The formats array is allocated separately with devm_kcalloc() and only referenced through the gsc_context. Make it a flexible array member at the end of the context and allocate both in one go with struct_size().
Annotate it with __counted_by(num_formats) so the array accesses can be bounds checked with FORTIFY_SOURCE and UBSAN_BOUNDS. Assisted-by: LLM Signed-off-by: Rosen Penev <[email protected]> --- drivers/gpu/drm/exynos/exynos_drm_gsc.c | 17 ++++++----------- 1 file changed, 6 insertions(+), 11 deletions(-) diff --git a/drivers/gpu/drm/exynos/exynos_drm_gsc.c b/drivers/gpu/drm/exynos/exynos_drm_gsc.c index d9637ddfcfc4..f1807ef664e1 100644 --- a/drivers/gpu/drm/exynos/exynos_drm_gsc.c +++ b/drivers/gpu/drm/exynos/exynos_drm_gsc.c @@ -99,7 +99,6 @@ struct gsc_context { void *dma_priv; struct device *dev; struct exynos_drm_ipp_task *task; - struct exynos_drm_ipp_formats *formats; unsigned int num_formats; void __iomem *regs; @@ -110,6 +109,7 @@ struct gsc_context { int id; int irq; bool rotation; + struct exynos_drm_ipp_formats formats[] __counted_by(num_formats); }; /** @@ -1222,21 +1222,19 @@ static int gsc_probe(struct platform_device *pdev) struct gsc_context *ctx; int num_formats, ret, i, j; - ctx = devm_kzalloc(dev, sizeof(*ctx), GFP_KERNEL); + num_formats = ARRAY_SIZE(gsc_formats) + ARRAY_SIZE(gsc_tiled_formats); + ctx = devm_kzalloc(dev, struct_size(ctx, formats, num_formats), GFP_KERNEL); if (!ctx) return -ENOMEM; + ctx->num_formats = num_formats; + formats = ctx->formats; + driver_data = device_get_match_data(dev); ctx->dev = dev; ctx->num_clocks = driver_data->num_clocks; ctx->clk_names = driver_data->clk_names; - /* construct formats/limits array */ - num_formats = ARRAY_SIZE(gsc_formats) + ARRAY_SIZE(gsc_tiled_formats); - formats = devm_kcalloc(dev, num_formats, sizeof(*formats), GFP_KERNEL); - if (!formats) - return -ENOMEM; - /* linear formats */ for (i = 0; i < ARRAY_SIZE(gsc_formats); i++) { formats[i].fourcc = gsc_formats[i]; @@ -1256,9 +1254,6 @@ static int gsc_probe(struct platform_device *pdev) formats[j].num_limits = driver_data->num_limits; } - ctx->formats = formats; - ctx->num_formats = num_formats; - /* clock control */ for (i = 0; i < ctx->num_clocks; i++) { ctx->clocks[i] = devm_clk_get(dev, ctx->clk_names[i]); -- 2.56.0

