Netdev List
 help / color / mirror / Atom feed
* [PATCH 0/2] nvme,tls: minimal handling for TLS records
@ 2026-09-22 13:37 Hannes Reinecke
  2026-09-22 13:37 ` [PATCH 1/2] nvme-tcp: start error recovery when read_sock fails Hannes Reinecke
  2026-09-22 13:37 ` [PATCH 2/2] tls: return a distinct error for control records from read_sock Hannes Reinecke
  0 siblings, 2 replies; 4+ messages in thread
From: Hannes Reinecke @ 2026-09-22 13:37 UTC (permalink / raw)
  To: Christoph Hellwig
  Cc: Keith Busch, Sagi Grimberg, linux-nvme, Jakub Kicinski,
	Sabrina Dubroca, netdev, Hannes Reinecke

Hi all,

TLS 1.3 can send additional TLS records while the connection is established,
and typically one would evaluate these records with passing in a control message
buffer for recvmsg(). But nvme-tcp is using the read_sock() interface which
does not allow for handling of control messages.
So as the lazy way out I opted for resetting the queue on any non-data TLS records
as this would be the default action anyway for most non-data TLS records.
But turns out that this does not work as planned, as the TLS records are evaluated
(and errors generated) before ->read_sock() is called, so nvme-tcp would receive
the error but not start error recovery.

This patchset is the minimal fix to handle it, start error recovery when a non-data
TLS record is received and also return a distinct error code from tls to indicate
the situation.

The 'real' fix will of course involve actually reading the control message and take
action based on the type, but that is a rather involved operation which will be addressed
later. So for now this simple fix should be sufficient.

Martin Belanger (2):
  nvme-tcp: start error recovery when read_sock fails
  tls: return a distinct error for control records from read_sock

 drivers/nvme/host/tcp.c | 18 +++++++++++++++++-
 net/tls/tls_sw.c        |  4 ++--
 2 files changed, 19 insertions(+), 3 deletions(-)

-- 
2.51.0


^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2026-09-23  0:56 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-22 13:37 [PATCH 0/2] nvme,tls: minimal handling for TLS records Hannes Reinecke
2026-09-22 13:37 ` [PATCH 1/2] nvme-tcp: start error recovery when read_sock fails Hannes Reinecke
2026-09-22 13:37 ` [PATCH 2/2] tls: return a distinct error for control records from read_sock Hannes Reinecke
2026-09-23  0:56   ` Jakub Kicinski

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox