The 'data' pointer field in 'struct acpi_gpio_mapping' is associated
with the 'size' field, which represents the number of elements of
type 'struct acpi_gpio_params' allocated for 'data'.

To improve bounds checking via CONFIG_UBSAN_BOUNDS and
CONFIG_FORTIFY_SOURCE, annotate 'data' with the __counted_by_ptr
attribute.

Analysis of allocation, assignment, and access points shows that the
pointer is never accessed before the count is set, which guarantees that
this annotation is safe and will not cause runtime panics or
false-positive bounds checks.

Cc: [email protected]
Assisted-by: LLM
Signed-off-by: Bill Wendling <[email protected]>
---
v2: Undefine "__counted_by" and "__counted_by_ptr" in the EFI stub
    library as it doesn't need it and Clang is missing a flag to
    enable them.
---
 drivers/firmware/efi/libstub/alignedmem.c      | 8 ++++++++
 drivers/firmware/efi/libstub/efi-stub-helper.c | 8 ++++++++
 drivers/firmware/efi/libstub/file.c            | 8 ++++++++
 drivers/firmware/efi/libstub/gop.c             | 8 ++++++++
 drivers/firmware/efi/libstub/mem.c             | 8 ++++++++
 drivers/firmware/efi/libstub/pci.c             | 8 ++++++++
 drivers/firmware/efi/libstub/printk.c          | 8 ++++++++
 drivers/firmware/efi/libstub/random.c          | 8 ++++++++
 drivers/firmware/efi/libstub/randomalloc.c     | 8 ++++++++
 drivers/firmware/efi/libstub/secureboot.c      | 9 +++++++++
 drivers/firmware/efi/libstub/smbios.c          | 8 ++++++++
 drivers/firmware/efi/libstub/tpm.c             | 9 +++++++++
 drivers/firmware/efi/libstub/x86-5lvl.c        | 9 +++++++++
 drivers/firmware/efi/libstub/x86-stub.c        | 8 ++++++++
 include/linux/gpio/consumer.h                  | 2 +-
 15 files changed, 116 insertions(+), 1 deletion(-)

diff --git a/drivers/firmware/efi/libstub/alignedmem.c 
b/drivers/firmware/efi/libstub/alignedmem.c
index 31928bd87e0f..36248a13f15b 100644
--- a/drivers/firmware/efi/libstub/alignedmem.c
+++ b/drivers/firmware/efi/libstub/alignedmem.c
@@ -1,5 +1,13 @@
 // SPDX-License-Identifier: GPL-2.0
 
+/*
+ * The EFI stub doesn't execute in the context of the kernel, only in the
+ * context of boot firmware, which isn't the time or place to crash the kernel.
+ * Therefore, disable the __counted_by__ attribute.
+ */
+#undef __counted_by
+#undef __counted_by_ptr
+
 #include <linux/efi.h>
 #include <asm/efi.h>
 
diff --git a/drivers/firmware/efi/libstub/efi-stub-helper.c 
b/drivers/firmware/efi/libstub/efi-stub-helper.c
index 8e43eb3f418b..a97d086a76a1 100644
--- a/drivers/firmware/efi/libstub/efi-stub-helper.c
+++ b/drivers/firmware/efi/libstub/efi-stub-helper.c
@@ -7,6 +7,14 @@
  * Copyright 2011 Intel Corporation; author Matt Fleming
  */
 
+/*
+ * The EFI stub doesn't execute in the context of the kernel, only in the
+ * context of boot firmware, which isn't the time or place to crash the kernel.
+ * Therefore, disable the __counted_by__ attribute.
+ */
+#undef __counted_by
+#undef __counted_by_ptr
+
 #include <linux/stdarg.h>
 
 #include <linux/efi.h>
diff --git a/drivers/firmware/efi/libstub/file.c 
b/drivers/firmware/efi/libstub/file.c
index b2601e284695..e845dc2e7aa0 100644
--- a/drivers/firmware/efi/libstub/file.c
+++ b/drivers/firmware/efi/libstub/file.c
@@ -7,6 +7,14 @@
  * Copyright 2011 Intel Corporation; author Matt Fleming
  */
 
+/*
+ * The EFI stub doesn't execute in the context of the kernel, only in the
+ * context of boot firmware, which isn't the time or place to crash the kernel.
+ * Therefore, disable the __counted_by__ attribute.
+ */
+#undef __counted_by
+#undef __counted_by_ptr
+
 #include <linux/efi.h>
 #include <asm/efi.h>
 
diff --git a/drivers/firmware/efi/libstub/gop.c 
b/drivers/firmware/efi/libstub/gop.c
index b800a6c2290c..f9736d2eff22 100644
--- a/drivers/firmware/efi/libstub/gop.c
+++ b/drivers/firmware/efi/libstub/gop.c
@@ -5,6 +5,14 @@
  *
  * ----------------------------------------------------------------------- */
 
+/*
+ * The EFI stub doesn't execute in the context of the kernel, only in the
+ * context of boot firmware, which isn't the time or place to crash the kernel.
+ * Therefore, disable the __counted_by__ attribute.
+ */
+#undef __counted_by
+#undef __counted_by_ptr
+
 #include <linux/bitops.h>
 #include <linux/ctype.h>
 #include <linux/efi.h>
diff --git a/drivers/firmware/efi/libstub/mem.c 
b/drivers/firmware/efi/libstub/mem.c
index fec561e3a792..65bea615420c 100644
--- a/drivers/firmware/efi/libstub/mem.c
+++ b/drivers/firmware/efi/libstub/mem.c
@@ -1,5 +1,13 @@
 // SPDX-License-Identifier: GPL-2.0
 
+/*
+ * The EFI stub doesn't execute in the context of the kernel, only in the
+ * context of boot firmware, which isn't the time or place to crash the kernel.
+ * Therefore, disable the __counted_by__ attribute.
+ */
+#undef __counted_by
+#undef __counted_by_ptr
+
 #include <linux/efi.h>
 #include <asm/efi.h>
 
diff --git a/drivers/firmware/efi/libstub/pci.c 
b/drivers/firmware/efi/libstub/pci.c
index 5daa7a0a0e87..a4c9bf67d5e0 100644
--- a/drivers/firmware/efi/libstub/pci.c
+++ b/drivers/firmware/efi/libstub/pci.c
@@ -6,6 +6,14 @@
  * Copyright 2019 Google, LLC
  */
 
+/*
+ * The EFI stub doesn't execute in the context of the kernel, only in the
+ * context of boot firmware, which isn't the time or place to crash the kernel.
+ * Therefore, disable the __counted_by__ attribute.
+ */
+#undef __counted_by
+#undef __counted_by_ptr
+
 #include <linux/efi.h>
 #include <linux/pci.h>
 
diff --git a/drivers/firmware/efi/libstub/printk.c 
b/drivers/firmware/efi/libstub/printk.c
index 0a18cfe32528..e2ae89a27b78 100644
--- a/drivers/firmware/efi/libstub/printk.c
+++ b/drivers/firmware/efi/libstub/printk.c
@@ -1,5 +1,13 @@
 // SPDX-License-Identifier: GPL-2.0
 
+/*
+ * The EFI stub doesn't execute in the context of the kernel, only in the
+ * context of boot firmware, which isn't the time or place to crash the kernel.
+ * Therefore, disable the __counted_by__ attribute.
+ */
+#undef __counted_by
+#undef __counted_by_ptr
+
 #include <linux/stdarg.h>
 
 #include <linux/ctype.h>
diff --git a/drivers/firmware/efi/libstub/random.c 
b/drivers/firmware/efi/libstub/random.c
index d63262d36e47..d370f0d79c07 100644
--- a/drivers/firmware/efi/libstub/random.c
+++ b/drivers/firmware/efi/libstub/random.c
@@ -3,6 +3,14 @@
  * Copyright (C) 2016 Linaro Ltd;  <[email protected]>
  */
 
+/*
+ * The EFI stub doesn't execute in the context of the kernel, only in the
+ * context of boot firmware, which isn't the time or place to crash the kernel.
+ * Therefore, disable the __counted_by__ attribute.
+ */
+#undef __counted_by
+#undef __counted_by_ptr
+
 #include <linux/efi.h>
 #include <asm/efi.h>
 
diff --git a/drivers/firmware/efi/libstub/randomalloc.c 
b/drivers/firmware/efi/libstub/randomalloc.c
index fd80b2f3233a..b09a26aa51e9 100644
--- a/drivers/firmware/efi/libstub/randomalloc.c
+++ b/drivers/firmware/efi/libstub/randomalloc.c
@@ -3,6 +3,14 @@
  * Copyright (C) 2016 Linaro Ltd;  <[email protected]>
  */
 
+/*
+ * The EFI stub doesn't execute in the context of the kernel, only in the
+ * context of boot firmware, which isn't the time or place to crash the kernel.
+ * Therefore, disable the __counted_by__ attribute.
+ */
+#undef __counted_by
+#undef __counted_by_ptr
+
 #include <linux/efi.h>
 #include <linux/log2.h>
 #include <asm/efi.h>
diff --git a/drivers/firmware/efi/libstub/secureboot.c 
b/drivers/firmware/efi/libstub/secureboot.c
index 516f4f0069bd..07c9782e0c44 100644
--- a/drivers/firmware/efi/libstub/secureboot.c
+++ b/drivers/firmware/efi/libstub/secureboot.c
@@ -7,6 +7,15 @@
  * Copyright (C) 2013 Red Hat, Inc.
  *     Mark Salter <[email protected]>
  */
+
+/*
+ * The EFI stub doesn't execute in the context of the kernel, only in the
+ * context of boot firmware, which isn't the time or place to crash the kernel.
+ * Therefore, disable the __counted_by__ attribute.
+ */
+#undef __counted_by
+#undef __counted_by_ptr
+
 #include <linux/efi.h>
 #include <asm/efi.h>
 
diff --git a/drivers/firmware/efi/libstub/smbios.c 
b/drivers/firmware/efi/libstub/smbios.c
index efbbfc3c2c0d..98dc3ee40958 100644
--- a/drivers/firmware/efi/libstub/smbios.c
+++ b/drivers/firmware/efi/libstub/smbios.c
@@ -2,6 +2,14 @@
 // Copyright 2022 Google LLC
 // Author: Ard Biesheuvel <[email protected]>
 
+/*
+ * The EFI stub doesn't execute in the context of the kernel, only in the
+ * context of boot firmware, which isn't the time or place to crash the kernel.
+ * Therefore, disable the __counted_by__ attribute.
+ */
+#undef __counted_by
+#undef __counted_by_ptr
+
 #include <linux/efi.h>
 
 #include "efistub.h"
diff --git a/drivers/firmware/efi/libstub/tpm.c 
b/drivers/firmware/efi/libstub/tpm.c
index 73f001114732..27bc0ccc2a2b 100644
--- a/drivers/firmware/efi/libstub/tpm.c
+++ b/drivers/firmware/efi/libstub/tpm.c
@@ -7,6 +7,15 @@
  *     Matthew Garrett <[email protected]>
  *     Thiebaud Weksteen <[email protected]>
  */
+
+/*
+ * The EFI stub doesn't execute in the context of the kernel, only in the
+ * context of boot firmware, which isn't the time or place to crash the kernel.
+ * Therefore, disable the __counted_by__ attribute.
+ */
+#undef __counted_by
+#undef __counted_by_ptr
+
 #include <linux/efi.h>
 #include <linux/tpm_eventlog.h>
 #include <asm/efi.h>
diff --git a/drivers/firmware/efi/libstub/x86-5lvl.c 
b/drivers/firmware/efi/libstub/x86-5lvl.c
index c3da05c0df8b..3112ab4b2623 100644
--- a/drivers/firmware/efi/libstub/x86-5lvl.c
+++ b/drivers/firmware/efi/libstub/x86-5lvl.c
@@ -1,4 +1,13 @@
 // SPDX-License-Identifier: GPL-2.0-only
+
+/*
+ * The EFI stub doesn't execute in the context of the kernel, only in the
+ * context of boot firmware, which isn't the time or place to crash the kernel.
+ * Therefore, disable the __counted_by__ attribute.
+ */
+#undef __counted_by
+#undef __counted_by_ptr
+
 #include <linux/efi.h>
 
 #include <asm/boot.h>
diff --git a/drivers/firmware/efi/libstub/x86-stub.c 
b/drivers/firmware/efi/libstub/x86-stub.c
index f4799e29f4cf..77e806c2b016 100644
--- a/drivers/firmware/efi/libstub/x86-stub.c
+++ b/drivers/firmware/efi/libstub/x86-stub.c
@@ -6,6 +6,14 @@
  *
  * ----------------------------------------------------------------------- */
 
+/*
+ * The EFI stub doesn't execute in the context of the kernel, only in the
+ * context of boot firmware, which isn't the time or place to crash the kernel.
+ * Therefore, disable the __counted_by__ attribute.
+ */
+#undef __counted_by
+#undef __counted_by_ptr
+
 #include <linux/efi.h>
 #include <linux/pci.h>
 #include <linux/stddef.h>
diff --git a/include/linux/gpio/consumer.h b/include/linux/gpio/consumer.h
index fceeefd5f893..2b80cf7aa7e7 100644
--- a/include/linux/gpio/consumer.h
+++ b/include/linux/gpio/consumer.h
@@ -667,7 +667,7 @@ struct acpi_gpio_params {
 
 struct acpi_gpio_mapping {
        const char *name;
-       const struct acpi_gpio_params *data;
+       const struct acpi_gpio_params *data __counted_by_ptr(size);
        unsigned int size;
 
 /* Ignore IoRestriction field */
-- 
2.56.0.rc1.315.gc6ed9934b7-goog


Reply via email to