From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-qv1-f54.google.com (mail-qv1-f54.google.com [209.85.219.54]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id E61B03FD94F for ; Tue, 21 Jul 2026 01:43:04 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.219.54 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784598186; cv=none; b=eSz5kK+iOoi2+VJt8m5A5pBZ8uesYK8gATrQYN5zTSse5g1lxJ1sLs3wBVF1Va6I/y5WRs8cxZkrVbExbs3jmutHp4p0E+q9UWPRO0CAbsZ2tUHZ/+G76plTL56RHAj1nD/Smw5PjV7V1BOIGeIrHbIUEdhag40bzqdtHjpZqzo= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784598186; c=relaxed/simple; bh=Cvd62BSbfK1YUoNmu2cB4JDmKSrIffYs7NUg+4REHIw=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=ISJi4be/XWKM3CJ+KgsX3eYVoMen0AmeW6ikHRTNT+AdiJobb9Z5Jv7FuOgYTD5uDoHtKxjJbPMJREQGgb4UeKGAtboUyb2C8jB6i2lsA5YP9esweOZ/IIr6WRHBanHkOs5L5ec31wcFjOlNPt5ZUnbXBQsRfQurpj1QopoX7zo= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=QqUNzFHZ; arc=none smtp.client-ip=209.85.219.54 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="QqUNzFHZ" Received: by mail-qv1-f54.google.com with SMTP id 6a1803df08f44-8f0d6853360so87231556d6.0 for ; Mon, 20 Jul 2026 18:43:04 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1784598184; x=1785202984; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=13+pPfiHFxOsE9sDGlKpSdwFAptP38k5m91XQ1ijMSw=; b=QqUNzFHZPzCG3pDpkkATGqBqa6u+IZ99mdtBjCquUHRCYlnlX97GWpgOD+vNDlehgt qI5PCOCWiBcWYPk2StSsk9ZcwxD6v8JQvbeb/+kLpmIuHj27AZ3B91+NsFK5Qa+W7QbB 27/1jFpsKrnxsIgLmO4wji95cSANXGwfvc5ioL2Nk6dxzeSC9xTcHBMWWlodQF6EEhv/ p4CR/zKXjOTsglJJyw6Wha81teM634eFSsWmtKQs+6RLiLOAQElyxiPu16z1N268G4wI bHDP4j9iwM7YoH9YtlR4ebowGSb3vqft1rDxuJrkVeVuXWTHPuRPyMsZ8+zEvv46Z70r HN+Q== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784598184; x=1785202984; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=13+pPfiHFxOsE9sDGlKpSdwFAptP38k5m91XQ1ijMSw=; b=IlruWXlp9V5qr3E0gvbBJgtvCuDacL4RxXpVgOT2yH1IiKJRdloPq2hKzWEEulfko/ 3548VhFMdzxtrbl3P8Kw75tKhX6G+G7JFJR2+t01xLOkHQn3CspDNTu3TdrqhOMnkAW/ ISt5zQZMRLo75ZnhQBxXSrlR2qCjokTP/GXINlUq9IpAagDF1ap7K6Wia5Bb9rqq7VVS 8ABNbgjo8kcZsP8rkzhS+UG8SWrDDl5Qne6QC0vEn6mPoXK6UAyDSQ39n/4JXITNjJK4 4tlWC/YplkdGrto6oGs34AZZ/4sb7lLqVzD43LPbbx0XvH5sN8AC6uCGZ4ZlNjNuGVo3 fNxA== X-Gm-Message-State: AOJu0YzeJZLVui/m7myzn2fZ18OATz1J0dWOyDWUu5n+hvvijFT0+m4U xUhWZF3FAThpwoiaGUR6z9GyRQzQY82aAs3BhTv4b9xyTSljTR2o/dB0 X-Gm-Gg: AR+sD11rONYXt6oJ7OXpvFEhFnxAtTe+3EtRoBvPs0ucCx1ZE85I14oa+kE14nEXULX N6cr9lPhsv2tdbMlpifsbihct8G6YD3cSN8K79OUw+rsXDjMu9G/iQnbYjphmEKhSGYbOYHL8NI uffTDHRrtsEjspCkHUYKDHZ/Ubj93cUpA4B0tQlelQdyAtyevPDJvaw2+lq7CCRLLhhoSTySBzn igngiHw9mfm9Wg/Ej6JhsWlb5uvxkCmUMe0m9VhJxUlMzXDRdjxo9Ff7ceRBYbH/befFrYw7/25 5t7Y0iLLdC6h2I8I7XRUuyCJHPJNX9B3i/xbPJVRkb8de6ki2K8bS6TAwxZPSHsmbWHy3iHSxW2 PFwE+g7yAjxG9QPYk2Cs03KoKnxS/qII8RLQ5p/mKY8miA3FVSkGKih3X0u0HYvBDlG4iWek9YA E6AMt9B5aayZoTqjk+mDVbQlpw0beSSBmv/PtSGH+BIlsa+snA5llbhG6+6Ej9dp2/Fv9ZYaS0b 94QIUe7tqV9+ea2+Ftk7kZnvdA= X-Received: by 2002:ad4:5d63:0:b0:8ef:e857:c9d6 with SMTP id 6a1803df08f44-90778357dafmr156356076d6.22.1784598183672; Mon, 20 Jul 2026 18:43:03 -0700 (PDT) Received: from ip-172-31-15-253.ec2.internal (ec2-13-222-20-6.compute-1.amazonaws.com. [13.222.20.6]) by smtp.gmail.com with ESMTPSA id 6a1803df08f44-9077871f650sm104418266d6.45.2026.07.20.18.43.03 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 20 Jul 2026 18:43:03 -0700 (PDT) From: Deep Shah To: netdev@vger.kernel.org, Richard Cochran , "David S . Miller" , Jakub Kicinski , Paolo Abeni , Eric Dumazet , Andrew Lunn Cc: linux-kernel@vger.kernel.org, linux-kselftest@vger.kernel.org, Shuah Khan , Vadim Fedorenko , Simon Horman , Deep Shah Subject: [PATCH v2 net 2/2] selftests: ptp: add a regression test for the frequency adjustment overflow Date: Tue, 21 Jul 2026 01:42:56 +0000 Message-ID: <20260721014256.1876-3-deepshah146@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260721014256.1876-1-deepshah146@gmail.com> References: <20260721014256.1876-1-deepshah146@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit testptp's -f option stores the requested adjustment as an int ppb and converts it to scaled ppm, so it cannot express the 64-bit scaled-ppm values needed to overflow scaled_ppm_to_ppb() and bypass the max_adj check enforced by ptp_clock_adjtime(). Add a small test that crafts struct timex.freq directly and verifies that an overflowing frequency adjustment is rejected with -ERANGE. The test skips when no frequency-adjustable PTP device is available. Signed-off-by: Deep Shah --- tools/testing/selftests/ptp/Makefile | 2 +- .../testing/selftests/ptp/ptp_freq_overflow.c | 99 +++++++++++++++++++ 2 files changed, 100 insertions(+), 1 deletion(-) create mode 100644 tools/testing/selftests/ptp/ptp_freq_overflow.c diff --git a/tools/testing/selftests/ptp/Makefile b/tools/testing/selftests/ptp/Makefile index 8f57f88ecadd..dd7376cc9bf5 100644 --- a/tools/testing/selftests/ptp/Makefile +++ b/tools/testing/selftests/ptp/Makefile @@ -1,6 +1,6 @@ # SPDX-License-Identifier: GPL-2.0 CFLAGS += $(KHDR_INCLUDES) -TEST_GEN_PROGS := testptp +TEST_GEN_PROGS := testptp ptp_freq_overflow LDLIBS += -lrt TEST_PROGS = phc.sh diff --git a/tools/testing/selftests/ptp/ptp_freq_overflow.c b/tools/testing/selftests/ptp/ptp_freq_overflow.c new file mode 100644 index 000000000000..417c0516622d --- /dev/null +++ b/tools/testing/selftests/ptp/ptp_freq_overflow.c @@ -0,0 +1,99 @@ +// SPDX-License-Identifier: GPL-2.0 +/* + * Regression test for the scaled_ppm_to_ppb() integer overflow that allowed + * a crafted clock_adjtime(ADJ_FREQUENCY) to bypass the PTP max_adj check. + * + * testptp's -f option stores the adjustment as an int ppb and cannot express + * the 64-bit scaled-ppm values needed to overflow the conversion, so this + * test crafts struct timex.freq directly. + */ +#define _GNU_SOURCE +#define __SANE_USERSPACE_TYPES__ +#include +#include +#include +#include +#include +#include +#include +#include +#include "../kselftest.h" + +#define FD_TO_CLOCKID(fd) ((clockid_t)((((unsigned int)~(fd)) << 3) | 3)) + +/* clock_adjtime is not available in GLIBC < 2.14 */ +#if !__GLIBC_PREREQ(2, 14) +#include +static int clock_adjtime(clockid_t id, struct timex *tx) +{ + return syscall(__NR_clock_adjtime, id, tx); +} +#endif + +int main(int argc, char *argv[]) +{ + const char *device = argc > 1 ? argv[1] : "/dev/ptp0"; + struct ptp_clock_caps caps; + struct timex restore = { 0 }; + struct timex tx = { 0 }; + clockid_t clkid; + int fd, ret; + + ksft_print_header(); + ksft_set_plan(1); + + if (sizeof(tx.freq) < 8) + ksft_exit_skip("the overflow only affects 64-bit kernels\n"); + + fd = open(device, O_RDWR); + if (fd < 0) + ksft_exit_skip("cannot open %s: %s\n", device, strerror(errno)); + + clkid = FD_TO_CLOCKID(fd); + + if (ioctl(fd, PTP_CLOCK_GETCAPS, &caps)) + ksft_exit_skip("PTP_CLOCK_GETCAPS on %s: %s\n", device, strerror(errno)); + if (!caps.max_adj) + ksft_exit_skip("%s does not support frequency adjustment\n", device); + + /* + * Remember the current frequency. A vulnerable kernel accepts the + * bogus value below and programs it into the hardware, so restore the + * original afterwards instead of leaving the clock corrupted. + */ + if (clock_adjtime(clkid, &restore)) + ksft_exit_skip("clock_adjtime(get) on %s: %s\n", device, strerror(errno)); + restore.modes = ADJ_FREQUENCY; + + /* + * (1 + 147573952589676412) * 125 == 2^64 + 9, which overflows s64 in + * scaled_ppm_to_ppb() and wraps the result to a ppb of 0. A kernel + * that does not detect the overflow lets this absurd frequency past + * the max_adj check; a fixed kernel rejects it with -ERANGE. + */ + tx.modes = ADJ_FREQUENCY; +#if __SIZEOF_LONG__ >= 8 + tx.freq = 147573952589676412L; +#endif + + ret = clock_adjtime(clkid, &tx); + if (ret < 0 && errno == EBUSY) { + /* + * A free-running physical clock (virtual clocks active) rejects + * frequency adjustment with -EBUSY before the overflow is even + * evaluated, so the test cannot run here. + */ + ksft_test_result_skip("%s: frequency adjustment returned EBUSY, skipping\n", + device); + } else { + ksft_test_result(ret < 0 && errno == ERANGE, + "overflowing frequency adjustment is rejected (ret=%d errno=%d)\n", + ret, ret < 0 ? errno : 0); + } + + /* put the frequency back the way we found it */ + clock_adjtime(clkid, &restore); + + close(fd); + ksft_finished(); +} -- 2.43.0