[PATCH net-next v2 0/2] net: annotate remaining lockless sk->sk_err accesses

From: Quanye Yang via B4 Relay

Date: Sun Oct 04 2026 - 00:45:31 EST


The TCP/MPTCP series that annotated lockless sk_err peeks and
consumes is in net-next. Paolo asked for the same treatment on
kTLS and on the unmarked writers that still race those readers.

do_recvmmsg() and getsockopt(SO_ERROR) still call sock_error()
without the socket lock. kTLS is a ULP on that same struct sock,
so tls_rx_rec_wait() has the same peek-versus-consume split, and
the send path still does a double unmarked load.

sock_dequeue_err_skb() can store sk_err from MSG_ERRQUEUE before
lock_sock(). strp_abort_strp() and sk_psock_report_error() write
the same field on the TCP/TLS and sockmap paths.

Patch 1 annotates the TLS readers and consumes sk_err once on the
no-data path. Patch 2 pairs the remaining writers with WRITE_ONCE().
No extra ordering is added; ICMP error-queue overwrite semantics
are unchanged.

Link: https://lore.kernel.org/netdev/3d9d442f-f168-43da-87b0-010ad5a78365@xxxxxxxxxx/

Signed-off-by: Quanye Yang <quanyeyang@xxxxxxxxx>
---
Changes in v2:
- tls_encrypt_done(): fold the three unmarked sk_err loads into one
READ_ONCE()
- Link to v1: https://patch.msgid.link/20261002-tls-fix-sk-kcsan-err-v1-0-baa0ba056323@xxxxxxxxx

---
Quanye Yang (2):
tls: annotate lockless access to sk->sk_err
net: annotate lockless writes to sk->sk_err

include/linux/skmsg.h | 2 +-
net/core/skbuff.c | 5 +++--
net/strparser/strparser.c | 2 +-
net/tls/tls_device.c | 5 +++--
net/tls/tls_sw.c | 54 +++++++++++++++++++++++++++++++----------------
5 files changed, 44 insertions(+), 24 deletions(-)
---
base-commit: 071876fd50482a68603a9460d80dd6dd58827ee1
change-id: 20261002-tls-fix-sk-kcsan-err-6fef32744f15

Best regards,
--
Quanye Yang <quanyeyang@xxxxxxxxx>