[PATCH] bus: fsl-mc: Annotate fsl_mc_io.portal_virt_addr with __counted_by_ptr

Kees Cook kees at kernel.org
Wed Sep 23 01:12:14 PDT 2026


On Tue, Sep 22, 2026 at 10:35:38PM +0000, Bill Wendling wrote:
> The GCC and Clang compilers provide the __counted_by_ptr attribute,
> which is used by KASAN and compiler bounds-checking to detect
> out-of-bounds accesses to pointer fields.
> 
> In "struct fsl_mc_io", the "portal_virt_addr" pointer points to the MC
> command portal virtual address. The size of this allocated portal in
> bytes is tracked by the "portal_size" field within the same structure.
> 
> Annotate the "portal_virt_addr" pointer field with
> "__counted_by_ptr(portal_size)" to enable compiler bounds-checking and
> harden against potential out-of-bounds accesses.

Another one where I hope things agree. :)

        mc_portal_size = resource_size(dpmcp_dev->regions);

        error = fsl_create_mc_io(&mc_bus_dev->dev,
                                 mc_portal_phys_addr,
                                 mc_portal_size, dpmcp_dev,
                                 mc_io_flags, &mc_io);
...

        mc_io->portal_size = mc_portal_size;
	...
        mc_portal_virt_addr = devm_ioremap(dev,
                                                   mc_portal_phys_addr,
                                                   mc_portal_size);
	...
        mc_io->portal_virt_addr = mc_portal_virt_addr;

But it actually reminds me that I still want a warning for having
compile-time warning about pointers being stripped from their counter:

                status = mc_read_response(mc_io->portal_virt_addr, cmd);
...
static inline enum mc_cmd_status mc_read_response(struct fsl_mc_command __iomem
                                                  *portal,
                                                  struct fsl_mc_command *resp)
{
        int i;
        enum mc_cmd_status status;

        /* Copy command response header from MC portal: */
        resp->header = cpu_to_le64(readq_relaxed(&portal->header));

Not only is mc_io->portal_virt_addr separated from mc_io->portal_size
via getting passed to mc_read_response(), but it then immediately gets
cast to struct fsl_mc_command.

We should get the __singleton attribute so we can mark function arg
pointers as "not an array", and then these kinds of casts could generate
a run-time check at function call time to check
sizeof(struct fsl_mc_command) against mc_io->portal_size when
__singleton was there, or kick up a warning that the counter got
stripped.

Because as-is, this patch is a no-op: nothing dereferences
mc_io->portal_virt_addr with the counter in context.


-Kees

-- 
Kees Cook



More information about the linux-arm-kernel mailing list