<div dir="ltr">Hi ,<div><br></div><div>How to get access to min kenel git as i need to add some patches for reviews.</div><div><br></div><div>Bhagaban</div></div><div class="gmail_extra"><br><div class="gmail_quote">On Sat, Nov 8, 2014 at 10:30 PM, <span dir="ltr"><<a href="mailto:kernelnewbies-request@kernelnewbies.org" target="_blank">kernelnewbies-request@kernelnewbies.org</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">Send Kernelnewbies mailing list submissions to<br>
<a href="mailto:kernelnewbies@kernelnewbies.org">kernelnewbies@kernelnewbies.org</a><br>
<br>
To subscribe or unsubscribe via the World Wide Web, visit<br>
<a href="http://lists.kernelnewbies.org/mailman/listinfo/kernelnewbies" target="_blank">http://lists.kernelnewbies.org/mailman/listinfo/kernelnewbies</a><br>
or, via email, send a message with subject or body 'help' to<br>
<a href="mailto:kernelnewbies-request@kernelnewbies.org">kernelnewbies-request@kernelnewbies.org</a><br>
<br>
You can reach the person managing the list at<br>
<a href="mailto:kernelnewbies-owner@kernelnewbies.org">kernelnewbies-owner@kernelnewbies.org</a><br>
<br>
When replying, please edit your Subject line so it is more specific<br>
than "Re: Contents of Kernelnewbies digest..."<br>
<br>
<br>
Today's Topics:<br>
<br>
1. Re: Eudyptula challenge status (Drew Fustini)<br>
2. RE: lots of connections in SYN_RECV state (Puneet Agarwal)<br>
3. Re: lots of connections in SYN_RECV state<br>
(<a href="mailto:Valdis.Kletnieks@vt.edu">Valdis.Kletnieks@vt.edu</a>)<br>
4. Re: lots of connections in SYN_RECV state (Dave Tian)<br>
5. RE: lots of connections in SYN_RECV state (Puneet Agarwal)<br>
<br>
<br>
----------------------------------------------------------------------<br>
<br>
Message: 1<br>
Date: Fri, 7 Nov 2014 11:04:28 -0600<br>
From: Drew Fustini <<a href="mailto:pdp7pdp7@gmail.com">pdp7pdp7@gmail.com</a>><br>
Subject: Re: Eudyptula challenge status<br>
To: Dan <<a href="mailto:qsdconsulting@gmail.com">qsdconsulting@gmail.com</a>><br>
Cc: kernelnewbies <<a href="mailto:kernelnewbies@kernelnewbies.org">kernelnewbies@kernelnewbies.org</a>><br>
Message-ID:<br>
<<a href="mailto:CAEf4M_B6W3GJ8P_ShhpoL8QqtGEZ7h18p92BxuH0foQOQYj2Wg@mail.gmail.com">CAEf4M_B6W3GJ8P_ShhpoL8QqtGEZ7h18p92BxuH0foQOQYj2Wg@mail.gmail.com</a>><br>
Content-Type: text/plain; charset=UTF-8<br>
<br>
Yup, I submitted my current task 4 weeks ago, sent a note last week,<br>
and got reply the next day (Nov 1) with same sentiment: relax -<br>
everything is ok, it's a slow process, and it's not a race.<br>
<br>
On Tue, Nov 4, 2014 at 8:59 PM, Dan <<a href="mailto:qsdconsulting@gmail.com">qsdconsulting@gmail.com</a>> wrote:<br>
> Ramon Fried <ramon.fried <at> <a href="http://tandemg.com" target="_blank">tandemg.com</a>> writes:<br>
><br>
>><br>
>><br>
>> Hey all.<br>
>> Tasks are pending for a long time. Anyone has Info regarding the queue?<br>
>> Thanks.<br>
>> Ramon<br>
>><br>
>><br>
>> _______________________________________________<br>
>> Kernelnewbies mailing list<br>
>> Kernelnewbies <at> <a href="http://kernelnewbies.org" target="_blank">kernelnewbies.org</a><br>
>> <a href="http://lists.kernelnewbies.org/mailman/listinfo/kernelnewbies" target="_blank">http://lists.kernelnewbies.org/mailman/listinfo/kernelnewbies</a><br>
>><br>
><br>
><br>
> I've been on challenge 5 for about a month and a half. I sent him a follow<br>
> up email a few weeks ago and he replied "Relax, things are slow, there's no<br>
> rush..."<br>
><br>
> His response times before that were usually less than 2 days.<br>
><br>
><br>
><br>
> _______________________________________________<br>
> Kernelnewbies mailing list<br>
> <a href="mailto:Kernelnewbies@kernelnewbies.org">Kernelnewbies@kernelnewbies.org</a><br>
> <a href="http://lists.kernelnewbies.org/mailman/listinfo/kernelnewbies" target="_blank">http://lists.kernelnewbies.org/mailman/listinfo/kernelnewbies</a><br>
<br>
<br>
<br>
------------------------------<br>
<br>
Message: 2<br>
Date: Fri, 7 Nov 2014 23:11:26 +0530<br>
From: Puneet Agarwal <<a href="mailto:puneet.agr@outlook.com">puneet.agr@outlook.com</a>><br>
Subject: RE: lots of connections in SYN_RECV state<br>
To: Dave Tian <<a href="mailto:dave.jing.tian@gmail.com">dave.jing.tian@gmail.com</a>>, Silvan Jegen<br>
<<a href="mailto:me@sillymon.ch">me@sillymon.ch</a>><br>
Cc: "<a href="mailto:kernelnewbies@kernelnewbies.org">kernelnewbies@kernelnewbies.org</a>"<br>
<<a href="mailto:kernelnewbies@kernelnewbies.org">kernelnewbies@kernelnewbies.org</a>><br>
Message-ID: <SNT153-W7011B59E54B5FD99A3604699850@phx.gbl><br>
Content-Type: text/plain; charset="iso-8859-1"<br>
<br>
I use linux kernel 2.6. I have enabled SYN cookies already. But that does not seem to solve the problem. Overall request latency is very high with these many half open connections.<br>
<br>
Thanks and Regards<br>
Puneet<br>
----------------------------------------<br>
> Subject: Re: lots of connections in SYN_RECV state<br>
> From: <a href="mailto:dave.jing.tian@gmail.com">dave.jing.tian@gmail.com</a><br>
> Date: Fri, 7 Nov 2014 23:49:35 +0800<br>
> CC: <a href="mailto:puneet.agr@outlook.com">puneet.agr@outlook.com</a>; <a href="mailto:kernelnewbies@kernelnewbies.org">kernelnewbies@kernelnewbies.org</a><br>
> To: <a href="mailto:me@sillymon.ch">me@sillymon.ch</a><br>
><br>
> Latest kernel provides a TCP SYN Cookie feature to defense from SYN flooding.<br>
><br>
> -daveti<br>
><br>
><br>
>> On Nov 6, 2014, at 11:58 PM, Silvan Jegen <<a href="mailto:me@sillymon.ch">me@sillymon.ch</a>> wrote:<br>
>><br>
>> 2014-11-06 16:15,Puneet Agarwal:<br>
>>> Is there a way to check the reason, why they do not answer to the<br>
>>> SYN-ACK's?<br>
>><br>
>> I don't think so. After all, they just don't answer and they won't tell<br>
>> you why (AFAIK there is no way to ask them why either)...<br>
>><br>
>> You could try to check for patterns in the incoming IP addresses to see<br>
>> from how many different places these connections are being made. I think<br>
>> that way it should be possible to figure out from which geographic<br>
>> location these problematic connections are coming from as well. What you<br>
>> would do with these findings I am not sure though.<br>
>><br>
>> If these connection negatively impact the performance of your servers<br>
>> you should definitely look into to countermeasures mentioned in the RFC<br>
>> here.<br>
>><br>
>> <a href="http://tools.ietf.org/html/rfc4987" target="_blank">http://tools.ietf.org/html/rfc4987</a><br>
>><br>
>><br>
>> _______________________________________________<br>
>> Kernelnewbies mailing list<br>
>> <a href="mailto:Kernelnewbies@kernelnewbies.org">Kernelnewbies@kernelnewbies.org</a><br>
>> <a href="http://lists.kernelnewbies.org/mailman/listinfo/kernelnewbies" target="_blank">http://lists.kernelnewbies.org/mailman/listinfo/kernelnewbies</a><br>
><br>
<br>
<br>
<br>
------------------------------<br>
<br>
Message: 3<br>
Date: Fri, 07 Nov 2014 13:10:05 -0500<br>
From: <a href="mailto:Valdis.Kletnieks@vt.edu">Valdis.Kletnieks@vt.edu</a><br>
Subject: Re: lots of connections in SYN_RECV state<br>
To: Puneet Agarwal <<a href="mailto:puneet.agr@outlook.com">puneet.agr@outlook.com</a>><br>
Cc: Dave Tian <<a href="mailto:dave.jing.tian@gmail.com">dave.jing.tian@gmail.com</a>>, Silvan Jegen<br>
<<a href="mailto:me@sillymon.ch">me@sillymon.ch</a>>, "<a href="mailto:kernelnewbies@kernelnewbies.org">kernelnewbies@kernelnewbies.org</a>"<br>
<<a href="mailto:kernelnewbies@kernelnewbies.org">kernelnewbies@kernelnewbies.org</a>><br>
Message-ID: <<a href="mailto:9736.1415383805@turing-police.cc.vt.edu">9736.1415383805@turing-police.cc.vt.edu</a>><br>
Content-Type: text/plain; charset="us-ascii"<br>
<br>
On Fri, 07 Nov 2014 23:11:26 +0530, Puneet Agarwal said:<br>
<br>
> I use linux kernel 2.6. I have enabled SYN cookies already. But that does not<br>
> seem to solve the problem. Overall request latency is very high with these many<br>
> half open connections.<br>
<br>
So, out of curiosity, where are all these half open connections coming<br>
from? Are they from addresses in your local network? Outside sites that<br>
*should* be connecting? Places you've never heard and and probably *shouldn't*<br>
be connecting?<br>
<br>
(Also, if you have properly implemented syncookies, you shouldn't *have* any<br>
half-open connections. That's the whole point of syncookies....)<br>
<br>
-------------- next part --------------<br>
A non-text attachment was scrubbed...<br>
Name: not available<br>
Type: application/pgp-signature<br>
Size: 848 bytes<br>
Desc: not available<br>
Url : <a href="http://lists.kernelnewbies.org/pipermail/kernelnewbies/attachments/20141107/85f1f4aa/attachment-0001.bin" target="_blank">http://lists.kernelnewbies.org/pipermail/kernelnewbies/attachments/20141107/85f1f4aa/attachment-0001.bin</a><br>
<br>
------------------------------<br>
<br>
Message: 4<br>
Date: Sat, 8 Nov 2014 07:48:14 +0800<br>
From: Dave Tian <<a href="mailto:dave.jing.tian@gmail.com">dave.jing.tian@gmail.com</a>><br>
Subject: Re: lots of connections in SYN_RECV state<br>
To: <a href="mailto:Valdis.Kletnieks@vt.edu">Valdis.Kletnieks@vt.edu</a><br>
Cc: Puneet Agarwal <<a href="mailto:puneet.agr@outlook.com">puneet.agr@outlook.com</a>>, Silvan Jegen<br>
<<a href="mailto:me@sillymon.ch">me@sillymon.ch</a>>, <a href="mailto:kernelnewbies@kernelnewbies.org">kernelnewbies@kernelnewbies.org</a><br>
Message-ID: <<a href="mailto:3C9C05E5-9B76-4C85-ABB5-D6A9D345E871@gmail.com">3C9C05E5-9B76-4C85-ABB5-D6A9D345E871@gmail.com</a>><br>
Content-Type: text/plain; charset=utf-8<br>
<br>
Oops, my bad. I remember seeing sth on LWN for the 3.x kernel talking about a new feature related with TCP SYN. Thought this pretty old stuff was the one?<br>
<br>
-daveti<br>
<br>
<br>
> On Nov 8, 2014, at 12:58 AM, <a href="mailto:Valdis.Kletnieks@vt.edu">Valdis.Kletnieks@vt.edu</a> wrote:<br>
><br>
> On Fri, 07 Nov 2014 23:49:35 +0800, Dave Tian said:<br>
>> Latest kernel provides a TCP SYN Cookie feature to defense from SYN flooding.<br>
><br>
> If by "latest" you mean "since Andi Kleen submitted a patch for 2.1.44",<br>
> back in July 1997....<br>
<br>
<br>
<br>
<br>
------------------------------<br>
<br>
Message: 5<br>
Date: Sat, 8 Nov 2014 07:35:30 +0530<br>
From: Puneet Agarwal <<a href="mailto:puneet.agr@outlook.com">puneet.agr@outlook.com</a>><br>
Subject: RE: lots of connections in SYN_RECV state<br>
To: "<a href="mailto:Valdis.Kletnieks@vt.edu">Valdis.Kletnieks@vt.edu</a>" <<a href="mailto:valdis.kletnieks@vt.edu">valdis.kletnieks@vt.edu</a>><br>
Cc: Dave Tian <<a href="mailto:dave.jing.tian@gmail.com">dave.jing.tian@gmail.com</a>>, Silvan Jegen<br>
<<a href="mailto:me@sillymon.ch">me@sillymon.ch</a>>, "<a href="mailto:kernelnewbies@kernelnewbies.org">kernelnewbies@kernelnewbies.org</a>"<br>
<<a href="mailto:kernelnewbies@kernelnewbies.org">kernelnewbies@kernelnewbies.org</a>><br>
Message-ID: <SNT153-W6599D6BF8CD3550AB9FB9899820@phx.gbl><br>
Content-Type: text/plain; charset="iso-8859-1"<br>
<br>
These connections are from outside the network, and the IP's are legitimate ones which should be connecting.<br>
I don't know whether the IP's which I could see are the real ones or spoofed ones.<br>
<br>
sysctl -a says<br>
net.ipv4.tcp_syncookies = 1<br>
<br>
cat /proc/sys/net/ipv4/tcp_syncookies also gives 1<br>
<br>
Isn't this sufficient to enable syncookies?<br>
<br>
Thanks and Regards<br>
Puneet<br>
----------------------------------------<br>
> To: <a href="mailto:puneet.agr@outlook.com">puneet.agr@outlook.com</a><br>
> CC: <a href="mailto:dave.jing.tian@gmail.com">dave.jing.tian@gmail.com</a>; <a href="mailto:me@sillymon.ch">me@sillymon.ch</a>; <a href="mailto:kernelnewbies@kernelnewbies.org">kernelnewbies@kernelnewbies.org</a><br>
> Subject: Re: lots of connections in SYN_RECV state<br>
> From: <a href="mailto:Valdis.Kletnieks@vt.edu">Valdis.Kletnieks@vt.edu</a><br>
> Date: Fri, 7 Nov 2014 13:10:05 -0500<br>
><br>
> On Fri, 07 Nov 2014 23:11:26 +0530, Puneet Agarwal said:<br>
><br>
>> I use linux kernel 2.6. I have enabled SYN cookies already. But that does not<br>
>> seem to solve the problem. Overall request latency is very high with these many<br>
>> half open connections.<br>
><br>
> So, out of curiosity, where are all these half open connections coming<br>
> from? Are they from addresses in your local network? Outside sites that<br>
> *should* be connecting? Places you've never heard and and probably *shouldn't*<br>
> be connecting?<br>
><br>
> (Also, if you have properly implemented syncookies, you shouldn't *have* any<br>
> half-open connections. That's the whole point of syncookies....)<br>
><br>
<br>
<br>
<br>
------------------------------<br>
<br>
_______________________________________________<br>
Kernelnewbies mailing list<br>
<a href="mailto:Kernelnewbies@kernelnewbies.org">Kernelnewbies@kernelnewbies.org</a><br>
<a href="http://lists.kernelnewbies.org/mailman/listinfo/kernelnewbies" target="_blank">http://lists.kernelnewbies.org/mailman/listinfo/kernelnewbies</a><br>
<br>
<br>
End of Kernelnewbies Digest, Vol 48, Issue 10<br>
*********************************************<br>
</blockquote></div><br></div>