[PATCH net 1/2] lib/dim: fix 32-bit overflow in dim_calc_stats() rates

From: Shashank Mohan Jain

Date: Sun Sep 27 2026 - 01:18:36 EST


dim_calc_stats() computes the per-millisecond rates as

DIV_ROUND_UP(nbytes * USEC_PER_MSEC, delta_us)

where nbytes is a u32 and USEC_PER_MSEC is 1000L. On 64-bit the product
is done in 64-bit long arithmetic, but on 32-bit architectures long is
32 bits wide and the product wraps as soon as a measurement window
carries more than 4294967 bytes (about 4.3 MB). The same applies to the
packet and completion counts, although those need more than 4.29
million packets or completions per window.

A DIM window spans DIM_NEVENTS (64) events. Drivers count events per
interrupt or per NAPI poll, so under sustained load a window can easily
carry more than 4.3 MB: 64 full NAPI polls of 64 MTU-sized frames are
already 6.2 MB, and drivers such as mtk_eth_soc count one event per
interrupt while NAPI keeps polling with the interrupt masked. On 32-bit
users of the library (for example mtk_eth_soc on MT7621, bcmgenet and
bcmsysport on 32-bit ARM, or virtio_net in a 32-bit guest) bpms then
becomes the product modulo 2^32 divided by the window length, and
net_dim_stats_compare() makes its BETTER/WORSE decisions on a value
that has little to do with the real throughput.

For example, a 1 Gbit/s link at line rate that moves 5 MB in a 40 ms
window gives bpms = 125000 on 64-bit but 17626 on 32-bit, and 5 million
packets in 2 s gives ppms = 353 instead of 2500.

Widen the products to 64 bits and divide with DIV_ROUND_UP_ULL(). The
results are unchanged on 64-bit.

Fixes: cb3c7fd4f839 ("net/mlx5e: Support adaptive RX coalescing")
Fixes: 4c4dbb4a7363 ("net/mlx5e: Move dynamic interrupt coalescing code to include/linux")
Assisted-by: LLM
Signed-off-by: Shashank Mohan Jain <jain.sm@xxxxxxxxx>
---
Found by reading lib/dim with an LLM assistant (Claude Code, Claude
Opus 5.5), which also drafted the fix, the KUnit test and the
changelogs.

Tested: the new KUnit suite (patch 2), on mainline and on net, on UML
i386 (fails 4 of 7 dim_calc_stats cases without this patch, passes
with it) and UML x86_64 (passes with and without it); W=1 builds of
lib/dim/ for UML x86_64 and i386, and a native i386 vmlinux+modules
build, with no 64-bit division helper references.
Not tested: 32-bit ARM or MIPS builds (no cross compiler available),
and no run on a 32-bit NIC; the traffic levels at which drivers hit
the overflow are derived from how they count DIM events, not measured.

lib/dim/dim.c | 10 +++++++---
1 file changed, 7 insertions(+), 3 deletions(-)

diff --git a/lib/dim/dim.c b/lib/dim/dim.c
index 97c3d084ebf0..7f3eebae73cb 100644
--- a/lib/dim/dim.c
+++ b/lib/dim/dim.c
@@ -69,11 +69,15 @@ bool dim_calc_stats(const struct dim_sample *start,
if (!delta_us)
return false;

- curr_stats->ppms = DIV_ROUND_UP(npkts * USEC_PER_MSEC, delta_us);
- curr_stats->bpms = DIV_ROUND_UP(nbytes * USEC_PER_MSEC, delta_us);
+ /* u32 * USEC_PER_MSEC overflows a 32-bit long */
+ curr_stats->ppms = DIV_ROUND_UP_ULL((u64)npkts * USEC_PER_MSEC,
+ delta_us);
+ curr_stats->bpms = DIV_ROUND_UP_ULL((u64)nbytes * USEC_PER_MSEC,
+ delta_us);
curr_stats->epms = DIV_ROUND_UP(DIM_NEVENTS * USEC_PER_MSEC,
delta_us);
- curr_stats->cpms = DIV_ROUND_UP(ncomps * USEC_PER_MSEC, delta_us);
+ curr_stats->cpms = DIV_ROUND_UP_ULL((u64)ncomps * USEC_PER_MSEC,
+ delta_us);
if (curr_stats->epms != 0)
curr_stats->cpe_ratio = DIV_ROUND_DOWN_ULL(
curr_stats->cpms * 100, curr_stats->epms);
--
2.43.0