Skip to content

Investigation: stack teardown with parked closing sockets (unverified) #53

Description

@tinic

INVESTIGATION, UNVERIFIED: not a confirmed defect until the reference sequence is proven.

Hypothesis: the stack can be shut down with parked closing sockets still created in NetX.

Link Where Status
The drain gate is sb_StackRefs <= 1; the handoff flush subtracts sb_TransientStackRefs, this gate does not src/bsdsocket/socket.c:974; src/bsdsocket/library.c:1062-1063 read
An async AddressAllocation takes a transient hold; its release can drop the count to 0 and call bsd_netstack_shutdown_owned without draining bsd_closing_head src/bsdsocket/addralloc.c:762; library.c:1143-1150 read
nx_ip_delete returns NX_SOCKETS_BOUND without deleting the IP thread/timers; the status is discarded and ns (containing ns_Ip) is freed nx_ip_delete.c:107-115; src/netstack/netstack.c:213, :269-281 read
A real start/stop sequence ends on the transient release as the last reference NOT verified

Candidate sequence: network up with the hold released; tool T starts an async DHCP AddressAllocation and closes its base; app A connects to a peer that stops answering after SYN, CloseSocket (FIN outstanding), CloseLibrary (close_all sees 2 references and skips the drain); T's job completes and the stack is torn down.

Next step: host test over bsd_close_all + bsd_stack_transient_release asserting bsd_closing_head == NULL before netstack_shutdown and that nx_ip_delete returned NX_SUCCESS.

🤖 Generated with Claude Code

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions