[PATCH net v3 1/2] net: ethtool: reject an out of range hwtstamp provider index
From: Nicolai Buchwitz
Date: Fri Sep 25 2026 - 09:59:38 EST
A provider index of 0xFFFFFFFF picks a provider on hardware that has
none. phc_index is an int where -1 means no PHC, and the u32 from user
space ends up as -1, so the two match.
TSINFO_GET uses -1 for "no provider requested" and answers with the
default provider instead of an error.
Reject the value in the netlink policy, which covers every comparison
site.
Fixes: b9e3f7dc9ed9 ("net: ethtool: tsinfo: Enhance tsinfo to support several hwtstamp by net topology")
Signed-off-by: Nicolai Buchwitz <nb@xxxxxxxxxxx>
---
NLA_POLICY_MAX does not fit here, .max in struct nla_policy is s16.
net/ethtool/ts.h | 8 +++++++-
1 file changed, 7 insertions(+), 1 deletion(-)
diff --git a/net/ethtool/ts.h b/net/ethtool/ts.h
index d901a879a671..ab9805308353 100644
--- a/net/ethtool/ts.h
+++ b/net/ethtool/ts.h
@@ -5,9 +5,15 @@
#include "netlink.h"
+/* phc_index is an int and -1 means no PHC, so keep the request non-negative */
+static const struct netlink_range_validation ethnl_ts_prov_index_range = {
+ .max = INT_MAX,
+};
+
static const struct nla_policy
ethnl_ts_hwtst_prov_policy[ETHTOOL_A_TS_HWTSTAMP_PROVIDER_MAX + 1] = {
- [ETHTOOL_A_TS_HWTSTAMP_PROVIDER_INDEX] = { .type = NLA_U32 },
+ [ETHTOOL_A_TS_HWTSTAMP_PROVIDER_INDEX] =
+ NLA_POLICY_FULL_RANGE(NLA_U32, ðnl_ts_prov_index_range),
[ETHTOOL_A_TS_HWTSTAMP_PROVIDER_QUALIFIER] =
NLA_POLICY_MAX(NLA_U32, HWTSTAMP_PROVIDER_QUALIFIER_CNT - 1)
};
base-commit: 11536ee3d3e0b1bd35b6f3f8df55a6053eb0c71d
--
2.53.0