Found on real kernel 5.15 (netns+veth, challenge enabled): 1. truncated IP: after bpf_xdp_adjust_tail the IPv4 tot_len / IPv6 payload_len still claimed the original SYN size — peer silently dropped the malformed SYN-ACK, challenge never seen 2. endianness: marker/bad_ack written as raw host-order halfwords into network-order tcpw[] — client echoed swap16halves(bad_ack) in its RST.seq, verification always failed (CHAL_FAILED == CHAL_SENT) Post-fix e2e: SYN -> bad-ACK SYN-ACK (XDP_TX) -> client RST -> verified -> retry connects transparently; counters SENT=1 VERIFIED=1 FAILED=0 |
||
|---|---|---|
| .. | ||
| common.h | ||
| config.h | ||
| maps.h | ||
| prefix_stats.h | ||
| stats.h | ||
| syn_challenge.h | ||
| universal_filter.c | ||