Re: [PATCH] firmware: cs_dsp: Annotate struct cs_dsp_coeff_ctl with __counted_by_ptr
From: Bill Wendling
Date: Mon Sep 28 2026 - 15:04:30 EST
On Mon, Sep 28, 2026 at 1:51 AM Richard Fitzgerald
<rf@xxxxxxxxxxxxxxxxxxxxx> wrote:
>
> On 28/09/2026 5:45 am, Bill Wendling wrote:
> > Annotate the 'cache' pointer member of 'struct cs_dsp_coeff_ctl' with
> > the '__counted_by_ptr' attribute. This allows the compiler and KASAN
> > to perform run-time bounds checking on accesses to the 'cache' buffer,
> > preventing potential out-of-bounds reads or writes.
> >
> > The 'cache' pointer points to a buffer of size 'len' bytes, allocated
> > to hold the cached value of a DSP coefficient control. The 'cache' and
> > 'len' are initialized in 'cs_dsp_create_control()'.
> >
> > Every subsequent access to 'ctl->cache' is strictly validated to
> Is that true?
> When I last looked at these __counted_by they were only checked by
> a subset of library functions (which was documented) so I was still
> able to write code that overran the buffer.
>
There are several flags that need to be specified when trying to
trigger an out-of-bounds error, like this:
-fsanitize=array-bounds,object-size,local-bounds
They should produce code to check each array access if the compiler
can determine that it's from a struct. E.g., Clang probably won't
generate the bounds checks if the field was passed into a function
that isn't inlined. GCC may have better luck with that.
-bw
> However, recent compilers might do more checking now.
>
> Reviewed-by: Richard Fitzgerald <rf@xxxxxxxxxxxxxxxxxxxxx>