tls_sw_recvmsg() and tls_sw_read_sock() both read ctx->async_wait.err once they hold the reader lock, so a record that failed authentication fails the call. tls_sw_splice_read() has no such check. sk_err does not stand in for one. The first reader to reach sock_error() clears sk_err, while async_wait.err persists. A splice therefore keeps delivering records on a connection the other two readers have already refused.
Both patches come from a receive-path series for zero-length data records. Jakub asked for them separately, since the rest of that series is still under discussion. Link to the original series: https://patch.msgid.link/[email protected] --- Chuck Lever (2): net/tls: Fail tls_sw_splice_read() after a failed async decrypt selftests: tls: cover splice after a failed decrypt net/tls/tls_sw.c | 5 +++ tools/testing/selftests/net/tls.c | 75 +++++++++++++++++++++++++++++++++------ 2 files changed, 70 insertions(+), 10 deletions(-) --- base-commit: 594d905195024b228c962627ae5ae7c17bd582a4 change-id: 20260806-tls-splice-crypto-fix-2a6de3cc0224 Best regards, -- Chuck Lever <[email protected]>

