git: 5d3e31df7c4f - main - tcp md5: fix accounting for SYN segments with unexpected signature

From: Michael Tuexen <tuexen_at_FreeBSD.org>
Date: Fri, 04 Sep 2026 07:21:44 UTC
The branch main has been updated by tuexen:

URL: https://cgit.FreeBSD.org/src/commit/?id=5d3e31df7c4fc0e53168bac717bed5f94dab7068

commit 5d3e31df7c4fc0e53168bac717bed5f94dab7068
Author:     Michael Tuexen <tuexen@FreeBSD.org>
AuthorDate: 2026-09-04 07:18:10 +0000
Commit:     Michael Tuexen <tuexen@FreeBSD.org>
CommitDate: 2026-09-04 07:18:10 +0000

    tcp md5: fix accounting for SYN segments with unexpected signature
    
    When receiving a SYN segment with an MD5 option on a listening socket,
    which has not enabled TCP MD5 support, increment the counter for
    unexpected signatures (tcps_sig_err_sigopt).
    
    Reviewed by:            rscheff
    MFC after:              1 week
    MFC to:                 stable/14
    MFC to:                 stable/15
    Differential Revision:  https://reviews.freebsd.org/D59303
---
 sys/netinet/tcp_syncache.c | 4 +++-
 1 file changed, 3 insertions(+), 1 deletion(-)

diff --git a/sys/netinet/tcp_syncache.c b/sys/netinet/tcp_syncache.c
index 0d8f725455b7..1b7e03e4ff79 100644
--- a/sys/netinet/tcp_syncache.c
+++ b/sys/netinet/tcp_syncache.c
@@ -1528,8 +1528,10 @@ syncache_add(struct in_conninfo *inc, struct tcpopt *to, struct tcphdr *th,
 			    TCPMD5_INPUT(m, NULL, NULL) != ENOENT)
 				goto done;
 		}
-	} else if (to->to_flags & TOF_SIGNATURE)
+	} else if (to->to_flags & TOF_SIGNATURE) {
+		TCPSTAT_INC(tcps_sig_err_sigopt);
 		goto done;
+	}
 #endif	/* TCP_SIGNATURE */
 	/*
 	 * See if we already have an entry for this connection.