NetBSD-Bugs archive
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]
PR/60780 CVS commit: src/sys/kern
The following reply was made to PR port-mips/60780; it has been noted by GNATS.
From: "Taylor R Campbell" <riastradh%netbsd.org@localhost>
To: gnats-bugs%gnats.NetBSD.org@localhost
Cc:
Subject: PR/60780 CVS commit: src/sys/kern
Date: Sat, 3 Oct 2026 00:13:34 +0000
Module Name: src
Committed By: riastradh
Date: Sat Oct 3 00:13:33 UTC 2026
Modified Files:
src/sys/kern: kern_ntptime.c
Log Message:
ntp(9): Avoid more left shift of negative UB.
This logic is, presumably, intended to compute integer arithmetic, so
just write it as *16 instead of <<4. If there's an advantage to
using a machine shift instruction to get the same semantics, the
compiler can do that for us.
Also avoid arithmetic overflow. If set a few lines above,
time_monitor can lie anywhere in the interval [-MAXPHASE,MAXPHASE] =
[-500e6,500e6]. Multiplying by sixteen can therefore overflow the
bounds [-2.2e9,2.2e9] of long on LP32 platforms by a factor of four.
But mtemp >= 256 here, so even if time_monitor*16 overflows the
signed 32-bit range, the result (time_monitor*16)/mtemp will not.
Hence: cast to int64_t for the intermediate computation of
time_monitor*16.
This isn't the end of the analysis: time_monitor can also be set in
hardpps(9) to something else whose bounds aren't as clear to me, but
that only applies under `options PPS_SYNC' which is usually not set.
Perhaps we need to enforce bounds on that too.
PR port-mips/60780: UBSan complains about left-shifting outside of
int type range
To generate a diff of this commit:
cvs rdiff -u -r1.64 -r1.65 src/sys/kern/kern_ntptime.c
Please note that diffs are not public domain; they are subject to the
copyright notices on the relevant files.
Home |
Main Index |
Thread Index |
Old Index