Skip to content

sysctl: Two jiffies converter regressions from 2dc164a48e6f - #2661

Closed
vfsci-bot[bot] wants to merge 2 commits into
vfs.base.cifrom
pw/1170939/vfs.base.ci
Closed

vfsci-bot[bot] wants to merge 2 commits into
vfs.base.cifrom
pw/1170939/vfs.base.ci

Conversation

@vfsci-bot

@vfsci-bot vfsci-bot Bot commented Sep 22, 2026

Copy link
Copy Markdown

Series: https://patchwork.kernel.org/project/linux-fsdevel/list/?series=1170939
Submitter: Zhan Xusheng
Version: 1
Patches: 2/2
Message-ID: <20260922031229.2300283-1-zhanxusheng@xiaomi.com>
Base: vfs.base.ci
Lore: https://lore.kernel.org/linux-fsdevel/20260922031229.2300283-1-zhanxusheng@xiaomi.com


Automated by ml2pr

proc_int_k2u_conv_kop() reports the sign through *negp and the magnitude
through *u_ptr, but for a negative value it hands the sign-extended int to
the converter and negates the result:

	*u_ptr = k_ptr_op ? -k_ptr_op((ulong)val) : -(ulong)val;

With div_hz() and HZ=1000 a stored -1000 becomes
(ulong)-1000 / 1000 == 18446744073709550, and negating that wraps:

	# echo -1 > /proc/sys/net/ipv4/tcp_fin_timeout
	# cat /proc/sys/net/ipv4/tcp_fin_timeout
	-18428297329635842066

Take the magnitude first and convert that, which is what the open-coded
version did before commit 2dc164a ("sysctl: Create converter
functions with two new macros") folded it into a macro.  The
k_ptr_op == NULL branch was already correct.

proc_dointvec_jiffies() and proc_dointvec_ms_jiffies() are affected.

Fixes: 2dc164a ("sysctl: Create converter functions with two new macros")
Cc: stable@vger.kernel.org
Signed-off-by: Zhan Xusheng <zhanxusheng@xiaomi.com>
mult_hz() converts a user-supplied seconds value to jiffies for
proc_dointvec_jiffies().  proc_int_u2k_conv_uop() rejects a result above
INT_MAX, but it inspects the product, so a product that wraps arrives as a
small value and is stored:

	# echo 18446744073709552 > /proc/sys/net/ipv4/tcp_keepalive_time
	# cat /proc/sys/net/ipv4/tcp_keepalive_time
	0

One less is rejected; that value wraps to 384 jiffies at HZ=1000.  65
sysctls use proc_dointvec_jiffies(), among them tcp_keepalive_time,
tcp_fin_timeout and the conntrack timeouts.

Bound the input in the shape clock_t_to_jiffies() already uses and leave
the INT_MAX policy to the caller.  The bound was open-coded as
"*lvalp > INT_MAX / HZ" until commit 2dc164a ("sysctl: Create
converter functions with two new macros").

Fixes: 2dc164a ("sysctl: Create converter functions with two new macros")
Cc: stable@vger.kernel.org
Signed-off-by: Zhan Xusheng <zhanxusheng@xiaomi.com>
@vfsci-bot

vfsci-bot Bot commented Sep 28, 2026

Copy link
Copy Markdown
Author

Superseded by series 1174867 (v2). Closing automatically.


Automated by ml2pr

@vfsci-bot vfsci-bot Bot closed this Sep 28, 2026
@vfsci-bot
vfsci-bot Bot deleted the pw/1170939/vfs.base.ci branch September 28, 2026 04:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant