diff options
| author | Zhan Xusheng <zhanxusheng1024@gmail.com> | 2026-09-28 10:02:05 +0800 |
|---|---|---|
| committer | Joel Granados <joel.granados@kernel.org> | 2026-09-28 15:43:06 +0200 |
| commit | 4991c8b72b564cd16cb48124f880617fd49f1013 (patch) | |
| tree | 0a71711563f67253db4768d20122f4634d9e48f0 /tools/testing/selftests/bpf/prog_tests/btf_dump.c | |
| parent | b60237dc2146b45b0a6f72d2645220bd9fb4cb81 (diff) | |
| download | linux-next-4991c8b72b564cd16cb48124f880617fd49f1013.tar.gz linux-next-4991c8b72b564cd16cb48124f880617fd49f1013.zip | |
time/jiffies: Saturate in mult_hz() instead of wrapping
mult_hz() converts a user-supplied seconds value to jiffies for
proc_dointvec_jiffies(). proc_int_u2k_conv_uop() rejects a result above
INT_MAX, but it inspects the product, so a product that wraps arrives as a
small value and is stored.
The input has to exceed ULONG_MAX / HZ for the product to wrap, so the
value below is specific to CONFIG_HZ=1000:
# echo 18446744073709552 > /proc/sys/net/ipv4/tcp_keepalive_time
# cat /proc/sys/net/ipv4/tcp_keepalive_time
0
18446744073709551, one less, is correctly rejected. Dozens of sysctls
use proc_dointvec_jiffies(), among them tcp_keepalive_time,
tcp_fin_timeout and the conntrack timeouts.
Bound the input in the shape clock_t_to_jiffies() already uses and leave
the INT_MAX policy to the caller. The bound was open-coded as
"*lvalp > INT_MAX / HZ" until commit 2dc164a48e6f ("sysctl: Create
converter functions with two new macros").
Fixes: 2dc164a48e6f ("sysctl: Create converter functions with two new macros")
Cc: stable@vger.kernel.org
Signed-off-by: Zhan Xusheng <zhanxusheng@xiaomi.com>
Signed-off-by: Joel Granados <joel.granados@kernel.org>
Diffstat (limited to 'tools/testing/selftests/bpf/prog_tests/btf_dump.c')
0 files changed, 0 insertions, 0 deletions
