mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH] gpiolib: annotate struct acpi_gpio_mapping with __counted_by_ptr
@ 2026-09-28  6:38 Bill Wendling
  2026-09-28  7:22 ` Bill Wendling
  2026-10-02 12:42 ` [PATCH v2] " Bill Wendling
  0 siblings, 2 replies; 9+ messages in thread
From: Bill Wendling @ 2026-09-28  6:38 UTC (permalink / raw)
  To: Linus Walleij, Bartosz Golaszewski
  Cc: Kees Cook, Gustavo A. R. Silva, linux-gpio, linux-kernel,
	linux-hardening, Bill Wendling, codemender-patching+linux

The 'data' pointer field in 'struct acpi_gpio_mapping' is associated
with the 'size' field, which represents the number of elements of
type 'struct acpi_gpio_params' allocated for 'data'.

To improve bounds checking via CONFIG_UBSAN_BOUNDS and
CONFIG_FORTIFY_SOURCE, annotate 'data' with the __counted_by_ptr
attribute.

Analysis of allocation, assignment, and access points shows that the
pointer is never accessed before the count is set, which guarantees that
this annotation is safe and will not cause runtime panics or
false-positive bounds checks.

Cc: codemender-patching+linux@google.com
Assisted-by: LLM
Signed-off-by: Bill Wendling <morbo@google.com>
---
 include/linux/gpio/consumer.h | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/include/linux/gpio/consumer.h b/include/linux/gpio/consumer.h
index fceeefd5f893..2b80cf7aa7e7 100644
--- a/include/linux/gpio/consumer.h
+++ b/include/linux/gpio/consumer.h
@@ -667,7 +667,7 @@ struct acpi_gpio_params {
 
 struct acpi_gpio_mapping {
 	const char *name;
-	const struct acpi_gpio_params *data;
+	const struct acpi_gpio_params *data __counted_by_ptr(size);
 	unsigned int size;
 
 /* Ignore IoRestriction field */
-- 
2.56.0.rc1.315.gc6ed9934b7-goog


^ permalink raw reply	[flat|nested] 9+ messages in thread

* Re: [PATCH] gpiolib: annotate struct acpi_gpio_mapping with __counted_by_ptr
  2026-09-28  6:38 [PATCH] gpiolib: annotate struct acpi_gpio_mapping with __counted_by_ptr Bill Wendling
@ 2026-09-28  7:22 ` Bill Wendling
  2026-10-01 19:56   ` Linus Walleij
  2026-10-02 12:42 ` [PATCH v2] " Bill Wendling
  1 sibling, 1 reply; 9+ messages in thread
From: Bill Wendling @ 2026-09-28  7:22 UTC (permalink / raw)
  To: Linus Walleij, Bartosz Golaszewski
  Cc: Kees Cook, Gustavo A. R. Silva, linux-gpio, linux-kernel,
	linux-hardening, codemender-patching+linux

On Sun, Sep 27, 2026 at 11:38 PM Bill Wendling <morbo@google.com> wrote:
>
> The 'data' pointer field in 'struct acpi_gpio_mapping' is associated
> with the 'size' field, which represents the number of elements of
> type 'struct acpi_gpio_params' allocated for 'data'.
>
> To improve bounds checking via CONFIG_UBSAN_BOUNDS and
> CONFIG_FORTIFY_SOURCE, annotate 'data' with the __counted_by_ptr
> attribute.
>
> Analysis of allocation, assignment, and access points shows that the
> pointer is never accessed before the count is set, which guarantees that
> this annotation is safe and will not cause runtime panics or
> false-positive bounds checks.
>
> Cc: codemender-patching+linux@google.com
> Assisted-by: LLM
> Signed-off-by: Bill Wendling <morbo@google.com>
> ---
>  include/linux/gpio/consumer.h | 2 +-
>  1 file changed, 1 insertion(+), 1 deletion(-)
>
> diff --git a/include/linux/gpio/consumer.h b/include/linux/gpio/consumer.h
> index fceeefd5f893..2b80cf7aa7e7 100644
> --- a/include/linux/gpio/consumer.h
> +++ b/include/linux/gpio/consumer.h
> @@ -667,7 +667,7 @@ struct acpi_gpio_params {
>
>  struct acpi_gpio_mapping {
>         const char *name;
> -       const struct acpi_gpio_params *data;
> +       const struct acpi_gpio_params *data __counted_by_ptr(size);
>         unsigned int size;
>
>  /* Ignore IoRestriction field */

There's a problem with 'drivers/firmware/efi/libstub/Makefile'. Clang
needs a compiler flag to support the "__counted_by_ptr" attribute
referencing a field *after* the pointer, like in this patch. However,
the Makefile blasts the flag away for x86 platforms. Below is a hack
that copies the part of the top-level Makefile that adds the flag. I
don't think that's a good solution. The comment in the driver's
Makefile says that the stub code executes before the kernel does,
which I assume is why a lot of the flags are blown away... In any
event, I'm not sure how best to address this.

-bw

diff --git a/drivers/firmware/efi/libstub/Makefile
b/drivers/firmware/efi/libstub/Makefile
index 77a2b2d74f3f..945674048d8f 100644
--- a/drivers/firmware/efi/libstub/Makefile
+++ b/drivers/firmware/efi/libstub/Makefile
@@ -19,6 +19,14 @@ cflags-$(CONFIG_X86)         += -m$(BITS)
-D__KERNEL__ $(CC_FLAGS_DIALECT) \
                                   -fno-asynchronous-unwind-tables \
                                   $(CLANG_FLAGS)

+ifeq ($(CONFIG_X86_32)$(CONFIG_X86_64),y)
+ifdef CONFIG_CC_IS_CLANG
+ifdef CONFIG_CC_HAS_COUNTED_BY_PTR
+cflags-y                       += -fexperimental-late-parse-attributes
+endif
+endif
+endif
+
 # arm64 uses the full KBUILD_CFLAGS so it's necessary to explicitly
 # disable the stackleak plugin
 cflags-$(CONFIG_ARM64)         += -fpie $(DISABLE_KSTACK_ERASE) \

^ permalink raw reply	[flat|nested] 9+ messages in thread

* Re: [PATCH] gpiolib: annotate struct acpi_gpio_mapping with __counted_by_ptr
  2026-09-28  7:22 ` Bill Wendling
@ 2026-10-01 19:56   ` Linus Walleij
  2026-10-01 20:04     ` Bill Wendling
  0 siblings, 1 reply; 9+ messages in thread
From: Linus Walleij @ 2026-10-01 19:56 UTC (permalink / raw)
  To: Bill Wendling
  Cc: Bartosz Golaszewski, Kees Cook, Gustavo A. R. Silva, linux-gpio,
	linux-kernel, linux-hardening, codemender-patching+linux

On Mon, Sep 28, 2026 at 9:22 AM Bill Wendling <morbo@google.com> wrote:
> On Sun, Sep 27, 2026 at 11:38 PM Bill Wendling <morbo@google.com> wrote:
> >
> > The 'data' pointer field in 'struct acpi_gpio_mapping' is associated
> > with the 'size' field, which represents the number of elements of
> > type 'struct acpi_gpio_params' allocated for 'data'.
> >
> > To improve bounds checking via CONFIG_UBSAN_BOUNDS and
> > CONFIG_FORTIFY_SOURCE, annotate 'data' with the __counted_by_ptr
> > attribute.
> >
> > Analysis of allocation, assignment, and access points shows that the
> > pointer is never accessed before the count is set, which guarantees that
> > this annotation is safe and will not cause runtime panics or
> > false-positive bounds checks.
> >
> > Cc: codemender-patching+linux@google.com
> > Assisted-by: LLM
> > Signed-off-by: Bill Wendling <morbo@google.com>
> > ---
> >  include/linux/gpio/consumer.h | 2 +-
> >  1 file changed, 1 insertion(+), 1 deletion(-)
> >
> > diff --git a/include/linux/gpio/consumer.h b/include/linux/gpio/consumer.h
> > index fceeefd5f893..2b80cf7aa7e7 100644
> > --- a/include/linux/gpio/consumer.h
> > +++ b/include/linux/gpio/consumer.h
> > @@ -667,7 +667,7 @@ struct acpi_gpio_params {
> >
> >  struct acpi_gpio_mapping {
> >         const char *name;
> > -       const struct acpi_gpio_params *data;
> > +       const struct acpi_gpio_params *data __counted_by_ptr(size);
> >         unsigned int size;
> >
> >  /* Ignore IoRestriction field */
>
> There's a problem with 'drivers/firmware/efi/libstub/Makefile'. Clang
> needs a compiler flag to support the "__counted_by_ptr" attribute
> referencing a field *after* the pointer, like in this patch. However,
> the Makefile blasts the flag away for x86 platforms. Below is a hack
> that copies the part of the top-level Makefile that adds the flag. I
> don't think that's a good solution. The comment in the driver's
> Makefile says that the stub code executes before the kernel does,
> which I assume is why a lot of the flags are blown away... In any
> event, I'm not sure how best to address this.

But is this a problem with the current patch?

Does libefistub use <linux/gpio/consumer.h> in any way, shape
or form?

Yours,
Linus Walleij

^ permalink raw reply	[flat|nested] 9+ messages in thread

* Re: [PATCH] gpiolib: annotate struct acpi_gpio_mapping with __counted_by_ptr
  2026-10-01 19:56   ` Linus Walleij
@ 2026-10-01 20:04     ` Bill Wendling
  2026-10-01 21:24       ` Linus Walleij
  0 siblings, 1 reply; 9+ messages in thread
From: Bill Wendling @ 2026-10-01 20:04 UTC (permalink / raw)
  To: Linus Walleij
  Cc: Bartosz Golaszewski, Kees Cook, Gustavo A. R. Silva, linux-gpio,
	linux-kernel, linux-hardening, codemender-patching+linux

On Thu, Oct 1, 2026 at 12:56 PM Linus Walleij <linusw@kernel.org> wrote:
> On Mon, Sep 28, 2026 at 9:22 AM Bill Wendling <morbo@google.com> wrote:
> > On Sun, Sep 27, 2026 at 11:38 PM Bill Wendling <morbo@google.com> wrote:
> > >
> > > The 'data' pointer field in 'struct acpi_gpio_mapping' is associated
> > > with the 'size' field, which represents the number of elements of
> > > type 'struct acpi_gpio_params' allocated for 'data'.
> > >
> > > To improve bounds checking via CONFIG_UBSAN_BOUNDS and
> > > CONFIG_FORTIFY_SOURCE, annotate 'data' with the __counted_by_ptr
> > > attribute.
> > >
> > > Analysis of allocation, assignment, and access points shows that the
> > > pointer is never accessed before the count is set, which guarantees that
> > > this annotation is safe and will not cause runtime panics or
> > > false-positive bounds checks.
> > >
> > > Cc: codemender-patching+linux@google.com
> > > Assisted-by: LLM
> > > Signed-off-by: Bill Wendling <morbo@google.com>
> > > ---
> > >  include/linux/gpio/consumer.h | 2 +-
> > >  1 file changed, 1 insertion(+), 1 deletion(-)
> > >
> > > diff --git a/include/linux/gpio/consumer.h b/include/linux/gpio/consumer.h
> > > index fceeefd5f893..2b80cf7aa7e7 100644
> > > --- a/include/linux/gpio/consumer.h
> > > +++ b/include/linux/gpio/consumer.h
> > > @@ -667,7 +667,7 @@ struct acpi_gpio_params {
> > >
> > >  struct acpi_gpio_mapping {
> > >         const char *name;
> > > -       const struct acpi_gpio_params *data;
> > > +       const struct acpi_gpio_params *data __counted_by_ptr(size);
> > >         unsigned int size;
> > >
> > >  /* Ignore IoRestriction field */
> >
> > There's a problem with 'drivers/firmware/efi/libstub/Makefile'. Clang
> > needs a compiler flag to support the "__counted_by_ptr" attribute
> > referencing a field *after* the pointer, like in this patch. However,
> > the Makefile blasts the flag away for x86 platforms. Below is a hack
> > that copies the part of the top-level Makefile that adds the flag. I
> > don't think that's a good solution. The comment in the driver's
> > Makefile says that the stub code executes before the kernel does,
> > which I assume is why a lot of the flags are blown away... In any
> > event, I'm not sure how best to address this.
>
> But is this a problem with the current patch?
>
> Does libefistub use <linux/gpio/consumer.h> in any way, shape
> or form?
>
It's being #included transitively:

In file included from drivers/firmware/efi/libstub/efi-stub-helper.c:12:
In file included from ./include/linux/efi.h:20:
In file included from ./include/linux/rtc.h:18:
In file included from ./include/linux/nvmem-provider.h:16:
./include/linux/gpio/consumer.h:670:55: error: use of undeclared
identifier 'size'; did you
      mean 'ksize'?
  670 |         const struct acpi_gpio_params *data __counted_by_ptr(size);
      |                                                              ^~~~
      |                                                              ksize
././include/linux/compiler_types.h:392:64: note: expanded from macro
'__counted_by_ptr'
  392 | #define __counted_by_ptr(member)
__attribute__((__counted_by__(member)))
      |
       ^~~~~~
./include/linux/slab.h:602:8: note: 'ksize' declared here
  602 | size_t ksize(const void *objp);
      |        ^

> Yours,
> Linus Walleij

^ permalink raw reply	[flat|nested] 9+ messages in thread

* Re: [PATCH] gpiolib: annotate struct acpi_gpio_mapping with __counted_by_ptr
  2026-10-01 20:04     ` Bill Wendling
@ 2026-10-01 21:24       ` Linus Walleij
  2026-10-02  7:38         ` Ard Biesheuvel
  0 siblings, 1 reply; 9+ messages in thread
From: Linus Walleij @ 2026-10-01 21:24 UTC (permalink / raw)
  To: Bill Wendling, Ard Biesheuvel, Jeremy Kerr
  Cc: Bartosz Golaszewski, Kees Cook, Gustavo A. R. Silva, linux-gpio,
	linux-kernel, linux-hardening, codemender-patching+linux

On Thu, Oct 1, 2026 at 10:05 PM Bill Wendling <morbo@google.com> wrote:
> On Thu, Oct 1, 2026 at 12:56 PM Linus Walleij <linusw@kernel.org> wrote:
> > On Mon, Sep 28, 2026 at 9:22 AM Bill Wendling <morbo@google.com> wrote:
> > > On Sun, Sep 27, 2026 at 11:38 PM Bill Wendling <morbo@google.com> wrote:
> > > >
> > > > The 'data' pointer field in 'struct acpi_gpio_mapping' is associated
> > > > with the 'size' field, which represents the number of elements of
> > > > type 'struct acpi_gpio_params' allocated for 'data'.
> > > >
> > > > To improve bounds checking via CONFIG_UBSAN_BOUNDS and
> > > > CONFIG_FORTIFY_SOURCE, annotate 'data' with the __counted_by_ptr
> > > > attribute.
> > > >
> > > > Analysis of allocation, assignment, and access points shows that the
> > > > pointer is never accessed before the count is set, which guarantees that
> > > > this annotation is safe and will not cause runtime panics or
> > > > false-positive bounds checks.
> > > >
> > > > Cc: codemender-patching+linux@google.com
> > > > Assisted-by: LLM
> > > > Signed-off-by: Bill Wendling <morbo@google.com>
> > > > ---
> > > >  include/linux/gpio/consumer.h | 2 +-
> > > >  1 file changed, 1 insertion(+), 1 deletion(-)
> > > >
> > > > diff --git a/include/linux/gpio/consumer.h b/include/linux/gpio/consumer.h
> > > > index fceeefd5f893..2b80cf7aa7e7 100644
> > > > --- a/include/linux/gpio/consumer.h
> > > > +++ b/include/linux/gpio/consumer.h
> > > > @@ -667,7 +667,7 @@ struct acpi_gpio_params {
> > > >
> > > >  struct acpi_gpio_mapping {
> > > >         const char *name;
> > > > -       const struct acpi_gpio_params *data;
> > > > +       const struct acpi_gpio_params *data __counted_by_ptr(size);
> > > >         unsigned int size;
> > > >
> > > >  /* Ignore IoRestriction field */
> > >
> > > There's a problem with 'drivers/firmware/efi/libstub/Makefile'. Clang
> > > needs a compiler flag to support the "__counted_by_ptr" attribute
> > > referencing a field *after* the pointer, like in this patch. However,
> > > the Makefile blasts the flag away for x86 platforms. Below is a hack
> > > that copies the part of the top-level Makefile that adds the flag. I
> > > don't think that's a good solution. The comment in the driver's
> > > Makefile says that the stub code executes before the kernel does,
> > > which I assume is why a lot of the flags are blown away... In any
> > > event, I'm not sure how best to address this.
> >
> > But is this a problem with the current patch?
> >
> > Does libefistub use <linux/gpio/consumer.h> in any way, shape
> > or form?
> >
> It's being #included transitively:
>
> In file included from drivers/firmware/efi/libstub/efi-stub-helper.c:12:
> In file included from ./include/linux/efi.h:20:
> In file included from ./include/linux/rtc.h:18:
> In file included from ./include/linux/nvmem-provider.h:16:
> ./include/linux/gpio/consumer.h:670:55: error: use of undeclared
> identifier 'size'; did you
>       mean 'ksize'?
>   670 |         const struct acpi_gpio_params *data __counted_by_ptr(size);
>       |                                                              ^~~~
>       |                                                              ksize
> ././include/linux/compiler_types.h:392:64: note: expanded from macro
> '__counted_by_ptr'
>   392 | #define __counted_by_ptr(member)
> __attribute__((__counted_by__(member)))
>       |
>        ^~~~~~
> ./include/linux/slab.h:602:8: note: 'ksize' declared here
>   602 | size_t ksize(const void *objp);
>       |        ^

Hm I see.

Certainly Jeremy or Ard will have an idea about how to solve this,
so paging them in.

Yours,
Linus Walleij

^ permalink raw reply	[flat|nested] 9+ messages in thread

* Re: [PATCH] gpiolib: annotate struct acpi_gpio_mapping with __counted_by_ptr
  2026-10-01 21:24       ` Linus Walleij
@ 2026-10-02  7:38         ` Ard Biesheuvel
  2026-10-02 12:44           ` Bill Wendling
  0 siblings, 1 reply; 9+ messages in thread
From: Ard Biesheuvel @ 2026-10-02  7:38 UTC (permalink / raw)
  To: Linus Walleij, Bill Wendling, Jeremy Kerr
  Cc: Bartosz Golaszewski, Kees Cook, Gustavo A. R. Silva, linux-gpio,
	linux-kernel, linux-hardening, codemender-patching+linux


On Thu, 1 Oct 2026, at 23:24, Linus Walleij wrote:
> On Thu, Oct 1, 2026 at 10:05 PM Bill Wendling <morbo@google.com> wrote:
>> On Thu, Oct 1, 2026 at 12:56 PM Linus Walleij <linusw@kernel.org> wrote:
>> > On Mon, Sep 28, 2026 at 9:22 AM Bill Wendling <morbo@google.com> wrote:
>> > > On Sun, Sep 27, 2026 at 11:38 PM Bill Wendling <morbo@google.com> wrote:
>> > > >
>> > > > The 'data' pointer field in 'struct acpi_gpio_mapping' is associated
>> > > > with the 'size' field, which represents the number of elements of
>> > > > type 'struct acpi_gpio_params' allocated for 'data'.
>> > > >
>> > > > To improve bounds checking via CONFIG_UBSAN_BOUNDS and
>> > > > CONFIG_FORTIFY_SOURCE, annotate 'data' with the __counted_by_ptr
>> > > > attribute.
>> > > >
>> > > > Analysis of allocation, assignment, and access points shows that the
>> > > > pointer is never accessed before the count is set, which guarantees that
>> > > > this annotation is safe and will not cause runtime panics or
>> > > > false-positive bounds checks.
>> > > >
>> > > > Cc: codemender-patching+linux@google.com
>> > > > Assisted-by: LLM
>> > > > Signed-off-by: Bill Wendling <morbo@google.com>
>> > > > ---
>> > > >  include/linux/gpio/consumer.h | 2 +-
>> > > >  1 file changed, 1 insertion(+), 1 deletion(-)
>> > > >
>> > > > diff --git a/include/linux/gpio/consumer.h b/include/linux/gpio/consumer.h
>> > > > index fceeefd5f893..2b80cf7aa7e7 100644
>> > > > --- a/include/linux/gpio/consumer.h
>> > > > +++ b/include/linux/gpio/consumer.h
>> > > > @@ -667,7 +667,7 @@ struct acpi_gpio_params {
>> > > >
>> > > >  struct acpi_gpio_mapping {
>> > > >         const char *name;
>> > > > -       const struct acpi_gpio_params *data;
>> > > > +       const struct acpi_gpio_params *data __counted_by_ptr(size);
>> > > >         unsigned int size;
>> > > >
>> > > >  /* Ignore IoRestriction field */
>> > >
>> > > There's a problem with 'drivers/firmware/efi/libstub/Makefile'. Clang
>> > > needs a compiler flag to support the "__counted_by_ptr" attribute
>> > > referencing a field *after* the pointer, like in this patch. However,
>> > > the Makefile blasts the flag away for x86 platforms. Below is a hack
>> > > that copies the part of the top-level Makefile that adds the flag. I
>> > > don't think that's a good solution. The comment in the driver's
>> > > Makefile says that the stub code executes before the kernel does,
>> > > which I assume is why a lot of the flags are blown away... In any
>> > > event, I'm not sure how best to address this.
>> >
>> > But is this a problem with the current patch?
>> >
>> > Does libefistub use <linux/gpio/consumer.h> in any way, shape
>> > or form?
>> >
>> It's being #included transitively:
>>
>> In file included from drivers/firmware/efi/libstub/efi-stub-helper.c:12:
>> In file included from ./include/linux/efi.h:20:
>> In file included from ./include/linux/rtc.h:18:
>> In file included from ./include/linux/nvmem-provider.h:16:
>> ./include/linux/gpio/consumer.h:670:55: error: use of undeclared
>> identifier 'size'; did you
>>       mean 'ksize'?
>>   670 |         const struct acpi_gpio_params *data __counted_by_ptr(size);
>>       |                                                              ^~~~
>>       |                                                              ksize
>> ././include/linux/compiler_types.h:392:64: note: expanded from macro
>> '__counted_by_ptr'
>>   392 | #define __counted_by_ptr(member)
>> __attribute__((__counted_by__(member)))
>>       |
>>        ^~~~~~
>> ./include/linux/slab.h:602:8: note: 'ksize' declared here
>>   602 | size_t ksize(const void *objp);
>>       |        ^
>
> Hm I see.
>
> Certainly Jeremy or Ard will have an idea about how to solve this,
> so paging them in.
>

libstub code never executes in the context of the kernel, but only in
the context of the boot firmware. Generally, we disable instrumentation
there that has a significant runtime component, basically because we
cannot crash or panic the kernel before we have even booted it.

Can we just #define __counted_by_ptr(...) to nothing when building
from that Makefile?


^ permalink raw reply	[flat|nested] 9+ messages in thread

* [PATCH v2] gpiolib: annotate struct acpi_gpio_mapping with __counted_by_ptr
  2026-09-28  6:38 [PATCH] gpiolib: annotate struct acpi_gpio_mapping with __counted_by_ptr Bill Wendling
  2026-09-28  7:22 ` Bill Wendling
@ 2026-10-02 12:42 ` Bill Wendling
  1 sibling, 0 replies; 9+ messages in thread
From: Bill Wendling @ 2026-10-02 12:42 UTC (permalink / raw)
  To: Linus Walleij, Bartosz Golaszewski, Ard Biesheuvel, Jeremy Kerr
  Cc: Kees Cook, Gustavo A. R. Silva, linux-gpio, linux-kernel,
	linux-hardening, Bill Wendling, codemender-patching+linux

The 'data' pointer field in 'struct acpi_gpio_mapping' is associated
with the 'size' field, which represents the number of elements of
type 'struct acpi_gpio_params' allocated for 'data'.

To improve bounds checking via CONFIG_UBSAN_BOUNDS and
CONFIG_FORTIFY_SOURCE, annotate 'data' with the __counted_by_ptr
attribute.

Analysis of allocation, assignment, and access points shows that the
pointer is never accessed before the count is set, which guarantees that
this annotation is safe and will not cause runtime panics or
false-positive bounds checks.

Cc: codemender-patching+linux@google.com
Assisted-by: LLM
Signed-off-by: Bill Wendling <morbo@google.com>
---
v2: Undefine "__counted_by" and "__counted_by_ptr" in the EFI stub
    library as it doesn't need it and Clang is missing a flag to
    enable them.
---
 drivers/firmware/efi/libstub/alignedmem.c      | 8 ++++++++
 drivers/firmware/efi/libstub/efi-stub-helper.c | 8 ++++++++
 drivers/firmware/efi/libstub/file.c            | 8 ++++++++
 drivers/firmware/efi/libstub/gop.c             | 8 ++++++++
 drivers/firmware/efi/libstub/mem.c             | 8 ++++++++
 drivers/firmware/efi/libstub/pci.c             | 8 ++++++++
 drivers/firmware/efi/libstub/printk.c          | 8 ++++++++
 drivers/firmware/efi/libstub/random.c          | 8 ++++++++
 drivers/firmware/efi/libstub/randomalloc.c     | 8 ++++++++
 drivers/firmware/efi/libstub/secureboot.c      | 9 +++++++++
 drivers/firmware/efi/libstub/smbios.c          | 8 ++++++++
 drivers/firmware/efi/libstub/tpm.c             | 9 +++++++++
 drivers/firmware/efi/libstub/x86-5lvl.c        | 9 +++++++++
 drivers/firmware/efi/libstub/x86-stub.c        | 8 ++++++++
 include/linux/gpio/consumer.h                  | 2 +-
 15 files changed, 116 insertions(+), 1 deletion(-)

diff --git a/drivers/firmware/efi/libstub/alignedmem.c b/drivers/firmware/efi/libstub/alignedmem.c
index 31928bd87e0f..36248a13f15b 100644
--- a/drivers/firmware/efi/libstub/alignedmem.c
+++ b/drivers/firmware/efi/libstub/alignedmem.c
@@ -1,5 +1,13 @@
 // SPDX-License-Identifier: GPL-2.0
 
+/*
+ * The EFI stub doesn't execute in the context of the kernel, only in the
+ * context of boot firmware, which isn't the time or place to crash the kernel.
+ * Therefore, disable the __counted_by__ attribute.
+ */
+#undef __counted_by
+#undef __counted_by_ptr
+
 #include <linux/efi.h>
 #include <asm/efi.h>
 
diff --git a/drivers/firmware/efi/libstub/efi-stub-helper.c b/drivers/firmware/efi/libstub/efi-stub-helper.c
index 8e43eb3f418b..a97d086a76a1 100644
--- a/drivers/firmware/efi/libstub/efi-stub-helper.c
+++ b/drivers/firmware/efi/libstub/efi-stub-helper.c
@@ -7,6 +7,14 @@
  * Copyright 2011 Intel Corporation; author Matt Fleming
  */
 
+/*
+ * The EFI stub doesn't execute in the context of the kernel, only in the
+ * context of boot firmware, which isn't the time or place to crash the kernel.
+ * Therefore, disable the __counted_by__ attribute.
+ */
+#undef __counted_by
+#undef __counted_by_ptr
+
 #include <linux/stdarg.h>
 
 #include <linux/efi.h>
diff --git a/drivers/firmware/efi/libstub/file.c b/drivers/firmware/efi/libstub/file.c
index b2601e284695..e845dc2e7aa0 100644
--- a/drivers/firmware/efi/libstub/file.c
+++ b/drivers/firmware/efi/libstub/file.c
@@ -7,6 +7,14 @@
  * Copyright 2011 Intel Corporation; author Matt Fleming
  */
 
+/*
+ * The EFI stub doesn't execute in the context of the kernel, only in the
+ * context of boot firmware, which isn't the time or place to crash the kernel.
+ * Therefore, disable the __counted_by__ attribute.
+ */
+#undef __counted_by
+#undef __counted_by_ptr
+
 #include <linux/efi.h>
 #include <asm/efi.h>
 
diff --git a/drivers/firmware/efi/libstub/gop.c b/drivers/firmware/efi/libstub/gop.c
index b800a6c2290c..f9736d2eff22 100644
--- a/drivers/firmware/efi/libstub/gop.c
+++ b/drivers/firmware/efi/libstub/gop.c
@@ -5,6 +5,14 @@
  *
  * ----------------------------------------------------------------------- */
 
+/*
+ * The EFI stub doesn't execute in the context of the kernel, only in the
+ * context of boot firmware, which isn't the time or place to crash the kernel.
+ * Therefore, disable the __counted_by__ attribute.
+ */
+#undef __counted_by
+#undef __counted_by_ptr
+
 #include <linux/bitops.h>
 #include <linux/ctype.h>
 #include <linux/efi.h>
diff --git a/drivers/firmware/efi/libstub/mem.c b/drivers/firmware/efi/libstub/mem.c
index fec561e3a792..65bea615420c 100644
--- a/drivers/firmware/efi/libstub/mem.c
+++ b/drivers/firmware/efi/libstub/mem.c
@@ -1,5 +1,13 @@
 // SPDX-License-Identifier: GPL-2.0
 
+/*
+ * The EFI stub doesn't execute in the context of the kernel, only in the
+ * context of boot firmware, which isn't the time or place to crash the kernel.
+ * Therefore, disable the __counted_by__ attribute.
+ */
+#undef __counted_by
+#undef __counted_by_ptr
+
 #include <linux/efi.h>
 #include <asm/efi.h>
 
diff --git a/drivers/firmware/efi/libstub/pci.c b/drivers/firmware/efi/libstub/pci.c
index 5daa7a0a0e87..a4c9bf67d5e0 100644
--- a/drivers/firmware/efi/libstub/pci.c
+++ b/drivers/firmware/efi/libstub/pci.c
@@ -6,6 +6,14 @@
  * Copyright 2019 Google, LLC
  */
 
+/*
+ * The EFI stub doesn't execute in the context of the kernel, only in the
+ * context of boot firmware, which isn't the time or place to crash the kernel.
+ * Therefore, disable the __counted_by__ attribute.
+ */
+#undef __counted_by
+#undef __counted_by_ptr
+
 #include <linux/efi.h>
 #include <linux/pci.h>
 
diff --git a/drivers/firmware/efi/libstub/printk.c b/drivers/firmware/efi/libstub/printk.c
index 0a18cfe32528..e2ae89a27b78 100644
--- a/drivers/firmware/efi/libstub/printk.c
+++ b/drivers/firmware/efi/libstub/printk.c
@@ -1,5 +1,13 @@
 // SPDX-License-Identifier: GPL-2.0
 
+/*
+ * The EFI stub doesn't execute in the context of the kernel, only in the
+ * context of boot firmware, which isn't the time or place to crash the kernel.
+ * Therefore, disable the __counted_by__ attribute.
+ */
+#undef __counted_by
+#undef __counted_by_ptr
+
 #include <linux/stdarg.h>
 
 #include <linux/ctype.h>
diff --git a/drivers/firmware/efi/libstub/random.c b/drivers/firmware/efi/libstub/random.c
index d63262d36e47..d370f0d79c07 100644
--- a/drivers/firmware/efi/libstub/random.c
+++ b/drivers/firmware/efi/libstub/random.c
@@ -3,6 +3,14 @@
  * Copyright (C) 2016 Linaro Ltd;  <ard.biesheuvel@linaro.org>
  */
 
+/*
+ * The EFI stub doesn't execute in the context of the kernel, only in the
+ * context of boot firmware, which isn't the time or place to crash the kernel.
+ * Therefore, disable the __counted_by__ attribute.
+ */
+#undef __counted_by
+#undef __counted_by_ptr
+
 #include <linux/efi.h>
 #include <asm/efi.h>
 
diff --git a/drivers/firmware/efi/libstub/randomalloc.c b/drivers/firmware/efi/libstub/randomalloc.c
index fd80b2f3233a..b09a26aa51e9 100644
--- a/drivers/firmware/efi/libstub/randomalloc.c
+++ b/drivers/firmware/efi/libstub/randomalloc.c
@@ -3,6 +3,14 @@
  * Copyright (C) 2016 Linaro Ltd;  <ard.biesheuvel@linaro.org>
  */
 
+/*
+ * The EFI stub doesn't execute in the context of the kernel, only in the
+ * context of boot firmware, which isn't the time or place to crash the kernel.
+ * Therefore, disable the __counted_by__ attribute.
+ */
+#undef __counted_by
+#undef __counted_by_ptr
+
 #include <linux/efi.h>
 #include <linux/log2.h>
 #include <asm/efi.h>
diff --git a/drivers/firmware/efi/libstub/secureboot.c b/drivers/firmware/efi/libstub/secureboot.c
index 516f4f0069bd..07c9782e0c44 100644
--- a/drivers/firmware/efi/libstub/secureboot.c
+++ b/drivers/firmware/efi/libstub/secureboot.c
@@ -7,6 +7,15 @@
  * Copyright (C) 2013 Red Hat, Inc.
  *     Mark Salter <msalter@redhat.com>
  */
+
+/*
+ * The EFI stub doesn't execute in the context of the kernel, only in the
+ * context of boot firmware, which isn't the time or place to crash the kernel.
+ * Therefore, disable the __counted_by__ attribute.
+ */
+#undef __counted_by
+#undef __counted_by_ptr
+
 #include <linux/efi.h>
 #include <asm/efi.h>
 
diff --git a/drivers/firmware/efi/libstub/smbios.c b/drivers/firmware/efi/libstub/smbios.c
index efbbfc3c2c0d..98dc3ee40958 100644
--- a/drivers/firmware/efi/libstub/smbios.c
+++ b/drivers/firmware/efi/libstub/smbios.c
@@ -2,6 +2,14 @@
 // Copyright 2022 Google LLC
 // Author: Ard Biesheuvel <ardb@google.com>
 
+/*
+ * The EFI stub doesn't execute in the context of the kernel, only in the
+ * context of boot firmware, which isn't the time or place to crash the kernel.
+ * Therefore, disable the __counted_by__ attribute.
+ */
+#undef __counted_by
+#undef __counted_by_ptr
+
 #include <linux/efi.h>
 
 #include "efistub.h"
diff --git a/drivers/firmware/efi/libstub/tpm.c b/drivers/firmware/efi/libstub/tpm.c
index 73f001114732..27bc0ccc2a2b 100644
--- a/drivers/firmware/efi/libstub/tpm.c
+++ b/drivers/firmware/efi/libstub/tpm.c
@@ -7,6 +7,15 @@
  *     Matthew Garrett <mjg59@google.com>
  *     Thiebaud Weksteen <tweek@google.com>
  */
+
+/*
+ * The EFI stub doesn't execute in the context of the kernel, only in the
+ * context of boot firmware, which isn't the time or place to crash the kernel.
+ * Therefore, disable the __counted_by__ attribute.
+ */
+#undef __counted_by
+#undef __counted_by_ptr
+
 #include <linux/efi.h>
 #include <linux/tpm_eventlog.h>
 #include <asm/efi.h>
diff --git a/drivers/firmware/efi/libstub/x86-5lvl.c b/drivers/firmware/efi/libstub/x86-5lvl.c
index c3da05c0df8b..3112ab4b2623 100644
--- a/drivers/firmware/efi/libstub/x86-5lvl.c
+++ b/drivers/firmware/efi/libstub/x86-5lvl.c
@@ -1,4 +1,13 @@
 // SPDX-License-Identifier: GPL-2.0-only
+
+/*
+ * The EFI stub doesn't execute in the context of the kernel, only in the
+ * context of boot firmware, which isn't the time or place to crash the kernel.
+ * Therefore, disable the __counted_by__ attribute.
+ */
+#undef __counted_by
+#undef __counted_by_ptr
+
 #include <linux/efi.h>
 
 #include <asm/boot.h>
diff --git a/drivers/firmware/efi/libstub/x86-stub.c b/drivers/firmware/efi/libstub/x86-stub.c
index f4799e29f4cf..77e806c2b016 100644
--- a/drivers/firmware/efi/libstub/x86-stub.c
+++ b/drivers/firmware/efi/libstub/x86-stub.c
@@ -6,6 +6,14 @@
  *
  * ----------------------------------------------------------------------- */
 
+/*
+ * The EFI stub doesn't execute in the context of the kernel, only in the
+ * context of boot firmware, which isn't the time or place to crash the kernel.
+ * Therefore, disable the __counted_by__ attribute.
+ */
+#undef __counted_by
+#undef __counted_by_ptr
+
 #include <linux/efi.h>
 #include <linux/pci.h>
 #include <linux/stddef.h>
diff --git a/include/linux/gpio/consumer.h b/include/linux/gpio/consumer.h
index fceeefd5f893..2b80cf7aa7e7 100644
--- a/include/linux/gpio/consumer.h
+++ b/include/linux/gpio/consumer.h
@@ -667,7 +667,7 @@ struct acpi_gpio_params {
 
 struct acpi_gpio_mapping {
 	const char *name;
-	const struct acpi_gpio_params *data;
+	const struct acpi_gpio_params *data __counted_by_ptr(size);
 	unsigned int size;
 
 /* Ignore IoRestriction field */
-- 
2.56.0.rc1.315.gc6ed9934b7-goog


^ permalink raw reply	[flat|nested] 9+ messages in thread

* Re: [PATCH] gpiolib: annotate struct acpi_gpio_mapping with __counted_by_ptr
  2026-10-02  7:38         ` Ard Biesheuvel
@ 2026-10-02 12:44           ` Bill Wendling
  2026-10-02 13:51             ` Ard Biesheuvel
  0 siblings, 1 reply; 9+ messages in thread
From: Bill Wendling @ 2026-10-02 12:44 UTC (permalink / raw)
  To: Ard Biesheuvel
  Cc: Linus Walleij, Jeremy Kerr, Bartosz Golaszewski, Kees Cook,
	Gustavo A. R. Silva, linux-gpio, linux-kernel, linux-hardening,
	codemender-patching+linux

On Fri, Oct 2, 2026 at 12:38 AM Ard Biesheuvel <ardb@kernel.org> wrote:
> On Thu, 1 Oct 2026, at 23:24, Linus Walleij wrote:
> > On Thu, Oct 1, 2026 at 10:05 PM Bill Wendling <morbo@google.com> wrote:
> >> On Thu, Oct 1, 2026 at 12:56 PM Linus Walleij <linusw@kernel.org> wrote:
> >> > On Mon, Sep 28, 2026 at 9:22 AM Bill Wendling <morbo@google.com> wrote:
> >> > > On Sun, Sep 27, 2026 at 11:38 PM Bill Wendling <morbo@google.com> wrote:
> >> > > >
> >> > > > The 'data' pointer field in 'struct acpi_gpio_mapping' is associated
> >> > > > with the 'size' field, which represents the number of elements of
> >> > > > type 'struct acpi_gpio_params' allocated for 'data'.
> >> > > >
> >> > > > To improve bounds checking via CONFIG_UBSAN_BOUNDS and
> >> > > > CONFIG_FORTIFY_SOURCE, annotate 'data' with the __counted_by_ptr
> >> > > > attribute.
> >> > > >
> >> > > > Analysis of allocation, assignment, and access points shows that the
> >> > > > pointer is never accessed before the count is set, which guarantees that
> >> > > > this annotation is safe and will not cause runtime panics or
> >> > > > false-positive bounds checks.
> >> > > >
> >> > > > Cc: codemender-patching+linux@google.com
> >> > > > Assisted-by: LLM
> >> > > > Signed-off-by: Bill Wendling <morbo@google.com>
> >> > > > ---
> >> > > >  include/linux/gpio/consumer.h | 2 +-
> >> > > >  1 file changed, 1 insertion(+), 1 deletion(-)
> >> > > >
> >> > > > diff --git a/include/linux/gpio/consumer.h b/include/linux/gpio/consumer.h
> >> > > > index fceeefd5f893..2b80cf7aa7e7 100644
> >> > > > --- a/include/linux/gpio/consumer.h
> >> > > > +++ b/include/linux/gpio/consumer.h
> >> > > > @@ -667,7 +667,7 @@ struct acpi_gpio_params {
> >> > > >
> >> > > >  struct acpi_gpio_mapping {
> >> > > >         const char *name;
> >> > > > -       const struct acpi_gpio_params *data;
> >> > > > +       const struct acpi_gpio_params *data __counted_by_ptr(size);
> >> > > >         unsigned int size;
> >> > > >
> >> > > >  /* Ignore IoRestriction field */
> >> > >
> >> > > There's a problem with 'drivers/firmware/efi/libstub/Makefile'. Clang
> >> > > needs a compiler flag to support the "__counted_by_ptr" attribute
> >> > > referencing a field *after* the pointer, like in this patch. However,
> >> > > the Makefile blasts the flag away for x86 platforms. Below is a hack
> >> > > that copies the part of the top-level Makefile that adds the flag. I
> >> > > don't think that's a good solution. The comment in the driver's
> >> > > Makefile says that the stub code executes before the kernel does,
> >> > > which I assume is why a lot of the flags are blown away... In any
> >> > > event, I'm not sure how best to address this.
> >> >
> >> > But is this a problem with the current patch?
> >> >
> >> > Does libefistub use <linux/gpio/consumer.h> in any way, shape
> >> > or form?
> >> >
> >> It's being #included transitively:
> >>
> >> In file included from drivers/firmware/efi/libstub/efi-stub-helper.c:12:
> >> In file included from ./include/linux/efi.h:20:
> >> In file included from ./include/linux/rtc.h:18:
> >> In file included from ./include/linux/nvmem-provider.h:16:
> >> ./include/linux/gpio/consumer.h:670:55: error: use of undeclared
> >> identifier 'size'; did you
> >>       mean 'ksize'?
> >>   670 |         const struct acpi_gpio_params *data __counted_by_ptr(size);
> >>       |                                                              ^~~~
> >>       |                                                              ksize
> >> ././include/linux/compiler_types.h:392:64: note: expanded from macro
> >> '__counted_by_ptr'
> >>   392 | #define __counted_by_ptr(member)
> >> __attribute__((__counted_by__(member)))
> >>       |
> >>        ^~~~~~
> >> ./include/linux/slab.h:602:8: note: 'ksize' declared here
> >>   602 | size_t ksize(const void *objp);
> >>       |        ^
> >
> > Hm I see.
> >
> > Certainly Jeremy or Ard will have an idea about how to solve this,
> > so paging them in.
> >
>
> libstub code never executes in the context of the kernel, but only in
> the context of the boot firmware. Generally, we disable instrumentation
> there that has a significant runtime component, basically because we
> cannot crash or panic the kernel before we have even booted it.
>
> Can we just #define __counted_by_ptr(...) to nothing when building
> from that Makefile?
>
Doing it in the Makefile is tricky, because of how the "c_flags"
variable is defined and used. I couldn't find a good way to do it.
Instead, I inserted "#undef __counted_by{_ptr}" at the top of the
affected files. It's gross. If there's a way I'm missing, please let
me know.

-bw

^ permalink raw reply	[flat|nested] 9+ messages in thread

* Re: [PATCH] gpiolib: annotate struct acpi_gpio_mapping with __counted_by_ptr
  2026-10-02 12:44           ` Bill Wendling
@ 2026-10-02 13:51             ` Ard Biesheuvel
  0 siblings, 0 replies; 9+ messages in thread
From: Ard Biesheuvel @ 2026-10-02 13:51 UTC (permalink / raw)
  To: Bill Wendling
  Cc: Linus Walleij, Jeremy Kerr, Bartosz Golaszewski, Kees Cook,
	Gustavo A. R. Silva, linux-gpio, linux-kernel, linux-hardening,
	codemender-patching+linux



On Fri, 2 Oct 2026, at 14:44, Bill Wendling wrote:
> On Fri, Oct 2, 2026 at 12:38 AM Ard Biesheuvel <ardb@kernel.org> wrote:
>> On Thu, 1 Oct 2026, at 23:24, Linus Walleij wrote:
>> > On Thu, Oct 1, 2026 at 10:05 PM Bill Wendling <morbo@google.com> wrote:
>> >> On Thu, Oct 1, 2026 at 12:56 PM Linus Walleij <linusw@kernel.org> wrote:
>> >> > On Mon, Sep 28, 2026 at 9:22 AM Bill Wendling <morbo@google.com> wrote:
>> >> > > On Sun, Sep 27, 2026 at 11:38 PM Bill Wendling <morbo@google.com> wrote:
>> >> > > >
>> >> > > > The 'data' pointer field in 'struct acpi_gpio_mapping' is associated
>> >> > > > with the 'size' field, which represents the number of elements of
>> >> > > > type 'struct acpi_gpio_params' allocated for 'data'.
>> >> > > >
>> >> > > > To improve bounds checking via CONFIG_UBSAN_BOUNDS and
>> >> > > > CONFIG_FORTIFY_SOURCE, annotate 'data' with the __counted_by_ptr
>> >> > > > attribute.
>> >> > > >
>> >> > > > Analysis of allocation, assignment, and access points shows that the
>> >> > > > pointer is never accessed before the count is set, which guarantees that
>> >> > > > this annotation is safe and will not cause runtime panics or
>> >> > > > false-positive bounds checks.
>> >> > > >
>> >> > > > Cc: codemender-patching+linux@google.com
>> >> > > > Assisted-by: LLM
>> >> > > > Signed-off-by: Bill Wendling <morbo@google.com>
>> >> > > > ---
>> >> > > >  include/linux/gpio/consumer.h | 2 +-
>> >> > > >  1 file changed, 1 insertion(+), 1 deletion(-)
>> >> > > >
>> >> > > > diff --git a/include/linux/gpio/consumer.h b/include/linux/gpio/consumer.h
>> >> > > > index fceeefd5f893..2b80cf7aa7e7 100644
>> >> > > > --- a/include/linux/gpio/consumer.h
>> >> > > > +++ b/include/linux/gpio/consumer.h
>> >> > > > @@ -667,7 +667,7 @@ struct acpi_gpio_params {
>> >> > > >
>> >> > > >  struct acpi_gpio_mapping {
>> >> > > >         const char *name;
>> >> > > > -       const struct acpi_gpio_params *data;
>> >> > > > +       const struct acpi_gpio_params *data __counted_by_ptr(size);
>> >> > > >         unsigned int size;
>> >> > > >
>> >> > > >  /* Ignore IoRestriction field */
>> >> > >
>> >> > > There's a problem with 'drivers/firmware/efi/libstub/Makefile'. Clang
>> >> > > needs a compiler flag to support the "__counted_by_ptr" attribute
>> >> > > referencing a field *after* the pointer, like in this patch. However,
>> >> > > the Makefile blasts the flag away for x86 platforms. Below is a hack
>> >> > > that copies the part of the top-level Makefile that adds the flag. I
>> >> > > don't think that's a good solution. The comment in the driver's
>> >> > > Makefile says that the stub code executes before the kernel does,
>> >> > > which I assume is why a lot of the flags are blown away... In any
>> >> > > event, I'm not sure how best to address this.
>> >> >
>> >> > But is this a problem with the current patch?
>> >> >
>> >> > Does libefistub use <linux/gpio/consumer.h> in any way, shape
>> >> > or form?
>> >> >
>> >> It's being #included transitively:
>> >>
>> >> In file included from drivers/firmware/efi/libstub/efi-stub-helper.c:12:
>> >> In file included from ./include/linux/efi.h:20:
>> >> In file included from ./include/linux/rtc.h:18:
>> >> In file included from ./include/linux/nvmem-provider.h:16:
>> >> ./include/linux/gpio/consumer.h:670:55: error: use of undeclared
>> >> identifier 'size'; did you
>> >>       mean 'ksize'?
>> >>   670 |         const struct acpi_gpio_params *data __counted_by_ptr(size);
>> >>       |                                                              ^~~~
>> >>       |                                                              ksize
>> >> ././include/linux/compiler_types.h:392:64: note: expanded from macro
>> >> '__counted_by_ptr'
>> >>   392 | #define __counted_by_ptr(member)
>> >> __attribute__((__counted_by__(member)))
>> >>       |
>> >>        ^~~~~~
>> >> ./include/linux/slab.h:602:8: note: 'ksize' declared here
>> >>   602 | size_t ksize(const void *objp);
>> >>       |        ^
>> >
>> > Hm I see.
>> >
>> > Certainly Jeremy or Ard will have an idea about how to solve this,
>> > so paging them in.
>> >
>>
>> libstub code never executes in the context of the kernel, but only in
>> the context of the boot firmware. Generally, we disable instrumentation
>> there that has a significant runtime component, basically because we
>> cannot crash or panic the kernel before we have even booted it.
>>
>> Can we just #define __counted_by_ptr(...) to nothing when building
>> from that Makefile?
>>
> Doing it in the Makefile is tricky, because of how the "c_flags"
> variable is defined and used. I couldn't find a good way to do it.
> Instead, I inserted "#undef __counted_by{_ptr}" at the top of the
> affected files. It's gross. If there's a way I'm missing, please let
> me know.
>

Does that even build?

^ permalink raw reply	[flat|nested] 9+ messages in thread

end of thread, other threads:[~2026-10-02 13:52 UTC | newest]

Thread overview: 9+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-09-28  6:38 [PATCH] gpiolib: annotate struct acpi_gpio_mapping with __counted_by_ptr Bill Wendling
2026-09-28  7:22 ` Bill Wendling
2026-10-01 19:56   ` Linus Walleij
2026-10-01 20:04     ` Bill Wendling
2026-10-01 21:24       ` Linus Walleij
2026-10-02  7:38         ` Ard Biesheuvel
2026-10-02 12:44           ` Bill Wendling
2026-10-02 13:51             ` Ard Biesheuvel
2026-10-02 12:42 ` [PATCH v2] " Bill Wendling

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®