From: Eric Dumazet <edumazet@kernel.org>
To: "David S . Miller" <davem@davemloft.net>,
Jakub Kicinski <kuba@kernel.org>, Paolo Abeni <pabeni@redhat.com>
Cc: Simon Horman <horms@kernel.org>,
Neal Cardwell <ncardwell@google.com>,
Kuniyuki Iwashima <kuniyu@google.com>,
David Ahern <dsahern@kernel.org>,
Ido Schimmel <idosch@nvidia.com>,
edumazet@google.com, netdev@vger.kernel.org,
Eric Dumazet <edumazet@kernel.org>
Subject: [PATCH v2 net-next] ipv4: use zero IPID for atomic datagrams on connected sockets
Date: Thu, 1 Oct 2026 15:56:33 +0000 [thread overview]
Message-ID: <20261001155633.2562504-1-edumazet@kernel.org> (raw)
ip_select_ident_segs() uses the per-socket private generator
for connected sockets, even for packets with IP_DF set.
This was historically done to work around buggy Windows95/2000
VJ header compression implementations, dropping every other
packet in a TCP stream when the IP ID field did not change.
RFC 6864 section 4.2 states that "Originating sources MAY set the
IPv4 ID field of atomic datagrams to any value".
Packets with IP_DF set and skb->ignore_df cleared can not be
fragmented, neither locally (ip_fragment() refuses to do so)
nor by routers on the path.
Set their IPID to zero, like we already do for unconnected sockets
and in ip_build_and_send_pkt(). FreeBSD also does the same by
default (net.inet.ip.rfc6864 = 1).
For GSO packets, segments get IP IDs 0, 1, ..., n-1 from GSO/TSO.
This does not hurt GRO on receivers, because TCP already forces
a PSH flag on every TSO packet since commit 051ba67447de
("tcp: force a PSH flag on TSO packets"), so GRO already flushes
at TSO packet boundaries.
Connected sockets still use their private generator for packets
without IP_DF, or with skb->ignore_df set. Update the inet_id
kernel-doc accordingly.
This avoids an atomic operation on a shared cache line for
connected UDP sockets using IP_PMTUDISC_DO/IP_PMTUDISC_PROBE,
and TCP no longer touches inet->inet_id in the fast path.
Minor side effects: IP IDs can no longer be used to distinguish
network duplicates from TCP retransmits, or to correlate packet
captures taken at different points. OS fingerprints will also change.
Signed-off-by: Eric Dumazet <edumazet@kernel.org>
Reviewed-by: David Ahern <dsahern@kernel.org>
Reviewed-by: Kuniyuki Iwashima <kuniyu@google.com>
---
v2: update inet_id kernel-doc in include/net/inet_sock.h (Sashiko)
mention GSO/GRO behavior in the changelog.
v1: https://lore.kernel.org/netdev/20260929153834.566551-1-edumazet@kernel.org/
---
include/net/inet_sock.h | 2 +-
include/net/ip.h | 15 +++++++++------
2 files changed, 10 insertions(+), 7 deletions(-)
diff --git a/include/net/inet_sock.h b/include/net/inet_sock.h
index 7cdcbed3e5cbfd1a13698942da05b9ceabf72950..24cbabc2458231d0b0a449d30194508a58f2e415 100644
--- a/include/net/inet_sock.h
+++ b/include/net/inet_sock.h
@@ -207,7 +207,7 @@ struct rtable;
* @inet_saddr - Sending source
* @uc_ttl - Unicast TTL
* @inet_sport - Source port
- * @inet_id - ID counter for DF pkts
+ * @inet_id - ID counter for non atomic pkts
* @tos - TOS
* @mc_ttl - Multicasting TTL
* @uc_index - Unicast outgoing device index
diff --git a/include/net/ip.h b/include/net/ip.h
index 6f602df72ee621ee4ee45e70beef0a1b5145367f..ffa4ba0b571fc42ba9855e2f3bbcb1c6d12a1e1d 100644
--- a/include/net/ip.h
+++ b/include/net/ip.h
@@ -584,6 +584,13 @@ static inline void ip_select_ident_segs(struct net *net, struct sk_buff *skb,
{
struct iphdr *iph = ip_hdr(skb);
+ /* RFC 6864: the IPv4 ID of atomic datagrams has no meaning.
+ * DF packets without ignore_df can not be fragmented.
+ */
+ if ((iph->frag_off & htons(IP_DF)) && !skb->ignore_df) {
+ iph->id = 0;
+ return;
+ }
/* We had many attacks based on IPID, use the private
* generator as much as we can.
*/
@@ -603,12 +610,8 @@ static inline void ip_select_ident_segs(struct net *net, struct sk_buff *skb,
iph->id = htons(val);
return;
}
- if ((iph->frag_off & htons(IP_DF)) && !skb->ignore_df) {
- iph->id = 0;
- } else {
- /* Unfortunately we need the big hammer to get a suitable IPID */
- __ip_select_ident(net, iph, segs);
- }
+ /* Unfortunately we need the big hammer to get a suitable IPID */
+ __ip_select_ident(net, iph, segs);
}
static inline void ip_select_ident(struct net *net, struct sk_buff *skb,
--
2.56.0.rc1.315.gc6ed9934b7-goog
next reply other threads:[~2026-10-01 15:56 UTC|newest]
Thread overview: 2+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-01 15:56 Eric Dumazet [this message]
2026-10-05 23:00 ` [PATCH v2 net-next] ipv4: use zero IPID for atomic datagrams on connected sockets patchwork-bot+netdevbpf
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20261001155633.2562504-1-edumazet@kernel.org \
--to=edumazet@kernel.org \
--cc=davem@davemloft.net \
--cc=dsahern@kernel.org \
--cc=edumazet@google.com \
--cc=horms@kernel.org \
--cc=idosch@nvidia.com \
--cc=kuba@kernel.org \
--cc=kuniyu@google.com \
--cc=ncardwell@google.com \
--cc=netdev@vger.kernel.org \
--cc=pabeni@redhat.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox