Re: [PATCH net] lib/dim: fix 32-bit overflow of epms in dim_calc_stats()

From: Simon Horman

Date: Fri Oct 09 2026 - 09:10:03 EST


On Mon, Oct 05, 2026 at 07:14:11AM +0530, Shashank Mohan Jain wrote:
> Commit 0843b2389064 ("lib/dim: fix 32-bit overflow in dim_calc_stats()
> rates") moved the packet, byte and completion rates in dim_calc_stats()
> to 64-bit arithmetic, but left the event rate as
>
> DIV_ROUND_UP(DIM_NEVENTS * USEC_PER_MSEC, delta_us)
>
> DIV_ROUND_UP() computes (64000 + delta_us - 1) / delta_us. On 32-bit
> architectures that sum is done in a 32-bit unsigned long and wraps for
> delta_us >= 4294903297, the last 64 ms of the u32 microsecond range
> that the function is meant to cover ("u32 holds up to 71 minutes").
> epms then becomes 0 instead of 1.
>
> net_dim() and rdma_dim() only wait for DIM_NEVENTS events before they
> call dim_calc_stats(), with no time limit, so on an almost idle
> interface a window can last that long. With epms == 0, cpe_ratio is
> set to 0, net_dim_stats_compare() returns DIM_STATS_BETTER instead of
> DIM_STATS_SAME when bpms and ppms did not change significantly, and
> rdma_dim_stats_compare() compares a cpe_ratio of 0. The algorithm can
> then step to another moderation profile based on a wrong rate.
>
> Compute epms with DIV_ROUND_UP_ULL() as well. The result does not
> change on 64-bit, or on 32-bit for windows shorter than 4294903297 us.
>
> The issue was found by the Sashiko AI review of the original patch
> (see the Closes: link). The fix and the test were written with an LLM
> assistant. The dim KUnit suite computed the expected epms with the same
> DIV_ROUND_UP() expression as dim_calc_stats(), so it could not catch
> this; it now uses explicit expected values and gains two cases with
> delta_us of 4294903297 and U32_MAX. Without the fix both new cases fail
> on UML i386 and on qemu i386 (epms 0, expected 1) and pass on UML and
> qemu x86_64; with the fix all 10 dim cases pass on all four.
>
> Fixes: 0843b2389064 ("lib/dim: fix 32-bit overflow in dim_calc_stats() rates")
> Reported-by: Sashiko <sashiko-bot@xxxxxxxxxx>
> Closes: https://netdev-ai.bots.linux.dev/sashiko/#/patchset/20260927051743.71460-1-jain.sm@xxxxxxxxx
> Assisted-by: LLM
> Signed-off-by: Shashank Mohan Jain <jain.sm@xxxxxxxxx>

Reviewed-by: Simon Horman <horms@xxxxxxxxxx>