Source-Changes archive

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]

CVS commit: src/sys/kern



Module Name:    src
Committed By:   riastradh
Date:           Sat Oct  3 00:13:33 UTC 2026

Modified Files:
        src/sys/kern: kern_ntptime.c

Log Message:
ntp(9): Avoid more left shift of negative UB.

This logic is, presumably, intended to compute integer arithmetic, so
just write it as *16 instead of <<4.  If there's an advantage to
using a machine shift instruction to get the same semantics, the
compiler can do that for us.

Also avoid arithmetic overflow.  If set a few lines above,
time_monitor can lie anywhere in the interval [-MAXPHASE,MAXPHASE] =
[-500e6,500e6].  Multiplying by sixteen can therefore overflow the
bounds [-2.2e9,2.2e9] of long on LP32 platforms by a factor of four.
But mtemp >= 256 here, so even if time_monitor*16 overflows the
signed 32-bit range, the result (time_monitor*16)/mtemp will not.
Hence: cast to int64_t for the intermediate computation of
time_monitor*16.

This isn't the end of the analysis: time_monitor can also be set in
hardpps(9) to something else whose bounds aren't as clear to me, but
that only applies under `options PPS_SYNC' which is usually not set.
Perhaps we need to enforce bounds on that too.

PR port-mips/60780: UBSan complains about left-shifting outside of
int type range


To generate a diff of this commit:
cvs rdiff -u -r1.64 -r1.65 src/sys/kern/kern_ntptime.c

Please note that diffs are not public domain; they are subject to the
copyright notices on the relevant files.




Home | Main Index | Thread Index | Old Index