mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH RFT 0/3] firmware: exynos-acpm: Use __counted_by()
@ 2026-02-14 12:39 Krzysztof Kozlowski
  2026-02-14 12:39 ` [PATCH RFT 1/3] firmware: exynos-acpm: Use unsigned int for acpm_pmic_linux_errmap index Krzysztof Kozlowski
                   ` (2 more replies)
  0 siblings, 3 replies; 9+ messages in thread
From: Krzysztof Kozlowski @ 2026-02-14 12:39 UTC (permalink / raw)
  To: Tudor Ambarus, Krzysztof Kozlowski, Alim Akhtar, Kees Cook,
	Gustavo A. R. Silva, Nathan Chancellor, Nick Desaulniers,
	Bill Wendling, Justin Stitt
  Cc: linux-kernel, linux-samsung-soc, linux-arm-kernel,
	linux-hardening, llvm, Krzysztof Kozlowski

Improve safety of the code by using __counted_by/__counted_by_ptr.

Best regards,
Krzysztof

---
Krzysztof Kozlowski (3):
      firmware: exynos-acpm: Use unsigned int for acpm_pmic_linux_errmap index
      firmware: exynos-acpm: Count number of commands in acpm_xfer
      firmware: exynos-acpm: Count acpm_xfer buffers with __counted_by_ptr

 drivers/firmware/samsung/exynos-acpm-dvfs.c |  8 ++++----
 drivers/firmware/samsung/exynos-acpm-pmic.c | 16 ++++++++--------
 drivers/firmware/samsung/exynos-acpm.c      | 12 +++++++-----
 drivers/firmware/samsung/exynos-acpm.h      |  8 ++++----
 4 files changed, 23 insertions(+), 21 deletions(-)
---
base-commit: 635c467cc14ebdffab3f77610217c1dacaf88e8c
change-id: 20260214-firmare-acpm-counted-255f287c3dce

Best regards,
-- 
Krzysztof Kozlowski <krzysztof.kozlowski@oss.qualcomm.com>


^ permalink raw reply	[flat|nested] 9+ messages in thread

* [PATCH RFT 1/3] firmware: exynos-acpm: Use unsigned int for acpm_pmic_linux_errmap index
  2026-02-14 12:39 [PATCH RFT 0/3] firmware: exynos-acpm: Use __counted_by() Krzysztof Kozlowski
@ 2026-02-14 12:39 ` Krzysztof Kozlowski
  2026-02-19 10:16   ` Tudor Ambarus
  2026-02-14 12:39 ` [PATCH RFT 2/3] firmware: exynos-acpm: Count number of commands in acpm_xfer Krzysztof Kozlowski
  2026-02-14 12:39 ` [PATCH RFT 3/3] firmware: exynos-acpm: Count acpm_xfer buffers with __counted_by_ptr Krzysztof Kozlowski
  2 siblings, 1 reply; 9+ messages in thread
From: Krzysztof Kozlowski @ 2026-02-14 12:39 UTC (permalink / raw)
  To: Tudor Ambarus, Krzysztof Kozlowski, Alim Akhtar, Kees Cook,
	Gustavo A. R. Silva, Nathan Chancellor, Nick Desaulniers,
	Bill Wendling, Justin Stitt
  Cc: linux-kernel, linux-samsung-soc, linux-arm-kernel,
	linux-hardening, llvm, Krzysztof Kozlowski

acpm_pmic_to_linux_err() uses an unsigned integer obtained from messages
as index of array to map them to error codes.  Array index cannot be
negative, so make that explicit.

Signed-off-by: Krzysztof Kozlowski <krzysztof.kozlowski@oss.qualcomm.com>
---
 drivers/firmware/samsung/exynos-acpm-pmic.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/firmware/samsung/exynos-acpm-pmic.c b/drivers/firmware/samsung/exynos-acpm-pmic.c
index 961d7599e422..44265db34ae6 100644
--- a/drivers/firmware/samsung/exynos-acpm-pmic.c
+++ b/drivers/firmware/samsung/exynos-acpm-pmic.c
@@ -41,7 +41,7 @@ static const int acpm_pmic_linux_errmap[] = {
 	[2] = -EACCES, /* Write register can't be accessed or issues to access it. */
 };
 
-static int acpm_pmic_to_linux_err(int err)
+static int acpm_pmic_to_linux_err(unsigned int err)
 {
 	if (err >= 0 && err < ARRAY_SIZE(acpm_pmic_linux_errmap))
 		return acpm_pmic_linux_errmap[err];

-- 
2.51.0


^ permalink raw reply	[flat|nested] 9+ messages in thread

* [PATCH RFT 2/3] firmware: exynos-acpm: Count number of commands in acpm_xfer
  2026-02-14 12:39 [PATCH RFT 0/3] firmware: exynos-acpm: Use __counted_by() Krzysztof Kozlowski
  2026-02-14 12:39 ` [PATCH RFT 1/3] firmware: exynos-acpm: Use unsigned int for acpm_pmic_linux_errmap index Krzysztof Kozlowski
@ 2026-02-14 12:39 ` Krzysztof Kozlowski
  2026-02-14 19:13   ` Krzysztof Kozlowski
  2026-02-19 10:27   ` Tudor Ambarus
  2026-02-14 12:39 ` [PATCH RFT 3/3] firmware: exynos-acpm: Count acpm_xfer buffers with __counted_by_ptr Krzysztof Kozlowski
  2 siblings, 2 replies; 9+ messages in thread
From: Krzysztof Kozlowski @ 2026-02-14 12:39 UTC (permalink / raw)
  To: Tudor Ambarus, Krzysztof Kozlowski, Alim Akhtar, Kees Cook,
	Gustavo A. R. Silva, Nathan Chancellor, Nick Desaulniers,
	Bill Wendling, Justin Stitt
  Cc: linux-kernel, linux-samsung-soc, linux-arm-kernel,
	linux-hardening, llvm, Krzysztof Kozlowski

Struct acpm_xfer holds two buffers with u32 commands - rxd and txd - and
counts their size by rxlen and txlen.  "len" suffix is here ambiguous,
so could mean length of the buffer or length of commands, and these are
not the same since each command is u32.  Rename these to rxcnt and
txcnt, and change their usage to count the number of commands in each
buffer.

This will have a benafit of allowing to use __counted_by_ptr later.

Signed-off-by: Krzysztof Kozlowski <krzysztof.kozlowski@oss.qualcomm.com>
---
 drivers/firmware/samsung/exynos-acpm-dvfs.c |  8 ++++----
 drivers/firmware/samsung/exynos-acpm-pmic.c | 14 +++++++-------
 drivers/firmware/samsung/exynos-acpm.c      | 12 +++++++-----
 drivers/firmware/samsung/exynos-acpm.h      |  4 ++--
 4 files changed, 20 insertions(+), 18 deletions(-)

diff --git a/drivers/firmware/samsung/exynos-acpm-dvfs.c b/drivers/firmware/samsung/exynos-acpm-dvfs.c
index 1c5b2b143bcc..55ec6ad9d87e 100644
--- a/drivers/firmware/samsung/exynos-acpm-dvfs.c
+++ b/drivers/firmware/samsung/exynos-acpm-dvfs.c
@@ -25,11 +25,11 @@ static void acpm_dvfs_set_xfer(struct acpm_xfer *xfer, u32 *cmd, size_t cmdlen,
 {
 	xfer->acpm_chan_id = acpm_chan_id;
 	xfer->txd = cmd;
-	xfer->txlen = cmdlen;
+	xfer->txcnt = cmdlen;
 
 	if (response) {
 		xfer->rxd = cmd;
-		xfer->rxlen = cmdlen;
+		xfer->rxcnt = cmdlen;
 	}
 }
 
@@ -50,7 +50,7 @@ int acpm_dvfs_set_rate(const struct acpm_handle *handle,
 	u32 cmd[4];
 
 	acpm_dvfs_init_set_rate_cmd(cmd, clk_id, rate);
-	acpm_dvfs_set_xfer(&xfer, cmd, sizeof(cmd), acpm_chan_id, false);
+	acpm_dvfs_set_xfer(&xfer, cmd, ARRAY_SIZE(cmd), acpm_chan_id, false);
 
 	return acpm_do_xfer(handle, &xfer);
 }
@@ -70,7 +70,7 @@ unsigned long acpm_dvfs_get_rate(const struct acpm_handle *handle,
 	int ret;
 
 	acpm_dvfs_init_get_rate_cmd(cmd, clk_id);
-	acpm_dvfs_set_xfer(&xfer, cmd, sizeof(cmd), acpm_chan_id, true);
+	acpm_dvfs_set_xfer(&xfer, cmd, ARRAY_SIZE(cmd), acpm_chan_id, true);
 
 	ret = acpm_do_xfer(handle, &xfer);
 	if (ret)
diff --git a/drivers/firmware/samsung/exynos-acpm-pmic.c b/drivers/firmware/samsung/exynos-acpm-pmic.c
index 44265db34ae6..26a9024d8ed8 100644
--- a/drivers/firmware/samsung/exynos-acpm-pmic.c
+++ b/drivers/firmware/samsung/exynos-acpm-pmic.c
@@ -63,8 +63,8 @@ static void acpm_pmic_set_xfer(struct acpm_xfer *xfer, u32 *cmd, size_t cmdlen,
 {
 	xfer->txd = cmd;
 	xfer->rxd = cmd;
-	xfer->txlen = cmdlen;
-	xfer->rxlen = cmdlen;
+	xfer->txcnt = cmdlen;
+	xfer->rxcnt = cmdlen;
 	xfer->acpm_chan_id = acpm_chan_id;
 }
 
@@ -86,7 +86,7 @@ int acpm_pmic_read_reg(const struct acpm_handle *handle,
 	int ret;
 
 	acpm_pmic_init_read_cmd(cmd, type, reg, chan);
-	acpm_pmic_set_xfer(&xfer, cmd, sizeof(cmd), acpm_chan_id);
+	acpm_pmic_set_xfer(&xfer, cmd, ARRAY_SIZE(cmd), acpm_chan_id);
 
 	ret = acpm_do_xfer(handle, &xfer);
 	if (ret)
@@ -119,7 +119,7 @@ int acpm_pmic_bulk_read(const struct acpm_handle *handle,
 		return -EINVAL;
 
 	acpm_pmic_init_bulk_read_cmd(cmd, type, reg, chan, count);
-	acpm_pmic_set_xfer(&xfer, cmd, sizeof(cmd), acpm_chan_id);
+	acpm_pmic_set_xfer(&xfer, cmd, ARRAY_SIZE(cmd), acpm_chan_id);
 
 	ret = acpm_do_xfer(handle, &xfer);
 	if (ret)
@@ -159,7 +159,7 @@ int acpm_pmic_write_reg(const struct acpm_handle *handle,
 	int ret;
 
 	acpm_pmic_init_write_cmd(cmd, type, reg, chan, value);
-	acpm_pmic_set_xfer(&xfer, cmd, sizeof(cmd), acpm_chan_id);
+	acpm_pmic_set_xfer(&xfer, cmd, ARRAY_SIZE(cmd), acpm_chan_id);
 
 	ret = acpm_do_xfer(handle, &xfer);
 	if (ret)
@@ -199,7 +199,7 @@ int acpm_pmic_bulk_write(const struct acpm_handle *handle,
 		return -EINVAL;
 
 	acpm_pmic_init_bulk_write_cmd(cmd, type, reg, chan, count, buf);
-	acpm_pmic_set_xfer(&xfer, cmd, sizeof(cmd), acpm_chan_id);
+	acpm_pmic_set_xfer(&xfer, cmd, ARRAY_SIZE(cmd), acpm_chan_id);
 
 	ret = acpm_do_xfer(handle, &xfer);
 	if (ret)
@@ -229,7 +229,7 @@ int acpm_pmic_update_reg(const struct acpm_handle *handle,
 	int ret;
 
 	acpm_pmic_init_update_cmd(cmd, type, reg, chan, value, mask);
-	acpm_pmic_set_xfer(&xfer, cmd, sizeof(cmd), acpm_chan_id);
+	acpm_pmic_set_xfer(&xfer, cmd, ARRAY_SIZE(cmd), acpm_chan_id);
 
 	ret = acpm_do_xfer(handle, &xfer);
 	if (ret)
diff --git a/drivers/firmware/samsung/exynos-acpm.c b/drivers/firmware/samsung/exynos-acpm.c
index 0cb269c70460..242745e8394c 100644
--- a/drivers/firmware/samsung/exynos-acpm.c
+++ b/drivers/firmware/samsung/exynos-acpm.c
@@ -205,7 +205,7 @@ static void acpm_get_saved_rx(struct acpm_chan *achan,
 	rx_seqnum = FIELD_GET(ACPM_PROTOCOL_SEQNUM, rx_data->cmd[0]);
 
 	if (rx_seqnum == tx_seqnum) {
-		memcpy(xfer->rxd, rx_data->cmd, xfer->rxlen);
+		memcpy(xfer->rxd, rx_data->cmd, xfer->rxcnt * sizeof(*xfer->rxd));
 		clear_bit(rx_seqnum - 1, achan->bitmap_seqnum);
 	}
 }
@@ -259,7 +259,7 @@ static int acpm_get_rx(struct acpm_chan *achan, const struct acpm_xfer *xfer)
 		if (rx_data->response) {
 			if (rx_seqnum == tx_seqnum) {
 				__ioread32_copy(xfer->rxd, addr,
-						xfer->rxlen / 4);
+						xfer->rxcnt);
 				rx_set = true;
 				clear_bit(seqnum, achan->bitmap_seqnum);
 			} else {
@@ -270,7 +270,7 @@ static int acpm_get_rx(struct acpm_chan *achan, const struct acpm_xfer *xfer)
 				 * after the response is copied to the request.
 				 */
 				__ioread32_copy(rx_data->cmd, addr,
-						xfer->rxlen / 4);
+						xfer->rxcnt);
 			}
 		} else {
 			clear_bit(seqnum, achan->bitmap_seqnum);
@@ -425,7 +425,9 @@ int acpm_do_xfer(const struct acpm_handle *handle, const struct acpm_xfer *xfer)
 
 	achan = &acpm->chans[xfer->acpm_chan_id];
 
-	if (!xfer->txd || xfer->txlen > achan->mlen || xfer->rxlen > achan->mlen)
+	if (!xfer->txd || (xfer->txcnt * sizeof(*xfer->txd) > achan->mlen))
+		return -EINVAL;
+	if (xfer->rxcnt * sizeof(*xfer->rxd) > achan->mlen)
 		return -EINVAL;
 
 	if (!achan->poll_completion) {
@@ -448,7 +450,7 @@ int acpm_do_xfer(const struct acpm_handle *handle, const struct acpm_xfer *xfer)
 
 		/* Write TX command. */
 		__iowrite32_copy(achan->tx.base + achan->mlen * tx_front,
-				 xfer->txd, xfer->txlen / 4);
+				 xfer->txd, xfer->txcnt);
 
 		/* Advance TX front. */
 		writel(idx, achan->tx.front);
diff --git a/drivers/firmware/samsung/exynos-acpm.h b/drivers/firmware/samsung/exynos-acpm.h
index 2d14cb58f98c..422fbcac7284 100644
--- a/drivers/firmware/samsung/exynos-acpm.h
+++ b/drivers/firmware/samsung/exynos-acpm.h
@@ -10,8 +10,8 @@
 struct acpm_xfer {
 	const u32 *txd;
 	u32 *rxd;
-	size_t txlen;
-	size_t rxlen;
+	size_t txcnt;
+	size_t rxcnt;
 	unsigned int acpm_chan_id;
 };
 

-- 
2.51.0


^ permalink raw reply	[flat|nested] 9+ messages in thread

* [PATCH RFT 3/3] firmware: exynos-acpm: Count acpm_xfer buffers with __counted_by_ptr
  2026-02-14 12:39 [PATCH RFT 0/3] firmware: exynos-acpm: Use __counted_by() Krzysztof Kozlowski
  2026-02-14 12:39 ` [PATCH RFT 1/3] firmware: exynos-acpm: Use unsigned int for acpm_pmic_linux_errmap index Krzysztof Kozlowski
  2026-02-14 12:39 ` [PATCH RFT 2/3] firmware: exynos-acpm: Count number of commands in acpm_xfer Krzysztof Kozlowski
@ 2026-02-14 12:39 ` Krzysztof Kozlowski
  2026-02-19 11:20   ` Tudor Ambarus
  2 siblings, 1 reply; 9+ messages in thread
From: Krzysztof Kozlowski @ 2026-02-14 12:39 UTC (permalink / raw)
  To: Tudor Ambarus, Krzysztof Kozlowski, Alim Akhtar, Kees Cook,
	Gustavo A. R. Silva, Nathan Chancellor, Nick Desaulniers,
	Bill Wendling, Justin Stitt
  Cc: linux-kernel, linux-samsung-soc, linux-arm-kernel,
	linux-hardening, llvm, Krzysztof Kozlowski

Use __counted_by_ptr() attribute on the acpm_xfer buffers so UBSAN will
validate runtime that we do not pass over the buffer size, thus making
code safer.

Usage of __counted_by_ptr() (or actually __counted_by()) requires that
counter is initialized before counted array.

Signed-off-by: Krzysztof Kozlowski <krzysztof.kozlowski@oss.qualcomm.com>

---

__counted_by_ptr() actually maps to __counted_by() for clang v20.
Alternatively we could introduce new __sized_by(), already supported by
clang v20, but it is not available for GCC, AFAIU.

RFT, testing would need clang=20+ with COMNFIG_UBSAN and
CONFIG_UBSAN_BOUNDS enabled.
---
 drivers/firmware/samsung/exynos-acpm-dvfs.c | 4 ++--
 drivers/firmware/samsung/exynos-acpm.h      | 4 ++--
 2 files changed, 4 insertions(+), 4 deletions(-)

diff --git a/drivers/firmware/samsung/exynos-acpm-dvfs.c b/drivers/firmware/samsung/exynos-acpm-dvfs.c
index 55ec6ad9d87e..a4864973f65d 100644
--- a/drivers/firmware/samsung/exynos-acpm-dvfs.c
+++ b/drivers/firmware/samsung/exynos-acpm-dvfs.c
@@ -24,12 +24,12 @@ static void acpm_dvfs_set_xfer(struct acpm_xfer *xfer, u32 *cmd, size_t cmdlen,
 			       unsigned int acpm_chan_id, bool response)
 {
 	xfer->acpm_chan_id = acpm_chan_id;
-	xfer->txd = cmd;
 	xfer->txcnt = cmdlen;
+	xfer->txd = cmd;
 
 	if (response) {
-		xfer->rxd = cmd;
 		xfer->rxcnt = cmdlen;
+		xfer->rxd = cmd;
 	}
 }
 
diff --git a/drivers/firmware/samsung/exynos-acpm.h b/drivers/firmware/samsung/exynos-acpm.h
index 422fbcac7284..8392fcb91f45 100644
--- a/drivers/firmware/samsung/exynos-acpm.h
+++ b/drivers/firmware/samsung/exynos-acpm.h
@@ -8,8 +8,8 @@
 #define __EXYNOS_ACPM_H__
 
 struct acpm_xfer {
-	const u32 *txd;
-	u32 *rxd;
+	const u32 *txd __counted_by_ptr(txcnt);
+	u32 *rxd __counted_by_ptr(rxcnt);
 	size_t txcnt;
 	size_t rxcnt;
 	unsigned int acpm_chan_id;

-- 
2.51.0


^ permalink raw reply	[flat|nested] 9+ messages in thread

* Re: [PATCH RFT 2/3] firmware: exynos-acpm: Count number of commands in acpm_xfer
  2026-02-14 12:39 ` [PATCH RFT 2/3] firmware: exynos-acpm: Count number of commands in acpm_xfer Krzysztof Kozlowski
@ 2026-02-14 19:13   ` Krzysztof Kozlowski
  2026-02-19 10:27   ` Tudor Ambarus
  1 sibling, 0 replies; 9+ messages in thread
From: Krzysztof Kozlowski @ 2026-02-14 19:13 UTC (permalink / raw)
  To: Krzysztof Kozlowski, Tudor Ambarus, Alim Akhtar, Kees Cook,
	Gustavo A. R. Silva, Nathan Chancellor, Nick Desaulniers,
	Bill Wendling, Justin Stitt
  Cc: linux-kernel, linux-samsung-soc, linux-arm-kernel, linux-hardening, llvm

On 14/02/2026 13:39, Krzysztof Kozlowski wrote:
>  
>  	if (response) {
>  		xfer->rxd = cmd;
> -		xfer->rxlen = cmdlen;
> +		xfer->rxcnt = cmdlen;
>  	}
>  }
>  
> @@ -50,7 +50,7 @@ int acpm_dvfs_set_rate(const struct acpm_handle *handle,
>  	u32 cmd[4];
>  
>  	acpm_dvfs_init_set_rate_cmd(cmd, clk_id, rate);
> -	acpm_dvfs_set_xfer(&xfer, cmd, sizeof(cmd), acpm_chan_id, false);
> +	acpm_dvfs_set_xfer(&xfer, cmd, ARRAY_SIZE(cmd), acpm_chan_id, false);

Went fine through few build tests, but apparently there is a setup this
needs proper header (<linux/array_size.h>), as reported by kbuild robot.

There will be v2 in few days.

Best regards,
Krzysztof

^ permalink raw reply	[flat|nested] 9+ messages in thread

* Re: [PATCH RFT 1/3] firmware: exynos-acpm: Use unsigned int for acpm_pmic_linux_errmap index
  2026-02-14 12:39 ` [PATCH RFT 1/3] firmware: exynos-acpm: Use unsigned int for acpm_pmic_linux_errmap index Krzysztof Kozlowski
@ 2026-02-19 10:16   ` Tudor Ambarus
  0 siblings, 0 replies; 9+ messages in thread
From: Tudor Ambarus @ 2026-02-19 10:16 UTC (permalink / raw)
  To: Krzysztof Kozlowski, Krzysztof Kozlowski, Alim Akhtar, Kees Cook,
	Gustavo A. R. Silva, Nathan Chancellor, Nick Desaulniers,
	Bill Wendling, Justin Stitt
  Cc: linux-kernel, linux-samsung-soc, linux-arm-kernel, linux-hardening, llvm



On 2/14/26 2:39 PM, Krzysztof Kozlowski wrote:
> acpm_pmic_to_linux_err() uses an unsigned integer obtained from messages
> as index of array to map them to error codes.  Array index cannot be
> negative, so make that explicit.
> 
> Signed-off-by: Krzysztof Kozlowski <krzysztof.kozlowski@oss.qualcomm.com>

Reviewed-by: Tudor Ambarus <tudor.ambarus@linaro.org>

> ---
>  drivers/firmware/samsung/exynos-acpm-pmic.c | 2 +-
>  1 file changed, 1 insertion(+), 1 deletion(-)
> 
> diff --git a/drivers/firmware/samsung/exynos-acpm-pmic.c b/drivers/firmware/samsung/exynos-acpm-pmic.c
> index 961d7599e422..44265db34ae6 100644
> --- a/drivers/firmware/samsung/exynos-acpm-pmic.c
> +++ b/drivers/firmware/samsung/exynos-acpm-pmic.c
> @@ -41,7 +41,7 @@ static const int acpm_pmic_linux_errmap[] = {
>  	[2] = -EACCES, /* Write register can't be accessed or issues to access it. */
>  };
>  
> -static int acpm_pmic_to_linux_err(int err)
> +static int acpm_pmic_to_linux_err(unsigned int err)
>  {
>  	if (err >= 0 && err < ARRAY_SIZE(acpm_pmic_linux_errmap))
>  		return acpm_pmic_linux_errmap[err];
> 


^ permalink raw reply	[flat|nested] 9+ messages in thread

* Re: [PATCH RFT 2/3] firmware: exynos-acpm: Count number of commands in acpm_xfer
  2026-02-14 12:39 ` [PATCH RFT 2/3] firmware: exynos-acpm: Count number of commands in acpm_xfer Krzysztof Kozlowski
  2026-02-14 19:13   ` Krzysztof Kozlowski
@ 2026-02-19 10:27   ` Tudor Ambarus
  2026-02-19 10:31     ` Krzysztof Kozlowski
  1 sibling, 1 reply; 9+ messages in thread
From: Tudor Ambarus @ 2026-02-19 10:27 UTC (permalink / raw)
  To: Krzysztof Kozlowski, Krzysztof Kozlowski, Alim Akhtar, Kees Cook,
	Gustavo A. R. Silva, Nathan Chancellor, Nick Desaulniers,
	Bill Wendling, Justin Stitt
  Cc: linux-kernel, linux-samsung-soc, linux-arm-kernel, linux-hardening, llvm



On 2/14/26 2:39 PM, Krzysztof Kozlowski wrote:
> Struct acpm_xfer holds two buffers with u32 commands - rxd and txd - and
> counts their size by rxlen and txlen.  "len" suffix is here ambiguous,
> so could mean length of the buffer or length of commands, and these are
> not the same since each command is u32.  Rename these to rxcnt and
> txcnt, and change their usage to count the number of commands in each
> buffer.
> 
> This will have a benafit of allowing to use __counted_by_ptr later.

                    ^typo, benefit.
> 
> Signed-off-by: Krzysztof Kozlowski <krzysztof.kozlowski@oss.qualcomm.com>
> ---
>  drivers/firmware/samsung/exynos-acpm-dvfs.c |  8 ++++----
>  drivers/firmware/samsung/exynos-acpm-pmic.c | 14 +++++++-------
>  drivers/firmware/samsung/exynos-acpm.c      | 12 +++++++-----
>  drivers/firmware/samsung/exynos-acpm.h      |  4 ++--
>  4 files changed, 20 insertions(+), 18 deletions(-)
> 
> diff --git a/drivers/firmware/samsung/exynos-acpm-dvfs.c b/drivers/firmware/samsung/exynos-acpm-dvfs.c
> index 1c5b2b143bcc..55ec6ad9d87e 100644
> --- a/drivers/firmware/samsung/exynos-acpm-dvfs.c
> +++ b/drivers/firmware/samsung/exynos-acpm-dvfs.c
> @@ -25,11 +25,11 @@ static void acpm_dvfs_set_xfer(struct acpm_xfer *xfer, u32 *cmd, size_t cmdlen,
>  {
>  	xfer->acpm_chan_id = acpm_chan_id;
>  	xfer->txd = cmd;
> -	xfer->txlen = cmdlen;
> +	xfer->txcnt = cmdlen;
>  
>  	if (response) {
>  		xfer->rxd = cmd;
> -		xfer->rxlen = cmdlen;
> +		xfer->rxcnt = cmdlen;
>  	}
>  }
>  
> @@ -50,7 +50,7 @@ int acpm_dvfs_set_rate(const struct acpm_handle *handle,
>  	u32 cmd[4];
>  
>  	acpm_dvfs_init_set_rate_cmd(cmd, clk_id, rate);
> -	acpm_dvfs_set_xfer(&xfer, cmd, sizeof(cmd), acpm_chan_id, false);
> +	acpm_dvfs_set_xfer(&xfer, cmd, ARRAY_SIZE(cmd), acpm_chan_id, false);
>  
>  	return acpm_do_xfer(handle, &xfer);
>  }
> @@ -70,7 +70,7 @@ unsigned long acpm_dvfs_get_rate(const struct acpm_handle *handle,
>  	int ret;
>  
>  	acpm_dvfs_init_get_rate_cmd(cmd, clk_id);
> -	acpm_dvfs_set_xfer(&xfer, cmd, sizeof(cmd), acpm_chan_id, true);
> +	acpm_dvfs_set_xfer(&xfer, cmd, ARRAY_SIZE(cmd), acpm_chan_id, true);
>  
>  	ret = acpm_do_xfer(handle, &xfer);
>  	if (ret)
> diff --git a/drivers/firmware/samsung/exynos-acpm-pmic.c b/drivers/firmware/samsung/exynos-acpm-pmic.c
> index 44265db34ae6..26a9024d8ed8 100644
> --- a/drivers/firmware/samsung/exynos-acpm-pmic.c
> +++ b/drivers/firmware/samsung/exynos-acpm-pmic.c
> @@ -63,8 +63,8 @@ static void acpm_pmic_set_xfer(struct acpm_xfer *xfer, u32 *cmd, size_t cmdlen,
>  {
>  	xfer->txd = cmd;
>  	xfer->rxd = cmd;
> -	xfer->txlen = cmdlen;
> -	xfer->rxlen = cmdlen;
> +	xfer->txcnt = cmdlen;
> +	xfer->rxcnt = cmdlen;
>  	xfer->acpm_chan_id = acpm_chan_id;
>  }
>  
> @@ -86,7 +86,7 @@ int acpm_pmic_read_reg(const struct acpm_handle *handle,
>  	int ret;
>  
>  	acpm_pmic_init_read_cmd(cmd, type, reg, chan);
> -	acpm_pmic_set_xfer(&xfer, cmd, sizeof(cmd), acpm_chan_id);
> +	acpm_pmic_set_xfer(&xfer, cmd, ARRAY_SIZE(cmd), acpm_chan_id);
>  
>  	ret = acpm_do_xfer(handle, &xfer);
>  	if (ret)
> @@ -119,7 +119,7 @@ int acpm_pmic_bulk_read(const struct acpm_handle *handle,
>  		return -EINVAL;
>  
>  	acpm_pmic_init_bulk_read_cmd(cmd, type, reg, chan, count);
> -	acpm_pmic_set_xfer(&xfer, cmd, sizeof(cmd), acpm_chan_id);
> +	acpm_pmic_set_xfer(&xfer, cmd, ARRAY_SIZE(cmd), acpm_chan_id);
>  
>  	ret = acpm_do_xfer(handle, &xfer);
>  	if (ret)
> @@ -159,7 +159,7 @@ int acpm_pmic_write_reg(const struct acpm_handle *handle,
>  	int ret;
>  
>  	acpm_pmic_init_write_cmd(cmd, type, reg, chan, value);
> -	acpm_pmic_set_xfer(&xfer, cmd, sizeof(cmd), acpm_chan_id);
> +	acpm_pmic_set_xfer(&xfer, cmd, ARRAY_SIZE(cmd), acpm_chan_id);
>  
>  	ret = acpm_do_xfer(handle, &xfer);
>  	if (ret)
> @@ -199,7 +199,7 @@ int acpm_pmic_bulk_write(const struct acpm_handle *handle,
>  		return -EINVAL;
>  
>  	acpm_pmic_init_bulk_write_cmd(cmd, type, reg, chan, count, buf);
> -	acpm_pmic_set_xfer(&xfer, cmd, sizeof(cmd), acpm_chan_id);
> +	acpm_pmic_set_xfer(&xfer, cmd, ARRAY_SIZE(cmd), acpm_chan_id);
>  
>  	ret = acpm_do_xfer(handle, &xfer);
>  	if (ret)
> @@ -229,7 +229,7 @@ int acpm_pmic_update_reg(const struct acpm_handle *handle,
>  	int ret;
>  
>  	acpm_pmic_init_update_cmd(cmd, type, reg, chan, value, mask);
> -	acpm_pmic_set_xfer(&xfer, cmd, sizeof(cmd), acpm_chan_id);
> +	acpm_pmic_set_xfer(&xfer, cmd, ARRAY_SIZE(cmd), acpm_chan_id);
>  
>  	ret = acpm_do_xfer(handle, &xfer);
>  	if (ret)
> diff --git a/drivers/firmware/samsung/exynos-acpm.c b/drivers/firmware/samsung/exynos-acpm.c
> index 0cb269c70460..242745e8394c 100644
> --- a/drivers/firmware/samsung/exynos-acpm.c
> +++ b/drivers/firmware/samsung/exynos-acpm.c
> @@ -205,7 +205,7 @@ static void acpm_get_saved_rx(struct acpm_chan *achan,
>  	rx_seqnum = FIELD_GET(ACPM_PROTOCOL_SEQNUM, rx_data->cmd[0]);
>  
>  	if (rx_seqnum == tx_seqnum) {
> -		memcpy(xfer->rxd, rx_data->cmd, xfer->rxlen);
> +		memcpy(xfer->rxd, rx_data->cmd, xfer->rxcnt * sizeof(*xfer->rxd));
>  		clear_bit(rx_seqnum - 1, achan->bitmap_seqnum);
>  	}
>  }
> @@ -259,7 +259,7 @@ static int acpm_get_rx(struct acpm_chan *achan, const struct acpm_xfer *xfer)
>  		if (rx_data->response) {
>  			if (rx_seqnum == tx_seqnum) {
>  				__ioread32_copy(xfer->rxd, addr,
> -						xfer->rxlen / 4);
> +						xfer->rxcnt);

now __ioread32_copy fits on a single line, without bypassing 80 chars

>  				rx_set = true;
>  				clear_bit(seqnum, achan->bitmap_seqnum);
>  			} else {
> @@ -270,7 +270,7 @@ static int acpm_get_rx(struct acpm_chan *achan, const struct acpm_xfer *xfer)
>  				 * after the response is copied to the request.
>  				 */
>  				__ioread32_copy(rx_data->cmd, addr,
> -						xfer->rxlen / 4);
> +						xfer->rxcnt);
>  			}
>  		} else {
>  			clear_bit(seqnum, achan->bitmap_seqnum);
> @@ -425,7 +425,9 @@ int acpm_do_xfer(const struct acpm_handle *handle, const struct acpm_xfer *xfer)
>  
>  	achan = &acpm->chans[xfer->acpm_chan_id];
>  
> -	if (!xfer->txd || xfer->txlen > achan->mlen || xfer->rxlen > achan->mlen)
> +	if (!xfer->txd || (xfer->txcnt * sizeof(*xfer->txd) > achan->mlen))
> +		return -EINVAL;
> +	if (xfer->rxcnt * sizeof(*xfer->rxd) > achan->mlen)
>  		return -EINVAL;

how about:
        if (!xfer->txd ||
            (xfer->txcnt * sizeof(*xfer->txd) > achan->mlen) ||
            (xfer->rxcnt * sizeof(*xfer->rxd) > achan->mlen))
                return -EINVAL;

>  
>  	if (!achan->poll_completion) {
> @@ -448,7 +450,7 @@ int acpm_do_xfer(const struct acpm_handle *handle, const struct acpm_xfer *xfer)
>  
>  		/* Write TX command. */
>  		__iowrite32_copy(achan->tx.base + achan->mlen * tx_front,
> -				 xfer->txd, xfer->txlen / 4);
> +				 xfer->txd, xfer->txcnt);
>  
>  		/* Advance TX front. */
>  		writel(idx, achan->tx.front);
> diff --git a/drivers/firmware/samsung/exynos-acpm.h b/drivers/firmware/samsung/exynos-acpm.h
> index 2d14cb58f98c..422fbcac7284 100644
> --- a/drivers/firmware/samsung/exynos-acpm.h
> +++ b/drivers/firmware/samsung/exynos-acpm.h
> @@ -10,8 +10,8 @@
>  struct acpm_xfer {
>  	const u32 *txd;
>  	u32 *rxd;
> -	size_t txlen;
> -	size_t rxlen;
> +	size_t txcnt;
> +	size_t rxcnt;
>  	unsigned int acpm_chan_id;
>  };
>  
> 


^ permalink raw reply	[flat|nested] 9+ messages in thread

* Re: [PATCH RFT 2/3] firmware: exynos-acpm: Count number of commands in acpm_xfer
  2026-02-19 10:27   ` Tudor Ambarus
@ 2026-02-19 10:31     ` Krzysztof Kozlowski
  0 siblings, 0 replies; 9+ messages in thread
From: Krzysztof Kozlowski @ 2026-02-19 10:31 UTC (permalink / raw)
  To: Tudor Ambarus, Krzysztof Kozlowski, Alim Akhtar, Kees Cook,
	Gustavo A. R. Silva, Nathan Chancellor, Nick Desaulniers,
	Bill Wendling, Justin Stitt
  Cc: linux-kernel, linux-samsung-soc, linux-arm-kernel, linux-hardening, llvm

On 19/02/2026 11:27, Tudor Ambarus wrote:
> 
> 
> On 2/14/26 2:39 PM, Krzysztof Kozlowski wrote:
>> Struct acpm_xfer holds two buffers with u32 commands - rxd and txd - and
>> counts their size by rxlen and txlen.  "len" suffix is here ambiguous,
>> so could mean length of the buffer or length of commands, and these are
>> not the same since each command is u32.  Rename these to rxcnt and
>> txcnt, and change their usage to count the number of commands in each
>> buffer.
>>
>> This will have a benafit of allowing to use __counted_by_ptr later.
> 
>                     ^typo, benefit.

ack

>>
>> Signed-off-by: Krzysztof Kozlowski <krzysztof.kozlowski@oss.qualcomm.com>
>> ---
>>  drivers/firmware/samsung/exynos-acpm-dvfs.c |  8 ++++----
>>  drivers/firmware/samsung/exynos-acpm-pmic.c | 14 +++++++-------
>>  drivers/firmware/samsung/exynos-acpm.c      | 12 +++++++-----
>>  drivers/firmware/samsung/exynos-acpm.h      |  4 ++--
>>  4 files changed, 20 insertions(+), 18 deletions(-)
>>
>> diff --git a/drivers/firmware/samsung/exynos-acpm-dvfs.c b/drivers/firmware/samsung/exynos-acpm-dvfs.c
>> index 1c5b2b143bcc..55ec6ad9d87e 100644
>> --- a/drivers/firmware/samsung/exynos-acpm-dvfs.c
>> +++ b/drivers/firmware/samsung/exynos-acpm-dvfs.c
>> @@ -25,11 +25,11 @@ static void acpm_dvfs_set_xfer(struct acpm_xfer *xfer, u32 *cmd, size_t cmdlen,
>>  {
>>  	xfer->acpm_chan_id = acpm_chan_id;
>>  	xfer->txd = cmd;
>> -	xfer->txlen = cmdlen;
>> +	xfer->txcnt = cmdlen;
>>  
>>  	if (response) {
>>  		xfer->rxd = cmd;
>> -		xfer->rxlen = cmdlen;
>> +		xfer->rxcnt = cmdlen;
>>  	}
>>  }
>>  
>> @@ -50,7 +50,7 @@ int acpm_dvfs_set_rate(const struct acpm_handle *handle,
>>  	u32 cmd[4];
>>  
>>  	acpm_dvfs_init_set_rate_cmd(cmd, clk_id, rate);
>> -	acpm_dvfs_set_xfer(&xfer, cmd, sizeof(cmd), acpm_chan_id, false);
>> +	acpm_dvfs_set_xfer(&xfer, cmd, ARRAY_SIZE(cmd), acpm_chan_id, false);
>>  
>>  	return acpm_do_xfer(handle, &xfer);
>>  }
>> @@ -70,7 +70,7 @@ unsigned long acpm_dvfs_get_rate(const struct acpm_handle *handle,
>>  	int ret;
>>  
>>  	acpm_dvfs_init_get_rate_cmd(cmd, clk_id);
>> -	acpm_dvfs_set_xfer(&xfer, cmd, sizeof(cmd), acpm_chan_id, true);
>> +	acpm_dvfs_set_xfer(&xfer, cmd, ARRAY_SIZE(cmd), acpm_chan_id, true);
>>  
>>  	ret = acpm_do_xfer(handle, &xfer);
>>  	if (ret)
>> diff --git a/drivers/firmware/samsung/exynos-acpm-pmic.c b/drivers/firmware/samsung/exynos-acpm-pmic.c
>> index 44265db34ae6..26a9024d8ed8 100644
>> --- a/drivers/firmware/samsung/exynos-acpm-pmic.c
>> +++ b/drivers/firmware/samsung/exynos-acpm-pmic.c
>> @@ -63,8 +63,8 @@ static void acpm_pmic_set_xfer(struct acpm_xfer *xfer, u32 *cmd, size_t cmdlen,
>>  {
>>  	xfer->txd = cmd;
>>  	xfer->rxd = cmd;
>> -	xfer->txlen = cmdlen;
>> -	xfer->rxlen = cmdlen;
>> +	xfer->txcnt = cmdlen;
>> +	xfer->rxcnt = cmdlen;
>>  	xfer->acpm_chan_id = acpm_chan_id;
>>  }
>>  
>> @@ -86,7 +86,7 @@ int acpm_pmic_read_reg(const struct acpm_handle *handle,
>>  	int ret;
>>  
>>  	acpm_pmic_init_read_cmd(cmd, type, reg, chan);
>> -	acpm_pmic_set_xfer(&xfer, cmd, sizeof(cmd), acpm_chan_id);
>> +	acpm_pmic_set_xfer(&xfer, cmd, ARRAY_SIZE(cmd), acpm_chan_id);
>>  
>>  	ret = acpm_do_xfer(handle, &xfer);
>>  	if (ret)
>> @@ -119,7 +119,7 @@ int acpm_pmic_bulk_read(const struct acpm_handle *handle,
>>  		return -EINVAL;
>>  
>>  	acpm_pmic_init_bulk_read_cmd(cmd, type, reg, chan, count);
>> -	acpm_pmic_set_xfer(&xfer, cmd, sizeof(cmd), acpm_chan_id);
>> +	acpm_pmic_set_xfer(&xfer, cmd, ARRAY_SIZE(cmd), acpm_chan_id);
>>  
>>  	ret = acpm_do_xfer(handle, &xfer);
>>  	if (ret)
>> @@ -159,7 +159,7 @@ int acpm_pmic_write_reg(const struct acpm_handle *handle,
>>  	int ret;
>>  
>>  	acpm_pmic_init_write_cmd(cmd, type, reg, chan, value);
>> -	acpm_pmic_set_xfer(&xfer, cmd, sizeof(cmd), acpm_chan_id);
>> +	acpm_pmic_set_xfer(&xfer, cmd, ARRAY_SIZE(cmd), acpm_chan_id);
>>  
>>  	ret = acpm_do_xfer(handle, &xfer);
>>  	if (ret)
>> @@ -199,7 +199,7 @@ int acpm_pmic_bulk_write(const struct acpm_handle *handle,
>>  		return -EINVAL;
>>  
>>  	acpm_pmic_init_bulk_write_cmd(cmd, type, reg, chan, count, buf);
>> -	acpm_pmic_set_xfer(&xfer, cmd, sizeof(cmd), acpm_chan_id);
>> +	acpm_pmic_set_xfer(&xfer, cmd, ARRAY_SIZE(cmd), acpm_chan_id);
>>  
>>  	ret = acpm_do_xfer(handle, &xfer);
>>  	if (ret)
>> @@ -229,7 +229,7 @@ int acpm_pmic_update_reg(const struct acpm_handle *handle,
>>  	int ret;
>>  
>>  	acpm_pmic_init_update_cmd(cmd, type, reg, chan, value, mask);
>> -	acpm_pmic_set_xfer(&xfer, cmd, sizeof(cmd), acpm_chan_id);
>> +	acpm_pmic_set_xfer(&xfer, cmd, ARRAY_SIZE(cmd), acpm_chan_id);
>>  
>>  	ret = acpm_do_xfer(handle, &xfer);
>>  	if (ret)
>> diff --git a/drivers/firmware/samsung/exynos-acpm.c b/drivers/firmware/samsung/exynos-acpm.c
>> index 0cb269c70460..242745e8394c 100644
>> --- a/drivers/firmware/samsung/exynos-acpm.c
>> +++ b/drivers/firmware/samsung/exynos-acpm.c
>> @@ -205,7 +205,7 @@ static void acpm_get_saved_rx(struct acpm_chan *achan,
>>  	rx_seqnum = FIELD_GET(ACPM_PROTOCOL_SEQNUM, rx_data->cmd[0]);
>>  
>>  	if (rx_seqnum == tx_seqnum) {
>> -		memcpy(xfer->rxd, rx_data->cmd, xfer->rxlen);
>> +		memcpy(xfer->rxd, rx_data->cmd, xfer->rxcnt * sizeof(*xfer->rxd));
>>  		clear_bit(rx_seqnum - 1, achan->bitmap_seqnum);
>>  	}
>>  }
>> @@ -259,7 +259,7 @@ static int acpm_get_rx(struct acpm_chan *achan, const struct acpm_xfer *xfer)
>>  		if (rx_data->response) {
>>  			if (rx_seqnum == tx_seqnum) {
>>  				__ioread32_copy(xfer->rxd, addr,
>> -						xfer->rxlen / 4);
>> +						xfer->rxcnt);
> 
> now __ioread32_copy fits on a single line, without bypassing 80 chars


ack

> 
>>  				rx_set = true;
>>  				clear_bit(seqnum, achan->bitmap_seqnum);
>>  			} else {
>> @@ -270,7 +270,7 @@ static int acpm_get_rx(struct acpm_chan *achan, const struct acpm_xfer *xfer)
>>  				 * after the response is copied to the request.
>>  				 */
>>  				__ioread32_copy(rx_data->cmd, addr,
>> -						xfer->rxlen / 4);
>> +						xfer->rxcnt);
>>  			}
>>  		} else {
>>  			clear_bit(seqnum, achan->bitmap_seqnum);
>> @@ -425,7 +425,9 @@ int acpm_do_xfer(const struct acpm_handle *handle, const struct acpm_xfer *xfer)
>>  
>>  	achan = &acpm->chans[xfer->acpm_chan_id];
>>  
>> -	if (!xfer->txd || xfer->txlen > achan->mlen || xfer->rxlen > achan->mlen)
>> +	if (!xfer->txd || (xfer->txcnt * sizeof(*xfer->txd) > achan->mlen))
>> +		return -EINVAL;
>> +	if (xfer->rxcnt * sizeof(*xfer->rxd) > achan->mlen)
>>  		return -EINVAL;
> 
> how about:
>         if (!xfer->txd ||
>             (xfer->txcnt * sizeof(*xfer->txd) > achan->mlen) ||
>             (xfer->rxcnt * sizeof(*xfer->rxd) > achan->mlen))
>                 return -EINVAL;


sure, I don't have a preference.


Best regards,
Krzysztof

^ permalink raw reply	[flat|nested] 9+ messages in thread

* Re: [PATCH RFT 3/3] firmware: exynos-acpm: Count acpm_xfer buffers with __counted_by_ptr
  2026-02-14 12:39 ` [PATCH RFT 3/3] firmware: exynos-acpm: Count acpm_xfer buffers with __counted_by_ptr Krzysztof Kozlowski
@ 2026-02-19 11:20   ` Tudor Ambarus
  0 siblings, 0 replies; 9+ messages in thread
From: Tudor Ambarus @ 2026-02-19 11:20 UTC (permalink / raw)
  To: Krzysztof Kozlowski, Krzysztof Kozlowski, Alim Akhtar, Kees Cook,
	Gustavo A. R. Silva, Nathan Chancellor, Nick Desaulniers,
	Bill Wendling, Justin Stitt
  Cc: linux-kernel, linux-samsung-soc, linux-arm-kernel, linux-hardening, llvm



On 2/14/26 2:39 PM, Krzysztof Kozlowski wrote:
> Use __counted_by_ptr() attribute on the acpm_xfer buffers so UBSAN will
> validate runtime that we do not pass over the buffer size, thus making
> code safer.
> 
> Usage of __counted_by_ptr() (or actually __counted_by()) requires that
> counter is initialized before counted array.
> 
> Signed-off-by: Krzysztof Kozlowski <krzysztof.kozlowski@oss.qualcomm.com>
> 
> ---
> 
> __counted_by_ptr() actually maps to __counted_by() for clang v20.
> Alternatively we could introduce new __sized_by(), already supported by
> clang v20, but it is not available for GCC, AFAIU.
> 
> RFT, testing would need clang=20+ with COMNFIG_UBSAN and
> CONFIG_UBSAN_BOUNDS enabled.

Tested cpufreq (ACPM DVFS) with:
CONFIG_CLANG_VERSION=220100
CONFIG_UBSAN=y
CONFIG_UBSAN_BOUNDS=y

Tested-by: Tudor Ambarus <tudor.ambarus@linaro.org>
Reviewed-by: Tudor Ambarus <tudor.ambarus@linaro.org>

> ---
>  drivers/firmware/samsung/exynos-acpm-dvfs.c | 4 ++--
>  drivers/firmware/samsung/exynos-acpm.h      | 4 ++--
>  2 files changed, 4 insertions(+), 4 deletions(-)
> 
> diff --git a/drivers/firmware/samsung/exynos-acpm-dvfs.c b/drivers/firmware/samsung/exynos-acpm-dvfs.c
> index 55ec6ad9d87e..a4864973f65d 100644
> --- a/drivers/firmware/samsung/exynos-acpm-dvfs.c
> +++ b/drivers/firmware/samsung/exynos-acpm-dvfs.c
> @@ -24,12 +24,12 @@ static void acpm_dvfs_set_xfer(struct acpm_xfer *xfer, u32 *cmd, size_t cmdlen,
>  			       unsigned int acpm_chan_id, bool response)
>  {
>  	xfer->acpm_chan_id = acpm_chan_id;
> -	xfer->txd = cmd;
>  	xfer->txcnt = cmdlen;
> +	xfer->txd = cmd;
>  
>  	if (response) {
> -		xfer->rxd = cmd;
>  		xfer->rxcnt = cmdlen;
> +		xfer->rxd = cmd;
>  	}
>  }
>  
> diff --git a/drivers/firmware/samsung/exynos-acpm.h b/drivers/firmware/samsung/exynos-acpm.h
> index 422fbcac7284..8392fcb91f45 100644
> --- a/drivers/firmware/samsung/exynos-acpm.h
> +++ b/drivers/firmware/samsung/exynos-acpm.h
> @@ -8,8 +8,8 @@
>  #define __EXYNOS_ACPM_H__
>  
>  struct acpm_xfer {
> -	const u32 *txd;
> -	u32 *rxd;
> +	const u32 *txd __counted_by_ptr(txcnt);
> +	u32 *rxd __counted_by_ptr(rxcnt);
>  	size_t txcnt;
>  	size_t rxcnt;
>  	unsigned int acpm_chan_id;
> 


^ permalink raw reply	[flat|nested] 9+ messages in thread

end of thread, other threads:[~2026-02-19 11:20 UTC | newest]

Thread overview: 9+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-02-14 12:39 [PATCH RFT 0/3] firmware: exynos-acpm: Use __counted_by() Krzysztof Kozlowski
2026-02-14 12:39 ` [PATCH RFT 1/3] firmware: exynos-acpm: Use unsigned int for acpm_pmic_linux_errmap index Krzysztof Kozlowski
2026-02-19 10:16   ` Tudor Ambarus
2026-02-14 12:39 ` [PATCH RFT 2/3] firmware: exynos-acpm: Count number of commands in acpm_xfer Krzysztof Kozlowski
2026-02-14 19:13   ` Krzysztof Kozlowski
2026-02-19 10:27   ` Tudor Ambarus
2026-02-19 10:31     ` Krzysztof Kozlowski
2026-02-14 12:39 ` [PATCH RFT 3/3] firmware: exynos-acpm: Count acpm_xfer buffers with __counted_by_ptr Krzysztof Kozlowski
2026-02-19 11:20   ` Tudor Ambarus

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®