Found on real kernel 5.15 (netns+veth, challenge enabled):
1. truncated IP: after bpf_xdp_adjust_tail the IPv4 tot_len / IPv6
payload_len still claimed the original SYN size — peer silently
dropped the malformed SYN-ACK, challenge never seen
2. endianness: marker/bad_ack written as raw host-order halfwords into
network-order tcpw[] — client echoed swap16halves(bad_ack) in its
RST.seq, verification always failed (CHAL_FAILED == CHAL_SENT)
Post-fix e2e: SYN -> bad-ACK SYN-ACK (XDP_TX) -> client RST ->
verified -> retry connects transparently; counters SENT=1 VERIFIED=1
FAILED=0