Browse Source
When etcp_link_close() frees a link while INFLIGHT_PACKET entries still reference it via last_link, a later ACK causes SIGSEGV in bbr_main(link->bbr=NULL). Fix: - etcp_inflight_nullify_link(): nullifies last_link in both input_wait_ack and input_send_q for entries pointing to dead_link - Called from etcp_link_close() before u_free(link) - Guard etcp_ack_recv: check acked_pkt->last_link->bbr before accessing BBR/inflight stats - Also fix bbr leak in etcp_link_close !link->conn path Verified: 30/30 runs of test_etcp_link_stress pass (was ~50% crash) Full suite: 71/71 passtopo_upd
2 changed files with 16 additions and 1 deletions
Loading…
Reference in new issue