[PATCH v2] tcp: Store the owner connections for flags frames
There is an issue reported by Volker Diels-Grabsch and Boleyn Su.
A segmentation fault occurs when executing the following command:
(sleep 0.1; ssh -p 22000 127.0.0.1) & passt -f -t 22000:22
It's caused by commit 78da088f7bab ("tcp: unify payload and flags
l2 frames array"). Fix it by storing the owner connections of flags
frames into tcp_frame_conns[] array.
Reported-by: Volker Diels-Grabsch
Dear Yumei, Thanks a lot for providing a proper fix for that issue. Just a minor nitpick from my side: Yumei Huang wrote:
@@ -209,13 +209,14 @@ int tcp_buf_send_flag(const struct ctx *c, struct tcp_tap_conn *conn, int flags) if (ret <= 0) return ret;
- tcp_payload_used++; + tcp_frame_conns[tcp_payload_used++] = conn; l4len = optlen + sizeof(struct tcphdr); iov[TCP_IOV_PAYLOAD].iov_len = l4len; tcp_l2_buf_fill_headers(conn, iov, NULL, seq, false);
if (flags & DUP_ACK) { struct iovec *dup_iov = tcp_l2_iov[tcp_payload_used++]; + tcp_frame_conns[tcp_payload_used - 1] = conn;
I find it a bit strange to read that way, incrementing tcp_payload_used just to subtract one from it in the next step. I, personally, would find it easier to read and to understand that way around: struct iovec *dup_iov = tcp_l2_iov[tcp_payload_used]; tcp_frame_conns[tcp_payload_used++] = conn; But maybe it's just me. Best regards, Volker -- .---<<<((()))>>>---. | [[||]] | '---<<<((()))>>>---'
participants (2)
-
Volker Diels-Grabsch
-
Yumei Huang