From: Deep Shah <deepshah146@gmail.com>
To: netdev@vger.kernel.org,
Richard Cochran <richardcochran@gmail.com>,
"David S . Miller" <davem@davemloft.net>,
Jakub Kicinski <kuba@kernel.org>, Paolo Abeni <pabeni@redhat.com>,
Eric Dumazet <edumazet@google.com>,
Andrew Lunn <andrew+netdev@lunn.ch>
Cc: linux-kernel@vger.kernel.org, linux-kselftest@vger.kernel.org,
Shuah Khan <shuah@kernel.org>,
Vadim Fedorenko <vadim.fedorenko@linux.dev>,
Simon Horman <horms@kernel.org>,
Deep Shah <deepshah146@gmail.com>
Subject: [PATCH net-next v3 0/2] ptp: reject frequency adjustments that overflow scaled_ppm_to_ppb()
Date: Sat, 1 Aug 2026 22:29:21 +0000 [thread overview]
Message-ID: <20260801222923.39017-1-deepshah146@gmail.com> (raw)
ptp_clock_adjtime() validates an ADJ_FREQUENCY request by converting
tx->freq to ppb and comparing it against ops->max_adj. On 64-bit systems
that conversion can overflow s64 and wrap the result back into range, so
a crafted tx->freq bypasses the check and reaches ->adjfine() unclamped.
No real user space asks for such a frequency, so this is hardening rather
than a fix anyone is waiting on, and it is targeted at net-next with no
Fixes tag per Jakub's feedback on v2.
Patch 1 rejects the overflow in ptp_clock_adjtime().
Patch 2 adds a regression test that crafts struct timex.freq directly
(testptp's int-ppb path cannot express the value) and confirms it is
rejected with -ERANGE.
Changes in v3:
- retarget at net-next and drop the Fixes tag (Jakub Kicinski)
- patch 1: unchanged
- patch 2:
- cast the test value to the type of tx.freq rather than guarding on
__SIZEOF_LONG__, which skipped the assignment on x32 and other
y2038 configurations and failed the test there (Simon Horman)
- add the built binary to .gitignore
Changes in v2:
- patch 1: added Reviewed-by from Vadim Fedorenko.
- patch 2 (all from Simon Horman's review):
- cast fd to unsigned before the shift in FD_TO_CLOCKID (UBSan)
- avoid a -Woverflow warning on 32-bit
- save and restore the clock frequency
- skip instead of fail on -EBUSY (free-running clock)
Link to v1:
https://lore.kernel.org/netdev/20260712040922.6403-1-deepshah146@gmail.com/
Link to v2:
https://lore.kernel.org/netdev/20260721014256.1876-1-deepshah146@gmail.com/
Deep Shah (2):
ptp: reject frequency adjustments that overflow scaled_ppm_to_ppb()
selftests: ptp: add a regression test for the frequency adjustment
overflow
drivers/ptp/ptp_clock.c | 14 ++-
tools/testing/selftests/ptp/.gitignore | 1 +
tools/testing/selftests/ptp/Makefile | 2 +-
.../testing/selftests/ptp/ptp_freq_overflow.c | 101 ++++++++++++++++++
4 files changed, 116 insertions(+), 2 deletions(-)
create mode 100644 tools/testing/selftests/ptp/ptp_freq_overflow.c
base-commit: 69963a0678a347d57c4ac8b16939dba216eb95ce
--
2.43.0
next reply other threads:[~2026-08-01 22:29 UTC|newest]
Thread overview: 7+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-01 22:29 Deep Shah [this message]
2026-08-01 22:29 ` [PATCH net-next v3 1/2] ptp: reject frequency adjustments that overflow scaled_ppm_to_ppb() Deep Shah
2026-08-02 18:49 ` Richard Cochran
2026-08-01 22:29 ` [PATCH net-next v3 2/2] selftests: ptp: add a regression test for the frequency adjustment overflow Deep Shah
2026-08-02 18:49 ` Richard Cochran
2026-08-06 1:16 ` [PATCH net-next v3 0/2] ptp: reject frequency adjustments that overflow scaled_ppm_to_ppb() Jakub Kicinski
2026-08-06 1:20 ` patchwork-bot+netdevbpf
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260801222923.39017-1-deepshah146@gmail.com \
--to=deepshah146@gmail.com \
--cc=andrew+netdev@lunn.ch \
--cc=davem@davemloft.net \
--cc=edumazet@google.com \
--cc=horms@kernel.org \
--cc=kuba@kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-kselftest@vger.kernel.org \
--cc=netdev@vger.kernel.org \
--cc=pabeni@redhat.com \
--cc=richardcochran@gmail.com \
--cc=shuah@kernel.org \
--cc=vadim.fedorenko@linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.