diff options
| author | Runyu Xiao <runyu.xiao@seu.edu.cn> | 2026-06-11 12:21:20 +0800 |
|---|---|---|
| committer | Pablo Neira Ayuso <pablo@netfilter.org> | 2026-06-23 08:11:22 +0200 |
| commit | 11d4bc4e26fb66040a5b5d95e9abf37deac2b1fc (patch) | |
| tree | 6bd5a8bcfc744770877120d55c3ea79f934eb07d /tools/testing/selftests/net | |
| parent | 22f9dbed18bcc865d750ed109c6ae2dd4cf2af55 (diff) | |
| download | lwn-11d4bc4e26fb66040a5b5d95e9abf37deac2b1fc.tar.gz lwn-11d4bc4e26fb66040a5b5d95e9abf37deac2b1fc.zip | |
netfilter: nft_synproxy: stop bypassing the priv->info snapshot
nft_synproxy_eval_v4() and nft_synproxy_eval_v6() already take a
whole-object READ_ONCE() snapshot of the shared priv->info state before
building the SYNACK reply, but nft_synproxy_tcp_options() still masks
opts->options with priv->info.options from the live shared object.
When a named synproxy object is updated concurrently with SYN traffic,
the eval path can then mix mss and timestamp handling from the local
snapshot with an options mask taken from a newer configuration, so one
SYNACK no longer reflects a coherent synproxy configuration.
Use info->options so nft_synproxy_tcp_options() stays on the same local
snapshot that the eval path already copied from priv->info.
Fixes: ee394f96ad75 ("netfilter: nft_synproxy: add synproxy stateful object support")
Signed-off-by: Runyu Xiao <runyu.xiao@seu.edu.cn>
Reviewed-by: Fernando Fernandez Mancera <fmancera@suse.de>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Diffstat (limited to 'tools/testing/selftests/net')
0 files changed, 0 insertions, 0 deletions
