Skip to content

fix(net): preserve TCP port ownership through TIME_WAIT - #2322

Merged
fslongjin merged 2 commits into
DragonOS-Community:masterfrom
fslongjin:codex/tcp-time-wait-lifecycle
Sep 22, 2026
Merged

fslongjin merged 2 commits into
DragonOS-Community:masterfrom
fslongjin:codex/tcp-time-wait-lifecycle

Conversation

@fslongjin

@fslongjin fslongjin commented Sep 22, 2026 •

Copy link
Copy Markdown
Member

Summary

Fix TCP port ownership and TIME_WAIT reuse rather than releasing all protection when a descriptor closes.

  • Track FD bindings and protocol lifetimes separately under one namespace-wide port authority, with indexed tuple ownership and independently inherited accepted-child state.
  • Apply both-sided SO_REUSEADDR rules, atomic listener promotion, and explicit nonzero-port retention on connection failure. Release unlocked bindings on protocol termination even when the old descriptor remains open.
  • Transfer unreachable TIME_WAIT sockets into compact protocol storage instead of discarding them or retaining full send/receive buffers. Keep expiry and namespace routing active in direct and NAPI polling.
  • Enable per-connection TCP timestamps and 60-second TIME_WAIT protection. Refresh the monotonic context after acquiring protocol locks so idle active-reuse attempts can advance without unrelated traffic.
  • Pin the smoltcp implementation and add 31 dunitest cases to the mandatory suite, including isolated two-port automatic reuse and unconsumed nonblocking-refusal close paths.

Dependency: DragonOS-Community/smoltcp#33 is merged into dragonos/v0.12.0. Pin its merge commit 9b9813e25323fb574f80b8aebfbbf2e7809f47ab; its Git tree is identical to the previously validated revision.

Validation

  • make fmt, make kernel, and whitespace checks passed.
  • DragonOS/QEMU: 31 new cases and 168 existing network cases passed.
  • Linux comparison: 31 cases passed; the original bind/child/TIME_WAIT reproducer now agrees with Linux.
  • smoltcp: 671 library tests and seven feature configurations passed; isolated port-logic tests: 8 passed.
  • nginx: 10 rounds of dual-stack HTTP, graceful exit, and immediate restart passed.
  • 40,000 client-active closes and 40,000 server-active closes passed, approximately 18.8s and 19.1s respectively.
  • A real 60-second protection interval expired with the original FD either open or closed (60.177s/60.176s); the two-port reconnect test requires no auxiliary packets.
  • 1,024 additional unconsumed nonblocking-refusal closes did not exhibit a full-buffer-per-close memory leak.
  • Independent security/concurrency, correctness, and resource/performance reviews were completed; confirmed findings were fixed and re-reviewed.

The 2,000-connection median changed from 905.7ms to 925.9ms (about +2.2%) while retaining the previously discarded protocol protection. Fixed-server-port batches remained approximately flat through 40,000 historical closes. Peak memory includes retained protocol records and allocator/container capacity; this is not a zero-cost compatibility change.

Scope

Dynamic migration of the same local IP between interface-owned protocol stacks remains a separate issue. Ordinary route/egress changes are not that migration case. This change does not relax tuple protection to hide that limitation and does not add a general TCP sysctl or recoverable-allocation framework.

Separate descriptor bindings from protocol ownership under a namespace-wide port authority. Inherit accepted-child identities independently, enforce both-sided reuse rules, and retain explicit bindings across refused connections.

Transfer unreachable TIME_WAIT sockets to compact smoltcp storage without dropping tuple protection. Maintain expiry in direct and NAPI polling and refresh the protocol clock under its locks so idle safe reuse does not depend on unrelated traffic.

Pin smoltcp 98c706ee7d5e62c77f74278531402637482a70bc and add 31 mandatory lifecycle regression tests. Validate with make fmt, make kernel, 168 existing guest network cases, 671 dependency tests, dual-stack nginx restart cycles, real 60-second expiry, and 40000 connections in each active-close direction.

Signed-off-by: longjin <longjin@dragonos.org>
@github-actions github-actions Bot added the Bug fix A bug is fixed in this pull request label Sep 22, 2026
@fslongjin

Copy link
Copy Markdown
Member Author

@codex review

Update the manifest and lockfile to the merge commit of DragonOS-Community/smoltcp#33 on dragonos/v0.12.0. The merged tree is identical to the previously validated dependency revision. Verify the updated dependency with make kernel.

Signed-off-by: longjin <longjin@dragonos.org>
@fslongjin
fslongjin merged commit 0029e5e into DragonOS-Community:master Sep 22, 2026
15 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Bug fix A bug is fixed in this pull request

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant