summaryrefslogtreecommitdiff
path: root/net/sunrpc
diff options
context:
space:
mode:
authorChuck Lever <cel@kernel.org>2026-08-08 11:40:15 -0400
committerAnna Schumaker <anna.schumaker@hammerspace.com>2026-09-22 09:23:53 -0400
commit706a92da0dee5870553a3bd96d8d3526e0ecbbe6 (patch)
treee7740378b40ea2c6e6a41fa164d871466a005726 /net/sunrpc
parent03faaee7e0811816173c514cd5bfe507bfa3cbe7 (diff)
downloadlinux-next-706a92da0dee5870553a3bd96d8d3526e0ecbbe6.tar.gz
linux-next-706a92da0dee5870553a3bd96d8d3526e0ecbbe6.zip
SUNRPC: fold xs_sock_process_cmsg() into its only caller
xs_sock_process_cmsg() switches on the TLS record type, and every arm but TLS_RECORD_TYPE_ALERT returns the -EAGAIN its caller passed in. The DATA arm clears MSG_EOR in the caller's msghdr, but xs_sock_recvmsg() has already cleared that flag before the call. Deriving the record type a second time inside the helper also fires trace_tls_contenttype() twice for every alert. Move the alert handling into xs_sock_recv_cmsg() and delete the helper. Every other record type still returns -EAGAIN. The DATA arm's account of MSG_EOR moves to xs_sock_recvmsg(), where the flag is cleared. Signed-off-by: Chuck Lever <cel@kernel.org> Signed-off-by: Anna Schumaker <anna.schumaker@hammerspace.com>
Diffstat (limited to 'net/sunrpc')
-rw-r--r--net/sunrpc/xprtsock.c85
1 files changed, 30 insertions, 55 deletions
diff --git a/net/sunrpc/xprtsock.c b/net/sunrpc/xprtsock.c
index 963e46a51421..f5a5136327ba 100644
--- a/net/sunrpc/xprtsock.c
+++ b/net/sunrpc/xprtsock.c
@@ -357,45 +357,6 @@ xs_alloc_sparse_pages(struct xdr_buf *buf, size_t want, gfp_t gfp)
}
static int
-xs_sock_process_cmsg(struct socket *sock, struct msghdr *msg,
- unsigned int *msg_flags, struct cmsghdr *cmsg, int ret)
-{
- u8 content_type = tls_get_record_type(sock->sk, cmsg);
- u8 level, description;
-
- switch (content_type) {
- case 0:
- break;
- case TLS_RECORD_TYPE_DATA:
- /* TLS sets EOR at the end of each application data
- * record, even though there might be more frames
- * waiting to be decrypted.
- */
- *msg_flags &= ~MSG_EOR;
- break;
- case TLS_RECORD_TYPE_ALERT:
- tls_alert_recv(sock->sk, msg, &level, &description);
- /* RFC 8446 Section 6: every alert but a closure alert is
- * an error alert, whatever the legacy AlertLevel octet
- * says.
- */
- switch (description) {
- case TLS_ALERT_DESC_CLOSE_NOTIFY:
- case TLS_ALERT_DESC_USER_CANCELED:
- ret = -EAGAIN;
- break;
- default:
- ret = -EACCES;
- }
- break;
- default:
- /* discard this record type */
- ret = -EAGAIN;
- }
- return ret;
-}
-
-static int
xs_sock_recv_cmsg(struct socket *sock, unsigned int *msg_flags, int flags)
{
union {
@@ -412,6 +373,7 @@ xs_sock_recv_cmsg(struct socket *sock, unsigned int *msg_flags, int flags)
.msg_control = &u,
.msg_controllen = sizeof(u),
};
+ u8 level, description;
int ret;
iov_iter_kvec(&msg.msg_iter, ITER_DEST, &alert_kvec, 1,
@@ -421,23 +383,32 @@ xs_sock_recv_cmsg(struct socket *sock, unsigned int *msg_flags, int flags)
* kTLS filled in u.cmsg.
*/
if (ret >= 0 && msg.msg_controllen < sizeof(u)) {
- if (tls_get_record_type(sock->sk, &u.cmsg) ==
- TLS_RECORD_TYPE_ALERT) {
- /* RFC 8446 Section 5.1 requires a record with an
- * Alert type to carry exactly one message. An alert
- * is two octets. tls_alert_recv() reads both without
- * checking the length. alert_kvec caps the count at
- * two, so a longer record fills it as well. kTLS
- * sets MSG_EOR only once the record has been
- * drained.
- */
- if (ret != sizeof(alert) ||
- !(msg.msg_flags & MSG_EOR))
- return -EACCES;
- iov_iter_revert(&msg.msg_iter, ret);
+ if (tls_get_record_type(sock->sk, &u.cmsg) !=
+ TLS_RECORD_TYPE_ALERT)
+ return -EAGAIN;
+ /* RFC 8446 Section 5.1: a record with an Alert type carries
+ * exactly one message, and an alert is two octets.
+ * tls_alert_recv() reads both without checking the length.
+ * alert_kvec caps the count at two, so a longer record
+ * fills it as well. kTLS sets MSG_EOR only once the
+ * record has been drained.
+ */
+ if (ret != sizeof(alert) || !(msg.msg_flags & MSG_EOR))
+ return -EACCES;
+ iov_iter_revert(&msg.msg_iter, ret);
+ tls_alert_recv(sock->sk, &msg, &level, &description);
+ /* RFC 8446 Section 6: every alert but a closure alert is
+ * an error alert, whatever the legacy AlertLevel octet
+ * says.
+ */
+ switch (description) {
+ case TLS_ALERT_DESC_CLOSE_NOTIFY:
+ case TLS_ALERT_DESC_USER_CANCELED:
+ ret = -EAGAIN;
+ break;
+ default:
+ ret = -EACCES;
}
- ret = xs_sock_process_cmsg(sock, &msg, msg_flags, &u.cmsg,
- -EAGAIN);
}
return ret;
}
@@ -451,6 +422,10 @@ xs_sock_recvmsg(struct socket *sock, struct msghdr *msg, int flags, size_t seek)
ret = sock_recvmsg(sock, msg, flags);
/* Handle TLS inband control message lazily */
if (msg->msg_flags & MSG_CTRUNC) {
+ /* TLS sets EOR at the end of each application data
+ * record, even though there might be more frames
+ * waiting to be decrypted.
+ */
msg->msg_flags &= ~(MSG_CTRUNC | MSG_EOR);
if (ret == 0 || ret == -EIO)
ret = xs_sock_recv_cmsg(sock, &msg->msg_flags, flags);