From: Li Chen <me@linux.beauty>
To: Kees Cook <kees@kernel.org>,
Nathan Chancellor <nathan@kernel.org>,
Nicolas Schier <nicolas.schier@linux.dev>,
linux-kernel@vger.kernel.org, linux-hardening@vger.kernel.org,
linux-kbuild@vger.kernel.org
Subject: [RFC PATCH 1/2] gcc-plugins: add cleanup_plugin for uninitialized cleanup detection
Date: Wed, 5 Nov 2025 16:46:56 +0800 [thread overview]
Message-ID: <20251105084733.3598704-6-me@linux.beauty> (raw)
In-Reply-To: <20251105084733.3598704-1-me@linux.beauty>
From: Li Chen <chenl311@chinatelecom.cn>
Add a GCC plugin to warn about uninitialized automatic variables with
cleanup attributes. This helps catch this potential interdependency problem
as documented in include/linux/cleanup.h.
The plugin detects uninitialized cleanup variables and warns developers
without blocking builds (warnings are not converted to errors by -Werror).
Signed-off-by: Li Chen <chenl311@chinatelecom.cn>
---
scripts/Makefile.gcc-plugins | 1 +
scripts/gcc-plugins/Kconfig | 6 ++
scripts/gcc-plugins/cleanup_plugin.c | 106 +++++++++++++++++++++++++++
3 files changed, 113 insertions(+)
create mode 100644 scripts/gcc-plugins/cleanup_plugin.c
diff --git a/scripts/Makefile.gcc-plugins b/scripts/Makefile.gcc-plugins
index b0e1423b09c21..b948261c142e6 100644
--- a/scripts/Makefile.gcc-plugins
+++ b/scripts/Makefile.gcc-plugins
@@ -1,5 +1,6 @@
# SPDX-License-Identifier: GPL-2.0
+gcc-plugin-$(CONFIG_GCC_PLUGIN_CLEANUP_ATTRIBUTE_WARN) += cleanup_plugin.so
gcc-plugin-$(CONFIG_GCC_PLUGIN_LATENT_ENTROPY) += latent_entropy_plugin.so
gcc-plugin-cflags-$(CONFIG_GCC_PLUGIN_LATENT_ENTROPY) \
+= -DLATENT_ENTROPY_PLUGIN
diff --git a/scripts/gcc-plugins/Kconfig b/scripts/gcc-plugins/Kconfig
index 6b34ba19358d8..906d50eb5efa6 100644
--- a/scripts/gcc-plugins/Kconfig
+++ b/scripts/gcc-plugins/Kconfig
@@ -36,4 +36,10 @@ config GCC_PLUGIN_LATENT_ENTROPY
* https://grsecurity.net/
* https://pax.grsecurity.net/
+config GCC_PLUGIN_CLEANUP_ATTRIBUTE_WARN
+ def_bool y
+ help
+ Warn when local automatic variables annotated with
+ __attribute__((cleanup(...))) are declared without an initializer.
+
endif
diff --git a/scripts/gcc-plugins/cleanup_plugin.c b/scripts/gcc-plugins/cleanup_plugin.c
new file mode 100644
index 0000000000000..d28f8969186de
--- /dev/null
+++ b/scripts/gcc-plugins/cleanup_plugin.c
@@ -0,0 +1,106 @@
+// SPDX-License-Identifier: GPL-2.0
+/*
+ * Warn about uninitialized automatic variables that use the
+ * __attribute__((cleanup(...))) attribute.
+ */
+
+#include "gcc-common.h"
+
+__visible int plugin_is_GPL_compatible;
+
+static struct plugin_info cleanup_plugin_info = {
+ .version = PLUGIN_VERSION,
+ .help = "Warn when cleanup attribute variables lack initializers\n",
+};
+
+static bool has_cleanup_attribute(tree var)
+{
+ tree attrs;
+
+ attrs = DECL_ATTRIBUTES(var);
+ if (!attrs)
+ return false;
+
+ return lookup_attribute("cleanup", attrs) != NULL_TREE;
+}
+
+static bool is_candidate_decl(tree var)
+{
+ if (TREE_CODE(var) != VAR_DECL)
+ return false;
+
+ if (DECL_ARTIFICIAL(var))
+ return false;
+
+ if (TREE_STATIC(var) || DECL_EXTERNAL(var))
+ return false;
+
+ if (!has_cleanup_attribute(var))
+ return false;
+
+ return true;
+}
+
+static bool has_declaration_initializer(tree var)
+{
+ if (DECL_INITIAL(var))
+ return true;
+
+#ifdef DECL_INITIALIZED_P
+ if (DECL_INITIALIZED_P(var))
+ return true;
+#endif
+
+ return false;
+}
+
+static void warn_if_uninitialized(tree var)
+{
+ location_t loc;
+ bool saved_warning_as_error;
+
+ if (has_declaration_initializer(var))
+ return;
+
+ loc = DECL_SOURCE_LOCATION(var);
+ if (loc == UNKNOWN_LOCATION)
+ return;
+
+ /* Temporarily disable treating warnings as errors for this specific warning */
+ saved_warning_as_error = global_dc->warning_as_error_requested_p();
+ global_dc->set_warning_as_error_requested(false);
+ warning_at(
+ loc, 0,
+ "%qD declared with cleanup attribute is not initialized at declaration",
+ var);
+ /* Restore the original setting */
+ global_dc->set_warning_as_error_requested(saved_warning_as_error);
+}
+
+static void cleanup_finish_decl(void *gcc_data, void *user_data)
+{
+ tree var = (tree)gcc_data;
+
+ (void)user_data;
+
+ if (!is_candidate_decl(var))
+ return;
+
+ warn_if_uninitialized(var);
+}
+
+__visible int plugin_init(struct plugin_name_args *plugin_info,
+ struct plugin_gcc_version *version)
+{
+ if (!plugin_default_version_check(version, &gcc_version)) {
+ error(G_("incompatible gcc/plugin versions"));
+ return 1;
+ }
+
+ register_callback(plugin_info->base_name, PLUGIN_INFO, NULL,
+ &cleanup_plugin_info);
+ register_callback(plugin_info->base_name, PLUGIN_FINISH_DECL,
+ cleanup_finish_decl, NULL);
+
+ return 0;
+}
--
2.51.0
next prev parent reply other threads:[~2025-11-05 8:48 UTC|newest]
Thread overview: 13+ messages / expand[flat|nested] mbox.gz Atom feed top
2025-11-05 8:46 [PATCH 0/3] dm-pcache: built-in support and metadata hardening Li Chen
2025-11-05 8:46 ` [PATCH 1/3] dm-pcache: allow built-in build and rename flush helper Li Chen
2025-11-05 8:46 ` [PATCH 2/3] dm-pcache: reuse meta_addr in pcache_meta_find_latest Li Chen
2025-11-05 8:46 ` [PATCH 3/3] dm-pcache: avoid leaking invalid metadata in pcache_meta_find_latest() Li Chen
2025-11-10 11:18 ` Dongsheng Yang
2025-11-10 12:32 ` Li Chen
2025-11-05 8:46 ` [RFC PATCH 0/2] Add cleanup_plugin for detecting problematic cleanup patterns Li Chen
2025-11-05 9:04 ` Li Chen
2025-11-05 9:49 ` Peter Zijlstra
2025-11-05 14:52 ` Li Chen
2025-11-05 8:46 ` Li Chen [this message]
2025-11-05 8:46 ` [RFC PATCH 2/2] gcc-plugins: cleanup_plugin: detect NULL init Li Chen
2025-11-05 12:41 ` [PATCH 0/3] dm-pcache: built-in support and metadata hardening Li Chen
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20251105084733.3598704-6-me@linux.beauty \
--to=me@linux.beauty \
--cc=kees@kernel.org \
--cc=linux-hardening@vger.kernel.org \
--cc=linux-kbuild@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=nathan@kernel.org \
--cc=nicolas.schier@linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox