Annotate the 'cache' pointer member of 'struct cs_dsp_coeff_ctl' with
the '__counted_by_ptr' attribute. This allows the compiler and KASAN
to perform run-time bounds checking on accesses to the 'cache' buffer,
preventing potential out-of-bounds reads or writes.

The 'cache' pointer points to a buffer of size 'len' bytes, allocated
to hold the cached value of a DSP coefficient control. The 'cache' and
'len' are initialized in 'cs_dsp_create_control()'.

Every subsequent access to 'ctl->cache' is strictly validated to
ensure that it lies within the bounds of 'ctl->len'.

Cc: [email protected]
Assisted-by: LLM
Signed-off-by: Bill Wendling <[email protected]>
---
 include/linux/firmware/cirrus/cs_dsp.h | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/include/linux/firmware/cirrus/cs_dsp.h 
b/include/linux/firmware/cirrus/cs_dsp.h
index 4e3baa557068..6aa1e1b2b4a5 100644
--- a/include/linux/firmware/cirrus/cs_dsp.h
+++ b/include/linux/firmware/cirrus/cs_dsp.h
@@ -96,7 +96,7 @@ struct cs_dsp_alg_region {
 struct cs_dsp_coeff_ctl {
        struct list_head list;
        struct cs_dsp *dsp;
-       void *cache;
+       void *cache __counted_by_ptr(len);
        const char *fw_name;
        /* Subname is needed to match with firmware */
        const char *subname;
-- 
2.56.0.rc1.315.gc6ed9934b7-goog


Reply via email to