From: Stephen Hemminger <stephen@networkplumber.org>
To: Aleksandr Khromov <haa@amicon.ru>
Cc: <dev@dpdk.org>, <thomas@monjalon.net>,
<konstantin.ananyev@huawei.com>, <olivier.matz@6wind.com>,
<sdl.dpdk@linuxtesting.org>, <rrv@amicon.ru>, <stable@dpdk.org>
Subject: Re: [PATCH] net: fix signed shift overflow in IPv6 phdr cksum
Date: Mon, 21 Sep 2026 14:15:15 -0700 [thread overview]
Message-ID: <20260921141515.759647f5@phoenix.local> (raw)
In-Reply-To: <20260918074729.79205-1-haa@amicon.ru>
On Fri, 18 Sep 2026 10:47:29 +0300
Aleksandr Khromov <haa@amicon.ru> wrote:
> In rte_ipv6_phdr_cksum() the next header field, a uint8_t, is promoted to
> a signed int before the left shift by 24. For protocol values >= 128
> (for example IPPROTO_SCTP), proto << 24 does not fit in int, which is
> undefined behaviour (signed left shift overflow) reported by UBSan:
>
> rte_ip6.h: runtime error: left shift of 132 by 24 places cannot be
> represented in type 'int'
>
> Cast the operand to uint32_t before the shift so it is performed in
> unsigned arithmetic. The resulting value is unchanged on two's
> complement platforms. The same idiom is already used in RTE_IPV4().
>
> Fixes: 6006818cfb26 ("net: new checksum functions")
> Cc: stable@dpdk.org
> Signed-off-by: Aleksandr Khromov <haa@amicon.ru>
> ---
Looks good, but there is also a pre-existing byte order issue here.
Review: [PATCH] net: fix signed shift overflow in IPv6 phdr cksum
Patchwork: 169805
Applies cleanly to main. Fixes: 6006818cfb26 verified; the line was
introduced there and carried over by 1a2b549bb4 (header split).
Cc: stable is correct.
The fix is right. ipv6_hdr->proto is uint8_t, promoted to int, and
proto << 24 for proto >= 128 (SCTP = 132) overflows int. Casting the
operand to uint32_t makes the shift unsigned; generated code is the
same.
Info
drivers/net/hinic/hinic_pmd_tx.c:740 has an identical copy of this
code with the same UB:
psd_hdr.proto = (ipv6_hdr->proto << 24);
Worth fixing in the same patch (or a v2 as a two patch series) so
the pattern does not survive in the driver.
Consider rte_cpu_to_be_32(ipv6_hdr->proto) instead of the shift.
psd_hdr.proto is rte_be32_t and must hold proto in the last byte in
memory. proto << 24 only achieves that on little-endian; on a
big-endian build it lands in the first byte and the pseudo-header
sum is wrong. rte_cpu_to_be_32() removes the shift, is correct for
both byte orders, and the compiler folds it to the same shift on
little-endian. Not a blocker since the endian issue is pre-existing.
next prev parent reply other threads:[~2026-09-21 21:15 UTC|newest]
Thread overview: 4+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-18 7:47 [PATCH] net: fix signed shift overflow in IPv6 phdr cksum Aleksandr Khromov
2026-09-21 21:15 ` Stephen Hemminger [this message]
2026-09-28 14:18 ` Thomas Monjalon
2026-09-29 7:21 ` Aleksandr Khromov
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260921141515.759647f5@phoenix.local \
--to=stephen@networkplumber.org \
--cc=dev@dpdk.org \
--cc=haa@amicon.ru \
--cc=konstantin.ananyev@huawei.com \
--cc=olivier.matz@6wind.com \
--cc=rrv@amicon.ru \
--cc=sdl.dpdk@linuxtesting.org \
--cc=stable@dpdk.org \
--cc=thomas@monjalon.net \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.