public inbox for passt-dev@passt.top
 help / color / mirror / code / Atom feed
* [PATCH v3] tcp: Store the owner connections for flags frames
@ 2025-09-11  1:09 Yumei Huang
  2025-09-11  2:31 ` David Gibson
  2025-09-11 15:45 ` Stefano Brivio
  0 siblings, 2 replies; 3+ messages in thread
From: Yumei Huang @ 2025-09-11  1:09 UTC (permalink / raw)
  To: passt-dev; +Cc: sbrivio, david, boleyn.su, v, jmaloy, yuhuang

There is an issue reported by Volker Diels-Grabsch and Boleyn Su.
A segmentation fault occurs when executing the following command:

	(sleep 0.1; ssh -p 22000 127.0.0.1) & passt -f -t 22000:22

It's caused by commit 78da088f7bab ("tcp: unify payload and flags
l2 frames array"). Fix it by storing the owner connections of flags
frames into tcp_frame_conns[] array.

Reported-by: Volker Diels-Grabsch <v@njh.eu>
Reported-by: Boleyn Su <boleyn.su@gmail.com>
Suggested-by: David Gibson <david@gibson.dropbear.id.au>
Fixes: 78da088f7bab ("tcp: unify payload and flags l2 frames array")
Signed-off-by: Yumei Huang <yuhuang@redhat.com>
---
 tcp_buf.c | 5 +++--
 1 file changed, 3 insertions(+), 2 deletions(-)

diff --git a/tcp_buf.c b/tcp_buf.c
index bc898de..d63c18d 100644
--- a/tcp_buf.c
+++ b/tcp_buf.c
@@ -209,13 +209,14 @@ int tcp_buf_send_flag(const struct ctx *c, struct tcp_tap_conn *conn, int flags)
 	if (ret <= 0)
 		return ret;
 
-	tcp_payload_used++;
+	tcp_frame_conns[tcp_payload_used++] = conn;
 	l4len = optlen + sizeof(struct tcphdr);
 	iov[TCP_IOV_PAYLOAD].iov_len = l4len;
 	tcp_l2_buf_fill_headers(conn, iov, NULL, seq, false);
 
 	if (flags & DUP_ACK) {
-		struct iovec *dup_iov = tcp_l2_iov[tcp_payload_used++];
+		struct iovec *dup_iov = tcp_l2_iov[tcp_payload_used];
+		tcp_frame_conns[tcp_payload_used++] = conn;
 
 		memcpy(dup_iov[TCP_IOV_TAP].iov_base, iov[TCP_IOV_TAP].iov_base,
 		       iov[TCP_IOV_TAP].iov_len);
-- 
@@ -209,13 +209,14 @@ int tcp_buf_send_flag(const struct ctx *c, struct tcp_tap_conn *conn, int flags)
 	if (ret <= 0)
 		return ret;
 
-	tcp_payload_used++;
+	tcp_frame_conns[tcp_payload_used++] = conn;
 	l4len = optlen + sizeof(struct tcphdr);
 	iov[TCP_IOV_PAYLOAD].iov_len = l4len;
 	tcp_l2_buf_fill_headers(conn, iov, NULL, seq, false);
 
 	if (flags & DUP_ACK) {
-		struct iovec *dup_iov = tcp_l2_iov[tcp_payload_used++];
+		struct iovec *dup_iov = tcp_l2_iov[tcp_payload_used];
+		tcp_frame_conns[tcp_payload_used++] = conn;
 
 		memcpy(dup_iov[TCP_IOV_TAP].iov_base, iov[TCP_IOV_TAP].iov_base,
 		       iov[TCP_IOV_TAP].iov_len);
-- 
2.47.0


^ permalink raw reply related	[flat|nested] 3+ messages in thread

* Re: [PATCH v3] tcp: Store the owner connections for flags frames
  2025-09-11  1:09 [PATCH v3] tcp: Store the owner connections for flags frames Yumei Huang
@ 2025-09-11  2:31 ` David Gibson
  2025-09-11 15:45 ` Stefano Brivio
  1 sibling, 0 replies; 3+ messages in thread
From: David Gibson @ 2025-09-11  2:31 UTC (permalink / raw)
  To: Yumei Huang; +Cc: passt-dev, sbrivio, boleyn.su, v, jmaloy

[-- Attachment #1: Type: text/plain, Size: 1900 bytes --]

On Thu, Sep 11, 2025 at 09:09:36AM +0800, Yumei Huang wrote:
> There is an issue reported by Volker Diels-Grabsch and Boleyn Su.
> A segmentation fault occurs when executing the following command:
> 
> 	(sleep 0.1; ssh -p 22000 127.0.0.1) & passt -f -t 22000:22
> 
> It's caused by commit 78da088f7bab ("tcp: unify payload and flags
> l2 frames array"). Fix it by storing the owner connections of flags
> frames into tcp_frame_conns[] array.
> 
> Reported-by: Volker Diels-Grabsch <v@njh.eu>
> Reported-by: Boleyn Su <boleyn.su@gmail.com>
> Suggested-by: David Gibson <david@gibson.dropbear.id.au>
> Fixes: 78da088f7bab ("tcp: unify payload and flags l2 frames array")
> Signed-off-by: Yumei Huang <yuhuang@redhat.com>

Reviewed-by: David Gibson <david@gibson.dropbear.id.au>

> ---
>  tcp_buf.c | 5 +++--
>  1 file changed, 3 insertions(+), 2 deletions(-)
> 
> diff --git a/tcp_buf.c b/tcp_buf.c
> index bc898de..d63c18d 100644
> --- a/tcp_buf.c
> +++ b/tcp_buf.c
> @@ -209,13 +209,14 @@ int tcp_buf_send_flag(const struct ctx *c, struct tcp_tap_conn *conn, int flags)
>  	if (ret <= 0)
>  		return ret;
>  
> -	tcp_payload_used++;
> +	tcp_frame_conns[tcp_payload_used++] = conn;
>  	l4len = optlen + sizeof(struct tcphdr);
>  	iov[TCP_IOV_PAYLOAD].iov_len = l4len;
>  	tcp_l2_buf_fill_headers(conn, iov, NULL, seq, false);
>  
>  	if (flags & DUP_ACK) {
> -		struct iovec *dup_iov = tcp_l2_iov[tcp_payload_used++];
> +		struct iovec *dup_iov = tcp_l2_iov[tcp_payload_used];
> +		tcp_frame_conns[tcp_payload_used++] = conn;
>  
>  		memcpy(dup_iov[TCP_IOV_TAP].iov_base, iov[TCP_IOV_TAP].iov_base,
>  		       iov[TCP_IOV_TAP].iov_len);
> -- 
> 2.47.0
> 

-- 
David Gibson (he or they)	| I'll have my music baroque, and my code
david AT gibson.dropbear.id.au	| minimalist, thank you, not the other way
				| around.
http://www.ozlabs.org/~dgibson

[-- Attachment #2: signature.asc --]
[-- Type: application/pgp-signature, Size: 833 bytes --]

^ permalink raw reply	[flat|nested] 3+ messages in thread

* Re: [PATCH v3] tcp: Store the owner connections for flags frames
  2025-09-11  1:09 [PATCH v3] tcp: Store the owner connections for flags frames Yumei Huang
  2025-09-11  2:31 ` David Gibson
@ 2025-09-11 15:45 ` Stefano Brivio
  1 sibling, 0 replies; 3+ messages in thread
From: Stefano Brivio @ 2025-09-11 15:45 UTC (permalink / raw)
  To: Yumei Huang; +Cc: passt-dev, david, boleyn.su, v, jmaloy

On Thu, 11 Sep 2025 09:09:36 +0800
Yumei Huang <yuhuang@redhat.com> wrote:

> There is an issue reported by Volker Diels-Grabsch and Boleyn Su.
> A segmentation fault occurs when executing the following command:
> 
> 	(sleep 0.1; ssh -p 22000 127.0.0.1) & passt -f -t 22000:22
> 
> It's caused by commit 78da088f7bab ("tcp: unify payload and flags
> l2 frames array"). Fix it by storing the owner connections of flags
> frames into tcp_frame_conns[] array.
> 
> Reported-by: Volker Diels-Grabsch <v@njh.eu>
> Reported-by: Boleyn Su <boleyn.su@gmail.com>
> Suggested-by: David Gibson <david@gibson.dropbear.id.au>
> Fixes: 78da088f7bab ("tcp: unify payload and flags l2 frames array")
> Signed-off-by: Yumei Huang <yuhuang@redhat.com>

Applied.

-- 
Stefano


^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2025-09-11 15:45 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2025-09-11  1:09 [PATCH v3] tcp: Store the owner connections for flags frames Yumei Huang
2025-09-11  2:31 ` David Gibson
2025-09-11 15:45 ` Stefano Brivio

Code repositories for project(s) associated with this public inbox

	https://passt.top/passt

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for IMAP folder(s).