From nobody Mon Sep 28 09:59:43 2026 Received: from mail-pj1-f48.google.com (mail-pj1-f48.google.com [209.85.216.48]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 17C85394E91 for ; Mon, 24 Aug 2026 07:31:33 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.216.48 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787556696; cv=none; b=JUnPmz6SoSWXGRug6+jebqA2G+rzGElsGgCmBnxDBThj+p9JRHvL1UbcUp7QcBByFkOn3jchdHHfQ6CZW6F8pWvf+EqeF0D+TxaFL3QiStpBom4wZdCGYUzuQg5p02x/9WkV1eA4m1silndVTJfMRipI9jd0xEbfKzHKOC7Qg/I= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787556696; c=relaxed/simple; bh=PveI3powooGQqU85bnZ0Z1EeX9FyZE3ak0omOVQUrTc=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=Ye0IagB3YzBbPCsTcMVa1oAeGIJruEOC686y2F3JNSG3mb6lnhIqLK9fEsNFSj9SvNa/EuV2kXg2DdhYacZCZj8LGYWCImrpfGow4VCKMlKsioaSy+SMF+dRuRHODrvXRpYpLhuxmTczIMLAXhIwqjNoSdXbHv99yfOcBmkCfHM= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=aronleigh.au; spf=fail smtp.mailfrom=aronleigh.au; dkim=pass (2048-bit key) header.d=aronleigh.au header.i=@aronleigh.au header.b=HIlH8TJ0; arc=none smtp.client-ip=209.85.216.48 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=aronleigh.au Authentication-Results: smtp.subspace.kernel.org; spf=fail smtp.mailfrom=aronleigh.au Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=aronleigh.au header.i=@aronleigh.au header.b="HIlH8TJ0" Received: by mail-pj1-f48.google.com with SMTP id 98e67ed59e1d1-38dc4553f62so4240548a91.0 for ; Mon, 24 Aug 2026 00:31:33 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=aronleigh.au; s=google; t=1787556692; x=1788161492; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=uLb5oidJqIEh95Ts+9Y1LRvCSg2t1mOJW2d3dmW0KHI=; b=HIlH8TJ0GGKwvSzeEALLYtnXZMQaQ1xZMJalClEBHa4c0660bpJFkLVCpax4NOcPzw T7YRsxaJH1s+7OFcZ4JyQz6WuuBHb9cWW/datcnMLLB1HhG5LIw/voAtOHMwqMNejBV9 gU83sGFeR+WD1SlAGFq4HEGLn7f6QqoXa5CwyHhuN9GiEdg0ZS6cea0Z9Me3X+AZDv8M Ksp+NBWu7Gq/Vj0wuB2xfLqTGzQ4xmfbI1ziz/ao2D83VT7l1TBlsAzSK14EDoMMwFHk gPSugZw4qGIwy9gGyFv3adQTanwaf53pFvCxk7o5wWd/ah48fjPtAb6U23vflPWDvdtB uc4w== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787556692; x=1788161492; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=uLb5oidJqIEh95Ts+9Y1LRvCSg2t1mOJW2d3dmW0KHI=; b=Gt2h8M+Jdje3bsx3fiCTR1U2+TZXVi7EJnmys03uc3DsW1LcQgsxN6K922YdKQIVpK hRRwYdiOFfqu6bZhg7+rvkgUp4qC8W2+3I54LcCmbQspbJVPY0Hd0qzQM7Q+keyPUv1Z sISoymDHCpUr72gilFkndo+hnyKRUvSREm5d6ZpndIDdZCJcPYb0wQ7Zp4aIiCBHim7h 1eqYbXoLD7jPcrkda1s679BFtj43vcrp+8aGnwV2bSKbs382Nzqr6klV/04T7TX3OPBs WXMeKe8GRNdEE1/5Dwq20oqrI+7/9G7yO+kJdCube3fFtOreM/1VCesCMWeCtk1ks/EW woAg== X-Forwarded-Encrypted: i=1; AHgh+RoOjDdlbdcDai+iofUQ8arhMtwCFhPskH4URCDPb64Iv2Czdd+14PeocCtkOGcm3Kktm5Sfc388POx7Cqc=@vger.kernel.org X-Gm-Message-State: AFuF++l+SR2bTcAvJZx/JT6/jxxWu8yLJTYYEzOH0bWsds84crReN7cT RhRlAF+WdpXcKjT6qtzmvDFr0167QfnS1wKEAWO0bKdNITu+tqp8zkbbw6vL4mJW+oep X-Gm-Gg: AR+sD12ptbOZM4XlHdFjfJ1RY4gVnD6fNZFuwByNEEq+2EFioK2/RygDIK2gHOB/ziR A/P/WuhMbhYYqlfzLhxWBZmhXUOI5Wx3BiO6wXtMa9PM3RkulgOTjlU+9/0MZfcR64jst0jGZef IITknc44W1AHeq/cLoq+ViROuCb/HjQT5PlB6VveeMWZDuWJB3RUPkgYS02P2P7sDkDCmjpYmdQ lrleIRvzBW03CLocfCmrqaUp8EvL37xoVBjG6jsqcg2u0KxFH5932cX2D3xBuEiImi2Xa5Ltmxu 30/r0fkEwU9vAIG5GBU+3U5ILjUYVkrPdoS42KcyIbDBbmOElL/ucjyYfw7vhk/rEOyVMPQ9rNZ F4NSwwMfq8wQ8kqaRC8e4kX3q5EGZ3NJXmTN4fE5OjJht/lQzwujiHRJbTF+nMeDtG4XzFe/KrK gV4xHbbkTeMxEMEbZgjRgaey+5GZHevh2wMm348g0SmFx3hX5nkSslsZbMmZ25f8ZihJGjfN/X8 Ai7Q09yIZCcC0wPJBx1nDXEqC7diHOKjRY= X-Received: by 2002:a17:90b:180d:b0:38e:2524:724f with SMTP id 98e67ed59e1d1-395c3733e65mr43431160a91.12.1787556692517; Mon, 24 Aug 2026 00:31:32 -0700 (PDT) Received: from ghostoverflow.. ([1.145.153.192]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-327f90cb8e3sm33763741eec.12.2026.08.24.00.31.24 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 24 Aug 2026 00:31:31 -0700 (PDT) From: Lilly Aronleigh To: steffen.klassert@secunet.com, herbert@gondor.apana.org.au Cc: Lilly Aronleigh , "David S. Miller" , Eric Dumazet , Jakub Kicinski , Paolo Abeni , Simon Horman , Christian Hopps , netdev@vger.kernel.org (open list:NETWORKING [IPSEC]), linux-kernel@vger.kernel.org (open list) Subject: [PATCH net v3] xfrm: iptfs: avoid canceling reorder-window drop timer Date: Mon, 24 Aug 2026 17:28:52 +1000 Message-ID: <20260824072851.301644-3-lilly@aronleigh.au> X-Mailer: git-send-email 2.43.0 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" IP-TFS uses xtfs->drop_timer for both partial inner-packet reassembly and the reorder-window drop timeout. Reassembly completion currently cancels the timer unconditionally. That is only correct when the reorder window is empty. If the reorder window already contains saved packets, the same timer belongs to the reorder-window state and must remain armed so the missing sequence can be considered lost and the window can advance. Only cancel drop_timer from __iptfs_reassem_done() when the reorder window has no saved packets. The existing drop_lock serializes this with the reorder-window paths, and a failed cancel remains harmless. Tested with a reproducer that completes reassembly while the reorder window contains saved packets. With this change, the reorder-window timeout remains active and the window can advance correctly when the missing sequence is not received. Fixes: 0756947654468 ("xfrm: iptfs: handle received fragmented inner packet= s") Assisted-by: ChatGPT:5.5-extrahigh Assisted-by: Claude:4.6-opus Signed-off-by: Lilly Aronleigh --- v3: - Resubmission via git send-email to fix formatting v2: - Rebased onto current net tree - No functional changes Link: https://lore.kernel.org/netdev/CAFrrV-O1fesaza+5_WqH8OciXRu9KKE4UsB6R= cMamDu0j2-nBA@mail.gmail.com/T/#u --- net/xfrm/xfrm_iptfs.c | 8 ++++++-- 1 file changed, 6 insertions(+), 2 deletions(-) diff --git a/net/xfrm/xfrm_iptfs.c b/net/xfrm/xfrm_iptfs.c index 6920940a35b4..23e0face2b9f 100644 --- a/net/xfrm/xfrm_iptfs.c +++ b/net/xfrm/xfrm_iptfs.c @@ -707,8 +707,12 @@ static void __iptfs_reassem_done(struct xfrm_iptfs_dat= a *xtfs, bool free) { assert_spin_locked(&xtfs->drop_lock); =20 - /* We don't care if it works locking takes care of things */ - hrtimer_try_to_cancel(&xtfs->drop_timer); + /* + * The drop timer also drives the reorder window timeout. Locking = makes + * a failed cancel harmless. + */ + if (!xtfs->w_savedlen) + hrtimer_try_to_cancel(&xtfs->drop_timer); if (free) kfree_skb(xtfs->ra_newskb); xtfs->ra_newskb =3D NULL; --=20 2.43.0