On Tue, Sep 29, 2026 at 1:36 AM Matthew Auld <[email protected]> wrote:
> On 28/09/2026 19:44, Bill Wendling wrote:
> > On Mon, Sep 28, 2026 at 5:20 AM Matthew Auld <[email protected]> wrote:
> >>
> >> On 25/09/2026 21:44, Bill Wendling wrote:
> >>> In 'struct gpu_buddy', the 'roots' field points to an array of pointers
> >>> to 'struct gpu_buddy_block'. The number of allocated roots is tracked
> >>> by the 'n_roots' field.
> >>>
> >>> Annotate the 'roots' pointer with the '__counted_by_ptr' attribute
> >>> referencing 'n_roots' to enable compile-time and runtime bounds-checking
> >>> via KASAN and '__builtin_dynamic_object_size'.
> >>>
> >>> In 'gpu_buddy_init', 'mm->n_roots' is initialized first, and 'mm->roots' 
> >>> is
> >>> subsequently allocated with 'kmalloc_objs(struct gpu_buddy_block *,
> >>> mm->n_roots)'.
> >>>
> >>> Since the bounds associated with 'roots' ('n_roots') are fully set prior
> >>> to any array allocation or access and remain invariant, this annotation
> >>> will not cause runtime panics or false-positive bounds checks.
> >>>
> >>> Cc: [email protected]
> >>> Assisted-by: LLM
> >>> Signed-off-by: Bill Wendling <[email protected]>
> >>
> >> Reviewed-by: Matthew Auld <[email protected]>
> >>
> >> Would it make sense to also do this for *_scoreboard and free_tree, if
> >> we add a new field n_orders?
> >>
> > Sure! There's already a 'max_order'. I assume that 'n_orders' would be
> > more dynamic?
>
> Yeah, I think just mm.n_orders = max_order + 1. I assume the
> __counted_by_ptr() only works with a field?
>
Well, yes*.

* The original Clang design of __counted_by (and associated)
attributes accepted context-free expressions. However, GCC isn't able
to handle expressions and we weren't able to agree on a syntax that
was acceptable to both compiler teams. Thus, we won't be supporting
expressions in these attributes, unless something miraculous happens.

-bw

> >
> > -bw
> >
> >>> ---
> >>>    include/linux/gpu_buddy.h | 2 +-
> >>>    1 file changed, 1 insertion(+), 1 deletion(-)
> >>>
> >>> diff --git a/include/linux/gpu_buddy.h b/include/linux/gpu_buddy.h
> >>> index 2c36124bb696..d7249e500ab6 100644
> >>> --- a/include/linux/gpu_buddy.h
> >>> +++ b/include/linux/gpu_buddy.h
> >>> @@ -172,7 +172,7 @@ struct gpu_buddy {
> >>>         * a power of two, with each root being the largest power-of-two
> >>>         * that fits in the remaining space.
> >>>         */
> >>> -     struct gpu_buddy_block **roots;
> >>> +     struct gpu_buddy_block **roots __counted_by_ptr(n_roots);
> >>>        /*
> >>>         * Per-order free block scoreboard: free_scoreboard[order] holds 
> >>> the
> >>>         * number of blocks of that order currently in the free state.
> >>
>

Reply via email to