Compare commits

...
Author SHA1 Message Date
Leency ad36532d4f kernel/net: reset a TCP connection closed with unread data or fed after close
Check kernel codestyle / Check kernel codestyle (pull_request) Successful in 37s
Test PR / Build (en_US) (pull_request) Successful in 3m27s
Test PR / Build (es_ES) (pull_request) Successful in 3m27s
Test PR / Build (ru_RU) (pull_request) Successful in 3m55s
Data arriving on a socket the application had already closed was
accepted into its receive buffer as if someone would read it; the
advertised window shrank by a segment per ACK, reached zero and the
peer then probed it every few seconds for as long as it wanted
(tcp_input only reset the connection when the whole process was gone,
by testing SOCKET.PID). A download cancelled in a browser left such a
connection behind every time.

Mark the socket SS_NOFDREF in socket_close (and on process
termination) and let the existing "data after close" path in tcp_input
act on that flag: the connection is closed and the segment answered
with RST, as BSD does. Closing a socket that still holds unread data
now resets the connection instead of sending FIN (RFC 2525, 2.17), so
the peer is not led to believe the data was delivered and stops sending
at once.

The unlock before tcp_close (and edx kept for the reset reply) is the same as 115910307 on kernel-tcp-socket-list-locking, so the two merge cleanly.
2026-09-30 10:14:24 +03:00
3 changed files with 25 additions and 8 deletions

No files matched your search

+2
View File
@@ -780,6 +780,7 @@ socket_close:
cmp [eax + SOCKET.Protocol], IP_PROTO_TCP
jne .free
or [eax + SOCKET.state], SS_NOFDREF ; the application is gone
test [eax + SOCKET.state], SS_ISDISCONNECTING
jnz @f
call tcp_disconnect
@@ -2406,6 +2407,7 @@ socket_process_end:
DEBUGF DEBUG_NETWORK_VERBOSE, "SOCKET_process_end: killing socket %x\n", ebx
mov [ebx + SOCKET.PID], 0
or [ebx + SOCKET.state], SS_NOFDREF
mov eax, ebx
mov ebx, [ebx + SOCKET.NextPtr]
+13 -2
View File
@@ -722,17 +722,28 @@ endl
.no_duplicate:
;--------------------------------------------------
; Handle data that arrives after process terminates
; Handle data that arrives after the application closed the socket
cmp [ebx + SOCKET.PID], 0 ;;; TODO: use socket flags instead??
test [ebx + SOCKET.state], SS_NOFDREF
jnz .closed_by_app
cmp [ebx + SOCKET.PID], 0
jne .not_terminated
.closed_by_app:
cmp [ebx + TCP_SOCKET.t_state], TCPS_CLOSE_WAIT
jbe .not_terminated
test ecx, ecx
jz .not_terminated
; Unlock the socket, tcp_close frees it
pusha
lea ecx, [ebx + SOCKET.mutex]
call mutex_unlock
popa
mov eax, ebx
push edx
call tcp_close
pop edx
inc [TCPS_rcvafterclose]
jmp .respond_seg_reset
.not_terminated:
+10 -6
View File
@@ -192,13 +192,13 @@ tcp_disconnect:
; je TCP_drop
.nolinger:
call socket_is_disconnecting
push eax
add eax, STREAM_SOCKET.rcv
mov ecx, [eax + RING_BUFFER.size]
call socket_ring_free
pop eax
; Unread data: reset the connection instead of sending FIN (RFC 2525, 2.17)
cmp [eax + STREAM_SOCKET.rcv.size], 0
jne .reset
call socket_is_disconnecting
call tcp_usrclosed
@@ -210,6 +210,10 @@ tcp_disconnect:
@@:
ret
.reset:
mov ebx, ECONNRESET
jmp tcp_drop
;-----------------------------------------------------------------;
; ;