Skip to content

[cgroup] fix uint32 overflow in CPU quota computation - #348

Open
ManoharPaturi wants to merge 1 commit into
google:masterfrom
ManoharPaturi:pr-cgroup-quota
Open

ManoharPaturi wants to merge 1 commit into
google:masterfrom
ManoharPaturi:pr-cgroup-quota

Conversation

@ManoharPaturi

Copy link
Copy Markdown

Problem

cgroup_cpu_ms_per_sec is a uint32 config field, and both quota writers compute the microsecond value with * 1000U, which evaluates in 32 bits. Any configured value ≥ 4294968 wraps around and writes a completely unrelated limit to the kernel:

configured ms/s intended µs written µs (32-bit wrap)
4,294,968 4,294,968,000 704
5,000,000 5,000,000,000 705,032,704

So an operator requesting ~4300 CPU-seconds per second silently gets a 704 µs quota in cgroup v1, and cgroup v2 gets an arbitrary wrapped cpu.max value — the enforced limit has no relation to the configuration.

Change

Compute the quota in uint64_t in both writers (cgroup.cc for v1, cgroup2.cc for v2). No behavior change for values that don't overflow.

Testing

Built and ran the full test suite (unit + cmdline) plus an ASan/UBSan build on Ubuntu 24.04 — all green, no new findings. The overflow itself is demonstrated by the table above (plain uint32 arithmetic).

cgroup_cpu_ms_per_sec is a uint32 config field. Computing the
microsecond quota with '* 1000U' evaluates in 32 bits, so any value
>= 4294968 wraps around: e.g. 4294968 becomes a 704us quota and
5000000 becomes 705032704us, silently writing a limit that has
nothing to do with the configured one. Compute in uint64_t in both
the v1 (cgroup.cc) and v2 (cgroup2.cc) writers.
@ManoharPaturi

Copy link
Copy Markdown
Author

Small branch hygiene fix: my local CI workflow file accidentally ended up in this branch — force-pushed the branch rebuilt from current master with only the intended change. The diff is now just the patch itself; the actions scan failure from earlier is gone.

@ManoharPaturi

ManoharPaturi commented Sep 27, 2026 •

Copy link
Copy Markdown
Author

@robertswiecki Could you take a look when you have a moment? This fixes a uint32 overflow in the CPU quota computation: cgroup_cpu_ms_per_sec * 1000U evaluates in 32 bits, so values above 4,294,967 wrap (e.g. 4294968 ms/s silently becomes a 704 µs quota). Both the v1 and v2 writers are affected; the fix computes in uint64_t. Verified with a full build, the test suite, and an ASan/UBSan run.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant