accel/ivpu: Annotate struct ivpu_job with __counted_by
authorKees Cook <keescook@chromium.org>
Fri, 22 Sep 2023 17:54:17 +0000 (10:54 -0700)
committerKees Cook <keescook@chromium.org>
Thu, 28 Sep 2023 23:39:08 +0000 (16:39 -0700)
Prepare for the coming implementation by GCC and Clang of the __counted_by
attribute. Flexible array members annotated with __counted_by can have
their accesses bounds-checked at run-time checking via CONFIG_UBSAN_BOUNDS
(for array indexing) and CONFIG_FORTIFY_SOURCE (for strcpy/memcpy-family
functions).

As found with Coccinelle[1], add __counted_by for struct ivpu_job.

[1] https://github.com/kees/kernel-tools/blob/trunk/coccinelle/examples/counted_by.cocci

Cc: Jacek Lawrynowicz <jacek.lawrynowicz@linux.intel.com>
Cc: Stanislaw Gruszka <stanislaw.gruszka@linux.intel.com>
Cc: Oded Gabbay <ogabbay@kernel.org>
Cc: Nathan Chancellor <nathan@kernel.org>
Cc: Nick Desaulniers <ndesaulniers@google.com>
Cc: Tom Rix <trix@redhat.com>
Cc: dri-devel@lists.freedesktop.org
Cc: llvm@lists.linux.dev
Reviewed-by: Stanislaw Gruszka <stanislaw.gruszka@linux.intel.com>
Link: https://lore.kernel.org/r/20230922175416.work.272-kees@kernel.org
Signed-off-by: Kees Cook <keescook@chromium.org>
drivers/accel/ivpu/ivpu_job.h

index aa1f0b9479b0b2b7d1e7965b2f51709653ac959d..5514c2d8a6096d7253f87687f7d83b6aaaa9ceca 100644 (file)
@@ -51,7 +51,7 @@ struct ivpu_job {
        u32 job_id;
        u32 engine_idx;
        size_t bo_count;
-       struct ivpu_bo *bos[];
+       struct ivpu_bo *bos[] __counted_by(bo_count);
 };
 
 int ivpu_submit_ioctl(struct drm_device *dev, void *data, struct drm_file *file);