All of lore.kernel.org
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Danilo Krummrich" <dakr@kernel.org>
Cc: ojeda@kernel.org, linux-pci@vger.kernel.org
Subject: Re: [PATCH REF v4 24/27] gpu: nova-core: use lifetime for Bar
Date: Fri, 22 May 2026 01:28:40 +0000	[thread overview]
Message-ID: <20260522012840.CD1C11F000E9@smtp.kernel.org> (raw)
In-Reply-To: <20260521233501.1191842-25-dakr@kernel.org>

Thank you for your contribution! Sashiko AI review found 2 potential issue(s) to consider:
- [High] The raw pointer cast artificially extends a short-lived local reference to the `'bound` lifetime, bypassing the borrow checker and causing undefined behavior.
- [High] Creating a self-reference to a standard, non-Opaque field violates Rust's aliasing rules and causes Undefined Behavior.
--

commit 324bc88b7f0822485a9eb9d34c17aabba9845b74
Author: Danilo Krummrich <dakr@kernel.org>
Subject: gpu: nova-core: use lifetime for Bar

This commit removes the Arc<Devres<Bar0>> indirection and replaces it with
a lifetime-parameterized pci::Bar<'bound> in NovaCore. It passes a borrowed
reference to Gpu<'bound> by attempting to use a self-reference during pin
initialization.

> diff --git a/drivers/gpu/nova-core/driver.rs b/drivers/gpu/nova-core/driver.rs
> index d3f2245ba2e0c..d4cf4379ee87c 100644
> --- a/drivers/gpu/nova-core/driver.rs
> +++ b/drivers/gpu/nova-core/driver.rs

[ ... ]

> @@ -95,14 +93,14 @@ fn probe<'bound>(
>              // other threads of execution.
>              unsafe { pdev.dma_set_mask_and_coherent(DmaMask::new::<GPU_DMA_BITS>())? };
>  
> -            let bar = Arc::new(
> -                pdev.iomap_region_sized::<BAR0_SIZE>(0, c"nova-core/bar0")?
> -                    .into_devres()?,
> -                GFP_KERNEL,
> -            )?;
> -
>              Ok(try_pin_init!(NovaCore {
> -                gpu <- Gpu::new(pdev, bar.clone(), bar.access(pdev.as_ref())?),
> +                bar: pdev.iomap_region_sized::<BAR0_SIZE>(0, c"nova-core/bar0")?,
> +                // TODO: Use &bar self-referential pin-init syntax once available.
> +                //
> +                // SAFETY: bar is initialized before this expression is evaluated
> +                // (try_pin_init!() initializes fields in declaration order), lives at a pinned
> +                // stable address, and is dropped after gpu (struct field drop order).
> +                gpu <- Gpu::new(pdev, unsafe { &*core::ptr::from_ref(bar) }),

[Severity: High]
Does coercing this local reference through a raw pointer artificially extend
its lifetime to 'bound?

Since Gpu<'bound> requires its bar reference to live for the 'bound lifetime
(which is tied to the PCI device), and the NovaCore allocation has a strictly
shorter lifespan than the device itself, could this forged lifetime bypass
the borrow checker and cause undefined behavior?

[Severity: High]
Could creating a self-reference to a standard, non-Opaque field here violate
Rust's aliasing rules?

Because bar is not wrapped in kernel::types::Opaque, any subsequent mutable
borrow of the NovaCore struct (such as when the allocation is finalized into
a Pin<Box<NovaCore>>) asserts exclusive mutable access over all its fields.

Wouldn't this recursively invalidate the shared reference to Bar0 stored
inside gpu, leading to undefined behavior upon later access?

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260521233501.1191842-1-dakr@kernel.org?part=24

  reply	other threads:[~2026-05-22  1:28 UTC|newest]

Thread overview: 63+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-05-21 23:34 [PATCH v4 00/27] rust: device: Higher-Ranked Lifetime Types for device drivers Danilo Krummrich
2026-05-21 23:34 ` [PATCH v4 01/27] rust: alloc: remove `'static` bound on `ForeignOwnable` Danilo Krummrich
2026-05-22  0:13   ` sashiko-bot
2026-05-21 23:34 ` [PATCH v4 02/27] rust: driver: move 'static bounds to constructor Danilo Krummrich
2026-05-21 23:34 ` [PATCH v4 03/27] rust: driver: decouple driver private data from driver type Danilo Krummrich
2026-05-21 23:56   ` sashiko-bot
2026-05-21 23:34 ` [PATCH v4 04/27] rust: driver core: drop drvdata before devres release Danilo Krummrich
2026-05-22  0:10   ` sashiko-bot
2026-05-21 23:34 ` [PATCH v4 05/27] rust: pci: implement Sync for Device<Bound> Danilo Krummrich
2026-05-21 23:34 ` [PATCH v4 06/27] rust: platform: " Danilo Krummrich
2026-05-21 23:34 ` [PATCH v4 07/27] rust: auxiliary: " Danilo Krummrich
2026-05-21 23:34 ` [PATCH v4 08/27] rust: usb: " Danilo Krummrich
2026-05-22  0:16   ` sashiko-bot
2026-05-21 23:34 ` [PATCH v4 09/27] rust: device: " Danilo Krummrich
2026-05-21 23:34 ` [PATCH v4 10/27] rust: device: make Core and CoreInternal lifetime-parameterized Danilo Krummrich
2026-05-25  4:21   ` Eliot Courtney
2026-05-25 11:02   ` Alexandre Courbot
2026-05-21 23:34 ` [PATCH v4 11/27] rust: pci: make Driver trait lifetime-parameterized Danilo Krummrich
2026-05-22  0:14   ` sashiko-bot
2026-05-21 23:34 ` [PATCH v4 12/27] rust: platform: " Danilo Krummrich
2026-05-21 23:34 ` [PATCH v4 13/27] rust: auxiliary: " Danilo Krummrich
2026-05-21 23:34 ` [PATCH v4 14/27] rust: usb: " Danilo Krummrich
2026-05-22  0:23   ` sashiko-bot
2026-05-25  4:31   ` Eliot Courtney
2026-05-21 23:34 ` [PATCH v4 15/27] rust: i2c: " Danilo Krummrich
2026-05-21 23:34 ` [PATCH v4 16/27] rust: driver: update module documentation for GAT-based Data type Danilo Krummrich
2026-05-21 23:34 ` [PATCH v4 17/27] rust: pci: make Bar lifetime-parameterized Danilo Krummrich
2026-05-22  0:49   ` sashiko-bot
2026-05-25  4:37   ` Eliot Courtney
2026-05-25 11:40     ` Gary Guo
2026-05-25 12:05       ` Danilo Krummrich
2026-05-25 11:10   ` Alexandre Courbot
2026-05-25 11:12     ` Alexandre Courbot
2026-05-21 23:34 ` [PATCH v4 18/27] rust: io: make IoMem and ExclusiveIoMem lifetime-parameterized Danilo Krummrich
2026-05-22  0:45   ` sashiko-bot
2026-05-25 13:10   ` Alexandre Courbot
2026-05-21 23:34 ` [PATCH v4 19/27] samples: rust: rust_driver_pci: use HRT lifetime for Bar Danilo Krummrich
2026-05-22  1:27   ` sashiko-bot
2026-05-25 13:55   ` Alexandre Courbot
2026-05-21 23:34 ` [PATCH v4 20/27] gpu: nova-core: separate driver type from driver data Danilo Krummrich
2026-05-25  4:40   ` Eliot Courtney
2026-05-25 14:11   ` Alexandre Courbot
2026-05-21 23:34 ` [PATCH v4 21/27] rust: types: add `ForLt` trait for higher-ranked lifetime support Danilo Krummrich
2026-05-22  0:31   ` sashiko-bot
2026-05-23 15:46   ` Danilo Krummrich
2026-05-25 12:31     ` Eliot Courtney
2026-05-21 23:34 ` [PATCH v4 22/27] rust: auxiliary: generalize Registration over ForLt Danilo Krummrich
2026-05-22  0:49   ` sashiko-bot
2026-05-25  6:03   ` Eliot Courtney
2026-05-25 14:42   ` Alexandre Courbot
2026-05-21 23:34 ` [PATCH v4 23/27] samples: rust: rust_driver_auxiliary: showcase lifetime-bound registration data Danilo Krummrich
2026-05-25 14:48   ` Alexandre Courbot
2026-05-21 23:34 ` [PATCH REF v4 24/27] gpu: nova-core: use lifetime for Bar Danilo Krummrich
2026-05-22  1:28   ` sashiko-bot [this message]
2026-05-26  2:10   ` Alexandre Courbot
2026-05-26  5:48     ` Alexandre Courbot
2026-05-21 23:34 ` [PATCH REF v4 25/27] gpu: nova-core: unregister sysmem flush page from Drop Danilo Krummrich
2026-05-22  0:47   ` sashiko-bot
2026-05-21 23:34 ` [PATCH REF v4 26/27] gpu: nova-core: replace ARef<Device> with &'bound Device in SysmemFlush Danilo Krummrich
2026-05-22  0:46   ` sashiko-bot
2026-05-21 23:34 ` [PATCH REF v4 27/27] gpu: drm: tyr: use lifetime for IoMem Danilo Krummrich
2026-05-22  0:42   ` sashiko-bot
2026-05-22 10:14 ` [PATCH v4 00/27] rust: device: Higher-Ranked Lifetime Types for device drivers Greg KH

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260522012840.CD1C11F000E9@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=dakr@kernel.org \
    --cc=linux-pci@vger.kernel.org \
    --cc=ojeda@kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.