From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from gabe.freedesktop.org (gabe.freedesktop.org [131.252.210.177]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.lore.kernel.org (Postfix) with ESMTPS id 3CFEEE74901 for ; Mon, 2 Oct 2023 18:02:08 +0000 (UTC) Received: from gabe.freedesktop.org (localhost [127.0.0.1]) by gabe.freedesktop.org (Postfix) with ESMTP id C23AF10E076; Mon, 2 Oct 2023 18:02:07 +0000 (UTC) Received: from mail-wr1-x435.google.com (mail-wr1-x435.google.com [IPv6:2a00:1450:4864:20::435]) by gabe.freedesktop.org (Postfix) with ESMTPS id 9D1B610E063; Mon, 2 Oct 2023 18:02:05 +0000 (UTC) Received: by mail-wr1-x435.google.com with SMTP id ffacd0b85a97d-3226cc3e324so73801f8f.3; Mon, 02 Oct 2023 11:02:05 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20230601; t=1696269724; x=1696874524; darn=lists.freedesktop.org; h=content-transfer-encoding:in-reply-to:from:references:cc:to :content-language:subject:user-agent:mime-version:date:message-id :from:to:cc:subject:date:message-id:reply-to; bh=zam6JpvTJFSRB7Mf1N6WASAM0s+ax1vMTASmJwGp/GQ=; b=OWyGp/gEByRgyM4MY9Ye5RpslnTSZ2ikYlWyXs3wBpkwUYLljzKUnb32PT8SD96zdT ILULchDT9/U+v9c8aHQL5z4depnGr/yKc7Me1ifAZvHB6o4ioQw3fNmTK1GVSR1RzaMK rgcREADI3fgdEFUTvBcRnpJ1KjvpQliCjIzQPxbAXMcRvZhTfiPjaMt7eNh1l6p+5VeD Z6+nutPI/hL9cPvvVllnmrfTka6dUMiaFg0L1BAvQ01a1Q1RgnbFTcicnFQg4J5HxSvq JzqkXyGtVvSedD8GnIeQZx1+J19IFgZh2qCOdhccJ9OdMjJ+VoufRo5eIbAiCDyXIzEL yqnQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1696269724; x=1696874524; h=content-transfer-encoding:in-reply-to:from:references:cc:to :content-language:subject:user-agent:mime-version:date:message-id :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to; bh=zam6JpvTJFSRB7Mf1N6WASAM0s+ax1vMTASmJwGp/GQ=; b=jHuvBE1XxLQvua1CvNxPd+fRhVQIkz58FSV/NAuuxWFqijsKeg2KCRCrSWyS71NWcD PpECTy5zrPziq9S5ySWNIaJ12KITuExm6/YB2lruuc+buVWbPEkDPeaNBjQcLHIeO/pu Zxp6R9Ble0STZJf7z23U7oRXdLa/R18prlxxra+CwTVPkcviNEU6Z7l/PecPrGGhHSPa 7N1rA9uoDSIbpTUjF25eNwObVyK++RcrPPKeuEpCTVcGH0tgS2LgQXlEjqTmHsANlMXy tehvV/svFA7pLgQcRopyfCA+sp9pgCsPpqjt7dE1ngEK8YCsylupAJyOWz6+qD2umzb8 JVHQ== X-Gm-Message-State: AOJu0Yz/rNVvj6AZ2v82S6l1HCxEFNAFVDkISa5ec4FfINH5TyatZJyt obBQuyFmMHjQ9d3tq9YnOIs= X-Google-Smtp-Source: AGHT+IHXROz9dJDWlLZd0E9oyaIxp9J/Vso2ikdsfsbdxkJUFVX9OGXOEmAj9p/hMQ4gi+RMtS0pLQ== X-Received: by 2002:adf:d4c2:0:b0:317:ddd3:1aed with SMTP id w2-20020adfd4c2000000b00317ddd31aedmr10422745wrk.68.1696269723540; Mon, 02 Oct 2023 11:02:03 -0700 (PDT) Received: from [10.254.108.106] (munvpn.amd.com. [165.204.72.6]) by smtp.gmail.com with ESMTPSA id g16-20020adfa490000000b003232380ffd5sm20650839wrb.106.2023.10.02.11.01.59 (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Mon, 02 Oct 2023 11:02:02 -0700 (PDT) Message-ID: <10644b5f-b0a7-85ef-0658-2353ee14df0d@gmail.com> Date: Mon, 2 Oct 2023 20:01:57 +0200 MIME-Version: 1.0 User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:102.0) Gecko/20100101 Thunderbird/102.15.1 Subject: Re: [PATCH 0/9] drm: Annotate structs with __counted_by Content-Language: en-US To: Kees Cook , Alex Deucher References: <20230922173110.work.084-kees@kernel.org> <169601600138.3014939.8511343741428844249.b4-ty@chromium.org> <83cd056c-52ae-01dd-7576-42d41da64c26@gmail.com> <202310020952.E7DE0948C0@keescook> From: =?UTF-8?Q?Christian_K=c3=b6nig?= In-Reply-To: <202310020952.E7DE0948C0@keescook> Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: 8bit X-BeenThere: amd-gfx@lists.freedesktop.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: Discussion list for AMD gfx List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Cc: Tejas Upadhyay , Emma Anholt , Tom Rix , Joonas Lahtinen , llvm@lists.linux.dev, dri-devel@lists.freedesktop.org, Chris Wilson , Prike Liang , Huang Rui , Gerd Hoffmann , Andrzej Hajda , Marijn Suijten , David Airlie , Matthew Brost , Karol Herbst , Neil Armstrong , amd-gfx@lists.freedesktop.org, Kuogee Hsieh , VMware Graphics Reviewers , Ben Skeggs , Andi Shyti , nouveau@lists.freedesktop.org, David Airlie , virtualization@lists.linux-foundation.org, Chia-I Wu , linux-hardening@vger.kernel.org, Alex Deucher , Lijo Lazar , Tvrtko Ursulin , linux-arm-msm@vger.kernel.org, intel-gfx@lists.freedesktop.org, Kevin Wang , Abhinav Kumar , Jani Nikula , Nathan Chancellor , Le Ma , Gurchetan Singh , Maxime Ripard , Rodrigo Vivi , Evan Quan , Sean Paul , Yifan Zhang , Xiaojian Du , freedreno@lists.freedesktop.org, Bjorn Andersson , "Pan, Xinhui" , Nick Desaulniers , linux-kernel@vger.kernel.org, Rob Clark , Melissa Wen , Zack Rusin , Daniel Vetter , Dmitry Baryshkov , Nirmoy Das , Lang Yu , =?UTF-8?Q?Christian_K=c3=b6nig?= , John Harrison , Hawking Zhang Errors-To: amd-gfx-bounces@lists.freedesktop.org Sender: "amd-gfx" Am 02.10.23 um 18:53 schrieb Kees Cook: > On Mon, Oct 02, 2023 at 11:06:19AM -0400, Alex Deucher wrote: >> On Mon, Oct 2, 2023 at 5:20 AM Christian König >> wrote: >>> Am 29.09.23 um 21:33 schrieb Kees Cook: >>>> On Fri, 22 Sep 2023 10:32:05 -0700, Kees Cook wrote: >>>>> This is a batch of patches touching drm for preparing for the coming >>>>> implementation by GCC and Clang of the __counted_by attribute. Flexible >>>>> array members annotated with __counted_by can have their accesses >>>>> bounds-checked at run-time checking via CONFIG_UBSAN_BOUNDS (for array >>>>> indexing) and CONFIG_FORTIFY_SOURCE (for strcpy/memcpy-family functions). >>>>> >>>>> As found with Coccinelle[1], add __counted_by to structs that would >>>>> benefit from the annotation. >>>>> >>>>> [...] >>>> Since this got Acks, I figure I should carry it in my tree. Let me know >>>> if this should go via drm instead. >>>> >>>> Applied to for-next/hardening, thanks! >>>> >>>> [1/9] drm/amd/pm: Annotate struct smu10_voltage_dependency_table with __counted_by >>>> https://git.kernel.org/kees/c/a6046ac659d6 >>> STOP! In a follow up discussion Alex and I figured out that this won't work. > I'm so confused; from the discussion I saw that Alex said both instances > were false positives? > >>> The value in the structure is byte swapped based on some firmware >>> endianness which not necessary matches the CPU endianness. >> SMU10 is APU only so the endianess of the SMU firmware and the CPU >> will always match. > Which I think is what is being said here? > >>> Please revert that one from going upstream if it's already on it's way. >>> >>> And because of those reasons I strongly think that patches like this >>> should go through the DRM tree :) > Sure, that's fine -- please let me know. It was others Acked/etc. Who > should carry these patches? Probably best if the relevant maintainer pick them up individually. Some of those structures are filled in by firmware/hardware and only the maintainers can judge if that value actually matches what the compiler needs. We have cases where individual bits are used as flags or when the size is byte swapped etc... Even Alex and I didn't immediately say how and where that field is actually used and had to dig that up. That's where the confusion came from. Regards, Christian. > > Thanks! > > -Kees > > >>> Regards, >>> Christian. >>> >>>> [2/9] drm/amdgpu/discovery: Annotate struct ip_hw_instance with __counted_by >>>> https://git.kernel.org/kees/c/4df33089b46f >>>> [3/9] drm/i915/selftests: Annotate struct perf_series with __counted_by >>>> https://git.kernel.org/kees/c/ffd3f823bdf6 >>>> [4/9] drm/msm/dpu: Annotate struct dpu_hw_intr with __counted_by >>>> https://git.kernel.org/kees/c/2de35a989b76 >>>> [5/9] drm/nouveau/pm: Annotate struct nvkm_perfdom with __counted_by >>>> https://git.kernel.org/kees/c/188aeb08bfaa >>>> [6/9] drm/vc4: Annotate struct vc4_perfmon with __counted_by >>>> https://git.kernel.org/kees/c/59a54dc896c3 >>>> [7/9] drm/virtio: Annotate struct virtio_gpu_object_array with __counted_by >>>> https://git.kernel.org/kees/c/5cd476de33af >>>> [8/9] drm/vmwgfx: Annotate struct vmw_surface_dirty with __counted_by >>>> https://git.kernel.org/kees/c/b426f2e5356a >>>> [9/9] drm/v3d: Annotate struct v3d_perfmon with __counted_by >>>> https://git.kernel.org/kees/c/dc662fa1b0e4 >>>> >>>> Take care, >>>> From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from gabe.freedesktop.org (gabe.freedesktop.org [131.252.210.177]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.lore.kernel.org (Postfix) with ESMTPS id 09298E74901 for ; Mon, 2 Oct 2023 18:02:11 +0000 (UTC) Received: from gabe.freedesktop.org (localhost [127.0.0.1]) by gabe.freedesktop.org (Postfix) with ESMTP id E9EAC10E0C1; Mon, 2 Oct 2023 18:02:07 +0000 (UTC) Received: from mail-wr1-x435.google.com (mail-wr1-x435.google.com [IPv6:2a00:1450:4864:20::435]) by gabe.freedesktop.org (Postfix) with ESMTPS id 9D1B610E063; Mon, 2 Oct 2023 18:02:05 +0000 (UTC) Received: by mail-wr1-x435.google.com with SMTP id ffacd0b85a97d-3226cc3e324so73801f8f.3; Mon, 02 Oct 2023 11:02:05 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20230601; t=1696269724; x=1696874524; darn=lists.freedesktop.org; h=content-transfer-encoding:in-reply-to:from:references:cc:to :content-language:subject:user-agent:mime-version:date:message-id :from:to:cc:subject:date:message-id:reply-to; bh=zam6JpvTJFSRB7Mf1N6WASAM0s+ax1vMTASmJwGp/GQ=; b=OWyGp/gEByRgyM4MY9Ye5RpslnTSZ2ikYlWyXs3wBpkwUYLljzKUnb32PT8SD96zdT ILULchDT9/U+v9c8aHQL5z4depnGr/yKc7Me1ifAZvHB6o4ioQw3fNmTK1GVSR1RzaMK rgcREADI3fgdEFUTvBcRnpJ1KjvpQliCjIzQPxbAXMcRvZhTfiPjaMt7eNh1l6p+5VeD Z6+nutPI/hL9cPvvVllnmrfTka6dUMiaFg0L1BAvQ01a1Q1RgnbFTcicnFQg4J5HxSvq JzqkXyGtVvSedD8GnIeQZx1+J19IFgZh2qCOdhccJ9OdMjJ+VoufRo5eIbAiCDyXIzEL yqnQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1696269724; x=1696874524; h=content-transfer-encoding:in-reply-to:from:references:cc:to :content-language:subject:user-agent:mime-version:date:message-id :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to; bh=zam6JpvTJFSRB7Mf1N6WASAM0s+ax1vMTASmJwGp/GQ=; b=jHuvBE1XxLQvua1CvNxPd+fRhVQIkz58FSV/NAuuxWFqijsKeg2KCRCrSWyS71NWcD PpECTy5zrPziq9S5ySWNIaJ12KITuExm6/YB2lruuc+buVWbPEkDPeaNBjQcLHIeO/pu Zxp6R9Ble0STZJf7z23U7oRXdLa/R18prlxxra+CwTVPkcviNEU6Z7l/PecPrGGhHSPa 7N1rA9uoDSIbpTUjF25eNwObVyK++RcrPPKeuEpCTVcGH0tgS2LgQXlEjqTmHsANlMXy tehvV/svFA7pLgQcRopyfCA+sp9pgCsPpqjt7dE1ngEK8YCsylupAJyOWz6+qD2umzb8 JVHQ== X-Gm-Message-State: AOJu0Yz/rNVvj6AZ2v82S6l1HCxEFNAFVDkISa5ec4FfINH5TyatZJyt obBQuyFmMHjQ9d3tq9YnOIs= X-Google-Smtp-Source: AGHT+IHXROz9dJDWlLZd0E9oyaIxp9J/Vso2ikdsfsbdxkJUFVX9OGXOEmAj9p/hMQ4gi+RMtS0pLQ== X-Received: by 2002:adf:d4c2:0:b0:317:ddd3:1aed with SMTP id w2-20020adfd4c2000000b00317ddd31aedmr10422745wrk.68.1696269723540; Mon, 02 Oct 2023 11:02:03 -0700 (PDT) Received: from [10.254.108.106] (munvpn.amd.com. [165.204.72.6]) by smtp.gmail.com with ESMTPSA id g16-20020adfa490000000b003232380ffd5sm20650839wrb.106.2023.10.02.11.01.59 (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Mon, 02 Oct 2023 11:02:02 -0700 (PDT) Message-ID: <10644b5f-b0a7-85ef-0658-2353ee14df0d@gmail.com> Date: Mon, 2 Oct 2023 20:01:57 +0200 MIME-Version: 1.0 User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:102.0) Gecko/20100101 Thunderbird/102.15.1 Content-Language: en-US To: Kees Cook , Alex Deucher References: <20230922173110.work.084-kees@kernel.org> <169601600138.3014939.8511343741428844249.b4-ty@chromium.org> <83cd056c-52ae-01dd-7576-42d41da64c26@gmail.com> <202310020952.E7DE0948C0@keescook> From: =?UTF-8?Q?Christian_K=c3=b6nig?= In-Reply-To: <202310020952.E7DE0948C0@keescook> Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: 8bit Subject: Re: [Intel-gfx] [PATCH 0/9] drm: Annotate structs with __counted_by X-BeenThere: intel-gfx@lists.freedesktop.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: Intel graphics driver community testing & development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Cc: Emma Anholt , Tom Rix , llvm@lists.linux.dev, dri-devel@lists.freedesktop.org, Chris Wilson , Prike Liang , Huang Rui , Gerd Hoffmann , Andrzej Hajda , Marijn Suijten , David Airlie , Karol Herbst , Neil Armstrong , amd-gfx@lists.freedesktop.org, Kuogee Hsieh , VMware Graphics Reviewers , Ben Skeggs , nouveau@lists.freedesktop.org, David Airlie , virtualization@lists.linux-foundation.org, Chia-I Wu , linux-hardening@vger.kernel.org, Alex Deucher , Lijo Lazar , linux-arm-msm@vger.kernel.org, intel-gfx@lists.freedesktop.org, Kevin Wang , Abhinav Kumar , Nathan Chancellor , Le Ma , Gurchetan Singh , Maxime Ripard , Rodrigo Vivi , Evan Quan , Yifan Zhang , Xiaojian Du , freedreno@lists.freedesktop.org, Bjorn Andersson , "Pan, Xinhui" , Nick Desaulniers , linux-kernel@vger.kernel.org, Melissa Wen , Zack Rusin , Daniel Vetter , Dmitry Baryshkov , Nirmoy Das , Lang Yu , =?UTF-8?Q?Christian_K=c3=b6nig?= , Hawking Zhang Errors-To: intel-gfx-bounces@lists.freedesktop.org Sender: "Intel-gfx" Am 02.10.23 um 18:53 schrieb Kees Cook: > On Mon, Oct 02, 2023 at 11:06:19AM -0400, Alex Deucher wrote: >> On Mon, Oct 2, 2023 at 5:20 AM Christian König >> wrote: >>> Am 29.09.23 um 21:33 schrieb Kees Cook: >>>> On Fri, 22 Sep 2023 10:32:05 -0700, Kees Cook wrote: >>>>> This is a batch of patches touching drm for preparing for the coming >>>>> implementation by GCC and Clang of the __counted_by attribute. Flexible >>>>> array members annotated with __counted_by can have their accesses >>>>> bounds-checked at run-time checking via CONFIG_UBSAN_BOUNDS (for array >>>>> indexing) and CONFIG_FORTIFY_SOURCE (for strcpy/memcpy-family functions). >>>>> >>>>> As found with Coccinelle[1], add __counted_by to structs that would >>>>> benefit from the annotation. >>>>> >>>>> [...] >>>> Since this got Acks, I figure I should carry it in my tree. Let me know >>>> if this should go via drm instead. >>>> >>>> Applied to for-next/hardening, thanks! >>>> >>>> [1/9] drm/amd/pm: Annotate struct smu10_voltage_dependency_table with __counted_by >>>> https://git.kernel.org/kees/c/a6046ac659d6 >>> STOP! In a follow up discussion Alex and I figured out that this won't work. > I'm so confused; from the discussion I saw that Alex said both instances > were false positives? > >>> The value in the structure is byte swapped based on some firmware >>> endianness which not necessary matches the CPU endianness. >> SMU10 is APU only so the endianess of the SMU firmware and the CPU >> will always match. > Which I think is what is being said here? > >>> Please revert that one from going upstream if it's already on it's way. >>> >>> And because of those reasons I strongly think that patches like this >>> should go through the DRM tree :) > Sure, that's fine -- please let me know. It was others Acked/etc. Who > should carry these patches? Probably best if the relevant maintainer pick them up individually. Some of those structures are filled in by firmware/hardware and only the maintainers can judge if that value actually matches what the compiler needs. We have cases where individual bits are used as flags or when the size is byte swapped etc... Even Alex and I didn't immediately say how and where that field is actually used and had to dig that up. That's where the confusion came from. Regards, Christian. > > Thanks! > > -Kees > > >>> Regards, >>> Christian. >>> >>>> [2/9] drm/amdgpu/discovery: Annotate struct ip_hw_instance with __counted_by >>>> https://git.kernel.org/kees/c/4df33089b46f >>>> [3/9] drm/i915/selftests: Annotate struct perf_series with __counted_by >>>> https://git.kernel.org/kees/c/ffd3f823bdf6 >>>> [4/9] drm/msm/dpu: Annotate struct dpu_hw_intr with __counted_by >>>> https://git.kernel.org/kees/c/2de35a989b76 >>>> [5/9] drm/nouveau/pm: Annotate struct nvkm_perfdom with __counted_by >>>> https://git.kernel.org/kees/c/188aeb08bfaa >>>> [6/9] drm/vc4: Annotate struct vc4_perfmon with __counted_by >>>> https://git.kernel.org/kees/c/59a54dc896c3 >>>> [7/9] drm/virtio: Annotate struct virtio_gpu_object_array with __counted_by >>>> https://git.kernel.org/kees/c/5cd476de33af >>>> [8/9] drm/vmwgfx: Annotate struct vmw_surface_dirty with __counted_by >>>> https://git.kernel.org/kees/c/b426f2e5356a >>>> [9/9] drm/v3d: Annotate struct v3d_perfmon with __counted_by >>>> https://git.kernel.org/kees/c/dc662fa1b0e4 >>>> >>>> Take care, >>>> From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from vger.kernel.org (vger.kernel.org [23.128.96.18]) by smtp.lore.kernel.org (Postfix) with ESMTP id 5CD52E74902 for ; Mon, 2 Oct 2023 18:02:09 +0000 (UTC) Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S231499AbjJBSCK (ORCPT ); Mon, 2 Oct 2023 14:02:10 -0400 Received: from lindbergh.monkeyblade.net ([23.128.96.19]:40598 "EHLO lindbergh.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S229600AbjJBSCI (ORCPT ); Mon, 2 Oct 2023 14:02:08 -0400 Received: from mail-wr1-x42b.google.com (mail-wr1-x42b.google.com [IPv6:2a00:1450:4864:20::42b]) by lindbergh.monkeyblade.net (Postfix) with ESMTPS id 7A2979B; Mon, 2 Oct 2023 11:02:05 -0700 (PDT) Received: by mail-wr1-x42b.google.com with SMTP id ffacd0b85a97d-32320381a07so93577f8f.0; Mon, 02 Oct 2023 11:02:05 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20230601; t=1696269724; x=1696874524; darn=vger.kernel.org; h=content-transfer-encoding:in-reply-to:from:references:cc:to :content-language:subject:user-agent:mime-version:date:message-id :from:to:cc:subject:date:message-id:reply-to; bh=zam6JpvTJFSRB7Mf1N6WASAM0s+ax1vMTASmJwGp/GQ=; b=QS6ZD+uMxiya5EGaWSBQVsdE5heWfEHr1m/rv5WkvePRRelpkxM927XwulTiV9BJPc iBzmZkl5SqqUE6/iOW2hAKLxibUcx2nrT1fjTVFRVUYaipBkaDCT/j/x8OPCuY6BX6ma WO+OsLpZjijQ22stG2uIOD8nqJpGXdte4/u6PSrgjEBWkc9wlTUjxXuM9vxhm39n8oqr HlAUhuCmZaSJo/LquYHldKttpEW8Cpx5uxgOKMAlU8IM9IN+XWbKSp7H8w31rfmmR2od IaoxiPNuKfWVHKabRIrAs1YDDXtu45ctjjd9iVBLSWjI95MfvlVn3jTxqTpsf/mfnfh3 udKA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1696269724; x=1696874524; h=content-transfer-encoding:in-reply-to:from:references:cc:to :content-language:subject:user-agent:mime-version:date:message-id :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to; bh=zam6JpvTJFSRB7Mf1N6WASAM0s+ax1vMTASmJwGp/GQ=; b=r2K3f4IV6g2P9bhQdB4lFjNtAodm4Iydg9DKwzB2XDNOnS29xThjZ8wNfXINcBr4Hz TMLly3qVf6LYx1Vf53mTbv29OgEjgKNrdKcSMtBELc2MdPF4SbtahM2BGMJqGV53FkeC uRpiaAuBrgeNvYn49grGnzZq1gQ2QNpjD9d8Rc072H2POr49m1E3qPaITMPv/QL+I/mv +HtShjksG1JQX/sYvNym2KjCm6LZZEuZFrbmjpNse/j86BeHRQNV5gOvCeoQaOSYFZHE jbgC/TM3v3s+Hy3T06y4QZxZQTDL8jsxU+5Fv4O+28p9MslYLqCSNKPchD4vWgkqCmYQ Vvtg== X-Gm-Message-State: AOJu0Yw5B3yi/lDz8qCMB8AU7XkVXw81DEMqnWyfi8rhmufRDX1fT9vK u0pAEXZRUUc18bcfgJoSHAY= X-Google-Smtp-Source: AGHT+IHXROz9dJDWlLZd0E9oyaIxp9J/Vso2ikdsfsbdxkJUFVX9OGXOEmAj9p/hMQ4gi+RMtS0pLQ== X-Received: by 2002:adf:d4c2:0:b0:317:ddd3:1aed with SMTP id w2-20020adfd4c2000000b00317ddd31aedmr10422745wrk.68.1696269723540; Mon, 02 Oct 2023 11:02:03 -0700 (PDT) Received: from [10.254.108.106] (munvpn.amd.com. [165.204.72.6]) by smtp.gmail.com with ESMTPSA id g16-20020adfa490000000b003232380ffd5sm20650839wrb.106.2023.10.02.11.01.59 (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Mon, 02 Oct 2023 11:02:02 -0700 (PDT) Message-ID: <10644b5f-b0a7-85ef-0658-2353ee14df0d@gmail.com> Date: Mon, 2 Oct 2023 20:01:57 +0200 MIME-Version: 1.0 User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:102.0) Gecko/20100101 Thunderbird/102.15.1 Subject: Re: [PATCH 0/9] drm: Annotate structs with __counted_by Content-Language: en-US To: Kees Cook , Alex Deucher Cc: David Airlie , "Pan, Xinhui" , Karol Herbst , Tom Rix , Joonas Lahtinen , dri-devel@lists.freedesktop.org, Chris Wilson , Prike Liang , Huang Rui , Gerd Hoffmann , Andrzej Hajda , Marijn Suijten , Matthew Brost , Evan Quan , Emma Anholt , amd-gfx@lists.freedesktop.org, Kuogee Hsieh , Lijo Lazar , VMware Graphics Reviewers , Ben Skeggs , Andi Shyti , nouveau@lists.freedesktop.org, David Airlie , Dmitry Baryshkov , Chia-I Wu , llvm@lists.linux.dev, Yifan Zhang , linux-arm-msm@vger.kernel.org, intel-gfx@lists.freedesktop.org, Kevin Wang , Abhinav Kumar , Jani Nikula , Tvrtko Ursulin , Nathan Chancellor , Le Ma , Gurchetan Singh , Maxime Ripard , Rodrigo Vivi , virtualization@lists.linux-foundation.org, Sean Paul , Neil Armstrong , Xiaojian Du , Lang Yu , Bjorn Andersson , Tejas Upadhyay , Nick Desaulniers , linux-kernel@vger.kernel.org, Hawking Zhang , Rob Clark , Melissa Wen , John Harrison , Daniel Vetter , Alex Deucher , Nirmoy Das , freedreno@lists.freedesktop.org, =?UTF-8?Q?Christian_K=c3=b6nig?= , Zack Rusin , linux-hardening@vger.kernel.org References: <20230922173110.work.084-kees@kernel.org> <169601600138.3014939.8511343741428844249.b4-ty@chromium.org> <83cd056c-52ae-01dd-7576-42d41da64c26@gmail.com> <202310020952.E7DE0948C0@keescook> From: =?UTF-8?Q?Christian_K=c3=b6nig?= In-Reply-To: <202310020952.E7DE0948C0@keescook> Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: 8bit Precedence: bulk List-ID: X-Mailing-List: linux-arm-msm@vger.kernel.org Am 02.10.23 um 18:53 schrieb Kees Cook: > On Mon, Oct 02, 2023 at 11:06:19AM -0400, Alex Deucher wrote: >> On Mon, Oct 2, 2023 at 5:20 AM Christian König >> wrote: >>> Am 29.09.23 um 21:33 schrieb Kees Cook: >>>> On Fri, 22 Sep 2023 10:32:05 -0700, Kees Cook wrote: >>>>> This is a batch of patches touching drm for preparing for the coming >>>>> implementation by GCC and Clang of the __counted_by attribute. Flexible >>>>> array members annotated with __counted_by can have their accesses >>>>> bounds-checked at run-time checking via CONFIG_UBSAN_BOUNDS (for array >>>>> indexing) and CONFIG_FORTIFY_SOURCE (for strcpy/memcpy-family functions). >>>>> >>>>> As found with Coccinelle[1], add __counted_by to structs that would >>>>> benefit from the annotation. >>>>> >>>>> [...] >>>> Since this got Acks, I figure I should carry it in my tree. Let me know >>>> if this should go via drm instead. >>>> >>>> Applied to for-next/hardening, thanks! >>>> >>>> [1/9] drm/amd/pm: Annotate struct smu10_voltage_dependency_table with __counted_by >>>> https://git.kernel.org/kees/c/a6046ac659d6 >>> STOP! In a follow up discussion Alex and I figured out that this won't work. > I'm so confused; from the discussion I saw that Alex said both instances > were false positives? > >>> The value in the structure is byte swapped based on some firmware >>> endianness which not necessary matches the CPU endianness. >> SMU10 is APU only so the endianess of the SMU firmware and the CPU >> will always match. > Which I think is what is being said here? > >>> Please revert that one from going upstream if it's already on it's way. >>> >>> And because of those reasons I strongly think that patches like this >>> should go through the DRM tree :) > Sure, that's fine -- please let me know. It was others Acked/etc. Who > should carry these patches? Probably best if the relevant maintainer pick them up individually. Some of those structures are filled in by firmware/hardware and only the maintainers can judge if that value actually matches what the compiler needs. We have cases where individual bits are used as flags or when the size is byte swapped etc... Even Alex and I didn't immediately say how and where that field is actually used and had to dig that up. That's where the confusion came from. Regards, Christian. > > Thanks! > > -Kees > > >>> Regards, >>> Christian. >>> >>>> [2/9] drm/amdgpu/discovery: Annotate struct ip_hw_instance with __counted_by >>>> https://git.kernel.org/kees/c/4df33089b46f >>>> [3/9] drm/i915/selftests: Annotate struct perf_series with __counted_by >>>> https://git.kernel.org/kees/c/ffd3f823bdf6 >>>> [4/9] drm/msm/dpu: Annotate struct dpu_hw_intr with __counted_by >>>> https://git.kernel.org/kees/c/2de35a989b76 >>>> [5/9] drm/nouveau/pm: Annotate struct nvkm_perfdom with __counted_by >>>> https://git.kernel.org/kees/c/188aeb08bfaa >>>> [6/9] drm/vc4: Annotate struct vc4_perfmon with __counted_by >>>> https://git.kernel.org/kees/c/59a54dc896c3 >>>> [7/9] drm/virtio: Annotate struct virtio_gpu_object_array with __counted_by >>>> https://git.kernel.org/kees/c/5cd476de33af >>>> [8/9] drm/vmwgfx: Annotate struct vmw_surface_dirty with __counted_by >>>> https://git.kernel.org/kees/c/b426f2e5356a >>>> [9/9] drm/v3d: Annotate struct v3d_perfmon with __counted_by >>>> https://git.kernel.org/kees/c/dc662fa1b0e4 >>>> >>>> Take care, >>>> From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from gabe.freedesktop.org (gabe.freedesktop.org [131.252.210.177]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.lore.kernel.org (Postfix) with ESMTPS id 38403E74905 for ; Mon, 2 Oct 2023 18:02:13 +0000 (UTC) Received: from gabe.freedesktop.org (localhost [127.0.0.1]) by gabe.freedesktop.org (Postfix) with ESMTP id 66F2810E0C8; Mon, 2 Oct 2023 18:02:08 +0000 (UTC) Received: from mail-wr1-x435.google.com (mail-wr1-x435.google.com [IPv6:2a00:1450:4864:20::435]) by gabe.freedesktop.org (Postfix) with ESMTPS id 9D1B610E063; Mon, 2 Oct 2023 18:02:05 +0000 (UTC) Received: by mail-wr1-x435.google.com with SMTP id ffacd0b85a97d-3226cc3e324so73801f8f.3; Mon, 02 Oct 2023 11:02:05 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20230601; t=1696269724; x=1696874524; darn=lists.freedesktop.org; h=content-transfer-encoding:in-reply-to:from:references:cc:to :content-language:subject:user-agent:mime-version:date:message-id :from:to:cc:subject:date:message-id:reply-to; bh=zam6JpvTJFSRB7Mf1N6WASAM0s+ax1vMTASmJwGp/GQ=; b=OWyGp/gEByRgyM4MY9Ye5RpslnTSZ2ikYlWyXs3wBpkwUYLljzKUnb32PT8SD96zdT ILULchDT9/U+v9c8aHQL5z4depnGr/yKc7Me1ifAZvHB6o4ioQw3fNmTK1GVSR1RzaMK rgcREADI3fgdEFUTvBcRnpJ1KjvpQliCjIzQPxbAXMcRvZhTfiPjaMt7eNh1l6p+5VeD Z6+nutPI/hL9cPvvVllnmrfTka6dUMiaFg0L1BAvQ01a1Q1RgnbFTcicnFQg4J5HxSvq JzqkXyGtVvSedD8GnIeQZx1+J19IFgZh2qCOdhccJ9OdMjJ+VoufRo5eIbAiCDyXIzEL yqnQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1696269724; x=1696874524; h=content-transfer-encoding:in-reply-to:from:references:cc:to :content-language:subject:user-agent:mime-version:date:message-id :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to; bh=zam6JpvTJFSRB7Mf1N6WASAM0s+ax1vMTASmJwGp/GQ=; b=jHuvBE1XxLQvua1CvNxPd+fRhVQIkz58FSV/NAuuxWFqijsKeg2KCRCrSWyS71NWcD PpECTy5zrPziq9S5ySWNIaJ12KITuExm6/YB2lruuc+buVWbPEkDPeaNBjQcLHIeO/pu Zxp6R9Ble0STZJf7z23U7oRXdLa/R18prlxxra+CwTVPkcviNEU6Z7l/PecPrGGhHSPa 7N1rA9uoDSIbpTUjF25eNwObVyK++RcrPPKeuEpCTVcGH0tgS2LgQXlEjqTmHsANlMXy tehvV/svFA7pLgQcRopyfCA+sp9pgCsPpqjt7dE1ngEK8YCsylupAJyOWz6+qD2umzb8 JVHQ== X-Gm-Message-State: AOJu0Yz/rNVvj6AZ2v82S6l1HCxEFNAFVDkISa5ec4FfINH5TyatZJyt obBQuyFmMHjQ9d3tq9YnOIs= X-Google-Smtp-Source: AGHT+IHXROz9dJDWlLZd0E9oyaIxp9J/Vso2ikdsfsbdxkJUFVX9OGXOEmAj9p/hMQ4gi+RMtS0pLQ== X-Received: by 2002:adf:d4c2:0:b0:317:ddd3:1aed with SMTP id w2-20020adfd4c2000000b00317ddd31aedmr10422745wrk.68.1696269723540; Mon, 02 Oct 2023 11:02:03 -0700 (PDT) Received: from [10.254.108.106] (munvpn.amd.com. [165.204.72.6]) by smtp.gmail.com with ESMTPSA id g16-20020adfa490000000b003232380ffd5sm20650839wrb.106.2023.10.02.11.01.59 (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Mon, 02 Oct 2023 11:02:02 -0700 (PDT) Message-ID: <10644b5f-b0a7-85ef-0658-2353ee14df0d@gmail.com> Date: Mon, 2 Oct 2023 20:01:57 +0200 MIME-Version: 1.0 User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:102.0) Gecko/20100101 Thunderbird/102.15.1 Content-Language: en-US To: Kees Cook , Alex Deucher References: <20230922173110.work.084-kees@kernel.org> <169601600138.3014939.8511343741428844249.b4-ty@chromium.org> <83cd056c-52ae-01dd-7576-42d41da64c26@gmail.com> <202310020952.E7DE0948C0@keescook> From: =?UTF-8?Q?Christian_K=c3=b6nig?= In-Reply-To: <202310020952.E7DE0948C0@keescook> Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: 8bit Subject: Re: [Nouveau] [PATCH 0/9] drm: Annotate structs with __counted_by X-BeenThere: nouveau@lists.freedesktop.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: Nouveau development list List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Cc: Tejas Upadhyay , Emma Anholt , Tom Rix , Joonas Lahtinen , llvm@lists.linux.dev, dri-devel@lists.freedesktop.org, Chris Wilson , Prike Liang , Huang Rui , Gerd Hoffmann , Andrzej Hajda , Marijn Suijten , Matthew Brost , Neil Armstrong , amd-gfx@lists.freedesktop.org, Kuogee Hsieh , VMware Graphics Reviewers , Ben Skeggs , Andi Shyti , nouveau@lists.freedesktop.org, David Airlie , virtualization@lists.linux-foundation.org, Chia-I Wu , linux-hardening@vger.kernel.org, Alex Deucher , Lijo Lazar , Tvrtko Ursulin , linux-arm-msm@vger.kernel.org, intel-gfx@lists.freedesktop.org, Kevin Wang , Abhinav Kumar , Jani Nikula , Nathan Chancellor , Le Ma , Gurchetan Singh , Maxime Ripard , Rodrigo Vivi , Evan Quan , Sean Paul , Yifan Zhang , Xiaojian Du , freedreno@lists.freedesktop.org, Bjorn Andersson , "Pan, Xinhui" , Nick Desaulniers , linux-kernel@vger.kernel.org, Rob Clark , Melissa Wen , Zack Rusin , Daniel Vetter , Dmitry Baryshkov , Nirmoy Das , Lang Yu , =?UTF-8?Q?Christian_K=c3=b6nig?= , John Harrison , Hawking Zhang Errors-To: nouveau-bounces@lists.freedesktop.org Sender: "Nouveau" Am 02.10.23 um 18:53 schrieb Kees Cook: > On Mon, Oct 02, 2023 at 11:06:19AM -0400, Alex Deucher wrote: >> On Mon, Oct 2, 2023 at 5:20 AM Christian König >> wrote: >>> Am 29.09.23 um 21:33 schrieb Kees Cook: >>>> On Fri, 22 Sep 2023 10:32:05 -0700, Kees Cook wrote: >>>>> This is a batch of patches touching drm for preparing for the coming >>>>> implementation by GCC and Clang of the __counted_by attribute. Flexible >>>>> array members annotated with __counted_by can have their accesses >>>>> bounds-checked at run-time checking via CONFIG_UBSAN_BOUNDS (for array >>>>> indexing) and CONFIG_FORTIFY_SOURCE (for strcpy/memcpy-family functions). >>>>> >>>>> As found with Coccinelle[1], add __counted_by to structs that would >>>>> benefit from the annotation. >>>>> >>>>> [...] >>>> Since this got Acks, I figure I should carry it in my tree. Let me know >>>> if this should go via drm instead. >>>> >>>> Applied to for-next/hardening, thanks! >>>> >>>> [1/9] drm/amd/pm: Annotate struct smu10_voltage_dependency_table with __counted_by >>>> https://git.kernel.org/kees/c/a6046ac659d6 >>> STOP! In a follow up discussion Alex and I figured out that this won't work. > I'm so confused; from the discussion I saw that Alex said both instances > were false positives? > >>> The value in the structure is byte swapped based on some firmware >>> endianness which not necessary matches the CPU endianness. >> SMU10 is APU only so the endianess of the SMU firmware and the CPU >> will always match. > Which I think is what is being said here? > >>> Please revert that one from going upstream if it's already on it's way. >>> >>> And because of those reasons I strongly think that patches like this >>> should go through the DRM tree :) > Sure, that's fine -- please let me know. It was others Acked/etc. Who > should carry these patches? Probably best if the relevant maintainer pick them up individually. Some of those structures are filled in by firmware/hardware and only the maintainers can judge if that value actually matches what the compiler needs. We have cases where individual bits are used as flags or when the size is byte swapped etc... Even Alex and I didn't immediately say how and where that field is actually used and had to dig that up. That's where the confusion came from. Regards, Christian. > > Thanks! > > -Kees > > >>> Regards, >>> Christian. >>> >>>> [2/9] drm/amdgpu/discovery: Annotate struct ip_hw_instance with __counted_by >>>> https://git.kernel.org/kees/c/4df33089b46f >>>> [3/9] drm/i915/selftests: Annotate struct perf_series with __counted_by >>>> https://git.kernel.org/kees/c/ffd3f823bdf6 >>>> [4/9] drm/msm/dpu: Annotate struct dpu_hw_intr with __counted_by >>>> https://git.kernel.org/kees/c/2de35a989b76 >>>> [5/9] drm/nouveau/pm: Annotate struct nvkm_perfdom with __counted_by >>>> https://git.kernel.org/kees/c/188aeb08bfaa >>>> [6/9] drm/vc4: Annotate struct vc4_perfmon with __counted_by >>>> https://git.kernel.org/kees/c/59a54dc896c3 >>>> [7/9] drm/virtio: Annotate struct virtio_gpu_object_array with __counted_by >>>> https://git.kernel.org/kees/c/5cd476de33af >>>> [8/9] drm/vmwgfx: Annotate struct vmw_surface_dirty with __counted_by >>>> https://git.kernel.org/kees/c/b426f2e5356a >>>> [9/9] drm/v3d: Annotate struct v3d_perfmon with __counted_by >>>> https://git.kernel.org/kees/c/dc662fa1b0e4 >>>> >>>> Take care, >>>> From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from smtp3.osuosl.org (smtp3.osuosl.org [140.211.166.136]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.lore.kernel.org (Postfix) with ESMTPS id C34C7E74902 for ; Mon, 2 Oct 2023 18:02:12 +0000 (UTC) Received: from localhost (localhost [127.0.0.1]) by smtp3.osuosl.org (Postfix) with ESMTP id 35FE760B1B; Mon, 2 Oct 2023 18:02:12 +0000 (UTC) DKIM-Filter: OpenDKIM Filter v2.11.0 smtp3.osuosl.org 35FE760B1B Authentication-Results: smtp3.osuosl.org; dkim=fail reason="signature verification failed" (2048-bit key) header.d=gmail.com header.i=@gmail.com header.a=rsa-sha256 header.s=20230601 header.b=LtBbuGu+ X-Virus-Scanned: amavisd-new at osuosl.org Received: from smtp3.osuosl.org ([127.0.0.1]) by localhost (smtp3.osuosl.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id yAM5mWa8lKGe; Mon, 2 Oct 2023 18:02:11 +0000 (UTC) Received: from lists.linuxfoundation.org (lf-lists.osuosl.org [140.211.9.56]) by smtp3.osuosl.org (Postfix) with ESMTPS id AA66760B21; Mon, 2 Oct 2023 18:02:10 +0000 (UTC) DKIM-Filter: OpenDKIM Filter v2.11.0 smtp3.osuosl.org AA66760B21 Received: from lf-lists.osuosl.org (localhost [127.0.0.1]) by lists.linuxfoundation.org (Postfix) with ESMTP id 825A4C0071; Mon, 2 Oct 2023 18:02:10 +0000 (UTC) Received: from smtp3.osuosl.org (smtp3.osuosl.org [IPv6:2605:bc80:3010::136]) by lists.linuxfoundation.org (Postfix) with ESMTP id 1F7A8C0032 for ; Mon, 2 Oct 2023 18:02:09 +0000 (UTC) Received: from localhost (localhost [127.0.0.1]) by smtp3.osuosl.org (Postfix) with ESMTP id E760260B21 for ; Mon, 2 Oct 2023 18:02:08 +0000 (UTC) DKIM-Filter: OpenDKIM Filter v2.11.0 smtp3.osuosl.org E760260B21 X-Virus-Scanned: amavisd-new at osuosl.org Received: from smtp3.osuosl.org ([127.0.0.1]) by localhost (smtp3.osuosl.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id LaE9_xRPRh1Z for ; Mon, 2 Oct 2023 18:02:06 +0000 (UTC) Received: from mail-wr1-x42e.google.com (mail-wr1-x42e.google.com [IPv6:2a00:1450:4864:20::42e]) by smtp3.osuosl.org (Postfix) with ESMTPS id 419C160B1B for ; Mon, 2 Oct 2023 18:02:05 +0000 (UTC) DKIM-Filter: OpenDKIM Filter v2.11.0 smtp3.osuosl.org 419C160B1B Received: by mail-wr1-x42e.google.com with SMTP id ffacd0b85a97d-32320381a07so93575f8f.0 for ; Mon, 02 Oct 2023 11:02:05 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20230601; t=1696269724; x=1696874524; darn=lists.linux-foundation.org; h=content-transfer-encoding:in-reply-to:from:references:cc:to :content-language:subject:user-agent:mime-version:date:message-id :from:to:cc:subject:date:message-id:reply-to; bh=zam6JpvTJFSRB7Mf1N6WASAM0s+ax1vMTASmJwGp/GQ=; b=LtBbuGu+hkgxW1hrFy3q13PmozUDKyp3akZmuu2ptjhZZh76FqdjEfD8VqqZfFur23 Lc9HffA7Qg0xqd5+WySFAAtHn3fzxIH/jFrWtRTfpnrGO+1i8egRqf3dqxMLoOKXS4Ca MuzOT4VQKc1orPUHVT9+RQLSoKppIwmlEfgaVqJkUr4xIjbVkgy6rIF22MuQRLNaRFf+ ttYPOPnYKhv+I1lBHptGiw9fZEXRPfqJM6PpfcG134nYQCvsiYGLHUI0+2ewYgQ6aEEc FGEqGi/c50UAeReb4zF9VcTQ7usSXrJzcZwm0eglCze0qnAMFvZZB8xouvsNL1eMZZ7v e5FA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1696269724; x=1696874524; h=content-transfer-encoding:in-reply-to:from:references:cc:to :content-language:subject:user-agent:mime-version:date:message-id :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to; bh=zam6JpvTJFSRB7Mf1N6WASAM0s+ax1vMTASmJwGp/GQ=; b=sraB0RCetzHVlCPLUiJj7mKHqMfM4nAtmebaA665B4DjbPgArAwIHSu0k+uCC5omBw i9ahq3cLY2f3CkkwlByD3Utqnqg6QLe8P3pIfwgwBPKiIGcbCKr8G2RllxmSH+7AxeL5 XMJCc+07P6V8jJ/kH1uBgKT4oxcG0iLb5EDLEqAR691+zemnvm7baTD4oO7oz+dldz2L s5yWQMcst75FCaZLE2Xw0H77bYjLfsZTQO/RbuO1odqLUCQwsh/4p8Uo4MlUpv4YVDOu LxVCDb7FAFzmjKd4v/K7WJeiDfzqX2Fsldr5SfLq/kGya5VpV4Gj+z2G47UE3bfLeZvb VnOg== X-Gm-Message-State: AOJu0YyoC58wQXCCctH5dGSwVUfeOKGZweRbFcR5odCbv2C845EyWFm+ W3xTb1hdD2YQD4GWL3Q3sVs= X-Google-Smtp-Source: AGHT+IHXROz9dJDWlLZd0E9oyaIxp9J/Vso2ikdsfsbdxkJUFVX9OGXOEmAj9p/hMQ4gi+RMtS0pLQ== X-Received: by 2002:adf:d4c2:0:b0:317:ddd3:1aed with SMTP id w2-20020adfd4c2000000b00317ddd31aedmr10422745wrk.68.1696269723540; Mon, 02 Oct 2023 11:02:03 -0700 (PDT) Received: from [10.254.108.106] (munvpn.amd.com. [165.204.72.6]) by smtp.gmail.com with ESMTPSA id g16-20020adfa490000000b003232380ffd5sm20650839wrb.106.2023.10.02.11.01.59 (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Mon, 02 Oct 2023 11:02:02 -0700 (PDT) Message-ID: <10644b5f-b0a7-85ef-0658-2353ee14df0d@gmail.com> Date: Mon, 2 Oct 2023 20:01:57 +0200 MIME-Version: 1.0 User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:102.0) Gecko/20100101 Thunderbird/102.15.1 Subject: Re: [PATCH 0/9] drm: Annotate structs with __counted_by Content-Language: en-US To: Kees Cook , Alex Deucher References: <20230922173110.work.084-kees@kernel.org> <169601600138.3014939.8511343741428844249.b4-ty@chromium.org> <83cd056c-52ae-01dd-7576-42d41da64c26@gmail.com> <202310020952.E7DE0948C0@keescook> From: =?UTF-8?Q?Christian_K=c3=b6nig?= In-Reply-To: <202310020952.E7DE0948C0@keescook> Cc: Tejas Upadhyay , Emma Anholt , Tom Rix , Joonas Lahtinen , llvm@lists.linux.dev, dri-devel@lists.freedesktop.org, Chris Wilson , Prike Liang , Huang Rui , Andrzej Hajda , Marijn Suijten , David Airlie , Matthew Brost , Karol Herbst , Neil Armstrong , amd-gfx@lists.freedesktop.org, Kuogee Hsieh , VMware Graphics Reviewers , Ben Skeggs , Andi Shyti , nouveau@lists.freedesktop.org, David Airlie , virtualization@lists.linux-foundation.org, Chia-I Wu , linux-hardening@vger.kernel.org, Alex Deucher , Lijo Lazar , Tvrtko Ursulin , linux-arm-msm@vger.kernel.org, intel-gfx@lists.freedesktop.org, Kevin Wang , Abhinav Kumar , Jani Nikula , Nathan Chancellor , Le Ma , Gurchetan Singh , Maxime Ripard , Rodrigo Vivi , Evan Quan , Sean Paul , Yifan Zhang , Xiaojian Du , freedreno@lists.freedesktop.org, Bjorn Andersson , "Pan, Xinhui" , Nick Desaulniers , linux-kernel@vger.kernel.org, Rob Clark , Melissa Wen , Zack Rusin , Daniel Vetter , Dmitry Baryshkov , Nirmoy Das , Lang Yu , =?UTF-8?Q?Christian_K=c3=b6nig?= , John Harrison , Hawking Zhang X-BeenThere: virtualization@lists.linux-foundation.org X-Mailman-Version: 2.1.15 Precedence: list List-Id: Linux virtualization List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Content-Transfer-Encoding: base64 Content-Type: text/plain; charset="utf-8"; Format="flowed" Errors-To: virtualization-bounces@lists.linux-foundation.org Sender: "Virtualization" QW0gMDIuMTAuMjMgdW0gMTg6NTMgc2NocmllYiBLZWVzIENvb2s6Cj4gT24gTW9uLCBPY3QgMDIs IDIwMjMgYXQgMTE6MDY6MTlBTSAtMDQwMCwgQWxleCBEZXVjaGVyIHdyb3RlOgo+PiBPbiBNb24s IE9jdCAyLCAyMDIzIGF0IDU6MjDigK9BTSBDaHJpc3RpYW4gS8O2bmlnCj4+IDxja29lbmlnLmxl aWNodHp1bWVya2VuQGdtYWlsLmNvbT4gd3JvdGU6Cj4+PiBBbSAyOS4wOS4yMyB1bSAyMTozMyBz Y2hyaWViIEtlZXMgQ29vazoKPj4+PiBPbiBGcmksIDIyIFNlcCAyMDIzIDEwOjMyOjA1IC0wNzAw LCBLZWVzIENvb2sgd3JvdGU6Cj4+Pj4+IFRoaXMgaXMgYSBiYXRjaCBvZiBwYXRjaGVzIHRvdWNo aW5nIGRybSBmb3IgcHJlcGFyaW5nIGZvciB0aGUgY29taW5nCj4+Pj4+IGltcGxlbWVudGF0aW9u IGJ5IEdDQyBhbmQgQ2xhbmcgb2YgdGhlIF9fY291bnRlZF9ieSBhdHRyaWJ1dGUuIEZsZXhpYmxl Cj4+Pj4+IGFycmF5IG1lbWJlcnMgYW5ub3RhdGVkIHdpdGggX19jb3VudGVkX2J5IGNhbiBoYXZl IHRoZWlyIGFjY2Vzc2VzCj4+Pj4+IGJvdW5kcy1jaGVja2VkIGF0IHJ1bi10aW1lIGNoZWNraW5n IHZpYSBDT05GSUdfVUJTQU5fQk9VTkRTIChmb3IgYXJyYXkKPj4+Pj4gaW5kZXhpbmcpIGFuZCBD T05GSUdfRk9SVElGWV9TT1VSQ0UgKGZvciBzdHJjcHkvbWVtY3B5LWZhbWlseSBmdW5jdGlvbnMp Lgo+Pj4+Pgo+Pj4+PiBBcyBmb3VuZCB3aXRoIENvY2NpbmVsbGVbMV0sIGFkZCBfX2NvdW50ZWRf YnkgdG8gc3RydWN0cyB0aGF0IHdvdWxkCj4+Pj4+IGJlbmVmaXQgZnJvbSB0aGUgYW5ub3RhdGlv bi4KPj4+Pj4KPj4+Pj4gWy4uLl0KPj4+PiBTaW5jZSB0aGlzIGdvdCBBY2tzLCBJIGZpZ3VyZSBJ IHNob3VsZCBjYXJyeSBpdCBpbiBteSB0cmVlLiBMZXQgbWUga25vdwo+Pj4+IGlmIHRoaXMgc2hv dWxkIGdvIHZpYSBkcm0gaW5zdGVhZC4KPj4+Pgo+Pj4+IEFwcGxpZWQgdG8gZm9yLW5leHQvaGFy ZGVuaW5nLCB0aGFua3MhCj4+Pj4KPj4+PiBbMS85XSBkcm0vYW1kL3BtOiBBbm5vdGF0ZSBzdHJ1 Y3Qgc211MTBfdm9sdGFnZV9kZXBlbmRlbmN5X3RhYmxlIHdpdGggX19jb3VudGVkX2J5Cj4+Pj4g ICAgICAgICBodHRwczovL2dpdC5rZXJuZWwub3JnL2tlZXMvYy9hNjA0NmFjNjU5ZDYKPj4+IFNU T1AhIEluIGEgZm9sbG93IHVwIGRpc2N1c3Npb24gQWxleCBhbmQgSSBmaWd1cmVkIG91dCB0aGF0 IHRoaXMgd29uJ3Qgd29yay4KPiBJJ20gc28gY29uZnVzZWQ7IGZyb20gdGhlIGRpc2N1c3Npb24g SSBzYXcgdGhhdCBBbGV4IHNhaWQgYm90aCBpbnN0YW5jZXMKPiB3ZXJlIGZhbHNlIHBvc2l0aXZl cz8KPgo+Pj4gVGhlIHZhbHVlIGluIHRoZSBzdHJ1Y3R1cmUgaXMgYnl0ZSBzd2FwcGVkIGJhc2Vk IG9uIHNvbWUgZmlybXdhcmUKPj4+IGVuZGlhbm5lc3Mgd2hpY2ggbm90IG5lY2Vzc2FyeSBtYXRj aGVzIHRoZSBDUFUgZW5kaWFubmVzcy4KPj4gU01VMTAgaXMgQVBVIG9ubHkgc28gdGhlIGVuZGlh bmVzcyBvZiB0aGUgU01VIGZpcm13YXJlIGFuZCB0aGUgQ1BVCj4+IHdpbGwgYWx3YXlzIG1hdGNo Lgo+IFdoaWNoIEkgdGhpbmsgaXMgd2hhdCBpcyBiZWluZyBzYWlkIGhlcmU/Cj4KPj4+IFBsZWFz ZSByZXZlcnQgdGhhdCBvbmUgZnJvbSBnb2luZyB1cHN0cmVhbSBpZiBpdCdzIGFscmVhZHkgb24g aXQncyB3YXkuCj4+Pgo+Pj4gQW5kIGJlY2F1c2Ugb2YgdGhvc2UgcmVhc29ucyBJIHN0cm9uZ2x5 IHRoaW5rIHRoYXQgcGF0Y2hlcyBsaWtlIHRoaXMKPj4+IHNob3VsZCBnbyB0aHJvdWdoIHRoZSBE Uk0gdHJlZSA6KQo+IFN1cmUsIHRoYXQncyBmaW5lIC0tIHBsZWFzZSBsZXQgbWUga25vdy4gSXQg d2FzIG90aGVycyBBY2tlZC9ldGMuIFdobwo+IHNob3VsZCBjYXJyeSB0aGVzZSBwYXRjaGVzPwoK UHJvYmFibHkgYmVzdCBpZiB0aGUgcmVsZXZhbnQgbWFpbnRhaW5lciBwaWNrIHRoZW0gdXAgaW5k aXZpZHVhbGx5LgoKU29tZSBvZiB0aG9zZSBzdHJ1Y3R1cmVzIGFyZSBmaWxsZWQgaW4gYnkgZmly bXdhcmUvaGFyZHdhcmUgYW5kIG9ubHkgdGhlIAptYWludGFpbmVycyBjYW4ganVkZ2UgaWYgdGhh dCB2YWx1ZSBhY3R1YWxseSBtYXRjaGVzIHdoYXQgdGhlIGNvbXBpbGVyIApuZWVkcy4KCldlIGhh dmUgY2FzZXMgd2hlcmUgaW5kaXZpZHVhbCBiaXRzIGFyZSB1c2VkIGFzIGZsYWdzIG9yIHdoZW4g dGhlIHNpemUgCmlzIGJ5dGUgc3dhcHBlZCBldGMuLi4KCkV2ZW4gQWxleCBhbmQgSSBkaWRuJ3Qg aW1tZWRpYXRlbHkgc2F5IGhvdyBhbmQgd2hlcmUgdGhhdCBmaWVsZCBpcyAKYWN0dWFsbHkgdXNl ZCBhbmQgaGFkIHRvIGRpZyB0aGF0IHVwLiBUaGF0J3Mgd2hlcmUgdGhlIGNvbmZ1c2lvbiBjYW1l IGZyb20uCgpSZWdhcmRzLApDaHJpc3RpYW4uCgo+Cj4gVGhhbmtzIQo+Cj4gLUtlZXMKPgo+Cj4+ PiBSZWdhcmRzLAo+Pj4gQ2hyaXN0aWFuLgo+Pj4KPj4+PiBbMi85XSBkcm0vYW1kZ3B1L2Rpc2Nv dmVyeTogQW5ub3RhdGUgc3RydWN0IGlwX2h3X2luc3RhbmNlIHdpdGggX19jb3VudGVkX2J5Cj4+ Pj4gICAgICAgICBodHRwczovL2dpdC5rZXJuZWwub3JnL2tlZXMvYy80ZGYzMzA4OWI0NmYKPj4+ PiBbMy85XSBkcm0vaTkxNS9zZWxmdGVzdHM6IEFubm90YXRlIHN0cnVjdCBwZXJmX3NlcmllcyB3 aXRoIF9fY291bnRlZF9ieQo+Pj4+ICAgICAgICAgaHR0cHM6Ly9naXQua2VybmVsLm9yZy9rZWVz L2MvZmZkM2Y4MjNiZGY2Cj4+Pj4gWzQvOV0gZHJtL21zbS9kcHU6IEFubm90YXRlIHN0cnVjdCBk cHVfaHdfaW50ciB3aXRoIF9fY291bnRlZF9ieQo+Pj4+ICAgICAgICAgaHR0cHM6Ly9naXQua2Vy bmVsLm9yZy9rZWVzL2MvMmRlMzVhOTg5Yjc2Cj4+Pj4gWzUvOV0gZHJtL25vdXZlYXUvcG06IEFu bm90YXRlIHN0cnVjdCBudmttX3BlcmZkb20gd2l0aCBfX2NvdW50ZWRfYnkKPj4+PiAgICAgICAg IGh0dHBzOi8vZ2l0Lmtlcm5lbC5vcmcva2Vlcy9jLzE4OGFlYjA4YmZhYQo+Pj4+IFs2LzldIGRy bS92YzQ6IEFubm90YXRlIHN0cnVjdCB2YzRfcGVyZm1vbiB3aXRoIF9fY291bnRlZF9ieQo+Pj4+ ICAgICAgICAgaHR0cHM6Ly9naXQua2VybmVsLm9yZy9rZWVzL2MvNTlhNTRkYzg5NmMzCj4+Pj4g WzcvOV0gZHJtL3ZpcnRpbzogQW5ub3RhdGUgc3RydWN0IHZpcnRpb19ncHVfb2JqZWN0X2FycmF5 IHdpdGggX19jb3VudGVkX2J5Cj4+Pj4gICAgICAgICBodHRwczovL2dpdC5rZXJuZWwub3JnL2tl ZXMvYy81Y2Q0NzZkZTMzYWYKPj4+PiBbOC85XSBkcm0vdm13Z2Z4OiBBbm5vdGF0ZSBzdHJ1Y3Qg dm13X3N1cmZhY2VfZGlydHkgd2l0aCBfX2NvdW50ZWRfYnkKPj4+PiAgICAgICAgIGh0dHBzOi8v Z2l0Lmtlcm5lbC5vcmcva2Vlcy9jL2I0MjZmMmU1MzU2YQo+Pj4+IFs5LzldIGRybS92M2Q6IEFu bm90YXRlIHN0cnVjdCB2M2RfcGVyZm1vbiB3aXRoIF9fY291bnRlZF9ieQo+Pj4+ICAgICAgICAg aHR0cHM6Ly9naXQua2VybmVsLm9yZy9rZWVzL2MvZGM2NjJmYTFiMGU0Cj4+Pj4KPj4+PiBUYWtl IGNhcmUsCj4+Pj4KCl9fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19f X19fClZpcnR1YWxpemF0aW9uIG1haWxpbmcgbGlzdApWaXJ0dWFsaXphdGlvbkBsaXN0cy5saW51 eC1mb3VuZGF0aW9uLm9yZwpodHRwczovL2xpc3RzLmxpbnV4Zm91bmRhdGlvbi5vcmcvbWFpbG1h bi9saXN0aW5mby92aXJ0dWFsaXphdGlvbg== From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from gabe.freedesktop.org (gabe.freedesktop.org [131.252.210.177]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.lore.kernel.org (Postfix) with ESMTPS id 5ADAFE74906 for ; Mon, 2 Oct 2023 18:02:15 +0000 (UTC) Received: from gabe.freedesktop.org (localhost [127.0.0.1]) by gabe.freedesktop.org (Postfix) with ESMTP id 6352610E0C3; Mon, 2 Oct 2023 18:02:08 +0000 (UTC) Received: from mail-wr1-x435.google.com (mail-wr1-x435.google.com [IPv6:2a00:1450:4864:20::435]) by gabe.freedesktop.org (Postfix) with ESMTPS id 9D1B610E063; Mon, 2 Oct 2023 18:02:05 +0000 (UTC) Received: by mail-wr1-x435.google.com with SMTP id ffacd0b85a97d-3226cc3e324so73801f8f.3; Mon, 02 Oct 2023 11:02:05 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20230601; t=1696269724; x=1696874524; darn=lists.freedesktop.org; h=content-transfer-encoding:in-reply-to:from:references:cc:to :content-language:subject:user-agent:mime-version:date:message-id :from:to:cc:subject:date:message-id:reply-to; bh=zam6JpvTJFSRB7Mf1N6WASAM0s+ax1vMTASmJwGp/GQ=; b=OWyGp/gEByRgyM4MY9Ye5RpslnTSZ2ikYlWyXs3wBpkwUYLljzKUnb32PT8SD96zdT ILULchDT9/U+v9c8aHQL5z4depnGr/yKc7Me1ifAZvHB6o4ioQw3fNmTK1GVSR1RzaMK rgcREADI3fgdEFUTvBcRnpJ1KjvpQliCjIzQPxbAXMcRvZhTfiPjaMt7eNh1l6p+5VeD Z6+nutPI/hL9cPvvVllnmrfTka6dUMiaFg0L1BAvQ01a1Q1RgnbFTcicnFQg4J5HxSvq JzqkXyGtVvSedD8GnIeQZx1+J19IFgZh2qCOdhccJ9OdMjJ+VoufRo5eIbAiCDyXIzEL yqnQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1696269724; x=1696874524; h=content-transfer-encoding:in-reply-to:from:references:cc:to :content-language:subject:user-agent:mime-version:date:message-id :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to; bh=zam6JpvTJFSRB7Mf1N6WASAM0s+ax1vMTASmJwGp/GQ=; b=jHuvBE1XxLQvua1CvNxPd+fRhVQIkz58FSV/NAuuxWFqijsKeg2KCRCrSWyS71NWcD PpECTy5zrPziq9S5ySWNIaJ12KITuExm6/YB2lruuc+buVWbPEkDPeaNBjQcLHIeO/pu Zxp6R9Ble0STZJf7z23U7oRXdLa/R18prlxxra+CwTVPkcviNEU6Z7l/PecPrGGhHSPa 7N1rA9uoDSIbpTUjF25eNwObVyK++RcrPPKeuEpCTVcGH0tgS2LgQXlEjqTmHsANlMXy tehvV/svFA7pLgQcRopyfCA+sp9pgCsPpqjt7dE1ngEK8YCsylupAJyOWz6+qD2umzb8 JVHQ== X-Gm-Message-State: AOJu0Yz/rNVvj6AZ2v82S6l1HCxEFNAFVDkISa5ec4FfINH5TyatZJyt obBQuyFmMHjQ9d3tq9YnOIs= X-Google-Smtp-Source: AGHT+IHXROz9dJDWlLZd0E9oyaIxp9J/Vso2ikdsfsbdxkJUFVX9OGXOEmAj9p/hMQ4gi+RMtS0pLQ== X-Received: by 2002:adf:d4c2:0:b0:317:ddd3:1aed with SMTP id w2-20020adfd4c2000000b00317ddd31aedmr10422745wrk.68.1696269723540; Mon, 02 Oct 2023 11:02:03 -0700 (PDT) Received: from [10.254.108.106] (munvpn.amd.com. [165.204.72.6]) by smtp.gmail.com with ESMTPSA id g16-20020adfa490000000b003232380ffd5sm20650839wrb.106.2023.10.02.11.01.59 (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Mon, 02 Oct 2023 11:02:02 -0700 (PDT) Message-ID: <10644b5f-b0a7-85ef-0658-2353ee14df0d@gmail.com> Date: Mon, 2 Oct 2023 20:01:57 +0200 MIME-Version: 1.0 User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:102.0) Gecko/20100101 Thunderbird/102.15.1 Subject: Re: [PATCH 0/9] drm: Annotate structs with __counted_by Content-Language: en-US To: Kees Cook , Alex Deucher References: <20230922173110.work.084-kees@kernel.org> <169601600138.3014939.8511343741428844249.b4-ty@chromium.org> <83cd056c-52ae-01dd-7576-42d41da64c26@gmail.com> <202310020952.E7DE0948C0@keescook> From: =?UTF-8?Q?Christian_K=c3=b6nig?= In-Reply-To: <202310020952.E7DE0948C0@keescook> Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: 8bit X-BeenThere: dri-devel@lists.freedesktop.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: Direct Rendering Infrastructure - Development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Cc: Tejas Upadhyay , Emma Anholt , Tom Rix , llvm@lists.linux.dev, dri-devel@lists.freedesktop.org, Chris Wilson , Prike Liang , Huang Rui , Gerd Hoffmann , Andrzej Hajda , Marijn Suijten , Matthew Brost , Karol Herbst , Neil Armstrong , amd-gfx@lists.freedesktop.org, Kuogee Hsieh , VMware Graphics Reviewers , Ben Skeggs , Andi Shyti , nouveau@lists.freedesktop.org, David Airlie , virtualization@lists.linux-foundation.org, linux-hardening@vger.kernel.org, Alex Deucher , Lijo Lazar , Tvrtko Ursulin , linux-arm-msm@vger.kernel.org, intel-gfx@lists.freedesktop.org, Kevin Wang , Abhinav Kumar , Nathan Chancellor , Le Ma , Gurchetan Singh , Maxime Ripard , Rodrigo Vivi , Evan Quan , Sean Paul , Yifan Zhang , Xiaojian Du , freedreno@lists.freedesktop.org, Bjorn Andersson , "Pan, Xinhui" , Nick Desaulniers , linux-kernel@vger.kernel.org, Melissa Wen , Dmitry Baryshkov , Nirmoy Das , Lang Yu , =?UTF-8?Q?Christian_K=c3=b6nig?= , John Harrison , Hawking Zhang Errors-To: dri-devel-bounces@lists.freedesktop.org Sender: "dri-devel" Am 02.10.23 um 18:53 schrieb Kees Cook: > On Mon, Oct 02, 2023 at 11:06:19AM -0400, Alex Deucher wrote: >> On Mon, Oct 2, 2023 at 5:20 AM Christian König >> wrote: >>> Am 29.09.23 um 21:33 schrieb Kees Cook: >>>> On Fri, 22 Sep 2023 10:32:05 -0700, Kees Cook wrote: >>>>> This is a batch of patches touching drm for preparing for the coming >>>>> implementation by GCC and Clang of the __counted_by attribute. Flexible >>>>> array members annotated with __counted_by can have their accesses >>>>> bounds-checked at run-time checking via CONFIG_UBSAN_BOUNDS (for array >>>>> indexing) and CONFIG_FORTIFY_SOURCE (for strcpy/memcpy-family functions). >>>>> >>>>> As found with Coccinelle[1], add __counted_by to structs that would >>>>> benefit from the annotation. >>>>> >>>>> [...] >>>> Since this got Acks, I figure I should carry it in my tree. Let me know >>>> if this should go via drm instead. >>>> >>>> Applied to for-next/hardening, thanks! >>>> >>>> [1/9] drm/amd/pm: Annotate struct smu10_voltage_dependency_table with __counted_by >>>> https://git.kernel.org/kees/c/a6046ac659d6 >>> STOP! In a follow up discussion Alex and I figured out that this won't work. > I'm so confused; from the discussion I saw that Alex said both instances > were false positives? > >>> The value in the structure is byte swapped based on some firmware >>> endianness which not necessary matches the CPU endianness. >> SMU10 is APU only so the endianess of the SMU firmware and the CPU >> will always match. > Which I think is what is being said here? > >>> Please revert that one from going upstream if it's already on it's way. >>> >>> And because of those reasons I strongly think that patches like this >>> should go through the DRM tree :) > Sure, that's fine -- please let me know. It was others Acked/etc. Who > should carry these patches? Probably best if the relevant maintainer pick them up individually. Some of those structures are filled in by firmware/hardware and only the maintainers can judge if that value actually matches what the compiler needs. We have cases where individual bits are used as flags or when the size is byte swapped etc... Even Alex and I didn't immediately say how and where that field is actually used and had to dig that up. That's where the confusion came from. Regards, Christian. > > Thanks! > > -Kees > > >>> Regards, >>> Christian. >>> >>>> [2/9] drm/amdgpu/discovery: Annotate struct ip_hw_instance with __counted_by >>>> https://git.kernel.org/kees/c/4df33089b46f >>>> [3/9] drm/i915/selftests: Annotate struct perf_series with __counted_by >>>> https://git.kernel.org/kees/c/ffd3f823bdf6 >>>> [4/9] drm/msm/dpu: Annotate struct dpu_hw_intr with __counted_by >>>> https://git.kernel.org/kees/c/2de35a989b76 >>>> [5/9] drm/nouveau/pm: Annotate struct nvkm_perfdom with __counted_by >>>> https://git.kernel.org/kees/c/188aeb08bfaa >>>> [6/9] drm/vc4: Annotate struct vc4_perfmon with __counted_by >>>> https://git.kernel.org/kees/c/59a54dc896c3 >>>> [7/9] drm/virtio: Annotate struct virtio_gpu_object_array with __counted_by >>>> https://git.kernel.org/kees/c/5cd476de33af >>>> [8/9] drm/vmwgfx: Annotate struct vmw_surface_dirty with __counted_by >>>> https://git.kernel.org/kees/c/b426f2e5356a >>>> [9/9] drm/v3d: Annotate struct v3d_perfmon with __counted_by >>>> https://git.kernel.org/kees/c/dc662fa1b0e4 >>>> >>>> Take care, >>>>