The formats array is allocated separately with devm_kcalloc() and only
referenced through the gsc_context. Make it a flexible array member at
the end of the context and allocate both in one go with struct_size().

Annotate it with __counted_by(num_formats) so the array accesses can be
bounds checked with FORTIFY_SOURCE and UBSAN_BOUNDS.

Assisted-by: LLM
Signed-off-by: Rosen Penev <[email protected]>
---
 drivers/gpu/drm/exynos/exynos_drm_gsc.c | 17 ++++++-----------
 1 file changed, 6 insertions(+), 11 deletions(-)

diff --git a/drivers/gpu/drm/exynos/exynos_drm_gsc.c 
b/drivers/gpu/drm/exynos/exynos_drm_gsc.c
index d9637ddfcfc4..f1807ef664e1 100644
--- a/drivers/gpu/drm/exynos/exynos_drm_gsc.c
+++ b/drivers/gpu/drm/exynos/exynos_drm_gsc.c
@@ -99,7 +99,6 @@ struct gsc_context {
        void            *dma_priv;
        struct device   *dev;
        struct exynos_drm_ipp_task      *task;
-       struct exynos_drm_ipp_formats   *formats;
        unsigned int                    num_formats;
 
        void __iomem    *regs;
@@ -110,6 +109,7 @@ struct gsc_context {
        int     id;
        int     irq;
        bool    rotation;
+       struct exynos_drm_ipp_formats   formats[] __counted_by(num_formats);
 };
 
 /**
@@ -1222,21 +1222,19 @@ static int gsc_probe(struct platform_device *pdev)
        struct gsc_context *ctx;
        int num_formats, ret, i, j;
 
-       ctx = devm_kzalloc(dev, sizeof(*ctx), GFP_KERNEL);
+       num_formats = ARRAY_SIZE(gsc_formats) + ARRAY_SIZE(gsc_tiled_formats);
+       ctx = devm_kzalloc(dev, struct_size(ctx, formats, num_formats), 
GFP_KERNEL);
        if (!ctx)
                return -ENOMEM;
 
+       ctx->num_formats = num_formats;
+       formats = ctx->formats;
+
        driver_data = device_get_match_data(dev);
        ctx->dev = dev;
        ctx->num_clocks = driver_data->num_clocks;
        ctx->clk_names = driver_data->clk_names;
 
-       /* construct formats/limits array */
-       num_formats = ARRAY_SIZE(gsc_formats) + ARRAY_SIZE(gsc_tiled_formats);
-       formats = devm_kcalloc(dev, num_formats, sizeof(*formats), GFP_KERNEL);
-       if (!formats)
-               return -ENOMEM;
-
        /* linear formats */
        for (i = 0; i < ARRAY_SIZE(gsc_formats); i++) {
                formats[i].fourcc = gsc_formats[i];
@@ -1256,9 +1254,6 @@ static int gsc_probe(struct platform_device *pdev)
                formats[j].num_limits = driver_data->num_limits;
        }
 
-       ctx->formats = formats;
-       ctx->num_formats = num_formats;
-
        /* clock control */
        for (i = 0; i < ctx->num_clocks; i++) {
                ctx->clocks[i] = devm_clk_get(dev, ctx->clk_names[i]);
-- 
2.56.0


Reply via email to