mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH] compiler_types: Allow opting out of __counted_by and __counted_by_ptr
@ 2026-10-05 10:25 Bill Wendling
  2026-10-05 10:44 ` Justin Stitt
                   ` (3 more replies)
  0 siblings, 4 replies; 7+ messages in thread
From: Bill Wendling @ 2026-10-05 10:25 UTC (permalink / raw)
  To: Kees Cook, ardb
  Cc: gustavoars, nathan, ndesaulniers, justinstitt, broonie, elver,
	alan.maguire, namjain, peterz, linux-kernel, linux-hardening,
	llvm, Bill Wendling

Code that runs outside the kernel proper, such as the EFI stub, gets
nothing out of the counted_by annotations: the bounds checks they feed
(FORTIFY_SOURCE, UBSAN_BOUNDS) are already disabled there.

The annotations can also break the build. A __counted_by_ptr() that
names a member declared after the pointer needs Clang's
'-fexperimental-late-parse-attributes', which the top-level Makefile
adds to 'KBUILD_CFLAGS'. The x86 EFI stub builds its own cflags and does
not get that flag, so it fails as soon as such a struct is pulled in
through a common header.

Overriding the macros from a Makefile doesn't work:
'compiler_types.h' is pulled in with '-include', which is processed
after all -D/-U options, so it re-establishes the definitions. Follow
the '__NO_FORTIFY' precedent instead: let a build define
'__NO_COUNTED_BY' or '__NO_COUNTED_BY_PTR' to turn the corresponding
annotation into a no-op.  The two are kept separate but parallel so they
can be folded together once all supported compilers handle
'__counted_by' on pointers.

Assisted-by: LLM
Signed-off-by: Bill Wendling <morbo@google.com>
---
 include/linux/compiler_types.h | 15 +++++++++++++--
 1 file changed, 13 insertions(+), 2 deletions(-)

diff --git a/include/linux/compiler_types.h b/include/linux/compiler_types.h
index c5921f139007..916a946f623c 100644
--- a/include/linux/compiler_types.h
+++ b/include/linux/compiler_types.h
@@ -371,8 +371,14 @@ struct ftrace_likely_data {
  *
  * __bdos on clang < 19.1.3 can be off by 4:
  * https://github.com/llvm/llvm-project/pull/112636
+ *
+ * Code that runs outside the kernel proper (e.g. the EFI stub) can define
+ * __NO_COUNTED_BY to drop the annotation, since it gains nothing from the
+ * bounds checks. Kept in step with __NO_COUNTED_BY_PTR below so the two can
+ * be folded together once __counted_by covers pointers on all supported
+ * compilers.
  */
-#ifdef CONFIG_CC_HAS_COUNTED_BY
+#if defined(CONFIG_CC_HAS_COUNTED_BY) && !defined(__NO_COUNTED_BY)
 # define __counted_by(member)		__attribute__((__counted_by__(member)))
 #else
 # define __counted_by(member)
@@ -387,8 +393,13 @@ struct ftrace_likely_data {
  *
  *   gcc: https://gcc.gnu.org/pipermail/gcc-patches/2025-April/681727.html
  * clang: https://clang.llvm.org/docs/AttributeReference.html#counted-by-counted-by-or-null-sized-by-sized-by-or-null
+ *
+ * Code that runs outside the kernel proper (e.g. the EFI stub) can define
+ * __NO_COUNTED_BY_PTR to drop the annotation, as with __NO_COUNTED_BY. Such
+ * code may also lack the flag Clang needs to parse a reference to a
+ * later-declared member (-fexperimental-late-parse-attributes).
  */
-#ifdef CONFIG_CC_HAS_COUNTED_BY_PTR
+#if defined(CONFIG_CC_HAS_COUNTED_BY_PTR) && !defined(__NO_COUNTED_BY_PTR)
 #define __counted_by_ptr(member)	__attribute__((__counted_by__(member)))
 #else
 #define __counted_by_ptr(member)
-- 
2.56.0.rc1.315.gc6ed9934b7-goog


^ permalink raw reply	[flat|nested] 7+ messages in thread

* Re: [PATCH] compiler_types: Allow opting out of __counted_by and __counted_by_ptr
  2026-10-05 10:25 [PATCH] compiler_types: Allow opting out of __counted_by and __counted_by_ptr Bill Wendling
@ 2026-10-05 10:44 ` Justin Stitt
  2026-10-05 10:53 ` Ard Biesheuvel
                   ` (2 subsequent siblings)
  3 siblings, 0 replies; 7+ messages in thread
From: Justin Stitt @ 2026-10-05 10:44 UTC (permalink / raw)
  To: Bill Wendling
  Cc: Kees Cook, ardb, gustavoars, nathan, ndesaulniers, broonie,
	elver, alan.maguire, namjain, peterz, linux-kernel,
	linux-hardening, llvm

Hi,

On Mon, Oct 05, 2026 at 10:25:18AM +0000, Bill Wendling wrote:
> Code that runs outside the kernel proper, such as the EFI stub, gets
> nothing out of the counted_by annotations: the bounds checks they feed
> (FORTIFY_SOURCE, UBSAN_BOUNDS) are already disabled there.
> 
> The annotations can also break the build. A __counted_by_ptr() that
> names a member declared after the pointer needs Clang's
> '-fexperimental-late-parse-attributes', which the top-level Makefile
> adds to 'KBUILD_CFLAGS'. The x86 EFI stub builds its own cflags and does
> not get that flag, so it fails as soon as such a struct is pulled in
> through a common header.
> 
> Overriding the macros from a Makefile doesn't work:
> 'compiler_types.h' is pulled in with '-include', which is processed
> after all -D/-U options, so it re-establishes the definitions. Follow
> the '__NO_FORTIFY' precedent instead: let a build define
> '__NO_COUNTED_BY' or '__NO_COUNTED_BY_PTR' to turn the corresponding
> annotation into a no-op.  The two are kept separate but parallel so they
> can be folded together once all supported compilers handle
> '__counted_by' on pointers.
> 
> Assisted-by: LLM
> Signed-off-by: Bill Wendling <morbo@google.com>
> ---
>  include/linux/compiler_types.h | 15 +++++++++++++--
>  1 file changed, 13 insertions(+), 2 deletions(-)
> 
> diff --git a/include/linux/compiler_types.h b/include/linux/compiler_types.h
> index c5921f139007..916a946f623c 100644
> --- a/include/linux/compiler_types.h
> +++ b/include/linux/compiler_types.h
> @@ -371,8 +371,14 @@ struct ftrace_likely_data {
>   *
>   * __bdos on clang < 19.1.3 can be off by 4:
>   * https://github.com/llvm/llvm-project/pull/112636
> + *
> + * Code that runs outside the kernel proper (e.g. the EFI stub) can define
> + * __NO_COUNTED_BY to drop the annotation, since it gains nothing from the
> + * bounds checks. Kept in step with __NO_COUNTED_BY_PTR below so the two can
> + * be folded together once __counted_by covers pointers on all supported
> + * compilers.
>   */
> -#ifdef CONFIG_CC_HAS_COUNTED_BY
> +#if defined(CONFIG_CC_HAS_COUNTED_BY) && !defined(__NO_COUNTED_BY)
>  # define __counted_by(member)		__attribute__((__counted_by__(member)))
>  #else
>  # define __counted_by(member)
> @@ -387,8 +393,13 @@ struct ftrace_likely_data {
>   *
>   *   gcc: https://gcc.gnu.org/pipermail/gcc-patches/2025-April/681727.html
>   * clang: https://clang.llvm.org/docs/AttributeReference.html#counted-by-counted-by-or-null-sized-by-sized-by-or-null
> + *
> + * Code that runs outside the kernel proper (e.g. the EFI stub) can define
> + * __NO_COUNTED_BY_PTR to drop the annotation, as with __NO_COUNTED_BY. Such
> + * code may also lack the flag Clang needs to parse a reference to a
> + * later-declared member (-fexperimental-late-parse-attributes).
>   */
> -#ifdef CONFIG_CC_HAS_COUNTED_BY_PTR
> +#if defined(CONFIG_CC_HAS_COUNTED_BY_PTR) && !defined(__NO_COUNTED_BY_PTR)
>  #define __counted_by_ptr(member)	__attribute__((__counted_by__(member)))
>  #else
>  #define __counted_by_ptr(member)
> -- 
> 2.56.0.rc1.315.gc6ed9934b7-goog
> 

Reviewed-by: Justin Stitt <justinstitt@google.com>

Thanks
Justin

^ permalink raw reply	[flat|nested] 7+ messages in thread

* Re: [PATCH] compiler_types: Allow opting out of __counted_by and __counted_by_ptr
  2026-10-05 10:25 [PATCH] compiler_types: Allow opting out of __counted_by and __counted_by_ptr Bill Wendling
  2026-10-05 10:44 ` Justin Stitt
@ 2026-10-05 10:53 ` Ard Biesheuvel
  2026-10-05 15:52   ` Bill Wendling
  2026-10-05 19:19 ` Bill Wendling
  2026-10-05 19:20 ` [PATCH v3] " Bill Wendling
  3 siblings, 1 reply; 7+ messages in thread
From: Ard Biesheuvel @ 2026-10-05 10:53 UTC (permalink / raw)
  To: Bill Wendling, Kees Cook
  Cc: Gustavo A. R. Silva, Nathan Chancellor, Nick Desaulniers,
	Justin Stitt, Mark Brown, Marco Elver, alan.maguire, namjain,
	Peter Zijlstra, linux-kernel, linux-hardening, llvm

Hi Bill,

On Mon, 5 Oct 2026, at 12:25, Bill Wendling wrote:
> Code that runs outside the kernel proper, such as the EFI stub, gets
> nothing out of the counted_by annotations: the bounds checks they feed
> (FORTIFY_SOURCE, UBSAN_BOUNDS) are already disabled there.
>
> The annotations can also break the build. A __counted_by_ptr() that
> names a member declared after the pointer needs Clang's
> '-fexperimental-late-parse-attributes', which the top-level Makefile
> adds to 'KBUILD_CFLAGS'. The x86 EFI stub builds its own cflags and does
> not get that flag, so it fails as soon as such a struct is pulled in
> through a common header.
>
> Overriding the macros from a Makefile doesn't work:
> 'compiler_types.h' is pulled in with '-include', which is processed
> after all -D/-U options, so it re-establishes the definitions. Follow
> the '__NO_FORTIFY' precedent instead: let a build define
> '__NO_COUNTED_BY' or '__NO_COUNTED_BY_PTR' to turn the corresponding
> annotation into a no-op.  The two are kept separate but parallel so they
> can be folded together once all supported compilers handle
> '__counted_by' on pointers.
>

I'd prefer a single macro here - if there is ever a case where we need to
turn off one but not the other, we can revisit.

Otherwise, this looks good to me - thanks.

^ permalink raw reply	[flat|nested] 7+ messages in thread

* Re: [PATCH] compiler_types: Allow opting out of __counted_by and __counted_by_ptr
  2026-10-05 10:53 ` Ard Biesheuvel
@ 2026-10-05 15:52   ` Bill Wendling
  0 siblings, 0 replies; 7+ messages in thread
From: Bill Wendling @ 2026-10-05 15:52 UTC (permalink / raw)
  To: Ard Biesheuvel
  Cc: Kees Cook, Gustavo A. R. Silva, Nathan Chancellor,
	Nick Desaulniers, Justin Stitt, Mark Brown, Marco Elver,
	alan.maguire, namjain, Peter Zijlstra, linux-kernel,
	linux-hardening, llvm

On Mon, Oct 5, 2026 at 3:54 AM Ard Biesheuvel <ardb@kernel.org> wrote:
>
> Hi Bill,
>
> On Mon, 5 Oct 2026, at 12:25, Bill Wendling wrote:
> > Code that runs outside the kernel proper, such as the EFI stub, gets
> > nothing out of the counted_by annotations: the bounds checks they feed
> > (FORTIFY_SOURCE, UBSAN_BOUNDS) are already disabled there.
> >
> > The annotations can also break the build. A __counted_by_ptr() that
> > names a member declared after the pointer needs Clang's
> > '-fexperimental-late-parse-attributes', which the top-level Makefile
> > adds to 'KBUILD_CFLAGS'. The x86 EFI stub builds its own cflags and does
> > not get that flag, so it fails as soon as such a struct is pulled in
> > through a common header.
> >
> > Overriding the macros from a Makefile doesn't work:
> > 'compiler_types.h' is pulled in with '-include', which is processed
> > after all -D/-U options, so it re-establishes the definitions. Follow
> > the '__NO_FORTIFY' precedent instead: let a build define
> > '__NO_COUNTED_BY' or '__NO_COUNTED_BY_PTR' to turn the corresponding
> > annotation into a no-op.  The two are kept separate but parallel so they
> > can be folded together once all supported compilers handle
> > '__counted_by' on pointers.
> >
>
> I'd prefer a single macro here - if there is ever a case where we need to
> turn off one but not the other, we can revisit.
>
> Otherwise, this looks good to me - thanks.

Hi Ard,

I wanted to do it this way because the two attributes rely upon
compiler versions, and this gives us more flexibility. Eventually,
there will be Only One(tm), once the minimal compiler version supports
both __counted_by and __counted_by_ptr.

But it's a small issue. I can resend with just the __NO_COUNTED_BY_PTR part.

-bw

^ permalink raw reply	[flat|nested] 7+ messages in thread

* [PATCH] compiler_types: Allow opting out of __counted_by and __counted_by_ptr
  2026-10-05 10:25 [PATCH] compiler_types: Allow opting out of __counted_by and __counted_by_ptr Bill Wendling
  2026-10-05 10:44 ` Justin Stitt
  2026-10-05 10:53 ` Ard Biesheuvel
@ 2026-10-05 19:19 ` Bill Wendling
  2026-10-05 19:20 ` [PATCH v3] " Bill Wendling
  3 siblings, 0 replies; 7+ messages in thread
From: Bill Wendling @ 2026-10-05 19:19 UTC (permalink / raw)
  To: Kees Cook, ardb
  Cc: gustavoars, nathan, ndesaulniers, justinstitt, broonie, elver,
	alan.maguire, namjain, peterz, linux-kernel, linux-hardening,
	llvm, Bill Wendling

Code that runs outside the kernel proper, such as the EFI stub, gets
nothing out of the counted_by annotations: the bounds checks they feed
(FORTIFY_SOURCE, UBSAN_BOUNDS) are already disabled there.

The annotations can also break the build. A __counted_by_ptr() that
names a member declared after the pointer needs Clang's
'-fexperimental-late-parse-attributes', which the top-level Makefile
adds to 'KBUILD_CFLAGS'. The x86 EFI stub builds its own cflags and does
not get that flag, so it fails as soon as such a struct is pulled in
through a common header.

Overriding the __counted_by_ptr macro from a Makefile doesn't work:
'compiler_types.h' is pulled in with '-include', which is processed
after all -D/-U options, so it re-establishes the definitions. Follow
the '__NO_FORTIFY' precedent instead: let a build define
'__NO_COUNTED_BY_PTR' to turn the corresponding annotation into a no-op.

Assisted-by: LLM
Signed-off-by: Bill Wendling <morbo@google.com>
---
v2: Only specify __NO_COUNTED_BY_PTR. Leave __NO_COUNTED_BY until we need it.
---
 include/linux/compiler_types.h | 7 ++++++-
 1 file changed, 6 insertions(+), 1 deletion(-)

diff --git a/include/linux/compiler_types.h b/include/linux/compiler_types.h
index c5921f139007..8bde6798b4ec 100644
--- a/include/linux/compiler_types.h
+++ b/include/linux/compiler_types.h
@@ -387,8 +387,13 @@ struct ftrace_likely_data {
  *
  *   gcc: https://gcc.gnu.org/pipermail/gcc-patches/2025-April/681727.html
  * clang: https://clang.llvm.org/docs/AttributeReference.html#counted-by-counted-by-or-null-sized-by-sized-by-or-null
+ *
+ * Code that runs outside the kernel proper (e.g. the EFI stub) can define
+ * __NO_COUNTED_BY_PTR to drop the annotation. Such code may also lack the flag
+ * Clang needs to parse a reference to a later-declared member
+ * (-fexperimental-late-parse-attributes).
  */
-#ifdef CONFIG_CC_HAS_COUNTED_BY_PTR
+#if defined(CONFIG_CC_HAS_COUNTED_BY_PTR) && !defined(__NO_COUNTED_BY_PTR)
 #define __counted_by_ptr(member)	__attribute__((__counted_by__(member)))
 #else
 #define __counted_by_ptr(member)
-- 
2.56.0.rc1.315.gc6ed9934b7-goog


^ permalink raw reply	[flat|nested] 7+ messages in thread

* [PATCH v3] compiler_types: Allow opting out of __counted_by and __counted_by_ptr
  2026-10-05 10:25 [PATCH] compiler_types: Allow opting out of __counted_by and __counted_by_ptr Bill Wendling
                   ` (2 preceding siblings ...)
  2026-10-05 19:19 ` Bill Wendling
@ 2026-10-05 19:20 ` Bill Wendling
  2026-10-05 21:25   ` Ard Biesheuvel
  3 siblings, 1 reply; 7+ messages in thread
From: Bill Wendling @ 2026-10-05 19:20 UTC (permalink / raw)
  To: Kees Cook, ardb
  Cc: gustavoars, nathan, ndesaulniers, justinstitt, broonie, elver,
	alan.maguire, namjain, peterz, linux-kernel, linux-hardening,
	llvm, Bill Wendling

Code that runs outside the kernel proper, such as the EFI stub, gets
nothing out of the counted_by annotations: the bounds checks they feed
(FORTIFY_SOURCE, UBSAN_BOUNDS) are already disabled there.

The annotations can also break the build. A __counted_by_ptr() that
names a member declared after the pointer needs Clang's
'-fexperimental-late-parse-attributes', which the top-level Makefile
adds to 'KBUILD_CFLAGS'. The x86 EFI stub builds its own cflags and does
not get that flag, so it fails as soon as such a struct is pulled in
through a common header.

Overriding the __counted_by_ptr macro from a Makefile doesn't work:
'compiler_types.h' is pulled in with '-include', which is processed
after all -D/-U options, so it re-establishes the definitions. Follow
the '__NO_FORTIFY' precedent instead: let a build define
'__NO_COUNTED_BY_PTR' to turn the corresponding annotation into a no-op.

Assisted-by: LLM
Signed-off-by: Bill Wendling <morbo@google.com>
---
v2: Only specify __NO_COUNTED_BY_PTR. Leave __NO_COUNTED_BY until we need it.
v3: Add the version to the Subject line.
---
 include/linux/compiler_types.h | 7 ++++++-
 1 file changed, 6 insertions(+), 1 deletion(-)

diff --git a/include/linux/compiler_types.h b/include/linux/compiler_types.h
index c5921f139007..8bde6798b4ec 100644
--- a/include/linux/compiler_types.h
+++ b/include/linux/compiler_types.h
@@ -387,8 +387,13 @@ struct ftrace_likely_data {
  *
  *   gcc: https://gcc.gnu.org/pipermail/gcc-patches/2025-April/681727.html
  * clang: https://clang.llvm.org/docs/AttributeReference.html#counted-by-counted-by-or-null-sized-by-sized-by-or-null
+ *
+ * Code that runs outside the kernel proper (e.g. the EFI stub) can define
+ * __NO_COUNTED_BY_PTR to drop the annotation. Such code may also lack the flag
+ * Clang needs to parse a reference to a later-declared member
+ * (-fexperimental-late-parse-attributes).
  */
-#ifdef CONFIG_CC_HAS_COUNTED_BY_PTR
+#if defined(CONFIG_CC_HAS_COUNTED_BY_PTR) && !defined(__NO_COUNTED_BY_PTR)
 #define __counted_by_ptr(member)	__attribute__((__counted_by__(member)))
 #else
 #define __counted_by_ptr(member)
-- 
2.56.0.rc1.315.gc6ed9934b7-goog


^ permalink raw reply	[flat|nested] 7+ messages in thread

* Re: [PATCH v3] compiler_types: Allow opting out of __counted_by and __counted_by_ptr
  2026-10-05 19:20 ` [PATCH v3] " Bill Wendling
@ 2026-10-05 21:25   ` Ard Biesheuvel
  0 siblings, 0 replies; 7+ messages in thread
From: Ard Biesheuvel @ 2026-10-05 21:25 UTC (permalink / raw)
  To: Bill Wendling, Kees Cook
  Cc: Gustavo A. R. Silva, Nathan Chancellor, Nick Desaulniers,
	Justin Stitt, Mark Brown, Marco Elver, alan.maguire, namjain,
	Peter Zijlstra, linux-kernel, linux-hardening, llvm



On Mon, 5 Oct 2026, at 21:20, Bill Wendling wrote:
> Code that runs outside the kernel proper, such as the EFI stub, gets
> nothing out of the counted_by annotations: the bounds checks they feed
> (FORTIFY_SOURCE, UBSAN_BOUNDS) are already disabled there.
>
> The annotations can also break the build. A __counted_by_ptr() that
> names a member declared after the pointer needs Clang's
> '-fexperimental-late-parse-attributes', which the top-level Makefile
> adds to 'KBUILD_CFLAGS'. The x86 EFI stub builds its own cflags and does
> not get that flag, so it fails as soon as such a struct is pulled in
> through a common header.
>
> Overriding the __counted_by_ptr macro from a Makefile doesn't work:
> 'compiler_types.h' is pulled in with '-include', which is processed
> after all -D/-U options, so it re-establishes the definitions. Follow
> the '__NO_FORTIFY' precedent instead: let a build define
> '__NO_COUNTED_BY_PTR' to turn the corresponding annotation into a no-op.
>
> Assisted-by: LLM
> Signed-off-by: Bill Wendling <morbo@google.com>
> ---
> v2: Only specify __NO_COUNTED_BY_PTR. Leave __NO_COUNTED_BY until we need it.
> v3: Add the version to the Subject line.
> ---
>  include/linux/compiler_types.h | 7 ++++++-
>  1 file changed, 6 insertions(+), 1 deletion(-)
>
> diff --git a/include/linux/compiler_types.h 
> b/include/linux/compiler_types.h
> index c5921f139007..8bde6798b4ec 100644
> --- a/include/linux/compiler_types.h
> +++ b/include/linux/compiler_types.h
> @@ -387,8 +387,13 @@ struct ftrace_likely_data {
>   *
>   *   gcc: 
> https://gcc.gnu.org/pipermail/gcc-patches/2025-April/681727.html
>   * clang: 
> https://clang.llvm.org/docs/AttributeReference.html#counted-by-counted-by-or-null-sized-by-sized-by-or-null
> + *
> + * Code that runs outside the kernel proper (e.g. the EFI stub) can 
> define
> + * __NO_COUNTED_BY_PTR to drop the annotation. Such code may also lack 
> the flag
> + * Clang needs to parse a reference to a later-declared member
> + * (-fexperimental-late-parse-attributes).
>   */
> -#ifdef CONFIG_CC_HAS_COUNTED_BY_PTR
> +#if defined(CONFIG_CC_HAS_COUNTED_BY_PTR) && 
> !defined(__NO_COUNTED_BY_PTR)
>  #define 
> __counted_by_ptr(member)	__attribute__((__counted_by__(member)))
>  #else
>  #define __counted_by_ptr(member)

Apologies, I may have been unclear.

What I would like to see here is something like

#ifndef __NO_COUNTED_BY
#define __counted_by(member)  __attribute__((....))
#define __counted_by_ptr(member)  __attribute__((....))
#else
#define __counted_by(member)
#define __counted_by_ptr(member)
#endif

^ permalink raw reply	[flat|nested] 7+ messages in thread

end of thread, other threads:[~2026-10-05 21:25 UTC | newest]

Thread overview: 7+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-10-05 10:25 [PATCH] compiler_types: Allow opting out of __counted_by and __counted_by_ptr Bill Wendling
2026-10-05 10:44 ` Justin Stitt
2026-10-05 10:53 ` Ard Biesheuvel
2026-10-05 15:52   ` Bill Wendling
2026-10-05 19:19 ` Bill Wendling
2026-10-05 19:20 ` [PATCH v3] " Bill Wendling
2026-10-05 21:25   ` Ard Biesheuvel

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®