[PATCH 0/2] wifi: iwlwifi: Fix GP2 to nanoseconds overflow on 32-bit

Zhan Xusheng <[email protected]>
Newsgroups org.kernel.vger.netdev,org.kernel.vger.linux-kernel,org.kernel.vger.linux-wireless
Message-ID <[email protected]>
GP2 is a free-running 32-bit microsecond hardware counter. Both the mvm
and mld PTP code convert a u32 GP2 value to nanoseconds with

	gp2 * NSEC_PER_USEC

NSEC_PER_USEC is a plain 'long' (1000L), so on 32-bit builds the
multiplication is performed in 32-bit arithmetic and overflows once the
GP2 value exceeds ~4.29 million microseconds (~4.3 s). Since GP2 wraps
only every 2^32 microseconds (~71.5 min), the product is truncated for
almost the entire counter range, producing bogus PTP timestamps.

Most conversions in the same files already cast to u64 first
((u64)gp2 * NSEC_PER_USEC); a handful of sites (the adjfine path, the
stored scale_update_gp2 and the monitor/RX timestamp path) simply missed
the cast. These patches add the missing u64 casts so the multiplications
are done in 64-bit, matching the existing call sites. 64-bit builds are
unaffected. The mld driver inherited the same pattern (and bug) from
mvm, so it is fixed in a separate patch with its own Fixes: tags.

Found by code inspection; not tested on 32-bit hardware. The change is a
straightforward u64 cast matching the surrounding code.


Zhan Xusheng (2):
  wifi: iwlwifi: mvm: Fix GP2 to nanoseconds overflow on 32-bit
  wifi: iwlwifi: mld: Fix GP2 to nanoseconds overflow on 32-bit

 drivers/net/wireless/intel/iwlwifi/mld/ptp.c  | 4 ++--
 drivers/net/wireless/intel/iwlwifi/mld/rx.c   | 6 ++----
 drivers/net/wireless/intel/iwlwifi/mvm/ptp.c  | 4 ++--
 drivers/net/wireless/intel/iwlwifi/mvm/rxmq.c | 4 ++--
 4 files changed, 8 insertions(+), 10 deletions(-)

-- 
2.43.0
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.