From: Eric Dumazet <edumazet@kernel.org>
To: "David S . Miller" <davem@davemloft.net>,
Jakub Kicinski <kuba@kernel.org>, Paolo Abeni <pabeni@redhat.com>
Cc: Simon Horman <horms@kernel.org>,
Neal Cardwell <ncardwell@google.com>,
Kuniyuki Iwashima <kuniyu@google.com>,
David Ahern <dsahern@kernel.org>,
Ido Schimmel <idosch@nvidia.com>,
edumazet@google.com, netdev@vger.kernel.org,
Eric Dumazet <edumazet@kernel.org>
Subject: [PATCH net-next] ipv4: use zero IPID for atomic datagrams on connected sockets
Date: Tue, 29 Sep 2026 15:38:34 +0000 [thread overview]
Message-ID: <20260929153834.566551-1-edumazet@kernel.org> (raw)
ip_select_ident_segs() uses the per-socket private generator
for connected sockets, even for packets with IP_DF set.
This was historically done to work around buggy Windows95/2000
VJ header compression implementations, dropping every other
packet in a TCP stream when the IP ID field did not change.
RFC 6864 section 4.2 states that "Originating sources MAY set the
IPv4 ID field of atomic datagrams to any value".
Packets with IP_DF set and skb->ignore_df cleared can not be
fragmented, neither locally (ip_fragment() refuses to do so)
nor by routers on the path.
Set their IPID to zero, like we already do for unconnected sockets
and in ip_build_and_send_pkt(). FreeBSD also does the same by
default (net.inet.ip.rfc6864 = 1).
Connected sockets still use their private generator for packets
without IP_DF, or with skb->ignore_df set.
This avoids an atomic operation on a shared cache line for
connected UDP sockets using IP_PMTUDISC_DO/IP_PMTUDISC_PROBE,
and TCP no longer touches inet->inet_id in the fast path.
Minor side effects: IP IDs can no longer be used to distinguish
network duplicates from TCP retransmits, or to correlate packet
captures taken at different points. OS fingerprints will also change.
Signed-off-by: Eric Dumazet <edumazet@kernel.org>
---
include/net/ip.h | 15 +++++++++------
1 file changed, 9 insertions(+), 6 deletions(-)
diff --git a/include/net/ip.h b/include/net/ip.h
index 6f602df72ee621ee4ee45e70beef0a1b5145367f..ffa4ba0b571fc42ba9855e2f3bbcb1c6d12a1e1d 100644
--- a/include/net/ip.h
+++ b/include/net/ip.h
@@ -584,6 +584,13 @@ static inline void ip_select_ident_segs(struct net *net, struct sk_buff *skb,
{
struct iphdr *iph = ip_hdr(skb);
+ /* RFC 6864: the IPv4 ID of atomic datagrams has no meaning.
+ * DF packets without ignore_df can not be fragmented.
+ */
+ if ((iph->frag_off & htons(IP_DF)) && !skb->ignore_df) {
+ iph->id = 0;
+ return;
+ }
/* We had many attacks based on IPID, use the private
* generator as much as we can.
*/
@@ -603,12 +610,8 @@ static inline void ip_select_ident_segs(struct net *net, struct sk_buff *skb,
iph->id = htons(val);
return;
}
- if ((iph->frag_off & htons(IP_DF)) && !skb->ignore_df) {
- iph->id = 0;
- } else {
- /* Unfortunately we need the big hammer to get a suitable IPID */
- __ip_select_ident(net, iph, segs);
- }
+ /* Unfortunately we need the big hammer to get a suitable IPID */
+ __ip_select_ident(net, iph, segs);
}
static inline void ip_select_ident(struct net *net, struct sk_buff *skb,
--
2.56.0.rc1.315.gc6ed9934b7-goog
next reply other threads:[~2026-09-29 15:38 UTC|newest]
Thread overview: 5+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-29 15:38 Eric Dumazet [this message]
2026-09-30 12:37 ` [PATCH net-next] ipv4: use zero IPID for atomic datagrams on connected sockets David Ahern
2026-10-01 5:09 ` Kuniyuki Iwashima
2026-10-01 9:29 ` netdev-bot+sashiko
2026-10-01 15:50 ` Eric Dumazet
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260929153834.566551-1-edumazet@kernel.org \
--to=edumazet@kernel.org \
--cc=davem@davemloft.net \
--cc=dsahern@kernel.org \
--cc=edumazet@google.com \
--cc=horms@kernel.org \
--cc=idosch@nvidia.com \
--cc=kuba@kernel.org \
--cc=kuniyu@google.com \
--cc=ncardwell@google.com \
--cc=netdev@vger.kernel.org \
--cc=pabeni@redhat.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox