From: Gary Guo <gary@garyguo.net>
To: Benno Lossin <benno.lossin@proton.me>
Cc: "Miguel Ojeda" <ojeda@kernel.org>,
"Wedson Almeida Filho" <wedsonaf@gmail.com>,
"Alex Gaynor" <alex.gaynor@gmail.com>,
"Boqun Feng" <boqun.feng@gmail.com>,
"Björn Roy Baron" <bjorn3_gh@protonmail.com>,
"Alice Ryhl" <aliceryhl@google.com>,
"Andreas Hindborg" <nmi@metaspace.dk>,
rust-for-linux@vger.kernel.org, linux-kernel@vger.kernel.org,
"Asahi Lina" <lina@asahilina.net>
Subject: Re: [PATCH v3 08/13] rust: init: Add functions to create array initializers
Date: Sun, 6 Aug 2023 17:07:08 +0100 [thread overview]
Message-ID: <20230806170708.174cc26c.gary@garyguo.net> (raw)
In-Reply-To: <20230729090838.225225-9-benno.lossin@proton.me>
On Sat, 29 Jul 2023 09:10:02 +0000
Benno Lossin <benno.lossin@proton.me> wrote:
> Add two functions `pin_init_array_from_fn` and `init_array_from_fn` that
> take a function that generates initializers for `T` from usize, the added
> functions then return an initializer for `[T; N]` where every element is
> initialized by an element returned from the generator function.
>
> Suggested-by: Asahi Lina <lina@asahilina.net>
> Reviewed-by: Björn Roy Baron <bjorn3_gh@protonmail.com>
> Reviewed-by: Alice Ryhl <aliceryhl@google.com>
> Signed-off-by: Benno Lossin <benno.lossin@proton.me>
> ---
> v2 -> v3:
> - changed doctest: instead of printing the array, assert the length,
> - added Reviewed-by's from Alice.
>
> v1 -> v2:
> - fix warnings and errors in doctests,
> - replace dropping loop with `drop_in_place` and `slice_from_raw_parts_mut`
> inside of `{pin_}init_array_from_fn` functions.
>
> rust/kernel/init.rs | 86 +++++++++++++++++++++++++++++++++++++++++++++
> 1 file changed, 86 insertions(+)
>
> diff --git a/rust/kernel/init.rs b/rust/kernel/init.rs
> index 460f808ebf84..af96d4acc26b 100644
> --- a/rust/kernel/init.rs
> +++ b/rust/kernel/init.rs
> @@ -875,6 +875,92 @@ pub fn uninit<T, E>() -> impl Init<MaybeUninit<T>, E> {
> unsafe { init_from_closure(|_| Ok(())) }
> }
>
> +/// Initializes an array by initializing each element via the provided initializer.
> +///
> +/// # Examples
> +///
> +/// ```rust
> +/// use kernel::{error::Error, init::init_array_from_fn};
> +/// let array: Box<[usize; 1_000_000_000]>= Box::init::<Error>(init_array_from_fn(|i| i)).unwrap();
> +/// assert_eq!(array.len(), 1_000_000_000);
> +/// ```
> +pub fn init_array_from_fn<I, const N: usize, T, E>(
> + mut make_init: impl FnMut(usize) -> I,
> +) -> impl Init<[T; N], E>
> +where
> + I: Init<T, E>,
> +{
> + let init = move |slot: *mut [T; N]| {
> + let slot = slot.cast::<T>();
> + for i in 0..N {
> + let init = make_init(i);
> + // SAFETY: since 0 <= `i` < N, it is still in bounds of `[T; N]`.
> + let ptr = unsafe { slot.add(i) };
> + // SAFETY: The pointer is derived from `slot` and thus satisfies the `__init`
> + // requirements.
> + match unsafe { init.__init(ptr) } {
> + Ok(()) => {}
> + Err(e) => {
> + // We now free every element that has been initialized before:
> + // SAFETY: The loop initialized exactly the values from 0..i and since we
> + // return `Err` below, the caller will consider the memory at `slot` as
> + // uninitialized.
> + unsafe { ptr::drop_in_place(ptr::slice_from_raw_parts_mut(slot, i)) };
Beware that this isn't unwind-safe.
You probably want to use a guard for dropping and set a field of that
guard in each iteration (a very common pattern in the Rust standard
library).
> + return Err(e);
> + }
> + }
> + }
> + Ok(())
> + };
> + // SAFETY: The initializer above initializes every element of the array. On failure it drops
> + // any initialized elements and returns `Err`.
> + unsafe { init_from_closure(init) }
> +}
> +
> +/// Initializes an array by initializing each element via the provided initializer.
> +///
> +/// # Examples
> +///
> +/// ```rust
> +/// use kernel::{sync::{Arc, Mutex}, init::pin_init_array_from_fn, new_mutex};
> +/// let array: Arc<[Mutex<usize>; 1_000_000_000]>=
> +/// Arc::pin_init(pin_init_array_from_fn(|i| new_mutex!(i))).unwrap();
> +/// assert_eq!(array.len(), 1_000_000_000);
> +/// ```
> +pub fn pin_init_array_from_fn<I, const N: usize, T, E>(
> + mut make_init: impl FnMut(usize) -> I,
> +) -> impl PinInit<[T; N], E>
> +where
> + I: PinInit<T, E>,
> +{
> + let init = move |slot: *mut [T; N]| {
> + let slot = slot.cast::<T>();
> + for i in 0..N {
> + let init = make_init(i);
> + // SAFETY: since 0 <= `i` < N, it is still in bounds of `[T; N]`.
> + let ptr = unsafe { slot.add(i) };
> + // SAFETY: The pointer is derived from `slot` and thus satisfies the `__pinned_init`
> + // requirements.
> + match unsafe { init.__pinned_init(ptr) } {
> + Ok(()) => {}
> + Err(e) => {
> + // We now have to free every element that has been initialized before, since we
> + // have to abide by the drop guarantee.
> + // SAFETY: The loop initialized exactly the values from 0..i and since we
> + // return `Err` below, the caller will consider the memory at `slot` as
> + // uninitialized.
> + unsafe { ptr::drop_in_place(ptr::slice_from_raw_parts_mut(slot, i)) };
> + return Err(e);
> + }
> + }
> + }
> + Ok(())
> + };
> + // SAFETY: The initializer above initializes every element of the array. On failure it drops
> + // any initialized elements and returns `Err`.
> + unsafe { pin_init_from_closure(init) }
> +}
> +
> // SAFETY: Every type can be initialized by-value.
> unsafe impl<T, E> Init<T, E> for T {
> unsafe fn __init(self, slot: *mut T) -> Result<(), E> {
next prev parent reply other threads:[~2023-08-06 16:07 UTC|newest]
Thread overview: 30+ messages / expand[flat|nested] mbox.gz Atom feed top
2023-07-29 9:09 [PATCH v3 00/13] Quality of life improvements for pin-init Benno Lossin
2023-07-29 9:09 ` [PATCH v3 01/13] rust: init: consolidate init macros Benno Lossin
2023-07-29 9:09 ` [PATCH v3 02/13] rust: init: make `#[pin_data]` compatible with conditional compilation of fields Benno Lossin
2023-08-01 10:50 ` Alice Ryhl
2023-08-02 17:47 ` Gary Guo
2023-08-05 17:04 ` Martin Rodriguez Reboredo
2023-07-29 9:09 ` [PATCH v3 03/13] rust: add derive macro for `Zeroable` Benno Lossin
2023-07-31 2:51 ` Boqun Feng
2023-07-29 9:09 ` [PATCH v3 04/13] rust: init: make guards in the init macros hygienic Benno Lossin
2023-08-02 17:52 ` Gary Guo
2023-07-29 9:09 ` [PATCH v3 05/13] rust: init: wrap type checking struct initializers in a closure Benno Lossin
2023-08-02 17:52 ` Gary Guo
2023-07-29 9:09 ` [PATCH v3 06/13] rust: init: make initializer values inaccessible after initializing Benno Lossin
2023-08-02 17:59 ` Gary Guo
2023-07-29 9:09 ` [PATCH v3 07/13] rust: init: add `..Zeroable::zeroed()` syntax for zeroing all missing fields Benno Lossin
2023-08-02 18:05 ` Gary Guo
2023-07-29 9:10 ` [PATCH v3 08/13] rust: init: Add functions to create array initializers Benno Lossin
2023-07-31 3:00 ` Boqun Feng
2023-08-05 17:11 ` Martin Rodriguez Reboredo
2023-08-06 16:07 ` Gary Guo [this message]
2023-07-29 9:10 ` [PATCH v3 09/13] rust: init: add support for arbitrary paths in init macros Benno Lossin
2023-08-06 16:07 ` Gary Guo
2023-07-29 9:10 ` [PATCH v3 10/13] rust: init: implement `Zeroable` for `UnsafeCell<T>` and `Opaque<T>` Benno Lossin
2023-08-05 17:12 ` Martin Rodriguez Reboredo
2023-08-06 16:08 ` Gary Guo
2023-07-29 9:10 ` [PATCH v3 11/13] rust: init: make `PinInit<T, E>` a supertrait of `Init<T, E>` Benno Lossin
2023-08-06 16:09 ` Gary Guo
2023-07-29 9:10 ` [PATCH v3 12/13] rust: init: add `{pin_}chain` functions to `{Pin}Init<T, E>` Benno Lossin
2023-08-05 17:15 ` Martin Rodriguez Reboredo
2023-07-29 9:10 ` [PATCH v3 13/13] rust: init: update expanded macro explanation Benno Lossin
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20230806170708.174cc26c.gary@garyguo.net \
--to=gary@garyguo.net \
--cc=alex.gaynor@gmail.com \
--cc=aliceryhl@google.com \
--cc=benno.lossin@proton.me \
--cc=bjorn3_gh@protonmail.com \
--cc=boqun.feng@gmail.com \
--cc=lina@asahilina.net \
--cc=linux-kernel@vger.kernel.org \
--cc=nmi@metaspace.dk \
--cc=ojeda@kernel.org \
--cc=rust-for-linux@vger.kernel.org \
--cc=wedsonaf@gmail.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.