From mboxrd@z Thu Jan 1 00:00:00 1970 Authentication-Results: passt.top; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: passt.top; dkim=pass (2048-bit key; unprotected) header.d=gmail.com header.i=@gmail.com header.a=rsa-sha256 header.s=20251104 header.b=C+7TnqBf; dkim-atps=neutral Received: from mail-oa1-x2d.google.com (mail-oa1-x2d.google.com [IPv6:2001:4860:4864:20::2d]) by passt.top (Postfix) with ESMTPS id 8D3355A026E for ; Sun, 30 Aug 2026 12:12:55 +0200 (CEST) Received: by mail-oa1-x2d.google.com with SMTP id 586e51a60fabf-469d76ce704so569210fac.2 for ; Sun, 30 Aug 2026 03:12:55 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1788084774; cv=none; d=google.com; s=arc-20260327; b=eSPc4ROQQ5aRs4FYhBtVlxY1Q6jD5KWEpkQtSQmAS7zitqX+7tR2INsicuGdYYTlVC PZi2QTLmCt+jyLLoVbCq8nLqG9Fx4oxj8jDn7rHW3uGg1oA9W9icDdjC6GNmdk7EQyle qBOyh0lg0kXVKHxDpk6iCtdBZZlW5PrOJuHOAsNEF3SvawNo1kfBzzLetR0pf5bjR6Po udKe0TkkLBPhVcRsN+HzbDhOOwd33iXyvUwL8y+1TOtvigmoPDfoIw2yh4FM2cnYJ+az LWdwQZl7NAm47qm1PgF8C+hZ5QZc3IMUjm35C7eInJ9o+9YJ5tu+Ri+TlIdkXXZEf+BG Z5IQ== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=to:subject:message-id:date:from:mime-version:dkim-signature; bh=sgEUMsxJUjAE4s3XZ8s6oezsXzV6SyiV63EdD8gd3nY=; fh=aOefhh6yE8HlxD6USnrqNmrgGuLIev995Q1hNR6z7Ws=; b=fpg3Qx+9WDv0jTXfcw/XOErLnqgJWoDErDLdvsR81WwTCwzJ/JSTQkcBdcO5H1Oj+6 C9hAs7szmETDsCzTpdugfEo4L6uriuKLdPJomLlpZrKX+6pFo8ZoSn8VIM5U7NaE0upl NgETON4+ZFxqUfQLy85ZIdWSbMigOSZOz/SU/Qa1mSLBFnrRA/yd/VdW26DVbrh/heEx biAzYD4r5eL4Suuvvn+mKI79lmZkyFdp0RCKW6C9V6pboKVDQjp3rsUj5K6e25w3g20v ZOQ5YAbLCxVNXSmdpFKy7U8xCdyA16oRasOIaFhBYbHnB7x6ZL6qjo0jwN2tkv5CzNHq 3HFA==; darn=passt.top ARC-Authentication-Results: i=1; mx.google.com; arc=none DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1788084774; x=1788689574; darn=passt.top; h=content-type:to:subject:message-id:date:from:mime-version:from:to :cc:subject:date:message-id:reply-to:content-type; bh=sgEUMsxJUjAE4s3XZ8s6oezsXzV6SyiV63EdD8gd3nY=; b=C+7TnqBfJTqvQumRONeELYFtb5Ud6+mhZmyARuGeZhdBhJG/98BFfRKfBzXUxVUB8S 2ZToYy8dK5EMX9jeIO54ash68U4iDkwHheZcvfVaEIfH9I4TVq//V1s3ZgEKwQ/eZX0M JHxmoTsxUKhFSQEKtybuMSNpeIeAQDpN/LJKwsC8yy0I0H5FgaTuXxgDIIqrzwwrs69+ 7HuDEg2BqMHjpzy6f8oTTQOZxWQXnHMsP532mr7ZMAQusEuc1s/Pm3+mGSHmY6ysgGdR JVuf2hQ66RtKO+Dzx1SOUxHEEIsvtXlKMy7ACyyggt95WBLCj5BysIbdFfArrqRpk/hY rehQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788084774; x=1788689574; h=content-type:to:subject:message-id:date:from:mime-version:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=sgEUMsxJUjAE4s3XZ8s6oezsXzV6SyiV63EdD8gd3nY=; b=WIj/8abemZ34c4Vz60UBEFGh5WBA8UWv5vFWpfKI+mMCOnxtjfpOUB4CZA7b2cxn94 4VCB/JSfsGXgydoPzefMOfUH8d1XQDBpRUCw5Zp2xlWImBTOUJYycsYIFe1YRVWjRkq6 DZOa8yCj2yvARTqt55QFykJigkonhjAJ2j6S3nKRS12M/49Ae6cJIMqVT/Qx5b8U6lMU L9Jld4GgueW0YGlUnDS8Ee0QZST4Snufh6mfX2qWVnwat3R7NqZ5mZ3siF1OyaIzA3vd GkODD2ugJqXRnJIObKsFQAOsoMi9QtKQ4nmlUa935u+81wGrLyGM5D4W0OTPdTo+63DG BROg== X-Gm-Message-State: AFuF++l9FQ+M1qtmlsrKEcShWrQw919XFt8EtgF1rl+mszt1JZPN2KkF Z0lAzuIaqF1MEjuicpnxFyRgigJI+rEXdkc9IZk3uE5RxgakJro+S9y7RCWBdlSTairPftazIKQ pjPmW458JsdL3GDbERQg5l3xR8tzPfO+2Ig== X-Gm-Gg: AYBFou00v6OtvQumIXGDmt6Bb0VmaNQLZPqFso4nL/4M+QFBXsi3GxnHV2PsuoIrYIL /UtTk9aoBMB068FFTd5GTcL+QSBSSKGNvvDRBsowg/JMi60l6chck1qyyH1B9tWhMiHFeNQ4Ftz Mikdai2MvacaO/XCeFaBzSVbVUBfuJp9x9bUdo54L6J+In9uMDTpnfwVa/w4l/Wa+7xkabLT4e+ t0jCioVMvlwZeR78fPIg3kPPyzB/mvwBzpctkoUF7CjYt700XancE1oNlzOguO2Nv3U4RIDhDDd GejQaz4mSXsjbZ8qG3n4Dck5Wx23zBp63Kv7+J9SmFE= X-Received: by 2002:a05:6871:418f:b0:46a:bd86:d25a with SMTP id 586e51a60fabf-46abd86ef57mr3802484fac.4.1788084774101; Sun, 30 Aug 2026 03:12:54 -0700 (PDT) MIME-Version: 1.0 From: Rahul Date: Sun, 30 Aug 2026 11:12:44 +0100 X-Gm-Features: AcwNN1XfbAJ_cOwhHyyVYNMTU0DWYQ-UNj3MmB4q7nWeauGXh78bR0nyLy73sq8 Message-ID: Subject: UDP drops when source port is in use in the init namespace To: passt-user@passt.top Content-Type: multipart/alternative; boundary="000000000000c9e764065a40ed01" X-MailFrom: llvm.zentrik@gmail.com X-Mailman-Rule-Hits: nonmember-moderation X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation Message-ID-Hash: KD4K7GVDRYFLBLUQ7JMCBT6H3B7FREO6 X-Message-ID-Hash: KD4K7GVDRYFLBLUQ7JMCBT6H3B7FREO6 X-Mailman-Approved-At: Sun, 30 Aug 2026 13:44:06 +0200 X-Mailman-Version: 3.3.8 Precedence: list List-Id: "For passt users: support, questions and answers" Archived-At: Archived-At: List-Archive: List-Archive: List-Help: List-Owner: List-Post: List-Subscribe: List-Unsubscribe: --000000000000c9e764065a40ed01 Content-Type: text/plain; charset="UTF-8" Hi, I'm seeing DNS requests being dropped when using pasta 20250217. As far as I can tell, UDP flows where the source port chosen in the namespace is already in use in the init namespace get dropped. All three fwd_nat_from_*() preserve the source port for UDP: tgt->oport = 0; if (proto == IPPROTO_UDP) /* But for UDP preserve the source port */ tgt->oport = ini->eport; That forces a bind() to it, and udp_flow_sock() treats bind failure as fatal, so the flow is cancelled and the datagram dropped with no error to the sender. I don't think I ever hit this with slirp4netns, it looks like libslirp's udp_attach() never binds a port, so the kernel just gives it a random free port. I'm not sure whether this is intended, but if it is, is there any way to work around it? Thanks --000000000000c9e764065a40ed01 Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable
Hi,

I'm seeing DNS requests being dropped when= using pasta 20250217. As far as I can tell, UDP
flows where the source = port chosen in the namespace is already in use in the
init namespace get= dropped.

All three fwd_nat_from_*() preserve the source port for UD= P:

tgt->oport =3D 0;
if (proto =3D=3D IPPROTO_UDP)
/* B= ut for UDP preserve the source port */
tgt->oport =3D ini->eport= ;

That forces a bind() to it, and udp_flow_sock() treats bind failur= e as fatal, so
the flow is cancelled and the datagram dropped with no er= ror to the sender.

I don't think I ever hit this with slirp4netn= s, it looks like libslirp's udp_attach() never
binds a port, so the = kernel just gives it a random free port.

I'm not sure whether th= is is intended, but if it is, is there any way to work
around it?
Thanks
=C2=A0
--000000000000c9e764065a40ed01--