On Tue, Oct 6, 2026 at 3:09 AM Ard Biesheuvel <[email protected]> wrote: > > > > On Tue, 6 Oct 2026, at 11:43, Bill Wendling wrote: > > Code that runs outside the kernel proper, such as the EFI stub, gets > > nothing out of the counted_by annotations: the bounds checks they feed > > (FORTIFY_SOURCE, UBSAN_BOUNDS) are already disabled there. > > > > The annotations can also break the build. A __counted_by_ptr() that > > names a member declared after the pointer needs Clang's > > '-fexperimental-late-parse-attributes', which the top-level Makefile > > adds to 'KBUILD_CFLAGS'. The x86 EFI stub builds its own cflags and does > > not get that flag, so it fails as soon as such a struct is pulled in > > through a common header. > > > > Overriding the macros from a Makefile doesn't work: > > 'compiler_types.h' is pulled in with '-include', which is processed > > after all -D/-U options, so it re-establishes the definitions. Follow > > the '__NO_FORTIFY' precedent instead: let a build define > > '__NO_COUNTED_BY' to turn the corresponding annotation into a no-op. > > > > Assisted-by: LLM > > Signed-off-by: Bill Wendling <[email protected]> > > --- > > v2: Only specify __NO_COUNTED_BY_PTR. Leave __NO_COUNTED_BY until we need > > it. > > v3: Add the version to the Subject line. > > v4: Use __NO_COUNTED_BY to reduce churn later on. > > --- > > include/linux/compiler_types.h | 7 ++++++- > > 1 file changed, 6 insertions(+), 1 deletion(-) > > > > diff --git a/include/linux/compiler_types.h b/include/linux/compiler_types.h > > index c5921f139007..05e2b637f1cd 100644 > > --- a/include/linux/compiler_types.h > > +++ b/include/linux/compiler_types.h > > @@ -371,8 +371,13 @@ struct ftrace_likely_data { > > * > > * __bdos on clang < 19.1.3 can be off by 4: > > * https://github.com/llvm/llvm-project/pull/112636 > > + * > > + * Code that runs outside the kernel proper (e.g. the EFI stub) can define > > + * __NO_COUNTED_BY to drop the annotation, since it gains nothing from the > > + * bounds checks. __NO_COUNTED_BY should be used sparingly, because there > > are > > + * better options for opting out of bounds checking. > > */ > > -#ifdef CONFIG_CC_HAS_COUNTED_BY > > +#if defined(CONFIG_CC_HAS_COUNTED_BY) && !defined(__NO_COUNTED_BY) > > # define __counted_by(member) > > __attribute__((__counted_by__(member))) > > #else > > # define __counted_by(member) > > > What happened to counted_by_ptr() now? __NO_COUNTED_BY should disable that > too. > I realized that just now. *sigh* I'd take up basketweaving, but I'd probably get splinters that would fester and I'd lose fingers.
Fixed in v5. -bw

