Re: [PATCH net-next 1/2] tls: annotate lockless access to sk->sk_err

From: Eric Dumazet

Date: Fri Oct 02 2026 - 04:55:54 EST


On Fri, Oct 2, 2026 at 9:29 AM Quanye Yang via B4 Relay
<devnull+quanyeyang.proton.me@xxxxxxxxxx> wrote:
>
> From: Quanye Yang <quanyeyang@xxxxxxxxx>
>
> kTLS sits on the same struct sock as TCP. do_recvmmsg() and
> getsockopt(SO_ERROR) still call sock_error() without the socket lock
> and clear sk_err with xchg().
>
> tls_rx_rec_wait() already peeks when data has been copied and consumes
> otherwise, but the outer if (sk_err) is an unmarked load. On the
> no-data path that check-then-sock_error() window can return 0 after
> another thread consumes the error. Call sock_error() once and only
> return when it is non-zero; keep READ_ONCE() on the peek path.
>
> tls_sw_sendmsg_locked(), tls_push_data() and bpf_exec_tx_verdict()
> read sk_err twice. Fold those unmarked loads into one READ_ONCE()
> and use that value as the returned errno. The field is still not
> consumed there.
>
> Link: https://lore.kernel.org/netdev/3d9d442f-f168-43da-87b0-010ad5a78365@xxxxxxxxxx/
> Signed-off-by: Quanye Yang <quanyeyang@xxxxxxxxx>
> ---
> net/tls/tls_device.c | 5 +++--
> net/tls/tls_sw.c | 45 ++++++++++++++++++++++++++++++---------------
> 2 files changed, 33 insertions(+), 17 deletions(-)
>
> diff --git a/net/tls/tls_device.c b/net/tls/tls_device.c
> index f11d0528fc43..03ce83a9d4e9 100644
> --- a/net/tls/tls_device.c
> +++ b/net/tls/tls_device.c
> @@ -444,8 +444,9 @@ static int tls_push_data(struct sock *sk,
> if ((flags & (MSG_MORE | MSG_EOR)) == (MSG_MORE | MSG_EOR))
> return -EINVAL;
>
> - if (unlikely(sk->sk_err))
> - return -sk->sk_err;
> + rc = -READ_ONCE(sk->sk_err);
> + if (unlikely(rc))
> + return rc;
>
> flags |= MSG_SENDPAGE_DECRYPTED;
> tls_push_record_flags = flags | MSG_MORE;
> diff --git a/net/tls/tls_sw.c b/net/tls/tls_sw.c
> index d1ad31986cf2..12e4458b44bb 100644
> --- a/net/tls/tls_sw.c
> +++ b/net/tls/tls_sw.c

It seems you missed tls_encrypt_done() ?

Thanks!