• Florian Westphal's avatar
    mptcp: enable JOIN requests even if cookies are in use · 9466a1cc
    Florian Westphal authored
    JOIN requests do not work in syncookie mode -- for HMAC validation, the
    peers nonce and the mptcp token (to obtain the desired connection socket
    the join is for) are required, but this information is only present in the
    initial syn.
    
    So either we need to drop all JOIN requests once a listening socket enters
    syncookie mode, or we need to store enough state to reconstruct the request
    socket later.
    
    This adds a state table (1024 entries) to store the data present in the
    MP_JOIN syn request and the random nonce used for the cookie syn/ack.
    
    When a MP_JOIN ACK passed cookie validation, the table is consulted
    to rebuild the request socket from it.
    
    An alternate approach would be to "cancel" syn-cookie mode and force
    MP_JOIN to always use a syn queue entry.
    
    However, doing so brings the backlog over the configured queue limit.
    
    v2: use req->syncookie, not (removed) want_cookie arg
    Suggested-by: default avatarPaolo Abeni <pabeni@redhat.com>
    Signed-off-by: default avatarFlorian Westphal <fw@strlen.de>
    Reviewed-by: default avatarMat Martineau <mathew.j.martineau@linux.intel.com>
    Signed-off-by: default avatarDavid S. Miller <davem@davemloft.net>
    9466a1cc
syncookies.c 12.3 KB