On Tue, Sep 22, 2026 at 10:09:50PM +0000, Bill Wendling wrote:
> Under compiler-supported bounds checking (via KASAN or UBSAN), pointer
> fields inside structures can be annotated with the '__counted_by_ptr'
> attribute to specify which field in the same structure holds the element
> count. This enables the compiler to perform runtime bounds checking on
> the pointer.
>
> Annotate the "base" pointer field in "struct adc5_device_data" with the
> "__counted_by_ptr" attribute pointing to "num_sdams". The number of
> SDAMs is determined from the device property and assigned to "num_sdams"
> which is then used to initialize "base" via "devm_kcalloc".
>
> By ensuring "num_sdams" is set to the correct element count prior to
> the "base" pointer allocation, and since the size of "base" is never
> reallocated or changed, this annotation is safe and will not cause any
> false-positive runtime bounds check panics or KASAN issues.
Welp, yes, it's allocated correctly to the size. It'll be interesting to
see if this:
ret = device_property_count_u32(dev, "reg");
if (ret < 0)
return ret;
adc->dev_data.num_sdams = ret;
is never at odds with this:
ret = devm_request_threaded_irq(dev,
adc->dev_data.base[ADC5_GEN3_VADC_SDAM].irq,
NULL, adc5_gen3_isr, IRQF_ONESHOT |
IRQF_SHARED,
adc->dev_data.base[ADC5_GEN3_VADC_SDAM].irq_name,
adc);
Nothing checks that num_sdams >= ADC5_GEN3_VADC_SDAM (0). I feel like
that ret = device_property_count_u32 should check for < 1 :)
--
Kees Cook