public inbox for passt-dev@passt.top
 help / color / mirror / code / Atom feed
* [PATCH v2] tcp: Store the owner connections for flags frames
@ 2025-09-10  9:56 Yumei Huang
  2025-09-10 10:49 ` Volker Diels-Grabsch
  0 siblings, 1 reply; 2+ messages in thread
From: Yumei Huang @ 2025-09-10  9:56 UTC (permalink / raw)
  To: passt-dev; +Cc: sbrivio, dgibson, yuhuang, v, boleyn.su, david, jmaloy

There is an issue reported by Volker Diels-Grabsch and Boleyn Su.
A segmentation fault occurs when executing the following command:

	(sleep 0.1; ssh -p 22000 127.0.0.1) & passt -f -t 22000:22

It's caused by commit 78da088f7bab ("tcp: unify payload and flags
l2 frames array"). Fix it by storing the owner connections of flags
frames into tcp_frame_conns[] array.

Reported-by: Volker Diels-Grabsch <v@njh.eu>
Reported-by: Boleyn Su <boleyn.su@gmail.com>
Suggested-by: David Gibson <david@gibson.dropbear.id.au>
Fixes: 78da088f7bab ("tcp: unify payload and flags l2 frames array")
Signed-off-by: Yumei Huang <yuhuang@redhat.com>
---
 tcp_buf.c | 3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

diff --git a/tcp_buf.c b/tcp_buf.c
index bc898de..d351c20 100644
--- a/tcp_buf.c
+++ b/tcp_buf.c
@@ -209,13 +209,14 @@ int tcp_buf_send_flag(const struct ctx *c, struct tcp_tap_conn *conn, int flags)
 	if (ret <= 0)
 		return ret;
 
-	tcp_payload_used++;
+	tcp_frame_conns[tcp_payload_used++] = conn;
 	l4len = optlen + sizeof(struct tcphdr);
 	iov[TCP_IOV_PAYLOAD].iov_len = l4len;
 	tcp_l2_buf_fill_headers(conn, iov, NULL, seq, false);
 
 	if (flags & DUP_ACK) {
 		struct iovec *dup_iov = tcp_l2_iov[tcp_payload_used++];
+		tcp_frame_conns[tcp_payload_used - 1] = conn;
 
 		memcpy(dup_iov[TCP_IOV_TAP].iov_base, iov[TCP_IOV_TAP].iov_base,
 		       iov[TCP_IOV_TAP].iov_len);
-- 
@@ -209,13 +209,14 @@ int tcp_buf_send_flag(const struct ctx *c, struct tcp_tap_conn *conn, int flags)
 	if (ret <= 0)
 		return ret;
 
-	tcp_payload_used++;
+	tcp_frame_conns[tcp_payload_used++] = conn;
 	l4len = optlen + sizeof(struct tcphdr);
 	iov[TCP_IOV_PAYLOAD].iov_len = l4len;
 	tcp_l2_buf_fill_headers(conn, iov, NULL, seq, false);
 
 	if (flags & DUP_ACK) {
 		struct iovec *dup_iov = tcp_l2_iov[tcp_payload_used++];
+		tcp_frame_conns[tcp_payload_used - 1] = conn;
 
 		memcpy(dup_iov[TCP_IOV_TAP].iov_base, iov[TCP_IOV_TAP].iov_base,
 		       iov[TCP_IOV_TAP].iov_len);
-- 
2.47.0


^ permalink raw reply related	[flat|nested] 2+ messages in thread

* Re: [PATCH v2] tcp: Store the owner connections for flags frames
  2025-09-10  9:56 [PATCH v2] tcp: Store the owner connections for flags frames Yumei Huang
@ 2025-09-10 10:49 ` Volker Diels-Grabsch
  0 siblings, 0 replies; 2+ messages in thread
From: Volker Diels-Grabsch @ 2025-09-10 10:49 UTC (permalink / raw)
  To: Yumei Huang; +Cc: passt-dev, sbrivio, dgibson, boleyn.su, david, jmaloy

Dear Yumei,

Thanks a lot for providing a proper fix for that issue.  Just a minor
nitpick from my side:

Yumei Huang wrote:
> @@ -209,13 +209,14 @@ int tcp_buf_send_flag(const struct ctx *c, struct tcp_tap_conn *conn, int flags)
>  	if (ret <= 0)
>  		return ret;
>  
> -	tcp_payload_used++;
> +	tcp_frame_conns[tcp_payload_used++] = conn;
>  	l4len = optlen + sizeof(struct tcphdr);
>  	iov[TCP_IOV_PAYLOAD].iov_len = l4len;
>  	tcp_l2_buf_fill_headers(conn, iov, NULL, seq, false);
>  
>  	if (flags & DUP_ACK) {
>  		struct iovec *dup_iov = tcp_l2_iov[tcp_payload_used++];
> +		tcp_frame_conns[tcp_payload_used - 1] = conn;

I find it a bit strange to read that way, incrementing tcp_payload_used
just to subtract one from it in the next step.  I, personally, would
find it easier to read and to understand that way around:

 		struct iovec *dup_iov = tcp_l2_iov[tcp_payload_used];
		tcp_frame_conns[tcp_payload_used++] = conn;

But maybe it's just me.


Best regards,
Volker

-- 
.---<<<((()))>>>---.
|      [[||]]      |
'---<<<((()))>>>---'

^ permalink raw reply	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2025-09-10 10:49 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2025-09-10  9:56 [PATCH v2] tcp: Store the owner connections for flags frames Yumei Huang
2025-09-10 10:49 ` Volker Diels-Grabsch

Code repositories for project(s) associated with this public inbox

	https://passt.top/passt

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for IMAP folder(s).