[PATCH] media: mali-c55: add padding to mali_c55_params_ccm structure

Arnd Bergmann posted 1 patch 1 week, 2 days ago
include/uapi/linux/media/arm/mali-c55-config.h | 1 +
1 file changed, 1 insertion(+)
[PATCH] media: mali-c55: add padding to mali_c55_params_ccm structure
Posted by Arnd Bergmann 1 week, 2 days ago
From: Arnd Bergmann <arnd@arndb.de>

The newly added structure has extra padding on the on
some architectures, which triggers a pedantic uapi check:

./usr/include/linux/media/arm/mali-c55-config.h:807:1: error: padding struct size to alignment boundary with 2 bytes [-Werror=padded]

Add explicit padding here to avoid risking information leaks
and incompatibilities between architectures.

Fixes: bb401df68c06 ("media: mali-c55: Add support for CCM")
Signed-off-by: Arnd Bergmann <arnd@arndb.de>
---
 include/uapi/linux/media/arm/mali-c55-config.h | 1 +
 1 file changed, 1 insertion(+)

diff --git a/include/uapi/linux/media/arm/mali-c55-config.h b/include/uapi/linux/media/arm/mali-c55-config.h
index 84d8f3901405..9c922290e035 100644
--- a/include/uapi/linux/media/arm/mali-c55-config.h
+++ b/include/uapi/linux/media/arm/mali-c55-config.h
@@ -804,6 +804,7 @@ struct mali_c55_params_ccm {
 	__u16 coeffs[3][3];
 	__u16 gains[3];
 	__u16 offs[3];
+	__u16 __pad;
 };
 
 /**
-- 
2.53.0
Re: [PATCH] media: mali-c55: add padding to mali_c55_params_ccm structure
Posted by Linus Walleij 1 week ago
On Tue, Sep 15, 2026 at 10:25 PM Arnd Bergmann <arnd@kernel.org> wrote:

> From: Arnd Bergmann <arnd@arndb.de>
>
> The newly added structure has extra padding on the on
> some architectures, which triggers a pedantic uapi check:
>
> ./usr/include/linux/media/arm/mali-c55-config.h:807:1: error: padding struct size to alignment boundary with 2 bytes [-Werror=padded]
>
> Add explicit padding here to avoid risking information leaks
> and incompatibilities between architectures.
>
> Fixes: bb401df68c06 ("media: mali-c55: Add support for CCM")
> Signed-off-by: Arnd Bergmann <arnd@arndb.de>

Reviewed-by: Linus Walleij <linusw@kernel.org>

Yours,
Linus Walleij
Re: [PATCH] media: mali-c55: add padding to mali_c55_params_ccm structure
Posted by Vincenzo Frascino 1 week, 1 day ago
Hi Arnd,

quick question since you are mentioning information leaking in the commit message.

On 15/09/2026 21:24, Arnd Bergmann wrote:
> From: Arnd Bergmann <arnd@arndb.de>
> 
> The newly added structure has extra padding on the on
> some architectures, which triggers a pedantic uapi check:
> 
> ./usr/include/linux/media/arm/mali-c55-config.h:807:1: error: padding struct size to alignment boundary with 2 bytes [-Werror=padded]
> 
> Add explicit padding here to avoid risking information leaks
> and incompatibilities between architectures.
> 
> Fixes: bb401df68c06 ("media: mali-c55: Add support for CCM")
> Signed-off-by: Arnd Bergmann <arnd@arndb.de>
> ---
>  include/uapi/linux/media/arm/mali-c55-config.h | 1 +
>  1 file changed, 1 insertion(+)
> 
> diff --git a/include/uapi/linux/media/arm/mali-c55-config.h b/include/uapi/linux/media/arm/mali-c55-config.h
> index 84d8f3901405..9c922290e035 100644
> --- a/include/uapi/linux/media/arm/mali-c55-config.h
> +++ b/include/uapi/linux/media/arm/mali-c55-config.h
> @@ -804,6 +804,7 @@ struct mali_c55_params_ccm {
>  	__u16 coeffs[3][3];
>  	__u16 gains[3];
>  	__u16 offs[3];
> +	__u16 __pad;

Does this field need to be explicitly zeroed/validated anywhere the structure is
populated? Turning implicit padding into a named member fixes the layout
warning, but by itself does not seem to prevent leaking uninitialized data if
this structure is ever copied from the kernel to userspace. It might also be
worth documenting that __pad is reserved and must be zero.

I think you already checked that changing the explicit structure layout/size is
safe for existing userspace :)

>  };
>  
>  /**

-- 
Regards,
Vincenzo
Re: [PATCH] media: mali-c55: add padding to mali_c55_params_ccm structure
Posted by Arnd Bergmann 1 week, 1 day ago
On Wed, Sep 16, 2026, at 17:43, Vincenzo Frascino wrote:
>> diff --git a/include/uapi/linux/media/arm/mali-c55-config.h b/include/uapi/linux/media/arm/mali-c55-config.h
>> index 84d8f3901405..9c922290e035 100644
>> --- a/include/uapi/linux/media/arm/mali-c55-config.h
>> +++ b/include/uapi/linux/media/arm/mali-c55-config.h
>> @@ -804,6 +804,7 @@ struct mali_c55_params_ccm {
>>  	__u16 coeffs[3][3];
>>  	__u16 gains[3];
>>  	__u16 offs[3];
>> +	__u16 __pad;
>
> Does this field need to be explicitly zeroed/validated anywhere the structure is
> populated? Turning implicit padding into a named member fixes the layout
> warning, but by itself does not seem to prevent leaking uninitialized data if
> this structure is ever copied from the kernel to userspace. It might also be
> worth documenting that __pad is reserved and must be zero.

It depends on how the structure is initialized. Depending on the compiler
version and optimization level, a local variable declared as

   struct mali_c55_params_ccm v = {};

may end up with uninitialized stack data in unnamed padding, but if you
do a memset(), that should always be safe. If the fields are set individually,
then you also have to set the __pad field, but that's not how you do it here.

> I think you already checked that changing the explicit structure layout/size is
> safe for existing userspace :)

On all architectures other than m68k, the position of the struct members
and the struct size are unchanged by my patch. On m68k. there is no
implied padding at the end of this structure, so this is theoretically
an ABI change, but nobody has a mali device on m68k, so we know that it
is safe.

      Arnd
Re: [PATCH] media: mali-c55: add padding to mali_c55_params_ccm structure
Posted by Vincenzo Frascino 1 week ago

On 16/09/2026 19:55, Arnd Bergmann wrote:
> It depends on how the structure is initialized. Depending on the compiler
> version and optimization level, a local variable declared as
> 
>    struct mali_c55_params_ccm v = {};
> 
> may end up with uninitialized stack data in unnamed padding, but if you
> do a memset(), that should always be safe. If the fields are set individually,
> then you also have to set the __pad field, but that's not how you do it here.

Fine by me. With this:

Reviewed-by: Vincenzo Frascino <vincenzo.frascino@arm.com>

-- 
Regards,
Vincenzo