git: 5d3e31df7c4f - main - tcp md5: fix accounting for SYN segments with unexpected signature
- Go to: [ bottom of page ] [ top of archives ] [ this month ]
Date: Fri, 04 Sep 2026 07:21:44 UTC
The branch main has been updated by tuexen:
URL: https://cgit.FreeBSD.org/src/commit/?id=5d3e31df7c4fc0e53168bac717bed5f94dab7068
commit 5d3e31df7c4fc0e53168bac717bed5f94dab7068
Author: Michael Tuexen <tuexen@FreeBSD.org>
AuthorDate: 2026-09-04 07:18:10 +0000
Commit: Michael Tuexen <tuexen@FreeBSD.org>
CommitDate: 2026-09-04 07:18:10 +0000
tcp md5: fix accounting for SYN segments with unexpected signature
When receiving a SYN segment with an MD5 option on a listening socket,
which has not enabled TCP MD5 support, increment the counter for
unexpected signatures (tcps_sig_err_sigopt).
Reviewed by: rscheff
MFC after: 1 week
MFC to: stable/14
MFC to: stable/15
Differential Revision: https://reviews.freebsd.org/D59303
---
sys/netinet/tcp_syncache.c | 4 +++-
1 file changed, 3 insertions(+), 1 deletion(-)
diff --git a/sys/netinet/tcp_syncache.c b/sys/netinet/tcp_syncache.c
index 0d8f725455b7..1b7e03e4ff79 100644
--- a/sys/netinet/tcp_syncache.c
+++ b/sys/netinet/tcp_syncache.c
@@ -1528,8 +1528,10 @@ syncache_add(struct in_conninfo *inc, struct tcpopt *to, struct tcphdr *th,
TCPMD5_INPUT(m, NULL, NULL) != ENOENT)
goto done;
}
- } else if (to->to_flags & TOF_SIGNATURE)
+ } else if (to->to_flags & TOF_SIGNATURE) {
+ TCPSTAT_INC(tcps_sig_err_sigopt);
goto done;
+ }
#endif /* TCP_SIGNATURE */
/*
* See if we already have an entry for this connection.