mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Sasha Levin <sasha.levin@oracle.com>
To: linux-kernel@vger.kernel.org
Cc: Sasha Levin <sasha.levin@oracle.com>,
	Thomas Gleixner <tglx@linutronix.de>
Subject: [PATCH] time: do a safe overflow check in ktime_add_safe
Date: Mon,  1 Dec 2014 23:04:05 -0500	[thread overview]
Message-ID: <1417493050-13594-1-git-send-email-sasha.levin@oracle.com> (raw)

ktime_add_safe would check for overflows, but since ktime variables are
signed, overflowing them is an undefined behaviour and should be avoided.

Rather than checking for wraparound after the overflow, check for
potential overflowing values prior to adding both ktimes.

Signed-off-by: Sasha Levin <sasha.levin@oracle.com>
---
 kernel/time/hrtimer.c |    8 +++-----
 1 file changed, 3 insertions(+), 5 deletions(-)

diff --git a/kernel/time/hrtimer.c b/kernel/time/hrtimer.c
index 37e50aa..42fb631 100644
--- a/kernel/time/hrtimer.c
+++ b/kernel/time/hrtimer.c
@@ -290,16 +290,14 @@ EXPORT_SYMBOL_GPL(ktime_divns);
  */
 ktime_t ktime_add_safe(const ktime_t lhs, const ktime_t rhs)
 {
-	ktime_t res = ktime_add(lhs, rhs);
-
 	/*
 	 * We use KTIME_SEC_MAX here, the maximum timeout which we can
 	 * return to user space in a timespec:
 	 */
-	if (res.tv64 < 0 || res.tv64 < lhs.tv64 || res.tv64 < rhs.tv64)
-		res = ktime_set(KTIME_SEC_MAX, 0);
+	if (lhs.tv64 > (KTIME_MAX - rhs.tv64))
+		return ktime_set(KTIME_SEC_MAX, 0);
 
-	return res;
+	return ktime_add(lhs, rhs);
 }
 
 EXPORT_SYMBOL_GPL(ktime_add_safe);
-- 
1.7.10.4


             reply	other threads:[~2014-12-02  4:05 UTC|newest]

Thread overview: 7+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2014-12-02  4:04 Sasha Levin [this message]
2014-12-02  4:04 ` [PATCH] time: make sure tz_minuteswest is set to a valid value when setting time Sasha Levin
2014-12-02  4:04 ` [PATCH] vfs: calculate seek offsets using unsigned variables Sasha Levin
2014-12-02  4:04 ` [PATCH] mm: fadvise: avoid signed integer overflow calculating offset Sasha Levin
2014-12-02  4:04 ` [PATCH] time: settimeofday: validate the values of tv fomr user Sasha Levin
2014-12-02 11:16   ` Thomas Gleixner
2014-12-02  4:04 ` [PATCH] fs: sync_file_range: avoid overflowing signed calculation Sasha Levin

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=1417493050-13594-1-git-send-email-sasha.levin@oracle.com \
    --to=sasha.levin@oracle.com \
    --cc=linux-kernel@vger.kernel.org \
    --cc=tglx@linutronix.de \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®