All of lore.kernel.org
 help / color / mirror / Atom feed
* [PATCH net 0/9] net/tls: Receive-path fixes for zero-length data records
@ 2026-07-27  0:33 Chuck Lever
  2026-07-27  0:33 ` [PATCH net 1/9] net/tls: Bound time spent on no-data records in tls_sw_read_sock() Chuck Lever
                   ` (9 more replies)
  0 siblings, 10 replies; 29+ messages in thread
From: Chuck Lever @ 2026-07-27  0:33 UTC (permalink / raw)
  To: John Fastabend, Jakub Kicinski, Sabrina Dubroca, David S. Miller,
	Eric Dumazet, Paolo Abeni, Simon Horman, Chuck Lever, Dave Watson,
	Shuah Khan
  Cc: netdev, linux-kselftest

Commit 3be28e2c9cd0 ("net/tls: Consume empty data records in
tls_sw_read_sock()") fixed one reader. TLS 1.2 and TLS 1.3 both
permit a zero-length application_data record as a traffic-analysis
countermeasure (RFC 5246, Section 6.2.1; RFC 8446, Section 5.1), so
a peer that pads its stream emits them by design. The other two
software readers still mishandle one. splice(2) reports the empty
record as EOF and the caller tears down a connection that is still
live. recvmsg(2) neither advances nor returns, so a peer that
streams such records holds the caller in the kernel past SIGKILL
while rx_list grows without bound.

Which fix a reader gets depends on where it returns to. splice and
recvmsg return to userspace and drop the socket lock, so consuming
the record and testing signal_pending() is enough. read_sock runs
from kernel context and holds the lock across the whole call, so it
needs the return boundary a system call would otherwise supply: a
deadline armed by the first record that delivers no bytes and
disarmed by the first that delivers some (patch 1). Scoping that
cap to read_sock alone is deliberate, since a flood on the other
two paths costs the caller only its own scheduler time.

Two user-visible changes follow, both toward what a plain TCP
socket already does. splice(2) on a nonblocking socket, and
sendfile(2) from one, now return -EAGAIN where they used to block.
A splice that reaches a control record behind an empty one now
returns -EINVAL rather than the zero that was the false EOF.

No existing selftest variant reads a zero-length record back any
way but recv(2), so neither the splice path nor MSG_PEEK was
exercised against a record that decrypts to no payload. New
variants cover both.

---
Chuck Lever (9):
      net/tls: Bound time spent on no-data records in tls_sw_read_sock()
      net/tls: Consume empty data records in tls_sw_splice_read()
      net/tls: Fail tls_sw_splice_read() after a failed async decrypt
      net/tls: Honor O_NONBLOCK in tls_sw_splice_read()
      net/tls: Consume empty data records in tls_sw_recvmsg()
      selftests: tls: add peek and splice coverage for zero-length records
      selftests: tls: skip the zero_len tests when TLS is unavailable
      selftests: tls: cover splice on a nonblocking socket
      selftests: tls: cover splice after a failed decrypt

 net/tls/tls_sw.c                  | 113 +++++++++++--
 tools/testing/selftests/net/tls.c | 322 ++++++++++++++++++++++++++++++++++++--
 2 files changed, 414 insertions(+), 21 deletions(-)
---
base-commit: 53658c6f3682967a5e76ed4bc7462c4bdcddaec3
change-id: 20260726-tls-follow-on-486f1ba8bbb0

Best regards,
--  
Chuck Lever <cel@kernel.org>


^ permalink raw reply	[flat|nested] 29+ messages in thread

end of thread, other threads:[~2026-08-07  0:21 UTC | newest]

Thread overview: 29+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-07-27  0:33 [PATCH net 0/9] net/tls: Receive-path fixes for zero-length data records Chuck Lever
2026-07-27  0:33 ` [PATCH net 1/9] net/tls: Bound time spent on no-data records in tls_sw_read_sock() Chuck Lever
2026-07-30  9:12   ` Sabrina Dubroca
2026-07-30 13:05     ` Chuck Lever
2026-07-30 17:21       ` Sabrina Dubroca
2026-08-07  0:17         ` Chuck Lever
2026-08-03 22:39   ` Jakub Kicinski
2026-08-04  0:35     ` Chuck Lever
2026-08-04  1:19       ` Jakub Kicinski
2026-07-27  0:33 ` [PATCH net 2/9] net/tls: Consume empty data records in tls_sw_splice_read() Chuck Lever
2026-07-30 10:38   ` Sabrina Dubroca
2026-08-07  0:19     ` Chuck Lever
2026-07-27  0:33 ` [PATCH net 3/9] net/tls: Fail tls_sw_splice_read() after a failed async decrypt Chuck Lever
2026-08-03 22:59   ` Jakub Kicinski
2026-07-27  0:33 ` [PATCH net 4/9] net/tls: Honor O_NONBLOCK in tls_sw_splice_read() Chuck Lever
2026-07-30 10:59   ` Sabrina Dubroca
2026-08-07  0:19     ` Chuck Lever
2026-07-27  0:33 ` [PATCH net 5/9] net/tls: Consume empty data records in tls_sw_recvmsg() Chuck Lever
2026-07-30 12:40   ` Sabrina Dubroca
2026-08-07  0:21     ` Chuck Lever
2026-08-03 22:47   ` Jakub Kicinski
2026-08-07  0:20     ` Chuck Lever
2026-07-27  0:33 ` [PATCH net 6/9] selftests: tls: add peek and splice coverage for zero-length records Chuck Lever
2026-07-27 14:07   ` Sabrina Dubroca
2026-07-27  0:33 ` [PATCH net 7/9] selftests: tls: skip the zero_len tests when TLS is unavailable Chuck Lever
2026-07-27  0:33 ` [PATCH net 8/9] selftests: tls: cover splice on a nonblocking socket Chuck Lever
2026-07-27  0:33 ` [PATCH net 9/9] selftests: tls: cover splice after a failed decrypt Chuck Lever
2026-07-27 15:19   ` Sabrina Dubroca
2026-08-03 22:58 ` [PATCH net 0/9] net/tls: Receive-path fixes for zero-length data records Jakub Kicinski

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.