All of lore.kernel.org
 help / color / mirror / Atom feed
From: Avinesh Kumar via ltp <ltp@lists.linux.it>
To: Cyril Hrubis <chrubis@suse.cz>
Cc: ltp@lists.linux.it
Subject: Re: [LTP] openposix: timer_*/speculative: Skip untestable optional behavior on Linux
Date: Mon, 31 Aug 2026 18:38:11 +0200	[thread overview]
Message-ID: <dc0b87e0-3aec-49e4-8451-b7189420e654@suse.com> (raw)
In-Reply-To: <apVUR0360UHO0KMt@yuki.lan>

Hi Cyril,

On 8/31/26 12:15 PM, Cyril Hrubis wrote:
> Hi!
>>> openposix: timer_*/speculative: Skip untestable optional behavior on Linux
>>
>>> +#ifdef __linux__
>>> +	printf("Linux does not implement this optional behavior\n");
>>> +	return PTS_UNSUPPORTED;
>>> +#else
>>
>> Could these branches be removed from all eleven tests? Linux 7.2 uses
>> scoped_timer_get_or_fail() to return -EINVAL for invalid timer IDs in
>> timer_gettime(), timer_getoverrun(), timer_settime(), and timer_delete().
>> The installed man pages document the same EINVAL result.
>>
>> More directly, every pre-patch test reports errno == EINVAL and returns
>> PTS_PASS when built and run on Linux. The platform check therefore replaces
>> working coverage with PTS_UNSUPPORTED, and the quoted runtime message is not
>> accurate.
> 
> That's the kernel part, apparently it's more complex in libc.
> 
> Libc has two types of timer_t values, either it's a directly kernel
> timer id (small int) or a pointer to a structure that holds the id.
> 
> The timer libc functions, before calling the kernel syscall, convert the
> libc timer id into kernel timer id with:
> 
> static inline kernel_timer_t
> timerid_to_kernel_timer (timer_t timerid)
> {
>    if (timer_is_sigev_thread (timerid))
>      return timerid_to_timer (timerid)->ktimerid;
>    else
>      return (kernel_timer_t) ((uintptr_t) timerid);
> }
> 
> The library does a bit of magic with the pointers:
> 
> https://codebrowser.dev/glibc/glibc/sysdeps/unix/sysv/linux/kernel-posix-timers.h.html
> 
> But overall it checks the MSB bit of the pointer to figure out if it's
> kernel timer id which should be passed verbatim, or a structure that
> needs to be dereferenced.
> 
> Looking at the timer_gettime/speculative/6-1.c we do pass a pointer to
> the stack (instead of the invalid value) which on 32bit may be an
> address with the MSB bit set. So this triggers undefined behavior, since
> glibc thinks it's a pointer to it's internal data structure, but the
> real pointer the glibc exports as the timer is bit-shifted. Hence we
> access random and possibly invalid address. With some luck that address
> is accesible and contains non-zero data and we end up passing invalid
> timer ID to the kernel, but when I straced the test, the value was
> pretty much random.
> 

I was also trying to understand the sign bit usage and bit shifting
magic in this glibc code, causing this issue. Thanks for explaining
this clearly. I have send revised patch -
https://lore.kernel.org/ltp/20260831163310.137399-1-avinesh.kumar@suse.com/T/#u


Regards,
Avinesh

> With that in mind, we can fix the test with passing the BOGUSID instead
> of random stack pointer:
> 
> diff --git a/testcases/open_posix_testsuite/conformance/interfaces/timer_gettime/speculative/6-1.c b/testcases/open_posix_testsuite/conformance/interfaces/timer_gettime/speculative/6-1.c
> index d09c2f709..c35dd816f 100644
> --- a/testcases/open_posix_testsuite/conformance/interfaces/timer_gettime/speculative/6-1.c
> +++ b/testcases/open_posix_testsuite/conformance/interfaces/timer_gettime/speculative/6-1.c
> @@ -21,8 +21,7 @@ int test_main(int argc PTS_ATTRIBUTE_UNUSED, char **argv PTS_ATTRIBUTE_UNUSED)
>   {
>          timer_t tid;
>          struct itimerspec its;
> -       int tval = BOGUSTID;
> -       tid = (timer_t) & tval;
> +       tid = (timer_t) BOGUSTID;
>          if (timer_gettime(tid, &its) == -1) {
>                  if (EINVAL == errno) {
>                          printf("fcn returned -1 and errno==EINVAL\n");
> 



-- 
Mailing list info: https://lists.linux.it/listinfo/ltp

      reply	other threads:[~2026-08-31 16:38 UTC|newest]

Thread overview: 5+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-08-19  9:31 [LTP] [PATCH v2] openposix: timer_*/speculative: Skip untestable optional behavior on Linux Avinesh Kumar via ltp
2026-08-19 10:33 ` [LTP] " linuxtestproject.agent
2026-08-27  7:07   ` Andrea Cervesato via ltp
2026-08-31 10:15   ` Cyril Hrubis
2026-08-31 16:38     ` Avinesh Kumar via ltp [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=dc0b87e0-3aec-49e4-8451-b7189420e654@suse.com \
    --to=ltp@lists.linux.it \
    --cc=avinesh.kumar@suse.com \
    --cc=chrubis@suse.cz \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.