From: Eric Dumazet <redacted>
Date: Tue, 08 Nov 2011 22:23:25 +0100
OK, it seems we let a timer running while we free the socket (same error
path than your previous bug report, because of the NULL route)
We arm this keepalive timer in tcp_create_openreq_child()
net/ipv4/tcp_minisocks.c:513
if (sock_flag(newsk, SOCK_KEEPOPEN))
inet_csk_reset_keepalive_timer(newsk,
keepalive_time_when(newtp));
I would try to add a call to tcp_clear_xmit_timers() as well
Please try following patch :
We've been waiting quite some time to get some testing validation on
this patch, but I think it's correct.
Eric can you formally submit this? Thanks!