[SRU][N][PATCH 1/3] net: tls: fix silent data drop under pipe back-pressure
Cengiz Can
cengiz.can at canonical.com
Wed Jun 24 22:22:55 UTC 2026
From: Jakub Kicinski <kuba at kernel.org>
BugLink: https://bugs.launchpad.net/bugs/2155609
tls_sw_splice_read() uses len when advancing rxm->offset / rxm->full_len
after skb_splice_bits(), rather than copied (the actual number of bytes
successfully spliced into the pipe). When the destination pipe cannot
accept all the requested bytes, splice_to_pipe() returns fewer bytes
than len, and 'len - copied' of data is effectively skipped over.
Fixes: e062fe99cccd ("tls: splice_read: fix accessing pre-processed records")
Link: https://patch.msgid.link/20260429222944.2139041-2-kuba@kernel.org
Signed-off-by: Jakub Kicinski <kuba at kernel.org>
(cherry picked from commit 7e7be31bfdb066c1c780dcd6b1224078fc54063f)
Signed-off-by: Cengiz Can <cengiz.can at canonical.com>
---
net/tls/tls_sw.c | 6 +++---
1 file changed, 3 insertions(+), 3 deletions(-)
diff --git a/net/tls/tls_sw.c b/net/tls/tls_sw.c
index 057da95f0fc6..71b3100ccb43 100644
--- a/net/tls/tls_sw.c
+++ b/net/tls/tls_sw.c
@@ -2285,9 +2285,9 @@ ssize_t tls_sw_splice_read(struct socket *sock, loff_t *ppos,
if (copied < 0)
goto splice_requeue;
- if (chunk < rxm->full_len) {
- rxm->offset += len;
- rxm->full_len -= len;
+ if (copied < rxm->full_len) {
+ rxm->offset += copied;
+ rxm->full_len -= copied;
goto splice_requeue;
}
--
2.43.0
More information about the kernel-team
mailing list