From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-qt1-f171.google.com (mail-qt1-f171.google.com [209.85.160.171]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 4757B288BA for ; Sat, 1 Aug 2026 22:29:26 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.160.171 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785623368; cv=none; b=X4v+3xprJF0ndZQ0AmMipGKs5G3IuAJVvzLa/gF9+GuqZfqkIPRNIeChpQcSs6ujJNW9WaO+JoX3xuIiSeJFZZICr5aSZYMGD8oi8C2a70eSClPOcxVA7uwzOVKK7zU2FO1PwdX/sIScZlR6UhRnK0oqny04CQgw65uJIOVbrF4= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785623368; c=relaxed/simple; bh=1Gw9vWPrfRCTzHFJ2sAvaTRJm7NJukBvxnv7HCFp5Rg=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=m04aXpkf8cRwjQypuZa9JmtOvtKXIK/EtrMncK2RWbboR6m3ealigJvCxHupFhK6FwCOnlfxDzjRQf0OHhsnt7a9/4bgyz8xkgLDeyob7NalutDGk2KFLN42J3EVbQ9Lo3xsA/IRbuoYagD6vMu6cL2Ns/ZZQk2cRWkWlFvpR/8= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=M8cGmM4X; arc=none smtp.client-ip=209.85.160.171 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="M8cGmM4X" Received: by mail-qt1-f171.google.com with SMTP id d75a77b69052e-52b4e988c77so8694191cf.3 for ; Sat, 01 Aug 2026 15:29:26 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1785623365; x=1786228165; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=MdyeTfAUUQXGl2cyRUlJj9U9a1L8ImHdvXwmoKXqi2U=; b=M8cGmM4XZ5NvSjTRRSQ6jLPgqktuUT0yOi1bhPMRkDE/OliBGt6rlvs013nLVSULu2 gtosw+FpIy23vTLcc5UqUZrbbCBa+DSHXyOdgUi8D0FIoGI4HUujbG3So423eF06MqE0 2YMfI8iq4tUSFYp7F7SpBiO0CkWrUuikprrRZSpbfxxjbYzXYBHukVz5QnDqc96F9pzL WLqXCTC7yIXd7bdT6xAUPfbLOBVDvkpP77i/ztJOZ0mORHg0T0CC9Nr9rHm4GoUdm5Z6 YDAd/zQjDdhuKafekpBlG+ydPW/nHPgdgATPZ3nbDKUfjoLaGblR1bTl/ZFGCwuoN6AB T8tw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785623365; x=1786228165; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=MdyeTfAUUQXGl2cyRUlJj9U9a1L8ImHdvXwmoKXqi2U=; b=E4gTA6CJ50ahajY65KvQatAFkrcKCGeT9r2RzXlV1sBFXzk6TURvzFclR5pp+Epizw qb90huMsez8iFc4a4O7aV4KJOKA6d9Fv0ZmgNKVcaBvj4rHzdEFVH9iMd8RDyyfB5HM2 qL1eVyph1LR3sqQ5lfAeaH/csSh8+0bRBg7o/L6qtPDCqSSbghO/zsuBIrzWF1b6ABH4 XXXVjfpvx01mWrr7Gy+dyXQandschH2CiorFtXML6linDfORRfmhv73i5PMHQISgye+B An9uuRZy08s2Wmd5nconHaIoeHXfx2gIfqkjz/biLzCf5b4sJOES0v2dhOSpkH5OJntB mZpQ== X-Gm-Message-State: AOJu0Yzxl4151A+ruFfmRodU1SvT1WYzKnc/iErdyrg6TDJpzBG4xrY3 rhX4AYVIGHYvj9FKXDOPzf8sugoCyey1HOi+9vpsVuSVJV7rtODhen3f X-Gm-Gg: AR+sD11OzWh3GbLZDAaVfiW6MPSoc5ONpnhtfrXGsg1+zpGE/MXnp/eVoFB5Lu1IsLQ EAne4QUqv0xCLBoeSaNXxNTZfEvGgB/hPhFAcVWb4D2VywvPTH+bs0OocAS3QY2txpmmCKs1x/z R+Q4ofzCjaaLOndz8wU2enTeUtAQInugIJy0ovToQk11UgOB+cYiq2O3YmtMj66TuR0kakcWCmK JVsvuthmBbjjJbfB07Pxr/Qfmw0TuiJYrTXAcLTKmd56vWVIaWgK1y1nKY01t5n3z9VtgWiiXAn ncGnyUZObH9mABNjyB55QPBn/xXcNbJ9j4LZ/ppS8Rb05uDE0VfqHrT74PWgSskbt+4mBoWPPYg h+E2exjX0z3mf5ywTBxSttL6v503wg/EiYWK3FviHEiQV6+yPlN+vBfTa0xL2mnHAW8+H4ebnsl uiYkftUp4nyzIdo4bb851BDNKQN4cvuq/96UAA7i+etMNg2S7s3sD3CLE4y4WSWJpW4ku5Dc7Y4 kyVlELtpEpGvzt3ZUGM82+pqR/TmAALkSacs0j6+I2aai331EX/dHFGgXK60qgt6k6AERAa0o+z GGrEN90s037s/q0= X-Received: by 2002:ac8:574d:0:b0:519:89b6:78b4 with SMTP id d75a77b69052e-52b567dab59mr95475271cf.40.1785623365113; Sat, 01 Aug 2026 15:29:25 -0700 (PDT) Received: from ip-172-31-15-253.ec2.internal (ec2-32-195-55-166.compute-1.amazonaws.com. [32.195.55.166]) by smtp.gmail.com with ESMTPSA id d75a77b69052e-52b4eb956c3sm33403831cf.22.2026.08.01.15.29.23 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sat, 01 Aug 2026 15:29:24 -0700 (PDT) From: Deep Shah To: netdev@vger.kernel.org, Richard Cochran , "David S . Miller" , Jakub Kicinski , Paolo Abeni , Eric Dumazet , Andrew Lunn Cc: linux-kernel@vger.kernel.org, linux-kselftest@vger.kernel.org, Shuah Khan , Vadim Fedorenko , Simon Horman , Deep Shah Subject: [PATCH net-next v3 0/2] ptp: reject frequency adjustments that overflow scaled_ppm_to_ppb() Date: Sat, 1 Aug 2026 22:29:21 +0000 Message-ID: <20260801222923.39017-1-deepshah146@gmail.com> X-Mailer: git-send-email 2.43.0 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit ptp_clock_adjtime() validates an ADJ_FREQUENCY request by converting tx->freq to ppb and comparing it against ops->max_adj. On 64-bit systems that conversion can overflow s64 and wrap the result back into range, so a crafted tx->freq bypasses the check and reaches ->adjfine() unclamped. No real user space asks for such a frequency, so this is hardening rather than a fix anyone is waiting on, and it is targeted at net-next with no Fixes tag per Jakub's feedback on v2. Patch 1 rejects the overflow in ptp_clock_adjtime(). Patch 2 adds a regression test that crafts struct timex.freq directly (testptp's int-ppb path cannot express the value) and confirms it is rejected with -ERANGE. Changes in v3: - retarget at net-next and drop the Fixes tag (Jakub Kicinski) - patch 1: unchanged - patch 2: - cast the test value to the type of tx.freq rather than guarding on __SIZEOF_LONG__, which skipped the assignment on x32 and other y2038 configurations and failed the test there (Simon Horman) - add the built binary to .gitignore Changes in v2: - patch 1: added Reviewed-by from Vadim Fedorenko. - patch 2 (all from Simon Horman's review): - cast fd to unsigned before the shift in FD_TO_CLOCKID (UBSan) - avoid a -Woverflow warning on 32-bit - save and restore the clock frequency - skip instead of fail on -EBUSY (free-running clock) Link to v1: https://lore.kernel.org/netdev/20260712040922.6403-1-deepshah146@gmail.com/ Link to v2: https://lore.kernel.org/netdev/20260721014256.1876-1-deepshah146@gmail.com/ Deep Shah (2): ptp: reject frequency adjustments that overflow scaled_ppm_to_ppb() selftests: ptp: add a regression test for the frequency adjustment overflow drivers/ptp/ptp_clock.c | 14 ++- tools/testing/selftests/ptp/.gitignore | 1 + tools/testing/selftests/ptp/Makefile | 2 +- .../testing/selftests/ptp/ptp_freq_overflow.c | 101 ++++++++++++++++++ 4 files changed, 116 insertions(+), 2 deletions(-) create mode 100644 tools/testing/selftests/ptp/ptp_freq_overflow.c base-commit: 69963a0678a347d57c4ac8b16939dba216eb95ce -- 2.43.0