Pádraig Brady <[email protected]> writes: > On 29/09/2026 06:48, Collin Funk wrote: >> * src/join.c (struct line): Use the COUNTED_BY attribute on the fields >> member. >> (struct seq): Use the COUNTED_BY attribute on the lines member. >> (freeline): When setting a pointer using the COUNTED_BY attribute to >> NULL, set its counter to zero. > Ok cool. This helps when runtime bounds checking is enabled: > https://gcc.gnu.org/onlinedocs/gcc/Common-Attributes.html#index-counted_005fby > > I see gnulib defines this away where it's not supported on pointers.
Exactly. If I understand correctly __builtin_dynamic_object_size, which is mentioned in that link, is used to implement _FORTIFY_SOURCE. The attribute is also used by -fsanitize=bounds. If you wrongfully mark "fields" as "COUNTED_BY (nfields)" instead of the correct "COUNTED_BY (nfields_allocated)", then when you compile with -fsanitize=bounds, you can see the test suite crash when 'join' tries to write to the newly allocated field. At least that is how I tested it, since I had never used it before. There is also an experimental Clang feature called -fbounds-saftey that uses it among other attributes [1] [2]. I assume GCC will take whatever ideas prove helpful and/or create its own. As long as it doesn't break compilation with older compilers and isn't too unmaintainable, I am for experimenting with those features. Collin [1] https://clang.llvm.org/docs/BoundsSafety.html [2] https://clang.llvm.org/docs/BoundsSafetyImplPlans.html
