Hi, On Mon, Oct 5, 2026 at 2:25 PM Ard Biesheuvel <[email protected]> wrote: > > > > On Mon, 5 Oct 2026, at 21:20, Bill Wendling wrote: > > Code that runs outside the kernel proper, such as the EFI stub, gets > > nothing out of the counted_by annotations: the bounds checks they feed > > (FORTIFY_SOURCE, UBSAN_BOUNDS) are already disabled there. > > > > The annotations can also break the build. A __counted_by_ptr() that > > names a member declared after the pointer needs Clang's > > '-fexperimental-late-parse-attributes', which the top-level Makefile > > adds to 'KBUILD_CFLAGS'. The x86 EFI stub builds its own cflags and does > > not get that flag, so it fails as soon as such a struct is pulled in > > through a common header. > > > > Overriding the __counted_by_ptr macro from a Makefile doesn't work: > > 'compiler_types.h' is pulled in with '-include', which is processed > > after all -D/-U options, so it re-establishes the definitions. Follow > > the '__NO_FORTIFY' precedent instead: let a build define > > '__NO_COUNTED_BY_PTR' to turn the corresponding annotation into a no-op. > > > > Assisted-by: LLM > > Signed-off-by: Bill Wendling <[email protected]> > > --- > > v2: Only specify __NO_COUNTED_BY_PTR. Leave __NO_COUNTED_BY until we need > > it. > > v3: Add the version to the Subject line. > > --- > > include/linux/compiler_types.h | 7 ++++++- > > 1 file changed, 6 insertions(+), 1 deletion(-) > > > > diff --git a/include/linux/compiler_types.h > > b/include/linux/compiler_types.h > > index c5921f139007..8bde6798b4ec 100644 > > --- a/include/linux/compiler_types.h > > +++ b/include/linux/compiler_types.h > > @@ -387,8 +387,13 @@ struct ftrace_likely_data { > > * > > * gcc: > > https://gcc.gnu.org/pipermail/gcc-patches/2025-April/681727.html > > * clang: > > https://clang.llvm.org/docs/AttributeReference.html#counted-by-counted-by-or-null-sized-by-sized-by-or-null > > + * > > + * Code that runs outside the kernel proper (e.g. the EFI stub) can > > define > > + * __NO_COUNTED_BY_PTR to drop the annotation. Such code may also lack > > the flag > > + * Clang needs to parse a reference to a later-declared member > > + * (-fexperimental-late-parse-attributes). > > */ > > -#ifdef CONFIG_CC_HAS_COUNTED_BY_PTR > > +#if defined(CONFIG_CC_HAS_COUNTED_BY_PTR) && > > !defined(__NO_COUNTED_BY_PTR) > > #define > > __counted_by_ptr(member) __attribute__((__counted_by__(member))) > > #else > > #define __counted_by_ptr(member) > > Apologies, I may have been unclear. > > What I would like to see here is something like > > #ifndef __NO_COUNTED_BY > #define __counted_by(member) __attribute__((....)) > #define __counted_by_ptr(member) __attribute__((....)) > #else > #define __counted_by(member) > #define __counted_by_ptr(member) > #endif
FWIW, Bill's original patch had this explanation "The two are kept separate but parallel so they can be folded together once all supported compilers handle '__counted_by' on pointers." Justin

