On Tue, Sep 22, 2026 at 10:09:50PM +0000, Bill Wendling wrote:
> Under compiler-supported bounds checking (via KASAN or UBSAN), pointer
> fields inside structures can be annotated with the '__counted_by_ptr'
> attribute to specify which field in the same structure holds the element
> count. This enables the compiler to perform runtime bounds checking on
> the pointer.
> 
> Annotate the "base" pointer field in "struct adc5_device_data" with the
> "__counted_by_ptr" attribute pointing to "num_sdams". The number of
> SDAMs is determined from the device property and assigned to "num_sdams"
> which is then used to initialize "base" via "devm_kcalloc".
> 
> By ensuring "num_sdams" is set to the correct element count prior to
> the "base" pointer allocation, and since the size of "base" is never
> reallocated or changed, this annotation is safe and will not cause any
> false-positive runtime bounds check panics or KASAN issues.

Welp, yes, it's allocated correctly to the size. It'll be interesting to
see if this:

        ret = device_property_count_u32(dev, "reg");
        if (ret < 0)
                return ret;

        adc->dev_data.num_sdams = ret;

is never at odds with this:

        ret = devm_request_threaded_irq(dev, 
adc->dev_data.base[ADC5_GEN3_VADC_SDAM].irq,
                                        NULL, adc5_gen3_isr, IRQF_ONESHOT | 
IRQF_SHARED,
                                        
adc->dev_data.base[ADC5_GEN3_VADC_SDAM].irq_name,
                                        adc);

Nothing checks that num_sdams >= ADC5_GEN3_VADC_SDAM (0). I feel like
that ret = device_property_count_u32 should check for < 1 :)


-- 
Kees Cook

Reply via email to