Re: [PATCH v2 1/2] ipvs: do not propagate one-packet flag to synced conns

Julian Anastasov <[email protected]> Tue, 14 Jul 2026 13:09:23 +0300 (EEST)
Newsgroups org.kernel.vger.lvs-devel,org.kernel.vger.netfilter-devel
Message-ID <[email protected]>
	Hello,

On Mon, 13 Jul 2026, Ren Wei wrote:

> From: Zhiling Zou <[email protected]>
> 
> Synced connections can be created before their destination exists. When
> the destination is later added, ip_vs_bind_dest() copies connection flags
> from the destination into cp->flags.
> 
> IP_VS_CONN_F_ONE_PACKET connections are not synced. If a synced
> connection inherits IP_VS_CONN_F_ONE_PACKET while it is already hashed,
> expiry can treat it as a one-packet connection and skip unlinking the
> existing conn_tab node, leaving stale hash nodes pointing at a freed
> struct ip_vs_conn.
> 
> Drop IP_VS_CONN_F_ONE_PACKET from destination flags when binding synced
> connections.
> 
> Fixes: 26ec037f9841 ("IPVS: one-packet scheduling")
> Cc: [email protected]
> Reported-by: Yuan Tan <[email protected]>
> Reported-by: Yifan Wu <[email protected]>
> Reported-by: Juefei Pu <[email protected]>
> Reported-by: Xin Liu <[email protected]>
> Suggested-by: Julian Anastasov <[email protected]>
> Signed-off-by: Zhiling Zou <[email protected]>
> Signed-off-by: Ren Wei <[email protected]>

	Looks good to me for the nf tree, thanks!

	For this patch:

Acked-by: Julian Anastasov <[email protected]>

> ---
> Changes in v2:
> - Replace the v1 approach that preserved hash-related flags on late
>   destination binding.
> - Drop IP_VS_CONN_F_ONE_PACKET from conn_flags for synced connections,
>   because one-packet connections are not synchronized.
> - Leave forwarding method updates to the follow-up hn1 hashing fix in
>   patch 2.
> - Add Suggested-by for Julian's review suggestion.
> 
> v1 Link: https://lore.kernel.org/all/1b914f41d725bc064c9ba9830dc8169329737270.1782540466.git.roxy520tt@gmail.com/
> 
>  net/netfilter/ipvs/ip_vs_conn.c | 3 +++
>  1 file changed, 3 insertions(+)
> 
> diff --git a/net/netfilter/ipvs/ip_vs_conn.c b/net/netfilter/ipvs/ip_vs_conn.c
> index 6ed2622363f0..0682cec5f0a7 100644
> --- a/net/netfilter/ipvs/ip_vs_conn.c
> +++ b/net/netfilter/ipvs/ip_vs_conn.c
> @@ -1014,6 +1014,9 @@ ip_vs_bind_dest(struct ip_vs_conn *cp, struct ip_vs_dest *dest)
>  	flags = cp->flags;
>  	/* Bind with the destination and its corresponding transmitter */
>  	if (flags & IP_VS_CONN_F_SYNC) {
> +		/* Synced conns are hashed, so they can not get this flag */
> +		conn_flags &= ~IP_VS_CONN_F_ONE_PACKET;
> +
>  		/* if the connection is not template and is created
>  		 * by sync, preserve the activity flag.
>  		 */
> -- 
> 2.43.0

Regards

--
Julian Anastasov <[email protected]>