[PATCH net v3 04/14] rxrpc: Fix packet encryption error handling
David Howells
dhowells at redhat.com
Thu Jul 23 01:41:02 PDT 2026
Simon Horman <horms at kernel.org> wrote:
> > ret = call->security->secure_packet(call, txb);
> > - if (ret < 0)
> > + if (ret < 0) {
> > + if (ret == -ENOMEM)
> > + goto maybe_error;
>
> [Severity: High]
> If secure_packet() fails with -ENOMEM, does this jump to maybe_error bypass
> rxrpc_queue_packet() but still return a successful write length?
>
> Looking at rxrpc_send_data(), the user data has already been copied into txb
> and 'copied' has been incremented. The maybe_error path handles this:
Ummm... I'm not sure how best to deal with this.
Technically, the call transmission could be completed by calling sendmsg()
again - but as Sashiko points out, the fact that I return the full amount
copied will give the caller the impression that we've done everything.
I also can't just return -ENOMEM, because the caller will then resend
everything.
I could perhaps make it work by reverting msg->msg_iter by 1 and deducting 1
from copied (provided copied > 0; this could be called with zero-length data,
but in that case I can just return -ENOMEM directly).
David
More information about the linux-afs
mailing list