The 'struct dma_fence_array' holds a pointer field 'fences' that points to an array of 'dma_fence' pointers, and its element count is stored in the 'num_fences' field within the same structure.
Annotate 'fences' with the '__counted_by_ptr' attribute to allow compilers supporting this attribute to perform runtime bounds checking via KASAN and '__builtin_dynamic_object_size'. The structure is allocated in 'dma_fence_array_alloc()' which initializes all fields, including 'fences' and 'num_fences', to zero. The structure is initialized in 'dma_fence_array_init()'. Cc: [email protected] Assisted-by: LLM Signed-off-by: Bill Wendling <[email protected]> --- include/linux/dma-fence-array.h | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/include/linux/dma-fence-array.h b/include/linux/dma-fence-array.h index 0c49d7ccefb6..85e5879e8a1e 100644 --- a/include/linux/dma-fence-array.h +++ b/include/linux/dma-fence-array.h @@ -39,7 +39,7 @@ struct dma_fence_array { unsigned num_fences; atomic_t num_pending; - struct dma_fence **fences; + struct dma_fence **fences __counted_by_ptr(num_fences); struct irq_work work; -- 2.56.0.rc1.315.gc6ed9934b7-goog

