The 'struct dma_fence_array' holds a pointer field 'fences' that points
to an array of 'dma_fence' pointers, and its element count is stored in
the 'num_fences' field within the same structure.

Annotate 'fences' with the '__counted_by_ptr' attribute to allow
compilers supporting this attribute to perform runtime bounds checking
via KASAN and '__builtin_dynamic_object_size'.

The structure is allocated in 'dma_fence_array_alloc()' which
initializes all fields, including 'fences' and 'num_fences', to zero.
The structure is initialized in 'dma_fence_array_init()'.

Cc: [email protected]
Assisted-by: LLM
Signed-off-by: Bill Wendling <[email protected]>
---
 include/linux/dma-fence-array.h | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/include/linux/dma-fence-array.h b/include/linux/dma-fence-array.h
index 0c49d7ccefb6..85e5879e8a1e 100644
--- a/include/linux/dma-fence-array.h
+++ b/include/linux/dma-fence-array.h
@@ -39,7 +39,7 @@ struct dma_fence_array {
 
        unsigned num_fences;
        atomic_t num_pending;
-       struct dma_fence **fences;
+       struct dma_fence **fences __counted_by_ptr(num_fences);
 
        struct irq_work work;
 
-- 
2.56.0.rc1.315.gc6ed9934b7-goog


Reply via email to