On Tue, Oct 6, 2026 at 1:08 AM Ard Biesheuvel <[email protected]> wrote: > On Tue, 6 Oct 2026, at 09:30, Justin Stitt wrote: > > Hi, > > > > On Mon, Oct 5, 2026 at 2:25 PM Ard Biesheuvel <[email protected]> wrote: > >> > >> > >> > >> On Mon, 5 Oct 2026, at 21:20, Bill Wendling wrote: > >> > Code that runs outside the kernel proper, such as the EFI stub, gets > >> > nothing out of the counted_by annotations: the bounds checks they feed > >> > (FORTIFY_SOURCE, UBSAN_BOUNDS) are already disabled there. > >> > > >> > The annotations can also break the build. A __counted_by_ptr() that > >> > names a member declared after the pointer needs Clang's > >> > '-fexperimental-late-parse-attributes', which the top-level Makefile > >> > adds to 'KBUILD_CFLAGS'. The x86 EFI stub builds its own cflags and does > >> > not get that flag, so it fails as soon as such a struct is pulled in > >> > through a common header. > >> > > >> > Overriding the __counted_by_ptr macro from a Makefile doesn't work: > >> > 'compiler_types.h' is pulled in with '-include', which is processed > >> > after all -D/-U options, so it re-establishes the definitions. Follow > >> > the '__NO_FORTIFY' precedent instead: let a build define > >> > '__NO_COUNTED_BY_PTR' to turn the corresponding annotation into a no-op. > >> > > >> > Assisted-by: LLM > >> > Signed-off-by: Bill Wendling <[email protected]> > >> > --- > >> > v2: Only specify __NO_COUNTED_BY_PTR. Leave __NO_COUNTED_BY until we > >> > need it. > >> > v3: Add the version to the Subject line. > >> > --- > >> > include/linux/compiler_types.h | 7 ++++++- > >> > 1 file changed, 6 insertions(+), 1 deletion(-) > >> > > >> > diff --git a/include/linux/compiler_types.h > >> > b/include/linux/compiler_types.h > >> > index c5921f139007..8bde6798b4ec 100644 > >> > --- a/include/linux/compiler_types.h > >> > +++ b/include/linux/compiler_types.h > >> > @@ -387,8 +387,13 @@ struct ftrace_likely_data { > >> > * > >> > * gcc: > >> > https://gcc.gnu.org/pipermail/gcc-patches/2025-April/681727.html > >> > * clang: > >> > https://clang.llvm.org/docs/AttributeReference.html#counted-by-counted-by-or-null-sized-by-sized-by-or-null > >> > + * > >> > + * Code that runs outside the kernel proper (e.g. the EFI stub) can > >> > define > >> > + * __NO_COUNTED_BY_PTR to drop the annotation. Such code may also lack > >> > the flag > >> > + * Clang needs to parse a reference to a later-declared member > >> > + * (-fexperimental-late-parse-attributes). > >> > */ > >> > -#ifdef CONFIG_CC_HAS_COUNTED_BY_PTR > >> > +#if defined(CONFIG_CC_HAS_COUNTED_BY_PTR) && > >> > !defined(__NO_COUNTED_BY_PTR) > >> > #define > >> > __counted_by_ptr(member) __attribute__((__counted_by__(member))) > >> > #else > >> > #define __counted_by_ptr(member) > >> > >> Apologies, I may have been unclear. > >> > >> What I would like to see here is something like > >> > >> #ifndef __NO_COUNTED_BY > >> #define __counted_by(member) __attribute__((....)) > >> #define __counted_by_ptr(member) __attribute__((....)) > >> #else > >> #define __counted_by(member) > >> #define __counted_by_ptr(member) > >> #endif > > > > FWIW, Bill's original patch had this explanation > > > > "The two are kept separate but parallel so they > > can be folded together once all supported compilers handle > > '__counted_by' on pointers." > > > > When opting out of this, whether or not the compiler supports > all variants of counted_by() is irrelevant. The same #define > should just opt out of all of them. > > If the need arises to be more granular here, we can always add > that later but I don't want to have to add > > -D__NO_COUNTED_BY -D__NO_COUNTED_BY_PTR > > everywhere today, and go back and remove the second part once > all compilers have caught up. > It would reduce churn in the code base once we no longer need a separate '__counted_by_ptr' macro. However, we should specify that __NO_COUNTED_BY should be used sparingly, as there are other, better ways to "opt out" of the __counted_by family of attributes. Basically, it should only be used if the Makefile doesn't inherit its KCFLAGS from the root Makefile.
-bw

