Re: [PATCH 0/4] ipvs: add per-service secure_tcp
flat view
From: Julian Anastasov <ja@ssi.bg>
Date: 2026-09-15 19:40:04
Also in:
lvs-devel, netfilter-devel
Hello, On Fri, 11 Sep 2026, Adriano Cordova wrote:
IPVS currently exposes secure_tcp as a per-netns sysctl. It switches the
TCP state machine to the hardened tcp_states_dos table.
These patches make it per-service: a virtual service can set
IP_VS_SVC_F_SECURE_TCP which is passed into IP_VS_CONN_F_SECURE_TCP at
connection creation. set_tcp_state() then selects tcp_states_dos for those
connections with IP_VS_CONN_F_SECURE_TCP set and keeps pd->tcp_state_table
(the netns default, including the nomem floor) otherwise.
The flag is part of BACKUP_MASK, so it is preserved on sync to backups.
1. uapi: define the per-service secure_tcp flags
2. carry the flag on every connection-creation path (scheduler,
persistence, RS-initiated, cache-bypass) and on FTP data channels
3. honor it in the TCP state machine, resolving the stale FIXME
4. kselftest contrasting a secure vs. a plain service.Note that there is a review for patch 4 by Sashiko: https://sashiko.dev/#/patchset/20260912013216.588300-1-adrianox%40gmail.com My comments: Patch 1: - lets start IP_VS_SVC_F_SECURE_TCP from 0x0100, i.e. to reserve some bits for the schedulers - IP_VS_CONN_F_SECURE_TCP: should we really sync this flag? It can be configured in every director differently. As pd->tcp_state_table can be changed at any time, it should be safe to sync cp->state between different secure_tcp modes (directors). So, if it is not synced, next free value should be (1 << 17). Patch 2: - looks like we have many places that read svc->flags. Better ip_vs_bind_dest() to check for IP_VS_SVC_F_SECURE_TCP and to set IP_VS_CONN_F_SECURE_TCP. It will allow the synced connection to inherit the flag from the local director. Patch 3: - there was even tcp_timeouts_dos, see commit f1f71e03b17d. The idea was to use reduced timeouts under attack which can be also tuned by user space, something that can be implemented by using the netlink interface. Patch 4: - if you do not want packets to reach the real server you can send with TTL=1, the TCP state machine will be updated but at sending time an ICMP will be sent back.
Not sure about patch 4... could be dropped or absorbed into ipvs.sh
I'm not sure too. Regards -- Julian Anastasov [off-list ref]