Thread (6 messages) 6 messages, 2 authors, 24d ago

Re: [PATCH 0/4] ipvs: add per-service secure_tcp

flat view

From: Julian Anastasov <ja@ssi.bg>
Date: 2026-09-15 19:40:04
Also in: lvs-devel, netfilter-devel

	Hello,

On Fri, 11 Sep 2026, Adriano Cordova wrote:
IPVS currently exposes secure_tcp as a per-netns sysctl. It switches the
TCP state machine to the hardened tcp_states_dos table.

These patches make it per-service: a virtual service can set
IP_VS_SVC_F_SECURE_TCP which is passed into IP_VS_CONN_F_SECURE_TCP at
connection creation. set_tcp_state() then selects tcp_states_dos for those
connections with IP_VS_CONN_F_SECURE_TCP set and keeps pd->tcp_state_table
(the netns default, including the nomem floor) otherwise.

The flag is part of BACKUP_MASK, so it is preserved on sync to backups.

  1. uapi: define the per-service secure_tcp flags
  2. carry the flag on every connection-creation path (scheduler,
     persistence, RS-initiated, cache-bypass) and on FTP data channels
  3. honor it in the TCP state machine, resolving the stale FIXME
  4. kselftest contrasting a secure vs. a plain service.
	Note that there is a review for patch 4 by Sashiko:

https://sashiko.dev/#/patchset/20260912013216.588300-1-adrianox%40gmail.com

	My comments:

	Patch 1:

- lets start IP_VS_SVC_F_SECURE_TCP from 0x0100, i.e. to reserve
some bits for the schedulers

- IP_VS_CONN_F_SECURE_TCP: should we really sync this flag?
It can be configured in every director differently. As
pd->tcp_state_table can be changed at any time, it should be
safe to sync cp->state between different secure_tcp
modes (directors). So, if it is not synced, next free value
should be (1 << 17).

	Patch 2:

- looks like we have many places that read svc->flags.
Better ip_vs_bind_dest() to check for IP_VS_SVC_F_SECURE_TCP
and to set IP_VS_CONN_F_SECURE_TCP. It will allow the synced
connection to inherit the flag from the local director.

	Patch 3:

- there was even tcp_timeouts_dos, see commit f1f71e03b17d.
The idea was to use reduced timeouts under attack which can
be also tuned by user space, something that can be implemented
by using the netlink interface.

	Patch 4:

- if you do not want packets to reach the real server you can
send with TTL=1, the TCP state machine will be updated but at
sending time an ICMP will be sent back.
Not sure about patch 4... could be dropped or absorbed into ipvs.sh
	I'm not sure too.

Regards

--
Julian Anastasov [off-list ref]
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help