* Re: [PATCH] compiler_types: Allow opting out of __counted_by and __counted_by_ptr
2026-10-05 10:25 [PATCH] compiler_types: Allow opting out of __counted_by and __counted_by_ptr Bill Wendling
@ 2026-10-05 10:44 ` Justin Stitt
2026-10-05 10:53 ` Ard Biesheuvel
` (2 subsequent siblings)
3 siblings, 0 replies; 9+ messages in thread
From: Justin Stitt @ 2026-10-05 10:44 UTC (permalink / raw)
To: Bill Wendling
Cc: Kees Cook, ardb, gustavoars, nathan, ndesaulniers, broonie,
elver, alan.maguire, namjain, peterz, linux-kernel,
linux-hardening, llvm
Hi,
On Mon, Oct 05, 2026 at 10:25:18AM +0000, Bill Wendling wrote:
> Code that runs outside the kernel proper, such as the EFI stub, gets
> nothing out of the counted_by annotations: the bounds checks they feed
> (FORTIFY_SOURCE, UBSAN_BOUNDS) are already disabled there.
>
> The annotations can also break the build. A __counted_by_ptr() that
> names a member declared after the pointer needs Clang's
> '-fexperimental-late-parse-attributes', which the top-level Makefile
> adds to 'KBUILD_CFLAGS'. The x86 EFI stub builds its own cflags and does
> not get that flag, so it fails as soon as such a struct is pulled in
> through a common header.
>
> Overriding the macros from a Makefile doesn't work:
> 'compiler_types.h' is pulled in with '-include', which is processed
> after all -D/-U options, so it re-establishes the definitions. Follow
> the '__NO_FORTIFY' precedent instead: let a build define
> '__NO_COUNTED_BY' or '__NO_COUNTED_BY_PTR' to turn the corresponding
> annotation into a no-op. The two are kept separate but parallel so they
> can be folded together once all supported compilers handle
> '__counted_by' on pointers.
>
> Assisted-by: LLM
> Signed-off-by: Bill Wendling <morbo@google.com>
> ---
> include/linux/compiler_types.h | 15 +++++++++++++--
> 1 file changed, 13 insertions(+), 2 deletions(-)
>
> diff --git a/include/linux/compiler_types.h b/include/linux/compiler_types.h
> index c5921f139007..916a946f623c 100644
> --- a/include/linux/compiler_types.h
> +++ b/include/linux/compiler_types.h
> @@ -371,8 +371,14 @@ struct ftrace_likely_data {
> *
> * __bdos on clang < 19.1.3 can be off by 4:
> * https://github.com/llvm/llvm-project/pull/112636
> + *
> + * Code that runs outside the kernel proper (e.g. the EFI stub) can define
> + * __NO_COUNTED_BY to drop the annotation, since it gains nothing from the
> + * bounds checks. Kept in step with __NO_COUNTED_BY_PTR below so the two can
> + * be folded together once __counted_by covers pointers on all supported
> + * compilers.
> */
> -#ifdef CONFIG_CC_HAS_COUNTED_BY
> +#if defined(CONFIG_CC_HAS_COUNTED_BY) && !defined(__NO_COUNTED_BY)
> # define __counted_by(member) __attribute__((__counted_by__(member)))
> #else
> # define __counted_by(member)
> @@ -387,8 +393,13 @@ struct ftrace_likely_data {
> *
> * gcc: https://gcc.gnu.org/pipermail/gcc-patches/2025-April/681727.html
> * clang: https://clang.llvm.org/docs/AttributeReference.html#counted-by-counted-by-or-null-sized-by-sized-by-or-null
> + *
> + * Code that runs outside the kernel proper (e.g. the EFI stub) can define
> + * __NO_COUNTED_BY_PTR to drop the annotation, as with __NO_COUNTED_BY. Such
> + * code may also lack the flag Clang needs to parse a reference to a
> + * later-declared member (-fexperimental-late-parse-attributes).
> */
> -#ifdef CONFIG_CC_HAS_COUNTED_BY_PTR
> +#if defined(CONFIG_CC_HAS_COUNTED_BY_PTR) && !defined(__NO_COUNTED_BY_PTR)
> #define __counted_by_ptr(member) __attribute__((__counted_by__(member)))
> #else
> #define __counted_by_ptr(member)
> --
> 2.56.0.rc1.315.gc6ed9934b7-goog
>
Reviewed-by: Justin Stitt <justinstitt@google.com>
Thanks
Justin
^ permalink raw reply [flat|nested] 9+ messages in thread* Re: [PATCH] compiler_types: Allow opting out of __counted_by and __counted_by_ptr
2026-10-05 10:25 [PATCH] compiler_types: Allow opting out of __counted_by and __counted_by_ptr Bill Wendling
2026-10-05 10:44 ` Justin Stitt
@ 2026-10-05 10:53 ` Ard Biesheuvel
2026-10-05 15:52 ` Bill Wendling
2026-10-05 19:19 ` Bill Wendling
2026-10-05 19:20 ` [PATCH v3] " Bill Wendling
3 siblings, 1 reply; 9+ messages in thread
From: Ard Biesheuvel @ 2026-10-05 10:53 UTC (permalink / raw)
To: Bill Wendling, Kees Cook
Cc: Gustavo A. R. Silva, Nathan Chancellor, Nick Desaulniers,
Justin Stitt, Mark Brown, Marco Elver, alan.maguire, namjain,
Peter Zijlstra, linux-kernel, linux-hardening, llvm
Hi Bill,
On Mon, 5 Oct 2026, at 12:25, Bill Wendling wrote:
> Code that runs outside the kernel proper, such as the EFI stub, gets
> nothing out of the counted_by annotations: the bounds checks they feed
> (FORTIFY_SOURCE, UBSAN_BOUNDS) are already disabled there.
>
> The annotations can also break the build. A __counted_by_ptr() that
> names a member declared after the pointer needs Clang's
> '-fexperimental-late-parse-attributes', which the top-level Makefile
> adds to 'KBUILD_CFLAGS'. The x86 EFI stub builds its own cflags and does
> not get that flag, so it fails as soon as such a struct is pulled in
> through a common header.
>
> Overriding the macros from a Makefile doesn't work:
> 'compiler_types.h' is pulled in with '-include', which is processed
> after all -D/-U options, so it re-establishes the definitions. Follow
> the '__NO_FORTIFY' precedent instead: let a build define
> '__NO_COUNTED_BY' or '__NO_COUNTED_BY_PTR' to turn the corresponding
> annotation into a no-op. The two are kept separate but parallel so they
> can be folded together once all supported compilers handle
> '__counted_by' on pointers.
>
I'd prefer a single macro here - if there is ever a case where we need to
turn off one but not the other, we can revisit.
Otherwise, this looks good to me - thanks.
^ permalink raw reply [flat|nested] 9+ messages in thread
* Re: [PATCH] compiler_types: Allow opting out of __counted_by and __counted_by_ptr
2026-10-05 10:53 ` Ard Biesheuvel
@ 2026-10-05 15:52 ` Bill Wendling
0 siblings, 0 replies; 9+ messages in thread
From: Bill Wendling @ 2026-10-05 15:52 UTC (permalink / raw)
To: Ard Biesheuvel
Cc: Kees Cook, Gustavo A. R. Silva, Nathan Chancellor,
Nick Desaulniers, Justin Stitt, Mark Brown, Marco Elver,
alan.maguire, namjain, Peter Zijlstra, linux-kernel,
linux-hardening, llvm
On Mon, Oct 5, 2026 at 3:54 AM Ard Biesheuvel <ardb@kernel.org> wrote:
>
> Hi Bill,
>
> On Mon, 5 Oct 2026, at 12:25, Bill Wendling wrote:
> > Code that runs outside the kernel proper, such as the EFI stub, gets
> > nothing out of the counted_by annotations: the bounds checks they feed
> > (FORTIFY_SOURCE, UBSAN_BOUNDS) are already disabled there.
> >
> > The annotations can also break the build. A __counted_by_ptr() that
> > names a member declared after the pointer needs Clang's
> > '-fexperimental-late-parse-attributes', which the top-level Makefile
> > adds to 'KBUILD_CFLAGS'. The x86 EFI stub builds its own cflags and does
> > not get that flag, so it fails as soon as such a struct is pulled in
> > through a common header.
> >
> > Overriding the macros from a Makefile doesn't work:
> > 'compiler_types.h' is pulled in with '-include', which is processed
> > after all -D/-U options, so it re-establishes the definitions. Follow
> > the '__NO_FORTIFY' precedent instead: let a build define
> > '__NO_COUNTED_BY' or '__NO_COUNTED_BY_PTR' to turn the corresponding
> > annotation into a no-op. The two are kept separate but parallel so they
> > can be folded together once all supported compilers handle
> > '__counted_by' on pointers.
> >
>
> I'd prefer a single macro here - if there is ever a case where we need to
> turn off one but not the other, we can revisit.
>
> Otherwise, this looks good to me - thanks.
Hi Ard,
I wanted to do it this way because the two attributes rely upon
compiler versions, and this gives us more flexibility. Eventually,
there will be Only One(tm), once the minimal compiler version supports
both __counted_by and __counted_by_ptr.
But it's a small issue. I can resend with just the __NO_COUNTED_BY_PTR part.
-bw
^ permalink raw reply [flat|nested] 9+ messages in thread
* [PATCH] compiler_types: Allow opting out of __counted_by and __counted_by_ptr
2026-10-05 10:25 [PATCH] compiler_types: Allow opting out of __counted_by and __counted_by_ptr Bill Wendling
2026-10-05 10:44 ` Justin Stitt
2026-10-05 10:53 ` Ard Biesheuvel
@ 2026-10-05 19:19 ` Bill Wendling
2026-10-05 19:20 ` [PATCH v3] " Bill Wendling
3 siblings, 0 replies; 9+ messages in thread
From: Bill Wendling @ 2026-10-05 19:19 UTC (permalink / raw)
To: Kees Cook, ardb
Cc: gustavoars, nathan, ndesaulniers, justinstitt, broonie, elver,
alan.maguire, namjain, peterz, linux-kernel, linux-hardening,
llvm, Bill Wendling
Code that runs outside the kernel proper, such as the EFI stub, gets
nothing out of the counted_by annotations: the bounds checks they feed
(FORTIFY_SOURCE, UBSAN_BOUNDS) are already disabled there.
The annotations can also break the build. A __counted_by_ptr() that
names a member declared after the pointer needs Clang's
'-fexperimental-late-parse-attributes', which the top-level Makefile
adds to 'KBUILD_CFLAGS'. The x86 EFI stub builds its own cflags and does
not get that flag, so it fails as soon as such a struct is pulled in
through a common header.
Overriding the __counted_by_ptr macro from a Makefile doesn't work:
'compiler_types.h' is pulled in with '-include', which is processed
after all -D/-U options, so it re-establishes the definitions. Follow
the '__NO_FORTIFY' precedent instead: let a build define
'__NO_COUNTED_BY_PTR' to turn the corresponding annotation into a no-op.
Assisted-by: LLM
Signed-off-by: Bill Wendling <morbo@google.com>
---
v2: Only specify __NO_COUNTED_BY_PTR. Leave __NO_COUNTED_BY until we need it.
---
include/linux/compiler_types.h | 7 ++++++-
1 file changed, 6 insertions(+), 1 deletion(-)
diff --git a/include/linux/compiler_types.h b/include/linux/compiler_types.h
index c5921f139007..8bde6798b4ec 100644
--- a/include/linux/compiler_types.h
+++ b/include/linux/compiler_types.h
@@ -387,8 +387,13 @@ struct ftrace_likely_data {
*
* gcc: https://gcc.gnu.org/pipermail/gcc-patches/2025-April/681727.html
* clang: https://clang.llvm.org/docs/AttributeReference.html#counted-by-counted-by-or-null-sized-by-sized-by-or-null
+ *
+ * Code that runs outside the kernel proper (e.g. the EFI stub) can define
+ * __NO_COUNTED_BY_PTR to drop the annotation. Such code may also lack the flag
+ * Clang needs to parse a reference to a later-declared member
+ * (-fexperimental-late-parse-attributes).
*/
-#ifdef CONFIG_CC_HAS_COUNTED_BY_PTR
+#if defined(CONFIG_CC_HAS_COUNTED_BY_PTR) && !defined(__NO_COUNTED_BY_PTR)
#define __counted_by_ptr(member) __attribute__((__counted_by__(member)))
#else
#define __counted_by_ptr(member)
--
2.56.0.rc1.315.gc6ed9934b7-goog
^ permalink raw reply [flat|nested] 9+ messages in thread* [PATCH v3] compiler_types: Allow opting out of __counted_by and __counted_by_ptr
2026-10-05 10:25 [PATCH] compiler_types: Allow opting out of __counted_by and __counted_by_ptr Bill Wendling
` (2 preceding siblings ...)
2026-10-05 19:19 ` Bill Wendling
@ 2026-10-05 19:20 ` Bill Wendling
2026-10-05 21:25 ` Ard Biesheuvel
3 siblings, 1 reply; 9+ messages in thread
From: Bill Wendling @ 2026-10-05 19:20 UTC (permalink / raw)
To: Kees Cook, ardb
Cc: gustavoars, nathan, ndesaulniers, justinstitt, broonie, elver,
alan.maguire, namjain, peterz, linux-kernel, linux-hardening,
llvm, Bill Wendling
Code that runs outside the kernel proper, such as the EFI stub, gets
nothing out of the counted_by annotations: the bounds checks they feed
(FORTIFY_SOURCE, UBSAN_BOUNDS) are already disabled there.
The annotations can also break the build. A __counted_by_ptr() that
names a member declared after the pointer needs Clang's
'-fexperimental-late-parse-attributes', which the top-level Makefile
adds to 'KBUILD_CFLAGS'. The x86 EFI stub builds its own cflags and does
not get that flag, so it fails as soon as such a struct is pulled in
through a common header.
Overriding the __counted_by_ptr macro from a Makefile doesn't work:
'compiler_types.h' is pulled in with '-include', which is processed
after all -D/-U options, so it re-establishes the definitions. Follow
the '__NO_FORTIFY' precedent instead: let a build define
'__NO_COUNTED_BY_PTR' to turn the corresponding annotation into a no-op.
Assisted-by: LLM
Signed-off-by: Bill Wendling <morbo@google.com>
---
v2: Only specify __NO_COUNTED_BY_PTR. Leave __NO_COUNTED_BY until we need it.
v3: Add the version to the Subject line.
---
include/linux/compiler_types.h | 7 ++++++-
1 file changed, 6 insertions(+), 1 deletion(-)
diff --git a/include/linux/compiler_types.h b/include/linux/compiler_types.h
index c5921f139007..8bde6798b4ec 100644
--- a/include/linux/compiler_types.h
+++ b/include/linux/compiler_types.h
@@ -387,8 +387,13 @@ struct ftrace_likely_data {
*
* gcc: https://gcc.gnu.org/pipermail/gcc-patches/2025-April/681727.html
* clang: https://clang.llvm.org/docs/AttributeReference.html#counted-by-counted-by-or-null-sized-by-sized-by-or-null
+ *
+ * Code that runs outside the kernel proper (e.g. the EFI stub) can define
+ * __NO_COUNTED_BY_PTR to drop the annotation. Such code may also lack the flag
+ * Clang needs to parse a reference to a later-declared member
+ * (-fexperimental-late-parse-attributes).
*/
-#ifdef CONFIG_CC_HAS_COUNTED_BY_PTR
+#if defined(CONFIG_CC_HAS_COUNTED_BY_PTR) && !defined(__NO_COUNTED_BY_PTR)
#define __counted_by_ptr(member) __attribute__((__counted_by__(member)))
#else
#define __counted_by_ptr(member)
--
2.56.0.rc1.315.gc6ed9934b7-goog
^ permalink raw reply [flat|nested] 9+ messages in thread* Re: [PATCH v3] compiler_types: Allow opting out of __counted_by and __counted_by_ptr
2026-10-05 19:20 ` [PATCH v3] " Bill Wendling
@ 2026-10-05 21:25 ` Ard Biesheuvel
2026-10-06 7:30 ` Justin Stitt
0 siblings, 1 reply; 9+ messages in thread
From: Ard Biesheuvel @ 2026-10-05 21:25 UTC (permalink / raw)
To: Bill Wendling, Kees Cook
Cc: Gustavo A. R. Silva, Nathan Chancellor, Nick Desaulniers,
Justin Stitt, Mark Brown, Marco Elver, alan.maguire, namjain,
Peter Zijlstra, linux-kernel, linux-hardening, llvm
On Mon, 5 Oct 2026, at 21:20, Bill Wendling wrote:
> Code that runs outside the kernel proper, such as the EFI stub, gets
> nothing out of the counted_by annotations: the bounds checks they feed
> (FORTIFY_SOURCE, UBSAN_BOUNDS) are already disabled there.
>
> The annotations can also break the build. A __counted_by_ptr() that
> names a member declared after the pointer needs Clang's
> '-fexperimental-late-parse-attributes', which the top-level Makefile
> adds to 'KBUILD_CFLAGS'. The x86 EFI stub builds its own cflags and does
> not get that flag, so it fails as soon as such a struct is pulled in
> through a common header.
>
> Overriding the __counted_by_ptr macro from a Makefile doesn't work:
> 'compiler_types.h' is pulled in with '-include', which is processed
> after all -D/-U options, so it re-establishes the definitions. Follow
> the '__NO_FORTIFY' precedent instead: let a build define
> '__NO_COUNTED_BY_PTR' to turn the corresponding annotation into a no-op.
>
> Assisted-by: LLM
> Signed-off-by: Bill Wendling <morbo@google.com>
> ---
> v2: Only specify __NO_COUNTED_BY_PTR. Leave __NO_COUNTED_BY until we need it.
> v3: Add the version to the Subject line.
> ---
> include/linux/compiler_types.h | 7 ++++++-
> 1 file changed, 6 insertions(+), 1 deletion(-)
>
> diff --git a/include/linux/compiler_types.h
> b/include/linux/compiler_types.h
> index c5921f139007..8bde6798b4ec 100644
> --- a/include/linux/compiler_types.h
> +++ b/include/linux/compiler_types.h
> @@ -387,8 +387,13 @@ struct ftrace_likely_data {
> *
> * gcc:
> https://gcc.gnu.org/pipermail/gcc-patches/2025-April/681727.html
> * clang:
> https://clang.llvm.org/docs/AttributeReference.html#counted-by-counted-by-or-null-sized-by-sized-by-or-null
> + *
> + * Code that runs outside the kernel proper (e.g. the EFI stub) can
> define
> + * __NO_COUNTED_BY_PTR to drop the annotation. Such code may also lack
> the flag
> + * Clang needs to parse a reference to a later-declared member
> + * (-fexperimental-late-parse-attributes).
> */
> -#ifdef CONFIG_CC_HAS_COUNTED_BY_PTR
> +#if defined(CONFIG_CC_HAS_COUNTED_BY_PTR) &&
> !defined(__NO_COUNTED_BY_PTR)
> #define
> __counted_by_ptr(member) __attribute__((__counted_by__(member)))
> #else
> #define __counted_by_ptr(member)
Apologies, I may have been unclear.
What I would like to see here is something like
#ifndef __NO_COUNTED_BY
#define __counted_by(member) __attribute__((....))
#define __counted_by_ptr(member) __attribute__((....))
#else
#define __counted_by(member)
#define __counted_by_ptr(member)
#endif
^ permalink raw reply [flat|nested] 9+ messages in thread* Re: [PATCH v3] compiler_types: Allow opting out of __counted_by and __counted_by_ptr
2026-10-05 21:25 ` Ard Biesheuvel
@ 2026-10-06 7:30 ` Justin Stitt
2026-10-06 8:07 ` Ard Biesheuvel
0 siblings, 1 reply; 9+ messages in thread
From: Justin Stitt @ 2026-10-06 7:30 UTC (permalink / raw)
To: Ard Biesheuvel
Cc: Bill Wendling, Kees Cook, Gustavo A. R. Silva, Nathan Chancellor,
Nick Desaulniers, Mark Brown, Marco Elver, alan.maguire, namjain,
Peter Zijlstra, linux-kernel, linux-hardening, llvm
Hi,
On Mon, Oct 5, 2026 at 2:25 PM Ard Biesheuvel <ardb@kernel.org> wrote:
>
>
>
> On Mon, 5 Oct 2026, at 21:20, Bill Wendling wrote:
> > Code that runs outside the kernel proper, such as the EFI stub, gets
> > nothing out of the counted_by annotations: the bounds checks they feed
> > (FORTIFY_SOURCE, UBSAN_BOUNDS) are already disabled there.
> >
> > The annotations can also break the build. A __counted_by_ptr() that
> > names a member declared after the pointer needs Clang's
> > '-fexperimental-late-parse-attributes', which the top-level Makefile
> > adds to 'KBUILD_CFLAGS'. The x86 EFI stub builds its own cflags and does
> > not get that flag, so it fails as soon as such a struct is pulled in
> > through a common header.
> >
> > Overriding the __counted_by_ptr macro from a Makefile doesn't work:
> > 'compiler_types.h' is pulled in with '-include', which is processed
> > after all -D/-U options, so it re-establishes the definitions. Follow
> > the '__NO_FORTIFY' precedent instead: let a build define
> > '__NO_COUNTED_BY_PTR' to turn the corresponding annotation into a no-op.
> >
> > Assisted-by: LLM
> > Signed-off-by: Bill Wendling <morbo@google.com>
> > ---
> > v2: Only specify __NO_COUNTED_BY_PTR. Leave __NO_COUNTED_BY until we need it.
> > v3: Add the version to the Subject line.
> > ---
> > include/linux/compiler_types.h | 7 ++++++-
> > 1 file changed, 6 insertions(+), 1 deletion(-)
> >
> > diff --git a/include/linux/compiler_types.h
> > b/include/linux/compiler_types.h
> > index c5921f139007..8bde6798b4ec 100644
> > --- a/include/linux/compiler_types.h
> > +++ b/include/linux/compiler_types.h
> > @@ -387,8 +387,13 @@ struct ftrace_likely_data {
> > *
> > * gcc:
> > https://gcc.gnu.org/pipermail/gcc-patches/2025-April/681727.html
> > * clang:
> > https://clang.llvm.org/docs/AttributeReference.html#counted-by-counted-by-or-null-sized-by-sized-by-or-null
> > + *
> > + * Code that runs outside the kernel proper (e.g. the EFI stub) can
> > define
> > + * __NO_COUNTED_BY_PTR to drop the annotation. Such code may also lack
> > the flag
> > + * Clang needs to parse a reference to a later-declared member
> > + * (-fexperimental-late-parse-attributes).
> > */
> > -#ifdef CONFIG_CC_HAS_COUNTED_BY_PTR
> > +#if defined(CONFIG_CC_HAS_COUNTED_BY_PTR) &&
> > !defined(__NO_COUNTED_BY_PTR)
> > #define
> > __counted_by_ptr(member) __attribute__((__counted_by__(member)))
> > #else
> > #define __counted_by_ptr(member)
>
> Apologies, I may have been unclear.
>
> What I would like to see here is something like
>
> #ifndef __NO_COUNTED_BY
> #define __counted_by(member) __attribute__((....))
> #define __counted_by_ptr(member) __attribute__((....))
> #else
> #define __counted_by(member)
> #define __counted_by_ptr(member)
> #endif
FWIW, Bill's original patch had this explanation
"The two are kept separate but parallel so they
can be folded together once all supported compilers handle
'__counted_by' on pointers."
Justin
^ permalink raw reply [flat|nested] 9+ messages in thread* Re: [PATCH v3] compiler_types: Allow opting out of __counted_by and __counted_by_ptr
2026-10-06 7:30 ` Justin Stitt
@ 2026-10-06 8:07 ` Ard Biesheuvel
0 siblings, 0 replies; 9+ messages in thread
From: Ard Biesheuvel @ 2026-10-06 8:07 UTC (permalink / raw)
To: Justin Stitt
Cc: Bill Wendling, Kees Cook, Gustavo A. R. Silva, Nathan Chancellor,
Nick Desaulniers, Mark Brown, Marco Elver, alan.maguire, namjain,
Peter Zijlstra, linux-kernel, linux-hardening, llvm
On Tue, 6 Oct 2026, at 09:30, Justin Stitt wrote:
> Hi,
>
> On Mon, Oct 5, 2026 at 2:25 PM Ard Biesheuvel <ardb@kernel.org> wrote:
>>
>>
>>
>> On Mon, 5 Oct 2026, at 21:20, Bill Wendling wrote:
>> > Code that runs outside the kernel proper, such as the EFI stub, gets
>> > nothing out of the counted_by annotations: the bounds checks they feed
>> > (FORTIFY_SOURCE, UBSAN_BOUNDS) are already disabled there.
>> >
>> > The annotations can also break the build. A __counted_by_ptr() that
>> > names a member declared after the pointer needs Clang's
>> > '-fexperimental-late-parse-attributes', which the top-level Makefile
>> > adds to 'KBUILD_CFLAGS'. The x86 EFI stub builds its own cflags and does
>> > not get that flag, so it fails as soon as such a struct is pulled in
>> > through a common header.
>> >
>> > Overriding the __counted_by_ptr macro from a Makefile doesn't work:
>> > 'compiler_types.h' is pulled in with '-include', which is processed
>> > after all -D/-U options, so it re-establishes the definitions. Follow
>> > the '__NO_FORTIFY' precedent instead: let a build define
>> > '__NO_COUNTED_BY_PTR' to turn the corresponding annotation into a no-op.
>> >
>> > Assisted-by: LLM
>> > Signed-off-by: Bill Wendling <morbo@google.com>
>> > ---
>> > v2: Only specify __NO_COUNTED_BY_PTR. Leave __NO_COUNTED_BY until we need it.
>> > v3: Add the version to the Subject line.
>> > ---
>> > include/linux/compiler_types.h | 7 ++++++-
>> > 1 file changed, 6 insertions(+), 1 deletion(-)
>> >
>> > diff --git a/include/linux/compiler_types.h
>> > b/include/linux/compiler_types.h
>> > index c5921f139007..8bde6798b4ec 100644
>> > --- a/include/linux/compiler_types.h
>> > +++ b/include/linux/compiler_types.h
>> > @@ -387,8 +387,13 @@ struct ftrace_likely_data {
>> > *
>> > * gcc:
>> > https://gcc.gnu.org/pipermail/gcc-patches/2025-April/681727.html
>> > * clang:
>> > https://clang.llvm.org/docs/AttributeReference.html#counted-by-counted-by-or-null-sized-by-sized-by-or-null
>> > + *
>> > + * Code that runs outside the kernel proper (e.g. the EFI stub) can
>> > define
>> > + * __NO_COUNTED_BY_PTR to drop the annotation. Such code may also lack
>> > the flag
>> > + * Clang needs to parse a reference to a later-declared member
>> > + * (-fexperimental-late-parse-attributes).
>> > */
>> > -#ifdef CONFIG_CC_HAS_COUNTED_BY_PTR
>> > +#if defined(CONFIG_CC_HAS_COUNTED_BY_PTR) &&
>> > !defined(__NO_COUNTED_BY_PTR)
>> > #define
>> > __counted_by_ptr(member) __attribute__((__counted_by__(member)))
>> > #else
>> > #define __counted_by_ptr(member)
>>
>> Apologies, I may have been unclear.
>>
>> What I would like to see here is something like
>>
>> #ifndef __NO_COUNTED_BY
>> #define __counted_by(member) __attribute__((....))
>> #define __counted_by_ptr(member) __attribute__((....))
>> #else
>> #define __counted_by(member)
>> #define __counted_by_ptr(member)
>> #endif
>
> FWIW, Bill's original patch had this explanation
>
> "The two are kept separate but parallel so they
> can be folded together once all supported compilers handle
> '__counted_by' on pointers."
>
When opting out of this, whether or not the compiler supports
all variants of counted_by() is irrelevant. The same #define
should just opt out of all of them.
If the need arises to be more granular here, we can always add
that later but I don't want to have to add
-D__NO_COUNTED_BY -D__NO_COUNTED_BY_PTR
everywhere today, and go back and remove the second part once
all compilers have caught up.
^ permalink raw reply [flat|nested] 9+ messages in thread