mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Bill Wendling <morbo@google.com>
To: Linus Walleij <linusw@kernel.org>,
	Bartosz Golaszewski <brgl@kernel.org>,
	Ard Biesheuvel <ardb@kernel.org>,  Jeremy Kerr <jk@ozlabs.org>
Cc: Kees Cook <kees@kernel.org>,
	"Gustavo A. R. Silva" <gustavoars@kernel.org>,
	linux-gpio@vger.kernel.org,  linux-kernel@vger.kernel.org,
	linux-hardening@vger.kernel.org,
	 Bill Wendling <morbo@google.com>,
	codemender-patching+linux@google.com
Subject: [PATCH v2] gpiolib: annotate struct acpi_gpio_mapping with __counted_by_ptr
Date: Fri,  2 Oct 2026 12:42:25 +0000	[thread overview]
Message-ID: <20261002124226.435265-1-morbo@google.com> (raw)
In-Reply-To: <20260928063824.1386524-1-morbo@google.com>

The 'data' pointer field in 'struct acpi_gpio_mapping' is associated
with the 'size' field, which represents the number of elements of
type 'struct acpi_gpio_params' allocated for 'data'.

To improve bounds checking via CONFIG_UBSAN_BOUNDS and
CONFIG_FORTIFY_SOURCE, annotate 'data' with the __counted_by_ptr
attribute.

Analysis of allocation, assignment, and access points shows that the
pointer is never accessed before the count is set, which guarantees that
this annotation is safe and will not cause runtime panics or
false-positive bounds checks.

Cc: codemender-patching+linux@google.com
Assisted-by: LLM
Signed-off-by: Bill Wendling <morbo@google.com>
---
v2: Undefine "__counted_by" and "__counted_by_ptr" in the EFI stub
    library as it doesn't need it and Clang is missing a flag to
    enable them.
---
 drivers/firmware/efi/libstub/alignedmem.c      | 8 ++++++++
 drivers/firmware/efi/libstub/efi-stub-helper.c | 8 ++++++++
 drivers/firmware/efi/libstub/file.c            | 8 ++++++++
 drivers/firmware/efi/libstub/gop.c             | 8 ++++++++
 drivers/firmware/efi/libstub/mem.c             | 8 ++++++++
 drivers/firmware/efi/libstub/pci.c             | 8 ++++++++
 drivers/firmware/efi/libstub/printk.c          | 8 ++++++++
 drivers/firmware/efi/libstub/random.c          | 8 ++++++++
 drivers/firmware/efi/libstub/randomalloc.c     | 8 ++++++++
 drivers/firmware/efi/libstub/secureboot.c      | 9 +++++++++
 drivers/firmware/efi/libstub/smbios.c          | 8 ++++++++
 drivers/firmware/efi/libstub/tpm.c             | 9 +++++++++
 drivers/firmware/efi/libstub/x86-5lvl.c        | 9 +++++++++
 drivers/firmware/efi/libstub/x86-stub.c        | 8 ++++++++
 include/linux/gpio/consumer.h                  | 2 +-
 15 files changed, 116 insertions(+), 1 deletion(-)

diff --git a/drivers/firmware/efi/libstub/alignedmem.c b/drivers/firmware/efi/libstub/alignedmem.c
index 31928bd87e0f..36248a13f15b 100644
--- a/drivers/firmware/efi/libstub/alignedmem.c
+++ b/drivers/firmware/efi/libstub/alignedmem.c
@@ -1,5 +1,13 @@
 // SPDX-License-Identifier: GPL-2.0
 
+/*
+ * The EFI stub doesn't execute in the context of the kernel, only in the
+ * context of boot firmware, which isn't the time or place to crash the kernel.
+ * Therefore, disable the __counted_by__ attribute.
+ */
+#undef __counted_by
+#undef __counted_by_ptr
+
 #include <linux/efi.h>
 #include <asm/efi.h>
 
diff --git a/drivers/firmware/efi/libstub/efi-stub-helper.c b/drivers/firmware/efi/libstub/efi-stub-helper.c
index 8e43eb3f418b..a97d086a76a1 100644
--- a/drivers/firmware/efi/libstub/efi-stub-helper.c
+++ b/drivers/firmware/efi/libstub/efi-stub-helper.c
@@ -7,6 +7,14 @@
  * Copyright 2011 Intel Corporation; author Matt Fleming
  */
 
+/*
+ * The EFI stub doesn't execute in the context of the kernel, only in the
+ * context of boot firmware, which isn't the time or place to crash the kernel.
+ * Therefore, disable the __counted_by__ attribute.
+ */
+#undef __counted_by
+#undef __counted_by_ptr
+
 #include <linux/stdarg.h>
 
 #include <linux/efi.h>
diff --git a/drivers/firmware/efi/libstub/file.c b/drivers/firmware/efi/libstub/file.c
index b2601e284695..e845dc2e7aa0 100644
--- a/drivers/firmware/efi/libstub/file.c
+++ b/drivers/firmware/efi/libstub/file.c
@@ -7,6 +7,14 @@
  * Copyright 2011 Intel Corporation; author Matt Fleming
  */
 
+/*
+ * The EFI stub doesn't execute in the context of the kernel, only in the
+ * context of boot firmware, which isn't the time or place to crash the kernel.
+ * Therefore, disable the __counted_by__ attribute.
+ */
+#undef __counted_by
+#undef __counted_by_ptr
+
 #include <linux/efi.h>
 #include <asm/efi.h>
 
diff --git a/drivers/firmware/efi/libstub/gop.c b/drivers/firmware/efi/libstub/gop.c
index b800a6c2290c..f9736d2eff22 100644
--- a/drivers/firmware/efi/libstub/gop.c
+++ b/drivers/firmware/efi/libstub/gop.c
@@ -5,6 +5,14 @@
  *
  * ----------------------------------------------------------------------- */
 
+/*
+ * The EFI stub doesn't execute in the context of the kernel, only in the
+ * context of boot firmware, which isn't the time or place to crash the kernel.
+ * Therefore, disable the __counted_by__ attribute.
+ */
+#undef __counted_by
+#undef __counted_by_ptr
+
 #include <linux/bitops.h>
 #include <linux/ctype.h>
 #include <linux/efi.h>
diff --git a/drivers/firmware/efi/libstub/mem.c b/drivers/firmware/efi/libstub/mem.c
index fec561e3a792..65bea615420c 100644
--- a/drivers/firmware/efi/libstub/mem.c
+++ b/drivers/firmware/efi/libstub/mem.c
@@ -1,5 +1,13 @@
 // SPDX-License-Identifier: GPL-2.0
 
+/*
+ * The EFI stub doesn't execute in the context of the kernel, only in the
+ * context of boot firmware, which isn't the time or place to crash the kernel.
+ * Therefore, disable the __counted_by__ attribute.
+ */
+#undef __counted_by
+#undef __counted_by_ptr
+
 #include <linux/efi.h>
 #include <asm/efi.h>
 
diff --git a/drivers/firmware/efi/libstub/pci.c b/drivers/firmware/efi/libstub/pci.c
index 5daa7a0a0e87..a4c9bf67d5e0 100644
--- a/drivers/firmware/efi/libstub/pci.c
+++ b/drivers/firmware/efi/libstub/pci.c
@@ -6,6 +6,14 @@
  * Copyright 2019 Google, LLC
  */
 
+/*
+ * The EFI stub doesn't execute in the context of the kernel, only in the
+ * context of boot firmware, which isn't the time or place to crash the kernel.
+ * Therefore, disable the __counted_by__ attribute.
+ */
+#undef __counted_by
+#undef __counted_by_ptr
+
 #include <linux/efi.h>
 #include <linux/pci.h>
 
diff --git a/drivers/firmware/efi/libstub/printk.c b/drivers/firmware/efi/libstub/printk.c
index 0a18cfe32528..e2ae89a27b78 100644
--- a/drivers/firmware/efi/libstub/printk.c
+++ b/drivers/firmware/efi/libstub/printk.c
@@ -1,5 +1,13 @@
 // SPDX-License-Identifier: GPL-2.0
 
+/*
+ * The EFI stub doesn't execute in the context of the kernel, only in the
+ * context of boot firmware, which isn't the time or place to crash the kernel.
+ * Therefore, disable the __counted_by__ attribute.
+ */
+#undef __counted_by
+#undef __counted_by_ptr
+
 #include <linux/stdarg.h>
 
 #include <linux/ctype.h>
diff --git a/drivers/firmware/efi/libstub/random.c b/drivers/firmware/efi/libstub/random.c
index d63262d36e47..d370f0d79c07 100644
--- a/drivers/firmware/efi/libstub/random.c
+++ b/drivers/firmware/efi/libstub/random.c
@@ -3,6 +3,14 @@
  * Copyright (C) 2016 Linaro Ltd;  <ard.biesheuvel@linaro.org>
  */
 
+/*
+ * The EFI stub doesn't execute in the context of the kernel, only in the
+ * context of boot firmware, which isn't the time or place to crash the kernel.
+ * Therefore, disable the __counted_by__ attribute.
+ */
+#undef __counted_by
+#undef __counted_by_ptr
+
 #include <linux/efi.h>
 #include <asm/efi.h>
 
diff --git a/drivers/firmware/efi/libstub/randomalloc.c b/drivers/firmware/efi/libstub/randomalloc.c
index fd80b2f3233a..b09a26aa51e9 100644
--- a/drivers/firmware/efi/libstub/randomalloc.c
+++ b/drivers/firmware/efi/libstub/randomalloc.c
@@ -3,6 +3,14 @@
  * Copyright (C) 2016 Linaro Ltd;  <ard.biesheuvel@linaro.org>
  */
 
+/*
+ * The EFI stub doesn't execute in the context of the kernel, only in the
+ * context of boot firmware, which isn't the time or place to crash the kernel.
+ * Therefore, disable the __counted_by__ attribute.
+ */
+#undef __counted_by
+#undef __counted_by_ptr
+
 #include <linux/efi.h>
 #include <linux/log2.h>
 #include <asm/efi.h>
diff --git a/drivers/firmware/efi/libstub/secureboot.c b/drivers/firmware/efi/libstub/secureboot.c
index 516f4f0069bd..07c9782e0c44 100644
--- a/drivers/firmware/efi/libstub/secureboot.c
+++ b/drivers/firmware/efi/libstub/secureboot.c
@@ -7,6 +7,15 @@
  * Copyright (C) 2013 Red Hat, Inc.
  *     Mark Salter <msalter@redhat.com>
  */
+
+/*
+ * The EFI stub doesn't execute in the context of the kernel, only in the
+ * context of boot firmware, which isn't the time or place to crash the kernel.
+ * Therefore, disable the __counted_by__ attribute.
+ */
+#undef __counted_by
+#undef __counted_by_ptr
+
 #include <linux/efi.h>
 #include <asm/efi.h>
 
diff --git a/drivers/firmware/efi/libstub/smbios.c b/drivers/firmware/efi/libstub/smbios.c
index efbbfc3c2c0d..98dc3ee40958 100644
--- a/drivers/firmware/efi/libstub/smbios.c
+++ b/drivers/firmware/efi/libstub/smbios.c
@@ -2,6 +2,14 @@
 // Copyright 2022 Google LLC
 // Author: Ard Biesheuvel <ardb@google.com>
 
+/*
+ * The EFI stub doesn't execute in the context of the kernel, only in the
+ * context of boot firmware, which isn't the time or place to crash the kernel.
+ * Therefore, disable the __counted_by__ attribute.
+ */
+#undef __counted_by
+#undef __counted_by_ptr
+
 #include <linux/efi.h>
 
 #include "efistub.h"
diff --git a/drivers/firmware/efi/libstub/tpm.c b/drivers/firmware/efi/libstub/tpm.c
index 73f001114732..27bc0ccc2a2b 100644
--- a/drivers/firmware/efi/libstub/tpm.c
+++ b/drivers/firmware/efi/libstub/tpm.c
@@ -7,6 +7,15 @@
  *     Matthew Garrett <mjg59@google.com>
  *     Thiebaud Weksteen <tweek@google.com>
  */
+
+/*
+ * The EFI stub doesn't execute in the context of the kernel, only in the
+ * context of boot firmware, which isn't the time or place to crash the kernel.
+ * Therefore, disable the __counted_by__ attribute.
+ */
+#undef __counted_by
+#undef __counted_by_ptr
+
 #include <linux/efi.h>
 #include <linux/tpm_eventlog.h>
 #include <asm/efi.h>
diff --git a/drivers/firmware/efi/libstub/x86-5lvl.c b/drivers/firmware/efi/libstub/x86-5lvl.c
index c3da05c0df8b..3112ab4b2623 100644
--- a/drivers/firmware/efi/libstub/x86-5lvl.c
+++ b/drivers/firmware/efi/libstub/x86-5lvl.c
@@ -1,4 +1,13 @@
 // SPDX-License-Identifier: GPL-2.0-only
+
+/*
+ * The EFI stub doesn't execute in the context of the kernel, only in the
+ * context of boot firmware, which isn't the time or place to crash the kernel.
+ * Therefore, disable the __counted_by__ attribute.
+ */
+#undef __counted_by
+#undef __counted_by_ptr
+
 #include <linux/efi.h>
 
 #include <asm/boot.h>
diff --git a/drivers/firmware/efi/libstub/x86-stub.c b/drivers/firmware/efi/libstub/x86-stub.c
index f4799e29f4cf..77e806c2b016 100644
--- a/drivers/firmware/efi/libstub/x86-stub.c
+++ b/drivers/firmware/efi/libstub/x86-stub.c
@@ -6,6 +6,14 @@
  *
  * ----------------------------------------------------------------------- */
 
+/*
+ * The EFI stub doesn't execute in the context of the kernel, only in the
+ * context of boot firmware, which isn't the time or place to crash the kernel.
+ * Therefore, disable the __counted_by__ attribute.
+ */
+#undef __counted_by
+#undef __counted_by_ptr
+
 #include <linux/efi.h>
 #include <linux/pci.h>
 #include <linux/stddef.h>
diff --git a/include/linux/gpio/consumer.h b/include/linux/gpio/consumer.h
index fceeefd5f893..2b80cf7aa7e7 100644
--- a/include/linux/gpio/consumer.h
+++ b/include/linux/gpio/consumer.h
@@ -667,7 +667,7 @@ struct acpi_gpio_params {
 
 struct acpi_gpio_mapping {
 	const char *name;
-	const struct acpi_gpio_params *data;
+	const struct acpi_gpio_params *data __counted_by_ptr(size);
 	unsigned int size;
 
 /* Ignore IoRestriction field */
-- 
2.56.0.rc1.315.gc6ed9934b7-goog


      parent reply	other threads:[~2026-10-02 12:42 UTC|newest]

Thread overview: 14+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-28  6:38 [PATCH] " Bill Wendling
2026-09-28  7:22 ` Bill Wendling
2026-10-01 19:56   ` Linus Walleij
2026-10-01 20:04     ` Bill Wendling
2026-10-01 21:24       ` Linus Walleij
2026-10-02  7:38         ` Ard Biesheuvel
2026-10-02 12:44           ` Bill Wendling
2026-10-02 13:51             ` Ard Biesheuvel
2026-10-03  8:54               ` Bill Wendling
2026-10-03  9:10                 ` Ard Biesheuvel
2026-10-05  9:31       ` Justin Stitt
2026-10-05 10:26         ` Bill Wendling
2026-10-07 11:19           ` Linus Walleij
2026-10-02 12:42 ` Bill Wendling [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20261002124226.435265-1-morbo@google.com \
    --to=morbo@google.com \
    --cc=ardb@kernel.org \
    --cc=brgl@kernel.org \
    --cc=codemender-patching+linux@google.com \
    --cc=gustavoars@kernel.org \
    --cc=jk@ozlabs.org \
    --cc=kees@kernel.org \
    --cc=linusw@kernel.org \
    --cc=linux-gpio@vger.kernel.org \
    --cc=linux-hardening@vger.kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®