On Fri, Jul 17, 2026 at 10:15 AM Yuxiang Yang <[email protected]> wrote: > > The SYN-RECEIVED request-socket path in tcp_check_req() accepts an > in-window RST without requiring SEG.SEQ to exactly match RCV.NXT. A > non-exact RST therefore removes the request instead of eliciting a > challenge ACK. > > RFC 9293 section 3.10.7.4 applies the RFC 5961 reset check in > SYN-RECEIVED: an exact RST resets the connection, while a non-exact > in-window RST must trigger a challenge ACK and be dropped. > > Apply that check before the ACK-field validation, following the RFC > sequence-number, RST, then ACK processing order. Factor the per-netns > challenge ACK quota out of tcp_send_challenge_ack() so request sockets > can share it. Use the request socket's send_ack() callback and its own > out-of-window ACK timestamp to send and rate-limit the response. > > Reported-by: Yuxiang Yang <[email protected]> > Reported-by: Yizhou Zhao <[email protected]> > Reported-by: Ao Wang <[email protected]> > Reported-by: Xuewei Feng <[email protected]> > Reported-by: Qi Li <[email protected]> > Reported-by: Ke Xu <[email protected]> > Fixes: 282f23c6ee34 ("tcp: implement RFC 5961 3.2") > Cc: [email protected] > Signed-off-by: Yuxiang Yang <[email protected]>
Note : Please do not add a Reported-by: Yuxiang Yang <[email protected]> if you are the patch author. The amount of noise in this patch footer is quite annoying. Reviewed-by: Eric Dumazet <[email protected]>

