From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id CC0A33F3288; Mon, 5 Oct 2026 10:54:03 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1791197644; cv=none; b=G+vv7nMQXflWHnjEaDzOhC1yiOup3+ddbfpyABNHl2ECAHCVytgYRT/EH1ErCaHc1YMfBbNEtDJ0DQ6DPWGLdOJ0g2VeIeS9/xWPKuenx5EwST9lX2sTF8KnU8J+NDxI3jwm0AcCixGoOtUuDWutInd5G31t8RpU1reqyTLJTiY= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1791197644; c=relaxed/simple; bh=paPXWUYsnV7ykCsbiZzaQNLH27n/4AhlQ1LYPVddCFk=; h=MIME-Version:Date:From:To:Cc:Message-Id:In-Reply-To:References: Subject:Content-Type; b=Xu/902t5b954/7uhSwyEytRK57Y8RJKVvdSLvfti3s1DP7W56/Hr8dQPh8n5nHbJtgVsQ6GWCpivi+jHtI1fW256N5OrxbbGREQXpcHwf/ul0kLqX8mlMlgqjAZ9ez0I00RnkHh3j89MvEomWAdldeXmoCY7OTHi+rgJmbGnhpI= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=hKTT4Ynj; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="hKTT4Ynj" Received: by smtp.kernel.org (Postfix) with ESMTPSA id AD2BB1F00893; Mon, 5 Oct 2026 10:54:02 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kernel.org; s=k20260515; t=1791197643; bh=X9RFb/buyI8n2HPvTUKM+p0nQi/e6u6dw5s7YNwYpLc=; h=Date:From:To:Cc:In-Reply-To:References:Subject; b=hKTT4YnjfZafPj+ObvqjmrunS+uFiUV135chM3/vA4scqWvWKearR9W41Mp4TtR+4 +1E0dNGv50O2KZss1Ma0Gv9qk8hrmYhiIZ0j6HcYlxGmygvGAIdHiFshJ1+zd+dtL9 HLN0lSDj/Qvptb3zAMrXFFkl7NHykX/5wxL/mn3/MNVxqsw+t82r7vxRv9tZvjihC/ bYzsTjIMd/o9Ox5O2Ak2CiKGyfsx/vv1d9sGs1AMUIFluaNuNZsI+zOWvJuVn1jLPi F435tAIhPrpgfJ7fjVnLp48laYoPb/84SZdm4SAvlaoH6aYUrgPZnuHPeeGCmVk3Fc 3PoQTxAnFg8EA== Received: from ams-compute-02.internal (ams-compute-02.internal [10.64.2.62]) by mailfauth.ams.internal (Postfix) with ESMTP id CA6AA1980047; Mon, 5 Oct 2026 06:54:00 -0400 (EDT) Received: from ams-imap-11 ([10.64.2.31]) by ams-compute-02.internal (MEProxy); Mon, 05 Oct 2026 06:54:00 -0400 X-ME-Sender: X-ME-Proxy-Cause: dmFkZTGLdks8gB5Qx52BxQMp2/Yz0QHw5YjDPkSdp5TVhyLY6N1QLaTIp3WlWwACde0uTa BW/cgz4w3Ngk+7Dz590jcvc/Jlsa8+h8dlnnRkMjcj9dHpnhfjYs0Pe9lGJzr2bi6xuEEx ug7LDOpWoA17Q+yMpPx9AjIn53uNCUdtNogGRkAScebNJG1rGch4dmbUmpheHwaZ1+RA8s r2dayGEuj6i0XAOQh/7+s7xTGHzks1ootpmN8phOQ4gusqHwJqyy4YSOR8g7SMUTiVlbqa UJ2iDm6MN4R9tpj+pjQpGao33nGpLApaJG3edt4wmWkRXoV9AbA9Wkm3kAAoIQlKvmpGp7 HMds26gPzwLhslCAvmDcGPGD/pyAWDiP9WPANbErSY1951zw/fEy7rD5Lb5V5jy+qeAN/9 OfJVzSPLLIUUeA0hjttWMZFhqTS0cf1uMpNBzj0+4TQ2Oo6VDWD5euJpdo5AlDdqOvecKw 0N2yUin/mAyewFOHpQNYcJA9cgI42Mfi4CQriNOR/ND+mJ+7eL8b5RcbCQYkiCyjDUYKYz 3oHj8OHFybwR+PdDNcYqPMkdTqcjcbO0RV1W6j5/gvwaPTMnQL7skNEbxf8Ly54W/kZEZB KizkWF9JaM+o1ZvI3qnn0RcZiSS84ziaGIX13aJR02vvfJxSb1v+XMhaVFQg X-ME-Proxy: Feedback-ID: ice86485a:Fastmail Received: by mailuser.ams.internal (Postfix, from userid 501) id 3A33AF80086; Mon, 5 Oct 2026 06:53:58 -0400 (EDT) X-Mailer: MessagingEngine.com Webmail Interface Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Date: Mon, 05 Oct 2026 12:53:36 +0200 From: "Ard Biesheuvel" To: "Bill Wendling" , "Kees Cook" Cc: "Gustavo A. R. Silva" , "Nathan Chancellor" , "Nick Desaulniers" , "Justin Stitt" , "Mark Brown" , "Marco Elver" , alan.maguire@oracle.com, namjain@linux.microsoft.com, "Peter Zijlstra" , linux-kernel@vger.kernel.org, linux-hardening@vger.kernel.org, llvm@lists.linux.dev Message-Id: In-Reply-To: <20261005102518.2400984-1-morbo@google.com> References: <20261005102518.2400984-1-morbo@google.com> Subject: Re: [PATCH] compiler_types: Allow opting out of __counted_by and __counted_by_ptr Content-Type: text/plain Content-Transfer-Encoding: 7bit Hi Bill, On Mon, 5 Oct 2026, at 12:25, Bill Wendling wrote: > Code that runs outside the kernel proper, such as the EFI stub, gets > nothing out of the counted_by annotations: the bounds checks they feed > (FORTIFY_SOURCE, UBSAN_BOUNDS) are already disabled there. > > The annotations can also break the build. A __counted_by_ptr() that > names a member declared after the pointer needs Clang's > '-fexperimental-late-parse-attributes', which the top-level Makefile > adds to 'KBUILD_CFLAGS'. The x86 EFI stub builds its own cflags and does > not get that flag, so it fails as soon as such a struct is pulled in > through a common header. > > Overriding the macros from a Makefile doesn't work: > 'compiler_types.h' is pulled in with '-include', which is processed > after all -D/-U options, so it re-establishes the definitions. Follow > the '__NO_FORTIFY' precedent instead: let a build define > '__NO_COUNTED_BY' or '__NO_COUNTED_BY_PTR' to turn the corresponding > annotation into a no-op. The two are kept separate but parallel so they > can be folded together once all supported compilers handle > '__counted_by' on pointers. > I'd prefer a single macro here - if there is ever a case where we need to turn off one but not the other, we can revisit. Otherwise, this looks good to me - thanks.