_iptfs.c | 8 ++++++--
 1 file changed, 6 insertions(+), 2 deletions(-)

diff --git a/net/xfrm/xfrm_iptfs.c b/net/xfrm/xfrm_iptfs.c
index 6920940a35b4..23e0face2b9f 100644
--- a/net/xfrm/xfrm_iptfs.c
+++ b/net/xfrm/xfrm_iptfs.c
@@ -707,8 +707,12 @@ static void __iptfs_reassem_done(struct xfrm_iptfs_data *xtfs, bool free)
 {
 	assert_spin_locked(&xtfs->drop_lock);
 
-	/* We don't care if it works locking takes care of things */
-	hrtimer_try_to_cancel(&xtfs->drop_timer);
+        /*
+         * The drop timer also drives the reorder window timeout. Locking makes
+         * a failed cancel harmless.
+         */
+        if (!xtfs->w_savedlen)
+                hrtimer_try_to_cancel(&xtfs->drop_timer);
 	if (free)
 		kfree_skb(xtfs->ra_newskb);
 	xtfs->ra_newskb = NULL;
-- 
2.43.0


                 reply	other threads:[~2026-08-24  7:31 UTC|newest]

Thread overview: [no followups] expand[flat|nested]  mbox.gz  Atom feed

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260824072851.301644-3-lilly@aronleigh.au \
    --to=lilly@aronleigh.au \
    --cc=chopps@labn.net \
    --cc=davem@davemloft.net \
    --cc=edumazet@google.com \
    --cc=herbert@gondor.apana.org.au \
    --cc=horms@kernel.org \
    --cc=kuba@kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=netdev@vger.kernel.org \
    --cc=pabeni@redhat.com \
    --cc=steffen.klassert@secunet.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox