* [PATCH] compiler_types: Allow opting out of __counted_by and __counted_by_ptr
@ 2026-10-05 10:25 Bill Wendling
2026-10-05 10:44 ` Justin Stitt
` (4 more replies)
0 siblings, 5 replies; 12+ messages in thread
From: Bill Wendling @ 2026-10-05 10:25 UTC (permalink / raw)
To: Kees Cook, ardb
Cc: gustavoars, nathan, ndesaulniers, justinstitt, broonie, elver,
alan.maguire, namjain, peterz, linux-kernel, linux-hardening,
llvm, Bill Wendling
Code that runs outside the kernel proper, such as the EFI stub, gets
nothing out of the counted_by annotations: the bounds checks they feed
(FORTIFY_SOURCE, UBSAN_BOUNDS) are already disabled there.
The annotations can also break the build. A __counted_by_ptr() that
names a member declared after the pointer needs Clang's
'-fexperimental-late-parse-attributes', which the top-level Makefile
adds to 'KBUILD_CFLAGS'. The x86 EFI stub builds its own cflags and does
not get that flag, so it fails as soon as such a struct is pulled in
through a common header.
Overriding the macros from a Makefile doesn't work:
'compiler_types.h' is pulled in with '-include', which is processed
after all -D/-U options, so it re-establishes the definitions. Follow
the '__NO_FORTIFY' precedent instead: let a build define
'__NO_COUNTED_BY' or '__NO_COUNTED_BY_PTR' to turn the corresponding
annotation into a no-op. The two are kept separate but parallel so they
can be folded together once all supported compilers handle
'__counted_by' on pointers.
Assisted-by: LLM
Signed-off-by: Bill Wendling <morbo@google.com>
---
include/linux/compiler_types.h | 15 +++++++++++++--
1 file changed, 13 insertions(+), 2 deletions(-)
diff --git a/include/linux/compiler_types.h b/include/linux/compiler_types.h
index c5921f139007..916a946f623c 100644
--- a/include/linux/compiler_types.h
+++ b/include/linux/compiler_types.h
@@ -371,8 +371,14 @@ struct ftrace_likely_data {
*
* __bdos on clang < 19.1.3 can be off by 4:
* https://github.com/llvm/llvm-project/pull/112636
+ *
+ * Code that runs outside the kernel proper (e.g. the EFI stub) can define
+ * __NO_COUNTED_BY to drop the annotation, since it gains nothing from the
+ * bounds checks. Kept in step with __NO_COUNTED_BY_PTR below so the two can
+ * be folded together once __counted_by covers pointers on all supported
+ * compilers.
*/
-#ifdef CONFIG_CC_HAS_COUNTED_BY
+#if defined(CONFIG_CC_HAS_COUNTED_BY) && !defined(__NO_COUNTED_BY)
# define __counted_by(member) __attribute__((__counted_by__(member)))
#else
# define __counted_by(member)
@@ -387,8 +393,13 @@ struct ftrace_likely_data {
*
* gcc: https://gcc.gnu.org/pipermail/gcc-patches/2025-April/681727.html
* clang: https://clang.llvm.org/docs/AttributeReference.html#counted-by-counted-by-or-null-sized-by-sized-by-or-null
+ *
+ * Code that runs outside the kernel proper (e.g. the EFI stub) can define
+ * __NO_COUNTED_BY_PTR to drop the annotation, as with __NO_COUNTED_BY. Such
+ * code may also lack the flag Clang needs to parse a reference to a
+ * later-declared member (-fexperimental-late-parse-attributes).
*/
-#ifdef CONFIG_CC_HAS_COUNTED_BY_PTR
+#if defined(CONFIG_CC_HAS_COUNTED_BY_PTR) && !defined(__NO_COUNTED_BY_PTR)
#define __counted_by_ptr(member) __attribute__((__counted_by__(member)))
#else
#define __counted_by_ptr(member)
--
2.56.0.rc1.315.gc6ed9934b7-goog
^ permalink raw reply [flat|nested] 12+ messages in thread
* Re: [PATCH] compiler_types: Allow opting out of __counted_by and __counted_by_ptr
2026-10-05 10:25 [PATCH] compiler_types: Allow opting out of __counted_by and __counted_by_ptr Bill Wendling
@ 2026-10-05 10:44 ` Justin Stitt
2026-10-05 10:53 ` Ard Biesheuvel
` (3 subsequent siblings)
4 siblings, 0 replies; 12+ messages in thread
From: Justin Stitt @ 2026-10-05 10:44 UTC (permalink / raw)
To: Bill Wendling
Cc: Kees Cook, ardb, gustavoars, nathan, ndesaulniers, broonie,
elver, alan.maguire, namjain, peterz, linux-kernel,
linux-hardening, llvm
Hi,
On Mon, Oct 05, 2026 at 10:25:18AM +0000, Bill Wendling wrote:
> Code that runs outside the kernel proper, such as the EFI stub, gets
> nothing out of the counted_by annotations: the bounds checks they feed
> (FORTIFY_SOURCE, UBSAN_BOUNDS) are already disabled there.
>
> The annotations can also break the build. A __counted_by_ptr() that
> names a member declared after the pointer needs Clang's
> '-fexperimental-late-parse-attributes', which the top-level Makefile
> adds to 'KBUILD_CFLAGS'. The x86 EFI stub builds its own cflags and does
> not get that flag, so it fails as soon as such a struct is pulled in
> through a common header.
>
> Overriding the macros from a Makefile doesn't work:
> 'compiler_types.h' is pulled in with '-include', which is processed
> after all -D/-U options, so it re-establishes the definitions. Follow
> the '__NO_FORTIFY' precedent instead: let a build define
> '__NO_COUNTED_BY' or '__NO_COUNTED_BY_PTR' to turn the corresponding
> annotation into a no-op. The two are kept separate but parallel so they
> can be folded together once all supported compilers handle
> '__counted_by' on pointers.
>
> Assisted-by: LLM
> Signed-off-by: Bill Wendling <morbo@google.com>
> ---
> include/linux/compiler_types.h | 15 +++++++++++++--
> 1 file changed, 13 insertions(+), 2 deletions(-)
>
> diff --git a/include/linux/compiler_types.h b/include/linux/compiler_types.h
> index c5921f139007..916a946f623c 100644
> --- a/include/linux/compiler_types.h
> +++ b/include/linux/compiler_types.h
> @@ -371,8 +371,14 @@ struct ftrace_likely_data {
> *
> * __bdos on clang < 19.1.3 can be off by 4:
> * https://github.com/llvm/llvm-project/pull/112636
> + *
> + * Code that runs outside the kernel proper (e.g. the EFI stub) can define
> + * __NO_COUNTED_BY to drop the annotation, since it gains nothing from the
> + * bounds checks. Kept in step with __NO_COUNTED_BY_PTR below so the two can
> + * be folded together once __counted_by covers pointers on all supported
> + * compilers.
> */
> -#ifdef CONFIG_CC_HAS_COUNTED_BY
> +#if defined(CONFIG_CC_HAS_COUNTED_BY) && !defined(__NO_COUNTED_BY)
> # define __counted_by(member) __attribute__((__counted_by__(member)))
> #else
> # define __counted_by(member)
> @@ -387,8 +393,13 @@ struct ftrace_likely_data {
> *
> * gcc: https://gcc.gnu.org/pipermail/gcc-patches/2025-April/681727.html
> * clang: https://clang.llvm.org/docs/AttributeReference.html#counted-by-counted-by-or-null-sized-by-sized-by-or-null
> + *
> + * Code that runs outside the kernel proper (e.g. the EFI stub) can define
> + * __NO_COUNTED_BY_PTR to drop the annotation, as with __NO_COUNTED_BY. Such
> + * code may also lack the flag Clang needs to parse a reference to a
> + * later-declared member (-fexperimental-late-parse-attributes).
> */
> -#ifdef CONFIG_CC_HAS_COUNTED_BY_PTR
> +#if defined(CONFIG_CC_HAS_COUNTED_BY_PTR) && !defined(__NO_COUNTED_BY_PTR)
> #define __counted_by_ptr(member) __attribute__((__counted_by__(member)))
> #else
> #define __counted_by_ptr(member)
> --
> 2.56.0.rc1.315.gc6ed9934b7-goog
>
Reviewed-by: Justin Stitt <justinstitt@google.com>
Thanks
Justin
^ permalink raw reply [flat|nested] 12+ messages in thread
* Re: [PATCH] compiler_types: Allow opting out of __counted_by and __counted_by_ptr
2026-10-05 10:25 [PATCH] compiler_types: Allow opting out of __counted_by and __counted_by_ptr Bill Wendling
2026-10-05 10:44 ` Justin Stitt
@ 2026-10-05 10:53 ` Ard Biesheuvel
2026-10-05 15:52 ` Bill Wendling
2026-10-05 19:19 ` Bill Wendling
` (2 subsequent siblings)
4 siblings, 1 reply; 12+ messages in thread
From: Ard Biesheuvel @ 2026-10-05 10:53 UTC (permalink / raw)
To: Bill Wendling, Kees Cook
Cc: Gustavo A. R. Silva, Nathan Chancellor, Nick Desaulniers,
Justin Stitt, Mark Brown, Marco Elver, alan.maguire, namjain,
Peter Zijlstra, linux-kernel, linux-hardening, llvm
Hi Bill,
On Mon, 5 Oct 2026, at 12:25, Bill Wendling wrote:
> Code that runs outside the kernel proper, such as the EFI stub, gets
> nothing out of the counted_by annotations: the bounds checks they feed
> (FORTIFY_SOURCE, UBSAN_BOUNDS) are already disabled there.
>
> The annotations can also break the build. A __counted_by_ptr() that
> names a member declared after the pointer needs Clang's
> '-fexperimental-late-parse-attributes', which the top-level Makefile
> adds to 'KBUILD_CFLAGS'. The x86 EFI stub builds its own cflags and does
> not get that flag, so it fails as soon as such a struct is pulled in
> through a common header.
>
> Overriding the macros from a Makefile doesn't work:
> 'compiler_types.h' is pulled in with '-include', which is processed
> after all -D/-U options, so it re-establishes the definitions. Follow
> the '__NO_FORTIFY' precedent instead: let a build define
> '__NO_COUNTED_BY' or '__NO_COUNTED_BY_PTR' to turn the corresponding
> annotation into a no-op. The two are kept separate but parallel so they
> can be folded together once all supported compilers handle
> '__counted_by' on pointers.
>
I'd prefer a single macro here - if there is ever a case where we need to
turn off one but not the other, we can revisit.
Otherwise, this looks good to me - thanks.
^ permalink raw reply [flat|nested] 12+ messages in thread
* Re: [PATCH] compiler_types: Allow opting out of __counted_by and __counted_by_ptr
2026-10-05 10:53 ` Ard Biesheuvel
@ 2026-10-05 15:52 ` Bill Wendling
0 siblings, 0 replies; 12+ messages in thread
From: Bill Wendling @ 2026-10-05 15:52 UTC (permalink / raw)
To: Ard Biesheuvel
Cc: Kees Cook, Gustavo A. R. Silva, Nathan Chancellor,
Nick Desaulniers, Justin Stitt, Mark Brown, Marco Elver,
alan.maguire, namjain, Peter Zijlstra, linux-kernel,
linux-hardening, llvm
On Mon, Oct 5, 2026 at 3:54 AM Ard Biesheuvel <ardb@kernel.org> wrote:
>
> Hi Bill,
>
> On Mon, 5 Oct 2026, at 12:25, Bill Wendling wrote:
> > Code that runs outside the kernel proper, such as the EFI stub, gets
> > nothing out of the counted_by annotations: the bounds checks they feed
> > (FORTIFY_SOURCE, UBSAN_BOUNDS) are already disabled there.
> >
> > The annotations can also break the build. A __counted_by_ptr() that
> > names a member declared after the pointer needs Clang's
> > '-fexperimental-late-parse-attributes', which the top-level Makefile
> > adds to 'KBUILD_CFLAGS'. The x86 EFI stub builds its own cflags and does
> > not get that flag, so it fails as soon as such a struct is pulled in
> > through a common header.
> >
> > Overriding the macros from a Makefile doesn't work:
> > 'compiler_types.h' is pulled in with '-include', which is processed
> > after all -D/-U options, so it re-establishes the definitions. Follow
> > the '__NO_FORTIFY' precedent instead: let a build define
> > '__NO_COUNTED_BY' or '__NO_COUNTED_BY_PTR' to turn the corresponding
> > annotation into a no-op. The two are kept separate but parallel so they
> > can be folded together once all supported compilers handle
> > '__counted_by' on pointers.
> >
>
> I'd prefer a single macro here - if there is ever a case where we need to
> turn off one but not the other, we can revisit.
>
> Otherwise, this looks good to me - thanks.
Hi Ard,
I wanted to do it this way because the two attributes rely upon
compiler versions, and this gives us more flexibility. Eventually,
there will be Only One(tm), once the minimal compiler version supports
both __counted_by and __counted_by_ptr.
But it's a small issue. I can resend with just the __NO_COUNTED_BY_PTR part.
-bw
^ permalink raw reply [flat|nested] 12+ messages in thread
* [PATCH] compiler_types: Allow opting out of __counted_by and __counted_by_ptr
2026-10-05 10:25 [PATCH] compiler_types: Allow opting out of __counted_by and __counted_by_ptr Bill Wendling
2026-10-05 10:44 ` Justin Stitt
2026-10-05 10:53 ` Ard Biesheuvel
@ 2026-10-05 19:19 ` Bill Wendling
2026-10-05 19:20 ` [PATCH v3] " Bill Wendling
2026-10-06 9:43 ` [PATCH v4] " Bill Wendling
4 siblings, 0 replies; 12+ messages in thread
From: Bill Wendling @ 2026-10-05 19:19 UTC (permalink / raw)
To: Kees Cook, ardb
Cc: gustavoars, nathan, ndesaulniers, justinstitt, broonie, elver,
alan.maguire, namjain, peterz, linux-kernel, linux-hardening,
llvm, Bill Wendling
Code that runs outside the kernel proper, such as the EFI stub, gets
nothing out of the counted_by annotations: the bounds checks they feed
(FORTIFY_SOURCE, UBSAN_BOUNDS) are already disabled there.
The annotations can also break the build. A __counted_by_ptr() that
names a member declared after the pointer needs Clang's
'-fexperimental-late-parse-attributes', which the top-level Makefile
adds to 'KBUILD_CFLAGS'. The x86 EFI stub builds its own cflags and does
not get that flag, so it fails as soon as such a struct is pulled in
through a common header.
Overriding the __counted_by_ptr macro from a Makefile doesn't work:
'compiler_types.h' is pulled in with '-include', which is processed
after all -D/-U options, so it re-establishes the definitions. Follow
the '__NO_FORTIFY' precedent instead: let a build define
'__NO_COUNTED_BY_PTR' to turn the corresponding annotation into a no-op.
Assisted-by: LLM
Signed-off-by: Bill Wendling <morbo@google.com>
---
v2: Only specify __NO_COUNTED_BY_PTR. Leave __NO_COUNTED_BY until we need it.
---
include/linux/compiler_types.h | 7 ++++++-
1 file changed, 6 insertions(+), 1 deletion(-)
diff --git a/include/linux/compiler_types.h b/include/linux/compiler_types.h
index c5921f139007..8bde6798b4ec 100644
--- a/include/linux/compiler_types.h
+++ b/include/linux/compiler_types.h
@@ -387,8 +387,13 @@ struct ftrace_likely_data {
*
* gcc: https://gcc.gnu.org/pipermail/gcc-patches/2025-April/681727.html
* clang: https://clang.llvm.org/docs/AttributeReference.html#counted-by-counted-by-or-null-sized-by-sized-by-or-null
+ *
+ * Code that runs outside the kernel proper (e.g. the EFI stub) can define
+ * __NO_COUNTED_BY_PTR to drop the annotation. Such code may also lack the flag
+ * Clang needs to parse a reference to a later-declared member
+ * (-fexperimental-late-parse-attributes).
*/
-#ifdef CONFIG_CC_HAS_COUNTED_BY_PTR
+#if defined(CONFIG_CC_HAS_COUNTED_BY_PTR) && !defined(__NO_COUNTED_BY_PTR)
#define __counted_by_ptr(member) __attribute__((__counted_by__(member)))
#else
#define __counted_by_ptr(member)
--
2.56.0.rc1.315.gc6ed9934b7-goog
^ permalink raw reply [flat|nested] 12+ messages in thread
* [PATCH v3] compiler_types: Allow opting out of __counted_by and __counted_by_ptr
2026-10-05 10:25 [PATCH] compiler_types: Allow opting out of __counted_by and __counted_by_ptr Bill Wendling
` (2 preceding siblings ...)
2026-10-05 19:19 ` Bill Wendling
@ 2026-10-05 19:20 ` Bill Wendling
2026-10-05 21:25 ` Ard Biesheuvel
2026-10-06 9:43 ` [PATCH v4] " Bill Wendling
4 siblings, 1 reply; 12+ messages in thread
From: Bill Wendling @ 2026-10-05 19:20 UTC (permalink / raw)
To: Kees Cook, ardb
Cc: gustavoars, nathan, ndesaulniers, justinstitt, broonie, elver,
alan.maguire, namjain, peterz, linux-kernel, linux-hardening,
llvm, Bill Wendling
Code that runs outside the kernel proper, such as the EFI stub, gets
nothing out of the counted_by annotations: the bounds checks they feed
(FORTIFY_SOURCE, UBSAN_BOUNDS) are already disabled there.
The annotations can also break the build. A __counted_by_ptr() that
names a member declared after the pointer needs Clang's
'-fexperimental-late-parse-attributes', which the top-level Makefile
adds to 'KBUILD_CFLAGS'. The x86 EFI stub builds its own cflags and does
not get that flag, so it fails as soon as such a struct is pulled in
through a common header.
Overriding the __counted_by_ptr macro from a Makefile doesn't work:
'compiler_types.h' is pulled in with '-include', which is processed
after all -D/-U options, so it re-establishes the definitions. Follow
the '__NO_FORTIFY' precedent instead: let a build define
'__NO_COUNTED_BY_PTR' to turn the corresponding annotation into a no-op.
Assisted-by: LLM
Signed-off-by: Bill Wendling <morbo@google.com>
---
v2: Only specify __NO_COUNTED_BY_PTR. Leave __NO_COUNTED_BY until we need it.
v3: Add the version to the Subject line.
---
include/linux/compiler_types.h | 7 ++++++-
1 file changed, 6 insertions(+), 1 deletion(-)
diff --git a/include/linux/compiler_types.h b/include/linux/compiler_types.h
index c5921f139007..8bde6798b4ec 100644
--- a/include/linux/compiler_types.h
+++ b/include/linux/compiler_types.h
@@ -387,8 +387,13 @@ struct ftrace_likely_data {
*
* gcc: https://gcc.gnu.org/pipermail/gcc-patches/2025-April/681727.html
* clang: https://clang.llvm.org/docs/AttributeReference.html#counted-by-counted-by-or-null-sized-by-sized-by-or-null
+ *
+ * Code that runs outside the kernel proper (e.g. the EFI stub) can define
+ * __NO_COUNTED_BY_PTR to drop the annotation. Such code may also lack the flag
+ * Clang needs to parse a reference to a later-declared member
+ * (-fexperimental-late-parse-attributes).
*/
-#ifdef CONFIG_CC_HAS_COUNTED_BY_PTR
+#if defined(CONFIG_CC_HAS_COUNTED_BY_PTR) && !defined(__NO_COUNTED_BY_PTR)
#define __counted_by_ptr(member) __attribute__((__counted_by__(member)))
#else
#define __counted_by_ptr(member)
--
2.56.0.rc1.315.gc6ed9934b7-goog
^ permalink raw reply [flat|nested] 12+ messages in thread
* Re: [PATCH v3] compiler_types: Allow opting out of __counted_by and __counted_by_ptr
2026-10-05 19:20 ` [PATCH v3] " Bill Wendling
@ 2026-10-05 21:25 ` Ard Biesheuvel
2026-10-06 7:30 ` Justin Stitt
0 siblings, 1 reply; 12+ messages in thread
From: Ard Biesheuvel @ 2026-10-05 21:25 UTC (permalink / raw)
To: Bill Wendling, Kees Cook
Cc: Gustavo A. R. Silva, Nathan Chancellor, Nick Desaulniers,
Justin Stitt, Mark Brown, Marco Elver, alan.maguire, namjain,
Peter Zijlstra, linux-kernel, linux-hardening, llvm
On Mon, 5 Oct 2026, at 21:20, Bill Wendling wrote:
> Code that runs outside the kernel proper, such as the EFI stub, gets
> nothing out of the counted_by annotations: the bounds checks they feed
> (FORTIFY_SOURCE, UBSAN_BOUNDS) are already disabled there.
>
> The annotations can also break the build. A __counted_by_ptr() that
> names a member declared after the pointer needs Clang's
> '-fexperimental-late-parse-attributes', which the top-level Makefile
> adds to 'KBUILD_CFLAGS'. The x86 EFI stub builds its own cflags and does
> not get that flag, so it fails as soon as such a struct is pulled in
> through a common header.
>
> Overriding the __counted_by_ptr macro from a Makefile doesn't work:
> 'compiler_types.h' is pulled in with '-include', which is processed
> after all -D/-U options, so it re-establishes the definitions. Follow
> the '__NO_FORTIFY' precedent instead: let a build define
> '__NO_COUNTED_BY_PTR' to turn the corresponding annotation into a no-op.
>
> Assisted-by: LLM
> Signed-off-by: Bill Wendling <morbo@google.com>
> ---
> v2: Only specify __NO_COUNTED_BY_PTR. Leave __NO_COUNTED_BY until we need it.
> v3: Add the version to the Subject line.
> ---
> include/linux/compiler_types.h | 7 ++++++-
> 1 file changed, 6 insertions(+), 1 deletion(-)
>
> diff --git a/include/linux/compiler_types.h
> b/include/linux/compiler_types.h
> index c5921f139007..8bde6798b4ec 100644
> --- a/include/linux/compiler_types.h
> +++ b/include/linux/compiler_types.h
> @@ -387,8 +387,13 @@ struct ftrace_likely_data {
> *
> * gcc:
> https://gcc.gnu.org/pipermail/gcc-patches/2025-April/681727.html
> * clang:
> https://clang.llvm.org/docs/AttributeReference.html#counted-by-counted-by-or-null-sized-by-sized-by-or-null
> + *
> + * Code that runs outside the kernel proper (e.g. the EFI stub) can
> define
> + * __NO_COUNTED_BY_PTR to drop the annotation. Such code may also lack
> the flag
> + * Clang needs to parse a reference to a later-declared member
> + * (-fexperimental-late-parse-attributes).
> */
> -#ifdef CONFIG_CC_HAS_COUNTED_BY_PTR
> +#if defined(CONFIG_CC_HAS_COUNTED_BY_PTR) &&
> !defined(__NO_COUNTED_BY_PTR)
> #define
> __counted_by_ptr(member) __attribute__((__counted_by__(member)))
> #else
> #define __counted_by_ptr(member)
Apologies, I may have been unclear.
What I would like to see here is something like
#ifndef __NO_COUNTED_BY
#define __counted_by(member) __attribute__((....))
#define __counted_by_ptr(member) __attribute__((....))
#else
#define __counted_by(member)
#define __counted_by_ptr(member)
#endif
^ permalink raw reply [flat|nested] 12+ messages in thread
* Re: [PATCH v3] compiler_types: Allow opting out of __counted_by and __counted_by_ptr
2026-10-05 21:25 ` Ard Biesheuvel
@ 2026-10-06 7:30 ` Justin Stitt
2026-10-06 8:07 ` Ard Biesheuvel
0 siblings, 1 reply; 12+ messages in thread
From: Justin Stitt @ 2026-10-06 7:30 UTC (permalink / raw)
To: Ard Biesheuvel
Cc: Bill Wendling, Kees Cook, Gustavo A. R. Silva, Nathan Chancellor,
Nick Desaulniers, Mark Brown, Marco Elver, alan.maguire, namjain,
Peter Zijlstra, linux-kernel, linux-hardening, llvm
Hi,
On Mon, Oct 5, 2026 at 2:25 PM Ard Biesheuvel <ardb@kernel.org> wrote:
>
>
>
> On Mon, 5 Oct 2026, at 21:20, Bill Wendling wrote:
> > Code that runs outside the kernel proper, such as the EFI stub, gets
> > nothing out of the counted_by annotations: the bounds checks they feed
> > (FORTIFY_SOURCE, UBSAN_BOUNDS) are already disabled there.
> >
> > The annotations can also break the build. A __counted_by_ptr() that
> > names a member declared after the pointer needs Clang's
> > '-fexperimental-late-parse-attributes', which the top-level Makefile
> > adds to 'KBUILD_CFLAGS'. The x86 EFI stub builds its own cflags and does
> > not get that flag, so it fails as soon as such a struct is pulled in
> > through a common header.
> >
> > Overriding the __counted_by_ptr macro from a Makefile doesn't work:
> > 'compiler_types.h' is pulled in with '-include', which is processed
> > after all -D/-U options, so it re-establishes the definitions. Follow
> > the '__NO_FORTIFY' precedent instead: let a build define
> > '__NO_COUNTED_BY_PTR' to turn the corresponding annotation into a no-op.
> >
> > Assisted-by: LLM
> > Signed-off-by: Bill Wendling <morbo@google.com>
> > ---
> > v2: Only specify __NO_COUNTED_BY_PTR. Leave __NO_COUNTED_BY until we need it.
> > v3: Add the version to the Subject line.
> > ---
> > include/linux/compiler_types.h | 7 ++++++-
> > 1 file changed, 6 insertions(+), 1 deletion(-)
> >
> > diff --git a/include/linux/compiler_types.h
> > b/include/linux/compiler_types.h
> > index c5921f139007..8bde6798b4ec 100644
> > --- a/include/linux/compiler_types.h
> > +++ b/include/linux/compiler_types.h
> > @@ -387,8 +387,13 @@ struct ftrace_likely_data {
> > *
> > * gcc:
> > https://gcc.gnu.org/pipermail/gcc-patches/2025-April/681727.html
> > * clang:
> > https://clang.llvm.org/docs/AttributeReference.html#counted-by-counted-by-or-null-sized-by-sized-by-or-null
> > + *
> > + * Code that runs outside the kernel proper (e.g. the EFI stub) can
> > define
> > + * __NO_COUNTED_BY_PTR to drop the annotation. Such code may also lack
> > the flag
> > + * Clang needs to parse a reference to a later-declared member
> > + * (-fexperimental-late-parse-attributes).
> > */
> > -#ifdef CONFIG_CC_HAS_COUNTED_BY_PTR
> > +#if defined(CONFIG_CC_HAS_COUNTED_BY_PTR) &&
> > !defined(__NO_COUNTED_BY_PTR)
> > #define
> > __counted_by_ptr(member) __attribute__((__counted_by__(member)))
> > #else
> > #define __counted_by_ptr(member)
>
> Apologies, I may have been unclear.
>
> What I would like to see here is something like
>
> #ifndef __NO_COUNTED_BY
> #define __counted_by(member) __attribute__((....))
> #define __counted_by_ptr(member) __attribute__((....))
> #else
> #define __counted_by(member)
> #define __counted_by_ptr(member)
> #endif
FWIW, Bill's original patch had this explanation
"The two are kept separate but parallel so they
can be folded together once all supported compilers handle
'__counted_by' on pointers."
Justin
^ permalink raw reply [flat|nested] 12+ messages in thread
* Re: [PATCH v3] compiler_types: Allow opting out of __counted_by and __counted_by_ptr
2026-10-06 7:30 ` Justin Stitt
@ 2026-10-06 8:07 ` Ard Biesheuvel
2026-10-06 9:23 ` Bill Wendling
0 siblings, 1 reply; 12+ messages in thread
From: Ard Biesheuvel @ 2026-10-06 8:07 UTC (permalink / raw)
To: Justin Stitt
Cc: Bill Wendling, Kees Cook, Gustavo A. R. Silva, Nathan Chancellor,
Nick Desaulniers, Mark Brown, Marco Elver, alan.maguire, namjain,
Peter Zijlstra, linux-kernel, linux-hardening, llvm
On Tue, 6 Oct 2026, at 09:30, Justin Stitt wrote:
> Hi,
>
> On Mon, Oct 5, 2026 at 2:25 PM Ard Biesheuvel <ardb@kernel.org> wrote:
>>
>>
>>
>> On Mon, 5 Oct 2026, at 21:20, Bill Wendling wrote:
>> > Code that runs outside the kernel proper, such as the EFI stub, gets
>> > nothing out of the counted_by annotations: the bounds checks they feed
>> > (FORTIFY_SOURCE, UBSAN_BOUNDS) are already disabled there.
>> >
>> > The annotations can also break the build. A __counted_by_ptr() that
>> > names a member declared after the pointer needs Clang's
>> > '-fexperimental-late-parse-attributes', which the top-level Makefile
>> > adds to 'KBUILD_CFLAGS'. The x86 EFI stub builds its own cflags and does
>> > not get that flag, so it fails as soon as such a struct is pulled in
>> > through a common header.
>> >
>> > Overriding the __counted_by_ptr macro from a Makefile doesn't work:
>> > 'compiler_types.h' is pulled in with '-include', which is processed
>> > after all -D/-U options, so it re-establishes the definitions. Follow
>> > the '__NO_FORTIFY' precedent instead: let a build define
>> > '__NO_COUNTED_BY_PTR' to turn the corresponding annotation into a no-op.
>> >
>> > Assisted-by: LLM
>> > Signed-off-by: Bill Wendling <morbo@google.com>
>> > ---
>> > v2: Only specify __NO_COUNTED_BY_PTR. Leave __NO_COUNTED_BY until we need it.
>> > v3: Add the version to the Subject line.
>> > ---
>> > include/linux/compiler_types.h | 7 ++++++-
>> > 1 file changed, 6 insertions(+), 1 deletion(-)
>> >
>> > diff --git a/include/linux/compiler_types.h
>> > b/include/linux/compiler_types.h
>> > index c5921f139007..8bde6798b4ec 100644
>> > --- a/include/linux/compiler_types.h
>> > +++ b/include/linux/compiler_types.h
>> > @@ -387,8 +387,13 @@ struct ftrace_likely_data {
>> > *
>> > * gcc:
>> > https://gcc.gnu.org/pipermail/gcc-patches/2025-April/681727.html
>> > * clang:
>> > https://clang.llvm.org/docs/AttributeReference.html#counted-by-counted-by-or-null-sized-by-sized-by-or-null
>> > + *
>> > + * Code that runs outside the kernel proper (e.g. the EFI stub) can
>> > define
>> > + * __NO_COUNTED_BY_PTR to drop the annotation. Such code may also lack
>> > the flag
>> > + * Clang needs to parse a reference to a later-declared member
>> > + * (-fexperimental-late-parse-attributes).
>> > */
>> > -#ifdef CONFIG_CC_HAS_COUNTED_BY_PTR
>> > +#if defined(CONFIG_CC_HAS_COUNTED_BY_PTR) &&
>> > !defined(__NO_COUNTED_BY_PTR)
>> > #define
>> > __counted_by_ptr(member) __attribute__((__counted_by__(member)))
>> > #else
>> > #define __counted_by_ptr(member)
>>
>> Apologies, I may have been unclear.
>>
>> What I would like to see here is something like
>>
>> #ifndef __NO_COUNTED_BY
>> #define __counted_by(member) __attribute__((....))
>> #define __counted_by_ptr(member) __attribute__((....))
>> #else
>> #define __counted_by(member)
>> #define __counted_by_ptr(member)
>> #endif
>
> FWIW, Bill's original patch had this explanation
>
> "The two are kept separate but parallel so they
> can be folded together once all supported compilers handle
> '__counted_by' on pointers."
>
When opting out of this, whether or not the compiler supports
all variants of counted_by() is irrelevant. The same #define
should just opt out of all of them.
If the need arises to be more granular here, we can always add
that later but I don't want to have to add
-D__NO_COUNTED_BY -D__NO_COUNTED_BY_PTR
everywhere today, and go back and remove the second part once
all compilers have caught up.
^ permalink raw reply [flat|nested] 12+ messages in thread
* Re: [PATCH v3] compiler_types: Allow opting out of __counted_by and __counted_by_ptr
2026-10-06 8:07 ` Ard Biesheuvel
@ 2026-10-06 9:23 ` Bill Wendling
0 siblings, 0 replies; 12+ messages in thread
From: Bill Wendling @ 2026-10-06 9:23 UTC (permalink / raw)
To: Ard Biesheuvel
Cc: Justin Stitt, Kees Cook, Gustavo A. R. Silva, Nathan Chancellor,
Nick Desaulniers, Mark Brown, Marco Elver, alan.maguire, namjain,
Peter Zijlstra, linux-kernel, linux-hardening, llvm
On Tue, Oct 6, 2026 at 1:08 AM Ard Biesheuvel <ardb@kernel.org> wrote:
> On Tue, 6 Oct 2026, at 09:30, Justin Stitt wrote:
> > Hi,
> >
> > On Mon, Oct 5, 2026 at 2:25 PM Ard Biesheuvel <ardb@kernel.org> wrote:
> >>
> >>
> >>
> >> On Mon, 5 Oct 2026, at 21:20, Bill Wendling wrote:
> >> > Code that runs outside the kernel proper, such as the EFI stub, gets
> >> > nothing out of the counted_by annotations: the bounds checks they feed
> >> > (FORTIFY_SOURCE, UBSAN_BOUNDS) are already disabled there.
> >> >
> >> > The annotations can also break the build. A __counted_by_ptr() that
> >> > names a member declared after the pointer needs Clang's
> >> > '-fexperimental-late-parse-attributes', which the top-level Makefile
> >> > adds to 'KBUILD_CFLAGS'. The x86 EFI stub builds its own cflags and does
> >> > not get that flag, so it fails as soon as such a struct is pulled in
> >> > through a common header.
> >> >
> >> > Overriding the __counted_by_ptr macro from a Makefile doesn't work:
> >> > 'compiler_types.h' is pulled in with '-include', which is processed
> >> > after all -D/-U options, so it re-establishes the definitions. Follow
> >> > the '__NO_FORTIFY' precedent instead: let a build define
> >> > '__NO_COUNTED_BY_PTR' to turn the corresponding annotation into a no-op.
> >> >
> >> > Assisted-by: LLM
> >> > Signed-off-by: Bill Wendling <morbo@google.com>
> >> > ---
> >> > v2: Only specify __NO_COUNTED_BY_PTR. Leave __NO_COUNTED_BY until we need it.
> >> > v3: Add the version to the Subject line.
> >> > ---
> >> > include/linux/compiler_types.h | 7 ++++++-
> >> > 1 file changed, 6 insertions(+), 1 deletion(-)
> >> >
> >> > diff --git a/include/linux/compiler_types.h
> >> > b/include/linux/compiler_types.h
> >> > index c5921f139007..8bde6798b4ec 100644
> >> > --- a/include/linux/compiler_types.h
> >> > +++ b/include/linux/compiler_types.h
> >> > @@ -387,8 +387,13 @@ struct ftrace_likely_data {
> >> > *
> >> > * gcc:
> >> > https://gcc.gnu.org/pipermail/gcc-patches/2025-April/681727.html
> >> > * clang:
> >> > https://clang.llvm.org/docs/AttributeReference.html#counted-by-counted-by-or-null-sized-by-sized-by-or-null
> >> > + *
> >> > + * Code that runs outside the kernel proper (e.g. the EFI stub) can
> >> > define
> >> > + * __NO_COUNTED_BY_PTR to drop the annotation. Such code may also lack
> >> > the flag
> >> > + * Clang needs to parse a reference to a later-declared member
> >> > + * (-fexperimental-late-parse-attributes).
> >> > */
> >> > -#ifdef CONFIG_CC_HAS_COUNTED_BY_PTR
> >> > +#if defined(CONFIG_CC_HAS_COUNTED_BY_PTR) &&
> >> > !defined(__NO_COUNTED_BY_PTR)
> >> > #define
> >> > __counted_by_ptr(member) __attribute__((__counted_by__(member)))
> >> > #else
> >> > #define __counted_by_ptr(member)
> >>
> >> Apologies, I may have been unclear.
> >>
> >> What I would like to see here is something like
> >>
> >> #ifndef __NO_COUNTED_BY
> >> #define __counted_by(member) __attribute__((....))
> >> #define __counted_by_ptr(member) __attribute__((....))
> >> #else
> >> #define __counted_by(member)
> >> #define __counted_by_ptr(member)
> >> #endif
> >
> > FWIW, Bill's original patch had this explanation
> >
> > "The two are kept separate but parallel so they
> > can be folded together once all supported compilers handle
> > '__counted_by' on pointers."
> >
>
> When opting out of this, whether or not the compiler supports
> all variants of counted_by() is irrelevant. The same #define
> should just opt out of all of them.
>
> If the need arises to be more granular here, we can always add
> that later but I don't want to have to add
>
> -D__NO_COUNTED_BY -D__NO_COUNTED_BY_PTR
>
> everywhere today, and go back and remove the second part once
> all compilers have caught up.
>
It would reduce churn in the code base once we no longer need a
separate '__counted_by_ptr' macro. However, we should specify that
__NO_COUNTED_BY should be used sparingly, as there are other, better
ways to "opt out" of the __counted_by family of attributes. Basically,
it should only be used if the Makefile doesn't inherit its KCFLAGS
from the root Makefile.
-bw
^ permalink raw reply [flat|nested] 12+ messages in thread
* [PATCH v4] compiler_types: Allow opting out of __counted_by and __counted_by_ptr
2026-10-05 10:25 [PATCH] compiler_types: Allow opting out of __counted_by and __counted_by_ptr Bill Wendling
` (3 preceding siblings ...)
2026-10-05 19:20 ` [PATCH v3] " Bill Wendling
@ 2026-10-06 9:43 ` Bill Wendling
2026-10-06 10:08 ` Ard Biesheuvel
4 siblings, 1 reply; 12+ messages in thread
From: Bill Wendling @ 2026-10-06 9:43 UTC (permalink / raw)
To: Kees Cook, ardb
Cc: gustavoars, nathan, ndesaulniers, justinstitt, broonie, elver,
alan.maguire, namjain, peterz, linux-kernel, linux-hardening,
llvm, Bill Wendling
Code that runs outside the kernel proper, such as the EFI stub, gets
nothing out of the counted_by annotations: the bounds checks they feed
(FORTIFY_SOURCE, UBSAN_BOUNDS) are already disabled there.
The annotations can also break the build. A __counted_by_ptr() that
names a member declared after the pointer needs Clang's
'-fexperimental-late-parse-attributes', which the top-level Makefile
adds to 'KBUILD_CFLAGS'. The x86 EFI stub builds its own cflags and does
not get that flag, so it fails as soon as such a struct is pulled in
through a common header.
Overriding the macros from a Makefile doesn't work:
'compiler_types.h' is pulled in with '-include', which is processed
after all -D/-U options, so it re-establishes the definitions. Follow
the '__NO_FORTIFY' precedent instead: let a build define
'__NO_COUNTED_BY' to turn the corresponding annotation into a no-op.
Assisted-by: LLM
Signed-off-by: Bill Wendling <morbo@google.com>
---
v2: Only specify __NO_COUNTED_BY_PTR. Leave __NO_COUNTED_BY until we need it.
v3: Add the version to the Subject line.
v4: Use __NO_COUNTED_BY to reduce churn later on.
---
include/linux/compiler_types.h | 7 ++++++-
1 file changed, 6 insertions(+), 1 deletion(-)
diff --git a/include/linux/compiler_types.h b/include/linux/compiler_types.h
index c5921f139007..05e2b637f1cd 100644
--- a/include/linux/compiler_types.h
+++ b/include/linux/compiler_types.h
@@ -371,8 +371,13 @@ struct ftrace_likely_data {
*
* __bdos on clang < 19.1.3 can be off by 4:
* https://github.com/llvm/llvm-project/pull/112636
+ *
+ * Code that runs outside the kernel proper (e.g. the EFI stub) can define
+ * __NO_COUNTED_BY to drop the annotation, since it gains nothing from the
+ * bounds checks. __NO_COUNTED_BY should be used sparingly, because there are
+ * better options for opting out of bounds checking.
*/
-#ifdef CONFIG_CC_HAS_COUNTED_BY
+#if defined(CONFIG_CC_HAS_COUNTED_BY) && !defined(__NO_COUNTED_BY)
# define __counted_by(member) __attribute__((__counted_by__(member)))
#else
# define __counted_by(member)
--
2.56.0.rc1.315.gc6ed9934b7-goog
^ permalink raw reply [flat|nested] 12+ messages in thread
* Re: [PATCH v4] compiler_types: Allow opting out of __counted_by and __counted_by_ptr
2026-10-06 9:43 ` [PATCH v4] " Bill Wendling
@ 2026-10-06 10:08 ` Ard Biesheuvel
0 siblings, 0 replies; 12+ messages in thread
From: Ard Biesheuvel @ 2026-10-06 10:08 UTC (permalink / raw)
To: Bill Wendling, Kees Cook
Cc: Gustavo A. R. Silva, Nathan Chancellor, Nick Desaulniers,
Justin Stitt, Mark Brown, Marco Elver, alan.maguire, namjain,
Peter Zijlstra, linux-kernel, linux-hardening, llvm
On Tue, 6 Oct 2026, at 11:43, Bill Wendling wrote:
> Code that runs outside the kernel proper, such as the EFI stub, gets
> nothing out of the counted_by annotations: the bounds checks they feed
> (FORTIFY_SOURCE, UBSAN_BOUNDS) are already disabled there.
>
> The annotations can also break the build. A __counted_by_ptr() that
> names a member declared after the pointer needs Clang's
> '-fexperimental-late-parse-attributes', which the top-level Makefile
> adds to 'KBUILD_CFLAGS'. The x86 EFI stub builds its own cflags and does
> not get that flag, so it fails as soon as such a struct is pulled in
> through a common header.
>
> Overriding the macros from a Makefile doesn't work:
> 'compiler_types.h' is pulled in with '-include', which is processed
> after all -D/-U options, so it re-establishes the definitions. Follow
> the '__NO_FORTIFY' precedent instead: let a build define
> '__NO_COUNTED_BY' to turn the corresponding annotation into a no-op.
>
> Assisted-by: LLM
> Signed-off-by: Bill Wendling <morbo@google.com>
> ---
> v2: Only specify __NO_COUNTED_BY_PTR. Leave __NO_COUNTED_BY until we need it.
> v3: Add the version to the Subject line.
> v4: Use __NO_COUNTED_BY to reduce churn later on.
> ---
> include/linux/compiler_types.h | 7 ++++++-
> 1 file changed, 6 insertions(+), 1 deletion(-)
>
> diff --git a/include/linux/compiler_types.h b/include/linux/compiler_types.h
> index c5921f139007..05e2b637f1cd 100644
> --- a/include/linux/compiler_types.h
> +++ b/include/linux/compiler_types.h
> @@ -371,8 +371,13 @@ struct ftrace_likely_data {
> *
> * __bdos on clang < 19.1.3 can be off by 4:
> * https://github.com/llvm/llvm-project/pull/112636
> + *
> + * Code that runs outside the kernel proper (e.g. the EFI stub) can define
> + * __NO_COUNTED_BY to drop the annotation, since it gains nothing from the
> + * bounds checks. __NO_COUNTED_BY should be used sparingly, because there are
> + * better options for opting out of bounds checking.
> */
> -#ifdef CONFIG_CC_HAS_COUNTED_BY
> +#if defined(CONFIG_CC_HAS_COUNTED_BY) && !defined(__NO_COUNTED_BY)
> # define __counted_by(member) __attribute__((__counted_by__(member)))
> #else
> # define __counted_by(member)
What happened to counted_by_ptr() now? __NO_COUNTED_BY should disable that too.
^ permalink raw reply [flat|nested] 12+ messages in thread
end of thread, other threads:[~2026-10-06 10:09 UTC | newest]
Thread overview: 12+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-10-05 10:25 [PATCH] compiler_types: Allow opting out of __counted_by and __counted_by_ptr Bill Wendling
2026-10-05 10:44 ` Justin Stitt
2026-10-05 10:53 ` Ard Biesheuvel
2026-10-05 15:52 ` Bill Wendling
2026-10-05 19:19 ` Bill Wendling
2026-10-05 19:20 ` [PATCH v3] " Bill Wendling
2026-10-05 21:25 ` Ard Biesheuvel
2026-10-06 7:30 ` Justin Stitt
2026-10-06 8:07 ` Ard Biesheuvel
2026-10-06 9:23 ` Bill Wendling
2026-10-06 9:43 ` [PATCH v4] " Bill Wendling
2026-10-06 10:08 ` Ard Biesheuvel
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®