Pádraig Brady <[email protected]> writes:

> On 29/09/2026 06:48, Collin Funk wrote:
>> * src/join.c (struct line): Use the COUNTED_BY attribute on the fields
>> member.
>> (struct seq): Use the COUNTED_BY attribute on the lines member.
>> (freeline): When setting a pointer using the COUNTED_BY attribute to
>> NULL, set its counter to zero.
> Ok cool. This helps when runtime bounds checking is enabled:
> https://gcc.gnu.org/onlinedocs/gcc/Common-Attributes.html#index-counted_005fby
>
> I see gnulib defines this away where it's not supported on pointers.

Exactly. If I understand correctly __builtin_dynamic_object_size, which
is mentioned in that link, is used to implement _FORTIFY_SOURCE.

The attribute is also used by -fsanitize=bounds. If you wrongfully mark
"fields" as "COUNTED_BY (nfields)" instead of the correct
"COUNTED_BY (nfields_allocated)", then when you compile with
-fsanitize=bounds, you can see the test suite crash when 'join' tries
to write to the newly allocated field. At least that is how I tested it,
since I had never used it before.

There is also an experimental Clang feature called -fbounds-saftey that
uses it among other attributes [1] [2]. I assume GCC will take whatever
ideas prove helpful and/or create its own. As long as it doesn't break
compilation with older compilers and isn't too unmaintainable, I am for
experimenting with those features.

Collin

[1] https://clang.llvm.org/docs/BoundsSafety.html
[2] https://clang.llvm.org/docs/BoundsSafetyImplPlans.html

Reply via email to