]> git.ipfire.org Git - thirdparty/kernel/linux.git/commit
net: octeontx2-pf: Fix UB in shift operation
authorSergey V. Frolov <Sergey.V.Frolov@kaspersky.com>
Tue, 4 Aug 2026 12:04:48 +0000 (15:04 +0300)
committerPaolo Abeni <pabeni@redhat.com>
Thu, 6 Aug 2026 13:16:50 +0000 (15:16 +0200)
commit7e2d693af0d4c05bddccb3541a0aabd69f4cb244
treed36b6c62950ca8c7ced370c83c4e023334d19817
parentf684c514f7965385dae21f2535f99938e73ec1af
net: octeontx2-pf: Fix UB in shift operation

In function otx2_get_egress_burst_cfg, when the parameter `burst` is
255 and the max mantissa is 255 (0xFFULL), `burst_exp` is set to
`ilog2(255) - 1`, which equals 6.

This results in an unsigned wrap-around when calculating
`(1ULL << (*burst_exp - 7))`, since `*burst_exp - 7` becomes -1,
which makes the shift operand 0xFFFFFFFF. This value is greater than
the width of the left operand.

According to standard 6.5.7 p.3:
"The type of the result is that of the promoted left operand.
If the value of the right operand is negative or is greater than
or equal to the width of the promoted left operand, the behavior
is undefined."

Fix the off-by-one boundary condition.

Add a WARN_ON(*burst_exp < 7) before the else branch as an
explicit safeguard. This ensures that if max_mantissa ever changes
in a way that reintroduces this condition, it will be immediately
caught at runtime rather than silently triggering UB.

Found by Linux Verification Center (linuxtesting.org) with SVACE.

Fixes: e638a83f167e ("octeontx2-pf: TC_MATCHALL egress ratelimiting offload")
Signed-off-by: Sergey V. Frolov <Sergey.V.Frolov@kaspersky.com>
Cc: stable@vger.kernel.org
Reviewed-by: Ratheesh Kannoth <rkannoth@marvell.com>
Reviewed-by: Sunil Goutham <sgoutham@marvell.com>
Link: https://patch.msgid.link/20260804120446.1955448-1-Sergey.V.Frolov@kaspersky.com
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
drivers/net/ethernet/marvell/octeontx2/nic/otx2_tc.c