From nobody Mon Dec 1 21:30:53 2025 Received: from mail-pg1-f175.google.com (mail-pg1-f175.google.com [209.85.215.175]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id CFD6B25524C for ; Fri, 28 Nov 2025 03:39:00 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.215.175 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1764301142; cv=none; b=AFdzVeFXW0svpQkur0LOtIpZQ9JWzRwrvv6MqbOrUnbjsnBjscF+uiRzlyHDfGgZeiM/xLvABAWA0VHuq+unc+LpDhe/GE9ylcIz8yqBBVnHuqOtPNt0bY/pgVxDcB1epN9croKoUIO2eDmEXoRenQ6Z2/QwKhxJVBue5zmQTn0= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1764301142; c=relaxed/simple; bh=iuY0eu+BymU387rMM1XJMjI1HagYP3+/DvDnpdvKptk=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=sbCPPyBvvANZJUL4zPf42zhc6eHuEVE7xWMWKziPoqGlJSM9hsx3Ie+3i2mmaUrfm+PfECvmKQV4nrtDUnexifobhE1tn2dvX3tfJ90rvJUEB0ETkOKsADbccHMQ1bXH04orWLAVPg02G1qE1RlVD0mRfuQ0d5I8DPZ2ppg6kHE= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=OzJwr4NI; arc=none smtp.client-ip=209.85.215.175 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="OzJwr4NI" Received: by mail-pg1-f175.google.com with SMTP id 41be03b00d2f7-bc09b3d3b06so808594a12.2 for ; Thu, 27 Nov 2025 19:39:00 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20230601; t=1764301140; x=1764905940; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to; bh=iwhniX0ZJtvZTg2p7tVmTaAUVb8Ox0D0lnQSPuzqilw=; b=OzJwr4NI/xv+qcQU9npxhzsw4koNsI3exa4k3uac+VKLDHR2B6fDwifd2N75bF4QGq mk8l5gZE2pF6kW3NJo8e5R3NkEKbSZbym0p3QcOWUQoLUCb8WAg6zLrVQV/vmhV5u4M4 57kZ05d8v7Le1tT6PZ1kljCFSipbo4wyXzstF45wBShjr1IJeUY/ECR2kvrPgdu214sL GOdE/mLL58+dblXw1ySwyDjGwGrtu+62h7EAlgYCln6CR0t0jmT3kLIv9oMiPgOXOcoK LvVJdlCNHWYp9d7DopbvIvPxm3cWuLfzqjg5wUXiVaS2MVDNMmvrKg5EuiCP+APMSJ+1 xWaQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1764301140; x=1764905940; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to; bh=iwhniX0ZJtvZTg2p7tVmTaAUVb8Ox0D0lnQSPuzqilw=; b=nT/XQ4HDojIrolBsk3jioqTMe09S4iVVWCf/PBjI5+DqViLNuhiDDSnATEoClkl6n7 weFLpuqZj9UGPZ+ijh83ECjcA6XWJI0/tnGXE5X3h16PPMbze+Z4kz6CoboaRq2CgS0M pk/clOqiqYeJHi8FBHDXSBI9rP3wEtE3VTReHTCaSpAPikT+0pfEB1iJ2s6UlKp31fAJ nCsREkq9KHqCVNFd1iJ14XvwxBKXyJVGXrSWJVLwfqYJrW3JrOEHciZkn738LmZ0UgCm QT4qkfVsS20Uisv7KOLcZguvIYjkNf3nwOvkpSP+R3S0bZ2KqW1EdOC1UnEZKc0eGH5/ C7SA== X-Forwarded-Encrypted: i=1; AJvYcCU2OzEcCEJcD7mQZnw7aq8wDXJT2PhOGC+MmLsIL5ffOh1w2053xsDnivVeG7FpNit8OpwCpYwzvZHBFHA=@vger.kernel.org X-Gm-Message-State: AOJu0YxeoH+aUxvJzgjqtJcAvK+SUMLuKqeLULlAgw/HpPvH7X/8UrMj FeK2Pq5lwTf2hZG8gEiPY73Sa53nuthYdaYVTC8Xsr3U2IAAiKR1Ci0SmxX1NoBv X-Gm-Gg: ASbGnctrtFSK7EglJwJGFnHcZSTyCWKI2CGh/+ZLQnTP0QQaUdzQjPaeMU+cLdjPogm mvEim8n7oL2MZpl4FmV1CPi3K/rBTGKeLsPRF8Oww96xuII+Oi8nVA0H6NNGTIvMO5wPzzcuRei MLjtvXCgG8K1GjlJbNZsaN9HTd4dHeyEVjhUpy0McMKk2SNudZxbq4G4SNOB8k8FC7i6MBXKgF1 2T10ux3go0gLRJVZa5zDmmAML1girNoONV4K+s78RIaOLIbYTqrRd/nSsnOwXXWKhakw5A3fNSb KiED0VHbfq9XrwNqOdd67eUY8Bd3lAScVSMUwM1aulIunqE1yTdQ+UVrAvaRRYJ6VMzFONYLXwM egc5RUIRVm/vIOaMCWshKl7yxPnWek0UAj0fPgPqALiffS2eN4ehwNRnXG/Corlu8ndi0XUVsrq 3Wz5rrvOoiATSfVH2MsnF6dmmRKslU+FJM9XJ7wqKD0BU= X-Google-Smtp-Source: AGHT+IFQ2Ov7eS6bsSc2meQMzLbFTsAskoTl1ClkVsMkfKfn0z0A0du/1yMbRirUj4yvFp5szxoFeg== X-Received: by 2002:a05:7301:5795:b0:2a6:a0f0:d7c1 with SMTP id 5a478bee46e88-2a9415a402dmr7943316eec.12.1764301139978; Thu, 27 Nov 2025 19:38:59 -0800 (PST) Received: from ParadiseLost.localdomain (lohr.com.br. [177.69.253.233]) by smtp.gmail.com with ESMTPSA id a92af1059eb24-11dcb03cc7dsm13999469c88.5.2025.11.27.19.38.58 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 27 Nov 2025 19:38:59 -0800 (PST) From: "Rafael V. Volkmer" To: Kees Cook Cc: "Gustavo A . R . Silva" , linux-hardening@vger.kernel.org, linux-kernel@vger.kernel.org, "Rafael V. Volkmer" Subject: [PATCH 1/2] overflow: make check_shl_overflow() 128-bit aware Date: Fri, 28 Nov 2025 00:38:29 -0300 Message-ID: <20251128033830.331426-2-rafael.v.volkmer@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20251128033830.331426-1-rafael.v.volkmer@gmail.com> References: <20251128033830.331426-1-rafael.v.volkmer@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" check_shl_overflow() currently evaluates (@a << @s) in an unsigned long long accumulator. When callers pass __int128/u128 values, the intermediate is truncated to 64 bits before the comparison, so the helper always reports overflow and returns a zeroed result even when *@d is wide enough to hold the full shift. Introduce __shl_eval_type() to derive the internal evaluation type from @a and *@d. On architectures with CONFIG_ARCH_SUPPORTS_INT128 and compiler support for __int128, it promotes the accumulator to u128 when the promoted sum of @a and *@d is wider than 64 bits; otherwise it stays in an unsigned 64-bit type. This keeps the accumulator unsigned (avoiding UB when left-shifting negative signed values), preserves existing code generation for all current 32/64-bit users, and fixes the spurious overflow reporting for 128-bit shift users. Signed-off-by: Rafael V. Volkmer --- include/linux/overflow.h | 22 +++++++++++++++++++++- 1 file changed, 21 insertions(+), 1 deletion(-) diff --git a/include/linux/overflow.h b/include/linux/overflow.h index 725f95f7e416..ca8252e625d5 100644 --- a/include/linux/overflow.h +++ b/include/linux/overflow.h @@ -175,6 +175,26 @@ static inline bool __must_check __must_check_overflow(= bool overflow) __val; \ }) =20 +/** + * __shl_eval_type() - Choose evaluation type for shift checks + * @a: value to be shifted + * @d: destination pointer + * + * Returns the internal type used by check_shl_overflow() to evaluate + * (@a << @s), widening to unsigned __int128 when available and either + * @a or *@d promote wider than 64 bits, otherwise using unsigned long lon= g. + */ +#if defined(__SIZEOF_INT128__) +#define __shl_eval_type(a, d) \ + typeof(__builtin_choose_expr( \ + sizeof((a) + (typeof(*(d)))0) > sizeof(unsigned long long), \ + (unsigned __int128)0, \ + 0ULL)) +#else +#define __shl_eval_type(a, d) \ + typeof(0ULL + (a) + (typeof(*(d)))0) +#endif + /** * check_shl_overflow() - Calculate a left-shifted value and check overflow * @a: Value to be shifted @@ -199,7 +219,7 @@ static inline bool __must_check __must_check_overflow(b= ool overflow) typeof(a) _a =3D a; \ typeof(s) _s =3D s; \ typeof(d) _d =3D d; \ - unsigned long long _a_full =3D _a; \ + __shl_eval_type(_a, _d) _a_full =3D (__shl_eval_type(_a, _d))_a; \ unsigned int _to_shift =3D \ is_non_negative(_s) && _s < 8 * sizeof(*d) ? _s : 0; \ *_d =3D (_a_full << _to_shift); \ --=20 2.43.0 From nobody Mon Dec 1 21:30:53 2025 Received: from mail-dy1-f177.google.com (mail-dy1-f177.google.com [74.125.82.177]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 0200A2D6E7C for ; Fri, 28 Nov 2025 03:39:03 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=74.125.82.177 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1764301145; cv=none; b=C+WjxokDXf2wM9gV9C2dXLCxiyRWiUU7wu/wKt9OW8ifzgEEKCuHJstjNjjX4q5jatuEnoecLj1JpXi+muLqNypiVpFkbXMB3FUTaaYsm6wrmt6Eg8BDW/hUp16NVdubQkgFIEprOCYoFv1UJi6J9ZRApX0ZWD2DUofya+peIqE= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1764301145; c=relaxed/simple; bh=MJtcgcMVRbYqnz7yUeXOqkpQ9bJ6N+uilCKOuFcLl7w=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=J5NwxzPjcm02AcoVyC9b644kEv3fjDe918s1z5okYEdeW6KIU+AA8dtcXVZLctjLZcogNJAtksJR2qPQUTcQKOC9i8qRVecGeg7jGWJ1aocgnKn6jQy7H3ccbdM5g14rLmfzZFx6HR15tumsqZ1vzNMYOn/hNA3a5LSmxhfbS+A= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=YNXca38o; arc=none smtp.client-ip=74.125.82.177 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="YNXca38o" Received: by mail-dy1-f177.google.com with SMTP id 5a478bee46e88-2a45877bd5eso3402450eec.0 for ; Thu, 27 Nov 2025 19:39:03 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20230601; t=1764301143; x=1764905943; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to; bh=iXLSGxyqlw9PW9NDqgFwLCeID+cibWsbL+ACEydXwXc=; b=YNXca38oDHluT8SnWtE8fYPvLA0bnx2/Aq1SAToE+Eg2S5+oWjtbsS3qFMc4Wcb75+ ev42RpVfVNR/4+LsMANrg1tWuP3HWKRTqxxgUSV0pnrJLMpnjJfuc/kwmOVars31nevO Cle9pCOGPCevycQRlUWY/tkG24d3Rou1fDleTRNN37uImpB1UcLUoLFBIhXxAGRheBAx QGjPnQTkgRH6TL4GIK+Zcs5z4RVcjyxuBiSAEj6dOkUlJgpxgLmmVX7t39YDnJDoDT1f VMlJINj81TPckhsZtCLNmChYUybAobdGalR0T4RXU4oYZh+9+MaSU1YhBrm4Ar5fsM8T BV2A== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1764301143; x=1764905943; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to; bh=iXLSGxyqlw9PW9NDqgFwLCeID+cibWsbL+ACEydXwXc=; b=WAXPjvl+vx9YLNf3GOOWaXf/lvwTk6xSLlq8TbuvTxhoXLHgA6+luCYPa7fNnlmlDc kpQKM7jYGT1TbkzmDEt6a7MTAcn9BW/CRe6hcXa6ziROrCHjTT/b2se4t5GFE5oeBVZV s2t69swhyxtRINE1jPPcVINYa57RTtsGHOEOwvFqsXq29gzO75Xa+TTrAAybgHUvIl+t hj2mWQ4q+02YFbwDiQCoVxzgPClLrKxKJubsPlUWofyHtExr8DFIMjoNgZW3X1SaQgT7 gRlrX74nkGelmlokKpiSOWQiegdwIifkHNJt6mPX6IyJThzMRauERgfN5s+jBqk1Zd9k iIJQ== X-Forwarded-Encrypted: i=1; AJvYcCUOMVzFA+TqVvfYS6WuHtNeEttm7vCiTBAs2I9Lizw8ihWaxSJ36b2MoKWnE3cASvXTolvndKnVeKGwaQA=@vger.kernel.org X-Gm-Message-State: AOJu0YxN20prFiak34qOQ1RlBlXzTmT+9k7nIuQccXIFVPBpYQxscbXL 7+Ouosg6vRY4DZ4eSOTFrDRLo73kCGRzSpax1LPcsIZD+jNuZsT3BV1sWxOnbg== X-Gm-Gg: ASbGnct9lXoo1VN0FuyyrVML5kHLGgPRAGGNuz5N6v8QhG7hrBB8DIoJtDwiJXknTKn 7wcj8kAzbdd3D63gErLYvD1jktH7zc3ZDgbjSpj+nPdDTILuYwaDlR0On7tE2Tv7J4NAXLUFVqv xtQKZfNizOqmOaBD/wUL3240E86Lr0D+4lGOzcvMjDeZzbRGp3nOyZ/idgkyZVS4EaYD2yylfHB EtDVbi1E1oc/4Z8iwaV1Kq+DssX8eGerfy2Be2Opp/dkaR8S5Q5N7Ck2dnHH/WppAqhMyMCrYDL devHEphfsRm98qottqCoMOADhwiSAI3WHY8ssgLTmkfycdXoTW0r39LAgCL39yoI4tYJtMyTcD1 QlWPDW5znMlIFSQsA6lU4GMMsrB6+niWQpa/V4iLX5ugFJ8fP6iLhdi7GWdLYHpyIMGJvwComyE AlAcmZFNzHApb7G4ym3zsrzLKO6zJt1qBcepzOKMFfSl4= X-Google-Smtp-Source: AGHT+IE3ELtSLAn3cS8ZIIaoCXejMxDH6G7MwxZ/EqUfIf2ZaCbtg0fJtBdYds0m+odBYLXmysvpmA== X-Received: by 2002:a05:7300:a2ca:b0:2a6:a306:efdb with SMTP id 5a478bee46e88-2a718576e14mr17180250eec.3.1764301142957; Thu, 27 Nov 2025 19:39:02 -0800 (PST) Received: from ParadiseLost.localdomain (lohr.com.br. [177.69.253.233]) by smtp.gmail.com with ESMTPSA id a92af1059eb24-11dcb03cc7dsm13999469c88.5.2025.11.27.19.39.01 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 27 Nov 2025 19:39:02 -0800 (PST) From: "Rafael V. Volkmer" To: Kees Cook Cc: "Gustavo A . R . Silva" , linux-hardening@vger.kernel.org, linux-kernel@vger.kernel.org, "Rafael V. Volkmer" Subject: [PATCH 2/2] overflow: add size_shl() helper for saturated left shifts Date: Fri, 28 Nov 2025 00:38:30 -0300 Message-ID: <20251128033830.331426-3-rafael.v.volkmer@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20251128033830.331426-1-rafael.v.volkmer@gmail.com> References: <20251128033830.331426-1-rafael.v.volkmer@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" Introduce size_shl() as a sibling to size_mul(), size_add() and size_sub() for the left-shift case. It computes value << shift with both operands promoted to size_t and uses check_shl_overflow() to detect invalid or overflowing shifts, returning SIZE_MAX on failure. No functional change for existing callers; this only adds a new helper. Signed-off-by: Rafael V. Volkmer --- include/linux/overflow.h | 19 +++++++++++++++++++ 1 file changed, 19 insertions(+) diff --git a/include/linux/overflow.h b/include/linux/overflow.h index ca8252e625d5..91d0b5b00a56 100644 --- a/include/linux/overflow.h +++ b/include/linux/overflow.h @@ -404,6 +404,25 @@ static inline size_t __must_check size_sub(size_t minu= end, size_t subtrahend) return bytes; } =20 +/** + * size_shl() - Calculate size_t left shift with saturation at SIZE_MAX + * @value: value to be shifted + * @shift: how many bits left to shift + * + * Returns: calculate @value << @shift, both promoted to size_t, with any + * overflow or invalid shift causing the return value to be SIZE_MAX. The + * lvalue must be size_t to avoid implicit type conversion. + */ +static inline size_t __must_check size_shl(size_t value, size_t shift) +{ + size_t out; + + if (check_shl_overflow(value, shift, &out)) + return SIZE_MAX; + + return out; +} + /** * array_size() - Calculate size of 2-dimensional array. * @a: dimension one --=20 2.43.0