From: David Ahern <dsahern@kernel.org>
To: Eric Dumazet <edumazet@kernel.org>,
"David S . Miller" <davem@davemloft.net>,
Jakub Kicinski <kuba@kernel.org>, Paolo Abeni <pabeni@redhat.com>
Cc: Simon Horman <horms@kernel.org>,
Neal Cardwell <ncardwell@google.com>,
Kuniyuki Iwashima <kuniyu@google.com>,
Ido Schimmel <idosch@nvidia.com>,
edumazet@google.com, netdev@vger.kernel.org
Subject: Re: [PATCH net-next] ipv4: use zero IPID for atomic datagrams on connected sockets
Date: Wed, 30 Sep 2026 06:37:30 -0600 [thread overview]
Message-ID: <b752694c-6598-4ff6-a7b3-84a4903b296f@kernel.org> (raw)
In-Reply-To: <20260929153834.566551-1-edumazet@kernel.org>
On 9/29/26 10:38 AM, Eric Dumazet wrote:
> ip_select_ident_segs() uses the per-socket private generator
> for connected sockets, even for packets with IP_DF set.
>
> This was historically done to work around buggy Windows95/2000
> VJ header compression implementations, dropping every other
> packet in a TCP stream when the IP ID field did not change.
>
> RFC 6864 section 4.2 states that "Originating sources MAY set the
> IPv4 ID field of atomic datagrams to any value".
>
> Packets with IP_DF set and skb->ignore_df cleared can not be
> fragmented, neither locally (ip_fragment() refuses to do so)
> nor by routers on the path.
>
> Set their IPID to zero, like we already do for unconnected sockets
> and in ip_build_and_send_pkt(). FreeBSD also does the same by
> default (net.inet.ip.rfc6864 = 1).
>
> Connected sockets still use their private generator for packets
> without IP_DF, or with skb->ignore_df set.
>
> This avoids an atomic operation on a shared cache line for
> connected UDP sockets using IP_PMTUDISC_DO/IP_PMTUDISC_PROBE,
> and TCP no longer touches inet->inet_id in the fast path.
>
> Minor side effects: IP IDs can no longer be used to distinguish
> network duplicates from TCP retransmits, or to correlate packet
> captures taken at different points. OS fingerprints will also change.
>
> Signed-off-by: Eric Dumazet <edumazet@kernel.org>
> ---
> include/net/ip.h | 15 +++++++++------
> 1 file changed, 9 insertions(+), 6 deletions(-)
>
Reviewed-by: David Ahern <dsahern@kernel.org>
next prev parent reply other threads:[~2026-09-30 12:37 UTC|newest]
Thread overview: 5+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-29 15:38 [PATCH net-next] ipv4: use zero IPID for atomic datagrams on connected sockets Eric Dumazet
2026-09-30 12:37 ` David Ahern [this message]
2026-10-01 5:09 ` Kuniyuki Iwashima
2026-10-01 9:29 ` netdev-bot+sashiko
2026-10-01 15:50 ` Eric Dumazet
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=b752694c-6598-4ff6-a7b3-84a4903b296f@kernel.org \
--to=dsahern@kernel.org \
--cc=davem@davemloft.net \
--cc=edumazet@google.com \
--cc=edumazet@kernel.org \
--cc=horms@kernel.org \
--cc=idosch@nvidia.com \
--cc=kuba@kernel.org \
--cc=kuniyu@google.com \
--cc=ncardwell@google.com \
--cc=netdev@vger.kernel.org \
--cc=pabeni@redhat.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox