The 'struct hid_bpf' contains a 'device_data' pointer field (of type 'u8 *') and an 'allocated_data' field (of type 'u32') that specifies the size in bytes of the allocated memory for 'device_data'. Since 'device_data' is a pointer to 'u8' (elements of size 1 byte), 'allocated_data' represents the exact count of elements allocated for 'device_data'.
Annotate the 'device_data' field of 'struct hid_bpf' with the '__counted_by_ptr' attribute, pointing to 'allocated_data'. This enables bounds-checking sanitizers (like KASAN and UBSAN) to detect out-of-bounds accesses to 'device_data'. Because the count 'allocated_data' is always set before any access and accurately tracks the allocated buffer size at all times, adding '__counted_by_ptr' will not cause runtime panics or false-positive bounds checks. Cc: [email protected] Assisted-by: LLM Signed-off-by: Bill Wendling <[email protected]> --- include/linux/hid_bpf.h | 10 ++++++---- 1 file changed, 6 insertions(+), 4 deletions(-) diff --git a/include/linux/hid_bpf.h b/include/linux/hid_bpf.h index 19fffa4574a4..f45fb9cccece 100644 --- a/include/linux/hid_bpf.h +++ b/include/linux/hid_bpf.h @@ -185,10 +185,12 @@ struct hid_bpf_ops { /* stored in each device */ struct hid_bpf { - u8 *device_data; /* allocated when a bpf program of type - * SEC(f.../hid_bpf_device_event) has been attached - * to this HID device - */ + /* + * allocated when a bpf program of type + * SEC(f.../hid_bpf_device_event) has been attached + * to this HID device + */ + u8 *device_data __counted_by_ptr(allocated_data); u32 allocated_data; bool destroyed; /* prevents the assignment of any progs */ -- 2.55.0.1082.g2b9226bbc0-goog

