Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.kernel > #91311 > unrolled thread

Bug#1128522: linux-image-6.12.73+deb13-amd64: Recent security kernels break chrony's use of PHC clock (6.1.162, 6.12.73)

Started bymaney <maney@two14.net>
First post2026-02-20 21:30 +0100
Last post2026-02-20 21:50 +0100
Articles 3 — 3 participants

Back to article view | Back to linux.debian.kernel


Contents

  Bug#1128522: linux-image-6.12.73+deb13-amd64: Recent security kernels break chrony's use of PHC clock (6.1.162, 6.12.73) maney <maney@two14.net> - 2026-02-20 21:30 +0100
    Processed: Re: Bug#1128522: linux-image-6.12.73+deb13-amd64:  Recent security kernels break chrony's use of PHC clock (6.1.162, 6.12.73) "Debian Bug Tracking System" <owner@bugs.debian.org> - 2026-02-20 21:50 +0100
    Bug#1128522: linux-image-6.12.73+deb13-amd64: Recent security kernels break chrony's use of PHC clock (6.1.162, 6.12.73) Salvatore Bonaccorso <carnil@debian.org> - 2026-02-20 21:50 +0100

#91311 — Bug#1128522: linux-image-6.12.73+deb13-amd64: Recent security kernels break chrony's use of PHC clock (6.1.162, 6.12.73)

Frommaney <maney@two14.net>
Date2026-02-20 21:30 +0100
SubjectBug#1128522: linux-image-6.12.73+deb13-amd64: Recent security kernels break chrony's use of PHC clock (6.1.162, 6.12.73)
Message-ID<MqFiq-255x-5@gated-at.bofh.it>
Package: linux-image-6.12.73+deb13-amd64
Version: linux-image-6.12.73+deb13-amd64
Severity: normal

Observed on amd64 machines with both Bookworm (6.1.162) and Trixie (6.12.73)
current security linux-image releases. Different CPU familys (Jaguar and
Ryzen). Different chrony versions (4.3-2+deb12u1, 4.6.1-3).

To observe problem, with security kernels installed, setup a PHC clock
source for the existing I210 interface, eg.

refclock PHC /dev/ptp0:extpps

Observe error when starting chrony:

chronyd[837]: Fatal error : Could not enable external PHC timestamping

(wording may be different between the two systems, this was Trixie)

Both work fine under previous kernels 6.1.159 and 6.12.73 (I do not
guarantee there weren't any other versions released between these and the
recent security, neither machine is exposed to the internet and so don't
always get updated immediately.)

In both cases chrony's use of the PHC for timestamping appears unimpaired by
the kernels that fail the PHC refclock. The bookworm platform has linuxptp
installed. phc_ctl and ts2phc work fine with either kernel.

I left the severity at normal, but it's much more serious to a machine
that's syncing to a PPS source like this.

Workaround: roll back those security kernels, of course. And test any future
releases for this issue, of course.

-- System Information:
irrelevant, as I'm reporting from a third machine that has reportbug and
email setup.

[toc] | [next] | [standalone]


#91312 — Processed: Re: Bug#1128522: linux-image-6.12.73+deb13-amd64: Recent security kernels break chrony's use of PHC clock (6.1.162, 6.12.73)

From"Debian Bug Tracking System" <owner@bugs.debian.org>
Date2026-02-20 21:50 +0100
SubjectProcessed: Re: Bug#1128522: linux-image-6.12.73+deb13-amd64: Recent security kernels break chrony's use of PHC clock (6.1.162, 6.12.73)
Message-ID<MqFBM-25cF-5@gated-at.bofh.it>
In reply to#91311
Processing control commands:

> reassign -1 src:chrony
Bug #1128522 [linux-image-6.12.73+deb13-amd64] linux-image-6.12.73+deb13-amd64: Recent security kernels break chrony's use of PHC clock (6.1.162, 6.12.73)
Bug reassigned from package 'linux-image-6.12.73+deb13-amd64' to 'src:chrony'.
No longer marked as found in versions linux-image-6.12.73+deb13-amd64.
Ignoring request to alter fixed versions of bug #1128522 to the same values previously set
> forcemerge 1127659 -1
Bug #1127659 [src:chrony] linux-image-6.12.69+deb13-rt-amd64: chrony 4.6.1 cannot configure extpps for PHC refclocks due to new permission check
Bug #1128522 [src:chrony] linux-image-6.12.73+deb13-amd64: Recent security kernels break chrony's use of PHC clock (6.1.162, 6.12.73)
Set Bug forwarded-to-address to 'https://lore.kernel.org/stable/a85c602ecdd204145d4b7364418c7c52b8d6cd44.camel@pengutronix.de/'.
Severity set to 'important' from 'normal'
Marked as fixed in versions chrony/4.8-1.
Marked as found in versions chrony/4.3-2, chrony/4.6.1-3, and chrony/4.3-2+deb12u1.
Added tag(s) bookworm, trixie, fixed-upstream, and upstream.
Merged 1127659 1128522

-- 
1127659: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1127659
1128522: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1128522
Debian Bug Tracking System
Contact owner@bugs.debian.org with problems

[toc] | [prev] | [next] | [standalone]


#91313

FromSalvatore Bonaccorso <carnil@debian.org>
Date2026-02-20 21:50 +0100
Message-ID<MqFBM-25cF-7@gated-at.bofh.it>
In reply to#91311
Control: reassign -1 src:chrony
Control: forcemerge 1127659 -1

Hi,

On Fri, Feb 20, 2026 at 02:20:00PM -0600, maney wrote:
> Package: linux-image-6.12.73+deb13-amd64
> Version: linux-image-6.12.73+deb13-amd64
> Severity: normal
> 
> Observed on amd64 machines with both Bookworm (6.1.162) and Trixie (6.12.73)
> current security linux-image releases. Different CPU familys (Jaguar and
> Ryzen). Different chrony versions (4.3-2+deb12u1, 4.6.1-3).
> 
> To observe problem, with security kernels installed, setup a PHC clock
> source for the existing I210 interface, eg.
> 
> refclock PHC /dev/ptp0:extpps
> 
> Observe error when starting chrony:
> 
> chronyd[837]: Fatal error : Could not enable external PHC timestamping
> 
> (wording may be different between the two systems, this was Trixie)
> 
> Both work fine under previous kernels 6.1.159 and 6.12.73 (I do not
> guarantee there weren't any other versions released between these and the
> recent security, neither machine is exposed to the internet and so don't
> always get updated immediately.)
> 
> In both cases chrony's use of the PHC for timestamping appears unimpaired by
> the kernels that fail the PHC refclock. The bookworm platform has linuxptp
> installed. phc_ctl and ts2phc work fine with either kernel.
> 
> I left the severity at normal, but it's much more serious to a machine
> that's syncing to a PPS source like this.
> 
> Workaround: roll back those security kernels, of course. And test any future
> releases for this issue, of course.

This is #1127659. Background the issue will not be fixed in src:linux
as the commit introducing this is considered a security fix, but the
maintainer of src:chrony will is preparing updates.

Regards,
Salvatore

[toc] | [prev] | [standalone]


Back to top | Article view | linux.debian.kernel


csiph-web