From: Ido Schimmel <idosch@nvidia.com>
To: Kuniyuki Iwashima <kuniyu@google.com>
Cc: "David S . Miller" <davem@davemloft.net>,
Eric Dumazet <edumazet@google.com>,
Jakub Kicinski <kuba@kernel.org>, Paolo Abeni <pabeni@redhat.com>,
Simon Horman <horms@kernel.org>,
Kuniyuki Iwashima <kuni1840@gmail.com>,
netdev@vger.kernel.org, Yuwei Wang <wangyuweihx@gmail.com>
Subject: Re: [PATCH v1 net 2/4] neighbour: Enforce min/max to NDTPA_INTERVAL_PROBE_TIME_MS.
Date: Tue, 8 Sep 2026 13:05:48 +0300 [thread overview]
Message-ID: <20260908100548.GB903218@shredder> (raw)
In-Reply-To: <20260907215853.3709987-3-kuniyu@google.com>
On Mon, Sep 07, 2026 at 09:57:53PM +0000, Kuniyuki Iwashima wrote:
> NDTPA_INTERVAL_PROBE_TIME_MS sets .type and .min but misses
> .validation_type, so no validation is applied:
>
> # ynl --family rt-neigh --do setneightbl \
> --json '{"name": "arp_cache", "parms": {"interval-probe-time-ms": 0}}'
>
> # ynl --family rt-neigh --dump getneightbl --output-json | \
> jq '.[] | select(.name == "arp_cache" and has("config"))
> | .parms["interval-probe-time-ms"]'
> 0
>
> Moreover, nla_get_msecs() uses msecs_to_jiffies(), and u64 is
> silently cast to u32, so a larger value can bypass the min check:
>
> e.g. 4294967296 == 0x100000000
>
> # ynl --family rt-neigh --do setneightbl \
> --json '{"name": "arp_cache", "parms": {"interval-probe-time-ms": 4294967296}}'
>
> # ynl --family rt-neigh --dump getneightbl --output-json | \
> jq '.[] | select(.name == "arp_cache" and has("config"))
> | .parms["interval-probe-time-ms"]'
> 0
>
> msecs_to_jiffies() returns MAX_JIFFY_OFFSET if the value is
> larger than INT_MAX. Also, INT_MAX ms overflows int NEIGH_VAR()
> when HZ > 1000 (Alpha, MIPS), and passing a negative integer to
> queue_delayed_work(unsigned long delay) causes sign extension,
> which wraps around the expiry time to the past, resulting in it
> being handled as 0 delay in the timer wheel.
>
> Let's use NLA_POLICY_FULL_RANGE() and limit the max to 1 day.
Please add a note that this controls the probe interval for "managed"
entries and therefore a max of 1 day is unlikely to break any
deployments.
>
> The same max check is applied to sysctl as well.
>
> Fixes: 211da42eaa45 ("net, neigh: introduce interval_probe_time_ms for periodic probe")
> Signed-off-by: Kuniyuki Iwashima <kuniyu@google.com>
> ---
> Currently, the sysctl range check is not applied to
> interval_probe_time_ms, which needs this fix:
> https://lore.kernel.org/linux-fsdevel/20260905233819.1064529-2-kuniyu@google.com/
>
> Cc: Yuwei Wang <wangyuweihx@gmail.com>
> ---
> net/core/neighbour.c | 17 +++++++++++++----
> 1 file changed, 13 insertions(+), 4 deletions(-)
The maximum value should be documented in Documentation/networking/ip-sysctl.rst
Also in Documentation/netlink/specs/rt-neigh.yaml:
diff --git a/Documentation/netlink/specs/rt-neigh.yaml b/Documentation/netlink/specs/rt-neigh.yaml
index 0f46ef313590..c8e55c98d564 100644
--- a/Documentation/netlink/specs/rt-neigh.yaml
+++ b/Documentation/netlink/specs/rt-neigh.yaml
@@ -341,6 +341,9 @@ attribute-sets:
-
name: interval-probe-time-ms
type: u64
+ checks:
+ min: 1
+ max: 86400000
operations:
enum-model: directional
next prev parent reply other threads:[~2026-09-08 10:06 UTC|newest]
Thread overview: 12+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-07 21:57 [PATCH v1 net 0/4] neighbour: Small fixes for RTM_{GET,SET}NEIGHTBL Kuniyuki Iwashima
2026-09-07 21:57 ` [PATCH v1 net 1/4] neighbour: Add missing RCU annotation for neightbl_dump_info() Kuniyuki Iwashima
2026-09-08 10:05 ` Ido Schimmel
2026-09-08 16:46 ` Kuniyuki Iwashima
2026-09-07 21:57 ` [PATCH v1 net 2/4] neighbour: Enforce min/max to NDTPA_INTERVAL_PROBE_TIME_MS Kuniyuki Iwashima
2026-09-08 10:05 ` Ido Schimmel [this message]
2026-09-08 16:48 ` Kuniyuki Iwashima
2026-09-09 15:58 ` netdev-bot+sashiko
2026-09-07 21:57 ` [PATCH v1 net 3/4] neighbour: Don't render blackhole_netdev via RTM_GETNEIGHTBL Kuniyuki Iwashima
2026-09-07 21:57 ` [PATCH v1 net 4/4] neighbour: Skip default parms when resumed in neightbl_dump_info() Kuniyuki Iwashima
2026-09-08 10:06 ` Ido Schimmel
2026-09-09 15:58 ` netdev-bot+sashiko
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260908100548.GB903218@shredder \
--to=idosch@nvidia.com \
--cc=davem@davemloft.net \
--cc=edumazet@google.com \
--cc=horms@kernel.org \
--cc=kuba@kernel.org \
--cc=kuni1840@gmail.com \
--cc=kuniyu@google.com \
--cc=netdev@vger.kernel.org \
--cc=pabeni@redhat.com \
--cc=wangyuweihx@gmail.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.