Repository navigation
Conversation
When a new SYN reopens a connection while the old incarnation is in TIME_WAIT (RFC 1122), handleTimeWaitSegments only looks for a bound listening endpoint to hand the segment to. A stack that accepts connections through a tcp.Forwarder has no such endpoint, so the SYN is dropped for the rest of the TIME_WAIT period. Fall back to the protocol's default handler, giving the forwarder the same chance a listening endpoint gets. Fixes google#15013 Signed-off-by: drakeo338 <paranoyouz@gmail.com> Upstream: google#15019
…ment The reuseTW closure in handleTimeWaitSegments discarded the handler's return value. tcp.Forwarder.HandlePacket returns false for anything that is not a bare SYN, but a SYN-ACK with a higher sequence number still counts as a new SYN in TIME_WAIT, so it reached the handler, was declined, and was dropped without a reply. Send a RST as nic.DeliverTransportPacket does when the handler returns false. Adds a forwarder e2e test that sends a SYN-ACK during TIME_WAIT and expects a RST. [coder/gvisor: the e2e test is omitted. This branch is built from the test-free go branch and lacks the packages the test imports.] Signed-off-by: drakeo338 <paranoyouz@gmail.com> Upstream: google#15019
ibetitsmike
approved these changes
Oct 7, 2026
mafredri
added a commit
to coder/coder
that referenced
this pull request
Oct 8, 2026
The agent netstack accepts connections through tcp.Forwarder and has no listening endpoint, so gVisor drops a SYN that reuses a 4-tuple the agent holds in TIME_WAIT, and the client's dial hangs for about 63s. The new pin is the head of coder/gvisor#4, which cherry-picks google/gvisor#15019. That PR hands the SYN to the forwarder. It is open, from an outside contributor, and no gVisor maintainer has reviewed it.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Cherry-picks the two commits of google#15019 onto the commit coder/coder pins,
7a658db7b714. google#15019 is an open PR from an outside contributor, and no gVisor maintainer has reviewed it.With a
tcp.Forwarderas the TCP protocol handler, which is how tailscale's netstack accepts connections on Coder workspace agents, a new SYN that reopens a 4-tuple in TIME_WAIT was only handed to a listening endpoint. A forwarder stack has none, so the SYN and every retransmit were dropped until TIME_WAIT expired, and the client's dial hung for up to about 63s (google#15013). The first commit hands that SYN to the protocol's default handler. The second sends a RST when the handler declines the segment.The changed lines match google#15019 exactly. Its e2e test is left out because this branch is built from the test-free
gobranch, which lacks the packages it imports. Coverage lives in coder/coder: coder/coder#30471 adds a tailnet test that reopens a connection from the same source port after the agent closed it, and bumps coder/coder to this branch's head,ebe33a4c2cb5.The first commit keeps the PR's
Fixes #15013. That refers to google#15013; this repository has issues disabled.Tracked in PLAT-717.
When squash-merging: the default message lists both commit messages. Replace each
Upstream: https://github.com/google/gvisor/pull/15019trailer withCherry-picked from https://github.com/google/gvisor/pull/15019 (unmerged).