mirror of
https://github.com/tailscale/tailscale.git
synced 2026-10-10 04:12:47 -04:00
Add --tcp-save-syn on Linux to record client MSS in a Prometheus histogram. Count retrieval outcomes separately and limit saved-SYN error logs to one per ten minutes across clients. IPv6 extension headers are unsupported. Estimate the network-namespace SYN rate from kernel counters once per second. Disable TCP_SAVE_SYN on listeners above 100,000/s or if rate measurement fails, leaving it off until restart. Updates tailscale/corp#49139 Signed-off-by: James Tucker <james@tailscale.com>
34 lines
719 B
Go
34 lines
719 B
Go
// Copyright (c) Tailscale Inc & contributors
|
|
// SPDX-License-Identifier: BSD-3-Clause
|
|
|
|
//go:build linux
|
|
|
|
package main
|
|
|
|
import (
|
|
"fmt"
|
|
"syscall"
|
|
|
|
"golang.org/x/sys/unix"
|
|
)
|
|
|
|
// controlTCPSaveSyn sets TCP_SAVE_SYN on a listening socket when --tcp-save-syn
|
|
// is enabled. Accepted connections inherit the option.
|
|
func controlTCPSaveSyn(network string, c syscall.RawConn) error {
|
|
if !*tcpSaveSyn {
|
|
return nil
|
|
}
|
|
switch network {
|
|
case "tcp", "tcp4", "tcp6":
|
|
default:
|
|
return fmt.Errorf("--tcp-save-syn: unsupported network: %s", network)
|
|
}
|
|
var err error
|
|
if e := c.Control(func(fd uintptr) {
|
|
err = unix.SetsockoptInt(int(fd), unix.IPPROTO_TCP, unix.TCP_SAVE_SYN, 1)
|
|
}); e != nil {
|
|
return e
|
|
}
|
|
return err
|
|
}
|