From: "Chuck Lever" <cel@kernel.org>
To: netdev-bot+sashiko@kernel.org
Cc: john.fastabend@gmail.com, kuba@kernel.org, sd@queasysnail.net,
davem@davemloft.net, pabeni@redhat.com, horms@kernel.org,
davejwatson@fb.com, shuah@kernel.org, qingfang.deng@linux.dev,
edumazet@kernel.org, netdev@vger.kernel.org,
linux-kselftest@vger.kernel.org
Subject: Re: [PATCH net-next v2 1/8] tls: bound consecutive no-data records in tls_sw_read_sock()
Date: Tue, 06 Oct 2026 11:44:22 -0400 [thread overview]
Message-ID: <8cb468b1-0eea-446e-8d22-fa67442f5749@slotpi15m67> (raw)
In-Reply-To: <179124254155.434549.7182507019185765398@kernel.org>
On Mon, Oct 05, 2026, netdev-bot+sashiko@kernel.org wrote:
> > + if (++nodata >= TLS_RX_NODATA_LIMIT) {
> > + /* tls_rx_reader_release() calls
> > + * saved_data_ready(), not the callback a
> > + * consumer installs after the handshake.
> > + */
> > + sk->sk_data_ready(sk);
>
> [Severity: High]
> Can this direct call to sk->sk_data_ready() re-enter tls_sw_read_sock()
> and deadlock on sk_lock.slock?
Yes. kcm_attach() accepts a TCP socket that already has TLS_RX set
up, and strp_data_ready() calls strp_read_sock() directly when the
socket is not owned by user. From softirq, the nested
tls_sw_read_sock() finds reader_present set, and sk_wait_event()
calls release_sock() before it looks at the zero timeout. I have
not reproduced the deadlock.
Making the call after tls_rx_reader_release() does not fix it. The
nested call then acquires the reader, consumes its own 16 empty
records, and recurses again, so the depth is set by the peer.
The notification has to leave the reader's call chain. I'll rework
it for v3.
> [Severity: Low]
> Should this be READ_ONCE(sk->sk_data_ready)(sk), as the TCP call sites
> use?
The direct call goes away with the rework above.
pw-bot: cr
--
Chuck Lever (Come to NFS bake-a-thon! https://nfsv4bat.org)
next prev parent reply other threads:[~2026-10-06 15:44 UTC|newest]
Thread overview: 24+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-01 22:41 [PATCH net-next v2 0/8] net/tls: Receive-path fixes for zero-length data records Chuck Lever
2026-10-01 22:41 ` [PATCH net-next v2 1/8] tls: bound consecutive no-data records in tls_sw_read_sock() Chuck Lever
2026-10-05 23:22 ` netdev-bot+sashiko
2026-10-06 15:44 ` Chuck Lever [this message]
2026-10-01 22:41 ` [PATCH net-next v2 2/8] tls: check for a pending signal after an empty record Chuck Lever
2026-10-05 23:22 ` netdev-bot+sashiko
2026-10-06 15:45 ` Chuck Lever
2026-10-01 22:41 ` [PATCH net-next v2 3/8] tls: consume empty data records in tls_sw_splice_read() Chuck Lever
2026-10-05 23:22 ` netdev-bot+sashiko
2026-10-06 15:45 ` Chuck Lever
2026-10-01 22:41 ` [PATCH net-next v2 4/8] tls: honor O_NONBLOCK " Chuck Lever
2026-10-05 23:22 ` netdev-bot+sashiko
2026-10-06 15:46 ` Chuck Lever
2026-10-01 22:41 ` [PATCH net-next v2 5/8] tls: consume empty data records in tls_sw_recvmsg() Chuck Lever
2026-10-05 23:22 ` netdev-bot+sashiko
2026-10-06 15:47 ` Chuck Lever
2026-10-01 22:41 ` [PATCH net-next v2 6/8] selftests: tls: add peek and splice coverage for zero-length records Chuck Lever
2026-10-05 23:22 ` netdev-bot+sashiko
2026-10-01 22:41 ` [PATCH net-next v2 7/8] selftests: tls: skip the zero_len tests when TLS is unavailable Chuck Lever
2026-10-05 23:22 ` netdev-bot+sashiko
2026-10-01 22:41 ` [PATCH net-next v2 8/8] selftests: tls: cover splice on a nonblocking socket Chuck Lever
2026-10-01 22:45 ` [PATCH net-next v2 0/8] net/tls: Receive-path fixes for zero-length data records netdev-bot+sinfo
2026-10-02 15:30 ` Chuck Lever
2026-10-04 6:36 ` Qingfang Deng
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=8cb468b1-0eea-446e-8d22-fa67442f5749@slotpi15m67 \
--to=cel@kernel.org \
--cc=davejwatson@fb.com \
--cc=davem@davemloft.net \
--cc=edumazet@kernel.org \
--cc=horms@kernel.org \
--cc=john.fastabend@gmail.com \
--cc=kuba@kernel.org \
--cc=linux-kselftest@vger.kernel.org \
--cc=netdev-bot+sashiko@kernel.org \
--cc=netdev@vger.kernel.org \
--cc=pabeni@redhat.com \
--cc=qingfang.deng@linux.dev \
--cc=sd@queasysnail.net \
--cc=shuah@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox