public inbox for passt-dev@passt.top
 help / color / mirror / code / Atom feed
From: Stefano Brivio <sbrivio@redhat.com>
To: David Gibson <david@gibson.dropbear.id.au>
Cc: passt-dev@passt.top
Subject: Re: Migration failure across bridge
Date: Tue, 18 Mar 2025 09:28:23 +0100	[thread overview]
Message-ID: <20250318092823.0bca8887@elisabeth> (raw)
In-Reply-To: <Z9kC9q8ZHoZVChHo@zatzit>

On Tue, 18 Mar 2025 16:21:58 +1100
David Gibson <david@gibson.dropbear.id.au> wrote:

> Continued investigating the problem with migration failing across a
> bridge.
> 
> Good news is I've found the problem... or at least one problem.

\o/

> Bad
> news is we'll have to change the migration stream format to fix it.

Whoops, sorry, my bad. And now, RFC 7323, section 3.2, contrary to RFC
1323 (also section 3.2), requires that we keep sending timestamps if we
negotiated them:

   Once TSopt has been successfully negotiated, that is both <SYN> and
   <SYN,ACK> contain TSopt, the TSopt MUST be sent in every non-<RST>
   segment for the duration of the connection

...so we can't just disable them for migrated flows.

Strictly speaking, I don't think it's necessary to define a new version
of the format, because I'm really really sure nobody is using this yet,
other than for tests.

If you want to use this as a chance to play with/test a version bump,
we can do it. My preference would be to keep this as v1 anyway for the
moment, regardless of the *non*-breakage, for simplicity. That is,
whoops, migration is broken on 2025_02_17.a1e48a0.

> The packets are being dropped in tcp_validate_incoming() due to a
> failed PAWS check (skb drop reason "TCP_RFC7323_PAWS").  That in turn
> looks to be because we don't preserve TCP timestamp state across the
> migration.  We preserve _whether_ TCP timestamps are active on the
> connection (TCPOPT_TIMESTAMP entry in TCP_REPAIR_OPTIONS), but we
> don't preserve the current timestamp values (TCP_TIMESTAMP socket
> option).  The equivalent CRIU code is
> 
> https://github.com/checkpoint-restore/criu/blob/d18912fc88f3dc7bde5fdfa3575691977eb21753/soccr/soccr.c#L266
> 
> and
> 
> https://github.com/checkpoint-restore/criu/blob/d18912fc88f3dc7bde5fdfa3575691977eb21753/soccr/soccr.c#L572
> 
> I'll work on writing a fix tomorrow.
> 
> Not yet sure why we didn't hit this with a local migration.  I'm
> guessing some part of being a local connection means we're bypassing
> the PAWS check.

The TCP_TIMESTAMP option is documented... not where it should be
documented, grr:

  https://criu.org/index.php?title=TCP_connection#Timestamp

and I _guess_ that two guests using kvm-clock as clock source might
actually have the same jiffies, and from this description, same
jiffies, same timestamps.

Perhaps in your nested case not all guests are using kvm-clock, or
there's something else to it.

-- 
Stefano


      reply	other threads:[~2025-03-18  8:28 UTC|newest]

Thread overview: 2+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2025-03-18  5:21 Migration failure across bridge David Gibson
2025-03-18  8:28 ` Stefano Brivio [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20250318092823.0bca8887@elisabeth \
    --to=sbrivio@redhat.com \
    --cc=david@gibson.dropbear.id.au \
    --cc=passt-dev@passt.top \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
Code repositories for project(s) associated with this public inbox

	https://passt.top/passt

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for IMAP folder(s).