Sharvin Neve created a merge request: 
https://gitlab.rtems.org/rtems/rtos/rtems/-/merge_requests/1484

Project:Branches: Sharvin/rtems:fix-tod-year-2400-watchdog-overflow to 
rtems/rtos/rtems:main
Author:   Sharvin Neve



Closes #5749.

### Root Cause Analysis
1. `rtems_clock_set()` accepted years up to `TOD_LATEST_YEAR` (previously 
4095). However, `_TOD_Set()` asserts `_TOD_Is_valid_new_time_of_day()`, which 
rejected timestamps beyond `TOD_SECONDS_1970_THROUGH_2400`. Consequently, debug 
builds (`RTEMS_DEBUG=True`) abort on assertion failures in `spclock_err02` and 
`ts-validation-no-clock-0`.
2. Realtime watchdogs represent timestamps with 30 bits for nanoseconds and 34 
bits for seconds since UNIX Epoch (`WATCHDOG_MAX_SECONDS = 0x3ffffffff` = 
17,179,869,183 seconds, wrapping on 2514-05-31). Years beyond 2514 overflow 
this 34-bit field, corrupting watchdog timer list ordering and scheduling.
3. `TOD_SECONDS_1970_THROUGH_2400` was defined as `13569465600` 
(`2400-01-01T00:00:00Z`). As a result, setting any time past the very first 
second of year 2400 (such as `2400-02-28` in `spclock_err02` or `2400-12-31`) 
also exceeded this constant and triggered the assertion.

### Changes
- **`cpukit/include/rtems/score/todimpl.h`**:
  - Update `TOD_SECONDS_1970_THROUGH_2400` to `13601088000` 
(`2401-01-01T00:00:00Z`), covering all seconds through year 2400 and preserving 
at least 113.4 years of system uptime headroom before 34-bit watchdog overflow.
  - Set `TOD_LATEST_YEAR` to `2400`, documenting the 34-bit watchdog seconds 
constraint and uptime margin.
- **`cpukit/include/rtems/rtems/clock.h`**:
  - Update documentation to reflect that the time of day set by 
`rtems_clock_set()` shall be before `2401-01-01:00:00.000000000Z` and the 
latest valid time accepted by `clock_settime()` is 
`2401-01-01T00:00:00.000000000Z`.
- **`testsuites/sptests/spclock_err02/init.c`**:
  - Verify leap year rollover for year 2400 (Feb 28 to Feb 29).
  - Verify year-end rollover from 2400 to 2401 (Dec 31, 2400 to Jan 1, 2401).
  - Verify rejection of year 2401 with `RTEMS_INVALID_CLOCK`.
  - Remove defunct tests for years > 2400.
- **`testsuites/validation/tc-clock-set.c`**:
  - Update `RtemsClockReqSet_Pre_ToD_Oldest` to year 2400 
(`2400-12-31T23:59:59.999999999Z`).
  - Update `RtemsClockReqSet_Pre_ToD_TooOld` to year 2401 
(`2401-01-01T00:00:00.000000000Z`).

-- 
View it on GitLab: 
https://gitlab.rtems.org/rtems/rtos/rtems/-/merge_requests/1484
You're receiving this email because of your account on gitlab.rtems.org. 
Unsubscribe from this thread: 
https://gitlab.rtems.org/-/namespace/49/sent_notifications/5-6sz0cc3w905cq3xspelixc11x-1d/unsubscribe
 | Manage all notifications: https://gitlab.rtems.org/-/profile/notifications | 
Help: https://gitlab.rtems.org/help


_______________________________________________
bugs mailing list
[email protected]
http://lists.rtems.org/mailman/listinfo/bugs

Reply via email to