From: Kees Cook <kees@kernel.org>
To: Bill Wendling <morbo@google.com>
Cc: "Christophe Leroy (CS GROUP)" <chleroy@kernel.org>,
"Gustavo A. R. Silva" <gustavoars@kernel.org>,
Nathan Chancellor <nathan@kernel.org>,
Nick Desaulniers <ndesaulniers@google.com>,
Justin Stitt <justinstitt@google.com>,
linuxppc-dev@lists.ozlabs.org,
linux-arm-kernel@lists.infradead.org,
linux-kernel@vger.kernel.org, linux-hardening@vger.kernel.org,
llvm@lists.linux.dev, codemender-patching+linux@google.com
Subject: Re: [PATCH] bus: fsl-mc: Annotate fsl_mc_io.portal_virt_addr with __counted_by_ptr
Date: Wed, 23 Sep 2026 01:12:14 -0700 [thread overview]
Message-ID: <202609230106.7960C12@keescook> (raw)
In-Reply-To: <20260922223538.2287676-1-morbo@google.com>
On Tue, Sep 22, 2026 at 10:35:38PM +0000, Bill Wendling wrote:
> The GCC and Clang compilers provide the __counted_by_ptr attribute,
> which is used by KASAN and compiler bounds-checking to detect
> out-of-bounds accesses to pointer fields.
>
> In "struct fsl_mc_io", the "portal_virt_addr" pointer points to the MC
> command portal virtual address. The size of this allocated portal in
> bytes is tracked by the "portal_size" field within the same structure.
>
> Annotate the "portal_virt_addr" pointer field with
> "__counted_by_ptr(portal_size)" to enable compiler bounds-checking and
> harden against potential out-of-bounds accesses.
Another one where I hope things agree. :)
mc_portal_size = resource_size(dpmcp_dev->regions);
error = fsl_create_mc_io(&mc_bus_dev->dev,
mc_portal_phys_addr,
mc_portal_size, dpmcp_dev,
mc_io_flags, &mc_io);
...
mc_io->portal_size = mc_portal_size;
...
mc_portal_virt_addr = devm_ioremap(dev,
mc_portal_phys_addr,
mc_portal_size);
...
mc_io->portal_virt_addr = mc_portal_virt_addr;
But it actually reminds me that I still want a warning for having
compile-time warning about pointers being stripped from their counter:
status = mc_read_response(mc_io->portal_virt_addr, cmd);
...
static inline enum mc_cmd_status mc_read_response(struct fsl_mc_command __iomem
*portal,
struct fsl_mc_command *resp)
{
int i;
enum mc_cmd_status status;
/* Copy command response header from MC portal: */
resp->header = cpu_to_le64(readq_relaxed(&portal->header));
Not only is mc_io->portal_virt_addr separated from mc_io->portal_size
via getting passed to mc_read_response(), but it then immediately gets
cast to struct fsl_mc_command.
We should get the __singleton attribute so we can mark function arg
pointers as "not an array", and then these kinds of casts could generate
a run-time check at function call time to check
sizeof(struct fsl_mc_command) against mc_io->portal_size when
__singleton was there, or kick up a warning that the counter got
stripped.
Because as-is, this patch is a no-op: nothing dereferences
mc_io->portal_virt_addr with the counter in context.
-Kees
--
Kees Cook
prev parent reply other threads:[~2026-09-23 8:12 UTC|newest]
Thread overview: 3+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-22 22:35 Bill Wendling
2026-09-23 5:46 ` Gustavo A. R. Silva
2026-09-23 8:12 ` Kees Cook [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=202609230106.7960C12@keescook \
--to=kees@kernel.org \
--cc=chleroy@kernel.org \
--cc=codemender-patching+linux@google.com \
--cc=gustavoars@kernel.org \
--cc=justinstitt@google.com \
--cc=linux-arm-kernel@lists.infradead.org \
--cc=linux-hardening@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linuxppc-dev@lists.ozlabs.org \
--cc=llvm@lists.linux.dev \
--cc=morbo@google.com \
--cc=nathan@kernel.org \
--cc=ndesaulniers@google.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®