Page MenuHomeFreeBSD

tcp: fix TCPS_CLOSED state underleak in syncache_socket()
ClosedPublic

Authored by glebius on Sep 2 2026, 9:24 PM.
Tags
None
Referenced Files
Unknown Object (File)
Mon, Oct 5, 10:08 AM
Unknown Object (File)
Mon, Oct 5, 8:37 AM
Unknown Object (File)
Sun, Oct 4, 2:13 PM
Unknown Object (File)
Fri, Oct 2, 12:14 AM
Unknown Object (File)
Thu, Oct 1, 12:45 PM
Unknown Object (File)
Wed, Sep 30, 8:54 PM
Unknown Object (File)
Wed, Sep 30, 10:34 AM
Unknown Object (File)
Sun, Sep 27, 10:39 AM
Subscribers

Details

Summary

The syncache entry holds one TCPS_SYN_RECEIVED count that normally is
transferred to the the newborn tp. Upon failure syncache_socket() shall
not use TCPSTATES_INC/TCPSTATES_DEC (see 5050df3f4aa4 why). But when
syncache_socket() fails in_pcbconnect(), it calls tcp_discardcb() to free
resources that were just allocated by tcp_newtcpcb() and this
tcp_discardcb() would do TCPSTATES_DEC(tp->t_state). The t_state is
TCPS_CLOSED at this point.

Make tcp_discardcb() symmetrical to tcp_newtcpcb() - not responsible for
the TCPSTATES. Make the caller responsible for state count book keeping.

Fixes: 3703e1a73e0e0367c04f47f793e46495e46e647b
MFC After: 2 weeks

Diff Detail

Repository
rG FreeBSD src repository
Lint
Lint Not Applicable
Unit
Tests Not Applicable