Received: by 2002:a05:6a10:2726:0:0:0:0 with SMTP id ib38csp3143098pxb; Mon, 4 Apr 2022 08:44:16 -0700 (PDT) X-Google-Smtp-Source: ABdhPJwWbIzzyEBl7MkWx4n54khNCl+tFKK1i6SERhwEUD1E90A3FikOsuWGVzhTaWZ9HeL13/aj X-Received: by 2002:a05:6a00:2887:b0:4fa:e10c:7ca with SMTP id ch7-20020a056a00288700b004fae10c07camr644992pfb.9.1649087056315; Mon, 04 Apr 2022 08:44:16 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1649087056; cv=none; d=google.com; s=arc-20160816; b=jX4c6+7meGxq1vY2yiOPNG4Xap6NsNOqEglanSari8IcDUZnWulM8ds9valkARpGrW F55XBJ/Xdrf9l97V3WCgu8jUWG8+sqDxCKboutr7pOuV8aQWdtO5jRbFPR7PQJMhltfy wJqBb1UFj4Ctz+/EjWqDTIhO3U8dsFcBq+J2c6IgSrGu6ISENA4T9cWTOabx20KVz72j CKIDT/7eSqXa1+7o4sVvek91ZxbipR5Ag+fw7G6inmUOvR7ivQjPvGv8GROwls4BpV+C SA4di6+OYD1vRt+iRufWlMY3LpUTnDlpfnfsfN8PnJ9Bad4kqKTuB+9MFmzWcn8KgPbR zFVw== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:user-agent:in-reply-to:content-transfer-encoding :content-disposition:mime-version:references:message-id:subject:cc :to:from:date; bh=Tnf6KD39OiSEAqSnAxju1kCLyzcNCDqD9SblA0r/MCM=; b=JCWMM1th3ETLFhB0ZAtgD/XT9bXszxV4UdhiBxzPJPNU0DfibWyNKszeVqXP5OZk0V qYWenIpasSEOHyqDJIjD84XuStkAaKYrhOzBKfONAmWyP5dgQtRuCTOKS94a5fNntcO8 B+NDSuQpfTG1vSeP5n2TQJjXEhX3e+rNPU4/AtZ6Ml7sXwo6DlBxDaxl/Fhgk9Ce7gNM 9jYus23ZPoDPdr48L/o7QBPgRhgcdtU1k9WFXrH+RqfDNHyfUg4Ud6V/XJF1Usifc5T4 G9UKD2aWKmlGsjup6OoZAjsMY8EiqRbYUE+RWorHBgW5FAI52rvP8sfIU6DIDZ6jMz35 3Lcg== ARC-Authentication-Results: i=1; mx.google.com; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org Return-Path: Received: from out1.vger.email (out1.vger.email. [2620:137:e000::1:20]) by mx.google.com with ESMTP id i190-20020a626dc7000000b004fae7a23a5fsi9383005pfc.146.2022.04.04.08.43.59; Mon, 04 Apr 2022 08:44:16 -0700 (PDT) Received-SPF: pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) client-ip=2620:137:e000::1:20; Authentication-Results: mx.google.com; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1354914AbiDBOQI (ORCPT + 99 others); Sat, 2 Apr 2022 10:16:08 -0400 Received: from lindbergh.monkeyblade.net ([23.128.96.19]:43276 "EHLO lindbergh.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S238179AbiDBOQG (ORCPT ); Sat, 2 Apr 2022 10:16:06 -0400 Received: from Chamillionaire.breakpoint.cc (Chamillionaire.breakpoint.cc [IPv6:2a0a:51c0:0:12e:520::1]) by lindbergh.monkeyblade.net (Postfix) with ESMTPS id 46D973D1C4; Sat, 2 Apr 2022 07:14:12 -0700 (PDT) Received: from fw by Chamillionaire.breakpoint.cc with local (Exim 4.92) (envelope-from ) id 1naeW2-0005EG-Ka; Sat, 02 Apr 2022 16:14:10 +0200 Date: Sat, 2 Apr 2022 16:14:10 +0200 From: Florian Westphal To: Jaco Kroon Cc: Neal Cardwell , Florian Westphal , Eric Dumazet , LKML , Netdev , Yuchung Cheng , Wei Wang Subject: Re: linux 5.17.1 disregarding ACK values resulting in stalled TCP connections Message-ID: <20220402141410.GE28321@breakpoint.cc> References: <10c1e561-8f01-784f-c4f4-a7c551de0644@uls.co.za> <5f1bbeb2-efe4-0b10-bc76-37eff30ea905@uls.co.za> <429dd56b-8a6c-518f-ccb4-fa5beae30953@uls.co.za> MIME-Version: 1.0 Content-Type: text/plain; charset=iso-8859-15 Content-Disposition: inline Content-Transfer-Encoding: 8bit In-Reply-To: <429dd56b-8a6c-518f-ccb4-fa5beae30953@uls.co.za> User-Agent: Mutt/1.10.1 (2018-07-13) X-Spam-Status: No, score=-4.2 required=5.0 tests=BAYES_00,RCVD_IN_DNSWL_MED, SPF_HELO_PASS,SPF_PASS,T_SCC_BODY_TEXT_LINE autolearn=ham autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on lindbergh.monkeyblade.net Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org Jaco Kroon wrote: > Including sysctl net.netfilter.nf_conntrack_log_invalid=6- which > generates lots of logs, something specific I should be looking for?? I > suspect these relate: > > [Sat Apr? 2 10:31:53 2022] nf_ct_proto_6: SEQ is over the upper bound > (over the window of the receiver) IN= OUT=bond0 > SRC=2c0f:f720:0000:0003:d6ae:52ff:feb8:f27b > DST=2a00:1450:400c:0c08:0000:0000:0000:001a LEN=2928 TC=0 HOPLIMIT=64 > FLOWLBL=867133 PROTO=TCP SPT=48920 DPT=25 SEQ=2689938314 ACK=4200412020 > WINDOW=447 RES=0x00 ACK PSH URGP=0 OPT (0101080A2F36C1C120EDFB91) UID=8 > GID=12 I thought this had "liberal mode" enabled for tcp conntrack? The above implies its off.