From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-pl1-f198.google.com (mail-pl1-f198.google.com [209.85.214.198]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 524672931F5 for ; Wed, 23 Sep 2026 06:31:20 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.214.198 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790145083; cv=none; b=At6ghz9OMas2WIPwF5ACZh7LCGP0vAe6S6nX1xqeUEChprJjzAixIjKtT5LML2Eawjm4AAVT3ZUfiPuiqMdpuAdAd9925fp6TndHGewMyy6gSiN9IEy8Vhi8gu6eJkZQ42a9He8qxtbWuaNxoeIiC1VCUVhn+wDbh/2NVpNW08w= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790145083; c=relaxed/simple; bh=yMpiKx3kguhJmc8qDGn1V3CoMpzc68Grv59UbQqZkL0=; h=Date:Mime-Version:Message-ID:Subject:From:To:Cc:Content-Type; b=fFZg/kqw896CxeGht0CQk6rfh2VCkUSzQXPzQ306rMGRJmQPgtFK+/+cX7NmNpcn9s6lpeK5+5g3zurk1Pihnyhp2uNapFsTNU02nhcLkngl0RzrVjXs2TfWCUTlp63xahwogpeIn08lJsu1soXceuOoVhtkPjHwgBDR5KoQ6nU= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--morbo.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=FxpHxazF; arc=none smtp.client-ip=209.85.214.198 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--morbo.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="FxpHxazF" Received: by mail-pl1-f198.google.com with SMTP id d9443c01a7336-2cee1ec30f2so6126605ad.3 for ; Tue, 22 Sep 2026 23:31:19 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1790145077; x=1790749877; darn=vger.kernel.org; h=content-type:cc:to:from:subject:message-id:mime-version:date:from :to:cc:subject:date:message-id:reply-to:content-type; bh=tFs7REmvg7ALs7gDnIPL2Cm/x5EKpm+iCAcxe/e+E3M=; b=FxpHxazFm8D/CPAXV5DSHZoW+G0poMCEivZO3tIXv92LeWfvEvfuB2U8yNyWoEzEPG lNwmf7/LPBRcypLAD3FHrlFwqeGFTOusgZzeEM5tyUCxcAEsB6wMbpZTzFrXE1wXFVpf KHpD/wgsKjtiGKABseYf9aEaJRFpMUHx5XfYPFkQUZO6eJZfpUEPJOIXx1giRWZ2Pamj 3hU3IGzGNs8A9WrxKzmi9QgO2Og9saYy0gBukEhgrXtr71pn+7vxjC8Zdiwy/luzg2v0 vN68O9D5l3+9h1hvMl+XDfCMIRPfM4yfCrpw9K4klVjuOyngqhar66wM7YpBzXDIYaP0 VF6g== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790145077; x=1790749877; h=content-type:cc:to:from:subject:message-id:mime-version:date :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=tFs7REmvg7ALs7gDnIPL2Cm/x5EKpm+iCAcxe/e+E3M=; b=hKMqwBXKPUnK7eTVNug8C6H5AnUJWohtsLiUgkWytiLo33HDuTEUvS2eQHxzdaAfTV kuTx8bFfF0UicMqzXCpOFo+2zSQbXUhu1kDZhcMUzoopo5bztK/l5p5w38tt/PT9WIU5 jS0O+eqjX6i+qDgithUw/AUg4GgT6nxIhoPMEWGLGt0kxcM9lVuqG2CvxttUU9X1PFHn Z5BTmA1Km67sNDl5QIBOBUvMrde0uP+eeBjezZ1xJbpdSzOb/yJXO3EZU9DAYTtE6Lob HHFsLRfXzFp+/aCdBoTQoNovX1SzAmBuHAaDXKHIXAXiwhs/UZrYan4rL+x0hAHGG2le kxIA== X-Forwarded-Encrypted: i=1; AKwUvByYOp85vSM83csY5W+cJ8od79fMtTPdfV2BX1vCPUUnVlwb6R7BLX7bXZoGrD1VMYAZDLcxURsCE10FXq0=@vger.kernel.org X-Gm-Message-State: AFuF++le3kPDpwixt4Yb/yNyj06z6EXmRb46ayWKcEovG9e6GFKMZ0D+ /uRamd6klGmTZGSQXq24qLB84nZ69qk+CjFL3wiptV7SBQIkLXqTjQmdxUB7HuwFirbP998COXc P X-Received: from pleg9.prod.google.com ([2002:a17:902:e389:b0:2dd:26c1:6565]) (user=morbo job=prod-delivery.src-stubby-dispatcher) by 2002:a17:903:3d05:b0:2dd:319:c9ef with SMTP id d9443c01a7336-2df69d28094mr16150785ad.3.1790145077322; Tue, 22 Sep 2026 23:31:17 -0700 (PDT) Date: Wed, 23 Sep 2026 06:31:14 +0000 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 X-Mailer: git-send-email 2.55.0.1082.g2b9226bbc0-goog Message-ID: <20260923063114.2683575-1-morbo@google.com> Subject: [PATCH] HID: bpf: add __counted_by_ptr attribute to device_data From: Bill Wendling To: Jiri Kosina , Benjamin Tissoires Cc: Kees Cook , "Gustavo A. R. Silva" , linux-input@vger.kernel.org, linux-kernel@vger.kernel.org, linux-hardening@vger.kernel.org, bpf@vger.kernel.org, Bill Wendling , codemender-patching+linux@google.com Content-Type: text/plain; charset="UTF-8" The 'struct hid_bpf' contains a 'device_data' pointer field (of type 'u8 *') and an 'allocated_data' field (of type 'u32') that specifies the size in bytes of the allocated memory for 'device_data'. Since 'device_data' is a pointer to 'u8' (elements of size 1 byte), 'allocated_data' represents the exact count of elements allocated for 'device_data'. Annotate the 'device_data' field of 'struct hid_bpf' with the '__counted_by_ptr' attribute, pointing to 'allocated_data'. This enables bounds-checking sanitizers (like KASAN and UBSAN) to detect out-of-bounds accesses to 'device_data'. Because the count 'allocated_data' is always set before any access and accurately tracks the allocated buffer size at all times, adding '__counted_by_ptr' will not cause runtime panics or false-positive bounds checks. Cc: codemender-patching+linux@google.com Assisted-by: LLM Signed-off-by: Bill Wendling --- include/linux/hid_bpf.h | 10 ++++++---- 1 file changed, 6 insertions(+), 4 deletions(-) diff --git a/include/linux/hid_bpf.h b/include/linux/hid_bpf.h index 19fffa4574a4..f45fb9cccece 100644 --- a/include/linux/hid_bpf.h +++ b/include/linux/hid_bpf.h @@ -185,10 +185,12 @@ struct hid_bpf_ops { /* stored in each device */ struct hid_bpf { - u8 *device_data; /* allocated when a bpf program of type - * SEC(f.../hid_bpf_device_event) has been attached - * to this HID device - */ + /* + * allocated when a bpf program of type + * SEC(f.../hid_bpf_device_event) has been attached + * to this HID device + */ + u8 *device_data __counted_by_ptr(allocated_data); u32 allocated_data; bool destroyed; /* prevents the assignment of any progs */ -- 2.55.0.1082.g2b9226bbc0-goog