On 28/09/2026 5:45 am, Bill Wendling wrote:
Annotate the 'cache' pointer member of 'struct cs_dsp_coeff_ctl' with
the '__counted_by_ptr' attribute. This allows the compiler and KASAN
to perform run-time bounds checking on accesses to the 'cache' buffer,
preventing potential out-of-bounds reads or writes.
The 'cache' pointer points to a buffer of size 'len' bytes, allocated
to hold the cached value of a DSP coefficient control. The 'cache' and
'len' are initialized in 'cs_dsp_create_control()'.
Every subsequent access to 'ctl->cache' is strictly validated to
Is that true?
When I last looked at these __counted_by they were only checked by
a subset of library functions (which was documented) so I was still
able to write code that overran the buffer.
However, recent compilers might do more checking now.
Reviewed-by: Richard Fitzgerald <[email protected]>