From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from omta38.uswest2.a.cloudfilter.net (omta38.uswest2.a.cloudfilter.net [35.89.44.37]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id E346145D5FF for ; Wed, 23 Sep 2026 08:02:27 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=35.89.44.37 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790150549; cv=none; b=qz0oM4ebTB1YT1EE4ssmiZO8wkE/XamJurXSa2claceRp8+3p3lKp5JEv7BftmaAdNGrurzmCEzSlUMG59VwgR2gFjgyNR2VtVKGdJTqFN67HL1VhtS4rxNNeozkPTyWiKhYDqD6WDxT691dq5hy1GPHBVyKAghzvLsJBaAVhB0= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790150549; c=relaxed/simple; bh=NjFFa+JHvwkzY8oVLiPbDgALrnp7a6rOqFillHQtSDk=; h=Message-ID:Date:MIME-Version:Subject:To:Cc:References:From: In-Reply-To:Content-Type; b=NterAPUOwsmKZqYjkMgamqwvy44xetxD65UX786dHXbSpKSFQHNfXk8FbdA3XdX8RjxNwWmqgf2V+dOsxeh+DDiGv2KsmYAqa1UtEmDRmFdikgmF2V4Kb9m1EC4aJ7UlEjXpyMtJNSCVqqCwxRQpyUUshJ/bEjcYh3/V8aD4sr8= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=embeddedor.com; spf=pass smtp.mailfrom=embeddedor.com; dkim=pass (2048-bit key) header.d=embeddedor.com header.i=@embeddedor.com header.b=kYyd7LHl; arc=none smtp.client-ip=35.89.44.37 Authentication-Results: smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=embeddedor.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=embeddedor.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=embeddedor.com header.i=@embeddedor.com header.b="kYyd7LHl" Received: from eig-obgw-6007b.ext.cloudfilter.net ([10.0.30.166]) by cmsmtp with ESMTPS id 9CZbxbttcv0nd9Hvtxo2dd; Wed, 23 Sep 2026 08:02:25 +0000 Received: from gator4166.hostgator.com ([108.167.190.91]) by cmsmtp with ESMTPS id 9HvsxYJmHMB9V9HvsxiKG5; Wed, 23 Sep 2026 08:02:24 +0000 X-Authority-Analysis: v=2.4 cv=d5D1yQjE c=1 sm=1 tr=0 ts=6ab38791 a=vY9Mjuda9oMEc2E4Cx1x2A==:117 a=vY9Mjuda9oMEc2E4Cx1x2A==:17 a=IkcTkHD0fZMA:10 a=VdqzKS8jKosA:10 a=7T7KSl7uo7wA:10 a=1XWaLZrsAAAA:8 a=fr3FARZsm93X7T_27y0A:9 a=QEXdDO2ut3YA:10 a=2aFnImwKRvkU0tJ3nQRT:22 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=embeddedor.com; s=default; h=Content-Transfer-Encoding:Content-Type: In-Reply-To:From:References:Cc:To:Subject:MIME-Version:Date:Message-ID:Sender :Reply-To:Content-ID:Content-Description:Resent-Date:Resent-From: Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:List-Id:List-Help: List-Unsubscribe:List-Unsubscribe-Post:List-Subscribe:List-Post:List-Owner: List-Archive; bh=23Gz0e2PpXnP7QWwvqhbo8Ydj4EwHwL4tYVA9bUXDic=; b=kYyd7LHl4Xou lhlH3DoiSfFZYrwHIwZmS3iYMpq4UY9DF/E0qic4FT0u/OacLA3Zc4R1q16tzCY5ompfugq1zWzmt xAXQ88saJdOmRUYwthnqE+APx0CHk94HdYFrw4CfBq3EkvOVtbP2xoDW5wZ7riAaOSxoodQcUjZ9S 0MCIHbgp7Mm7x2OyPxZKe842db8QdhksnRGWcf3FhIsQVug/thvvOIwCRZblzQL001mnlohAqlyFs sheXApKQp/f2zyy9TNU+eKkFl4OSoB6n72ybWGaq95nYept+RXv3JND59fKfjegBhmdsL7XORtHjc JccJmQPHJRUPNIg3KrwbOQ==; Received: from flh4-125-195-69-90.tky.mesh.ad.jp ([125.195.69.90]:56168 helo=[10.203.100.34]) by gator4166.hostgator.com with esmtpsa (TLS1.3) tls TLS_AES_128_GCM_SHA256 (Exim 4.100) (envelope-from ) id 1x9Hvq-0000000476T-3FYT; Wed, 23 Sep 2026 03:02:22 -0500 Message-ID: <204fb990-7b45-4ce1-8e6a-260538bfb678@embeddedor.com> Date: Wed, 23 Sep 2026 17:02:12 +0900 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 User-Agent: Mozilla Thunderbird Subject: Re: [PATCH] Drivers: hv: vmbus: annotate struct vmbus_gpadl with __counted_by_ptr To: Kees Cook Cc: Bill Wendling , "K. Y. Srinivasan" , Haiyang Zhang , Wei Liu , Dexuan Cui , Long Li , "Gustavo A. R. Silva" , Nathan Chancellor , Nick Desaulniers , Justin Stitt , linux-hyperv@vger.kernel.org, linux-kernel@vger.kernel.org, linux-hardening@vger.kernel.org, llvm@lists.linux.dev, codemender-patching+linux@google.com References: <20260923055320.2602534-1-morbo@google.com> <202609230021.7F6F2140@keescook> Content-Language: en-US From: "Gustavo A. R. Silva" In-Reply-To: <202609230021.7F6F2140@keescook> Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: 7bit X-AntiAbuse: This header was added to track abuse, please include it with any abuse report X-AntiAbuse: Primary Hostname - gator4166.hostgator.com X-AntiAbuse: Original Domain - vger.kernel.org X-AntiAbuse: Originator/Caller UID/GID - [47 12] / [47 12] X-AntiAbuse: Sender Address Domain - embeddedor.com X-BWhitelist: no X-Source-IP: 125.195.69.90 X-Source-L: No X-Exim-ID: 1x9Hvq-0000000476T-3FYT X-Source: X-Source-Args: X-Source-Dir: X-Source-Sender: flh4-125-195-69-90.tky.mesh.ad.jp ([10.203.100.34]) [125.195.69.90]:56168 X-Source-Auth: gustavo@embeddedor.com X-Email-Count: 4 X-Org: HG=hgshared;ORG=hostgator; X-Source-Cap: Z3V6aWRpbmU7Z3V6aWRpbmU7Z2F0b3I0MTY2Lmhvc3RnYXRvci5jb20= X-Local-Domain: yes X-CMAE-Envelope: MS4xfATXHM4SdcptOivByVsbnY740iRVnrtdY/8u/ar/VOXNQLvJZtIFJb1YIloSAE/1ZLlR5AAlyvcK0Z+TQS08J2kd1L4D/ikUX4FN2W9+tsgE9M38D6J0 QK2aX45deR070f8zq6kgVI3g7n31+uLqVYdU+0N9uPPw6qApWSuaK4GYNxfoY1oinkwB+gW5G6ihf2LK8CHJnYPo7Hm4NvjhDi4nuCBBuzwAfsqWKVDTtXqz On 9/23/26 16:23, Kees Cook wrote: > On Wed, Sep 23, 2026 at 03:10:08PM +0900, Gustavo A. R. Silva wrote: >> >> >> On 9/23/26 14:53, Bill Wendling wrote: >>> Add the "__counted_by_ptr" attribute to the buffer field of "struct >>> vmbus_gpadl". This allows compilers (GCC and Clang) to perform >>> compile-time and runtime bounds-checking when KASAN is enabled, preventing >>> potential out-of-bounds accesses to the GPADL buffer. >>> >>> The fields "buffer" and "size" of "struct vmbus_gpadl" are assigned >>> exactly once, during GPADL establishment inside >>> "__vmbus_establish_gpadl()" in "drivers/hv/channel.c". >>> >>> To ensure that the count field ("size") is initialized before the >>> pointer field ("buffer") is assigned, we reorder the assignments in >>> "__vmbus_establish_gpadl()" so that "gpadl->size" is written before >>> "gpadl->buffer". >>> >>> Cc: codemender-patching+linux@google.com >>> Assisted-by: LLM >>> Signed-off-by: Bill Wendling >>> --- >>> drivers/hv/channel.c | 2 +- >>> include/linux/hyperv.h | 2 +- >>> 2 files changed, 2 insertions(+), 2 deletions(-) >>> >>> diff --git a/drivers/hv/channel.c b/drivers/hv/channel.c >>> index 7e4cc6f55237..7042de2dd481 100644 >>> --- a/drivers/hv/channel.c >>> +++ b/drivers/hv/channel.c >>> @@ -548,8 +548,8 @@ static int __vmbus_establish_gpadl(struct vmbus_channel *channel, >>> /* At this point, we received the gpadl created msg */ >>> gpadl->gpadl_handle = gpadlmsg->gpadl; >>> - gpadl->buffer = kbuffer; >>> gpadl->size = size; >>> + gpadl->buffer = kbuffer; >> >> I think in some cases these subtle changes are worth a short but >> informative comment saying that the _counter_ must be initialized >> before the first reference to the pointer. > > But that's only for dereferencing it... there's no ordering requirement Ah yes, I got a bit carried away by the change itself. > here at all (and I think swapping order is needless churn). Neither > order is correct: only having them both set before dereferencing > "buffer" is required. Yes; maybe this is something the LLM should learn. Thanks -Gustavo