mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH] firmware: cs_dsp: Annotate struct cs_dsp_coeff_ctl with __counted_by_ptr
@ 2026-09-28  4:45 Bill Wendling
  2026-09-28  8:50 ` Richard Fitzgerald
  2026-09-28 12:15 ` Mark Brown
  0 siblings, 2 replies; 3+ messages in thread
From: Bill Wendling @ 2026-09-28  4:45 UTC (permalink / raw)
  To: Simon Trimmer, Charles Keepax, Richard Fitzgerald
  Cc: Kees Cook, Gustavo A. R. Silva, patches, linux-kernel,
	linux-hardening, Bill Wendling, codemender-patching+linux

Annotate the 'cache' pointer member of 'struct cs_dsp_coeff_ctl' with
the '__counted_by_ptr' attribute. This allows the compiler and KASAN
to perform run-time bounds checking on accesses to the 'cache' buffer,
preventing potential out-of-bounds reads or writes.

The 'cache' pointer points to a buffer of size 'len' bytes, allocated
to hold the cached value of a DSP coefficient control. The 'cache' and
'len' are initialized in 'cs_dsp_create_control()'.

Every subsequent access to 'ctl->cache' is strictly validated to
ensure that it lies within the bounds of 'ctl->len'.

Cc: codemender-patching+linux@google.com
Assisted-by: LLM
Signed-off-by: Bill Wendling <morbo@google.com>
---
 include/linux/firmware/cirrus/cs_dsp.h | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/include/linux/firmware/cirrus/cs_dsp.h b/include/linux/firmware/cirrus/cs_dsp.h
index 4e3baa557068..6aa1e1b2b4a5 100644
--- a/include/linux/firmware/cirrus/cs_dsp.h
+++ b/include/linux/firmware/cirrus/cs_dsp.h
@@ -96,7 +96,7 @@ struct cs_dsp_alg_region {
 struct cs_dsp_coeff_ctl {
 	struct list_head list;
 	struct cs_dsp *dsp;
-	void *cache;
+	void *cache __counted_by_ptr(len);
 	const char *fw_name;
 	/* Subname is needed to match with firmware */
 	const char *subname;
-- 
2.56.0.rc1.315.gc6ed9934b7-goog


^ permalink raw reply	[flat|nested] 3+ messages in thread

* Re: [PATCH] firmware: cs_dsp: Annotate struct cs_dsp_coeff_ctl with __counted_by_ptr
  2026-09-28  4:45 [PATCH] firmware: cs_dsp: Annotate struct cs_dsp_coeff_ctl with __counted_by_ptr Bill Wendling
@ 2026-09-28  8:50 ` Richard Fitzgerald
  2026-09-28 12:15 ` Mark Brown
  1 sibling, 0 replies; 3+ messages in thread
From: Richard Fitzgerald @ 2026-09-28  8:50 UTC (permalink / raw)
  To: Bill Wendling, Simon Trimmer, Charles Keepax
  Cc: Kees Cook, Gustavo A. R. Silva, patches, linux-kernel,
	linux-hardening, codemender-patching+linux

On 28/09/2026 5:45 am, Bill Wendling wrote:
> Annotate the 'cache' pointer member of 'struct cs_dsp_coeff_ctl' with
> the '__counted_by_ptr' attribute. This allows the compiler and KASAN
> to perform run-time bounds checking on accesses to the 'cache' buffer,
> preventing potential out-of-bounds reads or writes.
> 
> The 'cache' pointer points to a buffer of size 'len' bytes, allocated
> to hold the cached value of a DSP coefficient control. The 'cache' and
> 'len' are initialized in 'cs_dsp_create_control()'.
> 
> Every subsequent access to 'ctl->cache' is strictly validated to
Is that true?
When I last looked at these __counted_by they were only checked by
a subset of library functions (which was documented) so I was still
able to write code that overran the buffer.

However, recent compilers might do more checking now.

Reviewed-by: Richard Fitzgerald <rf@opensource.cirrus.com>

^ permalink raw reply	[flat|nested] 3+ messages in thread

* Re: [PATCH] firmware: cs_dsp: Annotate struct cs_dsp_coeff_ctl with __counted_by_ptr
  2026-09-28  4:45 [PATCH] firmware: cs_dsp: Annotate struct cs_dsp_coeff_ctl with __counted_by_ptr Bill Wendling
  2026-09-28  8:50 ` Richard Fitzgerald
@ 2026-09-28 12:15 ` Mark Brown
  1 sibling, 0 replies; 3+ messages in thread
From: Mark Brown @ 2026-09-28 12:15 UTC (permalink / raw)
  To: Simon Trimmer, Charles Keepax, Richard Fitzgerald, Bill Wendling
  Cc: Kees Cook, Gustavo A. R. Silva, patches, linux-kernel,
	linux-hardening, codemender-patching+linux

On Mon, 28 Sep 2026 04:45:13 +0000, Bill Wendling wrote:
> firmware: cs_dsp: Annotate struct cs_dsp_coeff_ctl with __counted_by_ptr

Applied to

   https://git.kernel.org/pub/scm/linux/kernel/git/broonie/sound.git for-7.4

Thanks!

[1/1] firmware: cs_dsp: Annotate struct cs_dsp_coeff_ctl with __counted_by_ptr
      https://git.kernel.org/broonie/sound/c/3e71ea6dca1d

All being well this means that it will be integrated into the linux-next
tree (usually sometime in the next 24 hours) and sent to Linus during
the next merge window (or sooner if it is a bug fix), however if
problems are discovered then the patch may be dropped or reverted.

You may get further e-mails resulting from automated or manual testing
and review of the tree, please engage with people reporting problems and
send followup patches addressing any issues that are reported if needed.

If any updates are required or you are submitting further changes they
should be sent as incremental updates against current git, existing
patches will not be replaced.

Please add any relevant lists and maintainers to the CCs when replying
to this mail.

Thanks,
Mark


^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2026-09-28 14:53 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-09-28  4:45 [PATCH] firmware: cs_dsp: Annotate struct cs_dsp_coeff_ctl with __counted_by_ptr Bill Wendling
2026-09-28  8:50 ` Richard Fitzgerald
2026-09-28 12:15 ` Mark Brown

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®