mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Zhan Xusheng <zhanxusheng1024@gmail.com>
To: tglx@kernel.org, thomas.weissschuh@linutronix.de
Cc: luto@kernel.org, vincenzo.frascino@arm.com,
	david.laight.linux@gmail.com, linux-kernel@vger.kernel.org,
	zhanxusheng@xiaomi.com
Subject: [PATCH v5 4/4] vdso/gettimeofday: Assert that the clockid fits into the u32 bitmask
Date: Wed, 16 Sep 2026 10:32:52 +0800	[thread overview]
Message-ID: <20260916023252.418473-5-zhanxusheng@xiaomi.com> (raw)
In-Reply-To: <20260916023252.418473-1-zhanxusheng@xiaomi.com>

__cvdso_clock_gettime_common() and __cvdso_clock_getres_common() convert
the clockid into a bitmask and match it against VDSO_HRES, VDSO_COARSE,
VDSO_RAW and VDSO_AUX:

	msk = 1U << clock;

vdso_clockid_valid() rejects anything above CLOCK_AUX_LAST beforehand,
and CLOCK_AUX_LAST is 23, so the shift count is in range.  Nothing
records that dependency though.  Raising MAX_AUX_CLOCKS beyond 16 moves
CLOCK_AUX_LAST to 32 and makes the shift undefined.

Add a BUILD_BUG_ON() at both conversion sites.  The condition is on a
function parameter rather than a constant, so it relies on the compiler
deriving the range from the vdso_clockid_valid() bail-out above it.  gcc
13 and clang 18 both do: the x86 vdso64 and vdso32 builds stay clean, and
raising MAX_AUX_CLOCKS to 17 trips the assert.

Suggested-by: Thomas Weißschuh <thomas.weissschuh@linutronix.de>
Signed-off-by: Zhan Xusheng <zhanxusheng@xiaomi.com>
Reviewed-by: Thomas Weißschuh <thomas.weissschuh@linutronix.de>
---
 lib/vdso/gettimeofday.c | 2 ++
 1 file changed, 2 insertions(+)

diff --git a/lib/vdso/gettimeofday.c b/lib/vdso/gettimeofday.c
index f7a591aba59f..ef4dcc614489 100644
--- a/lib/vdso/gettimeofday.c
+++ b/lib/vdso/gettimeofday.c
@@ -285,6 +285,7 @@ __cvdso_clock_gettime_common(const struct vdso_time_data *vd, clockid_t clock,
 	 * Convert the clockid to a bitmask and use it to check which
 	 * clocks are handled in the VDSO directly.
 	 */
+	BUILD_BUG_ON(clock >= BITS_PER_TYPE(msk));
 	msk = 1U << clock;
 	if (likely(msk & VDSO_HRES))
 		vc = &vc[CS_HRES_COARSE];
@@ -438,6 +439,7 @@ bool __cvdso_clock_getres_common(const struct vdso_time_data *vd, clockid_t cloc
 	 * Convert the clockid to a bitmask and use it to check which
 	 * clocks are handled in the VDSO directly.
 	 */
+	BUILD_BUG_ON(clock >= BITS_PER_TYPE(msk));
 	msk = 1U << clock;
 	if (msk & (VDSO_HRES | VDSO_RAW)) {
 		/*
-- 
2.43.0


  parent reply	other threads:[~2026-09-16  2:33 UTC|newest]

Thread overview: 11+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-16  2:32 [PATCH v5 0/4] vdso: Keep the CLOCK_AUX base at full precision Zhan Xusheng
2026-09-16  2:32 ` [PATCH v5 1/4] vdso/math64: Use OPTIMIZER_HIDE_VAR() in __iter_div_u64_rem() Zhan Xusheng
2026-09-25  7:44   ` Thomas Weißschuh
2026-09-29 19:27   ` [tip: timers/vdso] " tip-bot2 for Zhan Xusheng
2026-09-16  2:32 ` [PATCH v5 2/4] vdso/math64: Add and use __iter_div64_u64_rem() Zhan Xusheng
2026-09-29 19:27   ` [tip: timers/vdso] " tip-bot2 for Zhan Xusheng
2026-09-16  2:32 ` [PATCH v5 3/4] vdso/vsyscall: Keep the CLOCK_AUX base scaled Zhan Xusheng
2026-09-29 19:27   ` [tip: timers/vdso] " tip-bot2 for Zhan Xusheng
2026-09-16  2:32 ` Zhan Xusheng [this message]
2026-09-29 19:27   ` [tip: timers/vdso] vdso/gettimeofday: Assert that the clockid fits into the u32 bitmask tip-bot2 for Zhan Xusheng
2026-09-30 12:41 ` [PATCH v5 0/4] vdso: Keep the CLOCK_AUX base at full precision Thomas Gleixner

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260916023252.418473-5-zhanxusheng@xiaomi.com \
    --to=zhanxusheng1024@gmail.com \
    --cc=david.laight.linux@gmail.com \
    --cc=linux-kernel@vger.kernel.org \
    --cc=luto@kernel.org \
    --cc=tglx@kernel.org \
    --cc=thomas.weissschuh@linutronix.de \
    --cc=vincenzo.frascino@arm.com \
    --cc=zhanxusheng@xiaomi.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®