netstack: don't ACK SYNs in TIME-WAIT

It was possible for a SYN to arrive after the endpoint sent an ACK as part of
the transition to TIME-WAIT, but before returning from handleSegmentsLocked().
This caused the SYN to be dequeued and ACK'd despite the change in
EndpointState.

Deflakes TestTCPTimeWaitNewSyn.

Tested with:
blaze test --config=gotsan --runs_per_test 10000 \
  //third_party/gvisor/pkg/tcpip/transport/tcp:tcp_x_test -j 2000 \
  //  --test_filter TestTCPTimeWaitNewSyn

PiperOrigin-RevId: 380639808
This commit is contained in:
Kevin Krakauer
2021-06-21 12:37:51 -07:00
committed by gVisor bot
parent d823b7bd97
commit 45cd7c1b11
2 changed files with 1 additions and 2 deletions
+1 -1
View File
@@ -1130,7 +1130,7 @@ func (e *endpoint) handleReset(s *segment) (ok bool, err tcpip.Error) {
func (e *endpoint) handleSegmentsLocked(fastPath bool) tcpip.Error {
checkRequeue := true
for i := 0; i < maxSegmentsPerWake; i++ {
if e.EndpointState().closed() {
if state := e.EndpointState(); state.closed() || state == StateTimeWait {
return nil
}
s := e.segmentQueue.dequeue()
-1
View File
@@ -559,7 +559,6 @@ func (r *receiver) handleTimeWaitSegment(s *segment) (resetTimeWait bool, newSyn
// (2) returns to TIME-WAIT state if the SYN turns out
// to be an old duplicate".
if s.flags.Contains(header.TCPFlagSyn) && r.RcvNxt.LessThan(segSeq) {
return false, true
}