git: 2515552e6216 - main - tcp: improve handling of SYN-ACK segments in TIMEWAIT state

From: Michael Tuexen <tuexen_at_FreeBSD.org>
Date: Mon, 03 Oct 2022 14:00:17 UTC
The branch main has been updated by tuexen:

URL: https://cgit.FreeBSD.org/src/commit/?id=2515552e6216095c3fa61d93ee024bb8861e07c2

commit 2515552e6216095c3fa61d93ee024bb8861e07c2
Author:     Michael Tuexen <tuexen@FreeBSD.org>
AuthorDate: 2022-10-03 12:46:47 +0000
Commit:     Michael Tuexen <tuexen@FreeBSD.org>
CommitDate: 2022-10-03 12:46:47 +0000

    tcp: improve handling of SYN-ACK segments in TIMEWAIT state
    
    Only consider segments with the SYN bit set and the ACK bit cleared
    as "new connection attempts", which result in re-using a connection
    being in TIMEWAIT state. This results in consistent handling of
    SYN-ACK segments.
    
    Reviewed by:            rscheff@
    MFC after:              1 week
    Sponsored by:           Netflix, Inc.
    Differential Revision:  https://reviews.freebsd.org/D36864
---
 sys/netinet/tcp_timewait.c | 6 +++---
 1 file changed, 3 insertions(+), 3 deletions(-)

diff --git a/sys/netinet/tcp_timewait.c b/sys/netinet/tcp_timewait.c
index ad97e2d3bed6..272734924384 100644
--- a/sys/netinet/tcp_timewait.c
+++ b/sys/netinet/tcp_timewait.c
@@ -464,13 +464,13 @@ tcp_twcheck(struct inpcb *inp, struct tcpopt *to, struct tcphdr *th,
 	 * are above the previous ones.
 	 * Allow UDP port number changes in this case.
 	 */
-	if ((thflags & TH_SYN) && SEQ_GT(th->th_seq, tw->rcv_nxt)) {
+	if (((thflags & (TH_SYN | TH_ACK)) == TH_SYN) &&
+	    SEQ_GT(th->th_seq, tw->rcv_nxt)) {
 		/*
 		 * In case we can't upgrade our lock just pretend we have
 		 * lost this packet.
 		 */
-		if (((thflags & (TH_SYN | TH_ACK)) == TH_SYN) &&
-		    INP_TRY_UPGRADE(inp) == 0)
+		if (INP_TRY_UPGRADE(inp) == 0)
 			goto drop;
 		tcp_twclose(tw, 0);
 		TCPSTAT_INC(tcps_tw_recycles);