From mboxrd@z Thu Jan 1 00:00:00 1970 Authentication-Results: passt.top; dmarc=pass (p=quarantine dis=none) header.from=redhat.com Authentication-Results: passt.top; dkim=pass (1024-bit key; unprotected) header.d=redhat.com header.i=@redhat.com header.a=rsa-sha256 header.s=mimecast20190719 header.b=Z0l0wHV1; dkim-atps=neutral Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.129.124]) by passt.top (Postfix) with ESMTPS id 381F15A0271 for ; Sat, 03 Oct 2026 00:26:31 +0200 (CEST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1790979990; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=VdXsP7AO99QphTtcEdUE4l5frB6YKv78X/bR4k6TQzQ=; b=Z0l0wHV1o14/aC3Vpagh9VSJNebgECnHRHpv0pd9Ki2+3OeJKc1aIlfmlx1YqzBG9jaKOb StY9aYmElQJFEW1Qjw/ZLCSbRCigtHoPLfmcTpKV/VLlfmgqn6FBdrqhbAFPnUUj7ZkCP7 Dmv6g6166EWXLHOnO8Wt2OJ/TcNJonE= Received: from mail-wm1-f69.google.com (mail-wm1-f69.google.com [209.85.128.69]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-647-SQbyl5zgPgWol0yi1aZGQA-1; Fri, 02 Oct 2026 18:26:28 -0400 X-MC-Unique: SQbyl5zgPgWol0yi1aZGQA-1 X-Mimecast-MFC-AGG-ID: SQbyl5zgPgWol0yi1aZGQA_1790979988 Received: by mail-wm1-f69.google.com with SMTP id 5b1f17b1804b1-4a022fee32fso2242945e9.0 for ; Fri, 02 Oct 2026 15:26:28 -0700 (PDT) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790979987; x=1791584787; h=date:content-transfer-encoding:content-type:mime-version :organization:references:in-reply-to:message-id:subject:cc:to:from :x-gm-gg:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to:content-type; bh=VdXsP7AO99QphTtcEdUE4l5frB6YKv78X/bR4k6TQzQ=; b=Qm+LL+BAYZ8u1q1SCMMaWWzQMcHu4D2TuSWXfKya+rnBnKIZSwhggpI2TKvS8madcP 2VX0etXK7HbKUNppjEW8SZ2cAKnXPu2beUpxkOR7HiF2Ud8efizVqmY75gYZfXSawG0K 0KBjUEaakzNj/4bA2eyMyA6jQsSSRabgXt6db8YBdjytdszEIc7gdEW3YLbmc2eOpzGX +lAg8ielhQXlXcKL4ZR4NF9vCTea9lYw+f5TiwBWzgDU4sEEQkf+PDQhgRBsG11NtDeL 07fwClzpKw2IPoEP/mbyXd8UE3Z9UzdlDrJY39dTP6CnybhFfK2L7lKml2qpmtLsSj4d EfUg== X-Gm-Message-State: AFuF++nsvEapP97WhvfswnBD1M/Aolnn8jpriT3q06aqpoKnPQZxMJag RM3Al8hoiEkk2rey58LCymzgmjYT7h+vjPKojUouuB9lJWkf+WKmnhsVZNdcb3ZbfRHd2ND5liu XwhgmIgflG8pwYnfMvESZMONNU+6idnIZL1y0IaxoIY7NsGxDpSBCkg== X-Gm-Gg: AYBFou0cZJA3xkgehk479XzwOGyPsp8kFU2sDk6Wo6ewhK9AOPOD0JeMrVasQXpu6kf xNAG7v4oye3r3UMupxUHSlAQn6LC3a3qQrvo6PPL08dVB+PvTN0URS2Irz4XJagfSYMe5u/u1lI ujuaxDqKuOIR0jKWM45jZ0ulcFFx+R0OaWZweu/DUX3vMOlj+RhHa8P4vvY8CdZY6RXhnZPvHCT PRx1YbERWdk7Bm9q55YZhNEzf2n1EnSTVOHArbgDwDHYc63k1+34DBTf8UXtr19F+bijLvhn8ns Zc2HmyrrW0uxmNbMgb8dAblrgOWe4fgMvg0FfeIb2v92i717YtPEpJ/Lq3hyYiY3xVwH3FwDSQ7 EXrrR7iOTbg== X-Received: by 2002:a05:600c:3111:b0:4a1:687b:8f3d with SMTP id 5b1f17b1804b1-4a1687b9015mr4586705e9.31.1790979987672; Fri, 02 Oct 2026 15:26:27 -0700 (PDT) X-Received: by 2002:a05:600c:3111:b0:4a1:687b:8f3d with SMTP id 5b1f17b1804b1-4a1687b9015mr4586425e9.31.1790979987158; Fri, 02 Oct 2026 15:26:27 -0700 (PDT) Received: from maya.myfinge.rs (ifcgrfdd.trafficplex.cloud. [2a10:fc81:a806:d6a9::1]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-4a027f2a4cfsm97849805e9.1.2026.10.02.15.26.26 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 02 Oct 2026 15:26:26 -0700 (PDT) From: Stefano Brivio To: Aris Konstantoulas Subject: Re: [PATCH] tcp: Don't fast re-transmit if only our FIN is outstanding Message-ID: <20261003002625.3babd1e8@elisabeth> In-Reply-To: <20260928103120.233586-1-arist.kon@gmail.com> References: <20260928103120.233586-1-arist.kon@gmail.com> Organization: Red Hat X-Mailer: Claws Mail 4.2.0 (GTK 3.24.49; x86_64-pc-linux-gnu) MIME-Version: 1.0 Date: Sat, 03 Oct 2026 00:26:26 +0200 (CEST) X-Mimecast-Spam-Score: 0 X-Mimecast-MFC-PROC-ID: KmvAurrH4n-qyLPsMD1DEeOkDterGfOCrwT40oagd8U_1790979988 X-Mimecast-Originator: redhat.com Content-Type: text/plain; charset=US-ASCII Content-Transfer-Encoding: 7bit Message-ID-Hash: SZFG2HQX66T3Q5WL6LP7KJGU62ZIDN7I X-Message-ID-Hash: SZFG2HQX66T3Q5WL6LP7KJGU62ZIDN7I X-MailFrom: sbrivio@redhat.com X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header CC: passt-dev@passt.top, David Gibson , Aris Konstantoulas X-Mailman-Version: 3.3.8 Precedence: list List-Id: Development discussion and patches for passt Archived-At: Archived-At: List-Archive: List-Archive: List-Help: List-Owner: List-Post: List-Subscribe: List-Unsubscribe: On Mon, 28 Sep 2026 13:31:20 +0300 Aris Konstantoulas wrote: > From: Aris Konstantoulas > > In the TAP_FIN_RCVD path of tcp_tap_handler(), a bare segment from the > guest acknowledging exactly seq_ack_from_tap, with an unchanged window, > is taken as a duplicate ACK and triggers a fast re-transmit. > > If the only unacknowledged sequence number is our own FIN, that's > harmful: tcp_rewind_seq() rewinds seq_to_tap and clears TAP_FIN_SENT, > so tcp_data_from_sock() immediately sends the FIN again. If the guest > answers that FIN with the same bare ACK, as a socket in TIME-WAIT will, > we loop at packet rate: > > - conn->retries is never incremented on this path, so we never reach > TCP_MAX_RETRIES and tcp_rst() > > - ACK_FROM_TAP_DUE is re-armed on every iteration, so the backed-off > re-transmission in tcp_timer_handler() never fires > > - TAP_FIN_ACKED can't be set, as it requires TAP_FIN_SENT, which the > rewind just cleared > > On an idle Podman host (rootless, pasta), this showed up as a single > flow exchanging ~45,000 54-byte segments per second between pasta and > a container whose socket was in TIME-WAIT, with pasta using ~75% of one > core, until the socket was killed by hand. It recurred on the idle > teardown of an HTTP/2 connection to an ACME server. > > With a raw-socket peer driving the same sequence against pasta at > f8df3f1, pasta re-sent the FIN 727,509 times in 10 seconds. With this > change it's re-transmitted by the timer at 1, 3, 7, 15, 31, 63 and 127 > seconds, and the connection is reset once TCP_MAX_RETRIES is reached. > > Don't consider a duplicate ACK as a fast re-transmit trigger if the > only outstanding sequence number is the FIN, and leave it to the timer. > Fast re-transmit of data is unaffected, with or without a FIN queued > after it. > > Fixes: bde1847960cf ("tcp: Fast re-transmit if half-closed, make TAP_FIN_RCVD path consistent") > Link: https://bugs.passt.top/show_bug.cgi?id=125 > Assisted-by: Claude:claude-opus-5-5 > Signed-off-by: Aris Konstantoulas > --- Applied, thanks for fixing this, and welcome to the git log! -- Stefano