From: Jack Wang <163wangjack@gmail.com>
To: netdev@vger.kernel.org
Cc: linux-kernel@vger.kernel.org, Jack Wang <163wangjack@gmail.com>,
Vinicius Costa Gomes <vinicius.gomes@intel.com>,
Jamal Hadi Salim <jhs@mojatatu.com>,
Jiri Pirko <jiri@resnulli.us>,
"David S. Miller" <davem@davemloft.net>,
Eric Dumazet <edumazet@google.com>,
Jakub Kicinski <kuba@kernel.org>, Paolo Abeni <pabeni@redhat.com>,
Simon Horman <horms@kernel.org>,
Jesus Sanchez-Palencia <jesus.sanchez-palencia@intel.com>,
Elena Salomatkina <esalomatkina@ispras.ru>
Subject: [PATCH net v2] net/sched: cbs: perform rate conversions in signed 64-bit arithmetic
Date: Wed, 12 Aug 2026 16:02:04 +0800 [thread overview]
Message-ID: <20260812080204.32373-1-163wangjack@gmail.com> (raw)
In-Reply-To: <20260806155253.50252-1-163wangjack@gmail.com>
cbs_set_port_rate() and cbs_change() multiply link rates and slope values
by BYTES_PER_KBIT, an unsigned long constant. On 32-bit architectures,
the multiplications therefore take place in 32-bit unsigned arithmetic
before the results are assigned to s64 fields.
For port rates above approximately 34.36 Gbit/s this wraps port_rate.
The same conversion turns a negative sendslope into a large positive
value, reversing the CBS credit adjustment. This affects software CBS;
port_rate is also refreshed on NETDEV_UP and NETDEV_CHANGE notifications.
Cast the first operand of each multiplication to s64 so all intermediate
operations use signed 64-bit arithmetic and preserve the value's sign on
every architecture
Also reject a non-positive idleslope. A negative idleslope can arm the
watchdog in the past and busy-loop.
Fixes: 585d763af09c ("net/sched: Introduce Credit Based Shaper (CBS) qdisc")
Fixes: 397006ba5d918 ("net/sched: cbs: Fix integer overflow in cbs_set_port_rate()")
Signed-off-by: Jack Wang <163wangjack@gmail.com>
---
v2:
- Reject a non-positive idleslope to prevent scheduling the watchdog in
the past.
- Leave the pre-existing timediff_to_credits() overflow for a separate
follow-up.
v1: https://lore.kernel.org/netdev/20260806155253.50252-1-163wangjack@gmail.com/
net/sched/sch_cbs.c | 10 +++++++---
1 file changed, 7 insertions(+), 3 deletions(-)
diff --git a/net/sched/sch_cbs.c b/net/sched/sch_cbs.c
index 1c93469c56e3..e960c8e01ef4 100644
--- a/net/sched/sch_cbs.c
+++ b/net/sched/sch_cbs.c
@@ -335,7 +335,7 @@ static void cbs_set_port_rate(struct net_device *dev, struct cbs_sched_data *q)
speed = ecmd.base.speed;
skip:
- port_rate = speed * 1000 * BYTES_PER_KBIT;
+ port_rate = (s64)speed * 1000 * BYTES_PER_KBIT;
atomic64_set(&q->port_rate, port_rate);
netdev_dbg(dev, "cbs: set %s's port_rate to: %lld, linkspeed: %d\n",
@@ -392,6 +392,10 @@ static int cbs_change(struct Qdisc *sch, struct nlattr *opt,
}
qopt = nla_data(tb[TCA_CBS_PARMS]);
+ if (qopt->idleslope <= 0) {
+ NL_SET_ERR_MSG(extack, "Idleslope must be greater than zero");
+ return -EINVAL;
+ }
if (!qopt->offload) {
cbs_set_port_rate(dev, q);
@@ -405,8 +409,8 @@ static int cbs_change(struct Qdisc *sch, struct nlattr *opt,
/* Everything went OK, save the parameters used. */
WRITE_ONCE(q->hicredit, qopt->hicredit);
WRITE_ONCE(q->locredit, qopt->locredit);
- WRITE_ONCE(q->idleslope, qopt->idleslope * BYTES_PER_KBIT);
- WRITE_ONCE(q->sendslope, qopt->sendslope * BYTES_PER_KBIT);
+ WRITE_ONCE(q->idleslope, (s64)qopt->idleslope * BYTES_PER_KBIT);
+ WRITE_ONCE(q->sendslope, (s64)qopt->sendslope * BYTES_PER_KBIT);
WRITE_ONCE(q->offload, qopt->offload);
return 0;
base-commit: 7b53449540502cb21b32bca62a6258e22cd97bbe
--
2.53.0
next prev parent reply other threads:[~2026-08-12 8:02 UTC|newest]
Thread overview: 5+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-06 15:49 [PATCH] net/sched: cbs: perform rate conversions in signed 64-bit arithmetic Jack Wang
2026-08-06 17:56 ` Vinicius Costa Gomes
2026-08-10 15:11 ` Jamal Hadi Salim
2026-08-12 8:02 ` Jack Wang [this message]
-- strict thread matches above, loose matches on Subject: below --
2026-08-12 10:00 [PATCH net v2] " Jack Wang
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260812080204.32373-1-163wangjack@gmail.com \
--to=163wangjack@gmail.com \
--cc=davem@davemloft.net \
--cc=edumazet@google.com \
--cc=esalomatkina@ispras.ru \
--cc=horms@kernel.org \
--cc=jesus.sanchez-palencia@intel.com \
--cc=jhs@mojatatu.com \
--cc=jiri@resnulli.us \
--cc=kuba@kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=netdev@vger.kernel.org \
--cc=pabeni@redhat.com \
--cc=vinicius.gomes@intel.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.