From nobody Mon Sep 28 11:38:56 2026 Received: from mail-pl1-f177.google.com (mail-pl1-f177.google.com [209.85.214.177]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id A323633B975 for ; Sat, 22 Aug 2026 00:00:30 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.214.177 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787356832; cv=none; b=L19Dhe9JfNBwy+aPa6qQsCrttODp+nFMv/itgkK+lnjFwoL9976HEZ/TkKrNl8ojQCQAZxtGnxLVjT612J15Pkl35MoCmSb0oz9ggHV4/iXdpzU2e385teM5CXwXx0CimnNZwFk5cMbpFzjYt0u9A3qeqQdirDyiY965UTdQwzc= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787356832; c=relaxed/simple; bh=SfaQPqYZ2TcCPfNmTQhPxeigT6af4F+W9zbI3dBjBSM=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=GwBIkl5N9G79hR5tQ9yPyeGFzhhe+fJQZMBSXtZHb3hbGkSJB/AFFI9n9D38t0MTI9nM9hD/becDDK5m03PeqSUi6reyJ5q7VxAO6MUnHpHGFxRAW37Sh1Fvb8wKjm5i/LeFLCFy4nFA6hn2pF0kgObwP+HIiAfjDMA78RSIhBE= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=trailofbits.com; spf=pass smtp.mailfrom=trailofbits.com; dkim=pass (2048-bit key) header.d=trailofbits.com header.i=@trailofbits.com header.b=Zi/dsn3Z; arc=none smtp.client-ip=209.85.214.177 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=trailofbits.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=trailofbits.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=trailofbits.com header.i=@trailofbits.com header.b="Zi/dsn3Z" Received: by mail-pl1-f177.google.com with SMTP id d9443c01a7336-2d560775ca2so13536715ad.1 for ; Fri, 21 Aug 2026 17:00:30 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=trailofbits.com; s=google; t=1787356830; x=1787961630; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=3i9zm7U75qqZoEzuNvaSawAYL3AG1P0lNOfzOpKLfms=; b=Zi/dsn3ZOx0Fhrbw5BGKq5vDhggieae1XtEW88b6WZ6Wigplck3W8wpW/FEtkOArGb uw48HDPcST2fQMY9PWA71BGPA8tN9CPobvsJHcx9dZn6zRGE4BGgFX1VC0yQawNoqETF uYXnJ7GlBUD62rVOzouMIQsYCuFZ5Ht2Gx/Y4Sh4canjy+2nYt3QMXjxHVpOJFW06Rha wwOboRoNiMUVvrmKMZc//nnqCEXJDt8abC+QeUszmfFfhLOT3bXqqpCkH2Rx/SLM4rGm 2+wGMjGYLkyGyG6Xhc0urOJHImCWWiFjbjb4YZw+OrC6fSo04IqYXX5Ljbwb9umXlCeA WZWA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787356830; x=1787961630; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=3i9zm7U75qqZoEzuNvaSawAYL3AG1P0lNOfzOpKLfms=; b=NI90dbsBXF7GeLybfdwgUjqHQAr/qWhlH8BMgNyQ71HuUrD1dHzFlyz34Mnpcd5uJt LPdtULFw7uTMbjTogENIiKQLo1xUMDd9YZJnnw7pKZ3e2/MSyEcJK04t4O71Ro2zsCjd wJ6U+zeYb5/Cx6rOQeiyRIPMImU96YIFZ9gimDZM55IWxOrouHE0CyrxQmc6WHNMKYf6 Zw0AdtBOiJ39GFeiWeRTOoAr4lV3kv5bq55A0jbUDp4XBQ+KUVBeqCXAPN3agc+CZ3NL Yy3y7nX+/J1b6Rm+XLSZ0t/Sa4oM7E8ruZvbqHxorEQI55SJjVj5fm4TmMDDJnQoxY0k mGlg== X-Forwarded-Encrypted: i=1; AHgh+Rpj/V2VQqxu1yNnVWzrUnvEcvuqbUriJQ306OlVRKOqldUTZW0bRgPZ1AGSXeQULh2q2eJ0ZtxraDLlkBI=@vger.kernel.org X-Gm-Message-State: AFuF++l2M02DoK7fJEszaLhEnxIRUZKu8MfU0HMXkaUbB4srL/NNHON6 PV4L3ps99tZCspInOP5nh7tGr3MJNn6w2ap3X2wAvD8WvsykQvncRZJM+2xWBnYV9/Y= X-Gm-Gg: AR+sD13gi939LdKGdT1hn9rIeu8n6BK7e48FwQSlo8j/Vsz1hpotOJAbJpega4Y5+GJ +DsBlXw8B3+aaDbLrvpo/V+RT3osaPDaddFzspKtcmgfKp1txDW6glp1/QIwK11VUpl9jJN6Jds Xf7m1wSvIZNK0rgngb5KKCWQalRGWkk6L0KKCPHPJVOqVhw+vCfoE2ujGrx129v+O5kCTxsVK1t B0FbvzvX9KFNq3Nz2vDS7V2ezCyrkcIcK14XqTaXCWoSBhYdcE5b1FK8ijnCzUBVCjCWvbJ4oxs 4dEBAxlO5J6Ybhv9K4GstMOLI0GsrvjOQFgZz8P0cnWB1r7/eX3/imbDV9UmLrYEOhWEI2+a9Cx S12JGci3rMsj+B0Wvzw3BbrHBg7GQ0Go5QPxWooKqqdBCalFoRjXCgY02hHTeKJY1mhu0ssuiTp hRSE/QLqqyL9x+9BnWfhN141X9TdNGiayE2fozb0uCzwEXP/c9ltV0fk8oMXBPIgXGylg12/dth aO4W7BX5NyJCdhoDRs0Zq7V75q9s8KTVub4y5Iw9K+tfGprcN61kWK7zI3I2Q== X-Received: by 2002:a17:90b:39ab:b0:393:19a3:4e5 with SMTP id 98e67ed59e1d1-395df686f1dmr3705527a91.16.1787356829643; Fri, 21 Aug 2026 17:00:29 -0700 (PDT) Received: from localhost.localdomain ([2603:8001:5f01:8bab:fc5e:9d66:f144:bfe9]) by smtp.gmail.com with ESMTPSA id a92af1059eb24-141861732f8sm1743425c88.10.2026.08.21.17.00.27 (version=TLS1_3 cipher=TLS_CHACHA20_POLY1305_SHA256 bits=256/256); Fri, 21 Aug 2026 17:00:27 -0700 (PDT) From: Artem Dinaburg To: stable@vger.kernel.org Cc: Sabrina Dubroca , Jakub Kicinski , Eric Dumazet , William Liu , Savino Dicanosa , Boris Pismenny , John Fastabend , linux-kernel@vger.kernel.org, Artem Dinaburg Subject: [PATCH 6.1.y 1/2] tls: fix lockless read of strp->msg_ready in ->poll Date: Fri, 21 Aug 2026 20:00:17 -0400 Message-ID: <20260822000018.48130-2-artem@trailofbits.com> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260822000018.48130-1-artem@trailofbits.com> References: <20260822000018.48130-1-artem@trailofbits.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" From: Sabrina Dubroca [ Upstream commit 0844370f8945086eb9335739d10205dcea8d707b ] tls_sk_poll is called without locking the socket, and needs to read strp->msg_ready (via tls_strp_msg_ready). Convert msg_ready to a bool and use READ_ONCE/WRITE_ONCE where needed. The remaining reads are only performed when the socket is locked. Fixes: 121dca784fc0 ("tls: suppress wakeups unless we have a full record") Signed-off-by: Sabrina Dubroca Link: https://lore.kernel.org/r/0b7ee062319037cf86af6b317b3d72f7bfcd2e97.17= 13797701.git.sd@queasysnail.net Signed-off-by: Jakub Kicinski Assisted-by: Codex:GPT-5 Signed-off-by: Artem Dinaburg --- Prerequisite for 2/2, applied verbatim with no source adaptation. This also fixes a real lockless read of msg_ready in ->poll that 6.1.y has on its own. include/net/tls.h | 3 ++- net/tls/tls.h | 2 +- net/tls/tls_strp.c | 6 +++--- 3 files changed, 6 insertions(+), 5 deletions(-) diff --git a/include/net/tls.h b/include/net/tls.h index 037049def..b5856a280 100644 --- a/include/net/tls.h +++ b/include/net/tls.h @@ -122,7 +122,8 @@ struct tls_strparser { u32 stopped : 1; u32 copy_mode : 1; u32 mixed_decrypted : 1; - u32 msg_ready : 1; + + bool msg_ready; =20 struct strp_msg stm; =20 diff --git a/net/tls/tls.h b/net/tls/tls.h index 8304afbe0..9fd5867a3 100644 --- a/net/tls/tls.h +++ b/net/tls/tls.h @@ -167,7 +167,7 @@ static inline struct sk_buff *tls_strp_msg(struct tls_s= w_context_rx *ctx) =20 static inline bool tls_strp_msg_ready(struct tls_sw_context_rx *ctx) { - return ctx->strp.msg_ready; + return READ_ONCE(ctx->strp.msg_ready); } =20 static inline bool tls_strp_msg_mixed_decrypted(struct tls_sw_context_rx *= ctx) diff --git a/net/tls/tls_strp.c b/net/tls/tls_strp.c index 850146ed2..32b57e574 100644 --- a/net/tls/tls_strp.c +++ b/net/tls/tls_strp.c @@ -366,7 +366,7 @@ static int tls_strp_copyin(read_descriptor_t *desc, str= uct sk_buff *in_skb, if (strp->stm.full_len && strp->stm.full_len =3D=3D skb->len) { desc->count =3D 0; =20 - strp->msg_ready =3D 1; + WRITE_ONCE(strp->msg_ready, 1); tls_rx_msg_ready(strp); } =20 @@ -533,7 +533,7 @@ static int tls_strp_read_sock(struct tls_strparser *str= p) if (!tls_strp_check_queue_ok(strp)) return tls_strp_read_copy(strp, false); =20 - strp->msg_ready =3D 1; + WRITE_ONCE(strp->msg_ready, 1); tls_rx_msg_ready(strp); =20 return 0; @@ -585,7 +585,7 @@ void tls_strp_msg_done(struct tls_strparser *strp) else tls_strp_flush_anchor_copy(strp); =20 - strp->msg_ready =3D 0; + WRITE_ONCE(strp->msg_ready, 0); memset(&strp->stm, 0, sizeof(strp->stm)); =20 tls_strp_check_rcv(strp); --=20 2.43.0 From nobody Mon Sep 28 11:38:56 2026 Received: from mail-pf1-f178.google.com (mail-pf1-f178.google.com [209.85.210.178]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id EF38B2931CE for ; Sat, 22 Aug 2026 00:00:33 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.210.178 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787356835; cv=none; b=FbBJ+9JZl+6p5EEx7gXCVGLXItEU9Wfc/TypgPMIHimM5xQDu6FxTWLqhow3bCJv0K+W78eXMJZjL5bVlkPXEN3Ibw6aVv9sAHGKK+tNp5BkbjigqpUS7375mVqiBNyyBFMygP27WTeF/TpvGqaeDsoq/Dn7T2kSoA4t6vvn15g= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787356835; c=relaxed/simple; bh=HJtc1kLXDLCMyh9y6Vm3Q++TQQesy6nrVmn55E/n5d8=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=YgMgDQ/m2MdUvo9Jv9JZ1Hzfqnx+MtfEK6N9yQ+02fO5SvmrpipApdxXuTmFAeXSMN0VqGgJkN0vxKd2gQuwbv0UBuoxuXffsGeJ/dlbNoAvWSiAkpOnSlavRWHWkI1phYvXUyDfunj+F6qirz6tMMHcs+hKKM4ZZp2k3J1OO2w= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=trailofbits.com; spf=pass smtp.mailfrom=trailofbits.com; dkim=pass (2048-bit key) header.d=trailofbits.com header.i=@trailofbits.com header.b=ZdzeUSiL; arc=none smtp.client-ip=209.85.210.178 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=trailofbits.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=trailofbits.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=trailofbits.com header.i=@trailofbits.com header.b="ZdzeUSiL" Received: by mail-pf1-f178.google.com with SMTP id d2e1a72fcca58-84830c774a0so1762846b3a.1 for ; Fri, 21 Aug 2026 17:00:33 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=trailofbits.com; s=google; t=1787356833; x=1787961633; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=zYgQHC2sj0tGkOYbvf91tzomhlBCh6E8FBNBbNM2y4M=; b=ZdzeUSiLJBhGiu3dZ4Rb7YKY+H21bY59RIf3hn+stibkeIeKvEOn5aKh2FPIzoxdTc RBnstDNxvBXrjFD3KNx6Zk7YVtuFJtIgo9VrIaecVpglto+xBqlOmsazoOD5RFqea37M Cjy0dN5Mfln3/OeXHYSqnbiHxcuVjWqMhurevsWbrGa0j2kC3ZkZxY0P8YHqQj6yzgp8 aXkIcz0n/VTB3r4q2WUh7xZuLmH+UHgUfx+l5cP+0V+Kkwn0PPlKvdCacLIyPejoAy2k RFnFgGsdKeC/1OyFm3H7+M+NT+N//RaBYB/hEcCmSpDQLsjauQm5F4E4LUsVLKPPqW3d 7vAQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787356833; x=1787961633; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=zYgQHC2sj0tGkOYbvf91tzomhlBCh6E8FBNBbNM2y4M=; b=oQ3mPvW/CW3S9mFAj4bcG8ie9LkC0j1orS7fEvQlRq5D5Q31cWu1JFfe94ofkhziw+ s5iaNo8UdmWOEQ+dyoV/whSowS1uHHEPgCIQagWOSRZYnbTw1VbD5WWsKOVgyi/UVpbg 5sKwrVtLFBYZWmzDpVuQ5XJ4VG+fW5jfwcXwPNYRFwMfsDB7tf2tP8m3GoCXfKDQkZGY JOEUKZU3k2oIAGBCHvGCQlte1s4yJR+VLB5nZdM4ddZ5mgedBNHZCGPfJ4dGwgDfT8Lf 72XdV1IcfuqD9OPO7a2irOpEwfIXCmEdSvP6qV62cBMXkHl38Ex2XrHSDyiaa6AxZe8T 5AtQ== X-Forwarded-Encrypted: i=1; AHgh+RqeSdIxAs/GpJ+PL86tQbQbWZOYf3Gl0p8JaPBVda8fbzkuBfZvcrK89f0iNSL4Mj/Q5iiVvnh4n8M4kcE=@vger.kernel.org X-Gm-Message-State: AFuF++m8bFGrxAw9FJnqLCAL4OO4d34KKjP8HeJrhaIHRs2ZR8u02WWh G+39FyUtWh1BBz7QvL6eonJLX2D7o7tL8TwWmDRVpufRV/frjTOXhgZJ/lrHyls7RgI= X-Gm-Gg: AR+sD12ODtskvd8YQeVHmCK6j1J20AH6Fa9I4xCsc7jPK7X+B5QPaJdtdkQtc1qVsaz 7hRgevrj35io3hZcZbg4MoLzrBgZUVAgD9ziFzKbKnia6d5NEO9xfIkmHo82b/Z9MCPhUNSLrBC RHLCmbVc+wYKonS1i5ONBKrdBjjo30AKui/ywNMTZjijRKX4ohW7zmlwEAtx5M6ZcFHjf/Vr2sb aoHKaLLAKUabG0Dmba/xq5TivuGxj7sHkjMfRVsp3Eqp8VwCYrNWoP1ECrXxI6cIoV4NDD3I3fC K694K2UZ2NmObTCyaqdz7JmaZ7r9Fe5t9+mciMAxzpLMc3mNEAy+4YB3fH75O0vg5aX3YMm11Ao fI0JiG5yHHfYwjtNo9ub/XoHauZkC1K9ZGojflKxZoYerlB4L23Uj3TEL2dBRTPTCb00Go2FciV JXZwzctJledR/sNI1kEFOoPlW9g3v0qnMEmMdlyQnX5ULHeTBRkIN4+j4O4d0UE0DwO0D5rrCmY MWCkKVWuMp0RpfWpN4zmCU8eCxrZT9fsrvb4NTjPWlFEdQk+aI51u9E9jdGABWsfTEOVXIF X-Received: by 2002:a05:6a20:d045:b0:3c3:76a8:c0f with SMTP id adf61e73a8af0-3cd2fdae77dmr19999183637.4.1787356832953; Fri, 21 Aug 2026 17:00:32 -0700 (PDT) Received: from localhost.localdomain ([2603:8001:5f01:8bab:fc5e:9d66:f144:bfe9]) by smtp.gmail.com with ESMTPSA id a92af1059eb24-141861732f8sm1743425c88.10.2026.08.21.17.00.30 (version=TLS1_3 cipher=TLS_CHACHA20_POLY1305_SHA256 bits=256/256); Fri, 21 Aug 2026 17:00:31 -0700 (PDT) From: Artem Dinaburg To: stable@vger.kernel.org Cc: Sabrina Dubroca , Jakub Kicinski , Eric Dumazet , William Liu , Savino Dicanosa , Boris Pismenny , John Fastabend , linux-kernel@vger.kernel.org, Artem Dinaburg Subject: [PATCH 6.1.y 2/2] tls: handle data disappearing from under the TLS ULP Date: Fri, 21 Aug 2026 20:00:18 -0400 Message-ID: <20260822000018.48130-3-artem@trailofbits.com> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260822000018.48130-1-artem@trailofbits.com> References: <20260822000018.48130-1-artem@trailofbits.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" From: Jakub Kicinski [ Upstream commit 6db015fc4b5d5f63a64a193f65d98da3a7fc811d ] TLS expects that it owns the receive queue of the TCP socket. This cannot be guaranteed in case the reader of the TCP socket entered before the TLS ULP was installed, or uses some non-standard read API (eg. zerocopy ones). Replace the WARN_ON() and a buggy early exit (which leaves anchor pointing to a freed skb) with real error handling. Wipe the parsing state and tell the reader to retry. We already reload the anchor every time we (re)acquire the socket lock, so the only condition we need to avoid is an out of bounds read (not having enough bytes in the socket for previously parsed record len). If some data was read from under TLS but there's enough in the queue we'll reload and decrypt what is most likely not a valid TLS record. Leading to some undefined behavior from TLS perspective (corrupting a stream? missing an alert? missing an attack?) but no kernel crash should take place. Reported-by: William Liu Reported-by: Savino Dicanosa Link: https://lore.kernel.org/tFjq_kf7sWIG3A7CrCg_egb8CVsT_gsmHAK0_wxDPJXfI= zxFAMxqmLwp3MlU5EHiet0AwwJldaaFdgyHpeIUCS-3m3llsmRzp9xIOBR4lAI=3D@syst3mfai= lure.io Fixes: 84c61fe1a75b ("tls: rx: do not use the standard strparser") Reviewed-by: Eric Dumazet Link: https://patch.msgid.link/20250807232907.600366-1-kuba@kernel.org Signed-off-by: Jakub Kicinski Assisted-by: Codex:GPT-5 Signed-off-by: Artem Dinaburg --- The CVE-2025-38616 fix, applied verbatim with no source adaptation. Patch 1/2 supplies the bool msg_ready that this patch's WRITE_ONCE() requires. net/tls/tls.h | 2 +- net/tls/tls_strp.c | 11 ++++++++--- net/tls/tls_sw.c | 3 ++- 3 files changed, 11 insertions(+), 5 deletions(-) diff --git a/net/tls/tls.h b/net/tls/tls.h index 9fd5867a3..c1be90019 100644 --- a/net/tls/tls.h +++ b/net/tls/tls.h @@ -147,7 +147,7 @@ void tls_strp_msg_done(struct tls_strparser *strp); int tls_rx_msg_size(struct tls_strparser *strp, struct sk_buff *skb); void tls_rx_msg_ready(struct tls_strparser *strp); =20 -void tls_strp_msg_load(struct tls_strparser *strp, bool force_refresh); +bool tls_strp_msg_load(struct tls_strparser *strp, bool force_refresh); int tls_strp_msg_cow(struct tls_sw_context_rx *ctx); struct sk_buff *tls_strp_msg_detach(struct tls_sw_context_rx *ctx); int tls_strp_msg_hold(struct tls_strparser *strp, struct sk_buff_head *dst= ); diff --git a/net/tls/tls_strp.c b/net/tls/tls_strp.c index 32b57e574..be8a79960 100644 --- a/net/tls/tls_strp.c +++ b/net/tls/tls_strp.c @@ -481,7 +481,7 @@ static void tls_strp_load_anchor_with_queue(struct tls_= strparser *strp, int len) strp->stm.offset =3D offset; } =20 -void tls_strp_msg_load(struct tls_strparser *strp, bool force_refresh) +bool tls_strp_msg_load(struct tls_strparser *strp, bool force_refresh) { struct strp_msg *rxm; struct tls_msg *tlm; @@ -490,8 +490,11 @@ void tls_strp_msg_load(struct tls_strparser *strp, boo= l force_refresh) DEBUG_NET_WARN_ON_ONCE(!strp->stm.full_len); =20 if (!strp->copy_mode && force_refresh) { - if (WARN_ON(tcp_inq(strp->sk) < strp->stm.full_len)) - return; + if (unlikely(tcp_inq(strp->sk) < strp->stm.full_len)) { + WRITE_ONCE(strp->msg_ready, 0); + memset(&strp->stm, 0, sizeof(strp->stm)); + return false; + } =20 tls_strp_load_anchor_with_queue(strp, strp->stm.full_len); } @@ -501,6 +504,8 @@ void tls_strp_msg_load(struct tls_strparser *strp, bool= force_refresh) rxm->offset =3D strp->stm.offset; tlm =3D tls_msg(strp->anchor); tlm->control =3D strp->mark; + + return true; } =20 /* Called with lock held on lower socket */ diff --git a/net/tls/tls_sw.c b/net/tls/tls_sw.c index 5eec7c10a..c923b7dc6 100644 --- a/net/tls/tls_sw.c +++ b/net/tls/tls_sw.c @@ -1510,7 +1510,8 @@ tls_rx_rec_wait(struct sock *sk, struct sk_psock *pso= ck, bool nonblock, return sock_intr_errno(timeo); } =20 - tls_strp_msg_load(&ctx->strp, released); + if (unlikely(!tls_strp_msg_load(&ctx->strp, released))) + return tls_rx_rec_wait(sk, psock, nonblock, false); =20 return 1; } --=20 2.43.0