Do not fence connections without valid greeting.

There is no reason to fence any connection that hasn't sent a valid
greeting, since they haven't progressed far enough for it to make
sense.

We remove the connection from the list of accepted clients, which then
removes the need for fencing, and the server won't need to restart.

Adds a test script that makes sure that we didn't actually restart the
server while this was happening.

Signed-off-by: Auke Kok <auke.kok@versity.com>
This commit is contained in:
Auke Kok
2026-08-12 16:06:55 -04:00
parent 5a6394e025
commit e023c2fa4a
4 changed files with 43 additions and 0 deletions
+11
View File
@@ -1452,6 +1452,17 @@ restart:
set_conn_fl(acc, reconn_freeing);
spin_unlock(&conn->lock);
if (!test_conn_fl(conn, shutting_down)) {
/*
* If we haven't seen a vg for this connection, don't bother fencing
* it - instead just drop it. If this was a real client, it will try
* again to connect.
*/
if (!test_conn_fl(acc, valid_greeting)) {
/* delete the conn */
list_del_init(&acc->accepted_head);
goto restart;
}
scoutfs_info(sb, "client "SIN_FMT" reconnect timed out, fencing",
SIN_ARG(&acc->last_peername));
ret = scoutfs_fence_start(sb, acc->rid,
+7
View File
@@ -0,0 +1,7 @@
== empty packets
Ncat: Connection refused.
Ncat: Connection refused.
== find portscan in connections
== find portscan in connections
+1
View File
@@ -65,4 +65,5 @@ block-stale-reads.sh
freed-list-wedge.sh
inode-deletion.sh
renameat2-noreplace.sh
portscan.sh
xfstests.sh
+24
View File
@@ -0,0 +1,24 @@
#
# portscan tests - assure malformed packets do not cause issues
#
t_require_commands scoutfs nc
echo "== empty packets"
sleep 1
echo " " | nc -p 33033 127.0.0.1 $T_PORT_START
echo " " | nc -p 33133 127.0.0.1 $((T_PORT_START+1))
echo " " | nc -p 33233 127.0.0.1 $((T_PORT_START+2))
echo "== find portscan in connections"
L=$(grep 'peer 127.0.0.1:33.33' /sys/kernel/debug/scoutfs/*/connections)
echo $L
# wait for fencing timeout (20s)
sleep 30
echo "== find portscan in connections"
L=$(grep 'peer 127.0.0.1:33.33' /sys/kernel/debug/scoutfs/*/connections)
echo $L
t_pass