All of lore.kernel.org
 help / color / mirror / Atom feed
From: Kuniyuki Iwashima <kuniyu@google.com>
To: Kees Cook <kees@kernel.org>,
	Joel Granados <joel.granados@kernel.org>,
	 Thomas Gleixner <tglx@kernel.org>
Cc: Kuniyuki Iwashima <kuniyu@google.com>,
	Kuniyuki Iwashima <kuni1840@gmail.com>,
	linux-fsdevel@vger.kernel.org
Subject: [PATCH 2/2] sysctl: Make proc_doulongvec_ms_jiffies_minmax() enforce minmax again.
Date: Sat,  5 Sep 2026 23:36:31 +0000	[thread overview]
Message-ID: <20260905233819.1064529-3-kuniyu@google.com> (raw)
In-Reply-To: <20260905233819.1064529-1-kuniyu@google.com>

Since the cited commit changed proc_doulongvec_ms_jiffies_minmax()
to use proc_ulong_conv(), proc_doulongvec_ms_jiffies_minmax() no
longer applies the range check.

It happened probably because do_proc_ulong_conv_ms_jiffies() does
not have the _minmax suffix.

In addition, sysctl_msecs_to_jiffies() casts u64 user input to u32,
and a truncated value could bypass the max check.

Let's rename do_proc_ulong_conv_ms_jiffies(), pass true to
k_ptr_range_check, and limit the max user input to INT_MAX in
sysctl_u2k_ulong_conv_ms() to avoid truncation and clamping to
MAX_JIFFY_OFFSET. (INT_MAX ms ~= 24 days is more than enough)

Fixes: b96b5c6708ea ("sysctl: Replace do_proc_do{int,ulong,uint}vec with do_proc_vec")
Signed-off-by: Kuniyuki Iwashima <kuniyu@google.com>
---
 kernel/time/jiffies.c | 15 +++++++++------
 1 file changed, 9 insertions(+), 6 deletions(-)

diff --git a/kernel/time/jiffies.c b/kernel/time/jiffies.c
index 70926b73905a..4737431fdb16 100644
--- a/kernel/time/jiffies.c
+++ b/kernel/time/jiffies.c
@@ -187,6 +187,9 @@ static int do_proc_int_conv_ms_jiffies_minmax(bool *negp, ulong *u_ptr,
 
 static int sysctl_u2k_ulong_conv_ms(const ulong *u_ptr, ulong *k_ptr)
 {
+	if (*u_ptr > INT_MAX)
+		return -EINVAL;
+
 	return proc_ulong_u2k_conv_uop(u_ptr, k_ptr, sysctl_msecs_to_jiffies);
 }
 
@@ -195,10 +198,10 @@ static int sysctl_k2u_ulong_conv_ms(ulong *u_ptr, const ulong *k_ptr)
 	return proc_ulong_k2u_conv_kop(u_ptr, k_ptr, sysctl_jiffies_to_msecs);
 }
 
-static int do_proc_ulong_conv_ms_jiffies(bool *negp, ulong *u_ptr, ulong *k_ptr,
-					 int dir, const struct ctl_table *tbl)
+static int do_proc_ulong_conv_ms_jiffies_minmax(bool *negp, ulong *u_ptr, ulong *k_ptr,
+						int dir, const struct ctl_table *tbl)
 {
-	return proc_ulong_conv(u_ptr, k_ptr, dir, tbl, false,
+	return proc_ulong_conv(u_ptr, k_ptr, dir, tbl, true,
 			       sysctl_u2k_ulong_conv_ms, sysctl_k2u_ulong_conv_ms);
 }
 
@@ -229,8 +232,8 @@ static int do_proc_int_conv_ms_jiffies_minmax(bool *negp, ulong *u_ptr,
 	return -ENOSYS;
 }
 
-static int do_proc_ulong_conv_ms_jiffies(bool *negp, ulong *u_ptr, ulong *k_ptr,
-					 int dir, const struct ctl_table *tbl)
+static int do_proc_ulong_conv_ms_jiffies_minmax(bool *negp, ulong *u_ptr, ulong *k_ptr,
+						int dir, const struct ctl_table *tbl)
 {
 	return -ENOSYS;
 }
@@ -333,7 +336,7 @@ int proc_doulongvec_ms_jiffies_minmax(const struct ctl_table *table, int dir,
 				      void *buffer, size_t *lenp, loff_t *ppos)
 {
 	return proc_doulongvec_conv(table, dir, buffer, lenp, ppos,
-				    do_proc_ulong_conv_ms_jiffies);
+				    do_proc_ulong_conv_ms_jiffies_minmax);
 }
 EXPORT_SYMBOL(proc_doulongvec_ms_jiffies_minmax);
 
-- 
2.55.0.1003.g10538fe699-goog


  parent reply	other threads:[~2026-09-05 23:38 UTC|newest]

Thread overview: 14+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-05 23:36 [PATCH 0/2] sysctl: Restore minmax check for proc_do{int,ulong}vec_ms_jiffies_minmax() Kuniyuki Iwashima
2026-09-05 23:36 ` [PATCH 1/2] sysctl: Make proc_dointvec_ms_jiffies_minmax() enforce minmax again Kuniyuki Iwashima
2026-09-08 11:06   ` Joel Granados
2026-09-08 18:38     ` Kuniyuki Iwashima
2026-09-09 13:48       ` Joel Granados
2026-09-05 23:36 ` Kuniyuki Iwashima [this message]
2026-09-08 12:15   ` [PATCH 2/2] sysctl: Make proc_doulongvec_ms_jiffies_minmax() " Joel Granados
2026-09-08 18:44     ` Kuniyuki Iwashima
2026-09-09 13:44       ` Joel Granados
2026-09-09 17:07         ` Kuniyuki Iwashima
2026-09-10  9:04           ` Joel Granados
2026-09-10 10:45             ` Joel Granados
2026-09-10 16:43               ` Kuniyuki Iwashima
2026-09-11  8:59                 ` Joel Granados

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260905233819.1064529-3-kuniyu@google.com \
    --to=kuniyu@google.com \
    --cc=joel.granados@kernel.org \
    --cc=kees@kernel.org \
    --cc=kuni1840@gmail.com \
    --cc=linux-fsdevel@vger.kernel.org \
    --cc=tglx@kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.