Page MenuHomeFreeBSD

cdefs: add bounds-safety annotation macros
AcceptedPublic

Authored by abhijeetsharma2002_gmail.com on Aug 19 2026, 11:52 AM.
Tags
None
Referenced Files
Unknown Object (File)
Sat, Oct 3, 1:17 PM
Unknown Object (File)
Thu, Oct 1, 5:29 PM
Unknown Object (File)
Thu, Oct 1, 3:02 AM
Unknown Object (File)
Tue, Sep 29, 5:33 PM
Unknown Object (File)
Sat, Sep 26, 2:18 PM
Unknown Object (File)
Fri, Sep 25, 10:25 AM
Unknown Object (File)
Fri, Sep 25, 8:32 AM
Unknown Object (File)
Wed, Sep 23, 6:49 PM
Subscribers

Details

Reviewers
rpaulo
emaste
imp
Summary

Define the -fbounds-safety vocabulary (counted_by, sized_by,
__single, the forge escape hatches). Every macro expands to nothing
under compilers without the extension, so the annotated tree builds
unchanged with the stock toolchain.

Sponsored by: The FreeBSD Foundation

Diff Detail

Repository
rG FreeBSD src repository
Lint
Lint Skipped
Unit
Tests Skipped
Build Status
Buildable 76328
Build 73211: arc lint + arc unit

Event Timeline

Ah! I complained that these were missing from a prior review, but they are just what I was hoping for.

This revision is now accepted and ready to land.Aug 19 2026, 7:24 PM
sys/sys/cdefs.h
408

Can you explain why these are under a different feature? What happens when one feature is ON but the other is off?

426

This is probably not going to be enough because you may need to add __indexable to static inline functions in headers which are going to be used by both compilers.

sys/sys/cdefs.h
408

bounds_safety_attributes enables the ABI-preserving annotations without applying the full bounds-safety pointer defaults, so unannotated parameters do not become __single. That provides an annotations-only migration mode where a file can be audited with -Wunsafe-buffer-usage before enabling full -fbounds-safety. The wide-pointer attributes are not supported in that mode, hence the bounds_attributes guard.

Separately, I noticed that my __has_ptrcheck definition is wrong, since I set it for either feature, whereas Clang's ptrcheck.h defines it only for bounds_attributes.

426

Makes sense. I will follow xnu and add a header_indexable/header_bidi_indexable pair that expands to nothing when unsupported.

This revision now requires review to proceed.Aug 29 2026, 11:21 PM
This revision is now accepted and ready to land.Aug 30 2026, 6:29 AM
jrtc27 added inline comments.
sys/sys/cdefs.h
406

Does this serve a purpose? That is, why not just use has_feature(bounds_attributes) everywhere; is there another case where we'd want has_ptrcheck to be 1?