Re: [PATCH net 1/2] net/tls: Fail tls_sw_splice_read() after a failed async decrypt

Sabrina Dubroca <[email protected]>
Newsgroups org.kernel.vger.netdev,org.kernel.vger.linux-kernel,org.kernel.vger.linux-kselftest
Message-ID <anr8PY66jUrIWcvJ@krikkit>
2026-08-06, 20:44:07 -0400, Chuck Lever wrote:
> When an async decrypt fails, tls_decrypt_done() records the error in
> ctx->async_wait.err and calls tls_err_abort(), which stores it in
> sk_err. tls_sw_recvmsg() and tls_sw_read_sock() each read
> async_wait.err once they hold the reader lock and fail the call: a
> record that did not authenticate breaks the connection.
> 
> tls_sw_splice_read() has no such check, and sk_err does not stand in
> for one. tls_rx_rec_wait() tests sk_err only inside the loop it
> skips whenever a record is already parsed, and the first reader to
> reach sock_error() clears it, while async_wait.err persists. A
> splice therefore keeps delivering records on a connection that
> recvmsg() and read_sock() refuse to read.
> 
> Read async_wait.err in tls_sw_splice_read() as the other two readers
> do.
> 
> Fixes: f314bfee81b1 ("tls: rx: return the already-copied data on crypto error")
> Reviewed-by: Jakub Kicinski <[email protected]>
> Signed-off-by: Chuck Lever <[email protected]>

Reviewed-by: Sabrina Dubroca <[email protected]>

-- 
Sabrina
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.