* [PATCH v2] tcp: Store the owner connections for flags frames
@ 2025-09-10 9:56 Yumei Huang
2025-09-10 10:49 ` Volker Diels-Grabsch
0 siblings, 1 reply; 2+ messages in thread
From: Yumei Huang @ 2025-09-10 9:56 UTC (permalink / raw)
To: passt-dev; +Cc: sbrivio, dgibson, yuhuang, v, boleyn.su, david, jmaloy
There is an issue reported by Volker Diels-Grabsch and Boleyn Su.
A segmentation fault occurs when executing the following command:
(sleep 0.1; ssh -p 22000 127.0.0.1) & passt -f -t 22000:22
It's caused by commit 78da088f7bab ("tcp: unify payload and flags
l2 frames array"). Fix it by storing the owner connections of flags
frames into tcp_frame_conns[] array.
Reported-by: Volker Diels-Grabsch <v@njh.eu>
Reported-by: Boleyn Su <boleyn.su@gmail.com>
Suggested-by: David Gibson <david@gibson.dropbear.id.au>
Fixes: 78da088f7bab ("tcp: unify payload and flags l2 frames array")
Signed-off-by: Yumei Huang <yuhuang@redhat.com>
---
tcp_buf.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/tcp_buf.c b/tcp_buf.c
index bc898de..d351c20 100644
--- a/tcp_buf.c
+++ b/tcp_buf.c
@@ -209,13 +209,14 @@ int tcp_buf_send_flag(const struct ctx *c, struct tcp_tap_conn *conn, int flags)
if (ret <= 0)
return ret;
- tcp_payload_used++;
+ tcp_frame_conns[tcp_payload_used++] = conn;
l4len = optlen + sizeof(struct tcphdr);
iov[TCP_IOV_PAYLOAD].iov_len = l4len;
tcp_l2_buf_fill_headers(conn, iov, NULL, seq, false);
if (flags & DUP_ACK) {
struct iovec *dup_iov = tcp_l2_iov[tcp_payload_used++];
+ tcp_frame_conns[tcp_payload_used - 1] = conn;
memcpy(dup_iov[TCP_IOV_TAP].iov_base, iov[TCP_IOV_TAP].iov_base,
iov[TCP_IOV_TAP].iov_len);
--
@@ -209,13 +209,14 @@ int tcp_buf_send_flag(const struct ctx *c, struct tcp_tap_conn *conn, int flags)
if (ret <= 0)
return ret;
- tcp_payload_used++;
+ tcp_frame_conns[tcp_payload_used++] = conn;
l4len = optlen + sizeof(struct tcphdr);
iov[TCP_IOV_PAYLOAD].iov_len = l4len;
tcp_l2_buf_fill_headers(conn, iov, NULL, seq, false);
if (flags & DUP_ACK) {
struct iovec *dup_iov = tcp_l2_iov[tcp_payload_used++];
+ tcp_frame_conns[tcp_payload_used - 1] = conn;
memcpy(dup_iov[TCP_IOV_TAP].iov_base, iov[TCP_IOV_TAP].iov_base,
iov[TCP_IOV_TAP].iov_len);
--
2.47.0
^ permalink raw reply related [flat|nested] 2+ messages in thread
* Re: [PATCH v2] tcp: Store the owner connections for flags frames
2025-09-10 9:56 [PATCH v2] tcp: Store the owner connections for flags frames Yumei Huang
@ 2025-09-10 10:49 ` Volker Diels-Grabsch
0 siblings, 0 replies; 2+ messages in thread
From: Volker Diels-Grabsch @ 2025-09-10 10:49 UTC (permalink / raw)
To: Yumei Huang; +Cc: passt-dev, sbrivio, dgibson, boleyn.su, david, jmaloy
Dear Yumei,
Thanks a lot for providing a proper fix for that issue. Just a minor
nitpick from my side:
Yumei Huang wrote:
> @@ -209,13 +209,14 @@ int tcp_buf_send_flag(const struct ctx *c, struct tcp_tap_conn *conn, int flags)
> if (ret <= 0)
> return ret;
>
> - tcp_payload_used++;
> + tcp_frame_conns[tcp_payload_used++] = conn;
> l4len = optlen + sizeof(struct tcphdr);
> iov[TCP_IOV_PAYLOAD].iov_len = l4len;
> tcp_l2_buf_fill_headers(conn, iov, NULL, seq, false);
>
> if (flags & DUP_ACK) {
> struct iovec *dup_iov = tcp_l2_iov[tcp_payload_used++];
> + tcp_frame_conns[tcp_payload_used - 1] = conn;
I find it a bit strange to read that way, incrementing tcp_payload_used
just to subtract one from it in the next step. I, personally, would
find it easier to read and to understand that way around:
struct iovec *dup_iov = tcp_l2_iov[tcp_payload_used];
tcp_frame_conns[tcp_payload_used++] = conn;
But maybe it's just me.
Best regards,
Volker
--
.---<<<((()))>>>---.
| [[||]] |
'---<<<((()))>>>---'
^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2025-09-10 10:49 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2025-09-10 9:56 [PATCH v2] tcp: Store the owner connections for flags frames Yumei Huang
2025-09-10 10:49 ` Volker Diels-Grabsch
Code repositories for project(s) associated with this public inbox
https://passt.top/passt
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for IMAP folder(s).