On Wed, 23 Sep 2026 14:48:24 +0900
"Gustavo A. R. Silva" <[email protected]> wrote:

> On 9/23/26 13:28, Bill Wendling wrote:
> > In 'struct iio_dev', the 'channels' pointer refers to an array of IIO
> > channel specifications ('struct iio_chan_spec const'), and the size of
> > this array is tracked by the 'num_channels' field within the same
> > struct.
> > 
> > Applying the '__counted_by_ptr' attribute to 'channels' allows KASAN
> > and compiler-based bounds checkers to verify that accesses to 'channels'
> > remain within bounds at runtime.
> > 
> > Cc: [email protected]
> > Assisted-by: LLM
> > Signed-off-by: Bill Wendling <[email protected]>  
> 
> Reviewed-by: Gustavo A. R. Silva <[email protected]>
> 
> Thanks
> -Gustavo
> 
> > ---
> >   include/linux/iio/iio.h | 2 +-
> >   1 file changed, 1 insertion(+), 1 deletion(-)
> > 
> > diff --git a/include/linux/iio/iio.h b/include/linux/iio/iio.h
> > index 711c00f67371..20505139a61b 100644
> > --- a/include/linux/iio/iio.h
> > +++ b/include/linux/iio/iio.h
> > @@ -648,7 +648,7 @@ struct iio_dev {
> >     struct iio_poll_func            *pollfunc;
> >     struct iio_poll_func            *pollfunc_event;
> >   
> > -   struct iio_chan_spec const      *channels;
> > +   struct iio_chan_spec const      *channels 
> > __counted_by_ptr(num_channels);
> >     int                             num_channels;
> >   
> >     const char                      *name;  
> 

Will be interesting to see if this shakes anything loose.
It's reasonably common for channels to actually point to a larger
array as some variant of a device only has a subset of channels.
Hopefully no driver is using that to be sneaky!

Anyhow, looks good to me.

Applied.

thanks,

Jonathan

Reply via email to