mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH] gpiolib: annotate struct acpi_gpio_mapping with __counted_by_ptr
@ 2026-09-28  6:38 Bill Wendling
  2026-09-28  7:22 ` Bill Wendling
  0 siblings, 1 reply; 2+ messages in thread
From: Bill Wendling @ 2026-09-28  6:38 UTC (permalink / raw)
  To: Linus Walleij, Bartosz Golaszewski
  Cc: Kees Cook, Gustavo A. R. Silva, linux-gpio, linux-kernel,
	linux-hardening, Bill Wendling, codemender-patching+linux

The 'data' pointer field in 'struct acpi_gpio_mapping' is associated
with the 'size' field, which represents the number of elements of
type 'struct acpi_gpio_params' allocated for 'data'.

To improve bounds checking via CONFIG_UBSAN_BOUNDS and
CONFIG_FORTIFY_SOURCE, annotate 'data' with the __counted_by_ptr
attribute.

Analysis of allocation, assignment, and access points shows that the
pointer is never accessed before the count is set, which guarantees that
this annotation is safe and will not cause runtime panics or
false-positive bounds checks.

Cc: codemender-patching+linux@google.com
Assisted-by: LLM
Signed-off-by: Bill Wendling <morbo@google.com>
---
 include/linux/gpio/consumer.h | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/include/linux/gpio/consumer.h b/include/linux/gpio/consumer.h
index fceeefd5f893..2b80cf7aa7e7 100644
--- a/include/linux/gpio/consumer.h
+++ b/include/linux/gpio/consumer.h
@@ -667,7 +667,7 @@ struct acpi_gpio_params {
 
 struct acpi_gpio_mapping {
 	const char *name;
-	const struct acpi_gpio_params *data;
+	const struct acpi_gpio_params *data __counted_by_ptr(size);
 	unsigned int size;
 
 /* Ignore IoRestriction field */
-- 
2.56.0.rc1.315.gc6ed9934b7-goog


^ permalink raw reply	[flat|nested] 2+ messages in thread

* Re: [PATCH] gpiolib: annotate struct acpi_gpio_mapping with __counted_by_ptr
  2026-09-28  6:38 [PATCH] gpiolib: annotate struct acpi_gpio_mapping with __counted_by_ptr Bill Wendling
@ 2026-09-28  7:22 ` Bill Wendling
  0 siblings, 0 replies; 2+ messages in thread
From: Bill Wendling @ 2026-09-28  7:22 UTC (permalink / raw)
  To: Linus Walleij, Bartosz Golaszewski
  Cc: Kees Cook, Gustavo A. R. Silva, linux-gpio, linux-kernel,
	linux-hardening, codemender-patching+linux

On Sun, Sep 27, 2026 at 11:38 PM Bill Wendling <morbo@google.com> wrote:
>
> The 'data' pointer field in 'struct acpi_gpio_mapping' is associated
> with the 'size' field, which represents the number of elements of
> type 'struct acpi_gpio_params' allocated for 'data'.
>
> To improve bounds checking via CONFIG_UBSAN_BOUNDS and
> CONFIG_FORTIFY_SOURCE, annotate 'data' with the __counted_by_ptr
> attribute.
>
> Analysis of allocation, assignment, and access points shows that the
> pointer is never accessed before the count is set, which guarantees that
> this annotation is safe and will not cause runtime panics or
> false-positive bounds checks.
>
> Cc: codemender-patching+linux@google.com
> Assisted-by: LLM
> Signed-off-by: Bill Wendling <morbo@google.com>
> ---
>  include/linux/gpio/consumer.h | 2 +-
>  1 file changed, 1 insertion(+), 1 deletion(-)
>
> diff --git a/include/linux/gpio/consumer.h b/include/linux/gpio/consumer.h
> index fceeefd5f893..2b80cf7aa7e7 100644
> --- a/include/linux/gpio/consumer.h
> +++ b/include/linux/gpio/consumer.h
> @@ -667,7 +667,7 @@ struct acpi_gpio_params {
>
>  struct acpi_gpio_mapping {
>         const char *name;
> -       const struct acpi_gpio_params *data;
> +       const struct acpi_gpio_params *data __counted_by_ptr(size);
>         unsigned int size;
>
>  /* Ignore IoRestriction field */

There's a problem with 'drivers/firmware/efi/libstub/Makefile'. Clang
needs a compiler flag to support the "__counted_by_ptr" attribute
referencing a field *after* the pointer, like in this patch. However,
the Makefile blasts the flag away for x86 platforms. Below is a hack
that copies the part of the top-level Makefile that adds the flag. I
don't think that's a good solution. The comment in the driver's
Makefile says that the stub code executes before the kernel does,
which I assume is why a lot of the flags are blown away... In any
event, I'm not sure how best to address this.

-bw

diff --git a/drivers/firmware/efi/libstub/Makefile
b/drivers/firmware/efi/libstub/Makefile
index 77a2b2d74f3f..945674048d8f 100644
--- a/drivers/firmware/efi/libstub/Makefile
+++ b/drivers/firmware/efi/libstub/Makefile
@@ -19,6 +19,14 @@ cflags-$(CONFIG_X86)         += -m$(BITS)
-D__KERNEL__ $(CC_FLAGS_DIALECT) \
                                   -fno-asynchronous-unwind-tables \
                                   $(CLANG_FLAGS)

+ifeq ($(CONFIG_X86_32)$(CONFIG_X86_64),y)
+ifdef CONFIG_CC_IS_CLANG
+ifdef CONFIG_CC_HAS_COUNTED_BY_PTR
+cflags-y                       += -fexperimental-late-parse-attributes
+endif
+endif
+endif
+
 # arm64 uses the full KBUILD_CFLAGS so it's necessary to explicitly
 # disable the stackleak plugin
 cflags-$(CONFIG_ARM64)         += -fpie $(DISABLE_KSTACK_ERASE) \

^ permalink raw reply	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2026-09-28  7:22 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-09-28  6:38 [PATCH] gpiolib: annotate struct acpi_gpio_mapping with __counted_by_ptr Bill Wendling
2026-09-28  7:22 ` Bill Wendling

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®