mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Kees Cook <kees@kernel.org>
To: Bill Wendling <morbo@google.com>
Cc: "Christophe Leroy (CS GROUP)" <chleroy@kernel.org>,
	"Gustavo A. R. Silva" <gustavoars@kernel.org>,
	Nathan Chancellor <nathan@kernel.org>,
	Nick Desaulniers <ndesaulniers@google.com>,
	Justin Stitt <justinstitt@google.com>,
	linuxppc-dev@lists.ozlabs.org,
	linux-arm-kernel@lists.infradead.org,
	linux-kernel@vger.kernel.org, linux-hardening@vger.kernel.org,
	llvm@lists.linux.dev, codemender-patching+linux@google.com
Subject: Re: [PATCH] bus: fsl-mc: Annotate fsl_mc_io.portal_virt_addr with __counted_by_ptr
Date: Wed, 23 Sep 2026 01:12:14 -0700	[thread overview]
Message-ID: <202609230106.7960C12@keescook> (raw)
In-Reply-To: <20260922223538.2287676-1-morbo@google.com>

On Tue, Sep 22, 2026 at 10:35:38PM +0000, Bill Wendling wrote:
> The GCC and Clang compilers provide the __counted_by_ptr attribute,
> which is used by KASAN and compiler bounds-checking to detect
> out-of-bounds accesses to pointer fields.
> 
> In "struct fsl_mc_io", the "portal_virt_addr" pointer points to the MC
> command portal virtual address. The size of this allocated portal in
> bytes is tracked by the "portal_size" field within the same structure.
> 
> Annotate the "portal_virt_addr" pointer field with
> "__counted_by_ptr(portal_size)" to enable compiler bounds-checking and
> harden against potential out-of-bounds accesses.

Another one where I hope things agree. :)

        mc_portal_size = resource_size(dpmcp_dev->regions);

        error = fsl_create_mc_io(&mc_bus_dev->dev,
                                 mc_portal_phys_addr,
                                 mc_portal_size, dpmcp_dev,
                                 mc_io_flags, &mc_io);
...

        mc_io->portal_size = mc_portal_size;
	...
        mc_portal_virt_addr = devm_ioremap(dev,
                                                   mc_portal_phys_addr,
                                                   mc_portal_size);
	...
        mc_io->portal_virt_addr = mc_portal_virt_addr;

But it actually reminds me that I still want a warning for having
compile-time warning about pointers being stripped from their counter:

                status = mc_read_response(mc_io->portal_virt_addr, cmd);
...
static inline enum mc_cmd_status mc_read_response(struct fsl_mc_command __iomem
                                                  *portal,
                                                  struct fsl_mc_command *resp)
{
        int i;
        enum mc_cmd_status status;

        /* Copy command response header from MC portal: */
        resp->header = cpu_to_le64(readq_relaxed(&portal->header));

Not only is mc_io->portal_virt_addr separated from mc_io->portal_size
via getting passed to mc_read_response(), but it then immediately gets
cast to struct fsl_mc_command.

We should get the __singleton attribute so we can mark function arg
pointers as "not an array", and then these kinds of casts could generate
a run-time check at function call time to check
sizeof(struct fsl_mc_command) against mc_io->portal_size when
__singleton was there, or kick up a warning that the counter got
stripped.

Because as-is, this patch is a no-op: nothing dereferences
mc_io->portal_virt_addr with the counter in context.


-Kees

-- 
Kees Cook

      parent reply	other threads:[~2026-09-23  8:12 UTC|newest]

Thread overview: 3+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-22 22:35 Bill Wendling
2026-09-23  5:46 ` Gustavo A. R. Silva
2026-09-23  8:12 ` Kees Cook [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=202609230106.7960C12@keescook \
    --to=kees@kernel.org \
    --cc=chleroy@kernel.org \
    --cc=codemender-patching+linux@google.com \
    --cc=gustavoars@kernel.org \
    --cc=justinstitt@google.com \
    --cc=linux-arm-kernel@lists.infradead.org \
    --cc=linux-hardening@vger.kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linuxppc-dev@lists.ozlabs.org \
    --cc=llvm@lists.linux.dev \
    --cc=morbo@google.com \
    --cc=nathan@kernel.org \
    --cc=ndesaulniers@google.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®