From: "Arnd Bergmann" <arnd@arndb.de>
To: "Vincenzo Frascino" <vincenzo.frascino@arm.com>,
"Arnd Bergmann" <arnd@kernel.org>,
"Daniel Scally" <dan.scally@ideasonboard.com>,
"Jacopo Mondi" <jacopo.mondi@ideasonboard.com>,
"Hans Verkuil" <hverkuil+cisco@kernel.org>,
"Linus Walleij" <linusw@kernel.org>
Cc: linux-media@vger.kernel.org, linux-kernel@vger.kernel.org
Subject: Re: [PATCH] media: mali-c55: add padding to mali_c55_params_ccm structure
Date: Wed, 16 Sep 2026 20:55:12 +0200 [thread overview]
Message-ID: <3052a817-3188-47b2-a95d-ec26aaa0d24d@app.fastmail.com> (raw)
In-Reply-To: <335cf0a8-4c0e-4c07-8d81-c076ac73d329@arm.com>
On Wed, Sep 16, 2026, at 17:43, Vincenzo Frascino wrote:
>> diff --git a/include/uapi/linux/media/arm/mali-c55-config.h b/include/uapi/linux/media/arm/mali-c55-config.h
>> index 84d8f3901405..9c922290e035 100644
>> --- a/include/uapi/linux/media/arm/mali-c55-config.h
>> +++ b/include/uapi/linux/media/arm/mali-c55-config.h
>> @@ -804,6 +804,7 @@ struct mali_c55_params_ccm {
>> __u16 coeffs[3][3];
>> __u16 gains[3];
>> __u16 offs[3];
>> + __u16 __pad;
>
> Does this field need to be explicitly zeroed/validated anywhere the structure is
> populated? Turning implicit padding into a named member fixes the layout
> warning, but by itself does not seem to prevent leaking uninitialized data if
> this structure is ever copied from the kernel to userspace. It might also be
> worth documenting that __pad is reserved and must be zero.
It depends on how the structure is initialized. Depending on the compiler
version and optimization level, a local variable declared as
struct mali_c55_params_ccm v = {};
may end up with uninitialized stack data in unnamed padding, but if you
do a memset(), that should always be safe. If the fields are set individually,
then you also have to set the __pad field, but that's not how you do it here.
> I think you already checked that changing the explicit structure layout/size is
> safe for existing userspace :)
On all architectures other than m68k, the position of the struct members
and the struct size are unchanged by my patch. On m68k. there is no
implied padding at the end of this structure, so this is theoretically
an ABI change, but nobody has a mali device on m68k, so we know that it
is safe.
Arnd
next prev parent reply other threads:[~2026-09-16 18:55 UTC|newest]
Thread overview: 4+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-15 20:24 Arnd Bergmann
2026-09-16 15:43 ` Vincenzo Frascino
2026-09-16 18:55 ` Arnd Bergmann [this message]
2026-09-17 12:54 ` Vincenzo Frascino
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=3052a817-3188-47b2-a95d-ec26aaa0d24d@app.fastmail.com \
--to=arnd@arndb.de \
--cc=arnd@kernel.org \
--cc=dan.scally@ideasonboard.com \
--cc=hverkuil+cisco@kernel.org \
--cc=jacopo.mondi@ideasonboard.com \
--cc=linusw@kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-media@vger.kernel.org \
--cc=vincenzo.frascino@arm.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®