From nobody Tue Sep 29 03:54:06 2026 Received: from mail-qk1-f170.google.com (mail-qk1-f170.google.com [209.85.222.170]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id AEF74345729 for ; Thu, 13 Aug 2026 06:03:16 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.222.170 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786600998; cv=none; b=YS8C5Q6Rb3Ri6q5PcoYjQZIvFdoNDUQPkCoNze71uBPNUMekzl61iLq60mprzfXYuPytxyiYQdBDpKvDjxfFqKcH8WYFWCYmwV4QJUXAoflWbT9fEyOBkoIycMXRzzxLz6NpgzzNLU99RSN8DfDsmPZIuQapdVOKtLPrPxhc8uw= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786600998; c=relaxed/simple; bh=k0IiTGCZPxaC6DbcUJgYzqOFviiZ29gLv8o0+WEHuhg=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=nq6x0aUD05VIJJ/TYwrrF2WavrDPdkKe2KFPFEX8Ib5humecd2rIF4d/BnJXTpI38p39k46ftcqcase0zoJHnEsVqpgJBc24wipWZ+8lT63LJujsKOzbHmS0ozIWyBR+CZzTPdzaXDCzmJ+1gE1GZTyTforpFJswQnPUACNteYE= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=MS9JxpWm; arc=none smtp.client-ip=209.85.222.170 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="MS9JxpWm" Received: by mail-qk1-f170.google.com with SMTP id af79cd13be357-92e6c4a867cso112989785a.0 for ; Wed, 12 Aug 2026 23:03:16 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1786600995; x=1787205795; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=sox5TAGummL92plkwLvVOIoXFT28V3HCqptnK0dIWn0=; b=MS9JxpWmvLPueWLkAXxV5lcN5Njx7fm87mG4+3RIz754FTrfJnGee4v/pDz4oZrr/H GsG3DjY3zWXycrFCzDd78NX3cdukBAfDhiVv5DpE6ahoIDLe/6CRbUucA0441FJq/f7p u0pUv4CNyos+Qb9URzS2A5kLSlPaPlo5Ph0Lh8ueWbR3x7Dey0WfKAEwNAZbVDx1CHzO OZVMSv4Lze2sSH2xO8uxenhMSF3ZEEgKcdu6AOpsxcr+GhiVzVCxeVsriYZhxwI1CPM9 VlVlq33T73zz9fxR78yy+OXPUZL6aLYmjp//HLSJYuKdvZiG5/cpMXwVHwBWBtfbu2Au gbJg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786600995; x=1787205795; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=sox5TAGummL92plkwLvVOIoXFT28V3HCqptnK0dIWn0=; b=BL8EQES/KLom3AvGjgmywpYwRrLmCwZ4VMU8/0NH3bBKOy3in1USDrINAd3Vcju6d5 lQjHr4Uc9bgs8Ym0uSvRriqs8hONIjMlKvzupKNQ+7LRUGGYKf6zpaH/Hr9DXKwSERfU DtgOa8dnrBLgGRVr12sc5OyL5rff8pqW9XyHXlgU0GzFd+QtJo949JbpNr6TUtz07VYW wm83OVTPg2UjO/xzuBYgLfga9X8yYGZd1w7nIt82DPOUR8LTU01vq5pdOs+Mt0T4lLJ7 tIYSxlFTa+e53pz5IYYmOFXandHc0WixIXN+OJdZbQytD4AGoyMoJibIJ26WjCI3P0wh BLjA== X-Gm-Message-State: AOJu0YyNUbYAOwJ7aUnDoZDYrM67Jmc/wYu+PkZgoW89oGahB82MFQ+S 7DnoSGGbwoXJTMfxvZD4v3+ozb6YNyLoMuPJ2SsjmtT4RMTh18wRY2aJ X-Gm-Gg: AR+sD12XzW/fN8yCt893IbQLPQLJl1zPh012CTvuX+8DRHRs9W+p8UTIBqA1O5eL23L DkPd3npnsRHOxPQNHes+OYuEqTWCoxmTTkkS/CEtam56rHyWcZLQjW2VOtO/6glXjPLH7QvJVu/ caV/+cto2fL58pC+JDcbGZER0mFII/R0B7vahIkmiAN9E9oUmgA4iKNsbEg5AubMwinBAQZ7ot1 7WEa0NjmePpgkvIEfEJ5snuab+g/vdvdzA8c0PU2GBR/ZnCsR8H8RqDr/d+lrQ/lJORXS71fwIW eqro/T9e4XTnVqx3jBdQ5eODYY7ov0K66nfodpcGA8YGvcTMinsPNx1J7x730MZHEPuQ38KnMoZ T69O3ak4rHqk8lgzjKZsQtDsOVzFqJ8biIS12w/kiMLJrJue3Q0TCP2ZLa3XT+/Jr5MKRV8lN4F 3brKrWhuucDHqzIRTuWMSlFqBtUt3tOuZcSOzh/KZ7Z0ZuvJNPd1ZyhI4zTc5wPkB3wQoAe+BS X-Received: by 2002:a05:620a:3d06:b0:92e:7cc9:a888 with SMTP id af79cd13be357-936bf9637femr228866885a.2.1786600995425; Wed, 12 Aug 2026 23:03:15 -0700 (PDT) Received: from localhost.localdomain ([38.91.104.44]) by smtp.gmail.com with ESMTPSA id af79cd13be357-936c1b4d57asm76880785a.35.2026.08.12.23.03.10 (version=TLS1_3 cipher=TLS_CHACHA20_POLY1305_SHA256 bits=256/256); Wed, 12 Aug 2026 23:03:14 -0700 (PDT) From: Jack Wang <163wangjack@gmail.com> To: netdev@vger.kernel.org Cc: linux-kernel@vger.kernel.org, Vinicius Costa Gomes , Jamal Hadi Salim , Jiri Pirko , "David S. Miller" , Eric Dumazet , Jakub Kicinski , Paolo Abeni , Simon Horman , Elena Salomatkina Subject: [PATCH net v3] net/sched: cbs: perform rate conversions in signed 64-bit arithmetic Date: Thu, 13 Aug 2026 14:02:56 +0800 Message-ID: <20260813060256.28748-1-163wangjack@gmail.com> X-Mailer: git-send-email 2.53.0 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" cbs_set_port_rate() and cbs_change() multiply link rates and slope values by BYTES_PER_KBIT, an unsigned long constant. On 32-bit architectures, the multiplications therefore take place in 32-bit unsigned arithmetic before the results are assigned to s64 fields. For port rates above approximately 34.36 Gbit/s this wraps port_rate. The same conversion turns a negative sendslope into a large positive value, reversing the CBS credit adjustment. This affects software CBS; port_rate is also refreshed on NETDEV_UP and NETDEV_CHANGE notifications. Cast the first operand of each multiplication to s64 so all intermediate operations use signed 64-bit arithmetic and preserve the value's sign on every architecture Also reject a negative idleslope. A negative idleslope can arm the watchdog in the past and busy-loop. Fixes: 585d763af09c ("net/sched: Introduce Credit Based Shaper (CBS) qdisc") Fixes: 397006ba5d918 ("net/sched: cbs: Fix integer overflow in cbs_set_port= _rate()") Signed-off-by: Jack Wang <163wangjack@gmail.com> --- v3: - Reject only negative idleslope values. - Keep idleslope 0 accepted for compatibility with existing tc-testing defaults, fixing test 1820 regression reported by Victor. - Keep the timediff_to_credits() overflow out of this series as a separate follow-up. v2: - Reject non-positive idleslope values to prevent scheduling the watchdog in the past. v1: https://lore.kernel.org/netdev/20260806155253.50252-1-163wangjack@gmail= .com/ net/sched/sch_cbs.c | 10 +++++++--- 1 file changed, 7 insertions(+), 3 deletions(-) diff --git a/net/sched/sch_cbs.c b/net/sched/sch_cbs.c index 1c93469c56e3..8db98d7c98a8 100644 --- a/net/sched/sch_cbs.c +++ b/net/sched/sch_cbs.c @@ -335,7 +335,7 @@ static void cbs_set_port_rate(struct net_device *dev, s= truct cbs_sched_data *q) speed =3D ecmd.base.speed; =20 skip: - port_rate =3D speed * 1000 * BYTES_PER_KBIT; + port_rate =3D (s64)speed * 1000 * BYTES_PER_KBIT; =20 atomic64_set(&q->port_rate, port_rate); netdev_dbg(dev, "cbs: set %s's port_rate to: %lld, linkspeed: %d\n", @@ -392,6 +392,10 @@ static int cbs_change(struct Qdisc *sch, struct nlattr= *opt, } =20 qopt =3D nla_data(tb[TCA_CBS_PARMS]); + if (qopt->idleslope < 0) { + NL_SET_ERR_MSG(extack, "Idleslope must not be negative"); + return -EINVAL; + } =20 if (!qopt->offload) { cbs_set_port_rate(dev, q); @@ -405,8 +409,8 @@ static int cbs_change(struct Qdisc *sch, struct nlattr = *opt, /* Everything went OK, save the parameters used. */ WRITE_ONCE(q->hicredit, qopt->hicredit); WRITE_ONCE(q->locredit, qopt->locredit); - WRITE_ONCE(q->idleslope, qopt->idleslope * BYTES_PER_KBIT); - WRITE_ONCE(q->sendslope, qopt->sendslope * BYTES_PER_KBIT); + WRITE_ONCE(q->idleslope, (s64)qopt->idleslope * BYTES_PER_KBIT); + WRITE_ONCE(q->sendslope, (s64)qopt->sendslope * BYTES_PER_KBIT); WRITE_ONCE(q->offload, qopt->offload); =20 return 0; base-commit: 7b53449540502cb21b32bca62a6258e22cd97bbe --=20 2.53.0