[tip: timers/vdso] vdso/gettimeofday: Assert that the clockid fits into the u32 bitmask

From: tip-bot2 for Zhan Xusheng

Date: Tue Sep 29 2026 - 15:27:58 EST


The following commit has been merged into the timers/vdso branch of tip:

Commit-ID: ca46a07c4b68246c4e400ce3649ab7228a878d8f
Gitweb: https://git.kernel.org/tip/ca46a07c4b68246c4e400ce3649ab7228a878d8f
Author: Zhan Xusheng <zhanxusheng1024@xxxxxxxxx>
AuthorDate: Wed, 16 Sep 2026 10:32:52 +08:00
Committer: Thomas Gleixner <tglx@xxxxxxxxxx>
CommitterDate: Tue, 29 Sep 2026 21:23:30 +02:00

vdso/gettimeofday: Assert that the clockid fits into the u32 bitmask

__cvdso_clock_gettime_common() and __cvdso_clock_getres_common() convert
the clockid into a bitmask and match it against VDSO_HRES, VDSO_COARSE,
VDSO_RAW and VDSO_AUX:

msk = 1U << clock;

vdso_clockid_valid() rejects anything above CLOCK_AUX_LAST beforehand,
and CLOCK_AUX_LAST is 23, so the shift count is in range. Nothing
records that dependency though. Raising MAX_AUX_CLOCKS beyond 16 moves
CLOCK_AUX_LAST to 32 and makes the shift undefined.

Add a BUILD_BUG_ON() at both conversion sites. The condition is on a
function parameter rather than a constant, so it relies on the compiler
deriving the range from the vdso_clockid_valid() bail-out above it. gcc
13 and clang 18 both do: the x86 vdso64 and vdso32 builds stay clean, and
raising MAX_AUX_CLOCKS to 17 trips the assert.

Suggested-by: Thomas Weißschuh <thomas.weissschuh@xxxxxxxxxxxxx>
Signed-off-by: Zhan Xusheng <zhanxusheng@xxxxxxxxxx>
Signed-off-by: Thomas Gleixner <tglx@xxxxxxxxxx>
Reviewed-by: Thomas Weißschuh <thomas.weissschuh@xxxxxxxxxxxxx>
Link: https://patch.msgid.link/20260916023252.418473-5-zhanxusheng@xxxxxxxxxx
---
lib/vdso/gettimeofday.c | 2 ++
1 file changed, 2 insertions(+)

diff --git a/lib/vdso/gettimeofday.c b/lib/vdso/gettimeofday.c
index f7a591a..ef4dcc6 100644
--- a/lib/vdso/gettimeofday.c
+++ b/lib/vdso/gettimeofday.c
@@ -285,6 +285,7 @@ __cvdso_clock_gettime_common(const struct vdso_time_data *vd, clockid_t clock,
* Convert the clockid to a bitmask and use it to check which
* clocks are handled in the VDSO directly.
*/
+ BUILD_BUG_ON(clock >= BITS_PER_TYPE(msk));
msk = 1U << clock;
if (likely(msk & VDSO_HRES))
vc = &vc[CS_HRES_COARSE];
@@ -438,6 +439,7 @@ bool __cvdso_clock_getres_common(const struct vdso_time_data *vd, clockid_t cloc
* Convert the clockid to a bitmask and use it to check which
* clocks are handled in the VDSO directly.
*/
+ BUILD_BUG_ON(clock >= BITS_PER_TYPE(msk));
msk = 1U << clock;
if (msk & (VDSO_HRES | VDSO_RAW)) {
/*