Re: [PATCH v6 nf-next 0/3] ipvs: add per-service secure_tcp
flat view
From: Julian Anastasov <ja@ssi.bg>
Date: 2026-10-07 03:52:38
Also in:
lkml, lvs-devel, netfilter-devel
Hello, On Mon, 5 Oct 2026, Adriano Cordova wrote:
IPVS currently exposes secure_tcp as a per-netns sysctl. It switches the
TCP state machine to the hardened tcp_states_dos table.
These patches make it per-service: a virtual service can set
IP_VS_SVC_F_SECURE_TCP which is passed into IP_VS_CONN_F_SECURE_TCP at
connection creation. set_tcp_state() then selects tcp_states_dos for those
connections with IP_VS_CONN_F_SECURE_TCP set and keeps pd->tcp_state_table
(the netns default, including the nomem floor) otherwise.
1. uapi: define the per-service secure_tcp flags and stamp the flag in
ip_vs_bind_dest() (cache-bypass has no dest)
2. honor it in the TCP state machine, resolving the stale FIXME, and
document the new default/opt-in split
3. kselftest contrasting a secure vs. a plain service
Changes in v2:
- Let IP_VS_SVC_F_SECURE_TCP be 0x0100, leaving 0x0040/0x0080 for the
scheduler flags. Let IP_VS_CONN_F_SECURE_TCP be (1 << 17) and no longer
in IP_VS_CONN_F_BACKUP_MASK.
- Set flag in ip_vs_bind_dest() instead of at every ip_vs_conn_new()
call site.
- selftest: send probes with TTL=1 instead of an nft drop, and fix
Sashiko comments.
Changes in v3:
- Merge patch 1/4 and 2/4
- Re-send patches (v2 dropped patches 3/4 and 4/4)
Changes in v4:
- selftest: check the return values of setsockopt(IP_HDRINCL), sendto()
and mnl_socket_bind(), and fail do_add() when IPVS does not reply.
- selftest: fix the remaining Sashiko comments: check inet_pton(),
initialize fam and the parsed addresses, and verify the flags attribute
length before copying it.
Changes in v5:
- Document secure_tcp as the netns-wide default and the new per-service
IP_VS_SVC_F_SECURE_TCP opt-in.
- selftest: reword the changelog to "a bare SYN followed by a bare ACK".
- selftest: skip when the ip_vs or ip_vs_rr module is unavailable.
- selftest: check the probe exit status so that a probe which dies after
the SYN cannot leave the secure-side SYN_RECV assertion passing.
Changes in v6:
- Rebase onto nf-next.
Adriano Cordova (3):
ipvs: add flags for per-service secure TCP state table
ipvs: tcp: enable per-connection secure_tcp in state machine
selftests: netfilter: ipvs: add per-service secure_tcp testPatches 1-2 look good to me, thanks! Acked-by: Julian Anastasov <ja@ssi.bg> Patch 3 for selftests looks ok but should be considered by the netfilter maintainers. Please consider providing ipvsadm patch: https://git.kernel.org/cgit/utils/kernel/ipvsadm/ipvsadm.git/ As for the Sashiko review: https://sashiko.dev/#/patchset/20261005230808.148478-1-adrianox%40gmail.com We decided not to restore the IP_VS_CONN_F_SECURE_TCP flag in the backup server, the flag will depend on the local configuration in the backup server.
Documentation/networking/ipvs-sysctl.rst | 4 + include/uapi/linux/ip_vs.h | 2 + net/netfilter/ipvs/ip_vs_conn.c | 4 + net/netfilter/ipvs/ip_vs_core.c | 3 + net/netfilter/ipvs/ip_vs_proto_tcp.c | 16 +- .../testing/selftests/net/netfilter/Makefile | 6 + .../selftests/net/netfilter/gen_tcp_probe.c | 158 ++++++++ .../net/netfilter/ipvs_secure_tcp.sh | 169 +++++++++ .../net/netfilter/ipvs_secure_tcp_mln.c | 337 ++++++++++++++++++ 9 files changed, 692 insertions(+), 7 deletions(-) create mode 100644 tools/testing/selftests/net/netfilter/gen_tcp_probe.c create mode 100755 tools/testing/selftests/net/netfilter/ipvs_secure_tcp.sh create mode 100644 tools/testing/selftests/net/netfilter/ipvs_secure_tcp_mln.c base-commit: 8b4e7209c842d8cb9516f1f5ef0a88aa2d8831a6 -- 2.51.0
Regards -- Julian Anastasov [off-list ref]