From: Rishikesh Jethwani <rjethwani@purestorage.com>
To: netdev@vger.kernel.org
Cc: saeedm@nvidia.com, tariqt@nvidia.com, mbloch@nvidia.com,
borisp@nvidia.com, john.fastabend@gmail.com, kuba@kernel.org,
sd@queasysnail.net, davem@davemloft.net, pabeni@redhat.com,
edumazet@google.com, leon@kernel.org,
andrew.gospodarek@broadcom.com,
Rishikesh Jethwani <rjethwani@purestorage.com>
Subject: [PATCH net-next v17 03/15] tls: reject rekey attempts on an existing HW-offloaded connection
Date: Thu, 17 Sep 2026 16:35:14 -0600 [thread overview]
Message-ID: <20260917224355.2288021-4-rjethwani@purestorage.com> (raw)
In-Reply-To: <20260917224355.2288021-1-rjethwani@purestorage.com>
On a TLS 1.3 rekey, do_tls_setsockopt_conf() must not set up a brand-new
device offload: reject the rekey with -EOPNOTSUPP for a HW-offloaded
connection (HW KeyUpdate is not supported yet, and we must not fall back
to software mid-connection), and for a SW-offloaded one re-init the
software crypto state via tls_set_sw_offload() directly.
Do this by moving the reject into the device-offload helpers and shaping
the dispatch in its final form:
- tls_set_device_offload() and tls_set_device_offload_rx() reject any
non-initial call (tx_conf / rx_conf != TLS_BASE) with -EOPNOTSUPP.
- do_tls_setsockopt_conf() always calls the device helper and, on
failure, either propagates the error (rekey on a HW connection) or
falls back to tls_set_sw_offload() (initial install, or rekey on a
SW connection).
Prep for the following patches: "tls: add TLS 1.3 hardware offload
support" drops the TLS_1_2_VERSION guards in those helpers (which today
also happen to reject a TLS 1.3 rekey), and the KeyUpdate patches replace
the reject guards above with real rekey handling in the helpers, leaving
the do_tls_setsockopt_conf() dispatch unchanged.
Signed-off-by: Rishikesh Jethwani <rjethwani@purestorage.com>
---
net/tls/tls_device.c | 18 ++++++++++++++++++
net/tls/tls_main.c | 22 ++++++++++++++++++----
2 files changed, 36 insertions(+), 4 deletions(-)
diff --git a/net/tls/tls_device.c b/net/tls/tls_device.c
index f11d0528fc43..f5e1b6b61ce3 100644
--- a/net/tls/tls_device.c
+++ b/net/tls/tls_device.c
@@ -1077,6 +1077,15 @@ int tls_set_device_offload(struct sock *sk)
ctx = tls_get_ctx(sk);
prot = &ctx->prot_info;
+ /* A rekey (setsockopt on an already-configured socket) is not
+ * supported on the device offload path yet; reject it here so the
+ * caller can decide (propagate the error for a HW connection, or
+ * re-init software crypto for a SW one). KeyUpdate support replaces
+ * this guard with real rekey handling.
+ */
+ if (ctx->tx_conf != TLS_BASE)
+ return -EOPNOTSUPP;
+
if (ctx->priv_ctx_tx)
return -EEXIST;
@@ -1202,6 +1211,15 @@ int tls_set_device_offload_rx(struct sock *sk, struct tls_context *ctx)
if (ctx->crypto_recv.info.version != TLS_1_2_VERSION)
return -EOPNOTSUPP;
+ /* A rekey (setsockopt on an already-configured socket) is not
+ * supported on the device offload path yet; reject it here so the
+ * caller can decide (propagate the error for a HW connection, or
+ * re-init software crypto for a SW one). KeyUpdate support replaces
+ * this guard with real rekey handling.
+ */
+ if (ctx->rx_conf != TLS_BASE)
+ return -EOPNOTSUPP;
+
netdev = get_netdev_for_sock(sk);
if (!netdev) {
pr_err_ratelimited("%s: netdev not found\n", __func__);
diff --git a/net/tls/tls_main.c b/net/tls/tls_main.c
index fbb274287aa5..15e83e853f22 100644
--- a/net/tls/tls_main.c
+++ b/net/tls/tls_main.c
@@ -713,8 +713,15 @@ static int do_tls_setsockopt_conf(struct sock *sk, sockptr_t optval,
rc = tls_set_device_offload(sk);
conf = TLS_HW;
if (!rc) {
- TLS_INC_STATS(sock_net(sk), LINUX_MIB_TLSTXDEVICE);
- TLS_INC_STATS(sock_net(sk), LINUX_MIB_TLSCURRTXDEVICE);
+ if (!update) {
+ TLS_INC_STATS(sock_net(sk), LINUX_MIB_TLSTXDEVICE);
+ TLS_INC_STATS(sock_net(sk), LINUX_MIB_TLSCURRTXDEVICE);
+ }
+ } else if (update && ctx->tx_conf == TLS_HW) {
+ /* HW rekey failed - return the actual error.
+ * Cannot fall back to SW for an existing HW connection.
+ */
+ goto err_crypto_info;
} else {
rc = tls_set_sw_offload(sk, 1,
update ? crypto_info : NULL);
@@ -733,8 +740,15 @@ static int do_tls_setsockopt_conf(struct sock *sk, sockptr_t optval,
rc = tls_set_device_offload_rx(sk, ctx);
conf = TLS_HW;
if (!rc) {
- TLS_INC_STATS(sock_net(sk), LINUX_MIB_TLSRXDEVICE);
- TLS_INC_STATS(sock_net(sk), LINUX_MIB_TLSCURRRXDEVICE);
+ if (!update) {
+ TLS_INC_STATS(sock_net(sk), LINUX_MIB_TLSRXDEVICE);
+ TLS_INC_STATS(sock_net(sk), LINUX_MIB_TLSCURRRXDEVICE);
+ }
+ } else if (update && ctx->rx_conf == TLS_HW) {
+ /* HW rekey failed - return the actual error.
+ * Cannot fall back to SW for an existing HW connection.
+ */
+ goto err_crypto_info;
} else {
rc = tls_set_sw_offload(sk, 0,
update ? crypto_info : NULL);
--
2.50.1
next prev parent reply other threads:[~2026-09-17 22:45 UTC|newest]
Thread overview: 29+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-17 22:35 [PATCH net-next v17 00/15] tls: Add TLS 1.3 hardware offload support Rishikesh Jethwani
2026-09-17 22:35 ` [PATCH net-next v17 01/15] net: tls: reject TLS 1.3 offload in chcr_ktls and nfp drivers Rishikesh Jethwani
2026-09-22 1:55 ` netdev-bot+sashiko
2026-09-17 22:35 ` [PATCH net-next v17 02/15] net/mlx5e: add TLS 1.3 hardware offload support Rishikesh Jethwani
2026-09-22 1:55 ` netdev-bot+sashiko
2026-09-17 22:35 ` Rishikesh Jethwani [this message]
2026-09-17 22:35 ` [PATCH net-next v17 04/15] tls: " Rishikesh Jethwani
2026-09-22 1:56 ` netdev-bot+sashiko
2026-09-17 22:35 ` [PATCH net-next v17 05/15] tls: split tls_set_sw_offload into init and finalize stages Rishikesh Jethwani
2026-09-17 22:35 ` [PATCH net-next v17 06/15] tls: prep helpers and refactors for HW offload KeyUpdate Rishikesh Jethwani
2026-09-22 1:56 ` netdev-bot+sashiko
2026-09-17 22:35 ` [PATCH net-next v17 07/15] net: sched: re-validate parked decrypted skbs on requeue Rishikesh Jethwani
2026-09-22 1:56 ` netdev-bot+sashiko
2026-09-17 22:35 ` [PATCH net-next v17 08/15] tcp: fence collapse against rtx-queue tail when write queue is empty Rishikesh Jethwani
2026-09-22 1:56 ` netdev-bot+sashiko
2026-09-17 22:35 ` [PATCH net-next v17 09/15] net: skbuff: add skb->decrypt_failed bit Rishikesh Jethwani
2026-09-22 1:56 ` netdev-bot+sashiko
2026-09-17 22:35 ` [PATCH net-next v17 10/15] net/mlx5e: flag TLS RX records that failed device decryption Rishikesh Jethwani
2026-09-22 1:56 ` netdev-bot+sashiko
2026-09-17 22:35 ` [PATCH net-next v17 11/15] tls: device: add TX KeyUpdate support Rishikesh Jethwani
2026-09-22 1:56 ` netdev-bot+sashiko
2026-09-17 22:35 ` [PATCH net-next v17 12/15] tls: device: add RX " Rishikesh Jethwani
2026-09-22 1:56 ` netdev-bot+sashiko
2026-09-17 22:35 ` [PATCH net-next v17 13/15] tls: device: add tracepoints for the KeyUpdate path Rishikesh Jethwani
2026-09-22 1:56 ` netdev-bot+sashiko
2026-09-17 22:35 ` [PATCH net-next v17 14/15] selftests: net: add TLS hardware offload test Rishikesh Jethwani
2026-09-22 1:56 ` netdev-bot+sashiko
2026-09-17 22:35 ` [PATCH net-next v17 15/15] tls: document TLS 1.3 hardware offload rekey handling Rishikesh Jethwani
2026-09-22 1:56 ` netdev-bot+sashiko
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260917224355.2288021-4-rjethwani@purestorage.com \
--to=rjethwani@purestorage.com \
--cc=andrew.gospodarek@broadcom.com \
--cc=borisp@nvidia.com \
--cc=davem@davemloft.net \
--cc=edumazet@google.com \
--cc=john.fastabend@gmail.com \
--cc=kuba@kernel.org \
--cc=leon@kernel.org \
--cc=mbloch@nvidia.com \
--cc=netdev@vger.kernel.org \
--cc=pabeni@redhat.com \
--cc=saeedm@nvidia.com \
--cc=sd@queasysnail.net \
--cc=tariqt@nvidia.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox