Linux Hardening
 help / color / mirror / Atom feed
* [PATCH] iio: add __counted_by_ptr attribute to channels in struct iio_dev
@ 2026-09-23  4:28 Bill Wendling
  2026-09-23  5:48 ` Gustavo A. R. Silva
  0 siblings, 1 reply; 3+ messages in thread
From: Bill Wendling @ 2026-09-23  4:28 UTC (permalink / raw)
  To: Jonathan Cameron
  Cc: David Lechner, Nuno Sá, Andy Shevchenko, Kees Cook,
	Gustavo A. R. Silva, linux-iio, linux-kernel, linux-hardening,
	Bill Wendling, codemender-patching+linux

In 'struct iio_dev', the 'channels' pointer refers to an array of IIO
channel specifications ('struct iio_chan_spec const'), and the size of
this array is tracked by the 'num_channels' field within the same
struct.

Applying the '__counted_by_ptr' attribute to 'channels' allows KASAN
and compiler-based bounds checkers to verify that accesses to 'channels'
remain within bounds at runtime.

Cc: codemender-patching+linux@google.com
Assisted-by: LLM
Signed-off-by: Bill Wendling <morbo@google.com>
---
 include/linux/iio/iio.h | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/include/linux/iio/iio.h b/include/linux/iio/iio.h
index 711c00f67371..20505139a61b 100644
--- a/include/linux/iio/iio.h
+++ b/include/linux/iio/iio.h
@@ -648,7 +648,7 @@ struct iio_dev {
 	struct iio_poll_func		*pollfunc;
 	struct iio_poll_func		*pollfunc_event;
 
-	struct iio_chan_spec const	*channels;
+	struct iio_chan_spec const	*channels __counted_by_ptr(num_channels);
 	int				num_channels;
 
 	const char			*name;
-- 
2.55.0.1082.g2b9226bbc0-goog


^ permalink raw reply related	[flat|nested] 3+ messages in thread

* Re: [PATCH] iio: add __counted_by_ptr attribute to channels in struct iio_dev
  2026-09-23  4:28 [PATCH] iio: add __counted_by_ptr attribute to channels in struct iio_dev Bill Wendling
@ 2026-09-23  5:48 ` Gustavo A. R. Silva
  2026-09-25  2:45   ` Jonathan Cameron
  0 siblings, 1 reply; 3+ messages in thread
From: Gustavo A. R. Silva @ 2026-09-23  5:48 UTC (permalink / raw)
  To: Bill Wendling, Jonathan Cameron
  Cc: David Lechner, Nuno Sá, Andy Shevchenko, Kees Cook,
	Gustavo A. R. Silva, linux-iio, linux-kernel, linux-hardening,
	codemender-patching+linux



On 9/23/26 13:28, Bill Wendling wrote:
> In 'struct iio_dev', the 'channels' pointer refers to an array of IIO
> channel specifications ('struct iio_chan_spec const'), and the size of
> this array is tracked by the 'num_channels' field within the same
> struct.
> 
> Applying the '__counted_by_ptr' attribute to 'channels' allows KASAN
> and compiler-based bounds checkers to verify that accesses to 'channels'
> remain within bounds at runtime.
> 
> Cc: codemender-patching+linux@google.com
> Assisted-by: LLM
> Signed-off-by: Bill Wendling <morbo@google.com>

Reviewed-by: Gustavo A. R. Silva <gustavoars@kernel.org>

Thanks
-Gustavo

> ---
>   include/linux/iio/iio.h | 2 +-
>   1 file changed, 1 insertion(+), 1 deletion(-)
> 
> diff --git a/include/linux/iio/iio.h b/include/linux/iio/iio.h
> index 711c00f67371..20505139a61b 100644
> --- a/include/linux/iio/iio.h
> +++ b/include/linux/iio/iio.h
> @@ -648,7 +648,7 @@ struct iio_dev {
>   	struct iio_poll_func		*pollfunc;
>   	struct iio_poll_func		*pollfunc_event;
>   
> -	struct iio_chan_spec const	*channels;
> +	struct iio_chan_spec const	*channels __counted_by_ptr(num_channels);
>   	int				num_channels;
>   
>   	const char			*name;


^ permalink raw reply	[flat|nested] 3+ messages in thread

* Re: [PATCH] iio: add __counted_by_ptr attribute to channels in struct iio_dev
  2026-09-23  5:48 ` Gustavo A. R. Silva
@ 2026-09-25  2:45   ` Jonathan Cameron
  0 siblings, 0 replies; 3+ messages in thread
From: Jonathan Cameron @ 2026-09-25  2:45 UTC (permalink / raw)
  To: Gustavo A. R. Silva
  Cc: Bill Wendling, David Lechner, Nuno Sá, Andy Shevchenko,
	Kees Cook, Gustavo A. R. Silva, linux-iio, linux-kernel,
	linux-hardening, codemender-patching+linux

On Wed, 23 Sep 2026 14:48:24 +0900
"Gustavo A. R. Silva" <gustavo@embeddedor.com> wrote:

> On 9/23/26 13:28, Bill Wendling wrote:
> > In 'struct iio_dev', the 'channels' pointer refers to an array of IIO
> > channel specifications ('struct iio_chan_spec const'), and the size of
> > this array is tracked by the 'num_channels' field within the same
> > struct.
> > 
> > Applying the '__counted_by_ptr' attribute to 'channels' allows KASAN
> > and compiler-based bounds checkers to verify that accesses to 'channels'
> > remain within bounds at runtime.
> > 
> > Cc: codemender-patching+linux@google.com
> > Assisted-by: LLM
> > Signed-off-by: Bill Wendling <morbo@google.com>  
> 
> Reviewed-by: Gustavo A. R. Silva <gustavoars@kernel.org>
> 
> Thanks
> -Gustavo
> 
> > ---
> >   include/linux/iio/iio.h | 2 +-
> >   1 file changed, 1 insertion(+), 1 deletion(-)
> > 
> > diff --git a/include/linux/iio/iio.h b/include/linux/iio/iio.h
> > index 711c00f67371..20505139a61b 100644
> > --- a/include/linux/iio/iio.h
> > +++ b/include/linux/iio/iio.h
> > @@ -648,7 +648,7 @@ struct iio_dev {
> >   	struct iio_poll_func		*pollfunc;
> >   	struct iio_poll_func		*pollfunc_event;
> >   
> > -	struct iio_chan_spec const	*channels;
> > +	struct iio_chan_spec const	*channels __counted_by_ptr(num_channels);
> >   	int				num_channels;
> >   
> >   	const char			*name;  
> 

Will be interesting to see if this shakes anything loose.
It's reasonably common for channels to actually point to a larger
array as some variant of a device only has a subset of channels.
Hopefully no driver is using that to be sneaky!

Anyhow, looks good to me.

Applied.

thanks,

Jonathan

^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2026-09-25  2:45 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-23  4:28 [PATCH] iio: add __counted_by_ptr attribute to channels in struct iio_dev Bill Wendling
2026-09-23  5:48 ` Gustavo A. R. Silva
2026-09-25  2:45   ` Jonathan Cameron

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox