INVESTIGATION, UNVERIFIED: not a confirmed defect until the reference sequence is proven.
Hypothesis: the stack can be shut down with parked closing sockets still created in NetX.
| Link |
Where |
Status |
The drain gate is sb_StackRefs <= 1; the handoff flush subtracts sb_TransientStackRefs, this gate does not |
src/bsdsocket/socket.c:974; src/bsdsocket/library.c:1062-1063 |
read |
An async AddressAllocation takes a transient hold; its release can drop the count to 0 and call bsd_netstack_shutdown_owned without draining bsd_closing_head |
src/bsdsocket/addralloc.c:762; library.c:1143-1150 |
read |
nx_ip_delete returns NX_SOCKETS_BOUND without deleting the IP thread/timers; the status is discarded and ns (containing ns_Ip) is freed |
nx_ip_delete.c:107-115; src/netstack/netstack.c:213, :269-281 |
read |
| A real start/stop sequence ends on the transient release as the last reference |
|
NOT verified |
Candidate sequence: network up with the hold released; tool T starts an async DHCP AddressAllocation and closes its base; app A connects to a peer that stops answering after SYN, CloseSocket (FIN outstanding), CloseLibrary (close_all sees 2 references and skips the drain); T's job completes and the stack is torn down.
Next step: host test over bsd_close_all + bsd_stack_transient_release asserting bsd_closing_head == NULL before netstack_shutdown and that nx_ip_delete returned NX_SUCCESS.
🤖 Generated with Claude Code
INVESTIGATION, UNVERIFIED: not a confirmed defect until the reference sequence is proven.
Hypothesis: the stack can be shut down with parked closing sockets still created in NetX.
sb_StackRefs <= 1; the handoff flush subtractssb_TransientStackRefs, this gate does notsrc/bsdsocket/socket.c:974;src/bsdsocket/library.c:1062-1063bsd_netstack_shutdown_ownedwithout drainingbsd_closing_headsrc/bsdsocket/addralloc.c:762;library.c:1143-1150nx_ip_deletereturnsNX_SOCKETS_BOUNDwithout deleting the IP thread/timers; the status is discarded andns(containingns_Ip) is freednx_ip_delete.c:107-115;src/netstack/netstack.c:213,:269-281Candidate sequence: network up with the hold released; tool T starts an async DHCP AddressAllocation and closes its base; app A connects to a peer that stops answering after SYN,
CloseSocket(FIN outstanding),CloseLibrary(close_all sees 2 references and skips the drain); T's job completes and the stack is torn down.Next step: host test over
bsd_close_all+bsd_stack_transient_releaseassertingbsd_closing_head == NULLbeforenetstack_shutdownand thatnx_ip_deletereturnedNX_SUCCESS.🤖 Generated with Claude Code