diff options
| author | Zhan Xusheng <zhanxusheng1024@gmail.com> | 2026-09-28 10:02:05 +0800 |
|---|---|---|
| committer | Joel Granados <joel.granados@kernel.org> | 2026-09-29 10:00:40 +0200 |
| commit | fdd6553e1e53b0421d89c7469c8a36d2eadb1115 (patch) | |
| tree | 86b8ee26e41c65883a283f114e365abfcb79163e /kernel | |
| parent | e955f14fa8467d70aaeea5830b4d1773d5b25500 (diff) | |
time/jiffies: Saturate in mult_hz() instead of wrapping
Return ULONG_MAX for values that don't fit an unsigned long.
proc_int_u2k_conv_uop() now correctly rejects a result above INT_MAX.
This is the erroneous behaviour that is being fixed. The input has to
exceed ULONG_MAX / HZ for the product to wrap, so the value below is
specific to CONFIG_HZ=1000:
# echo 18446744073709552 > /proc/sys/net/ipv4/tcp_keepalive_time
# cat /proc/sys/net/ipv4/tcp_keepalive_time
0
That value is now rejected with an error.
The original bound ("*u_ptr > INT_MAX / HZ") was removed in commit
2dc164a48e6f ("sysctl: Create converter functions with two new macros").
Fixes: 2dc164a48e6f ("sysctl: Create converter functions with two new macros")
Cc: stable@vger.kernel.org
Signed-off-by: Zhan Xusheng <zhanxusheng@xiaomi.com>
Signed-off-by: Joel Granados <joel.granados@kernel.org>
Diffstat (limited to 'kernel')
| -rw-r--r-- | kernel/time/jiffies.c | 2 |
1 files changed, 2 insertions, 0 deletions
diff --git a/kernel/time/jiffies.c b/kernel/time/jiffies.c index 80c354811538..9b3487d40cd6 100644 --- a/kernel/time/jiffies.c +++ b/kernel/time/jiffies.c @@ -101,6 +101,8 @@ void __init register_refined_jiffies(long cycles_per_second) #ifdef CONFIG_SYSCTL static ulong mult_hz(const ulong val) { + if (val >= ULONG_MAX / HZ) + return ULONG_MAX; return val * HZ; } |
