Re: [PATCH net] tcp: reject completely old segments during sequence validation

Jakub Kicinski <[email protected]>
Newsgroups org.kernel.vger.netdev
Message-ID <[email protected]>
On Tue, 18 Aug 2026 23:52:30 +0300 Michael Cohen wrote:
> tcp_sequence() rejects an incoming segment when end_seq is before
> rcv_wup. Since end_seq is one past the last sequence number consumed by
> the segment, this misses the boundary case where end_seq is equal to
> rcv_wup.
> 
> A segment that consumes sequence space and has end_seq equal to rcv_wup
> is therefore allowed to reach later processing, including ACK handling,
> even though it should be rejected as a completely old segment.
> 
> Reject this boundary case while retaining the existing behavior for
> segments that consume no sequence space.
> 
> Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
> Reported-by: Michael Cohen <[email protected]>
> Reported-by: Tamir Shahar <[email protected]>
> Reported-by: Amit Klein <[email protected]>
> Signed-off-by: Michael Cohen <[email protected]>

CI says the AccECN cases need to be adjusted.
Example failure output (tcp_accecn_synack_rexmit.pkt):

  tcp_accecn_synack_rexmit.pkt:15: error handling packet: live packet field
    tcp_ece: expected: 0 (0x0) vs actual: 1 (0x1)
  script packet:  0.104 .W  1:1(0) ack 1 <ECN e1b 1 ceb 0 e0b 1,nop>
  actual packet:  0.102 .EA 1:1(0) ack 1 win 1050 <ECN e1b 1 ceb 0 e0b 1,nop>

The AccECN tests expect the kernel to observe and react to the retransmitted
SYN-ACK, but the new boundary rejection prevents that.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.