Thread (3 messages) flat view 3 messages, 1 author, 5h ago
HOTtoday

[PATCH net 0/2] net/tls: Fail splice after a failed async decrypt

From: Chuck Lever <cel@kernel.org>
Date: 2026-08-07 00:44:18
Also in: linux-kselftest, lkml

tls_sw_recvmsg() and tls_sw_read_sock() both read ctx->async_wait.err
once they hold the reader lock, so a record that failed
authentication fails the call. tls_sw_splice_read() has no such
check. sk_err does not stand in for one. The first reader to reach
sock_error() clears sk_err, while async_wait.err persists. A splice
therefore keeps delivering records on a connection the other two
readers have already refused.

Both patches come from a receive-path series for zero-length data
records. Jakub asked for them separately, since the rest of that
series is still under discussion.

Link to the original series:
https://patch.msgid.link/20260726-tls-follow-on-v1-0-99bf4cc1c729@kernel.org

---
Chuck Lever (2):
      net/tls: Fail tls_sw_splice_read() after a failed async decrypt
      selftests: tls: cover splice after a failed decrypt

 net/tls/tls_sw.c                  |  5 +++
 tools/testing/selftests/net/tls.c | 75 +++++++++++++++++++++++++++++++++------
 2 files changed, 70 insertions(+), 10 deletions(-)
---
base-commit: 594d905195024b228c962627ae5ae7c17bd582a4
change-id: 20260806-tls-splice-crypto-fix-2a6de3cc0224

Best regards,
--  
Chuck Lever [off-list ref]
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help